3 ms·
I didn't think I'd come back but I liked your comment and wanted to rebut. There is a middle ground and where it lies is directly related to the assessed risk.
by ecma 11y ago
I didn't think I'd come back but I liked your comment and wanted to rebut.
There is a middle ground and where it lies is directly related to the assessed risk. To support a mechanism is a binary choice but its design is not.
In the San Bernardino example, an unexpected potential adversary (Apple) has emerged. An unexpected vector is being discussed which has nothing to do with the encryption mechanism itself. Perfect cryptography doesn't imply a perfect cryptosystem and it sure doesn't imply perfect privacy.
The balance that needs to be found is around the assistance which is rendered to warranted agencies to enable their access to data. IMO vendor supported key material attacks are not an unreasonable solution but obviously that mechanism can go horribly wrong if the software is leaked and it is not adequately designed. The same can be said for signed updates in general though. This is a hard technical problem but it's not a binary choice where the agency has some magic key they can use wherever they want or they have nothing. If they can be enabled on a case by case basis such that it is cost effective for them to do the rest, that might be enough.
Obviously this is all based on the assumption of a robust local judicial process. However, whatever decision making process occurs needs to take into account global implications. Other commenters here and elsewhere have mentioned what this could mean for agencies in other countries where judicial process may be less robust. Many have commented about a lack of transparency in our own. This is a separate but very closely related concern. There are also considerations for the open source community and how precedent like this might be applied to them. It's a hard problem but it's not binary.
- BinaryIdiot 11y ago> The balance that needs to be found is around the assistance which is rendered to warranted agencies to enable their access to data. IMO vendor supported key material attacks are not an unreasonable solution[...]If they can be enabled on a case by case basis such that it is cost effective for them to do the rest, that might be enough. Why is it not unreasonable? You're compelling companies to write custom software explicitly for law enforcement use. Let's say you own a company that creates product X. Now the FBI is compelling you, through the court system, to develop a completely custom version of product X to let them access it or use it in some way. Sure they're paying you but you now have to redirect resources to handle this and you likely hired people to do things other than work on a government project. This ultimately can hurt your company and its market position simply by consuming your resources. This is unprecedented outside of war times. It's hard for me to imagine anyone being okay with compelling a company to become a government contractor. > It's a hard problem but it's not binary. It absolutely is. The "middle ground" you pointed to isn't a middle ground; it's unconstitutional. I have yet to hear a technically viable AND constitutional "middle ground" in this debate.
- cmurf 11y agoI think this is an inadequate rebuttal. You're not being specific enough with what you mean by "its design is not [a binary choice]" Yes it really is. Either the cryptographic algorithm is broken or it's not; either the passphrase is known by 2+ parties or it's not; either there are backdoors, or there aren't. If no, no (1), and no, then the ciphertext is not determinable by the government if the only source for the passphrase can't or won't give it up. It's also a binary condition whether a company should produce an unsafe fork of their own software and make it available to any government. If they should, then in effect all governments will use it against their adversaries, foreign and domestic.
- studentrob 11y ago> vendor supported key material attacks are not an unreasonable solution Did you know encryption technology is not limited to Apple? It's not even limited to big companies. Anyone with a book or internet connection can implement encryption. This isn't plutonium, which is hard to come by. Any law that puts a backdoor on phone's encryption schemes will fail to stop criminals from hiding their communications. They'll simply use another device or download a different app that does give them encrypted communications. You and Obama are both correct to point out we should be seeking a balance to maintain our security. However, your calculation of that balance is missing some key elements, such as the one I mention above, which is that this is a gigantic game of whack-a-mole. It's the biggest one you could ever play. There's no way you can censor the internet or ban certain kinds of software. It's the same as censoring speech. Encryption is just code. The policy Obama is implicitly proposing simply won't work. I can see you've thought about this so I'll give you one example where I think we should unlock a phone. In the movie-like scenario where there's a nuclear weapon hidden somewhere, and an encrypted phone holds its location, then I would expect the NSA and FBI and every computer in the world to sick their processors on copies of that phone's data in an attempt to break the encryption. I believe this is already described as something the NSA has in place with a program called Bullrun. It seems likely to me that the FBI is unable to make use of this technology because decryption is so laborious, even for the mass of computers that the NSA has built up, and even for all of Google's machines. They just don't have enough to decrypt every criminal's phone. But I believe they could decrypt the movie-like scenario nuclear-weapons-hiding phone. So we're covered in the most extreme case. But in reality there are all kinds of ways to discover someone's password, and you don't always need a huge server farm to get at it. For example, software has weaknesses that are only known to the NSA. No software is 100% impregnable. Even Snowden admits this. We've existed as a society for a long time without encryption. Bad actors who collaborate exclusively online using encrypted technology, and who never meet in person, are few and far between. Unless the US government has some major secrets to reveal about the balancing factors of maintaining public security, then on balance, trying to force backdoors into phones will make us all less secure. This forced weakness will be exploitable by every hacker in the world, at no cost, and from positions which are not governable. And the phone manufacturer will be required to keep that weakness as-is because to fix it would be to break the law.