Apple’s dangerous game, part 2
washingtonpost.com
washingtonpost.com
Add into that the large question marks over FISA's legitimacy as a court ( https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveilla... ), and the potential for illegitimate use of the backdoor becomes decidedly alarming.
My way of thinking is to compare a potential backdoor to what would happen if the backdoor doesn't exist. You get a warrant, and now you use the warrant to try and compel the accused to reveal the passcode to their phone. The accused refuses. Now what? Two possibilities: 1) the defendant is protected by the 5th Amendment, and can refuse to answer on the grounds that it may incriminate. If this is how the law goes, then any attempt to backdoor the phone is essentially an attempted end run around the 5th amendment. 2) The courts decide that this does not infringe on the 5th, and is instead covered better by the provisions for warrant-based search as provided for in the 4th amendment. In this case, the courts already have well-established remedies for refusal to acquiesce to a search, which should be used. Again, the backdoor is unnecessary.
I'm pretty sure that's not how the 5th Amendment works: Just because your protection against self-incrimination allows you to withhold potential evidence doesn't imply that the government can't attempt to acquire that evidence themselves through other means.
You can refuse to answer questions like "What's written in your diary entry for the night of the murder?" or "Where did you hide your diary?". The police can still get a warrant to search your house for your diary and read it.
Dead people aren't protected by the US constitution.
In general, 5th Amendment protections do not give people the power to resist warrants for evidence. The law makes a distinction between evidence (which can be compelled via warrant) and testimony (which cannot due to the 5th Amendment). If digital information stored on a phone is evidence covered by the 4th amendment[1], then the court can compel a person to provide it, including compelling them to use their passcode.
Kerr's argument in his first post was that high-profile efforts to actively resist such warrants might lead the courts or Congress to "up the ante" by increasing the possible punishments. For example, imagine if Congress passed a law that failure to enter your passcode in a federal case results in a mandatory 10 year federal sentence (my invented example, not Kerr's). This is the legal equivalent of the "rubber hose" approach to defeating cryptography.
[1] Generally I think we probably do want it to be so treated, because it would be a strong basis for limiting the NSA's power to collect such information.
I have to say I must now applaud Orin Kerr, for taking the time to take the opposing arguments into account, and for publishing those reflections in somewhat of an apology. It is rare that a lawyer is prepared to reconsider their position, especially so objectively and publicly.
edit: If down-voting I'd like to know why as I'm not saying anything inflammatory. Please don't down-vote for disagreeing as that's not what down-voting is for!
He wrote a post based on legal considerations and upon his domain knowledge. One of the interesting things about domain knowledge, or, more to the point, lack thereof, is that without any, one cannot know the exact extent of one's ignorance of other domains.
I am not going to go so far as to assert the author was heretofore unfamiliar with the concept of a zero-day exploit, though it seems likely, but I would suggest that the author is now at least notionally familiar with the concept - and has written quite a good, clear follow-up article devoid of our jargon (which is easily among the worst of the several domains I've been exposed to over the years) indicating exactly and precisely why he reconsidered his position.
THIS IS HOW KNOWLEDGE WORKS. Forgive the caps, but they are appropriate in this case. If we waited for everyone to know everything we think relevant before they wrote anything at all, all we would have written would be recipes. And pornography.
A domain expert wrote a reasoned piece based on their domain knowledge. Others helpfully directed that expert to domains relevant to the piece. The domain expert then (quite speedily, I think) absorbed just enough of that domain's knowledge to draw and state reasonable conclusions.
This is also how the law works, which is why it is so maddeningly slow sometimes.
Editorial or "meta" notes: I upvoted because I don't believe in downvoting (I often upvote downvoted comments for this reason) - but I believe you were downvoted because you were lazy and chose to post ad hominem comments without due consideration.
He markets himself as an expert on computer law. He also brags about working on a government panel that studied privacy and other security related topics.
