FBI drives for encryption backdoors
arstechnica.com
arstechnica.com
It seems rather lazy and short-sighted of them to be pushing to compromise the security of all forms of encrypted communication just to make one aspect of their job a little easier. Besides, the Internet is global, so even if they succeeded, they'd simply push the innovative technology to other countries where it's still easily accessible to everybody except U.S. based businesses. How does that make our country more secure?
Why is this referred to in a way that suggests it is somehow not a routine part of serious police detective work?
This seems incredibly lazy and irresponsible.
And criminals use codes when talking on the phone, thinks like "making the bed" could be the code to steal something, "drink soda" putting a bomb, so you need the serious work anyway.
#1 the backdoor secret will FAIL, as it has for every DVD, BLU-RAY, XBOX, PS3, etc... DRM device. So criminals will be able to read all encrypted (obfuscated) data.
#2 people who want to hide illegal data will.... use real encryption.
This is like banning guns. Which oddly has the opposite effect in reducing crime. I wish Lawyers and Politicizations had to pass engineering school first. I swear, passing the LSTAT doesn't seem to prove anything about ones actual logic skills.
Guns aren't the problem. It is how us Americans perceive guns and our rights to own and use them that makes an issue out of owning them.
There might be a loose connection with crypto, where if all schemes have backdoors, only the criminals and "bad guys" who wish to send messages securely without government eavesdropping will implement or obtain ways to do so without backdoors.
The "break" in BD+ will be when someone finds a way to write a ripper that seamlessly handles BD+ refreshes, just like the players do. It'll happen eventually, but it hasn't happened yet.
The general public won't notice/know about a difference; the people who use encryption and those who have something to hide will switch to something that doesn't have a back door, thus defeating the entire purpose of the law; and black hats everywhere will smile like it's Christmas morning.
Don't believe me? Look at our park system. We've come out and said time and again that the trees in our parks are important. That is, until we sell 30 acres here to pay for this. Then 30 acres there to sell to pay for that. Eventually some of the parks are half the size they used to be. God help the redwood trees.
How can the agencies prevent crypto without backdoors being implemented on top of their crypto with backdoors?
One likes to think of the politics as a pendulum, swinging back and forth. Sometimes things are in the hands of one party, sometimes another. But when one side of the discussion is at "0", that biases the swings. It can't go into "negative" legislation, so the site championing the "0" can never win, and in the long term, the changes keep creeping away from the 0.
If you are committing treason, or something, the price of going to prison for using PGP is much less than the death sentence you'd get if you sent the messages in the clear.
I also don't see laws against crypto (and steganography) really being effective. A law is one thing, convicting people for violating them is another.
Think about what a tough time the government has in bringing cases against criminals. It's 50/50 as to whether or not they can convince a jury to convict when they have a security videotape of the accused gunning someone down. "And here we see the defendant discharging his handgun into Ms. Smith."
Do you really think they're going to be able to get convictions for people alleged to be hiding encrypted data in normal streams? "It's clear from the noise pattern in this image that there is a hidden bitstream in the low-order bits. This means that anyone exchanging this image is probably forwarding on encrypted terrorist communications. We can't actually prove this beyond a reasonable doubt... it is possible that they used a buggy version of Photoshop when they were resizing it for their lolcat blog. But probably terrorism!!"
I am not losing much sleep over this.
Well, yeah. But you have a right to be tried by a jury of your peers... who probably won't understand crypto. (The "drugs are bad... except coffee and cigarettes and high fructose corn syrup" propaganda caught on pretty well, so you are probably stuck there. But there is no "strong cryptography is bad" rhetoric out there, and it will be hard to argue for -- the opposite is "the government is trying to steal your credit card number".)
Anyway, the whole point of the Constitution was to allow people to do things that the government didn't want them to do. Using strong cryptography is the modern way to for one to "be secure in their persons, papers, and effects, against unreasonable searches and seizures".
Finally, it seems that this round of laws is directed at service providers that store encrypted messages; the government wants you to be able to read everything passing through your network. Of course, you do not control the P2P network that your movies and phone calls pass through, so this law has limited effect. Even then, if end users provide their own encryption, that's out of the scope of this law.
