Obama at SXSW: ‘Absolutist view’ on digital privacy cannot prevail
washingtonpost.com
washingtonpost.com
1. Criminals will still use encryption / get guns. Only lawful people will be harmed.
2. Compromises will just lead to defeat for the pro-encryption / pro-gun side.
3. If we want to stand up for all of our other civil rights, we need the right to encrypt / bear arms.
4. Consequentialism: the number of people being harmed by encryption/guns is smaller than the number of people who would be harmed by living in a world without encryption/guns.
Personally, I think these are all solid arguments that work for both guns and encryption, but I'm generally more libertarian than many in the SF tech scene.
A lack of faith in the absolute rationality of people is my argument against guns, and I include my own rationality there.
My argument for encryption is that tech is increasingly an extension of our minds, and we need to keep our mind private. I'm for encryption to the same degree that I'm against government use of a hypothetical mind scanner.
It is breaking encryption that is violent; that's the "gun" here, and it's one I'm against.
However, consider the war on drugs, billions spent, agencies created, military style task force, severe penalties including life in prison just for possession.
So if that didn't keep drugs out of the hands of bad people, why would changing some regulations keep guns out of peoples hands? I don't see any regulations that have ever been proposed that would make any difference and if we went all in as in the war on drugs, but war on guns, the war on drugs sets a precedent that it won't be successful.
In all cases, someone who compromised will view the compromise as a defeat.
Therefore, you can't really say it's a pro-gun argument per se, but that both are examples of a wide class of arguments.
I feel that holds for the rest of your points - they hold for nearly every argument, and aren't specifically pro-gun or pro-encryption.
For an example of #3, the US Supreme Court in Roe v. Wade says abortions are legal due to a right of privacy. Those who want to restrict or eliminate abortions view it as a right to life of the unborn, and believe the Court was incorrect in making their decision. Both sides base their arguments in civil rights.
Also, I think the comparison of cryptography to guns is not a good one.
If you want to think of cryptography as a munition, then it's much more like armor than it is to a gun. Bulletproof vests are sometimes used when committing a crime. There are also some laws against them.
And in the US, bulletproof vests are not, I believe, covered under the Second Amendment.
Such firmware can be mandated from manufacturers without outlawing encryption directly but making it useless nevertheless.
So the obvious first response to this is that it doesn't actually work. Have you seen the security of these vendors? Apple takes it more seriously than most because they're using it to maintain control over the App Store and yet people still root iPhones. Mandate it by law on vendors who don't even want to do it and it will be completely broken in two days. And completely broken against not only the user. Let's not forget the situation with wifi routers -- "only the manufacturer can issue updates" quickly turns into "security updates are not available from anyone anymore" with the consequent catastrophic nightmare following directly.
But let's pretend we're uninformed pedestrians who don't know that for a minute. How is this idea not even more outrageous than banning encryption to begin with?
2. This might be true for guns, but who cares?
3. In the age of tanks, machine guns, and grenades, consumer guns don't enable us to overthrow unjust governments as they did when the bill of rights was written. As such, they no longer play a role in protecting our civil rights. If anything, gun rights are frequently a talking point for Right-wing politicians who happily trample over all of our other civil liberties. As a political force, the pro-gun politics is actively harming our civil liberties.
4. Looking at the data, I don't see how your can argue this. In the US guns are used more in suicide or commission of a crime than in self-defense. In the UK, near-universal bans on guns have lead to a drastic decrease in gun deaths.
Ummm, the vast, vast majority of the guns in the U.S. are used for legal, positive reasons like target shooting or self-defense. The number of murders per gun-year is incredibly low, effectively infinitesimal.
60ish percent of deaths by firearms are suicide. Owning a firearm is a risk factor for suicide. This is because many (most?) suicides are not carefully planned out and given considerable deliberation but are somewhat impulsive. Removing an easy means to commit suicide actually reduces suicide.
I'm neither pro or anti gun.
Ultimately, though, I do agree that these numbers are all negligible: there are more car deaths annually than there have been civilian gun deaths in the last ten years. The argument that is important to me is that gun rights simply aren't very relevant any more, and they are being used as a talking point for political forces who are causing a lot of harm to much more relevant rights.
There seems to be a general "unenforceableness" in the US. It's near-impossible to carry out a near-universal ban of anything-at-all in the US.
Individuals, groups and even state/local governments in the US tend to simply take matters into their own hands if there's a law they dislike.
>just look at the data from the UK. Even the police are better off without guns.
I'm more afraid of harm from police than I am from criminals with guns.
>2. This might be true for guns, but who cares?
Meh, it's not a great point but a lot of people in the US care, even if you don't agree with them.
>3. In the age of tanks, machine guns, and grenades, consumer guns don't enable us to overthrow unjust governments as they did when the bill of rights was written.
Tanks are literally useless. As the wars in the Middle East have nicely demonstrated, they do not magically enable victory, especially against an entranched/integrated guerrilla enemy. This is true for all sorts of high-tech military weaponry/machinery.
>As such, they no longer play a role in protecting our civil rights.
I disagree with the premise of your argument, so I also disagree with this point.
>If anything, gun rights are frequently a talking point for Right-wing politicians who happily trample over all of our other civil liberties. As a political force, the pro-gun politics is actively harming our civil liberties.
I can agree with that. There are a lot of authoritarians/fascists/logically challenged people on the pro-gun side; and a lot of politicians who use divisive issues to agitate the more excitable parts of the electorate. They do it for abortion and LGBT/civil rights as well. It's not great, but also not an argument for/against gun rights.
>4. Looking at the data, I don't see how your can argue this.
I don't see how the US gov't can effectively collect all of the guns in the US without some pretty draconian/authoritarian measures of exactly the type that pro-2A folks oppose in principle, and that most Americans agree with.
>In the US guns are used more in suicide
I don't want a government to try to prevent me or anyone else from suicide by trying to nerf the environment.
> or commission of a crime than in self-defense. In the UK, near-universal bans on guns have lead to a drastic decrease in gun deaths.
I admit the numbers are hard to argue with, even factoring in the violent crimes committed with other weapons and against the unarmed. OTOH, I've noted a disturbing trend of the UK to ban or attempt to ban or regulate the sale of other items which may sometimes be used as a weapon, mainly pointy things like kitchen cutlery. That's certainly not something I would support.
As an analogy, note that the US has attempted to prevent the distribution of illegal amphetamines by restricting the sale of so-called precursor chemicals. It hasn't prevented the distribution of methamphetamine, but it has prevented the retail sale of drain cleaner, cold medicine, and other household chemicals/items. It's a moderate inconvenience for a lot of people and the only discernible effect it's had on drugs distribution is to decrease the quality/safety of illegal drugs (through criminals using inferior methods to produce them). Gun culture is so ingrained in the US that I feel we'd see the same sort of things happening with guns if the gov't attempted to ban them.
You can't say the same about encryption because it's a tool, not a weapon. A gun is a weapon meant to kill.
> 2. Compromises will just lead to defeat for the pro-encryption / pro-gun side.
A compromise in encryption hurts everybody. The whole platform for electronic banking needs strong encryption, for example.
> Consequentialism: the number of people being harmed by encryption/guns is smaller than the number of people who would be harmed by living in a world without encryption/guns.
If you own a gun you are statistically more likely to get shot or killed.
Or is it that if you have reason to believe you might get shot or killed, you are more likely to buy a gun?
I don't have an account, but I just made one because I'm genuinely curious about whether you have a good source for this claim. The usual study referenced for this is deeply flawed; if I remember correctly it examines people who were shot and checks whether they owned a gun. Of course that study is completely invalid because of the selection bias involved. P(X owns a gun | X gets shot) is not the same as P(X gets shot | X owns a gun).
There is also data showing for example that "the higher a state's firearm ownership rate, the lower its firearm homicide rate" – see https://www.facebook.com/UnbiasedAmerica/photos/a.1301843271..., based on FBI data.
The biggest reason is suicide. If you don't own a gun, you are much less likely to intentionally shoot yourself. The second reason is accidental shootings. If there is no gun in your house, there is practically no chance that you will accidentally shoot yourself, or that your toddler will accidentally shoot you.
Of course, the question that's really being asked is whether an individual is at greater risk of being shot intentionally by someone else if they own a gun or not. This is where the data is much thinner. This seems like a solid review article: http://www.iansa.org/system/files/Risks%20and%20Benefits%20o...
Their conclusion at the bottom of page 4 and top of page 5 is even after "controlling for illicit drug use, fights, arrests, living alone, and whether or not the home was rented", that "Yes, owning a gun increases your risk of death by gunshot". Still, I'd be interested in seeing a study that breaks apart statistics for hand guns and long guns.
(Welcome to HN!)
It's much easier to blow away a LUKS header than an entire disk.
And they keep header backups.
In case you didn't realize it, you're arguing for paternalistic authoritarianism.
