Implementing the "back door" might be a difficult problem, but stating a priori that it's an intractable problem is just lazy thinking.
Implementing the "back door" might be a difficult problem, but stating a priori that it's an intractable problem is just lazy thinking.
1) Have the device manufacturer, FBI and Federal Court system all create their own public/private key pairs. FBI and the courts publish their public keys; the device manufacturer includes their public key, the FBI's and the court's on each device.
2) Each of these organizations stores their private key in a their own central secure facility. The key is only to exist in airgapped systems, further encrypted using a secure multi-party scheme so that multiple people are needed any time the private keys are accessed. Include personnel vetting, logging, video cameras, secure vaults, etc. to add further security.
3) When the user selects their password, the storage media is encrypted using that password, and the password is stored in a separate location on the device encrypted using the FBI's public key, the device manufacturer's public key and finally the courts' public key.
4) When law enforcement needs to decrypt the phone, they request a warrant from the court. When the warrant is approved, they send a copy of the encrypted password to the court's secure facility. The court decrypts it using their private key and hands it back.
5) The FBI (or the court, whichever) brings a copy of the warrant and the partially decrypted password to the device manufacturer. If the device manufacturer wishes to contest the warrant, they go through the normal appeals process. If not, they decrypt again using their private key and hands the resulting encrypting password over to the FBI.
6) The FBI takes the resulting encrypted password back to their own secure facility and decrypts it once more using their own private key, giving them the plaintext password. They now have access to the device, and could only have done so with a valid warrant and further given a third party trusted by the suspect (the device manufacturer) a further say in whether or not to appeal the warrant.
There's my quick solution. Feel free to further the discussion by critiquing or improving it rather than downvoting to oblivion.
2) If you have jurisdiction over someone, you can force them to decrypt something based on a warrant, so it isn't even desireable for a backdoor to exist. Rather than hoping they follow the rules in their ultra-secret room that normal people will never see, they can work through the court system, publicly.
3) There's a concept called "attack surface." A backdoor increases that, by increasing the number of secrets.
4) The article goes into detail over the real-world failures of systems like these.
5) The device manufacturer does not necessarily have our interests at heart and should not be the party contesting warrants in any reasonable system.
6) Even if the encryption scheme was sound, human error trumps all. We're introducing all sorts of elements, each of which is a point of failure, and none of which has interests aligned with those of the end user (us). OTP is provably secure, you know. It's the key management that gets you.
So we haven't demonstrated the need for this vs. compelling someone via warrant to decrypt and other means. We have good reason to believe that illegal, dragnet surveillance is the real reason for opposition. Even if you believe that our own government is (and always will be) perfectly virtuous with that power, there are many foreign governments with similar capabilities. Not sending them any traffic? Think again (BGP hijacks). And we have lots of experience showing that such systems leave people vulnerable to bad guys.
So this asks us to take on big risks for bad reasons and we know that. There just aren't any good reasons not to dismiss and oppose such systems outright and there are many good reasons to be suspicious of the motives of anyone telling us otherwise.
I blacklisted WaPo some time ago as not being a credible news source. This editorial only gives me further reason to keep them blacklisted.
A lot of people in IT seem to be blind to this. Encryption is no different from a very good hiding spot. If the authorities know it exists and you know how to access the information within it, there are ways to get you to disclose that information. It's not like they will just let you walk away if you simply say "no".
And that's just for the normal "criminals" argument. For "terrorists" there are even more ways to get them to disclose information. Rubber-hose cryptanalysis is a thing.
Rather than critiquing your specific solution, allow me to explain why no solution is possible in general.
0. Because this is Apple, people are assuming Apple's model, but it is not acceptable to enshrine that model into legislation for all of the reasons I could go into if they don't seem sufficiently obvious to anyone. And if Cyanogen on a Nexus device or Debian on a PC doesn't support the backdoor (or does but the device owner has the power to remove it), it is clearly unreasonable to hold Apple to a different standard, and in any event would be ineffective because the "criminals" (or anyone desiring privacy) could just use non-Apple devices.
1. Even if you are willing to pass a law against general purpose computing, if you have a backdoor that can't be updated you have both a security vulnerability (because flaws can't be fixed) and an ineffective backdoor (because if someone e.g. loses their keys there is nothing you can do about it).
