Vimarsana.com

Transcripts For CSPAN3 Encryption Technology And Terrorism 20170331

• Source: archive.org
Good afternoon, everybody. Thank you for being here. Im shane harris with the wall street journal. And very happy to be talking about this panel on the challenge of emerging incription technologies. Since i both use incription technologies and feel challenged by them on a regular basis, im going to introduce our panel here starting to my left. Were going to open with letting each of these gentlemen here who are experts in this field give opening remarks on really how their approaching this question of the challenge of emerging technologies. After i introduce each of them, i think youll see how they come at it from their own perspective. Then well have a discussion here on the stage which ill lead. Youll see people with name tags with red bands on them. If you spot them, raise your hand and theyll bring a microphone you to. To my left is james baker. You are totally not busy right now. Thank you for taking time to be us with. The European Commission and at the end of the panel here, the Senior Council for the compute Eastern Communications industry association. I want to jump into this and ask mr. Baker to lead us off. Certainly the fbi has had a lot to say today about the challenges of incription. I know you think a lot about it. Please, kick us off. Thank you very much. Thank you for doing this. I appreciate it. We really appreciate it. Were eager to talk about this topic as much as possible to get out the information that the public needs to be able to understand the issue, to understand the complexities and subtleties. And for us to contribute to what we hope is a more informed, educated debate and discussion about these topics because theyre important to all of us f i can just sort goff through the issues and the perspective and set the table with respect to how were con front be incription. We con front incription a lot of ways. As i said, as i think the director said multiple times, the fbi supports strong incription. Incription has very significant benefits for society across a whole range of issues, across a whole range of protections of the data that we all care about, our personally identifiable information about us. Our financial information, commercial transactions that facilitates and enables. It protects our health data and a whole range of very important data that is essential for us to function as a society and to have a functioning economy. My sense is were beginning to acknowledge as a society that incription also has costs. What were experiencing in the Public Safety sector is that incription has costs for us, for the Public Safety for shows involved in the Public Safety with appropriate Legal Process and adhering to the constitution and laufz the United States. What i mean is in certain circumstances, incription has costs for our investigative efforts and variety of different ways. In some cases, in some instances that information or evidence simply will be unavailable. It is incrypted in motion or it is incrypted on a device and we dont have a key to get into that information and, therefore, gist not going to be available to us. Well pursue intrepid and creative and figure out ways to solve problems if con fronted with a problem. It will then, because they might not be able to use sort of a electronic surveillance an search means, they will do other things. And those other things have costs. We might have to use a source, a confidential source or undercover agent to go into a situation including circumstances where there may be physical dafrpg torte agent or to the source. And so that is risky. That is just risky. Doing all these things poses risk to the integrity of the investigation as well. So that is really what were trying to say. That incription is good. Incription has huge benefits. But it is not cost free. And we have to figure out as society how we want to deal with that. Historically we have thought in the United States that the balance between sort of privacy and security, if you will, or security and security however you want to frame the discussion was settled more than 200 years ago by the Fourth Amendment which talks about reasonable expectations of privacy and allowing the government to have access to certain materials if we go through a process and if we adhere to the Fourth Amendment and certain circumstances, get a warrant to have access with approval by a judge to the evidence to the material. So thats how we have done that, how we have set thald balance for more than 200 years. So incription is creating, however you want to phrase it, it is changing that balance. It is making things harder for us and information unavailable to us. All of the devices brought to the fbi technical experts to be open whether they came from federal, state, local authorities, we could not open we could not access 40 of them. So thats a significant number of device thats we are unable to open. The ones brought to us by some Law Enforcement agency. State, local, federal . Or the fbi itself. We could not get into 40 of those. That information that, data on the devices is simply not available us to. We are we dont have a solution to this problem. We the fbi. We dont have a solution to this problem. Were not trying to impose a solution on the United States or on any part of the world. We are not advocating a back door or a golden key. What i mean by that is were not trying we dont want a solution or a solution that somehow in a significant way undermines cybersecurity and undermines the security of our devices and communications is therefore not a solution. Any solution that we come up with has to appropriately in my mind balance the needs of Public Safety folks but also protect our privacy, protect cybersecurity, protect the right to free expression, free association, encourage our companies to be innovative and competitive in a global marketplace where we have competitors, users and regulators around the world. We have to make sure this is a global it is addressed in a global way. And where encryption is available in a global way. The genie is out of the bottle. Its not going back in, we know. That so any solution has to perfectly balance all the things. Corporations in america, for example, sol of this problem every day in a way they feel comfortable with. They maintain access to the emails of their employees for a variety of different purposes. So theyve been able to figure out a balance that is acceptable to them, taking on some cybersecurity risk but then but having access to data and protecting it in a meaningful way. There are other proposals out. There we can talk about maybe down the road. That may that may be fruitful. At the end of the day, we think about it is the fbi works for the American People. And youve given us responsibilities to protect you from a variety of threats and to do it simultaneously across the board. A lot of different threats that we face on any given day. But you want us to do it in a certain way consistent with obvious lit constitutional laws of the United States but you want us to do it, you know, with certain tools available to us. And you give those to us. You give those to us by law and by regulation and by funding and well make full use of them. The question is in confronting this problem, what tools do you want us to have available tous . What tools do you want us to have available to utilize in order to protect you . We will do what you want us to do. I hope you think its incumbent upon us to make sure you understand our current situation. Ill pause there. Okay. Great. You make your opening remarks and youre coming at this obviously from the point of view of european perspective. Ill ask you to try to speak entirely on behalf of all european views on this. But why dont you give us your introduction to just how you approach this challenge. Thank you, shane. Let me thank you gw for the invitation. T its a privilege to me to speak on behalf of the European Union and i subscribe almost everything that james just said. Two couldnt nents but the same problem. Incription is good. It is considered good for cybersecurity. Its good for privacy. Its good for economy. Its good for the users. Its a key feature of the general protection regulation that will apply by next year may 2018 to 28 Member States. Its a key feature of our eprivacy frameworkhere confidentiality of communication is the most important. But as james said in, particular, i have to say lik they said, before the situation in europe is the one that you know and the debate is eating up on the need for Law Enforcement and other authorities to perform the duties. There is organized crime and all around the state and encounter a problem with encryption in the investigation and those communication leader. We have 27 in europe encrypted. 