That is also an oversimplification. Have you considered the possibility that encryption can be used in commission of a non-victemless crime? Let me direct your attention to the state's now second favorite goto: child porn. Privacy advocates are as familiar with that justification as gunrights advocates are with the waving of bloody shirts following school shootings.
But you cannot prevent someone from using strong encryption using third party applications. How will you force a backdoor into, say, gnupg or dm-crypt? Outlaw that software? Any criminal worth his salt will use tools that are not backdoored, completely negating the gimped government-approved stock software.
Guns are physical items that require physical ammunition. It is a completely different situation. This discussion and comparison is also very strange for someone from Europe, where owning a gun is rare and completely undesirable for the vast majority.
You could argue it makes it easier for people to become criminals, but even that is a weak comparison. Guns are a lot harder to come by in the UK (for example) than encryption software would be in a more regulated world.
I don't see what this means for the topic at hand.
> Second, the 'protection' offered by the two technologies differs. Guns offer a dis-incentive to mistreat the user, but do not directly restrict behavior when at rest.
Same here. What's the significance? Would auto-firing guns be better?
This doesn't sound as crazy as it might at first glance, once you remember that strong encryption used to be treated as munition, and in some ways still is.
Hell, the US even invaded Iraq for the official reason that 'Iraq had weapons you weren't supposed to have' (chemical weapons). Yes, Iraq is not subject to the US constitution, but the concept of 'some weapons are okay, others are not' is still there.
It unnecessarily complicates the issue, even though I agree with you on the similarities. People will just find more ways to disagree on encryption and they won't have learned anything more about computer technology.
And what affects me is most important, morals be damned. /s
Majority oppression is very effective. And that's why I think this will turn out differently than guns. My prediction: you won't have to register encryption keys, or keep it disabled, or pay the state some ridiculous amount for a permit that they illegally stonewall, or be prevented from using any encryption made after 1986.
Applying an argument to something physical vs. something digital or something that directly kills people vs. something that prevents access to information makes a lot of difference.
Perhaps they're waiting for the 3rd and 7th amendments to suffer like the others, so they can react to the complete set in one go? Certainly the 4th, 6th, and 8th amendments have taken quite a pounding in the past couple of decades...
The UK is fairly close to crossing a line which would require me to either stop working (and do everything under the radar), or leave the country.
It sounds like the US might be doing a similar thing soon.
What happens if all of the (semi-competent) developers suddenly either refuse to work or simply can't?
The whole situation is truly bonkers to me - there is no debate to be had at all. If you ban secure encryption I cannot stay in your country any more - it is the last warning sign I will accept, if I wait too much longer the borders will close before me.
It represents my elected government telling me that I cannot do a thing which I do every single day without fail. It's as if someone turns around and says to my grandmother 'knitting is banned'. That just isn't how it works.
none of these regimes are "by the people, of the people, for the people"
so, I'm not really comfortable aping the examples you list...
Do tools have value? If you make something with tools, it's not the tools themselves which made it.
Do you know what SSL means and how it works?
I mean ultimately it would be a "dick move" anyway but it would drive the point home so quickly.
I'm sincerely asking here, I don't know.
Germany, for instance, looks rather pro privacy at the moment. But I am pretty sure they'd be some of the first to follow the UK/US.
In the US we actually have a chance to push back on our rights and enshrine them constitutionally. For the US this must be the end goal of the discussion on the privacy and encryption discussion. Protecting and clarifying existing rights, 1st, 4th, 5th all apply here and the courts should uphold them in the face of the executive branch and commercial interests pushing invasion into normalcy.
If we fail to protect those rights and clarify their meaning in the 21st century the answer to the question "But where will you go" will be "there is no place to go".
Iceland, Estonia, Finland, Norway, Netherlands, Switzerland, Ukraine, Hungary, Mexico, Argentina, Israel, India?
The result of these kinds of policies is brain drain. The people you are trying to ban the actions of are both some of the most driven and outspoken in the world, and also some of the most economically desirable in the world. If you prevent them from investigating their pet projects in their homeland, they will simply go and do it in another country, because it's not an obstacle for them. There's a tonne of countries out there that would gladly roll out the red carpet for a tech exodus from the former commonwealth states.
Hungary is a borderline dictatorship. Ukraine is a war-torn mess, and then some. Mexico is one of the most corrupt countries, with little to no history of respecting individual rights. Argentina just nearly became a failed state on par with Venezuela (the verdict is not yet in on whether they've avoided that outcome).
Half of that list is terrible and entirely unrealistic. Silicon Valley developers are not going to Hungary and Mexico.
They pretty much blackmailed RIM into handing over encryption keys.
Have a look at what the Stasi were up to in East Germany until 1989 to understand why Germans feel privacy is important.
I don't know a single (German) person outside of tech who thinks anything they (ordinarily) do online or on their smartphone could be used against them in one way or another. Some may complain about the government but they didn't change their habits when it comes to using their smartphone or laptop. They don't realize that, for instance, every picture they add to facebook will train algorithms that could be used for all kind of purposes.
President Gauck doesn't think it is valid to compare the Stasi and the NSA
> Gauck wehrt sich gegen Vergleich der NSA mit der Stasi
Das erklärt auch, warum er in dem Interview jeden Vergleich zwischen den Methoden der Stasi und den Aktivitäten der NSA weit zurückweist. Die Stasi habe wie jeder Geheimdienst in einer Diktatur "Krieg gegen das eigene Volk geführt". Sie habe die Bürger bespitzelt, um diese Bespitzelungen gegen die Bürger zu richten. Davon könne aktuell nicht die Rede sein. "Hier sprechen wir von einer Gefahr für die Demokratie innerhalb der Demokratie."
http://www.nzz.ch/international/nsa-forschte-merkel-umfassen...
And Chanchelor Merkel declared data the "raw material of the 21th century" and urged Germans to rethink their position on privacy
> Bundeskanzlerin Angela Merkel hat Daten als "Rohstoffe des 21. Jahrhunderts" bezeichnet. "Hier müssen wir jetzt aufpassen, dass der Datenschutz nicht die Oberhand über die wirtschaftliche Verarbeitung gewinnt", sagte die CDU-Politikern am Montag in Berlin beim Verlegerkongress Publishers' Summit.
http://www.heise.de/newsticker/meldung/Merkel-Daten-sind-Roh...
Both, Merkel and Gauck, grew up in the GDR!
Thanks for elaborating. I feel somewhat foolish trying to tell a German about the Stasi. On the internet we assume everyone is an American - well unless you're the NSA watching in which case it's definitely not domestic surveillance ;-)
As a European of 30+ years, I am actually pretty optimistic in that there is, in all areas of politics, a certain point at which EU governments will refuse to follow the US down the rabbit hole.
Germany feels pretty strongly about privacy (albeit not absolute privacy), and I doubt that they will start passing laws just "because the US did it".
UK, I'll give you that. Then again, the UK is culturally closer to the US than to mainland Europe in many ways, this being one of them.
Regardless of what you think of the Cock.li service or its owner, the seizure of all the company's emails suggests that demands from police authorities or politicians take precedence over data privacy concerns - even in privacy-conscious Germany.
[1] http://arstechnica.co.uk/tech-policy/2016/01/cock-li-server-...
"Made in Estonia with European-grade security"
"EuroSec(tm) certified to respect your privacy"
As for UK, from what I understand they have an open channel with US in terms of information exchange for anti-terrorism. Perhaps due to that it's expected from them to follow suit with US in legislation if they want to stay in the same terms. That would probably extend to a few other countries who are in such a privileged relationship.
Never going to happen, even in wild fantasies. Trying to get developers to all move in the same direction is like trying to herd cats.
Maybe all those IBM and Yahoo layoffs will consider the value of unionizing while fishing for new work in the next few months....
We should find something more targeted that could have a greater impact in a shorter timeframe.
The consequences would become clear soon enough. Bonus points if the White House and Houses of Parliament sites were taken offline with it.
Google is the enemy. Like Apple, they're a PRISM participant, and while that doesn't necessarily mean they offer "direct and open access to all user data" like some believe, it still means they willingly collaborate with the NSA, because they're required and obligated to do so under the law. Any company subject to US law is also subject to NSLs, with which they can be forced to act as covert agents for the NSA.
We're all in the same boat, but that's because the enemy is us. The entirety of the United States' IT and electronics industries is the enemy, here, and the victim.
Sure, employers would be wrongfully punished, but they'd all spend more money buying political decisions in favor of encryption (and spending money seems to be the only way to influence politicians in the US nowadays).
More like rightfully influenced.
That is exactly and precisely how it works. In a common law legal system like the UK everything is legal until it suddenly isn't because some act of legislation makes it so. There is no constitution to restrict what legislation the government may choose to enact. There is a body of EU law that has some bearing but much that is relevant here (e.g. Convention of Human Rights) either comes with or was enacted into UK law with 'except because crime or national security, think of the children' tagged onto every clause.
Over just the last few decades UK governments have banned all manner of things, all of which were things people were doing every day. Hunting, smoking, various types of porn and 'legal highs' are some that immediately come to mind, but there are plenty more.
