Live data from Hacker News

Man jailed indefinitely for refusing to decrypt hard drives loses appeal

arstechnica.com

391–400 of 413 posts

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#391
post #23

Earlier quoted context omitted.

> Forensic examination also disclosed that Doe [Rawls] had downloaded thousands of files known by their "hash" values to be child pornography. The files, however, were not on the Mac Pro, but instead had been stored on the encrypted external hard drives. Accordingly, the files themselves could not be accessed. He was running a Freenet node. Investigators were also running Freenet nodes, which peered with his. The wer…

Interesting, didn't think it could be Freenet related, as lists of hashes during synchronisation was stated. If so it could explain why the prosecution want the drive decryped although they on the surface seems to have enough evidence. But then the foregone conclusion argument could to be slightly disingenuous, depending on exact details which appears to be unknown at the moment?

By running their own Freenet nodes, investigators can create databases of observable chunk hashes and file content. And they can see traffic to peers. So they know that his node handled child porn.

But they can't really know that he was looking at child porn without finding saved files. They may also be interested in communications with other potential suspects.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#392

Earlier quoted context omitted.

> this case is one where the evidence is known to exist If that's the case the files aren't needed, they want to see the drive contents on the off chance of finding some other evidence.

Would you like to go to trial and attempt to persuade 12 non-technical jurors that "hashcodes" unequivocally demonstrate beyond any reasonable doubt that there is child porn on the external hard drive? It's a foregone conclusion technically that the illegal content is on the hard drive. His guilt is not a foregone conclusion (not in the US anyway). If you visit https://www.justice.org/sections/newsletters/articles/fi…

So it's True, but not True-to-a-jury True.

Sorry, but legally, the latter should be the only standard of truth. If he exposes himself to a higher standard of guilt, then he is incriminating himself.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#393
post #365

Earlier quoted context omitted.

I appreciate what you're saying about a slippery slope, but I don't find that the nuance of this case necessarily makes it a fallacy. The judge has compelled decryption based on hashes of files left around in logs on the hard drive, but what if an ISP reports that files with those hashes have been downloaded by a particular IP address? The FBI gets a warrant, executes a raid, picks up every piece of electronic equipm…

I'm glad you didn't take offense to me making reference to the fallacy as I appreciate our conversation and wasn't sure how else to express that thought. If you haven't done so, check out the source document for the article as Arstechnica didn't include some important details (and the headline "Man jailed indefinitely for refusing to decrypt hard drives loses appeal" talks past what is actually happening): https://ar…

> Actual question: where in the constitution is this clearly stated?

You're obviously way more legally savvy than I am. Just goes to prove that a _little_ knowledge is a dangerous thing. Totally agree on the "securing convictions" motivation.

I'm referring to the 4th, about needing a warrant to intercept communications. Is that not clearly stated? Maybe my ignorance is showing again. Doesn't the 4th -- on the face of it -- preclude any system of wholesale collection of electronic communications?

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#394
post #377
post #247

Earlier quoted context omitted.

I'm confused by your reasoning here. If we agree that the files are definitely on the system how is it a "fishing expedition" to want to see those files for further investigation. A fishing expedition would be forcing everyone to submit their devices for inspection on the off chance of finding evidence - this case is one where the evidence is known to exist and a person is refusing to hand it over. The less emotive c…

> If we agree that the files are definitely on the system [snip] then prosecute him and be done with it. Anything else is either a fishing expedition or we don't all agree that the files are definitely on the system... in which case it's still a fishing expedition. hashes can be inaccurate, it isn't a foregone conclusion in reality, just in their opinion.

> hashes can be inaccurate, it isn't a foregone conclusion in reality, just in their opinion.

Not really, no. The chance of multiple hash collisions on a set of arbitrary images is a near impossibility.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#395
post #61

Earlier quoted context omitted.

I've thought of this but it usually takes some time to overwrite a lot of data. I'm not savvy enough to know if there's a way to nuke the data that quickly, other than non-software methods. A friend of mine used to keep a massive electromagnet in is PC tower, that would theoretically wipe the hard drives when switched on. We never tried it. (He wasn't dealing in CP, just pirating mass quantities of movies and music).

FDE best practices are to encrypt the entire drive with a random key, and encrypt that random key with a derived key (key-encrypting key, or KEK) based on password. You don't have to nuke the whole drive; just the sector with the KEK-encrypted drive key.

Thanks, that helps me understand.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#396
post #365

Earlier quoted context omitted.

I'm glad you didn't take offense to me making reference to the fallacy as I appreciate our conversation and wasn't sure how else to express that thought. If you haven't done so, check out the source document for the article as Arstechnica didn't include some important details (and the headline "Man jailed indefinitely for refusing to decrypt hard drives loses appeal" talks past what is actually happening): https://ar…

> Actual question: where in the constitution is this clearly stated? You're obviously way more legally savvy than I am. Just goes to prove that a _little_ knowledge is a dangerous thing. Totally agree on the "securing convictions" motivation. I'm referring to the 4th, about needing a warrant to intercept communications. Is that not clearly stated? Maybe my ignorance is showing again. Doesn't the 4th -- on the face of…

> You're obviously way more legally savvy than I am. Just goes to prove that a _little_ knowledge is a dangerous thing.

