FBI argues it can force Apple to turn over iPhone source code
extremetech.com
extremetech.com
Comey went on record saying the tool should be secure in Apple's hands because Apple knows what it is doing [1]
And, he didn't even think of this tactic until Darrell Issa suggested it at the Congressional hearing [2].
> Issa: Did you receive the source code from Apple? Did you demand the source code?
> Comey: Did we ask Apple for their source code? Not that I'm aware of
It seems like the FBI is grasping at straws here. Does anyone buy this charade? The PR on the DOJ's side is atrocious. From the beginning, "just about one phone" was obviously a lie, and it's all been downhill since then.
For once, the fear, uncertainty and doubt tactics of the government are not working. I'm happy about that but concerned for our future when law enforcement blames technologists for not handing over data to phones. We need to continue educating each other on these issues regardless of what the courts say, and regardless of what ultimately comes out of Congress.
And it's a little early to say that it's not working. It's not working as well as they'd like. It's certainly not working for the echo chamber of HN and tech nerds, but what we think is irrelevant. It's not over 'til the fat lady sings, as they say....
True. I would also go a bit further and say it doesn't appear to be working with the House Judiciary Committee. I watched all five and a half hours of the inquiry and overall, the committee including the chairman seemed strongly on Apple's side. There were only 2-3 dissenting positions in favor of the FBI.
The original poll was biased in favor of the DOJ, since it only framed the question as, "should Apple unlock the phone or not". So it is hard to know if public favor has truly shifted.
Regardless, you're all correct that we need to continue educating each other about this. Find public figures and inform them. 42% is a lot of people who do not understand the issue and implications of what the DOJ is asking.
[1] http://www.dailydot.com/politics/apple-iphone-doj-fbi-wall-s...
[2] http://www.people-press.org/2016/02/22/more-support-for-just...
Ironically, Apple giving users encryption doesn't weaken the Fourth Amendment; it makes it stronger because it provides the ability for citizens to be "secure in their persons, houses, papers, and effects, against unreasonable searches and seizures" in a way that the courts recently have been unable to.
> Q: Can I do the weekly check-in on if you guys have anything to say on the Burr-Feinstein legislation on encryption coming out of the Senate?
> MR. EARNEST: I don’t have anything new -- which is to say we continue to be in touch with Congress, and I continue to be personally skeptical -- more broadly, going beyond just this specific legislation, I continue to be a little skeptical of Congress’s ability to handle such a complicated policy area, given Congress’s recent inability to handle even simple things.
[1] http://www.politico.com/tipsheets/morning-cybersecurity/2016...
[2] https://www.whitehouse.gov/the-press-office/2016/03/14/press...
I would've never occured to me... I thought all law enforcement was on the judicial branch. TIL.
Maybe we should change that. Countries like France and Germany don't seem to have all the wackiness in their legal systems that we do.
http://en.odfoundation.eu/a/6935,in-a-shocking-decision-fren...
Perhaps you're being too dismissive of the US system?
Even in France and Germany.
Marshals do prisoner security and transport, run the witness protection program, and are the legal enforcers of the court's orders. For instance, when the Supreme Court ordered the integration of Southern schools, it was US Marshals who actually enforced the order and were deployed to escort students into their schoools.
As a non-legal expert, the way this feels to me is that asking for a backdoor is like preemptively issuing a warrant for everyone on the grounds that they might commit a crime in the future that you'd want to investigate. Thus backdooring iOS is tantamount to issuing an unlimited warrant for everyone, which is exactly what the Fourth Amendment is trying to prevent.
The real tragedy is that if the government had good intentions about doing so in a responsible manner (setting aside the problems with key escrow in the first place), then the NSA burnt those bridges to the ground between 1990 and 2015.
Action. Reaction.
"I don't trust you to be an impartial seeker of the truth who's 'only' concerned with solving this murder rather than railroading me on random charges, therefore I will not answer even simple questions that you deem necessary to conduct your investigation."
(With that said, I really, really don't like the whole "don't talk to police" circlej---, like how it gets overapplied or dangerously applied ... but within a very narrow interpretation it's correct and well accepted enough to carry the implications over here.)
