Encryption before the key is John Kiriakou’s formulation of where communications security actually breaks down.
The question
He was asked to weigh two positions: John McAfee’s claim that there is no such thing as computer privacy or encryption and that everything which works has been compromised, against Edward Snowden’s position that properly implemented encryption works.[1]
His answer
Kiriakou disclaims expertise and cites his sources instead: “I’m not a computer expert, but I’ve been in touch with Ed Snowden and Bill Binney and Tom Drake and Kirk Wiebe — guys who are computer experts — and they tell me that if the encryption is sophisticated enough, if the key is sophisticated enough, that it can work.”[1]
The qualification is the substance of it. “The danger, though, is that it’s intercepted before you encrypt it. So if NSA for example is spying on you, or the FBI or CIA are spying on you, and they’re able to target your computer as you’re typing your message before you hit the encryption key — then they’ve got you.”[2]
His summary of the practical position: it is “far less safe and far less reliable than most people realize.”[2]
The same three NSA whistleblowers are the source of the settled conclusion he draws from it: that no matter how hard anyone tries, the government can probably still get to their communications, and the object is therefore to make it as hard for them as possible.[3]
What he does anyway
None of that stops him encrypting. He says he assumes he is under scrutiny — he was a surveillance instructor at the CIA and says he has documented being followed several times since coming home — and that encrypted communications are now “pretty much the only way I talk to people.”[4][5]
The reason he gives is not concealment but jurisdiction: “not because I necessarily have anything to hide, but just because it’s nobody’s damn business what I say in my communications.”[4] Stated in constitutional terms: the government has no right to intercept his communications without a warrant, and without one it has no right to know what is in his emails, his text messages or his telephone calls.[6][7]
Asked what an ordinary person can do, he answers by emptying his own phone. He uses several encrypted applications: WhatsApp, and Signal — “I like Signal a lot, although it’s still breakable… it’ll at least slow them down” — plus an encrypted telephone app called RedPhone that he says costs about a dollar, noting that calls made inside Signal are also encrypted and issue a key. For email he uses a ProtonMail account, which he describes as double encrypted and, more importantly, hosted on a server in Switzerland and therefore not subject to US subpoenas.[8][9][6][3]
His summary of the value of all of it is consistent with the caveat above: “if they really want to get you, they’re going to get you, but at least this way you might slow them down a little bit.”[9]
Against the case for banning it
Kiriakou rejects the argument, which he attributes to FBI director James Comey, that encrypted applications are what terrorists use to communicate. “First of all, that is just simply not true.”[7]
His first counter-example is Paris. The attackers communicated over online gaming systems, which were not encrypted — they were “out there in the ether for anybody to intercept” — and the NSA, CIA and FBI did not intercept them. “I call that an intelligence failure, not a problem with encryption.”[10]
His second is San Bernardino, where encryption was also blamed. Decent police work, he says, would have disrupted the attack: the FBI knew Syed Farook was in contact with a known terrorist overseas and did nothing about it — never questioned him, never detained him, never sought a warrant for his home or his electronics. “So it’s not that encryption is preventing the FBI from doing its job, it’s that the FBI is bad at doing its job. That’s not the American people’s fault, and that’s not a reason to ban encryption.”[11]
Asked what Americans should press their representatives on, he put keeping personal encryption legal first, ahead of repealing the Patriot Act and settling the torture question.[12]
The use he most cares about
The application that matters most to him is the one that bears on his own case. Major outlets — the New York Times, the Washington Post, the Guardian, the Intercept — publish encryption keys on their websites, so that a national security professional wanting to report waste, fraud, abuse or illegality without going through a chain of command can send the material directly and encrypted to a journalist.[13]
He recommends it not as the best option but as the only survivable one: “I fear that that’s the only way to do it — otherwise you literally take your life into your own hands.”[13][14]