Live data from Hacker News

UK anti-encryption law

falkvinge.net

101–110 of 198 posts

Re: UK anti-encryption law

#101

Earlier quoted context omitted.

Your point is usually true, when the system is working as intended. But it's not all that unusual for the gov't to really "have it in" for someone, but not be able to pin the crime on them, as with Al Capone. In his case, the government didn't think it could pin the true charges on him, so he was actually convicted on tax charges. The tax code is big, obscure, and no expert agrees on the detailed interpretation, so i…

Uk Judges are separate from the govenment. You would ahve to go back to the bad old days of the star chamber to find the UK law system doing anything as doddgy as Al Capone (not exactly the USAs Legal systems finest hour)

Here in the USA we like to periodically hold witch hunts. That's how we got Martha Stewart, for example.

Re: UK anti-encryption law

#102
post #86
post #78

Earlier quoted context omitted.

> Now question is - compression can be views as encryption. How does that pan out if you use a non-standard form of compression that does not require a key as the compression formula is the key in itself! GCHQ aren't idiots, and would be able to "decrypt" such toy crypto schemes. But, even if they couldn't be bothered to do so the law doesn't require only a key, but either a key or to make the data intelligible.

Nobody is saying GCHQ are idiots and I fail to see why you mention them. This is not about some "toy encryption schemes" it is a observation that as this law stands it there is no real way to say what is random and what is encrypted or in the case I point out - compressed. Now the whole argument of making the data intelligible is a completely different argument and gets back to how do you prove random data is actualy…

You say this:

> Now question is - compression can be views as encryption. How does that pan out if you use a non-standard form of compression that does not require a key as the compression formula is the key in itself!

You then ask why I mention GCHQ. I mention GCHQ because they control NTAC (National Technical Assistance Centre) - this is who will attempt to decrypt the data. This will happen in parallel to RIPA notices being issued.

If a person uses a non-standard form of compression and the police are interested there are two actions from police:

1) GCHQ trivially 'break the crypto'

2) A RIPA notice to make the data intelligible is issued, forcing the user to un-compress the data.

> Now the whole argument of making the data intelligible is a completely different argument

No, it really isn't. If you've encrypted it or compressed it or used steganography or used some simple code system to hide data they issue a notice and you have a limited amount of time to make the data intelligible.

> and gets back to how do you prove random data is actualy just that. You can't.

This is a different argument, and is not what you said.

Re: UK anti-encryption law

#104
post #11

Earlier quoted context omitted.

If you can write data to someone's hard drive it is simpler to just dump some child pornography.

I'm a bit disturbed that you suggest it's easier dump child porn onto somebody's hard drive than it is to dump a random bitstream onto the drive. It implies you've got a huge cache of it hanging around ready to go.

He means simpler as in "simpler to get them locked up" rather than "simpler to execute." Having lots of child porn is a sure fire way to go to prison, whereas as has been demonstrated in this thread, the laws surrounding this entropy-of-doom attack are convoluted and highly suspect.

Re: UK anti-encryption law

#105
post #96
post #20

Earlier quoted context omitted.

Yes. From the comments (credit to http://www.ktetch.co.uk/p/about-me.html ): "Funny thing about the RIPA act was that in 1999, when the act was first discussed, civil Liberties group Stand decided to show the problem. They sent an email to the Home Secretary (the minister for law and justice) containing a confession (source http://www.zdnet.com/surveillance-straw-petitioned-on-commer... ). That confession was encrypt…

> Yes, the law doesn’t actually apply to you is you’re the Home Secretary. Well, no. The law doesn't say 'if you have encrypted information you have to decrypt it'. It says 'if you have encrypted information you have to decrypt it if the police (or someone else with statutory powers to detain your property) require you to '. The HS wasn't required to. You can't just email someone an encrypted file and key, snap your…

But the email that was sent was a confession, so it was related to the open case and needed to be decrypted.

Re: UK anti-encryption law

#106
post #97

Earlier quoted context omitted.

Uk Judges are separate from the govenment. You would ahve to go back to the bad old days of the star chamber to find the UK law system doing anything as doddgy as Al Capone (not exactly the USAs Legal systems finest hour)

> Uk Judges are separate from the govenment. And how did that work out for the Guildford four for example? http://en.wikipedia.org/wiki/Guildford_Four_and_Maguire_Seve...

See also http://en.wikipedia.org/wiki/Alfred_Denning,_Baron_Denning#I...

Re: UK anti-encryption law

#107
post #96

Earlier quoted context omitted.

> Yes, the law doesn’t actually apply to you is you’re the Home Secretary. Well, no. The law doesn't say 'if you have encrypted information you have to decrypt it'. It says 'if you have encrypted information you have to decrypt it if the police (or someone else with statutory powers to detain your property) require you to '. The HS wasn't required to. You can't just email someone an encrypted file and key, snap your…

But the email that was sent was a confession, so it was related to the open case and needed to be decrypted.

The law doesn't work like that. It doesn't matter how important it is - if the police haven't given you a notice to decrypt it, the statute isn't engaged.

Re: UK anti-encryption law

#108

Earlier quoted context omitted.

>> they have to convince a judge that the allegations are true, and that getting the keys to your random noise will produce evidence You are correct. However, suppose you encrypt some data and forget the key, or you store some radio noise in a file, or whatever. Later, you are accused of a crime. The judge issues a warrant. The data/noise is now evidence against you. You are presumed guilty, and it is impossible to p…

No it's very easy. You claim the "key" is a one time pad, ie an XOR of the encrypted data - then you simply take the encrypted data and generate a "key" which XORs it into "the home secretary is a wonderful person and i support him"

So, perjury.

Re: UK anti-encryption law

#109

His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?

Here in Brazil is guaranteed by the constitution that no one can be forced to produce any evidence against him/herself. Isn't there something like this in the UK? You know... if someone says that you have ilegal encrypted data, they first would have to prove that it is really encrypted data and then that it is ilegal data.

There was a case where that defense was mounted, but failed [1]. The encryption keys were deemed to exist "separate from the will of the subject" i.e. they were deemed to be "physical". You can't use the defense against self-incrimination for physical keys either and the prosecution likened the encryption key to a physical key.

What hasn't been tested in court (afaik) is the refusal to hand over a passphrase that protects the encryption key. If the passphrase exists only in your head, it could be argued that it doesn't exist separate to your will.

[1] http://www.theregister.co.uk/2008/10/14/ripa_self_incriminat...

Re: UK anti-encryption law

#110
post #57

Earlier quoted context omitted.

I'm a bit disturbed that you suggest it's easier dump child porn onto somebody's hard drive than it is to dump a random bitstream onto the drive. It implies you've got a huge cache of it hanging around ready to go.

> It implies you've got a huge cache of it hanging > around ready to go. In the US at least, just a single image is illegal, so there is no need for a huge cache.

I imagine that a single image wouldn't quite motivate the police the same way that two gigabytes' worth would.
Post reply on HN