Senator asks FBI director to name the cryptographers who support backdoors
gizmodo.com
gizmodo.com
Maybe we should take the high road: the time has come that unbreakable crypto is to be considered a basic human right; the same as free speech, freedom of thought, or freedom of religion. In this digital age, a lot of those other rights can't be guaranteed without strong crypto. Whenever any mention of backdooring, weakening, disabling, preventing encrypted communication comes up, our reply should be, "no, you can't do that because crypto is a human right, the same as free speech, and is necessary to protect other fundamental rights".
If the government is pressuring organizations into backdooring their crypto, wouldn't it be relevant whether using effective crypto is considered a human right? Not sure why you think it's so out in left field.
- You have freedom of speech/thought unless it was the motivation behind a criminal action, in which case you're additionally punished for a hate crime
- You have freedom to keep & bear arms except not in some states if your Sheriff doesn't like you
- You have the right to privacy unless there is probable cause to believe you're involved in criminal activity, in which case the court can issue a search warrant
- etc. etc.
Even if you tried to argue that "crypto is a basic right," that wouldn't change anyone's mind who is arguing that there should be an asterisk if you're under criminal investigation.
https://en.wikipedia.org/wiki/Universal_Declaration_of_Human...
https://en.wikipedia.org/wiki/Beatitudes
Please share yours, if you like.
I don't think that crypto needs to be a stronger right than the Bill of Rights (confining myself to U.S. laws for the purpose of this discussion). What I'm saying is that whenever government proposals come up about restricting or backdooring crypto, we techies (and other thought leaders) should take the strong position that this is a right and then--maybe--have discussions about warrants, etc., afterward. What we've been doing for over 20 years is arguing that crypto is necessary for good security and backdooring is bad for security. That's all true, but it's a technology argument. It would be much better if we start off with the premise that unbreakable crypto is a right, that we're allowed to use it, that we don't need permission.
Crypto is a right that we're allowed to use, without permission. (Oh, you think it's a munition? Well, we have this Second Amendment thing...)
And we need good security, and backdooring is bad for security. Both are true; both should be argued as well as possible.
However, this is not true. To give an example, even as we enter an age of extreme political correctness and government authority--interepreted as intended to protect people from mean words--you can still find in mainstream media people arguing for the opposite.
Unfortunately, the sad reality of our civilization is that free speech's importance is only apparent when a cultural adversary infringes on it: https://www.theguardian.com/commentisfree/2015/feb/16/free-s...
In other words, unbreakable crypto may be a worthy goal to aim for, even if we know just as with other human rights that there will be slip ups and set backs.
I wouldn't say that the right to avoid cruel and unusual punishment be thrown out just because the military set up Guantanamo and other black sites around the world. It means we need to fight even harder, not give up on our ideals.
The idea that private use of encryption is any different than that is the recent propaganda.
If the police have a warrant then they can place a bug in your house or trojan your device, which gives them access to everything starting on the day they execute the warrant.
Which is the same as it is for anything else. A warrant isn't a time machine. You can't get one today and use it to read files the accused shredded five years ago. Nor does the government have the right to make everyone submit copies of all their paper files to them to put in a locked government room for hypothetical future access with a warrant. But that is what they want to do with encryption.
What encryption actually prevents is warrantless mass surveillance of content, which is exactly the sort of thing all the other rights categorically protect people from the government doing.
If they trojan your device, they can certainly view all of your communications and files from the past unless you've explicitly securely deleted them before-hand.
Rights are, in part, a recognition of the limits of the law. It makes sense to include the ability to hide and potentially destroy information in a way that the law cannot access, any more than policemen and prosecutors can levitate themselves.
Is the right to have the ability to pay to have anyone in the world you don't like murdered, without it getting back to you, a basic human right?
If so and people start getting murdered for hire, and law enforcement has no way to stop it, would you be okay with opening in certain cases a previously undisclosed back door, for example as part of tracing payments in the dark net?
What if normally cryptography were secure and uses of the backdoor only happened like this:
>The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
Would you be okay with the back door existing if it were used under such a court-ordered scenario? Why did I just quote this text, in your opinion? Why does this text not end with a period after the word violated? Then it would read:
>The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated.
Don't you agree that as a "basic human right" this version appears much stronger than the first version I quoted?
So, would you prefer if the second, abbreviated version replaced the first version?
This is, I think, the place where the metaphor shear between technical limits and legal limits actually happens.
Legally, we treat reasonableness as the salient divider. To a first approximation, everyone agrees that some searches and seizures are reasonable and some are not, and we've developed a well-defined social technology (warrants, judges, courts, etc.) to distinguish the two cases.
But technically the dividing line is possession of the backdoor. Third parties without a backdoor cannot perform a search, no matter how reasonable it may be, and third parties with a backdoor can perform even the most unreasonable search. There is no mechanical way to introduce a hole for reasonable cases but not unreasonable ones, no matter how well we formalize the decision making process.
Software does kinda work like a form of law, but one without recourse to human judgment. There's no judge, no jury, no prosecutorial discretion. It appears that, without a bit of hands on experience with technology, legally minded folks have a hard time really internalizing how constraining that fact is on what's actually possible.
If there is a way of bypassing technology then it should be assumed it will be bypassed, most particularly by those whom that technology's presence would be used to defend against.
Golden keys will be stolen or otherwise recovered (eventually).
Only by making the cost of that effort more than any possible reward will security be maintained. Just the same as physically defending a physical location.
And for golden keys, the reward is enormous.
No, because it would not stay that way. The problem is, that backdoor would get out, and all of the bad guys would know how to use it, and be able to use it. Now I have no protection anymore.
