Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, March 15, 2016

Security Roundup

Not only is the U.S. Congress about to vote on anti-encryption legislation, but so is California. The bill going through the CA State Assembly "would ban default encryption on all smartphones" sold in the state.

Those laws could make the push to have Apple build iPhones even it can't unlock moot. Though, some companies - including Facebook and Google - are working to increase privacy protections in the face of the next attack on this front - WhatsApp.

Unfortunately, President Obama is showing that he doesn't understand the importance or technical issues of encryption either. He "keeps mentioning trade-offs, but it appears that he refuses to actually understand the trade-offs at issue here. Giving up on strong encryption is not about finding a happy middle compromise. Giving up on strong encryption is putting everyone at serious risk."

Could the government demand the iOS source code and signing key? A footnote in the DOJ brief says the following:
For the reasons discussed above, the FBI cannot itself modify the software on Farook's iPhone without access to the source code and Apple's private electronic signature ... The government did not seek to compel Apple to turn those over because it believed such a request would be less palatable to Apple. If Apple would prefer that course, however, that may provide an alternative that requires less labor by Apple programmers."
In other words, "it would be a shame if we had to take that code from you."

Mr. Fart and phone security -- the comparison between cockpit security and phone security is great. 

Saturday, March 12, 2016

Why it matters

I've posted a lot about security and privacy lately and will continue to do so because I believe this could be a defining movement both in law and culture with respect to security, privacy, and surveillance (maybe Crypto Wars 2.0). It's not just the FBI's request to Apple either. Facebook could soon be clashing with the DOJ on the WhatsApp messaging application in a case regarding wiretapping. There is also activity in the U.S. Congress which is preparing to vote on a bill that would punish tech companies that refuse to cooperate with investigators, specifically on encryption. The importance of these events can't be overstated.

The importance of encryption per se can't be overstated either because it is an enabling technology that gives private citizens power against mass surveillance. John Reed at Just Security, wrote about this topic recently. He was reacting to the oft-cited yet dangerous argument that "if you don’t have anything to hide, you shouldn’t have anything to worry about." He states,
A government’s abuse of surveillance to intimidate and discredit law-abiding citizens isn’t something that happens only in places like Russia. It’s happened time and again, even in democracies as strong as the United States. Within living memory in the US alone, one can recall Nixon’s enemies, Sen. Joseph McCarthy’s anti-communist witch hunts, J. Edgar Hoover’s FBI files on everyone who may have posed a threat to his power, COINTELPRO, and more specifically, that program’s use of surveillance to assist in attempt to ruin Martin Luther King Jr., the list goes on. There is simply no reason to think that such abuse will not occur again. So why should you care if you’re always being watched? Because your self-perceived innocence may not protect you from the kind of abuses we’ve seen repeatedly over the past century (emphasis added).
Jenna McLaughlin at The Intercept shows how Reed's comment emphasized above is all too true with respect to Black Lives Matter movement. Quoting a grassroots organizer,
"The mundane surveillance of people of color is what gives rise to bulk surveillance at a federal level … not the other way around," she said. "Whatever has been considered normal at a local level" -- including systems of suspicious activity reports, predictive policing, and other tactics -- "has now been considered normal at the federal level."
Even beyond the realm of social justice movements, the fact of the matter is is that everyone has something to hide or something in their life that they want to keep private. Reed quotes Bruce Schneier as saying that "[p]rivacy is a basic human need," and that being watched turns us into children under watchful eyes waiting to be implicated by patterns from our past lives.

This is why the fight for strong encryption and against surveillance matters.

Saturday, February 20, 2016

The Security Chess Game

The Justice Department is now chiming in to defend the FBI's All Writs Act request to Apple. We've also learned that late last year the White House ordered government agencies to work around encryption. As Bloomberg reports, agencies were requested to "find ways to counter encryption software and gain access to the most heavily protected user data on the most secure consumer devices."


In the DOJ's defense of the FBI's request, they said that Apple's refusal to comply "appears to be based on its concern for its business model and public brand marketing strategy." That may be true, but the government is playing the same game. It looks like they are using the emotions around the San Bernardino incident to garner political support for a more strategic move against companies refusing to break encryption. They know this could set the precedent they need to strong arm industry players into either installing "backdoors" on encrypted devices or bending over whenever the FBI comes knocking.

So we have competing strategies at play: the enabling of security vs. the subversion of security. Which one were you taught in high school was the government's side?

As I mentioned in a previous post, government agencies have ways to get into devices. Andy Greenberg has an entire article on the ways government officials can get access to data on an iPhone. So this really does seem like the government is playing a chess game here.

***

Regarding the All Writs Act request, check out Orin Kerr's thoughts on the 1789 statute. The ruling precedent right now is the 1977 case United States vs. New York Telephone. According to Kerr,
The tricky part of New York Telephone is that the Court left the actual test for what the AWA allows frustratingly murky. The Court was comparatively clear about one essential limit on a Court’s power under the AWA: "We agree that the power of federal courts to impose duties upon third parties is not without limits; unreasonable burdens may not be imposed." Okay. But the rest of what the Court says is really unclear.
So the chess game could be a long one.