Live data from Hacker News

Man jailed over computer password refusal

bbc.co.uk

141–150 of 239 posts

Re: Man jailed over computer password refusal

#141
post #64
post #24

Earlier quoted context omitted.

The 5th amendment protects against forced testimony, not against compulsion to provide evidence. You can refuse to testify against yourself, you cannot refuse to comply with a valid search warrant.

Testifying is providing information to the court. Decrypting your hard drive is providing information to the court. What's the difference? I would argue that all evidence is really just information. Once again, the old lines dividing one category from another become blurred.

The difference is that testimony is revealing the contents of your brain ("I saw X, I did or did not do Y, I felt Z") and evidence is revealing the contents of your car trunk. Evidence does not have its own opinion of what did or did not happen, evidence does not decide what is or is not the truth. Evidence simply exists; it is for others (giving testimony) to give evidence context and relevance.

Re: Man jailed over computer password refusal

#142

Encryption and password privacy is an entirely unsettled area of US law. The courts can probably compel you to enter your password (to decrypt a drive, or what have you), while you can maintain that the content of your password can be protected under the 5th. So, for instance, say you had encrypted files of plans to build a bomb and detailed schematics of the White House. The judge can order you to decrypt the files…

Claiming forgetfulness concerning the key would give you a way out unless they could manage to crack it - at that point you would have dodged the self-incrimination bullet but could not be legally bound to simply "decrypt it." I agree though - the entire thing is an absurdly mucky business. Apparently however the English law doesn't have much like that in the way of loopholes, or he simply refused to decrypt it outri…

I believe there is a specific law in the UK that mandates key escrow -- the government must be able to decrypt anything.

This has been floated in the US before, but it has not gotten good PR. As it stands now, it is a Constitutional law issue -- does the fifth amendment mean that you can't be compelled to get up in the witness box and talk, or does it mean that you don't have to assist the prosecution in any way? Right now, the courts seem to be split 50/50, but I feel that practicality dictates that you don't have to give up your key. First they have to accuse you of a crime and bring it to trial, then you have to refuse to decrypt the key, then the first trial has to stop, then the government has to prove that you know the key, then you have to be convicted and sentenced, then you can go back to the original trial after analyzing all of the decrypted "evidence". If encryption becomes widespread, this just isn't practical. It's easy to prove that you sell drugs; someone goes up to you and buys them. It's not easy to prove that you didn't forget your encryption key, because we have no way to observe someone's mind. Laws that prohibit crimes that can't be proved tend not to do well.

Re: Man jailed over computer password refusal

#143

Earlier quoted context omitted.

Intentionally destroying incriminating evidence is probably not something you should ever do. Certainly not in such a way that leaves evidence in the form of pulverized IC remains all over your kitchen counter.

But how can they prove that it was incriminating evidence?

Usually there'll be a reason for the police to kick your door down. I imagine that plus destroyed evidence would be enough to prove beyond reasonable doubt.

Re: Man jailed over computer password refusal

#144
post #81
post #46

"50-character encryption password" - nice! I'm wondering ... Person A refuses for - pure principle (and maybe some ripped DvD's) Person B refuses for - let's say child pornography and a dirty bomb manual Both will get the same jail time?

There are other legitimate reasons to not want to reveal the contents of your hard-drive besides principle or self incrimination. For instance, if you had the private information of any other people. My SO works with HIV, and recently got access to sensitive data that had to be sent on DVD via courier. Who here trusts the police to not disclose their HIV status?

Disclaimer: IANAL

If you're in the Unites States, the data is probably protected by HIPAA, the Health Insurance Portability and Accountability Act[1]. HIPAA includes a clause stating that the Attorney General or their designee may issue a subpoena compelling your SO to disclose that information, but only to someone investigating a Federal health care offense.

I've searched through the rest of HIPAA for keywords such as "law enforcement", "criminal", and "disclosure", but I couldn't find anything about being compelled to disclose HIPAA-protected information to law enforcement in any other circumstance than investigation of a Federal health care offense. However, I did not thoroughly read HIPAA, and there might be something in another section of the US Code that's relevant.

