FBI Director Comments on San Bernardino Matter
fbi.gov
fbi.gov
So why are they asking the courts to stretch the 1789 All Writs Act beyond its breaking point, instead of going to Congress for a new law? The magistrate that signed off on this isn't even an Article III judge.
So who is pushing who exactly? And who has a louder voice in criminal justice matters than the FBI?
The FBI would love a federal law that forces Apple to crack phones for them. Since they don't have one, they are trying to get a court to invent one by stretching the All Writs Act.
This is why we have Rule of Law. There is no "we follow the law when it seems reasonable". Whatever the law is, it should be followed, and it does not matter at all what anyone's personal opinion is regarding what the law should be.
Perhaps it is more complex than this, for example in cases of civil disobedience. However, civil disobedience is for cases of conscience when you cannot personally participate in something that is immoral, so you refuse to participate or you protest it. The key here is that this is ignoring the law to resist immoral uses of power, not ignoring the law to remove intentional restrictions to the application of allocated authority.
This applies doubly to the legal system itself. An appeal to the inability of legislatures to "get things done" has been the argument of every tyrant since Caesar.
I can't think of any at the moment but I don't think anyone in a position to do anything with an answer is trying. The issue is too good a political bludgeon to bother even seeking some creative solution to the problem (again, not that I am 100% sure there even is a legislative solution that wouldn't be a vastly undesirable and possibly unconstitutional blow to encryption).
It is not a good starting presumption that no reasonable answer can be reached, especially when the topic under discussion isn't a core issue like "backdoor all encryption" but rather "is it possible to pass reasonable and generally acceptable legislation such that Apple can legally be compelled to aid this decryption effort without setting a terrible precedent?" There may be no solution to that problem, which is fine, but don't suggest that I was endorsing some vaguely Orwellian shit because I don't presume as a given that our opponents on the general issue of encryption have malicious aspirations of tyranny.
We can't kill every charismatic person, and we can't prevent hard times. We can insist on the rule of law.
Normally when people intentionally misread me in the most uncharitable fashion possible I can at least see the deranged logic, but in your case I can't see what evil you claim I am advancing or how you arrived at that conclusion.
I understand your clarification, I was nitpicking that you were saying my response to the original comment was 'crazy' or something, but without the context you gave in your reply I think my original response was appropriate.
I agree with your larger point, there is probably a workable solution that balances the threat of government with the benefits of government, but I disagree that it is 'not getting things done' that is the cause of us not finding that compromise.
In general, I think that appeals to 'a lack of will' are almost always incorrect. People, even politicians, are generally good and want to find good solutions. There is a lot of disagreement on what is a good solution, and even more disagreement on what the long term consequences of choices are. This is why there is gridlock, and if you read the Federalist Papers (in the case of the US), you will see that this gridlock is a Feature of the system, not a Bug.
I think we are fine though, we are safer than ever before. We don't need to extend government snooping power, because there is no need to do so. If someone disagrees, that is fine, but that is why we have a speed governor.
People have always complained about decisions being made too slowly, but they have never been made faster, if anything they are made more quickly now than ever before. Congress used to only meet a few times a year for a few weeks!
I want the legislature to be passing laws rolling back the security state, I want them to cancel or rework programs that don't work across the board. They can't do those things if they spend all their time in some arcane ritual circle jerk whose only and ultimate goal is just to make some of the other participants ultimately look more ridiculous than other participants.
We've normalized and accepted parliamentarian bullshit at the expense of governing (on both sides, but the republicans are the undisputed masters of the dark arts) for a couple decades now. Legislative lethargy (sorry, had to) is supposed to derive from lengthy debate and substantive disagreement, not from participants purposely tanking the process to score points in the cheap seats. Part of the reason that they got shit done in a couple of weeks in ye-olden-congress is that it was closer to a turn based game, news traveled slower and so the results of the whole session were what constituted news, not every little BS stunt.
The frustrated and vindictive part of me hopes that not a single senator or congressman pays a price for their cynical abandonment of their duty to govern. That way, next term we see months long shutdowns of the whole federal government and a collapse of federal services until [Bernie|Hillary] signs a budget that reallocates all non-entitlement social spending to some insane shit that polled well among likely voters suffering from bathtub-gin induced brain damage. The revolting (both senses) congressmen won't actually care about getting the spending reallocated, but them "standing up to" [Bernie|Hillary] will play well with their group so so be it.
Edit: to clarify the frustrated and vindictive part would be rooting for it in the sense that the worst part about democracy is that people get the government they deserve, and at the moment it doesn't seem like the process thinks we deserve much.
Stop with your short sighted, historically ignorant whining already.
And no, "Congress gridlock" is not a good response to abusing existing laws.
There is a fundamental conflict with how law enforcement and intelligence does it's job and the way people communicate today. Period.
If people want more secure communications they are going to have to tell the FBI in no uncertain terms "we are ok with you dropping leads."
Apparently in this specific case that has happened as a mother of the slain said:
“This is what separates us from communism, isn’t it? The fact we have the right to privacy,” Adams said to the Post. “This is what makes America great to begin with, that we abide by a constitution that gives us the right of privacy, the right to bear arms, and the right to vote.”
