Page 1 of 2 12 LastLast
Results 1 to 30 of 45

Thread: FBI blasts Apple, Google for locking police out of phones

  1. #1

    Default FBI blasts Apple, Google for locking police out of phones

    My views on this are generally pretty firm, but I can't get around the clear value that that phones and digital services have for policing. But it's a manifestly bad idea for government to have a legislatively-created back-door into digital systems. And yet...

    http://www.washingtonpost.com/busine...527_story.html

    FBI blasts Apple, Google for locking police out of phones

    FBI Director James B. Comey sharply criticized Apple and Google on Thursday for developing forms of smartphone encryption so secure that law enforcement officials cannot easily gain access to information stored on the devices — even when they have valid search warrants.

    His comments were the most forceful yet from a top government official but echo a chorus of denunciation from law enforcement officials nationwide. Police have said that the ability to search photos, messages and Web histories on smartphones is essential to solving a range of serious crimes, including murder, child pornography and attempted terrorist attacks.

    “There will come a day when it will matter a great deal to the lives of people . . . that we will be able to gain access” to such devices, Comey told reporters in a briefing. “I want to have that conversation [with companies responsible] before that day comes.”

    Comey added that FBI officials already have made initial contact with the two companies, which announced their new smartphone encryption initiatives last week. He said he could not understand why companies would “market something expressly to allow people to place themselves beyond the law.”

    Comey’s remarks followed news last week that Apple’s latest mobile operating system, iOS 8, is so thoroughly encrypted that the company is unable to unlock iPhones or iPads for police. Google, meanwhile, is moving to an automatic form of encryption for its newest version of Android operating system that the company also will not be able to unlock, though it will take longer for that new feature to reach most consumers.

    Both companies declined to comment on Comey’s remarks. Apple has said that its new encryption is not intended to specifically hinder law enforcement but to improve device security against any potential intruder.

    For detectives working a tough case, few types of evidence are more revealing than a smartphone. Call logs, instant messages and location records can link a suspect to a crime precisely when and where it occurred. And a surprising number of criminals, police say, like to take selfies posing with accomplices — and often the loot they stole together.

    But the era of easy law enforcement access to smartphones may be drawing to a close as courts and tech companies erect new barriers to police searches of popular electronic devices. The result, say law enforcement officials, legal experts and forensic analysts, is that more and more seized smartphones will end up as little more than shiny paperweights, with potentially incriminating secrets locked inside forever.

    The irony, some say, is that while the legal and technical changes are fueled by anger over reports of mass surveillance by the National Security Agency, the consequences are being felt most heavily by police detectives, often armed with warrants certifying that a judge has found probable cause that a search of a smartphone will reveal evidence of a crime.

    “The outrage is directed at warrantless mass surveillance, and this is a very different context. It’s searching a device with a warrant,” said Orin Kerr, a former Justice Department computer crimes lawyer who is now a professor at George Washington University.

    Not all of the high-tech tools favored by police are in peril. They can still seek records of calls or texts from cellular carriers, eavesdrop on conversations and, based on the cell towers used, determine the general locations of suspects. Police can seek data backed up on remote cloud services, which increasingly keep copies of the data collected by smartphones. And the most sophisticated law enforcement agencies can deliver malicious software to phones capable of making them spy on users.

    Yet the devices themselves are gradually moving beyond the reach of police in a range of circumstances, prompting ire from investigators. Frustration is running particularly high at Apple, which made the first announcement about new encryption and is moving much more swiftly than Google to get it into the hands of consumers.

    “Apple will become the phone of choice for the pedophile,” said John J. Escalante, chief of detectives for Chicago’s police department. “The average pedophile at this point is probably thinking, I’ve got to get an Apple phone.”

    The rising use of encryption is already taking a toll on the ability of law enforcement officials to collect evidence from smartphones. Apple in particular has been introducing tough new security measures for more than two years that have made it difficult for police armed with cracking software to break in. The new encryption is significantly tougher, experts say.

    “There are some things you can do. There are some things the NSA can do. For the average mortal, I’d say they’re probably out of luck,” said Jonathan Zdziarski, a forensics researcher based in New Hampshire.

    Los Angeles police Detective Brian Collins, who does forensics analysis for anti-gang and narcotics investigations, says he works on about 30 smartphones a month. And while he still can successfully crack into most of them, the percentage has been gradually shrinking — a trend he fears will only accelerate.

