Showing posts with label Encryption. Show all posts
Showing posts with label Encryption. Show all posts

Thursday, June 4, 2015

House passes CJS bill with some important amendments

There is always something going on in Congress.  The "do nothing" charge is false.  What that really means is "they're not doing what I want."

One big appropriations bill is called "CJS," H.R. 2578, Commerce, Justice, Science Appropriations Act

When looking in the news about the bill, I found articles on marijuana, NASA, and as The Hill wrote
gun control, immigration, U.S.-Cuba relations, Guantánamo Bay and marijuana
The Leadership Conference on Civil and Human Rights  opposed the bill saying
The House proposal significantly underfunds agencies, programs, and services that are critical to ensuring that the justice system works, and that the civil rights of all Americans are upheld.
Several notable amendments were passed, including










I am wondering if it is necessary to include FBI in this amendment, which prohibits NSA and CIA (but doesn't mention FBI) from weakening encryption standards with NIST (see also here).  I mentioned NIST in my post on the iPhone encryption.


Representative Joaquin Castro introduced funding for police body cameras.  I sent him my article on TASER.




Representative Gwen Moore spoke on the floor of the House yesterday about an amendment to CJS regarding the case of Dontre Hamilton and how police treat mentally ill citizens



Amendment Offered by Ms. Moore

  Ms. MOORE. Mr. Chair, I have an amendment at the desk.
  The Acting CHAIR. Is there objection to the gentlewoman        offering the amendment at this point in the reading?
  There was no objection.
  The Acting CHAIR. The Clerk will report the amendment.
  The Clerk read as follows:

       Page 34, line 19, after the dollar amount, insert 
     ``(reduced by $2,000,000)''.
       Page 42, line 24, after the dollar amount, insert 
     ``(increased by $2,000,000)''.
       Page 44, line 8, after the dollar amount, insert 
     ``(increased by $2,000,000)''.

  The Acting CHAIR. Pursuant to House Resolution 287, the gentlewoman from Wisconsin and a Member opposed each will control 5     minutes.
  The Chair recognizes the gentlewoman from Wisconsin.
  Ms. MOORE. Mr. Chair, my amendment transfers $2 million into   the Mentally Ill Offender Treatment and Crime Reduction Act for  the purpose of expanding and improving police training to safely and appropriately respond to mentally ill individuals.
  Now, Mr. Chair, we have heard a lot lately in the news about   high profile police-involved shootings that have become a major  subject here around the country and here in Congress. Not        surprising to some of us, especially those of us who hail from   large urban cities, this is a widespread problem that has been   around for a while.
  But today, I am offering this amendment to highlight one       serious issue that I think should be a major part of our current national dialogue: ensuring that police have adequate training to identify persons with mental illness and to safely, when it is  possible, resolve encounters during a crisis.
  Mr. Chair, indulge me for a moment while I tell you a story    about a 31-year-old man in my home district of Milwaukee,        Wisconsin, who, unfortunately, is no longer with us today. His   name was Dontre Hamilton.
  Dontre, like many people in this country, suffered from a      mental illness. He was diagnosed with schizophrenia 1 year prior to the incident and had been off his medication due to an        insurance issue.
  On April 30 of last year, Dontre was taking a nap on a public  park bench when employees of a nearby Starbucks called the       police. Two police officers came and did a wellness check and    left the scene, discerning that Mr. Hamilton was no threat to himself, nor to anyone in the park or the public.
  Soon thereafter, yet another call came from the Starbucks      employee because this gentleman was sleeping on the public park  bench. Another police officer, Officer Manney of the Milwaukee   Police Department, arrived and started to pat down Dontre. This  pat-down turned into a struggle, and Officer Manney pulled out   his baton to help him subdue Mr. Hamilton.
  The struggle escalated, and Dontre got control of the baton and swung it at Officer Manney. This caused Officer Manney to draw  his firearm and shoot 14 bullets into Dontre Hamilton.
  Officer Manney was terminated for conducting a pat-down in 
contravention of his training on dealing with mentally ill individuals but faced no charges in the death of Dontre Hamilton.
  Mr. Chair, perhaps this tragedy could have been prevented. Too often, our mental health infrastructure is woefully inadequate   for many Americans. A lack of treatment can turn a treatable mental illness into a severe debilitating condition. Many can't hold a job or pay rent. 
Many end up homeless on the streets. In fact, more than 124,000  of the 610,000 homeless people in the United States suffer from a severe mental illness.
  As a result of many failures in our system, our Nation's policeofficers have de facto become our country's first responders to  crisis calls, including those individuals experiencing mental    illness. Too often these calls, many intended to be out of       concern  for the individual in crisis, become a tragic fatality.
  As we know, mentally ill persons are not generally dangerous,  Mr. Chair. In fact, they are actually more likely to become      victims themselves than actual perpetrators of violence. Many of these tragic encounters could be prevented if police officers are trained and follow proper procedures.
  The Mentally Ill Offender Treatment and Crime Reduction Act is an important Federal initiative and tool that will help us bridge this gap. This law established a grant program called the       Justice and Mental Health Collaboration Program which helps      States and localities develop collaborative approaches to dealing with the intersection of criminal justice and mental health     systems.
  One of the authorized grant uses under the program is training to police officers for exactly these purposes: to safely respond to crisis calls and limit the chance of a tragic and often preventable consequence.
  I yield back the balance of my time.
  Mr. CULBERSON. Mr. Chairman, I claim the time in opposition,   but I am not opposed to the amendment.
  The Acting CHAIR (Mr. Woodall). Without objection, the         gentleman from Texas is recognized for 5 minutes.
  There was no objection.
  Mr. CULBERSON. The gentlewoman has a good amendment, and I want to encourage Members to support it.
  I yield back the balance of my time.
  The Acting CHAIR. The question is on the amendment offered by  the gentlewoman from Wisconsin (Ms. Moore).
  The amendment was agreed to.

