Cryptographer's doubts about Ozzie's CLEAR key-escrow system: securing private keys at OEMs and disabling a phone once law enforcement accesses it are hard
It Makes It Worse Robert Graham / Errata Security : No, Ray Ozzie hasn't solved crypto backdoors Zack Whittaker / ZDNet : Experts rip Ray Ozzie's plan for unlocking encrypted phones Department of Computer Science, Columbia University : Ray Ozzie's Proposal: Not a Step Forward William Gayde / TechSpot : Former Microsoft executive thinks he has a solution to the cryptography war with law enforcement
Context & Ripple Effects
Ray Ozzie, Microsoft's former CTO, has spent months shopping CLEAR, a key-escrow design meant to give law enforcement access to encrypted phones without the fiasco critics predict; the Wired profile of his backdoor quest framed it as an engineering problem waiting for a solution. The response from working cryptographers is that the two load-bearing steps — keeping OEM-held private keys safe and bricking a phone once investigators have used their access — are exactly where the scheme breaks.
The pushback is not isolated: a coalition representing Apple, Google, and Facebook criticized law-enforcement backdoors days later, extending a fight that dates back to Apple's CALEA-based argument against the FBI, which held that government cannot dictate phone design. Ozzie's proposal is the industry's attempt to settle that dispute by architecture rather than litigation — and the expert consensus so far is that the architecture does not hold.
First-order effects
- OEMs weighing whether to adopt escrow now have named technical objections on record: Columbia University's computer science department and other experts argue the private-key storage and post-access phone-disabling steps are impractical, giving device makers cover to decline.
- Law enforcement loses its most credible 'workable backdoor' talking point; if the design's own reviewers say it fails at its two core tasks, the mandate argument in the New York Times-reported technologist effort weakens.
Second-order effects
- Apple, Google, and Facebook can point to independent cryptographic review rather than corporate self-interest when resisting unlock mandates, hardening the coalition position they took against backdoors.
- The debate shifts toward policy process: as the ACLU's Jon Callas argued, lawmakers lack the security expertise to evaluate proposals like CLEAR, so expect pressure for technical review to precede any legal mandate.
Third-order effects
- If every escrow design fails the same two tests — key custody and revocation — the structural outcome is that exceptional-access mandates stay legally contested territory, as CALEA vs. All Writs Act established, rather than becoming a built-in feature of consumer devices.
- A durable pattern emerges where cryptographic peer review functions as de facto regulation: no backdoor proposal survives expert scrutiny, which keeps the decision about encryption in courts and legislatures instead of firmware.
The trend: The encryption-access fight is settling into a cycle where each proposed backdoor is tested by public cryptographic review and rejected, leaving device makers aligned against mandated escrow.