Live data from Hacker News

Former NSA lawyer: the cyberwar is between tech firms and the US government

theguardian.com

51–60 of 79 posts

Re: Former NSA lawyer: the cyberwar is between tech firms and the US government

#51

Earlier quoted context omitted.

Apple and Google are merely absolving themselves of being involved in the legal matters of others. The third-party doctrine basically forces third-parties to be legally culpable for discovery. Google and Apple don't want to be legally responsible anymore, so they've pushed the responsibility for complying with counsel to the end-user. i.e. instead of law enforcement going to Google and Apple and saying "I have a lega…

> i.e. instead of law enforcement going to Google and Apple and saying "I have a legal right to search X. Hand it over.", law enforcement now needs to go up to the person whose papers and effects are being searched and ask the same thing. Which is entirely the wrong way to conduct a criminal investigation. How effective can the police really be when they have to go to suspect and say "We've got enough evidence to sus…

Eh? Police do that routinely. How do you think they get evidence to prove a building was a meth lab or crack house? They get a warrant, bust down the door and go inside. How do you think they get internal business documents when prosecuting white collar fraud? They get a warrant or subpoena and force the potentially guilty parties to hand over documents.

I'm not sure why this seems like a radical departure. "The cloud" is a very recent phenomenon. Up until quite recently almost all interesting documents were held only by the suspect parties themselves.

Re: Former NSA lawyer: the cyberwar is between tech firms and the US government

#52
post #39

Earlier quoted context omitted.

> Stewart is extremely smart, should not be underestimated, and HN comments in this thread calling him "incompetent" reflect badly on the person making the comment. Incompetent may be the wrong word. What people (including you) are getting at is that his arguments are unpersuasive upon examination. It's all just fear mongering. There are two plausible explanations for this. The first is that he doesn't see the holes…

Welcome to the delightful world of Washington, D.C. realpolitik! A third possibility is that he honestly believes his position is the correct one--or is holding out the possibility of returning to a .gov/.mil job in this or a future administration--and (a) is using the best arguments for his case, however weak or (b) is on a conference panel, not in a courtroom, and is aiming for entertaining one-liners rather than a…

I didn't find his comments especially entertaining, and I don't think my sense of humour is faulty, so let's rule out the court jester theory.

That leaves "using the best arguments for the case he truly believes in, however weak". This I think would correctly fall under the umbrella of incompetence. At some point, rational people are supposed to evaluate their own arguments and change their beliefs if they can't sustain them anymore.

In this case he has strongly implied that "tech people" with a libertarian bent are naive and their beliefs crumble the moment they're faced with the real world. Insulting the people you need help from isn't a good start. But regardless, I don't know of any tech companies that have real problems complying with a robust, trustworthy process that includes many checks and balances to ensure only people widely agreed to be criminals get investigated. The whole problem has started because that system has broken down over time and post-Snowden been revealed as nothing more than a political sleight of hand.

Re: Former NSA lawyer: the cyberwar is between tech firms and the US government

#53

Earlier quoted context omitted.

> i.e. instead of law enforcement going to Google and Apple and saying "I have a legal right to search X. Hand it over.", law enforcement now needs to go up to the person whose papers and effects are being searched and ask the same thing. Which is entirely the wrong way to conduct a criminal investigation. How effective can the police really be when they have to go to suspect and say "We've got enough evidence to sus…

Eh? Police do that routinely. How do you think they get evidence to prove a building was a meth lab or crack house? They get a warrant, bust down the door and go inside. How do you think they get internal business documents when prosecuting white collar fraud? They get a warrant or subpoena and force the potentially guilty parties to hand over documents. I'm not sure why this seems like a radical departure. "The clou…

The two situations aren't analogous - in both my cell phone example and your meth lab example the police need warrants, but they don't need the owner's permission to bust open the door to a meth lab, and they can't bust open the login screen on an encrypted iPhone without the owner voluntarily decrypting it.

I linked to some case law examples in a previous comment[1], but basically the cops can't force you to decrypt an encrypted device because of your 5th Amendment rights, except in the rare case where you've already admitted that incriminating evidence is stored on that device (thus waiving your right to not self-incriminate).

In your white collar example, they're not demanding the suspect turn over the documents, they're demanding the employer turn over the documents, which would imply that a third party already had access to the unencrypted documents and was willing to cooperate with the police.

[1] https://news.ycombinator.com/item?id=8430501

Re: Former NSA lawyer: the cyberwar is between tech firms and the US government

#54
post #39

Earlier quoted context omitted.

> Stewart is extremely smart, should not be underestimated, and HN comments in this thread calling him "incompetent" reflect badly on the person making the comment. Incompetent may be the wrong word. What people (including you) are getting at is that his arguments are unpersuasive upon examination. It's all just fear mongering. There are two plausible explanations for this. The first is that he doesn't see the holes…

Welcome to the delightful world of Washington, D.C. realpolitik! A third possibility is that he honestly believes his position is the correct one--or is holding out the possibility of returning to a .gov/.mil job in this or a future administration--and (a) is using the best arguments for his case, however weak or (b) is on a conference panel, not in a courtroom, and is aiming for entertaining one-liners rather than a…

That's not a third possibility, but rather saying it might be the first ( = he honestly believes this) or the second ( = he doesn't, but either pretends he does for personal gain or is just stringing words together because hey, it's not like it matters).