Edit: Correspondingly, the advice would carry a lot less weight in counties with a much better government that actually could be trusted not to look for petty reasons to arrest people. And so a government that prices itself a better steward of privacy could be trusted with key escrow.
Is already limited by the 5th Amendment and other caveats. So it's never been unlimited in the US.
Put aside for a second that 4A is not in play here, because the phone's real owners consent to the search.
4A delegates to the courts the power to determine what evidence is and isn't in-bounds in an investigation. Nowhere in 4A will you find a prohibition on imaging someone's phone. Assuming the judiciary approves of a warrant, virtually nothing is out of bounds to a warranted search. That's what we're talking about here: a search that a judge has authorized.
It's that power that we're talking about clawing back because of a loss of trust in the government. And what I'm saying is, it's pretty silly to pretend that you can claw back the power to collect evidence without calling the whole state into question.
To me, that's an obvious example of evidence the government would like to have in many cases, but we clearly decided it cannot. A judge cannot grant a warrant compelling an individual to waive their 5A rights. That seems to have direct bearing on the idea of providing individuals a right to strong personal encryption.
Admittedly, there are many edge cases (furnishing information about a third party that one has personally encrypted), but we've bounded what the government can and cannot have before.
Although from another comment I made I generally agree with your position that this is a pretty serious point of balance between the individual and the state due to the nature of encryption.
Or to turn it around, what has the government historically desired to legally do after obtaining a warrant that it has been unable to do?
We never made locks or strong doors illegal. The closest would probably be mandating log retention at telecom providers for a certain period of time.
The question of how cryptography might stymie whole classes of search entirely is germane to the question of whether we should pass laws restricting default-on cryptography (obviously, I don't think we should). It is not germane to this case, which is not about "mathematics" or even "security", but instead whether the government has the power to compel a product manufacturer to assist in a search of their products.
Richard Clark seems to think the NSA would have the capability, and they might, but the FBI apparently (and believably) doesn't.
Apple "assisting in a search" is a little overly summarizing in my opinion. I think there's a difference between "we received your warrant, here's the information we have" and "we received your warrant, we will dedicate engineers employed by our company to actively exploit the security we designed into our products."
Is there precedent for compelling lockmakers to provide technical expertise in defeating their own lock systems? I can't imagine that's never come up historically.
The question becomes whether it is within the power of the government to mandate that flaw, or whether they will need to find some other approach. There is also a question of freedom of speech, as it has historically been held that you can be forced to not express something, however you cannot be forced to express something. In regards to key signing, it could be said that that is an expression of authenticity that you endorse whatever is being signed. Can the government force you to give that endorsement? Does the government's power to collect evidence supercede your right to freedom of speech (or the abdication of speech)?
We've seen the popular media analogies gradually become more accurate in their understanding that this is a novel question. And, admittedly, hats off to Tim Cooke and Apple for getting more technically accurate descriptions out in the media.
We do seem to be having a more productive discussion socially this time around.
I think the last major rebalancing of rights due to new technology concerned copyable copywritten digital media and... we decided to make a lot of things that are technically trivial illegal. Not the best message to kids that "these things are illegal, but easy to do and unenforceable."
But this doesn't mean that the state gets to do that however it wants. There have to be limits on such power.
Any state that cannot be trusted to be responsible should be disbanded. See the US Declaration of Independence.
I agree. But it is no where stated or implied that this should be an unlimited power. In fact, clear limits are placed upon that authority.
If I invent a cypher and store all of my physical written works using that cypher, can the government compel me to decrypt those works upon discovery that they lack the ability to do so? What if I taught that cypher to my family? Can they be compelled? If so, under what authority?
>You might just as productively suggest that we can't trust the USG to be a responsible state
This suggestion is inherent within the Constitution. It is framed upon a mistrust of any Government to not become tyrannical.
>therefore it should disband
uh, what? nice leap.. did you use rocket shoes to get over the gap?