Oh no, don't feel that way. The law is a man-made thing at the intersection of logic and opinion, which is why there's so many laws and tests -- if you haven't read the source document that's linked in the Arstechnica article, I would, as it has a lot of important detail.

> I'm referring to the 4th, about needing a warrant to intercept communications...Doesn't the 4th -- on the face of it -- preclude any system of wholesale collection of electronic communications?

Law enforcement were specifically targeting traffic expected to have child pornography and the people trying to exchange it on freenet who join very-special-purposed groups. Peer-to-peer platforms depend on people being free to join, and having special-purpose groups really helps with the "probable cause" condition of the 4th.

On the back of that, the defendant gave them confirmation of his illegal acts, so this case is about recovering evidence known to exist.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#397

Earlier quoted context omitted.

What's the penalty that goes with such a charge?

IDK, but you can't keep breaking the law, and have penalties stop. So it won't be one-and-done.

Yeah, but in this case you have to weigh it against the penalty for being proven guilty.

Maybe indefinite detention, and a chance at public attention is better than life in prison as a convicted child molester.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#398
post #103

Earlier quoted context omitted.

Quite aside from anything else, can someone explain whether or not the same logic would apply to (for example) asking someone to open a safe vs. the code to open the safe. It seems like this ruling would say that failing to open the safe is functionally the same? As a gratuitously distorted example, lets say i had cooked accounting books in a spreadsheet on my computer, and they were encrypted by a random password th…

> Quite aside from anything else, can someone explain whether or not the same logic would apply to (for example) asking someone to open a safe vs. the code to open the safe. It seems like this ruling would say that failing to open the safe is functionally the same? Basically, judges don't agree on which way this scenario comes out. > Outside of the law i don't like the forgone conclusion stuff - for example, revoluti…

Thanks for the answer! :D

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#399
post #83

Earlier quoted context omitted.

If this were the case, they would provide him immunity in exchange for cooperation in prosecuting up the "food chain" like they do with mobsters.

I think this is just a thing that happens in the movies. Also, check out the source document and let me know if you think someone found guilty of the described acts deserves immunity.

It's not really a matter of my opinion on the specific case. Even with the full documents, there is no way that I'd have enough information to judge fairly, so I wouldn't try to.

I'm just saying that they have a way out, and it seems that they've made the judgment that the potential of finding other criminals (if that's even a motivation) for them is not worth it. And the courts are making the downside "indefinite prison", which isn't much of a downside for the prosecutor.

I think you can expect this to be used far more broadly if this is allowed. If I were a prosecutor I'd probably abuse the power too as yet another lever to use to get my way.

Re: Man jailed indefinitely for refusing to decrypt hard drives loses appeal

#400
post #362
post #327

Earlier quoted context omitted.

Similarly, if the police have a reasonable suspicion that there are illegal materials in your home, they should never be allowed to enter and search it against your will. Either they have enough evidence to charge you or they don't, right? So why bother searching? It doesn't matter if you have a nuclear weapon in your basement, if you say no they aren't allowed to come in and check/collect evidence that makes them ce…

It's a bad analogy, the police don't need your permission to gain access to your home. It'd be akin to the police coming across a written document in rot13 and jailing you indefinitely until you show them how to decrypt it. What if it turns out to be a grocery list and you used rot13 just as a matter of course? You went to jail over a grocery list? I don't think you can compare searching a house to forcing the decryp…

The fact that police can't access your data without your permission is a technical reason, not a legal reason. Warrants say the police can search your home. Everything in your home. The data on the machines in your home. If a police officer knocks on your door and presents a valid warrant and you say "good luck, I've booby trapped my home as a fortress with shotguns and explosives and I refuse to disable them" you will be locked in jail until you do. Police don't have to deal with your bullshit when a judge orders you to do something and you refuse to comply. They just lock you in jail until you do what they say.

And no, none of your examples are appropriate. If the police could prove you had a grocery list had all of the items used in a crime and could tie you to it, went to a judge, got a warrant, and ordered you to turn over that list, you'd have to do it. If it's encrypted in some scheme you have to show them the real data. It's not the cops' job to work their way around every weird little obstacle you put in their way when they have a lawful order requiring you to hand over information.

In your scenario, if they had a warrant for your grocery list or XMPP server data, you wouldn't be "jailed indefinitely", you'd be jailed until you complied with a lawful order to turn over the data you possess. I don't know where you got the idea you'd be jailed indefinitely because of the content of the chats, that one came out of nowhere. If they discuss crimes you've committed you'd be jailed for those crimes, not indefinitely. After you turn over the logs. If you refuse you're breaking the law. If you don't have access, you can go ahead and try to prove that to the judge, or convince the judge you forgot your password. But the police can provide evidence to suggest you DO have access, you are just willfully refusing to give it up. Like, e.g. logs of you accessing it successfully, recently.

Yes there are legitimate reasons people encrypt things. I encrypt everything, all the time, just for the sake of doing it. I use Tor for my fairly mundane browsing all the time because I value my privacy.

But encryption does not mean "I never have to give anything to the authorities, under any circumstances, no matter what, and there can't ever be any consequences for me if I refuse when they go through proper channels and ask". Encryption does not mean you don't have to comply with the law.

Post reply on HN