// COMPLETE THREAD

doj_escrow_intercept.procedures (fwd)

5 expanded posts ยท every known parent and child

NODE a687f567doj_escrow_intercept.procedures (fwd)
Forwarded message:
From postmaster Fri Feb  4 17:49:23 1994
Date: Fri, 4 Feb 1994 17:47:39 -0500
From: Dan Brown <brown>
Message-Id: <199402042247.RAA00193@eff.org>
To: eff-board, eff-staff
Subject: doj_escrow_intercept.procedures

U.S. Department of Justice
Washington, D.C. 20530

February 4, 1994



AUTHORIZATION PROCEDURES FOR RELEASE OF ENCRYPTION KEY COMPONENTS    
     IN CONJUNCTION WITH INTERCEPTS PURSUANT TO TITLE III

The following are the procedures for the release of escrowed key 
components in conjunction with lawfully authorized interception of 
communications encrypted with a key-escrow encryption method. 
These procedures cover all electronic surveillance conducted 
pursuant to Title III of the Omnibus crime Control and Safe 
Streets Act of 1968, as amended (Title III), Title 18, United 
States Code, Section 2510 et seq.

	1) In each case there shall be a legal authorization for the 
interception of wire and/or electronic communications.

	2) All electronic surveillance court orders under Title III 
shall contain provisions authorizing after-the-fact minimization, 
pursuant to 18 U.S.C. 2518(5), permitting the interception and 
retention of coded communications, including encrypted 
communications.

	3) In the event that federal law enforcement agents discover 
during the course of any lawfully authorized interception that 
communications encrypted with a key escrow encryption method are 
being utilized, they may obtain a certification from the 
investigative agency conducting the investigation, or the Attorney 
General of the United States or designee thereof. Such 
certification shall

		(a) identify the law enforcement agency or other 
authority conducting the interception and the person providing the 
certification; 

		(b) certify that necessary legal authorization has been 
obtained to conduct electronic surveillance regarding these 
communications; 

		(c) specify the termination date of the period for which 
interception has been authorized; 

		(d) identify by docket number or other suitable method 
of specification the source of the authorization;

		(e) certify that communications covered by that 
authorization are being encrypted with a key-escrow encryption 
method;

		(f) specify the identifier (ID) number of the key escrow 
encryption chip providing such encryption; and

		(g) specify the serial (ID) number of the key-escrow 
decryption device that will be used by the law enforcement agency 
or other authority for decryption of the intercepted 
communications.

	4) The agency conducting the interception shall submit this 
certification to each of the designated key component escrow 
agents. If the certification has been provided by an investigative 
agency, as soon thereafter as practicable, an attorney associated 
with the United States Attorney's Office supervising the 
investigation shall provide each of the key component escrow 
agents with written confirmation of the certification.

	5) Upon receiving the certification from the requesting 
investigative agency, each key component escrow agent shall 
release the necessary key component to the requesting agency. The 
key components shall be provided in a manner that assures they 
cannot be used other than in conjunction with the lawfully 
authorized electronic surveillance for which they were requested.

	6) Each of the key component escrow agents shall retain a 
copy of the certification of the requesting agency, as well as the 
subsequent confirmation of the United States Attorney's Office. In 
addition, the requesting agency shall retain a copy of the 
certification and provide copies to the following for retention in 
accordance with normal record keeping requirements:

		(a) the United States Attorney's Office supervising the 
investigation, and
		
		(b) the Department of Justice, Office of Enforcement 
Operations.

	7) Upon, or prior to, completion of the electronic 
surveillance phase of the investigation, the ability of the 
requesting agency to decrypt intercepted communications shall 
terminate, and the requesting agency may not retain the key 
components.

	8) The Department of Justice shall, in each such case,

		(a) ascertain the existence of authorizations for 
electronic surveillance in cases for which escrowed key components 
have been released;

		(b) ascertain that key components for a particular key 
escrow encryption chip are being used only by an investigative 
agency authorized to conduct electronic surveillance of 
communications encrypted with that chip; and 

		(c) ascertain that, no later than the completion of the 
electronic surveillance phase of the investigation, the ability of 
the requesting agency to decrypt intercepted communications is 
terminated.

