U.S. Government's Right to an Encryption Scheme's Backdoor Keys

Just to be clear about my previous post: I am not claiming that the answer to the OP’s question is “yes”.

The NSA got their backdoor into the NIST standards through subterfuge, not by getting a law passed mandating crypto software companies to use their algorithm. Once the secret came out, NIST quickly distanced itself from it, as did several tech companies who had been using dual-ec-dbrg in their software.

There have certainly been attempts to essentially make a backdoor mandatory through legal means, though. Back in the nineties there was the short-lived Clipper Chip attempt, a hardware-based encryption product designed by the NSA, of which the output could be decoded using either the user’s normal key or a special “law enforcement” key, like a software version of those TSA-approved luggage padlocks. The idea was to make use of the Clipper chip mandatory in certain telecommunication products and outlaw alternatives, but it never got that far.

What did happen was that American companies were forbidden from exporting software with key lengths above a certain limit. So not a backdoor exactly, but you simply were not allowed to make your crypto strong enough to be uncrackable.

Even today, in order to export software which incorporates crypto technology from the US, you need to fill in some forms, which includes giving the government information about which algorithms your product uses. There is no longer a requirement to deliberately weaken the key, though. However, as of 2010, any software incorporating “non-standard” encryption, is not automatically licensed for export…

There is no law (yet) requiring businesses to hand over keys, they seem to have done it either willingly, or due to secret court orders. The trick was for the NSA to fool the not-so-tech-savy judges in the FISA court(?) into issuing a secret subpoena based on an alleged threat, and making the request such that instead of having a particular user’s email or files decoded, the company was ordered to provide complete access, the main private key.

So no law, but a secret court order. And by secret - the recipient is forbidden from even disclosing they have received the court order.

This is about the shutdown of Lavabit. The NSA apparently got the court order demanding their keys and a back door - or so we can infer, the recipient had to be very very careful what he said or he would be liable for disclosing secret information. The owner chose to shutter his service rather than comply with a request that was basically a fishing expedition and made a mockery of his claim to privacy for customers.