Damn, the UK is pretty f'ed up - the list of things that British citizens can't enjoy compared to a lot of other countries (even developing ones) is growing every day. Meanwhile, a criminal could easily just store everything on an encrypted microSD card, then eat it if anything goes wrong - the oldest trick in the book still works in the digital age :-D...
Add this to putting missiles on top of apartment blocks for the Olympics and I really have to agree with you.
UK anti-encryption law
71–80 of 198 posts
Re: UK anti-encryption law
#72s.53(3):
"For the purposes of this section a person shall be taken to have shown that he was not in possession of a key to protected information at a particular time if—
(a) sufficient evidence of that fact is adduced to raise an issue with respect to it; and
(b) the contrary is not proved beyond a reasonable doubt."
In other words, if there's evidence for there to be 'an issue' about whether you actually do have a key (or whether e.g. it's just random noise), it's up to the prosecution to prove beyond reasonable doubt that it is actually data, and you do have the key.
So the flowchart is:
- If the police can prove they have reasonable grounds to believe that something is encrypted data that you have the key to, then
- That raises an evidential presumption that you do have it, which you can rebut by
- adducing evidence that just has to raise an issue about whether you have a key (inc. whether it's encrypted data at all), in which case the police have to
- Prove beyond reasonable doubt that it is encrypted, and you do have the key.
(IANAL)
Re: UK anti-encryption law
#73Earlier quoted context omitted.
You can decrypt random data to anything if you want to. Say R is your random data and M is the message you want. Compute Key=R+M, then decrypt R-Key=M.
Assuming the encryption method can create the bit sequence that is the random data. It very well might not. There may be gaps in the encrypted data's number space. For any non-trivial encryption method, you'd be brute forcing your way through a bunch of them to find the key that can decrypt the random noise to that message. Typical "20 times longer than the existence of the universe" warnings apply. :)
Re: UK anti-encryption law
#74Earlier quoted context omitted.
The argument isn't totally correct. The Police can't just make allegations and force you to surrender keys - they have to convince a judge that the allegations are true, and that getting the keys to your random noise will produce evidence. RIPA is objectively flawed legislation, but it definitely doesn't "outlaw encryption" by anything less than a very long stretch of the imagination (as appears in this article).
Your point is usually true, when the system is working as intended. But it's not all that unusual for the gov't to really "have it in" for someone, but not be able to pin the crime on them, as with Al Capone. In his case, the government didn't think it could pin the true charges on him, so he was actually convicted on tax charges. The tax code is big, obscure, and no expert agrees on the detailed interpretation, so i…
You would ahve to go back to the bad old days of the star chamber to find the UK law system doing anything as doddgy as Al Capone (not exactly the USAs Legal systems finest hour)
Re: UK anti-encryption law
#75His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?
Isn't there something like this in the UK? You know... if someone says that you have ilegal encrypted data, they first would have to prove that it is really encrypted data and then that it is ilegal data.
Re: UK anti-encryption law
#76I don't like or support the legislation - but I think this is a bit of an over-reaction. The law as I understand it says that if you've got data (and the context of the law is in focussed primarily on targeting terrorism, child-porn etc) that you've encrypted but refuse to give over the encryption keys to; then if the police then convince a judge that there is valuable evidence in the encrypted data, and you still re…
> Police argue the files "could be child pornography, there could be bomb-making recipes."
Note that he was in prison -serving a sentence- but has since been transferred to a secure mental health hospital where he can be detained under the MHA until he is well.
I don't know if he had an appropriate adult with him at any police interviews. I don't know if he had any legal representation at any time. These are weaknesses in the UK system.
Re: UK anti-encryption law
#77I don't like or support the legislation - but I think this is a bit of an over-reaction. The law as I understand it says that if you've got data (and the context of the law is in focussed primarily on targeting terrorism, child-porn etc) that you've encrypted but refuse to give over the encryption keys to; then if the police then convince a judge that there is valuable evidence in the encrypted data, and you still re…
what kind of person has a file of random (or near enough to not be able to tell without 32gb of them) numbers?
Any cryptographer? Many astronomers? Physicists? Better lock them all up!
Re: UK anti-encryption law
#78I stand by my argument that you can have a encryption key that is say 2000 characters long. Print it out 1 character per page and submit that in advance at your local police station, getting a receipt. You are then within the law. Now question is - compression can be views as encryption. How does that pan out if you use a non-standard form of compression that does not require a key as the compression formula is the k…
GCHQ aren't idiots, and would be able to "decrypt" such toy crypto schemes. But, even if they couldn't be bothered to do so the law doesn't require only a key, but either a key or to make the data intelligible.
Re: UK anti-encryption law
#79Earlier quoted context omitted.
If you can write data to someone's hard drive it is simpler to just dump some child pornography.
I'm a bit disturbed that you suggest it's easier dump child porn onto somebody's hard drive than it is to dump a random bitstream onto the drive. It implies you've got a huge cache of it hanging around ready to go.
And getting onto the darknet is but a simple download away...
Re: UK anti-encryption law
#80Damn, the UK is pretty f'ed up - the list of things that British citizens can't enjoy compared to a lot of other countries (even developing ones) is growing every day. Meanwhile, a criminal could easily just store everything on an encrypted microSD card, then eat it if anything goes wrong - the oldest trick in the book still works in the digital age :-D...
Add this to putting missiles on top of apartment blocks for the Olympics and I really have to agree with you.