New York DA Wants Apple, Google To Roll Back Encryption (tomsguide.com) 254
An anonymous reader writes: Manhattan District Attorney Cyrus Vance Jr. called on Apple and Google to weaken their device encryption, arguing that thousands of crimes remained unsolved because no one can crack into the perpetrators' phones. Vance, speaking at the International Conference on Cyber Security here, said that law enforcement officials did not need an encryption "backdoor," sidestepping a concern of computer-security experts and device makers alike. Instead, Vance said, he only wanted the encryption standards rolled back to the point where the companies themselves can decrypt devices, but police cannot. This situation existed until September 2014, when Apple pushed out iOS 8, which Apple itself cannot decrypt. "Tim Cook was absolutely right when he told his shareholders that the iPhone changed the world," Vance said. "It's changed my world. It's letting criminals conduct their business with the knowledge we can't listen to them."
And you shouldn't be.... (Score:5, Insightful)
You shouldn't be able to listen to them... you shouldn't be able to listen to anyone. Try doing your job the old fashioned way... outsmart them.. stop trying to take short cuts at the expensive our our rights and liberties...
But hey.. that's just my opinion
Re:And you shouldn't be.... (Score:5, Insightful)
The "bad guys" will still find that classic abandoned warehouse across the train tracks and plot their evil in the veil of darkness. Perhaps we should require spotlights and mandatory cameras over every square inch of the planet too?
"Register your crimes! It's the law!" (Score:5, Insightful)
One problem time and again is that crypto only works for "the good guys" (which may or may not include LEOs, this is not automatic) if it isn't diddled, and therefore it also works for "the bad guys", whoever those might be. This is well-known in "intelligence"-land, but the concepts that are well-known and -understood there, quite certainly aren't in, oh, LEO land. Or the land of the liars, er, politicians. Or much anywhere else, really. Something that will have to change, thanks to information technology and world-wide networks.
Another problem is that the LEOs are now the tail wagging the dog. Maybe they should re-read the Peelian principles, instead of fancying themselves the militarised "command and control" hub of society.
Re:"Register your crimes! It's the law!" (Score:5, Interesting)
A security guy (admittedly someone random on the internet) mentioned the relative ease with which criminals can make their own communications and storage apps (or have them made). Apps which due to their custom nature render trying to strongarm the (now sidelined) 'big guys' into weakening their encryption completely useless.
In fact, the possibilities for any serious criminal network to create their own secure communications channels and data storage are so mindbogglingly vast that the only criminals the current situation is 'letting [...] conduct their business' are pretty obviously small time or just stupid drug dealers. Hardly the type of criminals envisioned when urged to give up the basic human right of privacy.
Re: (Score:3)
I'm sure we can come to an agreement. If the government rolls back the Patriot Act, for example, then maybe we look at rolling back encryption.
Re:And you shouldn't be.... (Score:5, Insightful)
Perhaps we should require spotlights and mandatory cameras over every square inch of the planet too?
Please, for the love of all that is holy: stop giving them ideas!
Re:And you shouldn't be.... (Score:4, Insightful)
Think of the children!
Don't censor this worthwhile idea.
Re:And you shouldn't be.... (Score:4, Insightful)
They already do my friend...
You own a cellphone, tablet, laptop?
They got us covered.
That's why all personal portable electronics are banned from classified government spaces.
Re:And you shouldn't be.... (Score:5, Funny)
Hillary's email was intercepted by the Russians at the request of Trump, and forwarded off to Wikileaks.
Re:And you shouldn't be.... (Score:5, Funny)
I'll turn on Fox News for the fair and balanced report!
Re: (Score:2)
Perhaps we should require spotlights and mandatory cameras over every square inch of the planet too?
Don't the Brits already do that? CCTV on every corner with car tag readers? You folks don't think MI-5 is not harvesting oll of this stuff in real time and tracking cars and people?
Re: (Score:2)
Ah... but the difference is that at least the populous knows about those cameras!
I'd be more worried about the hidden camera in my outhouse, my woodshed, and my dog house (never can trust some breeds).
Re: (Score:2)
"populace"
Re: (Score:2)
populace...
