6 ms·
>NSA currently requires companies (like Microsoft, Apple) to provide encryption keys corresponding to devices Link, please?
by declan 12y ago
>NSA currently requires companies (like Microsoft, Apple) to provide encryption keys corresponding to devices
Link, please?
- xnull2guest 12y ago"They can promise strong encryption. They just need to figure out how they can provide us plain text." - FBI General Counsel Valerie Caproni, September 27, 2010 Didn't we already chat about key escrow requirements, CALEA, etc? The Clinton Administration's big thing was key escrow. Clipper, of course, and as that policy failed the administration moved control of encryption from Military/Exports and Munitions to the Department of Commerce under the agreement that key escrow systems would be put in place where weak cryptography had been previously. Major companies (including RSA, IBM, Apple, Sun, HP, AOL, others) collaboratively drafted industry standard key escrow systems (aside: crypto key escrow patents are a fun things to look up on patent searches). Additional pressure was exerted of course because the United States had seen a very strong rise in geopolitical espionage and sabotage and strong crypto was becoming a problem for the NSA. That's where things were at the end of the Clinton Administration. During Bush's administration we saw nothing but an expansion of powers and budgets for intelligence agencies and reclassification of laws applying to other media (for tap and trace/pen register) to the internet (although CALEA already applies to broadband internet) and to computers, 'computer systems and networks' and electronic equipment. Bush (and Clinton before him) warned of rising international cyberwarfare, but couldn't get the populace concerned about it. Anyway, you do NOT see a reversal on escrow requirements during the Bush or the Obama administration - rather you see an expansion of escrow and an expansion of hardware, software and standard backdoors as well as the leaks from Snowden. There are a number of ways that escrow is done (we're ignoring backdoors right now). The TPM is one novel way that keys are stored in a way that gives access for law enforcement. TPMs are in essentially every computer, 'spooks' showed up at the standardization meetings for the chip, Germany announced they provided backdoor access during diplomatic troubles (and have since 'rescinded the announcement' whatever that means), China blocks all electronics with TPM chips coming from the United States (and allies) and after a bunch of international and technical/commercial problems the TPM 2.0 spec (again attended by Five Eyes spooks) it was for the most part abandoned. And honestly, does a low end consumer device ($650 laptop or $300 phone) require a self destructing chip that can't be examined using standard equipment or at room temperature? The TPM also almost always resides on the low pin count bus (the spec does not specify where it needs to sit), which gives it DMA (TPMs do NOT need DMA). Or check out Microsoft's Cryptographic Service Provider (CSPs). This is where you store, provision, can generate, access, and utilize your keys in a Microsoft system. It's also famous for being where the NSAKEY gave access. Microsoft will tell you that it keeps your keys secured, but it is well known to any pentester that access to admin on a box can dump all of the keys, including those that are so-called 'marked non-exportable'. From what I can tell by the public MSDN articles on the subject contents of the CSPs can be controlled via group policies, and interops with other management systems. This isn't to mention that bitlocker keys are automatically synchronized with Skydrive (Onedrive) accounts and that Onedrive was onboarded to PRISM for NSA access. Well, that's only if you have a Microsoft Account. Oh, one is automatically made for you and you're essentially required to sign up for an account to use any new Microsoft OS. Well, that and bitlocker keys are also backed up inside of organizations to Active Directory (i.e. don't 'domain join' your personal computer). Anyway. Check the flurry of Apple news items recently. The narrative would like to use that as some sort of David vs. Goliath story of the good guy capitalist protecting his consumer. But check the details. The addition of encryption is not new. What's new is that they are publicly claiming that with this encryption system they will not have access to the private keys, and so can not comply with requests. Now we don't have to believe them (I don't), but we do have to acknowledge that -not having a facility for escrow- is their 'dangerous game'. Encryption is not a 'dangerous game'. Not providing escrow is.
- declan 12y agoThanks for your reply. I'm aware of what the FBI was asking for (Val Caproni is no longer there, FYI) four years ago. My reporting before I founded recent.io was the first to disclose some elements of the bureau's demands and strategy, in fact. You're right that it's unreasonable to place blind trust in a closed encryption system, even Apple's, that we're unable to review or audit. Even if their intentions are pure, it could be poorly implemented. But my point is simply this: there is no U.S. law mandating key escrow for Apple, Google, Microsoft, etc. One was proposed in the 1990s. It didn't pass. One was proposed in the Going Dark era 4-5 years ago. It didn't pass. One is being quasi-proposed now. It hasn't passed. I actually think I'll agree with you on a lot of issues based on your post above -- but it is nevertheless a conspiracy theory to claim that Silicon Valley companies somehow engage in key escrow for the NSA or that there is a legal requirement for them to do so. As I said before, if you claim otherwise, URL, please. >NSA currently requires companies (like Microsoft, Apple) to provide encryption keys corresponding to devices PS: ^^^ I'm still waiting for the link that backs up this claim too.
- xnull2guest 12y agoAFAIK there is no explicit law requiring every company that sells cryptography (in the general case, i.e. not as a service provider) to provide key escrow. However, this is not to discount law in praxis, how CALEA is interpreted and enforced, the history of key escrow, current technology considerations, known and suspected escrow mechanisms, and pressures exerted by federal law enforcement (e.g. the removal of effective crypto from Skype when it captured its market), and how all of this hangs together. My (reasonably, educated and technically informed :p) suspicion is that companies at a certain size, federal agents will come to your company and make demands for data, which you must comply with and slowly as you are compelled by law to give keys and data on a regular basis it becomes the best thing for your business to install automatic escrow mechanisms. It is my assertion that law enforcement interprets laws that read as "...unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication" as enough to force companies to create escrow mechanisms. I would argue some of this story played out very publicly with Google. Another great example here would be the NSL of Lavabit - how they asked for far more than was legally obligated and the forcefulness and non-public nature of the demands made it impossible to put forward a reasonable defense. To summarize it is apparent to me that the difference in our perspectives is whether a specific law (another being proposed again now, as you point out) is required in the current climate of practice of law, along with the leverage and the compliance requirements that exist inside it, for key escrow to be 'required of companies'. I come down on the side of 'no'. I believe they have what they need now to get escrow. Maybe this Apple and Google thing will clarify it. But somehow I doubt it. Prediction: no explicit law on key escrow will be passed (it would be entirely too harmful for US exports) but it will continue to be practiced.