5 ms·
> All large corporations weaken encryption for the government This is simply false. It is untrue to claim that all U.S. companies have somehow "weakened" encry
by declan 12y ago
> All large corporations weaken encryption for the government
This is simply false. It is untrue to claim that all U.S. companies have somehow "weakened" encryption or inserted backdoors in their products for the Feds. I normally wouldn't waste my time correcting conspiracy theories, but sometimes it's necessary to stop the more credulous from believing them.
Yes, the NSA has boasted of having a surveillance "partnership" with certain U.S. companies, but those are telecommunications carriers -- AT&T, Verizon, Sprint, etc., not Silicon Valley firms: http://www.cnet.com/news/surveillance-partnership-between-ns.. http://www.cnet.com/news/surveillance-partnership-between-ns....
For an additional indictment of AT&T, look at the sworn affidavit that EFF obtained from local SF bay area whistleblower Mark Klein -- an AT&T technician who revealed the existence of the NSA's fiber taps at the 2nd & Folsom Street SF facility.
But the Silicon Valley companies that we know and more-or-less love have done the opposite. Look at the announcements about device encryption by Google and Apple in the last month (that have irked the Feds so much they're threatening new laws). Look at Google's Adam Langley, Wan-Teh Chang, Ben Laurie, and Elie Bursztein deploying a better TLS cipher suite in Chrome. Look at Twitter's surveillance lawsuit this week against the Feds over, apparently, the legality of a warrant canary.
And of course the two links in the conspiracy theory posted above prove the opposite of the "weaken encryption" claim. First, CALEA doesn't apply to web companies. And even the carriers it does apply to are permitted to (at 47 USC 1002(b)(3)) provide secure end-to-end encryption: "A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication."
Second, the FOIA'd doc was written in the late 1990s before the Feds liberalized encryption export controls. It's 15+ years out of date. You can now freely export strong crypto. And even in the dark days of the 1990s, there were no domestic controls on encryption use, though the TLAs did give it a shot at one point.
A better argument for the conspiracy theory set is the very odd relationship between EMC Corporation's RSA business unit and NSA. But even if allegations of intentional security flaws are true, EMC is a Massachusetts company, not a left coast firm, and a cozy relationship between the NSA and EMC/AT&T/VZ/etc. certainly does not indict all companies and their founders.
- xnull2guest 12y agoIt's funny you call it a conspiracy theory. There's no conspiracy. And it is not a theory. The NSA currently requires companies (like Microsoft, Apple) to provide encryption keys corresponding to devices where pertinent. If you look at Bush era legislation most of the pen register, tap-and-trace laws and rulings were precisely pulling existing laws for telecommunication onto the domain of the internet by arguing technical equivalence. It is also true today that essentially all telecommunications are done over digital lines. Finally Apple isn't a "web company", nor is Microsoft or the majority of 'large corporations'. > "...unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication" I don't think I need to say very much here. Regarding Apple's encryption there's lots of good information about how very little it actually does and can do. There was also a hacker news thread with yours truly. https://news.ycombinator.com/item?id=8389365 https://news.ycombinator.com/item?id=8389365 Regarding the 'antiquated' FOIA doc - you can export strong crypto but you backdoor it, keep the keys, or provide other ways to access the data. Blackberry's entire business model was secure communications and look where they are today. RSA is now in a similar boat. "Weaken encryption" does not mean 'lower the bit security under the standard attacker model' here. In this case it means 'subvert encryption through design or implementation flaws, key repositories, controlled PRNGs, side channel access or designed-in systems level access to the data'. "Weaken encryption" doesn't mean "choose smaller key sizes", it means "make the fact that something is encrypted a weak guarantee of security and privacy." > But the Silicon Valley companies that we know and more-or-less love have done the opposite Image management, nothing more. Why the public showdown? That doesn't make any sense at all. No sir, I'm certain that corporations would like to provide security and privacy for their customers. And they do. But not against federal law enforcement. There are no new laws that need passing right now. The machinery is there and we've witnessed it in action multiple times. There is no David and Goliath story here, no heroes to be heralded. It's romantic, alright. I wish it were realistic. Google (and others, that we are supposed to love) fought several battles that made it to the highest levels of court in the United States but lost. They were then forced to comply. The United States used extreme financial leverage to get QWest to comply (and when they still wouldn't, let/forced them to go bankrupt). What's changed since then? Where there some new Supreme or Circuit Court decisions that have depreciated the former?