The FBI Should Stop Attacking Encryption
eff.org
eff.org
I would argue that the conversations that have gone online are the interactions that were previously happening in-person (at least in term of criminal activity), to which the FBI didn't have access before.
There is something Orwellian with the idea that there shouldn't be a word that can be pronounced in the country that the government cannot record and listen to after the fact. The limits of what is legal or not have always moved (see homosexuality, drug and alcohol consumption, etc). So a 100% enforcement of the law is counter-intuitively undesirable.
But that is what happened, and most people are oblivious to this fact.
The idea that the government can use your mobile phone to spy on you is so widely understood that even the dumbest popcorn movies make sure to show fugitives ditching their phones and criminals collecting/discarding them before they discuss business without explaining why. Everybody understands the purpose of a "burner" phone.
The point is that we voluntarily paid/pay to build and maintain the tracking infrastructure. That's what most people don't realize.
But they do, that's what's baffling. The number of people I have heard parrot the "Bill Gates put a tracking chip in the vaccine" has me both baffled and worried. These are people who appear to be otherwise completely sane and mostly rational. When I've pointed out that's literally what their phone does, so why would Bill Gates waste any money putting something in a vaccine (ignoring that's not even physically possible) - I get a "well that's different".
They are concerned, but as a non-technical person for some reason they just can't quite wrap their heads around what is happening.
It's hard to disentangle the two effects, but there is a burgeoning symbol of status in people literally displaying their vaccine cards. It hasn't completely undone the damage, but it does seem to ameliorate it.
I think it's more that there's no other option.
They need their phone, and they don't like all the tracking just like you or I don't like the tracking, but that's their only option if they want to use a phone.
> I think you mean Enemy of the State?
Given the topic of mass surveillance, this doesn't sound like much of a distinction...
In the past addictive properties were enough to get people to do absurd things like roll up leaves, light them on fire, and deliberately huff the smoke. That's arguably more harmful than what mobile devices do to us.
It's a tad embarrassing that lawmakers (who aren't even computer scientists like c'mon are we for real here?) somehow forgot how and who broke the Enigma Machine. Alan Turing did that.
Same thing with the Tor browser developed by the US Navy. Either everyone has access to a tool which can guarantee that you can blend in with the rest of the crowd, or every civilian has a special color and we all pop out while the lawmakers and police are somehow wearing grey.
How did cypherpunks and computer scientists get blasted from the government like this? Shouldn't there be some laws regarding digital privacy for US citizens?
Somehow AD revenue is caked everywhere but I can't use a computer without the FBI wanting my social security card? What the duck. Shucks I thought this was America.
This is already happening. When the NSA decided the best approach to combat terrorism was to scoop up all emails, text, voice and internet browsing of every citizen on a daily basis, they inadvertently created a way we can all "blend in" now.
A perfect example is the Jan 6th capitol attack. It was being planned out on the open, on social media channels. They didn't use any obfuscation in their language and still, even with all the technology they have, the massive surveillance machine couldn't stop it from happening.
I still firmly believe encryption is needed for privacy, but over the last 10-15 years, the insane amount of data being vacuumed up is allowing people to hide in plain site.
While the rest of your point is salient, this example is flat out false. The FBI and multiple police departments were aware of what was about to happen and warned those in charge. It was summarily ignored, because the people in charge believed the rioters were on their side. It could have easily been stopped had they reacted with even a fraction of the force they did with the BLM protests a year earlier. The events of January 6th was a result of institutional prejudice and nothing less, not a lack of information from surveillance.
The dates however are spoiled,it’s going to need a total clean.
I am the walrus.
See Lasswell. "Who (says) What (to) Whom (in) What Channel (with) What Effect".
https://en.wikipedia.org/wiki/Lasswell%27s_model_of_communic...
It's arguably different industrial complexes that have lead to mass surveillance, perhaps mostly the military-security industrial complex, that has lead to the current path; fear as a distraction from what's really needed is healing and strengthening the individual to not be brittle and prone to manipulation.
Something really has fundamentally changed with the introduction of instant encrypted messages. I'm for that change, and against the government attempting to ban it.
what has changed is, like you say, how trivially easy it is to send instant encrypted messages. what was once the domain of spy agencies and organized crime is now practical for my mom to ask me what I would like for dinner. one wonders why the FBI finds that so concerning.
Indeed. But those conversations/meetings were visible, risky etc. They were thus possible to monitor/attack and they weren't scalable.
