back

by rietta·10y ago·view on hn ↗
I'm not so sure about that as the language of the bill states:

"(d) (1) ...that is not capable of being decrypted and unlocked by its manufacturer or its operating system provider shall not result in liability to the seller or lessor if the inability of the manufacturer and operating system provider to decrypt and unlock the smartphone is the result of actions taken by a person or entity other than the manufacturer, the operating system provider, the seller, or the lessor and those actions were unauthorized by the manufacturer, the operating system provider, the seller, or the lessor."

Presumably the "those actions were unauthorized" could be construed as prohibiting a FDE option from being built into the OS and provided by the manufacturer and this in conjunction with signed kernels in phones, would present a very high barrier on the user to be able to obtain device encryption without key escrow as we understand it today.

2 comments
This has been my understanding of what they really want, in particular when using the word "front door". That's key escrow. Not weakening encryption so that they can break it, but they want manufacturer or OS provider to have a copy of the keys used and in particular the law seems worded to burden the company to actually perform the decryption, not merely hand over the keys.
Addition: While I don't think either funded or unfunded mandate to do this decryption is OK; I think it's untenable for the company to hand over keys to just any government. With those keys, the government can not only decrypt, they can decrypt-modify-encrypt and thus frame dissidents or political enemies.
The argument has been around for a long time. The first crypto wars had their policy papers and summary pros/cons such as https://www.cs.cornell.edu/html/cs513-sp98/hw.policy.keyEscr....
This is where the bill breaks down logically. A seller of an unlocked/decryptable device can say "you're not authorized to encrypt this" all they like. As a user though, I don't require their authorization to do what I like to a device I own.

A gun seller does not 'authorize' someone to use the gun to commit murder. Best buy, AT&T, etc. likewise do not authorize a user to encrypt their device. Nor should they. What I do with my device is none of their concern so long as I pay my bill.