Live data from Hacker News

Australians who won't unlock their phones could face ten years in jail

nakedsecurity.sophos.com

71–80 of 167 posts

Re: Australians who won't unlock their phones could face ten years in jail

#71

Plausible deniability. The system should allow two (or more) passwords, one unlocks only the important stuff and one unlocks much less dangerous stuff while destroying any evidence of the first, including the multiple passwords protection layer. To add some credibility, the less dangerous data should contain something one could get in trouble for but not enough to have his life destroyed. As an example, if after bein…

Plausible deniability systems are pretty amazing but didn't seem to catch on. Truecrypt was awesome, it had hidden drives. Edit: "didn't seem to catch on" I mean you can't do this with popular products like FileVault. https://www.truecrypt71a.com/documentation/plausible-deniabi...

If LEO find you're using Truecrypt, do you think they'll not realize that you might have a hidden drive and ask for that password too??

Re: Australians who won't unlock their phones could face ten years in jail

#72

Earlier quoted context omitted.

that sounds like a really good idea and not that difficult to implement.

Truecrypt always had that - one password decrypts into your real partition, the other decrypts the prepared one, with a clear OS. It's impossible to say there is anything in the space where the hidden partition resides, and you have provided a password so at least in theory you are clear.

But it is possible to say that you have Truecrypt installed. Then the LEO just asks for the second password.

Re: Australians who won't unlock their phones could face ten years in jail

#73
post #49

Earlier quoted context omitted.

Yeah, the court would never figure that one out and charge with destruction of evidence!

For that to stick they would need proof that there was some evidence on the phone. Since the only way to prove that something was evidence on the phone is to know what was on the phone I'd expect that to be thrown out immediately. If they were able to get the phones contents from some other avenue then destroying the phone had no purpose.

> For that to stick they would need proof that there was some evidence on the phone.

They can make your life pretty fucking miserable while that's going on though.

And the innocence tax is pretty high. Most people on HN can afford good lawyers. What's the going rate for a good criminal defence team for a year?

Re: Australians who won't unlock their phones could face ten years in jail

#74
post #8

Genuinely curious - What is the current state / precedent for this type of situation in the US?

US: Life sentence. If a judge orders you to unlock your laptop/phone and you don't -- it could be a life sentence. IMHO, they go around the constitution with "Contempt of court". https://arstechnica.com/tech-policy/2017/03/man-jailed-indef...

Contempt of court is not a life sentence. It ends the moment the defendant complies. Whereas a sentence for a "10 years in jail for not revealing password" charge would not be vacated when you decide to reveal the password.

Re: Australians who won't unlock their phones could face ten years in jail

#75

Earlier quoted context omitted.

Plausible deniability systems are pretty amazing but didn't seem to catch on. Truecrypt was awesome, it had hidden drives. Edit: "didn't seem to catch on" I mean you can't do this with popular products like FileVault. https://www.truecrypt71a.com/documentation/plausible-deniabi...

If LEO find you're using Truecrypt, do you think they'll not realize that you might have a hidden drive and ask for that password too??

That is where LEO is screwed. They can't prove if you do or you don't have hidden data. EG. There isn't a /hidden_stuff_here/ directory. Its somehow baked into the encryption blocks.

Re: Australians who won't unlock their phones could face ten years in jail

#76

Earlier quoted context omitted.

Truecrypt always had that - one password decrypts into your real partition, the other decrypts the prepared one, with a clear OS. It's impossible to say there is anything in the space where the hidden partition resides, and you have provided a password so at least in theory you are clear.

But it is possible to say that you have Truecrypt installed. Then the LEO just asks for the second password.

> Then the LEO just asks for the second password.

But it's entirely _optional_ to use. They cannot prove there is a second password.

Re: Australians who won't unlock their phones could face ten years in jail

#77

Plausible deniability. The system should allow two (or more) passwords, one unlocks only the important stuff and one unlocks much less dangerous stuff while destroying any evidence of the first, including the multiple passwords protection layer. To add some credibility, the less dangerous data should contain something one could get in trouble for but not enough to have his life destroyed. As an example, if after bein…

LEO are not stupid. If you are using tech with this feature then they'll ask for both passwords.

N-passwords it is then.

Re: Australians who won't unlock their phones could face ten years in jail

#78

Earlier quoted context omitted.

Plausible deniability systems are pretty amazing but didn't seem to catch on. Truecrypt was awesome, it had hidden drives. Edit: "didn't seem to catch on" I mean you can't do this with popular products like FileVault. https://www.truecrypt71a.com/documentation/plausible-deniabi...

If LEO find you're using Truecrypt, do you think they'll not realize that you might have a hidden drive and ask for that password too??

Well, then you give them your second password, and it is fine, because you actually have 3 passwords.

The police can't just keep saying "we didn't find anything, therefore you MUST have ANOTHER double secret password!".

At that point you are indistinguishable from someone who is innocent.

Re: Australians who won't unlock their phones could face ten years in jail

#79

Earlier quoted context omitted.

Truecrypt always had that - one password decrypts into your real partition, the other decrypts the prepared one, with a clear OS. It's impossible to say there is anything in the space where the hidden partition resides, and you have provided a password so at least in theory you are clear.

But it is possible to say that you have Truecrypt installed. Then the LEO just asks for the second password.

Which is why you have 10 passwords, only 1 of which has the important stuff on it.

You are industiguisable from someone who has 9.

What, are the police just going to keep you in jail? What if you really ARE innocent? Jail for life then, because they didn't find anything incriminating?

Re: Australians who won't unlock their phones could face ten years in jail

#80

Don't keep anything sensitive on your phone, encrypted or otherwise. Keep it on some storage medium whose very existence is secret. They can't accuse you of refusing to unlock something whose whereabouts are unknown and, indeed, whose very existence is only alleged.

Related. The US government is starting to train dogs to find chemicals found in hard drives and usb drives. https://www.youtube.com/watch?v=Zt2UhSBCl8Q

Those chemicals aren't banned narcotics, so you can just plant them everywhere.
Post reply on HN