Live data from Hacker News

UK anti-encryption law

falkvinge.net

171–180 of 198 posts

Re: UK anti-encryption law

#171

Earlier quoted context omitted.

That situation is really independent of the law. Imagine the law said that nobody could be compelled to decrypt data (using fourth amendment type reasoning), and it was leaked to the press that this person was suspected of traffic child porn, but refused to decrypt his harddrive - even when decrypting the harddrive could prove his innocence, wink wink nudge nudge .

I think refusing to decrypt a hard drive in the US is dependent on whether it is self-incrimination (5th Amendment) while police activities are more tied to the 4th Amendment. But the point is "I gave you my password. I haven't seen the computer in a month while your forensic team was looking it over. Maybe I got it wrong, or maybe your boys screwed it up." That is not refusing to decrypt it. In fact it is very appar…

I agree, and I definitely meant the fifth. But the GP talked about being demonized in the public eye - which doesn't rely on the law being one way or the other.

Re: UK anti-encryption law

#173
Encryption isn't just about hiding your documents. It is also about securing your assets and providing identification.

- The passwords on your bitcoin wallet give you the authority to spend your money.

- Your encrypted signature requires your private key so other's know your message came from you.

So, this law gives the government the ability to impersonate you and consume/use your assets in an unrecoverable way.

While the government might not have the authority to impersonate you or spend your money, they do have the authority to acquire the means to do so. And then all it takes is one dishonest person working for the government to use that information maliciously.

Re: UK anti-encryption law

#174

Earlier quoted context omitted.

That situation is really independent of the law. Imagine the law said that nobody could be compelled to decrypt data (using fourth amendment type reasoning), and it was leaked to the press that this person was suspected of traffic child porn, but refused to decrypt his harddrive - even when decrypting the harddrive could prove his innocence, wink wink nudge nudge .

I think refusing to decrypt a hard drive in the US is dependent on whether it is self-incrimination (5th Amendment) while police activities are more tied to the 4th Amendment. But the point is "I gave you my password. I haven't seen the computer in a month while your forensic team was looking it over. Maybe I got it wrong, or maybe your boys screwed it up." That is not refusing to decrypt it. In fact it is very appar…

US courts have already ruled that the 5th ammendment does not apply to crypto keys. The court said that it was like requiring someone to hand over the keys to a container, etc.

Re: UK anti-encryption law

#175

Earlier quoted context omitted.

I think refusing to decrypt a hard drive in the US is dependent on whether it is self-incrimination (5th Amendment) while police activities are more tied to the 4th Amendment. But the point is "I gave you my password. I haven't seen the computer in a month while your forensic team was looking it over. Maybe I got it wrong, or maybe your boys screwed it up." That is not refusing to decrypt it. In fact it is very appar…

US courts have already ruled that the 5th ammendment does not apply to crypto keys. The court said that it was like requiring someone to hand over the keys to a container, etc.

US courts have split on the issue.

Re: UK anti-encryption law

#176
post #170
post #138

Earlier quoted context omitted.

Think of it like a stop-and-search power. It is too wide, but not choosing to stop and search everyone who they have the power to isn't really like selective enforcement - it's just a power they can choose to use if they feel they need to.

In America that is a violation of 4th amendment rights. Now clearly this applies to UK, but we didn't fight the UK in a war for nothing.

I'm not very familiar with US law, but a few moments googling suggests that that's nonsense, and the standard the police must reach to conduct a stop and search in the US, for e.g. weapons ("reasonable suspicion", per Terry v Ohio), is essentially identical to that in the UK ("reasonable grounds for suspecting"). Though the UK statute does cover a slightly wider class of items - e.g. stolen property, rather than just guns as in the US.

(It's true that the reasonable ground requirement was removed for certain areas by the Terrorism Act 2000. That provision was held incompatible with Article 8 of the ECHR (our nearest equivalent of your 4th amendment), and has consequently been repealed).

I'd also raise an eyebrow at your implication that the police are generally less prone to misuse of their powers in the US than the UK. I haven't researched it, but my impression was that in practice it's rather the other way round.

Re: UK anti-encryption law

#177
post #57

Earlier quoted context omitted.

> It implies you've got a huge cache of it hanging > around ready to go. In the US at least, just a single image is illegal, so there is no need for a huge cache.

I imagine that a single image wouldn't quite motivate the police the same way that two gigabytes' worth would.

I remember a story about the FBI going after some college kid with a single thumbnail in his browser cache, though the other circumstances were:

- Somehow they came up with his IP in a sting where a link to a file was posted somewhere. I don't know if this was posted to a kiddie porn forum (or someplace where just hanging out there is enough to make you suspicious) or just someplace like 4chan (where there's a number of people that will click the link out of curiosity).

- He had 'recently' re-installed Windows. They claimed that he had obstructed justice (or some other B.S.) b/c he had destroyed evidence. (Evidence that they couldn't prove even existed, IIRC.)

- He had a single thumbnail of kiddie porn in a browser cache.

I think that he just settled with the Feds, but cases like this stick out in my mind because it makes it seem like we're all riding the razor's edge and could fall into the Federal justice system at any moment for some random, stupid reason.

[ Plus taking down a pedophile is brownie points to local politicians, which may (or may not) be pressuring them about crime statistics. ]

Re: UK anti-encryption law

#179

His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?

Would be a valid defense argument for your lawyer to use. Lot of good that will do you in Gitmo (when the US implements this kind of law).

Re: UK anti-encryption law

#180
post #123

Isn't TrueCrypt's 'hidden volume' feature enough to make this law pointless? Just have two encoded sets of information in the same file. When you are asked to give the key it is up to you the key of which one you give. http://www.truecrypt.org/docs/?s=plausible-deniability

It still requires you to give up data for which it makes sufficient sense to be encrypted otherwise someone might get the idea that you are using this feature. While this is a solution it is certainly not as easy a solution as it might seem to be.

Some very nasty (legal) porn should do it.
Post reply on HN