Live data from Hacker News

European Union dedicated questionnaire on the Encryption of Data

blog.lukaszolejnik.com

81–90 of 113 posts

Re: European Union dedicated questionnaire on the Encryption of Data

#81

Earlier quoted context omitted.

On the other hand, not giving your password right away may be interpreted as an indication that you have something to hide (which you inevitably do), and they may tag you for even further scrutiny. Also, UK: don't give your password, go to prison. Indefinitely.

What about plausible deniability keys? 1 password hides the real stuff, and the second one that you give to the police just gives them access to your porn collection (which someone very well might want to hide!).

This is one of the major issues with laws requiring password disclosure.

First of all, a truly careful criminal can use this method to comply with the law while still hiding what they are really after -- negating the usefulness to some extent.

Secondly, once law enforcement catches on to this, they can then claim that someone that does disclose a password actually gave them a plausible deniability or duress key, and they haven't actually given up the real key, and thus the innocent person could potentially be convicted for not giving up a password that doesn't even exist.

Re: European Union dedicated questionnaire on the Encryption of Data

#82
post #17

Can anybody point to organized lobbying efforts we can support to maintain all of this as far away as possible from Europe ? My country has refused to give the answers citing security reasons (according to the article).

The UK has the Open Rights Group and Privacy International.

Re: European Union dedicated questionnaire on the Encryption of Data

#84

Earlier quoted context omitted.

Well, they don't matter wrt. the law. Either the prosecution is convinced you gave up all the keys (you win), or they believe you gave them a key that was just a distraction and they throw you in jail unless you give them the other key (you lose).

Which is terrifying, as the whole point of plausibly deniable passwords is that attitude will end up with innocent people in jail for data that doesn't exist have.

Until it's tested in court on a gray area case, it's hard to know for sure, but I'm pretty confident that UK courts would apply the "reasonable doubt" criterion to the fact that the defendant indeed posesses an encrypted volume they have not provided the keys to.

I.e. if the defendant can reasonably claim that there are no further encrypted volumes on their device, I don't believe they would be imprisoned under this rule.

Re: European Union dedicated questionnaire on the Encryption of Data

#85
post #60

Earlier quoted context omitted.

I come from Germany. The situation is complicated. The responsible politicians tend to make statements that are contradicting or don't make any sense. There have been multiple statements that at least could be interpreted as supportive of encryption regulation. In one occasion there was a joint statement by the french and german ministers of interior - with the slight problem that the french and german versions of th…

On the other hand, it has a larger constituency in government who oppose undermining encryption than most other western nations and a good negative example in the recent past (the Stasi). Just look at the recent legislation passed in the UK, and the statements of Theresa May on encryption or the recent lawsuits by the FBI against Apple. It may be our best hope in stopping legislation mandating backdoors to encryption…

The most important difference is the parliamentary sovereignty of the UK. The biggest protector of privacy here in Germany is the constitution, and the Constitutional court rules fairly assertively on issues of privacy and civil rights, so what PM's do or don't do is not that important.

The UK has no such safeguard due to governmental structure.

Re: European Union dedicated questionnaire on the Encryption of Data

#86

Earlier quoted context omitted.

How do you prove yourself innocent then? You did give them the keys. The point is that you look exactly the same as an innocent person. You are taking the only possible pathway to being proved innocent. It'd be like if I were to say "It doesn't matter what you do. The police are corrupt anyway, and will take you out back and shoot you no matter what. Guilty or innocent, if you get accused of a crime, you are dead." A…

> How do you prove yourself innocent then? You did give them the keys. Well, prosecution needs to have a legally convincing argument that indicates it is likely you have another encrypted partition you're not giving up keys to. In fact, the situation is no different from this: say you're a murder suspect and a neighbour saw you carrying several large heavy sacks into your car and you drove away. Say what really happe…

That's fine, but your argument is effectively that you are screwed no matter what.

If you are truly innocent, the prosecution might claim "oh they have extra keys that they haven't given up", and there is nothing you can do to prove them wrong.

Re: European Union dedicated questionnaire on the Encryption of Data

#87

Earlier quoted context omitted.

What about plausible deniability keys? 1 password hides the real stuff, and the second one that you give to the police just gives them access to your porn collection (which someone very well might want to hide!).

Well, they don't matter wrt. the law. Either the prosecution is convinced you gave up all the keys (you win), or they believe you gave them a key that was just a distraction and they throw you in jail unless you give them the other key (you lose).

In most jurisdictions, the prosecution being _convinced_ that you are guilty isn't enough to throw you in jail -- there's still the small issue of proving their case in front of a judge.

Re: European Union dedicated questionnaire on the Encryption of Data

#88
post #80

Earlier quoted context omitted.

Yes, there is a distinction in US law between acquiring physical and "mental" evidence. The former can be forced (e.g. I must provide my safe key) and the latter cannot (e.g. I don't have to reveal my password). The line gets blurry: keyed lock vs combination lock, password vs SSH key.

> (e.g. I must provide my safe key) Surely you don't need to participate in the activity? They are just allowed to take and use it, I assume?

In the US, you are required to assist in the execution of a warrant (though naturally officers prefer executing it without your participation if possible).

You must unlock your door, and you must unlock your safe, if it is within the scope of the warrant.

https://www.quora.com/Can-a-search-warrant-compel-me-to-unlo...

Re: European Union dedicated questionnaire on the Encryption of Data

#90
I think this shows the state of our intel community. They've been focused on wide-net operations. If a target is high enough of an asset, why not go the easiest route of installing booby-trapped login screens, hardware keyloggers and what not? It's the easiest and most effective way to spy on someone (I'm sure they already do this.) This is all a ploy to spy on citizens. Period.
Post reply on HN