Live data from Hacker News

TrueCrypt User Held in Contempt of Court

forums.truecrypt.org

31–40 of 200 posts

Re: TrueCrypt User Held in Contempt of Court

#31
Depending on what's on the drive, obstruction of justice might carry a much less onerous penalty than what he'd otherwise be facing.

For instance, if it's child porn, he'd be labeled a sexual predator for life. If it's state secrets, he'd be facing treason and espionage charges. If it's mp3s.. financial ruin on top of the felony charge..

Re: TrueCrypt User Held in Contempt of Court

#32
post #15
post #7

Earlier quoted context omitted.

"The user received a subpoena duces tecum requiring him to type the passwords or pass phrases necessary to produce the encrypted contents of drives seized 6 months earlier. The true crypt user has attempted to comply but he is still being held in contempt." Did he forget his TrueCrypt password?

Its a criminal case.,..which basically means if he judge requests a document that is encrypted on a hd than defendant cannot refuse or they are in contempt

I'm not familiar with US law.

In most European countries (that do not have specific crypto laws) you neither need to give the judge any information (except your name and address), nor help the prosecutor (i.e., the judge cannot order you to open a safe, but of course he can try to break the safe hismelf).

Re: TrueCrypt User Held in Contempt of Court

#33
So basically we have a guy in jail who is claiming something and making a public appeal. However, we can find little or no independent information about his case. He provides little information about his case. Indeed, the jail site containing his photo says Charges Unknown.

Let's not jump to conclusions just yet. He was arrested on April 14th. Find out the full case history, what was said, what he's accused of, etc.

It's entirely reasonable to assist anyone who's rights are being violated. But keep that separate from what he's accused of.

Re: TrueCrypt User Held in Contempt of Court

#35

Until the 5th amendment and encryption issues get worked out, these drives should delete themselves upon unauthorized access.

Here's an interesting discussion on the matter from a few months ago: http://news.ycombinator.com/item?id=1762157

It seems that the primary contention here is whether a password constitutes physical evidence, which must be supplied upon the production of the correct edicts, or whether it constitutes "testimony", which I interpret to mean non-recorded ideation or mental processes. Supposedly the same argument could apply to a safe combination, hence a defendant cannot be compelled to reveal a combo but can be compelled to open the safe. But how do we prove that the defendant has access to the safe? And how do we prove that the defendant has access to the encrypted files?

IANAL but this question particularly is of course interesting to me. At first glance it seems that the 5th Amendment guarantee against self-incrimination would preclude decrypting drives and I've read several proclamations to that effect, but when we consider the rules surrounding surrender of physical evidence, including evidence contained in a safe, it does become less clear where information cryptography fits.

If a defendant handwrites letters in a custom cipher, can he be compelled to reveal the cipher or decode the letter? Perhaps that's a better analog than the safe in our situation.

Re: TrueCrypt User Held in Contempt of Court

#36

Earlier quoted context omitted.

Fifth amendment and encryption issues are already worked out. Just like you can be compelled to open a safe, you can be compelled to decrypt a volume. A self-destroying drive would likely get you a conviction for obstructing justice, just like shredding the contents of a safe would.

A safe is obviously a safe. It obviously contains something. Encrypted data isn't so clear cut. It's trivial to make a datastore that has several encryption keys, so that you could give out one key, and it'd "decrypt" to some boring stuff, whilst keeping the real data, and the alternate key, secret. It'd also be trivial to devise a decryption algorithm, and key, which "decrypts" anyones hard drive to reveal illegal i…

Is it actually trivial to encrypt arbitrary text in such a way that it could be decrypted to the source text or a different but still meaningful alternate text? That sounds really hard to do. Is this indeed a solved problem and I just don't know about it?

Re: TrueCrypt User Held in Contempt of Court

#37
post #27
post #23

Earlier quoted context omitted.

Sympathy for a particular individual is irrelevant here. Some rights should apply to everyone, regardless of what they are accused of. I believe that the right to encryption belongs to this domain of fundamental rights.

You are correct. That does not however change the observation that an explanation of his charges is conspicuously absent.

So far, it's not clear at this point this guy has actually been charged with any criminal wrongdoing. From what I've seen on the forum, here, and reddit, there doesn't appear to be a criminal charge reported. It's entirely possible that he is being held in contempt due to some civil case.

What you're trying to do here is obvious, and I don't like it one bit. Everyone is innocent until proven guilty. You're trying to introduce bias, and shame on you for doing it.

Re: TrueCrypt User Held in Contempt of Court

#38
post #7

Earlier quoted context omitted.

"The user received a subpoena duces tecum requiring him to type the passwords or pass phrases necessary to produce the encrypted contents of drives seized 6 months earlier. The true crypt user has attempted to comply but he is still being held in contempt." Did he forget his TrueCrypt password?

In the forum post he says "Tell them that True Crypt can use more than just a password." Maybe he was using keyfiles?

[deleted]

Re: TrueCrypt User Held in Contempt of Court

#39

Until the 5th amendment and encryption issues get worked out, these drives should delete themselves upon unauthorized access.

Fifth amendment and encryption issues are already worked out. Just like you can be compelled to open a safe, you can be compelled to decrypt a volume. A self-destroying drive would likely get you a conviction for obstructing justice, just like shredding the contents of a safe would.

I wouldn't say this issue is fully "worked out" yet.

Disclaimer: I am not a lawyer. Most of what I know about this is from the last twenty minutes of googling.

In 2007 a federal judge ruled that passwords aren't like keys to a safe, and that the government can't force somebody to hand them over. (United States v. Boucher http://news.cnet.com/8301-13578_3-9834495-38.html )

However, that decision was partially overruled in 2009. ( http://www.bennettandbennett.com/node/5608 ) The judge ruled that the defendant didn't have to provide his password, but he did have to provide the contents on the hard drive. In other words, if the defendant happend to have an unencrypted copy of the hard drive hidden away somewhere he could have offered that in place of the password.

Using your safe analogy, it would be like saying that you don't have to provide the government with the key to the safe, but you do have to provide them with an identical copy of everything contained within the safe.

Now, like me you're probably wondering how the government could prove that the contents you provide from a secondary source really matches up with what's on the encrypted drive. The Boucher case mentioned above was unique because border control agents had already viewed the contents of the guy's laptop in unencrypted form, so they knew what to expect. (In his case, child porn.)

From what I can find, there don't appear to be any laws in the U.S. (and no case law) which specifically require people to hand over their passwords at the government's request.

Here are two more links I found which were helpful: http://volokh.com/files/BoucherDCT.1.pdf and http://en.wikipedia.org/wiki/United_States_v._Boucher

Re: TrueCrypt User Held in Contempt of Court

#40
A couple of points ; 1: He said he attempted to comply but was unsuccessful. So he already seems to have conceded the principle of a right to not decrypt. It's now analagous to a judge telling him to produce something, him agreeing, then claiming he lost it and the judge not believing him.

2: Someone in his position may have made the rational choice that it's better to spend some time in jail for contempt rather than a lengthy sentence for a criminal conviction. However here's a case where someone was held for 14 years for contempt!

http://abcnews.go.com/2020/story?id=8101209&page=1

Post reply on HN