Jim Baker served as the FBI's general counsel from 2014 until 2017, and he presided over the the FBI's attempt to force Apple to undermine its cryptography under the rubric of investigating the San Bernadino shooters; he has long been a prominent advocate for mass surveillance, but he has had a change of heart: in a long, detailed essay on Lawfare, Baker explains why he believes that governments should not seek to introduce defects into cryptographic systems.
Baker's argument is primarily instrumental: he rejects the idea that you can create cryptography that works perfectly when it's being used to protect good guys, but fails completely when bad guys try to use it. He acknowledges that any effort to ban working cryptography would simply send American criminals to offshore software repositories to get access to working crypto, and that in so doing, it would be much harder for American law enforcement to spy on its adversaries, because the metadata from their encrypted communications would be out of US law enforcement's reach.
Baker is primarily responding to Attorney General William Barr's idiotic call to ban working crypto as a matter of public safety, and he builds on the usual instrumental arguments about the limited utility of crypto bans for law enforcement with a less-often-heard argument about national security and public safety.
Baker discusses how Huawei (and other companies with deep ties to nations that the US considers to be its rivals) will inevitably have some of its gear within the US's communications infrastructure. Baker describes US communications networks becoming "zero trust networks," that can't be trusted to protect their users' privacy -- and he suggests that well-designed cryptographic tools are America's best defense in this zero-trust environment. If you can't stop Huawei from sending your data to the People's Liberation Army, at least you can encrypt that data so the PLA can't make sense of it.
He also discusses the national security interest in having well-secured information systems with up-to-date patches, and criticizes efforts (like the one the FBI made with Apple) to suborn companies to ship out poisoned software updates in order to introduce defects into their software so governments can spy on them. This will poison the well, making American individuals and companies reluctant to apply updates when they arrive, thus preserving security defects that America's nation-state rivals (as well as criminals, terrorists, etc) can exploit.
I've made similar instrumental arguments about the foolishness of attempting to ban working cryptography, but I think it's important to note that there's a much more important equity in the crypto wars: the right to privacy.
As Baker himself notes, cryptography does not create a "law-free zone" where cops can't execute lawful orders. No US law allows government officials to "force manufacturers and service providers to unlock devices and decrypt communicationsthat is, to rewrite software."
This is not an oversight.
The framers of the US Constitution explicitly rejected the idea that people should be forced to arrange their affairs to make life easy for law enforcement.
The existence of conversations that law enforcement can't access after the fact is not a new development: we never passed a law requiring letter-writers to use indelible ink and fireproof paper so that cops could read them later if they needed to. We never passed a law requiring every restaurant to put a hidden mic in every salt cellar so that potential lunchtime plotters could have their whispers played back after a robbery took place. You are allowed to have a murmured conversation with your spouse in bed: no law requires you to shout your communications over a megaphone so that any cops listening by the windows can hear what you're saying.
Yes, it's impossible to keep people safe while taking away their working cryptography.
But even if it wasn't impossible, it would still be wrong. Countries like Russia, China, Iran, Australia and the UK have adopted laws banning working crypto -- these are countries with very different constitutional values, ones that make allowances for forcing people to arrange their affairs to make life easier for their cops.
But both William Barr and Jim Baker are oath-bound to uphold the US Constitution and its values. The relationship of those values to the right to live your life in ways that may inconvenience law enforcement is indisputable.
Baker's willingness to admit the technical incoherence of crypto bans is great, a massive step forward, but American legal officials shouldn't even be debating whether or not it's possible to ban crypto. If Barr managed to produce a working "solution" to the problems that Baker raises, we still shouldn't use it, because Americans have the right to make choices that enhance their own security, privacy and integrity, even if that makes cops work harder.
In other words, even though Snowden opposes crypto bans and Baker opposes crypto bans, they are not talking about the same thing. Snowden is talking about upholding the Constitution; Baker is talking about the regrettable impossibility of having his security cake and eating it too.
The Defense Innovation Board discussed the fact that even if the United States and its allies keep Huawei equipment out of their domestic networks for a sustained period of timewhich increasingly will be difficult to dothey will eventually encounter it somewhere in the world. Therefore, they will need to figure out how to operate in a zero-trust interconnected world, especially after the widespread deployment of 5G networks globally, much of which (at least abroad) will include Huawei equipment. They need to think about the reality of operating in a degraded communications security environment and never trust the internet, applying the zero-trust network concept on a global scale.
This strikes me as eminently sensible. The widespread deployment of Huawei and other Chinese equipment in the backbone of the internet increasingly provides China with the technical capability (whether utilized or not) to copy, corrupt or disrupt substantial portions of data traffic transmitted on Huawei equipment. In a crisis, China could direct Huawei and other companies to degrade key network elements of its adversaries and/or render them inoperable. Huawei denies that it would cooperate with the Chinese government in such activities, and some observers question the logic of Huawei ever doing so. But from a national security perspective it is prudent to focus on the capabilities of an adversary, not just stated intent. Living in a Huawei world means there are substantial risks to the confidentiality, integrity and availability of data that is essential to our effective functioning as a society.