Now, is it up to this mother to make that case? Yea, if the director is to be listened to. After all that is who he invokes when appealing his reasoning. So based on this statement it seems like they should back off, say shit happens, lets mourn our dead and move on.
We need more of the victims to speak out and tell investigations their true thoughts.
Agreed. It's not like the investigators are totally in the dark here, either.
In addition to the rest of the FBI investigation, given the terrorist/national security nature of the case, it's likely that anything the shooters did online during the past few years was pulled and analyzed—including internet history, e-mail, chat and phone conversations—rendering a pretty good picture of both their interests and associations.
If the FBI didn't do this (they can if it's a national security case), then the intelligence community certainly did.
[1] http://www.reuters.com/article/us-apple-encryption-victims-e...
There should be more discussion. Tech companies should seek to understand the government's job to keep people safe, and the government needs to understand that this is a game of whack-a-mole they can't win
It's amazing how many people don't get this. The Congress makes laws, which are the tools at the FBI's disposal. If they didn't give them this particular tool, then too bad: they have to figure out how to do their job without this tool.
And the DFBI did not address the gross incompetence shown by them, when they asked the County to reset the phone. If they didn't even know the consequences of that request, how can they predict the (supposed no) consequences of their request to Apple?
"a) The Supreme Court and all courts established by Act of Congress may issue all writs necessary or appropriate in aid of their respective jurisdictions and agreeable to the usages and principles of law.
(b) An alternative writ or rule nisi may be issued by a justice or judge of a court which has jurisdiction."
This law is basically "The courts can enable discovery and describe implementation of rulings." Setting up the rules of the game.
Could you share why you think that this is a stretch of the AWA? Is it because of the amount of work asked ?
I hate to be in the position of defending the FBI, but this new law would be irrelevant if it's ex post facto, yeah?
I know many people seem to gravitate to the extremes on every issue, but both Cook and Comey are right in saying that we as a nation need to question our fundamental assumptions in our thinking and think through what the would be the best balance between the two, if there be any. As Comey says, and I personally agree with this, the "balance" shouldn't be decided "by corporations that sell stuff for a living" or by "the FBI which investigates for a living,"...or in general, the government. We shouldn't be grass in a fight between two elephants. The American people need to decide how much involvement both government and large multinational corporations have in their lives. That's what this all comes down to, after all.
For one, it is forever weakening the security and privacy of your iphone. Bad guys who want to evade the policy officers will do it anyway with encryption systems/software available from any of the non US territories.
Considering that FBI can get significant meta data from telecom providers(who called whom etc), I think this requirement that FBI has gives little gain in security as the upside and comes with a significant downside[ huge loss in privacy].
Where does the article imply it does? It states correctly that the FBI would have easily hacked it had it been an android.
edit: I'm assuming you're going from this line:
>Although user content is encrypted on Android devices, too, Android is open-source software. Theoretically, the government can produce its own version of the system that would make it possible to hack the encryption.
This is poorly worded, as is the line about how all encryption can be hacked, but he gets the point about how Android would have been vulnerable. I think some of that can be chalked down to writing for the public and not a technical audience.
You are wrong in framing the debate as security vs security. Its like everything else when it comes to liberty and protection. The question is how much liberty are we willing to give up for protection. We can't let a corporation or the government anchor our opinions on the left or right.
Also I believe even without the citation that the notion that criminals can use encryption to protect themselves is pretty obvious.
Is the end goal no longer total information awareness? [0]
Side note: that was a rather scathing and slanted article you cited. It would have been nice to see the simple facts of the case presented in a neutral light.
Yet we don't cripple the effectiveness of these items for the sake of preventing crime. Doing so would only harm the quality of lives of the vast majority of innocent people who we trust to use these thing for their own benefit as free citizitens of a free country.
But investigators can get access to basements, cars, knives and guns and use them to solve the crime. In this case, post-crime, there is no way to gather information that could be important.
Which is irrelevant to how these individual items are used to actually prevent the crime from being solved.
While encryption prevents access to information that may or may not be useful, guns are used to kill witnesses that are never found, shovels are used to burry bodies that take decades to find, cars are impounded or destroyed after a getaway, I could go on. Often enough, even if any of these items are found, it doesn't help solve the crime because the criminal was simply too smart.
I fail to see why encryption is being treated differently than any other legal thing we, as free and innocent citizens, have access to. The cynic in me believes the only actual difference is in the level of familiarity the majority of the voting population has with this particular legal thing. They seem to have, unfortunately, been misinformed and poorly educated about this issue and technology in general.
Technically, there is some limited middle ground due to key escrow (clipper chip[1]) or cryptographic backdoors (DUAL_EC_DRBG[2]).
Both are interesting because the encryption algorithms stay mathematically strong.
Obviously, the golden keys would have to be well-protected. But that's mostly a solved problem; see CAs.
(Of course there's the problem of which governments get the keys. And it's good that Clipper and DUAL_EC_DRBG died.)
[1] https://en.wikipedia.org/wiki/Clipper_chip [2] https://en.wikipedia.org/wiki/Dual_EC_DRBG
That's fine with me. The actions of the few does not justify the loss of privacy for all.
