Live data from Hacker News

FBI Director Comments on San Bernardino Matter

fbi.gov

121–130 of 142 posts

Re: FBI Director Comments on San Bernardino Matter

#121

Earlier quoted context omitted.

My point is that encryption is good and bad, but we can't completely enable it to be utilized for criminal activity. There will be the need for a resolution to be reached on who gets access to this information, in what situations, and maybe even strict prosecution if the information is ever used incorrectly.

Encryption is either secure or it isn't. You can't have a middle ground. It's unfortunate that under rare, and very particular circumstances criminals can perhaps evade crimes because they have access encryption, but it's also unfortunate that they can get away with crimes because they have access to guns, knives, vaults, cars, basements, gasoline, matches, duck tape, chain saws, shovels, etc... Yet we don't cripple…

> Encryption is either secure or it isn't. You can't have a middle ground.

Technically, there is some limited middle ground due to key escrow (clipper chip[1]) or cryptographic backdoors (DUAL_EC_DRBG[2]).

Both are interesting because the encryption algorithms stay mathematically strong.

Obviously, the golden keys would have to be well-protected. But that's mostly a solved problem; see CAs.

(Of course there's the problem of which governments get the keys. And it's good that Clipper and DUAL_EC_DRBG died.)

[1] https://en.wikipedia.org/wiki/Clipper_chip [2] https://en.wikipedia.org/wiki/Dual_EC_DRBG

Re: FBI Director Comments on San Bernardino Matter

#122
post #114

Earlier quoted context omitted.

It's possible that I missed any concern the judge may have had for precedent when I read the ruling. If you know of any (or any other document I may have missed), I'd appreciate a pointer. I think you're applying some fairly strict high-mindedness to the US legal system while others (myself included) worry that creative extension of intent appears rampant in cases that touch on technology or terrorism and therefore f…

>I think you're applying some fairly strict high-mindedness to the US legal system while others (myself included) worry that creative extension of intent appears rampant in cases that touch on technology or terrorism and therefore fall into your second form. My main point related to this was above: >The only concern would seem to be if the future court fails to analyse a case properly. But they can fail regardless of…

> To argue against that, you'd need to claim that precedent makes it easier for the later court to fail.

No, I'm arguing that incrementalism means the court doesn't have to fail (as a court) - the follow-on steps that I outlined and you found perfectly acceptable will not stop wherever you personally think they will, nor have I outlined (or even imagined) all the incrementally creative applications of this case that will likely follow. I'm also arguing (which you didn't counter) that this case lays the groundwork for the FBI to request _new_ products from companies.

> This is the part that doesn't follow from precedent. Giving over control of the tool to the FBI who could use it without a warrant is novel, and would require a judge to justify it.

I was being brief to illustrate, not to set a literal expectation of progression; I'm not here to present an argument for court. Giving the FBI control over the tool could be argued at any point in the very long lifetime of this decision, be it tomorrow or years from now. Perhaps after the courts have decided to allow for multiple devices or when suspect X is holed up for weeks in their cabin eating pizza and playing candy crush and the FBI cannot reach them by normal investigative means.

> Pure tinfoil material here.

Perhaps. Consider the probable value of the data on the phone beyond what's already available externally. Consider that the FBI could have simply requested Apple provide the data on the phone instead of specifying the mechanism and thereby creating precedent that they can compel a company to create something new. Consider that, in spite of generally dim views of the FBI's technical capabilities, the FBI usually provides sound, conservative advice with regard to electronic evidence (as a forensic analyst I've been party to a lot). Consider that over the past year+ the FBI has been protesting with little effect in congressional hearings that $todays_crime_buzzword are "going dark", that technology companies need to cooperate with them, that "securely insecure" (my words) systems are possible if created "at the design level" (not my words). They were nearly shouted down in those hearings. Consider the subsequent public visit the FBI and others made to Silicon Valley, extending an olive branch and returning effectively empty-handed.

Then consider that this case, involving an older and still-vulnerable version of a technology the FBI has been warning about, suddenly falls into the FBI's lap. It's politically and emotionally charged, it involves terrorists - they can ask for the world and society will rubberstamp it "because terrorists."

So the FBI asks for something small but very specific, and in doing so "happens" to set a precedent that they can compel companies to create a new product to bypass the very security measures they've been arguing vehemently against. Do you really think that's accidental?

