The Encryption Debate Isn't About Stopping Terrorists, It's About Solving Crime
lawfareblog.com
lawfareblog.com
It used to be easy for people to make anonymous phone calls from phone booths - try making an anonymous call today.
Strong on-device encryption of data at-rest has the nice effect of making mobile device theft much less attractive.
Strong encryption of data in transit, including auto-deleting messages, can prevent lots of other crime as well, and protects vulnerable people such as victims of domestic violence who may have to show their phone to their abuser at any time.
Imagine that happening before cell phones. The criminals carrying a tracker 24x7.
The Unabomber sent mail bombs for 18 years. The austin bomber gets caught in 3 weeks.
https://www.dallasnews.com/news/crime/2018/03/21/authorities...
They also said that if someone was smart, they would just leave their phone at home, or somewhere else as an alibi and do whatever. Then they would have to go back to the drawing board which they admittedly said they haven't had to do in a long while.
In other words, the guy who plans out a careful alibi tends not to be the guy who needs one. The previous post mentioned the Unabomber, who was a rare example of someone who had excellent planning skills, high intelligence, and excellent impulse control. It took almost two decades to catch him, and only because his brother recognized his writing.
The "little tracking devices" helped them solve a lot more crimes than they ever dreamed of, but they said that it also requires a lot more paperwork, desk work, warrants, etc to do anything now. So even though it's easier, they have to jump through a lot more hoops to get the data.
They also said that that work is 90% of their jobs now. The other 10% is "non-it computer work."
It's a small local sheriff's dept (if that makes any difference).
There is no "debate", or "the issue". There are only those who understand reality and those who refuse to do so.
We could say that we put a man on the sun, but by what measure a 'man' by the time they arrive, and upon what part of the fusion reaction do we land in order to define 'on'?
Excellent, I say, into an echo chamber.
The free ride enjoyed by law enforcers in terms of solving crimes by following the money and listening to unguarded communications may be coming to an end, thanks to cryptography. But end-to-end encryption by default isn't going to do anything but raise the lowest-hanging fruit a bit higher. Stupid criminals will still be easily caught, because they cannot avoid doing stupid things. And no one has perfect op-sec. Everyone makes mistakes, and mistakes lead to convictions. The difference is that police resources will have to be prioritized and targeted to uncover those mistakes, rather than continually picking up cheap finds from a surveillance dragnet.
This is no longer a matter for debate, at least in the US. We already went over this with Clipper Chip, and rehashed it several times. Encryption is protected by the 1st Amendment. Back doors can be used by adversaries in addition to law enforcers. Law enforcers cannot be trusted to use their granted powers responsibly. Indeed, encryption has advanced this far in part because governments cannot be trusted.
Maybe it is, but the actual point of the 1st Amendment seems to me that to be able to express idea, opinions, etc. publicly and without fear of retaliation by the government, which is a much higher grade of freedom IMHO than merely allowing pople to exchange those ideas and opinions in a form that noone else but the recipient can access.
It would somehow feel more appropriate if encryption was protected by (an extension of) the Fourth and/or of the Fifth.
1. Insecure systems: government can get in, but so can hackers.
2. Secure systems: hackers can't get in, but neither can government.
It's a binary choice. Like being pregnant. You are, or you are not. There is no try.
So your choices are:
1. Only the user has their key
2. Someone else has the user's key
If a company, law enforcement, or anybody else has a trove of everyone's keys, that trove will be extremely valuable to hackers, organized crime, domestic and foreign intelligence, etc, and it will be stolen. Whether we'll know it's been stolen is another question.
If we accept that mechanisms in common use, like warrantful search of physical belongings under the Fourth Amendment of the US Constitution, are legitimate and rightful functions of government, then warrantful key disclosure is a logical compromise that protects the individual's privacy, except when the government compels them with good cause to reveal information. Balancing this with protections against self-incrimination is one complication that's currently playing out.
- hardware key storage, iphone/TPM style
- mechanism for the manufacturer to authorise key release from a device
- important 1: this process should be irreversibly tamper-evident, such as IC "fuses" or one-time PROM. This should be permanently visible in the UI, so it cannot be applied invisibly.
- important 2: an obligation on the state to pay for replacement devices which have been compromised in the previous step but not used in court. This is to prevent it being routineised.
If nobody but me has the device encryption key, and my device is stolen, I can be sure that nobody will have access to whatever data it contains. If anybody else has the device encryption key, however, and the device is stolen, I can no longer know whether anybody else had access to the data, no matter how much tamper evidence the device has.
Brilliantly awful.
You realize, of course, that, of your two choices, the DOJ would probably choose the former (i.e. general insecurity).
Again, any government backdoor = security failure and there is no way around this.
What was interesting about Dual_EC_DRBG was that the default points served as sort of a secret master key to generator state leakage. It was harder than usual for another party to gain illicit access, leaving the vulnerability largely in the hands of the NSA.
