Live data from Hacker News

Man jailed indefinitely for refusing to decrypt hard drives loses appeal

arstechnica.com

31–40 of 413 posts

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#31

This case is interesting. If I'm reading https://en.m.wikipedia.org/wiki/United_States_v._Hubbell correctly, the fifth amendment only applies if "they don't know what they're looking for." In this case, because there is (enough) evidence of CP on his computer, they are subpoenaing him to produce the unencrypted drives. In some sense, they're not asking for a password - they're asking for the drive contents, which the…

It is amazing that anything produced would be admissible.

I don't see how this is different than having circumstantial evidence that someone is a murderer, so ordering them to lead you to where they buried the body.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#32
post #15

and this is why the software you use to encrypt hard drives should support plausible deniability. You give away the (other) password and the decrypted drive contains nothing but cat pictures.

On the third failed try, it should re-encrypt the drive with a random key.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#33
post #17
post #13

Earlier quoted context omitted.

It would be interesting to know why he has not used this excuse. Imagine having encrypted disk format where fast delete happens by writing over the main key in the volume header with random data and not all zero or some other magic value. You could have lots of deleted disks and memory sticks and go to jail because you can't decrypt them when asked.

It's possible that the suspect wasn't thinking things through when he was hit with the search warrant. It says that he gave them his iPhone 5S password but not his Mac password, or the passwords for the hard drives. They apparently were able to get into the Mac (maybe the password was the same as his iPhone?) but not his hard drives. He is said to have "refused" to give those passwords. I suppose he gave up the abili…

One can know the hash of the file without having it - i.e. if one got the hash as an ID from the file exchange network, and LEOs have the logs suggesting that has was used to download these files - but they don't have the files themselves.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#35
This raises an interesting idea: why not create two passwords for encrypted drives, one password decrypt the drive, another password completely wipes the drive. This way if someone is forced to give a password to decrypt something, that password renders the data moot.

Thoughts?

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#36
post #16

This reads as extremely bizarre. I mean, reading the fifth amendment makes it pretty clear - no one should be compelled to witness against oneself. However, it looks like the current executive and judicial are thinking "well, those Founders were just idiots for putting such an amendment in, clearly it'd be much easier to prosecute people if we could compel them to witness against themselves, so why don't we just igno…

The supreme court is unelected, and are the supreme authority in this nation, above president and congress. the solution is simple - make the supreme court stand up to elections.

America has had atrocious decisions from the supreme court. In Dred Scott, they said black people have no rights because they are black. In Roe v Wade, the abortion laws of 47 states were struck down by 5 oligarchs. No matter what you believe about black people or abortion, it isn't right that 5 unelected people should determine the fate of a nation, able to overrule every state and federal law with no consequences.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#37

This raises an interesting idea: why not create two passwords for encrypted drives, one password decrypt the drive, another password completely wipes the drive. This way if someone is forced to give a password to decrypt something, that password renders the data moot. Thoughts?

Here's mine: destruction of evidence is a crime.

Probably not the best idea.

Hiding the partition or otherwise making the encrypted data hidden is probably your only bet.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#38
post #31

This case is interesting. If I'm reading https://en.m.wikipedia.org/wiki/United_States_v._Hubbell correctly, the fifth amendment only applies if "they don't know what they're looking for." In this case, because there is (enough) evidence of CP on his computer, they are subpoenaing him to produce the unencrypted drives. In some sense, they're not asking for a password - they're asking for the drive contents, which the…

It is amazing that anything produced would be admissible. I don't see how this is different than having circumstantial evidence that someone is a murderer, so ordering them to lead you to where they buried the body.

I think they key is that the evidence is beyond circumstantial - they have concrete evidence that he uploaded files that were CP from that computer. It's a bit worrying why that isn't circumstantial (hacked computers aren't a thing?), but maybe the standard for issuing a subpoena is lower than guilt but higher than circumstantial.

Sounds like the only right answer for your password is "I do not recall"

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#39

This raises an interesting idea: why not create two passwords for encrypted drives, one password decrypt the drive, another password completely wipes the drive. This way if someone is forced to give a password to decrypt something, that password renders the data moot. Thoughts?

Here's mine: destruction of evidence is a crime. Probably not the best idea. Hiding the partition or otherwise making the encrypted data hidden is probably your only bet.

Which would you rather go down for: destruction of evidence, or what's in your hard drive? I'm asking a technical question, not a legal one. There are many instances where this would be preferable than giving up the data.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#40
post #14

Earlier quoted context omitted.

That would be an interesting case but that's not what seems to be argued here. The state is arguing that they have enough evidence that "the presence of child porn on his drives was a 'foregone conclusion.'". It's likely the defendant didn't use forgetting-the-password as a defense because it was obvious via IP traffic and witness testimony that he had regularly and recently used his computer. The ruling here seems f…

The self-incrimination clause was motivated by the practice of forced confessions, which were elicited by threats, indefinite detention and torture. You can get a DNA sample with a cotton swab, but it takes much worse to extract information from someone's mind.

It's not only because of the amount of force used. It's also because of the power it gives to the police.

If they had a mental scanner that allowed to get information out of people's brain without keeping them in jail forever or torturing them, it still be a problem - because without controls on it what the police would do is just round up everyone looking suspicious enough, brain-scan them en masse and use all the information gathered. And of course they would claim "if you're a honest man, you don't have a reason to be concerned".

So it's not only about torture & detention, it's about not giving police the power to own any information they'd like to have just because they want it. We have "due process" because police and state power is huge even as it is, without strict controls on it a private citizen has very little chance to resist any abuse and to correct any error.

Post reply on HN