5 ms·
Maybe for warrantless wiretaps, yes. But for any legal surveillance, they'll just get a warrant and compel Apple/Microsoft/Twitter/Whoever to hand over any data
by archon 14y ago
Maybe for warrantless wiretaps, yes. But for any legal surveillance, they'll just get a warrant and compel Apple/Microsoft/Twitter/Whoever to hand over any data they have.
- shalmanese 14y agoend-to-end means Apple itself doesn't ever know what is being sent.
- Nrsolis 14y agoApple can get access to the keys because they control the platform. I have no doubt in my mind that Apple can produce end-user keys and traffic if they were served a warrant from any US court.
- doe88 14y agoI think it's more complicated than that IMO, by controlling the platform i.e. by signing keys and authenticating users they certainly can impersonate clients to others clients, but I doubt they can collect users private keys generated on users devices (of course they could if their app was explicitly sending private key to their servers but I doubt they do and I don't see a reason why they'd do it, in any case they don't need to do it).
- Nrsolis 14y agoWhen IOS 6.1.4 gets pushed to your iPhone in the future, consider how difficult it would be for Apple to add code that copies your privately generated keys back to Apple for "key-escrow purposes".
- __david__ 14y agoUp-thread there is a claim that the keys are embedded in the processor during manufacture and cannot be read.
- Nrsolis 14y agoThat's a claim that hasn't been independently verified. Absent such proof, I'd expect there to be a ready mechanism to get key material off the chip. Even if the claim is correct, there is no guarantee that the implementation that does use the key material can use it in a way that doesn't reveal the key in another way. Other supposedly secure key storage mechanisms have had disappointingly little luck against determined attackers. Ask any cryptographer about attacks that reveal key info in deployed and implemented crypto-systems.
- nthj 14y agoI'm doing my best to track this conversation, but it's a bit over my head. So say the key cannot be read. What is to prevent Apple from delivering an iMessage software update which just POSTs each message to api.nsa.gov/warrants? If I can copy-paste an iMessage, it's getting turned into plain text at some point...
- alex_doom 14y agoI believe someone noted above that Apple has no access to user keys, as they are generated by the device.
- Nrsolis 14y agoIf the end user isn't managing the keys, and the service provider is then the law states that they MUST provide decrypted traffic or provide the keys to decrypt the traffic to law enforcement.
- declan 14y agoDo you have a cite to the section of the U.S. Code that says that? That applies to companies such as Apple, Google, FB, etc.? (Hint: it doesn't exist.)
- Nrsolis 14y agohttp://www.law.cornell.edu/uscode/text/47/1002 http://www.law.cornell.edu/uscode/text/47/1002 "(3) Encryption A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication." More info: http://paranoia.dubfire.net/2011/02/deconstructing-calea-hearing.html http://paranoia.dubfire.net/2011/02/deconstructing-calea-hea... Also, declan, I was in the room during meetings with the FBI when I worked for a large telecommunications carrier. I integrated the CALEA mediation platform with the IP network and I'm well aware of what is required and not required to be present in the network regarding CALEA. IANAL, but you would be wise to consider that the FBI considers the former "information service providers" to be "telecommunications providers" to the extent that they can convince a judge that they are acting as one. I wouldn't think I was safe because I was using any kind of messaging where I couldn't control the keys, the software that uses them, and the distribution and verification of said keys.
- declan 14y agoThanks for your response! I don't disagree with your representation of the law (or the practice of the FBI) as it applies to traditional telecommunications carriers. They're clearly covered by CALEA. But Apple, Google, Facebook, Twitter, etc. are simply not telecommunications carriers. That's the whole point. CALEA as enacted in 1994 doesn't apply to them, and even the FCC didn't try to apply CALEA to them when subsequently expanding the law. This is why both the FBI director and the FBI general counsel said in the last two weeks they want Congress to rewrite the law to cover those companies. CALEA applies to "facilities-based broadband Internet access providers and providers of interconnected Voice over Internet Protocol (VoIP)." Pure TCP/IP services are not "interconnected." See page #2 of the FCC's order: http://hraunfoss.fcc.gov/edocs_public/attachmatch/FCC-06-56A1.pdf http://hraunfoss.fcc.gov/edocs_public/attachmatch/FCC-06-56A... If you're saying that the FBI sometimes gets judges and companies to go beyond what the law allows, you may be right. On the other hand, companies are under no obligation to comply, as we see in this new lawsuit: http://news.cnet.com/8301-13578_3-57577958-38/google-fights-fbis-warrantless-data-requests-in-federal-court/ http://news.cnet.com/8301-13578_3-57577958-38/google-fights-...