Attorney general: Americans should accept security risks of encryption backdoors
techcrunch.com
techcrunch.com
Rosenstein: https://www.justice.gov/opa/speech/deputy-attorney-general-r...
Sessions: https://www.justice.gov/opa/speech/attorney-general-sessions...
Comey: https://www.theguardian.com/technology/2015/jul/08/fbi-chief...
Comey engaged in a long running campaign on this from at least 2014, until he was fired.
Lynch: https://www.networkworld.com/article/3040224/attorney-genera...
Holder: https://www.washingtonpost.com/news/the-switch/wp/2014/09/30...
Let's all hope they continue to fail.
Not that I’m taking a position on things either way really. The likes of apple should be able to do what they please — just not be surprised when they find the government installing the backdoors themselves.
They're just in a different position... In the DOJ, encryption gets in the way of their job--catching criminals... while the penalties for a backdoor fall on others (those responsible for the data). There's no downside to them personally (and very little for the DOJ itself) for getting a backdoor.
The opposite is true for those not in the DOJ... the protection for our data is compromised.. and in exchange, the DOJ is able to prosecute some criminal we've never known, met, or had any contact with.
To those in the DOJ who deal with criminals everyday, their ability to prosecute criminals is of the upmost importance to them personally... and for the rest of us, unless we're a victim of a crime, there's only downsides to a backdoor.
There is if the people in the DOJ suffer from identity theft and get their bank accounts cleaned out because some nefarious people exploited the backdoors.
People in the DOJ have more options available to them if they choose to try to find or punish an identity thief than the general public.
Also, the direct fear of not being able to do your job because of strong encryption is more focused than a nebulous fear of possible identity theft.
I've known a few cops and they all have stories that are hard to hear and are worse than what you hear on most true crime shows. I assume access to high level intelligence involves endlessly seeing cases where people were caught attempting to purchase weapons grade nuclear materials, endless plots that never happened but are very scary to read about, etc.
That being said, it is bias and it shouldn't be allowed to unilaterally influence politics. Banning strong encryption is both impractical and destructive to our society and economy.
"But terrorists will just ignore the law" is a bad argument. It ignores the fact that the ban still increases the power of the government to act against terrorists. The problem with the law isn't that it's useless against terrorists. The problem is that it also increases the power of the government against the innocent, and possibly the power of some non-governmental criminals as well (depending on implementation).
A problem could be that people in general don't care about: "increases the power of the government against the innocent" -- because that's a theoretical problem in the "distant" future?
Personally I think the US gov getting too much power and gradually in small steps get access to "everyone's" communication, is like 1000 times more dangerous than "encrypted terrorism messages",
and, what can be a good way to make people in general better understand the risks & dangers with small steps towards a dictatorship? Maybe if everyone reads 1984 :- / or if everyone was better educated about what happens if you're in China an critizise the government there?
I didn't mean literally all lawmakers etc (although that's what I wrote). The next time I can try to write "some of them" instead.
I think I have more to fear from the government than I do from the types of criminals that encryption backdoors would thwart.
Most of the recent attacks in America were carried out by lone-wolf far-right extremists. Some of the ones who were caught were actual government employees.
Furthermore, there's more to fear than someone spraying bullets into a crowd; ICE is performing 3am Gestapo raids and imprisoning citizens.
So you bet your ass I'm more afraid of the government than a guy driving a semi-truck. The government can hurt more people in a day than a terror group can in a year.
Of course. But we need to remind myself this: what it is the probability that they are going to willingly hurt innocent people on a massive scale at the moment?
Aligned with your comment:
I have to admit that one of my paranoid fears is that this will change in the future and who is supposed to protect us is actually going to be our enemy. This was also one of the founding fathers.I guess, we are in a good company.
History is full of examples of good kings that die and their successors are very wicked men.
At the moment I think that "being able to find out what they need to" is net positive for the world ( see https://news.ycombinator.com/item?id=20509347 ) but what really bother me is that if in a future (hopefully remote) this change, there is no way to undo the past.
From my prospective the security that they are able to provide because of being able to tap in any conversation and the risk of citizen data being used against innocent people is clearly a huge compromise.
How can a man even hold both of those viewpoints?
Well, given that they're doing it now, I'd say somewhere near 100%.
The reality is that we should be just as concerned by a guy blowing up a truck at the Apple Store as we should about ICE raids at 3 in the morning. With both right wing terrorists and the government, scope creep has a way of ensnaring us all eventually.
