Slashdot Mirror


Why Crypto Backdoors Wouldn't Work

An anonymous reader writes: Your devices should come with a government backdoor. That's according to the heads of the FBI, NSA, and DHS. There are many objections, especially that backdoors add massive security risks.

Would backdoors even be effective, though? In a new writeup, a prominent Stanford security researcher argues that crypto backdoors "will not work." Walking step-by-step through a hypothetical backdoored Android, he argues that "in order to make secure apps just slightly more difficult for criminals to obtain, and just slightly less worthwhile for developers, the government would have to go to extraordinary lengths. In an arms race between cryptographic backdoors and secure apps, the United States would inevitably lose."

62 of 105 comments (clear)

  1. The 90s all over again... by Austerity+Empowers · · Score: 5, Insightful

    I seem to recall that we went through this in the mid to late 90s, where the government insisted any use of strong cryptography should as a matter of law, have a backdoor for the government. Then suddenly they dropped it, and all of us paying attention knew they got their way by some other means. Now post-Snowden, I guess we know what that was, and they're back to beating this horse all over again.

    The answer should be no, with absolutely no further discussion.

    1. Re:The 90s all over again... by StikyPad · · Score: 4, Interesting

      They didn't get their way through other means really. Mass surveillance doesn't trump encryption -- on the contrary, encryption is the only protection against mass surveillance. I think it was more that encryption just wasn't used for most communications, so they realized it was a moot point. Now that companies are shifting toward end-to-end encryption, it's becoming relevant again.

    2. Re:The 90s all over again... by UnderCoverPenguin · · Score: 2

      I seem to recall that we went through this in the mid to late 90s, where the government insisted any use of strong cryptography should as a matter of law, have a backdoor for the government. Then suddenly they dropped it,

      I recall reading that a researcher figured out a way to spoof the "Law Enforcement Access Field" shortly before the US government dropped their push.

      --
      Don't try to out wierd me, three-eyes. I get stranger things than you, free with my breakfast cereal. --Zaphod Beeblebr
    3. Re:The 90s all over again... by JosKarith · · Score: 2

      Does nobody remember the Clipper Chip debacle? - http://en.wikipedia.org/wiki/C...

      Funnily enough the sort of person that would be happy to hand law enforcement the spare keys to their house is not the sort of person that law enforcement's interested in investigating... Seems that memories are short in the NSA

      --
      'Don't worry' said the trees when they saw the axe coming, 'The handle is one of us.'
  2. Car analogy by Meshach · · Score: 1

    Would it work for the government to have access to everyone's cars? Cars can be used for criminal activities. Ditto for keys; should we have to al give the government access to our homes?

    --
    "Maybe this world is another planet's hell"
    Aldous Huxley
    1. Re:Car analogy by Anonymous Coward · · Score: 3, Insightful

      ... have access to everyone's cars?

      Police and government have promoted remote-controlled kill switches on cars for the last 20 years. Although it exists via General Motors OnStar, it's not practical. That will change with vehicle-assisted driving and driver-less cars.

      ... give the government access to our homes?

      The government already has access via hand-held battering rams and 14 tonne, wheeled wrecking-balls (AKA assault vehicles). Big money and brute force doesn't work on encryption, unless they turn it into rubber-hose decryption (Oblig. XKCD). But the three-letter agencies can't do that 200 times a day, so they want a cheap, simple solution that labels the common people as criminals without rights.

    2. Re:Car analogy by Meshach · · Score: 2

      The government already has access via hand-held battering rams and 14 tonne, wheeled wrecking-balls (AKA assault vehicles). Big money and brute force doesn't work on encryption, unless they turn it into rubber-hose decryption (Oblig. XKCD). But the three-letter agencies can't do that 200 times a day, so they want a cheap, simple solution that labels the common people as criminals without rights.

      There are law about that though - a warrant is required for the police to enter my home. DHS is not going to get a warrant to snoop on me.

