Live data from Hacker News

European Union dedicated questionnaire on the Encryption of Data

blog.lukaszolejnik.com

31–40 of 113 posts

Re: European Union dedicated questionnaire on the Encryption of Data

#32

Earlier quoted context omitted.

This. In the U.S. at least, the 5th amendment gives you the right not to incriminate yourself. A search warrant doesn't change that. Not all authentication methods are equal it appears. Fingerprint, facial recognition, other bio-metrics aren't considered the same as if you need to "speak" your password to someone. In other words, they can make you scan your finger or look into a camera, but they can't force you to te…

How about forcing you to type the password, behind a Mantle of Power if need be, such that they can decrypt the disk, without ever knowing the password?

As I understand it, in the US at least this is indeed the line. Same goes for combination vs keyed locks: you can't be forced to self-incriminate by sharing information, but you can be held in contempt for withholding evidence.

I imagine it gets murky around things like SSH keys, which are technically a kind of password, but too big for a human to remember - and therefore must be "instantiated" in a physical device somewhere.

Re: European Union dedicated questionnaire on the Encryption of Data

#33
post #4

Smart criminals will use strong encryption anyway and won't give the passwords to law enforcement both for data at rest and sent over the Internet. I'm encrypting my disk now, but I'll give the password to police if they have a search warrant. I'm encrypting so if somebody steals my computer they won't read my data. I think that almost everybody is like me. Weakening that encryption doesn't help me and doesn't help i…

Dumb people believe this is about whether encrypted data from criminals can be decrypted or not. It's not about that. It's about being able of charging a criminal with something just for using encryption. That way it won't matter if he refuses to give up the key.

Thats why you use something like TrueCrypt to provide plausible deniability.

You have 1 partition/password with the stuff you actually want to hide, and you have a second password/partition that just contains your porn collection.

"Yes officer, I just use encryption to hide this stuff. Nothing illegal here. It is just embarrassing. Thats why I hide it."

Thats really good plausible deniability.

Re: European Union dedicated questionnaire on the Encryption of Data

#34
post #11

Earlier quoted context omitted.

> but I'll give the password to police if they have a search warrant. That’s not right. In most countries, you don’t need to incriminate yourself. Before making wrongheaded decisions, contact a lawyer.

On the other hand, not giving your password right away may be interpreted as an indication that you have something to hide (which you inevitably do), and they may tag you for even further scrutiny. Also, UK: don't give your password, go to prison. Indefinitely.

What about plausible deniability keys? 1 password hides the real stuff, and the second one that you give to the police just gives them access to your porn collection (which someone very well might want to hide!).

Re: European Union dedicated questionnaire on the Encryption of Data

#35
post #11

Earlier quoted context omitted.

> but I'll give the password to police if they have a search warrant. That’s not right. In most countries, you don’t need to incriminate yourself. Before making wrongheaded decisions, contact a lawyer.

On the other hand, not giving your password right away may be interpreted as an indication that you have something to hide (which you inevitably do), and they may tag you for even further scrutiny. Also, UK: don't give your password, go to prison. Indefinitely.

Indefinitely? So if the police digs up an old encrypted disc from your attic, and you legitimately forgot the password, you can be put away for the rest of your life?

Re: European Union dedicated questionnaire on the Encryption of Data

#36

Earlier quoted context omitted.

This. In the U.S. at least, the 5th amendment gives you the right not to incriminate yourself. A search warrant doesn't change that. Not all authentication methods are equal it appears. Fingerprint, facial recognition, other bio-metrics aren't considered the same as if you need to "speak" your password to someone. In other words, they can make you scan your finger or look into a camera, but they can't force you to te…

How about forcing you to type the password, behind a Mantle of Power if need be, such that they can decrypt the disk, without ever knowing the password?

The way the law works here in the USA is that anything that requires you to disclose the contents of your mind (a passphrase, an explanation of where you were, your name) cannot be compelled because the fifth amendment precludes the use of that information to convict you.

Things that you ARE (such as fingerprints, DNA, hair color, photo, sample) can be compelled by a court order (e.g. a warrant) because they aren't the contents of your mind but physical aspects of your existence.

That's why the use of a strong passphrase that isn't tied to a biometric is important if you're worried about this sort of thing.

Re: European Union dedicated questionnaire on the Encryption of Data

#37
post #10

Earlier quoted context omitted.

When don't need inflammatory personas like John Oliver in Europe.

What can a "hacker" possibly have against John Oliver? He and his team were the most effective drivers for stronger Net Neutrality policies in the US. The man is a living legend. Edit: 12 million views on the abstract topic of Net Neutrality. That's what I would call a feat indeed: https://youtu.be/fpbOEoRrHyU

Just because you agree with a person doesn't mean you need to agree with their methods.

Re: European Union dedicated questionnaire on the Encryption of Data

#38
post #4

Smart criminals will use strong encryption anyway and won't give the passwords to law enforcement both for data at rest and sent over the Internet. I'm encrypting my disk now, but I'll give the password to police if they have a search warrant. I'm encrypting so if somebody steals my computer they won't read my data. I think that almost everybody is like me. Weakening that encryption doesn't help me and doesn't help i…

Almost nobody is entirely innocent under the law when sufficient scrutiny is applied, so giving LEO access to your computer invites a fishing expedition. IMO.

Re: European Union dedicated questionnaire on the Encryption of Data

#39
post #10

Earlier quoted context omitted.

When don't need inflammatory personas like John Oliver in Europe.

What can a "hacker" possibly have against John Oliver? He and his team were the most effective drivers for stronger Net Neutrality policies in the US. The man is a living legend. Edit: 12 million views on the abstract topic of Net Neutrality. That's what I would call a feat indeed: https://youtu.be/fpbOEoRrHyU

[deleted]

Re: European Union dedicated questionnaire on the Encryption of Data

#40
post #11

Earlier quoted context omitted.

> but I'll give the password to police if they have a search warrant. That’s not right. In most countries, you don’t need to incriminate yourself. Before making wrongheaded decisions, contact a lawyer.

On the other hand, not giving your password right away may be interpreted as an indication that you have something to hide (which you inevitably do), and they may tag you for even further scrutiny. Also, UK: don't give your password, go to prison. Indefinitely.

Please stop spreading FUD about RIPA, there is no "indefinitely" involved, the maximum sentence is two years, unless it relates to child indecency, in which case the maximum sentence is increased to five years. [1]

[1] https://en.wikipedia.org/wiki/Key_disclosure_law#United_King...

Post reply on HN