Live data from Hacker News

Judge: Fifth Amendment doesn't protect encrypted hard drives

arstechnica.com

41–50 of 135 posts

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#41
post #28

An important clarification since some people seem to be confusing the issue: the police seized her computer already, presumably legally and with a warrant. So while this does present an interesting edge case in the fifth amendment (does evidence count as evidence if it's encrypted?), it shouldn't set off civil liberty alarm bells in your head nearly as badly as several other things currently going on in this country.

I disagree. If you can be jailed for refusing to decrypt data on a computer seized under a legitimate warrant, then you can be jailed for not having the password for encrypted-looking data on a computer seized under a legitimate warrant. A warrant does not imply guilt, so this means innocent people may be imprisoned.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#42
post #19
post #12

To counter this, you need an encryption method with these properties: - you can be banned or self-banned, irrevocably, from accessing your data; - you can prove to the judge that you can't access your data; - even with full forensic copies of your disk, you can't be un-banned. You can do that by having part(s) of the key on server(s) online. Give yourself, a couple of trusted friends and optionally a script, the abil…

>Even better, there's no proof that you're the one who destroyed the keys: you can't be charged with evidence tempering. The court doesn't really work this way. Just because you cross your fingers when you do something doesn't mean you aren't going to be charged with destruction of evidence.

If an office had a policy of shredding old financial paperwork and that policy was faithfully followed on the day after, say, the COO was whisked away for embezzlement, would it count as evidence tampering?

Or to the point: if you use a remotely-stored encrypted volume with a dead man's switch as a day-to-day security policy, would it still be trivial to charge someone for evidence tampering?

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#43
post #7
post #3

Earlier quoted context omitted.

Yes. The term for that is plausible deniability. It is implemented (probably among others) in truecrypt: http://www.truecrypt.org/docs/?s=plausible-deniability

Plausible deniability is a much larger concept than that. Also if they know you're using Truecrypt, the "deniability" of the existence of a 2nd (or 3rd or 4th) OS goes down significantly.

I'm not so sure. TrueCrypt is first and foremost an encryption program. The fact that you have it might suggest that you encrypted something somewhere, but it doesn't directly suggest that you took the time to use its advanced "hidden volume" capabilities. So even if the police can say "hey, this looks encrypted, and you've got nothing else which looks similar, decrypt it for us," they are still stuck on "hey, we didn't find the evidence we were looking for -- maybe you have a hidden volume?". You say "I don't" and the judge says "GRR ARG DECRYPT IT NOW" and you say "I can't, it doesn't exist, I really am innocent, please get the scary men away from me."

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#44

I have question to those who know more about these things: Instead of hidden volumes, wouldn't it be better to have an "under duress" password? The hard drive is encrypted and sensitive folders are identified by the user. When a password is given all contents are decrypted. When a "under duress" password is given the sensitive folders are permanently wiped and all the (remaining, innoculous) contents are decrypted. T…

It would still be possible to copy the hard drive at a lower level before password entry. You could then compare before and after password entry and see that large chunks of data have been modified.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#45
post #6

Any technologies exist that let you have multiple encrypted OS's on multiple keys? For example, 1 key could boot up one OS and another key could boot up a different OS. Seems like it'd be difficult to prove that you booted one or the other...

I can see the legal issues that would be forthcoming if you refused to share the key to allow for access or agree to type it in yourself. Obstruction and all that. I'm wondering what the legal ramifications might be if you set a secondary key that would wipe the drive in the most secure method possible and then provide that key. Or even the alternate boot sequence as suggested.

These "wipe the drive" decoy password scenarios would never work in real life unless their forensics team was really inept.

There would be copies made and the drive that has the encrypted volume would likely be accessed with a "Write Blocker" forensic device, or in a virtual environment, etc.

This technique would only tip your hand that the volume contents changed after entering the password.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#46

What if lawyer-based service is created, which allows to automate representation of client including when client need access to data on the his hard drive. Essentially, develop algorithm allowing external OTP authentication. And this lawyer, representing user, will have in agreement something like this "In case my client is under investigation or incriminated or ..." I will not be allowed to release OTP password. Of…

In my lay opinion, you are treading very close to making the lawyer complicit in the crime, at which point there is no privilege shield.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#47

I have question to those who know more about these things: Instead of hidden volumes, wouldn't it be better to have an "under duress" password? The hard drive is encrypted and sensitive folders are identified by the user. When a password is given all contents are decrypted. When a "under duress" password is given the sensitive folders are permanently wiped and all the (remaining, innoculous) contents are decrypted. T…

What you want to do is to have a password that decrypts the content to something innocently looking. If the encryption program has the feature to both "dual encrypt" and do an ordinary encryption it should be hard to prove anything :) Not sure how you go about doing that algorithmically though so it would resist reverse engineering the program

TrueCrypt does exactly that. The problem is that everyone knows about it; so the police will always suspect there is a second hidden section.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#48

What if lawyer-based service is created, which allows to automate representation of client including when client need access to data on the his hard drive. Essentially, develop algorithm allowing external OTP authentication. And this lawyer, representing user, will have in agreement something like this "In case my client is under investigation or incriminated or ..." I will not be allowed to release OTP password. Of…

In my lay opinion, you are treading very close to making the lawyer complicit in the crime, at which point there is no privilege shield.

Only if lawyer is USA based this might make him commit a crime. But what if lawyer based in the country where forcing to reveal password is unlawful?

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#49
post #41
post #28

An important clarification since some people seem to be confusing the issue: the police seized her computer already, presumably legally and with a warrant. So while this does present an interesting edge case in the fifth amendment (does evidence count as evidence if it's encrypted?), it shouldn't set off civil liberty alarm bells in your head nearly as badly as several other things currently going on in this country.

I disagree. If you can be jailed for refusing to decrypt data on a computer seized under a legitimate warrant, then you can be jailed for not having the password for encrypted-looking data on a computer seized under a legitimate warrant. A warrant does not imply guilt, so this means innocent people may be imprisoned.

I agree completely.

Just saying that a question of what a court can compel you to do as part of a trial (before sentencing) is a quite different than a fourth amendment issue of illegal search and seizure which it seems some people are conflating this with.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#50

I have question to those who know more about these things: Instead of hidden volumes, wouldn't it be better to have an "under duress" password? The hard drive is encrypted and sensitive folders are identified by the user. When a password is given all contents are decrypted. When a "under duress" password is given the sensitive folders are permanently wiped and all the (remaining, innoculous) contents are decrypted. T…

Then they restore the hard drive from the cloned image they made before entering the password and ask you once more for the password. This time, with feeling.

They would also tack on extra charges for interfering with a police investigation by attempting to destroy evidence, and/or the court would find you in contempt.
Post reply on HN