Behind every proposed restriction on speech is actually a fear of freedom of thought. As though there are some ideas or beliefs are so powerful, that mearly exposing an individual to those ideas can forever change their allegiance. It used to be communism and now it's terrorism. It's a very pessimistic and condescending view of the nature of humans that I personally don't believe to be true.
It makes mainstream dissent like Occupy very much harder - and that's not even thinking about how it would have influenced historical dissent like the Civil Rights or Anti-War Movements.
Commercially it also guarantees that the US has access to corporate secrets. If encryption is de facto illegal, how do you communicate commercially sensitive information?
Everybody may have dissident thoughts all day long. They're absolutely harmless as long as they can't coordinate.
Say it's 1960 instead of 2016, but digital technology has taken off 60 years sooner. The NAACP youth council coordinates over Facebook and e-mail lists instead, and the civil rights movement is under government scrutiny because of potential terrorist links. The Greensboro Four, Joseph McNei, Franklin McCain, Ezell Black Jr. and David Richmond are planning their sit in over Whatsapp, which an algorithm picks up. Someone at the NSA, sympathising with segregation, passes this on to someone in local law enforcement through non-official channels. Before the four even get to the Woolworth, they are detained by a police officer in a "routine" traffic stop. The sit in never happens for national security reasons.
The right to coordinate seems absolutely essential to the right to congregate. I do think that the civil rights movement is a good example of how righting an injustice could be stifled by preventing people coordinating. Other historical what-ifs like the labor movements, the salt march, or concrete examples like the various secret polices of communist dictatorships spring to mind too. You could have dissident thoughts all day long in east Berlin as well, as long as noone heard them.
The government is demanding new powers: the power to search our communications. Perhaps the ability to conduct such searches will make their jobs easier, but keeping them from having this power does not make their jobs more difficult than the 200 year baseline. We are only asking them to do the same legwork that they've always done: look for suspicious behavior, track the purchase of dangerous materials, react to disasters and attacks when they happen, etc.
I don't think that's entirely accurate. The problem is that the content they were looking for 200, 100, and even 20 years ago used to be physical. Now it's digital.
Previously when they searched your home, they'd be looking for physical evidence -- mail, letters, receipts, paraphernalia, what have you. Today, a lot of that information has moved to electronic devices, taking what was once safeguarded by your front door, and putting it behind a new electronic lock.
I'm not commenting specifically on what powers should or shouldn't be available to law enforcement, but I think it's pretty clear that the situation has changed from 200 years ago, and we should be making decisions in the current context.
My original point was that in criminal cases, there is a treasure trove of physical evidence available to the government, and the value of this evidence has been under-weighted in discussions about encryption.
- If the suspect has dangerous equipment or substances at that location, then the government can gain access to and analyze those physical materials.
- If the suspect received deliveries to his address, then the government can get records from FexEx, UPS, USPS.
- If the suspect used a phone, the government can get access to carrier calls (I agree that this may not be possible for app-based calls).
- If the government finds credit cards used by the suspect (either by finding the physical card or by using the purchase history of any cars, residences, or other tools used by the suspect), then they can search the history of those cards.
That's not entirely accurate though. The United States has been allowed to search your mail and tap your phone if they have a warrant and there have been cases where it happened without a warrant.
They will, eventually, be shut out of the communications channel entirely due to encryption.
True. But the government never had a means to get the entire history of the bulk of your conversations. They could only install a wiretap after they suspected you of some crime, and even then it was a tedious process for them. Reading digital data is not tedious, it's instant. On balance, the idea of guaranteeing warranted access to encrypted data is a bad idea because it makes us less safe overall.
We put copies of everything into our phones these days. These are new powers that the government started to acquire when we all increased our PC and smart phone usage. We increased usage because we trusted the security systems designed by private companies. I did not start buying things online or banking online because the government kept those computer systems secure. I did it because the tech companies keep them secure. Data breaches cause customers to flee.
Tech companies have always been in an arms race against hackers and if we handcuff them in this manner they will not be able to fix weaknesses in their software as quickly as they do today. By definition of guaranteeing access to encrypted data, they will be required to maintain such weaknesses. It'd be catastrophic for our tech industry and my future as a software engineer.
Why do people here persistently insist, even after being corrected, that the government's 228 year old authority to conduct warranted search and seizure is some kind of shadowy and scary "new power"?
The government has always had the right to look at your photos, listen to your calls, and read your mail, when you are legitimately suspected of a crime.
Nowadays all those things are on your phone, so the government has the right to search your phone, when you are legitimately suspected of a crime.
Nothing about this is in any way new, and it's grossly dishonest to continue to claim that it is.
>By definition of guaranteeing access to encrypted data, they will be required to maintain such weaknesses. It'd be catastrophic for our tech industry and my future as a software engineer.
Maybe it legitimately is the case that it's impossible for techies to ensure warranted government access without guaranteeing that same access to any and every hacker on Earth.
But the more I read these doomsday scenarios from people who are mystified by the one-sentence, 64-word text of the 4th amendment, the less I'm able to believe them.
This idea that the government can regulate how you are permitted to communicate just so that it is convenient for them to interpret later if they have a legal basis for intercepting it is a novel claim of government power and, given that it cannot be exercised without creating the same convenience for both illegal government interception and third party interception, an absurd and dangerous one.
That's not entirely accurate though. Its an arms race between Cryptography and Cryptanalysis. We don't know what we don't know and there's still not enough transparency into the government's capabilities.
There are also government agents who are pushing for the right to decrypt everyone's communications and records without a warrant.
Interestingly, the government never "demanded" the right to search everyone's unencrypted communications. They just went out and did it.
In theory, yes. The technologies where available. But in practice, much has changed. In 2016, technically illiterate people are encrypting their files without even realizing it. Technology has changed what law enforcement can expect to encounter in practice.
(Also "decades ago"/"1996" ...Well now I feel old.)
This is an embarrassingly bad opinion and it's embarrassing for HN that it's at the top of the thread.
The constitution does not require a rewrite to the fourth amendment every time some nerd comes up with a new widget.
The government has always had the right to conduct warranted searches of communications, whether that was opening mail, wiretapping phones, or just good old-fashioned eavesdropping.
Strong unadulterated crypto threatens to take that existing, longstanding power away from the government. The government is hardly going to give up without a fight.
Fortunately a few smart senators have gotten their heads around the issue already. Lindsey Graham changed his mind [1] and Mike Lee made great points too [2] in an oversight hearing this week. Dianne Feinstein is of course still clueless [3]
On balance, putting backdoors on encrypted devices is not the right way to maintain security. For Obama's understanding, I'll concede one circumstance under which I feel we ought to help unlock an iPhone.
In the incredibly movie-like scenario where the location of a nuclear weapon is hidden on an encrypted iPhone, then we should sick all our computers on decrypting that phone. I believe this is already done by the NSA program, Bullrun, revealed by Snowden.
[1] https://www.youtube.com/watch?v=uk4hYAwCdhU
[2] https://www.youtube.com/watch?v=XOZLEhTlr6E
[3] http://www.c-span.org/video/?406201-1/attorney-general-loret... (seek to 51:00)
Indeed, it may merely create an additional category of criminals (analogous to drug traffickers) whose product is the provision of effective communication channels.
That's an absolutist position. It is a refusal to consider context, and has needlessly signaled an escalation to government.
Considering the context, this is a power play by the FBI, trying to apply an irrelevant law to further weaken privacy.
And so again, context: we're not arguing about whether getting the data is right, we're having some bizarre proxy argument mediated via all-writs which is being framed as an encryption battle, when it is at best a battle over how much compensation Apple should receive for it's work.
Since people keep complaining that they "totally should just get it from iCloud" it seems pretty obvious no one is actually not okay with the concept of a search.
So far I haven't seen any running list of events maintained by any blog or website that actually links to primary sources. Most websites link to themselves and are full of editorialization. I think if you line the facts up in the right manner and link directly not just to the primary sources but also to the relevant sections of those sources, then the story, equation and solution presents itself. And I think a github repo is a great way to do that. I'd welcome any help reformatting my current summary [2] (which right now is behind and does not include sources from my comment from the other thread), such as adding dates to events, recategorizing items, or adding significant new events. I do not intend to link to every blog post about the issue, just events from major participants such as Apple, the DOJ, politicians, and other public figures.
[1] https://news.ycombinator.com/item?id=11270745
[2] https://www.reddit.com/r/SandersForPresident/comments/49otvu...
When considering how the intelligence community could abuse their surveillance powers, most people focus on the coercive possibilities (blackmail). The real power, however, is not in controlling how someone makes decisions, but in controlling the options they have to choose from.
For a very good explanation of this, I recommend this[1] section from an older interview with Jacob Appelbaum about the time the CSE tried to recruit him.