Heh, that's a good catch, slightly different words there. Must have never had that word on a spelling test in school - dern publik skoool sistem!
Re: (Score:2)
The "bad guys" will still find that classic abandoned warehouse across the train tracks and plot their evil in the veil of darkness. Perhaps we should require spotlights and mandatory cameras over every square inch of the planet too?
The problem has never been all that hard for the authorities: They have always known that to snag all the bad guys, they only have to monitor the small subset of warehouses that are built on a slanted "Dutch angle".
Re: (Score:2)
The "bad guys" will still find that classic abandoned warehouse across the train tracks and plot their evil in the veil of darkness. Perhaps we should require spotlights and mandatory cameras over every square inch of the planet too?
The problem has never been all that hard for the authorities: They have always known that to snag all the bad guys, they only have to monitor the small subset of warehouses that are built on a slanted "Dutch angle".
Accomplished criminals know to conduct all their dealings via email with a lawyer and label all communication "Attorney Client Privileged".
Re: (Score:3)
> That would make everyone safer and be much gooder.
. . . and be much MORE gooder.
Although 'goodly', or 'goodfully' are also considered to be acceptable alternatives.
Re: (Score:2)
Much more good doubleplus gooder
Re: (Score:2)
I recall something about throwing stones in glass houses not being conducive to one's health...
Re: (Score:2)
We should only allow clear plastic clothes...
Ah! The true reason behind American obesity: Security through disgust.
Re: (Score:2)
Fixed.
Re:And you shouldn't be.... (Score:5, Insightful)
I think it is more to the point. We as a culture should be brave enough to say We are willing to take these security risks in order to protect our privacy.
The people who work in security are doing their job. And it is their responsibility to ask for things and changes that will make their job more effective, I don't blame them for the request.
However we seem to lack the fortitude to go to these people and say, no that is asking a bit too much, I know it isn't ideal but we need to keep people's freedom as well, at the expense of ideal security.
Re:And you shouldn't be.... (Score:5, Insightful)
at the expense of ideal security.
*Having a backdoor into any encryption is not ideal security*, as that back door, or weak encryption is equally, if not more so, vulnerable to the bad guys as well.
What makes you think only the good guys will use backdoors or exploit weaker encryption? What if it's a bad guy that gets ahold of the cops phone and looks inside? Which agency will be compromised?
Bad guys often have better equipment than the good guys and by bad guys I am also including foreign nations, mafia, competing corporations, and Militaries of the world in addition to criminals.
When will people get it through their heads that the same tools are used by both good and bad? Good people with guns stop bad people with guns. But bad people with guns also stop good people with guns. Good encryption can be used to protect bad people, but good encryption can also protect the good people.
The catch here is the bad people won't care about artificial constructs such as laws. If they need a gun they will steal one or make one. If they want to cover their tracks online they will find a way to do it. The rest is just FUD and ignorance.
Re:And you shouldn't be.... (Score:4, Insightful)
There's really not much risk here. They're trying to play the fear card too much. It wasn't long ago when we didn't have smart phones with encryption. It is so recent that even a millenial can remember those days. And was it a world where all criminals were captures, all crimes solved, people were always safe and secure? No! Rates of violent crime were higher. Criminals still figured out how to talk to each other securely without the FBI listening in. We had organized crime operating with impunity for long periods of time, they even figured out how to use encryption.
There's nothing law enforcement can do to put this genie back in the bottle. One simple app to do a pgp style communication and encryption is back no matter how many back doors the manufacturers put in (or get a warrant to get the phone maker to stick on keyloggers, but everyone's going to avoid those phones like the plague once word is out). Use some third party SOCs from outside America as your key dongle on the PC and you can detect tampering and destroy your keys.. There's just no way they can lock this down.
We have some phones locked tight that may or may not contain evidence about crimes. So what?? This is not a disaster. We've never had a time when we could gather all possible evidence, search everywhere we liked, and solve all crimes. Claiming that it's wrong that they can't open up the phones and get the data from them is like whining that the parrot at the crime scene isn't talking.
Re: And you shouldn't be.... (Score:4, Insightful)
My response would have just been a middle finger followed by "Next subject."
