Live data from Hacker News

UK anti-encryption law

falkvinge.net

151–160 of 198 posts

Re: UK anti-encryption law

#151
post #64

I don't like or support the legislation - but I think this is a bit of an over-reaction. The law as I understand it says that if you've got data (and the context of the law is in focussed primarily on targeting terrorism, child-porn etc) that you've encrypted but refuse to give over the encryption keys to; then if the police then convince a judge that there is valuable evidence in the encrypted data, and you still re…

This is the reaction that is going to destroy all of our civil liberties. "It's only a problem if you're guilty." what kind of person has a file of random (or near enough to not be able to tell without 32gb of them) numbers? Any cryptographer? Many astronomers? Physicists? Better lock them all up!

Me. I was just recently curious how base64 encoded data would compress (gzip) compared to non-base64 encoded data. I tried it out on a few types of input, including random bytes. It was not, of course, 32gb, but it was large enough it could have been my nefarious plans or not-tiny collection of child porn images or whatever. It doesn't have to be huge to be important - an encrypted file listing a few hundred account numbers could be vital to a money laundering investigation or whatever.

Re: UK anti-encryption law

#153

Earlier quoted context omitted.

Not sure you can commit perjury if you are the accused !

In the US you can, and I'd be surprised if many other jurisdictions saw it differently. In the US you have a right against self incrimination, not a right to lie and misdirect. See Martha Stewart as an example, part of her conviction was making false statements to an investigator.

Martha "Stewart was found guilty in March 2004 of conspiracy, obstruction of an agency proceeding, and making false statements to federal investigator". The lying to investigators was most of her "crime". If she'd told them to talk to her lawyer and clammed up, she'd have been way ahead. The Feds never did prove securities fraud.

https://en.wikipedia.org/wiki/Martha_Stewart#Stock_trading_c...

Re: UK anti-encryption law

#154
Can you say, "Who is John Galt?"

Eventually the preposterous laws drive those with mobility to simply leave. Follow that to it's logical conclusion; the UK will make it difficult to impossible to leave with your assets intact. Loss of privacy is a just a precursor to loss of private property altogether.

Re: UK anti-encryption law

#155
post #119

Earlier quoted context omitted.

Fortunately its nowhere near that bad. The prosecution needs to prove beyond reasonable doubt that the file contains encrypted data and that you have the key. So if you did have a file of random noise then the police would not be able to prove these things. And if you had software for using that file as a random number stream then that would be evidence in your defence. Remember, its for the police to prove your guil…

> (and in that scenario it would be a lot easier to frame someone by simply writing some child porn). Well, you'd have to get some child porn to frame someone that way. Random data is much easier to procure.

Sadly not by much.

Re: UK anti-encryption law

#156

Earlier quoted context omitted.

Well, if I remember right, the UK had their "fair share" of terror (IRA), long before the US suffered from 9/11. So this argumentation does not strike me so extraordinary. But that does not change the point, that this law really has the possibility to be misused.

Yes but remarkably after 100years of bombings and assassinations by the IRA the response was to carry on as normal, don't give in to them. The only visible sign was removing litter bins from railway stations and some checkpoints on vehicles enter the financial district of London Yet 5 minutes after the 9/11 attacks on America the UK suddenly needed a whole raft of laws to intercept all phone calls, hold people withou…

IRA terrorism was pretty extensive too. They murdered close members of the UK royal family (http://en.wikipedia.org/wiki/Louis_Mountbatten,_1st_Earl_Mou...), major damage to cities (http://en.wikipedia.org/wiki/1996_Manchester_bombing) and actual mortar attacks on a sitting Prime Minister and other key high level ministers (http://en.wikipedia.org/wiki/Downing_Street_mortar_attack). Have a look at the list for London alone (http://en.wikipedia.org/wiki/List_of_terrorist_incidents_in_...).

I had no idea the IRA was this level of threat - a personal threat to the people in power. And the problem was pretty much solved through the long hard slog of getting them round a table talking (http://en.wikipedia.org/wiki/Good_Friday_Agreement).

Re: UK anti-encryption law

#157

Earlier quoted context omitted.

Yes but remarkably after 100years of bombings and assassinations by the IRA the response was to carry on as normal, don't give in to them. The only visible sign was removing litter bins from railway stations and some checkpoints on vehicles enter the financial district of London Yet 5 minutes after the 9/11 attacks on America the UK suddenly needed a whole raft of laws to intercept all phone calls, hold people withou…

IRA terrorism was pretty extensive too. They murdered close members of the UK royal family ( http://en.wikipedia.org/wiki/Louis_Mountbatten,_1st_Earl_Mou... ), major damage to cities ( http://en.wikipedia.org/wiki/1996_Manchester_bombing ) and actual mortar attacks on a sitting Prime Minister and other key high level ministers ( http://en.wikipedia.org/wiki/Downing_Street_mortar_attack ). Have a look at the list for…

Hence the slightly raised English eyebrow when American politicians - especially a Kennedy at a St Patricks Day parade in Boston - talk about supporting terrorism.

Re: UK anti-encryption law

#158
post #60

Earlier quoted context omitted.

If you're caught though the consequences are terrible whilst encrypted Shakespeare given names to look like something illegal would only really have you under unauthorized access charges.

I don't know. I would think that attempting to frame someone with it shows some amount of malicious intent. There's got to be something else to charge them with other then the equivalent of "breaking and entering" to plant evidence.

viola-12-hot.zip looks tasty to a police officer who thinks they found illegal images but is just a keyword + title word + one-word review of a favourite play when you find the contents are Twelfth Night ... maybe?

Re: UK anti-encryption law

#159
post #76
post #64

I don't like or support the legislation - but I think this is a bit of an over-reaction. The law as I understand it says that if you've got data (and the context of the law is in focussed primarily on targeting terrorism, child-porn etc) that you've encrypted but refuse to give over the encryption keys to; then if the police then convince a judge that there is valuable evidence in the encrypted data, and you still re…

( http://www.computerweekly.com/blogs/the-data-trust-blog/2009... ) > Police argue the files "could be child pornography, there could be bomb-making recipes." Note that he was in prison -serving a sentence- but has since been transferred to a secure mental health hospital where he can be detained under the MHA until he is well. I don't know if he had an appropriate adult with him at any police interviews. I don't kno…

From that article: he Missed bail; traces of explosives; carrying home made rockets; had a stash of encrypted storage drives with him and the authorities wanted to see what was on them. In such cases the person is still innocent but the authorities have a duty to investigate.

Don't get me wrong I am a hacker and someone who has written lots of crypto code, but i don't see this as an example to support the case against the legislation.

Re: UK anti-encryption law

#160

Earlier quoted context omitted.

Here in Brazil is guaranteed by the constitution that no one can be forced to produce any evidence against him/herself. Isn't there something like this in the UK? You know... if someone says that you have ilegal encrypted data, they first would have to prove that it is really encrypted data and then that it is ilegal data.

There was a case where that defense was mounted, but failed [1]. The encryption keys were deemed to exist "separate from the will of the subject" i.e. they were deemed to be "physical". You can't use the defense against self-incrimination for physical keys either and the prosecution likened the encryption key to a physical key. What hasn't been tested in court (afaik) is the refusal to hand over a passphrase that pro…

Is it illegal to hand over passwords yet if it's self-incriminating? Because encasing the encryption key in a passworded file could get you out. You would be providing the key, but wouldn't be self-incriminating yourself.

It would be like handing over an virtually unbreakable safe and saying "open it".

Post reply on HN