From the perspective of law enforcement, criminals being able to discuss crimes or make payments without there being a phyiscal exchange is a nightmare. In the past, they could monitor meetings between criminals. Now they basically need to look over the shoulder of criminals in order to prove that CriminalA spoke to CriminalB. It must be extremely difficult.
Even end to end encrypted systems know who is talking to who, and how often, and where those two parties are (due to client IP geolocation).
In aggregate, you would still be able to identify which group of people used which endpoints, but aggregate information won't hold up in court.
Yes, geolocation would solve that, but I would expect such people to absolutely disable the GPS, so you'd need to rely on cell tower pings, which are not found on the same servers.
Back in France at the time of Richelieu, there wasn't a concept of free speech or religious freedom. Thus if you said that you thought the king was an idiot, you could be hanged. Or you doubted the Church, or doubted God existed.
Remember, blasphemy could be punished by death at that time.
Nowadays, in most free democracies you are free to say you don't believe in religion, or think the leaders are idiots and there are minimal consequences.
It doesn't really matter that they quantitatively have access to more to them, from the POV of law enforcement though they had access to everything that was available if they wanted it then and they don't now. Law enforcement chafes and pushes against any attempt to limit them because their self image is that of protectors and good guys so what they do has good reason even if people don't want them to, it's a whole self justifying greater good/ends justify the means self justifying loop a lot of place fall into, including tech companies. You see it constantly with unjustified searches, stops and seizures, given a limit, eg the requirement for probable cause for a search, police find any way around it they can to justify the action they already want to take, eg smell of drugs or 'acting suspicious'.
There are definitely crimes that go unsolved because police can't monitor everything 24/7, that irritates a group tasked with 'protecting' society so they push back. We feel the same thing in software engineering to a certain extent, governance, architectural approval, etc all suck to work with but they exist for a reason in big orgs but just because they're useful agencies doesn't mean they suck less when you're held up because the architects take 3 months to approve something and want 20 Powerpoint decks to do it.
This is perhaps one of the more simple and persuasive arguments against domestic surveillance and spying that I’ve heard.
A backdoor is a vulnerability that doesn't care who you are or what your purpose is or who pays you. If you found the backdoor it is open to you.
However hard the backdoor's security is, an insider recruited by Swedish intelligence (or Russia whatever the bogeyman du jour is) will leak the key at some point. Now all your "secure" shit can be accessed invisibly by Swedish hackers. By its very nature, the backdoor cannot easily be changed and its use cannot be detected.
A mundane example is the TSA keys. In addition to being leaked by greedy insiders making a quick buck, they've been leaked by accident several times. E.g. https://hackaday.com/2015/09/18/dear-tsa-this-is-why-you-sho... They are now public knowledge, and a backdoor into your luggage from anyone who cares enough to file up a key.
I don't know much about locks, but I wonder how it could ever be secure, even if they never leaked photos of the masterkeys. In principle, it should be possible to reverse-engineer the shape of the masterkey from any masterkey-compatible lock. Would it be practical to do this?
- You can make/buy them
- Luggage locks are all garbage anyway
Most mechanical locks are garbage and neither resistant to practical physical attacks nor at all pick resistant. Many are vulnerable to super-generic low-skill attacks like bump keys and comb picks.
Many electronic locks are garbage.
Smart locks are complete garbage.
See https://www.youtube.com/channel/UCm9K6rby98W8JigLoZOh6FQ for many practical examples.
Law enforcement ends up having to rely more on undercover work and informants, as it used to in the past. The CIA and NSA end up getting less intelligence for the same budget, but conversely, spies who infiltrate the CIA, NSA, etc. get less bang for their buck, as well.
For the citizenry, the only way to deal with this situation is to avoid storing data, and hardening their devices.
Basically saying you have no control is saying that the US is no democracy.
The thing you reference is just a cover story. It's plain as day to anyone paying attention who runs that country.
There is no party you can vote for that will stop the perpetual war or perpetual ubiquitous surveillance, despite a vast majority of people in the country being against both war and surveillance.
> A majority of voters say they are satisfied with the authority given to U.S. intelligence agencies to monitor Americans suspected of committing a crime, according to a poll released Thursday.
> Fifty-one percent of respondents in a recent Hill-HarrisX survey said the intelligence community has the "right amount of power" in determining who should be subject to government surveillance.
https://thehill.com/hilltv/what-americas-thinking/433071-pol...