Most of the time, when we're arguing against back doors, it's not because we're worried that the government is going to collect evidence to use against us in court. It's because we don't want our payment transfers to be intercepted by bad guys. We don't want our computers hacked.
This isn't facetious. We do not yet know which of Impagliazzo's Five Worlds [0] we inhabit. Currently, the best guess is that we live in Cryptomania, but we haven't proven it. Since we would have to live in Cryptomania for your proposal to carry any reasonable weight, we should probably postpone any talk of adding to the list of human rights.
On the other hand, the ability to multiply numbers, while perhaps not a right, is something that the government should probably not bother trying to criminalize.
[0] http://blog.computationalcomplexity.org/2004/06/impagliazzos...
The privacy & crypto policy fights is a replay of the election integrity fight. We democracy defending noobs (in the USA) walked right into the trap of trying to rebut the vendor's appeal to authority and the torrent of bullshit they spewed.
Big Tobacco easily found scientists eager to support their mendacity, for a price. Of course the FBI, NSA, etc. have experts for hire peddling their freedom destroying agenda.
In contrast, the German activists successfully argued that private voting and public counting is a basic human right.
In addition to being The Correct Answer (morally, ethically, legally, logically, etc), such as affirmative position also has the benefit of being easier to communicate.
The government should not be able to take freedom from the people at large. Peaceful use of something shouldn't be abridged just to further the goals of the government. It is the government which should serve the people, not the other way around.
"The powers not delegated to the United States by the Constitution, nor prohibited by the Constitution, nor prohibited by it to the States, are reserved to the States respectively, or the people."
But the Federal government will argue what "unreasonable searches" means (IV) or the citizens will argue what "a well regulated Militia" means (II).
I wish people would see this for what it is. The head of the FBI shouldn't be lobbying for laws. He should be working within the boundaries of the law. He shouldn't be lobbying to take something away from many because a few may abuse it and it would make his job more difficult.
Yes, but you're asking a set of people who have not given us much evidence they're capable or willing to implement that human right. It takes a strong will and a stiff spine to stand up to powerful interests and I'm not convinced the people I see reported on in mainstream so-called journalism have that political will. Hiding behind technological inferiority seems to take precedence over standing for our rights on principle.
Freedom of speech, which you mentioned, also takes a beating these days in light of completely and accurately conveying messages some people don't agree with in a timely manner. We can't have freedom of speech because that might involve giving up conveniences, they argue.
Not American, but isn't criminality in the U.S. like at about lowest point in history? Is there some actual evidence that the lack of ability to do mass surveillance is somehow making criminal investigations less effective?
The problem with large scale conspiracies is that they require a lot of people, and eventually someone slips up. This sort of crime is the bread and butter of the SEC, and they aren't making any claims about it increasing.
[1] http://www.nationalreview.com/corner/427758/careful-panic-vi...
[2] https://www.factcheck.org/2016/07/dueling-claims-on-crime-tr...
What other kinds of crime are there, and how would you measure how much of it there is?
There's no data I've seen that suggest anything other than a broad decades long drop in crime.
They know that "outlaw secure encryption to stop inside traders" is going to be an even tougher sell than "outlaw secure encryption to stop murderers," so they try to make an illogical argument involving scary criminals instead of a stronger argument with not-scary criminals.
The FBI doesn't give a shit as long as it's the anus of the average citizen being ravaged. They only care when it's against the 1%.
The white collar crime, yeah, some forms of it might benefit from encrypted communication. But again, where is the evidence? Is the tax evasion (non-institutionalized) skyrocketing?
The whole claim is just very suspicious. I think there is so much open data today that even with encrypted phones it's much harder to leave less trace than in the past.
In the 60's you also got a lot more check fraud. Which is similar to CC fraud, but that's again for more global.
While I count all attacks from a single process to be “one attack” and “one crime”, others may not.
Then there’s “unlawful pornography”, which varies wildly by jurisdiction — when a friend pointed me at fetlife, one of my thoughts was that the entire site is illegal to view in the UK unless you disable images (I’m no lawyer though).
There are probably a lot of other things describable as “conspiracy to X”, but that’s a guess on my part.
(I think there may be a lot of victimless crimes too, but that’s a different topic).
It's generally been declining since the trailing edge of the Baby Boomers got out of the prime criminality age range.
But the demographically (and possibly also lead-exposure) driven “crime wave” was a boon to political support for law enforcement and authoritarian politicians, so both have learned that selling the idea of rampant crime is a good way to get what they want politically.
Not sure if you are making a claim, but I don't really think this is generational other than a coincidence in technological timing - the time you are talking about is the 90's-2000s, which is when improved surveillance techniques, information sharing databases, and other deterrents became more possible and widely used. At that time most of the people on the ground would be gen-Xers (think 21 jumpstreet, colors, new jack city, boyz n the hood, etc, usa wise)
Also, timing wise, the cold war ended and so along with it much of the foreign funny money on all sides for subversive activities, and police spending went up bigtime in most areas..
As you say, most of that became available in the (mid-to-late-) 1990s and into the 2000s, the crime peak happened in the early 1990s (violent crime specifically in 1991.)
There's something of a demographic case to be made (not so much generational as the fact that the Baby Boom was a boom, and a big demographic bulge going through that age range has an impact), there's a plausible, and arguably stronger, lead exposure case to be made (the decline, and the preceding rise, closely tracks the drop off, and preceding rise, in use of leaded gasoline.)
The variety of intended policy mitigations adopted well after the peak certainly didn't cause the drop, and probably have no-to-minimal impact.
tl;dr: Lead exposure has been shown to stunt intellectual development and increase aggression. With the 50s came the personal automobile, powered by leaded gasoline. Crime rose as that generation grew to adulthood. In the 70s use of lead in gasoline declined due to the clean air act. As that generation grew to adulthood crime rates fell. In the 90s the use of lead was banned. That generation is reaching adulthood now.
