Live data from Hacker News

Man jailed over computer password refusal

bbc.co.uk

81–90 of 239 posts

Re: Man jailed over computer password refusal

#81
post #46

"50-character encryption password" - nice! I'm wondering ... Person A refuses for - pure principle (and maybe some ripped DvD's) Person B refuses for - let's say child pornography and a dirty bomb manual Both will get the same jail time?

There are other legitimate reasons to not want to reveal the contents of your hard-drive besides principle or self incrimination. For instance, if you had the private information of any other people. My SO works with HIV, and recently got access to sensitive data that had to be sent on DVD via courier.

Who here trusts the police to not disclose their HIV status?

Re: Man jailed over computer password refusal

#82
post #76

Encryption and password privacy is an entirely unsettled area of US law. The courts can probably compel you to enter your password (to decrypt a drive, or what have you), while you can maintain that the content of your password can be protected under the 5th. So, for instance, say you had encrypted files of plans to build a bomb and detailed schematics of the White House. The judge can order you to decrypt the files…

How easy would it be for an officer to present an encrypted computer and say - if you don't unlock this, you're getting thrown in jail. This is no different than a witch hunt, it's totally unprovable and throwing people in jail over not knowing a piece of information is unethical.

People did that as a protest when the law was introduced - they emailed random numbers to the then home secretary (the minister in charge of the police in the UK)

Re: Man jailed over computer password refusal

#83

It seems like a bad idea to store anything incriminating on your local hard drive. Why not keep your encrypted files on a flash drive? If the police show up destroy the flash drive using a hammer, ensuring that the flash memory chip is thoroughly pulverized and completely unreadable. Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access…

Intentionally destroying incriminating evidence is probably not something you should ever do. Certainly not in such a way that leaves evidence in the form of pulverized IC remains all over your kitchen counter.

Good point, I didn't think of that. Obviously I'm not a master criminal.

Re: Man jailed over computer password refusal

#84
Would it be possible to have one password for accessing the system, and a separate password for permanently wiping sensitive parts (in the background, even)? What would be the legal implications (other than the obvious obstruction of justice charges if the authorities catch on)?

Re: Man jailed over computer password refusal

#85
post #19

Earlier quoted context omitted.

Can you be tried for the same crime twice?

In the USA you cannot be tried for the same crime twice under double jeopardy laws. From wikipedia: There are three essential protections included in the double jeopardy principle, which are: - being tried for the same crime after an acquittal - retrial after a conviction, unless the conviction has been reversed, vacated or otherwise nullified - being punished multiple times for the same offense London and Wales repe…

London and Wales? Was this some Ken Livingstone law? :P

Re: Man jailed over computer password refusal

#86

It seems like a bad idea to store anything incriminating on your local hard drive. Why not keep your encrypted files on a flash drive? If the police show up destroy the flash drive using a hammer, ensuring that the flash memory chip is thoroughly pulverized and completely unreadable. Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access…

> disposing of evidence

Authorities are very aware of this. One reason for "raids", no knock warrants, arresting you on the road, at work, away from home, etc.

Re: Man jailed over computer password refusal

#87

Earlier quoted context omitted.

TrueCrypt already has this feature: http://www.truecrypt.org/hiddenvolume

Ah well...at least I thought of something worth doing :)

More people should learn from this attitude. This is what I say every time I have an idea, and I later found out someone already built a startup around it (happens quite a lot, since I spend half my waking time thinking of startups).

Re: Man jailed over computer password refusal

#88

Would it be possible to have one password for accessing the system, and a separate password for permanently wiping sensitive parts (in the background, even)? What would be the legal implications (other than the obvious obstruction of justice charges if the authorities catch on)?

The problem there is that any evidence should have been copied and should be accessed from a read-only media at that point.

Re: Man jailed over computer password refusal

#89
post #7

Earlier quoted context omitted.

Presumably the UK police are aware of this feature, which could lead to a more interesting situation when you can't prove that you've really unlocked to the deepest level.

My understanding of the feature is that is is impossible to verify whether or not you are using a hidden volume within a TC encrypted volume. Although file-hosted TrueCrypt volumes (containers) do not contain any kind of "signature" either (until decrypted, they appear to consist solely of random data), they cannot provide this kind of plausible deniability, because there is practically no plausible explanation for t…

Clarification: it's impossible to determine if a hidden volume exists in a TrueCrypt volume. It is trivial to determine whether a given password unlocks the main, hidden, or neither volume.

Re: Man jailed over computer password refusal

#90

Encryption and password privacy is an entirely unsettled area of US law. The courts can probably compel you to enter your password (to decrypt a drive, or what have you), while you can maintain that the content of your password can be protected under the 5th. So, for instance, say you had encrypted files of plans to build a bomb and detailed schematics of the White House. The judge can order you to decrypt the files…

I was a grad student in CS at Cambridge when this law was introduced. A nice man from the police came to lecture us about it. We asked about proving that say the results from a Monte Carlo simulation, or even just a blank disc weren't encrypted - we were told not to worry the law would only be used against terrorists.

Since this was before 911 - the 'terrorists' in question were presumably the IRA, not sure they had much of an online presence back then.

Post reply on HN