Republicans Push Bill Requiring Tech Companies Give Encrypted Data
cnet.com
cnet.com
> The bill also allows the attorney general to create a competition with a prize for anyone who can come up with a way to access encrypted data while protecting privacy and security. Security experts have long noted that this is an impossible request.
Why they're at in, why don't they push a bill for permanent rainbows.
Also, the article states "The proposed legislation stops short of requiring tech companies to create a backdoor", so if end-to-end encryption is still available, this legislation does nothing. And if lawmakers try to ban end-to-end encryption, well then "banning math" should be the name of this legislation (yes, I realize politicians have tried to do that before). Sure, large companies may comply and average joes may get less E2E encryption, but anyone who knows anything about tech will be able to get access to E2E encrypted messengers.
> The laws of Australia prevail in Australia, I can assure you of that. The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia.
This particular statement was widely lampooned in tech circles at the time as obvious nonsense. Yet it’s actually perfectly sound: legislation is all about restricting you from doing things that are possible. (Now some of the other stuff Mr. Turnbull said at that time was drivel; he seemed to be under the impression that it was possible to allow law enforcement to access end-to-end encrypted content without it comprising a backdoor, which the industry as a whole considers axiomatically false.)
It’s the government’s prerogative to ban mathematics. And indeed they already have in various areas due to copyright and possibly patent laws (c.f. illegal numbers). Now I personally think they would be unwise to ban any form of encryption, but realise that they’re quite at liberty to not just try to ban it.
Quite. I guess it also makes perfect sense to ban water from flowing down hills. It's possible, after all ...
The reality is some of their laws have already been torn apart. Australia used to have one of the strongest censorship regimes of any democracy. They gave only up after passing the silly things when then banned computer violent games, in an age where everybody bought them from an overseas online store. I think the kids must have blinked in disbelief at the stupidity of their elders, then returned to their game pads.
Then there are laws I really would like to work - like the anti spam laws. I'll lay odds the head of the Federal Police gets spam addressed to him every day. I hope for his sake it's blocked by technology, because it sure as hell isn't stopped by any of the laws they passed or his police force.
People aren't lampooning the idea the government can't ban whatever they want. They are laughing that in an age when encryption algorithms are form the core of ecommerce, are published on Wikipedia, thousands of web sites and government standards, the government is claiming banning them will have any more effect than passing a law saying π is 3.
It was an absurd statement. Moreover, Turnbull knew that, and didn't appear care. Which means it was pure bullshit. I'm guessing it was dog whistle to the crazy right that had sway in the party at time.
How else will police fund their new cars [1] or arrest the new boyfriend of their ex [2] ?
My point is that the government sees no problem at all with the potential for large scale abuse of government access, just like they don't have any serious safeguards against abuse of existing ones, for example, holding physical keys (for example, would you consider using emergency keys for entering a girls' dormitory and forcing everyone in the hallway to "check for lockdown laws being upheld" a perfectly legal precaution. And if they do it for such absurdly juvenile things, what hope is there for them to do better under pressure ?)
[1] https://www.aclu.org/issues/criminal-law-reform/reforming-po... [2] https://psmag.com/news/stalker-cop-police-protection-danger-...
So I propose a trade: any time Australians want to mock politicians we’ll refer to the Indiana Pi bill, any time North Americans want to mock politicians they can refer to “the laws of this country not the laws of mathematics”.
Noting that this was not about banning the possible but making the impossible mandatory.
A prize for a cake that can be eaten but will never be consumed.
It's possible but potentially expensive and has issues with who gets keys on international communication. And it's also dumb.
You know, this could be a total political cover move. Pass some bill that makes it seem like tech companies will open comms to law enforcement, but make sure it doesn't actually work. Then, you can campaign on being tough on crime in November, and if somebody ever brings up the topic later, you can blame the biased big-tech firms for not wanting to work with Republicans.
So encryption tech can't deliver permanent rainbows, but the politicians get them anyway.
Government attorneys show up to court after some poor citizen spends a ton of money on legal fees to challenge a bad faith law. Worse yet, some bad faith laws are crafted in such a way that no (living) person has standing to bring it to court to challenge the statute.
We are all lazy. I can use gpg, but how often am I going to do that? The NSA won't have access to the recipes that my brother sends to me, but aside from that, they'll get everything.
To bad for them, though. They'd be better off with the recipes than the rest of it.
