Edit: What I meant by "supports the FBI" is "supports the FBI on this issue". If you understand encryption and support the FBI in a general sense, but think they are wrong on this issue, then you aren't a counterpoint.
Edit: What I meant by "supports the FBI" is "supports the FBI on this issue". If you understand encryption and support the FBI in a general sense, but think they are wrong on this issue, then you aren't a counterpoint.
I understand cryptography and I broadly support the activities of the FBI. You have now “met” such a person.
It’s fully possible to simultaneously support opposing concepts like end-to-end encryption for users and the organizational imperatives of the FBI. A nuanced perspective might consider that citizens and the FBI have separate prerogatives and competing incentives with respect to private encryption, and this is perfectly fine.
A consequence of an organization optimized to reduce crime is its natural zeal for greater control over things that grant criminals freedom. Secure cryptography represents thermodynamically incontrovertible freedom of communication, which is intrinsically antagonistic to control. In the abstract, any organization striving to (in effect) reduce the rights of criminals will produce friction with the rights of citizens in general. But that doesn’t make the organization’s goals incoherent or evil, it means there must be a system of checks and balances. The ideal goal is one of compromise - we want to reduce net criminality, but we want to increase privacy.
We have that compromise because open, end-to-end encryption (and private companies willing to implement it securely) is available to us. But the existence of arms race between parties does not indicate that one party’s overarching goals shouldn’t be supported. One party desires greater control, the other desires greater freedom. Both can coexist despite their competing incentives.
Criminals are still citizens with rights, or else Due Process has no meaning. Striving to reduce the rights of any citizen is not a defensible goal for a US governmental organization. Rights should apply to all, or they're not really rights. The government steps in when rights are violated.
> But that doesn’t make the organization’s goals incoherent or evil, it means there must be a system of checks and balances.
It does make the organization's goals anti-constitutional.
> The ideal goal is one of compromise - we want to reduce net criminality, but we want to increase privacy.
No. No all the way. We don't and can't "reduce net criminality" directly. That drifts into implications of policing pre-crime, for which everybody in law enforcement wants surveillance as a magic bullet. Beyond "just" constitutional concepts, I think a lot of people would classify pre-crime surveillance, engagement, and enforcement as actual full blown Evil.
The penal system of a free and civilized country should police actual wrongdoings; and should foster positive educational, cultural, and environmental shifts away from crime. Not destroy freedoms in the name of "protecting" them (when in reality their goal is increasing internal & external political metrics), as the ghastly hypocritical current systems do.
This isn't some new balance to be discovered. It is a clear limitation of powers to prevent violations of rights that already represents a balance.
https://www.law.cornell.edu/constitution/fourth_amendment
> Amendment IV > > The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
You seem to be arguing against a strawman created by a limitation of our current technology. We don't have a way to give them limited access. Right now, we can give them everything, or we can give them nothing. But they're not asking for everything. So we should find a way to allow truly (technologically) limited access, and to make sure that those limits are tight.
The 4th amendment doesn't really affect any of the original crypto argument, because the search cannot be performed. Cryptography prevents the "this is the way that's acceptable" act from even starting. Note that the amendment simply says that a warrant is allowable in a bounded implementation; it doesn't demand that warrants must be executable.
For instance, if a warrant is issued to search a non-existent building it's just as moot. It doesn't require the building to be created if it's not there.
I'm not saying it's right but it's the way it is right now.
Would you consent to having a microphone embedded in your driver's license that the FBI could "only turn on if they really needed it"?
When the people with power get to define the meaning of the constraints on their power, their power is without constraints. It disgusts me when companies and individuals are press ganged into being enforcement arms of the government. In my opinion, it takes a certain blindness to history or a level of sociopathy to be fine with this.
Not the GP, but I didn't read anything in dsacco's post that implies any of these. I understood it as saying that it's possible to understand the technology, and even have a strong pro-encryption and pro-privacy stance, without believing that FBI as an institution is fundamentally corrupt or motivated by malice. There is an inherent tension between the FBI's mission, citizen's rights, and the nature of encryption, and it looks like that tension might never be fully resolved.
> When the people with power get to define the meaning of the constraints on their power, their power is without constraints.
I fully agree, and I'm as convinced as you are of people's inability to restrain themselves once they have unchecked power. "Just trust us" always ends in disaster.
> It disgusts me when companies and individuals are press ganged into being enforcement arms of the government. In my opinion, it takes a certain blindness to history or a level of sociopathy to be fine with this.