> Most people won't understand till it impacts them personally but imagine if you are robbed of all your money and the answer of who did it lies in a computer you are able to get your hand on. Wouldn't you love it if the police had a backdoor now.
No, I don't. Because that means the police can get into my data at any given time without any oversight and without me ever knowing it. It also means that anyone could attack my system and get that money as well.
I've been in this situation many times in the past, I've lost a lot of sensitive data because I forgot the password to my encrypted DMG files and I've moved on and I still encrypt my stuff in the DMG files.
Do I think the police and others should have a backdoor into my DMG files? No, and there is absolutely nothing that will ever justify it, not even terrorism or even the life of my family.
More Americans have been killed by Americans in the past few years than the entire history of terrorist attacks combined.
How about we take actions to ban guns in the country and see how it works.
> The question is how much liberty are we willing to give up for protection.
None. I don't deserve protection if I don't care about my privacy.
> We can't let a corporation or the government anchor our opinions on the left or right.
Sure we can, by voting and with our money. People trust Apple because they do focus on security of their devices.
It was the same thing with RIM/BlackBerry.
https://twitter.com/matthew_d_green/status/70115236890220134...
https://twitter.com/matthew_d_green/status/70115264061335142...
https://twitter.com/matthew_d_green/status/70115296105404006...
https://twitter.com/matthew_d_green/status/70115860701918412...
https://twitter.com/matthew_d_green/status/70115891912992768...
Certainly Comey is being deceitful in his first sentence. Even Hillary called for a Manhattan-like project to circumvent encryption back in December [1]. That shows it's something that's being discussed in Washington quite frequently.
I doubt any will ever admit they're trying to lead us towards an Orwellian state. Also, encryption is part of our protection from that. Heads of state and encryption currently appear to be directly at odds.
[1] http://www.cbsnews.com/news/democratic-debate-transcript-cli...
No mention of the iCloud password reset either.
Exactly. How can you not address that?
They necessitated this whole mess through their actions. I try not to ascribe malice to what can easily be explained through incompetence, but to not even mention it? Shameful.
Yeah, sorry, but I don't think I'm gonna trust them even though they promise it will only be this one time.
I'd love to live in a world where I trusted a government, which is supposed to be a composition of its people, more than a profit-motivated, self-interested business, but in some weird turn of events, something vastly different has festered in the last 15 years. You blew it, you asshole, you and every other cop.
America is entirely being driven by fear and anger. The current presidential race is a perfect reflection of the hate, anger, and fear that Americans believe exists. The system is a reflection of what the "good" people allow to happen.
The FBI has a job, and Apple has a commitment to its customers. Technology is going to get more advanced, does that mean that we should let it be a tool to obstruct justice. You may not trust the people tasked with the investigation, but people should also look at the fact that the encryption here is obstructing justice.
Tomorrow if a criminal kidnaps a bus of school children and the police are able to get a hold of a locked phone that holds their location, would you be as opposed to the current situation?
The creation of a method to disable the phones encryption is a slippery road, but the option of not aiding the FBI is also a slippery road. This is a organization created to protect the people.
We need to have a open discourse on how the information can be taken off this phone while minimizing the loss of public security and privacy . This is not a black and white issue like many people are treating it.
And just to make it clear, I do agree that the government has done extremely questionable things as well as committed offenses against the publics privacy. We need to fix the issue of distrust, because a lack of trust in our system is equal to cancer within a body.
No, it isn't. The phone they're trying to break into was the shooter's work phone, provided by his employer. He physically destroyed his personal phone before the acts in question. The idea that he kept relevant information on his work phone, which he left intact, is absurd.
(What the probability is though is hard for me to predict as I don't have enough information, but assuming he didn't have any slip ups on his work phone is a bad assumption. If there is a 1 percent chance that future attacks of similar scope could be prevented by knowledge gathered about this case, is it not our obligation to find out? Its a complex issue that the courts and media will play out over the next few months)
Did the shooter take the phone with him when meeting with accomplices? If so, perhaps there's GPS info on the phone.
What are the gaps in standard behavior (i.e. phone turned off...). Are these times where the FBI should dig deeper to discover the actions of the shooter?
The idea that bulk collection of metadata is objectionable is something we're seeing in civilized technical circles. Individual collection of the same is even worse.
Second, our system is essentially set up to make me powerless. It's actually engineered that way. I do what I can to educate people around me, but when it comes to voting or having any control over who's in office or who officiates our most important government positions, the ball's not just not in our court, it's on another planet.
Technology, as you said, will continue to get much more advanced. I reckon at some point, literally every moment of our lives will be perfectly catalogued, from birth to death. This is why what Mr. Comey wants scares me so much, because you can practically hear him salivating in that letter.
We have guarantees built into our constitutional freedoms, and one of the most important guarantees is that the government can't compel us to do things. Sure, there are laws to maintain the peace and common order, but you don't have to house or attend to military in your home, you don't have to testify against yourself, you're not compelled by police to follow their wishes until you're under arrest (which they ostensibly can't do without probable cause), and you don't have to aide in an investigation if you're not involved. These are vital because the moment we're legally compelled to aide investigators, all bets are off. We are no longer able to even protect ourselves against undue search and seizure.
Look at history. The encryption the Nazis had created helped them commit terrible acts of war and it was the backdoor the Allies discovered that helped bring justice to them.