If you have a lot of sophisticated and non-lazy criminals, my guess is that there is something very wrong. I'd like to know more about these characters and what kinds of crimes they are committing.
Of course the data would still be hackable if a bad actor were to get their hands on both of those keys, but security could be increased by, for example, increasing the number of parties needed to authorize the access.
(Please don't critique the ethical premise here - I make no claim that this is the "right" thing to do, just that it could be plausible)
Because, eventually, they'll leak. Security and intelligence agencies have lost keys and hacking tools and top security documents.
And when they leak, the surface for what you can exfiltrate before the keys are rolled over will be _everything_. If you can roll over the key.
Microsoft leaked their Secure Boot key once, and it wasn't possible for them to fix that on all of their devices. Whilst that isn't a particularly concerning leak, that changes if what it was protecting becomes someone's personal information.
To protect against a leak that compromises everyone, everywhere, you'd want the government keys to be unique per site and company. Which would also incidentally make securing those keys harder and lead to more leaks.
And that's before you question whether the people with access to the keys are actually trustworthy and won't do what law enforcement have done in the past, like stalk their ex.
It's a no-win situation.
All of them will leak? Seems like if each key is in possession of a different party, and you need all keys to decrypt, and at least a few are air-gapped only available for warrant holders via manual retrieval... the probability would be vanishingly small.
I agree it's impossible in theory, but in reality nobody has put out significant resources and made an honest effort to try, imo.
I bet I could come up with an encryption scheme that allows decryption for warrant holders only, but the scheme to decrypt will be very onerous for the warrant holder and will require manual retrieval of air-gapped asymmetric keys and lengthy background checks to establish trust (i.e. is this person who they say they are and did the judge really grant a warrant, etc.).
There are always tons of assumptions we make when we say these things.
We assume that the computer used to generate the keys was never connected to the internet, has not already been compromised at the time of key (re)generation, there are no backups of the computer, the engineer that performs the key generation is extremely trustworthy, the room this is done in is perfectly isolated from surveillance, etc. If you start calculating these probabilities and multiply them together, you start observing them moving further and further from 100%.
> but in reality nobody has put out significant resources and made an honest effort to try
These just seem like No True Scotsman fallacies. If anyone comes up with evidence of an effort, are you going to move your goalposts?
IMHO, the incentives don't exist. Law enforcement can't even secure their own technology and vendors (eg. BlueLeaks, OPM hack). The tech companies tasked with this project only see it as a cost center and see it as a potential massive risk to their brand if this system is misused. During the Snowden leaks, there were accusations of NSA contractors using the search system to spy on family members, dating partners, etc.
Human behavior is too predictable to naïvely assume that we can increase security while increasing the number of keys/people who have access to a massive tranche of data.
The nature of the federal executive is a problem here: keys spread among federal agencies are functionally in the hands of one party.
But I agree, it's a perfect example of why we can't trust even the most security-trusted people in the US government with skeleton keys to all of our data.
You can add whatever extra bureaucratic processes you want, but you're still making my encrypted data less secure.
You say that like there isn't form. The keys used by every DRM scheme has leaked. Every one. It was not from lack of trying, not because they didn't have access to the best and the brightest. HDMI was actually pretty good.
The problem is not just technology. It's also humans. Create a big enough prize for obtaining a single thing, and it will leak. Every man has his price.
When the prize is the ability to read every communication of every USA citizen, politician and corporation, if you aren't thinking about what sort resources nations like China and Russia can throw it at, you aren't thinking hard enough.
Whilst in theory ideas like these work, they don't in practice.
When security is tightened, and oversight is made more difficult, we regularly see the players involved skirting the system because they're human and don't think that they're really doing anything wrong.
Stuxnet was a while ago, but pierced an air-gapped network through a means that... Shouldn't have been possible. It was possible because of the failure of the humans involved. A factor that can't be removed.
You would find keys being surreptitiously shared over insecure shares, and getting caught up in other data leaks. Two or more departments sharing keys between employees to save some time and effort. Or forgetting to shred a key securely once it has been accessed. It doesn't take long until everyone in the department ends up with a key - and then each of those is a weak point.
The NSA has had repeated problems with their processes being avoided and ignored by employees skirting oversight to stalk their ex's, by doing things like listening to their phone calls - which supposedly required a warrant. [0]
You can't trust the people involved.
Now, there's a very, very simple way to avoid all of these problems. Secure the data to the fewest number of people required. Placing the responsibility of keeping the keys secure with the direct stakeholders.
