Live data from Hacker News

Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years

bleepingcomputer.com

141–150 of 284 posts

Re: Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years

#141
post #112
post #6

Earlier quoted context omitted.

Absolutely but I'll go further. Having something in your hard drive or book or whatever should never be a crime in itself. I mean in India it is a crime to carry an authentic map of India with you. What harm does the contents of an encrypted disk do to society? It is not like he was going out and trying to legalize child abuse. If the person was involved in child abuse, we must try to convict him absolutely but we sh…

What's an "Authentic Map of India"?

Based on a bit of Google-ing, it looks like this is what the GP was talking about:

https://www.washingtonpost.com/news/worldviews/wp/2016/05/06...

Re: Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years

#142
post #102

Earlier quoted context omitted.

> If the disk is encrypted how can they match file hashes? This is an attack, which contemporary block based FDE doesn't really protect you well from. Bitlocker, FileFault, TrueCrypt, VeraCrypt basically operate on one disk block at at time and this means they cannot hide data patterns well. Or as Thomas Ptacek put it in his article "You Don't Want XTS" [1] >It’s ECB-like. It can’t do a perfect job of providing priva…

This is 100% wrong. XTS-mode AES absolutely protects you from known-plaintext attacks like the investigators apparently claim to have pulled off. I suspect we don't have the full description.

> XTS-mode AES absolutely protects you from known-plaintext attacks like the investigators apparently claim to have pulled off.

1. I didn't claim XTS-mode AES is vulnerable to known-plaintext attacks.

2. I don't believe the investigators claim to have pulled off a known-plaintext attack. What is your source for this?

Re: Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years

#143
post #61

There's a better article in Ars: https://arstechnica.com/tech-policy/2017/03/man-jailed-indef... From that article: > The court also noted that the authorities "found [on the Mac Book Pro] one image depicting a pubescent girl in a sexually suggestive position and logs that suggested the user had visited groups with titles common in child exploitation." They also said the man's sister had "reported" that her brother s…

> The court also noted that the authorities "found [on the Mac Book Pro] one image depicting a pubescent girl in a sexually suggestive position and logs that suggested the user had visited groups with titles common in child exploitation." They also said the man's sister had "reported" that her brother showed her hundreds of pictures and videos of child pornography. The fact that hey have so much evidence and yet they…

One reason they want him to unlock the drive is to protect children. Each of these images is a child that has been abused. Some of these are historic cases, and the child is now safe. But some of these are new, and the child is still living with the abuser, and the abuse is continuing.

Re: Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years

#144

Earlier quoted context omitted.

Storing hashes of unencrypted files, would that allow FileVault to verify it was decrypted without error?

The correct order is hash then encrypt, exactly so you can't do that. Now I don't know if FileVault is doing this correctly, but hopefully it does. Edit: So two people have downvoted me without explanation. Is what I'm saying wrong?

two people have downvoted me without explanation

Sadly, that is the new normal for HN (and, I'll be downvoted for saying something like this)

Re: Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years

#145
post #91

Earlier quoted context omitted.

Your analogy fails for a couple of reasons: 1) Giving up the decryption key is clearly not analogous to deciphering the letter. When you decrypt a drive, it’s the computer does the actual deciphering operation. 2) Focusing on how easy the safe is to break without the key cuts against your position. We can jail people for not providing the key to a regular safe, even though the cops could break into it. But we can’t j…

>Giving up the decryption key is clearly not analogous to deciphering the letter. When you decrypt a drive, it’s the computer does the actual deciphering operation. The computer cannot decipher the drive without the decryption key. The computer doing it is just automation. Using that logic killing someone with a car isn't the person's fault since the car did the actual killing. It's about who is controlling the thing…

That article relies on Doe v. United States, 487 U.S. 201 (1988)[1], in which the Supreme Court found that a suspect could be compelled to sign a form authorizing banks to disclose records of any accounts over which he had a right of withdrawal, because 'neither the form nor its execution communicates any factual assertions, implicit or explicit, or conveys any information to the Government.' Applying that decision, a federal circuit court has already decided that the Fifth Amendment rights of the suspect in this case have not been infringed: United States v. Apple Mac Pro Computer, 851 F.3d 238 (2017)[2]. So, while the question is currently the subject of a petition to the Supreme Court, it is not accurate to say that judges agree that revealing a combination, or decrypting an encrypted volume, 'delves into the mind' so that compelling someone to do so would violate the Fifth Amendment.

[1] https://www.law.cornell.edu/supremecourt/text/487/201

[2] http://caselaw.findlaw.com/us-3rd-circuit/1853477.html

Re: Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years

#146
post #132

Earlier quoted context omitted.

The article says that there are hashes of known child pornography content on the drive.

How does that happen? Technically I mean? This isn't full disk encryption? What terrible software leaked the hashes of what it was encrypting? This seems highly relevant to the discussion.

It's a misunderstanding. The hashes are of files he's believed to have downloaded, and they want the disks unlocked to see if they're there.

Re: Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years

#147

When the FBI used the All Writs Act against Apple to attempt to force Apple to bypass the password functions of an iPhone or develop a backdoor method of access, the courts ruled that decryption was not a violation of the Fifth Amendment "if the contents were a foregone conclusion." So if "foregone conclusion" is the criteria that must be met, I have to ask how the contents of this man's external hard drive could be…

> What if he no longer possess them? He could have deleted them.

If that's the case he should give the FBI the key. That way he'll prove he wasn't possessing child pornography.

Re: Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years

#148
post #53
post #4

Earlier quoted context omitted.

Trump quite explicitely promised to double on police and prosecutor power. If what you want is better protection for accused, Trump is last person you should vote for.

I think the argument is that the system already allowed for this before Trump so it's only natural that people angry at a system will vote towards who they perceive to be as far away from it as possible and Trump definitely hits the mark there, compared to the competition.

Trump may be far away from system, but he boasted about supporting tough policies and whatever cops do repeatedly. Claiming that this is why people go for Trump is like claiming they vote him cause they want more benevolent pro-immigrant policies.

This is literally approach pro-Trump voters want. They complaint is that system became weak and does not do power play like this often enough.

Re: Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years

#149
post #49

So the police no longer need to plant drugs. They can just plant encrypted hard drives to which you have 'forgotten' the password. Hard-drives containing hashes of 'bad' pics. And then you can spend your life in jail (unless you plead guilty) ?

If they're going to do that, they might as well just leave the pictures unencrypted. I don't see how encrypting it and then going through all these gymnastics in court helps them; in fact doing that seems like a good way to draw unnecessary attention to the frame job.

No because then he gets convicted and sentenced for a definite amount of time. Leave the hard drive encrypted and he's in jail indefinitely.

Re: Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years

#150
post #59

Earlier quoted context omitted.

So much for that whole constitution thing anyway.. They can just create some "act" that overrides it! And nobody will complain because the person affected is the bad guy, until they come for them.

It doesn't override the Constitution, though. He's not compelled to testify against himself. In a pre-computer society, we'd understand the Fifth Amendment as allowing you not to testify to your crimes, but not allowing you to refuse the police the right to search your house with a court-signed warrant, simply because you keep incriminating things in the house. It might exploit a loophole, though (and I also think th…

[deleted]
Post reply on HN