Live data from Hacker News

Man jailed over computer password refusal

bbc.co.uk

211–220 of 239 posts

Re: Man jailed over computer password refusal

#211
post #81

Earlier quoted context omitted.

There are other legitimate reasons to not want to reveal the contents of your hard-drive besides principle or self incrimination. For instance, if you had the private information of any other people. My SO works with HIV, and recently got access to sensitive data that had to be sent on DVD via courier. Who here trusts the police to not disclose their HIV status?

Disclaimer: IANAL If you're in the Unites States, the data is probably protected by HIPAA, the Health Insurance Portability and Accountability Act[1]. HIPAA includes a clause stating that the Attorney General or their designee may issue a subpoena compelling your SO to disclose that information, but only to someone investigating a Federal health care offense. I've searched through the rest of HIPAA for keywords such…

So basically, if you obtain a copy of your own medical records and steganographically embed your private information into them, you're OK?

Re: Man jailed over computer password refusal

#212

Earlier quoted context omitted.

Disclaimer: IANAL If you're in the Unites States, the data is probably protected by HIPAA, the Health Insurance Portability and Accountability Act[1]. HIPAA includes a clause stating that the Attorney General or their designee may issue a subpoena compelling your SO to disclose that information, but only to someone investigating a Federal health care offense. I've searched through the rest of HIPAA for keywords such…

Yup, that's the case. The question is whether or your hard drive is protected from a criminal charges subpoena. The data is kept encrypted on the hard drive, but of course the authorities don't know what's on the hard drive until it's decrypted.

Disclaimer: IANAL.

Edit: My understanding of HIPAA was incorrect.

45 C.F.R 164.512:

A covered entity may use or disclose protected health information without the written consent or authorization of the individual... in the situations covered by this section, subject to the applicable requirements of this section.

(a) Standard: Uses and disclosures required by law. (1) A covered entity may use or disclose protected health information to the extent that such use or disclosure is required by law and the use or disclosure complies with and is limited to the relevant requirements of such law.

This would seem to give court orders and criminal subpoenas the power to demand decryption of your hard drive regardless of whatever HIPAA data it contains.

Re: Man jailed over computer password refusal

#213
post #175

Earlier quoted context omitted.

TrueCrypt already has this feature: http://www.truecrypt.org/hiddenvolume

It's very very annoying to use, and can cause data loss.

How is it annoying to use? You have to enter 2 passwords instead of 1... Is that it?

As for the data loss, if you only enter the first password, it will let you overwrite the space where the hidden encrypted volume is stored yes. How else would it work? If it didn't let you do this, it would be obvious that a hidden container exists...

Re: Man jailed over computer password refusal

#214

Earlier quoted context omitted.

Yup, that's the case. The question is whether or your hard drive is protected from a criminal charges subpoena. The data is kept encrypted on the hard drive, but of course the authorities don't know what's on the hard drive until it's decrypted.

Disclaimer: IANAL. Edit: My understanding of HIPAA was incorrect. 45 C.F.R 164.512: A covered entity may use or disclose protected health information without the written consent or authorization of the individual... in the situations covered by this section, subject to the applicable requirements of this section. (a) Standard: Uses and disclosures required by law. (1) A covered entity may use or disclose protected he…

[deleted]

Re: Man jailed over computer password refusal

#215

Earlier quoted context omitted.

Disclaimer: IANAL If you're in the Unites States, the data is probably protected by HIPAA, the Health Insurance Portability and Accountability Act[1]. HIPAA includes a clause stating that the Attorney General or their designee may issue a subpoena compelling your SO to disclose that information, but only to someone investigating a Federal health care offense. I've searched through the rest of HIPAA for keywords such…

So basically, if you obtain a copy of your own medical records and steganographically embed your private information into them, you're OK?

No, for two reasons.

1. HIPAA doesn't apply to you unless you're an employee of a covered entity, that is, a health care provider, health care plan, or a firm contracted by a member of the previous two categories to handle billing. You can hand out your private medical information to whomever you want without worrying about HIPAA.

