Slashdot Mirror


US Says It Doesn't Need a Court Order To Ask Tech Companies To Build Encryption Backdoors (gizmodo.com)

schwit1 shares a report from Gizmodo: According to statements from July released this weekend, intelligence officials told members of the Senate Intelligence Committee that there's no need for them to approach courts before requesting a tech company help willfully -- though they can always resort to obtaining a Foreign Intelligence Surveillance Court order if the company refuses. The documents show officials testified they had never needed to obtain such an FISC order, though they declined to tell the committee whether they had "ever asked a company to add an encryption backdoor," per ZDNet. Other reporting has suggested the FISC has the power to authorize government personnel to compel such technical assistance without even notifying the FISC of what exactly is required. Section 702 of the Foreign Intelligence Surveillance Act gives authorities additional powers to compel service providers to build backdoors into their products.

249 comments

  1. They are correct by Anonymous Coward · · Score: 5, Insightful

    And companies don't need a court order to ignore them.

    1. Re:They are correct by Anonymous Coward · · Score: 1

      A company ignores these kind of requests at their peril.
      Play ball and you might be the next Microsoft.
      Give us crap and your prospects might mysteriously disappear.
      These guys have power that the mafia can only dream about.

    2. Re:They are correct by Anonymous Coward · · Score: 1

      Do a Sergeants scoff.
      Give them a buggy back door, then keep changing the firmware often (breaking said backdoor), plus leak a high security corporate patch.

      Poor Cisco, backdoors certainly hurt their market cap, as did others in Wikileaks. Google, Facebook and VPN's have too much to loose if their brand is tarnished.
      OTOH a Chinese company has been blackballed on nonspecific assertions, just like a .ru AV firm. .

      Or roll your own privacy solutions - opensource and Pi are cheap. These add on dongles also risk big firms being caught out. Just wait until AI gets started and fake data gets transmitted.

    3. Re:They are correct by Anonymous Coward · · Score: 5, Insightful

      Yeah, until wikileaks releases said documents and your company goes under. Too much risk involved and the government doesn't exactly offer protection from such cases. The risks involved is higher than the government ruining your prospects, because now your reputation is tarnished forever, just like Blackberry. These government officials no longer hold the sway as they used too pre-2010. Threats of ruining your business now results in these people closing up shop and the government ends up with absolutely nothing, other than stifling innovation and security in the process. This approach is no longer viable.

    4. Re:They are correct by Billly+Gates · · Score: 3, Interesting

      And companies don't need a court order to ignore them.

      You know the federal government has tens of millions of seat licenses of sales to keep your share prices high.

      It would be a shame if something happened to that deal?

    5. Re:They are correct by Opportunist · · Score: 1

      OTOH a Chinese company has been blackballed on nonspecific assertions, just like a .ru AV firm. .

      Maybe they didn't build backdoors into their products...

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    6. Re:They are correct by Opportunist · · Score: 3, Insightful

      And governments as well as corporations abroad have even more.

      You can now choose between pissing off about 5% of your market share or 95% of your market share when it comes out that you bent over and sold the 95% out to the 5%.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    7. Re:They are correct by Anonymous Coward · · Score: 0

      Yea, it's a non-issue clickbait article.

    8. Re:They are correct by Anonymous Coward · · Score: 1

      A company ignores these kind of requests at their peril.
      Play ball and you might be the next Microsoft.
      Give us crap and your prospects might mysteriously disappear.
      These guys have power that the mafia can only dream about.

      Google. Apple. Facebook. Amazon. Government often forgets that they run on American Capitalism.

      As far as mafia power goes, it's also Too-Big-To-Fail-obvious who actually runs this country.

    9. Re:They are correct by Anonymous Coward · · Score: 0

      Careful with percentages. They do not reflect the actual balance of power. For instance 1% of all people are more powerful than 99% of them.

    10. Re:They are correct by Antique+Geekmeister · · Score: 3, Interesting

      In particular, they'll lose the licenses necessary to export the goods, or to import them if manufactured overseas. They can also lose government sales. With abusive legal tactics such as "Patriot Act" orders, a company refusing to cooperate with orders for backdoors is vulnerable to extremely destructive legal and extra legal abuse from the FCC and from Homeland Security.

    11. Re: They are correct by Anonymous Coward · · Score: 2, Informative

      Just like Qwest?

    12. Re:They are correct by currently_awake · · Score: 2

      The US Constitution prohibits searches without a warrant. Doing "Jobs" for the government makes you an employee of the government and therefore subject to the Constitution, so this should be illegal. Of course the Federal Government chooses the supreme court judges so the law can be interpreted.

    13. Re:They are correct by Anonymous Coward · · Score: 4, Interesting

      Qwest provides a case in point example of what happens when you refuse the request. That's a real nice company you have there, it'd be a real shame if something was to happen to it.

    14. Re:They are correct by Opportunist · · Score: 1

      Erh... this is the Germany of "Mutti" Merkel, not Big Daddy Adi.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    15. Re:They are correct by Anonymous Coward · · Score: 0

      Good luck selling to those folks abroad if you find your export license was cancelled or not renewed.

    16. Re:They are correct by Anonymous Coward · · Score: 0

      "Nice company you have there. Would be a shame if it became subject to an anti-trust investigation, wouldn't it."

    17. Re:They are correct by Anonymous Coward · · Score: 0

      I wouldn't worry about that. No country is going to import US-made products with encryption that is knowingly breakable by US government officials.

    18. Re: They are correct by Anonymous Coward · · Score: 0

      No they are not correct. There is in fact a law that forbids the government from telling companies how to build and design a product.

    19. Re:They are correct by networkBoy · · Score: 1

      Actually I predict a new software Si Valley in some country that won't require back-doors.
      Parent company can remain in the US or can leave, but the subsidiary company (not just a division of the parent) exists outside of jurisdiction of these asshats.

      The long game is that this likely *will* push the highest talent out of the US and into these haven countries. This generation will be here, but the newer generations will migrate elsewhere.

      --
      whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
    20. Re:They are correct by dpilot · · Score: 1

      and good luck selling to those folks abroad if you kept your export license because you installed backdoors for the US government.

      Basically, US software companies are put at a serious disadvantage. The real question becomes, whose cryptographic software can you trust? Certainly not Russian or Chinese, I'd say, and I'm sure others would add to that list.

      --
      The living have better things to do than to continue hating the dead.
    21. Re:They are correct by Anonymous Coward · · Score: 0

      After Sep 11, few months later there was law passed, about mandatory backdoor for any US encryption software. ALL the software using encryption at this moment have mandatory backdoor in it.

    22. Re:They are correct by Anonymous Coward · · Score: 1

      Facebook and VPN's have too much to loose if their brand is tarnished.

      10 Words You Need to Stop Misspelling

    23. Re:They are correct by datavirtue · · Score: 1

      Right. "Backdoors" are essentially fake encryption and the tech companies are distinctively aware of this even if legislators think it is like the stuff they see on hacker movies. You technically cant call it encryption if you don't control the key. It is mathematically incorrect.

      --
      I object to power without constructive purpose. --Spock
    24. Re: They are correct by Anonymous Coward · · Score: 0

      Meh, even Russia allows it.

      The world is full of corrupt people.

    25. Re:They are correct by david_thornley · · Score: 1

      What country will be better than the US at not requiring back doors? I can't think of any that I'd trust.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    26. Re:They are correct by Anonymous Coward · · Score: 0

      Huh? How is it mathematically incorrect to encrypt a session key with the receiver's public key and then another copy of the session key encrypted with the government's public key? It's not only not-not-encryption, it's more encryption! (Heh.) PGP could do that quarter century ago, except the user has to decide who all is supposed to receive the message, instead of the government being automatically added.

      To me, the silliness here is that people would use a "tech company's" encryption. If you give 0.001 fucks about security, then all your crypto is done using standard protocols, and you just happen to be using one of the various implementations. There isn't any one party to pressure. What are they going to do, ask Debian to include a forked version of GnuPG and also get PGP to be compatible with that? Both versions will include the government's copy of the session key, but not show it when you ask the program to show how a message is encrypted, and they're going to nicely ask all GnuPG forks to go along with that?

      It's impossible for the government to win this, unless The People simply don't care at all. If you care, then you aren't using any proprietary programs for communication, so there isn't someone to sabotage their own program.

      You. If you decide that you would rather their attack not work, then their attack is definitely not going to work. Period. That's how easy it is for us to win this.

      The only people who should worry about this kind of stuff, are people who choose tools before deciding their requirements. i.e. someone decides "I want to use Apple's products no matter what" or "I will use Snapchat" or "my company makes me use Telegram so I'm going to use Telegram for my personal stuff too." Those people cannot be helped, until they decide they want to stop being vulnerable. And once they do that, they don't even need help. If anything, their life gets easier.

      Requirement: "it must be standard." There. From that requirement alone, it flows that you aren't going to be using a proprietary protocol that depends on one company's implementation. At that point, you're mostly just left with pretty secure stuff. Then if you throw "it must be secure" onto the requirements list...

    27. Re:They are correct by Anonymous Coward · · Score: 0

      So, you will have a low security US version and a high security international version.

      Its either that or US companies will find they are excluded from 95% of the worlds population.

      The USA is NOT the leader of the free world , there are a number of countries that are freer.
      Its a title the US gave its self, not the world.
      The USA makes up only 4%-5% of the worlds population, US laws, US government, etc finish at the US boarders.
      The world is entitled to its own copyright/patent laws and they may NOT be the ones that suit US corporations.

    28. Re:They are correct by Anonymous Coward · · Score: 0

      Iceland, or maybe some of the Scandinavian countries. I've heard better things about them.

    29. Re:They are correct by Anonymous Coward · · Score: 0

      How about the EU?

    30. Re: They are correct by Zero__Kelvin · · Score: 1

      Evidently you were unaware of Open Source and how that works.

      --
      Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
    31. Re:They are correct by Anonymous Coward · · Score: 0

      Watch them move then. A company that's desiring to protect it's customers from government overreach is a Good Company(TM) in the eyes of many. They could even make it a platform for their products.

      Even better is the idea of pissing off the hand that feeds them. After all, someone's got to get those circus bits to the masses. Unless the government wants to do the technical difficulty of that themselves, (good luck with that btw), they should play nice with the people who distract what would otherwise be an angry populous.

      Also, for those that can't read the fine print, this is a group in government that says: "Everyone's security should be weakened for the benefit of the government." without the slightest fear. This is the type of tyrannical government your grandpappy warned you about kids.

    32. Re:They are correct by networkBoy · · Score: 1

      Yup, non 5 eyes, non EU countries.

      I could even see Latin America starting to try and woo tech, simply based on:
      We don't like the US government either, come build your product here and we'll leave you alone.

      --
      whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
    33. Re:They are correct by AutodidactLabrat · · Score: 1

      Who let in the truth speaker?
      Libertarian Censors! Wake up!
      Someone is pushing the UnPropaganda!

    34. Re:They are correct by Billly+Gates · · Score: 1

      Any competent CEO would accept the US deal and keep it secret as to still sell overseas. After all they don't know anything about it ... wink.

      If they refused the same paranoid governments such as Russia still wouldn't do business with you anyway. Might as well sign a pact with the devil if you want to keep your job by the mercy of Wall Street.

      Remember when Cisco got excited and BEGGED and BRIBED to be able to work on the great firewall of China???!! Ethics take a back seat to money everytime.

      MY guess is if Cisco refused China would find a smaller CHinese company or Avaya (owner of Nortel) would sign up for it and now this smaller company would be a large Cisco competitor. We can't let that happen now could we?

    35. Re:They are correct by Anonymous Coward · · Score: 0

      Except that when wikileaks releases have already happened, and yet people aren't able to use their white matter to connect their gray matter, and when this stuff isn't properly absorbed into consciousness, then the hypothesis must be that ozone depletion and/or cosmic rays, and/or coal pollution, and/or WWII nuclear tests have depreciated IQ to the level of fish.

    36. Re: They are correct by Anonymous Coward · · Score: 0

      French citizen detected

    37. Re:They are correct by DontTrustWhatIType · · Score: 0

      In particular, they'll lose the licenses necessary to export the goods or to import them if manufactured overseas.

      No because (1) very, very few technologies require export licenses, and (2) when they do, it's not the DoD or the DoJ that issue licenses. If you are referring to the inability to export strong cryptography, then with very few exceptions (and, yes, made through the DoD to enable disseminating to close allies for military/government use only) you can't, whether you're Apple or John Doe. There is no "license" to allow you to export 40,000-bit, quantum-computing-unkrackable encryption -- it's just illegal. This has been circumvented by having (1) your dev team outside the US, so you are importing it into the US (which is currently largely legal, contrary to what you imply above), or (2) making the bit-depth configurable as PGP does, so what is exported is "legal" but when used it's configured to something stronger than would have been allowed.

      [...] They can also lose government sales.

      Meh. Only an issue if the government is your main or only target audience, in which case, do you individually really care if you bought something intended for the military and you find out that they can spy on you? (Note: having a backdoor on military tech is an even dumber idea, but we're not arguing if the government is always doing the smartest things). Apple, Google, Facebook, and even Microsoft are happy to play with the G-men, but none would abandon their 90% of non-government market

      With abusive legal tactics such as "Patriot Act" orders, a company refusing to cooperate with orders for backdoors is vulnerable to extremely destructive legal and extra legal abuse from the FCC and from Homeland Security.

      National security letters are the devil incarnate and can kill a startup and hamper almost any size company, but the FCC has nothing to do with them. Ajit Pai is a festering pustule poised to explode on the US's behind for a lot of good reasons, but not this one.

    38. Re:They are correct by Anonymous Coward · · Score: 0

      How about the EU?

      , he says with no sense of the irony at all, even though "Germany Preparing Law for Backdoors in Any Type of Modern Device" is still on the front page.

