Slashdot Mirror


U.S. Gov't Grapples With Clash Between Privacy, Security

schwit1 writes: WaPo: "For months, federal law enforcement agencies and industry have been deadlocked on a highly contentious issue: Should tech companies be obliged to guarantee U.S. government access to encrypted data on smartphones and other digital devices, and is that even possible without compromising the security of law-abiding customers?"

NSA director Adm. Michael S. Rogers wants to require technology companies to create a digital key that could open any smartphone or other locked device to obtain text messages or photos, but divide the key into pieces so that no one person or agency alone could decide to use it. But progress is nonexistent:

"The odds of passing a new law appear slim, given a divided Congress and the increased attention to privacy in the aftermath of leaks by former NSA contractor Edward Snowden. There are bills pending to ban government back doors into communications devices. So far, there is no legislation proposed by the government or lawmakers to require Internet and tech firms to make their services and devices wiretap-ready."

134 comments

  1. What's the acceptable limit? by Anonymous Coward · · Score: 2, Funny

    So what's the acceptable limit?

    Should they be allowed to watch you urinate?

    Should they be allowed to watch you defecate?

    Is it okay if they do this with a device that has an "Internet of Things" sticker on it?

    1. Re:What's the acceptable limit? by __aabppq7737 · · Score: 2

      I wouldn't doubt thaht the NSA has broken iPhone's encryption. https://firstlook.org/theinter...

    2. Re:What's the acceptable limit? by fustakrakich · · Score: 1

      Should they be allowed to watch you urinate?

      Should they be allowed to watch you defecate?

      Sure! If can watch them fornicate...

      --
      “He’s not deformed, he’s just drunk!”
    3. Re:What's the acceptable limit? by fustakrakich · · Score: 1

      *sigh* some day I will see the things that are missing, oh wait, I do see things that are missing, until it's too late of course. I should be a procurement officer for the Pentagon.

      --
      “He’s not deformed, he’s just drunk!”
    4. Re:What's the acceptable limit? by Opportunist · · Score: 1

      They should be required to! That might make them learn.

      Think Clockwork Orange like...

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    5. Re:What's the acceptable limit? by MrBigInThePants · · Score: 1

      Oh please. That is a false dichotomy.

      The only thing "clashing" here is the high tech political donations vs the military and surveillance dollars.

      Its funny how the only "clashes" follow this same pattern...ok not funny at all.

    6. Re:What's the acceptable limit? by Hognoxious · · Score: 1

      Should they be allowed to watch you urinate?

      Should they be allowed to watch you defecate?

      The government? Hell no.

      But if Twiglebook and their selected partners wish to serve up targeted ads to enhance my waste elimination experience then sign me up!

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    7. Re:What's the acceptable limit? by Anonymous Coward · · Score: 0

      I feel that most of this stuff is smoke and mirrors anyway, The best way to convince most people that they cant is to complain that they cant, someone needs to reign this agency in, someone who they dont have the goods on.

    8. Re:What's the acceptable limit? by Jane+Q.+Public · · Score: 4, Insightful

      I wouldn't doubt thaht the NSA has broken iPhone's encryption.

      This proposal by NSA mirrors the Clipper Chip/Skipjack + Key Escrow system proposed back in the early 90s. People didn't trust the government with their keys THEN... why the hell should they do so NOW, given that government intrusion into our lives has only increased in the interim?

      Unlike the 90s, by now they have proved they can't be trusted.

    9. Re:What's the acceptable limit? by Anonymous Coward · · Score: 1

      This Admiral is a treasonous POS. He took an oath to defend the constitution and here he is undermining it.

    10. Re:What's the acceptable limit? by Anonymous Coward · · Score: 0

      No matter how strong the encryption is, in the end it boils down to the strength of user's password (I don't think there is any way to use keyfiles in iThings). So, bruteforce will work against most people who use easy, short or just the same passwords everywhere. This omg-encryption circus by law enforcement is just a bluff.

    11. Re:What's the acceptable limit? by Anonymous Coward · · Score: 0

      So what's the acceptable limit?

      How does one define a limit that isn't an arbitrary line in the sand? How does one enforce limitation of powers particularly given the government's reluctance to obey laws. How does one hold the government, in particular, the bureaucrats with the guns and the prisons, accountable? Until these can be done, any demand for a limit is pointless.

    12. Re:What's the acceptable limit? by Anonymous Coward · · Score: 0

      They want *instant* access to your files and communications. They don't have weeks or months to crack the encryption, if they even can.

    13. Re:What's the acceptable limit? by Anonymous Coward · · Score: 0

      People didn't trust the government with their keys THEN... why the hell should they do so NOW, given that government intrusion into our lives has only increased in the interim?

      Because government deserved this trust by not killing anybody who is still capable of voting? It's the "Russian Roulette is safe or I would not still be playing it" argument.

      Unlike the 90s, by now they have proved they can't be trusted.

      Ah, but terrorists? And child molestors?

      And I am not talking about the DHS and Child Protective Services here. Because if I did, I'd not last long.

    14. Re:What's the acceptable limit? by Anonymous Coward · · Score: 0

      People didn't trust the government with their keys THEN... why the hell should they do so NOW...

      Because they have had twenty five years of getting people desensitized to mass surveillance. Talk to almost anyone under 40 and they really don't care that the government is listening in on all their phone conversations or tracking their car wherever they go. Besides today's government will simply "grant" themselves the power and we won't have any say, to protect us from terrorists of course. "To serve and protect" has really become "to oppress and enslave".

      NSA director Adm. Michael S. Rogers wants to require technology companies to create a digital key that could open any smartphone or other locked device to obtain text messages or photos, but divide the key into pieces so that no one person or agency alone could decide to use it.

      I laughed myself to tears when I read this (especially the part about warrants based on probable cause, which the feds haven't used for years). Like all these corrupt government agencies are not going to share their piece of the key with every other corrupt government agency, or threaten any companies with secret lawsuits or deals, like the NSA bullying AT&T into doing illegal mass surveillance for them (Hepting v. AT&T). This is just pure media spin for stupid people to believe.

    15. Re:What's the acceptable limit? by HiThere · · Score: 1

      With a gradation in punishment. Probably exponential. The current head of the NSA should be slowly boiled in tar. It's difficult to imagine something appropriate for his boss.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  2. Break the key apart? by __aabppq7737 · · Score: 1

    , but divide the key into pieces so that no one person or agency alone could decide to use it.

    Exactly how do they intend to split a key; by piling layers of encryption atop each other or by splitting the RSA public key modulo's factors into multiple authorities?

    Given the option of piling layers of encryption on top of each other, it would seem that private keys would need to be divulged to create this encrypted comm. system

    1. Re:Break the key apart? by Anonymous Coward · · Score: 0

      There is no KNOWN public law that will compel them to comply. That is different from no law.

