Rethinking Encryption
lawfareblog.com
lawfareblog.com
Re: the iPhone: when any country has the golden keys, every country has the golden keys. How hard is it to. Get that through your head. The moment the US demands golden keys, China is going to demand their own set of golden keys, followed by Saudi Arabia and any other foreign adversary. These keys are going to be used the same way the US is going to use them (spy on allies and enemies) as well as for seeking out minorities and problematic citizens.
As a foreigner, if something doesn't cross the US Senate of all bodies because of ethics or surveillance problems, that's really saying something. These are the people that brought us laws like the PATRIOT ACT and the CLOUD act, systematically expanding the reach of US law enforcement across borders. The EU, supposedly an ally, had to negotiate a quick, likely invalid or quickly overturned bandage treaty to make it legal to even just store personal data on US company servers. Is this what the US wants to become? A risk to their own allies?
Forcing weak encryption is not defence, it's offence. It's hard to believe that people like these aren't jealous of the spying network China has set up.
One thing the US has going for it is that unlike some countries, is that companies are more scared of their customers than the government.
What port knocking backdoor?
On a practical basis i cannot evaluate the jurisprudence involved and I would assume the number of people who credibly can is very small, especially in the context of "secret courts for national security reasons".
A useful test would be if any of those few had demonstrated a personal risk using this as a defense and succeeded. The rest of us can only guess the risk based on the reputation of the entites involved.
Remember the constitution only really, effectively, says whatever the current Supreme Court says it means. And really I don't think anyone want's the 100% literal 'shall make no law' interpretation of free speech; that would throw out any kind of labeling laws for starters, companies would have no government compulsion to accurately label drugs or food products for example.
I assume you mean two decades?
(unless I'm missing the point and you are referring to some specific fall-out from that event that had particular significance at a point ten years after?)
Yeah, that's not exactly the case...
huh? what's baseless about pointed out the 100% compliance of Chinese companies with the CCP?
What are you actually saying?
SURE. And they are all GDPR compliant as well.
Apple doesn't cut a custom firmware with special/additional golden keys or anything of that nature, as I understand it, for anyone.
The iPhone in this case is safe, assuming you don't use iCloud, in China.
But most people use iCloud, right? Apple forbids you from using competing full phone cloud backup services. The built in backup software continuously sends iCloud copies of most user data on the phone.
E.g. I would like the EU iCloud to be hosted in EU.
So a cloud service that's available worldwide should store and process data locally in every country (or perhaps even every sub-jurisdiction of every country) just so that that jurisdiction can serve warrants to it and others cannot? Or worse, people in multiple countries should have to use different services and hope those services interoperate with each other, just so that they can "shop local"?
The Internet does not and should not work that way. If we're going to go to the trouble of building interoperable, federated services, it should be to put them in the control of individual users, not in the control of governments.
Simply put, yes.
You are maybe concerned with the technical issues / problems to the service provider.
I'm more concerned with the decentralization, surveillance, and data sovereignty.
>Or worse, people in multiple countries should have to use different services and hope those services interoperate with each other, just so that they can "shop local"?
Yes. In fact, this decentralized nature, and resilience, was an early vision about the internet itself, and not just some hippie dream, even in its army-research origins... And of course all the way to ideas such as XMPP, Diaspora, and so on.
Nobody dreamed a Facebook silo somewhere gathering all the world's data...
>The Internet does not and should not work that way.
That it does not, it's obvious. That it should not, less so.
(And of course, if one's county is the one doing the data-gathering/policing of data for the rest of the world, it's "naturally" all A-OK to them that it is so).
>If we're going to go to the trouble of building interoperable, federated services, it should be to put them in the control of individual users, not in the control of governments.
Notice how I didn't propose putting them "in control of governments".
They already are in control of at least one government (the one of the country of Facebook, Google, MS, Apple, Twitter, etc).
So what I proposed is already de-centralized: putting each users data under democratic control in the places where they themselves are (and vote, have rights, etc), as opposed to a central place, where they don't vote, don't have any right or resource as foreigners and are "fair game" to the whims of both the service-origin government and the service company.
If they're going to go to control of individual users, even better. But stopping the control of a single foreign government is already a good first step.
(Exceptions could be made for non-democratic countries -- no reason to give control of a service's local data to a dictatorship).
Feel free to build such services, if you wish.
> You are maybe concerned with the technical issues / problems to the service provider.
Not just that (though I certainly don't consider it reasonable to expect a service to have thousands of servers in thousands of jurisdictions and deal with thousands of legal systems; frankly, I want services to expose themselves to as few jurisdictions as possible).