      --
      "Maybe this world is another planet's hell"
      Aldous Huxley
    3. Re:Car analogy by Anonymous Coward · · Score: 2, Interesting

      I heard a scream come from inside your house, and one of the windows is broken, I think that gives me enough cause the break in.

    4. Re:Car analogy by vux984 · · Score: 2

      No the car analogy isn't valid, because the police do have access to everyone's cars and homes. They get a warrant. They bring a crowbar. Done.

      That's the issue with encryption, they can get a warrant giving them the legal right to get in. But there is no crowbar.

      I'm not in favor of this, but we do need to understand it is a somewhat unique situation. Strongly encrypted data is not like other property.

    5. Re:Car analogy by Jason+Levine · · Score: 4, Insightful

      But warrants are [whining voice]SOOOO HAAARD. You have to show probable cause and all that stuff. It's too much work.[/whining voice]

      Plus, [overly paranoid voice]in the time it takes to get a warrant, a criminal could enact another 9-11 or could destroy the evidence that they were planning that.[/overly paranoid voice].

      Those are the reasons why law enforcement needs access to stuff without a warrant. The whiny, paranoid reasons why.

      --
      My sci-fi novel, Ghost Thief, is now available from Amazon.com.
    6. Re:Car analogy by vux984 · · Score: 1

      But the three-letter agencies can't do that 200 times a day, so they want a cheap, simple solution that labels the common people as criminals without rights.

      This is needlessly cynical. I don't dispute the TLAs love mass surveillance. But there is a legitimate concern where law enforcement can justify and obtain a legal warrant for someone's electronic records/communications but not have any way to actually legally act on the warrant.

      Ie... if they have your encrypted laptop AND a warrant they ARE allowed to break into it, but they can't. This is a legitimate issue.

      "Rubber hose decryption" is not legal, nor should it ever be.

      In a sense, encrypted data is like the contents of one's mind more than its like other property; in that there is currently no legal way to ensure they can get at it.

      Their desire for a backdoor is pretty reasonable, in a way, but the problem is what they are asking for is a key which is far too much. There is no good solution here.

      a) Giving them the power to demand the key is fine, but what if they demand the key of someone who genuinely doesn't have it? Is he guilty and imprisoned for not having something? That's bullshit.

      b) Giving them a back door so they can just come and go as they please is giving them far too much power and ripe for abuse.

      c) Not giving them a back door and requiring they break has the issue that properly encryption can't currently be broken.

      The sanest and only reasonable choice is 'c', but it is not really a solution to the legitimate problem... its just the only one that doesn't trample on the innocent.

    7. Re:Car analogy by Agripa · · Score: 1

      If law enforcement and national security had not been unconstitutionally seizing and searching everything they could call third party data then there would not be a push for ubiquitous encryption. There was a group at the NSA who pointed out that this would happen damaging their ability to do lawful intercepts if they were caught. Since they were willing to lie about what was going on and break the law before, why would we trust any government only backdoor scheme or what they say now?

      It does not matter how any government backdoor system is implemented. They will abuse it sooner or later.

  3. They can read your RAM by Anonymous Coward · · Score: 4, Interesting

    They can read your RAM
    Intel Active Management Technology
    (aka vpro, aka vt)

    1. Re:They can read your RAM by Anonymous Coward · · Score: 3, Interesting

      And 3G to continually update the microcode that scans memory for known password signatures.....

      http://www.infowars.com/91497/

  4. Snowden took out the phone batteries by Anonymous Coward · · Score: 5, Insightful

    Snowden insisted the journalists remove the battery from their phones and put the phones in the fridge.

    That pretty much tells you how useful 'encryption' on Android would be against back doors. None, if you can't protect your speech near the phone you can't protect the password.

    1. Re:Snowden took out the phone batteries by Pi1grim · · Score: 2

      >> Snowden insisted the journalists remove the battery from their phones and put the phones in the fridge.

      >> That pretty much tells you how useful 'encryption' on Android would be against back doors.