This is the part I have trouble with; as I see it, there are more than two ways to characterize one's position on this issue than simply 'for or against', 'principled vs. sellout', or 'clear-eyed vs. blind'.
My opposition to the FBI's stance on this is independent of whether or not the FBI is corrupt or motivated by malice. The FBI, being made up of mortals, is an ever changing organization. Giving a philosopher king autocratic powers is giving that power to the tyrant that comes later. The tension between those with power and those surrendering power is older than the FBI. I agree it will never be resolved.
> This is the part I have trouble with; as I see it, there are more than two ways to characterize one's position on this issue than simply 'for or against', 'principled vs. sellout', or 'clear-eyed vs. blind'.
It's a bit incendiary, I'll give you that. I feel pretty strongly about this and let some of that leak out.
Plus, granting that power actively attracts tyrants and other predators to pursue attaining or usurping that position.
Yes, thank you. This explains my thinking more succinctly and clearly than I did :)
There is no series of checks and balances you can wrap around breaking encryption that doesn't hurt a free society. How am I misunderstanding?
Why are we now debating the privacy of encrypted correspondance from a baseline of no privacy for unencrypted correspondance?
What says we will not continue to accept more and more, as long as it is only a small step from status quo?
The Overton Window [1] says this is exactly what will happen.
There's a great video [2] about how this applies to Trump (which is where I first heard about it) and gives a good example of what "shifting the Overton Window" looks like.
The problem is that digital paper isn't paper, and while you can be charged with a felony for bypassing a computer's access controls, the law doesn't respect those controls at all. Your electronic documents have to be in your home or in your direct control to be protected.
Which is funny, because paper correspondance does not have to be in your home or in your direct control to be protected.
The Fourth Amendment says the same thing. It has been under relentless attack from the Supreme Court, but one senses a change in the weather...
That said, I think if we are to approach the question of the FBI analytically/intellectually we might want to start by asking a few questions.
1. How should we measure the efficacy of the FBI? - Net lives saved / dollar spent? Is it a conflict of interest if we let the FBI self-report lives saved?
2. How do we account for the risks of the agency "going rogue" and not following the rule of law? For example, how can we quantify the risk to civil rights caused by the FBI-King suicide letter [1]?
3. When the FBI presents an argument that encryption is a problem, how can we measure whether it's a trade-off we [the people] want to make [safety vs privacy] unless we're presented with a proposal that articulates what credible threats may be prevented (how many lives saved, program cost)?
4. If the majority of citizens do not consider want to forgo their privacy for additional safety, should the FBI be beholden to respect the will of The People who hire it (via taxes)?
1- https://en.wikipedia.org/wiki/FBI%E2%80%93King_suicide_lette...
If only it were so ...
https://yougov.co.uk/news/2015/01/18/more-surveillance-pleas...
I cannot understand how any thoughtful person can support anything more invasive than hard police work and a warrant... any legal case can be cracked with human tools, because no criminal operation has 100% operational security. The need to spy on the thoughts of innocence is an insane price for any extra crime fighting ability we get on top of this.
Why does the FBI need to decrypt the phone of a spree shooter?
What could they possible learn, after the fact?
What could they possible know that isn't more easily ascertained by other means?
Every thing about every person is known in real time. If the NSA, FBI, whomever could not identify and thwart undesired behavior with existing tools (follow the money, network analysis, profiling, sentiment analysis, follow the bullets, etc, etc)... Well, they'd have to be unforgivably incompetent.
[I believe they do all these obvious things. Which is why we've seen so few terrorist attacks. (If only they cared as much about spree shooters.)]
Further, what enemy of the state is using COTS communication system? You'd have to be an incredibly stupid drug dealer, human trafficker, money launderer indeed to conduct business via iPhones.
So if the panopticon doesn't and can't help defeat the bad guys, what's the point? Does the government really need to eavesdrop on the selfie nudes my teenagers are sending their friends?
The protagonists have a limited opportunity to go back in time and attempt to thwart the crime, prevent a catastrophe. Paradoxes! Unintended consequences! Regrets!
Now all we need is a working time machine.
This heavily includes COINTELPRO.
I think (some of) what the FBI is asking for lately is actually not that unreasonable -- assuming we could do it right. Chris Wray, like Comey before him, is claiming that they only need a way to get into a few selected devices in "exceptional" circumstances for criminal investigations. Whenever the FBI/DOJ guys argue this point, they also make sure to say nice things about the value of encryption for protecting the public.
Do they really believe the nice things they say? I have no idea, but for now I'm willing to take them at their word for the sake of the debate.