I'm being devils advocate here because I don't people should view this as "us vs them". Comey may seem like he is salivating to you, but he does raise the notion that at the other end is a corporation, who also has an agenda.
Are you suggesting the Nazi's were the only ones to use encryption during World War II?
You forgot to mention at least 9 other nations (including the USA)
This is a two way street.
So can literally anything in the wrong hands, though.
Of course encryption will obstruct justice in some cases. The same applies equally to the 4th amendment. Sometimes criminals will escape justice because the means to identify them are simply not reasonable. Obstructing justice is not always considered a bad thing. Where we draw the line is crucially important.
The law demands that the particulars of the crime are irrelevant. We must accept that whatever capability we give police can be deployed, with probable cause, in any criminal investigation. So I'll completely ignore your hypothetical case. If bypassing encryption is possible, then bypassing encryption becomes routine. Apple was routinely tasked under the AWA to assist in recovering phone data prior to them deploying encryption which they believed they could not crack.
Worse still is the fact that all police powers will be, at times, abused by the police. So another important question is are you comfortable with this capability being used disproportionately against the poor and marginalized, being used to harass and intimidate, and being used to suppress political dissent?
I believe the police must be capable of working with some limitations on their ability to access our personal electronic devices. Compelling manufacturers to create backdoors in our devices to bypass their security might help the police solve cases, but it would do at an unacceptable risk to the security and privacy of everyone who uses those devices. Generally available and widely usable encryption is a vital national interest. It is the linchpin enabling trillions of dollars of electronic commerce. Even if you dilude yourself into thinking the backdoor would only be lawfully accessed, its mere existence would inflict real economic damage by furthering global distrust of American technology. And it would set the stage for even more troubling backdoors in the future, because the All Writs Act is the wrong legal framework for them to get it.
Under the AWA, how is compelling the creation of this backdoor any different from compelling creation of any software which might produce evidence of co-conspirators? If tomorrow the FBI wants access to an iPhone 6s's camera and microphone, or the ability to remotely download the phone's contents? What if the FBI needs Mozilla to install a backdoor in the Tor Browser Bundle? How can the AWA grant one backdoor and not the other?
This directly contradicts Tim Cook's statement, in fact he used the same term "master key":
> In the physical world, it would be the equivalent of a master key, capable of opening hundreds of millions of locks — from restaurants and banks to stores and homes.
It either is a master key or it isn't.
the FBI asked for a specialised OS image that would have a check so that it could only work on this specific phone. Combined with Apple's encryption/signing of the update, this image could not be applied to any other device.
So the "work" asked of Apple would produce something that would only work on the phone with the warrant
"Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession. The FBI may use different words to describe this tool, but make no mistake: Building a version of iOS that bypasses security in this way would undeniably create a backdoor. And while the government may argue that its use would be limited to this case, there is no way to guarantee such control."
The software asked for by the FBI would only work on one phone because it would both have a check for the specific phone, and be signed by Apple (so can't be modified).
The software would need to be modified and resigned by Apple to be used on another phone.
You really, honestly, truly and genuinely believe that if Apple just does this for them, just this one time, just for this one phone, then that's the end of it? That the FBI and other law-enforcement agencies would never, not once, not for the rest of the lifetime of the universe (and certainly not, say, about 24 hours later) come back and say "Well, we're glad you helped us with that case, now here's this list of other cases we'd like help with, and now you've proven that you can do this we're going to be bringing you a lot of these"?
That's what Tim Cook is worried about: it won't stop with this one phone unless it's stopped before that one phone gets unlocked and becomes the precedent that makes this just another routine thing. Every now-routine violation of privacy and security was originally marketed as "just this one case, this one's unique and special and sensitive and we absolutely have to get it done, just this one, trust us" and eventually morphed into "eh, it's Tuesday, time to ship off another truckload of requests to have this done to people".
The slippery slope argument being applied here is that FBI search warrants will now work on phones less than the iPhone 5S from now on (until Apple closes the iOS update backdoor I guess). This is far from "China will be able to mass-hack into iPhones from now on"-style comments I've seen from others.
The fact is that Apple left a backdoor in their phones and are now being told to exploit it. An argument against having the backdoor in the first place.
Furthermore, the US legal system encourages elaboration on stare decisis, applying prior case law to novel cases rather than hashing out new decisions. This means that creative applications of this ruling ("give me an uncontrolled backdoor") are simply a question of time once the landmark case is made.
What this case is doing is setting precedent that the courts can compel a company to _create_, no matter how trivial one may think that creation may be today. _That_ is the precedent so many draw exception to, because stare decisis is also a doctrine of incrementalism, of gradual expansion of interpretations. Today Apple is compelled to create a very controlled firmware; who's to say in the figurative tomorrow that Samsung won't be compelled to create and send a firmware update to a specific Blu-Ray player that creates an air microphone out of the laser? Where does it stop?
To be complete (as was pointed out in another sibling thread) incrementalism may be curtailed if implications are carefully argued and acknowledged by the judge. I am skeptical of the value of that approach, but have no hard argument against it.
You can't even downgrade to an old iOS version, because Apple won't sign them anymore.
