How the FBI's numbers fumble moves the encryption debate
The FBI has long made the case that it needs access to encrypted cell phones to stop crime. But one of the key statistics the agency has recently cited to support that case was grossly inflated thanks to a programming goof, the Washington Post reported Tuesday.
Why it matters: Supporters of strong encryption will likely see this screw-up — the second of its kind that we’ve learned of in two months — as a problem of honesty. But there's a chance there may be a more material effect on the encryption debate in changing how risk gets balanced with safety.
The bottom line: The deeply entrenched sides of the public debate will continue their standoff, but behind closed doors, where real compromise is being discussed, the calculations may shift.
By the (wrong) numbers: FBI director Christopher Wray has claimed there were around 7,800 phones related to crimes being investigated that the bureau could not access due to unbreakable security measures. It turns out that, while an exact tally is still being calculated, the accurate figure is somewhere between 1,000 and 2,000.
"This is a pretty bad mistake," said David Kris, former assistant attorney general for national security and founder of Culper Partners.
- Law enforcement authorities seek legislation mandating “backdoors” in phones and other devices letting them access even encrypted contents in extraordinary circumstances.
- Experts believe nearly unanimously that weakening encryption with backdoors would catastrophically reduce global cybersecurity.
- The public debate on this issue centers around whether it’s possible to find a technological solution that would give law enforcement access to encrypted data without everyone else suffering those catastrophic consequences.
- That technological solution likely doesn’t exist, meaning that the more nuanced debate that proceeds behind closed doors is about risk management. Participants in that debate are wrestling with how to limit the use of back doors by finding a risk/reward balance. The risk to be contained is the impact of a future Wannacry type of event; the reward is the crime-fighting value of accessing a certain number of phones.
But, but, but: You can’t do good risk management with bad data.
- With numbers overinflated between 4 and 8-fold, the FBI was arguing backdoors were 4 to 8 times more important than they actually are.
- Balancing the risk/reward equation, that meant the FBI was giving itself license to justify 4 to 8 times as much risk.
Flashback: Two months ago, an FBI inspector general report found that the FBI had incorrectly testified before Congress about the encryption issue during the San Bernardino terrorism case in 2016. Then-director James Comey claimed to have exhausted all avenues to break into a cell phone belonging to a suspected terrorist and used that issue to make the case for backdoors. One problem: The FBI had not, in fact, exhausted its resources.
Reality check: Though stakeholders may make try to make this about the FBI's honesty, even staunch supporters of strong encryption generally agree these repeated misstatements haven't been intentional. "The fact the FBI came forward with these errors — let’s see where that goes before seeking out an investigation," said backdoor opponent Rep. Will Hurd (R-Texas) at a Wednesday panel discussion at the Aspen Institute in Washington, D.C.
FBI will keep making the same case: At the Aspen event, FBI associate deputy director Paul Abbate argued that even 1000 phones are more than enough to be concerned about: "Each one of those numbers represents a terrorist attack that could have been prevented or a child that could have been protected."
So will the opposition: The way proponents of strong encryption see it, the FBI’s flubs might weaken the agency’s hand but don't change the fundamentals of their case at all.
"When the denominator is the 350 million Americans whose cell phones might become vulnerable if you introduced backdoors," said McAfee chief technology officer Steve Grobman, "it doesn't matter if the numerator is 1,000 or 7,000."