      Not this manure again. What if I told you, that those phones could easily be bugged physically, by adding a little mic with an antenna, that would feed of phone's main battery, sure it requires some legwork, but Snowden is high enough on US's list of targets to actually do soome physical snooping. The whole "take the battery out and put it in the fridge" has nothing to do with magic backdoors that magically activate the phone and turn it into recording device and has everything to do with physical listening devices and malice on the part of phone owner. The little electronic bug works on all phones, doesn't require breaking any encryption, device being turned on and doesn't need to use the crappy mic on the phone.

      >> None, if you can't protect your speech near the phone you can't protect the password.

      The door to your house won't stop a team of highly trained team of CIA assasins, so why bother locking it, right? Android encryption is used in order to raise the cost of mass snooping where they snoop first and then look for anyone looking guilty enough and to raise the cost of stealing personal information by criminal elements. If they have to spend 1000 bucks to crack one phone and the information is worth 100 on average - then they won't even do it. If it costs 10 cents per device and information is worth a dollar on average - then they will do it. Take a look at botnets and other shady businesses.

      If you need to secure yourself from directed snooping by a team of professionals - then this is a completely different game and other measures come into play.

  5. It's about more than that by monkeyzoo · · Score: 5, Informative

    Reading the article, it's very intersting. His argument is that you CAN'T backdoor a platform. Summarizing:
    1) Say Android rolls over and backdoors the encrypted filesystem.
    2) 3rd party apps can use the cryptography library, so Google would also have to backdoor that.
    3) Then apps could use a 3rd party crypto library, so gov't would have to compel google to monitor for at least respond to takedown requests for strong crypto 3rd party apps.
    4) But apps can easily download and incorporate new code, so Google would have to audit running apps with static and dynamic analysis.
    5) Even then, people could use other app stores or sideloads, so Google would have to have an app kill switch option. This would be HUGE INTRUSION and delete apps from people's phones (even innocent people).
    6) But how to identify apps? Sideloaded apps could generate a new appID with each download, so Google would have to scan for app characteristics (think antivirus software here).
    7) Even if the above worked, browser-based apps could be built that use secure data stores or end-to-end messaging. This would mean the gov't would have to block these web apps, i.e., Internet censorship.

    It's just not technically feasible if there is any respect for liberty, not to mention the significant technical challenges involved.

    1. Re:It's about more than that by Anonymous Coward · · Score: 1

      A war usually solves that issue.

    2. Re:It's about more than that by Helix_Sky · · Score: 4, Interesting

      I want to start by saying that I'm against these measures but while all that is true, it only gets that bad if you try to enforce 100% compliance. Simply making cryptographic systems without backdoors illegal would have a large deterrent effect. It'd be the equivalent of the fact that locks on your doors don't provide 100% security because windows are so easily broken, but we still lock our doors.

      First off making non-breakable crypto illegal would prevent such crypto from being used in traditional commercial products. Second, the government wouldn't have to attack the problem from the front like the article suggested. They could use their NSA spying capability (once gain no a big fan) to look for unauthorized encrypted communications. They already take special note of encrypted data use, and with it being made illegal they could directly legally target the users of such tech. The chilling effect of such a large scale NSA backed takedown would be huge.
       

    3. Re:It's about more than that by Anonymous Coward · · Score: 1

      Another problem would be that the USA would not be the only country wanting access.
      Do phones now become "Zoned" ? How will that impact international travellers ?
      Do the phones come with multiple backdoors so each country can access the devices ?
      Do Americans travelling overseas want foreign governments to have access to their phones ?
      Could China kill Apps that they dont like on any phone in the world ?

      What is needed is better police, intelligent, diligent, honest, capable police. What we have is dull thugs who shoot first and ask questions later.
      What is needed is a professional police force, independent from political whim. We need a police conduct authority independent of political whim and police
      who must investigate EVERY police weapons discharge.
      What we need is politicians who are not on the take and use police to enforce their dishonesty.
      What we need is honest, intelligent politicians FFS Michelle Bachman.... please, why ?

