FBI renews broad Internet surveillance push
news.cnet.com
news.cnet.com
Of course, the same worry exists for the data at each individual company, but at least those breaches are limited to a single company's data. And, from what we've seen, externally, it seems like at least some companies are more interested in protecting privacy than covering things up. When Google found that an engineer was using his access to stalk someone, he was fired, and the indecent wasn't covered up. It's not uncommon for companies to tell users about security breaches in their own product that would otherwise have gone completely unnoticed (e.g., Pinterest announced a security flaw they had rather than just silently fixing it).
Conversely, in most cases of police and government corruption I hear about, the news breaks after a failed cover-up. No doubt I don't even hear about most cases, because they're swept under the rug. I don't have a particular fondness for Google's employees or process, but, given their track record, I trust them with my data a lot more than I trust some random government employee.
Moreover, if this law gets passed, why would serious criminals continue to use any of these services? This strikes me as having the same impact as most anti-piracy measures: highly inconvenient to non-criminals (in this case, when data gets leaked to actual criminals), but completely ineffective against real criminals. Not to mention the effect on the companies themselves -- I'm certainly not going to use a Chinese email service, because I don't want the Chinese government reading my email. What's an EU citizen going to do if this law is passed?
On the other hand, the FBI and NSA aren't full of total idiots. They must realize that centralized solutions have these huge problems. Do they believe they can secure against the potential universal data breeches, or do they have some overriding ulterior motive that allows them to accept the risk?
Security needs to be taken seriously at a practically fractal level. Historically the FBI has not been good at this.
For the same reason they use cell phones which are easily monitored - it's how the bad guys you're dealing with are already accustomed to communicating.
You have to get pretty high up on the chain before encountering a criminal who's taking any real steps at counter-surveillance.
However, an issue for the FBI is that while the big telcos have back doors in place, companies like Tango, Text+, etc do not, making it a pain in the ass to monitor/identify those criminals who at least take that step to duck law enforcement.
[0]: http://en.wikipedia.org/wiki/Pretty_Good_Privacy#Criminal_in... [1]: http://en.wikipedia.org/wiki/Clipper_chip
Protecting commonly deployed asymmetric crypto against quantum computers [1] in the future is AFAIK impossible. Shor's algorithm and the ecc/dlp variants turn factoring, dlp, and ecc dlp, into BQP problems. Key lengths to protect against quantum attacks would render rsa, ecdsa, dh, and ecdh much too computationally expensive.
There are some alternatives like NTRU (lattice-based crypto) but none are in wide use, and patents don't help that situation.
[1] real quantum computers... there is still plenty of skepticism about the capability of d-wave's devices. http://www.scottaaronson.com/blog/?p=954
Or switch old security holes out for new ones.
Also note the persitent rumors that the FBI's own DCS-3000/DCS-6000 gets 0wned all the time, and used for nefarious/hilarious purposes.
But it's important to note that most services will cooperate fully with law enforcement when provided with valid legal documentation. (Probably a warrant or other court order.)
See, for a good example, Hushmail. (http://en.wikipedia.org/wiki/Hushmail)
I guess it's better that they're asking for transparently weakened services, and access with warrants, rather than just hiring grey-hats to hack the systems.
Even if it were possible, and legal, and secure, what about the other 95% of the world's population that can make apps outside of the US?
This is not to say I approve of the idea of an insecure back door into my online behaviours, more that I wonder whether there is not at least some validity in their desire to replicate land line style monitoring for currently untraceable online communications.
That's not what's being talked about here.
Compare with the modern internet, where secure end-to-end communication is easy to accomplish and requires no cooperation from the parties involved in transmitting the message. This is totally different from before, when the police could just go have a friendly chat with the phone company. Now they need to get access to at least one end of the communication in order to eavesdrop reliably. This is vastly more onerous than the previous regime, even if their ultimate goal is the same.
Ness started his career trying to enforce prohibition ... 80 years later our privacy is being prohibited.
This article, cached: 223 requests, 75.66KB transferred, 4.84s
http://lucb1e.com/rp/randomupload/thatnews.html
Uncached: 10 requests, 163.10KB transferred, 0.54s
Cached: 6 requests, 0.16KB transferred, 0.19s
The only thing I did was remove html. The article looks identical, the menu and site structure is intact, and there is a lot less clutter on the page.
Fun fact: CNET has todo comments in their production code.