3 ms·
Can you elaborate on “you cannot be made to unlock anything”? Jail time, denying entry, a gun to your head are all potential ways I can think of. For manufact
by htkibar 4y ago
Can you elaborate on “you cannot be made to unlock anything”?
Jail time, denying entry, a gun to your head are all potential ways I can think of.
For manufacturer & government; it depends on which government. If we are talking of the US government; you are right. If we are talking about most smaller authoritarian regimes? Not so much.
- cowtools 4y ago>Jail time, denying entry, a gun to your head are all potential ways I can think of. A gun may motivate someone to unlock their hard drive, but if they are are not sufficiently motivated then a gun cannot do anything. You could imagine a spy or a terrorist who prefers to die vs reveal important information, or a journalist who prefer to spend years in jail vs reveal an in-progress investigation that might get them assassinated. Really, rubber hose attacks are a question of motivation, not technical ability. If apple invented a feature that wiped your storage when you are detained by border guards in some tyrannical state, then you would probably just be tortured to death. In that case you would prefer the ability to unlock your device because the purpose of torture is not to reveal secrets, but to "persuade" you into revealing your secrets. It's a completely different mode of attack. If the manufacturer has control over the phone, and the gov. makes the manufacturer unlock it, then you will have no idea that you have been attacked, or how much information the gov has on you. They do not need to confront you at all. When only you have control over the phone, you will know when the government has access to your information, and what information they will have because they will need to torture it out of you. That's why this "crypto-nihilism" that munroe entertains is just stupid. It leads people to believe that cryptography doesn't matter when in reality it's a major hurdle for the government and corporations trying to exert tyrannical control over people. In his comic, Munroe doesn't present the case where the laptop is unencrypted which is often what gets journalists/protesters/spies' data leaked unbeknownst to them, and then their collaborators are killed in a car bomb weeks later. In the smartphone case, this has to do with manufacturers choosing to encourage low-entropy passwords that can be easily cracked (e.g. 4-digit pin), "secure boot" that isn't really secure, and biometrics that are not used for disk encryption. These are all intentional flaws. >For manufacturer & government; it depends on which government. If we are talking of the US government; you are right. If we are talking about most smaller authoritarian regimes? Not so much. North Korea? The government can simply ban phones that aren't backdoored. It's not a question of size, it's a question of technical competence. China, a much larger country than North Korea, is apparently only using user-space malware; you can still buy phones with unlocked bootloaders and run AOSP. And this assumes that you purchase your device from a manufacturer whose supply chain lies only within the jurisdiction of governments friendly to your interests, and also from a manufacturer that is friendly to your interests. I don't think I can name a single manufacturer I trust that much to control my hardware over the wire with no oversight, merely because all organizations can eventually succumb to corruption.