11 ms·
Last Week Tonight with John Oliver: Encryption [video]
- Tempest1981 11y agoAwesome summary of the issue. All it takes is 1 disgruntled/bribed/blackmailed employee, and everyone could be compromised. Not worth the risk.
- XorNot 11y agoAs opposed to the current situation with Apple's signing key?
- dogma1138 11y agoDepending on how it's done if the signing key is delivered to the USG yes, if Apple only delivers on-demand software updates then the security remains pretty much the same - anyone within apple who has access to the current signing key / authority to push software updates to apple devices. Handing out the signing key to the USG will probably be quite disastrous as they more likely than not offload it to any 3rd party in the private sector which will offer to make them the next best phone scrapping kit or spyware. If Apple is compelled and goes trough the software route then it's will be bombarded by 1000's of requests to unlock phones, and worse in the future to potentially install "wiretaps" on phones of suspects not in custody who haven't been charged with anything yet which will be quite a costly operation for Apple.
- nickik 11y agoIn the house meeting the security expert said this pretty well. As soon as the process becomes routine its going to be in a huge amount of danger.
- dogma1138 11y agoThat one I don't really buy sorry, wiretaps have been around for ages and while they have been misused by law enforcement I haven't heard about too many cases in which criminals actually exploit them. While cyber criminals are sophisticated it's just not going to be worth the effort for them, most large cyber crimes were pretty low tech. Foreign intelligence agencies is another deal, but then again they could just as easily penetrate Apple now. So while there will be some technical risk its really not substantial, the privacy implications however are going to be very severe.
- nickik 11y agoYou attack the weakest aspect of a system and with traditional phones that was not the interface to the state. Apple having a well such a key now is problematic but it is necessary. As long as apple only signs individuel versions that is hardcoded to one perticular phone, the danger is not that large. These keys are protected with lots of effort and access to it is limited. If apple is forced to unlock hundreds of phones they will not sign a version for each phone individually, the will have a version that runs on all phones. This software is way more problematic then the key itself. This is by the way exactly what the securty expert said in front of the house: https://judiciary.house.gov/hearing/the-encryption-tightrope-balancing-americans-security-and-privacy/ https://judiciary.house.gov/hearing/the-encryption-tightrope...
- dogma1138 11y agoApple doesn't and as far as I can tell cannot sign a version for an individual phone a signed binary by apple that removes the security settings for a phone lock/wipe will be valid for any other apple phone as long as you can trigger an update which you can using iTunes you should be able to deploy it on any device you want. There are no individual singing keys for phones that would be unmanageable there are probably a handful (or even a single one) singing keys that apple has which are valid on their devices and that's it.
- nickik 11y agoThat is wrong. The phones have hardware ids and those can be checked in code. They can sign a binary blob that runs on one phone only.
- dogma1138 11y agoNo its not, phones have hardware ID's that are used to generate the encryption key (on phones with a secure enclave, this isn't even one) I have seen no evidence that there is any specific per phone signing of apple software.
- vonmoltke 11y agoOne disgruntled/bribed/blackmailed employee with access. Without knowing how many that is and what measures are in place to stop those people it isn't possible to quantify the risk. Note that I'm not defending the idea of encryption backdoors. I still believe they are a bad idea, period. I'm just getting annoyed that the pro-encryption crowd here and on other tech sites is engaging in the same kind of out-of-touch hyperbole that the anti-encryption crowd is.
- senectus1 11y agoany chance of a non-geoblocked link?
- samwillis 11y agohttps://m.facebook.com/story.php?story_fbid=858905877571756&id=479042895558058&refsrc=http%3A%2F%2Fwww.reddit.com%2Fr%2Flastweektonight%2Fcomments%2F4ac0it%2Flast_week_tonight_with_john_oliver_hbo_encryption%2F&_rdr https://m.facebook.com/story.php?story_fbid=858905877571756&... Supprisingly their Facebook video isn't...
- tdy721 11y agohttps://eztv.ag/shows/1025/last-week-tonight-with-john-oliver/ https://eztv.ag/shows/1025/last-week-tonight-with-john-olive...
- Freak_NL 11y agoInteresting; I can see the video in The Netherlands. I wonder which specific regions they are blocking and why.
- deleted 11y ago[deleted]
- thwarted 11y agoHe used phrasing like "widely thought by experts to be impossible" (13m2s) a few times through this piece. Which cryptographers and cryptography experts think, in 2016, that a crypto system could be created that is, baring bugs, completely secure right up until the point where you don't want it to be? He showed clips of legislators asking for magic crypto unicorns (10m). Is this some kind of 4 out of 5 cryptographers think it's an "impossibility", and do we really think that that remaining one is actually an expert? Or is this just an attempt at "fair and balanced" reporting, implying that, while they couldn't find any "experts" to take the opposite side, there must be some out there. John Oliver doesn't usually do that though.
- datapolitical 11y agoIf you sound overly certain when people disagree with you they won't take you seriously.
