

SUBSCRIBE TO OUR FREE NEWSLETTER
Daily news & progressive opinion—funded by the people, not the corporations—delivered straight to your inbox.
5
#000000
#FFFFFF
To donate by check, phone, or other method, see our More Ways to Give page.


Daily news & progressive opinion—funded by the people, not the corporations—delivered straight to your inbox.
"The need for privacy has never been more urgent," said one advocate. "Encryption is a shield that protects everyone but most especially the most targeted and vulnerable communities."
A global coalition of more than 40 companies and digital rights groups on Wednesday urged governments around the world to publicly vow to "protect encryption and ensure a free and open internet."
The coalition sent its open letter to policymakers in Australia, Canada, the European Union, India, the United Kingdom, and the United States on World Press Freedom Day because digital privacy safeguards are particularly important to journalists and their sources, though advocates stressed they're essential to preserving democracy and human rights at large.
"Encryption is a critical tool for user privacy, data security, safety online, press freedom, self-determination, and free expression," states the letter. "Without encryption, users' data and communications can be accessed by law enforcement and malicious actors."
"Government attacks on encrypted services threaten privacy and put users at risk," the letter continues. "This might seem like a distant problem primarily faced in authoritarian countries but the threat is just as real and knocking at the doors of democratic nations."
"Policymakers understand the importance of privacy when it comes to opening someone else's physical mail, accessing their banking or other private information, but limit such protections online."
As the coalition, organized by Tutanoa, Fight for the Future, and Tor, explained, the value of end-to-end encryption "in defending privacy cannot be overstated, but is also seen as a threat to law enforcement who argue that the ability to freely access individuals' communications is critical for criminal investigations."
Law enforcement's narrative "has spurred worrying initiatives such as the Online Safety Bill in the U.K., the Lawful Access to Encrypted Data Act and EARN IT Act in the U.S., India's Directions 20(3)/2022 – CERT-In, Bill C26 in Canada, the Surveillance Legislation Amendment Act in Australia as well as the proposed rules to prevent and combat child sexual abuse in the E.U.," the coalition noted. "These laws aim to take away the right to privacy online by forcing encrypted services to weaken the security of their users and give law enforcement access to user information upon request."
In a statement, the coalition condemned the aforementioned proposals as "alarming examples of democratic governments following in the path of authoritarian governments like Russia and Iran, who actively limit their citizens' access to encrypted services thereby weakening their human rights."
Pushing back against such measures, the letter calls on "democratic leaders" to "protect encryption and uphold the human right to privacy."
Specifically, signatories implored all governments to:
"Encrypted services are at the forefront of the battle for online privacy, freedom of the press, freedom of opinion and expression," says the letter. "Many journalists, whistleblowers, and activists depend on secure, encrypted solutions to protect their data as well as their identity. Access to these tools can be literally life or death for those who rely on them."
The open letter echoes United Nations Secretary-General António Guterres' fresh warning that "in every corner of the world, freedom of the press is under attack."
"Freedom of the press is the foundation of democracy and justice," said Guterres. "It gives all of us the facts we need to shape opinions and speak truth to power."
"Meanwhile, journalists and media workers are directly targeted on and offline as they carry out their vital work. They are routinely harassed, intimidated, detained, and imprisoned," he added. "At least 67 media workers were killed in 2022—an unbelievable 50% increase over the previous year."
"Many policymakers believe they can have a 'magical key' to access encrypted communication—completely ignoring technical facts: Encryption is either securing everyone or it is broken for everyone."
While legislative and regulatory attempts to undermine encryption are especially hazardous to reporters and dissidents, experts made clear that weakening digital privacy ultimately endangers everyone.
"Encryption is a necessary tool for safeguarding our digital rights and the principles of a free and open society. By upholding encryption within messaging apps, websites, file sharing, and other online services, we empower journalists to report on important issues while protecting their sources without fear of surveillance and retribution," said Isabela Fernandes, executive director of the Tor Project. "The Tor network is underpinned by encryption, and we have partnered with many news outlets and social media sites to launch Onion Sites that bypass censorship and allow people to safely and anonymously access, share, and publish information."
Fight for the Future campaigner Eseohe Ojo argued that "the need for privacy has never been more urgent."
"Encryption is a shield that protects everyone but most especially the most targeted and vulnerable communities," said Ojo. "This ranges from journalists and activists to LGBTQ+ folks, abortion seekers, [and] ethnic and other minorities. Why take away the tools needed to help protect them at a time they need these tools the most?"
"Policymakers understand the importance of privacy when it comes to opening someone else's physical mail, accessing their banking or other private information, but limit such protections online," she added. "Encrypted services protect and empower individuals. It is about time governments recognize and safeguard access to these tools."
Tutanota co-founder Matthias Pfau lamented that "many policymakers believe they can have a 'magical key' to access encrypted communication—completely ignoring technical facts: Encryption is either securing everyone or it is broken for everyone."
