Blogs > The Law Blogger

The Law Blogger is a law-related blog that informs and discusses current matters of legal interest to readers of The Oakland Press and to consumers of legal services in the community. We hope readers will  find it entertaining but also informative. The Law Blogger does not, however, impart legal advice, as only attorneys are licensed to provide legal counsel.
For more information email: tflynn@clarkstonlegal.com

Monday, March 7, 2016

Privacy vs National Security: Apple Strikes Back

The San Bernardino shooting has taught us that, if you are a terrorist intent on communicating with your comrades-in-arms, the devices you select for such communication, data transmission and storage will be manufactured by Apple. This is largely because the NSA, FBI, Homeland Security or other law enforcement agencies cannot reach the data contained in the device without it self-destructing.

The battle between privacy -more specifically, encryption- and national security has been playing out at least since Edward Snowden drew attention to the issue with his leaks back in 2013. Apple has drawn a line-in-the-sand on the San Bernardino shooting case, which is puzzling at first considering that the device in question was supplied by the county government and also considering Apple's track record of cooperation in other criminal investigations.

Walter Isaacson's 2011 authorized biography of Apple founder Steve Jobs sets a detailed stage for the privacy vs security debate that the December California terrorist shooting has brought onto center stage within the national security context. By now, it is a matter of technological and intellectual history that Jobs and co-founder Steve Wozniak had fundamental differences on the critical issue of the software architecture to be designed and implemented for their wonderful computing machines.

Jobs favored, and prevailed, on the use of closed-source software for Apple devices, shunning Wozniak's preferred open-source approach; the approach utilized by Microsoft's Bill Gates. Now, as a result of these 1980s macro-planning decisions, Apple products are rarely afflicted with computer viruses like Microsoft products and hardware.

In addition, it turns out that the closed source approach is far superior from a privacy and data integrity standpoint. For example, if someone other than the owner attempts to infiltrate the data -to hack into the data- then the data stored on an Apple device will be destroyed.

This is the problem currently facing the FBI in the California shooting case. They have sought and have been granted injunctive relief from the United States District Court for California's Central District, Eastern Division.

In the introduction to Apple's motion to set aside the injunction, the tech giant's heavy-weight lawyers from Gibson, Dunn & Crutcher state their client's position on the matter:
Apple is committed to data security. Encryption provides Apple with the strongest means available to ensure the safety and privacy of its customers against threats known and unknown. For several years iPhones have featured hardware and software based encryption of their password-protected contents.These protections safeguard the encryption keys contained on the device with a passcode designated by the user during setup. This passcode immediately becomes entangled with the iPhone's Unique ID ["UID"] which is permanently assigned to that one device during the manufacturing process. The iPhone's UID is neither accessible to other parts of the operating system nor known to Apple. These protections are designed to prevent anyone without the passcode from accessing encrypted data on iPhones.
Cyber-attackers intent upon gaining unauthorized access to a device could break a user-created passcode, if given enough chances to guess and the ability to test passwords rapidly by automated means. To prevent such "brute-force" attempts to determine the passcode, iPhones running the iOS 8 or higher include a variety of safeguards. For one, Apple uses a "large iteration count" to slow attempts to access an iPhone, ensuring that it would take years to try all combinations of a six-character alphanumeric passcode. Finally, Apple includes a setting that -if activated- automatically deletes encrypted data after ten consecutive incorrect attempts to enter the passcode. This combination of security features features protects users from attackers or if, for example, the user loses the device.
Apple does not believe the federal government's assurances that it is just this one device; just this one time. Apple knows there will be another time with another one of its devices.

Also, the world's most valuable company is concerned about the precedent this case would set if it is forced by the feds to create software to access a user's private data, even when that user is a murderous terrorist. Apple asserts such an injunction would fundamentally compromise the privacy of its users; an unacceptable scenario for the corporation.

For its part, the USDOJ advanced a traditional and fundamental point: companies -and for that matter, citizens- cannot select which laws it will honor and which it will violate. In addition, they characterize this case as a particularly dangerous one which could lead to more deaths if not aggressively pursued.

A hearing on Apple's motion is currently scheduled for March 22, 2016, in Riverside, CA. Stay tuned for further developments in this important privacy rights case.

Post #526

www.clarkstonlegal.com
info@clarkstonlegal.com





Labels: , , , , , , , , ,

Monday, June 24, 2013

National Security vs Individual Privacy in the Big Data Era

By:  Timothy P. Flynn

This post is about the rights of a now famous arrest warrant fugitive, and about each of our rights to maintain private electronic data.

The Fourth Amendment to the United States Constitution guarantees rights to all private citizens:
...to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
This important amendment arose, in part, as a response to abuses of power during the American Revolution associated with the reviled "writ of assistance"; a general search warrant that allowed the King's soldiers to toss your home with or without reason.

Fast forward to the 21st Century, which opened with unprecedented foreign terrorist attacks on our soil, and we see that our "papers and effects" have been digitized.  Most of us now have fairly robust electronic profiles as opposed to actual "papers and effects".

Now, 13-years into the e-Century, and a dozen years after the fateful 9/11 attacks on New York and Washington, the federal government wants, and apparently gets, direct access to the Big Data of our private lives.  This access has been granted in the name of national security and is backed by the Patriot Act, and other powerful national security-based federal laws.

The extradition and federal prosecution of  Edward Snowden will test these opposing concepts of liberty and national security in the digital age.  Like the cases of Julian Assange and Aaron Swartz, Snowden's revelations about the federal government's snooping is becoming a digital clarion call.

Snowden, a former NSA contractor, made some significant disclosures about what the NSA has been doing, to the Guardian newspaper in London earlier in the month.  The feds have been hunting him with an international arrest warrant ever since for violations of the Espionage Act.

Apparently, Mr. Snowden is now on the move, internationally, as in Jason Bourne style.  Only this is real, not fiction.  Once the United States has Mr. Snowden either extradited or rendered back to the US, he will face criminal charges in federal court in Virginia for leaking the NSA's digital secrets to the media.

Since its inception in 1917 up to the current administration, Presidents have only charged 3 individuals with violating the Espionage Act.  President Obama has prosecuted 6 individuals under the Act.

What does this tell us about the balance between our rights to have our data secure from the prying eyes of the government, and the governments duty to protect our shores from invasion?  Can both interests be served simultaneously?

www.clarkstonlegal.com
info@clarkstonlegal.com

Labels: , , , , , , ,