good news from Congress

Congressional Record June 2, 2015, House of Representatives

PDF Page 81, Page H3725

AMENDMENT OFFERED BY MR. POE OF TEXAS

Mr. POE of Texas. I have an amendment at the desk regarding the Fourth Amendment to the Constitution, with multiple cosponsors.

The Acting CHAIR.

The Clerk will report the amendment.

The Clerk read as follows:
At the end of the bill (before the short title), insert the following: SEC. ll. (a) Except as provided by subsection (b), none of the funds made available by this Act for the Department of Justice or the Federal Bureau of Investigation may be used to mandate or request that a person (as defined in section 101(m) of the Foreign Intelligence Surveillance Act of 1978 (50 U.S.C. 1801(m)) alter the product or service of the person to permit the electronic surveillance (as defined in section 101(f) of such Act (50 U.S.C. 1801(f)) of any user of such product or service. (b) Subsection (a) shall not apply with respect to mandates or requests authorized under the Communications Assistance for Law Enforcement Act (47 U.S.C. 1001 et seq.).
Mr. POE of Texas (during the reading). Mr. Chair, I ask unanimous consent to dispense with the reading of the amendment.

The Acting CHAIR.

Is there objection to the request of the gentleman from Texas? There was no objection.

The Acting CHAIR. Pursuant to House Resolution 287, the gentleman from Texas and a Member opposed each will control 5 minutes. The Chair recognizes the gentleman from Texas. Mr. POE of Texas.

Mr. Chairman, I have a simple, straightforward amendment to protect the Fourth Amendment of the U.S. Constitution. This is a very similar amendment that passed DOD Appropriations last year. I would like to thank Representatives LOFGREN, MASSIE, CONYERS, AMASH, NADLER, FARENTHOLD, POLIS, LABRADOR, and LIEU for working with me as cosponsors on this important amendment. James Comey, the Director of the Federal Bureau of Investigation, recently asked Congress to update the law to ensure that the Federal Government can access information from Americans’ cell phones and personal electronic devices in the future. Many U.S. technology companies have also been approached by the government agencies, urging them either through intimidation or just request to create back doors on their products’ encryption system so the government can access it later down the road. We have all learned recently about the government’s abuse of section 215 under the PATRIOT Act and abuse under section 702 of the FISA Amendments Act. Basically what this amendment does, Mr. Chairman, is prohibit the government from going to Apple, for example, and telling Apple that they want an encryption in cell phones that they sell to Americans, an encryption that would allow the FBI to have access to this information, which would include not just conversations, not just include emails, but it would also include text messaging as well. This is a straightforward amendment. This prohibits the Federal Government—specifically, the FBI—from going in and receiving this information. Privacy is important. It is under our Constitution. There should be no doubt that the Federal Government should have no access to our cell phones and the information that is in those cell phones. That is what this amendment does. I reserve the balance of my time.

Mr. CULBERSON. I ask unanimous consent to claim the time in opposition, but I do not oppose the gentleman’s amendment. I agree with his amendment and encourage the House to support it.

Ms. LOFGREN. Mr. Chairman, reserving the right to object.

The Acting CHAIR. The gentlewoman from California is recognized on her reservation. Ms. LOFGREN.

Mr. Chairman, I had also sought to seek the time in opposition, although I also do not oppose the amendment.

Mr. CULBERSON. Does the gentlewoman support the amendment? Ms. LOFGREN. I support the amendment, as does the gentleman.

Mr. CULBERSON. That was my point. I think it is important. We are here in this Chamber looking at George Mason, who refused to sign the Constitution because he was so concerned that the power of the Federal Government would just absolutely obliterate——

The Acting CHAIR. The gentleman will suspend. Does the gentlewoman withdraw her reservation?

Ms. LOFGREN. Mr. Chairman, further reserving, I was wondering if the Democratic side of the aisle might be able to split the time. That is why I was reserving the right to object.

Mr. CULBERSON. Mr. Chairman, I would be happy to split the time with the gentlewoman. I am claiming the time in opposition, although I do not oppose it. The gentleman still has some time remaining on his initial time. I will yield in just a moment, but I really think it is important in this age of electronic communication that we in the Congress debate and be keenly aware of the new boundaries.

The Acting CHAIR. The gentleman will suspend.

Ms. LOFGREN. I withdraw my reservation.

The Acting CHAIR. The reservation is withdrawn. Without objection, the gentleman from Texas (Mr. CULBERSON) is recognized for 5 minutes. There was no objection.