Same is true of any terrorist, and any government.
So look, the question is not: Whether or not compromising my personal privacy will bring me more or less security? But rather the question is: Whether or not compromising my personal privacy is consistent with American Ideals?
I say no. So in my personal opinion we, as a nation, have no business mandating that people compromise their personal privacy.
I can't be the only person completely unconcerned by events like this taking place. And I'm not someone without copious anxiety in their life.
/s?
I disagree.
> With both right wing terrorists and the government, scope creep has a way of ensnaring us all eventually.
What's an example of a terrorist group's scope creep?
> So look, the question is not: Whether or not compromising my personal privacy will bring me more or less security? But rather the question is: Whether or not compromising my personal privacy is consistent with American Ideals?
Disagree.
> So in my personal opinion we, as a nation, have no business mandating that people compromise their personal privacy.
Agree.
Good talk.
So the argument goes, you should focus on the much more direct and practical impact that laws & politics can have on your life.
Just because they opted to go with low-hanging fruit doesn't mean the fruit needs to be low-hanging for them to make use of it.
Untested hypothesis: what we consider to be trivial, politicians consider to be advanced magic.
Alternative hypothesis: politicians understand the skill level required perfectly, but they also have good reason to believe the terrorists are complete morons who wouldn’t be able to find, generate, or use a one-time pad if their life depended on it (and in this case their life literally would depend on it).
> “You will deal with a person who doesn’t have those clearances only from the point of view of what you want him to believe and what impression you want him to go away with, since you’ll have to lie carefully to him about what you know. In effect, you will have to manipulate him. You’ll give up trying to assess what he has to say. The danger is, you’ll become something like a moron. You’ll become incapable of learning from most people in the world, no matter how much experience they may have in their particular areas that may be much greater than yours.”
https://www.motherjones.com/kevin-drum/2010/02/daniel-ellsbe...
"We need pervasive surveillance to protect you from the cannibals we imported to lower your salaries, peasants."
It might be less of a red flag if regulation was likely to be able to prevent terrorists from using encrypted communication technology, but that's absurd as long as we have general-purpose computers and access to the open internet.
Personally, I fear all advancements it cryptology will be classified in the future.
Well, it's hacker news, so let me pull a word we like to bandy about: "scale".
I think that the only way agencies were able to keep postponing the end of the Patriot act and related laws ( https://en.wikipedia.org/wiki/Patriot_Act ) is presenting massive evidence to the congress of the tragedies they were able to avoid with the power granted by those laws.
Somebody that was publicly martyred by a country of great power makes more noise than a war that was avoided.
Weakening strong cryptography is not the solution but I think we sometimes grossly underestimate the other face of the coin.
I'd like to see more of that made public.
Sure, because we're never told. And you know what? Maybe there's good reasons. But "we can't tell you why, but trust us, it's super effective!" isn't enough of an argument.
Aren't the ones we hear of are the ones where the FBI set the whole scenario up?
I mildly prefer the "neither confirm nor deny" responses https://en.wikipedia.org/wiki/Glomar_response
I am not an expert but I think the general feeling most of people have is we are hearing a lot of constructed lies. Is there a list of stories told to the public that were proven to be lies? Did they even come out and say "Yes, we lied and this is why..." ?
The fact that we don't suggests either that (1) backdoors aren't that essential to thwart them or (2) there are no such regular massive attacks.
Further, as people like the US Attorney General helps to publicize those backdoors, more criminals will choose alternative messaging systems (fewer of which are backdoored), making the US less safe.
Law enforcement seems overeager to label anything and everything terrorism if they possibly can. For instance, someone at my previous workplace vandalized prod in a fit of rage when he left and they called it terrorism because the system had utility companies as customers. Why would law enforcement be so interested in juicing their terrorism numbers if the real thing was plentiful?
My hypothesis: real terrorism isn't plentiful, but the budget to go after it became plentiful after 9/11, and the people who benefit from the budget do what they can to keep it that way. Erosion of freedoms and judicial overreach are side-effects.
It is easy to see that the risk is that if plaintext data is available, the data can be mined for a lot of other purposes including illegal or not ethical ones. It is also possible that eventually that data could leak to the wrong entities.
And yes, in any big organization, the left hand may not know what the right hand is doing and, while one is concern in matters of public safety, the other may be primary concerned with the hegemony of its own power.
So it is complex.