	9) In reporting to the Administrative Office of the United 
States Courts pursuant to 18 U.S.C. Section 2519(2), the Assistant 
Attorney General for the Criminal Division shall, with respect to 
any order for authorized electronic surveillance for which 
escrowed encryption components were released and used for 
decryption, specifically note that fact.

These procedures do not create, and are not intended to create, 
any substantive rights for individuals intercepted through 
electronic surveillance, and noncompliance with these procedures 
shall not provide the basis for any motion to suppress or other 
objection to the introduction of electronic surveillance evidence 
lawfully acquired.

*************************************************************



U.S. Department of Justice
Washington, D.C. 20530

February 4, 1994



AUTHORIZATION PROCEDURES FOR RELEASE OF ENCRYPTION KEY COMPONENTS
    IN CONJUNCTION WITH INTERCEPTS PURSUANT TO STATE STATUTES

Key component escrow agents may only release escrowed key 
components to law enforcement or prosecutorial authorities for use 
in conjunction with lawfully authorized interception of 
communications encrypted with a key-escrow encryption method. 
These procedures apply to the release of key components to State 
and local law enforcement or prosecutorial authorities for use in 
conjunction with interceptions conducted pursuant to relevant 
State statutes authorizing electronic surveillance, and Title III 
of the Omnibus crime Control and Safe Streets Act of 1968, as 
amended, Title 18, United States Code, Section 2510 et seq.

	1) The state or local law enforcement or prosecutorial 
authority must be conducting an interception of wire and/or 
electronic communications pursuant to lawful authorization.

	2) Requests for release of escrowed key components must be 
submitted to the key component escrow agents by the principal 
prosecuting attorney of the State, or of a political subdivision 
thereof, responsible for the lawfully authorized electronic 
surveillance.

	3) The principal prosecuting attorney of such State or 
political subdivision of such State shall submit with the request 
for escrowed key components a certification that shall

		(a) identify the law enforcement agency or other 
authority conducting the interception and the prosecuting attorney 
responsible therefor; 

		(b) certify that necessary legal authorization for 
interception has been obtained to conduct electronic surveillance 
regarding these communications; 

		(c) specify the termination date of the period for which 
interception has been authorize;

		(d) identify by docket number or other suitable method 
of specification the source of the authorization;

		(e) certify that communications covered by that 
authorization are being encrypted with a key-escrow encryption 
method;

		(f) specify the identifier (ID) number of the key escrow 
chip providing such encryption; and 

		(g) specify the serial (ID) number of the key-escrow 
decryption device that will be used by the law enforcement agency 
or other authority for decryption of the intercepted 
communications.

	4) Such certification must be submitted by the principal 
prosecuting attorney of that State or political subdivision to 
each of the designated key component escrow agents.

	5) Upon receiving the certification from the principal 
prosecuting attorney of the State or political subdivision, each 
key component escrow agent shall release the necessary key 
component to the intercepting State or local law enforcement 
agency or other authority. The key components shall be provided in 
a manner that assures they cannot be used other than in 
conjunction with the lawfully authorized electronic surveillance 
for which they were requested.

	6) Each of the key component escrow agents shall retain a 
copy of the certification of the principal prosecuting attorney of 
the State or political subdivision. In addition, such prosecuting 
attorney shall provide a copy of the certification to the 
Department of Justice, for retention in accordance with normal 
record keeping requirements.

	7) Upon, or prior to, completion of the electronic 
surveillance phase of the investigation, the ability of the 
intercepting law enforcement agency or other authority to decrypt 
intercepted communications shall terminate, and the intercepting 
law enforcement agency or other authority may not retain the key 
components.

	8) The Department of Justice may, in each such case, make 
inquiry to

		(a) ascertain the existence of authorizations for 
electronic surveillance in cases for which escrowed key components 
have been released;

		(b) ascertain that key components for a particular key 
escrow encryption chip are being used only by an investigative 
agency authorized to conduct electronic surveillance of 
communications encrypted with that chip; and

		(c) ascertain that, no later than the completion of the 
electronic surveillance phase of the investigation, the ability of 
the requesting agency to decrypt intercepted communications is 
terminated.