    4. Re:It's about more than that by monkeyzoo · · Score: 4, Insightful

      Making strong crypto illegal would only affect those in the US's jurisdiction. It would not affect the most desirable targets (outside US jurisdiction) and would have a chilling effect on demand for US technology products.

    5. Re:It's about more than that by twitnutttt · · Score: 2

      What is needed is better police, intelligent, diligent, honest, capable police. What we have is dull thugs who shoot first and ask questions later.
      What is needed is a professional police force, independent from political whim. We need a police conduct authority independent of political whim and police
      who must investigate EVERY police weapons discharge.
      What we need is politicians who are not on the take and use police to enforce their dishonesty.
      What we need is honest, intelligent politicians FFS Michelle Bachman.... please, why ?

      Yes, we do. I would also like a pet unicorn.

    6. Re: It's about more than that by chromeronin799 · · Score: 5, Insightful

      And the even simpler argument. I'm not a U.S. Citizen. Why would I be happy the U.S. Has the ability to backdoor my app?

    7. Re:It's about more than that by myowntrueself · · Score: 4, Insightful

      Making strong crypto illegal would only affect those in the US's jurisdiction. It would not affect the most desirable targets (outside US jurisdiction) and would have a chilling effect on demand for US technology products.

      Theres already a chilling effect on demand for US technology products.

      I'd like to see a company in a privacy-respecting nation such as Netherlands to release some decent network hardware...

      --
      In the free world the media isn't government run; the government is media run.
    8. Re:It's about more than that by myowntrueself · · Score: 1

      I believe that the head of the NSA has already indicated that he believes there should be a framework to give, eg the Chinese, access.

      --
      In the free world the media isn't government run; the government is media run.
    9. Re:It's about more than that by fustakrakich · · Score: 5, Insightful

      It's just not technically feasible if there is any respect for liberty...

      *Ah, there's the rub, isn't it?*

      --
      “He’s not deformed, he’s just drunk!”
    10. Re:It's about more than that by ShanghaiBill · · Score: 3, Insightful

      8) People will only buy tech made outside of America, costing America jobs and draining away expertise.

    11. Re:It's about more than that by Anonymous Coward · · Score: 1

      Or they could just criminalise customer usage of non-backdoored crypto.

    12. Re:It's about more than that by Buck+Feta · · Score: 1

      A war usually solves that issue.

      Isn't Iran hiding some crypto of math construction?

      --
      I am Audience.
    13. Re:It's about more than that by Anonymous Coward · · Score: 3, Insightful

      3) Then apps could use a 3rd party crypto library, so gov't would have to compel google to monitor for at least respond to takedown requests for strong crypto 3rd party apps ...

      And this is where you get off track. The whole point is to backdoor enough of the system that there's a means to collect 90% of the information from 99% of people. There is no presumption for a "technically feasible" way to collect 100% of the necessary information from 100% of the people. If there were--and presuming we had a just system in place to use the information--, then we'd have a way to catch all criminals who planned terrorist attacks, or really anything, with an Android phone. Instead, at best the hope is to get large bits and pieces that narrow down the list of who to monitor and monitor as best as one can in as many ways as one can (since not everything is done with smart phones, anyways).

      Honestly, the whole point is precisely that pervasive surveillance is key. It's not that any sort of surveillance must be 100% effective. Because that's a useless definition of the word "work".

    14. Re:It's about more than that by johanw · · Score: 3, Informative

      " a privacy-respecting nation such as Netherlands"

      Ouch... You don't live in The Netherlands, do you? We have, like most western countries, our share of privacy attacks from the government. Mostly to satisfy the tax service, like storing all license plates of cars who drive on the highways or park in a private parking garage (to catch drivers of a leasecar who claim they use it only for business and don't pay the extra income tax). And there is discussion about forcing people to give up their encryption keys if the police wants them, ignoring laws that you have the right to remain silent (except when...).

    15. Re: It's about more than that by Anonymous Coward · · Score: 1

      SNAP.

      Why should the US Government be able to cripple/spy on my phone when I did not purchase it from an American company, do not live in America or communicate with American agencies?

