Thomas Jefferson and Apple versus the FBI
blog.cr.yp.to
blog.cr.yp.to
In 1977 the Institute of Electrical and Electronics
Engineers (IEEE) scheduled a symposium at which several
important papers on cryptography were to be presented.
Research had established a basis for developing powerful
new encryption schemes, using fundamental concepts of
computer science, and examples of these schemes were
included in the papers. Prior to the symposium, however, a
letter arrived at IEEE headquarters warning that the
presentations might subject the authors and the IEEE to
prosecution under the Arms Export Control Act of 1976. The
letter was signed by an IEEE member, Joseph Meyer, who gave
only his home address, but who turned out to be an employee
of the National Security Agency (NSA).
40 years later, we still repeat the same arguments and make the same mistakes.Would you elaborate?
It would be interesting to see a visualization of our political "family tree". For example, Rep George Miller from California was in office from 1975-2014. Who worked for him over those years, where are they now? Or flip it around, who did our current pols work/mentor under?
Keith Sebelius was a rep for KS in 1976. Father-in-law of Kathleen Sebelius. No direct ties to the 1976 bill, but that isn't the point I'm making. Nepotism and family ties run deep.
Rep Paul Tsongas voted Yea for the bill in 1976. His widow is now a Rep for California.
Rep John Conyers is the longest serving member of the house, having been elected in 1965.
Senator Trent Lott retired in 2007. Was elected to House in 1973.
Senator Chuck Grassley elected to House in 1975.
Recently retired Senator Tom Harkin elected to house in 1975.
Rep John T. Myers in office 1967 to 1997. His son-in-law takes over the seat 2001-2003.
Senator Paul Sarbanes served in the House from 1971-77 then moved over to Senate until 2007.
Rep Charles Rangel in office continuously since 1971.
Rep Norm Mineta server from 1975 to 1995, then went on to Sec of Commerce and Sec of Transportation.
Not all these people voted for the bill. Again, not the point. The point is, our system makes the same stupid decisions because it's a lot of the same stupid people.
The more I look at the govtrack.us page for this bill, the more names I recognize, the more I think "we really need to get away from politics being a legit `career` option."
Which has been tried, and the extreme on the other end isn't pretty either. Strict term limits in California (prior to some revision in 2012) meant that Senators and Congresspeople were almost never around long enough to truly get involved and understand an issue. There was a lot of freshman lawmakers all trying to make their own mark, perpetually blind to the prior efforts.
The question really is how many years in congress, the senate, or both is too much, and how low of term limits is too low? If we can't find a happy middle ground (I honestly don't know), then maybe we need to step back and examine the question again, and decide whether there are some other levers and incentives and regulations we can use to our benefit.
Note: It's also worth looking at whether passing institutional attitude (knowledge?) as you described is actually a bad thing, or a natural correlation. If that district or state has a particular leaning, it could be that it's just natural that a similarly positioned person will be more likely to pick up the seat later.
Sounds a lot like our own industry...
Term limits are a stop-gap measure. And let's say they go into effect. Well, the day after the term is up, the politician will step through the revolving door into the lobbying world, advising the new crop of term-limited representatives on how to "get things done."
If you could truly split congress from its technocratic base, such that each new member of the House or Senate is just "plugged in" to a long-lived technocratic base-infrastructure (in the same way the President is!) then we could achieve much shorter term-limits while still achieving high effectiveness.
I love this - definitely not a side to the argument that I'd considered before, but I find it very compelling. Well written article all around.
So the FBI's ability to secure the code isn't currently relevant.
The FBI wants them to create an operating system that would run entirely from RAM without touching any of the flash memory on the device.
The code cryptographers use to communicate ideas is the same code the computer can execute. Are you contending that the same information is speech sometimes but not other times? What if the thing you're going to do with the information hasn't even been decided yet at the time of dissemination?
SCOTUS can make special distinction for encryption because implementations in practice are both a tool with independent utility and communicate an idea.
Speech is a thing humans do, not a characteristic of bits or bricks or black armbands. The First Amendment doesn't protect particular types of things. It protects communications between humans. If one human isn't using a thing to communicate to other humans, it's not speech.
Imagine a coder refusing an order from the FBI to create a tool. She is refusing to translate her thoughts into code. What is that other than refusing an attempt to compel speech?
There is only one human in this picture. But the code an FBI order is attempting to extract from her brain is still speech.
http://c.fastcompany.net/multisite_files/fastcompany/imageca...
But law enforcement can still tell you to "Stop and put your hands above your head!"