2. If you have a backdoor that can be updated, whatever process is used for updating the backdoor is now a security vulnerability. Having the updates signed by the Director of the FBI and the Pope provides no security because the Director of the FBI and the Pope have neither the expertise nor the time to understand what it is they're signing, and a rubber stamp enforced by digital signatures is still a rubber stamp.
Also, what happens once a key is leaked? Are we supposed to throw away every phone and every computer?
Also, if you allow firmware to reflash its keys, then you have a mechanism that again can be subverted (as well as what you point out). I think we've seen it with games that that sort of DRM doesn't work in the long run -- it's routinely cracked, but manufacturers don't care too much as long as it allows them time-windows long enough to make bank. Making it the basis of all data-handling in the land doesn't seem particularly smart.
Saying "it's not possible to build a secure backdoor" is a cop-out.
The truth is, we can build systems so that your data can be decrypted with either your key, or a master key. And we can build systems where the master key requires multiple coordinated parties.
Such systems can be used to implement secure backdoors, but only if we can trust those parties with the master keys to do their job properly.
That requires:
- Proper key security so their keys don't get exposed
- Proper access controls so that the keys are only used for the purpose for which they're intended.
The problem is that we know with complete confidence that all of the parties involved in that process will fail at one or both of those hurdles.
This isn't a technical problem. "Secure golden keys" are technically feasible, and not even particularly hard. It's simply an issue that there is no one that you ought to trust with such a key.
Your alternative is basically saying "it's theoretically possible, but in practice impossible". If so, the theory is incomplete: it fails to account for the human factor.
We've seen law enforcement abuse every form of power they've been handed (see National Security Letters for one example), so I don't trust them to Do What's Right. Ever.
I think that as N grows, the probability that q >= 1 approaches 1. It strikes me as a self-evident feature of human nature.
[source] http://www.sciencedirect.com/science/article/pii/S1048984314...
Russian brides I suppose, in the context of this discussion?
Unlike me stealing your data, there are very legitimate reasons for law enforcement to have access to devices to carry out investigations. The warrant requirement is a check on abuse. If there's an issue regarding abuse of power (e.g.: bribing employees, intimidating judges, overly broad laws), it would be better for everyone to work to address the real problems than taking away means for law enforcement to investigate actual criminals.
Correction: it could work, in theory, if US companies were willing to sacrifice massive amounts of revenue for no reward.
The making of phones is going to get commoditized - everyone could make a phone in a few years, from parts and using open source software. Then we will have choices and never have to use spyware again.
The gov't will be able to get the encrypted input for the device mfr, and the output decrypted from that. Given this data, they will have a huge headstart in backing out a solution to what the mfr's private key is.
Even if this weren't so, it makes every major vendor a very cost-effective target for the government. They'll devote resources to either breaking their private key (as I described above), or just using straightforward human engineering techniques. This apparent extra layer of security will not last long in practice.
EDIT - in my 2nd para above, it assumes that a mfr has a single private key, which is probably not the case. But generating a unique key pair for every discrete device is both an expense problem and introduces difficulties with managing the set of keys, which makes its security even more difficult.
A backdoor is a backdoor is a backdoor: an entrance on which you have no visibility nor control. And this is exactly what a "golden key" would be, regardless of how it's implemented.
> how to reduce the risk of 3rd parties [...] gaining access.
Don't you see the contradiction there? Our systems are already full of holes, so let's create some more...?
You also assume I'm a US citizen, which I am not. The minute the US mandate backdoors to manufacturers, all governments will want in, including some very nasty customers. So what do you do next, have separate keys for each government and country-based firmware, i.e. even more holes? It's a slippery slope.
"The thing to look at" is how to remove the capability for third parties to access your data, regardless of who they are. Say that tomorrow I'll wake up in Nazi Sweden (not terribly unlikely, seeing current Euro trends), I'd rather not have brownshirts with keys to all my data - would you?
With regards to other countries, manufacturers are already required to comply with all laws in any country they operate in. I don't think Americans should have to make a decision as to whether or not their own law enforcement should have the ability to decrypt phones based on what Chinese police might do in their own country.
