Lawmakers Question FBI’s Push for Backdoors in Encrypted Devices

Ivan C/Shutterstock.com

They also push a wave of privacy bills post-Facebook’s Hill visit.

A bipartisan crew of 10 House lawmakers took FBI Director Christopher Wray to task Friday following an inspector general report that found the bureau rushed to court to force Apple to help it break into the encrypted iPhone used by San Bernardino shooter Syed Farook in 2015 without exploring other options.

Ultimately, the FBI withdrew its case against Apple when an unnamed third party offered to sell the bureau a tool to break into the phone without Apple’s help—a tool that a separate FBI division knew was nearly complete when the FBI first brought the Apple case, the IG found.

The rush to litigation, detailed in the IG report, suggests the FBI hasn’t been completely honest about the threat that warrant-proof encryption systems pose to national security, the lawmakers write.

Wray and his predecessor James Comey have warned that such end-to-end encryption systems allow criminals and terrorists to “go dark” online. The FBI has said it encountered 7,800 locked mobile devices that it could not access last year.

The lawmakers, including Rep. Zoe Lofgren, D-Calif., and Darrell Issa, R-Calif., ask whether the FBI has worked with companies that might be able to help it hack into the 7,800 locked devices the bureau says it was stymied by last year. The lawmakers also want to know if the FBI has explored other options, such as accessing the same data in the cloud.

Lawmakers Poke at Zuckerberg

Mark Zuckerberg’s marathon testimony this week before two congressional appeared to raise more questions than it answered regarding data privacy, online politicking and the tech industry’s influence on society. The hearings renewed calls to regulate the social media giant, and lawmakers grilled the Facebook CEO on a handful of bills that would scale back the company’s power over personal information and address close some of the online loopholes that allowed Russian actors to meddle in the 2016 election.

Among the potential legislation are two bills that would create mandatory opt-in policies for companies collecting user data, a measure that would require companies to notify customers of data breaches within 30 days, and an amendment that would force web platforms to disclose who paid for political ads on their site.

Three Cyber Threat Indicators and a Pickle Jar as Big as Your Head, Please

The Homeland Security Department is urging large and cyber-savvy companies that might not necessarily benefit from the department’s automated indicator sharing program for cyber threat data to sign up anyway, Secretary Kirstjen Nielsen told House appropriators Wednesday.

The department’s expectation is that smaller companies will benefit from information those larger companies share, Nielsen said, describing it as the Costco model: “The more people who join this program, the better information that we can give out.”

House Approps Getting in on the Cyber Game

During that same hearing, Rep. Dutch Ruppersberger, D-Md., announced he’s prepping a report for the House Appropriations Committee about Homeland Security’s cyber authorities. Major topics for the report will include the department efforts to counter leaks of cyber tools, threats to industrial control systems and information sharing between government and the private sector, Ruppersberger said.

Ruppersberger also urged a subcommittee hearing focused on cybersecurity, an idea Nielsen said she supported.  

From the Department of Weights and Measures

Three top former cyber officials endorsed in principle, a bill from Rep. Joe Wilson, R-S.C., Wednesday that would create a measuring system for the severity of digital attacks. Wilson’s goal is to develop a common language that will help government prioritize cyber threats and gauge the appropriate responses, a goal that appealed to Former Homeland Security Secretaries Jeh Johnson and Michael Chertoff and former National Security Agency Director Keith Alexander.

Johnson warned, however, that cyberattacks vary widely and it would be difficult to clearly measure them across targets.

Bill Aims to Boost Defense Manufacturer Cyber Protections

A consortium of public-private partnership groups that help manufacturers meet federal guidelines would receive broader authority to help defense manufacturers amp up their cyber protections, under a bill introduced Friday by House and Senate lawmakers.

The bill would authorize Manufacturing Extension Partnerships to conduct voluntary assessments of small defense manufacturers’ cyber protections and to help those manufacturers implement fixes for cyber vulnerabilities.

Sponsors include Rep. Jimmy Panetta, D-Calif., and Sen. Chris Coons, D-Del.

Anti-Sex Trafficking Act Signed into Law

Days after federal authorities on April 7 seized Backpage.com, a classifieds website often accused of enabling prostitution and child trafficking, President Donald Trump signed the Allow States and Victims to Fight Online Sex Trafficking Act into law. The signing followed a months-long debate over whether the bill aimed at curbing internet sex trafficking would stifle internet freedom and stunt the growth of small tech companies. The legislation will arm state and local prosecutors with a new set of legal tools to take action against web platforms that “knowingly” facilitate sex trafficking or prostitution.

“The political people around the desk, every one of them—Democrat and Republican—have worked very hard,” Trump said before signing the bill Wednesday.  “It was surprisingly difficult—you would think it would be easy, but it was much more difficult than any of us would have assumed because people have reasons. This should not have been as hard and it shouldn't have taken as long.”

COMING UP

Congress has a blockbuster week for tech and cyber issues this week. Here’s a rundown.

On Monday at 5 p.m., the House Rules Committee will consider bills including one aimed at boosting technology and cybersecurity at the IRS and another protecting children from identity theft.

On Tuesday at 10 a.m., the House Armed Services Committee will hear from the Pentagon’s Defense Innovation Board and its undersecretary of Defense for research and engineering.

At that same time, a House Appropriations panel will hold a budget hearing for the General Services Administration.

At 10:15 a.m., the House Energy Committee will convene a hearing on internet prioritization.

On Wednesday at 10 a.m., the Senate Commerce Committee will examine how to end abusive robocalls.

At the same time, the Senate Judiciary Committee will conduct an oversight hearing of the U.S. Patent and Trademark Office, and the House Oversight Committee will hold a hearing on top management and performance challenges identified by inspectors general across the government.

At 10:30, a House Appropriations Committee will delve into challenges, technical and otherwise, facing the 2020 census.

At 2 p.m., a House Oversight panel will hold its third hearing on game changers in artificial intelligence.

At 2:30, a Senate Armed Services panel will study new technologies and emerging threats in the Defense Department.  

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.