    2. Re:Break the key apart? by Anonymous Coward · · Score: 0

      Simple: encrypt users private key with agency's public key and force storage of this package on the phone.
      When needed agency can decrypt user's key with agency's private key, which they can use to decrypt contents of the phone.

      Now agency's golden private key becomes most valuable item on the planet. Who can guarantee that it will be secure within agency? (for answer see Snowden snafu).

    3. Re:Break the key apart? by bohmt · · Score: 2

      , but divide the key into pieces so that no one person or agency alone could decide to use it.

      Exactly how do they intend to split a key; by piling layers of encryption atop each other or by splitting the RSA public key modulo's factors into multiple authorities?

      Given the option of piling layers of encryption on top of each other, it would seem that private keys would need to be divulged to create this encrypted comm. system

      The modulo is a semiprime number, so it has only 2 factors. I think he wants a Threshold cryptosystem, where m out of n parties need to use their keys for it to work.

    4. Re:Break the key apart? by The+New+Guy+2.0 · · Score: 1

      Yep, they don't understand "digital tear point"...

      It's a way of sending a block to a lower-level person that gives them the headline and some of the story, enough to convince them to hand it to the high-level authorities that get the rest of the story by decrypting a second block that's only for them.

      Breaking a key apart just means they have to get together and they they have everybody's secrets... that's not how it's supposed to be done.

    5. Re:Break the key apart? by __aabppq7737 · · Score: 1

      splitting the RSA public key modulo's factors

      The user generates 64 bits of the first key, the US Govt. generates the next 64 bits, the Canadian govt. generates the next 64 bits, et cetera. Apply same process for both keys, then use a one-way conversion process to create a new key from the old one such that only govt.s whose random numbers went into the making can reverse the new key in a finite amount of time. Of course, this would get hurt by FREAK-like vulnerabilities.

    6. Re:Break the key apart? by The+New+Guy+2.0 · · Score: 2

      There's no such thing as a secret law in the USA... it's either in Lexis or it never existed.

    7. Re:Break the key apart? by Anonymous Coward · · Score: 0

      It's trivial to split a key. Generate a random metakey, XOR them together, and distribute the metakey and the result. XORing those two pieces together will produce the original key, but either alone is useless. Repeat with new metakeys if you want it in more than two pieces.

      (Strictly speaking, this is a form of encryption: a one-time pad. It's usually impractical, but it's practical in this case, and completely unbreakable.)

      Of course, as a safeguard against abuse this is completely worthless, because all the pieces of the key are going to be held by entities that are willing to cooperate in carrying about the abuse.

    8. Re:Break the key apart? by davester666 · · Score: 2

      But there are secret interpretations of the law, where the gov't basically does lawyer-shopping, going from one lawyer to the next [whom they hire], to write a legal opinion about something, and they just keep going through lawyers until they get the 'opinion' they want, and then use it as a legal justification for doing something.

      You would think they would at least have to run it by a judge, but no. It only gets looked at by a judge:

      -if someone finds out about it [hard to do when it is classified as top secret]
      -you have standing to challenge it [good luck with this, given how much leeway judges are giving the gov't in most cases]

      --
      Sleep your way to a whiter smile...date a dentist!
    9. Re:Break the key apart? by Anonymous Coward · · Score: 0

      Exactly how do they intend to split a key

      The keyword you are looking for is "secret sharing", e.g. the secret is the X=0 value of a polynome p(X) of high enough degree and you distribute values where p(X) = 0. Knowledge of a single such point (X,0) does not discern anything about (0, SECRET), but knowledge of enough such points does.

    10. Re:Break the key apart? by Shakrai · · Score: 1

      You would think they would at least have to run it by a judge

      That's not how the American judicial system works. Courts can only rule on cases and controversies, you can't go to a Federal Judge to get his opinion on the legality of a desired course of action. That's what lawyers are for, both in private and government practice. Lawyer-shopping as you describe does happen, both in the private sector and in Government, but it's generally considered ill advised to ignore the mainstream legal consensus in favor of fringe opinions. If the matter does ultimately end up in court you're not going to have much of a leg to stand on.

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
    11. Re:Break the key apart? by Anonymous Coward · · Score: 0

      https://en.wikipedia.org/wiki/Secret_sharing

      Go there and learn my friend, it isn't actually a completely brain-dead idea.

      Normally, I am against anything the NSA says, but in this case, he is at least proposing something that COULD actually be handled securely. In theory, if bureaucracies aren't corrupt, and just NSL the other peoples parts of the secret away and muzzle them.

    12. Re:Break the key apart? by Zontar+The+Mindless · · Score: 1

      At one time, there were no secret courts in the USA. And we see what happened to that.

      Just something to think about.

      --
      Il n'y a pas de Planet B.
    13. Re:Break the key apart? by PopeRatzo · · Score: 1

      Exactly how do they intend to split a key

      They don't. This is just for public consumption. They have no intention of slowing themselves down with any privacy safeguards.

      They just think everybody's stupid. And, they would be right, except post-Snowden the number of people paying attention has gone up.

      --
      You are welcome on my lawn.
    14. Re:Break the key apart? by PopeRatzo · · Score: 4, Insightful

      There's no such thing as a secret law in the USA... it's either in Lexis or it never existed.

      There's not supposed to be, but there are. Every time a secret court like FISA makes a secret decision, new secret law is created on the fly. Secret precedent.

      And by the way, there's also supposed to be no such thing as anonymous local police in the USA, but they take off their ID and pull balaclavas over their faces at the sight of three black people walking down the street with a protest sign.

      There are a lot of things in the USA that are not supposed to exist. Secret laws, secret courts, secret trade agreements. Secret police. Secret police blacksites. Secret "crowd control" weapons for the secret police to use domestically. Torture. Rendition. Off-shore prisons. Extrajudicial assassination.

      And secret donors, of course. That's what it's all for. There was a secret coup in the US decades ago, and we were collateral damage.

      --
      You are welcome on my lawn.
    15. Re:Break the key apart? by Anonymous Coward · · Score: 0

      The FISA court does actually advise the NSA and other parties on how to construct their wiretap requests so that they are successful. This was discovered by the Obama's commission that studied the FISA court shortly after Snowden broke the ice. A large part of the reason why they get away with it is because of the secret nature of the court, and the fact that only one party (the government) is permitted to attend FISA proceedings.