47 here in the u. S. Use encryption. So are we going back as somebody has said . I dont know. Probably certainly not. But the reason i need to study options and james will think there are option thats are being assessed, developed further interception requirement that goes back to the ordinary mobile communication and out with these socalled ott, over the top providers. What we have done is when they move from access to design to privacy by design with the end of encryption. The approach of the European Union and European Commission is an inclusive one. We dont have solution coming from one earlier because others are involved. Intelligence cannot solve the problem. Privacy advocates cannot solve the problem. Law enforcement and industry cannot solve the problem alone. So we have in place a mechl nick that will allow us to have all different stake holders. First of all to define the problem. Because as has been said, we have to understand what we can do white house compromising privacy and allowing Law Enforcement to move forward. And we have to assess the option in a way that necessity of proportion alt of infringement or is respected. We have to ensure that Member States, Law Enforcement can access to data when they need. And we have to say because we have Many Companies arent table. Companies need to do their part. They have to take up their social responsibility and understand they contribute to the final good which is to ensure the security of the citizens. So we have a setup in 2015 a specific structure which is called the eu Internet Forum. But as mentioned, this brings together all the Law Enforcement and public authorities of the Member States. The major social media companies, some of them are present here and they can come back on this. And clearly our own agency and we are trying to identify a solution. It takes time. We avoid calling for back door from the front door. Because we have to find a solution and allow us to enter from the front door. And there are challenges. We are a continent. We are working to create an environment in 28, then we are only one part of the whole geographic world. So we have a challenge of enforcement of the law. Balance was saying that several Member States are putting up laws at a national level. How do we enforce this law . So fate law has always given Law Enforcement the ability to instruct the order and provides the only territory. But how do we do with the internet which is borderless . And how do we do a concept of localization of data . Thats another big issue that we need to discuss. And thats also challenging. Do we need an International Framework . Do we need to make sure that all states share the same instrument. At the moment we dont have solution because we dont want solution today. We want a solution tomorrow knowing encryption is a word at second best solution. You cant agree with both of the guys. I can agree with one statement. Thank you once again for having us. That should be the take away. History and Law Enforcement on the same page. Feel free to go home now. I think many people in this room, show of hands, have been to a panel on incription in the last three yea encryption in the last three years . It became publicly available to throughout the United States and worldwide . But i think what industry perspective is that we regularly have the solution this conversation around solutions and we, i think the american public, users generally come to the same conclusion that weighing the cost of encryption with the benefits, the cost to Law Enforcement investigations and Public Access and the costs of sort of scaling potential solutions to the encryption problem across what is now a global internet, the ultimate answer is that the question is answered. The costs are too great. Scaling those scaling second best solution to encryption across the internet puts too many users at risk either from a financial inspective that, you know, perhaps on a one off instance may be appropriate. I think in aggregate makes it a very tough second best solution to put forward. Thats where they approach it from. On the user side of it, as i said this is not some i think remarks have been made in the past that the characterized, the industry perspective on encryption is one of business practices. This can help us sell phones or get more users ton ott platforms or social media. I dont think i dont think anyone realic tickly believes theyre doing that. Theyre under pressure from users and regulatory authorities to provide the best possible protection for privacy and security as possible. Encryption is difficult to design at scale. Theyre incredibly difficult to design, you know, os burden to os versions. And so i think the industry is that rather than looking to Technical Solutions and i understand the no Technical Solutions are provided from industry or Law Enforcement, we should look to ways to aid Law Enforcement, counsel ducting their investigations. See what we can do to improve use of the tools. There has to be recognition from both sides that there is not going to be a perfect solution. To cracking the indication of encryption. It may be that we have to live with the cost of encryption because benefits are too great and to the extent that Internet Users and public are able to help the government recognize that, i think thats where we would like to go going forward. If you watched 6 o minutes last night, you saw a smart terrorism analyst. You saw him standing in front of a Bulletin Board with his great diagram of terrorist faces and lines going between them, somethin you would see in home land. And there were two very interesting take aways from that. One is he talked about terrorists including one thats were monitoring and isis who were in communications with people in the United States using encrypted apps and talking to the individuals by encryption. It seems they have adopted these and must be frustrating to Law Enforcement. It is also the case there is a pretty sophisticated diagram and somehow even despite the use of encryption, we were able to understand it seems a fair amount about who the people are and how theyre communicating. So i wonder if we can take this example this real world example, if we know terrorists groups are clearly uing this technology to communicate that, has challenges to Law Enforcement intelligence. But it seems to me somewhat surmountable at least in some instances. I wonder if i could provoke with you that idea. Mr. Baker, lets start with you. It seems so obviously fall and directly into your lane. Talk about that challenge. Because obviously terrorists are using this stuff. But were finding out ways to understand how theyre connecting with each other. Can you give us some insight into what that really looks like on the ground when you grapple with the cases . So i saw that starry last night. You think about the diagram and the connections and the network, the social network if you will. You can look at the Internet Connections to understand what that network looks like, who theyre in contact with and how often. It doesnt tell