Live data from Hacker News

Man jailed 16 months, and counting, for refusing to decrypt hard drives

arstechnica.com

381–390 of 504 posts

Re: Man jailed 16 months, and counting, for refusing to decrypt hard drives

#381
post #338

Earlier quoted context omitted.

> A possible answer to the first question: Alice is not compelled to provide the key. She is compelled to decrypt the drive. Obviously she can't do that without Bob. Alice is screwed and will spend the rest of her life in prison. Yes, and in this scenario she would not be held in contempt, so your hypothetical does not apply. You can only be held in contempt for refusing to comply with court orders, not for the failu…

I wonder if he had an encryption scheme that deleted the data in the event of n password failures and also something of legal value like bitcoins on the drive. Perhaps, then he could argue that knowingly attempting to log in using potentially incorrect passwords constitutes undue harm.

Such a scheme could probably be circumvented by making copies of the encrypted file (or the entire disk), or denying the decryptor write access etc.

Re: Man jailed 16 months, and counting, for refusing to decrypt hard drives

#383

Earlier quoted context omitted.

> A possible answer to the first question: Alice is not compelled to provide the key. She is compelled to decrypt the drive. Obviously she can't do that without Bob. Alice is screwed and will spend the rest of her life in prison. Yes, and in this scenario she would not be held in contempt, so your hypothetical does not apply. You can only be held in contempt for refusing to comply with court orders, not for the failu…

How far can court orders go? Let's say he was a crooked accountant and the police couldn't understand his spreadsheet. Is he obligated to show him what he was doing? To me this is what the disk encryption is like. The cops can't understand how to read the disk. Is he obligated to help them? What if the pictures in there are encoded using a weird format? Should he be forced to produce a program to read them?

How does the Fifth Amendment apply here?

Re: Man jailed 16 months, and counting, for refusing to decrypt hard drives

#384

Earlier quoted context omitted.

"bad guys" who distribute illegal material Honestly, I fail to see how or why this should be a problem, considering that no actual injuries are inflicted in the storage or possession of ones and zeroes. Sure, that's an obtuse abstraction, but honestly, the buck stops there. At the end of the day, they have a circuit encoded in a given state. Magnetic media that can be arbitrarily degaussed. It's not real. Stop prosec…

If it is all 1s and 0s, I am curious how you feel about the NSA having a good deal of your personal information stored on their drives?

The obvious retort is that having it on a hard drive isn't the crime, the act of collecting it is. So it's the act and not the possession that is the crime.

I would note as a counter-counter argument that we often make things illegal that are not in themselves harmful, but can lead to harm.

Re: Man jailed 16 months, and counting, for refusing to decrypt hard drives

#385

Earlier quoted context omitted.

From the article: "Rawls, the government argues, (PDF) "repeatedly asserts that the All Writs Act order requires him to divulge his passcodes, but he is incorrect: the order requires no testimony from [Rawls], and he may keep his passcodes to himself. Instead, the order requires only that [Rawls] produce his computer and hard drives in an unencrypted state.""

That's like being forced to translate your own notebook written in code. Not my problem, get your own codebreakers to do it.

It's different because you can't verify the authenticity of the custom hand-rolled cipher. This is a request for the accused to produce the keys only, not to do the work of manually decoding.

Re: Man jailed 16 months, and counting, for refusing to decrypt hard drives

#386

Earlier quoted context omitted.

Omg people watching illegal porn is so bad that we should give up our privacy. One day, some one is going to pass a law or do something that you don't like because the government will have unprecedented access and control of information flow. They can stop you seeing or even sharing. And it may be happening already but nobody knows.

I should not like to think anyone mistook me to be arguing in favor of restrictions on cryptography in general, because someone might use it in the commission or furtherance of a crime. But responding to a case where cryptography is (maybe) used to conceal evidence of possession and/or distribution of child pornography, with, and I paraphrase, "why do we care about this kind of nonsense?", does not advance the cause…

I think people can argue all they want about making exceptions to various beliefs in various circumstances but I for one am happy privacy absolutists and people like RMS and the like exist.

Police have more than enough tools to catch people using encryption without the ability to compel people to decrypt data. At the end of the day if you have to try force someone to enter a password or fetch you a key then you already fucked up and should have to admit your failure and try assemble a case with what you were able to get before you fucked it up by not getting the data in-flight or otherwise unencrypted.

Re: Man jailed 16 months, and counting, for refusing to decrypt hard drives

#387
post #372
post #329

Earlier quoted context omitted.

> directly supports an industry of violence against children Not necessarily, and even so, can it be proven?