It's unclear whether you will eventually be compelled into decrypting documents. One circuit says you can't be, because of 5A. But that ruling was situational, and other courts might rule otherwise. Certainly I don't personally agree with the logic that compelled decryption is necessarily testimonial in nature, any more than opening a safe for which only you have the combination is testimony. The primary purpose of the ban on coerced self-testimony is to prevent bogus confessions elicited under torture. That's not at issue here.
I don't understand your "inherent within the Constitution" argument. The Constitution says what it says. I'm citing it.
The issue is whether a third party can be compelled to provide access to that evidence in order to make it intelligible and therefore meaningful. The combination to the lock (which apple claims they would be forced to construct, as it does not yet exist. The government seems to have accepted the veracity of this claim when they agreed to perform the labor if handed the tooling).
What is the purpose of explicitly stating 4A if we can simply trust the government to be a good actor?
It is inherent in the statement of explicit restraint that there is not trust.
Preamble to the Bill of Rights -
"The Conventions of a number of the States, having at the time of their adopting the Constitution, expressed a desire, in order to prevent misconstruction or abuse of its powers, that further declaratory and restrictive clauses should be added: And as extending the ground of public confidence in the Government, will best ensure the beneficent ends of its institution."
I like that they use confidence.. it implies a matter of shades or degrees. Trust seems to imply something much more B&W.
(http://www.archives.gov/exhibits/charters/bill_of_rights_tra...)
If you can't trust any part of the government, the Fourth Amendment is immaterial: you can't trust the entity to whom is entrusted the power to adjudicate reasonableness.
The court is compelling a third party to perform an act that really isn't part of a search and seizure of items.
Search and Seizure as defined by 4A is over and done with. The Prosecution has searched the "places to be searched" and is in possession of the "persons or things to be seized."
Now can it compel Apple to make them useful? (Potentially useful, as even the State has argued there likely isn't really any useful evidence there anyway.. sorta makes this whole thing look like a dog and pony show.)
Either way, Congress isn't a check on the Supreme Court. It's typically rather the other way around.
The Supreme Court isn't a factor at this stage.
"Typically" you are correct. The formal method for checking the power of the Judiciary is for Congress to remove Judges from the bench.
Apple is arguing that All Writs doesn't grant the authority that is being used. If that authority is to be sought then it will have to come from Congress. At least one Judge agrees.
Creation of new works is just such a limit.
If there is not a limit, then what the courts may compel as "assistance" becomes absurd.
This is the argument Apple is making and it is the foundation of the opinion of at least one Judge that has ruled against use of the AWA to compel the unlocking of a phone.
What I do think is that people who are intimately involved with new technologies will tend to believe that the complexities of their technologies must somehow swamp the Constitution.
No, its not the technologists who don't get it.
Anyway to the point: we need to clarify if searching my house, and searching my person, and searching my laptop, and searching my cloud-based email history are in the same class. Hell, even searching my breath or blood isn't protected like they should be. Its a long way from clear, what Constitutional protections are extended to modern situation and which aren't. Technology has challenged everything we thought we knew.
E.g. If I was ordered to produce logs that may be evidence in a case, and I only had and only produced a 10GB+ text log with a single line the warrant was interested in. Can a warrant order me to parse the log to find the relevant information?
Furthermore, at what point does a digital space become similar to a physical space? When I can carry 3 hard drives that can contain almost as much information as the Library of Congress print collections, is it reasonable to think of them as "one thing" for legal purposes? In that if you have access to the physical container, you have access to all its contents?
[1] http://www.newyorker.com/tech/elements/how-lavabit-melted-do...
It is certainly not "mistrust government" ergo "disband government", especially when the government in question was formed near entirely upon the notion that a government should exist in a perpetual state of mistrust.
Not being able to collect evidence precludes legal enforcement, which precludes laws, which precludes the existence of a state in the modern definition. Which is the same line of reasoning that most of the "pro-legally breakable encryption" follow, even if they don't carry it out to conclusion explicitly.
I think it's fair to say a state in which everyone uses strong encryption (that cannot be penetrated by the state in any circumstance) in every digital facet of their lives does look very different from the one we currently have (at least in technologically advanced states).
