You really can’t go down your line of argument without answering thar
You really can’t go down your line of argument without answering thar
That's an interesting technical problem. A lot of people dismiss it as impossible out of hand, but they are underestimating what you can do with modern cryptography.
You make it a distributed back door that requires several independent third parties to cooperate to use it.
You choose the third parties so that no particular warrant seeker will be able to get enough power or influence over enough of the third parties to force them to enable the back door unless they think the use is valid and just. (You can actually design it so that the warrant seeker does not know who the third parties are).
Some aspects of this may be too complicated to be practical, but it is not impossible.
All solution fundamentally boil down to someone has the keys required to decrypt all your content. This is ignoring the other technical costs (now your service has to record all ephemeral keys as well).
It doesn’t matter /who/ has that decryption key, the requirement is that access to the key is guarded only by policy.
You also resort to “with a warrant” but a NSL is effectively a warrant, and I’m fairly sure the DPRC has “warrants”. Who gets to request those keys? The position of the us government is that they have the right to access data from people in other countries, so can they provide a warrant to access that data? Can Germany ask for the data for someone in the US? What if someone travelled through another country - can that country now access those keys?
Note these all questions regarding /legitimate/ access, I’m completely ignoring police officers looking up people they stopped and stealing nudes, of people stealing the information and using that information to steal money, stalking, etc
I am sick and tired of people who say “modern cryptography is amazing, so it must be able to fulfill my unicorn dreams”. Either stop claiming nonsense or provide a prove that it is possible by designing a system that does what you say must be possible.
What happens when you’re investigating a criminal act sponsored by one of the governments you supposedly trust? What if they compel the lawyers in their countries to not provide the keys?
I generally dislike “what if” but given the problem space you do actually need to explain how your system works, and how it resolves these problems.
Remember there are plenty of countries with terrible human rights records, but they also still have regular crimes happen.
Then when people point out the problems, you don't answer. You make a lot of assertions that are flat out wrong.
Of course it matters. Apple already has nearly total power to modify their devices, and are clearly acting with caution. American courts are not going to give a warrant so an officer can steal nudes. There is no a priori reason that your phone should require a greater kind of warrant than your home or your bank account, and wanting zero access at all only makes sense if you think law enforcement has negative utility.
Personally I'd do something more like this: Print one code on the inside of each device, so as to make access strictly harder than physical access, store one code internally as per your other mission-critical keys, distribute one key each to choice governments, inside a physical module so as to prevent clumsy storage and reduce the chance of cloning (since singly-owned keys can just be revoked if stolen), perhaps with some protocol so multiple members are needed to agree, if you are particularly paranoid. That way you can only get access if Apple wills (either given a warrant or otherwise coerced), the court wills (either a genuine case or simply corrupt), and you had physical access to the device. Apple could not then backdate court keys, so can only be coerced by China into providing access for future phones exactly as they are already in the position to do, though of course OS updates means they already effectively have a backdoor.
Also: murderers and kidnappers don’t have to use broken cryptography. So again the only people who are harmed are people who aren’t criminals.
Also the statement from the Indiana police is extremely vague, and doesn’t make any details available about what they were doing.
Your foolishly conceived system does have any way to ensure that the several parties are not corrupt or evil. You would need to solve that problem first. Assuming it is solved does not work.
In the meantime, devices need to be designed to protect the human rights of users.
What does Apple do if they have this capability and China puts pressure on them to unencrypt some information on Chinese "dissidents"? China has incredible leverage over Apple, seeing as how all their devices are built there. Would Apple dare resist these requests from Chinese national law enforcement agencies?
Better to not have this ability at all, and thus never be put into this precarious situation.
1-https://apnews.com/699236946e3140659fff8a2362e16f43/ap-acros...
With this I agree completely.
Apple has this ability now, by installing an OS that allows bruteforcing the pin.
Imagine the conversation if Veedrac was running the show at Apple.
Saudi Police: "We need the key to this user's phone because they are suspected of having a video of their own gay sex and we want to prove it and if they are guilty of gay sex, we will give the user 60 lashes and then execute them and their partner by chopping off their heads with a sword."
Veedrac: "Oh, OK, yes here you go, here is a single secure key on a one time basis so you can get the user's video and kill them."
Do you really think this is a great scenario, that Apple wants to actively enable by spending money and effort on their designs to make it happen?
Let’s hear your approach then. Don’t be coy.
Aside from the many, many known cases where they are: http://legacydirs.umiacs.umd.edu/~tdumitra/papers/CCS-2017.p...
And having more mechanisms by which they can access user data is not something that ever should be encouraged.