An end-to-end encrypted chat still has the possibility of keys being leaked. But only the people who will be directly impacted are involved. You don't need a large and complicated scheme, and it is dead simple to implement, comparatively. You only have to trust the people involved, not swathes of departments.
A far simpler solution to this problem would be to change the law to mandate disclosure of encryption keys / passwords if served with a warrant. I don't agree with this either, but at least it's more elegant than what is being proposed.
Could you argue the stress of going through the legal system made you forget your twenty word password?
Not "if", "when". It will happen, and as soon as it does, everyone's privacy (for previously encrypted content) is gone forever. It is impossible for me (and I think a lot of other people) to imagine the government can keep those keys secret for a reasonable period of time, nonetheless forever.
• https://en.wikipedia.org/wiki/Shamir%27s_Secret_Sharing
• https://cs.jhu.edu/~sdoshi/crypto/papers/shamirturing.pdf
I agree with the sibling commentators though that it just isn't strong enough to withstand a threat model of "people motivated to get the master key to vast amounts of encrypted communication". Even if such a scheme couldn't be cracked algorithmically, it wouldn't hold up against the relentless social engineering efforts that would be thrown at it.
Or, more likely, people charged with protecting the master key being negligent.
One of potentially many examples: https://www.renderlab.net/advisories/mta-key/
For instance, with functional encryption, you are able to distribute or derive keys that have a very specific functional purpose and leaks no other information. Basically it allows you to derive a "function key" that basically computes f(x) for you given an encryption of x. As long as the crypto is strong, no other information about x is exposed (only info about f(x) is revealed).
With the right system architecture, this would allow the government to perform a very specific, pre-defined query to check for illegal content without exposing any additional information about the encrypted data.
Another approach you could use is based on zero-knowledge proofs and verifiable computation. Essentially a government could come along and ask you to provide a proof that your encrypted data does not contain malicious content. Given a program that can check for what they are looking for, you can provide them a zero-knowledge proof that convinces them that you correctly ran their provided algorithm on the suspect data and that the algorithm did not identify any malicious content. In this process, no other bits of information are exposed or handed to the government other than the data is not malicious.
Scheme: multiple copies of symmetric key followed by symmetrically encrypted body (pgp-style). One copy of the symmetric key is secured by user's private key, another is wrapped in an onion of all required "side" keys.
The issue is that the government-held keys only need to be exposed once, and then someone has a key to all of everything, everywhere.
The US government couldn't even keep the most sensitive information about its personnel secret, see the OPM breach: https://en.wikipedia.org/wiki/Office_of_Personnel_Management... The Inspector General had warned Congress of "persistent deficiencies in OPM's information system security program" and nothing was done. This resulted in some really sensitive data being exfiltrated, probably some good blackmail info. The US government has not done a great job even protecting its own employees.
The biggest problem here, though, is incentives. A government cannot be sued, or suffer any other negative impact, if it accidentally loses keys that lead to others' death, blackmail, or job loss. Too bad, so sad. If tomorrow it becomes illegal or unacceptable to do something that today is legal, a government can retroactively punish those who engaged in it. In short, the government has no strong incentive to protect the keys, only you do.
It's easy to enable a third party to read encrypted data, simply give them the key. That is not and never has been the problem.
The problem is ensuring that only authorized uses occur. There is no algorithm that can determine good guys from bad guys. Keys are notoriously hard to keep secret. Any mechanism that tries to transmit them now adds a third party, and we have enough problems trying to keep things secure when they're only two parties. Storing them securely is highly improbable to occur in practice. We cannot even store simple data securely. The OMB breach showed that employees were unwilling to apply basic security practices to protect data about themselves... why would they securely store data when they won't be hurt? Splitting them helps a little, but it doesn't solve the fundamental problem.
And this ignores the fundamental problem that groups like terrorists can simply use a different algorithm. When somebody says please think of the terrorist children, they assume that somehow they will use the bad encryption everyone else is stuck with. If someone is willing to violate one law, they will be willing to violate another.
I am not sure how you got this from conversation above. Still sounds impossible to me.
Problem as stated is, that if skeleton keys are broken, then everything everywhere gets broken.
The fact that government has bad initiatives to keep keys secret, just means it will be easier for bad actors to steal them. But that is just a side argument.
When discussing encryption, many people say that this is an impossible problem to solve because of math. This conversation has shifted to being a problem about incentives. Math is impossible to change. Incentives are changeable. If the only problems here are the specifics of the scheme and the incentives of people involved, those are solvable.
