Apple May Use a First Amendment Defense in That FBI Case. And It Just Might Work
wired.com
wired.com
This is probably a gambit by the FBI to get access to this type of data for their other criminal investigations. If it is publicly known that the FBI has a way to break iPhones, they can lean on the NSA/CIA to provide more effective methods (without breaking cover of the existence of those methods.)
IMO a better tactic is the one the NSA has taken: let the industry build it, and we will hack it. This is just better tradecraft because it lulls targets into a false sense of security. Look at the engineering behind Stuxnet and the Equation Group viruses - these guys are obviously in another league from the FBI (and likely even from Apple). Given the gap in skills and mission, I don't blame them for not trusting the FBI.
Is there any reason Apple can't use more than one argument in its defense?
According to USA vs. New York Telephone, "unreasonable burdens may not be imposed". I think Apple will bear quite a burden if it must force its engineers to implement this code. It will be telling them to reverse their work and go against company values. Also, the public is going to know the outcome of this case. If Apple doesn't come out cheering, we will all know its security features have been weakened, which will impact sales.
No.
I wonder how it would go down if they said it was against their religion, a la Hobby Lobby.
"Say you sue me because you say my dog bit you. Well, now this is my defense: My dog doesn't bite. And second, in the alternative, my dog was tied up that night. And third, I don't believe you really got bit. And fourth, I don't have a dog."
Apple should have thought about this before they got into the phone Biz.
Of course Apple can invoke the First Amendment just like you or I could to avoid compelled speech. They may win or lose that argument, but it's not going to be thrown out just because they're a corporation.
People speak and act. The fact that they do so on behalf of a corporation is not of primary importance.
By saying that there's "corporate speech" and "personal speech", and that the latter is protected and the former not, is essentially the same reasoning that allows corporations to commit crimes with no personal crimes taking place.
You are essentially claiming that a person's rights aren't violated because they still have a choice between expressing a concept in code or losing their livelihood. This is analagous to saying that a person's fifth amendment rights are not violated because they have a choice between answering questions and going to jail. This is the precise definition of coercion, which is exactly what the US government is forbidden to do except in very limited circumstances.
Furthermore, their employer is not the government so the ultimatum does not exist without coercion. Their manager is a human being who is forced to give them orders or fire them, which is again a first amendment violation. They get their orders from their manager, who was coerced, etc.
> or losing their livelihood.
I write code for a living(1). I'm pretty sure that if I walked in to work tomorrow and told my boss I wasn't going to write any more code then he would tell me pretty soon thereafter that was fine but he was going to stop paying me to come to work every day.
That's not coercion. That's what a job is.
It's interesting, by the way, that you bring up the 5th amendment. You have it exactly backwards. The government has wide latitude to compel testimony at a trial. If you witness a crime, for example, you aren't allowed to refuse to testify about what you saw because of your first amendment rights. The 5th amendment outlines one of the very few exceptions to the government's ability to compel speech in the context of criminal investigations.
1. Strictly speaking I'm more of a manager these days. But, for the purposes of clarity, let's pretend I'm talking about the "me" from 5 years ago.
And assuming the process that led to the writ being issued in court was fair and followed correctly, you wouldn't be able to just walk away from it. Which is why the first amendment and other laws matter for the government and not for your employer-employee example.
That might be true for senior officials at Apple (Tim Cook, etc) but definitely not for rank and file employees. Any of them that are asked to implement GovOS (to use Apple's shorthand for the proposed software) could surely quit instead of doing the work.
To be honest, they wouldn't even have to quit. I'm sure there are plenty of people at Apple qualified to do the work. If some of them have moral issues I'm sure they can go work on other things. Apple will have no problem finding a few folks to comment out a few lines of code and recompile the OS.
You're basically repeating FUD spread by Apple and others to make the situation seem worse than it is. Normally this kind of FUD spreading is reviled by the hacker community.
The argument that the newly-developed technique could be stolen by unwanted adversaries is the same. In both cases the government has to get hold of the physical object to crack the (digital) safe.
To apply your argument, your safe is a Narnia portal that brings you access to every facet of someone's life, all to track down the contents that fit on a few pieces of paper.
Equating smartphones with physical safes is ridiculous.
The important points are these: the mechanism-replacement machine wouldn't be limited to that one safe, and the technician won't install it unless Apple Safes said that it had the same level of security after the alteration. This isn't cracking one safe; it's developing (easily redistributable) instructions for cracking all the safes of that model and marking the modified mechanisms as unmodified, against their will.
Maybe in that scenario, it would be the author who writes that code who would be protected but the person who executes the deadly code who is breaking the law?
Holmes's famous phrase means that not all forms of speech are protected. For example, the First Amendment does not protect obscenity, child pornography, true threats, fighting words, incitement to imminent lawless action, criminal solicitation or defamation.[1]
[1]: http://1forall.us/teach-the-first-amendment/the-first-amendm...
The ELI5 of free speech is: you can say whatever you want so long as it doesn't come at a cost to another legal entity (normally people, but not always).
