Live data from Hacker News

U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

bloomberg.com

261–270 of 350 posts

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#261
post #24

Earlier quoted context omitted.

I don't support what the government is trying to do here, but minimizing this issue like this is not doing us any favors. The issue isn't that law enforcement can no longer "look around" your phone. The issue is that they can no longer get a warrant and use what is on your phone as evidence in an investigation or court case without the phone owner's cooperation. Basically your phone goes from being personal property…

They can get a warrant, and they can use anything they find as evidence. Encryption might make it hard for them to find much of use, but that's not our problem. A really sturdy safe will make it difficult to execute a warrant too, but that's not an argument for deliberately compromising the integrity of safes. I can, of course, understand why law enforcement wouldn't be happy about this. They shouldn't be happy about…

As I've pointed out in another comment on the thread, I've never come across a safe that couldn't be drilled in a few hours, and that's without any government intervention to compromise their integrity. Strong encryption is an entirely different beast.

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#262

Earlier quoted context omitted.

They can get a warrant, and they can use anything they find as evidence. Encryption might make it hard for them to find much of use, but that's not our problem. A really sturdy safe will make it difficult to execute a warrant too, but that's not an argument for deliberately compromising the integrity of safes. I can, of course, understand why law enforcement wouldn't be happy about this. They shouldn't be happy about…

As I've pointed out in another comment on the thread, I've never come across a safe that couldn't be drilled in a few hours, and that's without any government intervention to compromise their integrity. Strong encryption is an entirely different beast.

How about encasing something in 20ft of reinforced concrete and then sinking it to the bottom of the ocean?

Strong encryption may be tougher to break but I disagree that it's entirely different. It's merely a quantitative difference. It's a standard principle that the police can break into whatever they can if they have a warrant, but they can't force you to make things easy for them ahead of time.

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#263
post #103

I hypothesize that this is a coordinated yet simple ruse to rebuild trust in these brands post-Snowden [1][2]. There was similar press coverage regarding the DEA and iCloud encryption that was misreported in a similar way [3]. The Intercept (where Glenn Greenwald is now reporting from) has a story on what data Apple can still easily give away if you do believe they can't decrypt individual machines [4]. But maybe you…

But the article isn't just talking about the NSA and National Security Letters - this is about law enforcement . If Apple and Google claim to be technically unable to comply with LE requests, it won't take long to see whether that is indeed the case or not - unlike national security-related demands, law enforcement won't be able to keep their successes or failures at demanding access to this data a secret. If this wa…

I don't see why it's such a big deal for law enforcement investigators. They'll still be able to force Apple and Google to send trojan clients to targets, as happened with Hushmail, won't they?

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#264

Earlier quoted context omitted.

As I've pointed out in another comment on the thread, I've never come across a safe that couldn't be drilled in a few hours, and that's without any government intervention to compromise their integrity. Strong encryption is an entirely different beast.

How about encasing something in 20ft of reinforced concrete and then sinking it to the bottom of the ocean? Strong encryption may be tougher to break but I disagree that it's entirely different. It's merely a quantitative difference. It's a standard principle that the police can break into whatever they can if they have a warrant, but they can't force you to make things easy for them ahead of time.

You can keep coming up with analogies that are increasingly more difficult for the cops to get into, but ultimately it's just an exercise in sophistry. Only when people begin commonly storing their belongings inside 20ft of reinforced concrete at the bottom of the ocean will it become analogous to seeking a warrant to gain access to their phone.

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#265
post #232

Earlier quoted context omitted.

If the device is backed up in iCloud, Apple already has the decryption key and will have to provide it if they receive a supoena. The only way you're safe, even in theory, is to only do local encrypted backups.

The whole point of the updated system is that they don't have your decryption key. They will still turn over encrypted data, but LE won't be able to decrypt. That might be a leap of faith though.

> The whole point of the updated system is that they don't have your decryption key.

It's a nice thought.[1]

> While Apple does not have the crypto keys that can unlock the data on iOS 8 devices, they do have access to your iCloud backup data. Apple encrypts your iCloud data in storage, but they encrypt it with their own key, not with your passcode key, which means that they are able to decrypt it to comply with government requests.

[1] https://firstlook.org/theintercept/2014/09/22/apple-data/

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#266

Earlier quoted context omitted.

But the article isn't just talking about the NSA and National Security Letters - this is about law enforcement . If Apple and Google claim to be technically unable to comply with LE requests, it won't take long to see whether that is indeed the case or not - unlike national security-related demands, law enforcement won't be able to keep their successes or failures at demanding access to this data a secret. If this wa…

I don't see why it's such a big deal for law enforcement investigators. They'll still be able to force Apple and Google to send trojan clients to targets, as happened with Hushmail, won't they?

Yes, but it still makes their jobs a lot more difficult.

I'm of the opinion that this is not a ruse or scheme, and that law enforcement are genuinely dissatisfied with this. Note that law enforcement and the NSA have a tenuous relationship at best.

Even if the NSA still do have privileged access after default mobile encryption is fully rolled out, law enforcement generally will not be able to tap into that except in extreme and rare cases.

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#267
post #218

Earlier quoted context omitted.

Out of interest do you have an example of Google's weasel wording this issue? They're getting criticised by all the same people and seem to be doing the same thing - is there actually an advantage either way here? Just to clarify, I'm skeptical on both sides - both companies were in the prism leaks after all. But I haven't seen weasel wording and I'm curious if I missed it.

Actually, no, that was just a prediction. I am making an assumption - and maybe not a fair one - that because Google mines user data on the web that they also mine user data on the phone. Skepticism seems warranted. With Apple, I try to be skeptical, but with Google, I always assume that I am the product until they demonstrate otherwise.

I don't believe in that claim.

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#268
post #233

Earlier quoted context omitted.

Judging by the amount of karma i'm shedding, the consensus would seem to agree with you....

Just to clarify, I strongly dislike Apple's controlling policies on iOS. I think it's ridiculous that they won't allow sideloading apps or downgrading your OS, let alone installing custom OS builds. However, going from "they can tell your phone to download a U2 album if you ticked the box" to "thus they own your vacation photos" is still a complete non-sequitur.

Ignoring the actual legalities involved, if some three-letter agency went to Apple and said "we want all the data on the Apple devices belonging to to so-and-so," Could Apple theoretically access it, and hand it over?

If not, then I'll concede I was massively too paranoid, which wouldn't be the first time when it comes to Apple (and Google.. definitely and Google cars, and Adobe as soon as they pulled that BS with Creative Cloud) But if so then (even if I was wrong about the U2 thing) I don't believe i'm speculating too wildly.

Apple owns the content to the degree that they can limit your access to it more than you can limit theirs - "ownership" in this case is not so much a legal as a practical matter. You can't really own something you don't control. I'll extend this to any app-based OS as far as it applies.

Re: U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data

#269

Earlier quoted context omitted.

I don't see why it's such a big deal for law enforcement investigators. They'll still be able to force Apple and Google to send trojan clients to targets, as happened with Hushmail, won't they?

Yes, but it still makes their jobs a lot more difficult. I'm of the opinion that this is not a ruse or scheme, and that law enforcement are genuinely dissatisfied with this. Note that law enforcement and the NSA have a tenuous relationship at best. Even if the NSA still do have privileged access after default mobile encryption is fully rolled out, law enforcement generally will not be able to tap into that except in…

>law enforcement generally will not be able to tap into that except in extreme and rare cases

Like when they pull someone over for having a tail light out? I can't reconcile your statement here with what we already know about parallel construction.

Post reply on HN