4 ms·
The first statute you're quoting, 47 USC 1002, was part of the 1994 CALEA legislation. A basic principle of legal interpretation is that newer laws trump old on
by declan 12y ago
The first statute you're quoting, 47 USC 1002, was part of the 1994 CALEA legislation. A basic principle of legal interpretation is that newer laws trump old ones if that is clearly the legislative intent.
So if the 1997 ban-strong-crypto bill had been enacted, it would have overriden that portion of CALEA -- effectively repealing it -- to the extent it was in conflict.
Put another way, if Congress has the power to say X one year, they typically have the power to say not(X) the next year.
- xnull2guest 12y agoIt would be interesting to see what a crypto ban would do if it were to override CALEA and the Stored Communications Act. Where a key escrow solution was previously required, a sudden ban on encryption would do what - force the companies to change key sizes? Since companies are already required to give plaintext access to communications and records (if they provide the security themselves), what difference would a crypto-ban really achieve other than removing the companies in question from knowing which records law enforcement sought to access?
- declan 12y agoWell, there is no U.S. law requiring key escrow. There are a very few laws that impose escrow-like requirements on some sectors. If you're a financial services firm you may be required to monitor employees' email, which makes some forms of encryption tricky. And even the CALEA excerpt you quoted above authorizes telecom carriers to provide secure end-to-end crypto (they wouldn't have "the information necessary to decrypt the communication"). CALEA doesn't apply to the tech firms HN knows and loves; they're not telecom carriers, a term of art. But putting all that aside for the moment, banning crypto without backdoors would, at a minimum, create real difficulties for U.S. companies and require many open source/free software projects to move overseas. It would also make felons of many HN readers. That's no exaggeration; an ex-Mozilla fellow now building the crypton.io framework wrote to me this evening saying: "That bill would have made my work criminal." https://twitter.com/deezthugs/status/556678844120576000 https://twitter.com/deezthugs/status/556678844120576000 To be clear, I don't believe the FBI|NSA|DOJ|DEA|DHS|CIA|etc. cadre of TLAs are pushing for a ban on domestic crypto now. But they tend to take the long view. Look very carefully at what is eventually proposed. Is it a ban on whole-disk encryption without backdoors? Would it extend to PCs? What about open source projects and AOSP? Would mere possession of non-backdoored crypto be a crime, or distribution, or commercial sale? Etc. I view a lot of this as the Feds trying to pressure Apple and Google into adopting an escrowed solution for encrypted devices -- without actually enacting a law. Laws are public, subject to legal challenge (a federal appeals court in the Junger case held there are 1A issues involved in a crypto ban), and tend not to make it through Congress very quickly. But extralegal pressure can be applied in secret, is not subject to legal challenge, and can happen much sooner. HN threads in the past have discussed some of these extralegal pressures that can be brought to bear. Multi-billion dollar .gov contracts are a big one too.
- xnull2guest 12y agoThank you for the informative post. By letter of the law, CALEA does not require key escrow. Do you believe that in practice along with extralegal pressure in the manner described above, that CALEA and associated laws amount to near ubiquitous key escrow?
- declan 12y agoNope. I think the opposite, in fact. But it's late in the SF area, and it's time for me to go to sleep. Happy to resume this in the morning.
- xnull2guest 12y agoCheers for good sleep! Do you believe that the USG can get access to nearly any telecommunication record in close to real time for emergencies if it needs it, and to nearly any telecommunication record history up to some amount of time later for investigations? If you do not, could you defend this belief - it runs counter to conventional wisdom. Presuming you do believe that access to telecommunication records can be made post hoc and/or on demand: do you believe this is because of weak crypto (KASUMI, A/5, etc) or because there is no encryption for there to be escrowed for large or critical parts of the infrastructure? Or is it something else?
- declan 12y agoThere are too many questions here crossing too many areas of the law to answer in an HN comment; some of the language you're using includes legal terms of art where the meaning is not necessarily intuitive. A blog post would be more suitable and I can't take that much time away from my work on http://recent.io/ http://recent.io/ But briefly: You should assume, as I've written in many places in the past, that your records in the hands of the AT&T/VZ/etc. phone companies can easily be accessed by TLAs. The NSA itself brags of a surveillance "partnership" with those companies, as I wrote in this CNET piece: http://www.cnet.com/news/surveillance-partnership-between-nsa-and-telcos-points-to-at-t-verizon/ http://www.cnet.com/news/surveillance-partnership-between-ns... In those cases, crypto has little to do with it. In this HN comment yesterday, I wrote here about some of the privacy differences between our favorite Silicon Valley companies and AT&T/VZ/etc.: https://news.ycombinator.com/item?id=8902638 https://news.ycombinator.com/item?id=8902638