    “I’ve been an investigator for almost 27 years,” Collins said, “It’s concerning that we’re beginning to go backwards with this technology.”

    The new encryption initiatives by Apple and Google come after June’s Supreme Court ruling requiring police, in most circumstances, to get a search warrant before gathering data from a cellphone. The magistrate courts that typically issue search warrants, meanwhile, are more carefully scrutinizing requests amid the heightened privacy concerns that followed the NSA disclosures that began last year.

    Civil liberties activists call this shift a necessary correction to the deterioration of personal privacy in the digital era — and especially since Apple’s introduction of the iPhone in 2007 inaugurated an era in which smartphones became remarkably intimate companions of people everywhere.

    “Law enforcement has an enormous range of technical and old-fashioned methods to go after the perpetrators of real crime, and no amount of security effort at Silicon Valley tech companies is going to change that fact,” said Peter Eckersley, director of technology projects at the Electronic Frontier Foundation, a civil liberties group based in San Francisco. “The reality is that if the FBI really wants to investigate someone, they have a spectacular arsenal of weapons.”

    Sometimes, police say, that’s not enough.

    Escalante, the Chicago chief of detectives, pointed to a case in which several men forced their way into the home of a retired officer in March and shot him in the face as his wife lay helplessly nearby. When the victim, Elmer Brown, 73, died two weeks later, city detectives working the case already were running low on useful leads.

    But police got a break during a routine traffic stop in June, confiscating a Colt revolver that once belonged to Brown, police say. That led investigators to a Facebook post, made two days after the homicide, in which another man posed in a cellphone selfie with the same gun.

    When police found the smartphone used for that picture, the case broke open, investigators say. Though the Android device was locked with a swipe code, a police forensics lab was able to defeat it to collect evidence; the underlying data was not encrypted. Three males, one of whom was a juvenile, eventually were arrested.

    “You present them with a picture of themselves, taken with the gun, and it’s hard to deny it,” said Sgt. Richard Wiser, head of the Chicago violent crimes unit that investigated the case. “It played a huge role in this whole thing. As it was, it took six months to get them. Who knows how long it would have taken without this.”

  2. #2
    I have mixed feelings on this.

    For one I have no problem from a legal side in creating as secure encryption as you want and would never been in favor of legislating outlawing something like that.

    However I do feel that Apple and Google as good corporate citizens should as a matter of ethics, create a backdoor for law enforcement to execute legal warrants.

    I also think demanding a suspect unlock their own phone (with a warrant) or face several criminal prosecution isn't a 5th amendment issue. But I could easily see liberal courts being stupid about it.

  3. #3
    Any backdoor accessible to every municipal police department or county sherrif's office is going to be available to anyone who wants to use it, law enforcement or not, very quickly. So no, Apple and Google (and others) should not be creating backdoors for law enforcement. Obstruction of justice for refusing to unlock a phone covered by a warrant is and should be standard practice though.
    Last night as I lay in bed, looking up at the stars, I thought, “Where the hell is my ceiling?"

  4. #4
    Quote Originally Posted by LittleFuzzy View Post
    Any backdoor accessible to every municipal police department or county sherrif's office is going to be available to anyone who wants to use it, law enforcement or not, very quickly. So no, Apple and Google (and others) should not be creating backdoors for law enforcement. Obstruction of justice for refusing to unlock a phone covered by a warrant is and should be standard practice though.
    I'm pretty confident that companies like Apple and Google can find a way to create a backdoor that has to go through their systems. Nothing is full proof of course but logically it shouldn't be too complex.

  5. #5
    Hang on. What makes anyone think Google, Apple, or Microsoft are "good corporate citizens"?

    For that matter....what makes us think any other powerful corporate entities are "good", and conducting their business ethically, which means nothing more than following old laws that are already full of conflict but have never been challenged or changed?
    Last edited by GGT; 09-28-2014 at 01:22 AM.

  6. #6
    Quote Originally Posted by LittleFuzzy View Post
    Any backdoor accessible to every municipal police department or county sherrif's office is going to be available to anyone who wants to use it, law enforcement or not, very quickly. So no, Apple and Google (and others) should not be creating backdoors for law enforcement. Obstruction of justice for refusing to unlock a phone covered by a warrant is and should be standard practice though.
    I think the issue here is creating phones that Apple and Google can't unlock, even if they wanted to. Basically pre-empting contempt by making it impossible (or making it unavoidable, depending on how you look at it).

