It seems some believe that Comey is playing with semantics in order to obfuscate, or doesn't understand the argument he's making -- I don't.
It seems some believe that Comey is playing with semantics in order to obfuscate, or doesn't understand the argument he's making -- I don't.
My personal definitional taste would be:
* Backdoor - an additional way to decrypt a communication without the consent of the communicating parties.
* Secret Backdoor - a backdoor which the communicating parties are not aware of (DUAL_EC).
* Public Backdoor - a backdoor which is built into the public description the of the encryption system so that the communication parties are aware of it (lotus email backdoor).
* Frontdoor - a type of public backdoor which requires a warrant to access and whose key is controlled by a neutral (disinterested) third party. I'm not sure this is exactly what the FBI wants.
Thus, frontdoors are a very specific form of backdoors.
A front door would be using Microsoft's signing keys. As long as you don't leak the keys, you aren't diluting security in general. A back door would be just leaving vulnerabilities around. It's a meaningful distinction.
Moreover, the ability of software vendors to push malicious updates is a security vulnerability. Just because we haven't eradicated it yet doesn't mean we should codify our inability to address it in the future, e.g. by allowing users to choose what party they trust to verify and sign updates.
The FBI would probably be happy with a front door. Unfortunately, a "frontdoor" means some "neutral" third party (or anyone who hacks it) then has the ability to decrypt all your communications. Furthermore, a "neutral" third party isn't necessarily that trustworthy. The saving grace of the CA system is that non-targeted attacks are likely to be detected, because the CAs don't have the certificates' private keys, and use of alternate keys is detectable, or even preventable (only in advance) with pinning.
Everyone would balk at a CA system where the CAs had all the servers' private keys. No matter how trustworthy the CA. It would be undetectable, and pinning wouldn't mitigate it. And that's exactly what the FBI wants for Google, Facebook, Microsoft, and Whatsapp communication products.
If a neutral third party holds the keys, then you have the company (1) that makes the communications products having the keys, transferring them to the neutral third party (2) and deleting them ("we promise!"), so only the third party holds them for possible eventual use by the FBI (3). That's three entities that may potentially have access to key material in the future, not to mention anyone who hacks those three entities.
I say we refrain from adopting any new silly terminology that anyone attempts to foist upon us regarding this issue.
Something is either cryptographically secure, or it isn't. A "cryptographic" method that allows access to anyone not authorized by the one doing the encryption is not cryptographically secure. And in that case, what's the point in using it or even calling it cryptography?
Isn't it relatively speedy to get a warrant? In some cases just hours?
https://en.m.wikipedia.org/wiki/Fifth_Amendment_to_the_Unite...
Second, in this case, "routing around" is distinct from "respecting".
The courts and constitution state that in some circumstances, a person has the right to encrypt messages and not divulge the encryption key. The fundamental right here is the right to a private internal dialogue -- the state can't compel you to speak on certain questions. The FBI is trying to route around that fundamental right by creating a technical mechanism that allows them to never have to ask you to hear your internal dialog.
In short, the existence of a technical means for violating the intent of an guaranteed right without technically violating the letter of constitutional law is a game that the courts eventually shut down as unconstitutional bullshit. But a lot of people get hurt in the in-between.
But again, just to be extremely clear on the most important issue here, encouraging Congress to pass laws is not in any way police work...
Who said it was? Police work is obtaining evidence while respecting the Constitution. As technology changes, Congress and the courts must redefine exactly how that can be done, and the police participate in that discussion.
The fifth amendment guarantees the right not to be a witness against oneself. It doesn't guarantee unbreakable encryption.
That said, I don't think Congress can stop criminals from using encryption and I don't think Congress should stop law-abiding citizens from using encryption.
Not always, especially when law enforcement can request data straight from the provider, which I would imagine happens in the majority of internet crime investigations. Because let's be real, how many internet companies have a zero knowledge policy towards their users' data?
Well, the whole point of TFA is that Apple, Google, Yahoo and the likes want to progressively move in that direction (not totally for sure, but just enough so that the FBI/NSA doesn't like it).