- shard972 11y agoPretty much explained why Donald Trump is so popular at the moment.
- mistermann 11y agoGlib dismissals like this are just one of his sources of power.
- jlubawy 11y agoIt doesn't sound likely to be possible, but has it been proven so (in the rigorous mathematical sense)?
- kevinwang 11y agoI'm not sure I completely understand your comment. Do you mean that instead of "widely thought by experts to be impossible", he should have said "all experts believe it to be impossible"?
- manuelflara 11y ago
- dcw303 11y agoLike everyone on this site, I've been following this story too closely to get any new info from this segment, so I couldn't tell if this will convince people. It was up to the always high standards of Last Week Tonight though. I really hope the message got through to his audience. We need every single non-technical person in the world to understand this clearly if we have any hope of getting the US Government to back down.
- baldfat 11y agoA) Yes John Oliver is awesome B) Holy Crap! A comedian is the best for reporting on issues that are actually important. What a sad state of journalism we have been for the last decade or so.
- kawsper 11y agoComedy is very effective, and I have been a fan of Juice Rap News for a long time, they are really good at breaking things down, explain things with references and asking the right questions. My favorite is this: https://www.youtube.com/watch?v=o66FUc61MvU https://www.youtube.com/watch?v=o66FUc61MvU
- Renaud 11y agoThanks for that. It's very well done and the message is spot on!
- jerf 11y agoUnfortunately, the problem is that the media isn't any better than a comedian, not that the comedian is very good. Having been on both sides of some of John's issues, I have to say that he is a master of making you think you understand an issue, when in fact you are carefully sealed off from getting even a whiff of what the other side's points may be, with snark and mockery substituted instead. Many people criticize the mainstream media for the fake controversy approach where every issue has two sides no matter how silly, but John Oliver is even worse than that. It's fun, but that's all it is... it is not informative. Only fun. If you think he's "really good" at covering the issues, I strongly suggest tuning your media consumption; you're not even getting one side of an issue so much as one spoon-fed preparation of one side of an issue. You're dangerously underexposed. (And to be clear, I do think he is fun. I've watched a goodly number of his videos myself. I'm not saying I don't like his schtick... just that it is a schtick.)
- anc84 11y agoWhat a shame that Signal is not mentioned as encryption app.
- ehartsuyker 11y agoI know, right? I actually got excited for a second thinking he'd name drop that.
- maxerickson 11y agoOpen Whisper is based in the US so Signal isn't different from Apple in a way that was interesting for the story.
- lorenzhs 11y agoIf someone shows up with a phone, Open Whisper Systems can't read the messages stored on it if they don't have the passphrase. The messages are encrypted at rest, so they can't create an update that would circumvent it. The only option would be brute-forcing the passphrase. In that way, it's fundamentally different from Apple.
- maxerickson 11y agoSure, but the segment that mentioned other encryption apps was talking about what would happen under a US government mandate. Open Whisper Systems would have to comply, move or cease operating (Just like Apple). Apple also improved the latest iPhones, the OS replace bypass at question here will no longer work. So Signal has an advantage over older iPhones, but not all of them.
- meritt 11y agoTelegram is good at marketing and Signal/OWS is good at encryption. Not too surprising.
- deleted 11y ago[deleted]
- aauchter 11y agoWould it be possible to build devices that could be unlocked a fixed number of times across all units (say 1,000 times). Devices could be heavily hardware encrypted, but unlockable with an encryption key, a portion of which comes from a publicly monitored blockchain/distributed ledger, that when used reduces the number of future uses. This way, the government could be granted access for extreme cases, but without the potential for abuse or mass surveillance. Once there were 1,000 check-ins, not more keys could be generated. Thoughts?
- ohazi 11y agoNo, you can't do this in a way that's as strong as conventional encryption. It would be too easy to present your system with an older view of the "ledger" to compel it to reveal expired/locked information. If your system were to mutate some encrypted internal state to keep track of the read count, this could be worked around via backups. The only way your system could work is if it relied on some sort of TPM, which is essentially security by obscurity.
- alain94040 11y agoDoesn't the blockchain offer some solution to that problem?