	9) In reporting to the Administrative Office of the United 
States Courts pursuant to 18 U.S.C. Section 2519(2), the principal 
prosecuting attorney of a State or of a political subdivision of a 
State may, with respect to any order for authorized electronic 
surveillance for which escrowed encryption components were 
released and used for decryption, desire to note that fact.

These procedures do not create, and are not intended to create, 
any substantive rights for individuals intercepted through 
electronic surveillance, and noncompliance with these procedures 
shall not provide the basis for any motion to suppress or other 
objection to the introduction of electronic surveillance evidence 
lawfully acquired.

*************************************************************



U.S. Department of Justice
Washington D.C. 20530

February 4, 1994



AUTHORIZATION PROCEDURES FOR RELEASE OF ENCRYPTION KEY COMPONENTS
         IN CONJUNCTION WITH INTERCEPTS PURSUANT TO FISA

The following are the procedures for the release of escrowed key 
components in conjunction with lawfully authorized interception of 
communications encrypted with a key-escrow encryption method. 
These procedures cover all electronic surveillance conducted 
pursuant to the Foreign Intelligence Surveillance Act (FISA), Pub. 
L. 95-511, which appears at Title 50, U.S. Code, Section 1801 et 
seq.

	1 ) In each case there shall be a legal authorization for the 
interception of wire and/or electronic communications.

	2) In the event that federal authorities discover during the 
course of any lawfully authorized interception that communications 
encrypted with a key-escrow encryption method are being utilized, 
they may obtain a certification from an agency authorized to 
participate in the conduct of the interception, or from the 
Attorney General of the United States or designee thereof. Such 
certification shall

		(a) identify the agency participating in the conduct of 
the interception and the person providing the certification;

		to conduct electronic surveillance regarding these 
communications;

		(c) specify the termination date of the period for which 
interception has been authorized;

		(d) identify by docket number or other suitable method 
of specification the source of the authorization;

		(e) certify that communications covered by that 
authorization are being encrypted with a key-escrow encryption 
method;

		(f) specify the identifier (ID) number of the key escrow 
encryption chip providing such encryption; and

		(g) specify the serial (ID) number of the key-escrow 
decryption device that will be used by the agency participating in 
the conduct of the interception for decryption of the intercepted 
communications.

	4) This certification shall be submitted to each of the 
designated key component escrow agents. If the certification has 
been provided by an agency authorized to participate in the 
conduct of the interception, a copy shall be provided to the 
Department of Justice, Office of Intelligence Policy and Review. 
As soon as possible, an attorney associated with that office shall 
provide each of the key component escrow agents with written 
confirmation of the certification.

	5) Upon receiving the certification, each key component 
escrow agent shall release the necessary key component to the 
agency participating in the conduct of the interception. The key 
components shall be provided in a manner that assures they cannot 
be used other than in conjunction with the lawfully authorized 
electronic surveillance for which they were requested.

	6) Each of the key component escrow agents shall retain a 
copy of the certification, as well as the subsequent written 
confirmation of the Department of Justice, Office of Intelligence 
Policy and Review.

	7) Upon, or prior to, completion of the electronic 
surveillance phase of the investigation, the ability of the agency 
participating in the conduct of the interception to decrypt 
intercepted communications shall terminate, and such agency may 
not retain the key components.

	8)   The Department of Justice shall, in each such case,

		(a) ascertain the existence of authorizations for 
electronic surveillance in cases for which escrowed key components 
have been released;

		(b) ascertain that key components for a particular key 
escrow encryption chip are being used only by an agency authorized 
to participate in the conduct of the interception of 
communications encrypted with that chip; and 

		(c) ascertain that, no later than the completion of the 
electronic surveillance phase of the investigation, the ability of 
the agency participating in the conduct of the interception to 
decrypt intercepted communications is terminated.

	9) Reports to the House Permanent Select Committee on 
Intelligence and the Senate Select Committee on Intelligence, 
pursuant to Section 108 of FISA, shall, with respect to any order 
for authorized electronic surveillance for which escrowed 
encryption components were released and used for decryption, 
specifically note that fact.