You cannot be an expert on computer law if you lack the context that is provided by a basic understanding of privacy / network security issues.
The man is an incompetent fraud at best. Shortsighted and technologically ignorant people acquiring authority is a large part of the reason the United States' computer laws are terrible.
We aren't talking about a complex issue that requires domain specific knowledge, this guy was genuinely surprised that a backdoor designed for admin access could be used by those with malicious intent. If he really cared about justice, he would hand over his license to practice and refrain from talking while there are adults in the room.
If the government wants a backdoor and it wants Apple to open up iPhones based on court orders then the government needs to make a law explictly ordering Apple and similar to provide this service.
There is a parallel in my opinion in the legaslation for telecommunication companies in many western countries requiring them to log their users activity and when a court and in some cases just the police requires it, give them the data. For a national telco this is major cost; just in Denmark it was estimated by the former telemonopoly TDC to be in tune of 20 mio usd per year.
No company bears that sort of expense out of morals/patriotics.
Secondly other countries than the US may be interested in requiring this feature of the phones sold in their jurisdiction.
If such legislation passes Congress and fails to be ruled unconstitutional, 1984 was just 30 years late.
Big Brother is Watching You
WAR (on terror) IS PEACE
FREEDOM (privacy) IS SLAVERY
IGNORANCE (gag orders) IS STRENGTH
(and Apple's 1984 superbowl ad takes on a suddenly literal meaning)
What rot.
Keep things like encryption out of regulation; because it can't be.
* edit: was "amused", which was incorrect.
The sentence doesn't strike me as 100% native phrasing with that substitution, by the way, but it would be clearly comprehensible.
Weep for the future of our world governments, which will be shaped by people like this.
Seems like the kind of person we need more of. Not going to weep!
Apple possesses the key for most data synced with iCloud, or a huge number of iCloud features would not work. According to [1] Apple can still turn over iCloud data.
[1]: http://www.washingtonpost.com/business/technology/2014/09/17...
iOS backups are/could essentially be encrypted zip archives (poor example, but you get the idea) - this doesn't require apple to have the key for it.
Is it possible to (en/de)crypt something using a password, if that password changes?
"This means that your data is protected from unauthorized access both while it is being transmitted to your devices and when it is stored in the cloud."
And
"iCloud Keychain encryption keys are created on your devices, and Apple can't access those keys. Only encrypted keychain data passes through Apple's servers, and Apple can't access any of the key material that could be used to decrypt that data."
And finally:
"You can choose to disable keychain recovery, which means that iCloud Keychain is kept up to date across your approved devices, but the encrypted data is not stored with Apple and cannot be recovered if all of your devices are lost."
(The last is opt-in, but seems quite explicit.)
That said, he's got an MS in mechanical engineering from Stanford and a BS in mechanical/aerospace engineering from Princeton. If his technical background isn't sufficient to you, I'm not really sure what to do for you. It seems that you have mistaken him admitting that he doesn't know something as a sign that he is not technical.
He's changed his position to "need more information to decide". Well DUH! how about getting that information before scaring up a call to backdoor all of our data?
1. The author is Orin Kerr, a nationally recognized Law professor, and co-blogger at the single most influential Law blog - the Volokh conspiracy.
2. His highest cited academic paper (421 cites, which is a lot in law world) is titled "The fourth amendment and new technologies: constitutional myths and the case for caution", so this is literally his domain of expertise, so maybe you might want to acknowledge the possibility that he knows what he is talking about.
3. He actually changed his mind based on additional evidence that was presented to him in the form of counterarguments. Given how rarely this happens, anybody capable of doing this in a public forum automatically gets +10 Respect points from me.
4. He has a technical background, as timsally pointed out, including mechanical engineering degrees. Now if he has such trouble grappling with the subtleties of cryptography and security threat models, maybe that is also partially our fault as security practitioners. We should acknowledge that.
