FBI blasts Apple, Google for locking police out of phones
washingtonpost.com
washingtonpost.com
One thing the FBI does not realize, or does not care, is that THEY ARE NOT THE ONLY ONES THE BACKDOORS WORK FOR.
A backdoor is a backdoor. Period. When so much private information is on a single device it's not just about being beyond the law (which is a great reason in and of itself because law enforcement is itself beyond the law). It's about being safe.
"Leave your front door unlocked. Just in case we want to search you for drugs/obscene material/weapons/etc."
I don't know about you, but I don't want to leave my house unlocked 24/7 "just in case" the FBI wants to serve me with a warrant.
Now the FBI complains they can't just go through the front door anymore. Well yes.
Edit: downvote all you like, but this is a simple factual statement.
Your reply is overly pedantic, when taken in the best light.
You even admit I'm right yet claim I'm not. So I'm kinda confused.
The key phrase there is "break in". As in, they acquire access without the consent of the owner. In this case, the "door" is the encryption key which they are expected to acquire and/or break so that they can gain access.
A conventional door you can:
1) Get a locksmith to essentially duplicate the essential function of a key to gain access. [Steal the Key]
2) Kick it in. [Brute Force]
3) Convince the owner to cooperate. [Social engineering]
They have the same options to acquire an encryption key. The fact it makes their job more difficult isn't relevant.
Cash makes their job more difficult as well since its essentially anonymous when handled with gloves. Should we ban cash and gloves too?
More likely you have a basic level of security that deters crimes of opportunity, perhaps even a serious burglar, and that is sufficient, same as for most people. Now maybe I'm wrong and you live in a decommissioned missile silo or some other super-hardened structure, but to pretend that there's no difference between basic security measures and leaving your front door unlocked is total BS.
Say you use TextSecure. If someone installs Malware on the phone and keylogs, they can capture your password. With the password and the phone, they can decrypt the messages.
I'm not sure why this is the equivalent of a bank vault to you? It can be defeated by some guy in his basement.
Law enforcement has shown the ability and willingness to use malware as well.
http://www.wired.com/2013/09/freedom-hosting-fbi/
So given that:
1) The app store is still controlled by the corporation. 2) Malware to capture the key is all that is required. 3) Law enforcement is capable of producing malware competently and legally forcing it onto machines. 4) The corporation can be legally compelled to install said malware via an automatic update [thereby disabling and/or capturing the key]. If that isn't an option, there are various other methods [such as taking the person into custody, installing the malware manually, then releasing them].
The only difference is the number of steps involved.
Now you're saying it's just a basic locked door and it's trivial to break anyway and law enforcement can legally force malware onto machines if they need to do password harvesting, which to my mind sounds worse than having a backdoor in the first place that might be exploitable.
If I understand you right you just want some additional steps for law enforcement to go through (although the legal step of getting a warrant should be sufficient; making it more difficult after that is obstructing a lawful search rather than an opportunistic one. But now you also potentially have malware in the wild, because it's not beyond the capacity of bad guys to set up a honey pot to attract the attention of law enforcement.
Sorry, I just find you argument fundamentally circular.
Let us start from the top to get this across:
Me: > "Leave your front door unlocked. Just in case we want to search you for drugs/obscene material/weapons/etc."
I said people have the right to lock their door [encryption key -> encryption software == key -> door].
You: > Except it isn't. When the FBI has a warrant they are legally entitled to break into your house even if you don't want them to.
Yes, they have the right to break into your phone. That doesn't stop me from having a lockable door. It is perfectly legal and has always been so. There was a fight about it in the 90s with PGP and such.
So you are agreeing with me. Except for the fact you put "except it isn't" without providing any actual proof it isn't. Because y'know, there is no actual proof I'm wrong.
Me: > The key phrase there is "break in". As in, they acquire access without the consent of the owner. In this case, the "door" is the encryption key which they are expected to acquire and/or break so that they can gain access.
You: > Your original claim was that you were being asked the equivalent of leaving your house unlocked for their convenience, which is a wild exaggeration.
That isn't a wild exaggeration. Plain text being stored accessibly from the internet is the equivalent of leaving your house unlocked. Its basic, fundamental security. Its why you hash your password and store your backups in an encrypted container.
I don't understand why basic, standard precautions any competent IT person engages in is "wild exaggerations".
Me: > No, it isn't. If I don't have the ability to prevent 3rd parties from entering my house, it isn't a wild exaggeration.
