Tech firms “can and must” put backdoors in encryption, AG Barr says
arstechnica.com
arstechnica.com
If you want to be able to resist these assholes (e.g. having anti-war or anti-ICE meetings that aren't snooped on, enable whistleblowers, etc), you need secure communications. Don't give them a backdoor.
I work in a small company where I honestly believe everyone is trustworthy. Still it is a good thing that our users' passwords are hashed and none of our staff can decode them. It's a tragic example of motivated reasoning that the head of the Department of Justice doesn't get that.
There's another point to make here: Not giving individuals the keys to the kingdom protects them from being targets.
The government already has so many resources & advantages against individuals, groups and companies.
They don't get this one, too.
But I'm interested in what the constructive path forward is on the rather more important issue of ubiquitous encryption. I think most people generally accept that well-regulated wiretapping (and other forms of interception of communication) are a useful and important law enforcement tool. Easy-to-use, commodity encryption makes this tool mostly useless. But obviously any "back door" would be immediately leaked/abused, and more to the point would just be circumvented by anybody who really did still want privacy. You can't shut the stable door etc.
We do sometimes choose to outlaw useful and entirely legitimate technology because of the potential for abuse. Is there a reasonable argument for doing so with mass-market encryption? In reality, it seems that the public benefit of having encryption in place is so overwhelming that this is a total non-starter. Or is it simply the case that we now have to accept that this tool is no longer one which can be used? I think we'd have to accept that ubiquitous encryption is here to stay and stop trying to fight it.
The legal reality today is that while legally we broadly interpret things like "companies are people", we very narrowly look at "papers, and effects" as literal, physical objects. Equating backdoors with wiretapping is only similar on the surface. A traditional wiretap allows the police to hear a series of conversations. A backdoor in an iPhone or your Dropbox/OneDrive/iCloud account potentially allows the police access to the entirety of your "papers, and effects".
I would be willing soften my opinion on the issue, but only if there was a meaningful change in how the law protects digital documents.
An irreverent marketer could generate a ton of earned media out of this.
Me too. I would have thought they would have been in favour of very strong encryption.... Made from girders.
The cost of backdoors is measured in hospitals paralyzed by ransomware, personal information stolen by hackers, government secrets obtained by hostile nations. Not to mention the threat of pervasive surveillance by our own government, which has long shown it's willing to intrude on our privacy as much as it possibly can, laws be damned.
- The right to secure encryption is like the right to bear arms
- Government mandated weakened encryption are like gun control
- The victims of weak encryption (stolen data for example) are similar to innocents harmed by gun control? (I'm not sure on this one, please correct me if I'm wrong).
- Saying weak encryption is bad is like saying gun control is bad
I'm not trying to straw man you, if that's not what you mean, please correct me.
Also, I completely disagree.
Note: more plausible. You can easily point to examples where physical object distribution control has failed, and where information distribution control has succeeded (Prohibition and video DRM are the examples which most obviously spring to mind), but those cases are the extremes.
That's not to mention the business damage this would cause. The US is trying to block Huawei products due to back doors. Other countries will block US products if the US government starts requiring back doors.
No, and yes.
This is not cynicism speaking, this is realism. Basic principle of security is to make the cost of breaking the security greater than the value of what is being protected. In this case, the "backdoor" keys will be protecting many, many billions and probably trillions of dollars of worth of information. At that scale, a foreign (or domestic...) intelligence agency finding the n of m people necessary to get the key and making it clear that if they love their family, their personal well-being, or indeed, anything in the world at all, they will hand over the key information is completely on the table. It isn't even just that there isn't anyone who can't be trusted with the keys, there isn't anyone who can stand up to the pressure that can be brought to bear on them. Put the keys in the hands of the most honest person on Earth who literally can not be coerced into giving it up, and it just means their family is the walking dead until the agency finally gives up and murders our magically honest person, and the key falls to the next in line and they try again.
(Or, in other words, if this backdoor is created, and the people in charge of the backdoor and all their families are still alive in a year, yes, I would consider that proof positive it's already been compromised. The stakes are that high.)
These backdoors would literally be massively more valuable than the nuclear codes, which still require various physical access and other things to be penetrated to use them, whereas these will be immediately valuable simply upon possession. Even if we entirely ignore the question of internal trustworthiness of the holding organization, which we shouldn't, but even if we do, no conceivable organization consisting of conceivable human beings can possibly secure this information. It's just impossible.
