There's an excellent reason why just about everyone in Silicon Valley is alarmed by the FBI's demands for encryption backdoors: we expect the feds will show up at our doorsteps next.
That's why Google, Twitter, Facebook, Microsoft, WhatsApp, and other software companies are backing Apple publicly. They filed a brief in federal court this week warning that requiring a backdoored fbiOS would kick off an unprecedented wave of surveillance demands. They say, with some understatement, that "investigative tools meant for extraordinary cases may become standard in ordinary ones."
This is not merely a convenient intersection of marketing and customer privacy. Given the existence of scores of federal police agencies, it's simple self-preservation. Once an fbiOS precedent is set, the U.S. Marshals, Homeland Security, postal inspectors, Secret Service, and military police will also invoke the All Writs Act to demand that companies build equally extensive backdoors. Local and state police won't want to be left behind.
It's true that, given enough time and resources, any large Silicon Valley firm could comply with a lone All Writs Act demand. They have capable engineering teams. Details like legality and constitutionality aside, Cupertino could puzzle out how to undermine its own security by creating a backdoor to unlock the San Bernardino shooter's iPhone.
But when there's a queue of police agencies already forming, the likelihood of being required to code custom backdoors for everyone should worry even the largest companies. The Manhattan district attorney, Cyrus R. Vance Jr., acknowledges he'd "absolutely" want to invoke an fbiOS precedent in his own criminal investigations.
To put these requests in perspective, there were 3,554 wiretaps authorized last year at an average cost of $40,000, plus thousands of additional surveillance orders not included in that total. In 2013, Apple was forced to create a waiting list because of so many police demands. Jon Matonis, the former CEO of Hushmail, said on Twitter: "We received so many international subpoenas for info that I had to create a subpoena division!" Custom backdoors would be far more tricky and expensive.
Operating system makers like Google and Apple are not the only companies at risk. If Apple can be forced to code fbiOS, then the same All Writs Act could force any software company to craft malicious features designed to spy on users. Would in-app searches for certain terms be required to trigger alerts? Travel to certain locations? Would automatic updates quietly implant backdoors? What criminal would enable them? (Most wiretaps are for drug offenses; expect libertarian-leaning software engineers to engage in creative civil disobedience.)
"It is hard to conceive of any limits on the orders the government could obtain in the future," Apple argued in a recent legal brief. "If Apple can be forced to write code in this case to bypass security features and create new accessibility, what is to stop the government from demanding that Apple write code to turn on the microphone in aid of government surveillance, activate the video camera, surreptitiously record conversations, or turn on location services to track the phone's user? Nothing."
The precedent that the FBI hopes to set could put smaller companies like mine out of business. My company, a San Francisco bay area startup that has released a smart news app for iOS and Android, has two founders. We both write code. We don't have a legal department. In fact, by limiting the log data we store, and allowing Recent News to be used anonymously, we're hoping to avoid being hit by legal orders at all.
If a judge chose to slap us with a backdoor order, we have no process to use to comply. My co-founder and I would have to write thousands of lines of code, at virtual gunpoint and on threat of being held in contempt over bugs, based on specifications drafted by prosecutors—who have no knowledge of our iOS or Android technology stack or how our recommendation engine written in Python works. (Normally we release new versions of Recent News to beta testers to flag device-specific bugs. I doubt the FBI would like that.)
The FBI could simply ask Congress to enact a law mandating backdoors—it's done this before, after all. In 1997, the FBI persuaded one House of Representatives committee to outlaw manufacturing, selling, or importing unapproved encryption devices without backdoors for the Feds. The bill died without a floor vote.
The FBI didn't give up. In early 2008, the bureau completed a "high-level explanation" of backdoor legislation, according to documents obtained by the Electronic Frontier Foundation through open records laws. In 2012, the proposal had morphed to sweep in social-networking sites, email providers, and services like Apple's iMessage. But for the last eight years, despite requests from Capitol Hill, neither the Bush nor Obama administration chose to forward the FBI's proposal to Congress.
If the FBI truly needs to conscript Silicon Valley's software developers, it should be forthright about it and ask Congress for that authority. My company and I would oppose any such law, but at least that would allow an open debate. It's unfortunate but telling that a federal police agency is attempting a clandestine power grab through the courts instead.
the same All Writs Act could force any software company to craft malicious features designed to spy on users.