"If policymakers want a 'magical key,' they will ultimately destroy the security of all citizens, including journalists and whistleblowers who depend on encryption to expose abuses of power or other grievances in society," Pfau warned. "That's why we at Tutanota will never weaken our encryption. If governments outlaw encryption, they need to block access to our encrypted email service, just like Russia and Iran are already doing."
The United Nations human rights chief on Friday warned that the U.S. government risks opening a "Pandora's Box" if it successfully forces Apple to unlock an iPhone belonging to one of the suspected San Bernardino shooters.
"Encryption and anonymity are needed as enablers of both freedom of expression and opinion and the right to privacy," UN High Commissioner for Human Rights Zeid Ra'ad Al Hussein said in a statement. "It is neither fanciful nor an exaggeration to say that, without encryption tools, lives may be endangered. In the worst cases, a government's ability to break into its citizens' phones may lead to the persecution of individuals simply exercising their fundamental human rights."
"To address a security-related issue related to encryption in one case, the authorities risk unlocking a Pandora's Box that could have extremely damaging implications for the human rights of millions of people, including their physical and financial security," he said.
The statement comes amid an escalating privacy battle between the FBI and Apple. The tech company continues to resist the government's orders to unlock Syed Farook's encrypted iPhone. While intelligence agencies have insisted that the FBI's demands are specific to the San Bernardino case, Apple, other tech companies, and privacy advocates have repeatedly warned that building a backdoor to encrypted data could set a dangerous precedent for expanding government authority.
Reporting earlier this month suggests that the Department of Justice is already pursuing court orders to force Apple to unlock iPhones in about a dozen undisclosed cases.
Moreover, Hussein said on Friday that weakening encryption could pose additional dangers to national security, such as exposing users' personal information to exploitation by hackers or repressive governments worldwide.
"This is not just about one case and one IT company in one country," Hussein said. "It will have tremendous ramifications for the future of individuals' security in a digital world which is increasingly inextricably meshed with the actual world we live in."
Apple and the FBI will take their high-profile encryption battle to Capitol Hill on Tuesday, with both sides calling on Congress to weigh in on the "watershed" privacy case and the significant precedents it could set.
FBI Director James Comey, Manhattan District Attorney Cyrus Vance Jr., and Apple's senior vice president and general counsel, Bruce Sewell, will testify at a House Judiciary Committee hearing titled "The Encryption Tightrope: Balancing Americans' Security and Privacy."
Sewell is expected to reiterate Apple's argument that building a backdoor to the iPhone linked to the San Bernardino attacks "would not affect just one iPhone."
"The FBI is asking Apple to weaken the security of our products," Sewell wrote in prepared testimony (pdf). "Hackers and cyber criminals could use this to wreak havoc on our privacy and personal safety. It would set a dangerous precedent for government intrusion on the privacy and safety of its citizens."
On the other hand, Vance will urge Congress to pass a law requiring companies like Apple to retain user keys for decrypting user data, according to testimony on the committee's website. A November proposal from Vance's office argued that Congress requires any phone manufactured or sold in the U.S. "must be able to be unlocked, or its data accessed, by the operating system designer" pursuant to a court order.
Not doing so, Vance will argue, "cripples even the most basic steps of a criminal investigation."
But in a statement on Tuesday, digital rights group Fight for the Future warned that "what the FBI is asking Apple to do will make us less safe, not more safe."
"If we allow the government to set a precedent that they can force private companies to punch holes in the technological defenses that keep us safe, it's not a question of if someone to will exploit that to cause harm to the public, it's a question of when," Fight for the Future co-founder Holmes Wilson said. "Congress needs to listen to security experts by unequivocally supporting strong encryption and opposing backdoors."
The hearing will occur at 1 p.m. EST, and can be watched on C-SPAN 3. The House Judiciary Committee hosts its own livestream as well.
The proceedings come one day after Apple "scored a major legal victory" when a judge in New York ruled that the U.S. government could not compel the tech company to unlock an iPhone so investigators could analyze its data as part of a drug case.
In a 50-page ruling, Magistrate Judge James Orenstein found that the All Writs Act--the same law the government is citing in the San Bernadino case--did not justify the government's request. According to Reuters, "Orenstein also found that Apple was largely exempt from complying with such requests by a 1994 law that updated wiretapping laws."
Ars Technica writes that "[t]he ruling, the first of its kind on the topic, has no legal bearing on the outcome of the California case as they are proceeding in different federal judicial districts. Apple hopes, however, that that Riverside judge will be 'persuaded' by the decision, according to a company executive who was granted anonymity on a call with reporters."
Meanwhile, security and law enforcement experts told Politico this week, it's unlikely that investigators will find "much useful new information" even if they are granted access to the iPhone in question.