The government cannot read every packet that passes over the Internet.
How about Tor being used for CP? That's a pretty prevalent and well known argument. Any competent lawyer is going to be able to spin the same argument for strong crypto.
I mean, guns are still legal right, despite the fact that people murder each other with them.
So while surely there will be some new law censoring the Internets, the courts will probably strike it down.
(I mean, are we really going to send people to prison for not upgrading their ssh servers? I doubt it.)
On a side note, why not to have our own separate internet? I've been thinking about OpenVPN tunnels between dedicated servers and letting users connect to them over vpn links, of course. This would form a closed network with services inside. It's a sad commentary, but having privacy friendly network sounds like a breath of fresh air just 20 years after the Internet took off.
[1] Available for free straight from Cory Doctorow: http://craphound.com/littlebrother/download/
My idea of the network like this is more about privacy than anonymity. And it shouldn't be too hard to set it up. I am just bouncing the idea around to see what others think of it.
Hackers on the internet care. Pandora's "free and instant information" box has been opened, I don't think you'll ever be able to close it again.
"Joe Plumber" on the internet will also care the first time someone hacks his bank account because his bank was using one of these backdoorable encryption schemes for online banking.
* The content protection scheme that binds DirecTV cards to paying accounts.
* The VM-based BD+ scheme that protects each wave of Blu-Ray releases, requiring disks to be cracked individually.
* The current incarnation of the iTunes video rental protection scheme.
-----BEGIN PGP MESSAGE----- Version: GnuPG v1.4.10 (GNU/Linux)
hQQOA1epHOklxC8KEBAAgPQJPDfmOM2CuU0aOXwRRmwejm/5zYGK4dhyh0B6W6/J 0KQ3trcF1O0MvLFAWtOJAS9WweGD/nvpBRWtyXKQh/xdP0uHtbLQExLPuSRffkhR /oldEh5kkqroIXF5w2cEmEjnOv3VdVHeJRo2mMx4kwMwy8P7nUdut2fj77njVfVF MVy0p0svdzSRVx+NIrbS9+dTVoQPXt4HBFmSb+kPoKTsc2KlobKSKC3J/VeVvtJE KHWVbh48fqJkfcxgY7C6B2PH+N1PwnfmlPKgORII0jv5CZDdJWuw37lip8SbVtzo 7B5QSTHrRZqw/lcB+kPkny9cPhNbvN7lYKUUxpmPh4IKT6zD5EGex64Uq2uAxk7K MdIwIz6nkzAbLWJl2CEr4wj1bVB3cp2Il5AvCHWo0eTbNeG1rrK1NqBPwh0X3ySy jJl81q7x8huuo1lykPu4SMEazCHvQLgLcFRE8lTYyHMi96zuT/vQI2aXWlg2Ttjx 9Vnmk/iObd+aRpAHrtRWO3jpOelhdEcHzYe0Uyao2Itc/h4JKOkqQAq/V/ijbL2U 12Upb230DIgpL1N0pbtAtGkulGMPOkMQ3Exe8CIaey3Ofp+awB4Q0jdQEkI86XX8 cOdpMV8vN5Oqf+yXPblYlUpoJIOiuly9Caj7/pN+zG1MRSO14F2mCdAReJyAg7kP /0/g/flbC9AO5qwfw+yKbN+G8FmqCPX7JUrUbkfGtNUb/kwPHTyDh1U7XF8D06z8 11NxMNUMOcTEFHS1OQrFh/oIAy37dz6MbNkdzHPoLOG8FS/s+RBH2YoODKSjECyE Mh56cesofNt47wIimz1Z/TRag2zr0A7gOgdM3Kh9Sd3rlEU7WEJTCisXJkYqVREi HTnMXfPcNxC9U/UxubeDVY1AGavDQDYrqSDk8ZRljZ3VfvFUYBx0AKPp1mkAPVAS vVe6YpPvxoKttgcmFG6Fe7X2JJvkbE2KhXraG8I4kxACzhPy0ENFA//hyxIIz+en fvKYxDIufYYvOiPbnTwBsWXFbS8JXXdAecML/loIy0DYWTq13yiKOz4ahzxWBZGP 4JrZnCsFxvjdmopxSQ6WZbHGWcdOFdv3lecVeybp8Aq40ViMf6NYO1wdG3u4Krrx uX6J2nlU50utl9P03VofuWLTL5909b86g8lhdTFtn7pOBsVDD0WPmYI7Xf3zFDav qWcF+kbwOTFMaa1UDIIbBtpBQBoEpLDn8ajDhrfuhPUzN6Qwlu6vQhIJFPwCj4VY rUiUIo5oXi72OEB0jWOVvPS43JVHSyrzuEAdSMcoYp7Iwd22gILOe0saf/VOIgCX TLNtgqEK07eUdiucS2wFXKYVbHDKDR+2Wsckcn5BGQX00kMB6CFmhwAQs8n3Fep+ BtizYTn+IFWSP7gkTpYuOA4ap+QBlx1bXssBHfrFzsEZu4i3yU64GyxeejIKyfjE JWSAkytZ =uUi8 -----END PGP MESSAGE-----
