17 ms·
Attorney General William P. Barr Delivers Address Conference on Cyber Security
- rplst8 7y agoDid he basically just announce a false flag? "Obviously, the Department would like to engage with the private sector in exploring solutions that will provide lawful access. While we remain open to a cooperative approach, the time to achieve that may be limited. Key countries, including important allies, have been moving toward legislative and regulatory solutions. I think it is prudent to anticipate that a major incident may well occur at any time that will galvanize public opinion on these issues. Whether we end up with legislation or not, the best course for everyone involved is to work soberly and in good faith together to craft appropriate solutions, rather than have outcomes dictated during a crisis. "
- java-man 7y agowhere did we see it before? "Further, the process of transformation, even if it brings revolutionary change, is likely to be a long one, absent some catastrophic and catalyzing event – like a new Pearl Harbor." [0] https://en.wikipedia.org/wiki/Project_for_the_New_American_Century https://en.wikipedia.org/wiki/Project_for_the_New_American_C...
- goda90 7y agoIt's either a false flag or fear mongering, neither of which should be used to take away rights.
- redler 7y ago"Be aware that the Reichstag could burn at any time."
- smacktoward 7y agoI'm no fan of Bill Barr, but I don't read this that way, no. It reads to me more like he's saying that from a planning perspective it's better to figure the worst thing that could happen and have a plan already developed that could handle that, rather than being caught by surprise and then having law and policy made in a mad, panicked rush. (In other words, let's not do with cybersecurity policy what we did with counter-terrorism policy in the weeks after 9/11.)
- jimbob45 7y agoThis is how I interpreted it. It seems like a wise, level-headed approach.
- knd775 7y agoWise? You think encryption back doors are wise?
- smacktoward 7y agoEncryption back doors are not wise, no. Barr's point is that it's better to have that argument now, in a level-headed moment and with opportunities for all the relevant stakeholders to provide input, than it would be to have it in the middle of some dire emergency. If you oppose back doors, I would think you would agree with him on this -- government tends to be delegated sweeping powers in emergencies, so it would be much harder to stop gov-friendly proposals like "back door all the things" in that kind of moment than it would be to stop them now.
- windexh8er 7y agoAgreed. It's better to have the conversation now because if we don't and the "event" does occur those who support encryption backdoors will use it as the basis of their argument in all possible manner. "We must do something now, it's clear that we need backdoors because of X!" <- That's a much worse position to be in during a debate.
- 7y ago
- TeMPOraL 7y agoI might be missing some subtleties here, because it does read surprisingly reasonable. A "crisis" "galvanizing public opinion" is always a recipe for disaster. See e.g. US overreaction to 9/11, from which the whole world still suffers.
- ceejayoz 7y agoYeah. I'm no fan of Barr, but "we should think about this stuff before a big event stirs public outrage" is very reasonable. "Don't do anything until we have a big problem" is how we got the TSA, Homeland Security, and the Patriot Act.
- yawboakye 7y agoSounds to me like he's trying to kick off a conversation about how to go about making it difficult for the bad guys to hide behind encryption and other security products. It's really not an easy solution as there's very few bad guys we need to expose but many good people we need to protect, for reasons currently known and, more importantly, unknown. This one is a hard dichotomy that will be interesting to solve: (1) give no hiding place to the bad guys (2) make the good guys undiscoverable. It'd be sad to see a solution by decree (9/11-style) but I fear that's where we're headed so long as private companies are unwilling to find a workable solution. Peacetime is a delusion.
- me_again 7y agoThey can issue as many decrees as they like but they can't solve the problem with decrees any more than they can decree that water is dry. All they can decree is that it is illegal to use effective encryption, which would be, um, unfortunate.
- yawboakye 7y agoYou have a point. By decree what I meant was that in the event of a disaster and panic the public will back any law that forces, say, Apple to give unfettered access to law enforcement. By then it's too late to engage in debates. The public became interested and very unforgivenly sided with law enforcement. They'd have prioritized their safety over being able to send cat pictures securely. Similar to 9/11.
- redisman 7y agoBreaking encryption would cause breaches orders of magnitude more catastrophic than encrypted communications between bad guys.