Lead polution peaked in 1973, violent crime peaked in 1993.
https://en.wikipedia.org/wiki/Lead-crime_hypothesis
https://en.wikipedia.org/wiki/Tetraethyllead
https://www.motherjones.com/environment/2016/02/lead-exposur...
I mean, it's always been a bit skewed. Example, Nixon targeting blacks, hippies, and the anti-war left: https://www.cnn.com/2016/03/23/politics/john-ehrlichman-rich...
There's an intimidation factor behind the thought that the government can read any communication you make, if you give them cause, even if you aren't doing anything wrong.
According to Dan Baum, after Ehrlichman died, years after Ehrlichman supposedly told him. Furthermore, even if Ehrlichman did tell him this, Ehrlichman was convicted of perjury, conspiracy, and obstruction of justice.
Hearsay, from a convicted liar, retold by a biased individual with no apparent proof other than his own word.
This could also be posed as:
> statement from at-the-time President's chief domestic advisor to a journalist during an interview, in 1994
But yeah, he's dead, and the fact that the reporter took so long to make it public makes it suspicious and doubtable.
Your criticism is fair, but surely you can think of a few other examples if you dislike this one? MLK wiretapping, McCarthyism, etc?
If not, and you are up for a read, check out this 69 page document from the ACLU:
https://www.aclu.org/other/unleashed-and-unaccountable-fbis-...
I don't need to read the aclu document. I'm not arguing with you. I'm pointing out that the moment you reference Ehrlichman in any way, you will lose all your credibility again. You do damage to your own causes when you try to mislead people like this.
All of those records exist now, and LEOs should have access to precisely none of them.
And at least if they search your desk you know about it. The idea that people can go behind your back and look at your info is disconcerting.
Sort of. We're approaching 1960s level of crime, but it was lower in the early 60s and 50s. I don't know if we tracked it before then. Crime rates, including homicide rates, are about half of what they were 20 years ago, but about 20% higher than they were in the mid 50s.
> Is there some actual evidence that the lack of ability to do mass surveillance is somehow making criminal investigations less effective?
No. Police investigations still tend to use things called search warrants and interrogation of witnesses and suspects to acquire incriminating evidence. Mass surveillance is very expensive in order to be effective.
I have family involved in law enforcement and they are able to request access to stingrays from state or federal police, but their use is fairly limited and still requires a search warrant in many cases. I don't believe it's gone to SCotUS yet, but many appellate courts have ruled that you've got to have one.
But there is reason to believe pre-1980 statistics had a huge problem of under-reporting more or less everywhere, especially in countries as big (and relatively desolate, at the time) as the US. Even just collating reliable statistics is a challenge today, let alone in the '50s.
Nowadays we almost have the opposite problem, with cellphones and vague laws resulting in increased reporting of entire classes of crimes. So having a declining trend despite these development, is either a huge win or proof that statistics can be tweaked at will (as The Wire taught us, and we all know The Wire is all true... /s )
> as The Wire taught us, and we all know The Wire is all true... /s
I could never get in to The Wire.
The very first scene of the very first episode is a courtroom where a woman changes her testimony on the stand, and the prosecutor doesn't: a) show the woman her sworn deposition, b) request an immediate continuance (surprise testimony is one of the things that warrants one), and c) threaten and then carry out charges of perjury against the woman for refusing to testify according to her statement. Instead, the prosecutor keeps asking questions over and over, driving into the jury's mind the woman's changed testimony. I'm not a lawyer, but I feel like I know something of courtroom procedure. This was just so unbelievable that it made me angry that the writers expected me to believe it. It would be like someone hacking a System/360 Model 30 from their iPhone in 10 seconds.
I understand it was for dramatic purposes to lead to the other witness's murder, but it broke my suspension of disbelief so badly I had a hard time watching the rest of the episode. I don't remember if I ever watched the second episode.
Not if done right, according to William Binney who worked on designing the systems that eventually (d)evolved to what Snowden leaked information about.
That was re: (actual) national security - but the same mechanisms are at play: if you can record what you need to achieve a stated goal for 250m - why do that if you can spend N billion on a less efficient system?
Compared to manual policing, automated surveillance is a really cheap way to run a police state.
Now, if the goal is to minimise crime, as opposed to maximise catching criminals (which really should be a means to an end, not a goal in itself) - better welfare, psychic health services and after school activities are probably the way to go...
Mental health services?
Edit: What I meant by "supports the FBI" is "supports the FBI on this issue". If you understand encryption and support the FBI in a general sense, but think they are wrong on this issue, then you aren't a counterpoint.
I understand cryptography and I broadly support the activities of the FBI. You have now “met” such a person.
It’s fully possible to simultaneously support opposing concepts like end-to-end encryption for users and the organizational imperatives of the FBI. A nuanced perspective might consider that citizens and the FBI have separate prerogatives and competing incentives with respect to private encryption, and this is perfectly fine.
A consequence of an organization optimized to reduce crime is its natural zeal for greater control over things that grant criminals freedom. Secure cryptography represents thermodynamically incontrovertible freedom of communication, which is intrinsically antagonistic to control. In the abstract, any organization striving to (in effect) reduce the rights of criminals will produce friction with the rights of citizens in general. But that doesn’t make the organization’s goals incoherent or evil, it means there must be a system of checks and balances. The ideal goal is one of compromise - we want to reduce net criminality, but we want to increase privacy.
We have that compromise because open, end-to-end encryption (and private companies willing to implement it securely) is available to us. But the existence of arms race between parties does not indicate that one party’s overarching goals shouldn’t be supported. One party desires greater control, the other desires greater freedom. Both can coexist despite their competing incentives.