    16. Re:Break the key apart? by Anonymous Coward · · Score: 1

      Unfortunately, the doctrine of parallel construction, which has been upheld in Federal court, means that there is. There have been several high-profile cases in Federal court settled based on secret case law, in which the judge's ruling itself was partially sealed. That's basically the definition of secret law. Case in point:

      https://firstlook.org/theintercept/2015/03/26/new-low-obama-doj-federal-courts-abusing-state-secrets-privilege/

      Unfortunately, Congress itself often does not have access to information it needs to make law, and they are not considered authorized to do so. If Congress cannot write law on matters which they are not cleared for, then someone else must.

      https://firstlook.org/theintercept/2015/04/03/property-insurance-companies-flooded-dark-money-groups-tied-gop-cash/

    17. Re:Break the key apart? by Anonymous Coward · · Score: 0

      Of course, under such a law, each agency could create a key of all zero's and be in compliance.

    18. Re:Break the key apart? by Anonymous Coward · · Score: 0

      There's no such thing as a secret law in the USA... it's either in Lexis or it never existed.

      Boy are you naive. Read some articles about people being refused an airline ticket because they are on the secret "no fly" list. Several have asked to see the law that allows that and they were told by TSA goons (and the courts) that the law itself is a secret and they are forbidden from reading it.

    19. Re:Break the key apart? by davester666 · · Score: 1

      That's not the kind of thing I'm talking about. More like the "we can kill an American anywhere on Earth except within the US, if we think he is a bad person". Or "the president or someone he delegates to, can decide you are a bad person, and can have you secretly detained and removed from US soil, without any judicial oversight or notification to anyone, and then keep you secretly detained for as long as they want".

      But he also pinky-swears not to abuse this power.

      --
      Sleep your way to a whiter smile...date a dentist!
    20. Re:Break the key apart? by Pseudonym · · Score: 1

      Regulations don't always appear in Lexis. They aren't laws, but they are laws.

      --
      sub f{($f)=@_;print"$f(q{$f});";}f(q{sub f{($f)=@_;print"$f(q{$f});";}f});
    21. Re:Break the key apart? by Shakrai · · Score: 1

      More like the "we can kill an American anywhere on Earth except within the US, if we think he is a bad person"

      That's not the power that the Executive has actually claimed for itself. They've claimed the power to kill Americans engaged in hostilities against the United States on foreign battlefields. Devil's Advocate: Benedict Arnold led enemy troops on the battlefield. If a solider in the Continental Army had the opportunity to take a shot at him would you regard it as murder?

      Or "the president or someone he delegates to, can decide you are a bad person, and can have you secretly detained and removed from US soil, without any judicial oversight or notification to anyone, and then keep you secretly detained for as long as they want"

      Citation needed.

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
    22. Re:Break the key apart? by davester666 · · Score: 1

      The battlefield for the war on terror is "everywhere". And it's just a couple of guys in a room, none of whom are particularly impartial.

      And this is a nice summary:
      http://americablog.com/2014/05/post-constitutional-era-scotus-allows-capture-rendition-u-s-citizens-ndaa.html

      --
      Sleep your way to a whiter smile...date a dentist!
    23. Re:Break the key apart? by Anonymous Coward · · Score: 0

      The plural of "zero" is "zeros" you semi-literate fuck.

    24. Re:Break the key apart? by Shakrai · · Score: 1

      The law that he linked does not say what he thinks it says. The notion that people captured on the battlefield can be held without trial until the end of hostilities is not a new one. Nor is the notion that unlawful combatants can be held accountable for their actions.

      I see nothing in that legislation that authorizes military custody for people on American soil. Such an action is arguably permissible in limited instances, but I'm not seeing it within the legislation that random blog you linked is griping about.

      And it's just a couple of guys in a room, none of whom are particularly impartial.

      That's not new either. FDR personally ordered the death of Yamamoto. He didn't get a trial, nor was he killed by happenstance on the battlefield, he was deliberately targeted for assassination. I don't see the practical difference between that and our current drone campaign. Dead is dead, it doesn't matter if you're shot down by a manually piloted P-38 or bite it when an Air Force tech halfway around the world sends a hellfire missile your way.

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
    25. Re:Break the key apart? by Anonymous Coward · · Score: 0

      This is just a red-herring idea. The crypto techniques he's describing are nowhere near ready for real-world usage, much less integration into the foundations of the web - even the simplest make TLS look like a walk in the park, and we're still struggling to pull that one together.

      He's essentially saying that since bank vaults are hard to get into, we should just have our money guarded by sharks-with-lasers. Never mind that it's unproven, fanciful, not the least bit practical or realistic... Oh wait, the military-industrial guys probably claim they can do it for $5B.

    26. Re: Break the key apart? by Anonymous Coward · · Score: 0

      FDR also locked up tens of thousands of Japanese Americans.

      Lincoln very nearly had his Chief Justice arrested.

      During times of war presidents often do things illegally. Sometimes the courts go along. That doesn't make it right, or even legal.

      But if you insist on equivocating, at least consider that the War on Terror will never end. Allowing the Executive some leeway during a time of war is one thing. Giving him that power for the foreseeable future is one of the defining characteristics of a military dictatorship.

       

    27. Re:Break the key apart? by dbIII · · Score: 1

      Easy, they give the key parts to other agencies and then the NSA seconds people from those other agencies so that they've got the full key fifteen minutes after the parts are sent out.
      There's so much pissing in each others pockets and "retiring to private enterprise" but getting millions of dollars in government work that there's no clear line between agencies and between government and private companies (eg. those Booz losers Snowden worked for). If the Chinese, Iranians, Russians etc don't have top level access into that shambolic mess then they are not trying.

    28. Re:Break the key apart? by dbIII · · Score: 1
      I'd say they understand all right and this is just PR. Remember the big fuss about needing a launch code, and then the launch code was all zeros so that it was just the same as if there was no launch code.

      Breaking a key apart just means they have to get together and they they have everybody's secrets

      Yes. I give it fifteen minutes, only because somebody will be making coffee before sharing the key in the first morning.

    29. Re:Break the key apart? by Anonymous Coward · · Score: 0

      Obviously, this won't work since they would have to disallow people from changing their master encryption key at will. There's enough open-source software out there already to thwart this plan, even if they tried to legislate it. They simply can't understand that the battle has been fought and lost...in the '90's.

    30. Re:Break the key apart? by MechaStreisand · · Score: 1

      If you don't see a difference between shooting down a warplane in a time of war, and attacking people just walking around without a declaration of war, thus extending it to potentially anyone on the planet, at any time, in a "war" that has no objectives, no defined enemy, and will never end, you are a truly evil person. Which you are.

      --
      Disclaimer: IANAL. This post is, however, legal advice, and creates an attorney-client relationship.
    31. Re: Break the key apart? by Anonymous Coward · · Score: 0

      That's why even though the law is public but the lawyer's interpretation is not, until it has to bevrevealed because of a case brought that depends on that interpretation. In many cases, the government does not bring cases that could force them to reveal these secret interpretations, they "anonymously" feed the information they illegally collected to another agency to let them pursue the case. Its like money laundering, but for evidence instead of goods.

    32. Re:Break the key apart? by anagama · · Score: 2

      We all know how it is _supposed_ to work. We also know how it _actually_ works.

