Live data from Hacker News

Man jailed over computer password refusal

bbc.co.uk

51–60 of 239 posts

Re: Man jailed over computer password refusal

#51

It seems like a bad idea to store anything incriminating on your local hard drive. Why not keep your encrypted files on a flash drive? If the police show up destroy the flash drive using a hammer, ensuring that the flash memory chip is thoroughly pulverized and completely unreadable. Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access…

Yes, of course any smart criminals will do that.

But my goal is not to be a smart criminal. My goal is to have a right to privacy to my own stuff.

That said, I don't see why the well-established precedents of opening locked doors and safes shouldn't apply to computers. If you subpoena my safe, I have to open it for you. Otherwise, I certainly won't.

Re: Man jailed over computer password refusal

#52

Encryption and password privacy is an entirely unsettled area of US law. The courts can probably compel you to enter your password (to decrypt a drive, or what have you), while you can maintain that the content of your password can be protected under the 5th. So, for instance, say you had encrypted files of plans to build a bomb and detailed schematics of the White House. The judge can order you to decrypt the files…

Can you provide some citations for your claims here? I'd really like to review them.

Re: Man jailed over computer password refusal

#53
post #11

Earlier quoted context omitted.

The police will just beat you up until the secret come out. They're not going to say "Drats! Our evil plans are foiled!" http://xkcd.com/538/

nah, the police can't torture you for your password. Only the evil criminals can do that. The courts can incarcerate you for not revealing a password, it's is up to you the criminal to decide if the punishment for not revealing the password is more/less severe than the punishment for whatever crime your hiding the evidence of with the password. Edit: OK now I have found evidence to prove myself wrong. At some point i…

technically no, but that's the beauty of extraordinary rendition.

Re: Man jailed over computer password refusal

#54
post #47

[deleted]

Absolutely. I think this is a great win for crypto; this guy is truly free from the prying eyes of the government.

It's good for society, too -- instead of convicting someone based on evidence on the guy's own computer (bringing into question context, chain of custody issues, and so on), the cops will have to build a solid case to convict him. When the police are forced to cross their ts and dot their is, society wins.

So I see this as good for everyone, even the children he may be abusing. They will get a fair trial that leaves no question about this guy's guilt. (If he is really guilty, of course.)

Re: Man jailed over computer password refusal

#55
This has happened before, although the details aren't clear. It was reported last year (http://www.theregister.co.uk/2009/08/11/ripa_iii_figures/) that two people had been convicted for similar offences. It seems that most people don't comply, but not all of them are charged: "Of the 15 individuals served, 11 did not comply with the notices. Of the 11, seven were charged and two convicted."

Re: Man jailed over computer password refusal

#56

Can anyone explain how TrueCrypt works for OS X? Could I have my entire home directory on the hidden partition? What about their hidden operating system feature? So I can have my normal OS as the decoy OS and then have a hidden Linux OS (as example) that I use for sys adm type stuff and boot to it when I need to? Can VMWare or Parallels see this partition and create a VM based on it?

Essentially, you can't true-crypt anything that can't run TrueCrypt before you need access to it. So you wouldn't be able to run TC and enter your password prior to logging in, which requires your home directory. Perhaps this could be sidestepped, but I'd think it'd be a mega-hack unless you can boot to a USB drive which can decrypt things and then boot OSX. I haven't heard of anyone doing that though, probably because Macs are a bit different with their bootup. You're essentially stuck making a file-as-a-volume or a hidden partition, though I don't know how / how well hidden partitions work in OSX.

Once your file / hidden partition is mounted, it's just another mounted volume. Anything which can read / write to a volume it's not on shouldn't notice a thing.

Also, it looks like it might just be Windows which gets the hidden-OS capability, as it requires a TC boot-loader on-disk or on an external booting device. Which means it should be possible for others as well, but it sounds like they haven't done it yet. http://www.truecrypt.org/docs/?s=hidden-operating-system

Re: Man jailed over computer password refusal

#57
post #28
post #3

Earlier quoted context omitted.

They already have this, It's called plausible deniability. What are the laws in the US on this?

In the US the current rules for personal hard drives are bound by the 5th amendment which has been interpreted as "a reasonable expectation for privacy." What happens is the police say "Give us your password and we'll drop whatever sentence by 75% for helping the investigation." You don't have to give your password but the NSA works pretty extensively with law enforcement and the FBI (most US cases that require passw…

Do you think the NSA is going to reveal to foreign governments that they've broken AES by going after some guy with child porn on his laptop? I personally doubt it.

Could the NSA cooperate with the FBI? Yes. Will they? Not if it means they can't spy on Russia anymore.

Re: Man jailed over computer password refusal

#58
post #50

It seems like a bad idea to store anything incriminating on your local hard drive. Why not keep your encrypted files on a flash drive? If the police show up destroy the flash drive using a hammer, ensuring that the flash memory chip is thoroughly pulverized and completely unreadable. Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access…

My understanding is that the "oops Agent Smith, my WiFi was unsecured" is not legally feasible, or is going away.. you are responsible for access to your pipe. Which sucks... heh.

Where did you get this idea from?

Re: Man jailed over computer password refusal

#59
post #21

I've been resetting people's 8 character passwords lost due to Post-Vacation-Insomnia for ages, I'd really like to see them expect me to remember a 50 character password under stress conditions.

I have a 12 character password and it is a pain in the ass to type it several times a day. I couldn't imagine using a 50 character password.

It is probably just a concatenated string of his credit card number or social security number and random words. I wonder if they are currently trying to crack it using some kind of dictionary brute force mechanism, or if there is some kind of lock out enabled after five tries.

Re: Man jailed over computer password refusal

#60

It seems like a bad idea to store anything incriminating on your local hard drive. Why not keep your encrypted files on a flash drive? If the police show up destroy the flash drive using a hammer, ensuring that the flash memory chip is thoroughly pulverized and completely unreadable. Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access…

I understand that in some areas, not only is it illegal to operate an insecure wireless access point (in the UK at least), you can be held accountable for the actions of people that use the access point.

[deleted]
Post reply on HN