Photo illustration by Slate. Photo by writerfantast/Getty Images Plus.
This article is part of Privacy in the Pandemic, a Future Tense series.
With so many of us working, teaching, and socializing online much more than usual due to the pandemic, strong encryption is more important than ever for ensuring commercial information security and protecting personal privacy. Zoom, whose video conferencing software has nearly replaced in-person meetings for many people, has felt this pressure directly over the past few months. At the start of the pandemic lockdowns, the company faced intense scrutiny as it surged in popularity and suffered from a series of privacy and security issues, from Zoom bombing to misleading advertising about its encryption. The companys leadership scrambled to respond, going so far as to acquire an entire cryptography company.
Earlier this month, the CEO announced a plan to roll out end-to-end encryption. E2EE is the gold standard of messaging encryptionit allows data, including messages, to stay scrambled in transit and only be decrypted by the recipient. But Zoom was only planning to make it available for paid corporate users, explicitly stating that the company didnt want to offer E2EE to free accounts because we also want to work together with the FBI, with local law enforcement. The backlash was swift, and within two weeks, Zooms security team updated its E2EE plans to extend the option to unpaid users. It was a victory.
But on Tuesday, a group of Republican senators introduced the Lawful Access to Encrypted Data Act, which would make Zooms plans illegaland more broadly threaten privacy just as Americans are relying on their devices more than ever.
This bill would compel tech companies to build lawful access mechanisms into a range of encryption products, including E2EE. E2EE means that the company providing the messaging platform, such as WhatsApp, doesnt ever see the unscrambled data as the message crosses its servers. It cant turn over the decrypted data to law enforcement even if it wants to. Cryptographers argue that theres no way to allow lawful access without putting all of the data at risk as it travels the internet.
The new bill would also require law enforcement backdoors to encrypted data at restthink a locked iPhone or protected hard drive. Apple currently doesnt have copies of iPhone decryption keys, so when the FBI demands it unlock a seized phone, it genuinely cannot comply, leaving the bureau to find another way into the phone. Although there has been controversy over the exact number, the FBI has been stymied at least 1,000 times by encrypted phones. Attorney General William Barr complained in October that this debate has dragged on, and our ability to protect the public from criminal threats is rapidly deteriorating. Proposals for regulating encryption have been floated since the 1990s, each time spurring loud objections from researchers and digital liberties groups.
Over the past year, the FBI has focused on the problem of encrypted data at rest, especially those seized phones. Seny Kamara, a cryptographer and associate professor of computer science at Brown University, told me that the resurgence of this debate over the past few years meant people sort of assumed something was coming the government had been making veiled threats about this for a while. But some researchers had hoped the FBI would leave aside the question of accessing E2EE data in transit in any new regulations. A bill solely requiring lawful access to devices wouldnt necessarily be worse during a pandemic lockdown; accessing a locked device requires law enforcement to have physical custody of a phone or hard drive. But scooping up encrypted data in transit from anywhere on the internet? Thats much more threatening now that so much day-to-day life is happening online.
Privacy advocates were skeptical that the federal government would be satisfied with just unlocking seized phones, though, and LAEDAs requirement of lawful access to any encrypted data proves them right. Riana Pfefferkorn, associate director of surveillance and cybersecurity at the Stanford Center for Internet and Society, wrote in her analysis of the bill that she did not believe for a single moment that law enforcement or Congress would settle for only regulating encryption as to devices and not data in transit. Pfefferkorn told me she believes the push now to regulate messaging in addition to encrypted devices is at least in part a reaction to Facebooks 2019 announcement that the company would add E2EE to all of its messaging products. This new bill also comes hot on the heels of another proposal that critics say is secretly designed to kill strong consumer encryption, called the EARN IT bill, and the ambitious scope of LAEDA may be designed to make EARN IT look reasonable by comparison.
Even if this bill doesnt end up succeeding, any uncertainty in the meantime might make companies like Zoom unwilling to push ahead with ambitious plans for encryption, which could hold back privacy timelines months or possibly years. Its a disruptive environment, Pfefferkorn said, referring to the continual pressure from law enforcement over encryption. She added that tech investors are following this debate closely. Even for a company that wants to work with law enforcement, the uncertainty about what might be required for lawful access and how to accomplish it make it difficult to allocate limited resources.