  2. Why would they need a court order by FrankHaynes · · Score: 4, Insightful

    when heavy-handed coercion will do the trick every time?

    --
    slashdot: A failed experiment.
    1. Re:Why would they need a court order by Anonymous Coward · · Score: 0

      Don't forget blackmail.

    2. Re:Why would they need a court order by AHuxley · · Score: 2

      Once the tech sector had a few bankruptcies described to them even the most dim witted management teams understood no court order was needed.

      --
      Domestic spying is now "Benign Information Gathering"
    3. Re:Why would they need a court order by Anonymous Coward · · Score: 2

      Sure you can choose your govt. Get dual citizenship and move

    4. Re:Why would they need a court order by Anonymous Coward · · Score: 1, Informative

      This is probably more explainable by a much greater ammount of nationalism in USA.

    5. Re:Why would they need a court order by TheRaven64 · · Score: 3, Interesting

      If I don't like Facebook, which I don't, at-least I don't have to use it.

      The problem, as always, is network effects. It was easy to avoid Microsoft too, right up until the point where you wanted to bid for a lucrative contract where the customer would only accept submissions using their complex Word template. Asking them for a copy in an open format would just have you marked as uncooperative and you'd lose automatically.

      The same is increasingly true for Facebook. I don't use it, but an increasing number of companies use Facebook and Twitter as their primary method of providing customer support and provide discounts for people who like them on these platforms.

      --
      I am TheRaven on Soylent News
    6. Re:Why would they need a court order by Anonymous Coward · · Score: 0

      So I can just click my ruby slipper heels and say "There' no place like Rome", and Glynda the Good Witch will bestow dual citizenship on me, just like that?

      Bwahahahaha. You crack me up.

      And then see the post above about good men running and tyrants.

    7. Re:Why would they need a court order by MooseTick · · Score: 2

      Just because you have an account doesn't mean you have to upload pics and statuses. If its your job, do what you have to do and no more. Then you aren't any more exposed than using any other web site including this one.

    8. Re:Why would they need a court order by TheRaven64 · · Score: 1

      Other web sites, including this one, don't invite people to 'friend' me, use that information (as well as my email address in any Facebook user's address book on a smartphone) to build a social graph, place tracking cookies to associate my account with other web pages that I visit that show ads, and so on.

      --
      I am TheRaven on Soylent News
    9. Re:Why would they need a court order by aliquis · · Score: 1

      Yeah. He said good men.

      Nationalism is a good thing.

      For America though I wouldn't call it nationalism but rather patriotism because the USA is a mixed country. I assume what you like there is the country not necessarily "your people."

      Another thing to consider is that the USA is one of very few countries which tax their citizens abroad or whatever so that may make it less interesting for someone from the USA to work abroad whereas many from other countries wouldn't mind working in the USA.

  3. boil it down by TheGratefulNet · · Score: 5, Interesting

    its boils down to:

    "I want this. give it to me!"
    "why? you have shown you can't be trusted with this. and, math also says its not possible."
    "I don't care. I'll force you if you don't volunteer."
    "looks like you want a fight. bring it."

    and so on, and so on.

    some companies will cave in, some will give the impression they are standing tall but actually do cave in. MAYBE there are actual companies that have enough power to say 'no' to the various governments, but I kind of doubt it.

    its sad to see the schoolyard bully - who has a power complex - unwilling to give in. every few weeks or so, we have another story about how some official wants to have access to ALL your shit and he will simply stomp his feet, cry and whine until he gets it.

    its a tiring process and such a waste of time and energy. and yet, here we are, revisiting this issue yet another time.

    --

    --
    "It is now safe to switch off your computer."
    1. Re:boil it down by rtb61 · · Score: 5, Interesting

      Too which the response is, "fine, if I can't have it than, fuck you, you can't have it either". You do that by shifting the encryption coding bit to FOSS, as a network add on and they can try to stick the back door in free open source code, which you can locally compile and then add to you software than lacks a network connection module. The encrypted network connection module can be served up by anyone and if they really need to hack your computer, they can hand you a national security letter and demand you hack yourself or just fucking apply for a search warrant and get busy with cameras and wires and people in the field, no 'bullshit control freak spy a thon for you' more specifically them. There was a time due to US regulation I had to download 128 bit encryption from the internet and install it myself, so, so hard, to do it again, in fact the US government drove FOSS encryption.

      --
      Chaos - everything, everywhere, everywhen
    2. Re:boil it down by Puls4r · · Score: 3, Interesting

      It's usually not argued nearly that seriously. What CEO or corporation would argue with a government willingly knowing that the end result is going to be a cessation of government contracts, barring from export, and anything else the government has that they can legally do that are in there powers?

      It's usually held behind closed doors and handled, and if it isn't like the Apple issue, then there is a reason you and I don't know about. It will STILL get handled behind closed doors, the government will just have to give something up in return like looking the other way on Irish tax havens, etc.

    3. Re:boil it down by Anonymous Coward · · Score: 0

      those that won't "cooperate" will get infiltrated by spooks and their products or services compromised anyway.

    4. Re:boil it down by Anonymous Coward · · Score: 1

      They'll ask for it even if it's impossible because it's not their asses on the line when you fail.

      These people will not feel the repercussions of their bad decisions. Worst case they'll bring down the world banks and every economy and hand all the data off to ISIS to defraud the entire American public out of billions of dollars. Those billions might be turned into missiles and fired at major cities in America, killing countless civilians and ruining our infrastructure. ...but these are politicians, and these people will die last in the holocaust they created.

    5. Re:boil it down by Anonymous Coward · · Score: 0

      These people will not feel the repercussions of their bad decisions.

      That's why we have 'scoped high-powered rifles.

      Drop a few at the top and suddenly they'll start taking objections a lot more seriously.

    6. Re:boil it down by Anonymous Coward · · Score: 0

      I still remember the disclaimers when downloading encryption software. Do not export to Iran, or you'll end up in prison! Now encryption is so common place, everyone has it.

    7. Re:boil it down by Anonymous Coward · · Score: 0

      It depends on the risks involved. The government has proven to be incompetent and a simple leak can cost such company complying with the government everything. Unless you're a too big to fail company, the risks is too much now, versus some silly things the government can do to you.

    8. Re:boil it down by Anonymous Coward · · Score: 1

      I have seen this stated a lot "The Government has proven to be incompetant". Compared to what? Basically every other large corporation that has also had data breaches and leaks and god knows what else. I don't really see that the private sector has done a whole lot better job with network security.

    9. Re:boil it down by TheRaven64 · · Score: 5, Interesting

      Bruce Schneier's book, Applied Cryptography, showed precisely how stupid these export restrictions were. They didn't limit algorithms, they limited key length. You could export RSA with short keys, but not with longer ones. His book had source code for them where the algorithms were compile-time constants. If you typed them in as-is, the resulting code was export-legal. If you changed a 128 to a 1024 (or whatever - I forget the exact allowed vs not-allowed numbers), it wasn't. Because of this, it was completely legal to ship the book anywhere in the world, and anyone in a country where it wasn't allowed simply had to change a constant when they typed in the code.

      --
      I am TheRaven on Soylent News
    10. Re:boil it down by TheRaven64 · · Score: 1, Interesting

      Compared to what?

      Compared to the level of security that you need from an organisation holding information that, if public, could cripple your company. Most companies are fairly good at keeping their own secrets, because they understand the cost of not doing so.

      --
      I am TheRaven on Soylent News
    11. Re:boil it down by coofercat · · Score: 2

      In that particular case, the export restrictions also meant that the rest of the world couldn't have online banks. To resolve this problem, the rest of the world found their own solutions to those problems (most often in the form of a Java applet), and thus created their own software companies to do what the US wasn't able to do. The corporations duked it out, and eventually the export restrictions went away because it was extremely disadvantageous to American international business to have them in place. I seriously doubt 'security' ever really came into those discussions.

      In this case, if the rest of the world can't have safe communications, then we'll just go ahead and make our own platforms. Hell, we don't even need to - there are enough around already, it's just that right now there's not much motivation to switch to them. Getting the meta out of the US companies is still better than getting precisely nothing, but of course the powers that be don't get that.

      If you want America First, you have to play along with everyone else, otherwise you actually end up with America Last.

    12. Re:boil it down by Xyrus · · Score: 1

      And your ISPs terminate all your traffic for not complying, which they now can with the upcoming repeal of net neutrality.

      Brave new world.

      --
      ~X~
    13. Re:boil it down by necro81 · · Score: 2

      If you want America First, you have to play along with everyone else, otherwise you actually end up with America Last.

      I am reminded of this saying: "a leader with no followers is just a guy taking a walk."

    14. Re: boil it down by Type44Q · · Score: 1

      ...and anything else the government has that they can legally do that are in there powers?

      "Legally?!" You're a funny guy.

    15. Re:boil it down by Anonymous Coward · · Score: 0

      its boils down to:

      "I want this. give it to me!"
      "why? you have shown you can't be trusted with this. and, math also says its not possible."

      Why? Because I know about your dirty secret. You wouldn't want everyone to know, would you?

      Captcha: consent

    16. Re:boil it down by Kernel+Kurtz · · Score: 1

      What CEO or corporation would argue with a government willingly knowing that the end result is going to be a cessation of government contracts, barring from export, and anything else the government has that they can legally do that are in there powers?

      I don't know, but it suggests that companies barred from government contracts or exports are probably the companies with integrity that you want to do business with.

    17. Re:boil it down by Anonymous Coward · · Score: 0

      its boils down to:

      "I want this. give it to me!"
      "why? you have shown you can't be trusted with this. and, math also says its not possible."

      Why? Because I know about your dirty secret. You wouldn't want everyone to know, would you?

      But... I don't have any dirty secrets.

      Hahaha! You do now. And there will be a new one each day you don't comply.

    18. Re:boil it down by david_thornley · · Score: 1

      It's a question of whose secret it is. Companies tend to not secure their customers' secrets well. The government tends not to secure company's secrets well.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    19. Re:boil it down by david_thornley · · Score: 1

      I approximately never see this happening. People with rifles rarely shoot people at the top. I'm not going to condone assassination, but there's times when it seems like a few bullets in the right brain stems could have some very positive effects.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    20. Re:boil it down by Anonymous Coward · · Score: 0

      Bull shit. Most companies suck at it, just like the government. Facebook, Google, Microsoft, they are exceptions because they have the capital, and understand the need to afford some of the most talented security people in the country. But as far as the "average company" being better than the US gov't: I sincerely doubt it. And frankly, "the government" is too vague, different levels of government, and even different departments, can implement security totally differently. I think the NSA is going to have a shitload more security than the city of Branson Missouri. It's just common sense. All that said, government (or otherwise) encryption backdoors are obviously stupid. I think we can all agree on that.

    21. Re:boil it down by TheRaven64 · · Score: 1

      Some of this worked out well for US corporations. For example, South Korea developed an ActiveX control that implemented crypto and required all banks to use it. If you wanted to use online banking, you had to use IE on Windows.

      --
      I am TheRaven on Soylent News
  4. List of assumed backdoors by Anonymous Coward · · Score: 1

    Microsoft OS
    Cisco iOS
    Intel ME
    AMD TrustZone

    Bottom line is they don't need encryption backdoors because they have lower level access. What the FBI and law enforcement need is a legal excuse for how they got your information without drawing attention to the more sophisticated exploits reserved for national security level operations (NSA, CIA, ect..)

    1. Re:List of assumed backdoors by nctritech · · Score: 4, Informative

      You forgot to mention "every radio coprocessor in every smart phone ever made." The radio coprocessor in cell phones typically has full "back door" access to the resources used by the main CPU and OS you interact with. The code for it is 100% closed off and the massive flaws in the cellular system's authentication that allow Stingrays etc. to actually work properly means you have this closed-off CPU that can do arbitrary stuff on your phone open to access from outsiders with knowledge of cell system architecture.

    2. Re:List of assumed backdoors by Anonymous Coward · · Score: 0

      And the sad fact is that phone Armageddon is fast approaching with more code being exploited and more phone encryption being cracked. Our wonderful government is too incompetent to correct and remedy the situation. Pretty soon, all our phones are going to be turned into the Windows 98 ME with all the rootkits and malware installed automatically from each cell tower you pass by. Even our damn military is now afraid of using cellphones ever since the discovery of fake cell towers by bases.

    3. Re:List of assumed backdoors by TheRaven64 · · Score: 4, Interesting

      The radio coprocessor in cell phones typically has full "back door" access to the resources used by the main CPU and OS you interact with

      This is not true on iOS devices. The connection between the baseband processor and main memory is quite restricted, because Apple's hardware team doesn't trust third-party IP cores and so locks them down. It's also not true for a few other SoCs, where the baseband core has its own private memory and communicates with the host via an on-chip serial interface. This was a very common way of implementing smartphone SoCs, because it meant that you could trivially validate that there was no way for the application core to modify the baseband core's state and so you could use the same baseband core on a bunch of SoCs without needing FCC approval for each one.

      --
      I am TheRaven on Soylent News
    4. Re:List of assumed backdoors by Eravnrekaree · · Score: 1

      But the backdoor could also be hidden in the operating system. IOS is closed source so there's no way to know. I know some parts are open source but much is closed source so there is no way to do your own build to rule out a backdoor.

    5. Re:List of assumed backdoors by CODiNE · · Score: 2

      https://googleprojectzero.blogspot.com/2017/10/over-air-vol-2-pt-3-exploiting-wi-fi.html
      This is literally the front page of Googles Project Zero blog right now.

      Sure Apple makes it a bit more difficult than some other phones but the core weakness is not eliminated. People often confuse vulnerabilities and exploits. Having a closed source chip in your baseband IS a form of vulnerability... there may not be a working exploit that is currently known, and it may be difficult to accomplish but it remains a weakness.