Really, it no longer deserves any consideration at this point.
Re: (Score:2)
Your response isn't extreme enough. The guy needs to be fired for incompetence. Unfortunately, he would likely end up on HRC staff
Re:And you shouldn't be.... (Score:5, Interesting)
This DA seems to be implying that pre-iPhone, his predecessors closed all their cases.
That kind of track record doesn't bode well for him. Is that really something he should be calling attention to? That his predecessors got results, but that his current office doesn't.
"Look! A squirrel!" (Score:2)
This DA seems to be implying that pre-iPhone, his predecessors closed all their cases.
"Look! A squirrel!"
(Sneaks quietly away from the podium, as all the domesticated grows look around wildly to see past their cones of shame...)
Re: (Score:3)
I gotta admit, that's what bothers me about his statement:
[...] thousands of crimes remained unsolved because no one can crack into the perpetrators' phones.
How do you know they're the perpetrator?
Re: (Score:2, Informative)
at the expense of our
Is this a new bit of illiteracy, or is it derived from the "intensive purposes" illiteracy?
Re:And you shouldn't be.... (Score:5, Insightful)
I realize that I phones are absurdly thin, but a typical audio bug is very tiny. If you can obtain a search warrant to search the phone, you can obtain a warrant for a ln authorised bug. Bugs take many forms, and can do many things. For instance, some can record the local EMI from a device, and then reproduce the activity of that device from that produced noise. That includes screen taps, gestures, etc.
Put one of those in, let it record away, then arrest the perp, collect the bug, analyze its contents, then use the analysis to unlock the phone for further data retrieval.
The real deal here is that the da does not want to have to physically bug the phones in question. He wants to arrest on weak charges, then go fishing.
Re: (Score:2)
People shouldn't be able to listen to HIM.
I agree, those guys [wikipedia.org] suck!
How were crimes solved before cell phones? (Score:5, Insightful)
Many law enforcement leaders are acting as if no crimes can be solved unless all cell phones are made more vulnerable.
What a great idea.... weaken everyone for a few rare cases.
Re:How were crimes solved before cell phones? (Score:5, Insightful)
> What a great idea.... weaken everyone for a few rare cases.
That's the norm in big gov't.
Some people use guns to commit crimes? Let's ban them, or at least severely restrict them!
Some people can't dispose of plastic bags? Ban them for everyone!
Terrorists took over some planes? Let's enact crazy "security" that can't actually catch anything, treats everyone like a criminal, and make sure we grope kids and grandma so we don't look like we're profiling.
Re:How were crimes solved before cell phones? (Score:5, Funny)
Banning planes would have been easier.
Re: (Score:2)
You can't just throw them in the trash and let the garbagemen take them away??
What's wrong with that...?
Re: (Score:2)
What's wrong with that is that they end up in a landfill or somewhere in the middle of the Pacific Ocean.
Re: (Score:2)
And?
They take up less space in a landfill than paper bags.
If you care, you be you, and bring your own bag. That's no justification to involve men with guns to enforce your preference.
Re: (Score:2)
Those evil "garbagemen" take those bags and tie them around the throats of poor, innocent dolphins, you insensitive clod!
Strat
Re: (Score:2)
The council couldn't take them even when they were taking plastic in.
There's your problem: If you have "the council", then you live in the UK, where they lack both Euros and technology. The rest of us have no problems recycling plastic. We could teach you how, all it requires is some electricity... er... does the UK have electricity?
Yes, Google assures me that 31% of their electrical grid is powered by coal, and another 31% is powered by gas. The UK has electricity. They are in theory capable of recycling plastic.
But if you insist on having reusable shopping bags, I have
Re:How were crimes solved before cell phones? (Score:5, Funny)
That's how Billy the Kid got off... they tried him for shooting Sheriff William Brady, but he was acquitted because his iPhone was encrypted and they couldn't get at the data. They even tried getting Steve Jobs' great grandfather involved, but the sonofabitch insisted that he didn't even know what a cell phone was, much less how to remove the encryption from one.
Julius Rosenberg also went free because they couldn't decrypt his thumb drive to prove he was spying for the Soviets.