you about the plans, intentions that, kind of thing. You dont understand what the intent is. And that is, you know, understanding that robust picture is critically important. We need to go into court, frafrm, afrafror example, and have evidence of intent n that particular case, for example, so even to the extent that we understood what the network looked like, we did not know and this is what we said in the there is the garland shooting. Yes, the gar land shooting or the nonshooting that was stopped by Law Enforcement officers. They were intent on killing a lot of people. So in that particular instance, we talked publicly before about the fact that the fbi had surveillance, electronic surveillance of those folks and we knew, we were able to see that they were having over 100 communications directly from the person who showed up in gar land, texas, and foreign terrorist operatives overseas. Part of an organization with whom we are add war, right, and who are trying to inspire and provoke people in the United States to kill other people in the United States. To use the incryptencrypted mes. So we couldnt see what it was that they were going to do. We could seat network and where they were, perhaps. But you didnt have we didnt have an understanding of exactly what it was they were planning. And thats the gap. So thats the cost. I dont think its so this is something these are cost thats society is going to have to bear. The families sh the cmunity and so on and so who is assessing that . Society is moving along and choices are being made by default, by just letting things happen. If thats what the American People want, then thats what theyll get. Its incumbent upon us as i said earlier to make sure they understand the choices. Its not for the fbi to be deciding what kind of country were going to live n but frankly, its not for companies to decide that either. All right. Would you tlik get in on this . I would like to comment even if i was on the plane dwroed come here so i didnt see the broadcast last night. But i can probably mention another case that actually the secretary mentioned himself following the london attack. She mentioned it and thats why i can mention it, just two minutes before driving on the Westminster Bridge saw a message, whats up . We dont know to who and we dont know and the uk intelligence dont know what was the content. So she clearly mentioned this and inviting yesterday to take up the responsibility to cooperate in this context. And thats exactly as jane just said. There is a social responsibility of the company to contribute. Its very relevant to allow Intelligent Service and Law Enforcement to have the means to assess and, therefore, make an anysis. Before i move on real quick, in both of you essentially said we need to find a way to do this. But its ultimately the job of legislatures to do that. I mean going back to what director comey introduced this phrase going dark. He didnt marry that with a legislative proposal. Just if i can press you on that a little bit, were a couple years into this as a policy issue right now. Where are you looking for this solution to come from . Well talk about what the solutions might be in a few minutes. But where is that going to come from if not from the people who are grappling with this problem and seem to be con fronting it on daily basis . The Obama Administration decided not no pursue legislation on this topic. Some say they dont see a legislative solution to it right now. Were not putting forward a legislative proposal ourselves. Weryinre t to make sure that debate remains alive, that it remains current but because the problem is current and the implications for us are significant. Well keep talking about it. Were here. We want to engage in robust, honestiscussion about this. The fact that the encryption conversation is sort of part of a wider conversation. Its not just the issue in encryption, right . It is always shifting. Which parts are filled in by technology and which arent . And so i think appreciating that, you know, in the in the last few years we noticed that i mean we had disclosed to us that Law Enforcements sort of filling in the lines ability is now greater than it has ever been before. Some of is surveillance and im sure you read that paper. It means there are other tools in the toolbox of Law Enforcement that dont necessarily provide all of the intent that perhaps content data would but can provide additional context that in many cases that years ago back when we were not living in a totally Digital World we didnt have. So there is, i think there are tradffs of encryption and tradeoffs of everyone having network devices. The connections are being made that simply werent before. So that is disorder. And for intent to be informed from other mechanisms. You know, this person talked to this person. This persons roll is hes previously been a runner for some purposes. There is information that can be iner iffed. So that is one piece that diagram sort of shows you. This isnt just a conversation about encryption. But its a piece its part of a whole. I think responding to one thing that mr. Baker said about legislation, i think i sympathize with them. The proposal is a difficult one to make. Because encryption is not just, i mean, we have panelists from we have transatlantic panelists. Encryption is not something that eu or its Member States or the u. S. Congress or state legislatures can address because the internet is global. Companies operate globally. Internet users use platforms from every corner of the world. And so legislating a solution which no one has proposed on this panel is a difficult one. Thats why there hasnt been that kind of successful proposal. If it existed, im sure director comey would have accepted it. Any legitimate proposal would be left to be seen why the context. You are here in the u. S. The internet Major Company are build here. But you should look at the same situation from the european perspective. The legislation should we do that, we will face the problem of jurisdiction. This is outside the jurisdiction on the specific judicial order. This is a major issue. That is why we are convinced that we have to look into other options. This is where the companies should help us if the best way forward. Go ahead. Im wonldering what sort of front door instruments that you can you might have in mind. You know, there are options. Options are being assessed. It is premature to mention it. But somebody talk about resipgs 2. 0 to make sure that some instrumentsre made available. Or announced. So that tl is judicial oversight. This needs to be further assessed to get to th company. But what we know from our discussions with all the constituencies is the amount of the solution will be fully satisfactory for the full benefit of Law Enforcement. Theyre probably encrypted while theyre on a server. But somebody has a key. So if you have an Insider Threat problem or you somebody is ill, kunyou cant access the da yachlt they want to access their own corporate emails, they have a way to do that. So corporations around the world have made a decision that balance between security of that data and the need to have access, they can figure it out. They can talk to their business in a sensible way. Thats one possibility. I dont know whether that would work on a scale with consumers and so on. The point, is i guess, were making choices. But were doing it in a sort of default kind of way. Encryption is just spreading. Encryption by default is growing and spreading across the sort of technology ecosystem. And its becoming more and more easily available to consumers who are law abiding. It is also becoming more easily available to criminals and to terrorists. High quality American Companies do it for you that know what theyre doing, youll have success using it as well. Following on that point, certainly sl are companies that can secure the data in such a way that somebody effect live has the master key. But