Mr. CULBERSON. Mr. Chairman, my neighbor and good friend, Judge TED POE, brings a very important point to the floor tonight. In this new era of expanding technology that now intrudes on every aspect of our lives, it is very important to remember the admonition that Benjamin Franklin gave us—that those who would surrender a little freedom to gain a little safety are soon going to find themselves with neither. I do find it instructive that we are here on this House floor looking at George Mason, who is on the right here, who refused to sign the Constitution because he was so concerned the Federal Government would become omnipotent and obliterate the rights of individuals and the rights of the States to control those issues that deal exclusively with the States. My favorite Founding Father, Thomas Jefferson, was keenly aware of and concerned about the power of the Federal Government. We are entering into a whole new era now where the government has got the ability to intrude on every aspect of our life. I share Judge POE’s concern. I support his amendment, and I urge the House to support it. If the FBI has a court order, if the National Security Agency gets a court order, I believe they could get access to what they need to get access to. Just like cracking a safe. In fact, I asked this question, if I could, of Director Comey in front of our subcommittee. He said these new iPhones—I dropped my iPhone 5 and had to get a 6—he said these can’t be cracked. So, therefore, you would have to open them up like you would a safe, as you had to order safes, I bet, opened on occasion, Judge POE. So I agree with the amendment, and I yield the balance of my time to the gentlewoman from California (Ms. LOFGREN).

Ms. LOFGREN. I thank the gentleman for yielding. As Mr. POE recognized, this is a very diverse group of authors who don’t agree on everything, but this is very important for a reason. First, it is fundamental that our privacy be protected; that the Fourth Amendment be adhered to. Secondly, we all know—and if you ask any computer scientist, they will tell you—that once the vulnerability is introduced for a good reason, it is available for hacking for very bad reasons. Finally, for competitiveness. Think how competitive it is to sell an American product around the world when everyone knows that it is compromised. Not a really good marketing tool. Last year, as Mr. POE mentioned, we had almost precisely this amendment on the floor as an amendment to the DOD appropriations. What was the vote on that amendment? It was 293–123; overwhelming. So I am hoping that Members will not flip-flop, that they will, in fact, vote the way they did last year. And I will just go a little trip down memory road. When I was first elected to the Congress, I took my oath of office January 4, 1995, and I met BOB GOODLATTE for the very first time. And he and I went all over this Congress to try and work on decontrol of encryption. Although a lot of people we talked to in 1995 had no idea what we were talking about when we talked about encryption, ultimately that bipartisan effort was successful. We must not let that successful effort to protect privacy, to protect technology, be eroded at this point. So I look forward to a very strong vote on this. I think it is important that we have a vote, even though there is agreement, just to send the message to the other body how serious that we are.

Mr. CULBERSON. Our most important right as Americans is to be left alone. If you are a law-abiding American, you are secure in your home and your possessions. Your home is your castle.

Ms. LOFGREN. Will the gentleman yield? Mr. CULBERSON. I yield to the gentlewoman from California.

Ms. LOFGREN. We might not agree on everything, but I think we agree on the Fourth Amendment. So this is a great day for this body to come together across the aisle for that purpose. And I thank the gentleman for yielding Mr. CULBERSON. I reserve the balance of my time.

Mr. FATTAH. Will the gentleman yield? Mr. POE of Texas. I yield to the gentleman from Pennsylvania.

Mr. FATTAH. I just wanted to indicate that on behalf of the minority, we support your amendment and are prepared to agree to it. Mr. POE of Texas. I yield 1 minute to the gentleman from Kentucky (Mr. MASSIE).

Mr. MASSIE. Thank you, Judge POE, for introducing this amendment. This was substantially the same amendment that we offered last summer that passed with a veto-proof majority 293– 123. Back doors are bad for three reasons. When the government forces companies to put back doors or weaken their encryption, it is bad for security because hackers are going to find these back doors and other foreign countries will find these back doors. It is bad for privacy because the Fourth Amendment can be violated. And it is bad for business. As my colleague ZOE LOFGREN from California mentioned, it is bad for business because it makes us less competitive overseas. Who wants to buy a piece of defective software that was made defective by our government? So I urge Members to vote for this amendment because it would prevent all of these bad things from occurring.

Mr. POE of Texas. Mr. Chairman, how much time do I have remaining?

The Acting CHAIR. The gentleman from Texas has 2 minutes remaining.

Mr. POE of Texas. In conclusion, I want to thank the minority, Ms. LOFGREN, and all the cosponsors on this, as well as the chairman of the subcommittee, for their support. On the issue of privacy, in this time where we have threats to this country, we can have security and we can certainly have privacy, and we can have the Constitution be followed as well. The Fourth Amendment has always required that if the government wants to search, the government must follow certain rules. And those rules are that you must get a warrant from a judge based on probable cause. That is still the law of the land, even in 2015. All this amendment does is ensure the fact that the government—the FBI—follows the Constitution. The idea that the Federal Government wants to have encryption in American cell phones so they can have access to the information is repulsive. So all this does is keep the Federal Government out of our business without appropriate constitutional protections. I ask for support of this amendment, and I yield back the balance of my time.