1) Despite Snowden, most Americans are not aware of the extent of the surveillance to which they are subjected.
2) Your first quoted paragraph mentions "suspected of committing a crime". This suggests to me that they were asked about targeted surveillance, that is, of criminal suspects. The issue is one of mass surveillance: the surveillance conducted of those who are not suspected of criminal activity.
Most people aren't okay with that, when informed of the full scope of that to which they are subjected.
If you look at polling on concerns about surveillance in general in 2015, it was pretty much an even split, with a slight majority who were concerned about surveillance.[0] A majority did say it was unacceptable to surveil American citizens, at 57%, with 40% saying it was acceptable - I would not call that a vast majority, though.
Even if somebody says they're against this sort of mass surveillance, that does not change anything unless people vote based on it. Like it or not, things like surveillance and war take a back seat to all the other issues voters care about, especially since those two are among the least likely to actually affect the individual voters in question. The result of this is that few Democrats are going to vote for Rand Paul or Ted Cruz just because they happen to position themselves against the NSA or war in Syria, and few Republicans are going to vote for Bernie Sanders based on the same, even if they have strong preferences against surveillance and war - and that's ignoring the fact that there are definitely people on the other side of these issues, who believe that pardoning Snowden and withdrawing from Afghanistan is bowing down to Russia or something.
Ultimately, people get the government they deserve.
[0]: https://www.pewresearch.org/internet/2015/03/16/americans-pr...
If the democratic oversight fails and transparency suffers, then the outcome will be less than ideal. But the answer is hardly "remove law enforcement authorities from level x", surely it must be improved transparency and oversight?
Also, no agency can be trusted with a back door. Back doors are available for all actors or no actor. An NSA back door to encryption is also a back door used by an authoritarian regime. There are no "exclusive" back doors.
You can use this to argue that the FBI and parts of the DHS should still exist in some form, but the CIA, NSA and military intelligence agencies are not law enforcement.
We DON'T trust them. We have about as much say in what those agencies do as a random shop keeper in 1980's USSR does with the KGB.
Law enforcement should never be given the easy way out in terms of breaking encryption. Asking for backdoors to be installed in every device is extremely lazy police work. I'm sure there are other ways of breaking encryption like the rubber-hose technique (of course with valid arrest warrant).
Arguing that law enforcement should stop attacking encryption because it jeopardises privacy seems a little naive to me. What about criminals that profit from creating spyware? In fact, allowing law enforcement to actively research new ways to break encryption can be productive for improving security in the long run. Stop using weak passwords people.
2. FBI isn’t arguing for new ways to break encryption, they’re arguing that old ways to cripple encryption should be used on purpose.
"rubber-hose technique" refers to torture, not to something that a warrant would allow.
ps: not charged, not convicted, very innocent. not a fan of the justice dept.
See In re Boucher for a case where Fifth Amendment protections were not upheld and US v. Doe for a case where they were.
It clearly isn't to protect the American People in general. The way to do that would be to give them the best security measures available ie: E2E encryption.
It is to strengthen the government against it's citizens. By having an encryption asymmetry between the government and it's citizens, the victory is that actions can be made easier in the case where the government and it's citizens are opposing forces.
It's pretty clear in my mind that the FBI views "it's team" as exclusively law enforcement, other three letter agencies and other governmental organizations and it views everyone else as a hostile. The FBI is not on your side.
This is the just the thing we’re already clearly willing to give up civil liberties for in another areas, primarily in freedom of speech and basic property rights. Complaining about it this seen as unacceptable — you can’t criticize or question any mainstream view put out by the media on this issue.
Identity politics is the clear and only vehicle for this kind of suppression of basic rights at the moment.
Support encryption backdoors, we need them to fight White Nationalist Terrorist Insurrectionists!
If there is some sort of PATRIOT Act 2.0 under the current administration targeted at “domestic terrorism” I absolutely guarantee you someone will at least try to put an encryption backdoor in it.
This is completely false: entire media companies are dedicated to it.
>Identity politics is the clear and only vehicle for this kind of suppression of basic rights at the moment.
Again, I could just as easily say >Fear of socialism is the clear and only vehicle for this kind of suppression of basic rights at the moment.
That does not make it true.
>If there is some sort of PATRIOT Act 2.0 under the current administration targeted at “domestic terrorism” I absolutely guarantee you someone will at least try to put an encryption backdoor in it.
