Live data from Hacker News

UK anti-encryption law

falkvinge.net

91–100 of 198 posts

Re: UK anti-encryption law

#91
post #72

While it is obviously a bad law, it's not quite as bad as he's making out. s.53(3): " For the purposes of this section a person shall be taken to have shown that he was not in possession of a key to protected information at a particular time if— (a) sufficient evidence of that fact is adduced to raise an issue with respect to it; and (b) the contrary is not proved beyond a reasonable doubt. " In other words, if there…

This would still concern me. It isn't hard to imagine the police assuming any file they don't understand is that way because it is encrypted and, being that they are police and not scientists or engineers, that number could be quite high. So now, you may actually know what's in that file. Great, no problems (other than the headache of dealing with explaining files in the first place). The real danger is what if you d…

> It isn't hard to imagine the police assuming any file they don't understand is that way because it is encrypted

True, but they have to prove they have reasonable grounds for believing, not just that it's encrypted, but also that you have the key to it.

> "I have no clue" is not going to cause reasonable doubt

It doesn't need to cause reasonable doubt, it just has to raise an issue about whether or not you have they key. In which case the police have to prove you do beyond reasonable doubt.

But you are right - it is ambiguous, and that evidential presumption is in danger of being interpreted in a very anti-defendant way.

But:

> I have lost faith in any chance of governments sticking to reasonableness

Thankfully, it's not up to the government to interpret legislation, it's up to the courts. And they have to interpret criminal legislation (a) in favour of the defendant (common law principle), and (b) compatibly with the human rights act.

That second one is powerful, and has resulted in anti-defendant statues being interpreted almost out of all recognition by a court happy to interpret stuff compatibly with the HRA right to a fair trial. See e.g. http://www.guardian.co.uk/uk/2001/may/18/lords.politics .

Re: UK anti-encryption law

#92
post #64

I don't like or support the legislation - but I think this is a bit of an over-reaction. The law as I understand it says that if you've got data (and the context of the law is in focussed primarily on targeting terrorism, child-porn etc) that you've encrypted but refuse to give over the encryption keys to; then if the police then convince a judge that there is valuable evidence in the encrypted data, and you still re…

Well, most people with old VHS tapes have several GB of noise lying around.

Re: UK anti-encryption law

#93

Damn, the UK is pretty f'ed up - the list of things that British citizens can't enjoy compared to a lot of other countries (even developing ones) is growing every day. Meanwhile, a criminal could easily just store everything on an encrypted microSD card, then eat it if anything goes wrong - the oldest trick in the book still works in the digital age :-D...

If they know you have it, destroying it is not really different in the eyes of the law than refusing to provide a key.

This sounds very 1984. If the police says you have encrypted data, how can they prove it really is encrypted data? Besides, how can they prove that you do have the keys for the hypothetical encrypted data?

It sounds absurd that you have to prove your innocence. It is common principle that who accuses is responsible for proving your guilty. Besides, even in the remote situation where they could prove somehow that a pile of random bits held some confidential data, no one should be acused of not deciphering it to provide proof against himself. It sounds like inquisition :) If you deny having a deal with the devil you die, and if you confess it, you die too.

Re: UK anti-encryption law

#94
post #48

Earlier quoted context omitted.

Add this to putting missiles on top of apartment blocks for the Olympics and I really have to agree with you.

I think you guys need to stop believing everything you read.

The missiles are stationed in 6 areas in London.

Whether they'll be used is another matter. People were asking "what's the difference between a plane that has been crashed into London and a plane that has been shot down over London?", to which the reply is "a plane that is shot down is, effectively, disintegrated and burnt in the air, leaving small fragments to scatter."

http://www.bbc.co.uk/news/uk-18766547

Re: UK anti-encryption law

#95
post #64

I don't like or support the legislation - but I think this is a bit of an over-reaction. The law as I understand it says that if you've got data (and the context of the law is in focussed primarily on targeting terrorism, child-porn etc) that you've encrypted but refuse to give over the encryption keys to; then if the police then convince a judge that there is valuable evidence in the encrypted data, and you still re…

With respect, the attitude above is the problem. The point is to never give them an inch, as they'll use it to take a mile. It goes against the very foundation of modern justice, innocent until proven guilty.

