Live data from Hacker News

UK anti-encryption law

falkvinge.net

41–50 of 198 posts

Re: UK anti-encryption law

#41

In the section of the act mentioned (Regulation of Investigatory Powers Act 2000, part III), two of the defined terms are: “key”, in relation to any electronic data, means any key, code, password, algorithm or other data the use of which (with or without other keys)— (a)allows access to the electronic data, or (b)facilitates the putting of the data into an intelligible form; -- and -- “protected information” means an…

It was being discussed well before this, in the early 90s i went to a computer lab seminar about this and we asked

- we have Tb of data in our detector system that is either truely random (ie part of a Monte Carlo sim) or is essentially random (the detector noise), how do we prove this isn't encrypted.

Oh don't worry, said the nice man from the police computer unit - it's only going to be used against terrorists.

Re: UK anti-encryption law

#42
post #10

Earlier quoted context omitted.

The argument isn't totally correct. The Police can't just make allegations and force you to surrender keys - they have to convince a judge that the allegations are true, and that getting the keys to your random noise will produce evidence. RIPA is objectively flawed legislation, but it definitely doesn't "outlaw encryption" by anything less than a very long stretch of the imagination (as appears in this article).

>> they have to convince a judge that the allegations are true, and that getting the keys to your random noise will produce evidence You are correct. However, suppose you encrypt some data and forget the key, or you store some radio noise in a file, or whatever. Later, you are accused of a crime. The judge issues a warrant. The data/noise is now evidence against you. You are presumed guilty, and it is impossible to p…

No it's very easy. You claim the "key" is a one time pad, ie an XOR of the encrypted data - then you simply take the encrypted data and generate a "key" which XORs it into "the home secretary is a wonderful person and i support him"

Re: UK anti-encryption law

#43
Damn, the UK is pretty f'ed up - the list of things that British citizens can't enjoy compared to a lot of other countries (even developing ones) is growing every day.

Meanwhile, a criminal could easily just store everything on an encrypted microSD card, then eat it if anything goes wrong - the oldest trick in the book still works in the digital age :-D...

Re: UK anti-encryption law

#44
post #20

Earlier quoted context omitted.

Yes. From the comments (credit to http://www.ktetch.co.uk/p/about-me.html ): "Funny thing about the RIPA act was that in 1999, when the act was first discussed, civil Liberties group Stand decided to show the problem. They sent an email to the Home Secretary (the minister for law and justice) containing a confession (source http://www.zdnet.com/surveillance-straw-petitioned-on-commer... ). That confession was encrypt…

And the reply to that: "This argument is ridiculous, since it’s missing the concept of intent. The Home Secretary clearly had no intent. That’s why he/she wasn’t charged."

And the reply to that is that there is no criteria requiring intent in this law.

Re: UK anti-encryption law

#45

So, now Random actually /is/ Resistance? http://www.youtube.com/watch?v=aE6RtzwVdHI

Every time I listen to that song, I imagine a movie in my head where that is the theme song for a resistance movement.

Never really thought about how terrifying that might be in reality.

Re: UK anti-encryption law

#46
post #5

Earlier quoted context omitted.

Point being that there is a good posibility they will misfile it and in that case you have extingished your liability. Ticking of the police is not against the law and if enough people do it then the sillyness of things starts to stand out. That all said you can have a trusted friend who lives in another counry maintain your key and vice versa, then things get messy. Sad part about all this is criminals will find a w…

This is silly. If they misfile it, they'll ask for it again. If you say "I already gave it to you but you lost it, nyah nyah," they'll find you in contempt of court. For that matter, if you're in the middle of trial and give them what they asked, but in the most massively inconvenient way you can think of, they'll find you in contempt of court. Judges are not (usually) stupid.

There is nothing saying you can't then use the defence of you forgot the encryption key. Having previously provided it your obligation to the law is extinguished.

Judges are not stupid, not the easiest job to get and takes alot of work. They may not be experts in every feild they have to deal with though and in that they depend on expert witness's.