So why do all the hubbubs happen over one single smartphone?
Politico reports: "Critics say the FBI is picking a fight with Apple over long-standing tensions about the increasing impenetrability of the iPhone's encryption, rather than acting from an immediate, pressing need to extract evidence."
As one ex-Department of Homeland Security official said, echoing arguments made by Apple and its supporters: The FBI is "hoping to set a precedent."
Indeed, said former FBI special agent and whistleblower Colleen Rowley in a recent op-ed, Comey's assertion to the contrary is "disingenuous."
"Does he not know that the government's 'Plan B' secret agenda to create 'workarounds' to defeat encryption recently came to light?" Rowley wrote. "Does he expect us to believe that he was not part of the secret White House meeting last fall where senior national security officials ordered agencies to find ways to counter encryption software and gain access to the most heavily protected user data on the most secure consumer devices, including Apple Inc.'s?"
Supporters rally around Apple in a watershed privacy rights case against the FBI. Activists, whistleblowers, and others are lining up to express their support for the tech company's refusal to hand over encrypted information to the intelligence agency.
National Security Agency (NSA) whistleblower Edward Snowden said Wednesday in a series of tweets, "This is the most important tech case in a decade...The FBI is creating a world where citizens rely on Apple to defend their rights, rather than the other way around."
Hours later, the Information Technology Industry Council, a trade group representing some of Silicon Valley's most influential companies--including Google, Facebook, Microsoft, IBM, Hewlett-Packard, and others--released a statement that read, "Our shared fight against terrorism must be grounded in principle. We worry about the broader implications both here and abroad of requiring technology companies to cooperate with governments to disable security features or introduce security vulnerabilities into technologies."
"Our fight against terrorism is actually strengthened by the security tools and technologies created by the technology sector, so we must tread carefully given our shared goals of improving security instead of creating insecurity," the Council continued.
Dozens of people rallied at Apple's flagship store in San Francisco on Wednesday evening in a rapid-response event organized by the digital rights group Fight for the Future, planning additional actions next Tuesday.
The FBI, with the help of a federal judge, is demanding that Apple unlock an iPhone belonging to one of the suspected San Bernardino shooters, which the tech company says is essentially a demand to build a backdoor to encryption, threatening all of its users' privacy rights and enabling a dangerous expansion of the government's authority.
"Governments have been frothing at the mouth hoping for an opportunity to pressure companies like Apple into building backdoors into their products to enable more sweeping surveillance," said Evan Greer, campaign director at Fight for the Future. "It's shameful that they're exploiting the tragedy in San Bernardino to push that agenda."
Other whistleblowers also expressed their support for Apple's stance. Mark Klein, an AT&T technician who exposed the telecom company's cooperation with the NSA in 2006, said Wednesday, "It's nice occasionally to have a company that has the balls to stand up to the government. The government--especially people like [CIA Director John] Brennan--is trying to browbeat everybody using the threat of terrorism. This allows the government to expand its powers continually."
And the San Francisco-based digital rights group Electronic Frontier Foundation (EFF), which is planning to file an amicus brief in support of Apple, released this statement: "We are supporting Apple here because the government is doing more than simply asking for Apple's assistance. For the first time, the government is requesting Apple write brand new code that eliminates key features of iPhone security--security features that protect us all. Essentially, the government is asking Apple to create a master key to open a single phone.
"And once that master key is created," EFF wrote, "we're certain that our government will ask for it again and again, for other phones, and turn this power against any software or device that has the audacity to offer strong security."
It seems everywhere he goes these days, Apple CEO Tim Cook is out there forcefully and publicly defending his company's decision to provide iPhone users with end-to-end text messaging and FaceTime encryption to protect against the constant threat of criminal hackers and foreign governments. The question is: when will other tech company leaders follow his lead?
If we're going to avoid having a horrible law banning encryption passed in the next year, more of the tech company giants' high-profile representatives - the Mark Zuckerbergs, Marissa Mayers and Eric Schmidts - need to use their platforms as the world's most well-known technology chiefs to make crystal clear how important encryption is to users everywhere.
US and UK officials have not let up on their months-long PR blitz villainizing encryption in an attempt to force tech companies to provide a surveillance backdoor into their products. This, despite the fact that officials still haven't produced any evidence that encryption was involved in the planning of any of the recent attacks in Paris and San Bernardino.
Not that it should matter; even if terrorists do use encrypted communications apps there are plenty of ways to track them and plenty of reasons to still encourage the technology's use. On 60 Minutes earlier this week, Cook explained why encryption is so important and why installing backdoors for government access to everyone's communications is such a bad idea:
Here's what the situation is on your smartphone today, on your iPhone, there's likely health information, there's financial information. There are intimate conversations with your family, or your co-workers. There's probably business secrets and you should have the ability to protect it. And the only way we know how to do that, is to encrypt it. Why is that? It's because if there's a way to get in, then somebody will find the way in. There have been people that suggest that we should have a back door. But the reality is if you put a back door in, that back doors for everybody, for good guys and bad guys.