But just assuming that you do not need them and they are just evil is a massive over generalization.
Fine, but assuming that they'll abuse any amount of power given is completely reasonable, in light of plentiful examples in the past.
Renewal: The best case is it foils a terrorist attack. The worst case (Snowden) has already occurred.
Nonrenewal: The best case is no terrorist attacks. The worst case is a terrorist attack that may have been prevented with Patriot Act level wiretapping.
No one wants to be blamed for a terrorist attack at the next election so the Patriot Act is renewed.
There's already freaking 1% of the population in jail; how many more do these assholes want to imprison?
The Philadelphia DA Larry Krasner is setting a fine example we all need to take note of.
Two things about this odd quote, which dances on the edge of the Orwellian "nothing to hide" argument:
1. I'd put the odds that current president has in fact stored the nuclear launch codes on a "consumer product" at 50:50. He's shown a shocking disregard and disdain for protocol. The way in which diplomacy is carried out through Twitter suggests he's not capable of evaluating the threats posed his uses of consumer-grade technology.
2. Barr assumes a threat model involving petty criminals. The real threat is the US federal government, which has demonstrated repeated disregard, under multiple administrations, for search and seizure boundaries set by the Constitution.
One can store material inappropriately even without authorisation.
The launch codes are used by the president. If a party has access to data then that data can be replicated and stored anywhere else that party can access.
The president is the authority that decides how the codes are stored, they exist primarily for his use.
Benjamin Franklin once said: "Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."
Though I would agree it's a quote of triteness and "just so" convenience that gets massively abused.
He also didn't think much of private property.
[1] http://press-pubs.uchicago.edu/founders/documents/v1ch16s12....
> Was he some sort of fundamentalist anarchist?
The quote plainly refutes that idea.
If you take someone else's property for your own use by force without their permission, they are perfectly justified in using force to take your property without your permission. That is the fundamental natural law which underlies property rights, as well as all other natural rights: reciprocation. It doesn't matter who the property belongs to, how much other property they have, or who is doing the taking.
If you take someone's property without their permission there are three possibilities: (1) you admit that it's wrong and deserving of punishment; (2) you claim that taking property without permission is universally right (i.e. that there are no property rights), in which case you can't complain when others take your property; or (3) you claim that rights are not universal, in which case others can claim the right to take your property just as easily as you claim the right to take theirs. Whichever path you choose, the act of theft justifies its own proportional punishment. The same reasoning applies to any other natural right, as they are all based on the principle of reciprocation.
This is neither the time nor the place, but if you're interested in a more complete treatment of the topic I would recommend this paper: http://www.mises.org/journals/jls/12_1/12_1_3.pdf
It doesn't matter whether or not I agree with you or Franklin (or neither) here - I was noting that your attempt at pointing out his "error" is itself logically flawed and does not demonstrate any such error on his part.
I should hope that this argument is not "unique", since it's just an application of basic logic, and I really couldn't care less whether the conclusions are universally accepted. The logic is sound whether you accept it or not.
I think this has run its course, it’s not a good media to get into something like this at depth.
But if people disagree they can go ride a bike without a helmet, people in the transplant list will thank you.
William Barr is none of these thing.
One is a person with a well-earned a reputation, the other.. well you get the point.
Yes
>An argument from authority, also called an appeal to authority, or argumentum ad verecundiam, is a form of defeasible argument in which a claimed authority's support is used as evidence for an argument's conclusion
You're not defending the point logically; you're only supporting argument is that someone with a good reputation supports it as well.
He absolutely is
The annoying thing about "logical fallacies" is that if anyone season argument they disagree with that resembles a "fallacy", that quote it and act like theyve won.
He is not saying that everything Benjamin Franklin has ever said is true. Obviously. However, if a well renowned and respected Authority has an opinion that some evil schmuck disagrees with, it provides evidence as to who is more likely to be correct. That's not what an appeal to Authority is
Show me where that happened.
>The annoying thing about "logical fallacies" is that if anyone season argument they disagree with that resembles a "fallacy", that quote it and act like theyve won.
That is annoying and I agree, but that's not what's going on here.
>He is not saying that everything Benjamin Franklin has ever said is true.
No one said he was.
>However, if a well renowned and respected Authority has an opinion that some evil schmuck disagrees with, it provides evidence as to who is more likely to be correct.