      For example: GWB used secret legal memos to get around the due process clause when locking people up in Gitmo. Obama used secret legal memos to get around the due process clause when executing people. And the courts were less than useless in doing anything about it, bowing out over litigant's standing.

      So ultimately, the law is basically whatever the President says it is. Yep -- that's authoritarian and fails to fit our mythical concept of America.

      --
      What changed under Obama? Nothing Good
    33. Re:Break the key apart? by anagama · · Score: 1

      Succinct. Eloquent. Perfect.

      --
      What changed under Obama? Nothing Good
    34. Re:Break the key apart? by murkwood7 · · Score: 1

      Disclaimer: IANAL. This post is, however, legal advice, and creates an attorney-client relationship.

      By claiming to be an attorney, (as in you are giving legal advice, thus laying claim to the attorney side of the attorney-client phrase), you _are_ claiming to be a lawyer:

      http://www.lawyeredu.org/attorney-vs-lawyer.html

      Thus, YOU are the evil one :)

      --
      - X/Y -
    35. Re:Break the key apart? by Agripa · · Score: 1

      There are a lot of things in the USA that are not supposed to exist. Secret laws, secret courts, secret trade agreements. Secret police. Secret police blacksites. Secret "crowd control" weapons for the secret police to use domestically. Torture. Rendition. Off-shore prisons. Extrajudicial assassination.

      Secret interrogation centers:

      http://www.theguardian.com/us-...

    36. Re:Break the key apart? by Agripa · · Score: 1

      Parallel construction also gets around 4th amendment restrictions on searches and seizures. The remedy for an unlawful search or seizure is exclusion of evidence but that does not apply when parallel construction is used.

    37. Re:Break the key apart? by Lennie · · Score: 1

      I believe I've seen Bitcoin Multi-Signature wallets use Shamir's algorithm:

      https://en.wikipedia.org/wiki/...

      A Bitcoin 'wallet' is the private key which allows you to spend your the Bitcoin you own.
      A Multi-Signature wallet is a wallet for which you need 2 out of 3 keys to spend the Bitcoin.

      How something like that could be used in a secure system in this case I'm not so sure about.

      --
      New things are always on the horizon
    38. Re: Break the key apart? by Anonymous Coward · · Score: 0

      Write encryption FOSS we can't break? Go to jail. You may not understand it but authority is power. Real power. Nerds should understand this since they've been at the mercy of stronger people most of their lives. Where was all this strength and courage you boast about while you were give brown swirlies?

    39. Re:Break the key apart? by Shakrai · · Score: 1

      The war has a clearly defined enemy, which you would know if you had actually bothered to read the legislation that we're discussing. It defines the enemy as Al Quada, the Taliban, and those persons or groups that support them.

      The Executive neither has nor has claimed a blank check. You may disagree with the drone campaign, I'm not entirely certain that I support it, but let us at least agree to confine our discussion to the facts rather than making shit up.

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
    40. Re:Break the key apart? by Anonymous Coward · · Score: 0

      Secret birth certificates...

      https://firstlook.org/theintercept/2014/10/02/the-nsa-and-me/

      This so-called “birth certificate,” the Justice Department report concluded, meant the NSA did not have to follow any restrictions placed on electronic surveillance “unless it was expressly directed to do so.” In short, the report asked, how can you prosecute an agency that is above the law?

      And secret donors, of course. That's what it's all for. There was a secret coup in the US decades ago, and we were collateral damage.

      Yes. I think anyone of any political leanings can attest to this.

      The other possibility, there have been countless accidents and it is just pure coincidence the U.S. lost its way and is just a little bit confused...is pure speculation and lacking any evidence.

      If there has not been various secret coups in the US, God hates us all. Option 3?

    41. Re:Break the key apart? by davester666 · · Score: 1

      Except that is a blank check. They can declare ANYONE to be a member of that set of people, without any oversight by anyone. And they can also have you killed on sight for being a member of that group. And there isn't anything anyone can do about it, either before or after you are killed.

      It amounts to "that guy standing over there is bad. kill him now."

      --
      Sleep your way to a whiter smile...date a dentist!
    42. Re:Break the key apart? by PopeRatzo · · Score: 1

      The other possibility, there have been countless accidents and it is just pure coincidence the U.S. lost its way and is just a little bit confused.

      Never underestimate the perfidy inherent in a system that's designed around profits. Never underestimate the greed of those who already have wealth beyond the dreams of avarice.

      There is a reason someone who has 100 million strives to get a billion. It's a pathology that tells them they should have a billion because they're "worth it". And when you're "worth it" you can rationalize any behavior to get "it".

      And no, if there is a God, he does not "hate us all". If he did, he wouldn't have given us music and a spring day.

      --
      You are welcome on my lawn.
    43. Re:Break the key apart? by JesseMcDonald · · Score: 1

      You could use Shamir's Algorithm, but the recommended way to create a multi-signature Bitcoin address is to use a transaction script which separately checks each of the desired keys. That way each key holder can sign the transaction independently of the others, and—more importantly—there is no need to get all the key fragments together in one place to reconstruct a master key.

      That last point, incidently, happens to be one of the problems with this proposal; once the master key has been reconstructed, anyone with access to it would have unrestricted access to every backdoored device. Key-splitting is really only intended for cases where the master key need only be used once, not on a routine basis as can be expected in this scenario. Rather than splitting a master key, a better approach would be to have a number of separate keys and require a certain number of signatures on a digital "warrant" which specifically identifies the device to be decrypted. (It wouldn't hurt to include the other Constitutionally-mandated warrant information, either, just for future reference.) The device would then need to validate the device ID in the warrant and check the signatures against a list of known public keys before decrypting itself.

      --
      "The state is that great fiction by which everyone tries to live at the expense of everyone else." - Bastiat
    44. Re:Break the key apart? by Shakrai · · Score: 1

      I hate to break it to you but that's pretty much how war works, by definition. You don't get judicial review on the battlefield. You get shot at. If you don't like it then don't take up arms.

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
    45. Re:Break the key apart? by davester666 · · Score: 1

      So, to avoid being killed as part of the war on terror, we have to leave the planet, because the US population has lost control of it's government...

      --
      Sleep your way to a whiter smile...date a dentist!
    46. Re:Break the key apart? by Shakrai · · Score: 1

      No, certain people think we've lost control of our Government. I am a member of the American electorate, more informed than most, and I'm content with the oversight that exists. I don't particularly care for our current President, or the one that preceded him, but on this particular issue I'm satisfied with the decisions they've made.

      We could talk about the oversight mechanisms that exist, if you'd like, though I'm skeptical that you would approach the issue with an open mind based on your comments to date.