Companies like Zoom and Slack have faced backlash too as their products expanded from an enterprise model to consumer accounts. Employers have long had an expectation that workers would give up some amount of privacy while at work, allowing bosses to monitor behavior and performance. Communication products aimed at enterprise customers sometimes have surveillance features allowing employers to access corporate email accounts, read chats, or monitor attention on webinars. Those features were developed within a labor employment law, HR context, said Pfefferkorn. As these tools have expanded directly to consumers, there has naturally been a backlash against those features as privacy invasions.
Many of those corporate surveillance features are compatible with the types of legal access LAEDA is asking for, and incompatible with E2EE. Some types of data mining, like what Google has been known to allow with Gmail, are also incompatible with E2EE. Pfefferkorn believes the government is using these types of corporate data collection as justification for law enforcement access: The government will say, well, if corporate has access to this type of information, we should be able to get our hands on that too. Sometimes, law enforcement can even buy third-party data directly, circumventing warrants altogether.
Tech companies trying to plan their privacy strategy over the next year or few years will have to balance different demands from enterprise interests, government, and consumers, said Kamara. Its difficult to sort of juggle. Tech companies and researchers also need to be thinking not just about whether theyre protecting the privacy of the data theyve collected, but considering should they have the data in the first place?
With many people working remotely for the foreseeable future, away from prying eyes of bosses, more people might look askance at back doors in their communication platforms regardless of who the back door is intended for. Having conversations with colleagues overheard in the office is one thing, but the idea of someone spying through your work video chat into your private home feels very different.
And with massive protests ongoing against law enforcement violence and systemic racism, giving those back doors to law enforcement is likely to be especially unpopular with consumers, particularly those from marginalized groups. Kamara pointed out that communities of color have historically borne the brunt of surveillance of all kinds. The new surveillance powers proposed in LAEDA would very likely also be applied disproportionately to Black people and other marginalized communities, many of whom are currently suffering disproportionately from the coronavirus pandemic.
With coronavirus cases rising in much of the United Statesincluding the states of the three Republican sponsors of this billand many places still in various forms of lockdown, voters might consider whether trying to weaken online security is the best use of congressional energy.
Future Tense is a partnership of Slate, New America, and Arizona State University that examines emerging technologies, public policy, and society.
The rest is here:
A Republican Senate bill would weaken encryption when we need it most. - Slate
- Report: NSA building comp to crack encryption types [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Report: NSA looking to crack all encryption with quantum computer [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Sound Advice: Explaining Comcast cable encryption [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- NSA Building Encryption-Busting Super Computer [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- NSA researches quantum computing to crack most encryption [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Advanced Encryption Standard - Wikipedia, the free encyclopedia [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- How Encryption Works - HowStuffWorks "Computer" [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Email Encryption - MB Technology Solutions - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Email Encryption - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Reversible Data Hiding in Encrypted Images by Reserving Room Before Encryption - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Toshiba WT8 Full Disk Encryption, Miracast, Easy Stand - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Australian Encryption | Text encryption software for the protection of your privacy - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- njRAT v0 6 4 server Clean Encryption - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- AlertBoot New Encryption Compliance Reports Prepare Covered Entities For HIPAA Audits [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- BlackBerry denies using backdoor-enabled encryption code [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- What Is Encryption? (with pictures) - wiseGEEK [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- HowStuffWorks "How Encryption Works" [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Gambling with Secrets Part 5 8 Encryption Machines - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- The Benefits of Hosted Disk Encryption - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Quill Encryption - what's that? - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- WhatsApp Encryption - Shmoocon 2014 by @segofensiva @psaneme - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- encryption demo2 - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- encryption demo - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Seven - Encryption Official Lyric Visual - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Quantum Computers - The Ultimate Encryption Backdoor? - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Eric Schmidt: Encryption will break through the Great Firewall of China [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- From NSA to Gmail: Ex-spy launches free email encryption service [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Tennessee bill takes on NSA encryption-breaking facility at Oak Ridge/SHUT. IT. DOWN. - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Substitute for:Measurements. 