Years ago I wrote software for supply chain loss prevention, every so often there would be a crisis (like a hijacking) that put the department into investigation mode - where there was no room for long term strategic thought. But the course was always corrected when the department director would remind everybody that the job was "loss prevention" and not "loss apprehension". So while criminal investigation is currently a big part of law enforcement, it isn't the primary objective. If that concept sounds strange, check out Bruce Schneier's work.
> ...which precludes the existence of a state in the modern definition.
Is that true, have we redefined the state to only include governments with laws? What do we call the entities formerly known as states that no longer fit the new definition? I wonder how long until we redefine law. I'm really hoping that when you say "modern definition" you actually mean "the definition Jay Leno would get while grabbing people off the street who previously gave the matter no thought".
I do agree with your point thought, I think that those who are predicting catastrophe are more concerned with maintaining the status quo - and when they say the world will end, they mean their estimate of the way the world works. The mental crisis is so great for some that they will craft incredibly convoluted justification, and may go so far was to start redefining words :)
Honestly curious, how else would you or anyone define it? And are we talking philosophical or real world examples?
I'm sure there must be others, I just can't think of any offhand.
A geographic location where there exists a monopoly on violence. For example: the USG gets to decide who is allowed to kill who and under what circumstances, exclusively, for a specific location. That monopoly can be made clear through laws, but it isn't necessary - consider monarchies with no legislative bodies. Also consider the fact that laws cannot be established without a monopoly on violence, which a lot of people seem to get confused about - thinking the authority over violence is somehow derived from law...
> And are we talking philosophical or real world examples?
I'm really tempted to launch into a rant about cognitive dissonance here, but I'll just save time and say that is a distinction without a difference. As far as examples, like I said, pick any monarchy without a legislative body - Native American history has plenty of that.
I would say that "a geographic location where there exists a monopoly on violence (such as a monarchy without legislature)" nonetheless has implicit laws that guide its hand. And by which it is judged! Indeed, transgressing unwritten social contracts has led to the downfall of most monarchies throughout history. Or to put it another way, co-opted power structures are necessary for the governance of any sufficiently large group, above and beyond sheer force. And power-structures require some sort of bargaining and negotiation even if it's rather one-sided.
Laws as instruments to communicate expectations are what makes scalable organization possible past a certain point, whether they're explicit or implicit.
That's why you don't see any long-lived civilizations with true violent anarchy as a form of government.
Philosophy is a pretty huge domain, where one end of the spectrum is navel gazing Platonic forms and the other is the propositional logic that informs compiler design. It sounds like you describing the trap that medieval scholars fell into, where they would recursively construct syllogisms until they found themselves talking about how many angles could dance on the head of a pin. This is what happens when you fail to check your premise, you end up with a logically consistent delusion. So the "self-coherent but completely impractical" philosophy you've condemned is just a condemnation of poor logic - which doesn't do your utilitarian argument much good.
As far as the the rest, you've now changed the topic from "what defines a state" to "what defines a well judged, scalable, long-lived civilization".
> ...anarchy as a form of government...
One of those words doesn't mean what you think it means :)
But digital goods are a different ball game. Even if the government is able to mandate back doors be put into phones, criminals will simply change to use other software.
We're going to need to face the fact that terrorists will still be able to hide their communications using encryption whether the US government attempts to rewrite all encryption communications software in the US or not. There are too many moles to whack.
I'd prefer that our law enforcement officers figure this out sooner or later so they can get back to figuring out how to keep us safe given the circumstances. They have a very difficult job which we need to support through whatever means we can. It's our job to help them learn how encryption works.
People say this a lot. But I'm not so sure. I'm sure they will some of the time, but I bet there are a lot of unsophisticated criminals out there who will use whatever consumer software I use to message my wife about who's picking up milk on the way home today. It's just easier.
We've actually seen evidence to support this position as well. The Paris attackers coordinated over unencrypted SMS when, even now, there are far more secure solutions that one can easily install.
For sure there are. Is that a good reason to pass laws mandating back doors in phones? I don't think so. The economic and security impact will be too large.
The FBI is focusing on terrorist cases as a means to win the public on their side. And, many sophisticated criminals have already figured out how to use encryption. The FBI is saying that criminals use Twitter as a means of connect, and then encourage followers to continue conversation via encrypted methods. I guess this is how they get metadata about who is talking to who but not the actual conversation content.