      With Apple continuing to lock down baseband access it may eventually be strong enough to resist even a malicious broadband chip. Much like the Intel Management Engine, years of people calling it safe doesn't make it so.

      --
      Cwm, fjord-bank glyphs vext quiz
    6. Re:List of assumed backdoors by sl3xd · · Score: 1

      It's not like the situation is any rosier on Android: For years, Google has been adding functionality not to the open source AOSP code base, but to its own proprietary binary libraries, specifically the ever-expanding GMS (Google Mobile Services), which it uses as a cudgel to force handset makers to stay in line. When a handset maker doesn't stay in line for any reason, Google cuts them off.

      For example, when Amazon decided to stop selling Google devices, Google retaliated by cutting off their own customers who had the nerve to use Amazon devices.

      --
      -- Sometimes you have to turn the lights off in order to see.
  5. Buy Chinese by PPH · · Score: 4, Insightful

    They may be spying on you as well. But they won't be using what they get for any parallel construction.

    --
    Have gnu, will travel.
    1. Re:Buy Chinese by Anonymous Coward · · Score: 0

      ;) true

    2. Re:Buy Chinese by DNS-and-BIND · · Score: 1, Insightful

      Yeah, this is why the intelligence community always freaks out about Chinese backdoors and such. This is their turf! Only they can spy on us!

      Unless your job is handling classified material, then you have nothing to fear from the Chinese government going through every bit of data you ever generate. They literally have no way to harm you. On the other hand, the US government has not only the means but the motivation to harm you.

      I remember some .ru email service was being promoted on Slashdot, and people were shouting, "It's bugged by the KGB, don't use it!" Like, who cares? They're not going to care one whit about my life. The same with Kapersky anti-virus.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    3. Re: Buy Chinese by c6gunner · · Score: 0

      If you believe that the CIA cares any more about your life than the KGB does, it's safe to say that you're either nuts, or you're planning to blow up a target in the US.

    4. Re: Buy Chinese by DNS-and-BIND · · Score: 2

      It is only tyrants that fear tyrant-killers.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    5. Re: Buy Chinese by Anonymous Coward · · Score: 0

      > ... If you believe that the CIA cares any more about your life than the KGB does ...

      Actually, CIA doesn't care about me

      They only want to SPY ON ME

      'nuff said !

    6. Re:Buy Chinese by gweihir · · Score: 1

      You have a point. What a sad, sad state of affairs.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    7. Re: Buy Chinese by fafalone · · Score: 1

      The problem is the CIA/NSA will forward information to domestic law enforcement like the DEA and FBI, or those agencies can request help, and they then use parallel construction to conceal the source. This isn't a "they could" thing, it's a "this is already business as usual" thing. From there it's shockingly easy to find yourself on the wrong end of a raid even if you're innocent, just for talking to the wrong person and saying the wrong thing then having it interpreted wrong.

    8. Re:Buy Chinese by Anonymous Coward · · Score: 0

      Unless your job is handling classified material, then you have nothing to fear from the Chinese government going through every bit of data you ever generate. They literally have no way to harm you.

      Good Luck with that. Some people believe in calling out the Chinese government on issues like censorship, religious and other anti-freedoms, and that whole mowing down peaceful civilian democracy protesters with machine guns and a dozen tanks back in 1989(jesus years)

    9. Re: Buy Chinese by TheRaven64 · · Score: 1

      I don't believe that either should care about me, but I know which one is likely to cause more negative consequences for me if I end up being a false positive in their big data inference engines. I have a friend who had the same name as someone on the now-fly list (he doesn't anymore, because after a few years that added middle initials to the list) who can attest for how inconvenient it is to have even a low level of interest from the intelligence agencies in a country that you regularly visit or live in.

      In contrast, if the FSB decided I was a person of interest, then it would likely have no impact on my life at all unless it escalated all of the way up to polonium time, and hopefully there's some human oversight at that level.

      --
      I am TheRaven on Soylent News
    10. Re: Buy Chinese by Anne+Thwacks · · Score: 1
      The problem is the CIA/NSA will forward information to Wikileaks

      FTFY

      --
      Sent from my ASR33 using ASCII
    11. Re:Buy Chinese by drinkypoo · · Score: 1

      I remember some .ru email service was being promoted on Slashdot, and people were shouting, "It's bugged by the KGB, don't use it!" Like, who cares? They're not going to care one whit about my life. The same with Kapersky anti-virus.

      This implies that you believe all the politics theater that you see in the press about how adversarial the relationship between the US and Russia is. But it is both cooperative and competitive in the region of information. We share some information. It's not safe to assume that your government isn't getting your personal information from some other government, in exchange for providing them the same kind of information about their own citizens.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    12. Re: Buy Chinese by Anonymous Coward · · Score: 0

      Nothing wrong with Wikileaks. Not sure why American's have such bee in their bonnet about it. You don't have to like Assange to appreciate that they expose illegal and unethical behaviours of people in power.

    13. Re: Buy Chinese by Antique+Geekmeister · · Score: 1

      They also forward data, wholesale, as part of intelligence sharing about shared threats. There is a reasonably good, though self-serving, analysis at https://www.cia.gov/library/ce... .

    14. Re: Buy Chinese by Anonymous Coward · · Score: 0

      Assange is a Russian intelligence agent, surely people can't believe otherwise. His bullshit leaked emails swung the election to Trump.

    15. Re:Buy Chinese by Anonymous Coward · · Score: 0

      Good Luck with that. Some people believe in calling out the American government on issues like censorship, gender and other anti-freedoms, and that whole mowing down peaceful civilians in Iraq, Somalia, Syria, and a dozen other countries with smart bombs and drones back in 2016(jesus years).

    16. Re:Buy Chinese by Anonymous Coward · · Score: 0

      Is your tinfoil hat tight enough? The only thing people remember about that is that the tank didn't run over that guy. What fantasy are you living?

    17. Re:Buy Chinese by Kernel+Kurtz · · Score: 2

      Absolutely. If you are a government or a corporation, foreign spying is bad. If you are an individual, foreign spying is a whole lot more benign than domestic spying.

    18. Re:Buy Chinese by david_thornley · · Score: 1

      We should probably be more precise. As a US citizen and resident who does not deal with classified information or other internationally important stuff, I don't really care about the Chinese or Russians spying on me, because they're highly unlikely to care about me or cooperate with anyone who does. That's one reason I keep using Kaspersky: I'm fairly sure they don't install back doors for the NSA or CIA or FBI.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    19. Re:Buy Chinese by Anonymous Coward · · Score: 0

      Good Luck with that. Some people believe in calling out the American government on issues like censorship, gender and other anti-freedoms, and that whole mowing down peaceful civilians in Iraq, Somalia, Syria, and a dozen other countries with smart bombs and drones back in 2016(jesus years).

      Tiananmen Square Massacre was an entirely different kind of situation. There weren't groups of well armed people in a large scale military battle at Tiananmen. Except the government and their tanks and guns of course.

      False equivalencies are evil. Sure, calling out the American government is a good tactic too. But talk to some older people. What happened at Tiananmen (or within a 1 square mile radius if you want to quibble with those that dictate Google's search results) was different. DIFFERENT.

      Watch the video of the event. This wasn't something akin to a bunch of racists and anti-racists with no intent to avoid violent confrontation. Tiananmen was thousands of PURELY PEACEFUL DEMOCRACY DEMONSTRATORS GETTING SLAUGHTERED BY THEIR GOVERNMENT. MASS MURDER.

      Fuck you you piece of shit. Watch the fucking video. Get a fucking clue.

  6. if the weight goes back on ... by Anonymous Coward · · Score: 0

    that's you americans doubly fucked then.

  7. Whelp by z3alot · · Score: 1

    So much for american technology

  8. Unlikely by Anonymous Coward · · Score: 0

    And given this is a Gizmodo article, entirely fabricated.

  9. Don't be surprised then by Anonymous Coward · · Score: 0

    When I say no.

  10. They are correct... by ad454 · · Score: 2

    They did not need a court order to get Intel to install a backdoor into ME, AMD to install a backdoor into PSP, or Microsoft to install a backdoor into Windows 10, since they all did so quite willingly.

    It is a shame consumers can no longer fully own their modern computers. And yet these government agencies refuse to cover any part of the cost of new computers which they have some control over.

    1. Re:They are correct... by Anonymous Coward · · Score: 0

      Wait, it's documented that the US government actually got backdoors added into ME, PSP and Windows 10? Can you point to such documentation?

    2. Re: They are correct... by Anonymous Coward · · Score: 0

      An exploit will always be an intentional backdoor to conspiracy theorists.

      Probably sometimes they'll be right, sometimes they'll be wrong.

    3. Re:They are correct... by Anonymous Coward · · Score: 3, Informative

      The Cisco backdoor was found because the US government said "hey, Huawei is copying our Cisco backdoor!" So not only was the Huawei backdoor found, which was a product of Huawei copying Cisco's code line for line, but Cisco's backdoor was discovered, as well as the US government involvement in that "accidental" backdoor.

      The only country proven to have officially requested backdoors in equipment is the USA. Yet the USA spends money on getting Australia to refuse to buy from Huawei, to protect Cisco's market share, as a reverse bribe for complicity.

      That you don't believe in Cointelpro doesn't mean it didn't happen.

    4. Re:They are correct... by Anonymous Coward · · Score: 0

      Meanwhile, there is a silent bailout of Cisco because nobody trusts them anymore. Their whole base of survival now is government contracts.

    5. Re:They are correct... by thegarbz · · Score: 1

      No, that was achieved entirely by the Independent Coalition For The Continued Sales Of Tin Foil Hats!

      Incidentally we're looking for a new acronym because ICFTCSOTFH doesn't really roll off the tongue.

    6. Re:They are correct... by AmiMoJo · · Score: 1

      There are plenty of ARM based systems available that don't contain these backdoors. Many use CPUs from non-US companies that are at least unlikely to have FIVE EYES backdoors in them, and some have extremely minimal ROMs that limit the scope for malware anyway. Plus those ROMs are real ROMs (not flash).

      There are RISC V boards that can run Linux too. You still have to trust the fab didn't backdoor the design, but it's about as good as you can get short of making your own CPU out of twigs and string.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    7. Re:They are correct... by coofercat · · Score: 1

      ...and so it'll continue.

      Let's say it'll cost $100 million to get the laws in place, and then to actually get all the tech companies to comply. Instead, just spend that money to 'motivate' those companies to do it for you without the laws and without the publicity.

    8. Re:They are correct... by networkBoy · · Score: 1

      Citation please.

      There is *no* intentional back door in Intel ME up to version 9 (I left the company before 10 shipped, so can make no comment).

      I am not gagged about not revealing anything via any NSL, and while I will respect my NDA with my former employer (even though the current CEO is a top shelf Asshat) I had full access to the source code, and had direct work with the authentication subsystem of the ME portion (NOT AMT) and I can categorically state that there was *NO* back door for any government in the codebase.

      If something was patched in after release to manufacturing I would have no way of knowing this, so if you have a citation that proves your statement and undermines a whole bunch of damn fine programmers that I worked with, all of whom honestly took security seriously and all of whom tried to make the best product they could then please show it here.

      Whether or not ME should be forced to be installed on all platforms was a matter of serious debate internally, but in the end the engineers were overruled by marketing, and we all need to eat. In the end we did the best we could to provide a secure base product (ME) for applications (AMT) to run on.

      --
      whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
    9. Re:They are correct... by david_thornley · · Score: 1

      Yeah, and the last time I suggested a better acronym you said I was working for the CIA, and rejected it. BTW, I've heard that the NSA carefully regulates the quality of tinfoil in this country. (Amazing the things you can correctly claim you heard when you say them yourself.)

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  11. That's why by Anonymous Coward · · Score: 0

    I'll only buy from the Chinese and the Russians. They don't care what's on my devices.

  12. "It never hurts to ask!" by Locke2005 · · Score: 4, Interesting

    Sure, they can ask, and any enlightened company will politely tell them, "No way!" And as long as companies are honest and upfront about whether or not they have built in back doors, so that their customers can chose whether or not they want to deal with the risk, I'm fine with it. The problem is, aren't the criminals the most likely to avoid all the tech with back doors? In other words, voluntary weakening of security doesn't really accomplish anything, does it?

    --
    I've abandoned my search for truth; now I'm just looking for some useful delusions.
    1. Re:"It never hurts to ask!" by Anonymous Coward · · Score: 0

      People that would like to develop novel ideas seem more likely than a criminal to have an actual need of privacy. Criminals are watched and allowed to continue unabated all the time. Good ideas on the other hand...

    2. Re:"It never hurts to ask!" by AHuxley · · Score: 1

      Re "the criminals the most likely to avoid all the tech with back doors? "
      Criminals will respond in a few ways.
      What the GCHQ always warned about, going dark, just stopping using any collect it all communications after some other gov talks about collection too much.
      Criminals will use expendable front groups to bait the networks and see what agency comes looking.

      Telco work in the street. A new FBI utility pole surveillance cam was installed.
      A small aircraft takes off at an airport, stays over a part of the USA for hours packed with a LETC upgrade. Lands back at the same airport. Collection range was about 2 miles.
      A much more advanced pressurised collection aircraft flys over the area once with a full mil grade collection kit.
      Both results can be very telling about what agency was induced to start collecting.
      Most of the more skilled criminal groups will just return to their family, tribe, cult, faith in their community.
      MI6, the CIA, MI5 will hope that induces the use of more courrier work.

      The real long term way criminals will respond is to flood the virtue signaling recruiting efforts by the Wests police and security services.
      A flood of "citizens" trusted by criminals and cults will all pass tests to join the police, mil and security services. Translators and contractors are another way in.
      The many that get in and advance up the ranks will stay in place and watch for new methods used to hunt criminals globally.
      Any informants entering no go areas will be detected long before they start their undercover mission.
      Put in the years and join projects working with international police cooperation for the next step in counter surveillance.
      The police and mil will be unable to block workers who pass exams due to political correctness and party political clearances. Security protections to get a job in the security services will start to fail and mission data will walk out every mission.
      The loss of encryption will be countered by criminal groups, faith groups, cults doing generations of counter surveillance at all levels on the gov, mil, police and special forces.

