Live data from Hacker News

Man jailed over computer password refusal

bbc.co.uk

121–130 of 239 posts

Re: Man jailed over computer password refusal

#121
post #102
post #24

Earlier quoted context omitted.

The 5th amendment protects against forced testimony, not against compulsion to provide evidence. You can refuse to testify against yourself, you cannot refuse to comply with a valid search warrant.

Perhaps a solution is to commit two crimes: crime A which has to do with the encrypted file, and crime B which has nothing to do with it. Then, use a phrase which is self-incriminating for crime B as the password for the encrypted volume. For example, "IBrokeTheSpeedLimitBy15MilesPerHourOnJuneTheTwenty-Seventh,InTheYearTwoThousandAnd4".

In which case the judge would compel you to reveal your password to your attorney. The attorney would not be able to reveal the password as that would violate privilege, but they would be compelled to uphold the terms of the valid search warrant on the decrypted data.

Re: Man jailed over computer password refusal

#122
post #77

Earlier quoted context omitted.

What happens if you say you forgot the password, and the files in question haven't been accessed in over a year? This is a question in my initial post that's still relevant to UK jurisprudence; an answer to which could move the conversation forward in a way far more productive than imagining I didn't know the article was about something that happened in the UK.

I apologized man... What more do you want?

He's probably bored and thus wants to extend the discussion

Re: Man jailed over computer password refusal

#123
post #117

Earlier quoted context omitted.

Apparently, not. This guy accidentally tested it the hard way: http://www.reddit.com/comments/afib1/truecrypt_and_the_fifth...

This entire story smells fake. If TrueCrypt just saved your life, would you really go tell reddit? The dialogue feels constructed; there's no insight about the experience. It's more likely that it's a fabrication by a district attorney, to be cited in the future (just as you have here). Edit: further evidence for this being a fake: * This supposedly happened in Februrary 2004, back when TrueCrypt was version 1.0a and…

It does; OTOH people post some outrageous shit w/r/t their adventures with the law on Reddit. Yesterday, for example, some guy posted pics of an FBI tracking device he found on the underside of his car (http://www.reddit.com/r/reddit.com/comments/dmh5s/does_this_...). A couple months ago some guy wrote an AMA a days before he was to start a multi-year bid in Federal. (http://www.reddit.com/r/IAmA/comments/chc3k/iama_fella_getti...)

Personally I am inclined to believe.

Re: Man jailed over computer password refusal

#124
post #7

Earlier quoted context omitted.

TrueCrypt already has this feature: http://www.truecrypt.org/hiddenvolume

Presumably the UK police are aware of this feature, which could lead to a more interesting situation when you can't prove that you've really unlocked to the deepest level.

I'm surprised that no one has mentioned Rubberhose Deniable Encryption by Julian Assange of Wikileaks fame. That's the entire concept.

Page: http://iq.org/~proff/rubberhose.org/

Description: http://iq.org/~proff/rubberhose.org/current/src/doc/maruguid...

Re: Man jailed over computer password refusal

#125
post #116

I am surprised that they didn't keylog his machine - as having a warrant to search/seize means a warrant to keylog probably could have been obtained. The police will learn from this and avoid these 'oh dammit' moments by just keylogging everybody from now (or at least those suspected of having encrypted volumes). Keylogging is the one real weakness of all the TrueCrypt/other encryption schemes (that and your password…

Could you defeat that somehow by having rotating keys?

Re: Man jailed over computer password refusal

#126
A friend of mine flew back home to Canada. After clearing customs, he was one of the random people chosen to have their luggage inspected. He had his laptop on him and the customs agent booted up the computer, asked him to enter his password and then took his laptop away before bringing it back without telling him anything about it.

I wondered what would have happened if he refused to type in the password.

Re: Man jailed over computer password refusal

#127

Encryption and password privacy is an entirely unsettled area of US law. The courts can probably compel you to enter your password (to decrypt a drive, or what have you), while you can maintain that the content of your password can be protected under the 5th. So, for instance, say you had encrypted files of plans to build a bomb and detailed schematics of the White House. The judge can order you to decrypt the files…

I was a grad student in CS at Cambridge when this law was introduced. A nice man from the police came to lecture us about it. We asked about proving that say the results from a Monte Carlo simulation, or even just a blank disc weren't encrypted - we were told not to worry the law would only be used against terrorists. Since this was before 911 - the 'terrorists' in question were presumably the IRA, not sure they had…

> Since this was before 911 - the 'terrorists' in question were presumably the IRA, not sure they had much of an online presence back then.

You do know that 9/11 was not the first terrorist attack on the US by Islamic extremists, do you?

Re: Man jailed over computer password refusal

#128

Encryption and password privacy is an entirely unsettled area of US law. The courts can probably compel you to enter your password (to decrypt a drive, or what have you), while you can maintain that the content of your password can be protected under the 5th. So, for instance, say you had encrypted files of plans to build a bomb and detailed schematics of the White House. The judge can order you to decrypt the files…

Claiming forgetfulness concerning the key would give you a way out unless they could manage to crack it - at that point you would have dodged the self-incrimination bullet but could not be legally bound to simply "decrypt it."

I agree though - the entire thing is an absurdly mucky business. Apparently however the English law doesn't have much like that in the way of loopholes, or he simply refused to decrypt it outright.

Re: Man jailed over computer password refusal

#129

Earlier quoted context omitted.

Clarification: it's impossible to determine if a hidden volume exists in a TrueCrypt volume. It is trivial to determine whether a given password unlocks the main, hidden, or neither volume.

How is it trivial to verify whether a password unlocks something the existence of which is impossible to verify?

Data about the hidden volume is encrypted and kept in the second 512 bytes of the volume, where as data about the normal volume is in the first 512 bytes. If there is no hidden volume, the second 512 bytes are purely random data.

It's impossible to tell an encrypted volume header apart from random data. It's very much "try, and if you fail, you either have the wrong key or the volume doesn't exist".

Re: Man jailed over computer password refusal

#130
post #21

I've been resetting people's 8 character passwords lost due to Post-Vacation-Insomnia for ages, I'd really like to see them expect me to remember a 50 character password under stress conditions.

I have a 12 character password and it is a pain in the ass to type it several times a day. I couldn't imagine using a 50 character password.

One way to have long, but memorable passwords is to construct them using the first letter of each word a rather long, but memorable quote/phrase. E.g., The opening of the Gettysburg Address yields: fsasyaofbfutcannciladttptamwce. And if you forget the exact words, you can always look them up.
Post reply on HN