Apple is an international company, while I trust my government I do not trust the Chinese.
the question is, why do we take Apple at their word here?
71–80 of 113 posts
Apple is an international company, while I trust my government I do not trust the Chinese.
the question is, why do we take Apple at their word here?
Earlier quoted context omitted.
I too was surprised by the author's question. It's as if he hasn't been following the news lately about the apparent impotence of the 4th amendment these days. Yet his wiki page says he "has been regarded as a leading scholar on Fourth Amendment jurisprudence in electronic communications and surveillance." In light of that, he comes across as extremely naive. (or worse?)
His Wikipedia page also relates his career in the DoJ and as a US Attorney, a very different background from the typical libertarian HN reader. I don't agree with Orin Kerr on this, but I'm willing to accept that he's likely seen things about the day-to-day business of law enforcement that I just don't understand. It's worth us spending at least a few moments entertaining the thought that maybe we are the naive ones.
But he has been exposed to highly unusual circumstances with a high bias.
Orin Kerr is clearly a lawyer. He argues not for what is right but for what is permissible given the existing body of law. Where the existing body of law is wrong, his writings have no sympathy for the damage inflicted on its victims nor any sense that resisting such wrongs is noble. If the government never abused its authority, I would be much more sympathetic to Kerr's position. Given the facts of prosecutorial abu…
I do think he thinks beyond the technicalities of the law. And I think he's correct that there are legitimate reasons to pierce device encryption. If a victim is murdered, and their phone is locked, it sure would be nice too see if there were some evidence on that phone that could help catch the killer.
That said, he knows better than most what the law does say, and I think that makes this an op-ed worth reading carefully. I found two of his points interesting.
1) A passcode is probably not covered by Fifth Amendment protections. Thus a phone owner who refuses to lock their phone could be punished by the court anyway.
2) An encryption system strong enough to thwart legitimate and legal police actions could lead to a legislative "backlash" (my word, not Orin's) of increased consequences for failure to unlock. This is the "game" in the title of the op-ed. Technology and law are often in tension and an escalation from one side could trigger an escalation from the other.
But I disagreed with his state that "The policy switch doesn’t stop hackers, trespassers, or rogue agents. It only stops lawful investigations with lawful warrants." That seems wrong to me because it's not just a policy change, it's an improvement in how the OS encryption actually works. Seems to me that could help keep out some bad guys too.
> Because the victim isn’t alive to share his password, and the phone will have locked before the body was found, the government won’t be able to search the phone to find the messages. Apple’s policy will keep the police from finding the killer. That seems bad. The problem with this argument is that it applies to all secure encryption. The purpose of encryption is to keep people not authorized to access private data…
> Because the victim isn’t alive to share his password, and the phone will have locked before the body was found, the government won’t be able to search the phone to find the messages. Apple’s policy will keep the police from finding the killer. That seems bad. The problem with this argument is that it applies to all secure encryption. The purpose of encryption is to keep people not authorized to access private data…
I think Orin's point is not that everything should have a backdoor (which would not comport with his many previous writings on tech and law), but that Apple's shift, and in particular the public way in which it has been done, could trigger unintended consequences from the courts or Congress. Hence the "dangerous game" title.
So basically, the author wants every "secure" software system to have a backdoor. iOS versions prior to 8 all had a backdoor and he's lamenting that Apple has closed this backdoor. Not only that, if this applies to the iPhone, it must apply to any and all encryption software. While it's widely known that the government already has backdoors into a lot of popular software, codifying this in law or expecting that all s…
iOS versions prior to version 8 didn't have a backdoor - I believe the difference is just that less content was stored encrypted before.
> Because the victim isn’t alive to share his password, and the phone will have locked before the body was found, the government won’t be able to search the phone to find the messages. Apple’s policy will keep the police from finding the killer. That seems bad. The problem with this argument is that it applies to all secure encryption. The purpose of encryption is to keep people not authorized to access private data…
I think Orin's point is not that everything should have a backdoor (which would not comport with his many previous writings on tech and law), but that Apple's shift, and in particular the public way in which it has been done, could trigger unintended consequences from the courts or Congress. Hence the "dangerous game" title.
Earlier quoted context omitted.
> Moreover, the fact that the approval rate is 99% is still evidence that judges are not being very critical in approving warrants. No it is not. > The high rate makes it statistically more likely that judges are approving warrants uncritically than would be the case if the rate was lower. As I said in another sub-thread, you are going to have to explain the statistics involved if you want to make an argument from th…
> No it is not. Yes it is. There is no question that it is evidence, so you can only be questioning whether the evidence supports the proposition. You want a mathematical proof? OK. Without knowing the percentage of approved warrants we can't exclude the possibility that exactly zero warrants were approved, which would be a hard disproof of the proposition that judges are uncritically approving warrants. Discovering…
Generally speaking, we mean 'critical' to involve the weighing of a decision against an ethical standard. Assuming the standard isn't changing, we would expect an equilibrium to emerge where the parties involved would come to understand the standard, especially given that the warrant process is not adversarial. So there's no reason not to expect the approval rate to settle at close to 100%, with the few denials being law enforcement attempts to skirt the boundaries.
Anything less than a very high rate would indicate that the standards are inconsistent or are being inconsistently applied. The only reason I can see to be inconsistent is to game statistics like this one that seem to mean more to certain people than they actually do.
"The first question is whether the government can lawfully compel the telephone’s owner to divulge the passcode. I believe the answer is that yes, a person can in fact face punishment for refusal to enter in the password to decrypt his own phone. If the government obtains a subpoena ordering the person to enter in the passcode, and the person refuses or falsely claims not to know the passcode, a person can be held in…
This actually isn't entirely settled law. Some argue that the 5th ammendment protection from self-incrimination would give someone the right not to give up their passcode. But different courts have ruled differently in differnet situations/jurisdictions, so far.
And since you're not proving this to a jury, but rather a judge, the standard of proof is going to be pretty low for a smartphone. Orin Kerr thinks possession of a phone at time of arrest will be enough to prove to a judge that you know the passcode, and given how low-level judges operate in the real world I'm inclined to agree (in practice, not legal theory or what's just.)
Anyway, iCloud backups are still fair game, so it's not like LEOs can't typically get the information they want anyway even without the passcode.