Mr. CULBERSON. Mr. Chairman, I just want to reaffirm that, as Judge POE has written this amendment, there is an exception in here that if the government gets a court order, they can go in and put a back door on the phone when the judge says there is a compelling reason to do so. I yield to the gentleman. Mr. POE of Texas. Certainly. The law—the Constitution—still applies that the government must go and get a warrant based upon probable cause under the Fourth Amendment. Of course, there are exceptions to warrantless search.

Mr. CULBERSON. Reclaiming my time, the way the amendment is written, the government can’t just force all phone companies to build a back door into all telephones. You have got to have a court order on that specific phone, on that specific person, before you can do it. That is absolutely reasonable. That is what Mr. Madison and Mr. Jefferson intended for us to do.

Therefore, I support the gentleman’s amendment, and I yield back the balance of my time.

The Acting CHAIR. The question is on the amendment offered by the gentleman from Texas (Mr. POE). The amendment was agreed to.

AMENDMENT OFFERED BY MR. POLIS

Mr. POLIS. Mr. Chairman, I have an amendment at the desk.

The Acting CHAIR. The Clerk will report the amendment.

The Clerk read as follows:
At the end of the bill (before the short title), insert the following: SEC. ll. None of the funds made available by this Act may be used to execute a subpoena of tangible things pursuant to section 506 of the Controlled Substances Act (21 U.S.C. 876) that does not include the following sentence: ‘‘This subpoena limits the collection of any tangible things (including phone numbers dialed, telephone numbers of incoming calls, and the duration of calls) to those tangible things identified by a term that specifically identifies an individual, account, address, or personal device, and that limits, to the greatest extent reasonably practicable, the scope of the tangible things sought.’’.
The Acting CHAIR. Pursuant to House Resolution 287, the gentleman from Colorado and a Member opposed each will control 5 minutes. The Chair recognizes the gentleman from Colorado. Mr. POLIS.

Mr. Chairman, here in Congress we have just been spending a lot of time and energy discussing NSA surveillance. The American public— and now, Members of Congress in both Chambers—have spoken clearly that the kind of bulk data collection the NSA has engaged in needs to be stopped. However, there is a corresponding change that we need to make with regard to the Drug Enforcement Administration. In a series of revelations from 2013 to 2015, it came to light that the DEA had for more than 20 years been gathering a vast database of information on America’s personal communications. There was no congressional authority for this program and no oversight by Congress or any area of the Federal Government. Legal experts who weighed in after the program was finally made public have said without hesitation that the program was illegal. In 2013, the Department of Justice brought this program to an end, but there is nothing to stop the government or the DOJ from resuming it at will unless Congress acts by inserting this language in the appropriations bill. Without this language, the DEA could once again unilaterally sweep up the communications records of millions of Americans. There is no reason that, as we work to end the unconstitutional surveillance that the NSA has engaged in, we should continue to allow the DOJ to have the very same abuses. This is a corresponding piece of legislation to something that already passed the House with regard to the NSA by an overwhelming majority. I urge my colleagues to support our bipartisan amendment that we worked on with Mr. GRIFFITH, Mr. SCHWEIKERT, Mr. NADLER, and Mr. FARENTHOLD to simply prohibit DOJ from using Federal funds to engage in bulk data collection of Americans’ phone records or other data, and I reserve the balance of my time.

Mr. CULBERSON. Mr. Chairman, I claim time in opposition.

The Acting CHAIR. The gentleman from Texas is recognized for 5 minutes.

Mr. CULBERSON. Just being given Mr. POLIS’ amendment, I oppose the idea of bulk data collection. I would like to accept the gentleman’s amendment because of my previous expressed concerns about how we want to make sure we are protecting the privacy of law-abiding Americans. So I would accept the gentleman’s amendment with the understanding that I would work with him. There may be unintended consequences here that I am not immediately aware of. Judiciary Committee staff is working with ours right now to make sure we have got our arms around this. I want to make sure that if the DEA has a valid court order, a valid subpoena, that they can go after lawbreakers and complete their investigations. Again, we want to protect the privacy of law-abiding Americans.

Mr. FATTAH. Will the gentleman yield?

Mr. CULBERSON. I yield to the gentleman from Pennsylvania.

Mr. FATTAH. I think with the understanding that the chairman has laid out, your accepting this amendment would move us forward, and I agree. I think we have a clear understanding that you are accepting it, but we will work together to make sure it doesn’t have any unintended consequences.

Mr. CULBERSON. Reclaiming my time, with that understanding, I want to make sure we reserve the right of DEA to get a court order to do their work. With that understanding, I withdraw my opposition and will accept the amendment. I yield back the balance of my time.

Mr. POLIS. I yield 1 minute to the gentleman from New York (Mr. NADLER), the coauthor of the amendment.

