How are they not drowning in gigantic obstruction of justice lawsuits and regulatory demands?
How are they not drowning in gigantic obstruction of justice lawsuits and regulatory demands?
You can lock it remotely at a moments notice as well and it'll remain encrypted against law enforcement attempts to unlock it.
Should you be held accountable for owning such a device?
MDM managed Windows, macOS laptops are such devices as well.
See how easy is it to reframe a feature in a nefarious way?
I understand having a process in place to be able to hide data from criminals stealing your data, that's not a problem. The problem becomes when companies start to hide data from legal requests, which is what Uber is in the hot for here.
Surely you're not advocating that every company should have to turn over all of its information without a warrant
If the data specified by the warrant is suddenly and intentionally encrypted then they still have to provide that data or argue the obstruction angle in front of a judge. Just because a company is incorporated doesn't mean they lose all rights.
If it's not stated that they are raiding the office to grab data, what could the raid even be for?
They don't have to hand over their entire database, and as a customer, I wouldn't want them to.
They don't have to let them grab whatever the want and root around in data not covered in the warrant.
Turns out, there are laws and the above would be 100% illegal.
If violence is not a solution, you're not using enough.
I agree there guilty and are behaving in a borderline devil way but given they're playing with the big boys in the valley who actually has any control over them?
It's like if I told you "I use Veracrypt" what for? Am I bring investigated?
It is clear that non-tech people wrote this. Any company device I used in the last 10 years was always encrypted and could be remotely locked to not boot.
Additionally most bigger companies will have "security" software like Crowdstrike on all devices which is basically a backdoor.
What hope there is about this sort of thing comes from the fact that they can't quite yet do to us as a profession what they do to taxi drivers.
Wouldn't a raid by police (at least if they have a warrant) be "authorized access" because they are law enforcement?
At the very least, they could trigger the kill switch when the raid first happens, but once it has been verified it is the police, the kill switch should be disengaged so they have full access.
Only when you’re legally obligated to do so, which is probably often not the case.
Generally, but not always, a separate court order would be required to force you to decrypt your servers.
That's like saying a warrant wouldn't include data found in a safe, and that would require a second warrant.
Now, if the data is remote, I'd understand it I guess. But if the kill switch simply burns the local data so only remote copies are still there, that kind of defeats the purpose of the raid in the first place.
Afaik, courts are undecided on whether you can be compelled to decrypt your own data.
Corporations are held to different standards though. They are often required to share information about themselves with the government, are constantly involved with discovery processes, and generally have different expectations of privacy.
Think about it... Would you prefer your Gmail to be down for a few hours, or for Moscow/Beijing to get a copy of all your sent/received emails cos they dumped them from Google's servers in the country?
https://docs.microsoft.com/en-us/windows/security/informatio...