Five Eyes nations plus Japan call for Big Tech put backdoors in everything
theregister.com
theregister.com
Big Tech: We have very smart people working for us who say it is not possible to do this safely. The risks greatly outweigh the rewards.
Gov'ts: no u
---
Not a new conversation. I've been wondering - what reason do big tech firms have to oppose backdoors except for concerns over compromising their legitimate users' privacy? I don't know what else would explain their resistance.
Assuming good faith and logic on both sides (tall order), how does the conversation progress?
You can change "Chromium" to "Safari" and "Google" to "Apple" and "Romanians" to whoever you like. Once the encryption or the backdoor or whatever is broken, there's a crisis. Google/Apple/Microsoft has to figure out what to do, and how to get the change past the various government certifications, and deal with the PR fallout.
If this happens 3 times, e-commerce becomes a thing of suspicion: nobody will want to have bank accounts on line.
There's some obvious 2nd order effects:
Slower development cycles. Every change has to be certified as a good back door by opaque government entities, from multiple governments. What a nightmare!
Open source goes away. If the source is available, someone recompiles without the backdoor. Illegal! Now we've got to ban open source. This is probably a good thing from the copyright maximalist position, but for nobody else.
Next order effect, is that governments will periodically sample traffic or test the backdoors to see if they work. They will find shady people with fake backdoors or encrypted-encryption with an unknown/better interior algorithm. This will lead to a lot of monitoring to ensure that only criminals have fake backdoors or better encryption.
There's a whole row of knock-on effects, every few of them with any benefit.
What happens when (not if) that common key leaks or is abused is not their concern. Until, of course, it invariably happens, and they find their citizens having their bank accounts siphoned, their agents being discovered and blackmailed for their basic 'civilian' internet use, etc.
Not to mention: being inundated with requests from law enforcement would impose significant operational costs on the industry. Just being able to shrug when asked for this kind of data probably saves a lot of man hours.
Can you imagine public opinion of this versus it being applied to Tech?
Regular people: no.
Govt's: Why not?
Regular people: We don't trust you
Govt's: Why not?
Regular people: History
Government: put a backdoor then
Big tech: no! (Except in our biggest market - china)
I’m only half joking
It is not just PR. You actually want the 'bad actors' to believe your platform is not compromised or even not compromizable, because otherwise they wouldn't use it and your backdoor would be useless. So fighting openly for backdoors by 5e+2 would, if not a ruse, be entirely self defeating.
So you can vehemently protest or deny even the potential for backdoors, while at the same time having it in your product already.
As always the agencies potential for acting on information gained is not straightforward, as doing so would compromise the secrecy of the infrastructure. So second sourcing would be strickly required, and you would only nudge official enquiries in the right direction under very high stakes circumstances.
"We, the undersigned, support strong encryption, which plays a crucial role in protecting personal data, privacy, intellectual property, trade secrets and cyber security,” the Statement commences, adding: “Encryption is an existential anchor of trust in the digital world and we do not support counter-productive and dangerous approaches that would materially weaken or limit security systems.”
Which is to say, they support encryption but then they want to have a backdoor that would materially weaken or limit security systems. Orwell would have been proud that double speak has emerged again in the wild.Currently you send an email/message and its encrypted between you and Google/FB/etc, they have a decrypted copy, and the encrypted copy is sent on to the recipient. Governments can submit a subpoena (or whatever the local equivalent is) and get copies of that communication. They can also require said companies to monitor those communications for child porn. With E2EE encryption all that goes away and combined with things like iPhone encryption you end up with a situation like Pensacola where the FBI cannot access the attackers messages without brute forcing (or however they cracked) the device itself.
I also suspect when they say Big Tech they really mean Facebook. One Facebook is the company most prominently moving in that direction. Two unlike most existing encrypted communication apps where you need to know the persons phone number or username, FB/IG allow you to search for and identify potential victims (e.g., child predators) or others sympathetic to your cause (e.g., ISIS) and subsequently contact them.
I wish those people would attempt to construct a proof-of-concept. Or they could could hire someone to do it. Then when the result is shown to the world and everyone laughs at how bad it is, maybe it'll start to be clear that what they want is "magic", not real.
The government might as well mandate the energy companies to develop perpetual motion machines.
https://www.wired.com/2015/09/apple-fighting-privacy-imessag...
Here it is: https://en.wikipedia.org/wiki/Transportation_Security_Admini...
It failed of course, but since their actual goal is not safety but control, they are going to continue pushing such things.
Central services were never good for us, just too easy to ignore. We should rip off the band-aid and get back to a decentralized web.
Defeats the purpose, doesn't it? Morons. I have a feeling I have to start backing up applications I use in case they start adding backdoors, and the older the safer will definitely be the case, regardless of bugs.