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
    47. Re:Break the key apart? by davester666 · · Score: 1

      It's only acceptable to you because you don't happen to live where they are killing a bunch of their 'targets'. There, if you happen to have gone to the wrong funeral, or the child of the wrong person, or just sitting in the wrong cafe, or walking on your own property with a rifle, oops, you get to be posthumously declared a terrorist. Hope you weren't with your wife and children.

      --
      Sleep your way to a whiter smile...date a dentist!
    48. Re:Break the key apart? by Shakrai · · Score: 1

      That kind of shit has always happened during wartime. I fail to see how some non-combatant dying in a drone strike is any worse than the non-combatants that died in Tokyo and Dresden. We aren't deliberately trying to kill them, sometimes they're too close to legitimate targets, other times we misidentify them.

      Newsflash: War is a messy business. I'd just as soon prefer we didn't have to engage in it at all, but I'm not the one refusing to live by the rules of the civilized world. Why don't you save some of your condemnation for the people that refuse to fight in uniform and hide behind civilians? Both of those actions are war crimes, just so you know.

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
    49. Re:Break the key apart? by The+New+Guy+2.0 · · Score: 1

      Regulations aren't law... they're Executive branch policies, under authority granted by a previous law. Mostly they set numbers on things that the law left to a range... and courts don't hold up most others.

    50. Re:Break the key apart? by The+New+Guy+2.0 · · Score: 1

      FISA creates a "sealed record"... they'll have to reveal it eventually if they want to use it in other courts.

  3. Parts of a key? by ckatko · · Score: 1

    Introducing my super clever hack:

    Wait till the key is needed.

    Write the key down.

    Use it whenever we want from then on, but make sure we tell everyone we're not.

  4. The Math by Lord+Duran · · Score: 5, Informative

    An example of how to do cryptographically secure secret sharing:
    Shamir's secret sharing.

    There are other secret sharing schemes there, follow the link to the main article.

    1. Re:The Math by The+New+Guy+2.0 · · Score: 1

      The problem here is that when the SSL snoops get credit card data, they become the cracker that's supposed to be arrested. These warrentless wiretap losers don't last long, yet they always seem to be making more of them.

  5. No legislation is needed by fustakrakich · · Score: 1

    They will just do it anyway. It doesn't matter. Most people prefer to feel secure, they don't care how it's done.

    --
    “He’s not deformed, he’s just drunk!”
    1. Re:No legislation is needed by Anonymous Coward · · Score: 0

      I'm sure it's already been done.

  6. Why shouldn't we trust them? They sound legit! by Anonymous Coward · · Score: 2, Insightful

    NSA director Adm. Michael S. Rogers wants to require technology companies to create a digital key that could open any smartphone or other locked device to obtain text messages or photos, but divide the key into pieces so that no one person or agency alone could decide to use it. But progress is nonexistent:

    Sure. I totally believe that you're going to do that. I mean, it's not like you scum have a history of blatantly lying to the American people and doing the complete opposite of what you say you will, right?

    How about no. Just fuck off and stop invading my privacy. You have absolutely no right there, whether you split that responsibility with other criminal--I mean, government-- organizations or not (not that I believe you'd even do that much).

    1. Re:Why shouldn't we trust them? They sound legit! by The+New+Guy+2.0 · · Score: 1

      [Quote]NSA director Adm. Michael S. Rogers wants to require technology companies to create... But progress is nonexistent:[/Quote]

      Nobody's helping him, so he's complaining to the media... nothing to see here, move along.

  7. personal privacy trumps all by Anonymous Coward · · Score: 0

    That was easy.

    1. Re:personal privacy trumps all by Anonymous Coward · · Score: 0

      personal privacy of people who chant death to america trumps the continuation of the state. Note that the constitution clearly allows search and seizure for a reason.

    2. Re:personal privacy trumps all by Anonymous Coward · · Score: 0

      Yes, and there are clearly defined methods for searching and seizing - you don't get to throw the rules out the window just because it's on a shared server or it's part of the "cloud". That sounds, to me, like problems they need to solve, not circumvent.

    3. Re:personal privacy trumps all by Pseudonym · · Score: 1

      To put it another way: There is no clash between privacy and security. Privacy is security.

      The word "security", or any variant thereof, appears exactly once in the US Constitution: "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated [...]"

      --
      sub f{($f)=@_;print"$f(q{$f});";}f(q{sub f{($f)=@_;print"$f(q{$f});";}f});
    4. Re:personal privacy trumps all by anagama · · Score: 1

      you don't get to throw the rules out the window just because it's on a shared server or it's part of the "cloud"

      Actually, at least according to the Supreme Court, they do get to throw out the rules. It's called the Third Party Doctrine.

      http://www.abajournal.com/maga...

      For too long, application of the third-party records doctrine has permitted absurd results. A person who stores documents and items in a physical space controlled by a third party in the business of renting it out retains a Fourth Amendment interest in those items. But if she stores the same information with an online lockbox in the business of providing on-line document storage services, she loses that Fourth Amendment protection and it is available to law enforcement with a mere subpoena.

      --
      What changed under Obama? Nothing Good
  8. Not a key, it's a password... by The+New+Guy+2.0 · · Score: 1

    The problem here is that uncrackable-without-the-secret crypto poses a problem for the "give us everything!" police investigators... these are the guys who want warrentless wiretaps and other gifts from the tech industry.

    There's no master key that can solve all crypto... what they really want is a password that causes the device to give up its locks.

    1. Re:Not a key, it's a password... by Anonymous Coward · · Score: 0

      There's no master key that can solve all crypto... what they really want is a password that causes the device to give up its locks.

      What I'd really like is a pony. Oh, any girl I want to have sex with must do so. Also all the money in the world and the power to crush my enemies.

  9. Perspective by laing · · Score: 4, Insightful
    When considering whether or not it should be okay for the US government to have backdoor access to any device, one should also consider whether other governments should also have that same access. The answer shouldn't depend upon which government you support.

    One should also remember that government employees with privileged access are people, and people can misuse the access they have.

    We should recognize that the Fourth Amendment of the US Constitution was created to prevent this exact scenario. Law abiding people encrypt sensitive information to protect it from misuse by criminals, but the information can be misused by ANYONE with access.

    Dividing a backdoor key between multiple parties simply creates a requirement that all parties agree to access the information before it can be accessed. It doesn't guarantee that the access will be lawful.

    1. Re:Perspective by MobSwatter · · Score: 3, Insightful

      You can't install a back door to anything without weakening the security for the less than lawful crowd, when taken into context it would appear that the entire surveillance thing is not only unconstitutional, unconstitutional is also unlawful beyond not being that smart. It also concludes that not only the NSA and the elite are above the law, but every other law enforcement agency is going make a play for it because the NSA got away with it. Now take all that and add the element of organized crime that we know has invaded every aspect of government and society today including national security, watch entire country fall down. Sometimes a new feature can be more of a bug.

