Leading Security Experts Say FBI Wiretapping Proposal Would Undermine Cybersecurity
Today, a group of 20 of the world’s preeminent experts in computer and network security released a report warning that an FBI proposal to modify Internet services to make them wiretap friendly would open major security holes, and that criminals would easily circumvent the wiretap capability that would have to be built in.
This security “dream team” brings deep expertise and experience in:
Design and implementation of secure communications software
Cryptographic algorithms and protocols
Computer security and security engineering
Surveillance and associated risks
Building communication tools for highly-adversarial contexts
The report comes on the heels of recent stories from The Washington Post and The New York Times describing the FBI wiretap proposal. The proposal would extend technical design mandates for “wiretap readiness” to peer-to-peer communications tools. According to reports, companies that do not comply with a wiretap order, including those that cannot comply because they have configured their communication service in a secure manner and do not themselves have access to user communications, or do not have access to such communications in unencrypted form, would face escalating, potentially ruinous fines. The threat of such liability would effectively force re-engineering of communications services so they are wiretap ready.
The experts’ report focuses on peer-to-peer communications tools that allow direct communications between users – essentially, peer-to-peer “endpoints.” The FBI has complained for years that peer-to-peer communications, including VoIP, video and text communications, are difficult for it to wiretap. These communications travel directly from computer to computer, and are often encrypted end-to-end. (VoIP communications that can call into the public telephone system are already covered by CALEA mandates as a result of a previous FBI demand effectuated through an FCC proceeding.)
The report makes three main points about the FBI proposal. First, wiretap functionality allows covert access to communications that can be exploited not only by law enforcement, but by criminals, terrorists, and foreign military and intelligence agencies. Wiretap endpoints will be vulnerable to exploitation and difficult to secure. Second, imposing the obligation to facilitate wiretapping on software developers forces them to choose between two dangerous, expensive, cumbersome options: they can either create a compliance department capable of responding 24/7 to law enforcement demands, or they can show personnel in law enforcement agencies world wide how to exploit their software to harvest user communications. Finally, the wiretap capability that the FBI seeks will be ineffective because it is easily disabled and because knock-off products that lack the wiretap functionality can be readily downloaded from websites abroad. Because many of the tools that people use to communicate are built on open standards and open source software, it will be trivial to remove or disable wiretap functionality.
The report concludes:
The FBI’s desire to expand CALEA mandates amounts to developing for our adversaries capabilities that they may not have the competence, access or resources to develop on their own. … We believe that on balance mandating that endpoint software vendors build intercept functionality into their products will be much more costly to personal, economic and governmental security overall than the risks associated with not being able to wiretap all communications.
That’s strong language. We hope the Administration and Congress take heed when they consider the FBI’s CALEA II proposal.
CDT-led Coalition Calls for Transparency for White House AI Framework
CDT and Americans for Responsible Innovation led a broad, bipartisan coalition of over two dozen civil society groups in calling on the White House to release its Framework for review of frontier AI models.
CDT Amicus Brief Calls on Fourth Circuit to Rein In Geofence Warrants
Earlier this year the Supreme Court ruled in Chatrie v United States that the Fourth Amendment protected all cell phone location information, which CDT lauded as a landmark decision, but sent the case back down to the Fourth Circuit to assess the propriety of the geofence warrant at issue.
CDT and Partners Post Floor Alert Opposing CA SB 1013 Automated License Plate Readers Bill
The best way to ensure that Automated License Plate Readers are not abused is to limit the retention of stored data and to keep loopholes to lawful process closed. CA SB 1013 is a step in the wrong direction, and we urge the California legislature to reject this approach.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.