(Also: Note the complete lack of reference to any technical considerations. It doesn't matter what the encryption algorithm is, or whether it's secure on its own terms, or whether the tech companies are being unpatriotic, or anything else. There is simply no way to secure any information this valuable.)
This assumes you have to knock on 2^256 bricks and not just wiggle the mortar free in one spot. WEP wifi encryption is an example of an implementation failure vs. theoretical time to brute force the encryption.
We simply can't let people legislate on issues they fundamentally don't understand. And understanding a backdoor is actually not that difficult - a smart, motivated person could literally learn the theory of this with some practical examples in a few hours of study.
I believe this is how Australia is going to have their backdoors.
I really don't know if people like Barr are arguing in good faith. But then I try to assume incompetence first and malice second.
This is an attempt to make sure ordinary people cannot have privacy, cannot be protected from either each other, other governments or this government, but wealthy people will continue to be able to buy that protection one way or another. It's a feudalist's proposition. You do not understand the motives without understanding the underlying ideologies. Not everyone can be a lord over their own data - it's a fact. Your data, peasant, is not your data! It belongs to your lord. And who the lord is case by case, it could be the government, it could be a particular corporation or a trade group of them.
This reminds me of the classic article about trisectors https://web.mst.edu/~lmhall/WhatToDoWhenTrisectorComes.pdf
Or drying water, or any number of other impossibilities.
Ice is dry water.
The government side of this is rhetorically, "we can imprison and kill engineers until one of you delivers us a flying pig, whether you still say that's impossible is your call." Some engineer is going to figure out how to meet their requirements. Pigs themselves can't fly per se, but when you get to discussing how far, in what direction, for how long, under what power, and the consequences of doing nothing, even flying pigs become a solvable problem. A technologist will say, "that's horrible, unethical, and wrong, you just ran those pigs off a cliff." Everyone else looks at the politicians and the guys with the guns and says, "See? Flying pigs." They also probably push that technologist over the cliff as well.
This is why they call politics the art of the possible.
What Barr is saying is that he plans to make tech companies accountable for his problems in justice. This kind of irrational posturing is probably a bargaining gambit on other regulatory areas or just an empty signal to rank and file law enforcement that the whitehouse and AG are on their sides.
[0] https://en.wikipedia.org/wiki/Triple_DES
[1] https://en.wikipedia.org/wiki/Advanced_Encryption_Standard
3DES was kind of a quick hacky extension to DES after it was found vulnerable to brute forcing in the late 90s to have something 'good enough' until a more suitable replacement was developed (which was AES). By the time any practical attacks had been developed against 3DES (Sweet32 from 2016 was probably the earliest) almost everyone had long since stopped using it other than in old legacy systems.
Firefox still uses 3DES to encrypt its password database though... it's probably not a major issue because all of the publicly known attacks on 3DES require gigabytes of ciphertext. Wikipedia has a 'citation needed' claim that "the whole 3DES keyspace can be searched thoroughly by affordable consumer hardware as of 2017" but good luck searching a 112 bit keyspace.
I certainly agree with your general point though.
Which makes them easy to find in a dragnet unless they're also using stenography.
I think this is just another step in a War on Change. Snooping was good when the bulk of the comms weren't encrypted, and cellphones could be confiscated and read because plaintext. Change to HTTPS, dominance of a cellphone company that isn't too compliant, and here's a change that needs to be reversed, to be stopped.
The tech community has repeatedly and thoroughly explained the impossibility of secure backdoors, but it is apparently a more difficult thing to grasp than 2+2=4, especially when one does not wish to grasp it.
--
[0] - They never do - they don't care, and it's hard to argue why should they care especially about this, over a million other urgent things. Media being saturated with outrage-inducing crap doesn't help push through the noise either.
This is the key point. Borrowing from Upton Sinclair,
It is difficult to get an authoritarian government functionary to understand something, when his pursuit of power depends on his not understanding it.
1) well, people just are too dumb / don't care enough / stubborn, we've done all we can and it is what it is
2) the message isn't getting through, let's try something different
At _some_ point, this quits being a failure of the tech community. _Some_ people simply are not teachable, because they refuse to listen. No "something different" is going to convince someone of something they don't want to believe.
P.S. You didn't say "issue" before, you said "failure." That it's an issue is indisputable. Assigning blame seems counter-productive at best.
I'd argue that it's actually giving the illusion of a working setup - not that the setup actually works.
It would be so much wiser to just keep quiet about that topic and rely on the neglicence of the common criminal - below the line there is a plethora of information in metadata and connection data, still incredibly better than anything law enforcement had 15 years ago.
