Apple Inc. logo The encryption engineers at Apple are considering their options, if the U.S. Federal Bureau of Investigation (FBI) is successful at forcing their employer to build back doors into one or several iPhones. The New York Times reported: that

"Apple employees are already discussing what they will do if ordered to help law enforcement authorities. Some say they may balk at the work, while others may even quit their high-paying jobs rather than undermine the security of the software they have already created, according to more than a half-dozen current and former Apple employees. Among those interviewed were Apple engineers who are involved in the development of mobile products and security, as well as former security engineers and executives."

One explanation for this:

“It’s an independent culture and a rebellious one,” said Jean-Louis Gassée, a venture capitalist who was once an engineering manager at Apple. “If the government tries to compel testimony or action from these engineers, good luck with that.”

The tech company estimated it would take 10 engineers about a month to develop the back-door software, some have called, "GovtOS." That estimate assumed the encryption engineers would be on staff and available. Security experts have warned that more court orders to unlock iPhones will likely follow, if the FBI is successful with forcing Apple to unlock the San Bernardino attacker's phone. 

Since the "back doors" are really software, that software must be developed, debugged, tested, and documented like any other. Those tasks require a broader team across multiple disciplines; all of which could be working (instead) on other projects that generate revenue. Then, multiply this by multiple unlock demands. Will the government reimburse Apple for the new, broader project team it creates to build back-door software? Will the government reimburse Apple for the opportunity cost from lost projects and revenues the team members could have completed instead? Will the government reimburse Apple for the costs of hiring engineers and workers to replace those who quit? It will be interesting to see how the financial markets evaluate all of this, if the FBI successfully forces Apple to unlock iPhones.

By using a 227-year-old law, it seems that the FBI and Director James Comey want to direct the development work of private companies to do tasks they should do themselves, while ignoring the unintended consequences to business and jobs. (Remember, experts warned in 2014 that NSA spying could cost the tech industry billions of dollars.) Has the government really thought this through? It seems like they haven't.

Federal Bureau of Investigation logo What are the FBI's goals? An article in Quartz suggested that the FBI is:

"... worried about is the fast-approaching future when its best hackers will be stymied by powerful corporate encryption and security systems. Federal law, in its current state, is of little help. There is no precedent that will allow the government to force a private company to change its security systems so that the FBI can get inside and take a peek. In fact, the Communications Assistance for Law Enforcement Act (CALEA) could be interpreted to restrict the government from doing so. The FBI has apparently decided that it’s time for federal law to change. So its officials have been searching for a particular case that would give them a shot at changing the established legal precedent.."

Learn more about CALEA and the FBI's attempts since 2010 to expand it. An MIT Technology Review article debunked the government's spin and fear-mongering claims of a new period of "warrant-proof phones" (e.g., newer iPhones) and "going dark." There have always been warrant-proof products and services because these (analog or paper-based) items historically didn't archive or store information. So, historical government surveillance was always "dark." While law enforcement may lose some information surveillance sources in the future due to encryption, the multitude of new technologies, products, services, companies, web sites, and mobile apps during the past few years have provided it with far more sources with far more detailed information than it ever had. The old saying seems to apply: can't see the forest for the trees.

I agree. We definitely live in the golden age of surveillance.

The government's argument is weak also because it ignores the option that the well-funded bad guys, such as drug cartels and terrorist networks, can, a) purchase encrypted communications products and services elsewhere outside the USA, and b) hire engineers and programs to maintain their own encrypted systems.

What are your opinions?


Chanson de Roland

Professor Hartzog's concern that we could progress to an Orwellian world of pervasive, if not ubiquitous, surveillance is important and real. But isn't probably of must use to Apple in its current legal disputed with the U.S. government over whether a court can compel Apple to design software that disables its iPhone and iPads' security devices, which essentially lockout even searches that a court's warrant authorizes. The reason that Apple can't make use of Prof. Hartzog's objections is that the All Writs Act, even given its most expansive reading, would only apply to devices that do record and store data so that there is something to search. If the information on a device is ephemeral so that there is nothing to search, then a search warrant is impossible to execute and is, therefore, a useless and vain thing, and no court has authority to order a vain thing or issue All-Writs orders to aid in execution of a vain act, nor does any person subject to such a vain order have any way of carrying it out.

That is why the DuckDuckGo search engine is immune to a search warrant: it is immune from a search warrant and any All-Writs order in aid of a search warrant because it has nothing to search, because it does not store any personally identifiable information, so a search of DuckDuckGo’s recorded searches for any particular person is impossible.

But Apple’s iPhones do store data, so the issue for Apple is different. The issue for Apple in its dispute with the FBI is whether it may design a device that cannot be unlocked for searching. The FBI wants the answer to that issue to be no for Apple and everyone, and it wants to achieve that by means of orders pursuant to the All Writs Act, without Congress taking any action to prohibit Apple et al. from designing lockout devices that prevent any attempt to search without the user’s passcode.

Now, some in government have been so bold as to suggest requiring that at least some systems and devices be designed and required to store heretofore ephemeral conversations, searches, and other information. Because no court could issue such an order pursuant to the All Writs Act, which isn’t an order to search but an order to design a device so that it stores something which can be searched, it would take an act of Congress to require that makers of smart devices design them to store everything that they are capable of recording and/or transmitting. And Congress, after so dramatically curtailing freedom, would presumably take the next step and order that makers of devices design them so that they can be searched, at least upon issuance of a warrant authorizing that search. That would be the end of legal lockout devices.

I think that Congress doing that would violate the First Amendment right of free speech and the constitutional implied rights of privacy and liberty. But the more important thing is this: Any Congress that would seriously contemplate such a thing, much less attempt it, would show that our progress from freedom to totalitarianism and despotism was at its penultimate stage, if not already consummated. And there Professor Hartzog, like Orwell before him, describes and foresees a danger that we must be forever vigilant against.