As mentioned above, China is not the only cyber threat actor. But China and Huawei exemplify the nature and scope of the pervasive cybersecurity risks that the United States and its allies face from many adversaries.
Rethinking Encryption [Jim Baker/Lawfare]
(via Schneier)
(Image: U.S. Air Force photo by J.M. Eddins Jr)
The EFFs Panopticlick tool (previously) is now a general purpose testing suite for browser privacy, checking Do Not Track, the effectiveness of ad- and tracker-blocking, and providing details on your browsers fingerprint. [via Hacker News]
Japan's Henn na Hotel chain, owned by the HIS Group, uses "bed-facing Tapia robots" in its rooms; these robots turn out to be incredibly insecure: you can update them by pairing with them using a NFC sensor at the backs of their heads. The robots do not check the new code for cryptographic signatures, meaning []
In the wake of Berkeley joining the growing list of cities that ban the use of facial recognition by governments, RIT philosophy prof Evan Selinger and Northeastern law/comp sci prof Woodrow Hartzog make the case in the New York Times for a nationwide ban on facial recognition technology.
Want an online presence that matters? As the graveyard of fallen start-ups can attest to, having a fancy website and a sleek logo isnt worth much unless people actually start engaging with them. Even on the fast changing web, there are ironclad strategies for marketing that can adapt to any platform. The best way to []
Big things are happening in tech with AI and deep learning. Thats not exactly a news flash when you look at how often companies use algorithms to manage everything from online advertising to the songs, videos, posts, and other digital content platforms recommend for their users. Getting into the field requires a pretty broad range []
In the early days of the web, everyone wanted a .com domain for their site. As a results, all the good ones got snapped up. But .com no longer has the cachet it once did. In fact, many new business and individuals are opting for other top-level domain extensions. One of the most memorable is []
Read the original:
The top FBI lawyer who tried to force Apple to backdoor its crypto now says working crypto is essential to public safety and national security - Boing...
- To Foil NSA Spies, Encrypt Everything [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- What is cryptography? - A Word Definition From the ... [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- cryptography: Definition from Answers.com [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Cryptography - Wikipedia, the free encyclopedia [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Cryptography - CISSP Domain 07 - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Cryptography Advanced Encryption Standard AES Tutorial,fips 197 - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Faraday Project for Network Security and Cryptography - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- An Overview of Cryptography - Gary C. Kessler [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- An Open Letter from US Researchers in Cryptography and ... [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Gambling with Secrets Part 4 8 Private Key Cryptography - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Gambling with Secrets Part 1 8 What is Cryptography - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Public Key Cryptography RSA Encryption Algorithm - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Public Key Cryptography Diffie Hellman Key Exchange - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Intro to Cryptography - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Caesar Cipher Ancient Cryptography - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- 50 top US cyber security experts write open letter calling for end to NSA 'snoop-ops' [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Prominent cryptography and security researchers deplore NSA's surveillance activities [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Obama Stays Silent on Reform of NSA's Crypto Subversion [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Cryptography experts sign open letter against NSA surveillance [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- US crypto researchers to NSA: If you must track, track responsibly [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Java Cryptography Architecture (JCA) Overview - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Cryptography - Part 1 - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Cryptography - Part 2 - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- International Journal on Cryptography and Information Security ( IJCIS) - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Bitcoin Lowdown: Block Chain Cryptography Trumps Human Trust, Deal With It - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Bitcoin Lowdown: Block Chain Cryptography Trumps Human Trust - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- NSA and GCHQ spoofed LinkedIn to hack Belgian cryptography professor [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Lecture 17: Elliptic Curve Cryptography (ECC) - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Cryptography event - Pravega 2014 - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- Lecture 1: Introduction to Cryptography - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- US and UK spy agencies accused of swoop on Belgian cryptography expert [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Conceal: Facebook's new Java APIs for cryptography on Android [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Cryptography Apps: How To Keep Your Personal Info Private [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Cryptography Breakthrough Could Make Software Unhackable [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Oi, Android devs! Facebook wants your apps to be more secure [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Lecture 19: Elgamal Digital Signature - Video [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Lecture 18: Digital Signatures and Security Services - Video [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Cryptography 1. List some of the attacks on the Diffie ... [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- Cryptography Breakthrough Could Make Software Unhackable ... [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- Cryptography: Secret Coding, Spying, and E-Commerce - Video [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- Cryptography - Video [Last Updated On: February 9th, 2014] [Originally Added On: February 9th, 2014]