What i am trying to figure out is if the FBI is saying that there is evidence on the phone of future attacks, or information about co-conspirators, or some other material that would lead to additional action. From what I have read, there is no indication that is the case.
What is it the FBI is gaining by unlocking the phone? Other than a legal precedent.
However, I don't know enough about the law to know if probable cause means to take action regardless of the outcome of that action. That seems to be slippery slope toward justified constant mass surveillance.
From what I've read, the FBI hasn't made such a claim. Only that it needs to be accessed because Farook committed a crime. The determination of his guilt does not rest on some data stored in the phone.
Going back to my original question, what does the FBI gain in the matter of this case by accessing one device in a way that compromises all existing and future devices? And is the, what I interpret to be a, massive imbalance between cost and gain of the action so great that it represents a threat to the 4th amendment.
The disclaimer that I'm not a lawyer was not intended to be cheeky, but an honest show of ignorance of how these kinds of questions are treated in the judiciary.
It's probable cause for the warrant against (??) Apple that I haven't wrapped my head around. Since apple has no known or suspected connection with the crime itself.
Who wants to start a key escrow company :)
"For the reasons discussed above, the FBI cannot itself modify the software on Farook's iPhone without access to the source code and Apple’s private electronic signature. The government did not seek to compel Apple to turn those over because it believed such a request would be less palatable to Apple. If Apple would prefer that course, however, that may provide an alternative that requires less labor by Apple programmers."
Currently, the best practices assume that such "keys to the kingdom" are, for example by Apple, only in some hardware devices, guarded, needing presence of more than one person to be used and that every signature made with them is permanently considered and logged. Even if FBI protects the keys, their use of the things they sign with them won't be able to be followed: these would be just plain easily copyable programs.
This is just theatrics. This can all be done behind closed doors without public involvement. The terms of this debate were chosen by the executive branch to vilify companies and individual supporters of encryption.
What the government wants is to have this debate in the open and for a large enough portion of the public to accept the argument the government should be able to break into your phone with a warrant.
The "with a warrant" clause is good cop - bad cop. The FBI is making the high road argument that all this is legit and above board and to fight terrorism. On the other hand the NSA is doing the dirty work and then oh by the way now the data they have collected is available to the FBI... You know to fight terrorism.
Indeed. It's more than likely that the FBI could just ask the NSA to break the phone, but if they do so then they have just admitted that the NSA can already do this and will have publicly exposed that capability.
If the FBI is smart then the plan is likely to fight Apple to the end, lose, and then have terrorists, pedophiles, drug dealers, and members of the woodwind sections of orchestras move to the iPhone because "it's so secure the FBI can't get in!" all while letting the NSA break any iPhone they need and bootstrap the found evidence through parallel construction.
I, and Apple too, claim that the terms were chosen to establish a precedent that would enable FBI to next time request from Apple to change their products all without going through the process of creating new laws. Because the current laws don't allow that demand, to "make such software" or "change hardware that way." The FBI cites the "All Writs Act" as what gives them that right (their current demand is already "write new software with a hole"), and that act absolutely doesn't contain anything more than "the courts can issue writs." (!) It sounds like a comedy but it's serious:
Where would it be ?
Now if that isnt the easiest way to start a civil war, I dont know what is.
Is the software signing key used to sign the OS the Achilles Heel of the Secure Enclave? If so than does Apple resort to a un-updatable, pure-hardware implementation of the Enclave? Would that prevent the FBI from decrypting phone data even if they installed a modified OS?
It's theorized that Apple considered this option but chose not to go this route because it's a little riskier and a software bug might permanently brick 100 million phones. They may reconsider now.
Does anyone know how far they need to go to put themselves outside of US jurisdiction? I know some companies already sign their software releases outside the US for tax reasons. Is that also enough to exclude themselves from being forced to hand over the keys?
I'm starting to picture a world, where software development (as well as corporate structures and finance) are off-shored to development havens, similar to the Swiss and their banking. We already have the start of data havens. How long until these large companies see the benefit from a legal perspective to defend themselves from an over-reaching government?