Re: FBI Director Comments on San Bernardino Matter

#123

> We simply want the chance, with a search warrant, to try to guess the terrorist’s passcode without the phone essentially self-destructing and without it taking a decade to guess correctly. That’s it. Bull crap. The FBI has it within their power to break the encryption in less than a decade by spinning up tens of thousands of EC2 GPU instances. Forcing Apple to develop products that don't yet exists is simply a choi…

No. https://www.reddit.com/r/theydidthemath/comments/1x50xl/time...

Re: FBI Director Comments on San Bernardino Matter

#124
post #114

Earlier quoted context omitted.

>I think you're applying some fairly strict high-mindedness to the US legal system while others (myself included) worry that creative extension of intent appears rampant in cases that touch on technology or terrorism and therefore fall into your second form. My main point related to this was above: >The only concern would seem to be if the future court fails to analyse a case properly. But they can fail regardless of…

> To argue against that, you'd need to claim that precedent makes it easier for the later court to fail. No, I'm arguing that incrementalism means the court doesn't have to fail (as a court) - the follow-on steps that I outlined and you found perfectly acceptable will not stop wherever you personally think they will, nor have I outlined (or even imagined) all the incrementally creative applications of this case that…

Three points.

> I'm also arguing (which you didn't counter) that this case lays the groundwork for the FBI to request _new_ products from companies.

I don't really have an opinion on that. I haven't commented much on whether they should have that power.

I think in this case, Apple would prefer to make it themself than be forced to hand over the code and keys to let the FBI make it. If Apple says "this is too hard for us", it's plausible that they'll need to do that instead. I have seen this point made elsewhere, but I'm not sure of its validity.

>Consider that the FBI could have simply requested Apple provide the data on the phone instead of specifying the mechanism and thereby creating precedent that they can compel a company to create something new.

My understanding was that the FBI asked for the data, Apple said "we can't do it", FBI countered with "Do X, Y, and Z, it is technically possible". Is my understanding incorrect? It sounded like the order needed to specify exactly what was to be done.

About the precedent point:

I think the proper response is to argue against specific details of the actual case (which you have with the point about forcing them to make a product). If you don't have specific objections against the actual case, but worry about precedent, then make explicit the difference between the specific case and the general one, and try to get that acknowledged by the judge. Introduce those arguments in briefs to the court, and try to make it very clear to a future court what the limits of the precedent set should be.

If you haven't imagined what could go wrong, then don't reject something because of unknown dangers. It seems to be born of a lack of trust in future courts, but there's no particular reason to distrust future courts over current ones.

(If you happen to know any philosophy of law articles that discuss this topic, I'd love to see them.)

Re: FBI Director Comments on San Bernardino Matter

#125
post #124

Earlier quoted context omitted.

> To argue against that, you'd need to claim that precedent makes it easier for the later court to fail. No, I'm arguing that incrementalism means the court doesn't have to fail (as a court) - the follow-on steps that I outlined and you found perfectly acceptable will not stop wherever you personally think they will, nor have I outlined (or even imagined) all the incrementally creative applications of this case that…

Three points. > I'm also arguing (which you didn't counter) that this case lays the groundwork for the FBI to request _new_ products from companies. I don't really have an opinion on that. I haven't commented much on whether they should have that power. I think in this case, Apple would prefer to make it themself than be forced to hand over the code and keys to let the FBI make it. If Apple says "this is too hard for…

Thanks for working with me, I understand your point about distrusting future courts over current ones.

I don't think it's too hard for Apple to do this; they could probably turn out the request in very short order. However, as soon as they let this go and do that very thing, their legal obligations skyrocket as thousands of cases pour in; in truth, my cynical conjecture is that this is the very reason Apple is fighting this fight. Not for the consumer, but to minimize the very real cost associated with satisfying this kind of request. The Secure Enclave is likely as much a legal defense for Apple as it is a technological one for the consumer. Whatever the motivation, in this case the consumer seems to win.

I must admit I don't disagree with the specific details of the actual case. What I draw exception to is the specificity of the ruling (dictating how Apple does business) and the precedent it sets of enabling courts to force a company to create. That exception is exacerbated by this case's proximity to the FBI's very recent and very real behavior regarding cryptographic systems.

Re: FBI Director Comments on San Bernardino Matter

#126
post #113

Earlier quoted context omitted.

Apple _will_ be compelled. You either don't understand the US legal doctrine of stare decisis or are being intentionally obtuse. Furthermore, the US legal system encourages elaboration on stare decisis, applying prior case law to novel cases rather than hashing out new decisions. This means that creative applications of this ruling ("give me an uncontrolled backdoor") are simply a question of time once the landmark c…

considering that the single-use nature of this exploit is a fundamental part of the ruling (and of the validity of the search warrant itself), you would not be able to use precedent to just get an uncontrolled backdoor.

