Live data from Hacker News

Man jailed over computer password refusal

bbc.co.uk

91–100 of 239 posts

Re: Man jailed over computer password refusal

#91
post #11

Just thought of a feature idea for TrueCrypt and other similar packages: encrypted files or partitions can have multiple passwords, which reveal different things. So you could have a password that reveals something embarrassing but not incriminating. If the police or border nazis threaten you with prosecution unless you reveal your password, you give them this one. Meanwhile, you hide anything really confidential beh…

The police will just beat you up until the secret come out. They're not going to say "Drats! Our evil plans are foiled!" http://xkcd.com/538/

This is about the UK, not about some banana republic.

Re: Man jailed over computer password refusal

#92
post #50

It seems like a bad idea to store anything incriminating on your local hard drive. Why not keep your encrypted files on a flash drive? If the police show up destroy the flash drive using a hammer, ensuring that the flash memory chip is thoroughly pulverized and completely unreadable. Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access…

My understanding is that the "oops Agent Smith, my WiFi was unsecured" is not legally feasible, or is going away.. you are responsible for access to your pipe. Which sucks... heh.

That doesn't sound feasible to me, because there are so many older people and non-technically savy individuals who don't know how to secure their wireless access point. In addition, some models don't support security that is strong enough to prevent hacking, or they are set up using default or easy to guess passwords. Lastly, many wireless points are deliberately left open so that they can be used by customers of cafes, etc.

So in summary, I seriously doubt that you can be held responsible for another person's use of your pipe.

Re: Man jailed over computer password refusal

#93
post #59

Earlier quoted context omitted.

I have a 12 character password and it is a pain in the ass to type it several times a day. I couldn't imagine using a 50 character password.

It is probably just a concatenated string of his credit card number or social security number and random words. I wonder if they are currently trying to crack it using some kind of dictionary brute force mechanism, or if there is some kind of lock out enabled after five tries.

If they have physical access, then there is no effective lock-out mechanism. Presumably they can determine which encryption software is used, and can use the algorithm as many times as they want.

Re: Man jailed over computer password refusal

#94
post #85

Earlier quoted context omitted.

In the USA you cannot be tried for the same crime twice under double jeopardy laws. From wikipedia: There are three essential protections included in the double jeopardy principle, which are: - being tried for the same crime after an acquittal - retrial after a conviction, unless the conviction has been reversed, vacated or otherwise nullified - being punished multiple times for the same offense London and Wales repe…

London and Wales? Was this some Ken Livingstone law? :P

Scotland has a different legal system, based on Roman law (not Common loaw). Scotland is moving to repeal double jeopardy but it hasn't passed yet.

Note that double jeopardy still applies in all but the most serious cases -- rape, murder, and comparable -- and AIUI charges cannot be brought again unless substantial new evidence comes to light.

Re: Man jailed over computer password refusal

#95

As great as hidden volumes are, traces showing the inconsistency between the fake and real volume will be left on your system unless you take heroic measures to erase them. Things like logs of all the external drives you connect, and links to recently opened files.

Your entire operating system can be a hidden volume. I don't know how "heroic" this is.

Re: Man jailed over computer password refusal

#96
post #46

"50-character encryption password" - nice! I'm wondering ... Person A refuses for - pure principle (and maybe some ripped DvD's) Person B refuses for - let's say child pornography and a dirty bomb manual Both will get the same jail time?

No - IIRC it's 5years for 'normal' crimes or 7 years for terrorist cases.

The whole law is ridiculous, it also includes unlimited spying by the security services with the bizarre Kafkesque part that you have to cooperate with the spys and it's a crime to inform anyone that you are being spyed on.

The law became a laughing stock when the government claimed it was necessary to fight international terrorism but then had to admit that there had been 1000s of intercepts by local school boards to investigate parents trying to get their kids into better school catchment areas, and city councils tracking cell phone locations to prosecute people for their dog's litter

Re: Man jailed over computer password refusal

#97

It seems like a bad idea to store anything incriminating on your local hard drive. Why not keep your encrypted files on a flash drive? If the police show up destroy the flash drive using a hammer, ensuring that the flash memory chip is thoroughly pulverized and completely unreadable. Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access…

Intentionally destroying incriminating evidence is probably not something you should ever do. Certainly not in such a way that leaves evidence in the form of pulverized IC remains all over your kitchen counter.

But how can they prove that it was incriminating evidence?

Re: Man jailed over computer password refusal

#98
post #11

Earlier quoted context omitted.

The police will just beat you up until the secret come out. They're not going to say "Drats! Our evil plans are foiled!" http://xkcd.com/538/

nah, the police can't torture you for your password. Only the evil criminals can do that. The courts can incarcerate you for not revealing a password, it's is up to you the criminal to decide if the punishment for not revealing the password is more/less severe than the punishment for whatever crime your hiding the evidence of with the password. Edit: OK now I have found evidence to prove myself wrong. At some point i…

Same case. Look later.

http://en.wikipedia.org/wiki/United_States_v._Boucher

Re: Man jailed over computer password refusal

#99
post #66

Earlier quoted context omitted.

In the USA you cannot be tried for the same crime twice under double jeopardy laws. From wikipedia: There are three essential protections included in the double jeopardy principle, which are: - being tried for the same crime after an acquittal - retrial after a conviction, unless the conviction has been reversed, vacated or otherwise nullified - being punished multiple times for the same offense London and Wales repe…

But ... this wouldn't be double jeopardy. It would be a second instance of him refusing to turn over the passwords. Just as you can be tried twice for murder twice if there are two separate murders, you could be tried twice in this situation.

But... it's the same password/encrypted data here.

Re: Man jailed over computer password refusal

#100
post #17

In the USA can you be compelled to testify against yourself by being coerced into giving a password to law enforcement? Has this been tested yet, out of curiosity? I remember reading they can deny you entry/exit to the USA if customs can't read your laptop but never heard anything like local/FBI. If not, I hope it doesn't go before this particular supreme court.

Apparently, not. This guy accidentally tested it the hard way:

http://www.reddit.com/comments/afib1/truecrypt_and_the_fifth...

Post reply on HN