> You claimed in the previous thread you linked to that CALEA (or, charitably, some other law) required US companies to backdoor their encryption schemes.
As a customer, encryption provided by a third party (especially in situations where it is difficult or impossible to provide my own encryption - like how would I provide my own encryption that goes over Skype?) which is designed to be removed upon request by the government is backdoored.
> I asked you to cite any authority anywhere backing that argument up. Your response is to cite examples of crappy software security, and then to sneakily reformulate your argument so that it applies only to encryption that isn't "end-to-end".
Neither Blackberry nor Skype were crappy software security solutions until they were subverted. They were subverted on purpose. It's disingenuous to call them crappy without digesting the context by which they came to remove strong security garuntees. Like the case with Apple (you didn't reply to that) either this subversion was done voluntarily or it was compelled.
My thesis is that the constellation of laws and their interpretation are such that the any products which become leading communication services will be subverted. Through mandatory data ecrow and the TPD as we spoke about earlier, and through financial and political pressures, incentives and (as we know in extreme cases from the Snowden docs) sabotage.
So perhaps it's a vocabulary issue? Companies that will sell in-transit encryption but remove it or store plaintext I would call a backdoor. We agree that this is required by law.
Where we seem to disagree most is the canonical case of Skype. Skype was purposefully subverted and I argue that the constellation of laws we've been discussing were used to do it. I can imagine two other stories one could tell:
1) E2E encryption was removed voluntarily; no compulsion (I would need a lot of convincing)
2) E2E encryption removal was a silly regression that has been noted but not fixed for years (I would need even more convincing)
I would agree wholeheartedly that when it comes to the Skype case there are technically, by letter of law, no laws that force companies to remove or backdoor E2E.
I think here is where we disagree: I think in practice, by the examples we've been able to witness, that broad interpretations of these laws, in conjunction with financial and political pressure are in fact used to leverage changes law enforcement and intelligence community members need.
As a customer, encryption provided by a third party (especially in situations where it is difficult or impossible to provide my own encryption - like how would I provide my own encryption that goes over Skype?) which is designed to be removed upon request by the government is backdoored.
> I asked you to cite any authority anywhere backing that argument up. Your response is to cite examples of crappy software security, and then to sneakily reformulate your argument so that it applies only to encryption that isn't "end-to-end".
Neither Blackberry nor Skype were crappy software security solutions until they were subverted. They were subverted on purpose. It's disingenuous to call them crappy without digesting the context by which they came to remove strong security garuntees. Like the case with Apple (you didn't reply to that) either this subversion was done voluntarily or it was compelled.
My thesis is that the constellation of laws and their interpretation are such that the any products which become leading communication services will be subverted. Through mandatory data ecrow and the TPD as we spoke about earlier, and through financial and political pressures, incentives and (as we know in extreme cases from the Snowden docs) sabotage.
So perhaps it's a vocabulary issue? Companies that will sell in-transit encryption but remove it or store plaintext I would call a backdoor. We agree that this is required by law.
Where we seem to disagree most is the canonical case of Skype. Skype was purposefully subverted and I argue that the constellation of laws we've been discussing were used to do it. I can imagine two other stories one could tell:
1) E2E encryption was removed voluntarily; no compulsion (I would need a lot of convincing)
2) E2E encryption removal was a silly regression that has been noted but not fixed for years (I would need even more convincing)
I would agree wholeheartedly that when it comes to the Skype case there are technically, by letter of law, no laws that force companies to remove or backdoor E2E.
I think here is where we disagree: I think in practice, by the examples we've been able to witness, that broad interpretations of these laws, in conjunction with financial and political pressure are in fact used to leverage changes law enforcement and intelligence community members need.