iPhone app iPad app Android phone app Android tablet app More

Featuring fresh takes and real-time analysis from HuffPost's signature lineup of contributors
Susan Landau

GET UPDATES FROM Susan Landau
 

Moving Rapidly Backwards on Security

Posted: 10/13/10 02:15 PM ET

What is the FBI thinking? The bureau wants to roll back technology -- peer-to-peer voice communications -- and government regulations on encryption in order to be able to wiretap more easily. But our real security problem doesn't lies in law enforcement's inability to read criminals and terrorist on-line communications. Our real problems lie in the cyberintrusions into U.S. systems and a consequent need to secure U.S. communications.

Electronic communications used to be voice calls using a central provider (think AT&T). These were relatively easy for law enforcement to wiretap. Now electronic communications are peer-to-peer and encrypted messages. These confuse wiretaps because peer-to-peer communications travel in unexpected ways through the network, while encrypted communications thwart wiretaps because the communications are unintelligible without a decryption key. A bill being drafted by the FBI seeks to turn this situation around.

The bureau wants peer-to-peer services to redesign their systems so they can easily accommodate wiretapping -- another way to put this is that the FBI wants applications carrying voice to work like the centralized phone system. The FBI also wants communications carriers that supply encryption to decrypt encrypted wiretapped communications. But contrary to what might appear, these proposed policies would move the U.S in a treacherous direction.

Making it easy for law enforcement to access voice communications means making it easy for others as well. These others include criminal groups and other nation states. In 1994, Congress passed the Communications Assistance for Law Enforcement Act (CALEA), mandating that all digitally-switched telephone networks be built "wiretap accessible." The question is "wiretap accessible" by whom? Consider what happened in Greece in 2004-2005. As a result of CALEA-type specifications built into the Vodafone Greece cellphone network, the communications of over one hundred leading members of the Greek government, including the Prime Minister, were eavesdropped upon for ten months by parties unknown. Nor was that situation unique.

Recently an IBM researcher found that a Cisco wiretapping architecture designed to accommodate law-enforcement requirements -- a system already in use by major carriers -- had numerous security holes in its design. This would have made it easy to break into the communications network and surreptitiously wiretap private communications.

The U.S. is a prime target for industrial espionage. In August, U.S. Deputy Secretary of Defense William Lynn III said that threats to U.S. intellectual property -- the inventions, processes, and business plans of U.S. industry -- "may be the most significant cyberthreat that the United States will face over the long term." The highly publicized attacks against Google that were revealed in January were part of a pattern that includes cyberthefts from U.S. Army sites, NASA, Oak Ridge National Laboratories, ExxonMobil, Northrop Grumman, and many other U.S. companies.

Governmental key escrow -- an idea that publicly reared its head in 1993 and was abandoned later that decade -- means that key repositories, whether governmental or carrier-owned, become a rich target for attack. Redesigning peer-to-peer communications systems to simplify FBI wiretapping means redesigning peer-to-peer communications systems to simplify interception by anyone, including organized crime and other nation states. Even the most innocuous sounding proposal -- requiring overseas communications providers to have a U.S. office to accommodate law-enforcement wiretapping -- opens a dangerous door. This past summer the governments of the United Arab Emirates and India demanded that BlackBerrys, which provide strong communications security to their users, be redesigned to accommodate efforts at interception. If the U.S. requires a U.S. presence of overseas communications providers to enable access to wiretapping, other nations will demand the same of U.S. communications providers. The privacy and security of communications of overseas U.S. travelers -- think businesspeople -- will suffer.

The FBI proposal occurs at a time when our highly networked society affords law enforcement increasing resources. Communications interception provides rich material to government investigators. Cell phones and the use of transactional information -- the who, what, where of telephone calls and email -- helped find Khalid Sheikh Mohammed, the alleged plotter of the September 11 attacks, and Hamdi Issac Adus, one of the participants in the failed London bombing of July 21, 2005, for example.

In many instances, it's not that the FBI can't wiretap; it is just that the bureau can't do so cheaply. Encryption and peer-to-peer technologies make law-enforcement capture of conversations expensive. So instead of expending funds on individual wiretaps, the bureau wants communications systems redesigned to simplify its problems. This would come at a cost of unsecuring the communications of everyone else. It is a solution we can't afford. The FBI's proposal is dangerous, and its benefits simply do not outweigh its risks.

 
What is the FBI thinking? The bureau wants to roll back technology -- peer-to-peer voice communications -- and government regulations on encryption in order to be able to wiretap more easily. But ou...
What is the FBI thinking? The bureau wants to roll back technology -- peer-to-peer voice communications -- and government regulations on encryption in order to be able to wiretap more easily. But ou...
 
 
  • Comments
  • 6
  • Pending Comments
  • 0
  • View FAQ
Comments are closed for this entry
View All
Recency  | 
Popularity
08:54 PM on 10/19/2010
The broader issue is this obsession with terrorism that is stripping away what privacy rights we have left. Telecom companies should not be discouraged from protecting the privacy rights of their customers. Read here: http://brighton-towne.blogspot.com/2010/10/keep-police-away-from-your-iphone.html
01:08 AM on 10/14/2010
I get the FBI rationale for wanting to be able to "wiretap" electronic communication, but I also agree with this article that doing so puts more data at risk. Though, it does make me wonder what was said at the time that the FBI wanted to make it easier for them to wiretap phones and if there was any controversy then...
This user has chosen to opt out of the Badges program
09:08 AM on 10/14/2010
The 1994 Communications Assistance for Law Enforcement Act (CALEA) was very controversial at the time it was passed; aspects of it were litigated for years afterwards (stemming from disagreements on how communications systems were to be designed and what data service providers had to give to law enforcement). CALEA explicitly exempted "information services" (understood to be the Internet), while in 2000, the U.S. government loosened export controls on products with strong cryptography. The latter decision was made with the expectation/understanding that this would mean more domestic use of encryption. So with respect to both wiretapping the Internet and encryption, policy decisions were in favor of increased communications security, even though it was understood that there would be risks from this. Now the FBI is trying to roll the clock back, even while the biggest threats are arising from cyberexploitation --- the theft of data electronically.
11:28 AM on 10/14/2010
Thanks for the follow-up info.
HUFFPOST SUPER USER
realitytrumpsbull
Two 'alves of coconut!
11:30 PM on 10/17/2010
I'd say if you're really really really worried about your data, you probably want to stay the hell off the internet to begin with, because everybody's out there spying on somebody else, and then you have the interesting issue of where this country's connected to the rest of the world by all these internet cable-things, so now you've got inquiring minds overseas, which includes things like intellectual property theft, business-related information, so forth, and so on. The internet is a boon, in that it provides us with information, but it can also provide unfriendly parties information about us, or from us without our consent, through the miracle of hacking. And, government people aren't the only ones out there with prying eyes and a burning desire to know what's on your hard drive. So, if you've got a Real Big Secret, you're back to using lemon juice.
jhNY
Mercy.
01:56 PM on 10/13/2010
What is the FBI thinking? That if they can do whatever they want whenever they want to, they can never be held to account for going too far-- just like always.