Live data from Hacker News

Man jailed over computer password refusal

bbc.co.uk

231–239 of 239 posts

Re: Man jailed over computer password refusal

#231
post #121
post #102

Earlier quoted context omitted.

Perhaps a solution is to commit two crimes: crime A which has to do with the encrypted file, and crime B which has nothing to do with it. Then, use a phrase which is self-incriminating for crime B as the password for the encrypted volume. For example, "IBrokeTheSpeedLimitBy15MilesPerHourOnJuneTheTwenty-Seventh,InTheYearTwoThousandAnd4".

In which case the judge would compel you to reveal your password to your attorney. The attorney would not be able to reveal the password as that would violate privilege, but they would be compelled to uphold the terms of the valid search warrant on the decrypted data.

Well, suppose that you do give them the unencrypted file. They already have the encrypted file and presumably are aware of the encryption scheme you used, so (this could be totally wrong, as I don't know enough about encryption) they should be able to figure out the encryption key.

Re: Man jailed over computer password refusal

#232

Earlier quoted context omitted.

Why? Given that in 2010, nearly a decade after 9/11 and almost 7 years after the invasion of Iraq, the US military, State Dept, domestic law enforcement agencies and presumably intelligence agencies still have a severe shortage of Arabic-speaking staff, why do you find the statement stupid? The UK before 9/11 was much less focused on terrorism than the US is now. Developing robust foreign language capability in large…

Of course most police forces and so on will not have speakers available, but the comment said "British intelligence". Every intelligence agency has translators for all major languages, and have for decades (Arabic was an important language in the Cold War almost from the start). And they have translators for minor languages on tap - I bet they could find a Basque, Lapp, or Chukchi speaker if they needed one quicker t…

"I bet they could find a Basque, Lapp, or Chukchi speaker if they needed one quicker than most universities."

That's probably where they get them.

Re: Man jailed over computer password refusal

#233
post #157

Encryption and password privacy is an entirely unsettled area of US law. The courts can probably compel you to enter your password (to decrypt a drive, or what have you), while you can maintain that the content of your password can be protected under the 5th. So, for instance, say you had encrypted files of plans to build a bomb and detailed schematics of the White House. The judge can order you to decrypt the files…

> The courts can probably compel you to enter your password (to decrypt a drive, or what have you), while you can maintain that the content of your password can be protected under the 5th. This is a really subtle point, but in the US this is not (usually) the case, because this is still self-incrimination. You see, by entering the password, you are demonstrating that you have access to the encrypted information, and…

Yes, this is the "act of production" privilege. The Fisher decision established that content is not protected as 'testimonial'.

  "but the Court has never on any ground, personal privacy included,
  applied the Fifth Amendment to prevent the otherwise proper 
  acquisition or use of evidence which, in the Court's view, did not
  involve compelled testimonial self-incrimination of some sort."

  "The taxpayer cannot avoid compliance with the subpoena merely by
  asserting that the item of evidence which he is required to pro-
  duce contains incriminating writing, whether his own or that of
  someone else"

  "The existence and location of the papers are a foregone conclu-
  sion and the taxpayer adds little or nothing to the sum total of
  the Government's information by conceding that he in fact has the
  papers. Under these circumstances by enforcement of the summons
  'no constitutional rights are touched. The question is not of 
  testimony but of surrender.'"
Fisher largely overturned the earlier (1886) Boyd decision. The court did not expand the Fisher limits until 2000, when the Hubbell decision expanded the testimonial aspect of production and limited the scope of the "foregone conclusion" rationale. For more on the act of production privilege, see http://www.georgemasonlawreview.org/doc/17-3_Cowen.pdf

But this all relies on a particularly narrow reading of the role of the password in these questions. You have no right (Boyd being long overturned) to withhold physical evidence that may incriminates you.

Anyway, this is an interesting area of law and definitely worth watching.

Re: Man jailed over computer password refusal

#234
post #180

Earlier quoted context omitted.

I'm surprised that no one has mentioned Rubberhose Deniable Encryption by Julian Assange of Wikileaks fame. That's the entire concept. Page: http://iq.org/~proff/rubberhose.org/ Description: http://iq.org/~proff/rubberhose.org/current/src/doc/maruguid...

This seems stale though. It's "currently available for Linux 2.2"?

Very stale. He moved on to other things:) But the code is available.

Re: Man jailed over computer password refusal

#235
post #231
post #121

Earlier quoted context omitted.

In which case the judge would compel you to reveal your password to your attorney. The attorney would not be able to reveal the password as that would violate privilege, but they would be compelled to uphold the terms of the valid search warrant on the decrypted data.

Well, suppose that you do give them the unencrypted file. They already have the encrypted file and presumably are aware of the encryption scheme you used, so (this could be totally wrong, as I don't know enough about encryption) they should be able to figure out the encryption key.

Any encryption scheme that is not worthless does not work that way. If you have the plaintext and the ciphertext (but did not get to choose the plaintext to be encrypted) then you are still no closer to getting the key.

Re: Man jailed over computer password refusal

#236

Earlier quoted context omitted.

Also, I don't think it necessarily needs to be proven that the evidence was incriminating; just destroying evidence is criminal behavior. Of course, IANAL, but that's how I'd do it if I ruled the world...

How do you know it was evidence or related to the bust?

There might be all sorts of reasons - if you're being busted for fraud or tax evasion and all of your hard drives are mysteriously blank, or there are empty filing cabinets and a big pile of ash then I would imagine that would go down fairly badly in court.

The modern equivalent is a whole bunch of destroyed media - thumb drives, flash cards or hard drives.

Re: Man jailed over computer password refusal

#237
post #126

A friend of mine flew back home to Canada. After clearing customs, he was one of the random people chosen to have their luggage inspected. He had his laptop on him and the customs agent booted up the computer, asked him to enter his password and then took his laptop away before bringing it back without telling him anything about it. I wondered what would have happened if he refused to type in the password.

Customs aren't law enforcement, they just like to think so. The request to enter a password should be treated as a impolite request, which you should politely deny.

Not sure why your were upvoted (probably for the sentiment that freely entering one's password without reason should not happen) because that is not correct.

In the US, "customs" typically refer to ICE and TSA, both are enforcement functions of the United States Department of Homeland Security.

Re: Man jailed over computer password refusal

#238
post #237

Earlier quoted context omitted.

Customs aren't law enforcement, they just like to think so. The request to enter a password should be treated as a impolite request, which you should politely deny.

Not sure why your were upvoted (probably for the sentiment that freely entering one's password without reason should not happen) because that is not correct. In the US, "customs" typically refer to ICE and TSA, both are enforcement functions of the United States Department of Homeland Security.

checking facts... You are correct. I incorrectly assumed they were equivalent to UK and Norwegian customs, where customs and border protection are separate entities.

Re: Man jailed over computer password refusal

#239

Earlier quoted context omitted.

>The fact that their plans would be written in a foreign language (never mind a foreign alphabet) would have been more than adequate to keep it secret from British intelligence. This is one of the stupidest statements I have ever seen.

Why? Given that in 2010, nearly a decade after 9/11 and almost 7 years after the invasion of Iraq, the US military, State Dept, domestic law enforcement agencies and presumably intelligence agencies still have a severe shortage of Arabic-speaking staff, why do you find the statement stupid? The UK before 9/11 was much less focused on terrorism than the US is now. Developing robust foreign language capability in large…

The one thing we are good at is SIGINT.

We may have a stifling bureaucracy and an overstretched military, but at least the British Foreign Office actually has local knowledge and people who speak the language.

Post reply on HN