4 ms·
This article links to another blog post where someone yet again proposes not just one master key, but a unique master key for every device manufactured (which w
by tmm 11y ago
This article links to another blog post where someone yet again proposes not just one master key, but a unique master key for every device manufactured (which would then presumably be protected by a master master key ... it is, as they say, turtles all the way down). But once again, someone will get a hold of that super-master key and it's game over.
Personally, I'm more afraid of the government/law enforcement (and by that I mean not just the US, but every country's government and law enforcement) having access to this. So maybe the US isn't looking at my data - after all they said they'd only look if they have a warrant[1] - but what's to stop the rest of the world? I'm not a citizen anywhere else, so there isn't any legal framework protecting my privacy there.
And besides, the LEA argument that having encryption they can break being no different than having houses, safes, safety deposit boxes, etc. accessible with a warrant is complete bollocks. If the technology existed which let a burglar break into every house in the world with a particular sort of lock, simultaneously and undetectablely and get away with the _entire_ contents of said house, these same agencies would be demanding better locks for everyone (well, actually they'd probably be demanding regulations on who can have access to the "be everywhere at once" tech and insisting that they needed it to fight terrorists and pedophiles). But make no mistake, that's what having an "encryption master key" means. It doesn't mean "great I have this super key, now when I burglarize houses I don't need to smash the door in", it means "great, now I can break into every house and no one will even notice until all their stuff is on eBay".
I don't believe that government/law enforcement should have this capability and I certainly don't believe that investigating a couple of _dead_ terrorists (or live ones for that matter) is worth giving up our privacy, but if this sort of tech is going to be required, at the very minimum using it must require physical access to and irreversible modification of the target device. For example, this mythical magic decoder ring device should have to work like so:
If I understand correctly how the security on iPhones works, your passcode is used to unlock a private key which is then used to decrypt your data. If a copy of that private key is also encrypted with an asymmetric cypher and different, per-device keypair and the private half of that keypair is stored in a special chip (which I describe below), then this should be pretty safe.
1. Get a warrant to take physical possession of the target device
2. Dismantle said device and remove the chip with the encryption keys
3. Insert the chip into the decoder machine
4. The decoder machine burns out one-time fuses (via pins which are left physically disconnected in the target device) in the encryption chip which enables access to aforementioned second private key (which is unique _per-device_) and prevents the device from working should the encryption chip (or a replacement) be reinstalled[2]
5. Data is decrypted using this copy of the private key
6. Now it is very obvious that this has been done, it isn't feasible to do it on a large scale and _no one_ is doing it remotely.
If you're still concerned that there may exist a remote exploit (and those fears are justified, even though as far as I can tell it should be impossible because the hardware to blow the fuses doesn't even exist in the target device), add an additional constraint that blowing those fuses also removes power from the radio baseband chipset, physically and permanently disconnecting the device from all networks. The obvious issue here is the potential for extreme mayhem if someone figures out this exploit, instantly bricking 100's of millions of mobile devices.
I'm not saying that this is a good idea or that we should back down from a pro-encryption stance, but if it comes down to some stupid law requiring such a thing, acting upon it must be _at least_ as difficult, time consuming, and apparent as my proposal above.
[1] I don't believe them, but that's not actually relevant
[2] This is probably the most hand-wavy part, but technically feasible I think