I honestly think he just hasn't thought it through. You can call me an idiot, and people will call you a conspiracist. I've no idea which of us is right, but completely unselfishly, I really hope it is me, and my gut says it's me. Even if it is not me, the course going forward should be the same. We should educate each other about the facts of the current circumstances so we can all weigh the balancing factors in our own minds. Let us not rely on experts here and share our own knowledge in order to empower each other. We do not need to tell people how to think. We can give them the facts and let them make up their own minds.
As for the "manipulation"... generally speaking, nobody ever thinks of themselves as "evil". The well-meaning but simply misinformed or misguided can be just as poor an instructor as someone with malicious intent.
My point is mainly that the president (and other decision-making positions) has to rely on advisers. If those advisers are not providing the necessary, accurate information then they have de facto power over the decision making process. Unlike the coercive strategies, this shift in power can happen without intending it.
Yes, but as it pertains to this particular issue, assuming there's no blackmail involved, if the public is informed and there's one political candidate who is for strong encryption, and another who is for backdoors, then we will vote in the man or woman who is for strong encryption. We may have lived with mandated backdoors for 4 or 8 years, but at some point we'll work our way out of that hole, so long as we stay vigilant and root our knowledge-sharing in facts.
Generally speaking, I agree completely that people can and do leave out facts in order to get what they want. Our government isn't free from this sort of manipulation, but I think we have a darned good system set up compared to some others. Lindsey Graham's change of heart on the encryption issue is evidence of that, as is much of the good work done by our government that often goes under-appreciated by the general public. This isn't the first time our government and people have argued over the proper interpretation of laws, and it won't be the last. Let's recall the successful civil rights movements of the past, remember that other countries still do not have some rights that have existed in the US since its founding, and look forward to winning many more. Free speech, women's right to vote, equal rights for all races. Our system isn't perfect but it has led to some really good things.
It's not that nerds are being absolutists. It's that the technology is absolute, and nerds understand the technology.
I also predict that once he is out of office he will reverse himself on this issue.
It's much more likely that they truly do not understand the nature of encryption. They lack the expertise, and their top level advisors do as well. It's not complicated (strong encryption is super easy, regardless of laws), but they just can't accept the simple fact because it clashes with their political desires.
I wonder how often those advisers are chosen based on being yes-men rather than for being actual experts in the/a subject area.
So many people speak the truth after they get out of office - that should tell us something.
To be clear his position here isn't about the value of encryption in all cases. But the specific case of whether law enforcement should be able to access the data on a phone that they have physical possession of.
These are the same thing; that's what makes encryption policy so hard. If you punch a hole in encryption for law enforcement, the hole is there for everyone.
Everybody currently or formerly in a senior position at the federal level believes that law enforcement should be able to access information on a seized phone. That's not controversial.
But at what cost? Shall we sacrifice the safety and security of everyone to meet this need for law enforcement? That's a harder question, and quite a few federal leaders have reversed themselves on it after leaving office (and a few in office).
So, I reject your bet because it relies on a false separation between what people like the President want, and what it costs to get that.
That is so predictable.
If he cared so much about children, he wouldn't be killing them with missiles from drones.
First, you've completely mischaracterized Obama's position. It's not as simple as, "Think of the children!" Obama is saying that encryption makes it practically impossible to prosecute some kinds of criminals. Of the examples he listed, one of them was child pornographers. Another was plotting terrorists. Now these examples are trotted out all the time, but that doesn't make them false. Robust encryption protects everyone's privacy, but it also means that some number of child pornographers and terrorists will get away with their crimes. Obama thinks the harms of those crimes outweigh the privacy protections. I don't agree with that, but it's not an unreasonable view to hold. And it's certainly not the view you claimed Obama had.
Second, it's absurd to think –even for a second– that Obama doesn't care about the lives of children in Iraq or Afghanistan or Syria or Libya. If coalition forces didn't care about innocents, they would have waged war like the Putin did in Chechnya: indiscriminate bombings, extrajudicial killings, and record-setting deployments of landmines. But that's not how coalition forces operate. The horrific stories you hear about are accidents, not deliberate. Due to incomplete information, poor decision-making, or just plain bad luck, soldiers sometimes kill innocents. When this happens, everyone agrees it's a tragedy, and everyone tries to prevent it from happening in the future. Sadly, militaries are incredibly blunt tools. The only way to completely avoid collateral damage is to never use them.
To make my point absolutely clear: In the case of drone strikes, children die because intel isn't always accurate and weapons aren't perfectly discriminating. Despite what you're trying to imply, if Obama could wage war with perfect intel and weaponry, he wouldn't harm a single innocent person.[1]
Lately, I've been seeing more of these drive-by misrepresentations on HN. I usually downvote and move on, but the situation only seems to be getting worse. I don't know of a good solution, as any reply takes far longer to write than three sentences of pandering.
1. A side note: The same can't be said for the leaders of the opposing forces (Abu Bakr al-Baghdadi and Ayman al-Zawahiri). They would use these hypothetical perfect weapons and intel to turn much of the world into a charnel house.
Obama thinks the harms of those crimes outweigh the privacy protections.
I think this is a silly argument. Forcing backdoors into people's phones will not stop any individual determined to maintain secrecy from using encryption. It will however allow government to spy on all individuals.Even with a dumbphone one could use something like: https://www.schneier.com/cryptography/solitaire
How is the backdoor law going to help?
Or is the government going to ban any and all encryption methods?
Eventually, though, as technology advances allow smaller groups of people to inflict larger amounts of damage with fewer specialized resources, how do you imagine that society could be kept secure without surveillance (or something even more invasive)? It seems clear to me that the side arguing for unlimited encryption in communications will ultimately be on the wrong side of the issue, even if backdooring the iPhone isn't a good idea.
Sure, and touching a child inappropriately is really just two electron clouds interacting. Van der Waals forces should not be illegal, right?
Not true at all, this is one of the many reasons why children, women and many innocents die because of drone strikes: http://www.nytimes.com/2015/04/24/world/asia/drone-strikes-r... http://www.nytimes.com/2012/05/29/world/obamas-leadership-in... http://www.theatlantic.com/international/archive/2015/04/war...
For all intents and purposes "Obama" and the people who serve under him don't care about killing children or innocent people in general. They don't even know who they are actually killing most of the time. It's not because technology is imperfect.
So the argument follows if you want perfect information; make everyone at birth wear an exploding neck tag with GPS and a cell phone that'll take your head clean off if you are ever thought of as a terrorist by the United States. No more war, no more collateral damage and yes, no more Edward Snowdon or Julian Assange.
If what we are after is perfect stability and no doors government can't unlock, why not aim to tag everyone up with a government controlled device, rather than doing it via mobile phones.
(sigh)
I'm not sure how I can make my point any better than you just did.
Not true. Just one example: in 2011, Obama authorized the assassination of an American man and his 16-year-old (American) son[0] by separate drone strikes. The father's assassination was completely deliberate. The son was killed two weeks later, when he went looking for his father.
Both the father and the boy were American citizens. Neither was even in a country with which the US is at war (although that wouldn't have been sufficient reason to order the extra-judicial assassinations of these US citizens them even if they were)[1].
Rather than "everyone agreeing this was a tragedy", it was pretty quickly buried in the news. Most news outlets actually refused to even acknowledge that they were American (using the euphemistic epithet "US-born", as if implying that either one renounced his citizenship).
[0] https://en.wikipedia.org/wiki/Abdulrahman_al-Awlaki
[1] Before anybody takes issue with the characterization of this man and boy as US citizens, arguing that Constitutional rights [should|do] apply to everyone: I certainly agree that the US should not be ordering extra-judicial assassinations of any civilian, American or not. But it's notable in this case, because it highlights the absurdity of the policy. If we can't expect US citizens to be protected against extra-judicial assassination by their own country's government, then what rights can they expect?
And it sure as hell wasn't buried in the news. It was a controversial event, on the front page of the NYT, and the Administration was forced to clarify specific policies on who they would target with drone strikes.
The argument from bad people is a false one, largely because bad people are people and hence do everything that people in general do. As a result, it can be applied to anything. If it's a universally valid point for the prohibition of anything, then it is cognitively meaningless.
Nor is it all absurd to believe that a ruler is ambivalent over their subjects. Why would such a thing be absurd? The state and political power are not instrumentalist concepts. We must apply behavioral symmetry to all power elites.
(It's also amusing to see "incomplete information" brought up again. That's the same pseudohistory used to justify Iraq in retrospect.)
Given that Obama chose not to conduct an independent investigation into 9/11 or prosecute the folks involved, it's actually a pretty unreasonable opinion to hold.
Or it would mean that Obama largely believed the 9-11 comission report. Who do you have in mind that he should have directed the AG to prosecute?
Second, how on earth is Obama going to force me to stop using crypto, except to threaten me with violence for using it? Perhaps the government will start to license programmers, and prosecute those caught writing software without a license? (Don't laugh -- they already license hairdressers, marriages, and dogs.)
God forbid we lived in a world where people had privacy and THEIR own money?