How would Wall Street react to such a move? Is such a move away from Wall Street even possible? Can companies switch exchanges?
Surely it'd be cheaper to essentially buy a small country (Shadowrun style megacorp?).
Once he sees that he'll change his mind. However, a lot of damage has been done in that law enforcement believes they could get access to data if only us technology wizards would stop being lazy and do some work for them.
Aside from the compelled speech argument, on balance, we are not more secure with back doors, we are less secure.
So long as law enforcement does not understand this, they will not be effective at their jobs, and they will point the finger at technologists in future terrorist attacks. Even if law enforcement officers do not point the finger, they've already convinced so much of the public that it is the technologists' fault.
We need to continue educating each other on how technology works. Seek public figures and ask them to support our cause. This could go on for years, potentially coming up during every terrorist attack.
We don't even have any tech journalists in the Press briefing room to bring further transparency. In the daily White House Press Briefing on Monday, the 14th, which is the one following Obama's remarks at SXSW, nobody asked any questions about what he said. I'd like to see us get a tech journalist in there.
Megan Smith is CTO of the United States. She is calling for more computer security experts to join her at the White House [1].
> The thrust of Obama's remarks, said Smith, was "making sure that the tech communities are understanding the challenges that law enforcement and their colleagues face so that they're conscious as they're thinking through this."
> So is this still an open policy-making process? "Yes," said Smith. And like others involving "complicated stuff," there's a wide range of voices at the table — including hers. To Smith, the public policy challenges and possibilities raised by the broad range of digital security issues echos the topic she was in Austin to highlight: the need to draw smart technologists to government service.
In other words, the CTO is outnumbered at the table in discussions about encryption.
I'd also like to see her produce meeting minutes for discussions about encryption, or some further transparency. The Digital Services team's self stated founding goal was to increase transparency of our government. However, on this encryption issue, they and Megan Smith have been too opaque. We need more details on what they are talking about. They are our public servants.
[1] http://www.politico.com/tipsheets/morning-tech/2016/03/us-ct...
So taking development off shore or the like won't do much. If anything if the FBI is successful then Apple's business will be hurt world wide as China had already "checked" Apple products to insure there weren't US back doors or such already.
I am curious when it will come to the point where source code is published to ensure that there aren't back doors.
Regardless, this is a quote from Apple's 2015 10K filing (whatever that is)
"The Company’s effective tax rates for 2015, 2014 and 2013 differ from the statutory federal income tax rate of 35% due primarily to certain undistributed foreign earnings, a substantial portion of which was generated by subsidiaries organized in Ireland, for which no U.S. taxes are provided when such earnings are intended to be indefinitely reinvested outside the U.S. The higher effective tax rate during 2015 compared to 2014 was due primarily to higher foreign taxes. The effective tax rate in 2014 compared to 2013 was relatively flat."
You offshore the control of the key signing, source code and development. If demands are made on US based execs, even through NSL, the execs can state that they do not hold the power to force the outside Apple entity to give over keys or source code.
It isn't unlike how US companies outsource the production of their clothes to Bangladesh in order to avoid problems with US labour laws that prevent children working in factories. Not that this example is noble one I might add. But the similarities are striking.
No judge is going to be willing to let this level of power grab against the judiciary to slide.
Apple's lawyers must be very happy right now.
But then again, it's more likely they just completely lost sight of how the real world actually functions, and their own mandate.
If this actually does go through, my view of the US will be closely aligned with Iran and North-Korea.
Source: I briefed and argued the Lavabit case in the Fourth Circuit.
If I were you I wouldn't trust the guy involved in LavaBit in the future, Ladar Levison. He frankly did not seem to be up to the challenge of running a company that is prepared to navigate this space, from the way he bungled the case. He got basic things wrong about how to engage first with the FBI, then with a court over a court order, and made his position worse by ineptly arguing with the court without advice of council. He blew his shot to raise arguments with the court later as a result. Furthermore, he clearly made misleading claims about the security of the product, and I believe knowingly. LavaBit had by that point had already helped the govt surveil other users, all the while maintaining that the communications were secure and that even they couldn't read them.