It was some pretty interesting math, harder for unintended (by the NSA) people to take advantage of, and still, of course, a crippling vulnerability.
At this point, I'd be hard pressed to trust the NSA with anything security related, as they have demonstrated different priorities.
Or it gets left on a USB key in a taxi
Or it gets left on an un-scrubbed laptop that's put up for government auction.
Or any of the other which-ways that humans get around policy limitations that don't have technical barriers, or socially-engineered to get around the technical barriers.
The more important the key, the more sought after it will be by hackers, especially one which could theoretically decrypt an entire countries communications. It's only a matter of time.
[1] https://boingboing.net/2015/08/21/make-your-own-tsa-universa...
Now if you mandate everyone use a government key or escrow their key with the government there's now a single place to attack. Also this place is affected by government whims, staff pay freezes, cutbacks, layoffs. All you need is one disgruntled employee or contractor with access and you now have access to _everything_.
This isn’t some hypothetical scenario either http://time.com/106319/heres-what-chinese-hackers-actually-s...
But law enforcement is only one component of a functional society.
And the rest of us, from time to time, have to deal with the criminals who have yet to be caught by our acceptably-efficient law enforcement apparatus.
This includes people who like to steal information, many of whom are probably out of US law enforcement's reach.
The author doesn't address that problem, which I can understand, as he's a lawyer and former fed prosecutor. And while it's tempting to tell him to stay in his lane, we're stuck with him and others like him.
And it doesn't seem possible for the people (whom government doesn't really trust, despite platitudes uttered for generations) and the government (whom the people do not trust, for reasons I have a hard time impeaching) to agree on a system for safeguarding information.
Which is too bad, because most people would probably like to help enforce laws, espeically those involving children and other vulnerable types.
BUT, we live in a world where even the most open and free societies do the following:
1) Use the police (more accurately, the threat of legal trouble) to silence, bankrupt, and intimidate problematic people.
2) Defeat or ignore the controls designed to prevent abuses of power.
3) Refuse to hold government institutions accountable for malfeasance.
It might help Dr. Rozenshtein's case if he would apply his gifts to solving the political problems listed above, which might restore the trust between government and governed, which in turn might get him the tools he thinks government should have for enforcing the law.
Privacy (and hence encryption) is a right.
End.
Governments have no rights (and prosecution is part of the Government), they only have mandates. To comply with these, they have powers, not rights.
Edit: no->not
Been that way for a long time.
The Four Horsemen of the Infocalypse https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
For those who don't know, Lawrefareblog has always been pro-mass surveillance. They only started doubting themselves a little when Trump won the election. But it seems they're back on the pro-mass surveillance horse now.
> When we founded this site more than six years ago, I never in my wildest dreams imagined myself writing these words about a man who will take the oath of office as President of the United States. We began Lawfare on the assumption that the U.S. federal executive branch was a tool with which to confront national security threats. While I accepted that its manner of doing so might threaten other values—like civil liberties—or prove counterproductive in protecting national security goods, I never imagined I would confront the day when I ranked the President himself among the major threats to the security of the country.
https://www.techdirt.com/articles/20161111/00230136015/long-...
Huh, no kidding? So a "bad" president could abuse the extensive powers that are given to him thoughtlessly to "fight crime and national secure threats"? It's only the argument privacy activists have always made.
Lawfareblog seems to always work with the assumption that the government is always the "good guys" and therefore will never abuse the powers given to them. That is wrong.
I think the article is only advocating for a checkbox in the settings menu to enable encryption for any would-be communication medium, which is turned off by default. I'm not especially against this, so long as there are no detractors to enabling this option.
Defaults matter.
- Most non-technical users won't know of this setting, and thus be unprotected.
- The consequence of forgetting to enable this setting is severe (forget it even once, and you risk leaking a secret for eavesdroppers).
- When security is optional, having security enabled is suspicious. When everyone has security enabled all the time, an attacker can't know whether someone is sending secrets or cat pictures.
This is why we're currently seeing a push towards encrypted by default everywhere. Not because everything needs encryption, but because then there's no risk of forgetting.
But boy do I like privacy / hope it sticks around.
The first private conversation that Martin Luther King, Jr. had about the injustice of his time was captured and automatically analyzed, and as a result he was identified as a disturber of the peace and arrested for unrelated violations long before his message ever reached an audience.
Rosa Parks was detained for disorderly conduct long before she made her stand, and as a result her stand never happened.
There was never a zeitgeist of change in the oppressed community, because there were never any stories of people resisting. They were all prevented from acting in any significant way, or from getting together to share their stories and find support.
The issue of racial discrimination never made it to court because all of the people who could have brought it there were stopped before they could get started.
Perfect surveillance can stop any threat to the status quo while it's in its infancy, long before it amounts to anything. It can probably do it without introducing any new, draconian laws by simply looking through recent history for "questionable" actions and harassing people over them.