Hopefully someone more knowledgeable about this can let me know if I've missed something.

[1]: http://www.legalarchiver.org/hipaa.htm

Re: Man jailed over computer password refusal

#145
post #49
post #38

Earlier quoted context omitted.

I think that the law is worded so that it's an offence to have encrypted files and not be able to decrypt them. Whether it's deliberate or just forgotten isn't relevant (though I'd hope it would make a difference in sentencing).

How can you even prove that a file is encrypted? The whole law is baloney.

Use TrueCrypt to do whole disk encryption on your Windows XP hard drive. Then boot your computer with a Linux Live CD and dd the first 512 bytes to stdout. This is what you'll see in plain text ASCII:

"TrueCrypt Boot Loader"

No expert is needed to prove that you are using TrueCrypt whole disk encryption. It has a huge stamp right up front.

Re: Man jailed over computer password refusal

#146
post #28

Earlier quoted context omitted.

In the US the current rules for personal hard drives are bound by the 5th amendment which has been interpreted as "a reasonable expectation for privacy." What happens is the police say "Give us your password and we'll drop whatever sentence by 75% for helping the investigation." You don't have to give your password but the NSA works pretty extensively with law enforcement and the FBI (most US cases that require passw…

Do you think the NSA is going to reveal to foreign governments that they've broken AES by going after some guy with child porn on his laptop? I personally doubt it. Could the NSA cooperate with the FBI? Yes. Will they? Not if it means they can't spy on Russia anymore.

"Breaking AES" is not at all necessary. All it takes is one implementation hole, or some plaintext unknowingly cached by a program.

The NSA don't merely employ scores of cryptanalysts to sit around all day to try to break ciphers (though I expect they do this too). Exploiting mistakes is their bread and butter.

Re: Man jailed over computer password refusal

#147
post #19

Earlier quoted context omitted.

Wait until they ask him again, 16 weeks from now...

Can you be tried for the same crime twice?

He's not being tried for refusing to hand over the password - he's being held for contempt of court or similar, which can (and does) go on indefinitely. He's free to leave any time as soon as he hands over his password.

Re: Man jailed over computer password refusal

#148

Earlier quoted context omitted.

In the US, the prosecution is going to have to prove beyond a reasonable doubt that there is, in fact, encrypted information and that the suspect knows the key. Yes, there are going to be gray areas. But if Bob has one computer in his house with his and only his finger prints all over it, wear that indicates that the computer has been used extensively, and the computer hard drive is filled with an encryption scheme w…

Perhaps the password is a sequence of 50 characters that he's never memorised but keeps on a slip of paper, and which has recently gone missing.

"Your honour, seeing how important this password is, I stored it in the encrypted drive."

Re: Man jailed over computer password refusal

#149
post #111

Earlier quoted context omitted.

But... it's the same password/encrypted data here.

Disclaimer: IANAL. Disclaimer: IANAA (I Am Not An American) Assaulting the same person twice would still be two different assaults. Stealing a truck, getting caught and punished, and stealing the same truck again would, to my understanding, not be risk-free, legally speaking. I suspect the same would probably apply here, though given how unintuitive the law is, especially in this area, I may well be dead wrong. Edit:…

By the same logic, if the authorities had asked him one hundred times in the first interview for his password, and he'd refused one hundred times, then he could be charged with one hundred counts of the offence and put away for 30 years.

The courts aren't run by robots. If it's substantially the same instance of the offence, he couldn't be tried again.

Re: Man jailed over computer password refusal

#150
It's about time this happened. In the UK we have a law called the Regulation of Investigatory Powers Act (RIPA) which allows access to certain data held by ISPs or can compel people in certain cases to not only hand over encryption material but prohibits them from acknowledging that they had been charged under such a law.

As you can imagine, that last bit results in some very complicated situations. The laws governing paedophilia are quite different, with paedophiles having to sign a sex offenders register.

In the case of a sex offender being caught, it's easier to just take the RIPA sentence instead. This is what appears to have happened. I hope the guy's password is long enough otherwise regardless of his crime he's in for a world of pain.

Post reply on HN