Live data from Hacker News

Man jailed indefinitely for refusing to decrypt hard drives loses appeal

arstechnica.com

231–240 of 413 posts

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#231

Earlier quoted context omitted.

So here's my concern: guy's now been in jail without charge for 18 months. The prosecutors say his guilt is a foregone conclusion, but apparently it's not foregone enough that they're willing to go ahead and prosecute without the contents of his hard drive. They're gonna hold off until they get what they need. We're starting to get to the edge of the point where this guy might legitimately forget his password. I thin…

Perhaps the FBI have unlocked it, but them having the password doesn't prove that the accused had it. My guess is they wouldn't be pushing on with the case if they didn't know for sure that access would 'demonstrate' criminality. Similarly I imagine the accused knows that if they admit access they're going to spend a lot longer incarcerated. An impasse for our times

That is precisely the scenario that actually would violate the Fifth Amendment, because it forces him to be a witness against himself.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#232
If they've got the evidence, legitimately charge him then? If it's sufficient, let a jury of his peers convict him then.

How is this any more complicated than that, no matter how you frame it? We have laws as a check and balance system for a reason, apparently the US courts are slowly forgetting it or something...

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#234
post #191

Earlier quoted context omitted.

Reading this story actually makes me ill. When a technical defense protects you from the state, they jail you for contempt. When you say, "but we have a constitutional amendment that protects us from self-incrimination", they say "sure but that doesn't apply here." And of course it is child porn that is in question. It is a mere crime to "possess" it, that is to say, possess a hard drive on which images are found. It…

If that's all they had, I'd probably agree with you. But that's not. They have: * Backup logs that show hashes of files that match that of known child porn image files. * Testimony from the guy's sister that she has seen him decrypting the drives, and that he showed her child porn from the drives. So yes, what you're saying is true, but in this case, I'm (reluctantly) on the side of the authorities.

I can see where you are coming from, and I really want to avoid commenting on if he is truly a pedo.

I agree with the poster below you that they should charge him if they do have that evidence.

But if they are holding him in contempt while waiting to force decrypt so that legal precedent can be set, or if they're holding him so that this way he is in jail without getting credit for time served on his potential cp charges, then this is all a pretty hefty abuse of due process and etc.

We really need to defend even the worst people's right to a decent correctional experience. Why?

Because if you are ever wrongfully imprisoned, you would want the same. And it really does happen!

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#236
post #53

This raises an interesting idea: why not create two passwords for encrypted drives, one password decrypt the drive, another password completely wipes the drive. This way if someone is forced to give a password to decrypt something, that password renders the data moot. Thoughts?

You would need something more sophisticated that produced innocuous, but believable, data when given the distress key. Still criminal though.

Or easier to implement, something that accepts the distress key, says it is starting to decrypt, then spews tons of fatal checksum errors, "corrupted block", and so forth.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#237

Earlier quoted context omitted.

If you refuse to hand over subpoenaed evidence you can be held in contempt of court which usually results in some sort of fine, but could potentially result in jail time. Note that this all occurs before your conviction, so time spent in jail for contempt does not count towards your eventual sentence.

Yes, but why are the files needed if it is know which files the drive contains based on hashes, as thousands of hashes matching known images should be plenty to convict on ? Maybe the hashes can only tell that some drive contains the images, and the prosecutor believes it is this particular drive, and tries to avoid having to deal with that defense ? If there is evidence that the particular drive contains those image…

Because without the images, you have to lead a jury through the fundamentals necessary to make them believe, beyond a reasonable doubt, that the presence of certain strings of hexadecimal digits in a log file is conclusive evidence in its own right. Because failure to do so means that the defendant walks free. Because as long as he's in contempt, he's behind bars indefinitely, so why attach a specific term to his incarceration unnecessarily?

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#238
post #15

and this is why the software you use to encrypt hard drives should support plausible deniability. You give away the (other) password and the decrypted drive contains nothing but cat pictures.

Or, you know, just be a decent person and don't download huge swathes of child pornography. To be honest, it's quite disgusting that you're most concerned with how to hide such horrendous material.

I highly doubt the parent poster was in any way contemplating how to hide child pornography, that is quite an unfair interpretation. Hiding illegal material is probably the least of concerns for most people here, but there are plenty others, I've written a few of them below.

One issue out of many, is that many who has worked with and used computers for decades has encrypted drives or volumes in a drawers, or closet which they have forgotten the password to, and could in a very theoretical sense be held in contempt if they were to be prosecuted for something and the prosecutor by some reason got a warrant for that drive.

Another is that according to what I have read the prosecutions appears to have enough to convict, so maybe setting a precedent that could be - but not necessarily is - dangerous to society might not be warranted here.

Yet another is that lots of people feel that it is their right and liberty to be able to store their personal information where it is safe from anyones eyes, even when it is completely legal. The inability to keep the private private feels like having a camera in you bedroom that you have been promised will never be turned on to film you, but the blinking red LED causes a relenting unease prompting you to wear a pyjamas to bed, even though you really like to sleep naked. This is called a chilling effect, where knowledge of surveillance or that someone can probe your most private writings and pictures causes you to not write and makes those images in the first place.

Every crime is a tradegy, but nothing creates more tradegy than legal systems or governments run amok. History teaches us that no government is safe from becoming a tyrant. This is why law enforcement sadly must always be ineffective, as the power wielded by government through law enforcement would otherwise become far too great. This is more important today than it has ever been because today we could probably implement an almost perfect police state, a perfect prison, the perfect nightmare from where there is no return. A place where no revolution is possible, no dissent is ever visible, and the fear is total and all encompassing.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#239

Earlier quoted context omitted.

I think we’re about to see an increase in interest in deniable encryption. A simple solution is to have your encryption software automatically add a large garbage file inside every encrypted volume. When you have something to hide, replace the garbage file with your new encrypted data. This lets you nest your encryption to arbitrary depth, allowing plenty of room for plausible deniability. E.g. you could put your fin…

That's an interesting idea. But it arguably wouldn't have helped Mr. Rawls. Investigators claimed to know what they sought, so they'd still argue that he was holding out. Maybe it's safer to keep encrypted stuff anonymously in cloud storage. Mr. Rawls could have run his Freenet node on an anonymously-leased VPS, used Tor onion services for the various WebGUIs, and accessed it all via Tails. There would have been noth…

Rawls’ is an odd case. If the reports are accurate, he seems to have believed that a strong password on his hard drive gave him legal immunity, and didn’t really try to conceal what he was doing.

Nonetheless, a line has been crossed, and cyber-libertarians have been predicting this breach for as long as I can remember. There’s nothing cyber-libertarians love more than a technical solution to state oppression.

Post reply on HN