Live data from Hacker News

Man jailed over computer password refusal

bbc.co.uk

171–180 of 239 posts

Re: Man jailed over computer password refusal

#171
post #28

Earlier quoted context omitted.

In the US the current rules for personal hard drives are bound by the 5th amendment which has been interpreted as "a reasonable expectation for privacy." What happens is the police say "Give us your password and we'll drop whatever sentence by 75% for helping the investigation." You don't have to give your password but the NSA works pretty extensively with law enforcement and the FBI (most US cases that require passw…

Do you think the NSA is going to reveal to foreign governments that they've broken AES by going after some guy with child porn on his laptop? I personally doubt it. Could the NSA cooperate with the FBI? Yes. Will they? Not if it means they can't spy on Russia anymore.

It has nothing to do with holes in AES, NSA just has better brute force capabilities than the FBI or any other law enforcement. And while you sit in jail awaiting trial, they take the months it takes to brute force a key.

Re: Man jailed over computer password refusal

#172
post #141

Earlier quoted context omitted.

The difference is that testimony is revealing the contents of your brain ("I saw X, I did or did not do Y, I felt Z") and evidence is revealing the contents of your car trunk. Evidence does not have its own opinion of what did or did not happen, evidence does not decide what is or is not the truth. Evidence simply exists; it is for others (giving testimony) to give evidence context and relevance.

The password is among the contents of your brain.

It's not the password they want, it's the evidence in side the "safe" that your password protects.

You're compelled to provide access. You could probably make a legitimate case for not actually revealing the password if you provided access for them.

Re: Man jailed over computer password refusal

#173
post #152

Earlier quoted context omitted.

Where did you get this idea from?

I got this idea from the MPAA telling my ISP to tell me to secure my WiFi or lose my connectivity.

The MPAA telling you that is no different than me telling you that. I have no legal authority to do so, no matter how many lawyer's names appear on my letterhead.

Re: Man jailed over computer password refusal

#174
post #29
post #17

In the USA can you be compelled to testify against yourself by being coerced into giving a password to law enforcement? Has this been tested yet, out of curiosity? I remember reading they can deny you entry/exit to the USA if customs can't read your laptop but never heard anything like local/FBI. If not, I hope it doesn't go before this particular supreme court.

They can slap an "obstruction of justice" charge on. Or charge you with "contempt of court" and just jail you based on that. In broader terms yes the system has a way to inflict random punishment on you for disobidience. In other countries they will just start breaking your fingers, your loved ones fingers, and so on. So the password problem is solved a lot "easier" then.

They can do that. They face their own consequences if they do.

Re: Man jailed over computer password refusal

#175

Just thought of a feature idea for TrueCrypt and other similar packages: encrypted files or partitions can have multiple passwords, which reveal different things. So you could have a password that reveals something embarrassing but not incriminating. If the police or border nazis threaten you with prosecution unless you reveal your password, you give them this one. Meanwhile, you hide anything really confidential beh…

TrueCrypt already has this feature: http://www.truecrypt.org/hiddenvolume

It's very very annoying to use, and can cause data loss.

Re: Man jailed over computer password refusal

#176
post #127

Earlier quoted context omitted.

I was a grad student in CS at Cambridge when this law was introduced. A nice man from the police came to lecture us about it. We asked about proving that say the results from a Monte Carlo simulation, or even just a blank disc weren't encrypted - we were told not to worry the law would only be used against terrorists. Since this was before 911 - the 'terrorists' in question were presumably the IRA, not sure they had…

> Since this was before 911 - the 'terrorists' in question were presumably the IRA, not sure they had much of an online presence back then. You do know that 9/11 was not the first terrorist attack on the US by Islamic extremists, do you?

[deleted]

Re: Man jailed over computer password refusal

#177

Earlier quoted context omitted.

But how can they prove that it was incriminating evidence?

Usually there'll be a reason for the police to kick your door down. I imagine that plus destroyed evidence would be enough to prove beyond reasonable doubt.

Also, I don't think it necessarily needs to be proven that the evidence was incriminating; just destroying evidence is criminal behavior.

Of course, IANAL, but that's how I'd do it if I ruled the world...

Re: Man jailed over computer password refusal

#178
post #159

Earlier quoted context omitted.

I understand that in some areas, not only is it illegal to operate an insecure wireless access point (in the UK at least), you can be held accountable for the actions of people that use the access point.

that's amusing, considering that every wireless access point is insecure

WPA2 with authentication or WPA2 with a 64-character line-noise password?

Re: Man jailed over computer password refusal

#179
post #19

Earlier quoted context omitted.

Can you be tried for the same crime twice?

In the USA you cannot be tried for the same crime twice under double jeopardy laws. From wikipedia: There are three essential protections included in the double jeopardy principle, which are: - being tried for the same crime after an acquittal - retrial after a conviction, unless the conviction has been reversed, vacated or otherwise nullified - being punished multiple times for the same offense London and Wales repe…

What rationale do they have against double jeopardy? Without it you can make any jail sentence be until someone's death. You can be given a speeding ticket for the same offense until you have no money left.

Re: Man jailed over computer password refusal

#180
post #7

Earlier quoted context omitted.

Presumably the UK police are aware of this feature, which could lead to a more interesting situation when you can't prove that you've really unlocked to the deepest level.

I'm surprised that no one has mentioned Rubberhose Deniable Encryption by Julian Assange of Wikileaks fame. That's the entire concept. Page: http://iq.org/~proff/rubberhose.org/ Description: http://iq.org/~proff/rubberhose.org/current/src/doc/maruguid...

This seems stale though. It's "currently available for Linux 2.2"?
Post reply on HN