4 ms·
> How is that any different to information I store in my head? It's the difference between a 4th Amendment issue and a 5th Amendment issue. Whether or not the
by csandreasen 11y ago
> How is that any different to information I store in my head?
It's the difference between a 4th Amendment issue and a 5th Amendment issue. Whether or not the police could search your phone used to fall squarely within the bounds of the 4th Amendment. If you encrypted it yourself, it would then be a 5th Amendment issue - you have a right to not self-incriminate.
With the new iPhones, someone else (Apple) decided to encrypt your phone for you in such a way as to prevent any searches, regardless of whether or not there's a warrant involved. In doing so, Apple created a class of evidence that cannot be searched. People here tend to frame that in terms of my phone or my data - why should the police be searching me? Most of us will never have a search warrant issued on us - they exist to collect evidence of crimes and we're generally not criminals. If you step back and and look at it from a law enforcement perspective, do you really want companies that manufacture popular devices suddenly deciding that data on their products cannot be used as evidence in a crime? I'll provide my own reductio ad absurdum in response to your brain-scanning argument and ask how you would feel if the cops told you "Sorry, there's nothing we can do. It looks like your spouse was shot with an iGun."
A split key solution would definitely stop a border guard - the data is still encrypted and cannot be decrypted without cooperation from all n parties that hold the pieces of the key. No, it won't technically stop them from installing a backdoor on your laptop, but I think you're kind of shifting goalposts with that argument. We're talking about warrants to decrypt data here.
- zaroth 11y agoWhat Apple did was remove itself from the equation. Long before Apple, anyone could encrypt data they felt like encrypting, and trust that short of divulging the key, that data could not be decrypted. The only thing that has changed is the ease of use around applying the encryption. I don't agree that making encryption "too easy to use" should be illegal. Of course with iPhones we are still encrypting the data ourselves. You choose to apply a PIN lock (or not). If you choose to allow a fingerprint to unlock the phone from a cold boot, then the government can collect your fingerprint and decrypt your files (fingerprints are not testimony). If you choose a weak PIN, the government can guess it and decrypt your files. All Apple has done is choose to design a secure encryption library, one where there is no obvious backdoor, and one where they cannot be co-opted into secretly disclosing your personal data to the government through a 3rd-party warrant. The fact is, Apple is not in possession of your data, and they don't want to be in possession of your data. If somehow Congress manages to pass CALEA-type laws requiring Apple to maintain a backdoor into our data, we'll just bypass Apple and keep the data safe ourselves. It might take a few more years for the technology to become equally usable, but the 1st amendment guarantees our right to develop and publish and freely license the software necessary to achieve the end goal, namely, that people have the ability to control access to personal data that they themselves collect and maintain. Thankfully Tim Cook has the experience and unique perspective on these matters to truly understand the value and necessity of being able to keep personal data private. I'm sure the path that brought him to these strongly-held personal beliefs was not easy, but I believe the world actually is a better place because of it. I am also very thankful to live in a country where Tim can help craft a device which upholds his beliefs, and it would be a sad day indeed to see that freedom stifled. You're argument about "an encryption system installed by the manufacturer that the manufacturer itself cannot decrypt" does not make any sense. It sounds like an argument against functional encryption, which is an argument against functional computers. Please try following your thought to its logical conclusion, and consider if it's really a country you would want to live in?
- AnthonyMouse 11y ago> In doing so, Apple created a class of evidence that cannot be searched. This seems to be the fatal flaw in your argument, because you aren't recognizing the duality inherent in it. Apple 1) created a class of evidence 2) that cannot be searched. That class of evidence didn't exist in 1776 or 1976 or 1996. The police can solve crimes without it as they've been doing for hundreds of years. > "Sorry, there's nothing we can do. It looks like your spouse was shot with an iGun." Sorry, there's nothing we can do... except interview witnesses and suspects, check alibis, investigate the crime scene, autopsy the body, look for motive, review surveillance footage, etc. etc.
