Live data from Hacker News

What It's Like When the FBI Asks You to Backdoor Your Software

securitywatch.pcmag.com

21–30 of 37 posts

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#21

Sounds more like a marketing sham than a real FBI encounter to me. Really? The FBI agent approached her and started talking to her before she had even removed her mic? And everybody (including the agent) heard? Let me guess, she vehemently denied the offer? (I'll admit I didn't even bother to read past the second paragraph of this "article".) I don't think so...

Yeah it reads like a PR puff piece. I am sure that is what it is. It follows the template described in http://www.paulgraham.com/submarine.html.

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#22
post #19

Earlier quoted context omitted.

Bit of a risk, considering that impersonating a federal employee is a felony.

Impersonating a federal employee, as itself, is not a felony. Otherwise David Duchovny should have been arrested for impersonating an FBI agent in The X-Files and John Ratzenberger for impersonating a postal service employee in Cheers. The law is in 18 U.S. Code sec. 912: Officer or employee of the United States: > Whoever falsely assumes or pretends to be an officer or employee acting under the authority of the Unit…

Note that the "something of value" does not have to be tangible. Information has been held sufficient. See United States v. Sheker, 618 F.2d 607, where all that was done was ask about someone's location.

If this was done to ascertain information about the company, and their willingness to participate in government surveillance, it is likely to be held "a thing of value" under such precedent (which explicitly holds that things with value in the broader senses of the word count under the statute)

As a pragmatic approach, it is unlikely you are going to be find judges willing to let you slide on this kind of thing :)

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#23
I don't trust any of them. Period. It makes absolutely no sense to trust any of them. Not when peoples lives are at stake.

At this point, if I wanted to use my phone for any truly critical communication (e.g. like in middle eastern countries where lives are literally at stake), I'd only use open source software.

You could start a company that had the all of following people as founders:

  Ron Rivest
  Adi Shamir
  Leonard Adleman
  Phil Zimmermann
  Whitfield Diffie
  Martin Hellman
  Dan Bernstein
  Bruce Schneier
  Edward Snowden
  Keith Alexander
  Theo de Raadt
Even if every single one of those people were telling me to trust the software, I still wouldn't. Not without source.

Show me the source code. At first glance, I didn't see that option as available at the Wickr web site.

BTW stupid of Wickr to not obtain the wickr.com domain. I'll let people google for the real URL just to make my point.

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#24
post #19

Earlier quoted context omitted.

Impersonating a federal employee, as itself, is not a felony. Otherwise David Duchovny should have been arrested for impersonating an FBI agent in The X-Files and John Ratzenberger for impersonating a postal service employee in Cheers. The law is in 18 U.S. Code sec. 912: Officer or employee of the United States: > Whoever falsely assumes or pretends to be an officer or employee acting under the authority of the Unit…

Note that the "something of value" does not have to be tangible. Information has been held sufficient. See United States v. Sheker, 618 F.2d 607, where all that was done was ask about someone's location. If this was done to ascertain information about the company, and their willingness to participate in government surveillance, it is likely to be held "a thing of value" under such precedent (which explicitly holds th…

Thank you for pointing that out. "I am not a lawyer" and all that, but I do enjoy, oddly enough, reading judicial decisions.

That one says:

> We do not embrace the government's sweeping position that 18 U.S.C. 912 extends to anything that has value to the defendant. Such a broad reading of "value" negates any limitation the word could imply. By the same token, we cannot accept Sheker's suggestion that 18 U.S.C. 912 covers only things having commercial value. Information can be a thing of value. Whaley v. U. S., 324 F.2d 356 (9th Cir. 1963). In normal English usage commercial worth is not the exclusive measure of value. For instance, state secrets might trade hands without cash consideration. Information obtained for political advantage might have value apart from its worth in dollars. In each case the information sought would have value to others, in addition to the seeker. Such is the case here. Stokes would see value in keeping his whereabouts unknown to Sheker. The criminal justice system, concerned with the safety of witnesses, has a similar interest.

(In Whaley, Whaley impersonated an agent of the F.B.I and got information which he later paid paid $9, if I interpreted it correctly. Thus the information definitely has commercial value. In Sheker, the judge extends that to value other than commercial value.)

The information sought here is "is Sell (or Sell's company) willing to provide a back-door to the FBI?" This is just after Sell stated publicly that the "service wouldn't have a backdoor for anyone."

I honestly can't tell if this is a "thing of value."

If the answer is "yes", then I think that's a thing of value. That information might be revealed later to embarrass or otherwise affect Sell's company.

If the answer is "no", then there's no value. The statement to the public is the same as the statement to the alleged impersonator.

Given the context, it seems very likely that most people would have expected Sell to say "no." Thus, the overall value is very low.

It can't be that asking a question where the answer isn't already 100% known is illegal. The judge says that the law doesn't '[extend] to anything that has value to the defendant'.

But I don't know how that line is drawn.

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#25

I don't trust any of them. Period. It makes absolutely no sense to trust any of them. Not when peoples lives are at stake. At this point, if I wanted to use my phone for any truly critical communication (e.g. like in middle eastern countries where lives are literally at stake), I'd only use open source software. You could start a company that had the all of following people as founders: Ron Rivest Adi Shamir Leonard…

How do you compile your code? (Thompson reflections on trusting trust)

And beyond source-code:

How do you shield your equipment? (tempest, also active attack)

How do you guard your equipment? (evil maid)

Real life is the triumph of convenience over security :(

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#26

I don't trust any of them. Period. It makes absolutely no sense to trust any of them. Not when peoples lives are at stake. At this point, if I wanted to use my phone for any truly critical communication (e.g. like in middle eastern countries where lives are literally at stake), I'd only use open source software. You could start a company that had the all of following people as founders: Ron Rivest Adi Shamir Leonard…

How do you compile your code? (Thompson reflections on trusting trust) And beyond source-code: How do you shield your equipment? (tempest, also active attack) How do you guard your equipment? (evil maid) Real life is the triumph of convenience over security :(

[deleted]

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#27

I don't trust any of them. Period. It makes absolutely no sense to trust any of them. Not when peoples lives are at stake. At this point, if I wanted to use my phone for any truly critical communication (e.g. like in middle eastern countries where lives are literally at stake), I'd only use open source software. You could start a company that had the all of following people as founders: Ron Rivest Adi Shamir Leonard…

How do you compile your code? (Thompson reflections on trusting trust) And beyond source-code: How do you shield your equipment? (tempest, also active attack) How do you guard your equipment? (evil maid) Real life is the triumph of convenience over security :(

Convenience is exactly what I use in my real life. My texting security is whatever Apple implements in iMessage. I'd be a lot more paranoid if I were a "smuggler" or "revolutionary".

There's also the wrench cryptanalysis discussed in xkcd.com/538. For most people the mouseover text nails it:

  Actual actual reality: nobody cares about his secrets.

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#30

I don't trust any of them. Period. It makes absolutely no sense to trust any of them. Not when peoples lives are at stake. At this point, if I wanted to use my phone for any truly critical communication (e.g. like in middle eastern countries where lives are literally at stake), I'd only use open source software. You could start a company that had the all of following people as founders: Ron Rivest Adi Shamir Leonard…

How do you compile your code? (Thompson reflections on trusting trust) And beyond source-code: How do you shield your equipment? (tempest, also active attack) How do you guard your equipment? (evil maid) Real life is the triumph of convenience over security :(

The fact that you can't have complete security is not an argument for abdicating the effort, nor a valid criticism of anything that moves in the right direction. At least you can get to a better position in terms of (a) lower probability of compromise and (b) imposing more time and expense on the adversary.
Post reply on HN