2. Even if HIPAA did, it doesn't give you the power to refuse to disclose HIPAA data when such disclosure is required by law[1].

[1] 45 CFR 164.512 (a): http://www.publichealthlaw.net/Reader/docs/HIPAA.pdf

Re: Man jailed over computer password refusal

#216
post #94
post #85

Earlier quoted context omitted.

London and Wales? Was this some Ken Livingstone law? :P

Scotland has a different legal system, based on Roman law (not Common loaw). Scotland is moving to repeal double jeopardy but it hasn't passed yet. Note that double jeopardy still applies in all but the most serious cases -- rape, murder, and comparable -- and AIUI charges cannot be brought again unless substantial new evidence comes to light.

I believe estel was just pointing out that it should be "England and Wales", rather than "London and Wales". :)

Re: Man jailed over computer password refusal

#217
post #116

I am surprised that they didn't keylog his machine - as having a warrant to search/seize means a warrant to keylog probably could have been obtained. The police will learn from this and avoid these 'oh dammit' moments by just keylogging everybody from now (or at least those suspected of having encrypted volumes). Keylogging is the one real weakness of all the TrueCrypt/other encryption schemes (that and your password…

Adding a keylogger (presumably hardware) is not without its risks. If the suspect discovers it, they have a window of opportunity to cover their tracks.

Re: Man jailed over computer password refusal

#218

It seems like a bad idea to store anything incriminating on your local hard drive. Why not keep your encrypted files on a flash drive? If the police show up destroy the flash drive using a hammer, ensuring that the flash memory chip is thoroughly pulverized and completely unreadable. Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access…

That doesn't cover you for swap files / hibernate files or memory dumps which are written unencrypted and largely outside your control. Obviously it's hit or miss what may or may not be included in there but there are a fair number of leaks where even "secure" information is handled in an insecure fashion.

The TrueCrypt section on data leaks (http://www.truecrypt.org/docs/data-leaks) talks about them and how to get round them.

But if you're really serious about these things it's more complex than not storing things on your local drive or even using encryption.

Re: Man jailed over computer password refusal

#219

Earlier quoted context omitted.

Claiming forgetfulness concerning the key would give you a way out unless they could manage to crack it - at that point you would have dodged the self-incrimination bullet but could not be legally bound to simply "decrypt it." I agree though - the entire thing is an absurdly mucky business. Apparently however the English law doesn't have much like that in the way of loopholes, or he simply refused to decrypt it outri…

I believe there is a specific law in the UK that mandates key escrow -- the government must be able to decrypt anything. This has been floated in the US before, but it has not gotten good PR. As it stands now, it is a Constitutional law issue -- does the fifth amendment mean that you can't be compelled to get up in the witness box and talk, or does it mean that you don't have to assist the prosecution in any way? Rig…

I believe the law in the UK allows for a jail sentence of up to two years for not revealing a password or encryption key.

While it's a dubious law in may ways, when you hear a UK politician calling for longer detention without trial and stating needing to break encryption you can at least point to this law and say that their claims about longer detention are nonsense.

Re: Man jailed over computer password refusal

#220

Earlier quoted context omitted.

Ha-ha, oh, wow. http://en.wikipedia.org/wiki/Uses_of_torture_in_recent_times... http://en.wikipedia.org/wiki/Torture_and_the_United_States

I hope you weren't seriously trying to conflate the Northern Irish situation (which was more like a civil war or a war for independence) and the US military with the UK police. That doesn't make either of those right, there is no mistake about that, but the UK police is amongst the most professional forces in the world. Not quite the RCMP but to suggest that they'd torture inmates to get a password is simply nonsense…

>but the UK police is amongst the most professional forces in the world

http://en.wikipedia.org/wiki/Guildford_Four_and_Maguire_Seve...

http://www.inthenews.co.uk/news/health/crime/death-at-g20-po...

http://www.people.com/people/article/0,,1085543,00.html

http://www.timesonline.co.uk/tol/news/uk/crime/article646643...

http://www.google.ch/webhp?hl=en#hl=en&safe=active&b...

Really? Police in the rest of the world must beat down old ladies for quarters.

Post reply on HN