Blogs > The Law Blogger

The Law Blogger is a law-related blog that informs and discusses current matters of legal interest to readers of The Oakland Press and to consumers of legal services in the community. We hope readers will  find it entertaining but also informative. The Law Blogger does not, however, impart legal advice, as only attorneys are licensed to provide legal counsel.
For more information email: tflynn@clarkstonlegal.com

Tuesday, March 15, 2016

Encryption, Law Enforcement and WhatsApp

As the terrorist shooting case in San Bernardino, California receives world-wide headlines, another struggle over encryption is quietly playing out between the federal government and a well-known and well-liked technology company.

WhatsApp, the world's largest instant messaging service, is owned by Facebook. The app allows users to send and receive instant messages and to place phone calls over the Internet. It has over a billion daily users.

Recently, the app service has taken the steps necessary to encrypt its customers' messages from start to finish; no one but the relevant users will be able to access messages. With its long tradition of wiretapping land line phones, federal law enforcement agencies have been chaffing at their inability to tap into the data contained in WhatsApp messages.

Apparently, a federal judge has approved a wiretap request involving WhatsApp in a non-terrorist criminal investigation. Like the iPhone in the San Bernardino case, the feds cannot access the data due to the company's ingenious encryption.

There will be a growing number of cases like these where the antiquated federal wiretapping statutes become increasingly ineffectual relative to the always-improving encryption software and privacy applications.

Should Congress pass new laws that would force private technology companies to develop software allowing law enforcement to access encrypted data through a back door? For their part, law breakers love the idea that the technology they are using ensures no one other than the intended will receive their messages.

So far, the federal government has elected not to drag WhatsApp into court to compel a resolution. Some tech experts believe they are waiting for the perfect storm to bring the right case into the courthouse.

Post #530

www.clarkstonlegal.com
info@clarkstonlegal.com




Labels: , , ,

Monday, March 7, 2016

Privacy vs National Security: Apple Strikes Back

The San Bernardino shooting has taught us that, if you are a terrorist intent on communicating with your comrades-in-arms, the devices you select for such communication, data transmission and storage will be manufactured by Apple. This is largely because the NSA, FBI, Homeland Security or other law enforcement agencies cannot reach the data contained in the device without it self-destructing.

The battle between privacy -more specifically, encryption- and national security has been playing out at least since Edward Snowden drew attention to the issue with his leaks back in 2013. Apple has drawn a line-in-the-sand on the San Bernardino shooting case, which is puzzling at first considering that the device in question was supplied by the county government and also considering Apple's track record of cooperation in other criminal investigations.

Walter Isaacson's 2011 authorized biography of Apple founder Steve Jobs sets a detailed stage for the privacy vs security debate that the December California terrorist shooting has brought onto center stage within the national security context. By now, it is a matter of technological and intellectual history that Jobs and co-founder Steve Wozniak had fundamental differences on the critical issue of the software architecture to be designed and implemented for their wonderful computing machines.

Jobs favored, and prevailed, on the use of closed-source software for Apple devices, shunning Wozniak's preferred open-source approach; the approach utilized by Microsoft's Bill Gates. Now, as a result of these 1980s macro-planning decisions, Apple products are rarely afflicted with computer viruses like Microsoft products and hardware.

In addition, it turns out that the closed source approach is far superior from a privacy and data integrity standpoint. For example, if someone other than the owner attempts to infiltrate the data -to hack into the data- then the data stored on an Apple device will be destroyed.

This is the problem currently facing the FBI in the California shooting case. They have sought and have been granted injunctive relief from the United States District Court for California's Central District, Eastern Division.