If strangers can walk into my house without breaking in and do WTF they want, it isn't locked by any sane definition.
You: > Of course it is. You keep your front door locked, you might have a lockable screen door and bars on the windows, or a burglar alarm or a number of other security precautions, but I'm pretty sure you don't live in an impregnable fortress or a bank vault.
Now that is a wild exaggeration. Encryption is not an impregnable fortress.
Me: > http://www.wired.com/2013/09/freedom-hosting-fbi/ > 1) The app store is still controlled by the corporation. 2) Malware to capture the key is all that is required. 3) Law enforcement is capable of producing malware competently and legally forcing it onto machines. 4) The corporation can be legally compelled to install said malware via an automatic update [thereby disabling and/or capturing the key]. If that isn't an option, there are various other methods [such as taking the person into custody, installing the malware manually, then releasing them].
A couple of ways in which encryption can be circumvented (malware, two delivery methods)
You: > This is absurd.
At no point did I say it was "trivial". You've resorted to misrepresentations, putting word in mouth, etc. to argue with me.
The fact you are going to such lengths to argue against an obvious and accurate analogy [in the majority opinion, since I'm being upvoted while you are downvoted] is absurd.
You: > If I understand you right you just want some additional steps for law enforcement to go through
At no point did I say that. What I have said this whole time is "Same steps as serving a physical warrant? Well, same for technology."
Get Warrant from Judge -> Serve Warrant [Force Entry if required] -> Find Evidence.
That is how physical warrants are handled and it is how digital warrants should be handled. That is how it works for computers too, fyi. Like desktops with full disk encryption.
Is it clear enough now?
Dude, the Washington Post is owned by Jeff Bezos. Of course he's going to attack Apple and Google for their phones, while his phone kind of flopped.
I hope Apple & Google take a hard line on this, at least until the US government passes a law making it illegal to engineer things in a manner that makes it impossible for companies to comply with search warrants. I'm sure that will come, but hopefully it will take a while.
People in America who grew up on Nintendo and Xbox don't have a clue how stupidly brutal the world can be. This is why these "highly educated people" are "actually for it".
I will grant you that these activities should be under the oversight of the US government, State governments, who represent the People of the United States. The FBI is such a federal government agency.
Clearly, it's reasonable for people not to expect to have to pay airlines for travel to Europe.
Just a question, why would the terrorists be targeting children in particular? Why not a mix of infants, children, adults, and elderly people? Your scum-sucking interest in over-reaching government intrusiveness is leading you to come up with demented and perverse scenarios focused on children.
Dude clean up your mind.
I think people have a very good handle on how brutal the world can be. In fact, they believe it to be quite a bit more brtual than it actually is. There have been ONE really major terrorist attack in the US in the past century. And having access to every single one of their conversations did not do anything to prevent it. Having separate entrances for pilots and passengers on planes would have prevented it completely, though.
They probably believe that they will not be targeted by it, that if an algorithm scans over their data that it's no big deal, and that it may lead to some criminals being caught. They can live their entire lives from start to finish, and whether their own communications were ever intercepted will likely have had zero impact on their life.
I'm not trying to be dismissive of people who are concerned, just wanting to point out that there are also valid reasons to take the other view.
But that's exactly it: if you leave a gaping hole for the feds to get through I (in the sense of a hypothetical attacker) can go through it too, especially with how easily most federal secrets leak out and the fact that rekeying is essentially impossible for this use.
Your second point is true only if the access mechanism is reliant on weak security. It doesn't have to be.
That would not be rational. They have no capacity (nor does anyone else) to predict which of their behaviors will be cause for targetting at some point in the future. Additionally, once they are profiled for their 'normal usage pattern', any life changes which cause statistically significant alteration of that pattern are likely to result in scrutiny.
For instance, you are currently involved in a conversation on a website called "Hacker News" with people whose backgrounds and motivations you do not know. The likelihood you're NOT connected to someone who is a criminal is probably very, very low. Everyone should expect to be targetted. If not today, then at any point for the rest of your life because all of these stores are maintained forever.
I probably should have mentioned in my original comment that looking at it this way is purely self-interested. In reality, perhaps there are non-average attributes (eg. particular religions) which might see clusters of innocent people scrutinized. People outside those clusters may or may not take issue with that. It depends on their values. I don't mean to suggest that one opinion or the other on this is "correct", just that there might be rational (albeit self-interested) views on both sides of the argument.