  10. Keeping Secrets by Dutch+Gun · · Score: 5, Insightful

    So... what makes the NSA think that anyone could actually keep these ultimate "keys to the kingdom" secret? I mean, just about everything else of theirs that was secret has leaked out thanks to a single contractor. Can you imagine how valuable these keys are, and how much money could be made by selling them? Hell, the US couldn't even keep our nuclear weapon plans under wraps.

    And what's awesome about this scheme is that once the secret is out, every single smartphone in the US is compromised all at once. Whee!

    --
    Irony: Agile development has too much intertia to be abandoned now.
    1. Re:Keeping Secrets by Jaime2 · · Score: 4, Insightful

      It goes further... their scheme requires that the people holding the parts of the key work together regularly whenever access is needed. This is likely to be thousands of times every year. There's no way to keep a secret that needs to be accessed so often by so many. Enigma was broken due to poor operational security, not poor technology. Venona broke one-time pads due to poor OpSec. An encryption scheme used by all authorities wanting decrypts of cell phones would involve tens of thousands of people and would be impossible to carry out without making egregious operational errors. Add to that the fact that none of those who hold the keys have much to lose when they screw up. War time operatives know their way of life depends on them not screwing up. The local FBI office only cares about decrypting the phone, if they screw up, it doesn't hurt them, but it hurts me.

    2. Re:Keeping Secrets by dcollins117 · · Score: 2

      So... what makes the NSA think that anyone could actually keep these ultimate "keys to the kingdom" secret?

      Hubris, most likely. If Bruce Schneier is correct there appear to be a number of NSA and CIA leakers still active. Not to mention the foreign spies within the NSA and CIA that we don't hear about because they are doing their job correctly.

  11. 7 people who hold the keys to the internet by auric_dude · · Score: 1

    The idea could work. Meet the seven people who hold the keys to worldwide internet security http://www.theguardian.com/tec...

    1. Re:7 people who hold the keys to the internet by Culture20 · · Score: 1

      I smell a summer blockbuster action movie!

  12. Dear NSA by Opportunist · · Score: 4, Insightful

    No matter how many US agencies you distribute the key over, one thing is absolute certain: If you require US companies to make any and all contents on mobile devices available to US government (and, considering who owns it, US corporations), absolutely NO non-US company could sensibly buy anything anymore from a US tech company.

    Hell, the chance to not be spied on would be bigger if you bought Chinese crap!

    Quite seriously, why should anyone trust a country that has a worse record when it comes to industrial spying than China?

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    1. Re:Dear NSA by Anonymous Coward · · Score: 0

      "why should anyone trust a country that has a worse record when it comes to industrial spying than China?"

      Marketing and PR can do wonders.

    2. Re:Dear NSA by Anonymous Coward · · Score: 0

      SCREW EM !!!
      Strong encryption for everyone.

      And to all you safety and security whiners, screw you, man up and defend yourself, the cops cant help you, carry a sidearm.
      Flatten some buildings once every decade or two? Who gives a fuck, prosecute, rebuild, be proud and move the hell on with life.

    3. Re:Dear NSA by Anonymous Coward · · Score: 0

      citation please. I can assert that all Chinese routers are compromised in silicon, but it's no more valid than your accusation without a credible source..

    4. Re:Dear NSA by Anonymous Coward · · Score: 0

      I don't think any reputable source have done any direct comparison, but the US government sharing illegally obtained data with US based companies so that they can secure favorable deals have hit the news a bit more.

    5. Re: Dear NSA by Anonymous Coward · · Score: 0

      Yes. It's being released in The Guardian. If you subscribe they might deliver to the rock you're living under.

    6. Re:Dear NSA by zedaroca · · Score: 2
      Times, Guardian, Post, Intercept and Der Spiegel are credible sources that the US is doing worst than China.
      From your link:

      "I don't know if there are backdoors - but it doesn't matter since there are so many vulnerabilities."

      It was on the news that the NSA was hacking on Huawei. Maybe China was using the vulnerabilities and spying, but the US definitely was doing that. Now they want to put actual backdoors on American devices.

      Since then they said they would start using more open source and open their systems for being audited by third parties. The Chinese government didn't complain about increasing the security of Chinese made devices, the opposite of what is happening in the US.

    7. Re:Dear NSA by Opportunist · · Score: 1

      http://www.reuters.com/article...
      http://www.bbc.com/news/259075...
      http://www.cnet.com/news/snowd...

      If you can't be assed to google for 5 minutes, I cannot be assed to provide proper links.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  13. This is not a new problem by Anonymous Coward · · Score: 1

    "Those who would give up essential liberty to purchase a little temporary safety deserve neither liberty nor safety."

    ----Benjamin Franklin, Historical Review of Pennsylvania, 1759

  14. legality & open source enforcability by Anonymous Coward · · Score: 0

    Lets say that congress passes a law requiring all phone / tablet makers implement an encryption backdoor (key sharing or whatever - technical details aside for now).

    First, would this pass constitutional muster? You're compelling companies not to implement encryption unless the gov't has a way in. Seems like some sort of 1st Amendment issue to me but I'm not lawyery enough to have a valid opinion.

    Second, how would this work with open source projects? Cyanogenmod, for example. Same constitutional questions as above, but with the added problem of how do you enforce the law against an open source project? Do you declare git repos containing non-compliant Android forks to be illegal?

  15. How far would this law go? by BitterOak · · Score: 2

    Does this only apply to cellphones which are regulated telecommunications devices? Or would it also apply to tablets, which are really personal computing devices? And if it applies to tablets, would it apply to other personal computing devices such as laptops and desktop PCs? And if so, does it only apply to encryption software sold with the device, or also to third-party supplied encryption software? And if it does apply to 3rd party software, does it only apply to commercial software, or free open source software as well? Are there 1st Amendment issues involved in regulating the distribution of free software, and if so do they apply only to compiled machine code, or to source code as well? The devil is in the details and I'm not really sure where dividing lines would be drawn.

    --
    If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
    1. Re:How far would this law go? by Thor+Ablestar · · Score: 2

      As I know there is a thing named Arduino. Also, there is a thing named Arduino GSM shield. Basically it means that it's possible to make a primitive communication device with almost totally user-controlled code. (Almost - because the GSM shield has a firmware in it, but it's interface can be controlled). You can use it to make an encrypted communication between parties but unfortunately it doesn't save you from collecting metadata; it still needs a solution (Such as "Diverter" in good old days of blueboxing).

    2. Re:How far would this law go? by currently_awake · · Score: 1

      How do they avoid conflict with America's medical records privacy laws? Also, this is a death warrant for America's computer industry. Rule number one of spying: it must be done in secret, or you can't trust anything you get.

