> how to reduce the risk of 3rd parties [...] gaining access.
Don't you see the contradiction there? Our systems are already full of holes, so let's create some more...?
You also assume I'm a US citizen, which I am not. The minute the US mandate backdoors to manufacturers, all governments will want in, including some very nasty customers. So what do you do next, have separate keys for each government and country-based firmware, i.e. even more holes? It's a slippery slope.
"The thing to look at" is how to remove the capability for third parties to access your data, regardless of who they are. Say that tomorrow I'll wake up in Nazi Sweden (not terribly unlikely, seeing current Euro trends), I'd rather not have brownshirts with keys to all my data - would you?
With regards to other countries, manufacturers are already required to comply with all laws in any country they operate in. I don't think Americans should have to make a decision as to whether or not their own law enforcement should have the ability to decrypt phones based on what Chinese police might do in their own country.
If you're worried about brownshirts taking over your government, there's nothing preventing you from encrypting the data yourself - nothing prevented you from doing it before. There are legitimate reasons for law enforcement to search a device after being issued a valid warrant; same as your house, place of business, safe deposit boxes, etc. Strong encryption by default on hundreds of millions of devices on which people conduct much of their daily business is something new. Locks and safes will slow down an investigation, but never to the point of bringing it to a halt. Strong encryption will. Given how central these devices have become in our lives, I don't know that it makes much sense to prevent police from searching them when they are legitimately investigating an actual crime.
(1) The Mass. Supreme Court ruling/precedent can compel a suspect, with proper legal protocol, to decrypt a device and is NOT an infringement on one's constitutional rights. This makes the entire argument of "responsible disclosure" null and void.
(2) You seeing security holes as "forgot password functionality" shows how uninformed and inexperienced you are. When you start seeing everything from CPU fans (measuring audible signals to detect an encryption key) to the latest un-patchable USB bug (arbitrary code execution via invisible controller-chip firmware alterations) as attack vectors you will begin to realize just how wide the potential 'surface' is. Care to venture what could happen if someone were to, say, reverse engineer the baseband and had access to all firmware functions of a device within an environment where the decryption key was being used? A "golden key" is simply creating the largest historical hacking bounty, and a fool would think such keys could be kept secure indefinitely.
When you are admittedly an amateur and experts are telling you this is a bad idea, you should listen. Whether human or machine history has PROVEN that there is no "perfect system." Introducing unnecessary holes to accommodate bureaucratic pedantry is wholly unnecessary, and I would venture to say, idiocy.
(2) I'm not even going to bother responding to this one since you apparently couldn't be bothered to phrase your argument without an ad-hominem. If you care (which I doubt), I've already responded to a similar argument elsewhere on the thread.
It's not, of course, literally in the Constitution that you cannot encrypt things and then refuse to decrypt them for law enforcement. Nor is it in the Constitution that people selling encryption devices must include backdoors.
What words in the Constitution do you see as pertaining here?
Of course you can encrypt things yourself, and I would imagine you could probably refuse to hand over the password under your 5th Amendment rights. Nothing's changed there.
I think the issue here is that someone else (Apple) has gone and set up an encrypted environment for you in such a way that actively prevents law enforcement from carrying out legal investigations with a warrant on an incredibly popular series of devices that they were capable of searching before. Let's face it - the number of people who are buying iPhones because they are now encrypted is miniscule. If you really wanted to encrypt all of your data, optional full disk encryption already existed on other phones. The problem the police have with it is that it's now set up by default, they can no longer access it when they do have a valid warrant and this extends to everyone instead of just the handful of criminals that would take extra steps to encrypt their data. John Q. Criminal didn't choose to encrypt his phone, Apple made that decision for him.
Not at all true. The fifth amendment doesn't mean the court can't serve you with a subpoena for your device's unencrypted contents and imprison you until you provide it, for life if necessary.
[1] http://cyb3rcrim3.blogspot.com/2010/04/passwords-and-5th-ame...
[2] http://cyb3rcrim3.blogspot.com/2009/03/5th-amendment-bummer....
Why give law enforcement the ability to arbitrarily circumvent these protections? If the court says, "No, the defendant doesn't have to give it up." Why would you want to have a mechanism in place for the prosecutor to say, "Eff the court, we're taking that information anyway."
I'm no lawyer, but I suspect any evidence gathered that way would be thrown out anyway.
Likewise, you've always been able to encrypt your phone/computer/etc., and for the most part the police aren't able to decrypt it so long as you encrypt it properly. Nothing's changed in that respect. It's not a common enough phenomenon that an inability to decrypt some laptops will affect most cases.
The iPhone issue is different, though - it's not the user choosing to encrypt the device; it's Apple choosing to encrypt the device on the user's behalf. This won't affect the search of just a few suspects' property. Due to the popularity of the iPhone, it will likely affect conducting searches for a significant percentage of cases that wouldn't have been a problem before the last update to iOS. The police already needed a warrant to gather any evidence off of your cell phone, anyway; now Apple has gone and effectively stated that the warrant doesn't matter, the police don't have the right to search it to begin with.