      The few loyal police and mil will try and hide their investigations from telos, all other police, mil, gov, lawyers, courts and try and do their collection as a smaller elite trusted unit. Thats the real reason for the rise in parallel construction all over the USA. The good police and mil cant trust their own, the courts, telcos.
      Criminals will use all their collection abilities in the gov and mil to find such police units..
      Collection will go on but criminals fronts will be looking back at all police, mil, special forces, contractors and other agencies.
      Criminals will have gov/mil access to watch most city/state law enforcement once all US encryption gets trap door and backdoor.

      Its not the criminals that will have to avoid all the tech with back doors. The state and city police will be tracked 24/7 by criminals.
      Internal affairs will working very hard too.

      --
      Domestic spying is now "Benign Information Gathering"
    3. Re:"It never hurts to ask!" by Anonymous Coward · · Score: 1

      The situation gets even more fun to consider once one realizes that, in light of the relative ease with which any major company can be infiltrated (or bought out with printed money), the show of corporate defiance can easily end up being much more valuable to the spooks than mere compliance.

    4. Re:"It never hurts to ask!" by fafalone · · Score: 1

      You have an awfully high opinion of the sophistication of criminals. Everything you describe could only possibly be undertaken by the most elite organized crime orgs in the world. For the other 99.99% of criminals, they'll just continue carrying on over plain old SMS and cell phones just like they do now, even in the face of secure alternatives. There's a small subset that are slightly more sophisticated that laws on built in encryption matter; but let's face it, this really has nothing to do with criminals at all.

    5. Re:"It never hurts to ask!" by Bert64 · · Score: 2

      But why would they?
      Companies are run for short term gain... Deploying a backdoor could get you a short term injection of cash from the government for whom you created the backdoor.
      Sure there is a risk the backdoor will be leaked in the future, but by then the people who made those decisions have taken their cash and run so they won't care.
      Also even if a backdoor is discovered, it can usually be explained away as a bug. Even when obvious backdoors are found (see the recent juniper ssh backdoor) they can claim it was hackers and brush it under the carpet. Juniper lost very few customers over that incident.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    6. Re: "It never hurts to ask!" by Anonymous Coward · · Score: 0

      You naively assume that the criminals we catch are the same caliber of the criminals that we don't catch.

    7. Re:"It never hurts to ask!" by AHuxley · · Score: 1

      Why would a criminal group not photograph every person into and out of a court and police station?
      With the total loss of encryption not think to add some malware to every person near a police station?
      Have every face and account connected back in social media? Who did the advanced criminology course? Who only had just enough further education to stay at that rank?
      Who has lifestyle problems? Gambling? Drinking? A cash flow problem? Likes been in the media with a good story?
      Human weakness, investigative strengths, areas open to blackmail. Officials who are over extended with their lifestyle and who really need a big bribe.
      The loss of loss of encryption will help find the undercover offices and many informants who have to report back to other officers.
      To find an easy way to get a court, police job for people who are trusted by criminal groups but who can pass an exam and have not criminal background on file.
      The removal of strong encryption is one of the last good protections for honest law enforcement, their communication and their informants.

      Its not the criminals who trust their encrypted phones too much and will make mistakes its the police and city workers that will no longer have secure communications.

      --
      Domestic spying is now "Benign Information Gathering"
    8. Re:"It never hurts to ask!" by Locke2005 · · Score: 1

      I see why you've obviously named yourself after Aldous Huxley. You have a real knack for writing science fiction! I suspect organized crime isn't quite as organized as you imply it is. Even the Trump crime gang is usually much more like Keystone Cops than James Bond villains.

      --
      I've abandoned my search for truth; now I'm just looking for some useful delusions.
  13. Why should we expect open source to be any better? by Anonymous Coward · · Score: 4, Interesting

    What makes you think that open source software is somehow any better?

    As the Shellshock and Heartbleed bugs have proven, just because source code is available it doesn't mean that anyone actually looks at it. When major open source software projects have serious bugs in them that go undetected for years or even decades, it's doubtful that a well-hidden backdoor would be found.

    Then there are projects like systemd and GNOME 3, which have introduced a lot of new code into many Linux systems. Has all of this code undergone a strenuous security review? I very much doubt it!

    Even the OpenBSD project, which is perhaps the most stringent and careful open source project out there, has had scares in the past.

    So I don't think we should consider open source software to be any better. It could very well be much worse.

  14. Are these elected officials? by DNS-and-BIND · · Score: 1

    I wonder, are any of these people elected? Do they think that they owe any allegiance to the elected US government, seeing that it changes all the time? And when the elected government tries to control them, they hiss and threaten to strike back. If they don't think they should be under the control of the elected government, what's to stop them from doing any damn thing they please?

    --
    Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    1. Re:Are these elected officials? by Anonymous Coward · · Score: 0

      If you voted Republican, this is what you voted for. If not, then sorry, the rest of the country voted for Nazi 2.0.

    2. Re:Are these elected officials? by kenh · · Score: 1

      Yeah, because a Democrat would NEVER DREAM of such a thing. /sarcasm

      --
      Ken
    3. Re: Are these elected officials? by Anonymous Coward · · Score: 0

      Shut up you goddamned Nazi.

  15. Of course... by kenh · · Score: 2

    ASKING doesn't require a court order, and compliance is OPTIONAL .

    --
    Ken
    1. Re:Of course... by Anonymous Coward · · Score: 0

      ASKING doesn't require a court order, and compliance is OPTIONAL .

      In this case, "asking" also means "offering money" for anything they don't think the FISC would grant.

    2. Re:Of course... by Anonymous Coward · · Score: 0

      Sort of like compliance with your friendly local Mafia contact is "optional."

    3. Re:Of course... by Anonymous Coward · · Score: 0

      For some definition of optional.

    4. Re:Of course... by sl3xd · · Score: 1

      Sure. I could refuse that pill of cyanide, but if I don't take it, you'll shoot me in the head.

      Totally an option.

      --
      -- Sometimes you have to turn the lights off in order to see.
  16. So thats what PRISM had to hide by AHuxley · · Score: 1, Interesting

    the weasel words about PRISM.
    If a company never refuses the gov, legal protections never had to be mentioned.
    If the brand never says no the gov, they never have to tell their own legal department.

    The Rules of Collect it all Club.
    First rule of collect it all club, never tell an in house lawyer.
    Someone yells whistleblower, goes bankrupt, sells out, the collection is over.
    No lawyers, no admins.
    One agency at a time.
    Collection will go on as long as it has to.
    If this is your first connection to the Collection Club, you HAVE to collect it all.

    --
    Domestic spying is now "Benign Information Gathering"
  17. Why would they need a court order to ask? by mark-t · · Score: 1

    I could ask a company to put a backdoor in their product if I wanted to. I might be laughed at, but I can certainly ask.

    A court order is only required if you need to force the recipient to comply.

    1. Re:Why would they need a court order to ask? by gweihir · · Score: 1

      You need a court-order to ask, if what you are asking is actually illegal, not just morally reprehensible.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    2. Re:Why would they need a court order to ask? by Anne+Thwacks · · Score: 1
      "You can get much further with a kind word and a gun, than with a kind word alone"

      I think Abraham Lincoln said that.

      --
      Sent from my ASR33 using ASCII
    3. Re: Why would they need a court order to ask? by Anonymous Coward · · Score: 0

      Sounds more like an NRA commercial for Valentine's Day.

    4. Re:Why would they need a court order to ask? by mark-t · · Score: 1

      It's not generally illegal to simply ask someone to put a backdoor in their product, nor is it typically illegal for them to comply with such a request voluntarily unless there were patently obvious negative implications to public safety and security.

  18. That's not what by Anonymous Coward · · Score: 0

    she said.

  19. Just keep voting for the establishment by rsilvergun · · Score: 4, Interesting

    Keep putting millionaires and billionaires in charge. I'm sure they'll drain the swamp any moment now. And if they're not to your liking how about a nice blue dog democrat? He (or she) will promise not to raise your taxes, doesn't hate gay people and won't touch Social Security or Medicare (or anyone over 55). Remember folks, if you don't keep putting pro corporate, right wing people in charge those tax and spend liberals will raise your taxes. And if you're readying this and you're American than I know 60% of you are living paycheck to paycheck (google it) and can't afford it, right?

    The important thing is to remember to know your place, stay in your class, respect your betters, and don't ever screw with the aristocracy. Don't even suggest taking their money away, that would be morally wrong. You learned that in grade school economics. Capitalism got you into this mess and only capitalism can get you out of this mess.

    Can you tell I'm bitter and angry? I don't suppose there's anybody on this forum that can make an ounce of that anger go away, is there? Well guess what, there's millions of guys just like me. And guess what happens when there's too many of us? What happened in the 20s? How about the 40s? Anyone want to take a crack at proving me wrong and injecting a little hope into this thread?

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
    1. Re:Just keep voting for the establishment by Anonymous Coward · · Score: 0

      ...injecting a little hope into this thread?

      Sorry. Democracy despite its ancient Greek roots is relatively new. Early 20th century rulers allowed it to appease a growing unstoppable population.
      However, they have found ways to turn the clock back 200 years. Dukes, barons, and royalty is coming back, with different labels, the program is the same:
      Fuck the 99% as hard as possible.
      There is no hope. We lost.

    2. Re:Just keep voting for the establishment by Anonymous Coward · · Score: 0

      Want hope? Hope that the GOP keeps being soft on gun control legislation until it's too late.

    3. Re:Just keep voting for the establishment by DNS-and-BIND · · Score: 1

      At a certain point, you just have to consider emigration to a more progressive and just society, and leave old aristocratic USA behind. There's a whole world out there.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    4. Re:Just keep voting for the establishment by Anonymous Coward · · Score: 0

      Here's what the people need:

      1) Eliminate paid lobbying.
      2) Reduce the size of the military so we don't have a military that can defeat the world without allies.
      3) Related to (2) and (1), no corporate lobbying of military activities.
      4) No private companies allowed in any affairs of the military or government, i.e. Blackwater or the new article on private espionage.
      5) Eliminate high frequency trading.

      I'm intoxicated at the moment so probably not so clear, but I imagine this is a good start? What else did I miss?

    5. Re:Just keep voting for the establishment by Anonymous Coward · · Score: 1

      Puh-lease!!! Get a grip.

      Here's some hope:

      The taste of an orange. The radiant blue sky. The sound of a child saying, "Goodnight daddy." The smell of baking bread.,

      If you are lucky, you will die at eighty of prostate cancer married to somebody's grandmother. It's life. Deal with it.

      You seem to be dwelling on your lack rather than your wealth (and I don't mean money). Clearly we haven't got this govt by the people thing sorted properly quite yet, but efforts will continue. Meanwhile you have stuff you can do to help the rest of us get along, Focus on that. It's what I do. MLK said he saw a promised land, and I believe him.

      Billionaires can't buy another 80 years of life, and the most powerful politician can't stop the sun from rising. Money and politics are not most important in life. Only the foolish think they are.

      Captcha: meanders

    6. Re:Just keep voting for the establishment by Anonymous Coward · · Score: 0

      Never would have believed rsilvergun would admit he's a fascist. We all know he is, and most days he spends sucking Hillary's dick, but impressive turn to "truth in advertising" for the first time in his life.

    7. Re:Just keep voting for the establishment by TimSSG · · Score: 1

      At a certain point, you just have to consider emigration to a more progressive and just society, and leave old aristocratic USA behind. There's a whole world out there.

      I think you use "and" instead of the more correct "or". "At a certain point, you just have to consider emigration to a more progressive or just society ..." Tim S.

    8. Re:Just keep voting for the establishment by Anonymous Coward · · Score: 0

      Idiot. There are plenty of countries which are progressive and just. Especially if you compare to the US. E.g basically all of Europe, with the exception of the UK which is almost as astonishingly idiotic as the US and even worse in some aspects, would qualify.

      But I guess that's hard to grasp for someone who's never been any further than the nearest Wallmart.

    9. Re:Just keep voting for the establishment by Anonymous Coward · · Score: 0

      Have you been asleep the last 15 years? What on earth does this have to do with "right wing" ? You do realize Obama passed some of the very laws granting your current administration the authority, right?

      Not saying I agree with their power, but Trump certainly didn't create it.

      Slashdot has become one hell of an echo chamber lately, you're even killing anon posts (I have screenshots). Literally the message id's vanish.

    10. Re:Just keep voting for the establishment by Anonymous Coward · · Score: 0

      Can you tell I'm bitter and angry? ... And guess what happens when there's too many of us?

      A "tell them what they want to hear" cynical billionaire exploits their desperation and once again makes them once again vote against their own interests to perpetuate the aristocracy and increase the redistribution of wealth to the aristocracy.

    11. Re:Just keep voting for the establishment by Khashishi · · Score: 1

      Trump wasn't exactly the establishment.

    12. Re:Just keep voting for the establishment by jay+age · · Score: 1

      Try living in Europe.

      Our politicians may have an annoying habit of criticizing US while copying some of the wrong moves, but it's still way more social over here.

      Starting with 5 weeks of vacation (that you're urged to take), and continuing with social and medical security that actually deserve their names.

  20. Re:Why should we expect open source to be any bett by Excelcia · · Score: 5, Insightful

    Some code hasn't been looked at in a long time. Correct. There could be back doors. Correct. There could be vulnerabilities (intentional or not). Correct.