That's literally a given. I don't know what you're arguing. https://www.c-span.org/video/?c4876107/user-clip-joe-biden-w...
Whatever they are paying i could not imagine it's even close to enough to deal with what you are signing up for.
Intercepting the phones, tapping the lines, listening on broadcasts, surveilling deaddrops, compromising encryption, are all far easier than the computationally hard work of cracking strong crypto.
And LEO / Intel don't like to break a sweat.
So if you find a victim, you should be able to trace backwards to find the criminal.
It's just lazy crap policing to expect everyone to accept their security being compromised so you can dragnet everyone, including the vast majority who are innocent of any crime, and expect to sit on your ass and have your job done for you by google alerts.
This kind of dragnet surveillance of the entire populace was impossible (without unlimited manpower/funds) until very recently. It was not impossible to find criminals before smartphones/encryption, and it's not impossible now.
The authorities have so many more ways to catch criminals than at any time in history, but they still want more.
I don't want to live in a world where my every move and conversation is tracked and stored in a database forever.
Other wars before these played a role but I feel like WWII was the turning point after which the US was a different place. We entered more or less a permanent state of war or war-readiness since then, and the Cold War provided a rationale to massively increase the size of our espionage apparatus. Originally the idea was that this spy apparatus would only be aimed outward, but that was always a fantasy. Anything we aim outward will eventually be aimed inward.
Once you get national-level police that inherently see themselves are superior to and unaccountable to state-level bodies, then it is no surprise that they might want to wield that power, and that might have happened even without those foreign wars the US was involved in.
The way I see it, authorities all over have zero difficulty in breaking into devices (deus ex Cellebrite).
I always believe that any password we use (computers, phones, etc.) is only to protect us against the common criminal. Someone who will take your phone, and a strong PIN/password will only stop them from using your Apple/Android-Pay, read your emails, read your messages, etc.
If the gov wants to get something from you, then the gov will take something from you.
"Give up your password or go to jail: Police push legal boundaries to get into cellphones" (https://www.nbcnews.com/news/us-news/give-your-password-or-g...)
Also the Security by XKCD. (https://xkcd.com/538/) (in non-democratic countries, or really dark scenarios).
Also.. let's be honest, when the "default" on all devices is to "sync all with Google/Apple cloud", then there is minimal need to even alert someone to the fact that you need their data (e.g. by arresting them, confiscating their devices, etc.)
Just warrant+gag to Apple/Google/Dropbox/etc. and you got their "latest" backup easy-peasy.
I can't turn them off, I can't easily validate them, and there's little preventing an update just for my device being shipped.
The "welcome" should not be "all your data are belong to us". It should be "Hi, iCloud-Y/N, AutoUpdateOS-Y/N, Backup Message-Y/N, Backup Notes-Y/N, etc.).
I get it that for MANY reasons Apple wants everyone to run the latest OS/Apps versions, but.... did they ASK me?
Exiting their ecosystem is painful. Apple/Google rely on this. There are plenty of discussions on 'how to exit' and alternatives, but this is HN. The average HN-er is not exactly the same as the average smartphone user.
Without reproducible builds from multiple sources, how can we be sure of anything?
If there's a service we have a desperate need for, it's a change in ecosystem priorities that core functionality - OS's, chipsets, etc. - are open source, and updates go out as inspectable patches which get pulled into reproducible build farms and bittorrented out to users.
Start with C compilers and work your way outward from there, but I should be able to cryptographically prove to myself that the firmware update going into my Android phone was independently reproducible from public source code from users in a few different nations.
Once the virus hit the news in Wuhan, and the protests started to dial down the updates got fewer and fewer. And with the closing of the border I haven’t gotten a carrier upgrade in months. As part of the 2 million + crowd I know I’m tracked like a rat. But that’s how cellphones work
Desktop apps are much worse in this regard.
And ... that’s probably ok? The people are not meant to be protected against all searches, only warrantless search.
1000% ok. Caveat: the warrant is legit and they (judges/appropriate authorities per country) do their job right and don't have 100 pre-printed approvals (a la blank cheque) lying around and just hand them over to any policeman and/or torturer walks in asking for one.
(Also) I am thinking the people in China, Iran, Turkey, etc. where people dissapear in the middle of the night (even public figures). Do we not care for those 1.5bn people because they are outside the EU, USA, CA, AUS, NZ, etc?
My initial point is that one cannot hide from the State. One can only hide their data from the common criminal.