At this point, the only valid answer from Apple is that any future devices (if they aren't this way already) should either require the password to do a software update, or wipe the phone.
The core thing that makes this not a master key is that Apple has to make the decision to comply on each phone (and warrant). Which gives them the opportunity to push back if it chooses to. If the FBI has somebody's phone and secretly wants to unlock it, it can't without going through the courts and Apple.
At that point we should expect more world governments to get the key. Where does that end? Maybe with more companies having to demonstrate that they defend against their own subversion.
Apple could sign it offline when installing to the device.
The signature is customised to each device it's installed on, and has a nonce so it can't be saved.
The US legal system and education pertaining to it is largely composed of studying prior case law and its applications. Few cases (including this one) involve truly new decisions, and even those are usually novel applications of former decisions. That is what those who can see past their nose are concerned about. There is every probability that, in the near future, one or both of Apple or the judicial system will tire of the farce of one-phone-per-case firmware and request a new application of the law (because there would now be precedent).
To take any laywer-moderated statement (including Apple's) at face value belies credulity that does not become the HN audience. As others have pointed out, Comey's appeals to emotion and terrorism should be enough, but the idea that an FBI lawyer would advise pursuing this particular case in this particular manner without expecting to set precedent? Positively silly. This is what they do.
If a new case is not similar to this case, then this case doesn't count as precedent. If a new case is similar to this case, then the arguments put forward for this case apply to the new case, and we shouldn't care about precedent setting. If the new case is similar but different in important ways, then when that new case is fought, the lawyers point ou the substantive differences, and it doesn't count as precedent.
The only concern would seem to be if the future court fails to analyse a case properly. But they can fail regardless of what precedent is or is not set.
I don't think individual cases should be ruled improperly because of concern about the precedent effect. You might want meta-level rules (e.g. Bill of Rights, free speech), but the individual actors should not be taking them into account except insofar as they have been legislated (although the Supreme Court perhaps should).
TL;DR argue the damn object level.
Whatever you think they should do, judges absolutely consider the precedent effect when ruling on accepting arguments, and lawyers most certainly consider precedent and setting it when presenting those arguments. There may be some intentional offloading of those decisions from lower courts to the appeals process, but no judge makes their decision in a vacuum. Nor should they.
I mention that only when people assert incorrect facts about the case. Correcting someone when they're wrong about a matter of fact does not imply any legal opinions.
About your point: there's a difference between "If I agree with argument X in this case, I should agree with it in that case; however, X shouldn't apply in that case, and I can make no principled distinction between the two. Therefore, X can't apply even in this case" and "I agree with argument X in this case, but not in that case; here's a principled distinction between the two; however, since it might lead to someone misinterpreting it down the line, I'm going to rule against X."
The first is a concern for precedent that I'm fine with, the second is not. My understanding is that judges will lay out the reason X applies here but wouldn't apply in the other hypothetical, which makes the concern about it being used as precedent later unwarranted.
The form of the argument here seems to be the second. "Yeah, this one is mostly fine, but we're fighting because of precedent. If they can force us to sign software and install it on a single phone, who's to stop them from forcing us to put software on every device we sell?"
And the clear distinction between the two is that one is only being put on phones that have a warrant (and belong to the government, to boot), and the other would also harm innocents. So the proper response should be "comply with this order, but specifically because of the fact that no innocents are being caught up", and that way it doesn't set any harmful precedents.
Or if you think there's a different reason why this case is fine but the general case isn't, then that itself is a reason for the general case not to have this case as precedent. Whatever those reasons are, make them explicit. If Apple puts those arguments into the court record, and the judge explicitly says "it's ok for X but not for Y",that defeats the harmful precedent.
Am I misunderstanding anything, or do we just disagree?
I think you're applying some fairly strict high-mindedness to the US legal system while others (myself included) worry that creative extension of intent appears rampant in cases that touch on technology or terrorism and therefore fall into your second form. Many of us don't, as a general rule, trust the courts, law enforcement, or our government to do anything but what is politically expedient and beneficial to them at the moment.
While the wording of this ruling is about one phone and a particular method the FBI has laid out, it appears to set precedent that law enforcement can compel a product company create a non-existent product (no matter how trivial) in order to exploit a known security vulnerability in one of their products. This is what concerns me and many others, because it brings us very short steps away from "make us a version that works against the Secure Enclave" to "make it work as an OTA update over WiFi" to then "make it work as an OTA update over cellular" and subsequently "make a version we can incorporate into a StingRay" and forward. None of these would be illogical steps to take in abject pursuit of stamping out terrorism and might even applauded by parts of society, but taken as what some perceive as an inevitable whole they paint a dim picture for personal privacy.
It's an improbable coincidence that the FBI has elected this particular charged case in which to stake their flag. Given their pleas with technology companies for cooperation over bypassing cryptography in recent months, this appears to be a logical continuation of that campaign.
In conclusion, we likely disagree, specifically due to my cynicism and your seeming lack thereof.
My main point related to this was above:
>The only concern would seem to be if the future court fails to analyse a case properly. But they can fail regardless of what precedent is or is not set.
To argue against that, you'd need to claim that precedent makes it easier for the later court to fail. Do you have examples, where it should have been clear that precedent didn't apply, yet the court reached the conclusion that it did, incorrectly?