Re: UK anti-encryption law

#96
post #20

His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?

Yes. From the comments (credit to http://www.ktetch.co.uk/p/about-me.html ): "Funny thing about the RIPA act was that in 1999, when the act was first discussed, civil Liberties group Stand decided to show the problem. They sent an email to the Home Secretary (the minister for law and justice) containing a confession (source http://www.zdnet.com/surveillance-straw-petitioned-on-commer... ). That confession was encrypt…

> Yes, the law doesn’t actually apply to you is you’re the Home Secretary.

Well, no. The law doesn't say 'if you have encrypted information you have to decrypt it'. It says 'if you have encrypted information you have to decrypt it if the police (or someone else with statutory powers to detain your property) require you to'. The HS wasn't required to.

You can't just email someone an encrypted file and key, snap your fingers, and have them be breaking the law. They have to actually refuse to comply with a notice.

Yes, it's a stupid law, but this stunt doesn't actually show anything.

Re: UK anti-encryption law

#97

Earlier quoted context omitted.

Your point is usually true, when the system is working as intended. But it's not all that unusual for the gov't to really "have it in" for someone, but not be able to pin the crime on them, as with Al Capone. In his case, the government didn't think it could pin the true charges on him, so he was actually convicted on tax charges. The tax code is big, obscure, and no expert agrees on the detailed interpretation, so i…

Uk Judges are separate from the govenment. You would ahve to go back to the bad old days of the star chamber to find the UK law system doing anything as doddgy as Al Capone (not exactly the USAs Legal systems finest hour)

>Uk Judges are separate from the govenment.

And how did that work out for the Guildford four for example?

http://en.wikipedia.org/wiki/Guildford_Four_and_Maguire_Seve...

Re: UK anti-encryption law

#98

His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?

Encrypted data, at least that encrypted with TrueCrypt, is distinguishable from random data. [1] [1] http://superuser.com/questions/383526/is-a-normal-truecrypt-...

Says down below that it isn't: http://news.ycombinator.org/item?id=4234959

Re: UK anti-encryption law

#99
post #18

Earlier quoted context omitted.

>> if you can prove it's not actually encrypted But that's the thing: you can't prove that. You're saying: "prove that there does not exist any decryption method or key that will turn this blob into incriminating data." You can never prove that such a decryption method doesn't exist. In fact, maybe it does exist? Given a blob of random data and infinite time, couldn't you find a way to "decrypt" that into pre-defined…

You can decrypt random data to anything if you want to. Say R is your random data and M is the message you want. Compute Key=R+M, then decrypt R-Key=M.

This is why OTP encryption is unbreakable.

http://en.wikipedia.org/wiki/One_time_pad

Re: UK anti-encryption law

#100

Earlier quoted context omitted.

Your point is usually true, when the system is working as intended. But it's not all that unusual for the gov't to really "have it in" for someone, but not be able to pin the crime on them, as with Al Capone. In his case, the government didn't think it could pin the true charges on him, so he was actually convicted on tax charges. The tax code is big, obscure, and no expert agrees on the detailed interpretation, so i…

Uk Judges are separate from the govenment. You would ahve to go back to the bad old days of the star chamber to find the UK law system doing anything as doddgy as Al Capone (not exactly the USAs Legal systems finest hour)

Uk Judges are separate from the govenment.

In the UK, the term "government" refers to the executive branch. Outside that use, it encompasses the legislative, executive and judiciary power of a state. Wikipedia gives the following definition:

Government consists of the legislators, administrators, and arbitrators in the administrative bureaucracy who control a state at a given time, and the system by which they are organized.

Judges are part of that by definition, even if there's some separation from the other components.

Post reply on HN