Live data from Hacker News

Megaupload: A Lot Less Guilty Than You Think

cyberlaw.stanford.edu

41–50 of 122 posts

Re: Megaupload: A Lot Less Guilty Than You Think

#41
post #38

Earlier quoted context omitted.

Another excellent argument to use encryption. It seems every couple of weeks there is another high-profile incident where a lot of trouble would have been saved if people had taken the time to set up Enigmail. I would also love to see some advances in client-side steganography that could be usable as easily as GPG. Probably the closest thing we have now is TrueCrypt hidden volumes but that doesn't really work for ema…

Keeping encrypted data in the US is increasingly futile - see http://arstechnica.com/tech-policy/news/2012/01/judge-fifth-... . Steganography is a good idea, though. (edited: corrected stenography -> steganography per too-aggressive spellchecker usage)

> Stenography is a good idea, though.

Steganography is provably secure but requires a lot of cover data and careful implementation.

Steganography is less useful for most purposes than most people want.

Re: Megaupload: A Lot Less Guilty Than You Think

#42
post #38

Earlier quoted context omitted.

Another excellent argument to use encryption. It seems every couple of weeks there is another high-profile incident where a lot of trouble would have been saved if people had taken the time to set up Enigmail. I would also love to see some advances in client-side steganography that could be usable as easily as GPG. Probably the closest thing we have now is TrueCrypt hidden volumes but that doesn't really work for ema…

Keeping encrypted data in the US is increasingly futile - see http://arstechnica.com/tech-policy/news/2012/01/judge-fifth-... . Steganography is a good idea, though. (edited: corrected stenography -> steganography per too-aggressive spellchecker usage)

I think you mean steganography. "Stenography" is writing down what someone is saying.

Re: Megaupload: A Lot Less Guilty Than You Think

#43
post #17

Earlier quoted context omitted.

The sentiment that due process was not followed has come up multiple times. Is that what you mean by "well followed procedures"? If so, how did they violate due process? I am unaware of any way that they did. (Note that I am using "due process" to mean "due process as dictated by law" not "what I think is fair" or "the way I think things should be.") This article is really about the merits of the case, which is separ…

Well yes the fact that they are dead even before any judgement has been pronounced is quite infuriating. It's not a coincidence that money is seized and their domain name taken, it's made to destroy the website even before any kind of judgement can roll out. I may be the only one but I find that outrageous. But if the FBI loses this case and its image is tarnished then it could be a precedent and may change the way t…

I realize that you can lose your business if your equipment is confiscated and so forth, but isn't this akin to a temporary injunction? These stop a suspected-within-reason on-going crime and do not require a full trial to be placed. I don't know how long a temporary injunction lasts or what is considered reasonable, but every time I see the argument about shutting down the business, I am reminded of the temporary remedy. Perhaps it is abused in this case. IANAL and have little idea of what I am talking about, so please correct me on the legality here if you know better.

Re: Megaupload: A Lot Less Guilty Than You Think

#44
post #42
post #38

Earlier quoted context omitted.

Keeping encrypted data in the US is increasingly futile - see http://arstechnica.com/tech-policy/news/2012/01/judge-fifth-... . Steganography is a good idea, though. (edited: corrected stenography -> steganography per too-aggressive spellchecker usage)

I think you mean steganography. "Stenography" is writing down what someone is saying.

Indeed, I should have paid more attention to my spell checker which does not recognize "steganography". Thanks.

Re: Megaupload: A Lot Less Guilty Than You Think

#45
post #27

Earlier quoted context omitted.

So you're saying that the FBI should be allowed to arrest a business's operators and seize equipment that they believe are violating the law... but leave the business (which they believe is illegal) to keep running somehow? The FBI will attempt to prove that MegaUpload was an illegal business. Why should they just let it keep running if that is the case?

Why should the FBI be able to shut down a company without proving that the company is illegal first ?

I think the reasoning the feds use is it prevents the suspect from destroying evidence, and/or stops the activity from continuing to 'harm' the public.

Re: Megaupload: A Lot Less Guilty Than You Think

#46
post #41
post #38

Earlier quoted context omitted.