If you're worried about brownshirts taking over your government, there's nothing preventing you from encrypting the data yourself - nothing prevented you from doing it before. There are legitimate reasons for law enforcement to search a device after being issued a valid warrant; same as your house, place of business, safe deposit boxes, etc. Strong encryption by default on hundreds of millions of devices on which people conduct much of their daily business is something new. Locks and safes will slow down an investigation, but never to the point of bringing it to a halt. Strong encryption will. Given how central these devices have become in our lives, I don't know that it makes much sense to prevent police from searching them when they are legitimately investigating an actual crime.
(1) The Mass. Supreme Court ruling/precedent can compel a suspect, with proper legal protocol, to decrypt a device and is NOT an infringement on one's constitutional rights. This makes the entire argument of "responsible disclosure" null and void.
(2) You seeing security holes as "forgot password functionality" shows how uninformed and inexperienced you are. When you start seeing everything from CPU fans (measuring audible signals to detect an encryption key) to the latest un-patchable USB bug (arbitrary code execution via invisible controller-chip firmware alterations) as attack vectors you will begin to realize just how wide the potential 'surface' is. Care to venture what could happen if someone were to, say, reverse engineer the baseband and had access to all firmware functions of a device within an environment where the decryption key was being used? A "golden key" is simply creating the largest historical hacking bounty, and a fool would think such keys could be kept secure indefinitely.
When you are admittedly an amateur and experts are telling you this is a bad idea, you should listen. Whether human or machine history has PROVEN that there is no "perfect system." Introducing unnecessary holes to accommodate bureaucratic pedantry is wholly unnecessary, and I would venture to say, idiocy.
(2) I'm not even going to bother responding to this one since you apparently couldn't be bothered to phrase your argument without an ad-hominem. If you care (which I doubt), I've already responded to a similar argument elsewhere on the thread.
It's not, of course, literally in the Constitution that you cannot encrypt things and then refuse to decrypt them for law enforcement. Nor is it in the Constitution that people selling encryption devices must include backdoors.
What words in the Constitution do you see as pertaining here?
Of course you can encrypt things yourself, and I would imagine you could probably refuse to hand over the password under your 5th Amendment rights. Nothing's changed there.
I think the issue here is that someone else (Apple) has gone and set up an encrypted environment for you in such a way that actively prevents law enforcement from carrying out legal investigations with a warrant on an incredibly popular series of devices that they were capable of searching before. Let's face it - the number of people who are buying iPhones because they are now encrypted is miniscule. If you really wanted to encrypt all of your data, optional full disk encryption already existed on other phones. The problem the police have with it is that it's now set up by default, they can no longer access it when they do have a valid warrant and this extends to everyone instead of just the handful of criminals that would take extra steps to encrypt their data. John Q. Criminal didn't choose to encrypt his phone, Apple made that decision for him.
Not at all true. The fifth amendment doesn't mean the court can't serve you with a subpoena for your device's unencrypted contents and imprison you until you provide it, for life if necessary.
[1] http://cyb3rcrim3.blogspot.com/2010/04/passwords-and-5th-ame...
[2] http://cyb3rcrim3.blogspot.com/2009/03/5th-amendment-bummer....
Why give law enforcement the ability to arbitrarily circumvent these protections? If the court says, "No, the defendant doesn't have to give it up." Why would you want to have a mechanism in place for the prosecutor to say, "Eff the court, we're taking that information anyway."
I'm no lawyer, but I suspect any evidence gathered that way would be thrown out anyway.
Likewise, you've always been able to encrypt your phone/computer/etc., and for the most part the police aren't able to decrypt it so long as you encrypt it properly. Nothing's changed in that respect. It's not a common enough phenomenon that an inability to decrypt some laptops will affect most cases.
The iPhone issue is different, though - it's not the user choosing to encrypt the device; it's Apple choosing to encrypt the device on the user's behalf. This won't affect the search of just a few suspects' property. Due to the popularity of the iPhone, it will likely affect conducting searches for a significant percentage of cases that wouldn't have been a problem before the last update to iOS. The police already needed a warrant to gather any evidence off of your cell phone, anyway; now Apple has gone and effectively stated that the warrant doesn't matter, the police don't have the right to search it to begin with.
That is the key point here: The moment you introduce a backdoor you have painted a target on the parties that needs to hold those keys big enough to be seen from space.
Meanwhile, with compartmentalised keys, some users accounts get compromised all the time, but no single leak is sufficient to get everyone.