correct me if im wrong, but most of the popular Encryption Technology thats were talking about that people are using, certainly the ones i gravitate towards as a journalist, one by which the company does not have the ability to unlock it. What were talking about is coming up with some solution that might look like that is possible solution. Does that mean that passing a law that says can you not build incription systems that way. It seems like we had a debate way back in the 90s with the clipper chip and key escrow. Its what were daunsing around here saying if will is a legislative solution to this, might it look like saying there are certain kinds of encryption designs can you do and certain signs that are going to say can you not do . Isnt that what were were going to confront that eventually . Maybe. You want to do it in a way that doesnt destroy the benefits gf encryption. Thats why i dont have the technical answer how to roll this out across the Economy Today sitting here. They have valid points and populated by good citizens that dont want bad guys using the systems. We know. That its not a question of anybody on this panel, you know, good or evil or anything like that. It is the bad people that we all collectively agree want to, we dont want them to use it. We do want to protect the data and privacy of law abiding americans and other people around the world. Can either of you imagine . Putting you on the spot here, but maybe you saw this the system in which you have that balance. Maybe it is Something Like a key escrow kind of system or requiring they must have a way to unlock the data. Is that going to work. Lets say we define that. Is that a system that companies are going to agree to . Is apple going to say sounds great . I mean, it will be good and global marketplace. They sudly discover that were not quite as competitive elsewhere as we are here. I think thats a sk, right . The same problem that is a result that we havent had legislative proposal made is that anything that sort of in imposed way there is encryption or for domestic products necessarily makes them less appealing to consumers here and then elsewhere. And so sort of but having, you ow, having experience recently in 2014 with the revelation, yeah, 2014 2013, 13, we are aware that any sort of even patina of sort of these are Law Enforcement companies cooperate regardless of what engineers think. But, you know, any patina, companies being, you know, Law Enforcement without, you know, considered discussion has been is going to affect the prospect internationally. I mean it hasnt affected them and affected them to privately shield or safe harbor and in and out privacy shield. There are consequence thats we will have to deal with that f. We decide to go down in a road. Can you pick up on this too . From the european perspective, i mean open markets, competition. These are still things that most European Countries are agreeing on. If a company is working and going to have to giv away information that, is going to make another companys products more effective. We could outlaw strong encryption in the United States. Someone is just going to do it in switzerland. And im going to get it from them. Absolutely. This is not the way forward. It is not to impose companies to void encryption that we solve the problem. There is an ability to run the market. We have to find a way. That is not satisfactory to work with the company to allow Law Enforcement to have the ability to identify information they need. We help Law Enforcement to announce their ability to exploiting the vulnerabilities that still exist in the system even if for zero days. Because then immediately the company stepped in. But there is no i repeat, it is probably repetition. There is no solution, one exclusion to this problem and certainly we do not advocate a legislation that impose impose incripon. There probably is not one solution for all the different problems. The issues confronted with data in motion. Theyre very different fm when you have data rest. So maybe anything too is to take one part of that aeven focus our efforts on that. Lets say data at rest on devices that the government has lawful possession of pursuant to a warrant. So take that, for example, and try to work through scenarios, s technical scenario thats would require some changes to law and see if we can build a consensus around those around some part of this. Because trying to figure it all out,ts too complicad, all the different parts of it and try to come up with a solution to deal with everything is probably is probabl too much. So that is a potential way forward to pick one part of the landscape, focus on that and see what we can do. And quite frankly, we want to do this now. We want to do this now. We dont want to do this in the aftermath of some serious event. Right . When were going to be under pressure to make decisions and we might not make does decision thats appropriatebly balance all the different irrelevant and valuable equities that we talked about here. We want to get this right. We dont want to do it in a hasty way. We need to stay focused on it in a sustained way. I want to pick up on this idea that youre getting out and this notion of lawful hacking. A couple weeks ago we saw wikileaks dumb thp tragic information that it claims our hacking tools essentially, call it the hacking arsenal that the cia uses to break into electronic devices. I dont think it comes to a surprise to anyone that they try to find ways to Access Technology that is legally trying to gather information from. But one thing that struck me in this was this might be a fairly vivid illustration of all the ways that an Intelligence Agency has to try to find to get around encryption. Find ways to get on to penetrate the operating system of ahone so that they can see what someone is typing and to what is telegram rather than trying to break encryption on the telegram. And it shouldnt be surprising at all that as were seeing the rise of strong encryption you are going to see a con current rise in very dedicated, deliberate well funneledded eff to get around it and find at way to skin the cat. How comfortable is industry with that which seems to be an undeniable consequence . You press on this one side of encryption. Youre going to get more hacking by the intelligence agencies. I think industry recognizes that sort of, you know, the reaflt building a complex system. No implementation is ever going to be perfect. So i mean advising against any sort of Law Enforcement hacking is not it would be remisto s remiss to say that is off the table entirely. We want them to have the tools that they need and to the extent that encryption because it is more funneldamental to embedded systems and other systems and on device systems that are already deployed worldwide. To the extent that there are chifrpgs chifr chinks to that armor that theyre able to exploit. If that is done in a way that is managed by appropriate Legal Process, appropriate disclosure requirements, appropriate notice, i think there is at least some solution. There is not a perfect solution, viously. But part of the some of all Perfect Solutions is there, i think. It see unrealistic to expect youre going to have a system that is lawful, regulated, errs on the side of disclosure and the Intelligence Agency standpoint, they want it to be lawful and regulated. Theyre not interested in disclosure. Theyre interested in finding eventualer in anlts can you exploit before can you fix them. Now they have to get over this giant encryption idea s it not in your customers interests to find a compromise on encryption rather than creating this massive motivation for the cia and fbi . I think given different Law Enforcement. I think the ability to abide by lawful and if you are at risk of fight something key encryption compromise, that affects all user worldwide as opposed to where lawful hacking can be deployed by intelligence agencies. I think the