Why are we now debating the privacy of encrypted correspondance from a baseline of no privacy for unencrypted correspondance?
What says we will not continue to accept more and more, as long as it is only a small step from status quo?
The Overton Window [1] says this is exactly what will happen.
There's a great video [2] about how this applies to Trump (which is where I first heard about it) and gives a good example of what "shifting the Overton Window" looks like.
The problem is that digital paper isn't paper, and while you can be charged with a felony for bypassing a computer's access controls, the law doesn't respect those controls at all. Your electronic documents have to be in your home or in your direct control to be protected.
Which is funny, because paper correspondance does not have to be in your home or in your direct control to be protected.
The Fourth Amendment says the same thing. It has been under relentless attack from the Supreme Court, but one senses a change in the weather...
Would you consent to having a microphone embedded in your driver's license that the FBI could "only turn on if they really needed it"?
When the people with power get to define the meaning of the constraints on their power, their power is without constraints. It disgusts me when companies and individuals are press ganged into being enforcement arms of the government. In my opinion, it takes a certain blindness to history or a level of sociopathy to be fine with this.
Not the GP, but I didn't read anything in dsacco's post that implies any of these. I understood it as saying that it's possible to understand the technology, and even have a strong pro-encryption and pro-privacy stance, without believing that FBI as an institution is fundamentally corrupt or motivated by malice. There is an inherent tension between the FBI's mission, citizen's rights, and the nature of encryption, and it looks like that tension might never be fully resolved.
> When the people with power get to define the meaning of the constraints on their power, their power is without constraints.
I fully agree, and I'm as convinced as you are of people's inability to restrain themselves once they have unchecked power. "Just trust us" always ends in disaster.
> It disgusts me when companies and individuals are press ganged into being enforcement arms of the government. In my opinion, it takes a certain blindness to history or a level of sociopathy to be fine with this.
This is the part I have trouble with; as I see it, there are more than two ways to characterize one's position on this issue than simply 'for or against', 'principled vs. sellout', or 'clear-eyed vs. blind'.
Yes, thank you. This explains my thinking more succinctly and clearly than I did :)
My opposition to the FBI's stance on this is independent of whether or not the FBI is corrupt or motivated by malice. The FBI, being made up of mortals, is an ever changing organization. Giving a philosopher king autocratic powers is giving that power to the tyrant that comes later. The tension between those with power and those surrendering power is older than the FBI. I agree it will never be resolved.
> This is the part I have trouble with; as I see it, there are more than two ways to characterize one's position on this issue than simply 'for or against', 'principled vs. sellout', or 'clear-eyed vs. blind'.
It's a bit incendiary, I'll give you that. I feel pretty strongly about this and let some of that leak out.
Plus, granting that power actively attracts tyrants and other predators to pursue attaining or usurping that position.
There is no series of checks and balances you can wrap around breaking encryption that doesn't hurt a free society. How am I misunderstanding?
That said, I think if we are to approach the question of the FBI analytically/intellectually we might want to start by asking a few questions.
1. How should we measure the efficacy of the FBI? - Net lives saved / dollar spent? Is it a conflict of interest if we let the FBI self-report lives saved?
2. How do we account for the risks of the agency "going rogue" and not following the rule of law? For example, how can we quantify the risk to civil rights caused by the FBI-King suicide letter [1]?
3. When the FBI presents an argument that encryption is a problem, how can we measure whether it's a trade-off we [the people] want to make [safety vs privacy] unless we're presented with a proposal that articulates what credible threats may be prevented (how many lives saved, program cost)?
4. If the majority of citizens do not consider want to forgo their privacy for additional safety, should the FBI be beholden to respect the will of The People who hire it (via taxes)?
1- https://en.wikipedia.org/wiki/FBI%E2%80%93King_suicide_lette...
If only it were so ...
https://yougov.co.uk/news/2015/01/18/more-surveillance-pleas...
This heavily includes COINTELPRO.
Criminals are still citizens with rights, or else Due Process has no meaning. Striving to reduce the rights of any citizen is not a defensible goal for a US governmental organization. Rights should apply to all, or they're not really rights. The government steps in when rights are violated.
> But that doesn’t make the organization’s goals incoherent or evil, it means there must be a system of checks and balances.
It does make the organization's goals anti-constitutional.
> The ideal goal is one of compromise - we want to reduce net criminality, but we want to increase privacy.
No. No all the way. We don't and can't "reduce net criminality" directly. That drifts into implications of policing pre-crime, for which everybody in law enforcement wants surveillance as a magic bullet. Beyond "just" constitutional concepts, I think a lot of people would classify pre-crime surveillance, engagement, and enforcement as actual full blown Evil.
The penal system of a free and civilized country should police actual wrongdoings; and should foster positive educational, cultural, and environmental shifts away from crime. Not destroy freedoms in the name of "protecting" them (when in reality their goal is increasing internal & external political metrics), as the ghastly hypocritical current systems do.
This isn't some new balance to be discovered. It is a clear limitation of powers to prevent violations of rights that already represents a balance.
https://www.law.cornell.edu/constitution/fourth_amendment
> Amendment IV > > The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
You seem to be arguing against a strawman created by a limitation of our current technology. We don't have a way to give them limited access. Right now, we can give them everything, or we can give them nothing. But they're not asking for everything. So we should find a way to allow truly (technologically) limited access, and to make sure that those limits are tight.
The 4th amendment doesn't really affect any of the original crypto argument, because the search cannot be performed. Cryptography prevents the "this is the way that's acceptable" act from even starting. Note that the amendment simply says that a warrant is allowable in a bounded implementation; it doesn't demand that warrants must be executable.
For instance, if a warrant is issued to search a non-existent building it's just as moot. It doesn't require the building to be created if it's not there.
