Sparks fly over Apple v. FBI dispute at major cybersecurity gathering
Loading...
| SAN FRANCISCO
It was all anyone seemed to want to talk about. Whether inside the vast exhibit halls or at the after parties at this year's RSA Conference, just about everyone had something to say about the legal dispute between Apple and the FBI.
Shouting over a DJ's thumping music at the many lavish parties thrown by cybersecurity vendors hoping to land new customers at聽the world's biggest digital security expo,聽Washington officials and tech executives polled one another about whether the US government's case against聽Apple would reach the Supreme Court.
Over pickled eggs and veal tartare, they fiercely debated whether聽it would be technically possible for Apple to help investigators access data on just one iPhone 鈥 or if the order amounts to a government backdoor into many devices that could compromise millions of consumers鈥 security and privacy.
Apple's fight against US court order demanding it write new software to bypass strong security measures on the smartphone used by the San Bernardino shooter has ignited one of the most controversial, high-profile debates about digital security the country has seen in years.
So it鈥檚 no surprise it was the talk of the town here.听"It鈥檚 been a huge focus," says Merritt Maxim, a senior analyst at Forrester Research.听"The dialogue's been happening all week."
"It鈥檚 interesting to everyone, and not just in security," he continued, "My mother鈥檚 interested in it. It鈥檚 not just about the technical issues, but the underlying issues: What rights does the government have, what rights does the individual have, and where do you find that balance? This a high-profile event to have these discussions."
Ever since the so-called "cryptowars" in the 1990s over a government plan to install a backdoor into encryption, the RSA Conference聽has been a hotbed for debate about whether the US government should be able to build in access to secure consumer technology.
This year's furor over the Apple court order, to many longtime attendees like Mr. Maxim, brings the so-called backdoor controversy full circle. "The same issues are percolating again now."
Even as many senior Obama administration officials sought to avoid directly addressing the Apple case in public, it became the unavoidable headline in coverage of many of their official talks, from to聽鈥 even overshadowing聽news of聽creative new initiatives aimed at working together with hackers.听
Yet the controversy was on full display聽, as industry and government officials went toe to toe over which outcome would be truly better for national security.
"In this particular case, the stakes are high," said John Carlin, the Justice Department鈥檚 assistant attorney general for national security, at the Beat the Breach event. "It's the most serious terrorist attack since 9/11. The community is suffering and wants answers 鈥 and an important investigative step here would be to access the phone of what is actually a customer that wants help."
But Richard Clarke, a former White House counterterrorism adviser, shot back: "This isn鈥檛 something you want to search. You鈥檙e trying to force American citizens to do something 鈥 in this case write code 鈥 that they don鈥檛 want to write." Apple argues the order violates its First Amendment rights by compelling the company to write new code it believes is too dangerous for its consumers.
Mr. Clarke says he has "enormous sympathy for people who are fighting terrorists, and I understand that they want all the tools they can get."
But he also insisted that national security argument doesn鈥檛 hold water here. "We have already decided long ago that we鈥檙e not going to let counterterrorism people have everything they want 鈥. Having secure encryption end-to-end has greater national value than this incremental addition to the FBI [capabilities]."
This is a case where the interests of law enforcement and intelligence agencies, said RSA President Amit Yoran, does not "align with those trying to defend our critical infrastructure, and our networks."
What鈥檚 more, Mr. Yoran openly worried, a win for the US government in this case could compromise users鈥 trust in all American technology. "We鈥檙e setting a very, very dangerous precedent where consumers鈥 trust in the products and technology they use, and security and privacy protection technologies they use, will at its core be in question."
As the conference continued, a stampede of companies announced they would back Apple.
What most everyone at the conference wants to know, Forrester鈥檚 Maxim says, "is regardless of where the court decision goes, what kind of precedent does that set?"
Some of the world鈥檚 biggest brains in the cryptography field asked those same questions this week.
At a time when criminal and terrorist hackers are growing more advanced, "the good of the country relies on people having strong security. The systems we have are so fragile," says cryptographer Ron Rivest, a Massachusetts Institute of Technology professor, "that trying to extra keys or extra ways in鈥 is asking for all kinds of trouble."
Other big name keynote speakers from companies echoed this view.听"Despite the best of intentions, one thing is clear: The path to hell starts at the backdoor. And we need to make sure that encryption technology remains strong," Microsoft鈥檚 President Brad Smith, pledging to stand with Apple to thunderous applause.
Yet even those with such strong opinions on the issue acknowledged the public will have to decide the appropriate trade-offs between consumer security and privacy 鈥 and law enforcement鈥檚 pursuit of criminals and terrorists 鈥 in American society.
"We need to have a discussion where we figure out what鈥檚 right for the country, rather than what鈥檚 right for this agency or that company, said cryptographer Paul Kocher.
On that, at least, US officials seem to agree.
"Let鈥檚 all stop talking past each other," said National Security Agency chief Adm. Mike Rogers. While he didn鈥檛 mention the Apple brouhaha or encryption specifically, the subtext was clear.
"We have got to get to a dialogue. That dialogue shouldn鈥檛 be the government unilaterally deciding what we should do; the industry unilaterally deciding what they ought to do. We鈥檝e got to team up together to decide what is in the realm of the possible," he said.
What鈥檚 more, Admiral Rogers, "our citizens need to be the ones who say: 'This is what we are comfortable with, and this is not.' "