Justice Dept. Revives Push to Mandate a Way to Unlock Phones
nytimes.com
nytimes.com
Comey was the key advocate in this during the Obama years. He spoke for years advocating backdoors... even after Trump took office. Here's an article from March 2017 when he advocated an international backdoor[0]. Here's one in May 2017 when he backed Feinsteins decrypt bill[1].
It receded because Comey was pushed out. And it took a while for Wray to come in and make it an issue again.
It's worth remembering that this is not some faceless government action. They're just people who are lobbying for the change. Remember to contact your representatives regularly to advocate your position on these issues.
0. https://www.techdirt.com/articles/20170327/10121437009/james...
1. https://techcrunch.com/2017/05/03/fbi-director-comey-backs-n...
>Against that backdrop, law enforcement officials have revived talks inside the executive branch over whether to ask Congress to enact legislation mandating the access mechanisms. The Trump White House circulated a memo last month among security and economic agencies outlining ways to think about solving the problem, officials said.
Obama's whitehouse was the reason the FBI never got very far on this issue. Even up until he left, all he could agree to was that it was an issue and solutions should be looked into. Obviously Trump is much more open to passing something on this than Obama was. But note Congress never put a bill on Obama's desk... even the floated Compliance with Court Orders Act of 2016 got little congressional support, and ended up never being introduced.
Constant vigilance, yall
And of course his Trump-appointed successor shares the same opinion.
Why are you making this a partisan issue when it's clearly not.
Mueller certainly was pro-backdoors... but he started out advocating for a backdoor into encrypted communications.. and didn't widen that idea into a backdoor into phones and other devices until his last year in office. Comey picked up where he left off. It's certainly true the FBI and DOJ have produced many people who are pro-backdoors.
This clearly isn't a partisan issue, since there are democrats and republicans that support backdoors.. and democrats and republicans that don't support backdoors. You really do have to pay attention to the names, and support Republicans and Democrats that are against this issue.
In addition if Google and Apple builds some backdoor into their products, any regime of any country which Google and Apple operates in will demand to get the same backdoor. How are they going to not give them that, they won't be able to.
I'm sure the Justice Department, and the FBI does not care about foreign implications of their wishes, but their are parts of the American government that has to. It is deeply naive to believe that something like this will fly on the international stage.
Exactly. So we end up with 1000s of people (many services from many countries) that have authorized access to your phone. This cannot be contained in any way. Not something to look forward to....
The US is a big enough market that they could force this to be built. Other countries will just write similar laws to get the same access to the same backdoors.
Sure...
> Why would we agree to this? The privacy of our citizens is at stake!
> You'll be able to spy on them too!
> Done!
How big a percentage of the electorate would back canceling the next election cycle?
In the US, a president who leaves office before the expiration of their term is replaced by the Vice President (or the next in the line of succession if there is no Vice President). In Germany, a chancellor can only recalled by electing a replacement. If they resign or die, the President gets to make a few decision, and they will usually task the leader of the largest party to find themselves a majority. Only after two or three failures of that process would a President turn to early elections.
I don't understand this. How does privacy/anonymity not protect you from a corrupt government?
There are some systems designed to protect keys and admin access from lower tier admins (for crypto fill, etc), but with those they are generally not archival, just transport security, and there are ways to downgrade or replace keys on request. The judiciary also doesn’t in practice have any real ability to do things to the executive without cooperation of parts of the executive; if we had some insane civil war type situation where a federal judge wanted to enforce an order against the executive, it would be basically impossible to do so without some support of the executive (or an external force, like a state national guard). This isn’t how it should be, but probably was like this within a decade of the constitution’s ratification and has gotten more so with time.
China operates like you describe and people that think like that should just move there. Perhaps we could create a program to swap citizens between countries so people can live with their ideological peers.
But once they know it's you, you're screwed against a corrupt govt.
Trump campaign supported Government demanding Apple to bake in a backdoor in their OS.
How do you think the 2016 election is any sort of last straw?