>Problem as stated is, that if skeleton keys are broken, then everything everywhere gets broken.
Which is why you build redundancy into the system that would require multiple independent breaches and a system to reencrypt data in the event of a breach.
It's still a math problem in the end.
Today if you want to break into someones encrypted data, you either have to break encryption algorithm (which is hard and by hard I mean even stuff we consider insecure like 3ple DES are still not broken) or you have to break each data individually.
With skeleton keys that changes. Suddenly all the world secrets are one* key away. That is the big difference. Doesn't matter how you do it, it fundamentally changes the equation
And you open up HUGE attack vector, by enabling bad actors to bribe/coerce people with access to skeleton keys.
* Doesn't matter if you split it up, have different org have parts of keys etc.
During usage, all pieces of master key will have to be brought together into one place (phisical or virtual), so eventually still only one breach is needed.
If I encypt data using encryption without backdoor, then to illegitimately get clear text requires effort X, and it gives access to 1 persons data. If whole country encrypts data using backdoored scheme, then effort Y will give access to data of 100 000 000 people. It would seem that security of the backdoor should be 100mil times stronger then that of usual crypto.
By allowing anyone to encrypt a file to the government's private key, you're vastly increasing the chances that one of these attacks goes from infeasable to easily doable.
Right now, if someone were to find a chosen plaintext attack on AES, they could find someone who will encrypt things with their key, get them to encrypt the chosen plaintext, and then break other things that person had encrypted.
If we used the proposed system, then the chosen plaintext attack would allow me to encrypt the plaintext on my own, and then use it to break everything in the world that was encrypted.
It maybe be technically possible to make such a scheme, but due to the unitary executive, keys split among N government agencies have the same essential practical security as 1 key held by one counterparty, and one counterparty that has no particular interest in the security of your data. So this fails the “preserves security” aspect for the same reason that any system that enables government access must.
Well, with current encryption techniques this is impossible, but depending on what is meant by 'access', there are certainly ways of encrypting data in such a way that it maintains privacy while still being able to question if the data contains knowledge of certain things.
For example, you can have a child pornography machine learning detector that operates over completely encrypted data via homomorphic machine learning. You can also use zero-knowledge proofs to ask a properly stored piece of data whether or not it contains a particular fact, without actually having to read the data. Depending on what is meant by 'access', this is a reasonable request.
Requiring homomorphic encryption of encrypted data channels while government overreach perhaps, seems like something that can satisfy both a desire to have encrypted, unencryptable data, while still being able to examine the data in flight.
> Bad actors exploit warrant-proof encryption to shield dangerous and illegal activity —including terrorism, child sexual abuse, and international drug trafficking — from authorities.
Bad actors also exploit warrant proof use of their voice to send sound waves directly at other bad actors ears to shield dangerous and illegal activity —including terrorism, child sexual abuse, and international drug trafficking — from authorities.
I realize that end-to-end vs speaking verbally is a bit of a leap but bills like this make it seem like they don’t want US citizens to have a voice.
https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
I guess money-launderers are no longer on the target list. Too much of a white-collar crime, these days.
The fact of the matter is some parties (by which I mean groups, not political parties) have an abiding interest in keeping strong encryption and privacy out of the hands of the population at large. Banning E2E encryption either outright, or through the backdoor (EARN IT act) from major Internet platforms will accomplish this. Therefore, arguments like "You can't ban math" or "The real criminals will just move to platforms that use E2E encryption" don't work.
What's worse, they try and pass these laws using Think of the Children[1]. It's tested, and effective. It works because it's an emotional appeal and most voters are emotional creatures (including me, and you). Like a popular Internet meme says "You can't reason someone out of an opinion they didn't reason themselves into."
Fortunately we can (honestly) use Think of the Children to fight back. Literally every child in the US uses the Internet to chat with their friends and send pictures, write their journal, do their homework, get their grades, and communicate with their doctors or therapists. Weakening encryption therefore endangers every child, risking exposing their innermost thoughts and conversations to the worst sort of people online.
We have to start couching this issue in terms that regular people understand.
"Would you lock your backyard gate, where your children play, with a TSA lock?"
"What if your pediatrician's office told you their doors and file cabinets have a TSA lock on them? Anyone can just buy a key on Amazon, walk in, and rifle through everything they have."
I honestly worry about a future where my children have no privacy. Where any online predator can potentially access everything they say, send, post, or do online. That makes me anxious and frankly, a little angry.