So yeah, taxes existed before the internet - they used paper deposit slips.
[0] http://digitalcommons.law.yale.edu/cgi/viewcontent.cgi?artic...
From your lips to God's ears.
Maybe I'm being naive and that was gone a long time ago (I've never been), but typically tech or art-oriented events don't really care for politicians much.
I briefly peeked in on a talk Rick Perry gave at E3 2008 (promoting Texas to game developers), and the room was probably 95% empty. Tumbleweeds. Granted, I'm sure the President draws far bigger crowds, but it still strikes me as odd.
When Leslie died, he took the "weird" with him.
He flip-flopped on a number of issues almost immediately after entering office and has continue highly questionable programs like drone strikes.
What he's asking for in the article is the same old trope of backdoor crypto just worded differently. When are they going to get that NOBUS does not work?
http://mediaroots.org/glenn-greenwalds-bill-of-rights-aclu-s...
Not excusing the government on the encryption debate. We absolutely need it. Just saying when you are given new, secret information that you didn't previously have, it's not unreasonable to change your policy.
Of course, campaigning on "I will increase the national security state" isn't a plank that will likely get a candidate elected.
Note, too, that I am just criticizing Obama here. Every president breaks campaign promises, because most campaign promises are nothing more than marketing.
Does anybody actually want to erode their own privacy or send their friends and relatives into armed combat? Even the people who ostensibly support these actions are just giving these agencies the benefit of the doubt that there is some great unspecified danger that us common folk can't be trusted with.
If these threats do exist, I think it's past time that we bear the responsibility for them together.
The folks in the military and at the NSA have long careers that outlast presidents, more likely they're pretty effective in manipulating politicians than there's some big secret that changes everyones perspective once they're in office.
Maybe after he was presented with "his file" he changed his mind.
Nobody can stop the mighty intelligence machine now.
This is the most important issue of our generation. You cannot have it both ways Mr. President. There is no middle ground. You either support the right to privacy or you do not. There are only two options and you have to pick one.
The argument is that if you support the right to keep your document private from everything except legitimate government access, you can't insist that manufacturers build in back doors to allow government access. There just isn't a technologically feasible way to build a backdoor that only government agencies with warrants can use.
https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
Far as the argument, it's weak because none of the claims they made last time came true. If anything, the U.S. is spying on and locking up so many Americans they might need to cut back so they can stop putting dangerous people back on the street. Prosecution is so one-sided in FBI's favor that plea bargain rate is 97%. Prisons are simply too full. Plus, they got a conviction almost every time they ran into encryption per their own documents. They're not "going dark" or at any disadvantage. That's straight up lies given their publicly released documents.
Far as backdoors, Bruce Schneier shows how retarded Comey and Obama's side is with a simple counter:
https://www.schneier.com/blog/archives/2015/07/back_doors_wo...
" But the problem isn't that most encrypted communications platforms are securely encrypted, or even that some are -- the problem is that there exists at least one securely encrypted communications platform on the planet that ISIL can use.
Imagine that Comey got what he wanted. Imagine that iMessage and Facebook and Skype and everything else US-made had his backdoor. The ISIL operative would tell his potential recruit to use something else, something secure and non-US-made. Maybe an encryption program from Finland, or Switzerland, or Brazil. Maybe Mujahedeen Secrets. Maybe anything. "
My own counter is that even North Korea can't lock down all covert communications in their country. Dissidents routinely get us info with cheap cellphones using towers planted on other side of border. China, which is more U.S. lawmakers' style, has all kinds of covert communications, organized crime, and so on. So, Bruce's argument is supported by the evidence, other surveillance states show surveillance won't protect us at all, and U.S. government's behavior up to this point indicate it's a power grab for a tool of control rather than protection. They abuse everything else routinely.
Most of the increase in prison occupancy is due to drug offenses and this has been dropping since 2008ish; not due to 'spying'
>>Prosecution is so one-sided in FBI's favor that plea bargain rate is 97%.
This is 97% of the 92% of cases that are not dismissed or dropped by the prosecution after charges are filed. So only about 89% of the cases brought by federal prosecutors are resolved by a plea bargain. This also covers cases that are not brought or investigated by the FBI at all. The vast majority of criminal cases brought by prosecutors are slam-dunks(after all, they wouldn't charge someone otherwise). You don't need to believe the FBI in any case. Most criminal cases around the world are resolved very quickly and with a high conviction rate for the prosecution.
Yes, they're not caused by spying. Im pointing out that the Feds have plenty tools as aimed at Americans with tons of convictions while publicly talk like they're powerless and going dark. They have more than enough power.
Re conviction rates
Im basing those claims off things like this piece:
http://www.nybooks.com/articles/2014/11/20/why-innocent-peop...
The US government wanting to enforce warrants is not a power grab.
Crypto is an infringement on the existing, 100% constitutional power of the US government to conduct warranted search and seizure.
Physical: You usually received notice and could physically spot insertions of fake evidence or mishandling. Only one target.
Digital: They capabilities they ask for can be used invisibly on as many targets as they like. They allow undetectable insertion of forged evidence as well in many cases.
The FBI showed their true colors in Lavabit case where they acknowledged that getting the key or attaching their box could compromise ALL accounts. The FBI's argument? Do it then lie to customers that it didnt happen and their emails are still private. FBI said no harm to business that way. Judge agreed, too.
This is not isolated case. They abuse the other authorities similarly with coercion of affected parties and deception of US public. So, I fight backdoors or similar capabilities to avoid enabling tyrants.
A read-only, auditable search a 3rd party can restrict to just warranted targets woukd be a totally different discussion. They've usually rejected tgat stuff in favor of overreach and subversion. That's telling.
Crypto War II has begun.
On the encryption issue he has been cowardly hiding behind Comey and the DoJ "hey, it's not me saying that, it's the FBI. I do like strong encryption! In fact, some of my best friends use strong encryption."
So at least I'm glad that charade is over, so he openly admits that his "legacy" will be a president fighting to expand mass surveillance and to end strong encryption.
I didn't want to make this political, but time is running out and we can't afford to tiptoe around this anymore. As we speak Obama is working to legalize all the illegal NSA sharing with the DEA and FBI, and it's probably just a matter of time until local police departments have easy access to all of that data, too. We need to stop that NOW!
There's only one presidential candidate who actually has a track record voting against laws like the Patriot Act, FISA and CISA, beyond already promising to end mass surveillance (which anyone could do, just like Obama did) - and that's Bernie Sanders. If you care about not seeing your country turn into a police state (which is what will happen when NSA sharing with civil agencies gets legalized), then go vote for him in the primaries and tell all of your friends and family to do so.
This may be the last chance you get to stop encryption backdoors in the US and turn back the mass surveillance capabilities in a more significant way. I can't imagine what the US would look like after another 8 years with a president or presidents that are even more hawkish than Obama was on these issues.
But my guess it will look a lot more like China. The DoJ is already using the rhetoric that "Apple has been helping China unlock its phones this way, anyway, so why doesn't it help the US, too?" First off, that's false, and second you can see they don't want to make any distinction between China and US anymore on this issue. To them, what China is doing is the "ideal" that they strive for. There needs to be someone to change that culture in the government from top to bottom, and do it soon.
I believe its very clear, if it hasn't been before, that both major U.S. political parties are not in alignment with those of us in the tech community that understand the issues. At the rate we're going, encryption itself will be regulated before too long. What a Charlie Foxtrot.
I read this morning that some scientists wrote to the Department of Justice asking them to use RICO to investigate climate deniers. RICO, for those of you who don't know, is a draconian law passed in order to deal with large crime syndicates. We were told at the time that vast new powers were needed if the government had a chance against organized crime.
This is relevant because over and over again, we see encroachment on our liberties in terms of "Well, what if there was a ticking nuclear bomb", we adjust the legal system, then find those adjustments being used for political purposes. The same thing will happen with prying in your phone.
I know in my heart that we have crossed the line into a system that's unsustainable over the long run. I fear that this trend is accelerating. It certainly would be nice if we had some governmental body that was concerned with the proper structure and limits on governmental powers. I don't see anybody like that, however. Just a lot of rationalization.
This is simple:
1. Most people will not actually "go dark" because the consequence of going dark is you lose everything if you lose your password. That severe consequence for a relatively common human error is not a good fit for most people's personal records and photographic life memories.
The right fit for most people is
(a) unbreakable security on their physical devices so they don't have to worry about getting hacked if they lose them, plus
(b) cloud backup that can be recovered by a trusted custodian, so they don't have to worry if they lose their password.
And that is exactly what Apple is providing. Law enforcement will still be able to go after their backups.
2. As for the case where someone really does want to "go dark", weakening physical device security isn't going to stop them. They will simply use alternative encryption software. Law enforcement still can't get it. So why make everyone more vulnerable to the hacking of stolen devices?
Case in point: law enforcement did get access to the terrorist's last iCloud backup. And if he turned off backups with the conscious intention of going dark, then even if Apple made that impossible on the iPhone, he would have simply used a different solution (e.g. not use the phone for secret info or use a different, secure phone with open source software if necessary, etc.)