So the decryption key on your phone (or perhaps a key to the key, same thing AFAICT) would have to be stored by the manufacturer so that it could be accessed by various US government agencies.
If it’s a Chinese company, that means the Chinese government would have access, too.
And if such a law and precedent was set by the US, the likely reaction from other countries would be to enact similar laws.
So, lots of people all over the world will be able decrypt your data, for lots of reasons.
I personally wouldn’t hope for that.
My money is on "until about the next Tuesday after the scheme is first deployed", and then every phone is open to every sufficiently-motivated country's intelligence agencies and law enforcement, and that's the end of business, law-enforcement and possibly even military security for anyone stuck using one of those devices.
Once backdoors are introduced, that is the outcome that will come of this.
Imagine you're a high-minded, fair, and absolutely law-abiding FBI officer charged with solving some white collar crime, like corruption or fraud.
You started some time in the 80s. The usual MO was to get a warrant and search someone's house and office. You'd find 60 to 100 binders full of letters, transaction records, and org charts for this criminal enterprise you're investigation.
Today, you find an iPhone and a smug banker telling you take it. "The new model is coming out anyway." Then, he orders a Vodka Soda from his butler and you slink out, iPhone in hand.
Just to be clear (again): I absolutely do not think that this scenario is reason enough to mandate backdoors. But I am similarly convinced that it happens, probably quite often. And that it would be rather frustrating to deal with.
It will be far easier to convince people if we start acknowledging what they already think to be true, to avoid hyperbole, and not to obscure our real motivation behind some rather ridiculous claims of technical impossibility[0[.
[0[: bitcoin already has 2-of-3 multisig, so 1-of-2 shouldn't really be impossible if anybody, you know, tried
Which they will. All they are asking for is some form of key escrow; which can (and has) been given a reasonable security definition.
The problem is that secure implementations of key escrow are much harder; and (given the amount of use the escrowed key will get), certainly going to be broken in practice.
OS security has limited impact when other subsystems, not in control of the OS, run on the device.
Besides, any selective "break glass" scheme is going to be vulnerable to arguments about the need for urgent access to prevent terror or something.
Either the population has access to strong crypto or it doesn't --- and technological prohibition never actually works. You may be able to make it easy to crack phones used by the naive, but you can't stop determined people writing and running software.
There's basically no way you convince them to use this when more secure alternatives already exist, for free.
I think Apple has the will to fight this and I think a strong 4th amendment case can be made. Freedom of the people must be protected.
We must reform money’s role in our democracy, but basic political balances are intrinsic to the game. In retrospect, privacy advocates may have relied too heavily on the support of a single segment.
It might not be feasible, but a way for citizens to send everyone home easily every 1-2 years if they screw up would be beneficial.
If it's going to happen hopefully Apple can do some jujutsu and get GDPR in the US out of it as part of an omnibus bill [1].
[1] https://www.bloomberg.com/news/articles/2018-03-24/apple-s-t...
If everyone has a self-defeatist "inevitable" attitude on the other hand...
At least this way something of value is gained.
Oh, that's not "legitimate"? I've seen serious proposals for those in the past few years, and not a few actual instances. All invoking the L-word.
What do people mean by "legitimate" then? Mostly, I see it as begging the question, an attempt to redefine and color the argument. Of course their interests are "legitimate" -- whose are not? Does passing a law make something legitimate? What about an unconstitutional law?
History has proven that capabilities like the ones proposed are always abused by power, and that compromised security systems grow more compromised over time.
My head is not in the sand.
I'm personally completely ok with the special devices specific unlock code suggested. It's not universal, and requires the government to go through the company first who at some level at least have a stake in me believing my device is secure.
The insentives seem to work and I still have reasonable security.
Backdoored “security” is in no way reasonable. It’s essentially not security at all.
Sure, let's just have Equifax store this data. They're good at protecting confidential information right? or maybe Facebook?
I think you have an unreasonably low threshold for what qualifies as "reasonable security".