tradeoff is probably a better one there. At least from the perspective of the companies. If i may. We talk about investigation and not surveillance. When i was mentioning lawful hacking, ways referring to investigatns, criminal investigations and specific case. Thats what were aiming at. National security is not a part of the European Union. It is in our Member States. So when we train and help Law Enforcement to train the abilities, its in order to have a lawful hacking under a specific investigation, under a specific judicial order and oversight, i want to clarify this. Sure. But i mean to be able to have the capabilities, they need to be developed. Yeah. Basically sitting upn the shelf for when you might have to use them. For you a little bit on the spot with. This the apple the San Bernardino case, right . You had a warrant, absolutely. And what was undeniably an act of terrorism and pertinent to a relevant investigation of one. You face the challenge of saying cant we find a way to work it out . And then at least reportedly, i think the director may confirm this you found a way around it. Which i think everyone takes to mean you found a way to hack the phone and get what you needed. Reflect on that experience. That is the most public one that we have and it seems to sort of, you know, kind of encase all o the dilemmas test. Test. Test. Test. That we need to be public about it and tell the company thats the vulnerability exists and to fix it. So its a very uncomfortable and challenging dilemma. So we engage in lawful hacking. I would say we dont relish it or like it. Its a very its not as useful as you would think and it poses some other dilemmas. To the extent the bureau is involve, there is a process that is designed to the review the vulnerabilities that the government is aware of, and when to disclose and notify the manufacturers of and the users of the products. Can you talk about whether that process works . Well, we do. It rks. Is it satisfactory . These are challenging decisions that people can disagree on. People in the government are doing their level best. But you can have a debate. Wou you have an idea of how youre doing it in the u. S. Or european context . Are we trying to have an even balance or is it too early to try to make a determination. The industry has navigated how this works and its associated with national security. I think its something to be said because its an informal process within the executive branch having that codified in some way, but we saw a bill that came out last week from the senator strausss office that looks at taking the existing vulnerabilities, ensuring that the appropriate stakeholders, the representatives from the department of commerce and state, but also equallyalanced on the Law Enforcement side. The eni, nsa representative, and ensuring that conversation when it does happen there may be a presumption that happens, but ensuring that the equities are properly addressed. The Ste Department has long vocated for ensuring that their voices are being heard as part of the process is very important to us. Dont to respond. Well, very simply, how long we are going to wait . We need to time to find one solution or another solution. Were giving ourselves the time for this inclusive process, and we hopefully we want to share this with our partners because we have to be clear about it. We cannot solve the problem in our own jurisdiction. We have to find a way to work with our partners, and the first one is, of course, the u. S. Government. But at the same time Law Enforcement intnceellige services locally they face an issue, and this will continue to do what they can in order to get the information. At the moment, the only possibility is another Something Like a system where you announce your ability to local hacking and you try to overcome the problem. But the we need to find a spectrum of solution that allows us in the median term to identify the best way forward. James alluded to this. In the case of the San Bernardino case, we had an investigation, ultimately an entity as you said, came forward to the fbi with a solution. Are you finding more entities coming forward with more solutions to problems that you think you have . A lot of people want to sell us stuff, yeah. For sure. Were i dont want to say too much about this. But, you know, we we have technologists that we have inside the government that are focused on ts kind of issue, and there is a there are groups of people and corporations on the outside that are invested in this too. Corporations are themselves trying to figure out the vulnerabilities on their systems. So its a very active environment. The thing i worry about a bit in terms of thinking about this process and how were going to handle it in terms of evaluating th vulnerabilities is is this stuf is moving very rapidly. Tenology is changing constantly. Things are being updated. The updated technologists have vulnerabilities. And theyre detected by the government and malicious hackers and they exploit that. And anytime you have a process that im worried about any process thats too bureaucratic in trying to make these assessments. The American People have to think about that because this process is moving at a very rapid pace. To that point, were talking about this environment and its easy to forget this is a relatively new environment. I dont think that two orhree years ago i had too many encrypted apps on my smartphones and today i have nine for various reasons. And this is a foundational question that we might have started with. But why did this happen . Why did we suddenly go from an environment where most people were not probably familiar at all with these technologies to be able to download from the app store and use them in any way that you want. Is this the snowden revelations . Is it a fundamental mistrust . Why are people putting signal on their phone and i know more people thanust engaged in my profession are doing it now. Why now . What unleashed it . Sn i dont want to say the den relation was the cause of it. That might have precipitated a conversation. And people who are in government access and who might be interested in reading what youre writing or look at what youre purchasing. I dont think that whatever, you know i dont think that the precipitating event. I think just a larger sort of recognition of the regularity of breaches going on. You know, they happened before snowden, they have happened since. I think the sort of the recognition on our sort of individual basis that youre not as secure on the internet as you thought you were has nothing to do with snowdensevelations about the government and just a wider understanding by the population that we didnt know the internet is designed to be secure and connected folks, and the idea of protecting yourself is incumbent upon yourself. Thats what i think youre seeing it. Joel. Only one comment. All of us have discovered the internet and the beauty of internet what you call the best guys have dis the bad guys haveiscovered the internet and the ability to collect. In europe the social media are being exploited quite exponentially more and more and therefore the need to for the corporation and the users to protect themselves also from these there are a series of issues that bring us to this. I think it was it was happening anyway and the snowden revelations accelerated it. I think thats the basic answer. And then layer on top of that i think concerns that people have about their government. ve said before, you know, you shouldnt trust the fbi. You should be accountable. That makes sense. So anyway, i thinkhats the basic explanation. Do you think weve reached the point if companies arent offering encryption that their customers are going to think theyre irresponsible if theyre not leading that . To put that out there like a Good Housekeeping seal of approval now . I dont know that the customers. But it is best practices to s. E. C. Act so companies are always