- yoha 11y agoNo. The blockchain is only a consensus through a network. Anyone can make a tiny isolated network and create a fork that will look real to the target (here, the iPhone). This is remotely related to the CAP Theorem [1]. Namely, you expect a blockchain not to fulfill the consistency requirement. [1] https://en.wikipedia.org/wiki/CAP_theorem https://en.wikipedia.org/wiki/CAP_theorem
- acqq 11y agoIt's irrelevant, since the goal of FBI now is to make a precedent in being able to demand the changes in hardware or software based on the "All Writs Act" which should otherwise be the wrong act to allow them to effectively introduce infinite "Clipper chip" equivalents the way they haven't succeeded through the regular legislation procedures up to now. Up to now such changes had to pass through the Congress, the laws had to be voted to solve such issues. This time they just quoted the Act which really just says they "may issue all writs necessary or appropriate." (check: https://en.wikipedia.org/wiki/All_Writs_Act https://en.wikipedia.org/wiki/All_Writs_Act ) Almost like citing the Catch 22. It sounds too trivial but it's fundamentally dangerous in the powers they obtain if their current interpretation is accepted: the state doesn't have to make laws, the government can just write anything whenever it likes and say it's covered by "All Writs." In the older cases when Apple cooperated Apple didn't have to change anything, neither their future hardware for retail nor the software of the hardware they produce for retail and the cases when nothing has to be changed but just the accessible data copied can be understood to be actually covered with the specific law, CALEA. And don't forget how weak the argument of the FBI really is, the phone in question was a business phone of the terrorist, who actually intentionally destroyed his private phone before being chased. For this one he didn't care. Apple gave FBI the backup of the business phone, and was able to give them even the current state of it, but the government changed the backup password themselves. And the FBI can actually without Apple copy the data from the SSD disk of the phone and restore it any time to allow them more password tries. But they really want to make the precedent. Because they don't want that Apple produces the next phone on which FBI can't have more access.
- fufefderddfr 11y agoVideo spam. Late night show bullshit.
- pointernil 11y agoSo there is an effort estimate to ADD what the authorities need? Does this indicate the crypto is already broken? What's hindering the "intelligence community" from doing it on their own on case by case basis? Did they already do this? Does Apple win disproportionately marketing wise by staging it self as the sound and secure provider?
- pfg 11y agoThe FBI is asking for firmware that disables its anti-brute-force delays and auto-wipe feature. The estimate Apple gave is for creating that firmware and signing it with their key. They're not breaking the crypto, but merely making an brute-force attack more viable (by reducing the delay to ~80ms, which is how long the hash algorithm takes per passcode). The intelligence community would need access to Apple's firmware signing key in order to do this themselves. (IIRC, in their latest court filing, the FBI actually mentioned this would work for them if Apple is unwilling to implement the firmware changes.)
- pointernil 11y agoThanks for clarifying this.
- will_hughes 11y agoThere's widespread speculation that this is a test case. I.e one big high visibility case where there is general support that the government should have access to a Terrorist's data. Once Apple has been forced to write this one version of the software, the legal precedent is there to force Apple (and every other company building software and devices) to do it again for all the other devices that any law enforcement agency has on hand, for scenarios that might not have as much support.
- nickik 11y agoI listen to the hole house commity about this issue. The FBI says it has "talked to anyone who would talk to them". The security expert is on record stating that she beliefes the NSA had the capability to break the 5C but did not want to share it with the FBI. She recommended the FBI build such capabity itself instead of threaten the security of everybody.
- mangeletti 11y agoI hoped he would have touched on one more important and oft overlooked point: Encryption is not a secret. It's accessible to criminals, and criminals don't give a shit about "backdoor" laws. In fact, I'd venture to guess that there is great encryption software already available on jail broken iPhones.
- baldfat 11y agoWell what we have seen in actual practice is in France and other terror attacks that they used no encryption so far. http://www.bloombergview.com/articles/2015-11-18/a-back-door-to-encryption-won-t-stop-terrorists http://www.bloombergview.com/articles/2015-11-18/a-back-door... What we have also seen in regards to just use of technology is the reign of default. I I doubt that criminals would go for an unlocked iPhone for security reasons for a few reason but one being that is beyond them.
- jschwartzi 11y agoISIS is known to use encryption in their communications.
- baldfat 11y agoI specifically spoke about the attacks in Paris which was originally blamed on Snowden and encryption but actually they didn't use encrypted communication.
- will_hughes 11y agoDo they? Do you have evidence to back that up? The bits I've read suggest that they don't - or at least not widely. Eg: https://www.schneier.com/blog/archives/2015/11/paris_terrorist.html https://www.schneier.com/blog/archives/2015/11/paris_terrori...
- stoshe 11y agohttp://www.businessinsider.com/telegram-isis-app-encrypted-propagandar-2015-11 http://www.businessinsider.com/telegram-isis-app-encrypted-p...
- Shivetya 11y agoOkay, while I am in full agreement that no back door is warranted why does Apple get a pass of their actions with regards to China? The rumor mill claims it means possibly handing over source code used to drive devices. If true, how would they not do the same for US officials? I certainly don't believe they should write the code request by the government but at the same time are they going to keep that stance in all markets?
- Tloewald 11y agoApple showed the Chinese its source code so they could verify that it had not been back doored (per Snowden's accusations). Since this did not entail revealing their signing keys, it's a completely irrelevant comparison (in fact, it's exculpatory).
- bhhaskin 11y agoThere is a big difference between handing over source code and pushing signed patches to a device. A key principle in modern Cryptography is that if your algorithm has to stay secret in order to remain secure then it is inherently insecure. The same could be said of source code. Handing over the source code to China should not effect the security of the platform, otherwise it is inherently insecure. Handing over signing keys however is completely different.