The former is the communication of an idea. The latter is just a physical movement. Even though it's the exact same action.
Have you got an answer to what compelled coding is, other than compelled speech?
Like raising your hands above your head when the cop tells you to.
You seem to be mixing up the standard for the fifth amendment and the first amendment. The fifth amendment says that the government can't compel you to testify against yourself, and that a physical action (like punching in a key code) can be testimonial if it involves accessing one's thoughts. The fifth amendment doesn't apply here because Apple is under no threat self-incrimination.
And "accessing your thoughts" is not the test under the first amendment. The test is whether the speaker is expressing an idea. Instructing a computer to do something is not expression, it's not communication with another human. It's a human acting on an inanimate object. The fact that the action involves accessing one's thoughts is irrelevant. E.g. the government can definitely compel a bank employee to punch in a key code to unlock a vault, even though that involves translating thoughts of the combination into a sequence of key presses.
NB: it's kind of interesting to be splitting hairs over what is and is not speech here. A court can compel you to come in and testify against someone, which is undoubtedly speech. Yet the power to compel testimony is one of the fundamental powers of a court, and has never been understood to be a violation of the first amendment.
This is substantially different from compelling coders to discover how to break their own secure implementation and implement a deliberately broken implementation. This is compelling a creative work, and a particularly perverse one.
The court wasn't saying that the government can't regulate what you can and cannot program a computer to do. It was saying that the government cannot restrict sharing of source code between people, which is often used to communicate ideas.
Example: "What? What's the problem? All I did was the send the signal 100100111011110[...] to my computer. I have the right to say '1', don't I? I have the right to say '0', yeah? So I must have the right to say '100100111011110[...]'. The fact that this triggered a destruction of the evidence on my hard drive is totally irrelevant, because we established I have the right to say '100100...', don't infringe on that, man."
In your example, giving instructions that destroys evidence can certainly make you guilty of obstruction of justice or some other similar crime. But the point is, the government cannot either compel you to give those instructions, or compel you to not give them. They don't have the right to do that - at least not until they've convicted you of a crime that allows them to restrict your rights. If you're a free citizen, you can give whatever instructions to your computer you damn well please - and then face the consequences, which may be to make you a criminal.
What the government ends up arguing in the Apple case, is they want to make you work to figure out what a "10101..." is that will break your own products and make you say it (to the right phone... and then the next phone, and the next). This, they want to do, even though you have not committed any crime. That is the issue at stake.
As a free, lawful person you have the right to decide for yourself whether you're going to say something that you disagree with ethically and commercially. The FBI wants to take away your right to make that decision. They want, without even having legislated on the topic, to force you to say what they want you to say "because terrorists".
With regard to publishing the encryption algorithm, the court found that he wasn't "refram[ing] an act to focus on speech" as you say but was engaging in the standard way that cryptologists communicate ideas: source code.
His style extends to his software - he offered a bounty for a verifiable security hole in his qmail software in 1997 which still stands today. Nobody has ever found any security holes in qmail. https://cr.yp.to/qmail/guarantee.html
I'm not saying that software is bad, but the security guarantee is too restricted to be practical anymore.
But qmail was a revelation in 1996, and a solid choice for at least ten years, despite never reving past 1.03. Those ten years were pretty ugly in the network services security world. djb's bounty was a significant statement in a crazy era.
No one uses qmail any more. But it was used by everyone who ran serious mail servers for a long time. The guarantee was well-tested.
It is not coincidental that Postfix uses a very similar multiprocess model. That is how you encapsulate security domains. djb didn't invent it, but he shined the light for everyone who followed.
You can cut out a lot of security issues by defining ahead of time what you're going to support, writing only that, and never doing anything else. New, small code rarely has terrible design flaws if there was a good plan ahead of time (and djb had an AWESOME plan) and you write it by yourself. Now if you live with a project for a long time, and actually maintain and extend it - that's would be even greater achievement. Postfix went in the similar direction as you mentioned and started around the time qmail got stable, but still lives.
Relatedly, djb is an academic who releases code sometimes, and Wietse is a sponsored open source developer. Their methods are very different, but they've both made huge and complementary contributions.
http://www.wired.com/2013/05/game-king/
The prosecutors argued that they were "hacking" the machines, and behaving illegally. That's ridiculous.
If Apple can be forced to falsely claim that any hacked software is "valid", then every single citizen of the USA can be forced to parrot the government line.
Free speech? Only when it's acceptable speech.
I don't think the OP falls into the trap that the above is pointing out, but it would be easy to take this argument and accidentally make it into an argument that does.