I’m coming down from spending a few days at Usenix Security, right here in my hometown of Baltimore. This means that my days have been taken up with two kinds of conversation: first, explaining to colleagues why Baltimore isn’t actually like The Wire. And second, trying not to talk about AI.
Here I’m going to break both of those rules.
I have many worries about what AI means for our field, for various definitions of “field”. But in this post I want to focus on just one thing I’ve started worrying about, and it’s a perverse thing: specifically, I’m concerned that AI is going to make software much too secure.
While that doesn’t sound so bad on the surface, there’s a consequence to this. I mean something very specific: I’m concerned that U.S. intelligence and law enforcement agencies are about to go dark, meaning: that they’re going to suddenly lose a huge portion of their capability. And that this isn’t going to be simply a problem for those agencies, but also for those of us who value computer security and privacy in general.
Going Dark, and the era of law enforcement hacking
To explain how we got here, we need to talk about recent history. This gives me a legitimate excuse to reference The Wire, just because it embeds a realistic snapshot of what electronic surveillance looked like way back in 2002. If you’ve seen the show, you’ll recall that the cops are trying to spy on drug dealers who use payphones and burners, and primarily use them for voice calls. The mobile phones in the show are relatively new — but from a technological perspective — nothing in this scenario would have shocked a cop who jumped forward from, say, 1989.
In less than a decade from the premier of that show, everything was entirely different.
The change began in the late 2000s, thanks to the rise of smartphones and texting. Because smartphones can actually store data as well as conveying it, those phones became a new source of law-enforcement capability. Coincidentally, around 2010 Apple began encrypting iPhone data using a key derived from the user’s passcode (with Android phones following shortly thereafter.) The following year, Apple deployed end-to-end encryption in iPhone text messages. By 2014, a texting startup named WhatsApp had gathered 600 million users worldwide. By 2016 those users, now nearly a billion, were all using default end-to-end encrypted messaging. The chart below gives one view of how quickly that change took place:
The FBI and law enforcement agencies were not insensitive to what was happening. In 2014, Director Comey announced an initiative called Going Dark, which would launch a “national conversation” about what providers could do — or be compelled to do — to make these new communications media legible to law enforcement and counterintelligence.
In 2016, the agency stopped merely talking about this. After a terrorist attack left the FBI holding a shooter’s locked iPhone, the agency ordered Apple to give them access. The company refused. What broke the stalemate — and, to some extent, ended “Going Dark” itself — was something that neither the FBI nor Apple expected. An outside company announced that there was no need for Apple’s assistance: they could simply hack the phone.
... continue reading