1 Episode. Strength of the encryption algorithm - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- RSA Encryption Checkpoint - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Gambling with Secrets 8 8 RSA Encryption 1 - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Google chairman says 'encrypting everything' could end China's censorship, stop NSA snooping [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Ex-spy launches free email encryption service [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- 3 2 The Data Encryption Standard 22 min - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- RSA Encryption step 3 - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- RSA Encryption step 2 - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- aes tutorial, cryptography Advanced Encryption Standard AES Tutorial,fips 197 - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Townsend Security Release First Encryption Key Management Module for Drupal [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- RSA Encryption step 5 - Video [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Lavabit case highlights legal fuzziness around encryption rules [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- A Beginner's Guide To Encryption: What It Is And How To Set It Up [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- How App Developers Leave the Door Open to NSA Surveillance [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- Intro to RSA Encryption step 1 - Video [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- “Honey Encryption” Will Bamboozle Attackers with Fake Secrets [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Encryption - A Life Unlived (DEMO) - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Baffle thy enemy: The case for Honey Encryption [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- New AlertBoot Encryption Reports Make Dental HIPAA Compliance Easier [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Encryption - The Protest - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Encryption - New Life - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Encryption - Intro - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Encryption - Blank Canvas - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Security First SPxBitFiler-IPA encryption pattern for the IBM PureApplication System - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- Revolutionary new cryptography tool could make software unhackable [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- viaForensics webinar: Mobile encryption - the good, bad, and broken - Aug 2013 - Video [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- K.OStream 0.2 File Encryption Test - Video [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Tumblr adds SSL encryption option, but not as the default [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Latest Java Project Source Code on Chaotic Image Encryption Techniques - Video [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Encryption - University of Illinois at Urbana–Champaign [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- A Beginner's Guide to Encryption: What It Is and How to ... [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- Real Data Encryption Software is More Important than Ever ... [Last Updated On: February 8th, 2014] [Originally Added On: February 8th, 2014]
- Caesar Cipher Encryption method With example in C Language - Video [Last Updated On: February 8th, 2014] [Originally Added On: February 8th, 2014]
- Hytera DMR 256 bit encryption - Video [Last Updated On: February 9th, 2014] [Originally Added On: February 9th, 2014]
- Townsend Security Releases Encryption Key Management Virtual Machine for Windows Azure [Last Updated On: February 10th, 2014] [Originally Added On: February 10th, 2014]
- Unitrends Data Backup Webinar: Utilizing The Cloud, Deduplication, and Encryption - Video [Last Updated On: February 10th, 2014] [Originally Added On: February 10th, 2014]
- Main menu [Last Updated On: February 12th, 2014] [Originally Added On: February 12th, 2014]
- Use of encryption growing but businesses struggle with it – study [Last Updated On: February 12th, 2014] [Originally Added On: February 12th, 2014]
- SlingSecure Mobile Voice Encryption Installation Video for Android - Video [Last Updated On: February 12th, 2014] [Originally Added On: February 12th, 2014]
- Data breaches drive growth in use of encryption, global study finds [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Darren Moffat: ZFS Encryption - Part 2 - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Darren Moffat: ZFS Encryption - Part 1 - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- How do I configure User Local Recovery in Endpoint Encryption Manager 276 - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Symmetric Cipher (Private-key) Encryption - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- SafeGuard File Encryption for Mac - Installation and Configuration - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Fundamentals of Next Generation Encryption - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Tutorial: Einrichten der EgoSecure Endpoint Removable Device Encryption - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- 'PGP' encryption has had stay-powering but does it meet today's enterprise demands? [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]
- Fact or Fiction: Encryption Prevents Digital Eavesdropping [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]
- RHCSA PREP:answer to question 20 (Central Authentication Using LDAP with TLS/SSL Encryption) - Video [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]
- Protect+ Voice Recorder with Encryption - Video [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]