I'm not saying it's right but it's the way it is right now.
I cannot understand how any thoughtful person can support anything more invasive than hard police work and a warrant... any legal case can be cracked with human tools, because no criminal operation has 100% operational security. The need to spy on the thoughts of innocence is an insane price for any extra crime fighting ability we get on top of this.
Why does the FBI need to decrypt the phone of a spree shooter?
What could they possible learn, after the fact?
What could they possible know that isn't more easily ascertained by other means?
Every thing about every person is known in real time. If the NSA, FBI, whomever could not identify and thwart undesired behavior with existing tools (follow the money, network analysis, profiling, sentiment analysis, follow the bullets, etc, etc)... Well, they'd have to be unforgivably incompetent.
[I believe they do all these obvious things. Which is why we've seen so few terrorist attacks. (If only they cared as much about spree shooters.)]
Further, what enemy of the state is using COTS communication system? You'd have to be an incredibly stupid drug dealer, human trafficker, money launderer indeed to conduct business via iPhones.
So if the panopticon doesn't and can't help defeat the bad guys, what's the point? Does the government really need to eavesdrop on the selfie nudes my teenagers are sending their friends?
The protagonists have a limited opportunity to go back in time and attempt to thwart the crime, prevent a catastrophe. Paradoxes! Unintended consequences! Regrets!
Now all we need is a working time machine.
I think (some of) what the FBI is asking for lately is actually not that unreasonable -- assuming we could do it right. Chris Wray, like Comey before him, is claiming that they only need a way to get into a few selected devices in "exceptional" circumstances for criminal investigations. Whenever the FBI/DOJ guys argue this point, they also make sure to say nice things about the value of encryption for protecting the public.
Do they really believe the nice things they say? I have no idea, but for now I'm willing to take them at their word for the sake of the debate.
Do they really want only a limited ability to access encrypted data? Again, I don't know.
But suppose we could construct a truly limited mechanism that would give them the ability to recover only a small amount of encrypted data. Then we could call their bluff. If they still want more, they'd have to make the case to the public that they should have the all-seeing power that our community claims they're trying to get.
We have some early work along these lines. I gave a talk about it at Enigma last week. https://www.usenix.org/conference/enigma2018/presentation/wr...
Hahahahahahahahahahahahaha.
Oh wait you're serious.
Why is this not possible? How could we improve the situation? What are the risks?
Suppose some magical system like this was possible "breakable encryption, but only in the presence of a warrant". What are the arguments against this?
How is that a good thing? Please explain.
I think the problem I see is in there somewhere. Did I state it poorly? How could I state it better?
And voting? You are assuming democracy. Also you're forgetting about the tyranny of the majority. If you aren't even going to read what I'm saying, let's just stop here.
It wasn't the default state. Past tense. You're taking a very 1980's view. The world has moved on. Sure, there are some types of data that are not yet protected, but that's a deficiency which should be corrected with time.
>Why is access to encrypted data magically different
Nothing magic about it, but it's different for a couple of reasons.
First, because a smartphone is more like an extension of your brain than it is like a file cabinet.
Second, because in the old paper world you imagine (or pretend?) we still live in, the entities interested in accessing people's private data didn't have the internet, so they would have to by necessity go to one house at a time to get written records. Now, they do have the internet, and they can hoover up everything. And they do. "They" meaning not necessarily good guys. Sometimes there are rogue cops, or haven't you heard? Not to mention black hat hackers.
So, because of this extraordinary change in how data can be accessed in bulk, and the personal nature of devices, private data needs better protection. Not magic. Just different times, with different snooping tools, different data, and different devices. So much has changed, you might as well ask what hasn't changed.
So that's it: there's actually no way to allow the FBI to decrypt an iPhones without also assuming hackers will (perhaps after a delay before a leak/weakness is discovered), you only get to choose "hackable" or "not hackable", there's no "hackable only by the honorable American government"
Also, it's already very hard to make things "not hackable" without deliberately introducing a certain way to hack it.
There might be some subset of things that fit this. Maybe a call record? But would the public be cool with the Russian Mafia definitely being able to get their GPS location and text message contents? Saved passwords? All your emails from the last decade? That's how I see the tradeoff and risk. There is little that the FBI would be interested in that criminals wouldn't be able to make a buck off of.
You may foolishly think that all law enforcement is perfect... it's hard to state what I think of this level of naiveté and stay within HN rules of polite commenting.
My eyes glazed over. Quantum computing isn't a fantasy realm, and non-quantum processors are still improving.
"And so the public policy debate around encryption has been framed as a binary choice between two absolutist positions: either we allow law enforcement no access at all to encrypted data, or we must effectively give them complete, unrestricted access to all our communications"
Most people support giving some level of data access to law enforcement, but the problem is that there's no way to restrict it to just law enforcement. As soon as we give one person or group access to the data, then we've effectively given everyone access to that data.
Perhaps there was more in the presentation, but this is the only idea I see in the slides:
"Idea: Make brute force key recovery possible but very expensive"
Again, that assumes governments that actually follow rule of law, but any criminal is going to use stolen credit cards to rent for servers in the cloud (or a hacked bot farm) and crack that encryption at no cost to themselves.
Yeah sorry, the TED-like format at Enigma makes the slides by themselves fairly useless.
OTOH, it also lends itself somewhat easily to posting the talk on Twitter, with text attached to each slide. So I did that. https://twitter.com/hackermath/status/956617943768481792
> I have never met anyone who understands what cryptography is, and supports the FBI.
Your reply:
> I think (some of) what the FBI is asking for lately is actually not that unreasonable -- assuming we could do it right. ... suppose we could construct a truly limited mechanism that would give them the ability to recover only a small amount of encrypted data.
One precludes the other...