  7. #7
    I am very skeptical, both from legal and technical viewpoint.

    The technical problem is, keeping a back-door open is technically dangerous. Doesn't matter if only the government has access to it. We have all seen the latest problems that always arise with software like Heartbleed and Shellshock. Having a back-door system in your system that you may not update (as a user) for legal reasons, means that you may have a undetectable and or unfix-able security threat in your own computer. This means threats to sensitive data, and I don't mean naked selfless, but bank account access date etc.

    Legally I have a huge problem if I won't be able to use my own devices for non-criminal purposes with the software . The backdoor policy is not legally compatible with open source software. At least not with those under GPL license (e.g. Linux). This legislation actually rules out Linux as an OS for any communicating device.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  8. #8
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Not to mention that it's a stupid thing to do if US companies want to sell their software anywhere else in the world.
    Quote Originally Posted by Dreadnaught View Post
    I think the issue here is creating phones that Apple and Google can't unlock, even if they wanted to. Basically pre-empting contempt by making it impossible (or making it unavoidable, depending on how you look at it).
    "pre-empting contempt"? What? The warrant says: "Unlock the phone and hand over the data." It doesn't matter in the slightest whether that encryption was activated later or automatically in the beginning. Because full-storage encryption is already available - it's just not activated by default.
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  9. #9
    Quote Originally Posted by Lewkowski View Post
    Nothing is full proof of course but logically it shouldn't be too complex.
    You want a backdoor that only the government can access, and only access while on legal grounds, and you think thats not complex?

    All this encryption does is move the snooping a little higher up the chain of law enforcement. You would have to be a bloody idiot to think the government doesn't already have the encryption algorithms. Its suggested thats why TrueCrypt shutdown, and Apple dropped its warrant canary from its transparency report a few months ago.

    Not that it matters much anyway, with everything being cloud based encryption doesn't mean shit. #fappening
    "In a field where an overlooked bug could cost millions, you want people who will speak their minds, even if they’re sometimes obnoxious about it."

  10. #10
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Technical detail: Of course they have the algorithms. EVERYONE has access to the algorithms. Doesn't do you much good, though, when no attacks are known because then you'll have to rely on brute force.
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  11. #11
    I wonder anyway how much good that is, you can use tethering on your phone and use the phone only as black channel, doing the encryption on a second device that is based on a bare metal software.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  12. #12
    Quote Originally Posted by Ominous Gamer View Post
    You want a backdoor that only the government can access, and only access while on legal grounds, and you think thats not complex?

    All this encryption does is move the snooping a little higher up the chain of law enforcement. You would have to be a bloody idiot to think the government doesn't already have the encryption algorithms. Its suggested thats why TrueCrypt shutdown, and Apple dropped its warrant canary from its transparency report a few months ago.

    Not that it matters much anyway, with everything being cloud based encryption doesn't mean shit. #fappening
    The government doesn't have access. Apple does, and Apple complies with the government when asked for it. That's the idea. This makes it so random Joe government official can't just snoop without a warrant.

  13. #13
    I want to decide myself which data I want to give to Apple/Google/Samsung and which I don't.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  14. #14
    Quote Originally Posted by Lewkowski View Post
    The government doesn't have access. Apple does, and Apple complies with the government when asked for it.
    You don't know this, and you wouldn't know if, or more likely when, the government did gain access. Thats why I mentioned Apple's canary statement. Its already been shown that the government can and does secretly take businesses to court for encryption solutions, and once those solutions are handed over the system thats based around them is compromised.
    "In a field where an overlooked bug could cost millions, you want people who will speak their minds, even if they’re sometimes obnoxious about it."

  15. #15
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Erm, no, Ominous. It doesn't work the way you think it does.

    There are three ways to break an encryption:
    a) There's a backdoor built in on purpose.
    b) The encryption algorithm has some kind of weakness
    c) The encryption algorithm has a bug (not exactly the same as b)
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  16. #16
    Quote Originally Posted by Khendraja'aro View Post
    Erm, no, Ominous. It doesn't work the way you think it does.

