Live data from Hacker News

UK anti-encryption law

falkvinge.net

51–60 of 198 posts

Re: UK anti-encryption law

#51
post #30

It is impossible to prove a PRNG'ed file is or is not encrypted data. TrueCrypt volumes look identical to `dd if=/dev/urandom of=file.bin bs=512`. Create a few of each and then evaluate them using ent to see this for yourself. Edit: Link to ent http://www.fourmilab.ch/random/ You could prove the file is encrypted if it is indeed encrypted and you have the passphrase and the program to decrypt it, but outside of that,…

The original UK phrasing of the law was even sillier. They had taken into account codes as well as cyphers. You could be forced to explain the meaning of any other messages such as "the geese fly south for the winter" .

But the wording was ridiculous, something about any hidden or private meaning in any otherwise innocuous text.

So if you happened to have a book of poetry around the police could compel you to explain the symbolism! Heaven help you if you had a Torah and they asked you to explain any "hidden meanings"

Re: UK anti-encryption law

#52

I have to wonder if this would ever hold up in court. I don't know much about the UK justice system, but in America it would be pretty rare to be convicted of a crime that they can't actually prove you committed. You could be jailed for refusing to comply with a court order to decrypt the file, but if you can prove it's not actually encrypted, they can't do anything about it.

>> if you can prove it's not actually encrypted But that's the thing: you can't prove that. You're saying: "prove that there does not exist any decryption method or key that will turn this blob into incriminating data." You can never prove that such a decryption method doesn't exist. In fact, maybe it does exist? Given a blob of random data and infinite time, couldn't you find a way to "decrypt" that into pre-defined…

To all the people commenting about how you can't prove it: in America, proof means "beyond a reasonable doubt". If you really did have random radio telescope data, the prosecution would have to prove beyond a reasonable doubt that your random data is actually encrypted. The proof for the defense would be called an alibi, wherein you would just say where you downloaded it from and what you used it for.

You don't need to prove that it could never be decrypted, you need to provide an alibi and then the prosecution needs to prove beyond a reasonable doubt that your alibi doesn't hold true. Your alibi is your proof.

Re: UK anti-encryption law

#53
post #20

Earlier quoted context omitted.

Yes. From the comments (credit to http://www.ktetch.co.uk/p/about-me.html ): "Funny thing about the RIPA act was that in 1999, when the act was first discussed, civil Liberties group Stand decided to show the problem. They sent an email to the Home Secretary (the minister for law and justice) containing a confession (source http://www.zdnet.com/surveillance-straw-petitioned-on-commer... ). That confession was encrypt…

And the reply to that: "This argument is ridiculous, since it’s missing the concept of intent. The Home Secretary clearly had no intent. That’s why he/she wasn’t charged."

And the reply to that:

The UK law in question does not require intent (mens rea).

Re: UK anti-encryption law

#54
post #27
post #18

Earlier quoted context omitted.

You can decrypt random data to anything if you want to. Say R is your random data and M is the message you want. Compute Key=R+M, then decrypt R-Key=M.

Assuming the encryption method can create the bit sequence that is the random data. It very well might not. There may be gaps in the encrypted data's number space. For any non-trivial encryption method, you'd be brute forcing your way through a bunch of them to find the key that can decrypt the random noise to that message. Typical "20 times longer than the existence of the universe" warnings apply. :)

But the encryption method doesn't need to be non-trivial, especially when you define key as anything that

  (a)allows access to the electronic data, or
  (b)facilitates the putting of the data into an intelligible form;

Re: UK anti-encryption law

#55
post #20

Earlier quoted context omitted.

Yes. From the comments (credit to http://www.ktetch.co.uk/p/about-me.html ): "Funny thing about the RIPA act was that in 1999, when the act was first discussed, civil Liberties group Stand decided to show the problem. They sent an email to the Home Secretary (the minister for law and justice) containing a confession (source http://www.zdnet.com/surveillance-straw-petitioned-on-commer... ). That confession was encrypt…

And the reply to that: "This argument is ridiculous, since it’s missing the concept of intent. The Home Secretary clearly had no intent. That’s why he/she wasn’t charged."

It appears that way. Mens rea is a legal concept applied to some of common law (although not always effectively).

http://en.wikipedia.org/wiki/Mens_rea#England

EDIT: British common law divides up laws between those requiring intent and those that don't.

Re: UK anti-encryption law

#56

His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?

There have been cases about this though and judges so far have not always bought this argument. There was a case I read about where someoen was using full disk encryption. He said he gave police his password but it didn't work. The judge dismissed the charges because of the difficulty proving that the key produced wasn't correct but that the hard drive was not corrupt, among other things.

That's BRILLIANT.

"I gave you the correct key, you morons, why have you fucked my hard drive?"

I live in the UK. This law, like all other dumb laws, will simply show the police up in court. Judges are smarter than you think - and they HATE crap laws.

Re: UK anti-encryption law

#57
post #11

Earlier quoted context omitted.

If you can write data to someone's hard drive it is simpler to just dump some child pornography.

I'm a bit disturbed that you suggest it's easier dump child porn onto somebody's hard drive than it is to dump a random bitstream onto the drive. It implies you've got a huge cache of it hanging around ready to go.

  > It implies you've got a huge cache of it hanging
  > around ready to go.
In the US at least, just a single image is illegal, so there is no need for a huge cache.

Re: UK anti-encryption law

#58
post #39
post #5

Earlier quoted context omitted.

Point being that there is a good posibility they will misfile it and in that case you have extingished your liability. Ticking of the police is not against the law and if enough people do it then the sillyness of things starts to stand out. That all said you can have a trusted friend who lives in another counry maintain your key and vice versa, then things get messy. Sad part about all this is criminals will find a w…

Ticking of the police is not against the law No, but wasting police time is.

Very true but not when they waste there own time. Personly it is a silly law made out of panic and in that is flawed. My approach just highlights the sillyness of the law in itself. I love the police but there again I don't break the law.

The point being that whilst your obligated to provide the key, there is nothing saying how that key is provided and that is another flaw in a flawed law. Though some people are taking it too literaly I suspect.

Until there is a case of this law being used to actualy procecute somebody unfairly and unjustly then it is hard to argue it's flaws, but we all see those flaws and shortcommings, like many things in life. Nothing is perfect.

Re: UK anti-encryption law

#59
Every digital storage device on earth should contain a randomly sized random data file called RANDOM-DATA. The user of said device could optionally replace this file with encrypted data. Once critical mass is achieved, states that do not respect individual liberty would have no way of determining the nature of every RANDOM-DATA file that they obtain by eavesdropping, theft or force.

I know the answer to this is 'easier said that done'. Certainly hardware and OS vendors can't be trusted with this task. Maybe FOSS installers could educate users and optionally create the file? How can we make this happen? I want to wear a t-shirt that says 'random numbers save lives.'

Re: UK anti-encryption law

#60
post #11

Earlier quoted context omitted.

If you can write data to someone's hard drive it is simpler to just dump some child pornography.

If you're caught though the consequences are terrible whilst encrypted Shakespeare given names to look like something illegal would only really have you under unauthorized access charges.

I don't know. I would think that attempting to frame someone with it shows some amount of malicious intent. There's got to be something else to charge them with other then the equivalent of "breaking and entering" to plant evidence.
Post reply on HN