Do they really want only a limited ability to access encrypted data? Again, I don't know.
But suppose we could construct a truly limited mechanism that would give them the ability to recover only a small amount of encrypted data. Then we could call their bluff. If they still want more, they'd have to make the case to the public that they should have the all-seeing power that our community claims they're trying to get.
We have some early work along these lines. I gave a talk about it at Enigma last week. https://www.usenix.org/conference/enigma2018/presentation/wr...
"And so the public policy debate around encryption has been framed as a binary choice between two absolutist positions: either we allow law enforcement no access at all to encrypted data, or we must effectively give them complete, unrestricted access to all our communications"
Most people support giving some level of data access to law enforcement, but the problem is that there's no way to restrict it to just law enforcement. As soon as we give one person or group access to the data, then we've effectively given everyone access to that data.
Perhaps there was more in the presentation, but this is the only idea I see in the slides:
"Idea: Make brute force key recovery possible but very expensive"
Again, that assumes governments that actually follow rule of law, but any criminal is going to use stolen credit cards to rent for servers in the cloud (or a hacked bot farm) and crack that encryption at no cost to themselves.
Yeah sorry, the TED-like format at Enigma makes the slides by themselves fairly useless.
OTOH, it also lends itself somewhat easily to posting the talk on Twitter, with text attached to each slide. So I did that. https://twitter.com/hackermath/status/956617943768481792
My primary concern and others’ was that strong crypto is already out there and can’t ever be taken away. I understand that you’re choosing to hand-wave over this for the sake of bringing a novel idea to the table, but I’d say it’s a fundamental flaw that can only be addressed by not only outlawing strong crypto in every country, but also finding a way to prevent criminals from implementing and using algorithms that have been known for a while now. That seems, to say the least, quite hard.
We're trying to get a productive discussion started, so hopefully we can reduce the risk of ever getting stuck with something truly horrible like mandated backdoors or key escrow.
Re: strong crypto can't be taken away - That's very true. I guess it depends on what threat model Wray is hoping to go after.
At least until a few years ago, the terrorists weren't even using encryption -- they were posting publicly about their upcoming attacks on Facebook! There was this awkward period of a couple of years where, after every attack, the authorities would claim there was encryption preventing them from stopping the attack. Then some days later, we came to find out that the attacker was already known to them and had been communicating in the clear!
So I think if Signal, WhatsApp, Telegram, ..., all moved to some very-very-expensive-but-breakable model, that would cover most of the guys doing knife and gun attacks, truck bombs, etc. in the real world.
Doubtful. There are enough privacy obsessed computer scientists that oprn source, secure alternatives would soon crop up. Then you're criminalizing perfectly legal behaviour (programming) just because it indirectly might help some criminals.
Most people are going to use whatever is easiest and/or most popular. The same forces that make it hard to get all your friends onto Signal would also make it hard for violent people to use something new.
https://en.wikipedia.org/wiki/Nudge_%28book%29
(Not that I think the Signal team would ever go for any kind of weakened security, unless it was an absolutely final last resort.)
Because if these measures were taken, it would become common knowledge, and criminals would just switch to what's safer for their coordination. It may cast suspicion on anyone using these services, but that's not really enough.
These arguments were all hashed out in the 1990's CALEA discussions. Assertions were made to "Trust Us", only limited use of the automated phone tapping requirements are envisioned.
A few years later the CALEA technical requirements for tapping capacity were published.
If I recall correctly (these are old bits), the capacity for the number of concurrent taps the FBI required for Manhattan was approximately the number of simultaneous off-hook phone lines expected for that size population. In other words, "capture it all".
That's how "limited use" tends to go.
We need strong technical limitations, on par with the strength of the crypto we use today.
Widespread cracking of 10 year old encryption would be a security disaster, which is why cryptographers think in terms of astronomical numbers, not earthly scales.
Lastly, why, given their track record, are you willing to take US law enforcement at their word? Do they deserve that consideration? Like any potentially deadly tool, law enforcement has to be approached with caution.
Do you believe that this is actually possible? How? I ask because this being doable is crux of your argument, and every proposal I have seen falls laughably short.
If you had asked me if oblivious RAM were possible, I'd have said no until I read papers on ORAM.
I think we could do a lot more than we are now.
> I have never met anyone who understands what cryptography is, and supports the FBI.
Your reply:
> I think (some of) what the FBI is asking for lately is actually not that unreasonable -- assuming we could do it right. ... suppose we could construct a truly limited mechanism that would give them the ability to recover only a small amount of encrypted data.
One precludes the other...