No it doesn't. It absolutely _does not_. Reputation isn't irrelevant in so far as it lends credibility to a person's statements, but the discussion doesn't stop there. If you're going to defend a quote then defend it. Saying "this is true because X is trustworthy and Y is an 'evil schmuck'" is not an argument.
If this is not a prime example of Appeal to Authority then show me why it's not and provide an example. You're just throwing out your opinions as if they were fact.
...huh?
>If all parties agree on the reliability of an authority in the given context it becomes a valid inductive argument.
No, it doesn't. Why do you believe that? How do you feel about quantum mechanics? Do you realize that Einstein fought tooth and nail against it for years?
>Otherwise every Citation or Source or Bibliography would be a "logical fallacy".
Citations link to works, not authorities. A citation may link to, say, an academic paper which provides evidence to support its assertions. No one is linking to random comments made by so-called authorities, that would never be accepted (unless the citation was to literally show that a quote is legitimate, i.e., made by the person claimed to have made it.)
I'd also like to point out you have yet to provide a single fact in support of anything you're saying.
Great! I didnt say that and neither did the gp you originally replied to. Whats your point?
That's you as you seem to have forgotten.
Are you actually trying to argue you can't tell the opinion of children and subject matter experts apart because gathering evidence based on reputation is a logical fallacy?
So that's really a bit of a non-starter. I would say that Franklin has more credibility however; if only because of the man's legendary common sense.
I'll also point out, Franklin's sentiment can be traced back to the principle that "Vigilia aeterna est pretium libertatis". A consequence of which is, sorry Mr. Barr. Tell your police to do some actual investigative work. It is not the job of the populace to relinquish essential liberty to make tyranny in the making that much further realized.
It is what we do with our Liberty that elevates us as angels, or drops us to the level of daemonic debasement.
Law enforcement needs to understand their job should never be made trivial as their very existence in and of itself is as the sole means to rescension of that which culturally we value most; hich should absolutely be as burdensome a process as possible in the light of what is being taken.
Never mind that making unbackdoored encryption illegal just adds a token charge to a long list of other charges, which to me is an absolute anti-pattern, of the same level as most firearm regulation in light of the second amendment; which I'll admit to being a bit of a hard-liner on.
My 2 cents.
To this day the United States Munitions List, classifies cryptographic devices under Category XIII Materials and Miscellaneous Articles.
All the way back to the pre-constitution 1784 Virgina General Assembly, to some extent recognizes the need for secure communications channels in a militia. "There shall be a private muster of every company once in every three months", and setting forth those in charge of initiating and communicating the time and place of the muster.
People often focus on the first amendment right to encryption. But I at least feel that the second amendment right is equally strong, with the governments own position on arms control behind it, legal interpretation should if anything not tolerate it's own inconsistency.
The governor was blocking this, because the Penn family, which owned a lot of Pennsylvania land, objected. The Penn family did recognize the need for defense (although they were largely absentee landlords so not in personal danger), and offered to donate a lump sum for the arms if the legislator would agree that it did not have the power to tax Penn land.
Franklin's quote was in a letter he wrote to the governor arguing for rejection of this offer.
The "essential Liberty" he was referring to was the liberty of the legislature to legislate how it saw fit, including taxing Penn land to pay for security, and the "purchase a little temporary Safety" was the one time lump sum for arms.
That was in 1755. He did re-use the phrase 20 years later in 1775 in a more general context, closer to what people quote it for nowadays.
But it turns out that his opinion of what constitutes security and safety is completely opposite my own.
I don't think opinions of people who were born before telegraphs matter much in today's political discourse. Basically, it boils down to, "I found a quote I agree with, and when I attach $(some famous dead person)'s name on to it, it sounds really great and authoritative."
You don't even need "backdoors" in encryption. Existing lawful-intercept on Slack, Discord, Facebook, Google and all the wireless carriers will net just about anything you could ever want to know.
I don't think you understand what end-to-end means.
So he's right theres no such thing as true end to end on common cell phones.
Hardly the only application though, is it?
That's kind of what HDCP is, so it could be done on an embedded display too.
I do not find that this comment proven, neither in your profile, nor in the context of this thread.
The last time I saw this matter being discussed here, tptacek was getting pretty upset at people who were suggesting that baseband processors presented a security threat. He's a security expert with a reputation to uphold so I expect he's probably right, but I would still like to see a detailed explanation of why he's right.
For a reason I don't understand, this topic seems to illicit a lot of insults, when calmly assuaging fears would doubtlessly be more effective.