      In fact, under EU law - it is almost certainly illegal for the US government to spy on my personal data when I'm in the EU, and a naturalised EU resident.

      Is the US willing to force US law on the entirety of the EU?

    16. Re:It's about more than that by MooseTick · · Score: 1

      "surrendering our ability to truly communicate privately and securely "

      Ever heard of talking in person? They can't ever take that away.

    17. Re:It's about more than that by RockDoctor · · Score: 1

      Don't forget (8) and upwards : people use something other than Android. Even something from outside the country, or at least outside the reach of the US govt.

      --
      Birds are not dinosaur descendants;birds are dinosaurs, for all useful meanings of "birds", "are" and "dinosaurs"
  6. Re:invalid premise by XanC · · Score: 2

    Did you read the article?

  7. Silly Rabbit. by MAXOMENOS · · Score: 1

    Just make encryption that isn't ridiculously easy to crack illegal, or subject to severe regulation and taxation. Get an expert devoid of care for privacy (say, Dorothy Denning) to endorse the law on the Sunday Morning talk shows. Cast anyone who cares about secure encryption as a bitter and deranged malcontent. Tell people it's for the Common Good.

    Problem solved.

    1. Re:Silly Rabbit. by whoever57 · · Score: 1

      Tell people it's for the Common Good.

      I think you mean the "greater good"

      --
      The real "Libtards" are the Libertarians!
  8. Re:Already FRONT DOORED by NotInHere · · Score: 1

    Almost fully agree.

    All those free messaging services that need all those permissions, you sign up and your contacts list is sent to them.

    Suggest a better method. The developers of the popular app TextSecure have posted their thoughts on how to solve this problem, but found no way that both satisfied their needs, scalability, and the user's needs.

  9. The author forgot one other option. by BitterOak · · Score: 4, Interesting

    I just read the entire article and the author forgot one other solution: the British solution Instead of putting the burden on app developers to include backdoors, or on Google to block apps that don't, put the burden on end users to turn over their keys to police when asked. I'm not saying I like this solution, but it is a solution the author of the article didn't consider. If you make the sentence for non-cooperation long enough, it doesn't really matter if the police find what they're looking for: they can just lock you up for not handing over the keys.

    --
    If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
    1. Re:The author forgot one other option. by pushing-robot · · Score: 3, Informative

      They could do that, but it wouldn't be a backdoor.

      --
      How can I believe you when you tell me what I don't want to hear?
    2. Re:The author forgot one other option. by Nonesuch · · Score: 3, Informative

      I just read the entire article and the author forgot one other solution: the British solution Instead of putting the burden on app developers to include backdoors, or on Google to block apps that don't, put the burden on end users to turn over their keys to police when asked. I'm not saying I like this solution, but it is a solution the author of the article didn't consider. If you make the sentence for non-cooperation long enough, it doesn't really matter if the police find what they're looking for: they can just lock you up for not handing over the keys.

      In the USA, this would likely require a constitutional amendment, it is widely held that the Fifth Amendment "Right Against Self-Incrimination" protects the right not to divulge an encryption key.

    3. Re:The author forgot one other option. by steelfood · · Score: 1

      Only they can't do that.

      Here on the other (this) side of the pond, we have constitutional protections from self-incrimination. Which means that we can't be compelled to reveal something that we choose not to. And if it happens, the evidence acquired by such means can (and likely would) be thrown out in court.

      Now, these protections don't extend to stupidity, so the cops usually get what they want anyway. Which is all the more reason why circumvention of strong encryption and mass surveillance largely is unjustified and should be fought against tooth and nail. It has no bearing on successfully catching real criminals, but it certainly will pick up undesired thinking.

      --
      "If a nation expects to be ignorant and free in a state of civilization, it expects what never was and never will be."
    4. Re:The author forgot one other option. by Anonymous Coward · · Score: 1

      Only they can't do that.