We can't.
This part isn't actually that hard. Suppose your computation costs $1M now, and Moore's Law continues doubling computation per watt every 18 months for the foreseeable future.
Then in 15 years, the same computation will cost 1/1024 as much as it does today. So you're paying about $1000 per message for 15-year-old data.
In 30 years, you'll be paying about $1 per message for 30-year-old data.
Is that good enough? It totally depends. For most messages, it's almost certainly fine, because the value of the message decays over time. For other messages that hold their value, you need to set the initial cost higher. The formula above shows how you could that to achieve a certain cost at a time a certain number of years in the future.
As to the rest of your comment - this is not how we do science (or engineering). If we cried and gave up every time we encountered a hard problem, we'd still be living in caves, hitting each other with rocks.
Yes and no. Can we predict it exactly? Of course not. But we can estimate the rough order of magnitude with high confidence. It's not hard to find charts showing transistor density over time, and Moore's Law holds up pretty well since the 1970s.
If anything, the two big changes on the horizon are (1) quantum computers and (2) the end of Moore's Law. (1) is really hard to predict, and it will make all our current techniques vulnerable anyway. When (2) finally happens, it will only make future predictions easier, not harder.
> Look at the cost curve of Bitcoin mining.
Sure. Mining was expensive, so people put in a lot of work to make it more efficient. Now it's more efficient, but the easy optimizations are gone. ASIC miners are something like 20000x more efficient than recent CPUs. Do you really think there's another 10000x hiding in there? 1000x? 100x?
For comparison, AsicBoost was (is?) regarded this huge big deal, and it only yields about 37% improvement in mining efficiency.
> Show me a multi-decades track record ... when cryptographers designing secure systems don't have such a track record.
I know this is not quite what you asked for, but you don't have to look very far to find an encryption primitive that has "stood the test of time" cryptanalytically. It's called DES, and it's older than most people posting here. The only reason we don't use it now is because it uses tiny little keys that can be efficiently brute-forced.
https://en.wikipedia.org/wiki/Data_Encryption_Standard
Its replacement, AES, is now 20 years old and is holding up comparably well.
That's quite insulting.
Personally, I'm getting a bit tired of hearing "lol nerd harder! It's impossible!" from people who can't even spell IND-CPA. (Not saying that you are one of those. Just that there are a lot of them around.)
If it's really impossible, then somebody needs to show up with a proof of impossibility.
If it's a matter of having the computing resources to crack a key, then people's computers are too easily compromised to act as bots to solve any such problem. Our computing infrastructure is simply too vulnerable. To avoid this scenario, you'd have to secure every operating system in the world in a way that they could not be compromised, even in principle. That's as close to a proof as should be needed, unless there's a compelling counterargument to suspect some assumption is false. I have yet to hear such an argument.
2. Dual EC isn't protecting anything of value, and hasn't in about 15 years. If your reply is meant to be pedantic about my phrasing, notice that the context is about encryption that is actually in use.
My primary concern and others’ was that strong crypto is already out there and can’t ever be taken away. I understand that you’re choosing to hand-wave over this for the sake of bringing a novel idea to the table, but I’d say it’s a fundamental flaw that can only be addressed by not only outlawing strong crypto in every country, but also finding a way to prevent criminals from implementing and using algorithms that have been known for a while now. That seems, to say the least, quite hard.
We're trying to get a productive discussion started, so hopefully we can reduce the risk of ever getting stuck with something truly horrible like mandated backdoors or key escrow.
Re: strong crypto can't be taken away - That's very true. I guess it depends on what threat model Wray is hoping to go after.
At least until a few years ago, the terrorists weren't even using encryption -- they were posting publicly about their upcoming attacks on Facebook! There was this awkward period of a couple of years where, after every attack, the authorities would claim there was encryption preventing them from stopping the attack. Then some days later, we came to find out that the attacker was already known to them and had been communicating in the clear!
So I think if Signal, WhatsApp, Telegram, ..., all moved to some very-very-expensive-but-breakable model, that would cover most of the guys doing knife and gun attacks, truck bombs, etc. in the real world.
Doubtful. There are enough privacy obsessed computer scientists that oprn source, secure alternatives would soon crop up. Then you're criminalizing perfectly legal behaviour (programming) just because it indirectly might help some criminals.
Most people are going to use whatever is easiest and/or most popular. The same forces that make it hard to get all your friends onto Signal would also make it hard for violent people to use something new.
https://en.wikipedia.org/wiki/Nudge_%28book%29
(Not that I think the Signal team would ever go for any kind of weakened security, unless it was an absolutely final last resort.)
Because if these measures were taken, it would become common knowledge, and criminals would just switch to what's safer for their coordination. It may cast suspicion on anyone using these services, but that's not really enough.
Why should the police only be able to search a phone for a terrorism investigation? If I or someone who I cared about was murdered, raped, burgled, etc, I would resent being a second class victim, unable to get justice.
Your approach is interesting. Some things on my phone are my personal papers and effects. Other things are just metadata or other incidental information. There's room for grey.
The hostname tells you when someone's visiting a rape counselling forum or a STI website or a whistleblowing site. It tells you what their political perspective is, their media landscape.
That's data the FBI can already get.
Do you believe that this is actually possible? How? I ask because this being doable is crux of your argument, and every proposal I have seen falls laughably short.
If you had asked me if oblivious RAM were possible, I'd have said no until I read papers on ORAM.
I think we could do a lot more than we are now.
These arguments were all hashed out in the 1990's CALEA discussions. Assertions were made to "Trust Us", only limited use of the automated phone tapping requirements are envisioned.
A few years later the CALEA technical requirements for tapping capacity were published.