I was under the impression that iMessage was end-end encrypted. So unless Apple has a secret backdoor built into their systems, nobody should be able to access those messages correct? Wireless carriers are just sending my encrypted messages over their networks.
What am I missing?
Do you believe my cell service provider could decrypt my HTTPS connections to my bank?
Since cellphones have a BMC that isn't user owned, which does have access to the full system memory (rather than being an isolated peripheral modem), and since OTA firmware updates can be pushed by the "infrastructure" (including fake 'towers' setup by TLAs, criminal hackers of other sorts, and hobbyists) containing code to compromise and silently ex-filtrate any data (including those keys, or even just the conversation directly); it is an inherently insecure environment.
This needs to be from the PCB traces, all of the component tolerances, all of the chips, all of the firmware (even the ROMs that are actually baked in ROMs on the chips), the bootloader, OS, and entire userland.
This is required not just for the host system but also the human interfaces and peripherals.
I hope we will be able to reach that point with a RISKV system at some point; but the various proprietary interfaces that require licences for implementation/etc might make this problematic. I am for standards, preferably completely free, but FRAND and non-restrictive on meeting the above goals might be good enough. The platform has to be fully open-book, but some of that book can be covered by reproduction limitations for a limited time. (I'd prefer standard patent duration at most, as this stuff NEEDS to become the digital version of paper at some point; and within my lifetime would be nice.)
If you can read your message history from an iPhone, Apple is just one silent update away from reading it as well.
To answer to that. Maybe the problem is in those hardwares and operating systems that do not have backdoors?
Unfortunately such a mechanism requires that we trust the government. That trust was broken with the Revelations from Snowden.
For now, the average citizen fears the government more than criminals and this is the easy calculation folks are making and will continue to make at the ballot box.
-An American
Snowden provided evidence (to the fourth estate) proving that trust has been already been broken.
The only place they seem to have gotten their way is anti-counterfitting thats injected into scanner silicon.
" From the moment Diffie and Hellman published their findings in 1976, the National Security Agency's crypto monopoly was effectively terminated. In short order, three M.I.T. mathematicians -- Ronald L. Rivest, Adi Shamir and Leonard M. Adleman -- developed a system with which to put the Diffie and Hellman findings into practice. It was known by their initials, RSA. It seemed capable of creating codes that even the N.S.A. could not break. They formed a company to sell their new system; it was only a matter of time before thousands and then millions of people began using strong encryption.
That was the National Security Agency's greatest nightmare. Every company, every citizen now had routine access to the sorts of cryptographic technology.....
The genie was out of the bottle. Next question: Could the genie be made to wear a leash and collar? Enter the Clipper chip."
[1] https://www.nytimes.com/1994/06/12/magazine/battle-of-the-cl...
Leash and collar indeed...
My impression is the NSA of today is very different than that of the 70s and 80s.
And I expect some would argue that the "slight incremental" and "massive" are incorrectly placed in that statement.
There's a good reason not to use encryption schemes that have backdoors, they aren't safe and this pull quote betrays the fact that Barr knows that.
I'd be willing to wager that the government isn't going to use backdoor-able encryption because the risk of failure is too great. While not being critical to national security, safety in storing your medical, financial records and your conversations with other is mission critical to citizens. Hopefully folks on capital hill see that.
They aren't going to see it. The government will just use the non-backdoored version. If a company gets its data popped because of the backdoor, the government will just blame the company, or it's acceptable losses because they catch some bad guys.
Everyone should be super, super, super pessimistic that attempts like these will be handled in the interests of citizens.
If you ask the government to do something impossible, such as provide COMPLETE safety and security, they will try to do that. I think the news media bears some responsibility in this regard, as they always blame or call out whatever agency that fails to maintain safety and security, thus leading to severe measures to try to mitigate the previous failure.
Cryptography technology is public knowledge now; there's no putting the cat back in the bag, so now it's about making the non-government approved use of it criminal / basis to assume guilt.
[1] https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
Australian Federal police are busy attacking journalists right now for exposing a coverup of their soldiers murdering children.
Americans should fight this with everything they have.
Make no mistake, the "free" world is well on its way to becoming a surveillance dystopia.
The nazis could only have dreamed about having the secret and unfettered surveillance apparatus politicians have created, and they are targeting that apparatus towards journalists and citizens.
It's not about terrorists or pedophiles, it's about you and I, and anyone else who could potentially expose government or military incompetence/wrongdoing.