That's quite insulting.
Personally, I'm getting a bit tired of hearing "lol nerd harder! It's impossible!" from people who can't even spell IND-CPA. (Not saying that you are one of those. Just that there are a lot of them around.)
If it's really impossible, then somebody needs to show up with a proof of impossibility.
If it's a matter of having the computing resources to crack a key, then people's computers are too easily compromised to act as bots to solve any such problem. Our computing infrastructure is simply too vulnerable. To avoid this scenario, you'd have to secure every operating system in the world in a way that they could not be compromised, even in principle. That's as close to a proof as should be needed, unless there's a compelling counterargument to suspect some assumption is false. I have yet to hear such an argument.
2. Dual EC isn't protecting anything of value, and hasn't in about 15 years. If your reply is meant to be pedantic about my phrasing, notice that the context is about encryption that is actually in use.
We can't.
This part isn't actually that hard. Suppose your computation costs $1M now, and Moore's Law continues doubling computation per watt every 18 months for the foreseeable future.
Then in 15 years, the same computation will cost 1/1024 as much as it does today. So you're paying about $1000 per message for 15-year-old data.
In 30 years, you'll be paying about $1 per message for 30-year-old data.
Is that good enough? It totally depends. For most messages, it's almost certainly fine, because the value of the message decays over time. For other messages that hold their value, you need to set the initial cost higher. The formula above shows how you could that to achieve a certain cost at a time a certain number of years in the future.
As to the rest of your comment - this is not how we do science (or engineering). If we cried and gave up every time we encountered a hard problem, we'd still be living in caves, hitting each other with rocks.
Yes and no. Can we predict it exactly? Of course not. But we can estimate the rough order of magnitude with high confidence. It's not hard to find charts showing transistor density over time, and Moore's Law holds up pretty well since the 1970s.
If anything, the two big changes on the horizon are (1) quantum computers and (2) the end of Moore's Law. (1) is really hard to predict, and it will make all our current techniques vulnerable anyway. When (2) finally happens, it will only make future predictions easier, not harder.
> Look at the cost curve of Bitcoin mining.
Sure. Mining was expensive, so people put in a lot of work to make it more efficient. Now it's more efficient, but the easy optimizations are gone. ASIC miners are something like 20000x more efficient than recent CPUs. Do you really think there's another 10000x hiding in there? 1000x? 100x?
For comparison, AsicBoost was (is?) regarded this huge big deal, and it only yields about 37% improvement in mining efficiency.
> Show me a multi-decades track record ... when cryptographers designing secure systems don't have such a track record.
I know this is not quite what you asked for, but you don't have to look very far to find an encryption primitive that has "stood the test of time" cryptanalytically. It's called DES, and it's older than most people posting here. The only reason we don't use it now is because it uses tiny little keys that can be efficiently brute-forced.
https://en.wikipedia.org/wiki/Data_Encryption_Standard
Its replacement, AES, is now 20 years old and is holding up comparably well.
The problem is that law enforcement, spooks, and the judicial system are all on the same side and see themselves that way. You can want a system of due process, but you won't get it.
Fool me once...
Why should the police only be able to search a phone for a terrorism investigation? If I or someone who I cared about was murdered, raped, burgled, etc, I would resent being a second class victim, unable to get justice.
Your approach is interesting. Some things on my phone are my personal papers and effects. Other things are just metadata or other incidental information. There's room for grey.
The hostname tells you when someone's visiting a rape counselling forum or a STI website or a whistleblowing site. It tells you what their political perspective is, their media landscape.
That's data the FBI can already get.
In practice, I'd like to see it require judicial oversight to release the funds.
Hahahahahahahahahahahahaha.
Oh wait you're serious.
Why is this not possible? How could we improve the situation? What are the risks?
So that's it: there's actually no way to allow the FBI to decrypt an iPhones without also assuming hackers will (perhaps after a delay before a leak/weakness is discovered), you only get to choose "hackable" or "not hackable", there's no "hackable only by the honorable American government"
Also, it's already very hard to make things "not hackable" without deliberately introducing a certain way to hack it.
There might be some subset of things that fit this. Maybe a call record? But would the public be cool with the Russian Mafia definitely being able to get their GPS location and text message contents? Saved passwords? All your emails from the last decade? That's how I see the tradeoff and risk. There is little that the FBI would be interested in that criminals wouldn't be able to make a buck off of.
Suppose some magical system like this was possible "breakable encryption, but only in the presence of a warrant". What are the arguments against this?
How is that a good thing? Please explain.