Keeping encrypted data in the US is increasingly futile - see http://arstechnica.com/tech-policy/news/2012/01/judge-fifth-... . Steganography is a good idea, though. (edited: corrected stenography -> steganography per too-aggressive spellchecker usage)

> Stenography is a good idea, though. Steganography is provably secure but requires a lot of cover data and careful implementation. Steganography is less useful for most purposes than most people want.

Unfortunately this is the case now. I am hoping that someone invents something that makes steganography more usable. "----BEGIN PGP MESSAGE----" is a little obvious for my taste, though of course encryption is much better than nothing.

Re: Megaupload: A Lot Less Guilty Than You Think

#47
post #38

Earlier quoted context omitted.

Another excellent argument to use encryption. It seems every couple of weeks there is another high-profile incident where a lot of trouble would have been saved if people had taken the time to set up Enigmail. I would also love to see some advances in client-side steganography that could be usable as easily as GPG. Probably the closest thing we have now is TrueCrypt hidden volumes but that doesn't really work for ema…

Keeping encrypted data in the US is increasingly futile - see http://arstechnica.com/tech-policy/news/2012/01/judge-fifth-... . Steganography is a good idea, though. (edited: corrected stenography -> steganography per too-aggressive spellchecker usage)

[deleted]

Re: Megaupload: A Lot Less Guilty Than You Think

#48
post #38

Earlier quoted context omitted.

Another excellent argument to use encryption. It seems every couple of weeks there is another high-profile incident where a lot of trouble would have been saved if people had taken the time to set up Enigmail. I would also love to see some advances in client-side steganography that could be usable as easily as GPG. Probably the closest thing we have now is TrueCrypt hidden volumes but that doesn't really work for ema…

Keeping encrypted data in the US is increasingly futile - see http://arstechnica.com/tech-policy/news/2012/01/judge-fifth-... . Steganography is a good idea, though. (edited: corrected stenography -> steganography per too-aggressive spellchecker usage)

It is not a settled question whether you can be forced to decrypt or not; some judges have considered encrypted drives protected and others have not. And the UK has compelled individuals to decrypt as well.

The fact remains that you are much better off encrypting in the first place even if you are eventually forced to decrypt. You can challenge the order to decrypt, you can add more time to the investigation and give your lawyers more time to put together a strategy for whatever angle they consider most prudent, you can prevent surreptitious listening that may arouse interest in your activity in the first place, and so on.

Even if you ultimately are forced to comply with an order to decrypt, which again is by no means guaranteed, you still do yourself a lot of favors by encrypting from the get go. And we haven't even mentioned protection from non-governmental entities like script kiddies, competitors, or tabloids.

Re: Megaupload: A Lot Less Guilty Than You Think

#49
post #40

Earlier quoted context omitted.

Another excellent argument to use encryption. It seems every couple of weeks there is another high-profile incident where a lot of trouble would have been saved if people had taken the time to set up Enigmail. I would also love to see some advances in client-side steganography that could be usable as easily as GPG. Probably the closest thing we have now is TrueCrypt hidden volumes but that doesn't really work for ema…

or just don't host in the USA, since apparently now you can be forced to decrypt. I wouldn't trust the UK, EU, Singapore, South Korea, Australia, New Zealand etc. either - which rules out most countries that have decent peering and colocation infrastructure. Can anybody suggest a country/host that is cheap, fast and outside of the reach or co-operation of a US federal investigation?

I don't think so. If you're really concerned about communication staying irretrievable by hostile players you will have to use some alternate channels and take care to ensure that you don't leave tracks on the devices that would get confiscated. I wouldn't just plop something in Costa Rica and expect it to be OK.

Re: Megaupload: A Lot Less Guilty Than You Think

#50

What kind of DMCA system did Megaupload provide? And what kind of DMCA system is required by law?

Apparently they responded to DMCA requests to take down individual links. But they did nothing to stop the same file from being uploaded again with a new link. I am not sure if that is required by the DMCA. I know youtube has this "fingerprinting" system that stops copyrighted uploads, but is that the law?

[deleted]
Post reply on HN