I think we're just using the word 'scrutiny' differently. I count extensive computational analysis of behavior patterns to be scrutiny. My worries are not that a human being will listen to my calls, read my emails, etc. My worries are that a piece of software will do it. The piece of software knows exactly and precisely whether I deviate from the norm and it would have no tolerance whatever for such deviation. Yes, we could pretty much completely guarantee maintenance of the status quo with automated analysis and really very civilized and quiet means of disrupting communication. It would prevent revolutions, riots, terrorism, and all sorts of negative things. But it would also doom everyone to a quiet tyranny and completely prevent any improvements as well as detriments.
Step 2: After the next telegenic kidnapping / bombing / school shooting, claim "I told you so" as the perpetrator would have been stopped if not for a secure phone / encrypted chat / requirement to get a warrant.
Step 3: 95% of the public demands mandatory backdoors, criminalizing strong encryption, and warrantless dragnet surveillance.
In saying this, you are literally placing yourself above any law. Above democracy itself, and in doing so, above all other humans.
In realizing this, you should abandon either the concept of democracy, or of your own importance above it.
Choose wisely.
I think you and I and other people here will be lucky to get to the latter half of the century without being scathed. A hard reboot is on the menu.
Choose wisely yourself. Personally I am leaving. There is no hope for reform but to paraphrase The Road, we can carry the fire.
But it will make some people think "good, these companies are finally standing up for us" which reduces the chances that people will look into products and services that offer end-to-end encryption or from companies that aren't as enthusiastically cooperative.
I'm okay with that. The whole idea of our government and society is that the mass of law-abiding and decent people are stronger than the criminal and malicious minority. People are by and large responsible, which is why they can and should govern themselves. Limiting the government's ability to snoop and intrude on citizens is a crucial check on the very real (if long-term) threat of government over-reach.
But let's not kid ourselves that our privacy, and its constraints on the government, is without consequences.
If this lowers that rate, it's possible that the difference in beatings, shootings, and home invasions will be basically even, because there isn't a large portion of the criminal element which is waiting for better encrypted cellphones to do these things (hint: other things about cellphones make these problematic, and most depend on other evidence anyway when prosecuted), where there is a reason to think that police being restrained in using illegal investigation methods will decrease the rate at which police use other illegal investigation methods.
X = how well the government is currently enforcing the law Y = amount of innocent people getting hurt K = role of encryption in all this
Y = X × K
What would you say K is? Is it big enough to be talking about it?
That's only true in a vacuum. Can you think of a case that has no other factors than an encrypted file, where someone, as a result, "got hurt?"
>If I understand how it works, the only time the new design matters is when the government has a search warrant, signed by a judge, based on a finding of probable cause. Under the old operating system, Apple could execute a lawful warrant and give law enforcement the data on the phone. Under the new operating system, that warrant is a nullity. It’s just a nice piece of paper with a judge’s signature. Because Apple demands a warrant to decrypt a phone when it is capable of doing so, the only time Apple’s inability to do that makes a difference is when the government has a valid warrant. The policy switch doesn’t stop hackers, trespassers, or rogue agents. It only stops lawful investigations with lawful warrants.
0:http://www.washingtonpost.com/news/volokh-conspiracy/wp/2014...
Incorrect: under the old operating system a human at Apple could give anyone the data on the phone. Apple had procedural safeguards that aimed to ensure that no one at Apple would do that without proper approval, but as anyone who pays attention to the news should be aware, procedural safeguards of data do not always prevent humans who are motivated to violate those safeguards. (Including, inter alia, "hackers, trespassers, and rogue agents" -- as certainly the US government is aware; its hardly as if the NSA didn't have procedural safeguards that applied to the data that Edward Snowden released.)
The change (which is a technical change, not a policy change) means no human at Apple can do this, and the phone user is protected from humans who might violate Apple's policies, including "hackers, trespassers, and rogue agents." It incidentally means that any warrant for data on the phone will have to be served on the only person who has access to that data, the phone owner.
It doesn't "stop lawful investigations with lawful warrants", it reduces the number of people who can access a phone, and therefore the set of people on whom a lawful warrant can be served. But law enforcement has no inherent right to expect that some third party will have access to my private property (whether physical or virtual) that enables law enforcement to serve a warrant on a third person, and that third person having access is always a compromise of my security that makes me more vulnerable to rogue actors. It is not simply a convenience for "lawful investigations with lawful warrants" that provides no risk to me outside of such investigations.
You distill it well, a broken security solution is not a good security solution. Foreign intelligence services, "hackers", etc... they all want our trade secrets. We need real security systems to defend against them.