Whether the exploit is single-use, about a phone, Apple, the 5c, or any other specific parameters is fundamentally irrelevant.

What this case is doing is setting precedent that the courts can compel a company to _create_, no matter how trivial one may think that creation may be today. _That_ is the precedent so many draw exception to, because stare decisis is also a doctrine of incrementalism, of gradual expansion of interpretations. Today Apple is compelled to create a very controlled firmware; who's to say in the figurative tomorrow that Samsung won't be compelled to create and send a firmware update to a specific Blu-Ray player that creates an air microphone out of the laser? Where does it stop?

To be complete (as was pointed out in another sibling thread) incrementalism may be curtailed if implications are carefully argued and acknowledged by the judge. I am skeptical of the value of that approach, but have no hard argument against it.

Re: FBI Director Comments on San Bernardino Matter

#127
post #120

> We simply want the chance, with a search warrant, to try to guess the terrorist’s passcode without the phone essentially self-destructing and without it taking a decade to guess correctly. That’s it. Bull crap. The FBI has it within their power to break the encryption in less than a decade by spinning up tens of thousands of EC2 GPU instances. Forcing Apple to develop products that don't yet exists is simply a choi…

> Bull crap. The FBI has it within their power to break the encryption in less than a decade by spinning up tens of thousands of EC2 GPU instances. How? They either need to break the PIN or they need to break the AES256 key that is used to encrypt file metadata. They cannot use EC2 GPU instances to attack the PIN because the function that derives the AES key from the PIN uses a key that is unique to each phone and no…

[deleted]

Re: FBI Director Comments on San Bernardino Matter

#128

Earlier quoted context omitted.

Forcing him how? If he came back with nothing, that's his answer. The answer of the American people. Perhaps he should learn what no means.

Except the American People also gave him the job to following any and every possible lead. There is a fundamental conflict with how law enforcement and intelligence does it's job and the way people communicate today. Period. If people want more secure communications they are going to have to tell the FBI in no uncertain terms "we are ok with you dropping leads." Apparently in this specific case that has happened as a…

Some victims are being represented pro-bono in a case against Apple [1]

[1] http://www.reuters.com/article/us-apple-encryption-victims-e...

There should be more discussion. Tech companies should seek to understand the government's job to keep people safe, and the government needs to understand that this is a game of whack-a-mole they can't win

Re: FBI Director Comments on San Bernardino Matter

#129
post #127
post #120

Earlier quoted context omitted.

> Bull crap. The FBI has it within their power to break the encryption in less than a decade by spinning up tens of thousands of EC2 GPU instances. How? They either need to break the PIN or they need to break the AES256 key that is used to encrypt file metadata. They cannot use EC2 GPU instances to attack the PIN because the function that derives the AES key from the PIN uses a key that is unique to each phone and no…

[deleted]

AES256 has 115, 792, 089, 237, 316, 195, 423, 570, 985, 008, 687, 907, 853, 269, 984, 665, 640, 564, 039, 457, 584, 007, 913, 129, 639, 936 possible keys (I've put spaces after the commas to allow HN to wrap because HN can have trouble with long strings lacking whitespace).

Suppose Amazon has some kind of super GPU that can try 1 trillion (10^12) keys per clock cycle, and rans at 1 THz (!0^12 Hz). Note that both of these far exceed any actual GPUs.

Suppose Amazon has a trillion of these available and you use them all. To search that entire key space would take 3669308250866118434801967410403995 years. On average you only have to search half the key space, which cuts this 1834654125433059217400983705201998 years.

Assuming that this computation can be done super efficiently...so efficiently that for each key tested only a single bit actually has to irreversibly change state, and that we are doing this in a system cooled by liquid helium, it would need a minimum amount of energy equal to the entire energy output of the Sun over 3.6x10^20 years. (I don't remember if that is worst case or average, so let's be generous and call it only 1.8x10^20 years worth of total solar energy output).

Re: FBI Director Comments on San Bernardino Matter

#130
post #127
post #120

Earlier quoted context omitted.

> Bull crap. The FBI has it within their power to break the encryption in less than a decade by spinning up tens of thousands of EC2 GPU instances. How? They either need to break the PIN or they need to break the AES256 key that is used to encrypt file metadata. They cannot use EC2 GPU instances to attack the PIN because the function that derives the AES key from the PIN uses a key that is unique to each phone and no…

[deleted]

Do you understand what "two raised to the 256th power" means? No, you can't bruteforce AES-256 in years or decades, even if you owned Amazon and were willing to use all the servers for this.
Post reply on HN