- Public Key Cryptography: RSA Encryption Algorithm - Video [Last Updated On: February 10th, 2014] [Originally Added On: February 10th, 2014]
- Is Bitcoin Anonymous? Arvind Narayanan | Princeton University | Real World Cryptography Workshop - Video [Last Updated On: February 10th, 2014] [Originally Added On: February 10th, 2014]
- A Competitive Study of Cryptography Techniques over Block Cipher - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- How Quantum Computing Will Change Cryptography [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]
- REALITY LOST - EXCERPT SIX (QUANTUM CRYPTOGRAPHY) - Video [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]
- Introduction to Cryptography of Bitcoin, Explained! - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- [FOSDEM 2014] USE OTR or how we learned to start worrying and love cryptography - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- Reshif's Cryptography Challenge Solution/Walkthrough - Video [Last Updated On: February 20th, 2014] [Originally Added On: February 20th, 2014]
- [DEFCON 19] Steganography and Cryptography 101 - Video [Last Updated On: February 22nd, 2014] [Originally Added On: February 22nd, 2014]
- A Brief Rundown Of The Spying Questions Intel's CEO Won't Answer [Last Updated On: February 25th, 2014] [Originally Added On: February 25th, 2014]
- DEF CON 8 - Jon Erickson - Number Theory Complexity, Theory, Cryptography, and Quantum Computing. - Video [Last Updated On: February 26th, 2014] [Originally Added On: February 26th, 2014]
- Was YOUR iPhone at risk of being hacked? Bug in Apple update left mobiles open to identity theft for up to 18 months ... [Last Updated On: February 27th, 2014] [Originally Added On: February 27th, 2014]
- Security researchers urge tech companies to explain their cryptographic choices [Last Updated On: February 27th, 2014] [Originally Added On: February 27th, 2014]
- Apple reveals algorithm behind 'encrypted' iMessages [Last Updated On: February 28th, 2014] [Originally Added On: February 28th, 2014]
- Wiliest Ways to Keep the NSA at Bay [Last Updated On: March 1st, 2014] [Originally Added On: March 1st, 2014]
- How to Pronounce Cryptography - Video [Last Updated On: March 1st, 2014] [Originally Added On: March 1st, 2014]
- cryptography in DNS - Video [Last Updated On: March 3rd, 2014] [Originally Added On: March 3rd, 2014]
- Who is the reclusive billionaire creator of Bitcoin? [Last Updated On: March 4th, 2014] [Originally Added On: March 4th, 2014]
- How to say cryptography in Italian - Video [Last Updated On: March 4th, 2014] [Originally Added On: March 4th, 2014]
- Massive Linux security flaw dwarfs Appleās cryptography problems of just last week [Last Updated On: March 5th, 2014] [Originally Added On: March 5th, 2014]
- Security lessons from RSA [Last Updated On: March 5th, 2014] [Originally Added On: March 5th, 2014]
- Visual Cryptography - Video [Last Updated On: March 5th, 2014] [Originally Added On: March 5th, 2014]
- Classical Computing Embraces Quantum Ideas [Last Updated On: March 6th, 2014] [Originally Added On: March 6th, 2014]
- Quantum Cryptography Conquers Noise Problem [Last Updated On: March 6th, 2014] [Originally Added On: March 6th, 2014]
- REALITY LOST Bonus scene 4. Quantum cryptography Founding Fathers. - Video [Last Updated On: March 7th, 2014] [Originally Added On: March 7th, 2014]
- Quantum Cryptography: From Theory to Practice - Video [Last Updated On: March 9th, 2014] [Originally Added On: March 9th, 2014]
- Forcing Trust: Nonlocal Games and Untrusted-device Cryptography - Video [Last Updated On: March 9th, 2014] [Originally Added On: March 9th, 2014]
- TrustyCon 2014 - New Frontiers in Cryptography - Video [Last Updated On: March 9th, 2014] [Originally Added On: March 9th, 2014]
- REALITY LOST Bonus scene 3. Christian Kurtsiefer on hacking quantum cryptography. - Video [Last Updated On: March 9th, 2014] [Originally Added On: March 9th, 2014]
- Nerlens Noel Tweets Date for Potential NBA Debut [Last Updated On: March 9th, 2014] [Originally Added On: March 9th, 2014]
- CISSP SG Cryptography - Video [Last Updated On: March 10th, 2014] [Originally Added On: March 10th, 2014]
- More secure communications thanks to quantum physics [Last Updated On: March 13th, 2014] [Originally Added On: March 13th, 2014]
- New Cryptography Scheme Secured By Quantum Physics [Last Updated On: March 13th, 2014] [Originally Added On: March 13th, 2014]
- History Of Cryptography - Video [Last Updated On: March 14th, 2014] [Originally Added On: March 14th, 2014]
- avc 19 Cryptography x264 - Video [Last Updated On: March 15th, 2014] [Originally Added On: March 15th, 2014]
- Edward Snowden Speaks at SXSW [Last Updated On: April 10th, 2017] [Originally Added On: March 15th, 2014]
- Tor is building an anonymous instant messenger [Last Updated On: April 10th, 2017] [Originally Added On: March 15th, 2014]
- learn cryptography learn the following pkcs refrences - Video [Last Updated On: March 16th, 2014] [Originally Added On: March 16th, 2014]
- [Lec-2][Part-2] Shift Cipher - Symmetric ciphers - Video [Last Updated On: March 16th, 2014] [Originally Added On: March 16th, 2014]