- yawboakye 7y agoSee it this way: we have to know what the bad guys are saying in order to be able to protect the public. The way I see it the US government (and governments around the world) will make this a non-negotiable objective. There's not a lot of pressure now because, as Barr said, the event that will turn the public against encryption hasn't arrived yet. If the parties involved don't find a solution in the meantime they'd be forced to weaken encryption for everyone when a catastrophe happens. The public is fickle. Our safety is paramount.
- shmerl 7y agoThe public opinion is clear - security should not be compromised, just because some want to have backdoors and can't get over the fact that it's a very bad idea. > We think our tech sector has the ingenuity to develop effective ways to provide secure encryption while also providing secure legal access. Yeah, may be he can also claim, tech sector can achive perpetuum mobile. This just keeps coming back all over again. He should get over the fact that it's impossible, and move on to dealing with it. Next time he should consult actual security expects before producing the above nonsense.
- youareostriches 7y agoIt’s really quite incredible how these subversions of our privacy (even including blatant disregard for the constitution) are rarely questioned when it comes to preventing terrorism, but when it comes to mass shootings that have actually killed far more people in the US, those guns are sacred objects. But notice how the label of “terrorist” is uniquely applied to the ethnic “other”, and now consider the first real gun control legislation — the Mulford Act: https://www.history.com/news/black-panthers-gun-control-nra-support-mulford-act https://www.history.com/news/black-panthers-gun-control-nra-...
- JudgeWapner 7y agoIt's not incredible at all if you understand that all the power in the world is ultimately derived from people with guns.
- youareostriches 7y agoIn case it wasn’t already blatantly obvious, my point is that terrorism in the US is fundamentally associated with “brown” people, and elicits the most immediate and direct attention from governments, whereas mass shootings are almost always committed by white men, and even the worst mass shootings against children elicit no real action. But yes, guns have been regulated in the past — when? After the Black Panther party brought open carry weapons to the state capitol during a protest.
- JudgeWapner 7y agoDifferent motives: mentally ill vs spiritual belief. and there are plenty of initiatives to ban guns after terrorist actions done by whites. not sure what your point is.
- youareostriches 7y agoI just stated my point with perfect clarity. And no, gun control has been legislated almost entirely in response to perceived violence from communities of color.
- deleted 7y ago[deleted]
- snowwrestler 7y agoMore likely transparent opportunism, in my opinion. Which is also bad and gross.
- kbd 7y agoMatt Blaze spent yesterday discussing this on Twitter: https://twitter.com/mattblaze/status/1153708198718840832 https://twitter.com/mattblaze/status/1153708198718840832 His Twitter feed is well worth a follow if you care about these issues.
- justin66 7y agoYou know how every cryptographer and security person feels when this comes up? Like the poor schmuck at NASA who signed up to explore space but instead has to spend their day explaining why the moon landing wasn't a hoax. Again and again.
- phkahler 7y agoHe claims encryption is "warrant proof" which is not true. You can have a court order someone to open the lock. They want the ability to dig through people's stuff without them knowing. That's what it's really about.
- ngngngng 7y agoSure, but I can just refuse to decrypt my data. They can just break physical locks.
- javagram 7y agoRefusing to decrypt is itself a crime (contempt of court?), so the government can jail you for years that way. Edit: this doesn’t help in cases like terrorism where the owner of the device has already been killed of course.
- lisper 7y agoThis situation also has an analogy in the physical world: if the owner of the key is dead or otherwise non-coercible, that's effectively the same as a physical document being destroyed.
- mbrumlow 7y agoI am not sure you can be compelled to remember something you forgot. And nobody can tell you if you remember or not, or if you will ever remember again. So no, some judge may try to hold you in contempt of court, and it may work for a while, but at some point -- if you have a good lawyer it will turn in to a civil rights issue. Also, you could plead the 5th as well. NOTE: I am not a lawyer, and these are just my opinions on this matter.
- ilikehurdles 7y agohttps://arstechnica.com/tech-policy/2017/03/man-jailed-indefinitely-for-refusing-to-decrypt-hard-drives-loses-appeal/ https://arstechnica.com/tech-policy/2017/03/man-jailed-indef...
- throw0101a 7y agoOver and over: * https://en.wikipedia.org/wiki/Crypto_Wars https://en.wikipedia.org/wiki/Crypto_Wars The open source folks have worked around this before: * https://wiki.debian.org/non-US https://wiki.debian.org/non-US
- makerofspoons 7y agoThe cat's out of the bag. All this would lead to is law-abiding citizens having their information at risk while criminals continue to use crypto without backdoors.