At least that's the impression I get from listening to these assholes whining that they can't spy on all of us 24/7.
Re: (Score:2)
Bombard them with "trigger words" in all your e-mails and other communications
Re: (Score:3)
I'm sure that if Jesus had simply handed over his GodPhone to the Pharisees, they would have realized he was not a threat to them and let him go in peace. At least then they could have asked the Man upstairs using Facetime.
Re: (Score:2)
Race to the bottom...
Re: (Score:2, Interesting)
Devil's advocate: How were crimes committed before cell phones? The old telephone system could be tapped. Letters could be intercepted. If people had to meet physically, they could be followed physically. These channels of communication are decreasing in popularity and are being replaced by a system that isn't as easy to spy on. This is probably a good thing overall, but it's making it more difficult for law enforcement to do that part of their jobs.
Many law enforcement leaders are acting as if no crimes can be solved unless all cell phones are made more vulnerable.
Are they? It looks like they're actually complaining that
Re: (Score:2)
Re: (Score:2)
Many law enforcement leaders are acting as if no crimes can be solved unless all cell phones are made more vulnerable.
Before Telephones; you could tell who someone was communicating with by monitoring their physical movements on foot. Telephones would have made that harder..... Until wiretapping became a thing that was allowed.
Ubiquitous technology, And "Ease of Snooping" made law enforcers' lives easier at investigating crimes than it ever was before Telephones were invented.
At this point th
Re: (Score:2)
Re: (Score:3)
Many law enforcement leaders are acting as if no crimes can be solved unless all cell phones are made more vulnerable.
There are a couple glaring problems that come to mind immediately when I read statements like the one the DA made:
1) They are claiming that having access to the phones would let them solve the crimes. While that may be true in some cases, it's certainly not a given. Look at the San Diego shooter's phone - when they finally got in, there was nothing worthwhile on it.
2) They are implying this is their only recourse. But if they have enough evidence to get a warrant, they can lock up the suspect if he/she does
Bullshit (Score:4, Interesting)
So what you can't listen to them? Have these guys never heard of police work? Here's a hint, it's not synonymous with spying. If you can't follow the money, them the crime is probably too petty to worry about.
Re: (Score:2)
Morons got government jobs!!! (Score:3, Informative)
It's the law enforcement's job to handle the criminals... if they need help, send their people to more technical education. Companies have only one job: To satisfy their customers... and if they can't do that, nobody will buy the stuffs, period!!!
Re: (Score:2)
Companies have only one job: To satisfy their customers... and if they can't do that, nobody will buy the stuffs, period!!!
What kind of fairy land do you live in?
Companies exist to make money.
If Apple decided to go back to non-encrypted devices I can pretty much guarantee that the masses wouldn't care one bit and iPhone sales would continue on as though nothing had happened. All most people care about is "can it run my pokemon game?"
Not saying they should do that. I just think your viewpoint is a bit idealistic.
No such thing as Apple-only backdoor (Score:4, Insightful)
Re: (Score:2)
http://gizmodo.com/you-can-now... [gizmodo.com]
Re:No such thing as Apple-only backdoor (Score:4, Informative)
The whole thing is an oxymoron
law enforcement officials did not need an encryption "backdoor," sidestepping a concern of computer-security experts and device makers alike. Instead, Vance said, he only wanted the encryption standards rolled back to the point where the companies themselves can decrypt devices
Making encryption standards so weak so that the company/person writing the software, can bypass them, is the very definition of a back door.
Re: (Score:2)
Re: (Score:2)
I'd like Cyrus Vance to have all of his personal conversations posted to the Internet.
Re: (Score:2)
No back-doors to my personal devices (Score:4, Insightful)
Re: (Score:3)
You can absolutely listen to their conversations and see their text messages. All you need is to convience a Judge to approve a wiretap order and the Carriers will let you spy to your hearts content.
If you're using an encrypted VoIP app or email to communicate, the carriers don't have access to the data either.
Not that I'm siding with this asshat. I'm just saying...
Re: (Score:2)
That's not unique to cellphones though. That's how general computing devices work on the internet. They are asking specifically for phones though so that's a bit odd in this case I think.
I think it's just a case of some LEO not understanding how technology works.
