Going Dark, and the era of law enforcement hacking
325 points - yesterday at 8:52 PM
SourceComments
That resulted in the Communications Assistance to Law Enforcement Act, which mandated that central offices offer remote wiretapping. Capacity up to 1% of lines is required.
Back in the electromechanical era, the only call data that could be collected was outgoing dial pulses, using a "pen register".[1] (The one shown in Wikipedia is mine. It's a beautiful piece of antique brass telegraph technology. It records dial pulses as dashes, and has to be wound up like a clock, with a big brass key.) The Supreme Court decision allowing "pen registers" without a warrant refers to these "extremely limited" devices. That definition has been stretched and stretched by law enforcement into all non-voice data collected by telcos.
Law enforcement still wants more.
This doesn't resonate with me. I see companies adding more sloppily written features with AI. I see more bugs in the software I use, not less. While it's plausible that software is getting both buggier and more secure, I suspect those two move in the same direction not opposite.
My guess is that we're getting better at finding _existing_ security issues with AI (and thus fixing those issues), but simultaneously adding more insecure surface areas _at a faster rate_.
It's like two parallel worlds, that exist in the same place at the same time, but somehow don't cross.
we live in a world where the government can't even do much about illegal drug markets anyone can access by downloading a piece of software.
if they pass laws that mandate backdoor access and block software which doesn't conform more and more people will move to the dark networks.
and if they effectively block the dark networks (in the limit they will have to block all encrypted communications) then we will be living in a tyranny.
freedom is messy. accept that digital crime can only be solved when the criminal makes a tangible mistake. LLM's will be building profiles on criminals to help with identifying mistakes.
I am just beside myself at such an idea that people looking to feed the prison machine cannot as easily find excuses to turn normal citizens into prison feed.
Just super sad guys.
I don't understand how you can both argue for that law enforcement (and intelligence) agencies will force others to implement intentional backdoors AND also everyone will be using AI to find and secure ALL potential holes in the software so there won't be any vulnerabilities anymore.
Wouldn't one AI or another detect this deliberate backdoor and report it, as it'll look just like any other security vulnerability, the only difference being the intention?
I have respect for the author so I feel like I probably misunderstand something from the overall text rather than I somehow have a better perspective on this topic that the author knows very much more about than me. I felt like I nodded along all up until "So how is this a problem?" and now I'm not sure I understood correctly.
Like if we were willing to stop adding new code and just have a small secure code base, AI could maybe help us find all the vulnerabilities in that code base.
But people have consistently been unwilling to do that. Like if we were willing to stop adding code we could have stopped decades ago and done SQLite level testing everywhere and probably have found almost all the bugs already.
heh. long greasy slide. It really does feel like that.
Apart from the obvious harms of invasion of privacy, and fishing expeditions being biased to the places you decided to fish. There is the simple fact that data can be misleading, especially without context. An interceped communication is a piece of data that is intrinsically tied to the trust of the inteceptor. A few people with an agenda can collaborate to create a seeming truth by 'discovering' the same thing from different sources.
Requiring warrants compelling information holders to provide data, not only serves the task of protection from abuse but also create a record of provenance that can be verified.
It also provides a degree of symmetry in capabilities which discourages actions that one party may do over another if they are motivated to act because they have a temporary advantage over another.
Exhausting infrastructure vulnerabilities even without quantum could be a game changer for many technologies and enable things we can’t do right now, like vote on our phones.
I'm more curious what could be a right choice, and more importantly who is the "we" in this, as many decisions are largely made by companies and governments.
Unless you remember 2013, Snowden, that nothing was done (at most was some concern about doing it to US citizens, the rest of the world doesn't deserve privacy), all US (and/or five-eyes) based web companies must disclose users information and be forced to not disclose that, and things kept going surely at a faster and more intrusive rate in everything else, and of course phones.
You are complaining being sprinkled by water while at the bottom of the ocean. At least the big companies can find their own vulnerabilities with the AI tools you mention, the rest of the doors are still wide open.
It also seems likely to me that the US Gov. probably already has routine mechanisms for compelling targeted software updates for persons of interest, so I'm not sure that a more formalized backdoor than automatic updates is going to be surfaced in the mainstream, unless that is avenue is also cut down somehow.
These laws exist - they aren't the focus yet. Right now there's still no need; just hack the device or compel the cloud service to give the data, why waste energy getting consent from its owner!
More bugfinding AI, more end to end encryption, more CVEs and more fixes, cannot happen soon enough.
It will be interesting to see if my prophecy becomes reality.
BTW I also hate that Hacker News is being dominated by articles on A.I. lately. Maybe we should vote on HN reducing or even eliminating A.I. related news?
150 years ago was the invention of the telephone, and I think that articles like this seem to assume that prior to this, police just never caught any criminals.
Law enforcement doesn’t need this surveillance ability at all. All time periods prior to 25 years ago didn’t have it.
Additionally, there is no correlation between “law enforcement reads text messages” and crime rates going down.
No, it was just good at it because it wasn't RL'd against it. I know this is a small detail, but it tosses journalistic credibility in my eyes.
If automated pentesting in PR review CI pipeline will become table stakes - which is very plausible - maybe the OP has a point.
I remember walking into some shitty congresscritter's office with a fucking years old one pager, with a few more citations written on the bottom in pen because I wasn't going to bother making it pretty this time around.
You should have seen his face when i asked him straight up: dude, you seem to have a problem processing information. Are you having some kind of medical issue? Because I'm not the last staffer: If you abuse my time, I am never coming back here again to add more citations to a fucking one pager from 1999 -- I'm making it my mission to remove you if you fuck this up on purpose ever again.
(Or something to that effect -- I've been told I can get a bit aggressive in my rhetoric.)
This was approximately 2016 and that individual is no longer in office.
I stand by my words.
Honestly though, framing this as a "tech issue" doesn't help IMHO, it just muddies the water. Ever since RSA was invented privacy has been about educating people on how to use it effectively and _why they should care_. If voters now are choosing authoritarianism over democracy and individual freedom, I think we have to face the reality that after almost 50 years of fighting battle after battle on the technology front, we've largely lost the war on the home front in this regard.
I, for one, usually tell my AI to start with secure code, make it small, and modular.
This is the first article I've seen that now says the opposite ! AI will make code too secure!
Since the small amount of AI coding I've done often results in buggy code (even a shell script written today) with the AI go-to solution of "write more buggy code to fix", this seems counterintuitive.
> Thus: over the next two years, major pieces of software are likely to run out of remotely-exploitable bugs.
His conclusion sounds extremely optimistic to me.
I personally welcome such spiraling offense-defense cycles as it is one of the main drivers of the technological progress.
Lmao this is like “I’m concerned the raccoons that I see in the storm drains are going to make our sewer system much too efficient”