    Every software project, open source included, will have vulnerabilities discovered. There will be scares and exploits of open source like any other software. But yes, you can expect open source to be better. Because:

    1) Very few major open source projects have any contributions that occur in a vacuum. Multiple eyes see every patch and for the most part, those multiple eyes are most often from people in multiple organizations with multiple day jobs and multiple personal goals/agendas. Aligning enough people's agendas to get a back door in would be difficult for any major open source project. Intentional vulnerabilities would be easier, but still not trivial. This isn't 20 years ago, people actively look at each patch with an eye towards whether it is introducing a vulnerability. This model is diametrically opposite of any closed source offering, where contributions are by one organization and at the sole control of whomever holds the purse strings.

    2) If a vulnerability is suspected anywhere, you (and literally everyone else on the planet) have the option and ability to examine the source at any time. When you do want to investigate any particular piece of open source software, you don't need to decompile or reverse engineer something to do it. You don't have to fight the software in order to test it.

    There have been (and will continue to be) vulnerabilities exposed from older open source code written when there was less oversight and less strenuous security testing, but if you want to compare this to the number of exploits (and in some cases intentional back doors) that have come to light in, say, Windows, from ancient code that has thunked it's way down from Windows 3.1, the score isn't even close. And it's not like Microsoft is performing strenuous reviews of their old code - these vulnerabilities have come to light often only from outside researchers performing painstaking and arduous external testing and reverse engineering.

    So while you are correct in that open source will never be free of bugs or exploits - it's still written by people, as much as the nut jobs still decry that hard AI is just around the corner. But yes, in this it is just plain better than closed source.

  21. Want to kill technology? This is how. by SilverBlade2k · · Score: 1

    No tech company would put in a back door.

    Any that does is basically saying "Don't buy our product" because, as soon as they do, GUESS WHAT..people won't buy it.

    Look at what happened to Microsoft after the news about PRISM. Microsoft tried to make the camera a 'requirement' for all X-Box One games until a massive backlash happened. Microsoft backtracked and it basically killed the X-Box camera for gaming outside of a short list.

    People won't buy a product with a built in back door. Companies won't make a product that people won't buy.

    1. Re:Want to kill technology? This is how. by gweihir · · Score: 4, Informative

      No tech company would put in a back door.

      Well, CISCO did.

      Any that does is basically saying "Don't buy our product" because, as soon as they do, GUESS WHAT..people won't buy it.

      Cisco did that too. And Intel is currently trying to do this as well.

      Look at what happened to Microsoft after the news about PRISM. Microsoft tried to make the camera a 'requirement' for all X-Box One games until a massive backlash happened. Microsoft backtracked and it basically killed the X-Box camera for gaming outside of a short list.

      People won't buy a product with a built in back door. Companies won't make a product that people won't buy.

      Yes, but only if they get think they will get caught. As any other criminal-minded entity, they of course assume they will not get caught...

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    2. Re: Want to kill technology? This is how. by Reverend+Green · · Score: 1

      Hi,

      I represent the real estate agency T. Ermite & Mould, and I have a special offer just for you! Have you ever considered purchasing oceanfront property in scenic Phoenix, Arizona? Call now, we can't wait to speak with you!

  22. Re: Why should we expect open source to be any bet by Anonymous Coward · · Score: 1

    I never said open source was more secure. The article is about the US coercing companies to build in backdoors. The US has their exploits in open source as well but their method of obtaining them is different. The method is crucial to the justice system. I am ok with law enforcement getting a warrant and breaking my front door down. I am not ok with them enforcing no locks on any doors because it makes their job easier. When private US companies are forced to build backdoors it puts everyone at risk. Also when backdoors and security holes are independently found on open source software they can be patched. This is not the case with built in, custom order, spyware disguised as a feature the public wanted.

  23. Re:Greetings from the Ku Klux Klan by Anonymous Coward · · Score: 0

    And you were doing so well until you brought up religion...

  24. Cannot choose the government by SuperKendall · · Score: 1

    You can choose politicians, but by and large the party division is a sham and the "real" government marches on regardless. Witness how many federal government departments shut down under Trump: 0

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
    1. Re:Cannot choose the government by thomst · · Score: 3, Insightful

      SuperKendall blathered:

      You can choose politicians, but by and large the party division is a sham and the "real" government marches on regardless. Witness how many federal government departments shut down under Trump: 0

      What utter, driveling bullTrump.

      Republicans are trying to impose tax "reform" that will benefit the rich and giant corporations at the expense of the poor and middle-class, and small businesses. Every Democrat in the Senate voted against their version, and almost every Democrat in the House voted against their even worse version. The Republican-led FCC is hellbent on repealing the net neutrality rules the Democrat-led version enacted. The Republican president is about to move the U.S. consulate in Israel from Tel Aviv to Jerusalem, which will further inflame anti-U.S. tensions in the region (and is guaranteed to spark a global wave of new terror attacks against U.S. citizens, as well as increase the number of fresh recruits for Daesh, et alia). The Republican-dominated Supreme Court has struck down every attempt Congress has made at campaign finance reform, and has granted corporations free reign to spend as much money as they choose to influence U.S. elections. The Republican head of the Department of Justice is determined to revive the incredibly wasteful and counterproductive "war on drugs" at the exact time that the de-criminalization/legalization of marijuana has gained majority support among voters of both parties. The Republican-led EPA is doing everything in its power to roll back the Clean Air and Clean Water acts (that were enacted under a Republican president).

      The list just goes on and on.

      "There's no difference between the two major parties" is an outright, boldfaced lie perpetrated by Republican spinmeisters in what has been a remarkably successful, concerted, long-term campaign to persuade prospective Democratic voters to stay away from the polls - while the Republican base reliably turns out to vote against its own best interests (because "conservative values").

      Benjamin Disreali noted, "There are three kinds of lie: lies, damned lies, and statistics." Well, "there's no difference between the two major parties," is a damned lie - and you are a damned liar ...

      --
      Check out my novel.
    2. Re:Cannot choose the government by SuperKendall · · Score: 2, Insightful

      Republicans are trying to impose tax "reform" that will... ...change almost nothing in reality.

      You claim to be Woke, but you have yet to Wake.

      --
      "There is more worth loving than we have strength to love." - Brian Jay Stanley
    3. Re:Cannot choose the government by Anonymous Coward · · Score: 1

      SuperKendall was right. You might not like to hear it, but something you may not have realized is that a politician can vote against a measure they want to pass because they need political cover *and they know it will pass anyway*.

      The other thing you miss is that the fight for "control" over the senate or house or presidency is a struggle between the *parties* and not the public. That is why the democrats (and republicans when the dems are in power) need the political cover of voting against measures that they actually want. It keeps the public distracted and confused because simpletons think that just because a politician voted against a bill that the politician actually opposed it.

      American democracy is a system whereby the mice vote to choose whether they are eaten by tabbies or calicos.

    4. Re:Cannot choose the government by DNS-and-BIND · · Score: 1

      You've got it backwards - "both parties are the same and there is no measurable difference between them" is the rationalization trotted out whenever the Democrats do something vile. When Republicans do something vile it is because of their inherent vile nature. Please get your narratives straight. "Both parties are the same" is a defense of Democrats, not an attack on Republicans.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    5. Re:Cannot choose the government by aliquis · · Score: 1

      You can choose politicians

      Actually I really can't.

      Here in Sweden we have a 4% border for parties so to get someone new in 4+% of the voters must support that meaning it would be far harder to get someone in than just giving that person 1/349 of the votes to get one place in the parliament.

      Also for the established parties while theoretically you are allowed to vote for a candidate if you don't like their own choices they do lock down their name lists meaning you can't vote for someone they haven't chosen that you can vote for (and even if it was allowed and you did of course enough people would have to to get that person on top of someone. I don't know if a vote without crossing a specific candidate count as a vote on the top one on the list or just on no-one specific.

      Also even if we vote for parties they together form their government and our government is usually not single majority party or a combination of the two largest parties (or even better that we skipped having a government whatsoever and let whole parliament vote, or better yet the actual people rather than having representatives, or better yet abandoned collective rule to liberate all individuals to rule themselves) meaning the parties themselves actually decide who will be the government and the government will likely be a group of parties which think similar rather than a group representing the majority of the people or one having a distribution like what the people voted on.

      Also in Sweden after the last election in the "December agreement" in 2014 because they didn't liked the influence of the Sweden democrats in the parliament they agreed that the largest block would be allowed to rule and get a budget through and the other block wouldn't vote on their own one risking the Sweden democrats also supported that, thereby setting up a scenario where the votes on the Sweden democrats didn't matter and the parliament was just like if only the other parties existed. Similarly when they are discussing various issues the Sweden democrats isn't allowed to participate.
      That agreement finally was publicly ended because it could make people feel they aren't living in a democracy! Which we aren't.
      But like even now when the more socialist people wanted to raise the tax rate on the investment savings account the people who are more against taxes and I guess wouldn't propose that themselves rather than vote no which the Sweden democrats did they simply abstained and hence it passed meaning our actual minority government got things their way even though I assume the majority of the parliament would actually be against it but since the Sweden democrats doesn't count in the democrature of Sweden they pretended the majority was for it and there was nothing which could be done so it was passed.

      So yeah. Our constitution may say that the government is our representatives and that all power comes from the people. But it's not the people who decide. The people are just tools to validate their own authority.
      Sweden is ruled from above and the people are lectured and taught what to think, vote and do. Not the other way around.

    6. Re:Cannot choose the government by Anonymous Coward · · Score: 0

      "There's no difference between the two major parties" is an outright, boldfaced lie perpetrated by Republican spinmeisters in what has been a remarkably successful, concerted, long-term campaign to persuade prospective Democratic voters to stay away from the polls - while the Republican base reliably turns out to vote against its own best interests (because "conservative values").

      There absolutely is a difference between the two parties: the Republicans are the old established corruption, the Democrats are the new corruption (though not that new any more). The words we put before "corruption" are the difference.

      Not much difference in outcomes, however, from the point of view of the public. Claiming otherwise is just a divide-and-conquer tactic. Corrupt is corrupt: both groups have been caught over and over again.

      You can come up with long lists of things either party has screwed up, and claim it means they're better: it doesn't. The party faithful always have such lists, because they're completely delusional fanatics.

      Things like tort reform (and other types of legal ethics reform, long overdue and a huge burden on society) would have happened a long time ago if it wasn't for corruption in BOTH parties - the Republicians have a vested interest in not changing the status quo (strong brain dead conservative influence, conservatives don't want change), the Democrats take huge campaign contributions from associations of legal professionals and thus do nothing (strong brain dead liberal influence, too dumb or delusional to figure out what's really going on) .

      Rational people would like to see both groups exported to Mars, one way tickets only.

  25. The real question by seven+of+five · · Score: 1

    The tech companies need to ask the feds if they want a modern internet with secure banking and communications. Cause if they DO, the whole "backdoor" nonsense is a nonstarter. If you compromise a mathematically-proven and trusted system, guess what? No one can trust it anymore. On the other hand, if the feds really don't care if there's secure online communications or not, then hey, no problem.

    What we seem to have are people who keep asking for the impossible without understanding what's really at stake.

    1. Re:The real question by Anonymous Coward · · Score: 0

      I like your narrative, but I think it's naive. Beyond that it doesn't seem like a grand idea to me to put your entire banking system at the mercy of math and other complexity that may prove fallable. I don't think your argument is effective at persuading the people it overtly targets. They really do imagine they will be quite happy with their backdoors. I tend to suspect the effective difference between here and there is already negligable. Snowden, etc.

  26. Just tell me who does by oldgraybeard · · Score: 1

    and I will adapt!

  27. This contradicts supreme court precedent by Anonymous Coward · · Score: 0

    They can make that argument, but they'd be wrong. Does nobody recall the Apple case and the one before that Apple relied on recently in its refusal to build a backdoor for the government? It boils down to this. The government can't compel a company to build it anything. The US isn't like Germany or other countries where courts have been able to force backdoors even into anonymous open source Tor-like homegrown anonymity network software.

    This is also why the copy"right" industry will fail at forcing companies to implement censorship filters unlike its successes elsewhere. Essentially what it boils down to is that ISPs are not required to build censorship filters nor have they. So long as an ISP does not take the initiative to do so on its own a company can't be ordered to censor a web site or list thereof. In other countries like Canada and the UK there are either "voluntary" (created via threat of legislation forcing it) censorship filters or mandatory ones. The basis for these censorship filters and remains a threat and danger to this day was child porn. The UK doesn't just censor child porn and Canada is quickly becoming censorship happy too. Other seemingly modern countries have been found to be censoring political speech.

  28. Rage quit, table flip by Anonymous Coward · · Score: 0

    This shit makes me so fking angry. Privacy is dead, and has been for a long time. They really need to stop flogging this dead horse.

    Encryption has made their job harder, boo effing hoo. Sounds like they need to just get better at their job and leave shit alone.

  29. Re:Greetings from the Ku Klux Klan by Anonymous Coward · · Score: 0

    He lost me at slashdot.

  30. Oh they can "request" all they want. by Chas · · Score: 1

    I'm sure it'll be VASTLY entertaining when they get told to pound sand.

    The second it's been found out one of these companies has compromised their encryption this way, it's The End for them.

    --


    Chas - The one, the only.
    THANK GOD!!!
  31. Well, seeing as you claim to be American: by Anonymous Coward · · Score: 0

    Despite all the corruption and crime in DC, you are probably far better off in terms of health and wealth in your life than what you would end up with, had you had to deal with a much more likely scenario.

    Consider what you have in terms of hot and cold running water, heating, air conditioning, Internet, travel by car (or public transportation in your area, if that's your thing), health care, medication, and readily available food. Consider also, by comparison, the life you'd have, were you born into a wealthy or royal family about 3-400 years or so ago. Also, by way of comparison, consider the sort of life which is to be expected in some place like North Korea. Would you be so upset with what you have if your alternative is what people these days are getting under the rule of Kim Jong Un?

