Live data from Hacker News

UK anti-encryption law

falkvinge.net

81–90 of 198 posts

Re: UK anti-encryption law

#81
>Yes, this is where the hairs rise on our arms: if you have a recorded file with radio noise from the local telescope that you use for generation of random numbers, and the police asks you to produce the decryption key to show them the three documents inside the encrypted container that your radio noise looks like, you will be sent to jail for up to five years for your inability to produce the imagined documents.

Of course, if you have access to the files, you could just XOR the noise with some innocuous documents, and send the result to the police saying it's a one-time-pad.

Re: UK anti-encryption law

#82
post #47

Earlier quoted context omitted.

Why do you make the jump here to "you are presumed guilty"? Your guilt would have to be proved in a court just like for any other crime. Are you suggesting that the courts would somehow just believe, with no evidence, that it's encrypted data relevant to the case and you're wilfully withholding the keys?

You are not presumed guilty. But you are found guilty of breaking the new law which comes with a 5 year prison term if you were accused of being involved with terrorism or hiding child porn. Regardless of any evidence.

> You are not presumed guilty. But you are found guilty of breaking the new law ... Regardless of any evidence.

"Being found guilty... regardless of evidence" makes no sense. Part of 'being found guilty of breaking the law' involves the prosecution giving evidence that a jury thinks proves your guilt beyond reasonable doubt (inc. proving that you were in possession of a key, and so that it was actually encrypted data). s.53(3).

Re: UK anti-encryption law

#83
post #32

Earlier quoted context omitted.

I'm a bit disturbed that you suggest it's easier dump child porn onto somebody's hard drive than it is to dump a random bitstream onto the drive. It implies you've got a huge cache of it hanging around ready to go.

I think he's saying it's easier to dump unencrypted vs encrypted.

The point was that it doesn't have to be real data, just random data.

Re: UK anti-encryption law

#84

His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?

Encrypted data, at least that encrypted with TrueCrypt, is distinguishable from random data. [1]

[1] http://superuser.com/questions/383526/is-a-normal-truecrypt-...

Re: UK anti-encryption law

#85
post #72

While it is obviously a bad law, it's not quite as bad as he's making out. s.53(3): " For the purposes of this section a person shall be taken to have shown that he was not in possession of a key to protected information at a particular time if— (a) sufficient evidence of that fact is adduced to raise an issue with respect to it; and (b) the contrary is not proved beyond a reasonable doubt. " In other words, if there…

This would still concern me. It isn't hard to imagine the police assuming any file they don't understand is that way because it is encrypted and, being that they are police and not scientists or engineers, that number could be quite high.

So now, you may actually know what's in that file. Great, no problems (other than the headache of dealing with explaining files in the first place).

The real danger is what if you don't know about the file, either? "I have no clue" is not going to cause reasonable doubt. The problem here is the law starts from a presumed guilt, which is problematic if you are, in fact, innocent.

But it really does come down to how the first clause of the law gets interpreted. Is it reasonably interpreted or not? I have lost faith in any chance of governments sticking to reasonableness when it comes to their threat of terrorism, protecting their "children", etc.

Re: UK anti-encryption law

#86
post #78
post #2

I stand by my argument that you can have a encryption key that is say 2000 characters long. Print it out 1 character per page and submit that in advance at your local police station, getting a receipt. You are then within the law. Now question is - compression can be views as encryption. How does that pan out if you use a non-standard form of compression that does not require a key as the compression formula is the k…

> Now question is - compression can be views as encryption. How does that pan out if you use a non-standard form of compression that does not require a key as the compression formula is the key in itself! GCHQ aren't idiots, and would be able to "decrypt" such toy crypto schemes. But, even if they couldn't be bothered to do so the law doesn't require only a key, but either a key or to make the data intelligible.

Nobody is saying GCHQ are idiots and I fail to see why you mention them.

This is not about some "toy encryption schemes" it is a observation that as this law stands it there is no real way to say what is random and what is encrypted or in the case I point out - compressed. Now the whole argument of making the data intelligible is a completely different argument and gets back to how do you prove random data is actualy just that. You can't.

Good encyption with have entropy akin to random data. Also a compressed file will have the entropy of poorly encypted data.

   Data is just that, data.  Intelligble data is information and is not data.  Big difference and in that any data set is random without meaning/interpritation.

Re: UK anti-encryption law

#87

Damn, the UK is pretty f'ed up - the list of things that British citizens can't enjoy compared to a lot of other countries (even developing ones) is growing every day. Meanwhile, a criminal could easily just store everything on an encrypted microSD card, then eat it if anything goes wrong - the oldest trick in the book still works in the digital age :-D...

I was under the impression that key disclosure laws are present in many countries.

Even in the US, with amendments against self-incrimination, if the authorities already know you have encrypted some incriminating data, you can be ordered to hand over the key.

  In the Colorado case, the police had intercepted a 
  telephone conversation in which the defendant, Ramona F.,
  acknowledged her ownership of the laptop and alluded to
  the existence of incriminating documents in the encrypted
  portions of the hard drive.

  ...

  I conclude that the Fifth Amendment is not implicated by 
  requiring production of the unencrypted contents of the
  Toshiba Satellite M305 laptop computer.
http://en.wikipedia.org/wiki/Key_disclosure_law#Legislation_...

Though you are right that the law in the UK seems very strict. As an international banker I would be weary bringing a master key or encrypted volume into the UK.

Re: UK anti-encryption law

#88

Roll on dual encryption. One key renders a dissertation on kittens, the other renders the original clear-text. Next problem?

It'll get more complicated later I'm sure, but yeah, that's the current patch. Except replace "dissertation on kittens" with "gay porn collection" (or "straight porn collection" if you're publicly gay. or whatever else makes good sense to encrypt, but is still perfectly legal).

Re: UK anti-encryption law

#89

In the section of the act mentioned (Regulation of Investigatory Powers Act 2000, part III), two of the defined terms are: “key”, in relation to any electronic data, means any key, code, password, algorithm or other data the use of which (with or without other keys)— (a)allows access to the electronic data, or (b)facilitates the putting of the data into an intelligible form; -- and -- “protected information” means an…

It was being discussed well before this, in the early 90s i went to a computer lab seminar about this and we asked - we have Tb of data in our detector system that is either truely random (ie part of a Monte Carlo sim) or is essentially random (the detector noise), how do we prove this isn't encrypted. Oh don't worry, said the nice man from the police computer unit - it's only going to be used against terrorists.

That is in practice the intention, though as it is a law on the book's it is open to be abused down the line against non-terroists.

As a rule the UK police tend to have alot of common sence, but they are also human. That all said the whole blackberry encryption affair recently arising due to the riots does highlight further shortcommings.

Still this law was instigated prior to 9/11 and in that you do wonder what it would look like if it was instigated after the event and how it may of looked.

Re: UK anti-encryption law

#90

His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?

There have been cases about this though and judges so far have not always bought this argument. There was a case I read about where someoen was using full disk encryption. He said he gave police his password but it didn't work. The judge dismissed the charges because of the difficulty proving that the key produced wasn't correct but that the hard drive was not corrupt, among other things.

Yes, but the chances of proving such nebulous ideas change greatly if you can be demonized in the public eye.
Post reply on HN