The argument that it's okay now basically amounts to saying that there is no longer any injustice and that today's system is a perfect example of virtue and fair play, and that anyone who disagrees is a malcontent who really does deserve to be silenced.
Sometimes the majority is wrong, and it takes brave people willing to break the rules in order to point it out and change things. I'd say that democracy does depend on privacy for this reason.
I'd argue with little to no privacy the government actually has less power in situations like this. Because the lack of privacy extends to what the government is doing also. Cameras/microphones/eyes everywhere means it's much more difficult to get away with a lot of the covert insanity that was happening before.
I would say things like Snowden/Panama Papers/Wiki leaks/many other examples are showing that having privacy can actually benefit the people in power more than the average Joe. Joe Blow doesn't want his dildo collection known about, the government doesn't want (insert insane things like funding drug cartels/terrorist organizations) to be known. All in all I'd say sacrifice knowledge your dildo collection for the greater good.
That said I do believe privacy still needs to be a thing. I hope it is a thing again in the future. But I actually don't know how horrible it is that it's gone away. People might just have to tell the truth for a while, which might benefit society in its current corrupt state?
Yes, it absolutely does. The most effective way to fight a political ideology is not meeting it fairly on the marketplace of ideas to fight it directly. If the opponent is allowed to an opportunity to fight, you might lose. To guarantee a win, you have to stop the opposing political ideas before the organize into an ideology that people can support and fight for.
Political movements need time to mature. It's easy to disrupt proto-ideologies if you can identify the people that might bring together separate parts of the social graph before they knit together into a self-sustaining political movement. This is what the FBI did to disrupt civil rights groups under COINTELPRO[1]. This is what GCHQ's JTRIG[2] group is probably doing today.
While the Freedom of Assembly doesn't get as much discussion compared to speech/religion/etc, it's one of the most important rights. Assembling with people in public is how an idea moves into public view. Ideas you only discussed cautiously in private ("in the closet"?) are a lot easier to discuss openly in public when you realize other people have the same beliefs.
The advent of the internet has caused us to question a lot of our rights as a people. We originally felt strongly around our right to free speech and our social networks embodied that to its logical conclusion, and now we're here at a dire state of hate speech and vitriol that threatens the (perceived) stability of our democracy. While the printing press and television have contributed to our partisanship, it's almost undeniable that the internet - and the ability for anyone anywhere to publish anything - has pushed us over the edge.
There have been serious considerations about what we can do about this. One of the issues is that, as a people, we might not be ready to have all this power ourselves.
I'm wondering if that extends to encryption and privacy. Can we, as a people, be trusted with this level of autonomy, power, and security?
A philosophical question is one worth considering for fun, but it has little practical value. There is no way to stop people from using mathematics to protect their privacy and their data, and any debate around that come from people who are innumerate.
We can discuss the should/could stuff as a matter of interest to waste taxpayers' dollars and time, I suppose, but that's not what lawmakers generally try to discuss. They want to figure out how to do the impossible, or at least lie about it.
Is not something I did.
Yes, things are now so good for the average person that you can create mass hysteria over mean words. Not a satanic child murdering panic, not teenage violence, sex and substance abuse... just words.
Once you stop consuming the outrage crack pipe, it all goes away. It's all a big game of signaling and sophistry. Ask yourself why the average journalist is qualified to whip you into a frenzy on topics that should rightly require years of study to become authoritative on.
You can be trusted, you just gotta turn your brain back on. When there is a breakdown in the accepted mechanisms for spreading social consensus, you go back to primary sources. It shouldn't be a surprise: nature has told us that monocultures are eminently vulnerable. The solution is always diversity, the actual kind, not the ideological puritanism that has appropriated that concept for themselves.
This is about to get even worse for law enforcement. To date, iCloud backup still offers a way for law enforcement to access data with a warrant. However that is about to change. Apple is about to roll out iMessages on iCloud, which sounds innocuous, but actually will premiere a major step forward in security: end-to-end encrypted data in the cloud by default.
This is huuuuuge.
The thing that has been holding back E2EE as the default is that it has sacrificed recoverability. That is, it has required a strong password, which is easy to forget, and if you forget it, no one can help you. So it's something you had to opt into. Not a default.
Now, Apple has created a backup solution that -- get this -- removes the need for a strong password. Sounds crazy, right? All you need to remember is your iPhone passcode. Obviously, this is brute forceable and can't secure your cloud data...
Except yes it can. They've implemented hardware security modules that prevent brute forcing. Then they destroyed the signing key for the HSM firmware. Neat.[1]
So, iMessages are going to transition to this, which probably means they won't be in the iCloud backup, and thus not available to law enforcement. And then it's probably just a matter of time until the whole backup is secured with E2EE.
Which means they would not be recoverable or even restorable to a new iPhone. Not a good default for a consumer device.
Apple made the right choice, letting you opt into stronger security at the sacrifice of recoverability. And now they're working on the best of both worlds.