If I recall correctly (these are old bits), the capacity for the number of concurrent taps the FBI required for Manhattan was approximately the number of simultaneous off-hook phone lines expected for that size population. In other words, "capture it all".
That's how "limited use" tends to go.
We need strong technical limitations, on par with the strength of the crypto we use today.
Widespread cracking of 10 year old encryption would be a security disaster, which is why cryptographers think in terms of astronomical numbers, not earthly scales.
Lastly, why, given their track record, are you willing to take US law enforcement at their word? Do they deserve that consideration? Like any potentially deadly tool, law enforcement has to be approached with caution.
In practice, I'd like to see it require judicial oversight to release the funds.
The problem is that law enforcement, spooks, and the judicial system are all on the same side and see themselves that way. You can want a system of due process, but you won't get it.
Fool me once...
There are however not people who are correct on both sides.
Hayden is absolutely a reasonable person, but:
1. He agrees with me on this issue. 2. He makes a pretty strong argument that people who disagree with him (and by extension me) are being unreasonable.
Hayden does does not agree with you on this issue.
That doesn't mean I think the FBI is on the right side of every (or even most) crypto debates. But I understand where they're coming from and foresee debates in the future where they'll be on the right side.
The points of control are pretty easy to find in a context where the Internet is run by a dozen large companies all headquartered in the United States.
Gun control is far easier than controlling AES.
That's nonsense, of course. They'll continue to catch the dumb ones the way they always have: when the criminal screws up and a cop whose shift is still young just happens to be around. They'll continue to catch the smart criminals only very rarely, when someone with enough clout gets pissed off enough. They'll continue to "catch" innocents all day every day, only now they'll have more circumstantial "evidence" of the "this guy googled TVs last month; he was obviously trying to decide which TVs to steal" variety. This is why the Founders wrote the Fourth Amendment.
The phrase "horrifying crimes" makes me think of something violent. Evidence in violent crimes tends to be physical rather than mobile-phone-based.
Of course, you've also already admitted [0] that none of this is about catching criminals.
Perhaps the notion that governments and their professional law enforcers are entitled to pry under certain conditions that tyrants can redefine at will, will have to give.
Not just talking about the FBI here. The issue is larger than just one country. There are plenty of tyrants out there who should not be given the tools the FBI wants.
The US already had crypto restrictions for years. Other nations didn't. It meant the US couldn't compete in technical markets that make use of encryption, which today is everything. Even so, crypto was still readily available. I wouldn't bet on the state.
I think what the FBI wants is for the default mode of encryption in commercial phones to be subject to court orders. I don't think that's viable either, though I understand why they want it.
You can sum my take on this up as "something's got to give at some point, and it probably won't be the state; also, don't be smug about this, because it's complicated".
The idea that nobody who understands encryption sympathizes with the FBI is silly. That might be moving the goalposts from the original argument --- nobody understands crypto and supports the FBI --- but I'm not sure people have a clear idea of what the FBI is asking for (vs. what the FBI's ambit claim is).
Later:
I misread the previous comment; I get the argument. I don't think the failure of export controls is a good indication of the capabilities of the state; in a sense, they served their purpose well, by ensuring that commercial products were sold in a default configuration that offered trivially breakable crypto.
Did they? I seem to recall that it was easy for international users to illegally download the "secure" 128-bit version of Netscape, and that most people did. I could be misremembering, though.
If we're talking about some other measure, I addressed some of those here: https://news.ycombinator.com/item?id=16236105
> If iMessage, WhatsApp, and SMS used escrowed encryption, they'd be in some way fundamentally insecure…You might respond by installing Signal (I sure would).
I'm not sure how lawmakers could meaningfully target iMessage and WhatsApp and not Signal with legislation.
Edit: Oh, I see you mentioned default apps shipped with devices. Seems like a nightmare to word that law so that it targets iMessage and WhatsApp, but not, say, HTTPS. (Besides, does WhatsApp even ship with iOS?) I guess it could work in theory, but it seems like a bad idea to me.
Anyone who thinks that a solution to this might be possible should be prepared to give a good answer the following question:
How does your system protect the rights of people subject to these searches in cases where law enforcement is evil?
Hint: it doesn't. And that's not a mere trivial inconvenience. It's a fatal flaw that can corrupt economies, bring down governments, wreak havoc on lives, destroy cultures, corrode societies, and crush freedom.
There's a reason Thomas Jefferson said "the price of freedom is eternal vigilance." I don't want to live in a place like today's Venezuela, Syria, China, North Korea... we should value our rights and our freedoms.
'Eternal vigilance' in the face of a significant portion of population hoping to forcibly enact sharia law on the rest of the likely takes the form of a ideologically moderate strongman...
An inconvenient fact that USians like to avoid discussing in order to continue simplemindedly branding people as 'evil'.. .. But only if we just fund more rebels, they will certainly magically embrace 1700's style western free market capitalism because the west is great!
And especially: when law enforcement becomes evil or goes rogue. For example, in 1936 in the Netherlands a census had established a list of all people - including their religious affiliation. When the Nazis marched in a couple years later, they had a perfectly validated source of Jews to deport (per https://de.wikipedia.org/wiki/Judenkartei#Niederlande).
While I do not believe that data about religion will be used as a round-them-up-and-kill-them list ever again, there are other things which we allow various forms of law enforcements or secret services to access or to do which may be OK under our current governments but may very well be used against us in the future. There's a reason why undocumented people have been afraid to register or interact with the government - what Trump and his cronies did basically confirmed all their decade-long suspicions.
This seems to go against centuries of crusade and genocide, but we can always try our best :)
I'm German. I seriously hope for this world that no one will ever again dare to repeat the atrocities that my ancestors have committed. But then, I am afraid, the Holocaust and the two World Wars have drifted so far out of living history that some may at least be tempted to try the latter one again.
