Live data from Hacker News

Man jailed over computer password refusal

bbc.co.uk

131–140 of 239 posts

Re: Man jailed over computer password refusal

#131
post #76

Earlier quoted context omitted.

How easy would it be for an officer to present an encrypted computer and say - if you don't unlock this, you're getting thrown in jail. This is no different than a witch hunt, it's totally unprovable and throwing people in jail over not knowing a piece of information is unethical.

In the US, the prosecution is going to have to prove beyond a reasonable doubt that there is, in fact, encrypted information and that the suspect knows the key. Yes, there are going to be gray areas. But if Bob has one computer in his house with his and only his finger prints all over it, wear that indicates that the computer has been used extensively, and the computer hard drive is filled with an encryption scheme w…

Perhaps the password is a sequence of 50 characters that he's never memorised but keeps on a slip of paper, and which has recently gone missing.

Re: Man jailed over computer password refusal

#132

Earlier quoted context omitted.

In the US, the prosecution is going to have to prove beyond a reasonable doubt that there is, in fact, encrypted information and that the suspect knows the key. Yes, there are going to be gray areas. But if Bob has one computer in his house with his and only his finger prints all over it, wear that indicates that the computer has been used extensively, and the computer hard drive is filled with an encryption scheme w…

To establish reasonable doubt all the defense has to do is come up with some alternative way all of your facts can be true without Bob having the key. I can think of two from the top of my head. 1. Bob has mischievous friends, or worse, enemies at school. He leaves his laptop unattended/exposed where someone installs the encryption then wipes their fingerprints, or perhaps has worn gloves. Bob takes his laptop home a…

I think you're confusing "reasonable doubt" with "any doubt at all." Postulating malicious data-encrypting malfeasance is not reasonable doubt, it's conspiracy theory.

Re: Man jailed over computer password refusal

#133

Encryption and password privacy is an entirely unsettled area of US law. The courts can probably compel you to enter your password (to decrypt a drive, or what have you), while you can maintain that the content of your password can be protected under the 5th. So, for instance, say you had encrypted files of plans to build a bomb and detailed schematics of the White House. The judge can order you to decrypt the files…

The point of plausible deniability is that is simplifies things, at least for you the owner of the data.

Re: Man jailed over computer password refusal

#134

Earlier quoted context omitted.

To establish reasonable doubt all the defense has to do is come up with some alternative way all of your facts can be true without Bob having the key. I can think of two from the top of my head. 1. Bob has mischievous friends, or worse, enemies at school. He leaves his laptop unattended/exposed where someone installs the encryption then wipes their fingerprints, or perhaps has worn gloves. Bob takes his laptop home a…

I think you're confusing "reasonable doubt" with "any doubt at all." Postulating malicious data-encrypting malfeasance is not reasonable doubt, it's conspiracy theory.

That's for the jury to decide, eh?

Re: Man jailed over computer password refusal

#135
post #115

Earlier quoted context omitted.

In the USA you cannot be tried for the same crime twice under double jeopardy laws. From wikipedia: There are three essential protections included in the double jeopardy principle, which are: - being tried for the same crime after an acquittal - retrial after a conviction, unless the conviction has been reversed, vacated or otherwise nullified - being punished multiple times for the same offense London and Wales repe…

With any luck now we have a basically sane[1] government, we'll get it back. [1] http://www.guardian.co.uk/politics/2010/may/27/theresa-may-s...

[deleted]

Re: Man jailed over computer password refusal

#136
post #127

Earlier quoted context omitted.

I was a grad student in CS at Cambridge when this law was introduced. A nice man from the police came to lecture us about it. We asked about proving that say the results from a Monte Carlo simulation, or even just a blank disc weren't encrypted - we were told not to worry the law would only be used against terrorists. Since this was before 911 - the 'terrorists' in question were presumably the IRA, not sure they had…

> Since this was before 911 - the 'terrorists' in question were presumably the IRA, not sure they had much of an online presence back then. You do know that 9/11 was not the first terrorist attack on the US by Islamic extremists, do you?

Yes, but I'm assuming the UK didn't draft a law in the mid 90s to prevent Islamic attacks on the US.

The fact that their plans would be written in a foreign language (never mind a foreign alphabet) would have been more than adequate to keep it secret from British intelligence.

ps. You do know that we have been having terrorist attacks for almost a century.

Re: Man jailed over computer password refusal

#137
post #19

Earlier quoted context omitted.

Can you be tried for the same crime twice?

You can certainly be tried for the same crime twice. You can't be tried twice for the same criminal act. Arguably, if they ask him again after doing his 16 weeks, it's a new action if he refuses to comply.

It's not a trial. It's refusal or follow a court issued order, the punishment is contempt of court. They don't need a trial in that case... the judge that issues the order can simply judge whether or not you're complying with it.

In all these scenarios, you're screwed the moment you find yourself in court (actually probably long before then when you convince some law enforcer that you're doing something wrong) Judges and lawyers aren't going to be hip to this hypothetical plausible deniability game.

A drive isn't an extension of your brain or your relationship with your wife. It's physical evidence. The only thing that makes it different than say a really big lock on the door of your house or a safe is the effort it takes to circumvent when a court agrees to admit the evidence. Almost never is that evidence used alone.

There are subtle issues to the meaning of the evidence provided, like you might not need to give up the password and thus decrypt everything else encrypted with it, you might just need to decrypt the data in question in a convincing manner to the court. Being able to decrypt the drive doesn't have to prove that you are responsible for the contents.

Re: Man jailed over computer password refusal

#138
post #116

I am surprised that they didn't keylog his machine - as having a warrant to search/seize means a warrant to keylog probably could have been obtained. The police will learn from this and avoid these 'oh dammit' moments by just keylogging everybody from now (or at least those suspected of having encrypted volumes). Keylogging is the one real weakness of all the TrueCrypt/other encryption schemes (that and your password…

Could you defeat that somehow by having rotating keys?

Wouldn't that take a very long time to re-encrypt a whole drive with a new key?

Re: Man jailed over computer password refusal

#139
post #11

Earlier quoted context omitted.

The police will just beat you up until the secret come out. They're not going to say "Drats! Our evil plans are foiled!" http://xkcd.com/538/

This is about the UK, not about some banana republic.

Ha-ha, oh, wow.

http://en.wikipedia.org/wiki/Uses_of_torture_in_recent_times...

http://en.wikipedia.org/wiki/Torture_and_the_United_States

Re: Man jailed over computer password refusal

#140
post #134

Earlier quoted context omitted.

I think you're confusing "reasonable doubt" with "any doubt at all." Postulating malicious data-encrypting malfeasance is not reasonable doubt, it's conspiracy theory.

That's for the jury to decide, eh?

Touché ;)
Post reply on HN