      Here on the other (this) side of the pond, we have constitutional protections from self-incrimination. Which means that we can't be compelled to reveal something that we choose not to. And if it happens, the evidence acquired by such means can (and likely would) be thrown out in court.

      Now, these protections don't extend to stupidity, so the cops usually get what they want anyway. Which is all the more reason why circumvention of strong encryption and mass surveillance largely is unjustified and should be fought against tooth and nail. It has no bearing on successfully catching real criminals, but it certainly will pick up undesired thinking.

      Yet, you can be compelled to open a safe, a safety deposit box, produce your company's books.. the list is endless. Currently, it depends on which circuit court you are in as to whether or not you will be in contempt of court for not producing your encryption keys. It should be noted that contempt of court has no minimum nor maximum time associated with it. it is usually "you are in contempt of court until such time as you produce ". So the question becomes which gets you more time in jail contempt or the crime they want the key to your crypto for...

      So, in the US if you are presented the right paperwork you have to produce your keys.

    5. Re:The author forgot one other option. by Fwipp · · Score: 1

      Or nab you on destruction of evidence. It's kinda a crime.

    6. Re:The author forgot one other option. by 93+Escort+Wagon · · Score: 2

      Simple enough - just require that all phones in the US use a fingerprint scanner for unlocking. The courts seem to be ruling that police can require you provide your fingerprint for phone access.

      Which, by the way, is a good reason to restart your iPhone the moment you think you just might get some unwanted attention from the constabulary.

      --
      #DeleteChrome
    7. Re:The author forgot one other option. by dcollins117 · · Score: 3, Informative

      In the USA, this would likely require a constitutional amendment...

      ... and a government that recognizes constitutional authority and the limits it places on government actions. First things, first.

    8. Re:The author forgot one other option. by BitterOak · · Score: 4, Informative

      In the USA, this would likely require a constitutional amendment, it is widely held that the Fifth Amendment "Right Against Self-Incrimination" protects the right not to divulge an encryption key.

      If you had read the article you link to (and I just did) you'd see that it does not conclude the same thing you do. Instead the article points out that it is far from a settled question on whether or not a defendant or suspect can be compelled to decrypt files. The Supreme Court has yet to deal with that issue directly, and the Circuit Courts of Appeal that have considered the issue have adopted a standard in which the government must first show they know the location and existence of encrypted data. If they've seized a suspect's phone, they certainly can know these two things, so the Fifth Amendment, under that analysis, would offer no real protection.

      --
      If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
    9. Re:The author forgot one other option. by l0n3s0m3phr34k · · Score: 1

      "I'm sorry Officer, my fingerprint scanner doesn't work...my wife got fingernail polish remover on it and melted it a bit" or whatever excuse you want to use after purposely disabling / ruining that hardware. Problem solved!

    10. Re:The author forgot one other option. by currently_awake · · Score: 1

      You are assuming the goal is to gather evidence for a police investigation. For that purpose your suggestion works. However if you assume the goal is to spy on everyone all the time, then your suggestion won't work.

    11. Re:The author forgot one other option. by Mathinker · · Score: 2

      > and existence of encrypted data

      I don't think it's possible to reliably show that encrypted data certainly exists. I also do not think it is always possible to prove that someone has the capability of decrypting data --- Bruce Schneier has proposed a scenario for people crossing borders where a long random key is used which is sent to the destination ahead of time so that any request for a decryption key could be truthfully answered with "I don't have the key". Assuming the trusted third party has been instructed to destroy the key in the case that the traveler is delayed, that scenario is indistinguishable from the scenario where the person is lying.

  10. Since When... by Stormy+Dragon · · Score: 4, Insightful

    ...has the fact a program simply won't work deterred the Government from attempting it anyways?

  11. Encrypt More by duke_cheetah2003 · · Score: 4, Insightful

    Seems to me, everytime they talk about this kind of thing, it does exactly what I want. Raise crypto awareness. Keep trying guberment. The more you preach for backdoors, the more people you make aware of the usefulness of crypto. Streisand effect anyone?