For both privacy and protection against criminals, cloud storage must become as impregnable as our physical devices. Do we truly lack the will or creativity to produce custodians who cannot recover our data without our permission?
It depends what you mean by permission. If you mean it's physically impossible, those exist, but then they can't help you if you forget your password so it's probably not the right option for most people.
"You wouldn't encrypt a child you just abducted. You
wouldn't encrypt potassium nitrate you plan to use to
make a bomb and blow up a bulding. You wouldn't encrypt
a stack of cash or a duffel bag of cocaine. So why would
you encrypt information you wish to keep private?"
The reality is that encrypted information may only be evidence of conspiracy, and even with 100% perfect encryption that the government is incapable of decrypting it's the equivalent of doing everything face to face, keeping the information in your head, and remaining silent under the Fifth Amendment. The government can't yet subpoena the contents of your thoughts against your will.Besides which, as soon as something criminal actually becomes criminal there's physical world, tangible evidence that cannot be encrypted -- the child, the explosive, the stacks of cash. And even if it's a purely digital crime, if there's sufficient suspicion of a crime, the government can get a warrant to install surveillance equipment to watch the device in question and watch the plaintext evidence.
However, I can't think of any of the government's proposed solutions as working. Someone who wants the security offered by encryption will just use a truly secure system, even if it means they buy the device or software on illegally or from a foreign country.
Where this is demand for true privacy, there will always be supply.
Say you get Apple to agree to allow law-enforcement to have another data decryption key loaded onto every device that is protected by a device specific key that Apple will provide to law enforcement on request. In theory this sounds ok.
Until you realise that anyone intent on any ACTUAL wrong doing is going to also use their own software encryption to protect anything worth protecting.
All you have done now is reduced the protection of the average law abiding citizen by creating a possible attack vector (no matter how tanky Apple HQ security may be) and not at all enabled law enforcement to attack actual high value targets.
You could argue that high value targets are not the actual targets here.. but then why bother? Do you really need access to someones phone to prove they stole a car? Or shot up a bunch of people? No, good old fashioned police work is good enough for that. The only time I see the need for easy access to someones phone is criminal conspiracy and in that case it's highly unlikely they are going to be just relying on the devices full disk encryption.
The entire argument from law enforcement on this issue is a complete joke so far, they need to get with the times and retool for the threats of today.
Personally, I don't consider my phone any more private than my desk drawer. I don't put anything on my phone that I wouldn't write down on a piece of paper. I know some do, and they're entitled to their view, but I find Obama's underwear analogy pretty convincing because I think of a phone just as a gadget.
None of that bears on what sorts of extremely personal information you may or may not voluntarily choose to additionally put on your phone. In the aggregate, however, it's about as intimate as you can get.
I understand the "I don't put anything personal on my phone" statement. I feel the same way. But that doesn't mean that there aren't extremely personal and sensitive pieces of information on there -- information I would not want to be sharing with others without my consent.
My other worry is that strong encryption already creates a black box. Obama is against the existence of black boxes, so the next logical step after government mandated back doors for phones is requiring that you share any encryption keys with the government.
People aren't arguing whether government should have the right to search your phone. They have that right. I support them having that right (when under a lawful order).
The argument is whether manufacturers should be forced to weaken the security of their devices so that law enforcement can break in. In this, there is no difference between the physical and digital realms: we don't require safe manufacturers to build in government skeleton keys either.
Won't somebody think of the children!!!
In seriousness though, the government and the the FBI have already show themselves capable of infiltrating and bringing down child pornography rings that use strong encryption.
There are ways to do that without backdooring everyone's phones 'just in case'.
USA companies will end up losing business to foreign companies and organized crime (I include terrorists when I talk about organized crime) will have an easier time wounding both citizens and businesses via cyber attacks.
I don't understand whether he continues to hold that view or not. Perhaps he does think it will hurt our economy but is worth the cost. Perhaps he thinks it is better for our security too. Of course he is wrong. I am so baffled that nobody has been able to explain this to him in a manner similar to the understanding Lindsey Graham was able to achieve.
Shouldn't the President have access to the best minds in technology? It's not as if any of us would refuse his phone call. Note I don't claim to be a best mind but I think I can talk through the issue to present understanding of the full tech side of the picture to a layperson, and at the same time be respectful of the challenges faced by the DOJ when trying to give justice to victims and security to the public. I think all of you on HN can, too.
[1] http://www.reuters.com/article/us-usa-obama-china-idUSKBN0LY...
http://www.wired.com/2012/11/ff-the-manuscript/
> For more than 260 years, the contents of that page—and the details of this ritual—remained a secret. They were hidden in a coded manuscript, one of thousands produced by secret societies in the 18th and 19th centuries. At the peak of their power, these clandestine organizations, most notably the Freemasons, had hundreds of thousands of adherents, from colonial New York to imperial St. Petersburg. Dismissed today as fodder for conspiracy theorists and History Channel specials, they once served an important purpose: Their lodges were safe houses where freethinkers could explore everything from the laws of physics to the rights of man to the nature of God, all hidden from the oppressive, authoritarian eyes of church and state. But largely because they were so secretive, little is known about most of these organizations. Membership in all but the biggest died out over a century ago, and many of their encrypted texts have remained uncracked, dismissed by historians as impenetrable novelties.
Obama's claim should not be taken as anything other than a blatant lie he knows the majority of people are too ignorant to notice.
Don't ascribe to malice, etc. (though of course when talking of the leader of a superpower, the ill effects of malice and ignorance may be indistinguishable enough to render the difference meaningless).
I was going to argue you with you until you added this. ;)
Malice and ignorance for someone in his position are identical in my world view. The man has a budget to hire the most intelligent people in the country to advise him.
Ignorance and/or incompetence in public interviews should be beyond the realm of a reasonable result.
That said, I realize not everyone feels that way.
Because not wanting the government to have full access to your phone is extremism.
Sanders may be the only current candidate to differ on that issue.
For example, the first mobile phones, could only store 10 text messages, you'd typically delete them after reading. Modern phones store years of messages, so the governments want that.
Further back, we communicated in person or the phone, for which there was no record of what was said (unless actively under surveillance). Now these conversations are stored forever Facebook messenger/What's app etc.
One solution would be to simply automatically delete messages after reading.
As you can readily do with Signal or Telegram.
I am not as bothered by Obama's conclusions as I am bothered by the errors in his supporting facts. These are going to contribute to the mis-education of portions of the American public. Here is his full keynote which I think we all should watch [2]
One year ago President Obama held nearly the opposite view. He spoke with President Xi in China about legislation Beijing was considering that would similarly handcuff tech companies [3]. He criticized Xi for this and pointed out that it would damage their economy.
I don't know whether Obama continues to hold the view that mandating backdoors would damage a country's economy or not. Perhaps he does think it will hurt our economy but is worth the cost. Perhaps he thinks it is better for our security too. Of course he is wrong.
I am baffled that nobody, to date, has been able to explain the entirety of the issues we must balance to maintain public safety and security to our President. Senator Lindsey Graham (R-SC) was able to achieve that understanding [4]
Shouldn't the President have access to the best minds in technology? It's not as if any of us would refuse his phone call. Note I don't claim to be a best mind but I think I can talk through the issue to present understanding of the full tech side of the picture to a layperson, and at the same time be respectful of the challenges faced by the DOJ when trying to give justice to victims and security to the public. I think all of you on HN can, too.
Fortunately, some Congressmen are well-informed. They realize Apple is not simply being disobedient here. Lindsey Graham changed his mind [4] and Mike Lee made great points too [5] in an oversight hearing this week. Dianne Feinstein is of course still clueless [6]. Other personalities have also changed their views when presented with facts. Sam Harris was initially very outspoken against strong encryption [10], but then changed his mind after reading responses to his initial video [11].
On balance, putting backdoors on encrypted devices is not the right way to maintain security. For Obama's understanding, I'll concede one circumstance under which I feel we ought to help unlock an iPhone.
In the incredibly movie-like scenario where the location of a nuclear weapon is hidden on an encrypted iPhone, then we should sick all our computers on decrypting that phone. I believe this is already done by the NSA program, Bullrun, revealed by Snowden.
Obama thinks he has technological advisors but he doesn't. Around 12:00 in the full keynote [2], he starts to talk about how he has coordinated with technologists to form a special task force that solve persistent technological issues the government faces. I think that is a good start. But he is still missing someone or some group who he trusts to act in an advisory role to him about technology and, in particular, encryption. In fact, in this part of the keynote, he's trying to appeal to technologists, but he's still treating them as a mere tool to bring about his goals. He says "We want to create a pipeline where there's a continuous flow of talent that is helping to shape the government." [2a] He says government propaganda is dangerous [2b], yet does not listen to the leagues of technologists who tell him backdoors are bad, or even himself from one year ago [3]. He is pursuing his own agenda and engaging in government propaganda that is unfactual, thus doing the very thing he says he isn't.