You can then have my passphrase. It's no longer any use.
That's certainly rich.
You'd think a selfie would be enough to find someone the traditional way, but they seem to think they needed to locate the phone that took the picture.
PDF(!) https://www.usenix.org/system/files/conference/woot12/woot12...
So is this whole thing REALLY about the US Government losing access or more about them not wanting to expose their over-the-air code execution techniques?
Since presumably if they capture an already running device, they can just get the warrant, and ask the cellular network to send their specially crafted packet (which can unlock the phone, SMS the encryption key, or similar).
Sorry but if the Intelligence Services cannot unlock an encrypted device STILL RUNNING then I'll eat my hat.
Obviously, the latter.
More to the point, the type of regular police who would push for this probably aren't even aware that such code execution techniques might exist.
Not to mention the NSA, and I believe FBI, conducting illegal spying operations.
Government has proven it cannot be trusted, now complains when companies stop trusting it?
Plus the iPhone is sold globally.
http://www.newyorker.com/news/news-desk/terror-prosecution-m...
http://www.theguardian.com/world/2011/nov/16/fbi-entrapment-...
http://www.salon.com/2013/07/10/only_1_percent_of_terrorists...
http://www.motherjones.com/politics/2011/08/fbi-terrorist-in...
You have a right to use strong encryption because you have not consented to give away that right. The government has no actual rights at all.
Edit: -because you think you might have left your oven on.
It's concerning that a veteran police investigator considers consumer privacy "backwards."
The disingeneous dimension to this issue is that smart phones are basically powerful hand held personal computers which make calls and take photos on the side. Less than 1% of their capability is used for for making calls. Orrin Kerr pretends not to understand this. He wouldn't insist that Microsoft, Apple and Linux developers weaken the encryption on regular laptops, desktops or servers for law enforcement to have access to data.
Why should he insist on it for smart phones which these days are just as powerful as PCs, the only difference being that people carry them around, make calls and store contact details on them?
Steve Job and Apple's desire to have complete control and have access to users information brought this situation about, and in doing so made themselves virtually accessories to whatever crimes people stored on their phones. Now they realize that it made them appear as agents and collaborators with the investigative agencies, they have decided to extricate themselves from that situation leaving them close to being labelled 'pedophile and terrorist facilitators'.
All it requires is for someone to find that backdoor & its mechanism and that's it, they can exploit the backdoor designed for someone else for their own purposes. And if that someone doesn't have legitimate intentions, what then? Am I supposed to accept making my device that much less secure because the FBI or another state actor may one day decide I'm trouble? The chance of that backdoor being exploited by someone other than the FBI is considerably higher than the FBI ever using it themselves, and the FBI seem to be in lalaland on this.
Ouch, those Apple and Google guys so bad that they following forth amendment, poor and evil FBI and NSA they can't do anything with american companies. They soo-o-o angry about their OS security that you definitely could trust it.
And don't, and again, don't use this bad bad TOR and other security stuff of bad hackers full of trashware: http://securitywatch.pcmag.com/apple-ios-iphone-ipad-ipod/32... that are suprisingly sticking at the top of your application store.
It is disingenuous to imply (let alone assert, as in this case) that you can't investigate criminal activity without the ability to access our phones/read our minds. Somehow you managed for many decades prior to the iPhone. To claim you need this access now is rather silly.
I would suggest that you allow people their private, augmented minds, enjoy the better society that will (hopefully) give us all, and pursue other investigatory avenues, of which there is no shortage and which should occur to your thought.
Perhaps he's entirely unaware of any history where "the law" was used to oppress. Perhaps he's also unaware that something being "the law" does not make it just. For instance, in Washington, where I live, just two years ago it was illegal to own marijuana. Now it's legal. Does this now mean that the moral status of owning and smoking marijuana has changed, or does it merely show that the law is inconstant and often at odds with justice? Much is taken for granted in his rhetorical question.
That would be golden
I realize that from a PR perspective, Apple would like to appear to be privacy conscious. And perhaps Apple was asking for legal fallout by flouting that particular aspect of correctly implemented encryption. It just seems a little too ironic that this is just standard off-the-shelf encryption we're talking about.
Why isn't he complaining about Starbucks? Conspirators can meet in a Starbucks and discuss illegal things over coffee. If Starbucks cared about people, they'd bug all of the tables.
USA, get ready for a "foreign terrorist attack" in the next few days (;
"There will come a day when..."
The prefix to every fantasy.I really don't have enough information and I don't trust anyone.