I'm concerned about the usefulness of the service to its users. As a user of a service, I will not accept partitioned and walled-off services where I cannot interact with people elsewhere in the world. That's my choice, and the choice of people and projects I collaborate with, and I choose to use services that allow me to collaborate with those people and projects.
> And of course all the way to ideas such as XMPP, Diaspora, and so on.
I did specifically say that:
If we're going to go to the trouble of building interoperable, federated services, it should be to put them in the control of individual users, not in the control of governments.
If you have the capability of interoperability and federation, then where you host your data should have nothing to do with jurisdiction, and everything to do with who wants to store and control the data.
Well, I don't propose or expect companies to volunteer doing this.
My point is that EU (for one) should mandate them, and if service providers like FB, etc, don't like them, they could skip the 500m market -- and just be careful not to let the door hit them on their way out...
>Not just that (though I certainly don't consider it reasonable to expect a service to have thousands of servers in thousands of jurisdictions and deal with thousands of legal systems; frankly, I want services to expose themselves to as few jurisdictions as possible).
As long as it's your jurisdiction? (assuming you're in the US, since it says on your HN profile that you work for Intel).
Or that's a happy accident (for you) that is not really relevant to your point, but others should be fine with?
I'd prefer the services I use to be under the control of my country's laws and my democratic vote -- not under what some third country dictates and controls.
Besides, hyperbole much?
There aren't "thousands of jurisdictions and legal systems". At worst, they are like 150 or so, as many countries. And some could get together and accept a single country as the host and set their common rules (like the EU could do for EU member states).
Major services already have tons of global CDNs servers, even on small countries.
And if there was a mandate, there could easily be an infrastructure and common services to deploy to span the globe (e.g. turn-key Amazon provision for sharding your data into multiple data centers per jurisdiction).
It doesn't even need to be all players, could be mandated on some size and above -- and surely Google, Facebook, Apple, etc scale.
No, not at all. I expect it to be the jurisdiction of whoever runs the service. That jurisdiction will necessarily have control over the authors of the service; there's no getting around that. (The authors can try to build the service with themselves as a threat model, which few services do, and even then that may not work.) Unless you want to mandate that people can't use services from outside their country (and enforce that with a country-wide firewall blocking access to the real Internet), then you're never going to get around that.
Also, you seem to be treating "store and use data locally" as a thing that protects the citizens of a country, rather than a thing that threatens the citizens of a country. Many countries want data stored locally so that they can seize it, and want services hosted locally so that they can block those services or make them consistent with the country's propaganda.
Also, you're assuming that data is nicely partitioned by user. For many useful services, it isn't. Just for the simplest case, consider collaboratively-edited works by multiple users.
> There aren't "thousands of jurisdictions and legal systems".
Tell that to states and equivalent sub-jurisdictions within countries. Tell that to many large cities and their local regulations. Thousands is if anything an underestimate.
> there could easily be an infrastructure and common services to deploy to span the globe
That sounds like a great way to introduce security holes and a vastly expanded threat model.
Also, to comment on something you edited into a previous comment:
> (Exceptions could be made for non-democratic countries -- no reason to give control of a service's local data to a dictatorship).
Who gets to decide that? Obviously not the countries themselves. That just leaves the people building the service and the people deciding which services to use; those are the same parties who already get to decide that today.
If you and a cohort were the last survivors of a dying tribe, with your own special language that no one understood, and you criminally conspired with them via written word, the government could not compel you to translate your messages just because they cannot understand them. That's the 5th Amendment in action, as you'd be creating testimony against yourself. The prosecution will have to pin you on some other charge, maybe a crime that you actually physically committed.
It's the same exact thing with encryption. It's a language that the government cannot understand, and cannot compel you to translate.
Now, to be fair, there is some wishy-washy here because the government desires not only to have compelled decryption, but to force companies to wiretap their own users. The later is not strictly a 5th Amendment violation - but it's the principle of the matter.
One day we'll have the ability to interface directly with our minds, and we need to draw the "stay the fuck out" line pretty damned clearly in the sand before that happens.
The reason this is a fight now is because you can target the chain. To use your analogy above: it is more like I know someone in that tribe and I send them a message in english and they translate and pass it along. On the other side is someone in the tribe who translates it back into english for the recipient. The message is never broken in its encoded form, only on the on/off ramps. Pressure can be applied to Apple or WhatsApp to provide access to the data pre/post encoding. This is what the Australia laws demands (and the inability to disclose the back door). The point remains the same, it is only as strong as its weakest link.
How can we know that WhatsApp hasn't been patched with a back door? What about the operating system? What about the secure enclave chip itself? The only hope we have here is that companies will say no and/or whistleblowers will speak out.