    1. Re:Well, seeing as you claim to be American: by Howitzer86 · · Score: 0, Troll

      North Korea? The Colonial Period? Why not compare your penis to a vagina while you're at it?

      America was built by dissatisfied people who knew they could do better. We should keep complaining. We can leave complacency to the denizens of former empires and modern dictatorships.

    2. Re:Well, seeing as you claim to be American: by jalet · · Score: 1

      Would you be so upset with what you have if your alternative is what people these days are getting under the rule of Kim Jong Un?

      It will be far worse for them when Kim Jong Deux will seize power !

      (sorry, french joke, I couldn't resist)

      --
      Votez ecolo : Chiez dans l'urne !
    3. Re:Well, seeing as you claim to be American: by Opportunist · · Score: 1

      Personally, I am not upset with what I have when I look at what the US is like.

      Greetings, Europe.

      P.S.: If you keep looking down for something to compare yourself to, you'll not improve. Look up to know what to aspire to.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    4. Re:Well, seeing as you claim to be American: by Wootery · · Score: 1
    5. Re:Well, seeing as you claim to be American: by Anonymous Coward · · Score: 0

      Well, that was the realistic perspective. If you were paying attention, you might have noticed that no attempt whatsoever was made to justify criminal conduct in high places.

      The very unrealistic perspective is that of people who enjoy a life of peace and prosperity in a stable Western Nation whining about how "The Man" is holding them down or about how "The People" ought to take it upon themselves to start righting the perceived wrongs (with a "by any means necessary" either stated explicitly or implied by the rhetoric). And, if you're proposing to attempt a rebellion, then you'd be talking about a situation which "somehow" tends to do more to bring about destruction and chaos than it tends to initiate Utopia (In addition to "mysteriously" giving lots of power to dictators - either someone who assumes power under the established system, or to whoever ends up leading the rebels).

  32. You know what I find funny ? by aepervius · · Score: 1

    People were comparing germany to stasi and worst here :
    https://yro.slashdot.org/story...

    Note that this article is from a local unknown journal, with NOBODY confirming what it pretend is happening, to my knowledge not even the local CCC knows about it, and at least if it tries to put it as law there will be a PUBLIC DEBATE, and this is the Germany, not the US, people tend to really debate such things.

    And here were have the US saying "fuck that we have above the law we can stamp you with FISC to have you add a backdoor" Bypassing the judicial , not even needing law , bypassing check and balance. And the reaction is.... Mutted, far less vitriolic. Fancy that.

    --
    C. Sagan : A demon haunted world:
    http://www.amazon.com/gp/product/0345409469/
    visit randi.org
    1. Re:You know what I find funny ? by Opportunist · · Score: 2

      It's a bit like if the US went and shot a person in public vs. North Korea doing it. In the US it would be an outrage. In NK, well, we kinda expect that by now.

      Same here. Domestic spying, privacy elimination, trying to establish a Fascist regime... that's something we had come to expect from the US, hearing this from Germany is so odd and unfathomable.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  33. Re:Why should we expect open source to be any bett by Plus1Entropy · · Score: 2

    What the Shellshock and Heartbleed bugs have proven is exactly the opposite of what you are saying. If they occurred in closed source software they would have never been found. Or they may be found but kept secret because it cost money to fix. Or they may be found but only the "currently supported" versions are patched, and people with old versions are just told to fork out more money to upgrade.

    The name of the game is not there will never be vulnerabilities in the code. The name of the game is whether those vulnerabilities will be found by good people before they are found by bad people. Since good people outnumber bad people, the more people in general who can look at the code the better the chances are that a good person finds the problem first.

    Shellshock, for example, was known by nobody (effectively) until it was discovered, patched, and reported. It was only then that a bunch of bad people started to try to exploit it.

    --
    Only crack the nuts that crack. You don't put the ones that don't crack in the sack.
  34. Re:boil it down: End of Internet Connections by BoRegardless · · Score: 1

    A lot of computer owners would probably wind up keeping certain computers completely off any network connected to the Internet if the government had the ability to force the of use backdoors.

    That would be worse for the value of the Internet than anything else I can think of.

  35. Microsoft and the FBI? by Anonymous Coward · · Score: 2, Informative

    Except they don't say no, remember Microsoft? Keen to get lots of surveillance contracts bent over backwards to give them disk encryption keys.

    https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-collaboration-user-data

    " Microsoft helped the NSA to circumvent its encryption to address concerns that the agency would be unable to intercept web chats on the new Outlook.com portal; The agency already had pre-encryption stage access to email on Outlook.com, including Hotmail; The company worked with the FBI this year to allow the NSA easier access via Prism to its cloud storage service SkyDrive, which now has more than 250 million users worldwide; Microsoft also worked with the FBI's Data Intercept Unit to "understand" potential issues with a feature in Outlook.com that allows users to create email aliases;"

    Blackberry? Remember their CTO's meeting with law enforcement to tout their cooperation?

    Can I point out something that people don't seem to connect in the current shock reveal. Erik Prince of Blackwater proposed to Trump to form a hit squad/propaganda/plumbers unit loyal to Trump and Trump alone funded privately to overcome 'deep state' legal resistance. Erick Prince also admitted to meeting Kirill Dmitriev, head of the Russian Direct Investment Fund, when he was a Trump team advisor. So who do they think would fund and run these mercenaries loyal to Trump?... It's really no different to the hacking squad that backed Trump, it would be run in the same way.

    1. Re:Microsoft and the FBI? by david_thornley · · Score: 1

      Microsoft doesn't have to care. Lots of people use Microsoft products because it's what's there. Microsoft - it's not just good, it's just good enough.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  36. Have you even been paying attention? by Anonymous Coward · · Score: 0

    Microsoft tried to push this as Palladium.

    The British by way of ARM got the foundation implemented for arm... 12-15 years ago. A similiar featureset was offered prior to that via the BREW signed Java app support cell phones had been using since the late 90s. Intel followed by implementing it in the Q35/Q45 chipsets along with IOMMU support, working out the kinks in a couple buggy hardware revisions. They got it right with Sandy Bridge, but it still wasn't enough. AMD got pressured during this period, but thanks to their marketshare being crippled by Intel weren't forced into implementing it until their next major model revision, which turned out to be the FM2 chip generation, when the first of the arm trustzone cores went in. They didn't work right until FM2+ when they were actually enabled. Following that they ended up in EVERY AMD processor, obstensibly to help with power management, but really to allow backdoor access. Now not even that is enough and the same is happening to our GPUs. First NVidia's signing of their firmware, and now AMD's implementation of PSP on the AMD Vega series GPUs.

    Combined with cell phones, literally every computer device less than 10 years old is DEFINITELY backdoored. They might not be doing anything now, but the provisions are there and they are just waiting for the 'probable cause' that will allow them to use it without the citizenry trying to fight back, and having hardware that is still secure.

    We are fast approaching the point of no return and too much of the populace is too narrowsighted, naive, uneducated, or just plain stupid to notice, put the pieces together, and learn to take the parables of history and overlay them with modern technology to understand the full brunt of the dangers being posed by these sorts of backdoors, not only to our immediate digital security, but also to our future mental, physical, and social freedom. Liberty is dead, long live Big Brother. Big Brother will protect you from all dangers, even those inside your own head!

  37. I2PD just got hit by this. by Anonymous Coward · · Score: 1

    A heartbleed-esque attack due to both keys and the packet buffer going on the heap. I don't get all the specific details, but it could convince the remote server to barf an arbitrary size packet back to it including whatever was currently on the stack.

    This is a project that has been around for 3+ years and has been claimed secure by its developers. Either the developers are inept, it was a genuine mistake, or it was malicious.

    Regardless of which it was, it has potentially compromised hundreds to thousands of nodes in the i2p network, as well as every service running on them. Even worse i2pd is mostly russian developers and commonly used among privacy oriented russians trying to stay off state surveillance. If this has been exploited in the wild (which would only be discovered through log correlation with full packet logging on a targetted honeypot system), it means that potentially thousands of russians can now be directly targetted by their government, and that users of any of their services could be connected to compromised hidden services believing them to be verified and safe.

    All it takes with crypto is one wrong bug in a popularly used project and it can compromise the security of thousands to billions of users.

    https://eyalitkin.wordpress.co... 'GarlicRust' has full details for anyone interested.

  38. the cyber is insecure by Anonymous Coward · · Score: 0

    So while you are correct in that open source will never be free of bugs or exploits - it's still written by people, as much as the nut jobs still decry that hard AI is just around the corner. But yes, in this it is just plain better than closed source.

    'just plain better' is still just plain wrong despite your several good points. I can imagine people working for the CIA, knowing they have an organization intimately familiar with say, closed source Winblowz, and I'm sure they have way more confidence in their closed source option than I have in my FOSS option. Does that mean I'm going to switch to closed source Winblowz- even if somehow I could assume that assessment is the actual case- Hell NO, of course not :) In the end there is a larger factor you didn't focus on (enough)- the deployment/configuration/actual-use-case-and-individual-threat-model matters I would guesstimate far more than the open/closed source issue. Situational issues. Are you concerned that any breach of this com channel will result in your family being burned to death? Or is it a situation with a dramatically lesser worst-case scenario? I wish I could vouch for some FOSS project that I'd be confident enough in for the former. Presumably one of these days we will (decades too late) witness some sort of com-sec international sport where it's capture the flag, but the flags are hundreds of millions of dollars worth of bitcoins. When I see some FOSS configuration defending that kind of a flag for years, then maybe I'll consider it *really secure*. But there are so many vastly less critical scenarios, that while I'll still opt with FOSS, I'm not going to try to tell others that it's "just plain better than" winblowz. I'm sure if you've got a CIA/NSA friend telling you to run winblowz in some very specific way, in that situation that closed source is going to be 'just plain better' than any FOSS option anybody I know who isn't NSA/CIA connected will come up with. And of course, GPG/SFTP/onetimepads/blablabla.

  39. I replied similiarly in another thread... by Anonymous Coward · · Score: 0

    It's good to know others have seen this for what it was.

    The question now is: What can we do to return future secure systems to commercially available status?

  40. In other news. by dicobalt · · Score: 1

    US government is forcing encryption specialists to move out of the US by implementing draconian laws.

    1. Re:In other news. by Anonymous Coward · · Score: 0

      Since the US is ready, willing and able to impose its laws to the rest of the world, it doesn't really solve the issue. There are countries that openly defy the US, but would you really like to live there?

  41. Court Order Not Needed... by Anonymous Coward · · Score: 0

    ...if you installed Windows 10 Spyware Edition.

  42. Re:Why should we expect open source to be any bett by Kjella · · Score: 1

    I think the main difference is that in open source it'd take some extraordinary trick to create a backdoor or unofficial feature for any particular group or organization. Could you have Heartbleed-class bugs? Yes. But they're double edged swords, it could expose your enemies but unless you manage to roll out a massive, secret patch/firewall regime you'll be vulnerable too. How often does open source software secretly log data and send it off to a server in China? It just doesn't happen. Why is open-source DRM an oxymoron? Because you can't hide what it's doing. Which is not to say you can't have controversy about default software and settings, like Ubuntu's shopping lens but it's at a whole other level.

    And it doesn't take all that much effort to make a version that modifies the behavior, quite probably there's already a fork or patch for you. Because even when or if I find out that Windows or macOS is doing something I don't really approve of it's very hard to do something about it, you can turn off settings which they turn back on, you can block it at the firewall and they change ports and servers, you can use third party hacks that may or may not work well but compared to open source it's a black box. And turning off those features could also be hardening the software, it might not prevent bugs but reduces your attack surface and information leaks.

    --
    Live today, because you never know what tomorrow brings
  43. You can have both... by Anonymous Coward · · Score: 0

    Just not in any existing country.

    You would think with all those 'Sovereign Person' kooks in the US, a few of them would be willing to formally renounce their citizenship and do what is necessary to establish a new state.

    But no. Because Sovereign People, like libertarians and a host of other ideological groups, are too big of chickenshits to even take the risks the colonial revolutionary army did to ensure they have the sort of liberties their forefathers pined for, but never recieved, even after founding their glorious new nation. And that folks is why the world today is only getting worst. Because nobody has bothered to learn from the past the changes necessary to avoid reliving the past.

  44. restricting crypto by Anonymous Coward · · Score: 2, Interesting

    It's usually not argued nearly that seriously. What CEO or corporation would argue with a government willingly knowing that the end result is going to be a cessation of government contracts, barring from export, and anything else the government has that they can legally do that are in there powers?

    Export of what exactly?

    For hardware, most things are made outside of the US, so they're actually "imported" by American consumers.

    For software, you shift the crypto component offshore, and US customers "import" that component. OpenSSL (then SSLeay) actually began in Australia during the first 'Crypto War' of the 1990s to get around the US ITAR restrictions. Ditto for for OpenBSD: strong crypto coded in Canada. Debian had a "non-us" repo for strong crypto:

    * https://wiki.debian.org/non-US

    As did FreeBSD:

    * https://svnweb.freebsd.org/base/head/crypto/

    People worked around the ITAR restrictions before, and while the infrastructure may be a bit stale, it can be brought back easily enough.

    We've been through this before.

  45. So F*** you Human Rights by Anonymous Coward · · Score: 0

    http://www.un.org/en/universal-declaration-human-rights/

    Article 12.

    No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.

    Article 28.

    Everyone is entitled to a social and international order in which the rights and freedoms set forth in this Declaration can be fully realized.

    Article 30.

    Nothing in this Declaration may be interpreted as implying for any State, group or person any right to engage in any activity or to perform any act aimed at the destruction of any of the rights and freedoms set forth herein.

