Live data from Hacker News

Judge: Fifth Amendment doesn't protect encrypted hard drives

arstechnica.com

121–130 of 135 posts

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#121

It's a variant of what's called "rubber hose cryptology": sometimes it's technologically a lot easier to just beat the password out of someone (smacking the soles of one's feet with a rubber hose apparently being a rather effective technique). I draw the line using a "rag doll" model. They can compel fingerprints, physical keys, DNA, etc. insofar as they can manipulate your limp unresitive (albeit uncooperative) body…

That's until they have mind readers. Then they'll get search warrants for our brains.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#122

Earlier quoted context omitted.

That's the beauty of full-disk encryption. Even the empty space is encrypted. So the hidden volume is truly hidden. Even TrueCrypt has no idea the hidden volume exists if you unlock the outer volume with a different key. Truly empty-space is indistinguishable from a secret inner volume.

Why can't I write a program that tries to expand itself to use any available space, then runs in to a wall if the "empty space" is actually encrypted data? If the space used by data + my program adds up to less than the total capacity of the disk, it indicates something is hiding right?

You seem to be misunderstanding. Read your parent's last line again. "Empty space" is indistinguishable from encrypted data. On the hard disk, everything will just look like randomized bits, empty space and data alike. There is no way to write the program you propose without the encryption key(s). So there's no way to tell, unless you have all the keys.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#123
post #12

To counter this, you need an encryption method with these properties: - you can be banned or self-banned, irrevocably, from accessing your data; - you can prove to the judge that you can't access your data; - even with full forensic copies of your disk, you can't be un-banned. You can do that by having part(s) of the key on server(s) online. Give yourself, a couple of trusted friends and optionally a script, the abil…

Maybe add a dead man switch? If you don't log on every week, then destroy the server side of the key.

That's a possibility, but the risk of having your data inadvertently destroyed is much higher. Moreover, you must trust your ability to stall inquiries for up to a week.

It really depends on the relative cost of having your data destroyed vs. having your data published, but I'm sure there are cases with a dead man switch is a good compromise.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#124

Earlier quoted context omitted.

That's the beauty of full-disk encryption. Even the empty space is encrypted. So the hidden volume is truly hidden. Even TrueCrypt has no idea the hidden volume exists if you unlock the outer volume with a different key. Truly empty-space is indistinguishable from a secret inner volume.

Why can't I write a program that tries to expand itself to use any available space, then runs in to a wall if the "empty space" is actually encrypted data? If the space used by data + my program adds up to less than the total capacity of the disk, it indicates something is hiding right?

The program will just overwrite the data of the hidden volume. That's why it's important to have a lot of empty ("empty") space on the primary volume when you have a hidden volume there.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#125

Earlier quoted context omitted.

Why can't I write a program that tries to expand itself to use any available space, then runs in to a wall if the "empty space" is actually encrypted data? If the space used by data + my program adds up to less than the total capacity of the disk, it indicates something is hiding right?

You seem to be misunderstanding. Read your parent's last line again. "Empty space" is indistinguishable from encrypted data. On the hard disk, everything will just look like randomized bits, empty space and data alike. There is no way to write the program you propose without the encryption key(s). So there's no way to tell, unless you have all the keys.

praptak's reply above yours explained exactly what I needed explained. The encrypted data will just be written over.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#126

I have question to those who know more about these things: Instead of hidden volumes, wouldn't it be better to have an "under duress" password? The hard drive is encrypted and sensitive folders are identified by the user. When a password is given all contents are decrypted. When a "under duress" password is given the sensitive folders are permanently wiped and all the (remaining, innoculous) contents are decrypted. T…

Then they restore the hard drive from the cloned image they made before entering the password and ask you once more for the password. This time, with feeling.

How would they know the incriminating evidence had been wiped though?

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#127

Classical jibberish passwords are mostly muscle memory. I know I wouldn't be able to remember some of my mine of that sort after two weeks. If you were incarcerated and you knew you might have to comply with an order to decrypt a hard drive, it might be in your best interest to create and shadow type many alternate passwords until you actually forget the important one. Then (hopefully) you're just a polygraph away fr…

Of what I understand of the methodology used by polygraph, forgetting the password wouldn't help you out here. You'd still be intentionally misleading the police, and that would lead to the signs the polygraph attempts to detect.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#128

Earlier quoted context omitted.

Then they restore the hard drive from the cloned image they made before entering the password and ask you once more for the password. This time, with feeling.

There might be a market for keeping your keys on some service "out there". Boot your computer, type in your password, your computer sends the password to the key service. If the password is correct they send back the key, if the password is the destruct codes they delete the key. No amount of hard-drive cloning will stop this. Paired with some other optional measures ("we delete the password unless you send an email…

I smell a startup.

Great Idea by the way. Like Wikileaks you would have to replicate all your server in the countries that are the "freeist" or you need a very good system to hide where you are. Tor is a good exampel.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#129

Earlier quoted context omitted.

In the USA it is not legal (in violation of the 5th amendment) for the court to compel you to reveal a password (if your read the brief the Judge says as much). However, if the court can prove by other means that you own the data on a drive, they can compel you to provide them with the unencrypted contents of the drive via a search warrant.

If they can prove it, why do they need you to decrypt it for them?

They know you stole the car because they've got surveillance video so now they're serving you with a warrant to produce the car so they can also prove physical presence in the vehicle. This is my view of the ruling.

The chick got recorded talking about the documents so they're asking for a readable version.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#130
post #79

It's a variant of what's called "rubber hose cryptology": sometimes it's technologically a lot easier to just beat the password out of someone (smacking the soles of one's feet with a rubber hose apparently being a rather effective technique). I draw the line using a "rag doll" model. They can compel fingerprints, physical keys, DNA, etc. insofar as they can manipulate your limp unresitive (albeit uncooperative) body…

> A fair argument may be made for compelling you to provide the key/combination to a safe, but only insofar as they CAN tear the safe apart with blowtorches & diamond saws if you don't cooperate. Interesting argument. Suppose I build a safe that costs $100 million to break open (because I spent $200 million of my ill-gotten money to hide $300 million more in ill-money). Now you've found my safe during your tax evasio…

Beware unrealistic hypotheticals. (Say, what's the cost to build such a safe?)

Short of dismissing the question out of hand, the point remains that it is still a mere matter of money - something which can be soaked out of taxpayers as needed. Even if we're talking a small jurisdiction with grossly insufficient funds, I'll meet your hypothetical with one where the US Military is invited to have a whack at it - and they can whack pretty hard. It's just a matter of money, and for all practical purposes through history that's been enough to crack any safe. ...and with that kind of money in that safe, I'm sure you could resolve the problem. Short of a scenario where forcing the safe would provably destroy evidence, or delays cause grave bodily harm, they can put the safe in the evidence warehouse and indefinitely assign someone to resolve the issue, while you cool your heels in Graybar Hotel until they open it or you save taxpayers the cost of doing so.

This in contrast to encryption, where any idiot can pick a good algorithm with a high-bitcount high-entropy key which could not be cracked using the resources of the universe. This isn't a hypothetical, this is the OP case. Here, the prosecution truly does hinge on the defendant incriminating himself: no cooperation = no conviction.

If you can prove a safe, like encryption, can't be cracked short of universe-scale efforts, I'll change my position.

Post reply on HN