Live data from Hacker News

European Union dedicated questionnaire on the Encryption of Data

blog.lukaszolejnik.com

51–60 of 113 posts

Re: European Union dedicated questionnaire on the Encryption of Data

#51

Earlier quoted context omitted.

On the other hand, not giving your password right away may be interpreted as an indication that you have something to hide (which you inevitably do), and they may tag you for even further scrutiny. Also, UK: don't give your password, go to prison. Indefinitely.

What about plausible deniability keys? 1 password hides the real stuff, and the second one that you give to the police just gives them access to your porn collection (which someone very well might want to hide!).

Well, they don't matter wrt. the law. Either the prosecution is convinced you gave up all the keys (you win), or they believe you gave them a key that was just a distraction and they throw you in jail unless you give them the other key (you lose).

Re: European Union dedicated questionnaire on the Encryption of Data

#52

Earlier quoted context omitted.

On the other hand, not giving your password right away may be interpreted as an indication that you have something to hide (which you inevitably do), and they may tag you for even further scrutiny. Also, UK: don't give your password, go to prison. Indefinitely.

Is there currently someone in UK prison for not giving up their password?

Only one case which I've seen mention of: http://www.bbc.co.uk/news/uk-25745989

He got an additional four months for the failure to disclose the passphrase, on top of five years three months for Terrorism Act offences.

Re: European Union dedicated questionnaire on the Encryption of Data

#53
post #32

Earlier quoted context omitted.

How about forcing you to type the password, behind a Mantle of Power if need be, such that they can decrypt the disk, without ever knowing the password?

As I understand it, in the US at least this is indeed the line. Same goes for combination vs keyed locks: you can't be forced to self-incriminate by sharing information, but you can be held in contempt for withholding evidence. I imagine it gets murky around things like SSH keys, which are technically a kind of password, but too big for a human to remember - and therefore must be "instantiated" in a physical device s…

Simple password that you can remember encrypting your SSH key, know they can't compel you to give the password unlocking the key.

Re: European Union dedicated questionnaire on the Encryption of Data

#55
post #4

Smart criminals will use strong encryption anyway and won't give the passwords to law enforcement both for data at rest and sent over the Internet. I'm encrypting my disk now, but I'll give the password to police if they have a search warrant. I'm encrypting so if somebody steals my computer they won't read my data. I think that almost everybody is like me. Weakening that encryption doesn't help me and doesn't help i…

Backdoors and weakened encryption means that there is no encryption going on at all. If any government official can get any information that means anyone can get that information as many of the people who break this stuff don't work for governments and governments are least technically capable actors. So it means there is effectively no encryption all if encryption is weakened or backdoored.

Re: European Union dedicated questionnaire on the Encryption of Data

#56
post #4

Smart criminals will use strong encryption anyway and won't give the passwords to law enforcement both for data at rest and sent over the Internet. I'm encrypting my disk now, but I'll give the password to police if they have a search warrant. I'm encrypting so if somebody steals my computer they won't read my data. I think that almost everybody is like me. Weakening that encryption doesn't help me and doesn't help i…

> I'm encrypting my disk now, but I'll give the password to police if they have a search warrant. I'm encrypting so if somebody steals my computer they won't read my data. I think that almost everybody is like me.

I may be taking the word "everyone" too literally, but I think that part of the problem is that most people don't think like you and don't really understand the benefits of encryption and why it's a practical tool for absolutely everyone, not just terrorists, pedophiles, and drug dealers. There's a very big educational gap when it comes to encryption, and I don't think that most people can even cover the basics of it very well, which makes it extremely difficult at times to tell if law enforcement and politicians even understand the implications of what they propose beyond the immediate benefit to their operations.

However, I do think that your position is probably the best that can help people to begin to understand why encryption is important; there still is a disconnect where most people don't understand that encryption is an all or nothing ordeal, or if they do, they accept the rationalization that the weakening of encryption is important for the security of the nation, whichever nation that may be.