One example that I found very demonstrative while trying to intuitively understand FOS was a very extreme one[1]. It's a difficult but worthwhile read. The best way to understand FOS is to read up[2] on how it has been applied.
[1]: https://en.wikipedia.org/wiki/National_Socialist_Party_of_Am... [2]: https://en.wikipedia.org/wiki/Category:United_States_Free_Sp...
So while not all speech is protected, the notion of what is protected can change over time -- hopefully in a pro-liberty direction.
Not a lawyer, but I don't think so. You can't just say anything you want, either (yelling "fire!" in a crowded room, slander, inciting violence, etc).
This is simply not true. Read Trope Two here [0] for a brief overview (although the entire essay is well worth reading), and [1] for a in-depth analysis of the trope.
[0] https://popehat.com/2015/05/19/how-to-spot-and-critique-cens...
[1] https://popehat.com/2012/09/19/three-generations-of-a-hackne...
The point is that the boundaries of where speech loses its First Amendment protections are very clearly defined. Now that you are aware that the "Fire!" example is not an example of unprotected speech, you would do a grave disservice to discourse if you continue to use it as an example of unprotected speech.
Of course in this case the person is a corporation; if this defense works I wonder if there will be calls for renewed scrutiny of corporate personhood. This may have been discussed in the article, but I was unable to read very far because I have an ad blocker turned on.
Yes, that's pretty much true, though actually executing that code to perform a nefarious task (or otherwise conspiring to execute the task or encouraging people to that end) may still be illegal.
How is that not the only sensible outcome?
Telling people about vulnerabilities is the only way they can defend against them. Defenders need actual exploit code to test their countermeasures against.
The person who uses the exploit to kill someone is the person who uses the exploit to kill someone.
It should. Code is speech, so banning private speech is to create a thought-crime. Unless the author of that code intends it to be used as a weapon and facilitates that use, yes, they ought to be protected. Your hypothetical also probably isn't all that hypothetical. Pacemakers have vulns, and it isn't illegal to create a PoC proving the vuln is real. There are probably real world examples.
https://en.m.wikipedia.org/wiki/Key_disclosure_law#United_St...
I have also been wondering if this is the wrong iPhone to take a stand on since it is owned by the employer, not the dead terrorist -- and the employer wants it unlocked.
But I guess this is more about forcing a company to manufacture an ad hoc backdoor than protecting the privacy of the owner of the device (my understanding is that if your employer owns the device, there is no privacy.)
But at some point, cooperation goes beyond reasonable into the area of "unreasonable burden." As a practical matter, the test tends to be one of economics. How much does it cost to comply, and is that cost a reasonable one given the party being compelled?
If Apple is finally compelled to write this backdoor code, and that backdoor code is used against a lawful customer, what happen if this customer then trie to sue Apple?
Will the DOJ be sued as well as they might be fully responsible? And could Apple sue DOJ as well for irremediable arm against his product safety?
"Your honor, it's a known fact that my client has had a long-standing adversarial relationship with Jack Smith, an employee at Apple. Jack Smith's motive and opportunity to frame my client by falsifying data in this case provides clear reasonable doubt of my client's guilt."
Additionally, let's say they destroy the phone. How can you establish that the evidence hasn't been tampered with after the fact? It's not like you can go pull the files again, the phone has been destroyed. So now you're not only trusting that a) Apple provided the right data, you're trusting that b) the FBI hasn't tampered with the data to frame somebody.
Once the software is already created, it is, at worst, just a question of getting the timing right for the next request in order to make such an order (to provide software to assist in the unlocking of phones) merely ordinary.
Aside from some arcana, what you are proposing is equivalent to the FBI's position, which I think many here disagree with.
Alas.
No, it's not. The right not to incriminate yourself is protected by the 5th amendment. People are subpoenaed and forced to speak all the time. That's why Apple isn't making that argument. (They do have a 5th amendment argument too, but it's not based on self-incrimination.)
> If you're an "enemy combatant," you're sitting in somewhere in Iraq or Afghanistan
It has never been put to the test (because the scenario is pretty unrealistic) but do you really think that if a U.S. citizen on U.S. soil made a credible claim to have planted a nuke somewhere in NYC, that the government would not mount an argument that the Constitution allows them to waterboard that person to get them to reveal the location of the bomb? And that they might win?
Then on each host, Chrome starts off with no javascript, and there is an icon in the URL bar to enable it. Thus I can enable all javascript for trusted hosts. And in regular mode, that change is permanent, so I'm not bothered
Additionally, open up an incognito, and allow javascript for a host, and that decision is only valid as long as the incognito window is open.
So the workflow is:
1.) Always surf with javascript disabled
2.) Permanently allow all trusted hosts
3.) When needed, temporarily allow a host via incognito (ex: blogspot sites)
This does not require any additional extensions.
For example, https://github.com/reek/anti-adblock-killer
In the end publishing the source code as a literal, printed book and exporting it from the USA as printed material (Free Speech!) then OCRing the contents in whatever country they wanted to get it to only now we already have a precedent for code is speech and those extra steps might not be necessary.