Basically, the only way to really hide data is to either use steganography, or to use an unapproved data-transfer protocol (and using unapproved protocols can be banned).
The exact quote is:
"Some argue that, to achieve at best a slight incremental improvement in security, it is worth imposing a massive cost on society in the form of degraded safety"
I'm purely making a statement on the article title.
When the government stops caring about my race, where my ancestors came from, my sexual orientation, my religion, my gender, my political leanings, and probably a few more I'm forgetting, and puts robust steps in place to ensure that it won't start caring about them again later, then maybe I'll consider entertaining the idea of allowing the government to peek at my messages.
[1]: https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
Most encryption software (including crypto libraries) is open source. Is he proposing banning open source or just mandating that it only be distributed as binaries by compromised companies?
Does he, and does anyone else proposing this, have the slightest notion what banning good encryption would actually entail?
- ban all Internet traffic that uses non-backdoored encryption (all ISPs would be required to report it)
- ban all amateur radio equipment, including all products one could use to build a satellite dish (like aluminium foil?..); keep a fleet of radio-direction-finding vans circling the streets
Eventually, maybe also ban general-purpose non-backdoored computers.
Ban random data ?
And ban the universe from being quantum ?
Talk about putting the cart before the horse! The USA is made of people, not hardware.
In other words, I think the "ticking time bomb" scenario often used to justify a backdoor is a fallacy. If the government really wanted or needed to, they could easily decrypt or break into a device (rubber hose method comes to mind).
Don't let fear rule your life, and convince others not to as well. That is our job.
And also no matter how much regulation and monitoring there is a big risk from government employees. It will be exploited by others.
And at the end of day, criminals are going to find a solution for themselves when they have to and this will only leave people vulnerable. And usually government itself will use a different tech for obvious reasons and leaves this for citizens only.
TC piece takes a way to harsh stance. He made some good points in there.
Honest question, if I have a key that can unencrypt all of your data, why is it important that it not literally be your key?
The obvious drawback being the huge damage when a master key is inevitably leaked.
It's also useful for recovering data that the user has forgotten their self set passphrase or wont share it in case of a hostile ex employee. Furthermore one can have multiple passphrases and revoke one if it is known to be compromised.
For the governments concept on it see "key escrow" and the clipper chip fiasco
https://en.wikipedia.org/wiki/Clipper_chip
Problems are legion and multifaceted. To put it briefly based on past actions no reasonable party would trust the US government to be respectful of their rights and privacy nor even competent enough to keep a secret.
It would force the entire world of computer security to be shackled and standardized upon what an incompetent bureaucracy understands and it would be a disaster inside a year.
If one recalls a lot of current woes with malware can be traced back to one of their geniuses that took home a hard drive full of tools and lost it all to the bad guys.
https://www.nytimes.com/2019/05/25/us/nsa-hacking-tool-balti...
If a golden key that unlocked everything in existence came into being it would be in the hands of state actors within 30 days and everywhere next year.
It has always required monumental arrogance and profound lack of foresight to suggest we should backdoor all security for the benefit of the keystone cops and their current fearless leader Sergeant Shultz here.
As the iconic tv character used to say "I know nothing. Nothing!!"
I don't like it as much as anyone else, but unfortunately I think this is viable in practice. Of course, nothing stops you, a hacker, from using non-backdoored encryption, but government is fine with that, as long as Google, Apple, Facebook etc. are forced to use backdoors.
Which just goes to show that this isn't actually about catching hardened criminals (who will just use non-backdoored encryption, either alone or layered on top of the compromised channels) but rather about enabling pervasive surveillance of ordinary citizens.
But yes, I think that there are lower-hanging fruits available for pick up here. I wish we lived in a reality where backdooring encryption was the best available path to reduce crime.
If what these criminals are doing is causing actual harm then there must be sufficient offline physical evidence to track and convict them by without direct access to their communications networks. Far from reducing crime, the enforcement of compulsory backdoors would itself be a crime committed by the government against its own citizens on a massive scale.
Isn't that exactly the Clipper Chip scheme? The arguments against it are as valid now as they were then. If you haven't seen them before, they can be found at the 1997 paper "The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption", and its 2015 followup "Keys Under Doormats: Mandating insecurity by requiring government access to all data and communications".
This is such a bad move the tragedy/comedy writes itself.
i'm interested in knowing the attitudes other governments have.