Why Security Backdoors are Bad (2016)
medium.com
medium.com
If we decide we don't have the right to conceal our digital correspondence from the government, what else should we not be allowed to conceal? The conversations you have in your car? In your home? Besides the right to privacy, what other rights make fighting terrorism harder? Freedom of association and movement? Freedom of speech, which is regularly used for recruitment?
Finally, if they really want someone's data, in a covert way, they're already able to plant hardware keyloggers, or spy on someone as they enter a password, etc. But it all requires manpower. What backdoors would let them do is monitor encrypted communications covertly and in bulk. To build up a database of all your chats and forum posts, and mine it for any anti-current-politics sentiment.
Crypto isn't a safe, it's the ability to talk in a language only two people understand. Unlike a safe, they have access to the data. They just can't understand it.
And more importantly, with legible handwriting! The FBI has limited resources and we wouldn't want them to waste time deciphering your handwriting only to learn what you've said to your lover, while a terrorist's handwriting goes unanalyzed.
I like this line of reasoning, that we must modify our behavior to enable surveillance. It switches things around from the traditional perspective, which is that we're doing extra things to increase our privacy, to instead be that we're doing extra things to decrease our privacy (using weak crypto, no crypto, adding and removing ssl here, etc).
Let's say the Government decides that it has a zero tolerance for domestic violence, it goes ahead and implements "preventive measures" - cameras and microphones in every home, in every room. Now, they might achieve the great reduction of violence, might even catch one terrorist. As always - think about the children, we could prevent all those terrible parents that beat their offspring and catch all those wife beating husbands. And, lets think about what that would do to society...
If device makers and online services are required to set aside a master key for the government, how would we be protected from abuse if the government was ever to become corrupt?
If pervs at the Department of Homeland Security wanted to rifle through pictures of our children, they could. With enough government corruption, if the local sheriff, or the US President, or anyone in between, wanted to read the most private thoughts shared with us by our loved ones, they could... keeping in mind that even if we have nothing to hide, our loved ones might like their privacy.
The more corrupt the government, the more ways they would dream up to abuse the power of this kind of mandatory master key.
In the case of the US, thankfully our government is headed by people with the highest ethical standards... oh, wait, it isn't!
Besides privacy invasion by rogue government employees, the other problem is the fact that such keys can, and likely will, leak out to bad people who will use them to get into our bank accounts and take our money. Even the US NSA cannot protect its most dangerous hacking tools from being released on the internet. It won't be able to protect this master key capability either.
Requiring a master key for the government would be a very misguided and dangerous policy.
Why worry about precedence? When I'm in power I'll just change the rules!
"FBI demands rights to look at your children's dick pics!"
It would be great to see some headlines like that.
And then in fine print down below: "And some other pics too"
Isn't that literally what the TSA lock on luggage is? Granted, I wouldn't regard a suitcase made of bunch of plastic or fabric as very secure against any form of attack, but why do all these arguments against backdoors never mention this? And with the TSA master keys leaked a couple of years ago all it needs is one malicious airport worker to open your bags and sniff your panties, erm, steal your laptop.
Good point.
> but why do all these arguments against backdoors never mention this?
However, I don't think arguments against back doors should mention TSA luggage locks! It's a bad prior.
You don't want people in the "airport" mindset when you're trying to convince them not to allow the government to snoop.
People who enter airports (or especially customs) basically give up all of their rights to privacy. And most Americans are apparently OK with this. Begrudgingly, perhaps, but ultimately most people accept it and go on with their life.
So, "think about airports" is a really terrible persuasive setting.
Instead, you want people thinking about their bedroom. About their car. About their child's playroom. About the settings where they live 99% of their life. Because that's the setting that government back doors in consumer electronics expose. And that's the setting where people get most uncomfortable about carte blanc government access.
Also, 'security backdoor' is an oxymoron. There is no such thing. It is either secure or has a backdoor.
I'm sure this actually happened somewhere in the US... it might just have been proposed but I distinctly remember reading about mailbox-like containers at the bottom of drives locked with a master key. Does anyone else?
Edit: More than once apparently, "lockbox" was the term I was missing when googling earlier: http://wcfcourier.com/news/local/update-cedar-falls-city-cou... http://archive.northjersey.com/community-news/2.4225/rescuer...
As scary as that sounds, it isn't /completely/ stupid. The system is designed to make using this backdoor is exceptionally noisy. Your Knox Box should have a tamper switch inside, so that any time it is opened, alarms go off. At the other end, when the key is removed from a firetruck for use, alarms go off.
"The oligarchy" who you never identify would include the owners and shareholders of businesses who would suffer catastrophic business losses in the event an encryption-defeating law were passed.