These procedures do not create, and are not intended to create, 
any substantive rights for individuals intercepted through 
electronic surveillance, and noncompliance with these procedures 
shall not provide the basis for any motion to suppress or other 
objection to the introduction of electronic surveillance evidence 
lawfully acquired.
NODE 28c8a1d8Re: doj_escrow_intercept.procedures (fwd)
Wow! That procedure, if it could be verified to be followed, is almost
good enough to satisfy my queasy feeling that some *very dificult* and
*very publicly* accessable means of opening a back door might just not
be appropriate.  Even though this goes strongly against my personal
interest I can envision situations where I would want them to have that
ability.  Imagine that it is your city that gets a terrorist nuke built
in one of its basements.  Truly secure and easy communication makes
that a whole lot easier but then since a truly secure box is real
simple to make, it sort of obviates the reasoning for trying to do the
standardization anyway.  Anybody who really wants absolute security
will be able to get it at some price that won't be too high.  :-)

I would like to propose us the challenge to come up with a way
utilizing this crypto technology and signatures and such to guarantee a
verifiable trail whenever it is done that is available to any court
of law.  The implication is clear that other forms will be outlawed
if this package is sold.  No point in even doing it otherwise.  So
in case they win this one I suggest that, as Tom Lehrer talks about
on his album Revisited, we "Be Prepared."  :-)


Peace,

Bob

-- 
Bob Cain    rcain@netcom.com   408-354-8021


           "I used to be different.  But now I'm the same."


--------------PGP 1.0 or 2.0 public key available on request.------------------
NODE 5d886b42Re: doj_escrow_intercept.procedures (fwd)
Robert Cain writes:
 > Wow! That procedure...

I'm having great difficulty extracting meaning from your prose, but I
think you're saying that you like that the government has escrowed
keys to Clipper phones for use in "national emergencies".

 > Imagine that it is your city that gets a terrorist nuke built
 > in one of its basements.

We don't have many basements in Austin.

 > Truly secure and easy communication makes
 > that a whole lot easier 

Makes *what* a whole lot easier, building the bomb or catching the
bombers?

 > but then since a truly secure box is real
 > simple to make, 

Really?

 > it sort of obviates the reasoning for trying to do the
 > standardization anyway.

Obviates the reasoning?  I'm confused.

 > Anybody who really wants absolute security
 > will be able to get it at some price that won't be too high.  :-)

So what exactly are you talking about?  Sounds like you're happy the
government introduced Clipper because it's so easy for anyone to build
secure cryptographic devices.  I'm having trouble understanding this.

 > I would like to propose us the challenge to come up with a way
 > utilizing this crypto technology and signatures and such to guarantee a
 > verifiable trail whenever it is done that is available to any court
 > of law.

Whenever *what* is done?  Whenever somebody builds a nuclear bomb?

 > The implication is clear ... I suggest that, as Tom Lehrer talks about
 > on his album Revisited, we "Be Prepared."  :-)

I think we should start with, "Be Lucid."

--
| GOOD TIME FOR MOVIE - GOING ||| Mike McNally <m5@tivoli.com>       |
| TAKE TWA TO CAIRO.          ||| Tivoli Systems, Austin, TX:        |
|     (actual fortune cookie) ||| "Like A Little Bit of Semi-Heaven" |
NODE 8cc71e84Re: doj_escrow_intercept.procedures (fwd)
Mike McNally sez:
> 
> 
> Robert Cain writes:
>  > Wow! That procedure...
> 
> I'm having great difficulty extracting meaning from your prose, but I

Hmmm, others have been having that problem lately.  :-)

> think you're saying that you like that the government has escrowed
> keys to Clipper phones for use in "national emergencies".

Yes, after long consideration that, that as I said runs counter to my
self interest, I had to come to the conclusion first that is was in
fact desirable to have a means to tap.  It should be very difficult
though and verifiable.

> 
>  > Imagine that it is your city that gets a terrorist nuke built
>  > in one of its basements.
> 
> We don't have many basements in Austin.

:-)

> 
>  > Truly secure and easy communication makes
>  > that a whole lot easier 
> 
> Makes *what* a whole lot easier, building the bomb or catching the
> bombers?

It makes it easier for any clandestine plan to be established and
carried out.  This is the greatest fear they have.  Arbitrary networks
of people with arbitrary purposes can be securely formed world wide
within the limits of the trust inherent in the people.  Can you spell
r e v o l u t i o n?  It's not me that's paranoid, it's them.  :-)

> 
>  > but then since a truly secure box is real
>  > simple to make, 
> 
> Really?

