Live data from Hacker News

UK anti-encryption law

falkvinge.net

31–40 of 198 posts

Re: UK anti-encryption law

#31

His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?

There have been cases about this though and judges so far have not always bought this argument.

There was a case I read about where someoen was using full disk encryption. He said he gave police his password but it didn't work. The judge dismissed the charges because of the difficulty proving that the key produced wasn't correct but that the hard drive was not corrupt, among other things.

Re: UK anti-encryption law

#32
post #11

Earlier quoted context omitted.

If you can write data to someone's hard drive it is simpler to just dump some child pornography.

I'm a bit disturbed that you suggest it's easier dump child porn onto somebody's hard drive than it is to dump a random bitstream onto the drive. It implies you've got a huge cache of it hanging around ready to go.

I think he's saying it's easier to dump unencrypted vs encrypted.

Re: UK anti-encryption law

#33
post #20

Earlier quoted context omitted.

Yes. From the comments (credit to http://www.ktetch.co.uk/p/about-me.html ): "Funny thing about the RIPA act was that in 1999, when the act was first discussed, civil Liberties group Stand decided to show the problem. They sent an email to the Home Secretary (the minister for law and justice) containing a confession (source http://www.zdnet.com/surveillance-straw-petitioned-on-commer... ). That confession was encrypt…

And the reply to that: "This argument is ridiculous, since it’s missing the concept of intent. The Home Secretary clearly had no intent. That’s why he/she wasn’t charged."

So a law which you have to prove yourself innocent and can be applied to anyone - but the police get to decide who to apply it to.

nope, can't see any problem with that.

Re: UK anti-encryption law

#34

I have to wonder if this would ever hold up in court. I don't know much about the UK justice system, but in America it would be pretty rare to be convicted of a crime that they can't actually prove you committed. You could be jailed for refusing to comply with a court order to decrypt the file, but if you can prove it's not actually encrypted, they can't do anything about it.

At least one person in the UK has been sent to prison for refusal to reveal passwords to encrypted data that I'm aware of: http://www.theregister.co.uk/2009/11/24/ripa_jfl/

These were PGP encrypted filesystems though, not random data.

Re: UK anti-encryption law

#36
post #11

His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?

If you can write data to someone's hard drive it is simpler to just dump some child pornography.

If you're caught though the consequences are terrible whilst encrypted Shakespeare given names to look like something illegal would only really have you under unauthorized access charges.

Re: UK anti-encryption law

#37

Earlier quoted context omitted.

>> if you can prove it's not actually encrypted But that's the thing: you can't prove that. You're saying: "prove that there does not exist any decryption method or key that will turn this blob into incriminating data." You can never prove that such a decryption method doesn't exist. In fact, maybe it does exist? Given a blob of random data and infinite time, couldn't you find a way to "decrypt" that into pre-defined…

It's really quite simple. Just xor it with some publicly available text, and then present the result of that xor as the "encryption key". When you xor that result with the original data, you get the publicly available text back.

And if that works, the prosecution can xor it with some incriminating text...

Re: UK anti-encryption law

#38
post #12

His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?

Well if you find yourself being asked for the encryption key for /dev/rand then you know things are pretty messed up. Given the technology intellegence of some law makers I do wonder when that day will come about.

actually when I read /dev/urandom I get a much larger stream of data. I think /dev/random is corrupted becuase it hangs after a bit when I try to read. So please hand over the key for /dev/urandom..... ;-)

Re: UK anti-encryption law

#39
post #5

Earlier quoted context omitted.

>> You are then within the law. What good does your maneuver do? Now you have to work with that key, and if they really care, they can laboriously type it in. All you've done is tick them off, right?

Point being that there is a good posibility they will misfile it and in that case you have extingished your liability. Ticking of the police is not against the law and if enough people do it then the sillyness of things starts to stand out. That all said you can have a trusted friend who lives in another counry maintain your key and vice versa, then things get messy. Sad part about all this is criminals will find a w…

Ticking of the police is not against the law

No, but wasting police time is.

Post reply on HN