Week 14 · lesson
Case Study: Lawful Access to an Encrypted Device
The Garden State Cyber curriculum asks students to study a case in which the FBI sought access to an encrypted iPhone and to review arguments about privacy and security.
This lesson does not supply case facts beyond the approved course materials.
Use the teacher-provided case packet, excerpts, or assigned sources for all factual claims.
Build the factual record first
Before taking a position, create a case table:
| Question | Evidence from the assigned material |
|---|---|
| What device or data was at issue? | |
| Who requested access? | |
| What was the stated investigative goal? | |
| What technical or legal action was requested? | |
| What concern did the technology company raise? | |
| What alternatives were discussed? | |
| What remained disputed? |
If the assigned material does not answer a question, write not established in the provided source.
Separate technical and policy claims
A technical claim might be:
A reusable access mechanism could change the security properties of future systems.
A policy claim might be:
Government should be permitted to require access under specified legal conditions.
Those are different kinds of claims and may require different evidence.
The exceptional-access question
A central design tension is whether a system can provide access to an authorized third party while preventing unauthorized parties from abusing the same capability.
Analyze this as an architecture problem:
- Who controls the access mechanism?
- How is authorization verified?
- Can the mechanism be copied or reused?
- What happens if the access key or process is compromised?
- Does the capability affect only one device or the broader product design?
- Who audits use?
Do not assume the answer. Use the assigned case material to determine which concerns were actually raised.
Build two strongest-argument cards
Create one card for each side of the policy dispute.
Card A: access argument
Include:
- strongest stated public-safety or investigative interest
- evidence from the case packet
- limiting condition or safeguard proposed
- strongest weakness in the argument
Card B: security/privacy argument
Include:
- strongest stated security or privacy concern
- evidence from the case packet
- alternative approach, if provided
- strongest weakness in the argument
Your job is to represent both positions accurately before deciding what you think.
Steelman before rebuttal
A steelman is the strongest fair version of an opposing argument.
Before writing a rebuttal, another student should be able to read your summary and say:
Yes, that is a fair version of the position even if I disagree with it.
This prevents debate from becoming caricature.
Risk-transfer analysis
Security choices move risk around.
If access is denied, some investigative opportunities may be lost.
If an access mechanism is created, new technical or governance risks may arise.
Create a table:
| Decision | Benefit | New risk | Who receives benefit | Who bears risk |
|---|
Use only claims supported by the assigned materials.
Evidence hierarchy
Rank the evidence you encounter:
- direct case document or primary source supplied by teacher
- technical explanation from a credible assigned source
- news summary
- opinion or commentary
- unsupported social-media claim
Explain why two sources discussing the same case may deserve different weight.
Prepare a neutral case brief
Write no more than one page:
Facts established by the packet
Technical question
Policy question
Strongest argument for access
Strongest argument against required access
Unresolved question
Do not include your personal conclusion yet.
Evidence for Lesson 2
Submit:
- factual case table
- two strongest-argument cards
- risk-transfer table
- source/evidence ranking
- neutral one-page case brief
Finish with:
The part of the debate that depends most on technical architecture is ________, while the part that depends most on policy values is ________.
Good cybersecurity debate starts by separating what happened, how the technology works, and what society should require.