Ignoring the fact that it seems, uh, unwise to ask a defendant to provide an unverifiable translation of self-incriminating evidence (which is different from most encryption scenarios)...
I imagine that if this scenario were actually common and law enforcement was complaining about it, there would be a political debate, much like this one, except including "should we reinterpret or amend the 5th amendment to allow a court to order them to translate it", and a lot of people would agree with them.
Now of course many criminals in the past have written down coded notes that have been seized as evidence, but they're often somewhat interpretable or inferences can be drawn from them even if the defendant doesn't cooperate, which is not the same as your hypothetical, or something that's been AES or RSA encrypted.
I do take your point about how terrible things are going to get once we have brain-computer interfaces, which is a major reason why I think we shouldn't build them.
That's the problem with these rights: they're always up for interpretation. And the interpretation can be anything a handful of politically appointed people want.
Also to take it further, technically, the US Constitution does not apply beyond our borders (like any other US law, absent a bilateral treaty).
I fail to see the connection you are trying to make.
If you prefer to hear similar sentiments from one of saints of comedy: https://youtu.be/gaa9iw85tW8?t=261
The genie is out of the bottle: Powerful criminal enterprises will have no difficulty hiring people to build overlay tools that they can run inside their backdoored comms that will provide adequate (at least, if not effectively unbreakable) cryptography.
Even if we ignore the considerable first amendment barriers and there were an effort to outright outlaw strong crypto, steganography has become very strong and even if not quite sufficient finding out your comms were being monitored via a use of crypto charge is way better than having the attacker learn all your info.
In light of this, I find it difficult to see the goverment's position as seeking to widen infrastructure for the wholesale surveillance of the general public with claims of terrorist groups as a dishonest cover for the demands.
The old adage "If guns are outlawed, then only outlaws will have guns"-- has serious limits owing to the nature of guns as physical objects. The sentiment applies a million fold for cryptography, which is fundamentally a collection of ideas with a zero marginal cost of reproduction or execution, mass-less, volume-less, capable of being distributed around the world in a fraction of a second and implausible to silence even with great leap forward mass murder.
Actions to block access to encryption would severely degrade the security and privacy of the general public, on this point I agree with the author. But would it prevent pedophiles and terrorist from having access to encryption? Not likely.
Would pedophiles and terrorists occasionally screw up and use insecure means... sure, but they already do that today.
As discussed in following article, NIBOR also combats steganography: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3425957
Perhaps that's the point.
It doesn't make sense because why they want it isn't honest - even if they fully believe their own lies with a passion.
One meaningful investigative tool was (and still is) the wiretap, where access to the physical channel gives unencrypted access to the contents. Phone encryption is possible, but was generally used rarely.
It sounds to me as if investigators want to preserve some equivalent of this tool, although its existence in the first place was more of a technical limitation than a legal one.
However, "going dark" is not what's happening. Only recently had government has this much power to examine, catalog, and track the masses. Instead of debating the ethics of encryption (and trying to outlaw math), we should be debating how best to curtail and audit government powers to prevent their abuse.
The text I would consider manipulative with its references of a terrorist bombing. State actors suppressing dissent isn't mentioned at all.
It is not a black and white issue, but in most parts of the world, people would benefit from strengthening encryption even further. And I don't see that changing anytime soon.
I don’t think about encryption as a method to protect myself from the US government (only) but from any entity that is local or foreign. I think everyone should have the right to privacy. To me this is more important than the right to guns. And no not because I want to have illegal content, I just want to keep my information secure from people who don’t have a right to my privacy.
What am I missing? Should we give up our rights because there are people who break the law? Aren’t they going to continue to break the law anyways? Including using encryption.
This is like CAPTCHAs. Punishing the majority for the crimes of a very tiny minority.
Is this really the only way to catch people who do illegal things or is this just the laziest way to do it?
The 'going dark' boogeyman - how predictable. Only in the mind of a spy agency shill does the rapidly growing number of surveillance cameras, facial recognition, flying surveillance drones with high-resolution cameras over cities, and interception of all communication metadata (if not the content), equate to decreasing ability. They won't be happy until we are stripped of even the last tiny scrap of privacy.
That wasn't an ability of government in 1900 or 1800, so why should we worry that this new-fangled ability has been decreasing lately?
Who said it should be an ability for government, and much more, an eternal one, and not a temporary accidental capability due to a few technical developments that allowed it for a short span of time?
It's no wonder that most agencies have pretty much entirely dropped their expertise on this as soon as the alternative showed up. I don't think they are geared up to get back into that game.
Which they use all the time still, so that's not a real difference. It's not xor with digital surveillance.
