From: smb@research.att.com
To: David Sobel <dsobel@washofc.cpsr.org>
Message Hash: 6963287445bad7d26de21fc60c7730f9a2d9570f584d0877fdb3a4cb85926502
Message ID: <9308120007.AA19082@toad.com>
Reply To: N/A
UTC Datetime: 1993-08-12 00:12:05 UTC
Raw Date: Wed, 11 Aug 93 17:12:05 PDT
From: smb@research.att.com
Date: Wed, 11 Aug 93 17:12:05 PDT
To: David Sobel <dsobel@washofc.cpsr.org>
Subject: Re: Clipper trapdoor?
Message-ID: <9308120007.AA19082@toad.com>
MIME-Version: 1.0
Content-Type: text/plain
Consider the following hypothetical: Iraqi agents smuggle
Clipper phones out of the U.S. Saddam Hussein uses them to
communicate with his military commander in Basra. NSA
intercepts the communications. Question: How does NSA
decrypt the messages?
You raise a valid point. I think there are several possible answers.
First, of course, since the key escrow mechanism has not yet been
established, an exception could be written into the procedures. (And
whether they would be established by law or executive order remains to
be seen.) There might be some clause saying, ``NSA may have access to
escrowed keys, provided that they certify that the targets of their
surveillance are foreign powers, as defined in the FISA. If, upon
decryption, it is determined that a U.S. citizen's conversations have
been intercepted, the procedures of the FISA for such eventualities
will apply.'' Yes, they could abuse such a clause -- but by that
logic, they could be listening in to cleartext domestic phone calls
today. (And of course, there have been such abuses.)
A second possible answer is for export phones to come from a separate
production run, using a different family key. These would be
export-only, and you'd never get a license to export a ``secure''
model. For U.S. residents to make an encrypted phone call to such a
site, either they, too, would need such a phone, or they need some way
to interoperate with a phone with a different family key. The obstacle
there is the verification procedures such phones have, to guard against
bogus narc headers being inserted. I'm not certain whether or not such
a solution can be found.
--Steve Bellovin
Return to August 1993
Return to “smb@research.att.com”
1993-08-12 (Wed, 11 Aug 93 17:12:05 PDT) - Re: Clipper trapdoor? - smb@research.att.com