The point being that it is a silly flawed law and the approach I outlined is one which is just as silly, yet still compitulates with the letter of the law fully.

Now if your in a situation were you are having to defend raw random encrypted looking data that is just raw data, then is the onus upon yoruself to prove it's just random data and if not anybody could say its not encyrpted its random data, could they not?

Question is how should the law actualy handle the situation were some data from a criminal activity is encrypted and would requitre 1000 years to brute force? This law was a way to cover those situations. It's not perfect and in many respects is down right offencive. But it's like this - if you have nothing to hide then why should you be made to feel like a criminal. That is the real crux of the matter, though some people may view it entirely differently. Heck a badly spelt/grammer document could be deemed as hiding encrypted data when it is just bad spelling/grammer or it could actualy be encypted/obfiscated data hidden within the document. you just can't tell and that is were it starts to get realy realy messy.

Re: UK anti-encryption law

#47
post #10

Earlier quoted context omitted.

The argument isn't totally correct. The Police can't just make allegations and force you to surrender keys - they have to convince a judge that the allegations are true, and that getting the keys to your random noise will produce evidence. RIPA is objectively flawed legislation, but it definitely doesn't "outlaw encryption" by anything less than a very long stretch of the imagination (as appears in this article).

>> they have to convince a judge that the allegations are true, and that getting the keys to your random noise will produce evidence You are correct. However, suppose you encrypt some data and forget the key, or you store some radio noise in a file, or whatever. Later, you are accused of a crime. The judge issues a warrant. The data/noise is now evidence against you. You are presumed guilty, and it is impossible to p…

Why do you make the jump here to "you are presumed guilty"? Your guilt would have to be proved in a court just like for any other crime.

Are you suggesting that the courts would somehow just believe, with no evidence, that it's encrypted data relevant to the case and you're wilfully withholding the keys?

Re: UK anti-encryption law

#48

Damn, the UK is pretty f'ed up - the list of things that British citizens can't enjoy compared to a lot of other countries (even developing ones) is growing every day. Meanwhile, a criminal could easily just store everything on an encrypted microSD card, then eat it if anything goes wrong - the oldest trick in the book still works in the digital age :-D...

Add this to putting missiles on top of apartment blocks for the Olympics and I really have to agree with you.

Re: UK anti-encryption law

#49
post #18

Earlier quoted context omitted.

>> if you can prove it's not actually encrypted But that's the thing: you can't prove that. You're saying: "prove that there does not exist any decryption method or key that will turn this blob into incriminating data." You can never prove that such a decryption method doesn't exist. In fact, maybe it does exist? Given a blob of random data and infinite time, couldn't you find a way to "decrypt" that into pre-defined…

You can decrypt random data to anything if you want to. Say R is your random data and M is the message you want. Compute Key=R+M, then decrypt R-Key=M.

This argument is interesting because it both a) makes the law worthless and b) removes the "scary slippery slope" argument.

After all, if you can provide a key to anything, then all you have to do (whether it's encrypted financial documents or random noise) is say, "Yep, it's encrypted, here's the key, it's the text of the Wikipedia page for 'kittens.'"

Prove that's not the correct key. If the onus for producing a key (whether one exists or not) is on the defendant, isn't the onus for proving the validity of the decrypted file on the prosecution?

All this comes back to cases like the one from CA (I think) where the guy who refused to decrypt the evidence that would prove his guilt.

And from another perspective, if you're Bernie Madoff and the evidence that will convict you is encrypted, won't you refuse to decrypt with a smile and take the 2-year punishment (with $500M in the bank) over life for financial fraud (and bankruptcy)?

Re: UK anti-encryption law

#50

Damn, the UK is pretty f'ed up - the list of things that British citizens can't enjoy compared to a lot of other countries (even developing ones) is growing every day. Meanwhile, a criminal could easily just store everything on an encrypted microSD card, then eat it if anything goes wrong - the oldest trick in the book still works in the digital age :-D...

If they know you have it, destroying it is not really different in the eyes of the law than refusing to provide a key.
Post reply on HN