Various billionaires are adversarial with respect to the laws they support and the media narratives their companies push (e.g. Washington Post vs Fox News). They don't act in concert.
If you really want to resonate with him, publish this in comic book form. I'm serious.
Perhaps a few politicians may even reconsider their attitudes towards encryption and security in general.
Eh, probably not.
So far Apple seem to protect it pretty well. They show that only the good guys can control the backdoor argument is not without merit.
EX: https://nakedsecurity.sophos.com/2012/10/25/sony-ps3-hacked-...
And no the US government has not done much better.
I just point that apple show that keeping keys really works.
I don't think that console jailbreaks are from leaked keys (except ps3) but from normal exploits.
Also, maintaining back doors would be a significantly harder problem than just keeping keys on a server used to sign things. Apple can for example keep the keys on an offline private server, but that's not really viable if 10 or 100's of thousands of people across multiple agency's of state, local, and federal law enforcement need access to break into things.
Worse you could quickly find nobody outside the US would be willing to use our software or services.
Yet within weeks, people had hacked it wide open and stuck hundreds of ROMs on it.
That we know of.
It's also important to remember that the only public trial against that backdoor was only for show, and despite not officially breaking it, the attacker got everything on the phone anyway.
1 - They are not guaranteed to always be in power.
2 - They will be the first to be targeted.
3 - They have the most to lose.
I just don't understand why they don't care about it.This line of argument would hopefully resonate with the constituencies of the politicians pushing hardest for these backdoors (although it's a fairly bipartisan effort).
I've never heard anything come out of that above kerfuffle, presumably because there was some backroom dealing done to ensure it's not a problem for them specifically.
Surely politicians should only be more worried if they fear their actions being exposed - the only reason I see for that is if they're guilty of something. Otherwise they've only equal reason to be guilty of you're of the crowd that considers "I've nothing to hide" not to matter.
A scheme such as Shamir's Secret Sharing - "An algorithm in cryptography created by Adi Shamir. It is a form of secret sharing, where a secret is divided into parts, giving each participant its own unique part, where some of the parts or all of them are needed in order to reconstruct the secret."
Source - https://en.wikipedia.org/wiki/Shamir's_Secret_Sharing
And the Bitcoin protocol has a similar thing, with escrow key permissions. Again, intended behavior, not some "super sekret backdoor".
I would accept the idea of a backdoor IFF the program encrypting hid the fact that it also encrypted to an escrow unawares to you, along with keeping that a secret.
And I assert that, no matter how carefully designed, a backdoor is always a bad idea.
Having two parties that have to agree is a mitigating feature. It makes it less bad. It doesn't make it good, though.
To be clear, I do not want James Comey, Donald Trump, Joe Biden, or any "heroes" or "villains" of our power structures to be given any access to my encrypted data, whether they call it "lawful" or not.
That said, I don't think the "all backdoor implementations will inevitably have bugs" argument holds water in all cases, so this battleground will move to a philosophical one based on reputation and the ideals we want to uphold. This means we can't just keep shouting, "you're too stupid to make a sufficiently secure system" at the government over and over again.
So what would an effective and "secure" backdoor system look like?
Say the manufacturer creates a device with a protection similar to Apple's Secure Enclave, where there is a key i burned into the system at manufacture, which is not accessible in any way after it has been programmed in.
A second, independent, random key j is created at the same time, and the value i' = "i xor j" can be retrieved from the device with physical access only, e.g. by programming i' into a separate memory section inside the IC itself that is not accessible on the data bus while the system is running normally, it is only powered on by the hardware if one of the microprocessor's pins is jumpered at system boot.
Now, to retrieve the value i, you need both i' and j, and you can only get i' with hardware access. So even if the database containing all the j-values ever created gets compromised, nobody can break into your phone without physical access.
Now, of course, if the list of j-values got published, that would be a huge embarrassment for the US, but it would not mean that everybody's bank account and private emails would be accessible to every script kiddie overnight.
This is not a 100% risk-free solution, but it is exactly the kind of so-called "balanced" approach that the government is going to try and sell us, because it does actually ensure that the gub'mint can't break into your encrypted data, at least without physical access.
So the argument to actually use against Jim Comey is simply to point out that rest of the free world won't require this of their manufacturers, so nobody outside the US will ever buy an Apple product again since they don't feel any US manufacturer can be trusted, even if the system is technically secure.
Also, any terrorist can still create an unbreakable crypto system by running custom software on a $20 Raspberry Pi, and good luck getting ISIS to cooperate with a lawful warrant for assistance in decrypting their operative's device.