Yep.  It would take me about three months of full time effort and
would be almost a single chip.  I am not the only one by any means.

> 
>  > it sort of obviates the reasoning for trying to do the
>  > standardization anyway.
> 
> Obviates the reasoning?  I'm confused.

Well, if it is as easy as I contend to make devices that are truly
secure all the people that they would want to be able to monitor
would undoubtedly have one.

> 
>  > Anybody who really wants absolute security
>  > will be able to get it at some price that won't be too high.  :-)
> 
> So what exactly are you talking about?  Sounds like you're happy the
> government introduced Clipper because it's so easy for anyone to build
> secure cryptographic devices.  I'm having trouble understanding this.

No, I think now that Clipper is ultimately stupid.  I do think that if
it were *not* possible to easily get around it (black market probably,
remember the "blue boxes" of yore :-) and not possible probably to even
detect the illegal device's use (just use it as a front end to a
Clipper :-), then an escrow system which was benign (I realize some
think that an oxymoron) would be a good idea.

> 
>  > I would like to propose us the challenge to come up with a way
>  > utilizing this crypto technology and signatures and such to guarantee a
>  > verifiable trail whenever it is done that is available to any court
>  > of law.
> 
> Whenever *what* is done?  Whenever somebody builds a nuclear bomb?

Whenever they use whatever process they may set up to allow back
door entry.  I'm wondering if something analogous to a paper
trail could be guaranteed using our technology.  I don't know
if that is possible but have an inkling that it is.

> 
>  > The implication is clear ... I suggest that, as Tom Lehrer talks about
>  > on his album Revisited, we "Be Prepared."  :-)
> 
> I think we should start with, "Be Lucid."

Or learn to write better.  I'm workin' on it.  :-)

Peace,

Bob

-- 
Bob Cain    rcain@netcom.com   408-354-8021


           "I used to be different.  But now I'm the same."


--------------PGP 1.0 or 2.0 public key available on request.------------------
NODE 7b7646c8Re: doj_escrow_intercept.procedures (fwd)
>> Makes *what* a whole lot easier, building the bomb or catching the
>> bombers?

> It makes it easier for any clandestine plan to be established and
> carried out.  This is the greatest fear they have.  Arbitrary
> networks of people with arbitrary purposes can be securely formed
> world wide within the limits of the trust inherent in the people.
> Can you spell r e v o l u t i o n?  It's not me that's paranoid,
> it's them.  :-)

While stopping terrorists may be easier in a country with pre-taped
communications, and organizing otherwise undetected insurrection
will be a little closer to possible, this is not the main purpose
of wiretaps today or in the future.

The real targets of wiretaps (now and in the future) are political
activists.  Anyone who poses a serious threat to large corporate
profits is a target for a wire tap.  This includes organizations
like Greanpeace, the communist party, CISPES, and even libertarians
who oppose superfluous military intervention.

Sure, blowing up the world trade center costs money, but cutting
arms sales to Indonesia just because of some little genocide on an
island with only a few hundred thousand inhabitants...  That cuts
into profits; especially if it catches on.

In the past, if Dow wants to put a tap on my friend's mom's phone
(a prominent anti-pesticide activist), they can just hire a private
investigator to climb the poll and sift through the conversations.
No, they never found out who was taping the line, for some reason
they didn't think to ask the guy who came around once a week to
change the tapes on top of the pole (go figure).

In the world where Clipper is predominant, the government will have
a monopoly on this sort of activity.  Two things are clear to
follow:  First, there will be fewer PIs able to do wiretaps.  People
chasing after abducted children or forgoten alimony cheques will
be out of luck.

Second, the government will be pressured into taking on the activities
that are now done by PIs (at a substantially greater cost of course).
This will force some relaxing of the rules governing obtaining
escrowed keys.

Since anyone purchasing the key escrow devices will have implicitly
agreed to (amongst other things) wave any expectation of privacy
associated with using the device, they probably wont have to much
legal ground to stand on when they discover the their phone
conversations have been sold to Exon.


brad