3 ms·
I've thought of systems like this as well. To be clear, I do not want James Comey, Donald Trump, Joe Biden, or any "heroes" or "villains" of our power structur
by crystalmeph 9y ago
I've thought of systems like this as well.
To be clear, I do not want James Comey, Donald Trump, Joe Biden, or any "heroes" or "villains" of our power structures to be given any access to my encrypted data, whether they call it "lawful" or not.
That said, I don't think the "all backdoor implementations will inevitably have bugs" argument holds water in all cases, so this battleground will move to a philosophical one based on reputation and the ideals we want to uphold. This means we can't just keep shouting, "you're too stupid to make a sufficiently secure system" at the government over and over again.
So what would an effective and "secure" backdoor system look like?
Say the manufacturer creates a device with a protection similar to Apple's Secure Enclave, where there is a key i burned into the system at manufacture, which is not accessible in any way after it has been programmed in.
A second, independent, random key j is created at the same time, and the value i' = "i xor j" can be retrieved from the device with physical access only, e.g. by programming i' into a separate memory section inside the IC itself that is not accessible on the data bus while the system is running normally, it is only powered on by the hardware if one of the microprocessor's pins is jumpered at system boot.
Now, to retrieve the value i, you need both i' and j, and you can only get i' with hardware access. So even if the database containing all the j-values ever created gets compromised, nobody can break into your phone without physical access.
Now, of course, if the list of j-values got published, that would be a huge embarrassment for the US, but it would not mean that everybody's bank account and private emails would be accessible to every script kiddie overnight.
This is not a 100% risk-free solution, but it is exactly the kind of so-called "balanced" approach that the government is going to try and sell us, because it does actually ensure that the gub'mint can't break into your encrypted data, at least without physical access.
So the argument to actually use against Jim Comey is simply to point out that rest of the free world won't require this of their manufacturers, so nobody outside the US will ever buy an Apple product again since they don't feel any US manufacturer can be trusted, even if the system is technically secure.
Also, any terrorist can still create an unbreakable crypto system by running custom software on a $20 Raspberry Pi, and good luck getting ISIS to cooperate with a lawful warrant for assistance in decrypting their operative's device.