points by exikyut 5 years ago

Ever since I learned Facebook greenlit "Signal is awesome, were using it" I've been trying to headscratch why. Then I realised WhatsApp had kicked the whole thing off years ago and got even more confused. Why do you want to encrypt everything??? It makes your life harder. It makes cooperating with law enforcement harder. It means legitimate users can't recover their messages. It means you can't do fun things with analytics, which is extremely contentious but concedably valuable. So, why??

I think I've figured it out. A tiny little bit of it, anyway.

Imagine you're a multi-million (okay, multi-billion) dollar communications company. You're WhatsApp. Apple (iMessage). Facebook. Google (RCS).

You store trillions of messages.

In those trillions of messages, you are going to have the statistical >100.00% guarantee that there are chats and conversations between individuals and groups that would launch World Wars 4 through 16 if certain other individuals, groups, governments and so forth were to learn/verify that A did really say <thing> to B. The nuclear launch codes don't fit in a football anymore.

I have no hope of ever confirming the validity of that Bloomberg article about the alleged Supermicro hack. But it seems "well duh" simple enough to be concerningly plausible (custom silicon packaged in WLCSP or SC70, bit-twiddling SPI? Too easy... :S). As a technically-flawless plausibility, I say it can serve as a concrete reference example of a fraction of the persistent, sweeping, ruthless, and terrifying scale of the super-industrial, Eye Of Sauron-style attacks that these companies have very obviously been facing for some time now.

So, my possibly-not-really-a-conspiracy-theory-since-the-pieces-come-together-without-fantastic-levels-of-extrapolation theory is, someone stumbled on an idea one day, maybe in a stuffy committee meeting, or maybe in a bar, to solve the problem by giving the people what they wanted... end-to-end encrypt everything... and go from encryption at rest, which is basically nothing, to encryption everywhere; and you instantaneously divest the massive, massive burden of owning all that readable data.

True, now "accidentally" forgetting the `s` in backend URLs doesn't let the NSA read everything anymore, but that kind of pales in comparison to being able to incontrovertibly, mathematically prove that, since the data really is encrypted before it leaves the device, there really is no chance any readable plaintext is leaking and potentially being stored; so if the nation states would kindly take stock of this situation and point the coherence death ray beams elsewhere that would be great since we are kind of on fire here at the moment and it's too hOT we are meLTING--

Getting this to catch on was obviously difficult. Anybody that can scare multi-billion dollar companies obviously has the skill to steer collective opinion and impression at scale. Whoever came up with the idea to piggyback on top of individual privacy is... a task-focused genius, I'll put it that way. On the one hand, the idea has scaled beautifully: all the tech folks have gone "Is private. Respects freedom. Og like." and loudly pushed for the idea everywhere they can. And from a sociopolitical perspective, the narrative is faultless and blameless, which is where the genius definitely shines through.

The first bit I can't say I like is the narrative appearance of first-class support for end-to-end encryption as a Scientific Advancement™. It's not. It's an implementationally-scoped, crowd control spin campaign to increase datacenter security beyond what disk encryption at rest can ever achieve. The scale of wreckage in the form of technically minded people who really believe the privacy narrative is disillusioning to see.

The other bit that I find unamusing is the long-term shifts in the attack landscape that will result from this. Specifically the fact that, an Eye Of Sauron style adversary is not ultimately going to care what their attack target is, or how to attack it, only that it gets vaporised. End-to-end encryption shifts the burden of responsibility to the owner of the server to the owner of the client. I can see the positive angle here from a think-tank standpoint - literal decentralization as a defence strategy - but still, Android/iOS are now the focus of some laser beams that were terrifying a bunch of rather large companies. Maybe it'll seem reasonable to heavily fund the vulnerability research scene to maintain a favorable status quo, and we'll see some impressive hacks going forward (or, er, we won't). Or maybe things are already "that bad" and I don't have anything to worry about. But considering that users are now that much more responsible for devices that are interesting in a way they were never before, this whole strategy kinda feels irresponsible to me if you squint at it from a certain angle. At the same time, it might ironically be ensuring our survival.

In this picture, law enforcement really is the afterthought. It's well known the law court system doesn't understand technology and is 20 (40? 50?) years in the past. That situation extends beyond the courts though, with law enforcement generally in the same position. But it's worse than it may at first seem, because the notion of "the past" that refer to a collective public interpretation of "now" doesn't do justice to the technological development that has happened at these companies over the last 5-10 years - these private companies are internally fighting battles of a complexity that the public law enforcement system cannot hope to comprehend, let alone help with.

In this fight, the best way to avoid World War 4 is to encrypt everything. But Washington is still getting over how cool they handled the Cold War, and the police still think it's "hard" and "complicated" and "special" to "hack phones".