Live data from Hacker News

Apple’s dangerous game

washingtonpost.com

51–60 of 113 posts

Re: Apple’s dangerous game

#51
post #43

The arguments in this article are hinged on one crucial premise: Apple stills owns your device even after selling it to you. This is different from gmail where your data is on servers owned by google. The analogy to this premise is that the producers of a safe that they sell to you must be able to provide the government a key to the safe. This clearly does not make sense, and neither does requiring Apple to always ha…

The arguments in this article are hinged on one crucial premise: Apple stills owns your device even after selling it to you. Hu? That idea isn't even mentioned in the article, and it seems entirely irrelevant. The analogy to this premise is that the producers of a safe that they sell to you must be able to provide the government a key to the safe. This clearly does not make sense.. It may not make sense to you, but k…

The point is that when someone sells you a thing, they should no longer be responsible to someone else for it. You should be responsible. It is now your thing.

Re: Apple’s dangerous game

#52

The article asks: > How is the public interest served by a policy that only thwarts lawful search warrants? Perhaps the answer is that judges act as rubber stamps now, authorizing way too many search warrants. The author assumes that the judges are fairly applying the 4th amendment.

> judges act as rubber stamps now Exactly. Our government is as overbearing and oppressive as it's been in a very long time. I read somewhere that judges approve something like 99% of the search warrants presented to them. They no longer serve as a check on law enforcement. I'd love to hear otherwise, to hear how judges are doing a good job balancing the interests of people against the interests of law enforcement.

> I read somewhere that judges approve something like 99% of the search warrants presented to them. They no longer serve as a check on law enforcement.

Where? Most sources I can find (usually focussing on individual departments) indicate rejected warrants applications aren't tracked, so there would likely be no basis for this conclusion.

Even if it was true, it would likely be misleading -- the fact that a warrant is approved doesn't mean its approved with the scope originally sought. Most sources I've seen also suggest that while rejections are uncommon, limiting the scope of the warrant is not.

Re: Apple’s dangerous game

#53

The article asks: > How is the public interest served by a policy that only thwarts lawful search warrants? Perhaps the answer is that judges act as rubber stamps now, authorizing way too many search warrants. The author assumes that the judges are fairly applying the 4th amendment.

Besides, a sufficiently competent criminal could benefit from the same level of security that Apple allegedly provides, using crypto. If something is lawful and technically possible, making it available to the masses (under the assumption that Apple's statements are correct) does not sound like a bad thing.

Re: Apple’s dangerous game

#55

Earlier quoted context omitted.

I did not downvote you, but there's a perfectly good explanation for why 99% of warrants would be approved. Consider that the police know what warrants a judge is likely to approve and which he's likely to turn down. Over time, police departments will learn to submit the warrants they can get approved and not bother wasting a judge's time with warrants that won't be approved. So very high approval rates do not necess…

> there's a perfectly good explanation for why 99% of warrants would be approved. Your argument is that the approval rate could be 99% legitimately. Even if true it doesn't actually provide any evidence that judges are not acting as a rubber stamp, it only attempts to discount some evidence in favor of it. Moreover, the fact that the approval rate is 99% is still evidence that judges are not being very critical in ap…

> the fact that the approval rate is 99%

How'd this get from "I read somewhere" to "fact"?

Re: Apple’s dangerous game

#56
>The first question is whether the government can lawfully compel the telephone’s owner to divulge the passcode. I believe the answer is that yes, a person can in fact face punishment for refusal to enter in the password to decrypt his own phone. If the government obtains a subpoena ordering the person to enter in the passcode, and the person refuses or falsely claims not to know the passcode, a person can be held in contempt for failure to comply.

I thought the exact opposite was true?

That no judge or any court can force you to disclose your password?

ie self incriminating your own person.

Apparently it varies from country to country: http://en.wikipedia.org/wiki/Key_disclosure_law

Re: Apple’s dangerous game

#57

The article asks: > How is the public interest served by a policy that only thwarts lawful search warrants? Perhaps the answer is that judges act as rubber stamps now, authorizing way too many search warrants. The author assumes that the judges are fairly applying the 4th amendment.

I too was surprised by the author's question. It's as if he hasn't been following the news lately about the apparent impotence of the 4th amendment these days. Yet his wiki page says he "has been regarded as a leading scholar on Fourth Amendment jurisprudence in electronic communications and surveillance." In light of that, he comes across as extremely naive. (or worse?)

His Wikipedia page also relates his career in the DoJ and as a US Attorney, a very different background from the typical libertarian HN reader.

I don't agree with Orin Kerr on this, but I'm willing to accept that he's likely seen things about the day-to-day business of law enforcement that I just don't understand. It's worth us spending at least a few moments entertaining the thought that maybe we are the naive ones.

Re: Apple’s dangerous game

#58
post #10

"The first question is whether the government can lawfully compel the telephone’s owner to divulge the passcode. I believe the answer is that yes, a person can in fact face punishment for refusal to enter in the password to decrypt his own phone. If the government obtains a subpoena ordering the person to enter in the passcode, and the person refuses or falsely claims not to know the passcode, a person can be held in…

I don't know how they can reasonably prove you remember what the code is.

Re: Apple’s dangerous game

#59
(IANAL.) From the three last options proposed in the article:

- Option 1 doesn't make sense to me because, if you assume that private crypto is lawful, the phone's data could be encrypted using the passcode, so that it would be technically impossible to bypass the passcode.

- Option 2 seems like a bad idea to me. The central premise is that there is one passcode which you must know, so you can be forced to provide it. However, if you are using deniable encryption you could have multiple passcodes, an "everyday" passcode, a "secondary" passcode for sensitive data, a "duress" passcode, etc., and there would be no way for you to prove that you have provided everything. Under this interpretation, forcing users to hand in "all available passcodes" sounds too much like asking the accused to help the investigation make sense of their encrypted data.

- Option 3 seems more reasonable (although I think it is undesirable). In fact, I am surprised that retention of text messages is not yet an obligation under the law (though maybe they are already retained, just not lawfully). Of course this would make a lot less sense if people (or their phones) encrypted texts...

Yes, telephony is stuck with historical ad-hoc messaging protocols (SMS), proprietary devices, OSes and applications, with strong dependencies to their manufacturers and mobile providers, and people do not often use serious crypto on them. But mobile phones with a mobile connection are essentially computers on a network, and one should be wary of special bypass mechanisms on passcodes or texts that would make no sense with computers.

Re: Apple’s dangerous game

#60

Kerr's argument sounds silly when you use analogies with conventional devices. Nobody would argue that a highly secure safe should have a backdoor that can be used by the manufacturer to open it.

This is an excellent point. The reason why the opposite view seems to make sense with smartphones is because in the current state of affairs they are not designed to be used without further manufacturer involvement (in fact they are actively designed to discourage any other party from acting like the manufacturer). But this is not a necessity, just the sad current state of the market, given consumers' present expectations.
Post reply on HN