It needs to be pointed out more often that law enforcement still has all of the physical access methods that they've had for the past 200 years. If the government wants to break into your home or office, they can and will do so. No "technological advance" from Silicon Valley has made this type of investigation more difficult. This means that all of the investigative methods that were available 200 years ago are available now.
The government is demanding new powers: the power to search our communications. Perhaps the ability to conduct such searches will make their jobs easier, but keeping them from having this power does not make their jobs more difficult than the 200 year baseline. We are only asking them to do the same legwork that they've always done: look for suspicious behavior, track the purchase of dangerous materials, react to disasters and attacks when they happen, etc.
> keeping them from having this power does not make their jobs more difficult than the 200 year baseline.
I don't think that's entirely accurate. The problem is that the content they were looking for 200, 100, and even 20 years ago used to be physical. Now it's digital.
Previously when they searched your home, they'd be looking for physical evidence -- mail, letters, receipts, paraphernalia, what have you. Today, a lot of that information has moved to electronic devices, taking what was once safeguarded by your front door, and putting it behind a new electronic lock.
I'm not commenting specifically on what powers should or shouldn't be available to law enforcement, but I think it's pretty clear that the situation has changed from 200 years ago, and we should be making decisions in the current context.
Of the examples that you list above, I agree that communication (what would have previously happened with letters) has mainly moved to the net. To the extent that receipts have moved, the government has access (either directly or through a subpoena) to many forms of electronic records.
My original point was that in criminal cases, there is a treasure trove of physical evidence available to the government, and the value of this evidence has been under-weighted in discussions about encryption.
- If the suspect has dangerous equipment or substances at that location, then the government can gain access to and analyze those physical materials.
- If the suspect received deliveries to his address, then the government can get records from FexEx, UPS, USPS.
- If the suspect used a phone, the government can get access to carrier calls (I agree that this may not be possible for app-based calls).
- If the government finds credit cards used by the suspect (either by finding the physical card or by using the purchase history of any cars, residences, or other tools used by the suspect), then they can search the history of those cards.
It's more complicated than that, however. The amount of data contained in a phone is stunning. Communication logs, location logs, metadata - at no point in history was it so simple to obtain so much information from a single object. The standards for evidence collection need to be higher here.
> The government is demanding new powers: the power to search our communications.
That's not entirely accurate though. The United States has been allowed to search your mail and tap your phone if they have a warrant and there have been cases where it happened without a warrant.
They will, eventually, be shut out of the communications channel entirely due to encryption.
> The United States has been allowed to search your mail and tap your phone if they have a warrant and there have been cases where it happened without a warrant.
True. But the government never had a means to get the entire history of the bulk of your conversations. They could only install a wiretap after they suspected you of some crime, and even then it was a tedious process for them. Reading digital data is not tedious, it's instant. On balance, the idea of guaranteeing warranted access to encrypted data is a bad idea because it makes us less safe overall.
We put copies of everything into our phones these days. These are new powers that the government started to acquire when we all increased our PC and smart phone usage. We increased usage because we trusted the security systems designed by private companies. I did not start buying things online or banking online because the government kept those computer systems secure. I did it because the tech companies keep them secure. Data breaches cause customers to flee.
Tech companies have always been in an arms race against hackers and if we handcuff them in this manner they will not be able to fix weaknesses in their software as quickly as they do today. By definition of guaranteeing access to encrypted data, they will be required to maintain such weaknesses. It'd be catastrophic for our tech industry and my future as a software engineer.
>These are new powers that the government started to acquire
Why do people here persistently insist, even after being corrected, that the government's 228 year old authority to conduct warranted search and seizure is some kind of shadowy and scary "new power"?
The government has always had the right to look at your photos, listen to your calls, and read your mail, when you are legitimately suspected of a crime.
Nowadays all those things are on your phone, so the government has the right to search your phone, when you are legitimately suspected of a crime.
Nothing about this is in any way new, and it's grossly dishonest to continue to claim that it is.
>By definition of guaranteeing access to encrypted data, they will be required to maintain such weaknesses. It'd be catastrophic for our tech industry and my future as a software engineer.
Maybe it legitimately is the case that it's impossible for techies to ensure warranted government access without guaranteeing that same access to any and every hacker on Earth.
But the more I read these doomsday scenarios from people who are mystified by the one-sentence, 64-word text of the 4th amendment, the less I'm able to believe them.
I'm within my rights if I write a bunch of jibberish on a piece of paper which represents some secret coding of my personal thoughts, and I refuse to tell you how to decode it. The government can get a warrant allowing them to look at that piece of paper, but as far as I know, they have never had the ability to compel me to explain how to interpret it.
In my opinion, encrypted data should effectively be treated like secret thoughts you may or may not reveal to others or something you've hidden so well nobody will find it. They can analyze the ciphertext, and they can attempt to use surveillance techniques to get you to reveal your secret/key/hidingplace, but compelling you to help them get those things goes too far.
> Why do people here persistently insist, even after being corrected, that the government's 228 year old authority to conduct warranted search and seizure is some kind of shadowy and scary "new power"?
I'm not talking about the 228 year old law. I'm talking about the government's ability to collect information about conversations you had 10 years ago after a suspected crime which occurred, say, last week. This massive collection of data creates an imbalance between safety and potential data breaches and abuses.
> Nothing about this is in any way new, and it's grossly dishonest to continue to claim that it is.
Please read my comments carefully. You misunderstand my meaning
> But the more I read these doomsday scenarios from people who are mystified by the one-sentence, 64-word text of the 4th amendment, the less I'm able to believe them.