- kromem 7y agoI wish laypeople hearing this stuff realized how easy it would be for the "bad guys" to use one time pads. It would be trivial to have terror cells be distributed a USB with several GB of a OTP, and that would be unbreakable even into the age of quantum computing if used properly. Thus isn't at all about terrorism or the "really bad guys." It's 100% about accessing the average Joe Blow's communications.
- masscrypteria 7y agoBad guys already do use such schemes and more. If the government can’t crack strong encryption as-is, the problem is that strong encryption is deployed at scale.
- masscrypteria 7y agoBuild a better exceptional access encryption system that solves human and technological shortcomings. Removing strong encryption at scale would have far more effect than what you’ve described.
- ryacko 7y agoIt is quite certain that law enforcement has more capabilities than they are willing to reveal in courts. Even if encryption backdoors were available, it is dubious they would routinely submit it in evidence. Encryption is not an impediment to an investigation into an ongoing activity, files need to be decrypted, there are side channels everywhere, etc. Metadata and physical surveillance is enough to convict or put a person in a position where they could be convicted under some other law if there is no convincing explanation for why they were where they were. Usually the point of mass surveillance is to retroactively look up a person of interest and blackmail them.
- masscrypteria 7y agoStrong encryption absolutely impedes investigations. And, what indication is there that the primary purpose of mass surveillance is blackmail?
- gumby 7y agoThe most concerning part to me is that this speech now prioritizes the interests of individuals (he calls "consumers") below that of large corporations and governments. A country is made of people. In some ways we of course act as "consumers" but that is not the beginning and end of what it means to be human. The government's needs are not endogenous; the government's justification for doing certain things is ultimately because people will be better off for it (otherwise it's simply "might makes right)". In addition, corporations, at the end of the day, get certain protections (and additional requirements as well) as they are they are machines to help people achieve various ends (e.g. providing goods, providing jobs, providing an opportunity to create wealth); they are not primary actors in themselves. BTW my observation is not a comment on the specific politics of the past few years; past AsG and FBI heads have given similar talks and inherently will desire to achieve their job's objectives with the minimum of barriers. This scary formulation just shows how the terms of discussion have shifted.
- deogeo 7y agoEven without encryption back-doors, people are under unprecedented levels of surveillance, and it's only getting more pervasive. So I find it very hard to believe the job of law-enforcement is getting harder, not easier, just because we have some tiny scrap of privacy left.
- mnm1 7y agoEither pass a law to do this or shut the fuck up. No one cares about his opinion and the justice department itself has no way to enforce this without a law being passed first which is not their purview. Otherwise this fucking moron should shut the fuck up because he clearly doesn't understand the technology and the rest of us are not interested in his stupid fucking rantings.
- emiliobumachar 7y agoHe's actively trying to pass such a law, in case this isn't obvious.
- duxup 7y agoIf a given nation requires back-doors or compromising encryption in any way.... It seems inevitable that it would help that given nation's "enemies" more than that given nation. Their "enemies" will get a hold of them, and they can make use of them however they want free of restrictions unlike the given nation. I don't see anyway around that problem.
- ilaksh 7y agoThis is another clear demonstration that traditional government has become obsolete in the technological era. This is one reason that decentralized solutions such as distributed autonomous organizations are so interesting.
- snowwrestler 7y agoA specific claim of the AG, and one that I've seen relatively smart people assert before, is that software update systems could be adapted to insert these backdoors into individual phones, securely and reliably, upon receipt of a valid warrant. Software update systems have been successfully exploited to deliver malware: > On a normal day, these servers push out routine updates—bug fixes, security patches, new features—to a piece of accounting software called M.E.Doc, which is more or less Ukraine’s equivalent of TurboTax or Quicken. It’s used by nearly anyone who files taxes or does business in the country. But for a moment in 2017, those machines served as ground zero for the most devastating cyberattack since the invention of the internet—an attack that began, at least, as an assault on one nation by another. https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/ https://www.wired.com/story/notpetya-cyberattack-ukraine-rus... Presumably the software update systems for major operating systems, like for Android or iOS, are typically more heavily secured than M.E.Doc. But they are also targets of limited value. To insert malware into iOS, you would need not only access to their software update system, you would need access to (and understanding of) their source code and build system, and access to their code signing key. And even then, it's not clear that these software update systems are even capable of targeting patches down to the level of the phone of an individual person. There's no reason for it now. The central system really just needs to make the update available in its various OS flavors, and each client can request what it needs. If we force these OS companies to create a targeted backdoor system, all the hard work will be done for the bad guys. They need only achieve access to the special "law enforcement access" system, they will have everything they need all ready to go. Under these conditions, could Google or Apple keep out the bad guys with 100% success? I have great respect for these teams, but those are very long odds. It's far safer, for them and for us, to just not build that functionality. This was the point that Apple so forcefully made when Jim Comey came after them to decrypt the San Bernadino iPhone. EDIT to add: these companies operate in more than just the U.S. If they build a targeted backdoor system, you don't think other countries will demand access to that system as well? Look: Apple already compromised on iCloud hosting to maintain access to the Chinese market.