Besides what you describe (double life, death, etc) would be a problem for the spy, not the general population. I could not care less about the spies.
But I wasn't talking about spying as much, but for government / police / etc surveillance. Where if they have to deploy humans to spy on some drug dealers or suspected murderer or whatever, is fine. And the fact that they're humans, makes it more costly to mass deploy (and thus serves as a natural check and balance).
> In my work at the FBI, I encountered directly how encryption makes it harder for law enforcement to detect, prevent and solve certain types of crime in specific instances.
Encrypted data is a known unknown. This doesn't work as an argument without speculating on the scope of unknown unknowns.
> I’m confident that this problem can be addressed from a technical perspective. In most cases, it’s just software, and software can be rewritten.
That works both ways. ( Source code for effective encryption is less text then this blog piece )
> the United States has not experienced a terrorist or other attack of sufficient magnitude where encryption clearly played a key role in preventing law enforcement from thwarting it
And i can't think of any realistic scenario in which it would. The window of cause-and-effect is extremely small. The attack needs to hinge on the tools that the US has authority over. i.e. Why would Osama use WhatsApp on an iPhone in the first place?
> inherently vulnerable network of networks
This is the wrong way around. Its a 'network of inherently vulnerable networks'. Which is the safest option. ( As the author later notes but doesn't reflect on )
If the government passes laws requiring backdoors in WhatsApp, terrorists can use another app. If the government passes laws requiring Apple and google to add backdoors to their phones, it will be almost impossible to avoid government surveillance. (And if the approach of the Australian government is anything to go by, we won’t even be able to tell this has happened. Instead they’ll pass a law demanding backdoors on request, then legally forbid Apple et al from making any of the details public.)
This is one of the reasons I buy phones from Apple. Unlike Google, Samsung, Huawei, etc they have at least made their opposition to government meddling very clear. And as this article points out in detail, they have put their money where their mouth is. If some of the sales price of my iPhone pays for Apple lawyers to fight for my digital rights, that is a tax I pay willingly.
I give Apple the benefit of the doubt and appreciate their stance, but with a legislative basis they too would have to comply.
I also think that professional criminals wouldn't use their phones in the first place if it is tied to their ID in any way. Sure, you might catch some of the riff-raff, but I think strong encryption is more beneficial for any form of security in the broader picture.
well as long as you can't easily build private fab out there capable of building such processors, good luck with that. There are not that many fabs out there. Fpga's aren't any better, since most of them you can't even make work without large quantities of proprietary blobs.
If your goal is to secure the entire internet via SSL or get people to use PGP signed emails in a mass market then the tremendous technical and cultural hurdles in place that create making a 'truly secure' implementation that gets widely accepted a near impossibility.
But if you goal is to secure the communication between trained people in a 'terrorist cell' or other small group then that is pretty easy. It's really as hard as you want it to be.
For example any decent programmer could write a program that utilizes a 'One Time Pad' of random data to encrypt communication. A program in a USB flash drive that is filled with randomly generated data and the program is all that would need to be exchanged ahead of time. The biggest challenge involved in that is making absolutely sure that the every section of the one time pad used is only used once and is destroyed afterwards. You don't need to really know anything about encryption or math or protocol details to make something like that work.
And if correctly done it'll be impossible to crack.
And we are dealing with threats and adversaries that are much more sophisticated then that. Even small terrorist groups are more often then not state-funded one way or another. Foreign threats are sophisticated enough to create their own encryption. Domestic threats and cartels are sophisticated to hire competent programmers to do work for them. Pedophiles are not idiots either. Many of them are talented technical people that will have no problem avoiding government backdoors in commercial software and hardware products.
The threats American face via encryption isn't that encryption is too strong. It's that Americans don't use it enough and don't use it properly.
I find the idea that Americans are under threat due to lack of backdoors a fallacious one. Legislating that backdoors need to put in place only increases threats.
The only thing that laws like that would accomplish is to make it illegal for Americans to be secure.
Take away legal ability to have secure software then it means that the only people who will have secure software is criminals. Criminalizing good software is never going to be productive.
Can you tell me what's wrong with that approach? In my head, it seems reasonable.
As a way out you can agree to a seed to a secure pseudo random algorithm but that's commonly called a password or pre-shared secret. In fact it's more secure to use just the string 'The Nth 4096 bits from this week's mod(N,100) top video on YouTube' as pre-shared secret.
<< Many of them are talented technical people that will have no problem avoiding government backdoors in commercial software and hardware products >>
Hand wavy as heck.
Then you meander. Not sure what you're responding to.
