What would happen if there is encrypted data on your system but you didn't set the key yourself? For example DRM systems usually work by encrypting data and trying their best to make sure you never acquire the key.
UK anti-encryption law
141–150 of 198 posts
Re: UK anti-encryption law
#142His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?
Re: UK anti-encryption law
#143While it is obviously a bad law, it's not quite as bad as he's making out. s.53(3): " For the purposes of this section a person shall be taken to have shown that he was not in possession of a key to protected information at a particular time if— (a) sufficient evidence of that fact is adduced to raise an issue with respect to it; and (b) the contrary is not proved beyond a reasonable doubt. " In other words, if there…
Re: UK anti-encryption law
#144Re: UK anti-encryption law
#145Earlier quoted context omitted.
There have been cases about this though and judges so far have not always bought this argument. There was a case I read about where someoen was using full disk encryption. He said he gave police his password but it didn't work. The judge dismissed the charges because of the difficulty proving that the key produced wasn't correct but that the hard drive was not corrupt, among other things.
Yes, but the chances of proving such nebulous ideas change greatly if you can be demonized in the public eye.
Re: UK anti-encryption law
#146Earlier quoted context omitted.
If you can write data to someone's hard drive it is simpler to just dump some child pornography.
OK, but suppose you're trying to frame them for bank fraud. Coming up with incriminating data is a lot trickier than just making it look like they have something .
Re: UK anti-encryption law
#147His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?
My dark side is thinking of a virus, let's call it YouGoToJail, that encrypts a file (say with gunpg - 4mb and works on all OSes) with a random very long password. The virus then deletes all traces to itself. You go to jail!
Re: UK anti-encryption law
#148Earlier quoted context omitted.
Well, if I remember right, the UK had their "fair share" of terror (IRA), long before the US suffered from 9/11. So this argumentation does not strike me so extraordinary. But that does not change the point, that this law really has the possibility to be misused.
Yes but remarkably after 100years of bombings and assassinations by the IRA the response was to carry on as normal, don't give in to them. The only visible sign was removing litter bins from railway stations and some checkpoints on vehicles enter the financial district of London Yet 5 minutes after the 9/11 attacks on America the UK suddenly needed a whole raft of laws to intercept all phone calls, hold people withou…
And considering how "comprehensive" it was, I'd say it was already written up and shelved for a crisis like that. I'm not much for the whole conspiracy theory stuff, but that just seems fairly obvious.
Re: UK anti-encryption law
#149Assuming this article is true (which I am pretty skeptical of, I live in the UK and never hear about people being jailed for not giving up an encryption key). What would happen if there is encrypted data on your system but you didn't set the key yourself? For example DRM systems usually work by encrypting data and trying their best to make sure you never acquire the key.
Re: UK anti-encryption law
#150I have to wonder if this would ever hold up in court. I don't know much about the UK justice system, but in America it would be pretty rare to be convicted of a crime that they can't actually prove you committed. You could be jailed for refusing to comply with a court order to decrypt the file, but if you can prove it's not actually encrypted, they can't do anything about it.