Mr. NADLER. I thank the gentleman for yielding. I rise in strong support of this amendment to prevent bulk collection of data at the Department of Justice. Last month, this House spoke loud and clear that we oppose the National Security Agency’s bulk collection of telephone metadata. Today, the Senate joined us in that judgment, and, together, we have reaffirmed our commitment to the Fourth Amendment and to protecting Americans from unconstitutional government surveillance. We learned earlier this year that long before the NSA program ban, the Drug Enforcement Administration engaged in its own bulk collection program that provided a model for the NSA to use nearly a decade later. This program included logs of virtually all telephone calls from the U.S. to as many as 116 countries, ostensibly linked to drug trafficking, all without a court order and without authorization from Congress. Mr. Chairman, enough is enough. Although the DOJ has since shut down this program, there is nothing preventing the Department from renewing it in secret without authorization, as it did before. This amendment would ensure that it remains dormant and that Americans’ privacy remains secure. I thank Mr. POLIS and the other cosponsors of the amendment, and I thank the gentleman from Texas for accepting this amendment. I urge my colleagues to support this amendment.

Mr. POLIS. Mr. Chairman, I yield 1 minute to the gentleman from Texas (Mr. FARENTHOLD).

Mr. FARENTHOLD. Mr. Chairman, I rise in support of this amendment and thank my colleague from Texas for agreeing to accept it. This has been a great victory this week in our ability to work with the Senate to rein in what I believe to be the unconstitutional bulk data collection by the NSA. Just because we stopped the NSA doesn’t mean we shouldn’t be ever vigilant. With the reports of the DEA engaging in similar activities, it is absolutely appropriate that we use the power of the purse to ensure that this type of spying on American citizens— this bulk data collection—is stopped. This is no different from the general warrants that were complained about when the King of England would send troops to rifle through people’s desks just looking for stuff. It is the exact same thing in the digital age. I encourage my colleagues to support it and look forward to working with my colleague, Mr. CULBERSON, in making sure it does become part of this bill.

Mr. POLIS. In conclusion, I want to thank the gentleman from Texas (Mr. CULBERSON). It is, indeed, the intended language and we believe the actual language of the amendment that would not interfere with any valid court orders or warrants. We are happy to work with them in that regard. The amendment is designed to pertain to bulk collection of data, which was never specifically authorized by Congress. I appreciate the gentleman from Texas accepting the amendment, and I yield back the balance of my time.

The Acting CHAIR. The question is on the amendment offered by the gentleman from Colorado (Mr. POLIS).

The amendment was agreed to. 

Friday, January 23, 2015

In 2015, Fix Your Passwords

With all the news recently about hacks, ISIS hacking CentCom's Twitter and YouTube accounts, SONY, Target, and on and on, and related stories about NSA dragnet surveillance, there is one central connection: bad passwords.

SplashData, an Internet security services firm, has released its annual list of the 25 worst Internet passwords.

Most "hacks" are not really hacks, but people guessing lousy passwords.
Guessing voicemail passwords? Not really a hack.
That college student made an educated guess at Palin's password. Sorry, not a hack!
There was also this important story about the importance of password privacy.
New Illinois Law Forces Students to Give Up Social Media Passwords….Or Face Criminal Charges
So I wrote
which is what Security in a Box also recognizes (emphasis mine)
Note: By using KeePass all the time, you never actually have to see or know what your password is. The copy/paste functions take care of moving it from the database to the required window. If you use the Random Generator feature and then transfer this password to a new email account registration process, you will be using a password that you have never seen in plain view. And it still works!
Because the key to many encryption features is a strong password, password managers are really important.  Security in a Box has a great guide to KeePass, which I use.





It's very simple to use.  You have one master password, which you can write down and keep at home, or memorize that one password which stores you other dozen passwords.

You add entries based on account type (you can mix and match anything, that doesn't really matter). I originally thought that KeePass logs you in automatically, but that is not how it works, you essentially just copy and paste the password into your login screen.

The beauty of KeePass is not having to remember secure passwords.



Thursday, October 2, 2014

About the iPhone Encryption

There have been lots of news stories about the iPhone 6 encryption, and lots of headlines claiming that it "locks out the NSA." It doesn't.

First, the bad journalism.

Signaling Post-Snowden Era, New iPhone Locks Out N.S.A.
Devoted customers of Apple products these days worry about whether the new iPhone 6 will bend in their jean pockets. The National Security Agency and the nation’s law enforcement agencies have a different concern: that the smartphone is the first of a post-Snowden generation of equipment that will disrupt their investigative abilities.
The phone encrypts emails, photos and contacts based on a complex mathematical algorithm that uses a code created by, and unique to, the phone’s user — and that Apple says it will not possess.
The result, the company is essentially saying, is that if Apple is sent a court order demanding that the contents of an iPhone 6 be provided to intelligence agencies or law enforcement, it will turn over gibberish, along with a note saying that to decode the phone’s emails, contacts and photos, investigators will have to break the code or get the code from the phone’s owner.
of course this is how the article ends instead of begins
Mr. Zdziarski said that concerns about Apple’s new encryption to hinder law enforcement seemed overblown. He said there were still plenty of ways for the police to get customer data for investigations. In the example of a kidnapping victim, the police can still request information on call records and geolocation information from phone carriers like AT&T and Verizon Wireless.
“Eliminating the iPhone as one source I don’t think is going to wreck a lot of cases,” he said. “There is such a mountain of other evidence from call logs, email logs, iCloud, Gmail logs. They’re tapping the whole Internet.”

