3 ms·
"If passed, the act would require tech companies to help investigators access encrypted data if that assistance would help carry out a warrant." Isn't that alr
by jeffdavis 6y ago
"If passed, the act would require tech companies to help investigators access encrypted data if that assistance would help carry out a warrant."
Isn't that already required? If someone shows up with a warrant (presumably signed by a judge and listing the particular things being searched), then basically you need to do everything you can to help them (as you should). Subpoenas are a little different and there's more room to argue about them, but are also important in general. Regardless, if it's encrypted and you don't have the key, then it's a dead end and that's the way things go.
So what is this law really doing? My guess is that it's actually asking tech companies to do something in advance of any specific criminal act, that would somehow preserve private information or prepare it so that it's easier to comply with hypothetical warrants that might be issued in the future against anyone on the platform. That's really a different kind of thing than just assisting in carrying out a warrant.
- alkonaut 6y agoHanding over data, with a warrant, seems fair. The question is if a law makes it illegal to keep data that you can't decrypt.
- xxpor 6y agoIt's much worse than the article describes. From the press release: "Senate Judiciary Committee Chairman Lindsey Graham (R-South Carolina) and U.S. Senators Tom Cotton (R-Arkansas) and Marsha Blackburn (R-Tennessee) today introduced the Lawful Access to Encrypted Data Act, a bill to bolster national security interests and better protect communities across the country by ending the use of “warrant-proof” encrypted technology by terrorists and other bad actors to conceal illicit behavior." https://www.judiciary.senate.gov/press/rep/releases/graham-cotton-blackburn-introduce-balanced-solution-to-bolster-national-security-end-use-of-warrant-proof-encryption-that-shields-criminal-activity https://www.judiciary.senate.gov/press/rep/releases/graham-c... I haven't read the exact text, but to me 'ending the use of “warrant-proof” encrypted technology' means banning end-to-end encryption, not just "requiring the assistance" of technology companies. And according to Eric Geller, who is one of the main cybersec reporters at Politico, it DOES require backdoors: https://twitter.com/ericgeller/status/1275813434123186177 https://twitter.com/ericgeller/status/1275813434123186177 "shall ensure the manufacturer has the ability to provide the assistance"
- resfirestar 6y ago> Isn't that already required? If someone shows up with a warrant (presumably signed by a judge and listing the particular things being searched), then basically you need to do everything you can to help them Only to a certain extent if the warrant is being served on the company, i.e. for access to data that they are storing. This sounds like it adds hardware manufacturers who aren’t a party to the warrant, and would also likely require cloud providers to give technical assistance (rather than merely hand over data). The main idea probably being to force Apple to develop a reliable way to break iPhone passcodes (something law enforcement has been unsuccessfully trying to get for years). > My guess is that it's actually asking tech companies to do something in advance of any specific criminal act That’s right. From the press release: > In addition, it allows the Attorney General to issue directives to service providers and device manufacturers to report on their ability to comply with court orders, including timelines for implementation. In the worst case, this would effectively prohibit un-backdoored encryption capabilities in devices and cloud services in the US.