looking to be as compliant as they can be with regulatory authorities that are interested in data security, and theyre also interested in i dont think its an advertising tool. Its something that users are coming to expect on the part of the companies. So not having it makes you circumspect. There is a lot that makes you seem ill make an exaggerated statement but just for the fact that youre a stooge of the government. When apple and the fbi were trading the briefs in the case, there was an acknowledgement by apples lawyers that if we give into the fbi its going to be hurting our market. We cant be seen as giving an inch there. I think they were making a First Amendment argument than one directly about marketing. I would say marketing. They left it out in the subsequent briefs, but it was in the first one. Certain Companies Might treat it as a marketing employ. I cant speak on their behalf. But interactions with other companies suggest to me that its either an issue of users wanting to trust the company that theyre choosing to provide them with services, or its an issue of, you know, basic optimized security. You dont want to be offering products to customers that are eventually going to break or eventually going to leave them vulnerable. Thats not a good way of doing business here or anywhere else in the world. Just being seens a responsibility to make safe products. Why dont we turn to the questions from the audience right now. So please put up your hand if you have a question. Ill come down to the two people here in the first couple of rows. Wait for the microphone to come down to you. There you go. Lets go here. Yes, thk. Im mike nelson and ive been working on encryption policy for 25 years since i was a white house cochair to find out how it works. It didnt because people didnt adopt it. I think we all agree that technology has to be something that both industry and customer want. And i represent now a west coastbased web security firm. So let me share our thoughts from the west coast. Our first thought is that, if there is this magic technology, it would have been invented five or ten years ago, and somebody would have made billions of dollars off it. All the technologists say there is no way to build a back door or a front door that people are going to trust and that arent going to introduce new problems. So we have to look at what really will work. And it seems to me that the scenario that none of you mentioned is a scenario where we have the government doing things to make sure we have strong encryption rather than undermining it. And youve already mentioned the cases where various leaks exposed efforts by the government to promulgate ineffective encryption. If we had instead strong inkrepi encryption a thousand times more data to go after the bad guys. We have the technology where everybody could practice selfsurveillance. I could have technology in my home that could focus on everything that happened there. A hundred million homes had that crime would be a lot more difficult. There are ways to deploy stronger technology if individuals had control of the data, and that data could then be used to fight crime and used on the streets, in banks, all the places it could be used. But it will only be used if we trust it. And right now, we have no reason to trust it. So my question really is, how can we have a higher level of transparency and trust . How can governments actually reveal the vulnerability dollars so that the industry can deploy the internet of things, the cloudless things, selfsurveillance, all these things which would give you data to prevent crime and prevent millions of crime, rather than giving you the data you need to investigate a few hundred crimes . Isnt that the billion dollar idea, though . Yeah. Strong encryption is 100 billion. I dont understand it. Im not sure what data youre talking about. Sound like metadata. Talking about a system in my own home where i record everything that happens. I have my own surveillance system, closed circuit tv. Anything that happens in my home, i know what happens. So with a wrant that we can come in and have access to the data. It wouldnt be encrypted but with a key that you maintain, right . Yes. How do i deal with an operate of isis lets say, who is communicating usi encryption overseas. Youll have a lot more data of what that person is doing in the real wld rather than what theyre doing. I dont know where that data they have to get it. And with this internet were going to have a lot more data than we have today and youll be able to get that data from lawabiding citizens i disagree with you. If you have two isil operatives in syria talking to each other using an american system, american messaging app thats end encrypted theyre going to take on communications and plot whatever theyre plating and we wont be able to see that. That data will not exist if the company doesnt have a key, the two communint have a key, theyre not about to give it to us. Youre focusing on 1 of the problem. The new data youre going to have to determine the American People want to make an a choice and how much Law Enforcement has to it. Im not going to preach at this entire country. What were trying to say is there is data that will be available. Your kind of system will have cost as well, right . If every single utterance, every single activity is recorded in your home, the American People will have to decide. Its only available if the individual wants it. If somebody gets in and steels the key because grandma left it on a note i get your point. There is a lot of data available, and we try to make use of it in legal means. I disagree. I dont think what youre dealing with is a solution because we have to deal with the global threat. Thats the poi. Were not going to have the way to find. David brin wrote a wonderful book where everybody watches everybody and at the end of the day you have control of it. We all focus on the isis person talking to the other isis person. Because i at the fbi have to deal with that. I have to deal with people trying to kill other people. I get your point. And we have to deal with the other scenario, and its another scenario. If you build the infrastructure for that scenario, you miss the 99 were not sitting here with a solution were trying to impose to anybody. There is a question, actually, behind you. David gern from new america. The question is with regard to the particular threat youre talking about and what you need material difference and how deadly or how attacks or attack plots inside the u. S. Have you seen because of communications back to syria. Is that actually increasing death toll . Is it in in europe and elsewhere weve seen cases where it mobilizes existing network that do seem to provide arms, et cetera. In the u. S. Do we really have that problem now . Are you looking forward . Is it already here . Thanks. The problem has been here for some time in terms of, again, its its operatives inside the u. S. Communicating with people outside and having communications about whatever it is tyre talking about and we cant see it. That has been an increasing problem over time. Look, there are examples that we are able to talk about, the garland,texas, one is the one we figured that we can talking about. There are other matters that we dont talk about because they might be under investigation, and we cant talk about that. Which is a problem. The government needs to be tran transparent, i agree with that. But we need to control it so the bad guys dont know what were capable of and not capable. But it is a real problem today. Its going to increase as we expect over time. But its a real problem today and we saw it over the next several years. Sir, in front of you. The gentleman in the beard here, first. My name is john meredith. I was surprised you mentioned you have no proposals from the fbi as far as legislation. How are we going to go forward if you dont make a formal request expressing what your requirements