- AnthonyMouse 7y ago> And even then, it's not clear that these software update systems are even capable of targeting patches down to the level of the phone of an individual person. There's no reason for it now. There is reason against it now, because it makes it impossible to do things like reproducible builds or other security checks like comparing the software being offered to other devices to verify that none of them is being offered compromised updates before installing any of them. It would also require prohibiting the transparency necessary to implement any of those checks independently, or anyone could do so and then use that to detect the attack regardless of whether or not the attackers are domestic state sponsored.
- xenadu02 7y agoIf the US Government succeeds in requiring a backdoor then so will every other government. Does anyone really think China won’t immediately demand backdoors?
- mattnewton 7y agoI thought they already did, but in the layers they control, like Chinese apps and telecoms.
- smacktoward 7y agoSo, not that different from AT&T's infamous Room 641A (https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A).
- mattnewton 7y agoRight, just with more people onboard and also owning the apps in user space.
- inflatableDodo 7y agoNot just governments, but various mafias, several corporates, random masonic offshoots, and the occaisional creative individual presumably have backdoors into all sorts of stuff. This isn't about creating backdoors, this is about being allowed to use them within the public legal framework.
- mtgx 7y agoChina already does require backdoors of both local Chinese firms and foreign firms with HQs in China, although the requirement may not be "technically official" (it can certainly be interpreted that way from their 2017 law, though). I think it's disgusting how supposed "democracies" have been trying to emulate China, both in terms of surveillance and censorship. UK is one of the worst offenders here -- sometimes they didn't even hide the fact they were using China as a role model. There used to be a time when the U.S. government and other countries would condemn China for this sort of stuff.
- carapace 7y agoHe talks about the Fourth Amendment, but not the Second. If encryption is a weapon then I would think the Second Amendment applies, eh?
- daveslash 7y agoModern encryption is really just math. Cryptography in consumer and off-the-shelf products (which Barr is targeting with his discussion) theoretically _could_ be modified in such a way that the government could decrypt it. The two ways of which I can think are (1) Encryption "backdoors" -- fancy math known only to the government; this would require new encryption ciphers or (b) key escrow. Both approaches have their shortcomings and I'm against both, but it's plausible that the government might try it anyway. All that said, because encryption is just math, any individual or group could employ their own encryption by implementing one of any known existing ciphers -- one without a known "fancy math back door" and refuse to follow the "key escrow" guidelines. In these discussions about the government being able to decrypt stuff, are we, in effect, suggesting that certain math be made illegal? If that's really what's being proposed, I'd urge people to consider "Illegal Numbers" and how effective that's been. https://en.wikipedia.org/wiki/Illegal_number https://en.wikipedia.org/wiki/Illegal_number
- api 7y agoThis is all true, but I think encryption backdoors are more possible than people think. The target here is not nerds able to pull code from GitHub or run open source or enterprise software. The target here is consumer stuff by companies like Apple and Google. The government doesn't want it to be easy to do end-to-end encryption. For the average user, easy equals possible. The average user has neither the time nor the expertise to roll their own solution or run nerd tools. Look at how PGP/GPG's complexity and absolutely horrible UX (even for technical users!) has prevented e-mail encryption from ever taking off. This reminds me of what a government guy told me about crypto export controls. Yes, they know that crypto export controls won't stop nerds using GitHub. What they want to do is to stop IBM, Google, Apple, Cisco, Juniper, etc. from selling ready-made polished crypto products to blacklisted countries. In both cases I think the target is large corporations not individuals and the goal is to make crypto hard and keep it out of the hands of the average user or less-technical foreign organization. That being said I still don't think it'll work. Just pointing out the thinking that's going on here.