Now some explanation.

The iPhone will automatically encrypt data stored on the device.
On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode.
Now Apple has said that they cannot decrypt data, even when asked by law enforcement or a court, but is not the end of the story.  Depending on the case the courts can force you to unlock it yourself. (See for example this court order)
In many cases, the American judicial system doesn’t view an encrypted phone as an insurmountable privacy protection for those accused of a crime. Instead, it’s seen as an obstruction of the evidence-gathering process, and a stubborn defendant or witness can be held in contempt of court and jailed for failing to unlock a phone to provide that evidence.
continued
In some cases, the Fifth Amendment’s protection against self-incrimination may block such demands
continued
but the few cases where suspects have pleaded the Fifth to avoid decrypting a PC—the legal equivalent of a smartphone—have had messy, sometimes contradictory outcomes.
 In some cases you can plead the Fifth 
The court ruled that forcing him to surrender his password and decryption keys would be the same as making him provide self-incriminating testimony, and let him off the hook.
But in other cases 
He refused, pleading the Fifth. A judge ruled against him, calling the contents of the computer a “foregone conclusion.” The police didn’t need Boucher’s “testimony” to get the files, in other words—they only needed him to stop obstructing access to them. 
In some situations other evidence can be considered
enough to nullify her Fifth amendment argument. As with Boucher, the judge ruled that she give police access to the files or be held in contempt.
NIST Encryption Standards

A really important, overlooked part seems to be NIST's weakened encryption standards. (Many thanks to Rayne)

**Update (November 21, 2014 EFF Joins calls for NIST reform


A reality check on encryption standards based on NIST
Let’s reset all the hype:
There is no smartphone security available on the market we can trust absolutely to keep out the National Security Agency. No password or biometric security can assure the encryption contained in today’s smartphones as long as they are built on current National Institute of Standards and Technology (NIST) standards and/or the Trusted Computing Platform. The NSA has compromised these standards and TCP in several ways, weakening their effectiveness and ultimately allowing a backdoor through them for NSA use, bypassing any superficial security system.
There is nothing keeping the NSA from sharing whatever information they are gleaning from smartphones with other government agencies. Citizens may believe that information gleaned by the NSA ostensibly for counterterrorism may not be legally shared with other government agencies, but legality/illegality of such sharing does not mean it hasn’t and isn’t done. (Remember fusion centers, where government agencies were supposed to be able to share antiterrorism information? Perhaps these are merely window dressing on much broader sharing.)
There is no exception across the best known mobile operating systems to the vulnerability of smartphones to NSA’s domestic spying.
More on NIST from Rayne

On NSA’s Subversion of NIST’s Algorithm

Our security is only as good as the tools we use to protect it, and compromising a widely used cryptography algorithm makes many Internet communications insecure.
continued
Improving the security of cryptographic standards is an issue where the equities overwhelmingly lie on one side of the equation. By increasing the funding for—and thus capabilities in—NIST’s Computer Security Division, Congress can help restore confidence in NIST’s cryptographic standards efforts. This is a win for all.

The NSA, NIST and the AMS

Among the many disturbing aspects of the behavior of the NSA revealed by the Snowden documents, the most controversial one directly relevant to mathematicians was the story of the NSA’s involvement in a flawed NIST cryptography standard.
continued
this is a clearly identifiable case where mathematicians seem to have been involved in using their expertise to subvert the group tasked with producing high quality cryptography.
Matt Green on NIST
In this post I'm going to try to explain the curious story of Dual-EC. While I'll do my best to keep this discussion at a high and non-mathematical level, be forewarned that I'm probably going to fail at least at a couple of points. I you're not the mood for all that, here's a short summary:
  • In 2005-2006 NIST and NSA released a pseudorandom number generator based on elliptic curve cryptography. They released this standard -- with very little explanation -- both in the US and abroad
  • This RNG has some serious issues with just being a good RNG. The presence of such obvious bugs was mysterious to cryptographers.
  • In 2007 a pair of Microsoft researchers pointed out that these vulnerabilities combined to produce a perfect storm, which -- together with some knowledge that only NIST/NSA might have -- opened a perfect backdoor into the random number generator itself.
  • This backdoor may allow the NSA to break nearly any cryptographic system that uses it. 

While encrypting data stored on the device is great, this is different from encrypting data like phone calls and internet activity.  Thankfully a new app called Signal from hacker security researcher Moxie Marlinspike is now available for iPhone (it's been on Android for four years already).
If you’re making a phone call with your iPhone, you used to have two options: Accept the notion that any wiretapper, hacker or spook can listen in on your conversations, or pay for pricey voice encryption software.
continued
Like any new and relatively untested crypto app, users shouldn’t entirely trust Signal’s security until other researchers have had a chance to examine it. Marlinspike admits “there are always unknowns,” such as vulnerabilities in the software of the iPhone that could allow snooping. But in terms of preventing an eavesdropper on the phone’s network from intercepting calls, Signal’s security protections are “probably pretty great,” he says.
After all, the technology behind Signal isn’t exactly new. Marlinspike first took on the problem of smartphone voice encryption four years ago with Redphone, an Android app designed to foil all wiretaps.
Another interesting question I have is what if any effect June's Supreme Court decision in Riley v California will have on iPhone, but I assume for now that the answer is the same--5th Amendment depends on the situation.  I will try to get some more answers.  For now see below.