I have no axe to grind with LavaBit - these are all conclusions I reached by investigating the case myself. You can see this for yourself by reading the court transcripts and news articles. While his intention to provide a secure communications product was noble in the abstract, I would personally trust neither his technology judgment nor his business judgment in how to run a company or handle tough legal circumstances in the future.
He did stupid, immature shit like, when finally ordered to provide his encryption key, he printed it out on paper in an illegibly small font. The court of course compelled him in an industry standard format. That kind of thing is just immature and makes the situation worse for him and his users by extension. http://arstechnica.com/tech-policy/2014/04/lavabit-held-in-c...
Any tech person with an adequate knowledge of encryption and security could have seen through LavaBit's security model. It's not possible to provide webmail in a mode where the webmail provider can't read your email.
http://www.infoworld.com/article/2609583/encryption/how-secu...
> "The ciphertext, key, and password," [Moxie] Marlinspike wrote [in his analysis of LavaBit], "are all stored on the server using a mechanism that is solely within the server's control and which the client has no ability to verify. There is no way to ever prove or disprove whether any encryption was ever happening at all, and whether it was or not makes little difference. ... Even though they advertised that they 'can't' read your email, what they meant was that they would choose not to." Marlinspike also took exception to the way the password supplied by the user also does double duty as an encryption key, a practice frowned upon by password researchers.
The article above also links to Levison's reply which is not convincing at all:
> Marlinspike is assuming that the Lavabit system was designed to be a substitute for the security provided by end-to-end encryption systems like PGP. It was not. Lavabit’s encrypted storage feature was designed solely to protect e-mails at rest.
Huge, huge hedging right there. If you're using PGP then there is virtually no benefit to using LavaBit at all.
> Why protect the data at rest? To limit the data Lavabit could access and therefore turn over to the government. When the government seeks a specific user’s data, it is given what is stored on disk, e.g., any metadata found in a server’s log files and any e-mail content the provider has access to.
Clearly the government wants to intercept data in transit too, and LavaBit had helped them do it prior to this case. Yet LavaBit continued running and advertising its services. Furthermore, if I recall correctly, LavaBit stored the user's data encryption key encrypted with the user's password, so all it took is one login from a user under surveillance and the government would have gotten the keys to decrypt all the data at rest too. A competent technologist should have known that was a risk from the beginning, so if he actually missed that threat vector it should tell you something; but even if he didn't know from the beginning, he knew after the first time he helped do that for the FBI.
There is only one circumstance in which LavaBit's security model would have worked, which is if the user under surveillance never logs into LavaBit again after the surveillance begins. But if they log in even once more, their password flows to LavaBit and thus the govt, which can decrypt all the user's data at rest. This is what the court initially ordered LavaBit to do IIRC: intercept the password of one user on login, and then provide the user's data. And LavaBit had done so upon earlier requests. The fact that he did not disclose this threat vector to his users from the beginning tells you something about his intentions.
If Apple were ordered to close in an instant, there would be mass upheaval, unrest, protests, and huge economic losses just because of the sheer number of people that depend on their products on a daily basis for mission-critical things. Violence would break out. We might even end up facing nothing short of a civil war, and the federal government probably wouldn't want to risk that.
* By which I mean I could see Apple purposefully fighting this to the Supreme Court, even if it means "appealing" a case they've already won so that it goes to a higher court.
The scary thing is that the FBI, with the support of the President and quite a few top Congressional leaders, could very well win.
(given it is a 5C with no secure enclave)
One assumes the NSA would make short work of this phone's lock if it had been recovered from the OBL compound, but using them in this instance also brings in some dicey legal issues (they "can't" operate domestically) and the NSA is even less willing to give up it's own tactics than a security consulting firm would be.
FBI seems to have chosen to go the "lawyer up and look for a court order and some wet blanket executives willing to hand things over" route-- Tim Cook is, thankfully, well principled enough to tell them to pound sand.
Surely, at some point in time, the FBI will figure out how to recruit technical staff that is capable of doing more than just extorting bitcoins from cyber drug kingpins.