    VIENNA CONVENTION
    https://treaties.un.org/doc/publication/unts/volume%201155/volume-1155-i-18232-english.pdf

    SECTION 3. INTERPRETATION OF TREATIES
    Article 31, GENERAL RULE OF INTERPRETATION
    1. A treaty shall be interpreted in good faith in accordance with the ordinary
    meaning to be given to the terms of the treaty in their context and in the light of its
    object and purpose.

  46. And US companies become untrusted internationally? by Midnight+Thunder · · Score: 1

    There was all this hand waving about the Chinese and Russians having backdoors to stuff sold in the US. How will the US having backdoors be any better, to any other government?

    If it is a question of backdoors, then you might as well have low grade encryption, since it is probably not much better than the master key getting leaked?

    --
    Jumpstart the tartan drive.
  47. Submitter and editor think this is newsworth? by Anonymous Coward · · Score: 0

    Why the fuck was this even promoted?
    Are they surprised that the government can ask companies to do things?

  48. Ha ha, land of the free! by Anonymous Coward · · Score: 0

    What a fucking shitpile. Get out while you can. Learn not-English and emmigrate before you're trapped in the prison.

  49. Re: Too late for what? by Anonymous Coward · · Score: 0

    A bunch of delusional gun nuts to all die by Predator Drone strikes?

    You cunts aint winning against your gubmints superior arms.

  50. Hackdoor software by Neuronwelder · · Score: 1

    How much of an idiot do they think I am. Anyone would know that someone, somewhere, is going to exploit, and hack into that backdoor they created. So I need a list of idiot software to avoid.

  51. give them all your data by layabout · · Score: 1

    and I mean *ALL*. every bit of VPN and encrypted data you generate should be sent to the FBI so they won't have to work so hard to collect what they want. I'm sure they have enough storage and bandwidth to handle it.

  52. Re:Why should we expect open source to be any bett by Anonymous Coward · · Score: 0

    I think the main difference is that in open source it'd take some extraordinary trick to create a backdoor or unofficial feature for any particular group or organization.

    No it does not.
    All it takes is for the malicious individual to have slightly more skill than the evaluators of the specific function they added a vulnerability to.
    Given how "thorough" open source code review is, a patient hostile actor will be able to get any vulnerability into the accept code of any project, the only issue is patience. In most cases, it doesn't require great coding skill, just the normal social-hacks that covert operatives are primarily trained in. Submit minor useful code changes while watching the bug tracker, fix one of the older bugs and see how the crowd responds. Mess up a fix on another old bug and see how the crowd responds. Just a few pokes to see what it takes to add truly malicious code.

  53. What happened to the 4th Amendment? by Anonymous Coward · · Score: 0

    The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.

    Certainly the modern definition of 'papers' extends to our data stored on remote servers and 'home' extends to the access of that data.

    1. Re:What happened to the 4th Amendment? by Agripa · · Score: 1

      The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.

      Certainly the modern definition of 'papers' extends to our data stored on remote servers and 'home' extends to the access of that data.

      That only extends to persons, houses, papers, and effects which existed at the time it was ratified.

  54. Sure. They can ask. by Anonymous Coward · · Score: 0

    Sure. They can ask. I don't mind.

    I asked my father to take the RV to prom too. He never answered.
    I asked to take the Lincoln to prom. He shook his head no.
    I asked to take the rabbit, he saw he would need to think about it.

    A week before prom, he said yes to the rabbit.

    If a company volunteers to break into a phone, THEN I have an issue.

    I think that strong, unbreakable, encryption is a human right. Clearly, many governments (including mine) don't agree. That just means that using only encryption provided to the masses isn't for me. Additional steps are needed.

    I just wish more people weren't so trusting and understood that 1 tiny bug is all that is necessary for any encryption system to be broken. There are probably 100+ bugs on any system, at least.

  55. So much for "SECURE" sockets layer... apk by Anonymous Coward · · Score: 0

    See my subject & WHY I posted THIS https://it.slashdot.org/comments.pl?sid=11433711&cid=55673813/ a few days ago...

    * Unbelievable!

    APK

    P.S.=> TheRaven64 made a HELL OF A GOOD POINT too https://yro.slashdot.org/comments.pl?sid=11443809&cid=55686303/ ... apk

    1. Re:So much for "SECURE" sockets layer... apk by Anonymous Coward · · Score: 0

      Ahhh, that feeling when you down mod everything this dumb fat troll cunt posts!

  56. Mod TheRaven64 up to +5... apk by Anonymous Coward · · Score: 0

    Mod TheRaven64 up to +5 (he's right) & I thought I'd mention it in my reply too (good job TheRaven64) https://yro.slashdot.org/comments.pl?sid=11443809&cid=55687683/

    APK

    P.S.=> So much for "SECURE" sockets layer... apk

  57. That's why I said right wing by rsilvergun · · Score: 1

    Instead of Republican. Obama was very much center right. What's needed is left wing politics. Single payer healthcare, infrastructure spending, progressive taxes, college paid for by the public, ending our 8 wars (yes, we're at war in 8 different countries all under the same authorizations Congress have for Iraq) . We need left wing action, not just left wing rhetoric.

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
    1. Re:That's why I said right wing by Anonymous Coward · · Score: 0

      I feel your pain. And if you look over history you will see that class warfare never ends well for some portion of the elite, but somehow they keep soldiering on.

      You could try and take cold comfort in knowing that the uber wealthy take out expensive insurance so that they can be flown outside of the US on emergency basis when the inevitable bloodshed starts. Yes, they are well aware of how things will play out, but their greed is too strong to give up a single red cent.

  58. Why is this still an issue? by harrkev · · Score: 1

    Seriously, why is this an issue?

    Public/private key cryptography has been proven secure. HTTPS is based on it, and it is strong enough for me to do banking on-line.

    For cases like the police needing to get into an iPhone, all that needs to be done is to take the phone secret (say, an AES key or the phone unlock code) could be encrypted using Apple's public key, and this encrypted secret could be made public (or presented over the USB port). Nobody can do anything with it, except the people who hold the private key (the manufacturer).

    Law enforcement can turn over a warrant and the manufacturer can decrypt the secret key, and turn it back over to law enforcement. The government still needs to present a warrant, it is secure, and everybody should be happy.

    Have I missed something?

    --
    "-1 Troll" is the apparently the same as "-1 I disagree with you."
    1. Re:Why is this still an issue? by JesseMcDonald · · Score: 2

      Have I missed something?

      Several things, actually. First, your scheme requires the ability to export the private key from the device (even if it is encrypted). This is poor security practice. The current trend—long overdue, and implemented in response to real security breaches—is to generate and store the private key in a tamper-resistant secure chip, with no external access to the key material. All operations involving the key occur inside the chip. This protects against vulnerabilities in the operating system as well as physical tampering.

      Second, why should the manufacturer have the ability to decrypt the user's data? Again, poor security practice. The manufacturer should not be considered a trusted party, beyond device itself as it was originally delivered and later software updates accepted by the owner and installed while the device is unlocked.

      Third, the private key on the device is generally only part of the information needed to decrypt the contents; you also need the user's password. Even assuming you could get the private key from a locked device, if the user chose a secure password (as opposed to a PIN you could easily brute-force) then the device key won't do you any good. Storing the combined key would, of course, be very poor security practice, even wrapped in some form of encryption.

      Fourth, the manufacturer's private key will eventually leak. Their backdoor access is a single point of failure, and a very tempting target for hackers and foreign governments alike. The manufacturer does not have nearly as much incentive to secure their backdoor as all of the end-users combined have to secure their individual devices.

      Fifth, the manufacturer cannot be trusted to represent the owner's interests by requiring a legally-sound warrant before exercising their backdoor. They can be coerced or bribed into complying "voluntarily", without a warrant—the subject of this very article—and they have no incentive to fight dubious warrants which have a chance of being overturned since it's not their data, the effort required to comply would be trivial, and they have the cover of a "legal" order (however threadbare) to protect them against any public backlash.

      --
      "The state is that great fiction by which everyone tries to live at the expense of everyone else." - Bastiat
    2. Re:Why is this still an issue? by harrkev · · Score: 1

      You missed a couple of things...

      First, your scheme requires the ability to export the private key from the device (even if it is encrypted). This is poor security practice.

      Why? If RSA and/or ECC are really "uncrackable", and is mathematically proven so, I fail to see the problem.

      generate and store the private key in a tamper-resistant secure chip

      Absolutely true. However, it has to be tamper-resistant because this chip stores PLAIN-TEXT KEYS. If they keys are stored encrypted, the the key encryption key has to be stored in pain-text. These chips often have limited memory, so you can off-load secrets from the crypto chip into the host, but this key is encrypted using a chip-specific key. What you call "poor security practice" is baked into the TPM spec.

      Second, why should the manufacturer have the ability to decrypt the user's data?

      OK. You have a point here. However, if you accept the postulate that somebody with a warrant signed by a judge has the right to break into your stuff, then you have to trust SOMEBODY. Maybe not the manufacturer, but a private company with a staff of lawyers to protect the rights of the customers.

      On the other hand, if you don't accept that postulate, then you probably trust nobody. I, for one, would like to help law enforcement if possible, provided that they can get a warrant. I would not trust them with the keys, but would be OK with having somebody else decrypt my info as long as my legal rights are respected.

      Fourth, the manufacturer's private key will eventually leak.

      Hmmm. There are a several companies that make a living issuing certificates that have managed to keep their private keys secret. There is already an ecosystem around this problem Why would this one use case be any different?

      Fifth, the manufacturer cannot be trusted to represent the owner's interests by requiring a legally-sound warrant before exercising their backdoor

      This is closely related to your second point. However, I could imagine that not protecting the customer's privacy would result in some backlash against the company, as it should be. Transparency would be the problem here. Once again, maybe have a trusted 3rd party be the key holder. Maybe some organization like the EFF could have the key-holder and charge the police $1,000 to decrypt the data.

      --
      "-1 Troll" is the apparently the same as "-1 I disagree with you."
    3. Re:Why is this still an issue? by david_thornley · · Score: 1

      If the private key can be exported from the chip, how unbreakable the asymmetric cipher system doesn't matter. Anyone who can get the private key will be able to read the ciphertext. That's the point of a key. Crypto is designed to make it hard to read something without the key, not with. Unless you're saying that the crypto is complete crap in the first place.

      I'd respond to your second paragraph if I knew what you were saying. It seems irrelevant to your arguments.

      A warrant gives law enforcement the authority to look at what they want. It does not mean they are guaranteed to understand what they find, and it never has. I'd assume that law enforcement has run into enciphered papers now and then, so this isn't new. I don't personally care what you want law enforcement to do with your phone, since you seem determined to destroy the security on mine. You suggest a way to do something without weakening my security and I'll consider it.

      The key would be a very valuable thing for state-sponsored crackers to get. I don't know that the EFF is capable of securing the key while still making it usable. As long as nobody can get my iPhone key, there is no such target.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    4. Re:Why is this still an issue? by harrkev · · Score: 1

      The private key is encrypted with a trusted party's public key. That is how encryption works. Play with the MBED-TLS library for a while to get a feel of things.

      I, for one, want a world where law enforcement can put criminals away -- even if the criminals use encryption. I don't want to "destroy security." Security involved keeping the bad guys away from your data. If you define the police as "bad guys" then that is a matter of semantics.

      As far as who keeps the keys, as I said, certificate organizations manage the run their entire business around keeping their private key private. Every organization that has an "https" web page has a private key that they somehow manage. You act as if this type of thing has never happened before. A state-sponsored cracker could also wreck economies if they could somehow get into banks, the stock market, etc. How is this any different, except that there is not billions of dollars at stake?

      --
      "-1 Troll" is the apparently the same as "-1 I disagree with you."
    5. Re:Why is this still an issue? by JesseMcDonald · · Score: 1

      First, your scheme requires the ability to export the private key from the device (even if it is encrypted). This is poor security practice.

      Why? If RSA and/or ECC are really "uncrackable", and is mathematically proven so, I fail to see the problem.

      First, there is no system other than the one-time pad (which is not a public-key cryptosystem and thus not applicable here) which is mathematically proven to be "uncrackable". Public-key cryptography depends on problems which are believed to be hard to solve, but it could be that there is a solution which simply hasn't been discovered yet.

      Second, even assuming that the encryption is "uncrackable", the security of the manufacturer's private key and the process meant to ensure that it is only used in response to a lawful warrant are both much weaker targets than the encryption algorithm. As the saying goes, two people can keep a secret—provided that one of them is dead. A key which only the device has access to is inherently more secure than one which is meant to be accessible to both the device and the manufacturer (or the owner or anyone else).

      If they keys are stored encrypted, the the key encryption key has to be stored in pain-text. These chips often have limited memory, so you can off-load secrets from the crypto chip into the host, but this key is encrypted using a chip-specific key. What you call "poor security practice" is baked into the TPM spec.

      Perhaps I over-simplified. The point is that the plain-text key only exists inside the tamper-resistant chip. While the encryption version can be stored outside the chip, it can't be decrypted anywhere else, not even by the owner of the device and certainly not by the manufacturer. This is entirely different from sending the encrypted key to a third party who has the ability to decrypt it.

      However, if you accept the postulate that somebody with a warrant signed by a judge has the right to break into your stuff, then you have to trust SOMEBODY.

      Assuming that they have probable cause to search the device, I accept that they have the right to seize it and try to break into it. I do not accept that they have any right to succeed, or to force anyone to help them do so, either before or after the fact.

      Maybe not the manufacturer, but a private company with a staff of lawyers to protect the rights of the customers.

      Moving the goalposts a bit, but OK. That resolves the issue of incentives and representation, so long as I get to pick the company (potentially myself), but the other objections still apply. No one has sufficient technical competence to protect the master key from falling into the wrong hands; that is why we have things like TPMs and HSMs and smartcards in the first place.

      As far as who keeps the keys, as I said, certificate organizations manage the run their entire business around keeping their private key private. Every organization that has an "https" web page has a private key that they somehow manage. You act as if this type of thing has never happened before.