I do believe that if Obama understood the facts about encryption then he would come to a different conclusion. If he really understood the equation, and the factors we must balance to maintain public security, then he would not be asking tech companies to add backdoors to their devices. However, at the moment he does not understand the technology, therefore he does not know the things we must balance, and therefore the result of his equation is wrong. There's an error in variables he's established in his mind. His calculation of the final result is reasonable given the facts he understands, but the calculation is based on mis-information.
Let's inform each other and contact our representatives to make sure they are informed so that when the time does come to vote on this issue, we are all voting knowing that the debate is primarily about security vs. security [7] [8] [9], and not just security vs. privacy.
[1] https://news.ycombinator.com/item?id=11270529
[2] https://www.youtube.com/watch?v=wfsIZioIpdI
[2a] https://youtu.be/wfsIZioIpdI?t=14m54s
[2b] https://youtu.be/wfsIZioIpdI?t=16m15s
[3] http://www.reuters.com/article/us-usa-obama-china-idUSKBN0LY...
[4] https://youtu.be/uk4hYAwCdhU?t=1m44s
[5] https://www.youtube.com/watch?v=XOZLEhTlr6E
[6] http://www.c-span.org/video/?406201-1/attorney-general-loret... (seek to 51:00)
[7] https://youtu.be/g1GgnbN9oNw?t=3h35m52s
[8] https://youtu.be/g1GgnbN9oNw?t=3h11m46s
[9] https://youtu.be/g1GgnbN9oNw?t=3h19m39s
Please post the link if you decide to.
I also wrote one letter to an assemblyman in California, Jim Cooper, who is proposing a law based on language from Manhattan DA Cyrus Vance [2]. I'll include that in the repo too. It's not comprehensive because there was a 2,000 character limit on the form used to send him comments, but it's something.
I'd rather not call it a war folder. This isn't a war. It's about educating reasonable people. Obama is simply missing some pieces to the equation, and we need to find a way to get him and the public those pieces. For the public, it's going to be even trickier, because the message will need to be very succinct. I think we can do it either way, so long as we stick to the facts and stay away from persuasive methods rooted in fear, uncertainty and doubt. Let us inform the public so that they are confident they are more safe and secure when they support strong encryption.
[1] https://www.reddit.com/r/SandersForPresident/comments/49otvu...
This is a poor and emotive analogy.
Access to a smartphone is more analogous to having an invisible, all seeing, all hearing, time travelling drone being sent to any time and location the authorities desire, where it can spy on a suspect with impunity.
Even though they usually communicate via SMS or other super low tech ways (at least during the Paris attacks). It's laughable really.
There is nothing bad about all of this, if there are proper mandates. The only obstacle here seems to be iPhone fanboys who feels they are attacked for some reason.
On top of this, if Apple really wants to not fall into this situation, they should have built a phone even they could not break (which I thought was already the case, and I'm surprised they didn't). If they can break into this phone, they should let it happen so that the FBI can do it.
And even if they don't supply this software, somebody else, or the FBI, will do it instead. Which is what Snowden said.
In the end, why should only Apple be able to break in that device? Nobody should be able to, not even Apple. That's what I feel it's Apple fault anyway.
To be fair this seems to be a play to make companies like Apple, who hold so much data about their users, to look bad. Because this only shows that Apple can access that data, which to me is a bad thing in itself.
Same thing for the juniper backdoor.
It should be up to the government to tighten up internet infrastructure security. I really don't see any initiative to do so, and it's the same thing for most businesses: there are no "security standard", mainly because all those communication technologies are very new, and a little too complex for engineers to think about making rules about them.
Ultimately, the law will say the last word, because that's how things work. I don't think tech companies should do what they want in all the countries of the world. If apple doesn't comply with the FBI, that same kind of story will happen later for another company in another country.
My point is that all those technology are new, so there is this vacuum which makes it impossible to really define things or protect yourself.
All those could be solved if there were better security standards, or any standard at all, no data centralization (all internet is structurally centralized), and more consumer awareness. P2P techs are already quite secure, and would make things very difficult for intelligence agencies.
And unfortunately we have seen plenty of examples of how screwed-up a default-trust scheme can become. Laptop vendors have abused their root-CA authority multiple times now, in recent memory. You don’t want the keys to the kingdom in anyone’s hands.
Besides, no matter how many assurances you give me today, I have no idea how careful you are when hiring people or how well you secure your Magic Keys. In the end, they get out in the open. This is why you can’t allow for even a single hole in the system.
So we need to rethink the current situation. The point is that the current proposal is insane. A master key to a backdoor for the US government (not other governments) is a bad idea for many reasons. So are there better alternatives? Of course there are and I think that we should look at the best alternative such that we keep our privacy AND police can ask a judge to break encryption of a phone or any storage device.
The first and obvious problem is how to break encryption. One could look into a system where the 'backdoor' needs three keys to open; one from a government, one from the supplier and one from a 'independent' agency (I do not present details here, I merely want to show that there may be alternatives looking at). A 3-key backdoor may work and break encyption on phones of rapists, terrorists and suspects of other crimes. Note that every request of the FBI and other agencies will have to go through a public court.
The second problem that I see is the secret orders in the US. There are no guarantees against unlawful behaviour of government agencies if the secret courts continue to exist. One can only have enough privacy if one can defend itself in a public court and the actions of governments are transparent. This is maybe the largest problem to overcome since the US government agencies like their secret powers (too) much. I think that the public cry for encryption and privacy is a reaction to the secret powers of the agencies. One can argue that Apple has enough of the secret powers and choose the path of unbreakable iphones because of this. So if these agencies cannot give gag orders to companies and cannot give secret orders to hand over data about individuals, the public might accept a 3-key backdoor.
Last personal thought: I'm not living in the USA and I fear this government will not do any good things for myself (especially since Snowden). A backdoor mostly in US hands is a very bad thing for me and I would not use products which such a US backdoor.
So what you end up with is a gimped encryption technology that is much more vulnerable than what we have now for the common man, and strong encryption (available for free, right now) for everyone with a modicum of know-how.
And how would you implement a global three-key backdoor? Which governments get to participate? Or should each country get their own backdoor for computing devices sold locally? Can I legally buy a computing device from another country and use it here? Can I legally install software of my own choosing?
I guess hipster are now trying on establishment ring-kissing for fashion. Maybe next they can host a d-bait.
a) US businesses will massively lose sales, or
b) US businesses will have to move to more democratic countries
Continue?
Though absolutist view on our privacy, digital included, MUST prevail.
For instance, either a integer is prime or it isn't.
Broken crypto is no crypto at all.
With secure encryption, none of this is possible. And should not be.
Obama and the government should be focused on actual bad BEHAVIORS not words that happen to float in the ether. Behaviors like the metadata of the terrorist's phone- who they called, where they went , etc. I'll allow them to see what I do and where I go on the net. But not what I am saying or thinking.
However we are not talking about a classroom scenario in which we are prioritizing our phones over other values.
The US Government secretly built a massive illegal surveillance infrastructure for spying on the American public and the citizens of nations we consider allies!
Since the programs were revealed by Snowden and corroborated by others, Obama has not once spoken directly about the excesses. He has not accepted responsibility for any mistakes, or vowed to take any corrective action. He's simply ignored the issue and let a few outspoken retirees from the intelligence community wage the PR campaign on his behalf.
Many of us realize that if we can't use strong encryption on devices, the power and scope of existing surveillance will increase dramatically.
Many of us realize that there has not just been a propaganda campaign by government to legitimize its surveillance goals, but outright lies reassuring the public that the data would only be used to fight terrorism (itself subject to an ever-expanding definition).
As we should all have learned by now, any mention of terrorism or child abuse or accusations of "absolutism" is clear evidence that we are hearing a propaganda message.
Government does not care about enforcing laws for the sake of justice, it cares about perpetuating its own power. The key insight of the American Revolution was that government should have reduced and carefully enumerated powers. Obama disagrees strongly with this.
If this is what happens when we elect an former constitutional scholar to high office, I shudder to think what will happen when someone with less exposure to enlightened ideas takes the helm.
Obama has never been "liberal". He capitalized during his first campaign by proposing a more business-friendly version of national healthcare, subtly eroding support from Clinton, while pretending to the democratic base that he had made fewer compromises and was more true to the party's views.
Both major American political parties are predominantly conservative. This is the only explanation for the success of someone like Trump, who is an extreme authoritarian more than a holder of any specific political ideology. With these remarks we see clearly the strong authoritarian streak in Obama, and also the blatant propagandist attempting to lure us into granting Government excessive power by fear-mongering about terrorism (which was George W. Bush's most insidious trait).
The key point is that we can't trust a government that has already betrayed our trust substantially and has not acknowledged the scope of illegal surveillance or sought remedies to restore the public trust. Also, the FBI's botched handling of the San Bernadino shooter's phone shows us that our most trusted law enforcement agency lacks basic competency with technology.