You mention all general computing devices work this way, and a smartphone is really just a small handheld computer, but he's not asking for computer encryption standards to be changed.
Trust No One (Score:3)
I do not trust big business with the ability to de-crypt my data any more than the government. Both entities are not interested in protecting you, but their bottom lines and political interests. The right to privacy means privacy from anyone!
If only (Score:3)
we could trust that Law Enforcement wouldn't abuse such a thing.
That sort of abuse is what got us here to begin with.
So you need to ask yourself: Whose fault is it you can't decrypt these things again ?
You reap what you sow . . . . . .
Re: (Score:2)
Ok. (Score:2)
We'll get right on that.
-Apple and Google
Re: (Score:3)
Your sig is outdated, bro.
Glad to hear it. Now, can I see the police files. (Score:5, Insightful)
Glad to hear he thinks we don't need privacy.
Now I have a long list of police files and videos I would like to see.
Wait, you mean you don't want us to see those? But thousands of accusations against police are going unsolved without access to them!
This unsolved crimes include yours (Score:4, Insightful)
We live in such a complex web of laws now that we are all breaking them every day... so if the government can on demand browse through your phone they WILL find evidence of some crime. Especially Slashdot readers I'd warrant.
So basically what the government wants is an easy way to harass or lock-up anyone it deems a nuisance for any reason,
Translation (Score:2)
Fuck you, no. (Score:2)
You heard me.
Thousands? (Score:2)
Thousands of crimes? THOUSANDS? What crimes are these that you can only solve if you are able to look at people's phones?
Re: (Score:2)
Re: (Score:2)
Good (Score:2)
It's letting criminals conduct their business with the knowledge we can't listen to them."
Good. That's not something that law enforcement should be able to rely on any way.
Re: (Score:2)
Now if you citizens would only let us put microphones on you to record everything you say, and a body cam to record everything you do, and make all the data available to police, we'd all be safer!
Why do you hate safety? What are you doing behind closed doors? If you aren't guilty, you have nothing to worry about!
Say... your teen daughter might be a terrorist. We need to review her shower footage again.
Vulnerability and trust issues (Score:2)
...thousands of crimes remained unsolved because no one can crack into the perpetrators' phones....
I have two strong concerns about the proposal in front of us.
.
1) vulnerability - reducing the encryption level for the phones affects not just criminals but everyone. Phones can (and are) used for very legitimate purposes and those phones need secure encryption. Once the encryption is weakened for criminals' phones, the encryption is weakened for all our phones.
2) trust - once the police have the ability to "crack" into criminals' phones, what is to stop them from "cracking" into anyone's phone (in a
The police must not be able to solve every crime (Score:5, Insightful)
Otherwise you have a full-blown Police State and that is far, far worse than almost any amount of unsolved crime. In a free state, the police must be severely limited in what it can do and must be kept at a level of power that allows them to reliably keep society functioning, but never above.
Thousands of crimes remained unsolved... (Score:4, Insightful)
thousands of crimes remained unsolved because no one can crack into the perpetrators' phones
is exaggerated speculation at best. There may well be thousands of crimes that include locked phones in their set of evidence, but there is no guarantee that data on those locked phones would lead to the crime being solved if it were unlocked. It's also possible that many of those crimes could be / will be solved eventually using other pieces of evidence and investigative avenues.
Re: (Score:2)
SubjectsInCommentsAreStupidCauseTheSubjectIsTFA (Score:2)
AES128 it is!
Dear pigs, (Score:4, Insightful)
Earn your pay instead of putting innocent citizens in danger.
People have a right to secure communications.
Deal with it bullies...
Contradicting himself! (Score:2)
In essence, what he's saying is: "We don't want a back door. We just want a back door!" Weakened encryption *is* a back door! And more than even the usual back door, it's a back door available to everyone! (Although that's true to some extent of every back door.)
imagine where it goes (Score:5, Insightful)
And, for that matter, wildly differing capabilities to securely handle and keep private the information they find on people's phones.
No thank you, and Apple is right to refuse them.
apple can turn off the auto wipe / time out system (Score:2)
apple can turn off the auto wipe / time out system and let the login take a usb keyboard.