- csandreasen 11y agoI don't think the "police have been solving crimes for centuries" argument is very persuasive. Back in 1996, we didn't have people walking around conducting half of all of their communication through a little box that they always carry with them. What used to entail walking across town and physically talking to someone is often now just a Facebook update or text message. Searching a cell phone now is probably about comparable to searching a home in 1996 in terms of how invasive it is, but we weren't making the argument two decades ago that the police shouldn't be able to get a search warrant for your home because it's too invasive. To continue following that logic out, neither phones in general nor surveillance existed in 1776. Does that mean the police shouldn't be able to get warrants to read someone's phone records or see surveillance footage because they could still gather evidence just fine before those existed?
- AnthonyMouse 11y ago> Back in 1996, we didn't have people walking around conducting half of all of their communication through a little box that they always carry with them. What used to entail walking across town and physically talking to someone is often now just a Facebook update or text message. Searching a cell phone now is probably about comparable to searching a home in 1996 in terms of how invasive it is, but we weren't making the argument two decades ago that the police shouldn't be able to get a search warrant for your home because it's too invasive. Searching a cell phone is much more than what they would get from searching a home. Twenty years ago if a suspect walked across town two weeks before the crime and had a conversation with someone, there would be no automatic record of it even happening, much less the content of the conversation being recorded indefinitely. Even for written correspondence, people rarely keep every letter they've ever received and even less often keep a copy of every letter they've ever sent. People have no obligation to carry around a tracking device that records everywhere they go and everything they say in a format understandable by the government. > To continue following that logic out, neither phones in general nor surveillance existed in 1776. Does that mean the police shouldn't be able to get warrants to read someone's phone records or see surveillance footage because they could still gather evidence just fine before those existed? You keep conflating the question of whether they can get a warrant with the utility of doing so. Encryption has existed longer than the United States. A warrant grants them the ability to look at your stuff, it doesn't imply that they'll be able to understand it, or even that you'll have kept any stuff worth looking at. For example, shouldn't you have the same objection to Snapchat as you have to encryption? The government's warrant gives them even less if the content no longer exists than if it exists encrypted. But the idea that people should be prohibited from automatically deleting old information is pretty clearly ridiculous.
- m4x 11y ago> No, it won't technically stop them from installing a backdoor on your laptop, but I think you're kind of shifting goalposts with that argument. We're talking about warrants to decrypt data here. That backdoor can then be used to acquire my encryption key and decrypt my data, so I think it's still entirely relevant. Less relevant but still entirely reasonable is my concern that compromising hardware during a border crossing should be considered even remotely acceptable! > It's the difference between a 4th Amendment issue and a 5th Amendment issue. Whether or not the police could search your phone used to fall squarely within the bounds of the 4th Amendment. If you encrypted it yourself, it would then be a 5th Amendment issue - you have a right to not self-incriminate. I don't think the main change between old phones which could be searched under the 4th amendment and new phones which cannot is encryption. The main change is that an old phone used to be a relatively impersonal tool akin to a car or gun, while a new phone holds an incredible amount of intensely personal information about a person. Seizing an old phone was no big deal; it would be as if the police wanted to seize the spade in my garage. Go for it. Use it to eliminate me from your investigations. Seizing a new phone, however, gives many of my intimate secrets to LEOs who are probably taking a hostile, confrontational stance towards me. It also gives those people an enormous amount of power over me. They now have access to my email accounts, forum accounts, personal contacts etc and could easily impersonate me or blackmail me. In theory they shouldn't take advantage of that power but I have no doubt that they would do so anyway, in some cases at least. The reason I mentioned mind-reading (how do I say that without sounding like a kook?) is that it illustrates that point with a bit more impact. At some point it will become possible, and probably even desirable under the right circumstances, but the potential for abuse is enormous and it will need to be governed under far stronger laws than anybody is currently protected by. The 5th amendment might be adequate if it can be used to simply outlaw the practice, but I doubt that will happen. So how do you control what personal data LEOs have access to? And this exact problem exists right now with your smart phone, albeit to a lesser extent. Another way of putting it would be: LEOs can currently request a warrant for particular searches - phone tap, call records, physical property at a specific address etc. But if they get one that covers "smartphone" (or, later, memories), that basically gives them access to everything, almost all of which will be quite personal and entirely unrelated to the case. So how do you control what they get access to? Right now, the most secure option is to never record anything personal on any device, but that's harder said than done (and nobody on HN has achieved it!). Another option is to encrypt anything you consider private, and hope that your hardware or encryption scheme hasn't already been broken.