Senators propose lawful access to encrypted data
androidauthority.com
androidauthority.com
A major, major problem with locks and technical solutions is, that they keep un-trained people out, trained people must jump through hoops, but the implementors have special insight and resources in how to break it. Therefore, the implementors get special powers that individuals do not have, trained or not trained. Once again, US Senators believe that the implementors are "good enough" to be useful, given that errors, omissions and yes, crime, will occur.
The end result is, from the point of view of the individual writing this, is that implementors have special powers over individuals moving forward. This may or may not be a bad deal. Historically, humans have victimized other humans at astounding rates, including incentiving others to do the same, sucessfully. So, do you an individual, or you a responsible organization leader, believe that these particular implementors will be special over time and not use this power to victimize others?
lastly, throw in the murkier sides of "legal" and "victimization" .. Famously, most everything done in 1930s Germany was legal, at each step, encapsulated in the derogatory term "little Eichmann"
edit- over time, technical solutions will break or be leaked, and then all the "should / should not" is irrevocably out of the equation.. this last part is often what is referred to by technical analysts.. the chain of responsibility becomes un-fixably broken "when" not "if"
Giving some group "special powers over individuals" "may or may not be a bad deal"?
If men were angels, no government would be necessary. If angels were to govern men,
neither external nor internal controls on government would be necessary.
In framing a government which is to be administered by men over men, the great
difficulty lies in this: you must first enable the government to control the governed;
and in the next place oblige it to control itself. A dependence on the people is,
no doubt, the primary control on the government; but experience has taught mankind
the necessity of auxiliary precautions.
-James Madison, Federalist No. 51
https://www.csus.edu/indiv/f/friedman/fa2019/govt1/schedule/...Even if you honestly wanted to implement this, the real elephant in the room is how to manage multiple jurisdictions. For example, the US government and its contractors routinely use off-the-shelf hardware and software. If China happens to confiscate one such device, would we want to live in a world where they too have exceptional access? If the implementation exists, you're kidding yourself if you think only the US can require it.
And what's stopping anyone from simply downloading or buying the "worldwide" version of software of devices which presumably have no known backdoors?
Also, they already make “special phones” for people in government:
> the “elected ones” will keep using crypto because laws don’t typically apply to the wealthy and powerful.
Sectéra phones/modules never made it outside of mandated government use because encryption (and security in general) only works if it's there on both ends and people want to use it. So pretty much the only option is with software on top of your smartphone of choice (like POTUS and the hardened Blackberry with encryption software on top). Already both presidents and presidential candidates alike repeatedly bypassed security measures in the interest of comfort and usability. In fewer words people want their iPhones (Samsungs? whatever) and they don't want to only talk to people who also have "the special phone", rather just a piece of software.
So I can't really see how "the wealthy and powerful" would have exclusive access to that encryption and make any meaningful use of it. Good encryption options are like backdoor keys: once they're out there sooner or later everyone will have access to them.
Ah, Nobody. Sylvia wrote a catchy song about her back in the early 80's.
This is something we should be biased about, and it's okay to embrace that.
I submitted that particular title since I was on mobile and in a hurry, so I converted the URL of 'http://www.androidauthority.com/lawful-access-to-encrypted-d... with two words such that the title would be a grammatically correctish sentence.
No editorialization intended and if I had more time I would have opened a separate tab to load the article, then copy/pasted the article title.
Mods, feel free to correct the title as needed.
Ironically, to use it, you currently need to pair the device with a smart phone, but that's not essential.
On one hand, I don't believe citizens should have the ability to protect communications (or anything, really) from a lawful warrant. It is obvious that the right to privacy is not a right to perfect forward secrecy. If there is a tool that achieves this I'm not convinced it should be legal to use.
On the other hand I trip up over the whole "lawful warrant" thing because of the long history of abuse.
Someone smarter than me should tell me what to think.
If you say something to someone before they get a warrant, the warrant can't give it to them because you didn't write it down. If you write it down but then destroy it before the warrant is executed, the warrant can't give it to them because it no longer exists. If you write it down but keep it somewhere they don't know where it is, the warrant can't give it to them because they can't find it. If you write it down but it's encrypted, a warrant can't give it to them because they can't decrypt it. These are not different scenarios.
People like to make out as if encryption has changed things to make it harder, because now more things will be encrypted! But the things that are now being encrypted were historically never written down to begin with. If you made a phone call in 1970, your ordinary phone didn't automatically record it in case the government wanted to execute a warrant later. If you send a text message today and your phone records it but the record is encrypted, that isn't any worse for them than if it didn't keep a record -- it's better for them, because if they can get your passphrase then they can get access to it. Historically they had nothing.
Now they want even more, even if it it allows criminals and corrupt officials to ravage everybody and sets a profoundly dangerous precedent for totalitarian regimes, with the corresponding technical changes to popular infrastructure.
The truly nefarious are going to use things like one-time pads and couriers anyway.
I'd fall short of calling this "security theater" (like the TSA) but flawed crypto seems more along the lines of keeping honest people honest.
Once the flaws are inserted in the crypto, then it's only a matter of time until Bad Actors figure out how to exploit the flaws.
It's not the first time that harm has been done in the name of good. But the technically savvy need to get the word out: this is not a "solvable" problem, and the optimal choice is to let crypto be crypto, if the individual citizen matters at all.
There are no guarantees about the people going forward, and the data live on.
Supposing there was a method to read thoughts or memories without physical contact, would you allow police to do so as long as they had a warrant?
edit: typo
Wouldn't the only chance for survival entail a daily, warranted scan by the thought reader of everyone to ensure nobody was tempted to do it? (Or, better, omniscient surveillance.)
The point here being that the "1984" route is a valid (if not ultimately preferable) choice in this philosophical fork in the road.
(Also, rest unassured, I hate having this opinion.)
That may sound like an unrealistic scenario, but there are already people with medical implants that record digital data, and there has been a case of using Fitbit data to help convict someone:
https://www.nytimes.com/2018/10/03/us/fitbit-murder-arrest.h...
It would be interesting to see how the courts would handle the fact that many thoughts are fleeting and not indicative of belief or intent.
Seriously? Should the government have the right to know what I whisper into someone's ear?
But what if the government can listen to every whisper in every ear? Dragnet surveillance could serious damage society. If this was available decades ago it might well be used to criminalize things like being gay.
( Sorry for how weird that all sounds, I wanted to respond, but I'm not sure how to best phrase my thoughts here )
It just means government can, with legally sufficient justification, seize something. It's their job, if they want to understand it, to find a way to do it. Restricting communication to means which are easily subject to correct interpretation when seized is a violation of the First Amendment right to free speech and also exposes people to security risks from threats other than the lawful government, since if it can be compromised by a lawful seizure by government it can be compromised by an unlawful seizure by any other party.
All these laws are rarely good faith laws, but mostly are "rules" set by your older brother: he wants you to behave a certain way, but obviously has no intent to follow the same rules. So if we look at the proposed "law" thru this prism, we see "some senators deliver a message from the bigger players that those don't like that common folks can hide their communications and want to end this practice."
It’s a terrible idea and it’s pretty much as simple as that.
On the flip side, this opens the door to mass hacking by criminals and foreign entities, which is why this is a fucking terrible idea. Not to mention that it basically destroys privacy and fosters mind censorship, because people will be afraid to search for what they are looking for.