Live data from Hacker News

Man jailed over computer password refusal

bbc.co.uk

111–120 of 239 posts

Re: Man jailed over computer password refusal

#111
post #66

Earlier quoted context omitted.

But ... this wouldn't be double jeopardy. It would be a second instance of him refusing to turn over the passwords. Just as you can be tried twice for murder twice if there are two separate murders, you could be tried twice in this situation.

But... it's the same password/encrypted data here.

Disclaimer: IANAL. Disclaimer: IANAA (I Am Not An American)

Assaulting the same person twice would still be two different assaults. Stealing a truck, getting caught and punished, and stealing the same truck again would, to my understanding, not be risk-free, legally speaking. I suspect the same would probably apply here, though given how unintuitive the law is, especially in this area, I may well be dead wrong.

Edit: To clarify, my point is that if the law amounts to "Refusal to turn over requested passwords => jail time", this would seemingly constitute a second refusal, even if the requested password was the same.

Re: Man jailed over computer password refusal

#112

It seems like a bad idea to store anything incriminating on your local hard drive. Why not keep your encrypted files on a flash drive? If the police show up destroy the flash drive using a hammer, ensuring that the flash memory chip is thoroughly pulverized and completely unreadable. Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access…

Intentionally destroying incriminating evidence is probably not something you should ever do. Certainly not in such a way that leaves evidence in the form of pulverized IC remains all over your kitchen counter.

Depends on what it's evidence of. If you're destroying evidence of murder, treason, or something else that'd guarantee you a life/death sentence, an obstruction of justice charge isn't going to seem like very much in comparison.

Re: Man jailed over computer password refusal

#113
post #17

In the USA can you be compelled to testify against yourself by being coerced into giving a password to law enforcement? Has this been tested yet, out of curiosity? I remember reading they can deny you entry/exit to the USA if customs can't read your laptop but never heard anything like local/FBI. If not, I hope it doesn't go before this particular supreme court.

In the USA of today you can be compelled into doing anything the government considers a matter of national security. It all changed starting with the Patriot Act. American citizens have no inalienable rights anymore merely those that are not inconvenient to the government.

Re: Man jailed over computer password refusal

#114
post #72

Earlier quoted context omitted.

That case was goofy because he initially typed in his password in front of law enforcement and provided them access, which nullified any claims of self incrimination. It'd be similar to confessing to murder, telling the cops where the body is, and then invoking your right to remain silent, and expecting them not to look for the body under "fruit of the poisonous tree" logic.

Did he? I thought he drove through the checkpoint with the machine turned on/suspended in his back seat with the drive mounted.

You might be right. The wikipedia page said "the laptop was powered-up", which is a little ambiguous ("was [already?] powered-up"). But I think the principal is the same in either case. He already volunteered the information once.

Re: Man jailed over computer password refusal

#115
post #19

Earlier quoted context omitted.

Can you be tried for the same crime twice?

In the USA you cannot be tried for the same crime twice under double jeopardy laws. From wikipedia: There are three essential protections included in the double jeopardy principle, which are: - being tried for the same crime after an acquittal - retrial after a conviction, unless the conviction has been reversed, vacated or otherwise nullified - being punished multiple times for the same offense London and Wales repe…

With any luck now we have a basically sane[1] government, we'll get it back.

[1] http://www.guardian.co.uk/politics/2010/may/27/theresa-may-s...

Re: Man jailed over computer password refusal

#116
I am surprised that they didn't keylog his machine - as having a warrant to search/seize means a warrant to keylog probably could have been obtained.

The police will learn from this and avoid these 'oh dammit' moments by just keylogging everybody from now (or at least those suspected of having encrypted volumes).

Keylogging is the one real weakness of all the TrueCrypt/other encryption schemes (that and your password is in memory in the clear while the volume is mounted, and even afterwards depending on your settings).

Re: Man jailed over computer password refusal

#117
post #17

In the USA can you be compelled to testify against yourself by being coerced into giving a password to law enforcement? Has this been tested yet, out of curiosity? I remember reading they can deny you entry/exit to the USA if customs can't read your laptop but never heard anything like local/FBI. If not, I hope it doesn't go before this particular supreme court.

Apparently, not. This guy accidentally tested it the hard way: http://www.reddit.com/comments/afib1/truecrypt_and_the_fifth...

This entire story smells fake. If TrueCrypt just saved your life, would you really go tell reddit? The dialogue feels constructed; there's no insight about the experience. It's more likely that it's a fabrication by a district attorney, to be cited in the future (just as you have here).

Edit: further evidence for this being a fake:

* This supposedly happened in Februrary 2004, back when TrueCrypt was version 1.0a and barely known.

* His story suggests that his laptop's system drive was encrypted. TrueCrypt added system disk encryption in version 5.0 in 2008.

* He slips up and says he used AES encryption; this is noticed in the comments and he edits it out (I assume).

Re: Man jailed over computer password refusal

#118
post #76

Earlier quoted context omitted.

How easy would it be for an officer to present an encrypted computer and say - if you don't unlock this, you're getting thrown in jail. This is no different than a witch hunt, it's totally unprovable and throwing people in jail over not knowing a piece of information is unethical.

In the US, the prosecution is going to have to prove beyond a reasonable doubt that there is, in fact, encrypted information and that the suspect knows the key. Yes, there are going to be gray areas. But if Bob has one computer in his house with his and only his finger prints all over it, wear that indicates that the computer has been used extensively, and the computer hard drive is filled with an encryption scheme w…

To establish reasonable doubt all the defense has to do is come up with some alternative way all of your facts can be true without Bob having the key. I can think of two from the top of my head.

1. Bob has mischievous friends, or worse, enemies at school. He leaves his laptop unattended/exposed where someone installs the encryption then wipes their fingerprints, or perhaps has worn gloves. Bob takes his laptop home and tries to regain access to the computer.

2. Bob unwittingly acquires the laptop from a criminal (he may have bought it, or maybe he fixes computers) who encrypted the drive and wiped away all fingerprints. Bob tries to gain access to the computer.

To be free from self-incrimination Bob can simply refuse to answer any questions about the laptop in question at all.

Re: Man jailed over computer password refusal

#119

Earlier quoted context omitted.

My understanding of the feature is that is is impossible to verify whether or not you are using a hidden volume within a TC encrypted volume. Although file-hosted TrueCrypt volumes (containers) do not contain any kind of "signature" either (until decrypted, they appear to consist solely of random data), they cannot provide this kind of plausible deniability, because there is practically no plausible explanation for t…

Clarification: it's impossible to determine if a hidden volume exists in a TrueCrypt volume. It is trivial to determine whether a given password unlocks the main, hidden, or neither volume.

How is it trivial to verify whether a password unlocks something the existence of which is impossible to verify?

Re: Man jailed over computer password refusal

#120
post #21

I've been resetting people's 8 character passwords lost due to Post-Vacation-Insomnia for ages, I'd really like to see them expect me to remember a 50 character password under stress conditions.

I'd bet it's a pass phrase. The first few lines of a song converted to 3l33t will give you 50 memorable characters pretty easily.
Post reply on HN