In the introduction to Apple's motion to set aside the injunction, the tech giant's heavy-weight lawyers from Gibson, Dunn & Crutcher state their client's position on the matter:
Apple is committed to data security. Encryption provides Apple with the strongest means available to ensure the safety and privacy of its customers against threats known and unknown. For several years iPhones have featured hardware and software based encryption of their password-protected contents.These protections safeguard the encryption keys contained on the device with a passcode designated by the user during setup. This passcode immediately becomes entangled with the iPhone's Unique ID ["UID"] which is permanently assigned to that one device during the manufacturing process. The iPhone's UID is neither accessible to other parts of the operating system nor known to Apple. These protections are designed to prevent anyone without the passcode from accessing encrypted data on iPhones.
Cyber-attackers intent upon gaining unauthorized access to a device could break a user-created passcode, if given enough chances to guess and the ability to test passwords rapidly by automated means. To prevent such "brute-force" attempts to determine the passcode, iPhones running the iOS 8 or higher include a variety of safeguards. For one, Apple uses a "large iteration count" to slow attempts to access an iPhone, ensuring that it would take years to try all combinations of a six-character alphanumeric passcode. Finally, Apple includes a setting that -if activated- automatically deletes encrypted data after ten consecutive incorrect attempts to enter the passcode. This combination of security features features protects users from attackers or if, for example, the user loses the device.
Apple does not believe the federal government's assurances that it is just this one device; just this one time. Apple knows there will be another time with another one of its devices.

Also, the world's most valuable company is concerned about the precedent this case would set if it is forced by the feds to create software to access a user's private data, even when that user is a murderous terrorist. Apple asserts such an injunction would fundamentally compromise the privacy of its users; an unacceptable scenario for the corporation.

For its part, the USDOJ advanced a traditional and fundamental point: companies -and for that matter, citizens- cannot select which laws it will honor and which it will violate. In addition, they characterize this case as a particularly dangerous one which could lead to more deaths if not aggressively pursued.

A hearing on Apple's motion is currently scheduled for March 22, 2016, in Riverside, CA. Stay tuned for further developments in this important privacy rights case.

Post #526

www.clarkstonlegal.com
info@clarkstonlegal.com





Labels: , , , , , , , , ,

Saturday, November 8, 2014

Another Encrypted Cell Phone Case Gets Attention

By: Timothy P. Flynn

A judge in Virginia was recently faced with a decision whether to allow a county prosecutor to compel an accused to produce two things: his cell phone passcode and his fingerprint.  In Virginia vs David Charles Baust, the judge granted the prosecutor's request for Baust to produce his fingerprint, but denied the request for his cell phone encrypted passcode.

The accused deployed technology in his bedroom; he utilized a recorder that sent images of his sex play to his cell phone.  Only, in February, a woman came forward saying that Baust assaulted her and that she believed the incident was recorded.

Jackpot for the prosecutor if they can get their hands on the video; game over for Mr. Baust.  Defense counsel, however, says "not-so-fast"; there are constitutional rights to consider.

Local law enforcement executed a search warrant and seized Baust's cell phone and video recording equipment. The police, however, have been prevented from "entering" Baust's cell phone due to the passcode encryption on the device.

The issue before the Virginia trial court was whether compelling the defendant to produce a piece of incriminating evidence violates his constitutional right against self-incrimination under the 5th Amendment to the United States Constitution; and whether producing the passcode and/or his fingerprint constitutes "testimonial communication".

If his passcode is deemed to be "testimonial communication" then it is protected under the 5th Amendment and Baust cannot be compelled to produce the information.  We've seen this movie before here in Detroit, Michigan: United States vs Kirschner, from the United States District Court for the Eastern District of Michigan.

Like the trial court judge in Virginia, Judge Paul Borman held in Kirschner that compelling an accused to provide a passcode for his encrypted cell phone involved a mental process deemed to constitute "testimonial communication" and was thus protected by the 5th Amendment.

As for the fingerprint, Baust could be forced to produce that all day long; just as he could be forced to submit to a line-up, provide a voice sample, biological sample, or a handwriting exemplar.  These things are not testimonial in nature.

It is a long way from a state trial court to SCOTUS review.  The SCOTUS granted Certiorari in a cell phone data retrieval case from California case last year; presumably, the California case will be argued to the High Court at some point this term.



Labels: , , , , , , , ,