But in general, encryption is a problem because it operates in a blackbox for the majority of people, and it's incredibly easy for talking heads to say just about whatever they want on it without being challenged. It feels to me like strong encryption is one of those lessons that people are going to have to learn the hard way, much like how a lot of people learn about backing up data only after having a hard-drive go with important data on it. Though it would likely be difficult to prove, I think it's going to require that a government exploit or something intentionally weakened by a governmental actor be utilized by criminals to harm the public at large before people really get the idea on what government-approved encryption really means.

Re: European Union dedicated questionnaire on the Encryption of Data

#57
post #11

Earlier quoted context omitted.

> but I'll give the password to police if they have a search warrant. That’s not right. In most countries, you don’t need to incriminate yourself. Before making wrongheaded decisions, contact a lawyer.

This. In the U.S. at least, the 5th amendment gives you the right not to incriminate yourself. A search warrant doesn't change that. Not all authentication methods are equal it appears. Fingerprint, facial recognition, other bio-metrics aren't considered the same as if you need to "speak" your password to someone. In other words, they can make you scan your finger or look into a camera, but they can't force you to te…

To be fair, AFAIK, this is only the case in criminal proceedings. In civil proceedings, your failure to comply will be held against you.

Re: European Union dedicated questionnaire on the Encryption of Data

#58

Earlier quoted context omitted.

Dumb people believe this is about whether encrypted data from criminals can be decrypted or not. It's not about that. It's about being able of charging a criminal with something just for using encryption. That way it won't matter if he refuses to give up the key.

Thats why you use something like TrueCrypt to provide plausible deniability. You have 1 partition/password with the stuff you actually want to hide, and you have a second password/partition that just contains your porn collection. "Yes officer, I just use encryption to hide this stuff. Nothing illegal here. It is just embarrassing. Thats why I hide it." Thats really good plausible deniability.

Or "This 500gb file is just a garbage file of random numbers I keep because I heard harddrives last longer if they aren't empty".

In any reasonable legislation there shouldn't be a difference between not providing a password and not admitting you have anything encrypted at all (because no one can prove the difference anyway).

An important thing that is often forgotten is that most many aren't challenged for encrypted contents in criminal cases but civil lawsuits where the burden of proof is (also) on the defendant because there is no "beyond reasonable doubt" . In that situation, the mere existence of e.g. a file transfer log with the movie file name + an encrypted disk is enough to end up with massive damages. In that situation you would be very interested to show your unencrypted data if you don't have the file in question.

Re: European Union dedicated questionnaire on the Encryption of Data

#59
post #52

Earlier quoted context omitted.

Is there currently someone in UK prison for not giving up their password?

Only one case which I've seen mention of: http://www.bbc.co.uk/news/uk-25745989 He got an additional four months for the failure to disclose the passphrase, on top of five years three months for Terrorism Act offences.

The Register reported a man getting 13 months (http://www.theregister.co.uk/2009/11/24/ripa_jfl?page=1) - though I couldn't find a better reference.

BBC also reported on a teenager getting 16 weeks (http://www.bbc.co.uk/news/uk-england-11479831).

In both cases it seems they were jailed purely for failure to disclose passwords and not in conjunction with any other offence.

Re: European Union dedicated questionnaire on the Encryption of Data

#60

I find the german answers [1] surprisingly reasonable. High Five for the final answer: > 11. Are there other issues that you would like to raise in relation to encryption and the possible approach to these issues? Please share any relevant national experience or considerations arising from your practice that need to be taken into account. > Yes. A regulation to prohibit or to weaken encryption for telecommunication a…

I come from Germany. The situation is complicated. The responsible politicians tend to make statements that are contradicting or don't make any sense. There have been multiple statements that at least could be interpreted as supportive of encryption regulation. In one occasion there was a joint statement by the french and german ministers of interior - with the slight problem that the french and german versions of the statement were different.

Recently they created a new institution supposed to help decrypting messages. They never explained what that actually means. (I mean you simply can't decrypt properly designed crypto systems.)

Germany isn't the privacy paradise that some people in the international debates sometimes like to see in it.

Post reply on HN