Exclusive interview with Cindy Cohn: “The idea that the Big Tech companies are going to stand up for us against the government seems laughable”

Iain Thomson interviews Cindy Cohn, outgoing director of the Electronic Frontier Foundation (EFF) and a key player in why we have encryption today

This is what happens when two rich techies and a Grateful Dead poet get together.

On 10 July 1990, the founder of Lotus, Mitch Kapor, employee number five at Sun, John Gilmore, and Grateful Dead lyricist John Perry Barlow, launched the non-profit internet rights organisation, the Electronic Frontier Foundation. This small band of activists is the reason you can use strong encryption today, as well as keeping governments on their toes over unlawful spying on their populace.

Five year later, a PhD student called Daniel Bernstein sued the US government for the right to publish a paper detailing a strong encryption system called Snuffle. At the time the government had declared such uncrackable systems as munitions and restricted access to them and their export. That’s when Bernstein – with the help of the EFF – went to the courts, and hired an outside lawyer, Cindy Cohn. The government backed down, although it took nine years before the case was fully resolved.

Inspired, Cohn joined the EFF and has worked there for the past 26 years, the most recent 11 of those as its boss. In that time, the group has created software tools like Privacy Badger and HTTPS Everywhere to make the internet safer. It has fought off patent trolls to allow royalty-free podcasting, protected file-sharing software users from random lawsuits, and advised lawmakers on passing sensible internet rules, including the ongoing battle over net neutrality.

Most notably, in 2006 an unassuming chap called Mark Klein knocked on the door of the EFF’s San Francisco office with a satchel full of documents and schematics and asked “Do you folks care about privacy?” Klein was an engineer at AT&T and realised he had wired up the telco’s network to a secret National Security Agency tapping room in the city that enabled them to illegally spy on people around the world. He tried going to the press and no one would touch the story, but the EFF helped file two lawsuits that exposed the surveillance.

This year Cohn retired from the EFF and published a memoir of her time there, Privacy’s Defender. We spoke to her after her return from the DEF CON and Hackers on Planet Earth conferences this month to talk about the past quarter of a century, and what lies ahead in her future.

Over your time at the EFF, what’s the biggest win in your mind?

I think that there’s really nothing like the encryption win. I think of the sheer number of things that we all rely on every day that are made more secure because we have ready access to strong encryption, it is just huge.

Everything from stuff like Signal to Let’s Encrypt for certificate authorities, to encrypting your phone so if you lose it, you don’t lose your whole life. There’s just encryption built into so many things that we all rely on every day, and there’s a world in which that wasn’t the case. Having all that stuff unencrypted would be a very different world. Now we still have a lot to do to have a secure internet, but we wouldn’t even be at the starting gate if we didn’t have access to strong encryption.

And what about the worst moments?

I would be lying if I said that there were not things that were very upsetting and angering.

One of the things I used to joke about at the EFF was that we would have an outrage stick and we would pass around. Everybody has their turn with the outrage stick because it’s often the case you’re really pissed off. So you get to hold the outrage stick for a while, and then you hand it off to someone else.

Sharing the weight is really important and having a team so that you’re not doing this all by yourself is one of the ways in which you kind of handle the setbacks that come along. I think that it really did take sitting down to write the book to realise how much change we actually helped get accomplished over time.

On encryption, the UK and other governments are arguing that law enforcement should have backdoor access – is that even possible to do safely?

It’s impossible to build a backdoor that only good guys can use, and the bad guys could never use.

If the cops came to your house and they said we want you to leave your back door open so that we can get in and find out if you’re a criminal or not. Most people would look at the cops and say, “Get better at your job. You’ve got to be kidding me. You’re making me less safe for everybody.” The cops said, “Oh, don’t worry about it. We’ll take your key, but we will protect it.”

We have an epidemic of police misusing their surveillance power right now [in the USA]. What makes you think they wouldn’t misuse this, or that the key wouldn’t get somewhere else? There is no way to build a vulnerability into a computer system and then make sure only people who you want to use it will ever use it. That’s just not how security works.

So many business plans these days have data collection as a revenue driver. What’s your advice to them in dealing with government data requests?

Either don’t collect it in the first place if you don’t have to, but don’t keep it any longer than you absolutely have to, for legal protection. I think that is the best protection that companies providing these kinds of services can have.

Depending on how the ask comes in, you might have other arguments that you could make to push back. Yahoo fought a big fight in the secret court for a very long time around an order that they were given, so companies can and do fight back in court when they get something that’s improper. But most companies are going to comply with the law at this point. A lot of the compliance is not voluntary; it’s required.

Still, a lot of tech companies are getting flak for this. Are they the biggest privacy weak spot?

In looking at the various organisations that have your data, I think people often overlook the telecommunications companies, and they are the big players in working with the NSA. AT&T and Verizon are the biggest players because they have so much information, and I’ve seen no indication that they are interested in pushing back on the government.

In fact, again, when they got caught, they ran to Congress and got retroactive immunity to protect them for what they had done that was flatly illegal. We’re in a time when everybody’s really mad at the tech companies, but if we’re actually worried about things like general warrants, the kinds of stuff that you know that enable mass surveillance, we have to keep the telecommunications companies in the front of our minds.

So few companies are controlling all this data, and they are increasingly cosy with governments. What’s your suggested solution?

People deserve more choices and better business models than the one we have.

If we didn’t just have five big tech companies people could try other models. I think that in terms of the work that we’ve done on behalf of old school constitutional rights that we’re trying to vindicate, the tech consolidation has been terrible. And now what we’ve seen is with the four or five billionaires currying favour with the Trump administration the idea that the companies are going to stand up for us against the government seems laughable.

And that’s because there are only a few of them, and they’re all run by guys who come from the same stripe. And if there were far more of these companies in a competitive landscape it would be a lot harder for the government to strong-arm them.

So what’s next for you?

I’m trying to hang out and recharge before I do my next thing, which will probably start in November or so. I’m talking to a bunch of organisations and trying to make a decision. So, in between, I’m just walking my dogs and trying to have an actual break, which I’m not very good at.

I’m missing being a litigator, being in a courtroom. When you’re the boss, you end up getting further and further away from the actual work. There’s a couple of different options that look really interesting, but they’re not going to take me very far from public interest law. We’ll see.

More interviews and articles by Iain Thomson

About The Author

Iain Thomson
Iain Thomson

In over 30 years as a tech journalist, Iain Thomson has worked for PC Magazine, PC Advisor, V3.co.uk, and was a cofounder of IT Pro. In the last 15 years worked for The Register he wrote over 5,000 news, analysis and feature articles for the site, and is also a regular guest and occasional host on The Week in Tech (TWiT) podcast. He is now a freelance tech reporter based in San Francisco.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.