Live data from Hacker News

UK anti-encryption law

falkvinge.net

131–140 of 198 posts

Re: UK anti-encryption law

#131
post #122
post #107

Earlier quoted context omitted.

The law doesn't work like that. It doesn't matter how important it is - if the police haven't given you a notice to decrypt it, the statute isn't engaged.

So they are infringing on personal privacy, and practicing selective enforcement? If this came to America everyone would be brown from the big shit storm.

Technically, no. "Selective enforcement" is when the authorities selectively choose whether to arrest and prosecute someone for breaking a law. That's not quite the case here, as there is no breach of the law unless & until a notice is sent and been refused.

Re: UK anti-encryption law

#132
post #128

Hidden volumes. Volume one contains hardcore porn, volume two contains bank job plans. Neither can be proved to exist with their keys. When asked, hand over the porn keys. Plausible deniability.

More people need to know about this. Unless you're quite foolish, this right here will stymie most government attacks. It's difficult to prove that a file full of random noise is actually an encrypted container (but possible, seeing that Truecrypt is installed and other factors), but it's damn near impossible to prove that a hidden volume exists in the same noise.

Better yet, if you do anything with the outer volume without explicitly telling truecrypt about the existence of the inner volume, you will likely corrupt the inner volume and render it unusable anyways.

Re: UK anti-encryption law

#133

His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?

Isn’t it worse than that? Doesn’t it mean that, so long as you possess a reasonable amount of digital data, you could be hiding something in it and are therefore guilty.

Re: UK anti-encryption law

#134
post #131
post #122

Earlier quoted context omitted.

So they are infringing on personal privacy, and practicing selective enforcement? If this came to America everyone would be brown from the big shit storm.

Technically, no. "Selective enforcement" is when the authorities selectively choose whether to arrest and prosecute someone for breaking a law. That's not quite the case here, as there is no breach of the law unless & until a notice is sent and been refused.

Technically you are right. Essentially the difference is bullshit. They simply don't send a notice to people they want to selectively ignore.

Re: UK anti-encryption law

#135
post #108

Earlier quoted context omitted.

So, perjury.

Not sure you can commit perjury if you are the accused !

In the US you can, and I'd be surprised if many other jurisdictions saw it differently. In the US you have a right against self incrimination, not a right to lie and misdirect. See Martha Stewart as an example, part of her conviction was making false statements to an investigator.

Re: UK anti-encryption law

#136
post #124
post #119

Earlier quoted context omitted.

Fortunately its nowhere near that bad. The prosecution needs to prove beyond reasonable doubt that the file contains encrypted data and that you have the key. So if you did have a file of random noise then the police would not be able to prove these things. And if you had software for using that file as a random number stream then that would be evidence in your defence. Remember, its for the police to prove your guil…

Does innocent until proven guilty and beyond a reasonable doubt apply to UK criminal law?

It is right there in the section linked from the article:

(3) For the purposes of this section a person shall be taken to have shown that he was not in possession of a key to protected information at a particular time if— (a)sufficient evidence of that fact is adduced to raise an issue with respect to it; and (b)the contrary is not proved beyond a reasonable doubt.

... which makes me sad that misinformation is being used to fight a good cause.

Re: UK anti-encryption law

#137
How does/would this affect Freenet users? As far as I know, a Freenet user's 'deniability' claim comes from the idea that the user does not know the key to the encrypted content hosted on their machine.

Re: UK anti-encryption law

#138
post #134
post #131

Earlier quoted context omitted.

Technically, no. "Selective enforcement" is when the authorities selectively choose whether to arrest and prosecute someone for breaking a law. That's not quite the case here, as there is no breach of the law unless & until a notice is sent and been refused.

Technically you are right. Essentially the difference is bullshit. They simply don't send a notice to people they want to selectively ignore.

Think of it like a stop-and-search power. It is too wide, but not choosing to stop and search everyone who they have the power to isn't really like selective enforcement - it's just a power they can choose to use if they feel they need to.

Re: UK anti-encryption law

#139
post #128

Hidden volumes. Volume one contains hardcore porn, volume two contains bank job plans. Neither can be proved to exist with their keys. When asked, hand over the porn keys. Plausible deniability.

More people need to know about this. Unless you're quite foolish, this right here will stymie most government attacks. It's difficult to prove that a file full of random noise is actually an encrypted container (but possible, seeing that Truecrypt is installed and other factors), but it's damn near impossible to prove that a hidden volume exists in the same noise. Better yet, if you do anything with the outer volume…

The only problem with this is that people are really bad liars.

Re: UK anti-encryption law

#140
post #11

His argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?

If you can write data to someone's hard drive it is simpler to just dump some child pornography.

But then you'd need to be in possession of it, and that has many issues that merely writing random data to a file does not.
Post reply on HN