If you look a bit outside a euro-centric view of things, you can see this happening today in the Middle East. Just because it isn’t white folks killing Jews doesn’t mean it doesn’t count.
The article is just a rewording of the letter; even the background information is just the Senator's first few paragraphs.
I suspect more than a few of us in ostrich country are considering joining you. It gets old, living where most voters can't be bothered to learn the issues before voting. Or after.
Come check it out, I'd be happy to buy you a beer.
It's an absolutely ridiculous notion that everyone in the Valley is pro-privacy. It's the exact opposite. Many of the security higher-ups in the Valley are complicit and working very closely with law enforcement to figure out a solution.
These companies are trying to figure out how to balance risk; the risk of providing a secret way to open up someone's phone to the government while keeping it hidden from everyone and the PR fallout of knowingly providing backdoors to supposedly secure personal electronic devices.
It's got nothing to do with some high-and-mighty goal that every person is entitled to privacy(of course the constitution would disagree but that's irrelevant).
This is a hilarious facade. If they need access to the phone data, they will get it.
On top of all that, the San Bernardino case illustrated that there is a market for private security companies to circumvent most security protections anyway.
You're trying to use logic and reason as they apply to the government. The dirty secret is: they don't. Ever.
They were banned because if a child swallows two of them, then they'll pull toward each other, possibly ripping a hole in the intestine.
That said, you can get spherical rare-earth magnets here:
https://www.kjmagnetics.com/products.asp?cat=12
...though a set of such won't be cheap, depending on the size of the magnets wanted.
Only problem -- if a little kid or animal swallows at least 2 of them, then they can pinch some intestines together inside you and be stuck there and kill you.
This just happened with foreign solar tariffs.
The other 96% of the world's population will know that if they want a secure product don't buy from the US.
I was rather hoping our PM had quietly dropped that nonsense a while back but it seems not. sigh
Yeah, I'm going to say we don't even need the list.
Sometimes it doesn't pan out, but such is the nature of criminal investigations.
I'm working to try and help get rid of Ted Cruz, we need good people running the company - we need more like Wyden - asking these kinds of questions!
Thoughts like these always remind me of this[0]:
>On two occasions I have been asked,'Pray, Mr. Babbage, if you put into the machine wrong figures, will the right answers come out?' I am not able rightly to apprehend the kind of confusion of ideas that could provoke such a question.
[0] I know that wasn't a direct quote from Mr. Wray, but it is in keeping with his thoughts.
The idea goes that about the same time someone is issued a social security number they are also issued a cryptographic key pair. The cool thing is that your key pair can establish identity and in case your private key is compromised a new one could be issued easily. The government would have to maintain copies of everyone's private keys.
The only way this would actually work in practice is if a number of new rights were established and a number of existing rights were updated. I don't want to enumerate what we came up with in discussions, but they are numerous.
The only real benefit to all of this is that encryption would have a backdoor which is established before any encrypted communication actually takes place so the protocols could be made as secure as possible. This also means that the government would have to establish a monopoly on something that we can do with a single openssl command.
1. That's a disaster waiting to happen. Lots of actors are targeting governments, not just hackers and criminals (other governments and people from inside the gov itself).
2. That doesn't stop terrorists from using secure encryption.
What you are proposing gives government unlimited access to innocent citizens data while it does nothing about access to malicious parties.
Sorry but this proposal makes no sense! At least the backdoor is a wolf in disguise for government intervention in citizens everyday life.
To be honest, I don't really know why I even posted it besides the fact that it's something me and my friends have been discussing on and off for about a year now because it keeps coming up in the news.
The "bad guy" problem is an inherent problem and while me and my friends have come up with a few novel work-arounds none of them solves the problem completely.
Another issue is that multi-layer encryption could disrupt the government's ability to execute a warrant. If this BAD IDEA were implemented then multi-layer encryption would need to be made illegal and that starts us down a very dangerous path.
The only thing I think is a good idea is using a crypto key pair as a replacement for ssn but only if it's not really used for encryption.
We need a way to let law enforcement do their job but also balance that with citizens rights. Backdooring encryption is not the answer, but perhaps there can be some other answer. The alternative is mass surveilance like we have today.
Something along the lines of a wiretap (this would technically be a state-sponsored MITM attack) for electronic communication which would only be possible with a warrant, but then we would probably end up with a secret court (a la FISA) issuing these warrants.
The only point I would like to make is that we need to be open to discussing possible solutions otherwise we might not like what the whistleblowers tell us.
Four members of the House have computer science degrees (at least they were House members back in 2016):
Democrat Ted Lieu of California and Republicans Will Hurd of Texas; Bill Johnson of Ohio; and Steve Scalise of Louisiana.
Example, first of many search engine hits: https://www.google.com/amp/s/techcrunch.com/2016/04/28/a-wha...
Ron Wyden is all over the issues I care about, to the point where on the rare occasions we disagree I’m willing to believe he’s right because he does policy for a living and I’m just a guy with strong opinions (which is precisely why representational democracies were invented).
The other four? I never hear them championing critical tech policy issues. Yes Ron is in the Senate and they are in the House, but Ron was in my feeds constantly long before he ran for the Senate (and I don’t even live in his district). Savvy doesn’t just mean a degree in my book. Savvy means able to cut through the noise and get to what matters.
And since we are clearly in agreement over the importance of this stuff and just quibbling around the margins, I’ll mention adding Suzan DelBene (D) WA to your list of reps to follow if she’s not there already. I’m not sure what her degree is in but she’s a former Microsoft VP who is incredibly smart and deeply knowledgeable about tech issues (though I haven’t seen that emerge yet as a top legislative focus area for her the way it has for Ron Wyden).
[Emphasis is mine.]