The USG doesn't need to (and doesn't bother to) break HTTPS for domestic LEO, because existing mechanisms are easier and approved by the courts.
The USG doesn't need to (and doesn't bother to) break HTTPS for domestic LEO, because existing mechanisms are easier and approved by the courts.
No, read my comment again. Every one of the links shows a completely legal way to grab someone's data from any company. The whole point of my initial comment was to point out that legal system is so well primed against any privacy pushback that it's irrelevant what data is encrypted in transit. All the repositories and databases are just one NSL away. And NSLs are so easy to get that you don't even need to convince a judge to approve one.
From EFF: https://www.eff.org/issues/national-security-letters/faq
>By using NSLs, the FBI can directly order companies to turn over information about their customers and then gag the companies from telling anyone that they did so. Because the process is secret, and because even the companies can’t tell if specific NSLs violate the law, the process is ripe for abuse.
>A judge does not have to approve the NSL or an accompanying gag order.
>Over 300,000 NSLs have been issued in the past 10 years alone. The most NSLs issued in a single year was 56,507 in 2004. In 2013, President Obama’s Intelligence Review Group reported; that the government continues to issue an average of nearly 60 NSLs every day. By contrast, in 2000 (the year before the passage of the USA PATRIOT Act that loosened NSL standards), 8,500 NSLs were issued.
1. HTTPS relies heavily on DNS. It’s as secure as DNS is. Nuff said.
2. As has been said, there’s law enforcement can get the logs. Not hard.
3. The way the web currently works strongly encourages users to wear a “name tag.” It’s hard to take that name tag off. HTTPS doesn’t help with that.
HTTPS is very important, but has much narrower scope, and chaotic implementation, than most people realize.
I don't think this is true: HTTPS (and TLS >= 1.3) provide a suite of protections that mostly address perceived weaknesses in DNS (ECH, ESNI, CT logging, HSTS, etc.).
As for DNS itself: DoH and DoT is widely available, and my understanding is that all major browsers currently support one or the other. I've been using outbound DoH for at least two years at this point via Pi-hole.
I interpreted "law enforcement doesn't seem to care [...]" as a claim that domestic LEO has meaningfully broken HTTPS on general traffic, which I don't believe is the case. But if you meant that they don't care because they have legal access mechanisms that already suit their purposes, then I agree.