Unfortunately, it is almost impossible to use this tactic to advocate in favor of something (rather than against it).
I wish I had a suggestion for how to parry the accusation, but I don't.
Without a law like this, we're just going to keep fighting the same battle every 4-6 years. They only have to win once, we have to win every time. It's not a fair fight.
I happen to believe that it was protected by the first, fourth, and ninth amendments, but I am not sure it is possible to erect permanent legal bulwarks against ever-expanding federal powers. As an example, the second amendment specifically enumerates gun rights, yet it is under constant assault. The only way I can see to protect this type of individual liberty would be to radically de-scope the federal government, but I don't think that's going to happen.
Again, I really wish I could be more optimistic, but I just don't see any realistic hope.
Think of the LGBT children who may want to speak to a safe and established community / therapist confidentially about problems in an abusive household which rejects them for what they are.
Think about all the children who may need counselling during the COVID-19 outbreak who do not need secrecy from family but can't physically attend and don't want strangers peeking in.
"Think of the children that want to embrace $RELIGION but happen to live in a den of $DEITYless liberals."
"Think of the children afraid to express conservative views online because of a lack of privacy protections."
Case in point, a similar bill (as I understand it) - The EARN IT Act was spearheaded by the same people as this bill, plus Dianne Feinstein (Democraft of CA):
"The EARN IT Act was introduced by Sen. Lindsey Graham (Republican of South Carolina) and Sen. Richard Blumenthal (Democrat of Connecticut), along with Sen. Josh Hawley (Republican of Missouri) and Sen. Dianne Feinstein (Democrat of California) on March 5."
https://www.theverge.com/interface/2020/3/12/21174815/earn-i...
Also:
Hopefully the won't category will be much larger than the will category, but I doubt the support will be exactly along party lines.
This is the real problem with america. Not that one party is evil but that both parties are, there is no choice.
When it comes to issues of money in politics (e.g. campaign finance), issues of government transparency (e.g. financial disclosures), or environmental protection, the differences are night and day.
You do have a point about civil liberties though. Both parties have become pretty extreme (on opposite sides of the ideological spectrum) about where to draw the line between acceptable/unacceptable discourse. I fear that the Dems have become too toothless to take on big tech companies due to the vast sums they receive from said companies. Nevertheless, anti-cryptography legislation still seems to be the GOP's play these days. The Dems of the 1990s are hardly equivalent to the Dems of 2020, especially with an ascendant activist wing running more and more of the show.
"Well, we have to at least look like we're fighting for them. If we all just agree to protect the Bill of Rights, then we aren't really working for them. How about Democrats get 4, 5, 7, 8, and 9; and Republicans get 1, 2, 3, 6, and 10?"
"Hey, why do we get the Third Amendment?"
"It was our idea."
(This comment is not meant to be taken literally and I'm sure that others will have a different mapping between Amendment numbers and parties.)
The people endlessly fight amongst themselves as the rich get richer.
Divide and rule.
How does breaking encryption get them closer?
https://www.washingtonpost.com/nation/2020/06/17/boogaloo-st...
Most of the stories I've read about terrorists and mass shooters report that they were using bog standard instant messaging, unencrypted e-mail, and social media. Most of these people are not highly technical and do not practice good opsec. Hell Dread Pirate Roberts was pretty technical and still got busted because of bad/lazy opsec, not (as far as anyone knows) because encryption or Tor were broken.
The child porn thing is a bad faith argument too. Child sexual abuse is under-investigated and under-prosecuted already even when the information is there or when actual reports are made. (Adult rape is under-prosecuted too.) They don't do enough to go after child predators using existing tools, so why would more tools matter?
Large amounts of child porn detected equals platform being used on similar scale for producing it / distributing new content / grooming. By playing with equivalence, you can push for tougher policy.
It is under-prosecuted for frankly embarrassing reasons. Tech companies can't submit it on the spot. They have to wait for them to come to them, and have to delete it if they take too long.
Isn't that already required? If someone shows up with a warrant (presumably signed by a judge and listing the particular things being searched), then basically you need to do everything you can to help them (as you should). Subpoenas are a little different and there's more room to argue about them, but are also important in general. Regardless, if it's encrypted and you don't have the key, then it's a dead end and that's the way things go.
So what is this law really doing? My guess is that it's actually asking tech companies to do something in advance of any specific criminal act, that would somehow preserve private information or prepare it so that it's easier to comply with hypothetical warrants that might be issued in the future against anyone on the platform. That's really a different kind of thing than just assisting in carrying out a warrant.
