Live data from Hacker News

Court rules that people can't be locked up indefinitely for refusing to decrypt

techdirt.com

121–130 of 180 posts

Re: Court rules that people can't be locked up indefinitely for refusing to decrypt

#121
post #114
post #92

The idea of being locked up for not handing over a password terrifies me. I was deployed a few years ago and living in the conexes. I was bored and decided to go all out on encrypting everything. I picked a completely random 16 character password (I piped the output from /Dev/urandom through some tr command that only allowed typeable characters through) and committed it to muscle memory. I used this laptop every day…

It is not a crime if, as a matter of fact, you forgot the password. As always, it’s up to the court to decide that fact after looking at the evidence.

How could a court possibly correctly deduce whether someone has forgotten a password?

They can't. That's why we have to say that you cannot be compelled to produce a password, because the alternative is that you go to jail for forgetting.

Re: Court rules that people can't be locked up indefinitely for refusing to decrypt

#122

Earlier quoted context omitted.

This explains why an innocent person should take the fifth: https://www.youtube.com/watch?v=d-7o9xYp7eE

Taking the fifth in a courtroom is rather different than not talking to police without a lawyer.

The two are related. In practice no indictment will issue if the prosecutor doesn't think they can win without the defendant's testimony, and in practice the defendant's statements to police are used to impeach them at trial (because the hearsay rule allows that hearsay) and thus make a part of the case just as much as if they made those statements in court, in the witness box. No case -> no trial, no trial -> definitely no testimony.

Watch that video. Then watch it again. Schedule a yearly watching or three.

Re: Court rules that people can't be locked up indefinitely for refusing to decrypt

#123
post #59
post #4

Idea: write malware that drops random data/encrypted files on the infected devices drive but is otherwise harmless, distribute widely. Bam! Plausible deniability for everyone.

We sort of already have this, since stegfs provides an existence proof: https://en.m.wikipedia.org/wiki/StegFS

One problem with this is even after fully cooperating, the prosecution can still claim you're hiding more.

Re: Court rules that people can't be locked up indefinitely for refusing to decrypt

#124
post #114

Earlier quoted context omitted.

It is not a crime if, as a matter of fact, you forgot the password. As always, it’s up to the court to decide that fact after looking at the evidence.

How could a court possibly correctly deduce whether someone has forgotten a password? They can't. That's why we have to say that you cannot be compelled to produce a password, because the alternative is that you go to jail for forgetting.

Read the judgment linked in the article:

> Following the forensic examination, the Government moved to show cause why Rawls should not be held in contempt for his failure to comply with the Decryption Order. Two hearings were held on the issue in which, “Rawls offered no on-the-record explanation for his present failure to comply.” Based on the evidence presented, the District Court found that Rawls remembered the passwords needed to decrypt the hard drives but chose not to reveal them because of the devices’ contents.

The legal process may not satisfy your epistemological requirements, but it allows courts to make these findings. The Fifth Amendment has nothing to do with “going to jail for forgetting.”

Re: Court rules that people can't be locked up indefinitely for refusing to decrypt

#125
post #7

> The Fifth Amendment gives witnesses a right not to testify against themselves. Rawls argued that producing a password for the hard drives would amount to an admission that he owned the hard drives. But the 3rd Circuit rejected that argument. It held that the government already had ample evidence that Rawls owned the hard drives and knew the passwords required to decrypt them. So ordering Rawls to decrypt the drives…

I guess if the crime you're accused of carries a sentence worse than 18 months, it might be worthwhile, but who knows...

But in the US a criminal record can haunt you for decades. At job applications or housing applications. Elections. And many other bad things that haunt people for a long time. 18 months is horrible too but better then a criminal record haunting you.

Re: Court rules that people can't be locked up indefinitely for refusing to decrypt

#126
post #107

Earlier quoted context omitted.

To lock up people forever for such things is to me unthinkable. There is no established responsibility to remember you password, or keep it safe. Memory failures are not very predictable

The law often uses the "reasonable person" as a standard to measure such responsibilities. So would it make sense for a reasonable person to forget a password they typed in only yesterday (and/or perhaps many times before)?

So would it make sense for a reasonable person to forget a password they typed in only yesterday

Judging by our password reset request tickets, I can say "yes"

I've even forgotten a password just minutes after typing it. And I can't even tell you my desktop password despite typing it a dozen times a day for nearly 6 months. I once tried to give my wife the password over the phone and I couldn't do it without a keyboard to silently type on.

Re: Court rules that people can't be locked up indefinitely for refusing to decrypt

#127

Earlier quoted context omitted.

> Rawls argued that producing a password for the hard drives would amount to an admission that he owned the hard drives. But the 3rd Circuit rejected that argument. It held that the government already had ample evidence that Rawls owned the hard drives and knew the passwords required to decrypt them. So ordering Rawls to decrypt the drives wouldn't give the government any information it didn't already have. Of course…

It's more like they can make you open a safe. It's too bad for you if you kept someone's head in that safe.

No, it's not more like making you open a safe.

Telling someone the encryption key is being compelled to act as a witness against yourself, which the 5th amendment provides protection against (if used).

Re: Court rules that people can't be locked up indefinitely for refusing to decrypt

#128

The problem with this new territory is exactly the unsettled issue of whether providing a password is testimonial and protected. The protection against self-incrimination is/was a protection against being put on trial and being forced to say or give testimony that you took part in or committed a crime. It is not a protection against any and all evidence from being produced against you. In a previous age, not saying w…

In Germany is rule is simply that you are not required to do anything to actively help our own prosecution.

They want to take your fingerprints? You don't need to help by lifting your arm. They want you to open a safe? No need to tell them the combination, through they will crack it open if you refuse. Same with encryption keys, you don't need to say anything. Telling the truth? As the accused you're allowed to lie in court however you want.

If you do get sentenced you can get a reduced sentence if the court thinks that you've been cooperative. But you can never get punished simply for the fact that you didn't help with your own prosecution.

Re: Court rules that people can't be locked up indefinitely for refusing to decrypt

#129
post #107

Earlier quoted context omitted.

To lock up people forever for such things is to me unthinkable. There is no established responsibility to remember you password, or keep it safe. Memory failures are not very predictable

The law often uses the "reasonable person" as a standard to measure such responsibilities. So would it make sense for a reasonable person to forget a password they typed in only yesterday (and/or perhaps many times before)?

That depends. I don't "remember" any of my passwords because I use a software program to randomly generate them as I need them and them store them for me. Occasionally, my password manager doesn't prompt me to save this new password and by the time I realize it, my clipboard has forgotten it or I've filled it with something else.

More than once, the first thing I've done after confirming a new account via email is reset my forgotten password. Am I guilty if I didn't bother to reset it right away?

Post reply on HN