I think the problem I see is in there somewhere. Did I state it poorly? How could I state it better?
And voting? You are assuming democracy. Also you're forgetting about the tyranny of the majority. If you aren't even going to read what I'm saying, let's just stop here.
It wasn't the default state. Past tense. You're taking a very 1980's view. The world has moved on. Sure, there are some types of data that are not yet protected, but that's a deficiency which should be corrected with time.
>Why is access to encrypted data magically different
Nothing magic about it, but it's different for a couple of reasons.
First, because a smartphone is more like an extension of your brain than it is like a file cabinet.
Second, because in the old paper world you imagine (or pretend?) we still live in, the entities interested in accessing people's private data didn't have the internet, so they would have to by necessity go to one house at a time to get written records. Now, they do have the internet, and they can hoover up everything. And they do. "They" meaning not necessarily good guys. Sometimes there are rogue cops, or haven't you heard? Not to mention black hat hackers.
So, because of this extraordinary change in how data can be accessed in bulk, and the personal nature of devices, private data needs better protection. Not magic. Just different times, with different snooping tools, different data, and different devices. So much has changed, you might as well ask what hasn't changed.
You may foolishly think that all law enforcement is perfect... it's hard to state what I think of this level of naiveté and stay within HN rules of polite commenting.
My eyes glazed over. Quantum computing isn't a fantasy realm, and non-quantum processors are still improving.
That doesn't mean I think the FBI is on the right side of every (or even most) crypto debates. But I understand where they're coming from and foresee debates in the future where they'll be on the right side.
The points of control are pretty easy to find in a context where the Internet is run by a dozen large companies all headquartered in the United States.
Gun control is far easier than controlling AES.
That's nonsense, of course. They'll continue to catch the dumb ones the way they always have: when the criminal screws up and a cop whose shift is still young just happens to be around. They'll continue to catch the smart criminals only very rarely, when someone with enough clout gets pissed off enough. They'll continue to "catch" innocents all day every day, only now they'll have more circumstantial "evidence" of the "this guy googled TVs last month; he was obviously trying to decide which TVs to steal" variety. This is why the Founders wrote the Fourth Amendment.
The phrase "horrifying crimes" makes me think of something violent. Evidence in violent crimes tends to be physical rather than mobile-phone-based.
Of course, you've also already admitted [0] that none of this is about catching criminals.
The US already had crypto restrictions for years. Other nations didn't. It meant the US couldn't compete in technical markets that make use of encryption, which today is everything. Even so, crypto was still readily available. I wouldn't bet on the state.
If we're talking about some other measure, I addressed some of those here: https://news.ycombinator.com/item?id=16236105
I think what the FBI wants is for the default mode of encryption in commercial phones to be subject to court orders. I don't think that's viable either, though I understand why they want it.
You can sum my take on this up as "something's got to give at some point, and it probably won't be the state; also, don't be smug about this, because it's complicated".
The idea that nobody who understands encryption sympathizes with the FBI is silly. That might be moving the goalposts from the original argument --- nobody understands crypto and supports the FBI --- but I'm not sure people have a clear idea of what the FBI is asking for (vs. what the FBI's ambit claim is).
Later:
I misread the previous comment; I get the argument. I don't think the failure of export controls is a good indication of the capabilities of the state; in a sense, they served their purpose well, by ensuring that commercial products were sold in a default configuration that offered trivially breakable crypto.
Did they? I seem to recall that it was easy for international users to illegally download the "secure" 128-bit version of Netscape, and that most people did. I could be misremembering, though.
> If iMessage, WhatsApp, and SMS used escrowed encryption, they'd be in some way fundamentally insecure…You might respond by installing Signal (I sure would).
I'm not sure how lawmakers could meaningfully target iMessage and WhatsApp and not Signal with legislation.
Edit: Oh, I see you mentioned default apps shipped with devices. Seems like a nightmare to word that law so that it targets iMessage and WhatsApp, but not, say, HTTPS. (Besides, does WhatsApp even ship with iOS?) I guess it could work in theory, but it seems like a bad idea to me.
Perhaps the notion that governments and their professional law enforcers are entitled to pry under certain conditions that tyrants can redefine at will, will have to give.
Not just talking about the FBI here. The issue is larger than just one country. There are plenty of tyrants out there who should not be given the tools the FBI wants.
Hayden is absolutely a reasonable person, but:
1. He agrees with me on this issue. 2. He makes a pretty strong argument that people who disagree with him (and by extension me) are being unreasonable.
Hayden does does not agree with you on this issue.
There are however not people who are correct on both sides.