  16. No Problem... by CharlieG · · Score: 3, Interesting

    They can have a back door to my phone - as soon as they give me the key to all THEIR systems (up to and including the President and IRS etc) so that when WE have the right to data, they can't say "we lost it". What? Its only fair - they watch me, I watch them

    --
    -- 73 de KG2V For the Children - RKBA! "You are what you do when it counts" - the Masso
  17. Grapples? Thats the nice way when a D is Prez? by Anonymous Coward · · Score: 0

    Jesus people....When a Democrat is in office, you whacked kid liberal lefty use kinder or "conflicted" words. When Bush was in, these same people were calling him the Devil. We laugh at you.

  18. There's only a clash in the minds of Republicans.. by Anonymous Coward · · Score: 1

    For normal people, we recognize the right to privacy so there is no clash. The title is misleading. The Republicans don't recognize the average person as human thus they believe we have no rights. They strongly believe in the Constitution, but don't think it applies to the average person.

  19. Naw by Dunbal · · Score: 4, Insightful

    There's no clash. The law is perfectly clear on that subject. Only the government is choosing to ignore it.

    --
    Seven puppies were harmed during the making of this post.
  20. Two Keys? by PPH · · Score: 3, Interesting

    Dr. Petrov: [Ramius has taken the Political officers Missile key and kept it] Sir! The reason for having two keys is so that no one man may...

    Captain Ramius: May what, Doctor?

    Dr. Petrov: Arm the missiles Captain.

    Captain Ramius: Mmm, thank you for your concern Doctor

    --
    Have gnu, will travel.
    1. Re:Two Keys? by Shakrai · · Score: 1

      "Russians don't take a dump son without a plan."

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
  21. Anchoring by Iamthecheese · · Score: 1

    Offer someone an extreme choice, "Here's a car for only $60,000!" and they'll be more likely to accept a more moderate choice (Here's a car for $30,000!) because it's better by contrast, not objectively. Today we're reading, "should the government get to read everything, everywhere?" and your answer is obviously "fuck no". But that immediate answer isn't the point.

    Later you'll be presented with, "Should the government get extra-legal access to some things?" and because of this framing you'll be more likely to say "yes".

    --
    If video games influenced behavior the Pac Man generation would be eating pills and running away from their problems.
    1. Re:Anchoring by Anonymous Coward · · Score: 0

      I believe the phenomenon you describe is called The Overton Window.

    2. Re:Anchoring by Iamthecheese · · Score: 1

      No, I'm pretty sure it's anchoring. But I applaud your efforts to associate my post with Beck's insanity. Anyone reading your comment will discount my own by association. Very clever.

      --
      If video games influenced behavior the Pac Man generation would be eating pills and running away from their problems.
  22. Only for very loose definitions of "grappling" by Anonymous Coward · · Score: 0

    "We know you're worried about the implications of all the snooping we're doing.

    But trust us, we're grappliing with the consequences.

    No, we're not about to stop. Nor are we even going to attempt to slow the growth of our snooping.

    But we are grappling with it.

    Trust us."

  23. Bullshit! by BrendaEM · · Score: 1

    In what manner was the US government concerned with privacy?

    After 9-11, we were supposed to just stop being Americans and give up the whole idea of what our founding fathers wanted.
    Be a coward, and given them all the power they want, and see where that will get you.

    --
    https://www.youtube.com/c/BrendaEM
  24. Divide the key by manu0601 · · Score: 1

    Dividing the key makes sure a single individual cannot have access. But since all individual workers obey to their employer, it does not prevent any NSA access.

    This is just a measure against rogue NSA employee access, not against NSA access.

  25. Re:There's only a clash in the minds of Republican by Anonymous Coward · · Score: 0

    For normal people, we recognize the right to privacy so there is no clash. The title is misleading. The Republicans don't recognize the average person as human thus they believe we have no rights. They strongly believe in the Constitution, but don't think it applies to the average person.

    Can we say "Diane Feinstein?" The disease is not specific to one political party or the other. The disease is specific to those those love power over everything else.

  26. Promise, we won't peek by Anonymous Coward · · Score: 0

    "NSA director Adm. Michael S. Rogers wants to require technology companies to create a digital key that could open any smartphone or other locked device to obtain text messages or photos, but divide the key into pieces so that no one person or agency alone could decide to use it."

    That has to be the most laugh-out-loud tactic I've heard in awhile, yet also really clever as it could easily fool someone trying to be reasonable yet isn't informed as to the NSA (and even FBIs) tactics and capabilities.

    Yes, you split your key into say 3 pieces. Company holds a piece of what becomes basically a password, as does the FBI and NSA. If the FISA court says OK to a request, the company/FBI/NSA give each other the pieces. There are a few problems:

    1. The NSA/others now just have to make it a serious goal to get those pieces via other means out of the FBI/CIA and corporate servers without telling anyone and they've got all the access all the time.

    2. If brute-forcing, you've drastically dropped the strength of the key.

    3. Stuff I'm not smart enough to think about.

    I swear they throw this stuff at low-information websites & voters to see what sticks, and it's sad how much of it does.

  27. Collecting more noise does not help signal/noise! by Anonymous Coward · · Score: 1

    I think most people fear a SWAT team coming in and shooting them in their own homes, than jihadist terrorists.

    NSA has not measurably made anyone more secure since they started this big brother program. You assume it works, but collecting more noise does not make the signal stronger.

    This idea of 'secure' you have, indicates a nice trust of the perfect nature of your leaders (i.e. the NSA), but those of us in foreign countries know where that leads to.

    Really, swap NSA for KGB and you've got the situation you're creating. A case where the spooks will slowly ensure that all the partner countries are further and further right wing and in a feedback loop those will ensure the US goes to a military extreme dictatorship.

    Consider the state of 5 eyes countries now, can you seriously tell me the info the US has on those political systems isn't used to twist them more US military centric? Because its visible for all to see what they've been doing. New parties (UKIP in the UK for example), face leak after leak of their most embarrassing secrets, and when phone calls from 3 years ago before the person was even a UKIP candidate are leaked, you ask yourself who records and indexes and stores that data, if its not the spooks?

  28. POST HOC Legalization by Anonymous Coward · · Score: 0

    When they want to pass a law to legalize adding a backdoor, it means they already added the backdoor and want to make it legal.

    See the 2007 tapping of US telephone exchanges, they made a law to legalize and give immunity to the telecoms companies it when it was exposed. Obviously you don't want to announce it if possible, so you only pass a law when forced to.

    PRISM showed they already plugin in to major corporations data.

    All those 'Cloud Cameras', that send the video up to the website.... All the phone calls you make, the messaging services,.... all feeding General Collect-it-all's giant datacenters. All with US corporate complicity.

  29. Re:There's only a clash in the minds of Republican by Anonymous Coward · · Score: 0

    But she is a DINO so everything she does is the fault of the Republicans.