(Preferably in important cases.)
>While the wording of this ruling is about one phone and a particular method the FBI has laid out, it appears to set precedent that law enforcement can compel a product company create a non-existent product (no matter how trivial) in order to exploit a known security vulnerability in one of their products.
I've said elsewhere that this argument seems to be useless. If Apple says it's "unreasonable" to expect them to do this, then they might be forced to hand over the source code, and the FBI will create it themself. The problem is
1. iOS is closed source and
2. iPhone requires a signature from Apple
If Apple doesn't help them, they could conceivably be forced to simply hand the keys and code over. It's a benefit to Apple to be able to create it themselves and maintain control over the keys.
>This is what concerns me and many others, because it brings us very short steps away from "make us a version that works against the Secure Enclave" to "make it work as an OTA update over WiFi" to then "make it work as an OTA update over cellular"
All of these seem fine, assuming that Apple is not modifying the phones to make it easier to hack. In other words, I agree that they follow as direct precedent from this case. (Although they can decide to only update a phone after a proper warrant.)
>make a version we can incorporate into a StingRay
This is the part that doesn't follow from precedent. Giving over control of the tool to the FBI who could use it without a warrant is novel, and would require a judge to justify it.
>In conclusion, we likely disagree, specifically due to my cynicism and your seeming lack thereof.
Maybe I'm just more cynical than you. You worry about a future court doing the wrong thing because they're misled by precedent here, I'm worried about a future court doing the wrong thing just because. I don't think the risk goes up significantly based on this precedent, because I think it could happen anyway.
>It's an improbable coincidence that the FBI has elected this particular charged case in which to stake their flag. Given their pleas with technology companies for cooperation over bypassing cryptography in recent months, this appears to be a logical continuation of that campaign.
Pure tinfoil material here. Do you know of any cases where the FBI had a phone but didn't try to unlock it, that could be said to be as urgent as this? This isn't the only court case with Apple going on, it's merely the one that got a lot of attention, and certainly much of that attention is Apple's fault (not all, but a lot).
No, I'm arguing that incrementalism means the court doesn't have to fail (as a court) - the follow-on steps that I outlined and you found perfectly acceptable will not stop wherever you personally think they will, nor have I outlined (or even imagined) all the incrementally creative applications of this case that will likely follow. I'm also arguing (which you didn't counter) that this case lays the groundwork for the FBI to request _new_ products from companies.
> This is the part that doesn't follow from precedent. Giving over control of the tool to the FBI who could use it without a warrant is novel, and would require a judge to justify it.
I was being brief to illustrate, not to set a literal expectation of progression; I'm not here to present an argument for court. Giving the FBI control over the tool could be argued at any point in the very long lifetime of this decision, be it tomorrow or years from now. Perhaps after the courts have decided to allow for multiple devices or when suspect X is holed up for weeks in their cabin eating pizza and playing candy crush and the FBI cannot reach them by normal investigative means.
> Pure tinfoil material here.
Perhaps. Consider the probable value of the data on the phone beyond what's already available externally. Consider that the FBI could have simply requested Apple provide the data on the phone instead of specifying the mechanism and thereby creating precedent that they can compel a company to create something new. Consider that, in spite of generally dim views of the FBI's technical capabilities, the FBI usually provides sound, conservative advice with regard to electronic evidence (as a forensic analyst I've been party to a lot). Consider that over the past year+ the FBI has been protesting with little effect in congressional hearings that $todays_crime_buzzword are "going dark", that technology companies need to cooperate with them, that "securely insecure" (my words) systems are possible if created "at the design level" (not my words). They were nearly shouted down in those hearings. Consider the subsequent public visit the FBI and others made to Silicon Valley, extending an olive branch and returning effectively empty-handed.
Then consider that this case, involving an older and still-vulnerable version of a technology the FBI has been warning about, suddenly falls into the FBI's lap. It's politically and emotionally charged, it involves terrorists - they can ask for the world and society will rubberstamp it "because terrorists."
So the FBI asks for something small but very specific, and in doing so "happens" to set a precedent that they can compel companies to create a new product to bypass the very security measures they've been arguing vehemently against. Do you really think that's accidental?
> I'm also arguing (which you didn't counter) that this case lays the groundwork for the FBI to request _new_ products from companies.
I don't really have an opinion on that. I haven't commented much on whether they should have that power.
I think in this case, Apple would prefer to make it themself than be forced to hand over the code and keys to let the FBI make it. If Apple says "this is too hard for us", it's plausible that they'll need to do that instead. I have seen this point made elsewhere, but I'm not sure of its validity.
>Consider that the FBI could have simply requested Apple provide the data on the phone instead of specifying the mechanism and thereby creating precedent that they can compel a company to create something new.
My understanding was that the FBI asked for the data, Apple said "we can't do it", FBI countered with "Do X, Y, and Z, it is technically possible". Is my understanding incorrect? It sounded like the order needed to specify exactly what was to be done.
About the precedent point:
I think the proper response is to argue against specific details of the actual case (which you have with the point about forcing them to make a product). If you don't have specific objections against the actual case, but worry about precedent, then make explicit the difference between the specific case and the general one, and try to get that acknowledged by the judge. Introduce those arguments in briefs to the court, and try to make it very clear to a future court what the limits of the precedent set should be.
