Live data from Hacker News

Judge: Fifth Amendment doesn't protect encrypted hard drives

arstechnica.com

61–70 of 135 posts

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#61

Earlier quoted context omitted.

What you want to do is to have a password that decrypts the content to something innocently looking. If the encryption program has the feature to both "dual encrypt" and do an ordinary encryption it should be hard to prove anything :) Not sure how you go about doing that algorithmically though so it would resist reverse engineering the program

TrueCrypt does exactly that. The problem is that everyone knows about it; so the police will always suspect there is a second hidden section.

From what I gathered Truecrypt provides plausible deniability through hidden volumes that appear to be random data. AFAIK it doesn't allow you to have a partition that when you decrypt with a certain password transforms to alternate content. So if the feds know you have something encrypted you might be in trouble.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#62

Earlier quoted context omitted.

What you want to do is to have a password that decrypts the content to something innocently looking. If the encryption program has the feature to both "dual encrypt" and do an ordinary encryption it should be hard to prove anything :) Not sure how you go about doing that algorithmically though so it would resist reverse engineering the program

TrueCrypt does exactly that. The problem is that everyone knows about it; so the police will always suspect there is a second hidden section.

Is it possible to have a third volume as well, opened with a different key? Or a fourth?

Maybe the solution is to have a first "primary" partition, then an "under duress" partition which you'll fight tooth and nail to protect, filing every appeal possible... and if you finally do give up the key, it's filled with entirely legal but extremely embarrassing pornography, plus a few self-written Harry Potter fanfictions.

Meanwhile, whatever you're ACTUALLY trying to hide is on a third.

Sure, it's a big damn hassle, but if you're conscious enough about the stuff you're trying to hide to go with a TrueCrypt hidden volume, it'll be worth your effort.

(I'm not actually sure this is possible, but if it is, I'm sure someone else has come up with it already.)

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#63
Classical jibberish passwords are mostly muscle memory. I know I wouldn't be able to remember some of my mine of that sort after two weeks.

If you were incarcerated and you knew you might have to comply with an order to decrypt a hard drive, it might be in your best interest to create and shadow type many alternate passwords until you actually forget the important one. Then (hopefully) you're just a polygraph away from a not guilty in an obstruction charge.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#64

Earlier quoted context omitted.

What you want to do is to have a password that decrypts the content to something innocently looking. If the encryption program has the feature to both "dual encrypt" and do an ordinary encryption it should be hard to prove anything :) Not sure how you go about doing that algorithmically though so it would resist reverse engineering the program

TrueCrypt does exactly that. The problem is that everyone knows about it; so the police will always suspect there is a second hidden section.

What you really need is a hard disk encrypted with many different partitions, e.g. one for programming projects, one for web browsing, one for email and correspondance, one of movies, one for porn, etc. This should be done using encryption software that allows for 100s of partitions, so it would be a lot harder for the police to argue that you're hiding some partitions.

The software should also, when if formats the disk, leave a random area of c.5% of it free, so the police can't count up trhe size of all your partitions and figure out you're hiding something.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#65

Earlier quoted context omitted.

In my lay opinion, you are treading very close to making the lawyer complicit in the crime, at which point there is no privilege shield.

Only if lawyer is USA based this might make him commit a crime. But what if lawyer based in the country where forcing to reveal password is unlawful?

In the USA it is not legal (in violation of the 5th amendment) for the court to compel you to reveal a password (if your read the brief the Judge says as much). However, if the court can prove by other means that you own the data on a drive, they can compel you to provide them with the unencrypted contents of the drive via a search warrant.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#66
post #42
post #19

Earlier quoted context omitted.

>Even better, there's no proof that you're the one who destroyed the keys: you can't be charged with evidence tempering. The court doesn't really work this way. Just because you cross your fingers when you do something doesn't mean you aren't going to be charged with destruction of evidence.

If an office had a policy of shredding old financial paperwork and that policy was faithfully followed on the day after, say, the COO was whisked away for embezzlement, would it count as evidence tampering? Or to the point: if you use a remotely-stored encrypted volume with a dead man's switch as a day-to-day security policy, would it still be trivial to charge someone for evidence tampering?

> If an office had a policy of shredding old financial paperwork and that policy was faithfully followed on the day after, say, the COO was whisked away for embezzlement, would it count as evidence tampering?

If it could be reasonably expected that the financial paperwork would be relevant to the ongoing litigation, yes, you're in trouble for destroying it. When companies are on notice of pending litigation, from that point forward they are required to take affirmative steps to preserve potentially relevant evidence. Failure to do so was one of the things that got the Enron folks in trouble.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#67
post #10
post #5

Just out of curiosity, what's the case-law like if she had encoded these documents and stored them on paper? I certainly don't want to see mandatory decryption, but at the same time it doesn't make sense to let an accused completely skip out on discovery by simply truecrypt-ing the evidence either.

To me, the most convincing argument is, what if you legitimately forget your password? If that alone gets you thrown in jail, then you're going to be jailing a lot of innocent people. On the other hand, if that does not get you thrown in jail, then one can simply claim to have forgotten the password without repercussion. Personally, I'd rather let people hide evidence by encrypting it than jail people for being forge…

You're creating a dichotomy that doesn't exist. What actually happens is that there is an intent element to crimes associated with destroying evidence. So you might get in trouble for purposefully destroying evidence, or in some cases negligently destroying evidence (e.g. a company that didn't have a proper data-retention policy). You usually can't get in trouble for accidentally destroying evidence. Then, you testify as to your intent, and the jury gets to decide whether you're telling the truth, making inferences from your circumstances. People might believe you forgot the password to some drive you never use, but probably won't believe you forgot the password to the drive holding the bank codes for all the money you embezzled.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#69
post #59
post #19

Earlier quoted context omitted.

>Even better, there's no proof that you're the one who destroyed the keys: you can't be charged with evidence tempering. The court doesn't really work this way. Just because you cross your fingers when you do something doesn't mean you aren't going to be charged with destruction of evidence.

The way courts generally work, they need a proof you've done something wrong to condemn you. If there are a dozen friends who had the wiping rights to your keys, and they knew you'd been arrested, any of them could have decided to wipe the key, just in case. Unless the judge can prove who did it, he can't condemn the 13 (12+you) of you because one of you did something wrong. Besides, the 12 innocents don't know who d…

You can also require at least 2 or 3 (or so) of your friends to all press the key to wipe your data. That way you don't have to trust everybody completely.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#70
post #5

Just out of curiosity, what's the case-law like if she had encoded these documents and stored them on paper? I certainly don't want to see mandatory decryption, but at the same time it doesn't make sense to let an accused completely skip out on discovery by simply truecrypt-ing the evidence either.

Interesting argument. Or what about different languages: if I write it in German, they can just get a translator. If I write it in a language of my own creation (hat tip to Tolkien here), then can they force me to translate?

Or if you write in gibberish, who does the burden of proof fall on to demonstrate the information is truly 'random' and not a cypher?
Post reply on HN