NYT Major Ruling Shields Privacy of CellphonesSupreme Court Says Phones Can’t Be Searched Without a Warrant
“Cellphones have become important tools in facilitating coordination and communication among members of criminal enterprises, and can provide valuable incriminating information about dangerous criminals,” he wrote. “Privacy comes at a cost.”
But other technologies, he said, can make it easier for the police to obtain warrants. Using email and iPads, the chief justice wrote, officers can sometimes have a warrant in hand in 15 minutes.
continued
What must the police do when they want to search a cellphone in connection with an arrest?
“Get a warrant,” Chief Justice Roberts wrote. 
Marcy Wheeler explains that
In real life, it’s likely that cops will integrate cellphone search warrants into their arrest warrant process. And Roberts’ opinion allows police to invoke exigent circumstances to search a phone. But at a minimum, this ruling will prohibit suspicion-less searches of cellphones.
continued
A different part of Sotomayor’s concurrence, arguing that the existing precedent holding that you don’t have a privacy interest in data you’ve given to a third party “is ill suited to the digital age,” has been invoked repeatedly in privacy debates since she wrote it. That’s especially true since the beginning of Edward Snowden’s leaks. Lawsuits against the phone dragnet often cite that passage, arguing that the phone dragnet is precisely the kind of intrusion that far exceeds the intent of old precedent. And the courts have – with the exception of one decision finding the phone dragnet unconstitutional – ruled that until a majority on the Supreme Court endorses this notion, the old precedents hold.
continued
Roberts cited from a different part of Sotomayor’s opinion, discussing how much GPS data on our movements reveals about our personal lives. That appears amid a discussion in which he cites things that make cellphones different: the multiple functions they serve, the different kinds of data we store in the same place, our Web search terms, location and apps that might betray political affiliation, health data or religion. That is, in an opinion joined by all his colleagues, the chief justice repeats Sotomayor’s argument that the sheer volume of this information makes it different.
That by no means says that those challenging the government’s national security surveillance will prevail by pointing to this opinion. Roberts includes an incredibly pregnant footnote, clarifying that “these cases do not implicate the question whether the collection or inspection of aggregated digital information amounts to a search under other circumstances.” Without naming the third-party doctrine explicitly, with his invocation of “search” Roberts makes it clear that’s what he’s discussing.
Here Marcy says Roberts kept it vague on purpose.

So for now, these cases about data on a smartphone or GPS collection are not being used to end NSA collection, which is still being reauthorized every 90 days.

The bill currently getting all the attention to reform the NSA is Senator Leahy's USA Freedom Act, but as Marcy has well documented, the proposed reforms are actually making some problems worse.
The ACLU and EFF normally do great work defending the Fourth Amendment. Both have fought the government’s expansive spying for years. Both have fought hard to require the government obtain a warrant before accessing your computer, cell phone, and location data.
continued
by outsourcing to telecoms, NSA will actually increase the total percentage of Americans’ telephone records that get chained on; sources say it will be more “comprehensive” than the current dragnet and Deputy NSA Director Richard Ledgett agrees the “the actual universe of potential calls that could be queried against is [potentially] dramatically larger.” In addition, the telecoms are unlikely to be able to remove all the noisy numbers like pizza joints — as NSA currently claims to – meaning more people with completely accidental phone ties to suspects will get sucked in. And USA Freedom adopts a standard for data retention — foreign intelligence purpose — that has proven meaningless in the past
But earlier this week, they may have taken action that directly undermines that good work.

So data on the iPhone is now automatically encrypted, but that won't stop police from issuing warrants or courts forcing you to unlock the data yourself.  Phone calls can now be encrypted for free using the Signal app.  All of these are great improvements, but it is still not the end of the story.