Unfortunately, Cook is badly outnumbered by an onslaught of ignorant politicians making misleading and false statements about how encryption works and why we should ban it. And it isn't just a problem in the US and the UK: all over the world, countries are grappling with their sudden loss of power to surveil everything their citizenry says or does. A judge in Brazil briefly ordered Facebook's WhatsApp messaging application be blocked across the entire country because the service has no way of decrypting a suspect's communications.
Thankfully, the court backed down, but in his statement on that ruling, Mark Zuckerberg did not even mention the word "encryption", let alone explain why it's so important that every user be given this protection even if it means that the government can never access the content. While they rightfully oppose the government's push to ban encryption, other tech companies have not been nearly as vocal in public as Apple, in many cases speaking privately through lobbyists or industry representatives.
That's not to say these companies aren't doing anything: They've all released statements at various points condemning attacks on encryption. Facebook's WhatsApp has brought end-to-end encryption to more people—over 800 million—than any other service. Google's engineering team has been a leader in securing much of the web in the post-Snowden era.
But this is more than an engineering fight - it's a political one where public opinion is crucial. And if the CEOs of these tech companies and their highest-profile representatives aren't out there every day loudly fighting for our right to encryption where millions of people can hear them, then it's quite likely we might wake up one day and find that the US or UK has passed some awful bill, which will only encourage China to do the same - and very soon half the world may try to outlaw encryption in some way, shape or form.
Since the most successful hack launched against government servers compromised the personal information of more than 4.2 million government employees, the government has been scrambling to prevent it from happening again.
On June 4, the Office of Personnel Management announced it had been hacked, and officials have speculated that Chinese sources are to blame.
With FBI officials concerned about their ability to defend national security, FBI Director James Comey has called on companies such as Apple and Google to build "back doors" into encryption to protect user information from hacks but allow government agencies to access the data.
The main problem with Comey's request is that there is no feasible way to create a back door to encryption for government access without making it susceptible to hacks from other sources. An open window is an open window, explained Bill Buddington, a software engineer for the Electronic Frontier Foundation.
"If history serves as any lesson, we know that once there's a back door for one government agency, then it's not a far jump to see that that back door is also accessible to others--to hackers and to malicious third parties," Buddington told Truthdig. "There's no way to build a back door so the government can get access to your device and no one else can," he said. An ironic aspect of this situation is that President Obama has criticized countries like China for proposing to make U.S. companies hand over encryption keys in the name of fighting terrorism.
According to Buddington, the FBI's own website used to recommend that citizens use encryption, because the agency knew that that added safeguard would help protect their information. Now, since the surveillance state has ramped up, the agency wants to make sure it can access any data it deems necessary to access. Even though the FBI can still perform targeted surveillance operations and get warrants to access this data, Buddington notes, it wants more options for retrieving intel.
As Johns Hopkins cryptography professor Matthew Green has stated, forcing companies such as Google and Apple to break their own encryption will do absolutely nothing to prevent terrorism. "You could strangle the whole U.S. tech industry, and ISIS would *still* be able to communicate with their followers using encryption," he tweeted in early June. Essentially, companies dealing with the data of ordinary U.S. citizens and employees would be wide open to hacks, while the people the FBI wants to go after would still just use encryption by other means. Even if encryption was made entirely illegal, there's little reason to believe terrorists would be afraid of breaking the law.
Beyond that, there is reason to believe that the data of more than 300 million people who don't work for the federal government could be extremely valuable to foreign entities. "If there are foreign governments that find value in getting U.S. government employee data, then there is no reason they'd stop [going after civilian data]," Buddington notes. He said a government that opposes the United States could do a lot with the metadata of U.S. citizens. "To see who is talking to whom, who is communicating with whom and who's meeting--these kind of diverse interactions are the bread and butter of intelligence-gathering more generally for nation-states," he said. "To know the movements of populations is to know how information flows more generally, and that can affect foreign policy decisions and national security decisions."
Malicious governments or other entities could collect all the information they want and then dive in to look for specific patterns or interactions. Information such as financial data, for example, could be of value to many hackers. What is thought to be the biggest bank heist ever involved more than 100 banks in 30 nations that were hacked by a cybercrime gang, and it is believed well over $300 million was lost--and possibly as much as $1 billion.
Buddington and other experts say citizens and government agencies should be encrypting all communications and data. As for the government's cybersecurity, Buddington says the technology it's using is antiquated and needs to be replaced to respond to evolving threats. He said the government also needs more cybersecurity experts at every level to advise those who may not know how to protect themselves. Keeping government data protected is important, but the country isn't any safer if only its leaders are out of the line of fire, he notes.