If you haven't imagined what could go wrong, then don't reject something because of unknown dangers. It seems to be born of a lack of trust in future courts, but there's no particular reason to distrust future courts over current ones.
(If you happen to know any philosophy of law articles that discuss this topic, I'd love to see them.)
I don't think it's too hard for Apple to do this; they could probably turn out the request in very short order. However, as soon as they let this go and do that very thing, their legal obligations skyrocket as thousands of cases pour in; in truth, my cynical conjecture is that this is the very reason Apple is fighting this fight. Not for the consumer, but to minimize the very real cost associated with satisfying this kind of request. The Secure Enclave is likely as much a legal defense for Apple as it is a technological one for the consumer. Whatever the motivation, in this case the consumer seems to win.
I must admit I don't disagree with the specific details of the actual case. What I draw exception to is the specificity of the ruling (dictating how Apple does business) and the precedent it sets of enabling courts to force a company to create. That exception is exacerbated by this case's proximity to the FBI's very recent and very real behavior regarding cryptographic systems.
Edit: LOL, downvotes because you don't like it. Apple made a bad design decision, and it's coming to bite them in the ass. Yeah, it sucks, but I'm not the one who designed the backdoor. Blame the corporate culture, not the messenger. Fix the problem and tell your customers about it. Don't pretend it doesn't exist.
User confirmation has come in later OS updates it seems, so the actual backdoor has been closed.
The right thing would have been for Apple to unlock the phone in question, and issue a security advisory for the longstanding but newly-relevant vulnerability. Then, if they want their devices to be secure against USG, actually fix their security model to remove their own privilege. Instead, they walked right into the FBI's trap on a completely unsympathetic case. They're setting us up for a horrible precedent simply to continue pretending they can provide a level of security that they didn't actually build.
1) Identify target phone and obtain warrant to search.
2) Invoke Apple<-->FBI-specific api to initiate OS image generation to the specified target phone. OS image would be automatically downloaded to target phone.
3) Once downloaded, OS image would present FBI-specific API to allow exfiltration of any desired data.
This might not violate the 4th Amendment ("The right of the people to be secure in their persons, houses, papers, and effects ...") because they'll have a warrant, but IMHO it's a clear violation of the 5th ("... nor shall be compelled in any criminal case to be a witness against himself ...").
Yes, the particular OS image they produce would only work on that phone. But all of the work they did to enable the hack would work on every iPhone in the world, and the work necessary to take this OS image and use it on another device is effectively zero. As such, you can be absolutely certain that the FBI would start demanding Apple do this for other phones. And it's not just the FBI, every repressive regime in the world would start demanding this same capability. And Apple would have no grounds to deny it at that point.
"Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession.
The FBI may use different words to describe this tool, but make no mistake: Building a version of iOS that bypasses security in this way would undeniably create a backdoor. And while the government may argue that its use would be limited to this case, there is no way to guarantee such control."
This is a big fat lie.
The way US legal system works makes any case like this about setting a precedent, be it intentional or not. The fact that the FBI director goes and straight up lies about this just supports the theory that it may very well be intentional.
http://www.theguardian.com/commentisfree/2015/mar/28/the-fbi...
http://www.dailydot.com/politics/second-crypto-war-hearing-w...
http://motherboard.vice.com/read/the-fbi-has-no-idea-how-to-...
These were all about a year ago.
This is about much more than just weakening encryption. I think Congressman Lieu put it well
>This FBI court order, by compelling a private sector company to write new software, is essentially making that company an arm of law-enforcement. Private sector companies are not—and should not be—an arm of government or law enforcement.
I hate this narrative so much. Just because we happen to be storing everything we do now, doesn't suddenly create tension between privacy and safety. We used to not store it at all! It's really just a question of keeping privacy with new tech.
The FBI appears to be using this tragedy as a trojan horse by which to commit atrocities upon our crucial freedoms. No, our thoughts and prayers are not enough, but our privacy and security is far too much.
Maybe, but it's fun to discuss, and there are enough of us spread throughout that can educate on this single issue. It's pretty easy for me to explain to my non-tech friends the implications of what the FBI is asking. Word of mouth travels fast and I would give pro-encryption the upper hand in this "debate". I have not heard anyone outside government protesting that Apple yield on this issue and I doubt I will.
In fact, the only ones who speak up against encryption are those who do not listen to the people. Since they're supposed to represent us, they will be very easy to not vote for.
Like you said though, it isn't even a question, encryption is here to stay whether the American government permits it or not. Ironically, by putting up such a fight, the government is simply telling criminals where the weak points are in law enforcement, and are thus empowering criminals.
I hope our government can have a good sit down with tech company leaders and experts in cryptology. Despite Comey's request to have an open discussion, they seem to be excluding this group. It's apparent from his discourse, Hillary's, and Obama's that they've spent no time sincerely listening to anyone with any knowledge about the benefits of encryption. The "conversation" he so desires has only happened in Washington among people with no tech background. Presumably there will be some public hearings coming up.