Re: Former NSA lawyer: the cyberwar is between tech firms and the US government

#55
post #31

I've known Stewart Baker, the ex-NSA GC quoted in the linked article, for about 15 years--not incredibly well, but well enough that he'd show up at parties I held in my home when I was living in D.C. before moving to the SF bay area. Stewart is extremely smart, should not be underestimated, and HN comments in this thread calling him "incompetent" reflect badly on the person making the comment. He's likely the single…

NSA old boy Stewart Baker is a fascinating character. Here's what he said at the Economic Warfare Institute at American Center for Democracy in 2012 (before Snowden leaks):

"We will map your social graph, compromise every computer and smartphone in your country"

https://www.youtube.com/watch?v=Mu9puGKfdZE

He is a long-time proponent of export controls for cryptography and government mandated escrow-keys. In 1994, he wrote an article for Wired Magazine titled: "Don't Worry Be Happy: Why Clipper Is Good For You". This guy is a cryptowars veteran.

So, in a sense--you're right, he's not incompetent. Rather, he is a professional ideologue: making the case against privacy rights that crypto-tech enables. If you have experience with KGB "agitprop" and "active measures", you'll be very familiar with the techniques that these sort of people employ for their cause. We should promptly react to his demagoguery by showing it for what it is--sophistry.

Re: Former NSA lawyer: the cyberwar is between tech firms and the US government

#57
post #39

Earlier quoted context omitted.

Welcome to the delightful world of Washington, D.C. realpolitik! A third possibility is that he honestly believes his position is the correct one--or is holding out the possibility of returning to a .gov/.mil job in this or a future administration--and (a) is using the best arguments for his case, however weak or (b) is on a conference panel, not in a courtroom, and is aiming for entertaining one-liners rather than a…

I didn't find his comments especially entertaining, and I don't think my sense of humour is faulty, so let's rule out the court jester theory. That leaves "using the best arguments for the case he truly believes in, however weak". This I think would correctly fall under the umbrella of incompetence. At some point, rational people are supposed to evaluate their own arguments and change their beliefs if they can't sust…

It can't be called incompetence if he makes the arguments he has been paid (and likely will again be paid) to make. The world is full of highly competent people who do exactly that, many of them lawyers. They're not called 'advocates' for nothing.

But this begs the question why otherwise self-respecting panels so often give a soapbox to propagandists. Perhaps instead of using the mindless daily news formula of pitting two self-interested views against each other to see who has better soundbites we should try to put rational, thoughtful people on the stage.

Re: Former NSA lawyer: the cyberwar is between tech firms and the US government

#58

Earlier quoted context omitted.

Apple and Google are merely absolving themselves of being involved in the legal matters of others. The third-party doctrine basically forces third-parties to be legally culpable for discovery. Google and Apple don't want to be legally responsible anymore, so they've pushed the responsibility for complying with counsel to the end-user. i.e. instead of law enforcement going to Google and Apple and saying "I have a lega…

> i.e. instead of law enforcement going to Google and Apple and saying "I have a legal right to search X. Hand it over.", law enforcement now needs to go up to the person whose papers and effects are being searched and ask the same thing. Which is entirely the wrong way to conduct a criminal investigation. How effective can the police really be when they have to go to suspect and say "We've got enough evidence to sus…

That is exactly how you conduct an investigation. You gather evidence establishing cause to search, get a warrant to conduct the search and get your evidence.

When the police seize your property, you're going to be compelled to provide access, or you'll be held in contempt until you do.

It does make to harder for a traffic stop to turn into a fishing expedition, but that's the point of the 4th amendment.

Re: Former NSA lawyer: the cyberwar is between tech firms and the US government

#59
post #44

Earlier quoted context omitted.

Unless that data is at rest somewhere outside an organization's control, that still does not require end to end Enron with key escrow/recovery.

I think I misunderstood your initial question - the I (well, really, Stewart Baker) was trying to make was that selling devices which are automatically encrypted with keys that can't be escrowed by the owning company (like the new iPhones) isn't going to be very welcome in a corporate environment. > end to end Enron I think you meant "end to end encryption". I'm guessing you're typing that on iPhone :)

That was Android's auto-incorrect. Evidently Google doesn't think I need end to end encryption either!

I understand your point, but key escrow and most corporate use cases don't overlap. You are better off not managing user keys, with or without key escrow, and, instead, securing your links back to your infrastructure with a VPN and encrypting your storage to secure data at rest. Key escrow gives you no more protection, or access. It's just more complicated.

Key escrow, therefore, is only useful for spying on individuals' interpersonal communication, and Baker knows this very well.

Re: Former NSA lawyer: the cyberwar is between tech firms and the US government

#60

Earlier quoted context omitted.

Apple and Google are merely absolving themselves of being involved in the legal matters of others. The third-party doctrine basically forces third-parties to be legally culpable for discovery. Google and Apple don't want to be legally responsible anymore, so they've pushed the responsibility for complying with counsel to the end-user. i.e. instead of law enforcement going to Google and Apple and saying "I have a lega…

> i.e. instead of law enforcement going to Google and Apple and saying "I have a legal right to search X. Hand it over.", law enforcement now needs to go up to the person whose papers and effects are being searched and ask the same thing. Which is entirely the wrong way to conduct a criminal investigation. How effective can the police really be when they have to go to suspect and say "We've got enough evidence to sus…

Warrants have never been a guarantee of producing evidence. If a prosecution relies in information alone, and that information is impossible to obtain, maybe it's not a good candidate for prosecution.
Post reply on HN