- awakeasleep 7y agoThe scenario you described accomplishes both goals. By banning 'the masses' from using encrypted communications, it'll sort the haystack and everyone who continues to do so can be profiled, plus they're already involved in illegal behavior.
- pgodzin 7y ago> The Department has made clear what we are seeking. We believe that when technology providers deploy encryption in their products, services, and platforms they need to maintain an appropriate mechanism for lawful access. This means a way for government entities, when they have appropriate legal authority, to access data securely, promptly, and in an intelligible format, whether it is stored on a device or in transmission. We do not seek to prescribe any particular solution. Our private-sector technology providers have immensely talented engineers who have built the very products and services that we are talking about. They are in the best position to determine what methods of lawful access work best for their technology. But there have been enough dogmatic pronouncements that lawful access simply cannot be done. It can be, and it must be. This seems to be the key part. He doesn't believe technologists who claim both goals cannot be achieved at once, he claims they can
- sb057 7y agoIs "technologists" a new term for someone who has a basic understanding of how math and computers function?
- jamesmadison66 7y agoThe discussion on this from the pro-encryption team has to move towards explaining it in terms of national security, as national security is the reasoning the anti-encryption group uses. National security is a major trump card across parties and administration, and will have to be responded to versus ignored, as that's where the argument is coming from. It's easy enough to explain that Russia has mathematicians, ISIS has mathematicians the same way they had chemical engineers for the oil fields, China/PLA has mathematicians, etc. The same fear mongering that is allowing an anti-encryption argument to advance can be used to fear monger right back towards encryption and be based in truth: Russia and terrorists can access my chats. For the pro-encryption crowd, we know this is actually feasible technically and the end result of backdoors. We just have to explain it on common ground, where the argument lives.
- partingshots 7y agoI’d like to petition for the usage of all prime numbers to be restricted as well. Far too dangerous and capable of harm in my opinion. We need to secure ourselves against these threats!
- glitchc 7y agoShared secret keys may work, with one key shard in the hands of the user themselves. That way a court order may compel the user to give up the key shard, but no govt. agency or other authority can unilaterally access the device.
- rossng 7y agoThen the shard _is_ the secret key. The court has no more power to compel you to give it up than any other secret key. I'm not sure what you're proposing here.
- glitchc 7y agoNot true. The shard alone is insufficient to unlock the secret. But to your point, the scheme could be designed in an n of m fashion. The simplest scheme is comprised of three shards: 1) You 2) Org 3) Govt. (ideally DoJ) Any two can be used in concert to unlock the secret. You and the Org combine shards to access account. You or Org can be compelled by Govt. to reveal shard, through a warrant. The third shard is held at the DoJ, and also requires a warrant.
- athenot 7y agoUltimately, enforcing agencies want privacy for themselves and transparency for everyone else. At the scale and speed of digital services, this asymmetry can go down very fast towards an authoritarian path. There can only be 2 solutions: - enshrine a right to privacy. Individuals should have a way to communicate in a way that is completely secure and free of evesdropping because they are believed to be innocent until proven guilty. Likewise, enforcement agencies should be granted the same to do their work. - adopt symmetric transparency. Individuals will then be allowed to follow the intimate communications of any leaders or enforcement agencies, with the same level of ease. So if you want me to have to file a FOI to get info about an official, an equally difficult/time-consuming process should exist the other way around. OR if you want an officer to be able to monitor any individual in real time, then I should be able to monitor any officer in real time. That second case should be automatic anytime the "nothing to hide" argument is invoked.
- masscrypteria 7y agoThere’s no discussion of how to build exceptional access encryption that solves the weakening issue, just that it “can’t be done”. The spirit of this initiative in 2019 is likely more about stopping strong encryption at scale, which is certain to be a frustrating black hole for LEO and the IC. Perhaps HN would do well to ask how to solve the problem from a technical perspective, given the requirements. This includes both how to build a better mousetrap (one that doesn’t have a “backdoor” or significantly weakens the encryption mechanism), and how to solve concerns about abuse of exceptional access.