Frankly, this type of order would deeply hurt moral at Apple. I imagine Cook knows that, and in addition to doing the right thing, he must double down on ensuring employee retention and future sale of products. End-to-end encryption is a feature many people buy the phone to get. If that disappeared, many techies would stop recommending it, and sales will slide.
There's a lot on the table here. I don't even think you could measure the impact for reimbursement by the government. sigh, at least you CA folks elected Ted Lieu, good job!
He is right on the fact that the specific task they're seeking Apple to perform is more or less obsolete and will be entirely so shortly so I'm inclined to believe that they're not really going through all this to abuse that specific tool (though the precedent would be worth the fight in order to abuse it).
It would be sad, but entirely his fault, if his prior efforts to set bad faith precedents to end-run consumer encryption alienated industry to the point where productive conversations are no longer possible.
[0] http://www.nytimes.com/2016/02/19/technology/how-tim-cook-be...
Edit: I'm not trying to suggest that Apple is suddenly being arbitrarily obstreperous in cases where they may have once been compliant. Apple made a decision to change course and it wouldn't make any sense for them to go back on it just because the FBI asked "Pretty please?".
And given that we're talking about a federal government that was perfectly happy with pictures of the TSA's master luggage key being published in newspapers, I don't fault Apple one bit for being scared of handing over what are basically the keys to the kingdom.
I think Apple's got a strong position that this is a stretch of the AWA.
Bull crap. The FBI has it within their power to break the encryption in less than a decade by spinning up tens of thousands of EC2 GPU instances. Forcing Apple to develop products that don't yet exists is simply a choice of economy, with the added benefit of being able to strongarm any other business into creating new products in the future if it suits the FBI.
How? They either need to break the PIN or they need to break the AES256 key that is used to encrypt file metadata.
They cannot use EC2 GPU instances to attack the PIN because the function that derives the AES key from the PIN uses a key that is unique to each phone and not readable by software so they cannot get a hold of it unless they resort to opening the crypto chip and trying to read the key by examining the hardware (and if they do that, they won't need a GPU...any desktop computer would be able to brute force the PIN quickly).
They can use EC2 GPU instances to go after the AES256 key for metadata encryption, but that will take a hell of a lot longer than a decade.
When the government revokes the Gulf of Tonkin resolution I will again put faith in its ability to act responsibly with emergency powers and provisions that might, just might set a precedence. Until then, fool me once, shame on you, fool me twice, fuck you.
In the meantime, FBI losing this case just means they try again. And again. And so will other governments, not just federal, but state and local. And foreign.
The reality is Apple can change the software to in effect cause the data to become accessible. Apple doesn't have keys to the front door. But they have the power to weaken the hinges. Saying they won't do that isn't the same as it not being possible.
Notice that Comey doesn't even bother to refute the technical and legal precedent arguments that Apple and other privacy advocates raise in the media.
Google or Facebook have to get involved and put something on their homepages; else, I think that the FBI wins this.
Everyone is going on about encryption, but notice it's not just encryption that protects us, but also vendor-controlled measures such as self-destruct.
I prefer a level playing field in these matters. I don't want the FBI to have a better chance at cracking my phone than anyone else, but I also don't want Apple to have the best chance either.
It's all or nothing. My vote is for strong encryption, but up until that point, everything else should be on the table for all parties such as crime investigators, not just exclusively controlled by tech giants.
Based on incentives, the government is incentivized to put as many people in jail as possible. Apple is incentivized to make people's phone/laptop experience as good as possible.
Based on worst-case actions, Apple can use your data to 1) sell you more devices, 2) generally reduce your consumer purchasing power, or unlikely 3) sell/share your data and seriously compromise your privacy. The government, on the other hand, can throw you in jail, for life.
Based on history (Germany, Russia, China, Iran, North Korea, ...), governments have demonstrated real threats with user data in hand that corporations have never really come close to competing with.
There's also an equivalence flaw in your argument that sounds like it's coming straight from infowars.com: "the government is incentivized to put as many people in jail as possible".
I'm with your on incentives though. And one thing Apple have no commercial interest or incentive for, is fighting crime.
We don't live in Star Wars. There's more than dark vs light. My position doesn't mean I am not aware of western government corruption, bungling, even war crimes. But I am not permanently polarized, forever holding "the government" in contempt for misguided actions and evil intentions.
On history... if we're talking tyrannical governments, then "protection of user data" I suggest would not have stopped any given government in your examples from unleashing hell on its people one way or another.
You seem to most strongly disagree with the assertion that "the government is incentivized to put as many people in jail as possible". It's pretty clear from my original comment that "the government" is referring to law enforcement agencies, such as the FBI. Note that the FBI has thousands of agents whose performance is measured ultimately by the percent of cases they close. Thus, the claim that FBI agents "are incentivized to put as many people in jail as possible" is more an observation than some crackpot theory. It doesn't mean that we should change that - running a law enforcement agency any other way wouldn't make much sense. But it does provide the rational backing for someone to be more concerned about worst-case government abuse of data than worst-case corporate abuse.
Interesting admission that they don't really have "probable cause" here, rather they apparently want to go on a fishing expedition. I guess if the owner of the phone is already established as a terrorist then that is cause enough, but I still would have expected them to be arguing they have specific reason to believe the phone is necessary for their investigation.