My dog would really like a pony, too. (Score:2)
My dog would really like a pony, too. Sometimes the world doesn't work the way we want for our own little special interests. The politicians all rant and rave about special interest groups. What's a more special interest than wanting to weaken security of everyone worldwide just so your job is a little easier?
Magical missing (D) (Score:2)
Good 'ol Vance Jr has been fucking up the country since Carter.
And he's doing it wrong too. Hey Cyrus; all need to persuade the bulk of these hapless government worshiping twits that your back door is a great idea is to convince them that you need it to prosecute wealthy tax evaders. Unbreakable iPhones are a tool of Those At The Top(tm) to keep from Paying Their Fair Share(tm).
You can still listen to them (Score:2)
Is it just that you don't want to give up the ease and lack of oversight on push button eavesdropping and stingray mass interceptions?
I doubt it's an issue regarding the cost of developing a police smartphone eavesdropper app, after all, those stingrays aren't cheap and I'm betting you have at least one of those.
Crimes will always go unsolved (Score:2)
thousands of crimes remained unsolved
That will always be the case crimes go unsolved, it is about having a balance between personal rights and solving crimes. Imagine how much easier if there was a video camera everywhere. Rape would no longer be a matter of who you believe, we would have video evidence of the incident. But we need to balance privacy with catching every offender.
Well gee darn, officer... (Score:4, Informative)
Vance said. "It's changed my world. It's letting criminals conduct their business with the knowledge we can't listen to them."
They can do that in an empty theater, a subway car, a taxi, a sewer... or in simple, pre-arranged, spoken code-phrases you'll have EVEN LESS CHANCE OF CRACKING. So it's "changed your world." Ala, forced you to think about hiring cops capable of doing actual investigative police work? You mean, like, when people used codes the police couldn't crack just 15 years ago, except they were written on paper, or ciphered into the actual text? You mean like when they spoke languages few if any other people spoke? You mean like back in the day when cops were expected to solve crimes with actual police-work, instead of relying on broad, warrantless searches of people's private property and communications with no restraint on the part of the police, who would instead prefer to violate the Constitution they swore an oath to uphold with the use of Stingray devices and the like just to nab an easy collar?
Frankly, if your only avenue for solving crime is bottomed on your ability to read the contents of people's private messages and cellphones, you should quit because you're an awful police officer with no ability or skill to solve crimes the way our nation of laws intended them to be solved: without violating people's equal rights, all because "but... crime!!1 Terrorism!1! 9/11!!!one" Even if I believed that giving you what you wanted wasn't a civil rights violation and was in the best interests of the public, the fact of the matter is that it would change nothing: the criminals would simply find other means and avenues, and frankly I seriously doubt such access is a relevant factor in even 1 out of 100,000 cases anyway, especially since your record of solving crimes has not improved in the least bit during the periods when you had this access, or since you've started illegally using stingray devices, even though overall crime rates have been on a downward tick for the last couple of decades.
Apple, Google want... (Score:4, Interesting)
Apple, Google want New York DA to roll back police shootings.
Guess neither of them gets what they want, right?
In other news.... (Score:3)
New York DA wants all citizens to be entirely naked at all times. Quote: "It isn't fair, clothes have pockets that people could be concealing weapons in."
Next request... (Score:2)
Next request...
DA: "We have the decryption keys; but that's not enough."
Person: "Why not?"
DA: "It's an asymmetric cypher."
Person: "So? You can decrypt it, and read what's there; what more do you want?"
DA: "We also need the encryption keys."
Person: "Why?"
DA: "With the decryption keys, we can only find what's there; we can't find what's not there... yet."
This just in (Score:2)
JThundley wants New York DA to get on knees, swallow hot sticky load.
Erroneous assumption (Score:2)
I wonder how long... (Score:3)
lazy days (Score:4, Insightful)
Its crazy how lazy these people have become. Its way to much trouble for them to actually do their job. They just want to be able to cheat and skip to the end.
Re: (Score:2)
"At THE fear the reaper"
Needs more cowbell.
Re: (Score:2)
Psst, you're in the wrong thread.
Re: (Score:2)