5. I am aware that this all sounds like an elaborate appeal to authority, but given the cavalier way people are criticizing the author (as opposed to his arguments), I thought these facts should be stated.
I will agree fully with you on 3), and partially on 5) (only partially, because on one hand I agree with the premise, but otoh if you're in a position of authority your job is precisely to understand despite potentially poor communication from other experts).
(I'm also not sure what my "accusations" are.)
I disagree with your sentiment that we should weep for the future of our world governments. I think things are slowly changing around in the right direction, and a lot of that is thanks to people like Orin Kerr who are capable of changing their minds when presented with hard evidence.
But I guess it's a good start that he acknowledges there can be "net public benefits" that outweigh the wiretapping benefits, maybe at some point he will start appreciating protection against the security state as well.
Realistically, a great part of my conversations and hence and great part of my thoughts are digital, therefore aggregated, analyzed, stored, distributed, vulnerable and everything else that comes with digital information.
The spies, the cops, the criminals, the banks, the entrepreneurs are all treating it as a resources they can tap into.
As the numerous recent data breaches have demonstrated, we need to build systems as securely as possible. Allowing anyone besides the key owner access to the data requires that the system be made fundamentally less secure. We have presumption of innonocence in the USA which means I am assumed to be a Good Guy (tm) until the government proves otherwise by due process of law. Furthermore, a citizen's desire not to disclose information to the government is not ns indication of guilt (5th amendment). The author of this these editorials either forgets or misunderstands these rights -- accepting the argument that everyone should surrender their privacy rights if they nothing hide. Living in a free society requires citizens take some degree of personal risk.
Are safe manufacturers required to provide back doors to safes for government searches? Is there any analogy to this in the real world?
The data services involved exist, from Apple's perspective, solely to entrench users in the ecosystem and thus sell ever more hardware. Implementing robust encryption prevents entanglement in anything beyond that objective goal.
Desktop operating systems similarly provide such tools either out of the box (e.g. bitlocker, filevault, dm-crypt) or through 3rd party applications (e.g. truecrypt).
Apple's old security model may have been convenient for law enforcment agencies, but that does not mean that they are entitled to this convenience, i.e. that it is reasonable to demand that this security model is the only one offered to users.
So Apple merely switched to a different model that other systems were already providing out-of-the-box.
What we should be debating is job security for domestic police. Because if we do not put user-centric-crypto in everything one day police will loose their jobs to robots and algorithms. Well, at least this argument is only as absurd as the authors FUD.
Their sense of ENTITLEMENT is ENORMOUS.
"We are ENTITLED to YOUR PRIVATE DATA."
In fact, the biggest crimes against humanity had been come from the state: Stalin, Hitler, Pol Pot. They are responsible for tens of millions of dead people, torture, kidnappings or rape and they were the heads of the State.
Hitler or Mussolini came from democracies.
If Apple could access ANY of their devices, they have to tell the NSA how they do it, thanks to "Patriot Act".
This means the gobertment could AUTOMATICALLY access any device, they don't need to ask anybody, only as a pantomime for justifying what they already know.
This is too dangerous, democracy means that power could change if it does not serve the public interest, but people in power want to remain in power by any means.
Knee-jerk fearmongering about the government doesn't help anyone.
That said, it is just ... naive... to argue that "Some instances of X have done good, so let's trust (all?) X".
Especially since these X evolve surprisingly over time, sometimes quickly.
(The whole of Europe demilitarised totally after the cold war and are now surprised we have something like a Hitler as a neighbour.)
Edit: Hmm... that comment was about internal US politics? OK... Living in a country with trusting idiots which believe what they are told to believe, I do know that politics for internal consumption can seem weird from the outside! Both the US extreme left/right seems crazy (say, Chomsky and Fox).
Governments are more complex these simplistic, blanket statements and positions.
I think it's just as naive to believe that the State always sides against your interest. Hitler and Stalin were heads of state, but so were FDR and Churchill.
Who is surprised?