- kyboren 7y ago> This includes both how to build a better mousetrap (one that doesn’t have a “backdoor” or significantly weakens the encryption mechanism), and how to solve concerns about abuse of exceptional access. There is a simple way to solve concerns about abuse of "exceptional access": Not to include any "exceptional access" mechanisms. Securely implementing a cryptosystem is a daunting task almost never achieved. Intentionally creating a human-controlled mechanism to access plaintext makes the problem much, much worse. > There’s no discussion of how to build exceptional access encryption that solves the weakening issue, just that it “can’t be done”. Please consider that there is fundamentally no way to solve concerns about exceptional access. "Exceptional access" means that there is necessarily a human attack vector: Those humans who control whatever mechanism exists to provide LEO access to plaintext. This necessarily weakens any cryptosystem. If those people are compromised, "exceptional access" will simply be "routine access". Further, because decryption of data emits no obvious signs of physical tampering, even citizens who trust that "exceptional access" is not being abused cannot verify that. I actually appreciate the name of your 5 hour old account. You're correct. We are experiencing mass hysteria over cryptography. However, it is not security professionals who are hysterical: it's people like you, who apparently never met an argument against liberty that they didn't like.
- masscrypteria 7y agoLet’s leave politics and assumptions about me out of it, please. Same point: figure out a technological and procedural solution to the human attack vector. If “security professionals” all agree on ideology or theory that it’s not possible and thus refuse to help solve the problem, then exceptional access solutions generally will be worse off for it. It’s independent of whether they actually are deployed.
- 40acres 7y agoIn general, I agree with the government stance that "warrant proof" communication is not in the best interests of US citizens. I believe that there is some precedent and established law that can be built upon to provide a compromise that allows for encryption to remain a strong privacy tool for society but one that does not hinder the state from lawful access. I believe that the US should establish a court similar to the Foreign Intelligence Surveillance Court created under the FISA Act. The government must make a case to a judge establishing probable cause, and if approved a warrant can be issued to a 3rd party communications provider to disable encryption on suspected devices such that lawful interception (i.e wiretap) can be executed. Warrants are subject to renewal every 90 days and access to encrypted communications prior to the date of warrant approval and not provided by the platform specified in the warrant are prohibited (ie, obtaining a warrant to disable and intercept WhatsApp does not mean you can disable and intercept Signal as well). I believe this balances the interests of individuals, governments and communication providers evenly.
- syn0byte 7y agoWarrant proof communication is absolutely in the best interests of the citizens for exactly the same reason it's not in the best interest of the ruling government.
- ericns 7y agoThe FISA Court isn't a legitimate court of law. Why would you want another one? There is no adversary there, it's one branch arguing to violate the Constitution while that same branch pretends to defend the target. It the Star Chamber of Technology. https://en.wikipedia.org/wiki/Star_Chamber https://en.wikipedia.org/wiki/Star_Chamber How often are the people making the arguments from the same political party? This problem extends to pretty much every court, as we currently have 3 branches being gamed by 2 political parties. This will be one of the fracture lines that break the country.
- newsreview1 7y agoThere is absolutely no way for the DMCA to keep up with the growth that may flow under it! How anyone expects the AG to prosecute every illegal infringer or posessor of illegal numbers is beyond me. There is a good article at https://www.natlawreview.com/article/digital-millennium-copyright-act-scope-reach-and-safe-harbors https://www.natlawreview.com/article/digital-millennium-copy...
- sdrinf 7y agoThe cost-benefit analysis is interesting: > If one already has an effective level of security — say, by way of illustration, one that protects against 99 percent of foreseeable threats — is it reasonable to incur massive further costs to move slightly closer to optimality and attain a 99.5 percent level of protection even where the risk addressed is extremely remote? > if the choice is between a world where we can achieve a 99 percent assurance against cyber threats to consumers, while still providing law enforcement 80 percent of the access it might seek; or a world, where we have boosted our cybersecurity to 99.5 percent but at a cost reducing law enforcements access to zero percent — the choice for society is clear. One issue with all proposals around this, is risk = probability X impact. While the above speaks to the risk, the impact of malicious actors having their hands on masterkeys would be insta-access to any & all gov-mandated communication channels, to the exact same access level as warrants would afford. While the attorney is right, that so far most corp master certificates have not been compromised, none of those had this pricetag attached to it. And the impact of this would be retroactively applicable -ie for any present-day communication, we'll be taking on faith that no future masterkeys will be leaked, ever. I would not take that bet; and so far, neither did insurance companies.