    There are three ways to break an encryption:
    a) There's a backdoor built in on purpose.
    b) The encryption algorithm has some kind of weakness
    c) The encryption algorithm has a bug (not exactly the same as b)

    Lavabit was forced to hand over their encryption keys when the government went after Snowden. 11 pages at type 4 font. There is nothing stopping our government from taking Apple to court in an attempt to force them to start/maintain a database of keys assigned to each device.
    "In a field where an overlooked bug could cost millions, you want people who will speak their minds, even if they’re sometimes obnoxious about it."

  17. #17
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    You're confusing the keys for the algorithms, though.

    And if you're letting the clients bring their own private keys then the government is shit out of luck. Because that's the way to do it: The stuff stays encrypted on the servers and you only decrypt it client-side. The only keys the server should possess are the public keys.
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  18. #18
    Khen is right here. Algorithms are and should be open. It's the keys that are private. This is like a door lock, knowing or not knowing how the door lock works should not be a part of the security it provides.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  19. #19
    Quote Originally Posted by earthJoker View Post
    It's the keys that are private.
    and thats the issue, from the phone 3gs and up, the encryption used is only as strong as your trust in the government not recording the keys as they are created. considering how many "secret" cases have come to light concerning the government going after similar information, that trust shouldn't exist.
    Last edited by Ominous Gamer; 09-29-2014 at 05:41 PM.
    "In a field where an overlooked bug could cost millions, you want people who will speak their minds, even if they’re sometimes obnoxious about it."

  20. #20
    Quote Originally Posted by Ominous Gamer View Post
    and thats the issue, from the phone 3gs and up, the encryption used is only as strong as your trust in the government not recording the keys as they created. considering how many "secret" cases have come to light concerning the government going after similar information, that trust shouldn't exist.
    That would fall under the back door category that Khend already mentioned. The software would have to be purposefully designed in such a way as to expose the private key. The government having the public key wouldn't make an ounce of difference.

  21. #21
    Im thinking more along the lines of being intercepted between the time of creation to it being burned into the silicon. Apple has admitted that they have chosen not to record the keys, not that it wasn't possible.
    "In a field where an overlooked bug could cost millions, you want people who will speak their minds, even if they’re sometimes obnoxious about it."

  22. #22
    It is actually possible to have encryption in the application layer, but of course only if the OS doesn't spy it's applications. Apple has a closed ecosystem where you cannot that easily install custom software.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  23. #23
    Quote Originally Posted by earthJoker View Post
    It is actually possible to have encryption in the application layer, but of course only if the OS doesn't spy it's applications. Apple has a closed ecosystem where you cannot that easily install custom software.
    Apple used to use software based encryption until the 3GS, investigators learned how to perform memory dumps.
    "In a field where an overlooked bug could cost millions, you want people who will speak their minds, even if they’re sometimes obnoxious about it."

  24. #24
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    And hardware based encryption helps you exactly how against that type of attack?
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  25. #25
    Hardware encryption is probably the most effective why to protect against an attacker that has physical access to the device. But I think that is the rare case, usually attackers try to access over the network, where software encryption is sufficient.

    Well as long as there is no Trojan in the system.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  26. #26
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    No kind of encryption scheme will help you against memory dumps - the key has to reside somewhere, after all.
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  27. #27
    How about your brain?

    Edit:
    The private encryption key resides in a part of the chip that can't be read. It only decrypts the partition if a password is entered into the device. That's how the chip on your credit/debit card works.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  28. #28
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    And this password, of course, never resides in memory.

    It may be a workable solution for chipcards where you have to enter your password once and it can be safely discarded immediately after the transaction has concluded. It's not so usable on a computer / smartphone where you need constant access to data. You'd have to enter your password for every e-mail you get. Every time you open the browser. Every time you open a new tab. Every time you browse to a new page. Every time you get a call. Every time you make a call.

    In short: A solution for the highly paranoid only. And even those would be pissed off after a while because it's so clunky.
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  29. #29
    But such chips exists. They are able to decrypt needed data on the fly. And no, you don't need to enter the password every single time, it gets stored in a non-readable register for some time.

    You never used Ubuntu? If you do a sudo call, you need to enter the password, but only the first time. Than it has a timeout.

    When you do on-line banking you also enter your password once per session.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  30. #30
    You may find this interesting.
    http://en.wikipedia.org/wiki/Secure_cryptoprocessor

    But as I said, this is only needed if the attacker has physical access to your device.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •