It is not possible to have secure by definition communication and facilitate a backdoor at the same time. The two concepts are strictly mutually exclusive.
In the United States you have the amazing freedom to communicate in any language you desire (including one unintelligible to a would-be snoop), and the State cannot force you to translate your communications just because they want to hear them. We should not be so eager to give up that freedom in our digital lives.
Courts say otherwise sometimes, but they have to use twisted, convoluted reasoning that doesn't really stand up to the written letter of the constitution. Given that nothing more we can do in the constitution is immune from that either so what is the point of another amendment?
Waterboarding was treated as a crime by the US during WW2:
* https://en.wikipedia.org/wiki/Waterboarding#World_War_II
And then conveniently it was not a crime after 9/11:
* https://en.wikipedia.org/wiki/Waterboarding#Classification_i....
Access to the escrowed keys may also be conveniently reclassified in the future.
And that assumes that the law is even followed: you can't trust that the "court ordered access" will remain only court ordered. Law enforcement agencies have violated laws in the past as a matter of policy:
Yeah.
- Obviously you can't reuse the same master key, so now you need 180+ keys, meaning 180+ backdoors into the system. It is ridiculous to expect that all of these will remain secure; the United States can't even secure the OPM database so even ours will probably be leaked, and countries with more bribe-prone law enforced will give it up even faster, and now everyone is pwned.
- Law enforcement are frequently the bad guys. YMMV on how often this is the case in the United States but it's certainly inarguably the case in many places abroad. Mandatory backdoors means no possibility for secure communications about dissidents and "inconvenients" in those countries.
Universal escrow == universal access. Leaking == global compromise.
There's a place for personal recovery key quorums, where multiple parts are joined to create an alternate recovery key, but that involves key management for each such key served, which is a Very Large Problem.
Might be possible to take it on, but the underlying problem of identity remains: The question "who are you?" is the most expensive one in information technology. No matter how you get it wrong, you're fucked.
Deny access to the right party: fucked.
Allow access to the wrong party: fucked.
The only advantage of security-based DoS over security-based unintended dislosure is that denied access doesn't propogate. Published data cannot be unpublished, at least not at any reasonable cost:assurance level.
Because of the key management issues, most seriously-proposed data-backdoor systems revolve around one or more of:
- Workfactor reduction in which known keys or values are used in key generation. The resulting keys are weak where the known inputs' secret elements are known, at least to state-leve actors.
- Specific escrow keys. No workfactor, just key access. Widespread key access is a Very Bad Day.
- Specified access accounts. Like above, but worse.
- Specific system bypass. Alternate paths to data access on systems.
- Alternate data submission. Various "phone home" or intercepts of in-the-clear transmisions, either through design or software/device compromise.
As a practical matter, alternate information channels (usually metadata), public data, standard detection, bug/zeroday exploitation, and various sideband attacks (Maginot compromise: don't go through, go around) tend to be used, though cryptographic attacks have some utility.
1. No one trusts the government not to abuse such a power. "Only usable with a valid court order" my ass.
2. The government doesn't trust citizens not to change around the escrow keys used (which would prevent them from decrypting things)
You can already do that by voluntarily providing access to your devices to anyone you want, including law enforcement. Other people don't necessarily share your ideology and accept that there could exist "legitimate law enforcement searches" of their private communications.
2015: https://cryptosense.com/blog/the-untold-story-of-pkcs11-hsm-...
2017: https://cryptosense.com/blog/infineon-rsa-key-generation-bug...
2019: https://cryptosense.com/blog/how-ledger-hacked-an-hsm/
Stop trying to build scenarios where key escrow solutions are technically sound. They are not. This is an intractable problem that is not solved by these half cocked technical measures. Key escrow cannot by definition be secure, and wasting time trying to invent solutions just confuses the matter, weakens security and leaves us all vulnerable. Basically, Sssssssh, or the politicians might actually believe this fantasy.
On paper, sure. In practice, not so much.
Because "we've" spent decades trying to figure out a method that will actually work, and universally failed?
Governments have shown time and again that they abuse any power they get - I wouldn't trust them with this.
This story should be repeated whenever anyone brings up 'solutions' involved with key escrow. Bruce warned us in 2006 this was a backdoor, ten years later, we find that not only was it implemented by Juniper, the backdoor was backdoored by unknown (and potentially malicious) actors. Really, this should be the last word on why this key escrow and general cryptographic backdoors are a terrible terrible idea.
In other news giving someone root access to your machine gives them root access.
What if you simply claim to encrypt it twice, but instead place random noise wherever the "encrypted for gov't" data should be? If the system works as intended, it shouldn't be possible to attempt decrypting it (and thus verify if you encrypted it properly) without a search warrant based on probable cause, as the key material would be in escrow and not accessible to anybody including law enforcement and intelligence agencies before a warrant is served.
So you can't have proactive detection of that and everybody who wants to ecrypt communications with criminal intent can and will continue to do so with the same consequences as right now, where they can be pressured to reveal the keys but their communications are otherwise secure; the process would risk the privacy of honest citizens (in case if the escrow system is broken) but not hamper the bad guys at all.
I'm assuming that bad guys can modify the software they use, which seems to be a reasonable assumption supported by practice.
And given the proposed rules of key escrow the government has to assume that they use it as-is, because doing traffic inspection to ensure that they really do so is impossible without a specific warrant, so whenever they do get a warrant and get the keys out of escrow, then that's the first moment when they can tell "ah, we actually can't decrypt Bobs messages because he's not using that key".
So the proposed naive system of simply "encrypt the message twice so that either the intended recipient or the government with 5 HSMs can decrypt it" won't work. You can have a more complicated system that works around my objections above, but that would be a different system that will also have other drawbacks. Cryptosystems are very hard in general, all small details matter, a random proposal that hasn't undergone significant expert analysis has almost 100% chance of being fundamentally flawed, and doing reasonable escrow will have all kinds of "interesting" consequences and potential attacks, I am not aware of any public proposals for the specific details of a mass-escrow system that would have reasonable consequences.