"Senate Judiciary Committee Chairman Lindsey Graham (R-South Carolina) and U.S. Senators Tom Cotton (R-Arkansas) and Marsha Blackburn (R-Tennessee) today introduced the Lawful Access to Encrypted Data Act, a bill to bolster national security interests and better protect communities across the country by ending the use of “warrant-proof” encrypted technology by terrorists and other bad actors to conceal illicit behavior."
https://www.judiciary.senate.gov/press/rep/releases/graham-c...
I haven't read the exact text, but to me 'ending the use of “warrant-proof” encrypted technology' means banning end-to-end encryption, not just "requiring the assistance" of technology companies.
And according to Eric Geller, who is one of the main cybersec reporters at Politico, it DOES require backdoors:
https://twitter.com/ericgeller/status/1275813434123186177
"shall ensure the manufacturer has the ability to provide the assistance"
Only to a certain extent if the warrant is being served on the company, i.e. for access to data that they are storing. This sounds like it adds hardware manufacturers who aren’t a party to the warrant, and would also likely require cloud providers to give technical assistance (rather than merely hand over data). The main idea probably being to force Apple to develop a reliable way to break iPhone passcodes (something law enforcement has been unsuccessfully trying to get for years).
> My guess is that it's actually asking tech companies to do something in advance of any specific criminal act
That’s right. From the press release:
> In addition, it allows the Attorney General to issue directives to service providers and device manufacturers to report on their ability to comply with court orders, including timelines for implementation.
In the worst case, this would effectively prohibit un-backdoored encryption capabilities in devices and cloud services in the US.
The key thing being the law enforcement agent has to present their warrant to the suspect.
As to the protection afforded by a password, a house is protected with a lock and ordinarily someone cannot compel you to grant them access, which is what the warrant is for, stating that they have reason to believe there is evidence on the premises.
If we want to say, "But unlocking a door doesn't require speech while telling someone your password does" then fine, silently punch that password into the device.
Mainly I'm looking for problems with this in the vein of "If we install backdoors into our software, that compromises security for everyone and grants unprecedented surveillance power to the government". A hand-delivered court-issued warrant to the owner of an individual device seems like a promising compromise to let law enforcement get on with investigating specific crimes without broadly crippling everyone's security in the process.
There are so many open source crypto tools out there with no backdoors that anyone savvy enough to find them and use them will do so.
Of course the average user probably wouldn't care enough to do that, but maybe a few privacy scandals could change all that.
edit: *leading to arguments like "Oh, you have Signal on your phone, only criminals use Signal."
https://www.techdirt.com/articles/20140501/01194327086/supre...
Like, what problem is this solving? Are there tons of criminals that are running wild, and if only we had their secret correspondence we could catch them?
And is social media not already some huge gift to law enforcement? Forget about tapping an encrypted line, just follow them on twitter.
There's no need to weaken the encryption at all when end-users don't actually control the software they run day-to-day. Just replace the software while they're asleep.
Nope. Can you link to an example?
"if an agency were undertaking an investigation into an act of terrorism and a provider was capable of removing encryption from the device of a terrorism suspect without weakening other devices in the market then the provider could be compelled under a technical assistance notice to provide help to the agency by removing the electronic protection"
As for the US, I wouldn't be surprised if the government has sought to achieve something like this using the All Writs Act[1]. However, in the recent case of Facebook helping the FBI with a targeted use of a vulnerability[2], it seems that they cooperated voluntarily, even paying a third party contractor to help.
[0] https://www.computerworld.com/article/3460071/encryption-has...
[1] https://en.wikipedia.org/wiki/All_Writs_Act#Application_to_e...
[2] https://gizmodo.com/report-facebook-helped-the-fbi-exploit-v...
AWS: Yes.
GOV: Decrypt it, please.
AWS: Lol all we have is the public keys, bruh.
GOV: Use the public key to decrypt, please.
AWS: Uhh...
Is this a last ditch effort for a Law & Order Bill prior to the election?
If memory-enhancing brain implants are developed in the future, it will be interesting to see whether data stored on them will be subject to subpoenas.
Madness. I wonder what would happen if the NRA started defending encryption as a second amendment issue, as encryption technology has historically fallen under munitions export control legislation.
"Tale As Old As Time - Lyrics - Celine Dion and Peabo Bryson"