Meaning, just having the code won't let them crack a phone and it won't let them patch the OS so that its subsequently crackable would it?
When the FBI is worse than the terrorists they need to take a step back and think about the bigger picture a little bit.
1) fear of a bug. just the right firmware bug and you have 100 million phones lose data, and perhaps bricked too. unlikely, but consider the cost. i would be worried about this if i were in charge of the iphone project and the secure enclave feature were newish. we can imagine pretty good solutions to this one though, with work and time.
2) out of 100+ countries where they sell phones, over time, some will give them a confidential court order saying they must retain this capability. if a foreign court order, they could refuse to comply, but then would have to exit that market -- infeasible if multiple countries. and a different 'version' for just those countries would be noticed over time by security researchers?
3) they might already have an order as such from the U.S., for foreign intelligence purposes. as mentioned a different international version if noticed is a PR disaster for apple. so the easiest way to comply is just do it that way for all phones.
perhaps they push back on the fbi request because that's the one they can talk about, yet it templates the whole issue.
This will be the actual issue for the courts (and ultimately SCOTUS) to decide, the specific device is just a pretext. Hopefully the judicial branch will recognize how this can essentially cut off both itself and the legislative branch from any real control.
Not a lot of hope on that front, as they've already demonstrated a willingness to abandon their duties: administrative subpoenas, tens of thousands, issued by federal law enforcement agencies - not courts.
So it is much closer to "meh, do whatever you please..." but more accurately it would be:
Executive branch: "Yeehaa! Get outta mah way checks and balances, we got bad guys to string up and no time for robe wearing slowpokes!"
Legislative branch: "Sounds like a great idea, white hats can do no wrong."
Judicial branch: "...blank stare...shrug".
> Clarke explained that the FBI was trying to get the courts to essentially compel speech from Apple with the All Writs Act. "This is a case where the federal government using a 1789 law trying to compel speech. What the FBI is trying to do is make code-writers at Apple, to make them write code that they do not want to write that will make their systems less secure," he said. "Compelling them to write code. And the courts have ruled in the past that computer code is speech."
http://arstechnica.com/tech-policy/2016/03/former-cyber-czar...
There are companies outside the US, you know. It's not like we're going go back to the Dark Ages if American corporations all suddenly ceased to exist. Apple users would be unhappy, of course, because they'd have to switch to LG or Samsung phones, but "absolutely horrible"? Are you kidding?
Do you really think that if Apple completely stopped existing right now that it wouldn't have a massive negative impact on consumers and other businesses?
I guess one drawback is that we'd probably see a significant uptake in Windows Phones, and they might actually get above 5% marketshare....
Anyway, MS bashing aside, my point is: Apple is just a seller of convenience, nothing they make is all that critical that it can't be replaced. Anything you can do with an iPhone, you can do with an Android phone. Anything you can do with a Mac, you can do with a Windows or Linux PC. It'd be annoying to have to get a replacement device and migrate to it and maybe new software, but "massive negative impact"? No.
Now, if everyone's Apple device suddenly winked out of existence too, that would be a bigger problem, but that's because of the data stored on those devices, not because of the devices themselves being so valuable. But as long as they kept backups of anything important (and not on Apple-branded backup devices...), that shouldn't be that hard to work around either.
Of course, part of this depends on whether MS's software also winks out of existence, or if only the corporation itself gets swallowed up in a space-time continuum rift. If the software stays, it wouldn't be much of a problem at all: people would just continue using MS-ware as they currently do. A lot of people use illegitimate MS software anyway, so no change for them. Corporations would have less hassle with licensing. The main problem would be security updates, but that's been screwed up lately anyway because MS has been using that to force unwanted updates and ad-ware and spyware.
I suppose the problem is that individuals might get away with using clandestine encryption, but no convenient service provided by companies like Apple would be able to.
I wouldn't support the government compelling Apple to implement that, but I don't think I'd have a problem with Apple doing it voluntarily. Of course, if it's not a government mandate then anyone who cares (for criminal reasons or otherwise) can just use other devices that don't have the same system in place, so in the end it's just security theater. But at least it might detour some government attempts to overreach and effectively outlaw encryption entirely.