When you put security in general terms such as the ones above, it sounds silly to mandate that contractors have a key to every home they have built. But in the wake of the iPhone debacle between the F.B.I. and Apple, a new bill in being introduced in Congress is trying to force technology manufacturers to make sure that your data is available to law enforcement, and anyone else who can get a copy of the key to your smartphone’s front door.
This Did Not Start In San Bernardino, California
Under normal circumstances, federal law mandates that technology companies provide information for investigations unless the company feels that providing that information would be harmful in some way. Apple argued that being asked to bypass its own encryption would weaken the security it offers its customers, and that sparked a battle that is still raging.
The Secure Data Act Versus The Compliance With Court Orders Act Of 2016
In 2015, long before any battles over encryption in the media, Senator Ron Wyden and Representative Zoe Lofgren introduced the Secure Data Act to Congress. In a nutshell, the Secure Data Act says that manufacturers cannot be told by any government agency to weaken the security of their products to allow investigators to access encrypted data. The bill is still in draft form in both houses, but it has gained a great deal of support since the battle between Apple and the F.B.I. over San Bernardino.
After the San Bernardino encryption battle was made public, Senators Dianne Feinstein and Richard Burr introduced the Compliance With Court Orders Act of 2016. This act basically says that manufacturers must create ways to bypass their own encryption, or have a method for storing user data so that it can be turned over to investigators. This is the legal version of the contractor with a key to your house example we started with. This bill is also in draft form, and it is causing a lot of controversy, but having problems gaining real traction.
The Core Of The Debate
If the new compliance bill becomes law, then user data could be exposed at levels that the lawmakers may not realize. A disgruntled Google employee could wind up selling data from millions of Gmail address, or a terrorist could access an iPhone to get all of the personal data that phone contains. As it stands right now, it is almost impossible for tech companies to access encrypted data, and that is what makes the data so safe. If things start to change, then there could be major issues with privacy that users may not realize until it is too late.