The reason government doesn't have or need keys to every house, because no matter how many lock you put on your door, government (SWAT team, for example) can break in anyways, if deem necessary.
So for this reason alone if they truly want to... every house can be and will be open to them, no matter what.
Meanwhile here the locks are based on sophisticated math.. and that math is smarter or more complicated than the largest compute power they can get hold of.. hence make your virtual locks unbreakable. I think that's the whole issue they have here.
People put locks on their homes to keep criminals out. It does not matter if the government can break those locks, until the government itself begins to act like a criminal. At that point, it becomes necessary to build locks that even a government cannot break.
The Snowden alarum showed us all that a portion of the US government has become functionally indistinguishable from an organized crime ring. So, sorry Comey, but perhaps the FBI should focus for a while on investigating and burning out the criminal corruption within its own umbrella organization before we talk about maybe allowing it the power to intrude upon our personal lives at will, in the name of the greater good.
By the house metaphor, law enforcement is more like vampire legends. The vampire has the strength to batter down any door, but if it crosses the threshold without first being invited inside, it loses its power. Except the cop-vampire can also be invited in by a magistrate who issues a warrant.
And perhaps even that is too lenient. Maybe our warrants should be issued by a grand jury. Allowing them to be issued by a sole judge, or panel of judges, seems an invitation to erect secret, rubber-stamp courts like those used for FISA warrants. Maybe your secret keys should be protected by an M-of-N consensus algorithm using about 30 cryptographically-random peers. The government then has to convince a bunch of presumably reasonable strangers that it should be allowed access to your keys. Should be no problem if you're a dangerous criminal, but impossible if the state just wants to sniff around in your dirty drawers.
The government can already enter anybody's home upon receiving a warrant to do so. If you don't let them in, they can bust through a door or tear down a wall. We trust the government not to do this without court oversight. We trust courts to provide good and honest oversight. It is far from a perfect system, but we set up lots of human-level checks and balances to keep power distributed enough that this basically works.
The problem with strong encryption is that this is impossible. Even if there is a very good reason signed off by an honest court, it is impossible to get in. This breaks that human-level checks-and-balances system. What replaces it?
That is a lot more out in the open than a "back door". When the government bashes through the door at least it's in plain site and the house owner knows it's happening. But with encryption how would you know if the government has used their access?
Personally, I find that suggestion repugnant.
We also require people to document their finances to accurately tax them. You're presumed 'guilty until proven innocent' in the sense that you're taxed on income unless you can document that it's untaxable(a business expense). There are penalties for failing to document things. What's wrong with requiring you to document your private keys, along with your receipts?
If you sell apples under the name "Loving Apples", you have to pay your state government to register that name. You can be fined for not registering your name, and your bank or other financial provider will want to see the government approval document. You could have the government maintain a central registry of all private keys, and make it a crime to encrypt a document with a key not documented in a state agency.
If you receive a document that is encrypted, you may be further required to tell the government who gave it to you, to ensure compliance with the encryption law; similar to how giving someone money requires you to tell the government about the transaction for compliance with tax law.
Which direction of the implication you take is a matter of preference. People who agree with giving the government full power(and trust them not to abuse it) or who agree with not giving the government any of this power are both logically consistent with my argument.
I'm only attempting to rule out people who are okay with all of the existing documentation requirements, but balk at documenting their encryption keys.
What if a hacker plants "secret encrypted documents" on your computer, and then the government demands that you produce a key for them? This situation has allegedly already played out with child porn[0], and planting drugs is not unheard of by unscrupulous police officers[1]. Essentially, you're back at the issue GP describes - we don't trust government employees with this much power over our lives.
[0] - https://www.nytimes.com/2016/12/09/world/europe/vladimir-put...
[1] - https://www.innocenceproject.org/leaked-documents-show-alaba...
That's exactly what my (UK) government has done.
It's a horrific idea.
If your personal escrow key is government mandated, and well-protected, that prevents the issue of you forgetting passwords (Estonia already has something like this). It also fully ensures that the government accessing escrowed keys requires you being informed.
I still don't support this plan, but it is the best thing I've seen.
Clearly the solution is to require every paper shredder to be equipped with a camera to scan documents and upload them to cloud.gov before shredding. Of course, nobody would be authorized to look at the data without a warrant, and we should trust that nobody working for the government would ever break this law.
Imagine if the government busted down a quarter of all doors in the country - that's a lot of industrial-scale police work, and it's very visible to all citizens. On the other hand, the government can tap half of all phones in the country, or intercept half of all emails sent by US residents, and we're not even legally allowed to know it happened, so we can't even argue against it in a public court of law.
Atomic-grade offense requires atomic-grade defense. We will have un-breakable encryption, or we will be crushed by secret intelligence agencies with immense power and no public accountability. It's a whole new game.
Anyway, I'm not too worried, strong encryption is open source and widely available already (even if not used in nearly all the circumstances it should be yet). This cat isn't going back in the bag.
The first, as others have mentioned, is how easy it is to use an escrowed key without detection. The second is the fact that strong encryption remains available. This means you need to outlaw strong encryption, at which point steganography comes up to hide the encryption. Finally, key-escrow is a massive increase of the attack surface of encryption. It's almost as if the government mandates we all use TSA locks on our doors.
Another line of argument is to emphasize the extent that our digital economy and national security rely on strong encryption. If you outlaw it, then all of our online banking and shopping, corporate and government secrets, and more are vulnerable to hackers and foreign governments. And just as the conservative gun advocacy argument goes, outlawing it won't necessarily take encryption out of the hands of criminals, only law-abiding citizens.
I think it's a good analogy.
https://www.wired.com/2015/09/lockpickers-3-d-print-tsa-lugg...
Black bag operations have always existed, and will always exist, despite legislation or other rule-making to the contrary.