are to the appropriate committees in congress . There are a lot of legislative proposals but the executive branch is whether there will be a proposal put forward. This is not so hard that you cant write in a concise way a legislative proposal. The challenge is getting a legislative proposal writing a law that achieves what you want to achieve. Thats the hard thing. So we as a society, i think, have not figured out what we want to achieve. Once we figure that out, balancing all these different he can quits weve been talking about, we dont agree how to balance of the different equits, and we are trying to figure it out. But once we come to some consensus, the writing on the page is not that hard. Just to follow up really quick. Can you imagine a world in which we dont bother with a law but the industry forms certain standards and say under certain circumstances we will cooperate with Law Enforcement if the following criteria are met, major terrorist attempt, preventing loss of life, Something Like that. The theme is were not getting a law anytime soon. They cant even get a Republican Congress to agree on health care. Were not going to move on to encryption anytime soon. Can you imagine a situation where we bypass the law and come to some sort of ethical conduct or Something Like that . The industry cooperates to the extent it can. Youve seen it through transparency reporting. There is a trend to cooperate. Sometimes to user chagrin, i think, with Law Enforcement investigation. Whether a consortium would come together to create an ethical conduct to decide when to provide access to encrypted systems, i cant imagine that being just because we run into the same problems that we now have a consortium of companies that far selling products that are less good than other products of the companies that are not under consortium. There are market pressures, i think. I think your your question is very interesting because we are still seeing within the European Union in our nation to the social Media Company exactly this kind of thread. We are engaged in the Internet Forum to regard to removal of terrorist content on the platform, inviting them to consult together and create a consortium so as to remove the terrorist content, calling to the terms and conditions. And some of the companies, i will not name which ones, even changed the terms of condition in order to make sure that the referral process from the internet referral unit or with a word or in particular in europe is immediately taken down. So the concept is the same. The public is discussing with the companies, inviting them to take up their own social responsibility and changing the framework or adapting the framework in which they work so under the voluntarily initiative they will make sure to intervene when is necessary, affecting themselves only their own terms and conditions when to do it. Its something that we are exploring as well in europe. Thank you. My name is i think your mic is off, maybe . Thank you. My name is ali shiraz. I come from a nation where tens of thousands of our people have been massacred by the taliban and we have considered the daesh with a beast inside the middle east. I appreciate the fact that you are all going to the tactical finding a solution for encryption. Even if you are to resolve the encryption problem youre not going to stop these people from killing and doing what their intending on doing. Why doesnt the world concentrate who the mother the queen bee that is funding the operation . The person who comes and does the killings in the United States or afs ghanistan supported by someone by him and then above him. Alb albaghdadi is funding this, and then there is somebody above who is funding him. Why dont we go after the people who fund this, and if we cut off the funding, they wont have the opportunity to pay the suicide they have to pay any suici suicide bomber, 5,000 and 15,000 lets give a chance to respond which is outside of the scope. I think there is a con severitied effort to try to take out the people funnelediding th groups. The United States is trying to weed out all the threats of isis, theres no doubt, trying to influence the funding sources. Theyre very highly funded and i agree that cutting the funding is a significant way to damage the organization, and we aggressively do this, but its hard. People on the side. I have a question from you, maam. I want to make sure people are taken into account. Raise your hand if you have one. Well go to you next. My name is didi cutler. Do you have a time frame to solve the encryption problem . Thats the question. Youre the expert. Thats a very reasonable question, and there is a lot of assumptions embedded in this discussion that this is intractable, right . But, i mean, is there a time horizon on Something Like that . Are we near it or is it frankly going to take a catastrophe that focuses the mind, to james earlier point, its not a great time to come up with policy solutions . Lets hope thats not the case, obviously. Sure. No is the direct answer to your question. I think that i know i dont know when this will be resolved. As i suggested earlier, i think a way to perceive is to focus on a part of the problem such as the data on devices or you can pick another part of the problem and try to focus on that and have a robust discussion, and as the gentleman was saying earlier, trying to sit down with the technical experts, if we did this, what is the cost, what is the tradeoff . I guess i dont agree that technologists dont think that it cant be done. Ive talked to them and they think it can be done. Their risks that we have today. And the systems that we have today is not perfect. Theyre filled with vulnerabilities. You have data that is acquired about us by lots of Different Companies and we have no clue where it is, whats happening to it. Its opaque, and there is a risk as well. Risks abound. And focusing our efforts on the one part of the problem may be a way forward to try to see if we can build consensus that does require folks to acknowledge that the Law Enforcement faces a problem, that the other alternatives available to us are insufficient, such as metadata and lawful hacking. They are insufficient. And then we can move with the dialogue. Luigi, you want to respond . As i told you last year, we have launched this kind of debate. And we are putting together technical people, the lawyers, the Civil Society, the politicians to have this discussion. We are planning to exhaust our preparation until the end of this year. But then we will put up option for a political debate. As james said already before, Society Needs to decide where is the balance. And through the political representative that will be elected in our country, we the Civil Society, the company, have a discussion and then a collective decision where to put exactly the demarcaon line, how far we want to go the discussion between security and nonsecurity. I dont bet on a march madness school. So no odds for me. As far as coming to a solution, so i think, you know, its not going to happen in the immediate term but more an a long term conversation. And god forbid, if there is an attack in the interim there, but if i were to, you know, put put money down on something i think the solution in the end to be some sort of recognition by access to public conversation and looks at technical balances and looking at the insufficiency of metadata and that is insufficient for the American People and worldwide. You have a question here. Put your hand up so they can see you with the mic. There you go. Thank you. My name is elizabeth mcorder. Im with the Senate Security committee. My question is for mr. Baker. I get that you dont want to advertise capability gaps to the bad guys. But the challenge for policy makers is that transparency helps provide legitimacy to provide will for action, and i think were lacking that transparency. And i know the fbi used to produce publicly available reports