      You act as if CAs have never had keys compromised, or abused their position of trust to issue false certificates (under duress or otherwise). Some organizations which have had exactly these problems are still around and allowed to issue keys trusted by all the major browsers. If anything, the CA system illustrates exactly why key escrow is a horrible idea.

      --
      "The state is that great fiction by which everyone tries to live at the expense of everyone else." - Bastiat
    6. Re:Why is this still an issue? by Agripa · · Score: 1

      Have I missed something?

      No, you have not missed anything. That is basically how Clipper worked.

    7. Re:Why is this still an issue? by harrkev · · Score: 1

      Public-key cryptography depends on problems which are believed to be hard to solve, but it could be that there is a solution which simply hasn't been discovered yet.

      And if it becomes possible to crack ECC or RSA keys economically, somebody getting your e-mails off of your phones is the least of society's problems. All economic transactions become practically impossible on the Internet.

      At some point, you have to trust the algorithms, because you ARE ALREADY TRUSTING THE ALGORITHMS TODAY. Even if YOU don't trust them, your bank does. The stock market does.

      In short, if ECC and/or RSA falls, all of society as we know it is screwed.

      You act as if CAs have never had keys compromised, or abused their position of trust to issue false certificates (under duress or otherwise). Some organizations which have had exactly these problems are still around and allowed to issue keys trusted by all the major browsers. If anything, the CA system illustrates exactly why key escrow is a horrible idea.

      You act as if all encryption is suddenly broken and not used anymore because it is useless. Hmmm. As I type this, I see "https" at the top of the URL bar. You do know that "certificate revocation" is a thing, right? Yes, some false certificates were issued. Do experts suddenly recommend that encrypted web traffic is a bad idea based on that information?

      Keep in mind that phones are devices that have their firmware in flash memory, not masked ROM. The firmware can be updated. New certificates can be loaded.

      To summarize, encryption can be applied to phones, the same techniques with are already being used billions of times a day to protect web traffic. I fail to see how a solution works well enough for everything else can suddenly become horrible when applied to a device that an attacker needs physical access to in order to compromise.

      --
      "-1 Troll" is the apparently the same as "-1 I disagree with you."
    8. Re:Why is this still an issue? by david_thornley · · Score: 1

      tl';dr: Gee, there are insecurities in the software world already. Therefore, it will make absolutely no difference if we create a nice new big one.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    9. Re:Why is this still an issue? by david_thornley · · Score: 1

      First, there is no system other than the one-time pad (which is not a public-key cryptosystem and thus not applicable here) which is mathematically proven to be "uncrackable".

      To expand on this, cryptosystems are in NP. If we're given the key and ciphertext, we can easily determine what the plaintext is. Therefore, until P=NP is settled, the absolute most we could prove is that a cryptosystem is NP-hard. That is not the same as proving it unbreakable.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    10. Re:Why is this still an issue? by harrkev · · Score: 1

      tl';dr: Even be biggest, baddest, most secure cryptographic algorithms are not powerful enough to protect my stash of porn.

      --
      "-1 Troll" is the apparently the same as "-1 I disagree with you."
  59. Unfortunately ... by Ihlosi · · Score: 1
    I'm sure they have enough storage and bandwidth to handle it.

    Unfortunately, the TLAs answer it ... "Just a second. Hold my beer."

  60. What happened to WE THE PEOPLE ? by mysidia · · Score: 1

    You in the XXX organization of government have no right to use official resources to ask third parties to do things that go against our interests.

    Congress hasn't passed an act directing you to "ask" companies to embed concealed defects into their products that you sell to the people, therefore, you doing so is an ABUSE.

    Now if your directors of departments want crypto backdoors in YOUR OWN GOODS that you buy for the use by that government department from those same companies, that's a different matter entirely; that's the ONLY kind of product design influence you should have on any private-sector individual or company.

    1. Re:What happened to WE THE PEOPLE ? by sl3xd · · Score: 1

      Well, the important thing to remember is that it's not about political parties: it's about power.

      A party is a means to that end, as is wealth.

      Power corrupts.

      --
      -- Sometimes you have to turn the lights off in order to see.
    2. Re:What happened to WE THE PEOPLE ? by Agripa · · Score: 1

      Congress hasn't passed an act directing you to "ask" companies to embed concealed defects into their products that you sell to the people, therefore, you doing so is an ABUSE.

      They seem to be arguing some other authority but congress did pass such an act:

      https://en.wikipedia.org/wiki/...

  61. Linux everyone? by Anonymous Coward · · Score: 0

    I should (hope) that the new Linux phones will be safe from back doors. One currently in development can be loaded with multiple Linux versions. Then, only an additional chip could back door a phone.

  62. Re:boil it down: End of Internet Connections by networkBoy · · Score: 1

    Already do.
    I have three networks at my house:
    * Internet connected (through IPFire and PiHole) LAN access (Wired/WiFi WPA2)
    * Internet connected (through IPFire and PiHole) WiFi open (NO LAN access) labeled GuestMonitoredConnection
    * Isolated. No Internet connection, different physical layer, no WiFi. Accessed through Bastion host that has IpKVM type connection to internal LAN. The bastion is able to RDP to all machines on isolated network, and it is connected to through use of a Raritan IPKvm on the LAN. The KVM is easily turned off to provide hard isolation if really needed.

    --
    whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
  63. Interception of private communications is a crime. by Anonymous Coward · · Score: 0

    That is why the court order is needed - not because anyone needs a court order to ask someone to intercept the communications, but because without the court order the person doing to the interception would be committing a crime. Actually, if the Feds asked someone to break encryption without a court order and that person complied then they should immediately arrest them. Choosing to follow an unlawful order and breaking the law does not absolve you of the crime. You might have a good duress defense but the crime still needs to be investigated. Law officers do not have responsibility of deciding the law, but do have the responsibility for enforcing all criminal laws equally.

  64. Re:Why should we expect open source to be any bett by Anonymous Coward · · Score: 0

    "The name of the game is whether those vulnerabilities will be found by good people before they are found by bad people. Since good people outnumber bad people, the more people in general who can look at the code the better the chances are that a good person finds the problem first."

    The incentives are disproportionate though. If a bad person finds a vulnerability they can make a lot of money, gather a lot of intelligence, etc. If a good person can find the vulnerability they can warn of the issue, maybe collecting some small bounty (or maybe getting sued/prosecuted for their trouble). Then you have situations were state-level bad guys collect exploits and write code to leverage them, and then those get hacked/leaked/etc. So I question the plausibility of your conclusion that it's more likely a good person will find them first than bad.

  65. "Fuck you, assholes." by Rick+Schumann · · Score: 1

    That's the only appropriate response to this. They can't 'force' anything. If they could, then the entire premise behind what the United States was founded on and ostensibly stands on becomes invalid.

    1. Re:"Fuck you, assholes." by Agripa · · Score: 1

      That's the only appropriate response to this. They can't 'force' anything. If they could, then the entire premise behind what the United States was founded on and ostensibly stands on becomes invalid.

      Force? Please. They call it mandatory voluntary cooperation now.

    2. Re:"Fuck you, assholes." by Rick+Schumann · · Score: 1

      Tell you what, friend: I don't want Civil War 2 in this country, but I'll tell you what precedent it'll take: armed forces, invading a targeted corporations offices sans warrant, literally putting guns to peoples heads to force them to 'comply', incarcerating people without charging them, denying them legal counsel, and so on. The first time that happens in this country is the last time we have Rule of Law and Government By The People For The People. Then there will be Civil War. And the rest of the world will likely fall with us. Hope, and pray to whatever god you believe in, that day never comes.

  66. Why I never started an encryption company. by Anonymous Coward · · Score: 0

    The government also doesn't need a court order to find ever so many ways to make your life miserable if you don't comply with their "request".

    There are many terrors in the night.

  67. Re:boil it down: End of Internet Connections by bagofbeans · · Score: 1

    So your hacker access point is the WPA2. Hope you have logs.

  68. Bitlocker by bagofbeans · · Score: 1

    Also bitlocker is 128 bit by default, and limited to 20 chars for the pw

  69. It's never illegal to "ask" by Anonymous Coward · · Score: 0

    They can "ask" all they want... doesn't mean they will receive compliance.

  70. Re:Why should we expect open source to be any bett by Plus1Entropy · · Score: 1

    So I question the plausibility of your conclusion that it's more likely a good person will find them first than bad.

    It's borne out by the historical evidence, especially the 2 examples cited by the GP. Many of the examples where exploits are known by bad guys for a long time are in closed source, e.g. the Windows exploits from the Shadow Broker releases that allowed WannaCry to take down the UK's National Health Service.

    --
    Only crack the nuts that crack. You don't put the ones that don't crack in the sack.
  71. Fix it then by Anonymous Coward · · Score: 0

    Clearly things need to change. A court order should be needed. They should not be allowed to ask nicely. Requiring a court order could remove the "we ask that you volunteer to help voluntarily" but with implied threats real or imagined that it is not voluntarily.

  72. Re:boil it down: End of Internet Connections by networkBoy · · Score: 1

    Of course I have logs, I also have physical remoteness and a couple other measures (remember everything is moderated through IPFire, which supports RADIUS authentication).

    --
    whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
  73. Re:Why should we expect open source to be any bett by david_thornley · · Score: 1

    If a good person can find the vulnerability they can warn of the issue, maybe collecting some small bounty (or maybe getting sued/prosecuted for their trouble).

    And here we see another advantage of F/OS software: a negligible chance of being sued if you bring up a problem.

    --
    "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  74. HAHA Ask Linus by Anonymous Coward · · Score: 0

    Remember when Linus said they came to him to put a back door into the Linux kernel?

  75. The Queen of Sheba adds her 2c by Hognoxious · · Score: 1

    I can say I'm the Queen of Sheba. That doesn't mean I've got tits and a crown.

    --
    Confucius say, "Find worm in apple - bad. Find half a worm - worse."
  76. Citation by Anonymous Coward · · Score: 0

    This Windows NSA key should satisfy your curiosity:

    Type Bits/KeyID Date User ID
      pub 1024/51682D1F 1999/09/06 NSA's Microsoft CAPI key

      -----BEGIN PGP PUBLIC KEY BLOCK-----
      Version: 2.6.3i

      mQCPAzfTdH0AAAEEALqOFf7jzRYPtHz5PitNhCYVryPwZZJk2B7cNaJ9OqRQiQoi
      e1YdpAH/OQh3HSQ/butPnjUZdukPB/0izQmczXHoW5f1Q5rbFy0y1xy2bCbFsYij
      4ReQ7QHrMb8nvGZ7OW/YKDCX2LOGnMdRGjSW6CmjK7rW0veqfoypgF1RaC0fABEB
      AAG0LU5TQSdzIE1pY3Jvc29mdCBDQVBJIGtleSA8cG9zdG1hc3RlckBuc2EuZ292
      PokBFQMFEDfTdJE+e8qoKLJFUQEBHnsH/ihUe7oq6DhU1dJjvXWcYw6p1iW+0euR
      YfZjwpzPotQ8m5rC7FrJDUbgqQjoFDr++zN9kD9bjNPVUx/ZjCvSFTNu/5X1qn1r
      it7IHU/6Aem1h4Bs6KE5MPpjKRxRkqQjbW4f0cgXg6+LV+V9cNMylZHRef3PZCQa
      5DOI5crQ0IWyjQCt9br07BL9C3X5WHNNRsRIr9WiVfPK8eyxhNYl/NiH2GzXYbNe
      UWjaS2KuJNVvozjxGymcnNTwJltZK4RLZxo05FW2InJbtEfMc+m823vVltm9l/f+
      n2iYBAaDs6I/0v2AcVKNy19Cjncc3wQZkaiIYqfPZL19kT8vDNGi9uE=
      =PhHT
      -----END PGP PUBLIC KEY BLOCK-----

  77. amicusNYCL don't talk w/ your mouth full! by Anonymous Coward · · Score: 0

    See subject amicusNYCL: It's impolite to talk w/ your mouth full as you EAT YOUR WORDS https://tech.slashdot.org/comments.pl?sid=11415277&cid=55646849/ failing as always vs. me!

    So - have some class @ least (& anyone can see your history & see who calls me that https://slashdot.org/~amicusNYCL/ to let you further bury yourself & show who is LOW class (more like NO class OR proof of your words)).

    * QUESTION: How did EATING YOUR WORDS taste amicusNYCL?

    Did they taste like YOUR FOOT IN YOUR MOUTH ramming them back down your chicken-neck throat washed down by the bitter taste of SELF-defeat? Bet they did!

    (Only problem is, I didn't defeat you directly - you defeated yourself FOR me!)

    APK

    P.S.=> "Your kind" just DOES NOT "get it" vs. me - you can downmod me ALL DAY & I'll just repost running you DRY of those 'downmodpoints' you + sockpuppets you fake name for fake lives types use online, as I have NO POSTCOUNT LIMITS unlike most ac posters do, & I win as always (you lose as always also - but then, nobody ever said you were smart either) ... apk

  78. Front door trumps back door every time by Anonymous Coward · · Score: 0

    You dont need back door access when you're being invited through the front.
    Think the NSA doesn't have the ability to scan facebook for a photo and come up awith a name in real time?
    FB techs have access to the data, you think that acess level isn't being shared ?

    The UK narcs wanted ID. The people didn't But everyone has given their details over to FB anyway and those that haven't have dark profiles anyway.
    All that data, cross matched for false positives and you think the agencies dont have access to it ??

    Its a global ID card system. It's a stasi wet dream.

  79. I think you're forgetting by rsilvergun · · Score: 1

    how many of them died rich and happy. It ends well all the time. Only very rarely do the elite get their comeuppance. And with modern militaries, drones and information control I'm not sure they ever will again. Not the real ones.

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/