Many security experts have focused on iCloud storage.  Micah Lee writes at The Intercept that
despite these nods to privacy-conscious consumers, Apple still strongly encourages all its users to sign up for and use iCloud, the internet syncing and storage service where Apple has the capability to unlock key data like backups, documents, contacts, and calendar information in response to a government demand. iCloud is also used to sync photos, as a slew of celebrities learned in recent weeks when hackers reaped nude photos from the Apple service. (Celebrity iCloud accounts were compromised when hackers answered security questions correctly or tricked victims into giving up their credentials via “phishing” links, Cook has said.)
 continued
The most prominent privacy improvement Apple made to its products last week is a new encryption feature built-in to iOS 8.
Since the iPhone 3GS, all iOS devices have supported encrypting personal data such as text messages, photos, emails, contacts, and call history. If you set a passcode it would be used to encrypt some, but not all, of the data on your device. Apple was still able to decrypt some of the data without knowing your passcode.
If law enforcement confiscated your phone and wanted to snoop at its data, all they would have to do is serve Apple a warrant and to get a copy of the plaintext data.
continued
The improved encryption in iOS 8 is a great move towards protecting consumer privacy and security. But users should be aware that in most cases it doesn’t protect your iOS device from government snoops.
While Apple does not have the crypto keys that can unlock the data on iOS 8 devices, they do have access to your iCloud backup data.
this is not the first time 
This isn’t the first time that Apple has oversold the security of its products. Shortly after the PRISM revelations were published in The Washington Postand The Guardian, Apple denied that it was part of the program and issued a statement claiming that “conversations which take place over iMessage and FaceTime are protected by end-to-end encryption so no one but the sender and receiver can see or read them. Apple cannot decrypt that data.” But security researchers showed that Apple could indeed eavesdrop on iMessage conversations without the user knowing.
ArsTechnica notes that
Apple executives never mentioned the words "iCloud security" during the unveiling of the iPhone 6
continued
In the name of security, we did a little testing using family members as guinea pigs. To demonstrate just how much private information on an iPhone can be currently pulled from iCloud and other sources, we enlisted the help of a pair of software tools from Elcomsoft. These tools are essentially professional-level, forensic software used by law enforcement and other organizations to collect data. But to show that an attacker wouldn’t necessarily need that to gain access to phone data, we also used a pair of simpler “hacks,” attacking a family member’s account (again, with permission) by using only an iPhone and iTunes running on a Windows machine.
As things stand right now, a determined attacker will still find plenty of ways to get to iPhone data. They need to gain physical access to the device, or harvest or crack credentials to do so. But there are ways to do this that won't alert the victim. The weakest links are components of the iCloud service.
passwords are essential but not impossible
We also went after a password-encrypted version of the backup on a local drive using EPPB’s dictionary and brute-force password attacks, cracking the seven-letter password after about two days
continued
since the iCloud backup is only protected by the iCloud password right now, once someone has obtained that password, everything in that backup is wide open.
And there’s a lot in that backup.
There are a number of things some people might be surprised to find in the iCloud backups. Among the data found were:
  • SQLite databases containing phone call history, SMS and iMessage messages, and voicemail message data (with the number they were from and timestamps for when they were trashed) dating back to the phone's original purchase. So much for deleting call history.
  • A file called “recents” that contained e-mail, Messenger, and SMS addresses with message header data and other information.
  • An “accounts” database with all the e-mail, Twitter, and Apple-associated identity accounts we've ever held. Some details synced over from accounts closed before the target phone was purchased.
  • A file with all “known” Wi-Fi hotspots, with the SSIDs and MAC addresses of every hotspot the phone ever connected to.
  • Images, many believed to be long deleted, in three separate photo folders on each backup. All of the images carried the default EXIF data that Apple’s camera app attaches to them: dates taken, GPS latitude, longitude, and altitude. These images, in our oldest iCloud backup, were part of a much older incremental backup that had not been cleared from the cloud, and were found in a duplicate image folder within the DCIM folder of the backup image.
  • A file containing Apple Maps addresses searched for.
  • Mailbox files for the e-mail accounts used with Apple’s Mail app.
  • An address book database with over 1,000 e-mail addresses, phone numbers, Facebook profile links, and other contact data.
That is just what we found sifting around for a few hours aimlessly. It’s clear that anyone targeted by an iCloud account hack hasn’t just had pictures exposed; their entire digital lives have been laid out on display.
and real-time tracking via "Find my iPhone"
Even creepier, the iCloud access also gives the attacker the ability to stalk the victim in real-time by using the Find My iPhone feature. If the phone is turned on and Find My iPhone was configured, the attacker can use the feature just as the owner would (of course, odds are that it’s on the owner’s person). We were able to identify the location of family members in this way as soon as the target phone was turned on. None of this is particularly high-tech. And it’s well within the threshold of pain for a mildly technically literate, very obsessed attacker.
continued
Apple could go a long way toward protecting customer privacy just by adding a second credential to encrypt stored iCloud data. An encryption password could be used to decrypt the backup when downloaded to iTunes or to the device, or it could be used to decrypt the data as it is read by iCloud to stream down to the device. That would at least give backups the same level of protection that they get when stored locally with encryption (already an option in iTunes).
this still won't stop NSA or police
These measures will not mean that the police, the FBI, or the NSA couldn’t get to your iPhone data if they had a need to. The fixes won't stop a determined attacker from finding other ways to compromise a user’s devices to gain access to information. But these tweaks raise the level of effort required enough to deter casual attacks, and they will hopefully raise people’s awareness to attacks in progress early enough to react.
Mashable has a good selection of security researches showing how police can still get your data, then there is a list of reasons not to trust Apple,

For the NSA, Four-hundred-thousand apps means 400,000 possibilities for attacks.  Apps can be used to spy on what users do elsewhere on the phone.  The NSA can replay phone calls, and is as I noted earlier still collecting phone metadata every 90 days.
all call detail records or "telephony metadata" created by Verizon for communications (i) between the United States and abroad; or (ii) wholly within the United States, including local telephone calls. This Order does not require Verizon to produce telephony metadata for communications wholly originating and terminating in foreign countries. Telephony metadata includes comprehensive communications routing information, including but not limited to session identifying information (e.g., originating and
terminating telephone number, International Mobile Subscriber Identity (IMSI) number, International Mobile station Equipment Identity (IMEI) number, etc.), trunk identifier, telephone calling card numbers, and time and duration of call.