On the other hand, if the article is to be interpreted strictly, as only making it illegal for online service providers (is that supposed to mean ISPs, or anyone who provides a service online?) to offer encrypted communication, then it will make it more inconvenient but by no means impossible to encrypt everything that you do. In other words, it'll be totally ineffective against serious criminals; but I thought stopping them was supposed to be the justification for a law like this.
I am mad.
However, to be truly effective, yes they would have to ban other forms on encryption - this obvious inference was totally ignored in all news I read or saw of the clipper chip in the 90s. A sad illustration of the prevalent shallowness in mainstream tech reporting.
Same thing here, if the US has a backdoor into https/ssh, then the Eu will also want one, and Russia, and China, and India and the middle east. How long is your online shopping going to be secure when Nigeria or Somalia has the official government backdoor into your bank login.
SO we can thank Amazon/Visa/Apple for quashing this one.
Not that this will ever pass as a law.
Of course, if there is a back door in all encryption between, say, businesses or minority political groups or anyone else who has legitimate reason to encrypt stuff, 1) there's the chance (very likely) that others will discover the back door, and 2) the government (or some of their employees) will probably abuse it at some point.
See, the whole point of encryption is to make your communications SAFE and eliminate these sorts of unknowns. It's a legitimate need, and just because it can be misused doesn't mean it shouldn't exist.
You did log the key for that https session when you used amazon checkout didn't you?
First, from what I can see, everything we know about this proposal was filtered through an NYTimes reporter. In other words, we have no idea what the specifics of the proposal are. The issue that's lighting everyone up is the "likely" requirement that "Developers of software that enables peer-to-peer communication must redesign their service to allow interception."
This, to my eyes, could mean one of two things: either (a) the DoJ expects independent developers to backdoor any voice app implemented with encryption, or (b) the DoJ wants a lever to use to get Skype to comply with law enforcement investigations.
Option (a) is crazy-talk and won't happen, if only because there's already judicial precedent for the idea that source code is a protected form of speech; you can't ban encryption in the US, and we're epsilon from overturning the idea that you can even restrict its realization in an actual product from international commerce. A more pragmatic reason this could never happen is that industry wouldn't allow it, and contrary to the notion of the government as a big clumsy untethered gorilla that can run wild, it actually is difficult to pass and enforce laws that incur 8-figure costs at Fortune 500 companies. It's also too easy to lobby against.
Option (b) is where I will annoy the hell out of you, because I don't think this is a totally unreasonable thing for the DoJ to pursue (whether they should actually get it is a separate issue).
In the United States, we don't actually have a right to be free from investigation. We don't even have an enumerated right to privacy! We're free from unreasonable searches and seizures of property, and court-authorized wiretaps simply aren't unreasonable in our jurisprudence (or even our common sense understanding of the law).
