Live data from Hacker News

Judge: Fifth Amendment doesn't protect encrypted hard drives

arstechnica.com

21–30 of 135 posts

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#21
What if lawyer-based service is created, which allows to automate representation of client including when client need access to data on the his hard drive. Essentially, develop algorithm allowing external OTP authentication.

And this lawyer, representing user, will have in agreement something like this "In case my client is under investigation or incriminated or ..." I will not be allowed to release OTP password.

Of course, this service will be based in country which treat law as a law, not inconvenience.

What I am missing? There are no such countries may be?

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#23

Did anybody see this? But the police had recorded a phone call between Fricosu and her husband in which she seemed to acknowledge ownership of the laptop and to reference incriminating material on it. I'd like more details about this - without any clarification, this sounds extremely scary .

Without any clarification, this sounds like perfectly normal wiretapping. Is there any reason to think the police didn't obtain a warrant?

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#24

Did anybody see this? But the police had recorded a phone call between Fricosu and her husband in which she seemed to acknowledge ownership of the laptop and to reference incriminating material on it. I'd like more details about this - without any clarification, this sounds extremely scary .

Presumably the phone call surveillance was under warrant.

It's also worth noting that they would have needed a warrant to seize the computer itself to begin with. The question is whether, having been seized, they can require her to decrypt it for them.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#25

Any technologies exist that let you have multiple encrypted OS's on multiple keys? For example, 1 key could boot up one OS and another key could boot up a different OS. Seems like it'd be difficult to prove that you booted one or the other...

I foresee Truecrypt-ception. An encrypted OS within an encrypted OS within an encrypted OS. They'll never find my porn/plans to take over the world/illegal software/hacked secret government cables NOW!!!

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#26
BTW, hackers, if you did not see it yet, check out what EncFs offer you. Essentially, it allows you to have multiple passwords on the same repository, and only files decryptable with currently used password are shown (require special option during mounting to ignore incorrect password warning).

Using that you can have any number of passwords and any number of "partitions" inside your folder. This is not like hidden partition in TrueCrypt, where you can not prove it exists at all.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#27

Any technologies exist that let you have multiple encrypted OS's on multiple keys? For example, 1 key could boot up one OS and another key could boot up a different OS. Seems like it'd be difficult to prove that you booted one or the other...

The technology for this does exist, but it's pretty annoying to use in practice. You need to use the "decoy" OS regularly -- preferably most of the time. After all, it's implausible that you haven't used your web browser in six months, etc, and your adversary would notice this.

The problem there is that the "hidden" OS is (by definition) undetectable from within the "decoy" OS. Therefore, you risk accidentally overwriting it. Some encryption software has workarounds for this, but that typically leaves you exposed while it's in use.

Whole-disk encryption is great for protecting credit card numbers, embarrassing information, and trade secrets from someone who should happen to steal your laptop. If you actually have anything so secret that you're worried about being coerced into decrypting it, I don't know how to help you.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#28
An important clarification since some people seem to be confusing the issue: the police seized her computer already, presumably legally and with a warrant.

So while this does present an interesting edge case in the fifth amendment (does evidence count as evidence if it's encrypted?), it shouldn't set off civil liberty alarm bells in your head nearly as badly as several other things currently going on in this country.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#29
post #14
post #7

Earlier quoted context omitted.

Plausible deniability is a much larger concept than that. Also if they know you're using Truecrypt, the "deniability" of the existence of a 2nd (or 3rd or 4th) OS goes down significantly.

It does indeed. However, what are they going to do? Torture you until you give them the "other" password? How can they distinguish whether you just cleaned your hard drive or if you gave them the wrong key?

The solution is of-course a honey-pot OS to boot.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#30
post #5

Just out of curiosity, what's the case-law like if she had encoded these documents and stored them on paper? I certainly don't want to see mandatory decryption, but at the same time it doesn't make sense to let an accused completely skip out on discovery by simply truecrypt-ing the evidence either.

Also analogous would be whether defendants can be required to provide they key to a safe, correct?

According to the article, Judge Blackburn's reasoning was that if defendants can be required to produce other documents, the existence of which is known, they can be required to "produce" encrypted documents via decrypting.

Post reply on HN