The effect of any public advance into "responsible encryption" is only causing criminals to harden their tools.
This is such an asinine comparison. It's not like the cops have access to every locked door of every house in their jurisdiction. You don't need to build a special "cop door" into your house so they can come in whenever they want to, and you don't need to make an extra copy to give to the precinct. Why should my "internet house" be any different?
Is it not the case that he couldn't be legally compelled to share his PIN even if he were alive?
Criminal law is more binary, and a far stronger burden of proof on the claiming party, the government.
This is already the case in many states when it comes to vehicular traffic laws. Most speeding is a civil offense, no right to plea bargain, or jury trial. It only becomes criminal after a certain speed (careless or wreckless), and becomes criminal after a certain amount and time for the unpaid fine.
It's what happens when people in a democracy aren't paying attention to state and local law making.
Put them in jail indefinitely, apparently.
https://arstechnica.com/tech-policy/2017/03/man-jailed-indef...
> ""Forensic examination also disclosed that Doe [Rawls] had downloaded thousands of files known by their "hash" values to be XXXXXXXXXX. The files, however, were not on the Mac Pro, but instead had been stored on the encrypted external hard drives. Accordingly, the files themselves could not be accessed.""
A good guess can figure out what I've redacted.
If it's a foregone conclusion they can start a trial, if it's not they should release him.
Information versus material.
This is an excellent point. That is why do I not use biometrics on my personal devices. I honestly don't have anything to hide, but I also have no desire to give people the idea that it's going to be easy to fish through my personal stuff.
We say not to roll your own encryption, but it's one thing to build a lock that is easily picked, and quite another to build one that instantly and silently opens to a key held by a stranger, outside your supervision. Even if there weren't open source crypto projects out there, some managed on servers outside the US, just because I don't roll my own, doesn't mean I can't.
I wrote a paper while in high school on the Clipper Chip, explaining why it was a bad idea. I have learned a lot since 1994, and these folks have apparently learned nothing. Backdoors are inherently flawed. DRM is inherently flawed. You can't create security by trusting an untrustworthy party, or by declaring the intended recipient to be the eavesdropper, or by redefining up to be down.
Computers either have unbreakable locks, or no locks whatsoever. There's no stable middle ground.
Replace that with "locks that have yet to be broken", and I agree.
Just add a 'USGOV BACKDOOR' tab and password/encrypt it or whatever the fuck. It doesn't need to be a real control panel or anything other than trivial options (a grayed-out unchangeable toggle box that says 'Enable backdoor', for instance). I'm not the guy to provide you UI tips.
Let users understand it's there without relying on security-through-obscurity. Disallow any temptation to use StO and ensure users are fully informed of the government's firm and fatherly hand.
Yes, I know that the GUI/man page information are not 'the backdoor'. It is also not actually any functionality for the software you're using. It is function through abstracted symbols.
Protest via abstracted symbolism - visible and immutable vulnerability.
Yes, one can measure the cost of encryption like this, just like you can measure the cost of lax gun controls or automobile traffic by their fatalities (= negative costs). But you also measure the cost of encryption and lax gun controls and automobile traffic by their benefits (positive costs). If the balance is sufficiently in the positive, the negative costs might get accepted. There is no logical point, to only reason from one side of the calculation.
I never heard Barr say:
"The cost of privacy is measured in 'victims' who might have been saved from crime if law enforcement had put an officer in every bedroom throughout the country."
"The cost of lax gun controls is measured in dead pupils who might have been saved from death if legislation had passed stricter gun control laws."
On top of that, we now have years of SCOTUS jurisprudence that "arms" are absolutely subject to _some_ regulations, with the debate focusing on what "some" actually means.
Maybe you were looking for someone notable, but I'll make it for you right now.
I suppose such an interpretation would have the side effect of making literally any hazardous substance legal to possess.
"Your rental car payment is due."
"OK, I will pay it on Wednesday at 10am. Stop nagging me."
I would imagine that if enough people knew everything had lawful intercept, then they would just obfuscate their communications.
I'd bet all the tea in China that they drop the antitrust investigation in exchange for backdoors.
If these companies continue to base their businesses in large part on services, they will need a trusted cryptographic method for protecting customer information. If these companies regress into being strictly product and advertising businesses, what is the loss of value? And what kinds of businesses fill the void? And will those businesses even be based in the U.S. if the legal regime mandates backdoors for all businesses? Besides, on what basis does DOJ require only big tech provide a backdoor?
"If you're not with us, you're against us."