on the domestic terrorism situation annually until it ended in 2005. I know g. W. University and shamus has provided reports and access. And i am glad to see that the fbi is more willing to talk about garland and investigations like that and why you are limitations, but moving forward it would be nice from a policy makers perspective to have more transparency and coordination and id like to know how the fbi plans to do that. So we with respect to trying to collect data. Thats how i was taking your question, data to explain what the problem is so people can have a sense. Its a totally legitimate point and were trying to collect data. We looked at different time periods but the one i have clear in my mind is from the last three months of last year, where we had, lets say, around 2,500 i think devices that were brought to the fbi from around the country for analysis, and we could not open about 40 of those. We had no technical means to open those. What kind of cases . I think we have the data to sort of a degree. One of the challenges that we face is that Law Enforcement officers and the intelligence officials who are busy and doing investigations quickly figure out what types of platforms they can get access to and which ones they cant. And theyre not going to waste their time seeking a title 3 order or a fisa on the intelligence side. These are labor intensive processes to get those surveillances. They wont waste the time if they know the thing is encrypted anyway so why do i bother. That is one of the most significant problem, is people saying im not going to waste my time. Its a data point thats missing that therefore any data that is going to come forward doesnt really reflect the true nature of the problem because people are selfsensoring out in the field, theyre not out bothering about it. They never make it to the Justice Department or the fbi. Its an incomplete picture. Were struggling with that and thats why we sort of not sort of. We have focused on this one point of collection data that we know is available to us. We have people actively thinking about how to do that. Because youre right, we need to back this up with data. I agree with you. Maybe not from a industry perspective, but a curious person perspective. What is for the fbi agent still manages to practice absent the encryption being done. The 43 of devices that we cant access, but what percentage of those cases were they able to move forward to a prosecution or close investigations . We keep moving all cases because were not going to stop because of these devices. We never give up. It may take longer. It may be riskier. You may have to put a human source or fbi agent in harms way in order to get the data. So thats its more expensive and risk to the integrity of the investigation. All of those costs add to it even at the end of the day were able to solve it. Notwithstanding encryption. The gentleman in the third row. Last question. My name is brian. Im a student here at g. W. Law. I want to talk about two groups that have been underrepresented, but its been a great conversation nonetheless. Its consumers who might need encryption and other policy to prevent hacks by terrorists or cyber access and theyre not usually adequately represented at conferences like this. And the human rights and Civil Society rights activists overseas, many of whom face autocratic governments and passing the right legislative policy solutions within the u. K. , and the u. S. , or the eu but the issues that happen is these get demanded by the governments overseas and if u. S. Government especially would have cooperated in the local governments and here and in the eu then cooperate with foreign governments as well. We should have a more autocratic stance. I wanted to ask what moves are you taking to ensure that the consumers and Civil Society activists are adequately represented . Okay. I can jump in. On the representation issue it turns out there is a conference in brussels happening this week. You should there may be some live streams. Most of the human rights and privacy rights representatives are there. But when it comes to sort of the the collaboration with these organizations i know industry, me in particular, i have robust relationships with folks in the human rights community, the private community, representing consumers rights, and im sure the fbi and and eu have similar interactions, i think, in your ill let you respond. Definitely to assure you, the consumers and when we call what we call in europe the Civil Society, including the ngos where they sit and they present the views and they are followed and a deposition is there. To respond to the question how do you deal with the potential ability that other foreign governments will use the that ability. That is something that we discuss and are potentially concerned about. Thats why the point and jurisdiction is so important, in my opinion. We have to be very careful to talk about legislative proposal that would then push the companies to make available not only to ourself or but to other Foreign Countries the ability to decrypt those systems. So thats something that we really take care of, and its part of the discussion that we have. James, last word. Sure. Were hopeful for a solution to this problem. But a solution that results in more peoples data being vulnerable and more cybersecurity threats and more consumers being exploited is not a solution. If we if it does that, then its not a solution. If it does not protect innocent people from abuse by oppressive golfs overseas, then its not a solution. We agree with that, we know that, and what we hope for is some type of solution that appropriately balances all these things in the right way, that protects innocent people, that enables Law Enforcement to do what it needs to do, that allows companies to be innovative and competitive in the market system. Otherwise its not a solution. And it wont be acceptable to society. And there will be no solution if not people deal with it. I think the host will have last words. I want to thank the panel very much for being here for a great discussion. Thank you, all. Thank you for your questions. [ applause ] i thank the panelists. Its been a absolutely great conversation. If i were to think of the three words that ive heard consistently from all of the speakers and from the barnones before that, is balance and discussion. Ill be brief. Just a note, were going to be starting again tomorrow at 9 00, we have coffee outside, and then 9 45, well have a keynote by doctor from the ue. I thank you for being here today. This was a fantastic appetizer, and i cannot think of a better one, one of more substance to the larger conversation well have tomorrow. Well be speaking again about encryption, privacy, a lot about countermessaging. So i look forward to seeing you tomorrow. And i want to thank you again for coming tonight. Thank you. [ applause ] this weekend on American History tv, on cspan 3. Saturday at 6 45 p. M. Eastern, james haily, author of captive paradise, a history of hawaii talks about the last queen of the kingdom of hawaii. She had been secretly been working on a new constitution that would restore her royal powers. From this pro session she went to the palace and announced her constitution and that was the beginning of the overthrow. At 9 00 historianian about 20th century president s. How weak the american presidency was in the late 19th century and how powerful it was when Theodore Roosevelt sur renders power. Sunday at 4 00 p. M. Eastern on real america, the 1961 documentary ordeal of woodrow wilson. These delegates were determined not to let idealism stand in their way and for their own purposes and desires. For our complete American History schedule go to cspan. Org. President trumps calls for large cuts to research programs. A mother whose young son died of a brain tumor testified about research in tumors and Clinical Trials to minorities and how the cuts would impact future