My crypto-fan acquaintances on Twitter are fond of pointing out that this proposal would do nothing to catch Bin Laden, which is of course true (no law will). But I don't think this is about Bin Laden; I think it's about garden-variety prostitution rings, racketeering investigations, drug and weapons smuggling, and other day-to-day law enforcement issues. As I understand it, wiretaps are an integral part of these kinds of criminal investigations, and it is a bona fide problem for LEO's that voice communication is moving to encrypted IP networks.
The reality, again as I understand it, is that 80% of criminals are simply too stupid to migrate from Skype to something more secure to avoid wiretaps. So if this is a law that basically says "people should not be immune from wiretaps by technological default", well, that seems sensible. If you care about the security of your voice comms, set something more secure up.
It's hard for me to get too up-in-arms about the idea that the FBI wants to tap Skype, since they can already tap GSM and they can already tap my land-line phone.
Some people, I think, feel intruded upon since this represents the FBI treading on their own personal technology. But remember, with a court order, the FBI is already capable of backdooring your machine with surreptitious keyloggers and all manner of other doohickeys. This rather moots any "P2P encryption" you might be relying on.
Au contraire, they'll never get my encrypted FrogPad that lives in my pocket and sleeps under my pillow!
The right to privacy is made explicit in many places, especially judicial precedent. It just isn't explicitly stated in the constitution.
http://en.wikipedia.org/wiki/Griswold_v._Connecticut
"While the opinion in Lawrence was framed in terms of the right to liberty, Kennedy described the 'right to privacy' found in Griswold as the 'most pertinent beginning point' in the evolution of the concepts embodied in Lawrence..."
That would qualify as "enumerated" to me.
You do have the right to be free of wiretaps - except in the course of a court-ordered investigation. You have a right to not be a slave - except when you violate the law and the state forces you to work, etc..
This is why its important to limit the purview of government, why even if we allow prosecutors to spy on people, we might not want them to easily spy on people, etc.
I have not looked deeply in to this though, so apart from that point I have no position on this proposal.
What I find interesting / related is Google, Yahoo and other internet companies and ISPs are pushing for less invasive probes from the DOJ (http://news.cnet.com/8301-13578_3-20002423-38.html), maybe the Feds need some draconian laws to bargin with.
Of course they were. DNSSEC has a centralized key and therefore already has the proposed backdoor.
At DEFCON I have seen several man in the middle attacks on TOR, the most successful of which required only 50% of the nodes.
https://svn.torproject.org/svn/projects/design-paper/tor-des...
You're correct in saying that Tor assures anonymity and not privacy: if you don't want other people to know what you're sending over Tor, it needs to be encrypted separately, because the communication between the Tor exit node you're using and the computer you're communicating with is unencrypted.
However, Tor still relies on encryption in order to provide anonymity, and messages are still encrypted when you first send them out (whether or not you're running a Tor router yourself).
Tor does onion encryption: when you send out a message, that message is wrapped in three layers of encryption. The first router you send it through can take off the outer layer to see who it send it to next, the second router you send it through can take off the second layer, and the third (exit) router you send it through can take off the final layer of encryption and see the actual message you sent (and where you want it sent). This encryption is very important, because it assures that each router can only see its immediate neighbors in the chain. If the encryption is broken, then whoever breaks it can see the entire circuit the message is traveling along (which will include the source and destination) and so anonymity is compromised.
Finally, it is worth noting that the fourth amendment requires a warrant, and existing wiretaps are done without warrants, just with "court orders" because getting a warrant was too much of a burden.
The inclusion from all of this is that the act of enforcing this law, if passed, would be itself a crime as there exists a federal law against violating constitutional rights under color of law. Further, passing the law jugs shows who illegal our government has become. If the government is not in comolaince with the document that authorizes it's existence, then it is not a legitimate government.
And while I do think the proposed law is shockingly broad and overreaching; I find your grasp of american jurisprudence to be lacking in several important respects.
For example, it the government can't constitutionally control communications, the FCC is illegal. And yet it hasn't been shut down by the Supreme Court or Congress.
You're right, it seems these days anything the Feds want to do can be justified by an allusion to "the Commerce Clause".
If we outlaw encryption then only criminals will be able to talk covertly, while good citizens will be abused. EPIC FAIL!