You can educate yourself and make up your own mind. You shouldn't believe or disbelieve a certain position based on the attitude of the person from whom you get your information. It's as unfortunate to miss the truth because of a terrible presenter (think of your worst science teacher) as it is to gulp down misinformation because it is presented in simple terms (think Trump). I've written tons of comments on HN about this issue with many citations. Here are detailed responses to Sam Harris [1] and President Obama [2]
To date, I feel the most compelling argument comes from Senator Lindsey Graham's position. He was initially very supportive of the DOJ's position, and publicly called for Apple to comply. Later, after researching the topic and questioning Attorney General Loretta Lynch, he found his view changed [3]
>I'm talking about the government's ability to collect information about conversations you had 10 years ago after a suspected crime which occurred, say, last week.
You know that people used to put a lot of their conversations onto paper, right?
If you kept your ten year old letters, and the government had cause to believe you'd committed a bunch of crimes (maybe you hadn't? you seem like an all right guy, the government probably just goofed, these things happen), it could go and search your ten year old conversations and see if they contained proof of you committing a bunch of crimes.
The fact that we uses electrons and binary math instead of paper and ink doesn't change anything at all.
>Here are detailed responses to Sam Harris [1] and President Obama [2]
I appreciate the effort but these read like the same doomsday scenarios where it's just treated as an inevitable given that providing a method of government access is directly equivalent to providing access to any and every hacker.
>there will be data breaches, people will be upset, they won't buy iPhones, and this industry will disappear from the US overnight
This is the kind of doomsaying I'm talking about. Most people don't buy iPhones for their disk encryption, they buy iPhones because they're shiny and have the apple logoand you can do facebook with them. The PSN breach didn't stop Sony from selling 35 million playstation 4s; an iPhone breach would inconvenience some people, be embarrassing for apple, and then everyone would continue on buying iPhones because the alternative is to not buy an iPhone, which most iPhone owners would consider about as acceptable as cutting off one of their own hands.
You are completely ignoring the singularly unique aspect of digital communications which enables unprecedented new powers, period:
Storage. History. Digital communications like email are stored, and can be stored FOREVER... with just a flip of a switch, a word, an order, a warrant...
One does not have a pile of previous analog telephone calls just waiting to be scooped up and analyzed retro-actively
Anyone can see that if I can run all your data backwards through retro-actively invented filters, I have a power that has no parallel in the analog world:
For example: they didn't stop the Boston Bombers, so they change the algorithms until when they run everything again, it lines up.
This is seriously scary stuff, and it's a double-edged sword. I feel that it goes too far in giving power to these wanna-be-omniscient agents.
I'm not comfortable having ANY human omniscient agents.
I don't give a rat's behind how "noble" or "sacred" their mission statement is... bad people will abuse such powers and they already are doing so...
They can get what is actually transmitted over the channel. They may have difficulty interpreting that data because of encryption, but that's always been the case -- encryption is older than electronics, and has been applied to sensitive data in every medium longer than the US has existed.
This idea that the government can regulate how you are permitted to communicate just so that it is convenient for them to interpret later if they have a legal basis for intercepting it is a novel claim of government power and, given that it cannot be exercised without creating the same convenience for both illegal government interception and third party interception, an absurd and dangerous one.
>They will, eventually, be shut out of the communications channel entirely due to encryption.
That's not entirely accurate though. Its an arms race between Cryptography and Cryptanalysis. We don't know what we don't know and there's still not enough transparency into the government's capabilities.
Fair. Realistically though they'll be shut out without company cooperation. As computing power and techniques improve both being able to use and break encryption will increase but breaking encryption, just because of how it works, always takes more power than the creation.
You are correct. I should have been more accurate and stated that the new power that the government is demanding is demanding in the Apple court case is the power to decrypt our records and communications with a warrant.
There are also government agents who are pushing for the right to decrypt everyone's communications and records without a warrant.
Interestingly, the government never "demanded" the right to search everyone's unencrypted communications. They just went out and did it.
You need to remember the difference between theory and practice.
In theory, yes. The technologies where available. But in practice, much has changed. In 2016, technically illiterate people are encrypting their files without even realizing it. Technology has changed what law enforcement can expect to encounter in practice.
(Also "decades ago"/"1996" ...Well now I feel old.)
Actually, in practice encryption was a big deal and widely used two decades ago, which is one of the reasons that there was a big controversy then over the government's last effort to regulate encryption (at the time, it was largely about it export, and for the convenience of the NSA rather than domestic law enforcement, but the debate was remarkably similar.)
Yes, technically illiterate people were using encryption without realizing it (or even knowing what encryption was) in the 1990s, both for files and other data at rest and for data in transit (e.g., via HTTPS.)
Certainly, the details of where and how encryption is commonly used has changed, but the substance of the debates over government encryption policies haven't changed much at all since the Clipper Chip and encryption-as-munition issues of the 1990s.
>The government is demanding new powers: the power to search our communications
This is an embarrassingly bad opinion and it's embarrassing for HN that it's at the top of the thread.
The constitution does not require a rewrite to the fourth amendment every time some nerd comes up with a new widget.
The government has always had the right to conduct warranted searches of communications, whether that was opening mail, wiretapping phones, or just good old-fashioned eavesdropping.
Strong unadulterated crypto threatens to take that existing, longstanding power away from the government. The government is hardly going to give up without a fight.
The government is demanding new powers: the power to search our communications. Perhaps the ability to conduct such searches will make their jobs easier, but keeping them from having this power does not make their jobs more difficult than the 200 year baseline. We are only asking them to do the same legwork that they've always done: look for suspicious behavior, track the purchase of dangerous materials, react to disasters and attacks when they happen, etc.