  12. Re:crypto? is that code for it's called now? by Anonymous Coward · · Score: 1

    i tried it but it made my phone stinky

  13. Why Crypto Backdoors Wouldn't Work by grep+-v+'.*'+* · · Score: 1

    to make ... apps just slightly more difficult ... and just slightly less worthwhile ... the government would have to go to extraordinary lengths.

    Ahh, well there's your problem: you expect resource restrictions and common sense from government.

    "the government would have to go to extraordinary lengths" Really!?! When has that ever stopped them from doing anything?

    --
    If the universe is someone's simulation -- does that mean the stars are just stuck pixels?
  14. Re:Device access by Damarkus13 · · Score: 2

    The issue is that I shouldn't have to trust the escrow service. Hell, even RSA lost a master key DB, and their entire reputation is built around security.

  15. Re:Preaching to the Converted by Damarkus13 · · Score: 1

    Does anyone believe the average citizen will understand what this is about or care?

    Thankfully we don't have to depend on the average citizen. Any sort of backdoor has risk management people sweating. For once, big business is on our side.

  16. Obligatory XKCD by rsilvergun · · Score: 2

    Surprised nobody posted this yet.

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
  17. It's already in progress by Antique+Geekmeister · · Score: 1

    Examine carefully the 'Trusted Computing' hardware and software components for new computers. Governmental agencies already have access to not only the escrowed keys, but to the master keys used to revoke and authorize other new keys. For personal security, it's quite troubling.

  18. Criminals are dumb by iamacat · · Score: 2

    Lots have been caught with plaintext browser history on their hard drives listing Google queries like "how to dispose of a body". That despite tools to clear or not record such history are easily available. To such end, having a half hearted, optional key escrow may do a lot of good. Let smartphones be encrypted by default, with a copy of the key encrypted with a public key of a cloud company that has an excellent security record. Then if someone forgets their password, and shows up at Apple or Verizon store with a valid ID, they can have their vacation photos back. So can law enforcement if they produce a valid and narrow scope search warrant.

    At the same time, people can install custom ROMs that support encryption that is potentially impractical to crack. That's important for many reasons including personal freedom and keeping country's technological edge by encouraging people to develop and understand software. Whistleblowers will get to keep their privacy, and so will a few criminal masterminds. But chances are, the later will have dumb associates who will set their password to 12345. I think a bet that smart people are generally also well intentioned is a good one for our society to make. In the meantime, we don't have to make life of the next Scott Peterson too easy.

    1. Re:Criminals are dumb by iamacat · · Score: 1

      That's not most people's risk profile. An average user is more likely to have personal data lost or stolen from their personal devices than a cloud provider with a professional IT department. Even in terms of legal risk, you could be jailed for contempt of court for failing to produce documents in what is otherwise a civil matter. Or not have access to favorable evidence.

      You absolutely should have legal right to run whatever software you want. I just disagree with article's premise that most criminals would go install custom ROMs and sideload apps. Anyone with enough wits and self control to do this consistently is likely smart enough to achieve their goals in legal ways.

    2. Re:Criminals are dumb by Mathinker · · Score: 1

      > make life of the next Scott Peterson too easy

      Had never heard of him, and after searching I discovered that he is on death row, even though there was no "hard" evidence that he murdered his wife. Could you explain, then, how he is a good example to use to justify weakening encryption for all of society? His case would seem to be exactly the opposite --- a good example how, even if encryption of all our devices were impregnable, most criminals are stupid and it wouldn't help them anyway (hey, that's even the subject of your post!)

  19. Thats why I always laugh at CSI by bobjr94 · · Score: 1

    The neighbor has a camera, hack into his internet and lets see it.

    First, you need his IP address, then is his router even port mapped to his camera to allow internet viewing and what port, what brand is his brand and model is the camera so you can get the right viewing software and what about the username and password he likely has to access the cameras ? Or does a CSI team have universal backdoor access to all devices.

    Give me 5 seconds....Ok Im in, Im pulling up lastnight's video now....