Live data from Hacker News

Man jailed over computer password refusal

bbc.co.uk

41–50 of 239 posts

Re: Man jailed over computer password refusal

#41
post #21

I've been resetting people's 8 character passwords lost due to Post-Vacation-Insomnia for ages, I'd really like to see them expect me to remember a 50 character password under stress conditions.

I have a 12 character password and it is a pain in the ass to type it several times a day. I couldn't imagine using a 50 character password.

Re: Man jailed over computer password refusal

#42
Encryption and password privacy is an entirely unsettled area of US law. The courts can probably compel you to enter your password (to decrypt a drive, or what have you), while you can maintain that the content of your password can be protected under the 5th. So, for instance, say you had encrypted files of plans to build a bomb and detailed schematics of the White House. The judge can order you to decrypt the files without forcing you to reveal that the password was "K1llt3hPr3zn0w!"

As a practical matter, I've wondered what would happen if someone simply claimed they couldn't remember the password. Especially if one could make it look like the encrypted files hadn't been accessed in over a year.

TrueCrypt's Plausible Deniability (http://www.truecrypt.org/docs/?s=plausible-deniability) makes these issues even more complicated.

But yeah: by simply refusing, you'd be thrown in jail for contempt and your only way out would be appellate review of the order. You'd have to challenge the contempt citation on the basis that the original order was unlawful.

Re: Man jailed over computer password refusal

#43
post #29

Earlier quoted context omitted.

They can slap an "obstruction of justice" charge on. Or charge you with "contempt of court" and just jail you based on that. In broader terms yes the system has a way to inflict random punishment on you for disobidience. In other countries they will just start breaking your fingers, your loved ones fingers, and so on. So the password problem is solved a lot "easier" then.

Once they start breaking your fingers, it gets a whole lot harder to enter that 50-character password.

Relevant: http://imgur.com/0YHea

Re: Man jailed over computer password refusal

#44

It seems like a bad idea to store anything incriminating on your local hard drive. Why not keep your encrypted files on a flash drive? If the police show up destroy the flash drive using a hammer, ensuring that the flash memory chip is thoroughly pulverized and completely unreadable. Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access…

I understand that in some areas, not only is it illegal to operate an insecure wireless access point (in the UK at least), you can be held accountable for the actions of people that use the access point.

Re: Man jailed over computer password refusal

#45

It seems like a bad idea to store anything incriminating on your local hard drive. Why not keep your encrypted files on a flash drive? If the police show up destroy the flash drive using a hammer, ensuring that the flash memory chip is thoroughly pulverized and completely unreadable. Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access…

Intentionally destroying incriminating evidence is probably not something you should ever do. Certainly not in such a way that leaves evidence in the form of pulverized IC remains all over your kitchen counter.

Re: Man jailed over computer password refusal

#46
"50-character encryption password" - nice!

I'm wondering ... Person A refuses for - pure principle (and maybe some ripped DvD's) Person B refuses for - let's say child pornography and a dirty bomb manual

Both will get the same jail time?

Re: Man jailed over computer password refusal

#48
post #7

Earlier quoted context omitted.

Presumably the UK police are aware of this feature, which could lead to a more interesting situation when you can't prove that you've really unlocked to the deepest level.

Seems like you're giving the police a lot of credit, but maybe not. Regardless, there's really no way to prove anything either way, is there?

I've met a couple of people who actually deal with computer forensics for the police and they are seriously smart people and totally on top of their game. So while you're average cop might not understand the details, they have forensics guy who certainly do.

As to proving anything, my understanding is that it is theoretically impossible to prove, but sometimes bugs in the implementation or various user mistakes mean that you can, in practice, sometimes get a good indication that something is hidden,

Re: Man jailed over computer password refusal

#49
post #38
post #23

I wonder why he didn't say he "forgot the password". Although it may seem implausible, how could they prove it's not true?

I think that the law is worded so that it's an offence to have encrypted files and not be able to decrypt them. Whether it's deliberate or just forgotten isn't relevant (though I'd hope it would make a difference in sentencing).

How can you even prove that a file is encrypted? The whole law is baloney.

Re: Man jailed over computer password refusal

#50

It seems like a bad idea to store anything incriminating on your local hard drive. Why not keep your encrypted files on a flash drive? If the police show up destroy the flash drive using a hammer, ensuring that the flash memory chip is thoroughly pulverized and completely unreadable. Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access…

My understanding is that the "oops Agent Smith, my WiFi was unsecured" is not legally feasible, or is going away.. you are responsible for access to your pipe. Which sucks... heh.
Post reply on HN