If you make a point of shooting policemen in video games, expect a knock flashbang grenade at your door.
Well at least they are not using tank mounted battering rams to tear down walls.
It's unfortunate but telling that a federal police agency is attempting a clandestine power grab through the courts instead.
Who better to know the needs of the law enforcement community than the law enforcement community? If the FBI says they need these tools who are the courts to say they don't? It's not a judge's place to substitute his judgement of what an agency needs or is allowed to have for that of the very people tasked with determining what that agency needs or is allowed to have, is it? That's judicial activism, by gum! Judicial deference demands the courts side with the agencies authorized by Congress and acting under the direction of the President absent a clear and compelling argument that they're acting contrary to the enabling legislation or the administrative regulations that bind them. Besides which, the FBI has every incentive to act lawfully, openly, and honestly (because reasons) so we can trust them. If you can't trust your own government, who can you trust?
I don't think people are waking up to how important this is yet. Not just for personal security either. Consider corporations who use smartphones - if the FBI wins, no company will let their employees use one for company business ever again.
It is basically the end of an industry.
Don't worry. It will be a SECURE back door.
Since corporations are evil you might be giving them another selling point.
Why would the government lie? It's only one phone! You're all a bunch of paranoid cynics!
"The iphone is not a "paper" so it's not covered by the Fourth Amendment." Someone who makes this argument will be the next member of the Supreme Court.
If only the Fourth Amendment referred to more than just paper. . . .
The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated,
But are they "special" effects?
If only the 4th amendment had anything to do with this case.
^ This there is no 4th amendment issue here at all. There is a valid, properly issued warrant, and the item to be searched is in police control, and the owner of the item agrees to the search.
Now, the 5th and 13th amendments present some issues...
If cops looked like that I might not mind a police state.
"A murder of local, state, and federal law enforcement agencies would want their own backdoors too."
"Murder" is a group of crows. The correct term for a group of law enforcement is a "sounder".
I don't get what makes the govt believe it has the authority to compel action on the part of these companies. Not that they won't eventually give in, but I'd like to see a judge tell me that I have to sit down, individually, and write code for him. Actually, I'd like to have the opportunity... so you say I have to do this -- okay, let's do it... but then, what, is it contempt or treason or something, when I instead wipe the phone the first time you try to brute-force the password? Prove that I did it willfully, and that it wasn't just an honest bug, After all, what you're asking me to write is something that was, by conscious design, intended to be impossible.
But then again... commerce clause.
That's a good point. These folks are not typically well-versed in any technical subject, never mind programming or crypto. I wonder if they just don't understand what they're asking. I mean, it's not like asking a painter to paint a house a different color. It's like forcing a heart surgeon to do a triple bypass at gunpoint.
An engine-builder friend of mine has a funny anecdote he relates, which is applicable here; he had a customer who was a surgeon of some sort, who was in the shop; I think it goes that one of the employees goes over to the surgeon and says something to the effect of how changing the cam is not unlike doing open-heart surgery, to which the surgeon immediately replies: "Sure, but next time, try doing it with the engine running."
Not sure if that's true, or his -- he's a bit of a storyteller -- but I always got a chuckle from it.
As any programmer will tell you, all you can do is deliver what they ask for which is almost never what they actually want.
Well, I mean, you could see the feature-creep at almost the first instance -- not only do you want me to somehow disable over-the-max-password-attempt wiping of the phone, but you also want me to hook you up to usb or wifi or whatever, and somehow let you enter the password programmatically? It's not like there would necessarily be tests in place for verifying how the system handles automation of brute-force password entry, since, you know, that's implicitly been done through a physical interface, given the basic design of the phone.
I've been writing my buddy at Apple asking him to suggest their bosses send donations to libertarian party candidates. If tech firms were to suddenly wake up and do a Aaron Swartz number recommending the ONLY party that does not want their doors kicked in by goons with guns, shucks, it could be more'n a Libertarian Moment. It could be an Alice's Restaurant Massacre complete with four-part harmony and constitutional amendments to restore the Bill of Rights!
