Live data from Hacker News

Man jailed indefinitely for refusing to decrypt hard drives loses appeal

arstechnica.com

21–30 of 413 posts

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#21
post #13
post #2

So if I forget my password, I can be in jail forever?

It would be interesting to know why he has not used this excuse. Imagine having encrypted disk format where fast delete happens by writing over the main key in the volume header with random data and not all zero or some other magic value. You could have lots of deleted disks and memory sticks and go to jail because you can't decrypt them when asked.

The prosecution would say that he frequently accessed the computer (which they could prove with forensic analysis) and argue it unlikely that he forgot his passphrase. The judge would accept that argument.

It's scary to me because I've forgotten my encryption passphrases more than once, and I'm highly-educated.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#22
post #12

Earlier quoted context omitted.

Then why hasn't this person been prosecuted yet? Are they just wanting him to give up his credentials so that they can refer to this case as a precedent?

A possibility is that if they prosecute based on what they have now, then he will _never_ decrypt it - they may be aiming to break up a porn-ring or the actual producers, and he may have very valuable data on the drive, that may potentially save lives

If this were the case, they would provide him immunity in exchange for cooperation in prosecuting up the "food chain" like they do with mobsters.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#23
post #14
post #2

So if I forget my password, I can be in jail forever?

That would be an interesting case but that's not what seems to be argued here. The state is arguing that they have enough evidence that "the presence of child porn on his drives was a 'foregone conclusion.'". It's likely the defendant didn't use forgetting-the-password as a defense because it was obvious via IP traffic and witness testimony that he had regularly and recently used his computer. The ruling here seems f…

> Forensic examination also disclosed that Doe [Rawls] had downloaded thousands of files known by their "hash" values to be child pornography. The files, however, were not on the Mac Pro, but instead had been stored on the encrypted external hard drives. Accordingly, the files themselves could not be accessed.

He was running a Freenet node. Investigators were also running Freenet nodes, which peered with his. The were using a tweaked Freenet client that logs lots of stuff. So they know that chunks of child porn files went to his node. What they arguably don't know is whether he requested them, or merely relayed requests from other peers. But they have experts who will bullshit convincingly enough about that.

Edit: The Freenet Project, in my opinion, has irresponsibly relied on "plausible deniability".

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#24
post #17
post #13

Earlier quoted context omitted.

It would be interesting to know why he has not used this excuse. Imagine having encrypted disk format where fast delete happens by writing over the main key in the volume header with random data and not all zero or some other magic value. You could have lots of deleted disks and memory sticks and go to jail because you can't decrypt them when asked.

It's possible that the suspect wasn't thinking things through when he was hit with the search warrant. It says that he gave them his iPhone 5S password but not his Mac password, or the passwords for the hard drives. They apparently were able to get into the Mac (maybe the password was the same as his iPhone?) but not his hard drives. He is said to have "refused" to give those passwords. I suppose he gave up the abili…

I'm assuming the files were downloaded using Bittorrent or some other file sharing service, and the hashes of the downloaded files were logged on his Mac.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#25
This is an interesting contrast to the article reported this past week about Nigel Lang, a black man in the UK who was accused of having or sharing child porn because of an extra digit added to an IP address during investigations[1].

One relevant section from the apology/explanation letter: "The issues around the downloading of IIOC [indecent images of children] are that statistically out of a cohort of offenders, the predominant characteristic is that the offence will be committed in the main by white males. Only a very small percentage will be black, around 3%, and only around 2% will be female. Consequently, any arrests that are made for this offence will revolve around the male in the address as the starting point for the investigation."

Notably Rawls (the man indefinitely jailed) is black.

[1] https://www.buzzfeed.com/matthewchampion/this-mans-life-was-...

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#26
Here's a recording of the oral arguments for the US Court of Appeals, Third Circuit back in September: http://www2.ca3.uscourts.gov/oralargument/audio/15-3537USAv....

The gov's argument seems to be that because the defendant doesn't have to give the government the password but rather produce the decrypted hard drives, his actions aren't protected under the fifth. Analogy drawn with unlocking a safe.

EFF counter-argument to the safe analogy is that the encrypted documents do not simultaneously exist in a decrypted form protected by an obstacle, like a safe, but rather are produced as an act of translating the data from decrypted to unencrypted form; the government already has the data on the drives, they just can't understand it without the contents of the defendant's mind.

Justices then press the gov lawyer on whether there are fourth amendment issues in the case, as in whether the government can search all files on the hard drive, if decrypted, for evidence of criminality beyond the specific files they seek. Gov lawyer punts on the issue.

Basically it seems like a steep hill for proponents of encryption. The justices talk about how we're heading for a world where almost everything is encrypted, and encryption proponents are asking the government to give up an enormous amount of power.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#28
This case is interesting. If I'm reading https://en.m.wikipedia.org/wiki/United_States_v._Hubbell correctly, the fifth amendment only applies if "they don't know what they're looking for." In this case, because there is (enough) evidence of CP on his computer, they are subpoenaing him to produce the unencrypted drives. In some sense, they're not asking for a password - they're asking for the drive contents, which they know to at least partially be illegal. IANAL though.

Assuming that interpretation of the 5th is correct, subpoenas can easily be used to access encrypted information. I just hope the judges that decide when to grant subpoenas know where that line is.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#29
post #17
post #13

Earlier quoted context omitted.

It would be interesting to know why he has not used this excuse. Imagine having encrypted disk format where fast delete happens by writing over the main key in the volume header with random data and not all zero or some other magic value. You could have lots of deleted disks and memory sticks and go to jail because you can't decrypt them when asked.

It's possible that the suspect wasn't thinking things through when he was hit with the search warrant. It says that he gave them his iPhone 5S password but not his Mac password, or the passwords for the hard drives. They apparently were able to get into the Mac (maybe the password was the same as his iPhone?) but not his hard drives. He is said to have "refused" to give those passwords. I suppose he gave up the abili…

As an example of p2p, when a user attempts todownload the song “In the AirTonight,” Gnutella will notlook at filenames, but rather, for other computers sharingthat file based upon its SHA-1 hash value. If,“In the AirTonight” is being shared by multiple users then it is possible for the Gnutella network to obtain parts of the filefrom several users; instead of the user downloading theentire song from one computer, he or she will get a smallpiece from several different users sharing the same file.This allows a computer to simultaneously download different portions of the song, making the entire downloadprocess faster and more reliable.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#30
post #24
post #17

Earlier quoted context omitted.

It's possible that the suspect wasn't thinking things through when he was hit with the search warrant. It says that he gave them his iPhone 5S password but not his Mac password, or the passwords for the hard drives. They apparently were able to get into the Mac (maybe the password was the same as his iPhone?) but not his hard drives. He is said to have "refused" to give those passwords. I suppose he gave up the abili…

I'm assuming the files were downloaded using Bittorrent or some other file sharing service, and the hashes of the downloaded files were logged on his Mac.

Ah, that makes perfect sense. Since they could log into his Mac, looking at the Bittorrent metadata would be trivial (apparently he didn't clear history, or at least do so securely), and some clients would indicate not only the downloaded file, but where it was saved to locally.
Post reply on HN