I think this article is great, but something did stand out for me.
I'm a huge supporter of universal end-to-end encryption, but Feinstein's point is making me feel some cognitive dissonance:
>"I think with a court order, with good justification, all of that can be prevented."
There are cases where I would want law enforcement to be able to read encrypted communications in an emergency situation, with a valid court order. If someone is being held hostage, for example. Of course I don't want intelligence agencies having this same access; just very specific requests during exigent circumstances, with judge approval. A real judge in a real court, not a secret FISA court.
But to do that you need some kind of key escrow already set up with the government, and if you have that, there's nothing stopping law enforcement and intelligent agencies from spying on what they want when they want.
Right now this isn't a huge problem since a lot of people still communicate in plaintext, or things that are encrypted but logged/intercepted by a central location (Skype). But eventually more and more things will move to end-to-end encryption.
I wish that with a court order, we could read the thoughts of a suspect, too... But that's not possible, either.
Remember that a police force doesn't need infinite, perfect access to all of a target's communications to catch them. Think about the case we're describing: we have enough information to convince a judge that this person is a suspect. In order to get evidence to convict, you can:
* hack into their devices to retrieve stored data or install malicious software like keyloggers
* bug their place of living and work for video, audio, and WiFi capture
* interview/interrogate them, and everyone they associate with
* search their place of living and work
* place tracking devices
* watch their every move with drone or human surveillance
* have a human or drone tail them
* record all the metadata from their Internet communication
* record the contents of any unencrypted communication
We actually have all the access we need, particularly since we're allowed to hack into the target's devices. The only thing we CAN'T do, is include the target in bulk communication capture schemes. We actually have to pick targets and spend resources on them.
To be honest, I might be OK with that practical limit even WITHOUT a warrant requirement. If a police force believes that a suspect is worth spending their limited resources on, they must be worth something. If adding someone to a watch list is free, they'll do it to everybody.
Given that its original purpose was to discourage the authorities from torturing or jailing you in order to compel you to give evidence against yourself, one could argue that the Fifth would need new justification in a future where thoughts were easily read.
The right way to handle this is to recognize that sometimes, technology that has all of the magical properties that you want simply does not exist, or cannot exist. Secure, global key escrow is one of those things.
I think universal end-to-end encryption is an all-or-nothing proposition. You can't sell it by saying, "It's secure, except when it isn't." It's also a slippery slope to establish a key escrow for the government; will it be a crime to encrypt using a key that isn't in escrow?
Encryption can facilitate evil, but it also protects against evil. Universal adoption is hampered by obstacles including:
1. It's hard to do.
2. It's hard to understand, even if the tools become more user-friendly.
3. Most people will share a private key with a stranger when asked.
The right way to handle this is to encourage people to use strong encryption and acknowledge that it can be safe from eavesdropping, but still subject to weaknesses or participants revealing the information in other ways.
The right way to handle it is to enforce laws in meatspace. To create CP, for example, you need to abduct and exploit children, and produce content. This leaves a trail of money, places, and witnesses. Bear down on that instead of snooping.
It could improve the effectiveness of law enforcement to force them to focus on meatspace crime rather than playing with their shiny computer toys.
I'm of the same frame of mind.. There was an article from earlier this year about the suspect in a child-porn case who successfully encrypted his machine which has completely prevented prosecution:
As tools become better, is the price we pay for strong encryption that criminals who are mildly technical can get away with their crimes? That's hard to stomach if it's the 'right' answer..
It's really tricky. I don't want people to be forced to self-incriminate and give up their password. I don't want encryption to be banned. I don't want people to only be permitted to use government-approved encryption with escrow. I don't even want intelligence agencies to research vulnerabilities in existing cryptographic algorithms and implementations, because they have no reason to not use that for dragnet surveillance.
But obviously, I don't want CP or terrorism subjects to evade detection and prosecution because of encrypted drives or communications.
I'm a huge supporter of universal end-to-end encryption, but Feinstein's point is making me feel some cognitive dissonance:
>"I think with a court order, with good justification, all of that can be prevented."
There are cases where I would want law enforcement to be able to read encrypted communications in an emergency situation, with a valid court order. If someone is being held hostage, for example. Of course I don't want intelligence agencies having this same access; just very specific requests during exigent circumstances, with judge approval. A real judge in a real court, not a secret FISA court.
But to do that you need some kind of key escrow already set up with the government, and if you have that, there's nothing stopping law enforcement and intelligent agencies from spying on what they want when they want.
Right now this isn't a huge problem since a lot of people still communicate in plaintext, or things that are encrypted but logged/intercepted by a central location (Skype). But eventually more and more things will move to end-to-end encryption.
What is the right way to handle this?