I know these "blow-by-blow" comments can seem petty, but there are just so many things wrong with this post. It's sad, because I have a lot of respect for Kerr (besides being a very intelligent guy, he participated in weev's legal defense pro bono).
> That’s hugely important. And under Apple’s old operating system, cryptography protects iPhones from rogue police officers, too.
Kerr is a lawyer, not a techie, and it really shows here. This statement first of all implies that the previous system was "adequate, but with a backdoor", which of course we know is not possible.
But that is a matter of theory; the practice, according to [1], is that previously iOS filesystem encryption wasn't tied to the user passcode anyway, so it wasn't even a matter of "decrypting" the devices, nor was it something only feasible for Apple to do. Indeed, vendors such as Elcomsoft (believably, given the info in those slides) claim that their software can grab most user data without a password [2].
The aforementioned slides mention a second level of encryption, "data protection", which is derived from the passcode, and which Elcomsoft claims to not be able to access. I wonder whether Apple could (since if implemented properly it shouldn't have).
> Because Apple demands a warrant to decrypt a phone when it is capable of doing so, the only time Apple’s inability to do that makes a difference is when the government has a valid warrant.
Kerr never says it, because he knows it's not true, but he gives the impression throughout the piece that because Apple could access on-device data when presented with a warrant, it had to. It didn't. Perhaps Kerr thinks they had/have a moral obligation?
> The policy switch doesn’t stop hackers, trespassers, or rogue agents. It only stops lawful investigations with lawful warrants.
I don't know what Kerr is getting at here. If it is within the means of "hackers" or "trespassers", it is surely within the means of law enforcement.
> How is the public interest served by a policy that only thwarts lawful search warrants?
But it doesn't only thwart lawful search warrants, it protects against other would-be intruders. Apple is simply choosing, in light of recent controversies regarding government incursions on privacy, to highlight that aspect.
> Apple’s new policy seems to thumb its nose at that great tradition. It stops the government from being able to access the phone precisely when it has a lawful warrant signed by a judge. What’s the public interest in that?
Apple is responding to a political and market reality: a lot of us don't believe that "great tradition", as practiced, is actually serving the public interest. I guess it is out of the scope of the piece for Kerr to explain why we're mistaken, but many of those applauding Apple's decision aren't going to buy it, and yet it's his argument's key premise.
> Because the victim isn’t alive to share his password, and the phone will have locked before the body was found, the government won’t be able to search the phone to find the messages. Apple’s policy will keep the police from finding the killer. That seems bad.
Maybe. But recall, for perspective, that 15 years (generously) ago people didn't carry these repositories of personal information with them.
> If we get a lot of cases like that, I suspect Congress may look to legislation to try to restore the privacy/security balance more in the direction of the traditional Fourth Amendment warrant requirement.
I would expand on the same point as above: what year's balance are we striving to "restore" to? Law enforcement today have unprecedented access to personal information, and that will be only marginally less true when smartphone encryption is more widespread and robust.
> The most obvious option would be follow the example of CALEA and E911 regulations by requiring cellular phone manufacturers to have a technical means to bypass passcodes on cellular phones.
I know Kerr is talking about what Congress might do and not what would be ideal, but I'm sure Kerr knows the lessons of the Clipper chip [3].
I know I'm preaching to the choir here, but I've been stewing over this since I read it on Friday. Apologies for the rantiness.
[1] http://www.slideshare.net/eltufl/ios-encryption-systems
[2] http://www.elcomsoft.com/eift.html?r1=pr&r2=ios6#passcode
[3] https://en.wikipedia.org/wiki/Clipper_chip