If I see proof (undoctored video) of a dog being beheaded (a child being sexually abused) I think I'm safe to conclude that a dog was killed (a child was raped). If then that video was sold (or distributed in any way) to fetishists of dog beheading I could conclude that there is some kind of commercial (distribution) process going on here. Note for children: I'm using parenthesis in a way that shouldn't be done.

My point was that the distribution of the material, especially free of charge does not necessarily encourage further abuse, nor does its possession. I do not know, though I admit that I suspect that the abuse would be encouraged because it is being paid for.

Edit: In my opinion, the following offences ought to exist with relation to child pornography and abuse:

(1) Child abuse is an offence as it currently stands, or with revised ages of consent to better reflect philosophical, scientific and psychological evidence (2) The act of recording of abuse with majority or express intention of furnishing the material for charge or otherwise in order finance or encourage continuing abuse is an offence

I think the second part needs some elaboration. I don't think that recording a certain act taking place ought to be illegal, nor I do I think it ought to be illegal to share that material with others. However this presents a dilemma: the abuse may be encouraged by the fact that the material is being sold or even enjoyed. If this encouragement to continue abuse can indeed be proven in a court of law, by some standard deemed appropriate (either the standard 'beyond a reasonable doubt' or the more strict 'balance of probabilities') then the act of making the recording and the act of furnishing the recording, I believe, ought to be an offence.

On the other hand, if the recordings are made merely to provide the enjoyment of others, and not for the purpose of encouraging abuse, I do not think there should be an offence.

At the risk of over-emphasising the point: A child abuser may be encouraged by (i) money (ii) the thought that people are watching the recording (there may be further motivations).

If it can be proven that abuse continued and the abuse was contingent on one or more of these factors, there is sufficient reason to believe that the intent of the recordings aided another crime, which I think may be sufficient to culminate in an offence.

Re: Man jailed 16 months, and counting, for refusing to decrypt hard drives

#389

There's a burden of proof here the court needs to meet before holding the defendant in contempt. For starters, it's reasonable to assume the defendant owns the hard drives in question if they're in their possession, irregardless of their testimony otherwise. Given that piece of information: 1: The court has to prove the disks are actually encrypted. It is not merely enough for the cops to pick up the disks, see some…

It's encrypted with FileVault, so #1 is satisifed. I suspect #2 is as well (I'm guessing using FV leaves "tracks" on the computer?).

Also, compelling them to decrypt doesn't necessarily mean compelling them to hand over the key.

Re: Man jailed 16 months, and counting, for refusing to decrypt hard drives

#390
post #375
post #315

Earlier quoted context omitted.

I co-authored a project that works on Debian that do unattended reboots of encrypted disk drives which allows for scenarios where Alice don't know any part of the key. Every time the machine boots up bob get a request on the network and he can chose to approve or deny. Bob in turn could be in a different country which would make coercion a bit hard. (Project called Mandos)

I think I remember you giving a talk about this at SmashTheStack in Malmo, Sweden. I believe I asked then about maybe having support for non-debian systems and eventually something like Windows in the distant future.. What kind of support would you need for it to be worthwhile investing in that?

(Other co-author here.) We did do that, yes.

(I’m not sure what support or investing would mean in this context.) A Windows programmer could probably port the server side program (which holds the passwords) relatively easily, since it is currently implemented as a normal daemon in Python, and could therefore conceivably be ported or re-written to suit any Internet-connected platform, and the network protocol is fully documented. The client program (which receives the password and uses it to de-crypt the disk), on the other hand, is not so simple to implement. But the problem is not the network protocol; that is relatively simple. The hard part is instead running in the limited environment which exists before the password is available. In Debian, this means writing a program to run in the initramfs system where a kernel is available, but no networking is configured, and no standard system services are available. I have no idea what this would mean in a Windows context. I have toyed with the idea that it might be technically possible to re-write the client to run in the EFI environment, but I have not looked into it – it may or may not be feasible; would one have to write one’s own ZeroConf library? How about a TLS library supporting OpenPGP keys (as per RFC 6091)? How would one even provide a password for unlocking the disk to, for instance, VeraCrypt? Would one have to write the whole thing as a kind of module in VeraCrypt, if such a thing is even supported? I haven’t the foggiest notion of any answers to these questions, and I’m not a Windows nor a macOS programmer, and we implemented it on Debian since that is what we used at the time (and still do). Also, I’m gainfully employed full-time, so I’m not really looking for more work. To sum up, I would not personally be very suited for this kind of work due to inexperience on other platforms, nor could I take it on even if I were, due to personal time constraints. However, I would gladly support (by being available on the Mandos development mailing list) anyone doing this kind of work.

Post reply on HN