I don't understand how all of a sudden the government is publicly and calmly asking permission to do something digitally when they have been so forceful and demanding in the recent past.
I don't understand how all of a sudden the government is publicly and calmly asking permission to do something digitally when they have been so forceful and demanding in the recent past.
The government is trying to use a dubious legal tactic to force Apple to create a hacking tool that does not exist. It's not an order to produce information, it's an order to do forced work.
But couldn't they write a modified iOS software themselves (obviously not easy as cake, but for the sake of the argument) and use a NSL to get Apple's key to sign the update?
It seems like having the update signed is the issue, not writing the update.
Edit: When looking at the scope of the NSL, it seems like only metadata can be requested, not arbitrary stuff. IANAL, but it seems like using an NSL makes no sense.
Both the validity of the NSL and the application of a nondisclosure ("gag") order to an NSL (not all NSLs are inherently gag-ordered) are reviewable by court, and gag orders have been struck down by courts.
So its not at all the case that an NSL would never be discussed in open court. Still, its impossible to say what NSLs have been issued with gag orders that haven't been struck down, since those particular orders would not be publicly disclosed.
From what I remember, the NSL comes with a gag order which prevents even the council of the recipient from knowing about the issue.
That was changed with the USA PATRIOT Reauthorization Act of 2005.
I think that Ladar Levison would disagree with that comment. According to wikipedia "US government ordered [Ladar] to turn over its Secure Sockets Layer (SSL) private keys" [0] which imho would be no different that forcing apple to turn over a software-signing key.
>“To make use of these keys, the FBI would have to manually input all 2,560 characters, and one incorrect keystroke in this laborious process would render the FBI collection system incapable of collecting decrypted data,” prosecutors wrote.
If there were true rule of the law and everyone would have been treated equally in US, then either both Lavabit and Apple should give out signing keys, or none at all.
Lavabit was forced and had no choice. As far as my reading and understanding goes, the Gov created some sort of loophole where Lavabit was denied a hearing and because of lack of hearing he was... found guilty (catch 22). I'm sure others can shed more light...
At this point, Lavabit could've complied by just handing over the original data, but instead decided to get cute. "Contempt of court" is an aptly named crime.
That may be. However, simply forcing them to hand over the key wouldn't imho.
And even if they did, it would take them months from receiving the source code to be even remotely prepared to do a custom iOS build to present to Apple to be signed. Domain expertise, familiarity with a code base, and just "simple" stuff like build/release engineering and QA aren't things you put together overnight.
>You make this sound hard: there are tons of qualified people who could do this in less than a week, including myself. We already have all of these tools just sitting around from the iPhone 4, and some of us have emulators for more recent devices: the only thing we don't have is Apple's key.
From the developer of cydia.
Well, yes and no. They do not come from a court (I've heard), so they are not a subpoena in the court sense, nor a court order. But they are an order to produce information, so I assume calling one a "subpoena" is correct, and I'm not arguing with you there. Just want to make clear for those reading without a law background that NSLs do not involve a court, which "subpoena" might imply.
An NSL (I've heard, hypothetical, yadda yadda) basically amounts to the FBI citing statute authority to demand information about a suspect and does not rest on, nor require, a court case. Indeed, the whole point the government makes about the nondisclosure aspect of an NSL is to keep a matter discreet from the investigated party for reasons of national security or imminent death (which a court case, on which to issue court-ordered subpoenas, would make far more difficult).
U.S. law specifically discusses upgrading an NSL to a court order in district court, for reasons of noncompliance.
But the guy who owned the phone can unlock it. Why not have a judge force him to unlock it? Why Apple?
Fingerprints can be used to unlock phones because your fingerprint is part of evidence.
Passcodes cannot be used to unlock phones because your passcode is information that's gained through testimony, and the 5th Amendment protects you from self-incrimination.
Different case.
I'm guessing that the USG has done this, and they want to move the "debate" into a more public arena so they can get political muscle into a crypto ban. Yadda yadda terrorism leading to fake compromises and "balance". In an election year.
Cynical me expects false flag operations to prop this up further. I hope I'm just being jaded and negative.
No, since it is the actual legal authority that the government is actually seeking to use.
> What's preventing the Federal Government from issuing Apple a National Security Letter and forcing them to comply in secrecy?
There are legal bounds on NSLs, and NSLs are judicially reviewable and may be altered or voided by the courts if they are "unreasonable, oppressive, or otherwise unlawful".
Further, the nondisclosure orders that can be tied to NSLs (the "comply in secrecy" part) are limited (by Congressional action after the earlier broad use was struck down as unconstitutional) and are themselves judicially reviewable, so NSLs aren't a "get out of judicial review free" card, nor are they a "get secrecy without review free" card.
Edited typo.
How can anyone be sure of that when the issuance and nature of every single NSL remains secret to this day?
[1] https://www.eff.org/cases/re-matter-2011-national-security-l...