  30. The FBI isn't the only law enforcement agency by ZeroWaiteState · · Score: 5, Insightful

    If a backdoor key exists, then the company that created it must by law give it to any lawful government authority that requests it. For example, if a company does business in Saudi Arabia, and a backdoor key exists, they may be compelled under Saudi law to give that key to the Saudi's. If a company does business in Russia, they may be compelled by the Russian government to give them the key. That's the nature of a backdoor. You can't just give it to only one entity. And let's not forget about Gemalto. They have cellphone encryption keys for the SIM cards they produced, which were held on their servers so that law enforcement agencies could obtain backdoor access to cellular communications via the legal process. However, the NSA broke into their servers and stole all of their secret keys, and then used them to mass decrypt cellular traffic. That's a real example of key escrow in action, and it completely failed to protect anyone.

  31. Seriosly? by Anonymous Coward · · Score: 0

    "but divide the key into pieces so that no one person or agency alone could decide to use it."

    We've already seen cases where the FBI will back local/state law enforcement in hiding information about Stingray. The other agencies would happily scratch each others back to share these keys, so there's no real effective "wall" between agencies that makes this acceptable.

  32. There's no good way to compromise a system... by Chas · · Score: 1

    Sorry, but if you create a system with a security compromising flaw in it, even a well hidden, obfuscated, extremely well guarded flaw, someone aside from the "intended" users of said compromise are going to use it to break in.

    The government's "need to know" does NOT trump my right to privacy. And if there's a real problem with that, they'd better be overtly bringing soldiers in to try to make me comply.

    --


    Chas - The one, the only.
    THANK GOD!!!
  33. Bull by Anonymous Coward · · Score: 0

    U.S. Gov't Grapples With Clash Between Privacy, Security.

    Are you kidding me? Our government has and will spy on us. We no longer live in the old USA.
    Why this kinda thing is even floated must be for the young who don't know better. I know for a fact it was going on via satellite (phone calls and more than meta data) since I was in A school in 1988. Only back then, key words flagged the targets because of computer speed. These days, game over for privacy

  34. I call BS by jodido · · Score: 1

    The only thing they're "grappling" with is how to continue unlimited spying while convincing you they're respecting your privacy.

  35. Intel Active Management Technology by Anonymous Coward · · Score: 0

    ./.

    Allready here.

    Like a vnc server pulling from the frame buffer OS independent?

  36. We went throught this already... by Anonymous Coward · · Score: 0

    Remember the BS in the 90's? Skipjack? Pushed by Janet Reno IIRC.

    It was shit then, and it's even stinkier now...

  37. Re:Grapples? Thats the nice way when a D is Prez? by VanessaE · · Score: 2

    And you war-obsessed, money-blinded, overly-religious conservatives are saying what, exactly, about the current president? That he's some kind of angel of sunlight? No. You guys are currently calling him the worst president ever, claiming he's gonna make himself dictator (despite the 22nd Amendment to the US Constitution), comparing his administration to ... well let's not Godwin this. Notice I did NOT single out any current or past US political party.

    Here's a newsflash: since before this country was founded, the person currently holding the highest office in most any country has been called every nasty name or epithet in [the then current version of] the book by his or her opposition, while that person's supporters of course use "softer" words when criticizing him or her, with variances of course depending on the country.

    And yeah, I meant every word of that opening sentence. Why? Because I am a moderate, and would like to think I can see *both* sides of the current political climate, and conservatives today are just as bad as they were 50, 100, 200 years ago. The noises you make are the same, only the reasons and target of that noise have changed.

    How's the phrase go? "Reality leans liberal" or something like that? Maybe it does, but only if you compare it to "conservative" as the terms are measured in the US. Compare it to the rest of the civilized world, and reality is (and should be) a lot closer to center/moderate.

    Steering this back on topic, that means we keep our privacy, security, strong encryption without ANYONE else holding the keys but us), and so on, and the government goes and dunks its collective heads in the toilet. They don't need our data to make us any safer, and we don't need to BE any "safer" anyway.

  38. Any legislation will result in disaster by Anonymous Coward · · Score: 0

    Anything the US Congress decides to do legally to force security gaps is going to end up in economic disaster. It's already happening with sales of Cisco and other networking gear manufacturers products taking huge hits abroad or even outright bans for certain contracts. And Silent Circle moved it's corporate headquarters to Switzerland just to be able to give the finger to any secret orders. Last time they tried this it was called the clipper chip. Failed miserably. How about instead of sanctioning privacy violations, you make sure your actions follow the moral high ground and aren't dubious. Then people will trust you enough to make exceptions.

    In the twisted world of espionage logic, it's guilty until proven innocent. Or at least innocent, but eventually you'll be guilty of something therefore we will watch you now. Just like the statistics, just with a little less perceived fear.

  39. whatever govs can do, crooks will do better by e**(i+pi)-1 · · Score: 3, Interesting

    It is in the interest of anybody to help in providing the best possible encryption because "Whatever govs can do, crooks will do better". It not only helps the industry or privacy. It also protects itself as it is likely that such mandatory back doors will be technically outdated and hacked quickly after put in place. Weak Encryption has decided the fate of Mary Queen, the deciphering of the Zimmerman telegram a hundred ago played a role in the outcome of WWI and weaknesses in the use of the enigma cryptology was important in WW2. Since then, technology has exploded and become more important everywhere. Any government proposing to weaken its own communication infrastructure by mandatory crippling their own industries will be in a disadvantage. The dream is of course that high up, secure systems are going to be used. As they will not have been well tested, they are likely to be hacked even faster than a device for the masses with a backdoor which has withstood standard attacks and gone through peer review by hackers. And if some really sweet military grade encryption will remain to be safe, it will be a goldmine for a company selling devices with such additions abroad.

  40. The reason not to have keys. by Anonymous Coward · · Score: 0

    However, the NSA broke into their servers and stole all of their secret keys, and then used them to mass decrypt cellular traffic. That's a real example of key escrow in action, and it completely failed to protect anyone.

    The reason not to have a back door key. Even if the key was divided up a copy of all parts would soon be gathered.

    Well this does show the encryption does at least slow them down or they wouldn't want a backdoor.

  41. Letter by Anonymous Coward · · Score: 0

    If I write a letter to my U.S. Congressman / Senator will that actually help?

  42. Errr... wha? by Anonymous Coward · · Score: 0

    I believe the FBI uses probable cause warrants for the vast majority of their cases; I even seem to recall an NYT article outlining the places where they'd screwed up -- they certainly existed, and were far larger than they should have been... but it was nothing like "all the time." As for "to oppress and enslave" and "stupid people", a) there is definitely stuff going on that I'm uncomfortable with, but b) the people making it happen are folks just like you: egomaniacs who are always sure they're right. It's clear you're smart. It's also clear you're stupid. These two statements are not mutually exclusive.