Live data from Hacker News

DOJ: We can force you to decrypt that laptop

news.cnet.com

41–50 of 128 posts

Re: DOJ: We can force you to decrypt that laptop

#41

Earlier quoted context omitted.

rights are rights because they allow you to do what would otherwise be illegal. for example, there's no need for a right to free speech if you're only going to say things that everyone thinks should be said. rights exist because some things are so important they are worth the cost of abuse. At first blush it may be thought surprising that one should have a right to do that which one ought not. Is it not better to con…

Nobody has the right to avoid a reasonable search in the United States. You are protected by the fourth amendment from unreasonable searches, but you aren't going to convince me that a detective has no right, with a warrant in hand, to search a suspect's home for a murder weapon. Similarly, you aren't going to convince me that a prosecutor, warrant in hand, has no right to search a computer for evidence of credit car…

You still make the assumption that the prosecuted knows the password and is implicitly guilty.

Imagine for a second that I was less technically minded and didn't use encryption and I purchased a used laptop from someone who did, I then get caught up in the legal system (guilty or innocent for the charged crime, it doesn't matter, but I did not use encryption) and some prosecutor has a warrant to compel me to unlock that encrypted volume, else I be held in contempt. What now?

Re: DOJ: We can force you to decrypt that laptop

#43
post #23
post #13

Earlier quoted context omitted.

US v Hubbell makes clear that the government cannot compel production of documents (except under immunity to prosecution) which it does not know, ahead of time, to exist.

Then how can they compel someone to unlock a laptop to enable arbitrary access? Wouldn't they be limited to requesting specific documents?

The legal system allows them to do things analogous to that, such as compelling someone to open a safe to enable arbitrary access to the contents (as mentioned in the article). Presumably they must suspect that the safe contains documents relevant to the case.

Re: DOJ: We can force you to decrypt that laptop

#44
post #5

The truly interesting bit, will be when a case of (real or alleged) multiple hidden encrypted volumes is publicized. If the government feels the information they want is on a laptop, the laptop's owner would suddenly find themselves forced to prove a negative (there are no more hidden volumes), lest they be held in contempt. If they can seemingly compel you to reveal something they can't proven even exists and lock y…

For her sake, she has a hidden & real TC volumes -- i.e. she has both a real and fake TC OS volume. I don't know of any other encryption methods that allow hiding a volume within another volume as such. Even so, if I boot up your fake volume and it's pretty apparent it hasn't been used in 8-months or simply has a blank My Docs folder, I don't know how that will go. I suppose somebody could make the argument that all…

The standard method is to use one operating system in normal, day-to-day operations and another (in a hidden volume) whenever you're doing something sensitive or potentially illegal (you would also change the MAC address, not use it on your own wifi network, and so forth). However, it's probably too much to hope that most people actually realize this, especially criminals. Extremely paranoid people will have absolutely nothing incriminating on the computer, leave it unencrypted (to avoid suspicion), and use disposable flash drives with a small Linux image on them whenever they want to do something illegal. The flash drives are destroyed after one use.

Oh, and anyone smart enough to do that wouldn't describe their method on a public forum.

Also, your first sentence really irritates me: having the entire OS volume encrypted in no way means that you have two OS volumes, which you seem to be saying.

Re: DOJ: We can force you to decrypt that laptop

#45
So, assuming the DOJ can force one to decrypt a laptop, then wouldnt it be wise to make all your sensitive informarmation in a cloud-mounted encrypted partition such that nothing actually lives on the laptop of value?

Think of the laptop, again, as a dumb terminal. Make sure that the mounting of said partition is an always manual event and no command logging/local logging occurs.

Here! take the laptop! Here's the password!

When working, data gets brought to a local, ram based, cache - all evidence of anything running on the machine dies with power loss.

Re: DOJ: We can force you to decrypt that laptop

#46
post #17

IANAL ( Edit to include a reference for my opinions[1] ) The general argument for forcing someone to turn over the key to a door once compelled by the court is that it is commonly known there are other reasonable means by which to access the content the door protects that do not require the key: 1) Locksmith 2) Break the door down 3) Use a different door if one exist These are reasonable methods as neither of them ta…

Right, so the Government's demand of my encryption key to unlock the contents of my "digital brain" is no less different than the Government forcing me to take some truth serum to force me to reveal something I don't wish too... because it would incriminate me.

And as far as I'm concerned, the 5th protects me from incriminating myself.

Re: DOJ: We can force you to decrypt that laptop

#48
post #23
post #13

Earlier quoted context omitted.

US v Hubbell makes clear that the government cannot compel production of documents (except under immunity to prosecution) which it does not know, ahead of time, to exist.

Then how can they compel someone to unlock a laptop to enable arbitrary access? Wouldn't they be limited to requesting specific documents?

Every case is a little different, but investigators do need probable cause to search a laptop.

This is a mortgage fraud case involving years of criminal activity, so I'm guessing that it's probably not too hard for the prosecution to produce witnesses who can say "yes, she sold me that crappy mortgage and used her laptop when I went to meet with her.", or direct information of her internet usage (ISP, or logs from cable modem), or observation of her using the laptop by police during the investigation.

Re: DOJ: We can force you to decrypt that laptop

#49
post #44

Earlier quoted context omitted.

For her sake, she has a hidden & real TC volumes -- i.e. she has both a real and fake TC OS volume. I don't know of any other encryption methods that allow hiding a volume within another volume as such. Even so, if I boot up your fake volume and it's pretty apparent it hasn't been used in 8-months or simply has a blank My Docs folder, I don't know how that will go. I suppose somebody could make the argument that all…

The standard method is to use one operating system in normal, day-to-day operations and another (in a hidden volume) whenever you're doing something sensitive or potentially illegal (you would also change the MAC address, not use it on your own wifi network, and so forth). However, it's probably too much to hope that most people actually realize this, especially criminals. Extremely paranoid people will have absolute…

I didn't mean to imply that, I meant to imply one "should" have two different volumes with different operating systems as to ensure no artifices from your misdeeds are on the "day to day" volume (assuming said criminal is using Windows). I'm merely going off my understanding of the ideal TC setup, as I don't bother having one setup in such a manner.

I am of the opinion, as you stated, most criminals are not wise enough to go through the extra steps necessary to truly make TC hidden volumes reliable. From my experience, the extent of most peoples' tech savvy is running CCleaner or in the RAREST of cases Eraser. Though, I should say my experiences are 90% corporate.

Re: DOJ: We can force you to decrypt that laptop

#50

Earlier quoted context omitted.

Nobody has the right to avoid a reasonable search in the United States. You are protected by the fourth amendment from unreasonable searches, but you aren't going to convince me that a detective has no right, with a warrant in hand, to search a suspect's home for a murder weapon. Similarly, you aren't going to convince me that a prosecutor, warrant in hand, has no right to search a computer for evidence of credit car…

You still make the assumption that the prosecuted knows the password and is implicitly guilty. Imagine for a second that I was less technically minded and didn't use encryption and I purchased a used laptop from someone who did, I then get caught up in the legal system (guilty or innocent for the charged crime, it doesn't matter, but I did not use encryption) and some prosecutor has a warrant to compel me to unlock t…

But, in the hypothetical counter example where the prosecution had evidence of you using the encrypted volume (let's say, a convincing photograph or video), would you then grant the prosecution the right to compel the decrypted information?
Post reply on HN