It is not an absolutist stance to call out the lies, propaganda and mishandling of data. It's simply common sense exercised by people who actually understand the power of data and the significance of widespread breach of that privacy. In order to engage in a calm and timely debate, Obama has to acknowledge and address the excesses that were revealed.
We should all expect more from our president than propaganda and fear-mongering.
This article has no mention of FBI backdoors, and Obama is in fact asking for people to propose other solutions. The question falls on everyone: How will we catch criminals in the digital age?
What has changed is that the phone has become an archive of my life and contains much more information than just a phone log. Invading my phone is equivalent to invading my brain. The govt already has mountains of metadata. Suspects are not invisible - they already are tagged by association. And email data, text data, and telephone data is all old. Even without decryption, there is so much of it that analysis cannot be done by humans. And by the time it gets to a human it's hours to days old - STALE.
Fresh intel requires surveillance. Drones are as small as flies and just as numerous. Real time surveillance of suspects by robot swarms is far better than analyzing cryptic email messages. Another change that has further enabled tyrannical control now is that tech allows mass surveillance, whereas in the 'good old days' , the govt had to be focussed and behave with more care simply because they did not have the resources to wiretap everyone.
Misuse of data ALWAYS happens because people are people. In the good old days, we would shudder at the idea of a guy like Trump with his finger on the nuclear button. giving him the ability to look into anyone's ledger is just scary.
There will always be crime scene forensics, surveillance cameras, human interviews, and all manner of other data collected and available for police to investigate crimes.
Is there more to this argument? "everything completely encrypted" doesn't really mean anything. What problem does the digital age present that require new trade-offs?
http://www.c-span.org/video/?406275-1/president-obama-remark...
And a transcript of the privacy related portion:
All of us value our privacy, and this is a society that is built on a Constitution and a Bill Of Rights and a healthy skepticism about overreaching government power. Before smartphones were invented and to this day, if there is probable cause to think that you have abducted a child, or that you are engaging in a terrorist plot, or you are guilty of some serious crime, law enforcement can appear at your doorstep and say we have a warrant to search your home and can go into your bedroom and into your bedroom drawers to rifle through your underwear to see if there’s any evidence of wrongdoing.
And we agree on that because we recognize that just like all of our other rights, freedom of speech, freedom of religion, etc, that there are going to be some constraints imposed to ensure we are safe, secure and living in a civilized society.
Technology is evolving so rapidly that new questions are being asked, and I am of the view that there are very real reasons why we want to make sure the government can not just wily-nilly get into everyone’s iPhones or smartphones that are full of very personal information or very personal data.”
What makes it even more complicated is that we also want really strong encryption because part of us preventing terrorism or preventing people from disrupting the financial system or our air traffic control system or a whole other set of systems that are increasingly digitized, is that hackers, state or non-state, can’t get in there and mess around.
So we have two values, both of which are important.
And the question we now have to ask is if technologically it is possible to make an impenetrable device or system where the encryption is so strong that there is no key there, there’s no door at all? And how do we apprehend the child pornographer? How do we solve or disrupt a terrorist plot? What mechanisms do we have available that even do simple things like tax enforcement? Because if you can’t crack that at all, and government can’t get in, then everybody’s walking around with a Swiss bank account in their pocket. So there has to be some some concession to the need to be able to get to that information somehow.”
Now what folks who are on the encryption side will argue is any key whatsoever, even if it starts off as just being directed at one device, could end up being used on any device. That’s just the nature of these systems.That is a technical question. I am not a software engineer. It is, I think, technically true, but i think it it can be overstated.
So the question now becomes, we as a society, setting aside the specific case between the FBI and Apple, setting aside the commercial interests, the concerns about what the Chinese government could do with this even if we trust the US government, setting aside all these questions, we’re going to have to make some decisions about how we balance these respective risks. I’ve got a bunch of smart people sitting there talking about it, thinking about it. We have engaged the tech community aggressively to help solve this problem.
My conclusion so far is that you cannot take an absolutist view on this. So if your argument is strong encryption no matter what, and we can’t and shouldn’t make black boxes, that I do not think strikes the balances we’ve struck for 200 or 300 years and it’s fetishizing our phones above every other value. And that can’t be the right answer. I suspect the answer will come down to how can we make sure the encryption is as strong as possible, the key as strong as possible, it’s accessible by the smallest number of people possible, for a subset of issues that we agree are important. How we design that is not something I have the expertise to do.
I am way on the civil liberties side of this thing…I anguish a lot over the decisions we make in terms of how we keep this country safe, and I am not interested in overdrawing the values that have made us an exceptional and great nation simply for expediency. But the dangers are real. Maintaining law and order in a civilized society is important. Protecting our kids is important. And so I would just caution against an absolutist perspective on this.
Because we make compromises all the time. You know, I haven’t flown commercial in a while. But my understanding is that it’s not great fun going through security. But we make the concession. It’s a big intrusion on our privacy, but we recognize it as important. We have stops for drunk drivers. It’s an intrusion but we think it’s the right thing to do.
And this notion that somehow our data is different and can be walled off from those other trade-offs we make, I believe is incorrect. We do have to make sure, given the power of the Internet and how much our lives are digitized, that it is narrow, and is constrained, and that there’s oversight. I’m confident that this is something that we can solve.
But we’re going to need the tech community, the software designers, the people who care deeply about this stuff to help us solve it. Because what will happen is if everyone goes to their respective corners and the tech community says ‘Either we have strong, perfect encryption or else it’s Big Brother and an Orwellian world,’ what you’ll find is that after something really bad happens, the politics of this will swing, and they will become sloppy, and rushed, and it will go through Congress in ways that have not been thought through. And then you really will have dangers to our civil liberties because the people who understand this best, who care most about privacy and civil liberties, will have disengaged or taken a position that is not sustainable for the general public as a whole over time.
I cannot agree that I recognize the "security theater" conducted by the TSA as important or useful. [1] I will grant that it may have helped the airline industry continue to attract travelers during the fear-filled period immediately following 9/11. Was that worth infecting air travel with a self-perpetuating institutional virus?
Are we prepared accept the consequences of similarly infecting a vastly more significant industry?
[1] https://www.schneier.com/essays/archives/2009/11/beyond_secu...
"Allowing the government access to iphones will make them criminals" and "Obama says a lot of things"
I agree with that
The tone is so reasonable but there's a fair amount of manipulative scaremongering here. 1) child pornography 2) terrorists 3) wealthy tax evaders (?!)
theyll have to work a little harder to catch 1 and 2 without putting everyones communications into a dragnet. Not even sure what he's getting at with the talk about Swiss bank accounts. It's just nonsense.
"I am way on the civil liberties side of this thing…I anguish a lot over the decisions we make in terms of how we keep this country safe, and I am not interested in overdrawing the values that have made us an exceptional and great nation simply for expediency. But the dangers are real."
> "My conclusion so far is that you cannot take an absolutist view on this," he said. "So if your bargain is strong encryption, no matter what, that we can and should in fact create 'black boxes,' then that I think does not strike the kind of balance that we have lived with for 200, 300 years, and it's fetishizing our phones above every other value. And that can't be the right answer."
http://www.wired.com/2012/11/ff-the-manuscript/
> For more than 260 years, the contents of that page—and the details of this ritual—remained a secret. They were hidden in a coded manuscript, one of thousands produced by secret societies in the 18th and 19th centuries. At the peak of their power, these clandestine organizations, most notably the Freemasons, had hundreds of thousands of adherents, from colonial New York to imperial St. Petersburg. Dismissed today as fodder for conspiracy theorists and History Channel specials, they once served an important purpose: Their lodges were safe houses where freethinkers could explore everything from the laws of physics to the rights of man to the nature of God, all hidden from the oppressive, authoritarian eyes of church and state. But largely because they were so secretive, little is known about most of these organizations. Membership in all but the biggest died out over a century ago, and many of their encrypted texts have remained uncracked, dismissed by historians as impenetrable novelties.
Encryption was in the hands of people outside the government since before the US came into existence.
Yeah, it looks that way but where is the substance?
Why doesn't he openly discuss the pros and cons of both sides to finally reach a conclusion?
"But the dangers are real." is not a rational balancing of reasons. It is just a paranoid statement.
Nailed the usual examples for inciting fear.
Fetishizing phones. Right.
The way you talk to people is more important than the points you're making.
That's what Obama is warning about.
1. They can't even restrict sale of guns, let alone ban them.
2. Banning the iPhone would make the issue headline news.
3. There'd be riots on the streets.
4. if they did, it'd back to the prohibition era, more crime, violence etc.1. There's no constitutional right to an encrypted phone.
2. No silly, they'll ban unbreakable encryption, and Apple will follow suit. IPhones will be searchable with a warrant. IPhones sales will drop an 0.0001%.
3. moot
4. Really? "No IPhones => more crime, violence"? is this the epitome of #FirstWorldProblem?