Furthermore it's practical to communicate in such a fashion that grabbing one party only grants you access to communication intended for this party.
If really paranoid it might only grant you access to communication between compromise and his fellows realizing that he is burned.
Maybe nothing at all if you can't successfully coerce and all devices are locked.
That is definitely not true if your adversary has the ability to control the endpoint and might even reflash the firmware of your USB stick.
If you use OTPs in such a threat scenario it's safest to use old school easy-to-burn paper OTPs with manual encoding/decoding.
You might get lucky if you have a cryptographer design you a custom algorithm but that's mostly security thru obscurity and if a state actor really wanted to defeat it they may just kidnap the cryptographer at gun point and have them reveal how to.
Cryptography as a weapon against state actors is NO LESS BRAINLESS than the right to bear arms to protect against the US gov. Just completely useless, if not brain dead.
Okay, this is the first time I can recall having ever asked the following:
Source?
I mean, if you're going to make that type of absolute claim, I must ask for some referenes to support same.
There is also good reason to assume that if e.g. you make your own Feistel cipher out of existing cryptographic primitives without caring too much about performance, then it will be secure enough against state actors.
Nowadays side channel attacks seem to be the rule, and there is no way to secure the endpoints without developing the whole technology in-house - which is essentially impossible even for organized crime. So the whole discussion is essentially moot, the FBI can buy 0-day exploits on the black market or develop their own like everyone else.
Or perhaps they are double-bluffing us? ;-)
Lets see your proofs demonstrating this
> Many would disagree strongly with the attorney general’s assessment that an acceptable technical solution to law enforcement’s problem—one that appropriately balances all of the equities at issue—actually exists.
> But, for the reasons discussed above, public safety officials should also become among the strongest supporters of widely available strong encryption.
Encryption _should_ be continued to be used, and used in a more effective manner across all communications. The net benefits of encryption outweigh the risks that these intelligence agencies complain about.
I may think of it as absolutely necessary, and Baker may think of it as a necessary evil, but if we two from very different worlds can both agree it is necessary, then it should be fully embraced.
As of secrets were something new.
“Society has failed to protect children”. No, man: they were never as protected as you purport they were. You are just rewriting history.
That kinda sums the article, but US Gov always finds ways to compel anyone to anything. Raw power. Takeaway is to be your own equipment manufacturer and service provider, as in cheap mini x86 boxes running open source daemons, over proxychains and VPNs. Rotate equipment, hacked wifi APs and identities monthly, use Signal on iOS and hide in the crowd, because if you're on the watch list, game is over. Cyberpunk at its best.
A beat cop knows there are many "tells" about what someone is doing. Similarly, one has to commit several crimes leading up to a terrorist act. Catching those before hand crimes is an effective way at stopping the final act.
And who is going to be investigating all the people with keywords in their texts? There are not enough cops in the US to do that.
If we use the net, there's a government file with a rating on how dangerous we are.
My blog on these issues www.cyderinc.net
https://www.c-span.org/video/?464971-3/attorney-general-barr...
"Only two ways to protect society ... 1) Ability to detect and apprehend criminals .. 2) Regiment society as a whole"
"Our ability to protect the public from criminal threats is rapidly deteriorating"
"Status quo is exceptionally dangerous"
Even if some of this gets unraveled and the worst actors get kicked out, people like him will still be active in local and federal government trying to roll back civil freedoms. It's rough. Hopefully the events of the past few years will act as a wake-up call for people who were previously willing to ignore what was already going on.
Highly-Secure Backdoors: Internet of Traitorous Things (IoTT)
https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3425957This guy was general counsel for the FBI at the same time they were abusing FISA warrants to secretly spy on Trump admins. You think they’ll stop at Trump? They’re just getting started.
We need to get back to our roots of being extremely careful about our intelligence agencies.
I know you’ll initially be turned off by the subject of the below article, but definitely read it. For the sake of our civil liberties, the leash of our intelligence agencies must be kept short.
https://www.theepochtimes.com/spygate-the-inside-story-behin...
Also: the article actually comes out in favour of strong encryption. How does that fit with your worldview?
Other than cock-blocking ISPs, what's the value in end-to-end encryption when one of those ends is a megacorporation that is A) super-friendly with the state security apparatus, and B) ready, willing, and able to sell you out to the highest bidder? E2E works great against basement-dwelling h4x0rs, not so much against people with actual power.
I know these companies will swear up and down how secure they are--but security of what? Who audits them? Last I checked, no one.
Say I want to block such-and-such domain. With unencrypted DNS, I put a record in my own resolver, and problem solved. With per-app DNS over HTTPS, my infrastructure is out of the loop, and SV has total control.