Live data from Hacker News

Judge: Fifth Amendment doesn't protect encrypted hard drives

arstechnica.com

91–100 of 135 posts

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#91
post #89

It's a variant of what's called "rubber hose cryptology": sometimes it's technologically a lot easier to just beat the password out of someone (smacking the soles of one's feet with a rubber hose apparently being a rather effective technique). I draw the line using a "rag doll" model. They can compel fingerprints, physical keys, DNA, etc. insofar as they can manipulate your limp unresitive (albeit uncooperative) body…

Could you not then argue the same for data encryption? Bruteforcing it would be the equivalent of a blowtorch in that case. Would that not then mean that they can compel you to give the key/password?

A blowtorch can open such a safe in <1 day. Depending on the encryption, cracking it in a year might be impressive. And that assumes they can prove it's even there.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#92
post #45
post #6

Earlier quoted context omitted.

I can see the legal issues that would be forthcoming if you refused to share the key to allow for access or agree to type it in yourself. Obstruction and all that. I'm wondering what the legal ramifications might be if you set a secondary key that would wipe the drive in the most secure method possible and then provide that key. Or even the alternate boot sequence as suggested.

These "wipe the drive" decoy password scenarios would never work in real life unless their forensics team was really inept. There would be copies made and the drive that has the encrypted volume would likely be accessed with a "Write Blocker" forensic device, or in a virtual environment, etc. This technique would only tip your hand that the volume contents changed after entering the password.

A technical solution to this might be a form of encryption the requires a writable disk to actually decrypt anything. I don't know if that is possible, but it would effectively prevent these safeguards to work. And remember, you don't need to wipe the entire drive. Changing a few random bits in the decryption key would already forever turn the drive contents into unreadable garbage.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#93

It's a variant of what's called "rubber hose cryptology": sometimes it's technologically a lot easier to just beat the password out of someone (smacking the soles of one's feet with a rubber hose apparently being a rather effective technique). I draw the line using a "rag doll" model. They can compel fingerprints, physical keys, DNA, etc. insofar as they can manipulate your limp unresitive (albeit uncooperative) body…

Being ordered to produce documentary evidence is not the same as being compelled to testify against yourself. Defendants are ordered to produce evidence all the time in the form of subpoenas.

http://en.wikipedia.org/wiki/Subpoena_duces_tecum

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#94
post #59
post #19

Earlier quoted context omitted.

>Even better, there's no proof that you're the one who destroyed the keys: you can't be charged with evidence tempering. The court doesn't really work this way. Just because you cross your fingers when you do something doesn't mean you aren't going to be charged with destruction of evidence.

The way courts generally work, they need a proof you've done something wrong to condemn you. If there are a dozen friends who had the wiping rights to your keys, and they knew you'd been arrested, any of them could have decided to wipe the key, just in case. Unless the judge can prove who did it, he can't condemn the 13 (12+you) of you because one of you did something wrong. Besides, the 12 innocents don't know who d…

Unfortunately, setting up such a scheme is clearly intended specifically to create reasonable doubt, which can get you charged with obstruction and contempt.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#95
post #72

Earlier quoted context omitted.

that's the most dodged response ever. i think for his question to even be made, it was assumed he was being accused of possessing encrypted something. Let's attach the old guy from france that got into the 3 strike law without even having a computer at the time. Now let's say instead of getting the IP of that old guy from france, the police got the IP of the comment above yours, from let's say mr Buttle. Now they con…

Then explain that to the judge. The defendant in this case is not claiming to be the victim of mistaken identity.

that was even less to the point. you are good

ignore the mistaken identity, was just a means to reach the false/wrong accusation resulting in the experiment he just did convicting him.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#96
post #67
post #10

Earlier quoted context omitted.

To me, the most convincing argument is, what if you legitimately forget your password? If that alone gets you thrown in jail, then you're going to be jailing a lot of innocent people. On the other hand, if that does not get you thrown in jail, then one can simply claim to have forgotten the password without repercussion. Personally, I'd rather let people hide evidence by encrypting it than jail people for being forge…

You're creating a dichotomy that doesn't exist. What actually happens is that there is an intent element to crimes associated with destroying evidence. So you might get in trouble for purposefully destroying evidence, or in some cases negligently destroying evidence (e.g. a company that didn't have a proper data-retention policy). You usually can't get in trouble for accidentally destroying evidence. Then, you testif…

And what if the police just think the drive holds the bank codes for all the money I embezzled, but is actually an archive of amusing cat pictures I forgot the password to a year ago?

Seems to me that the only way to reasonably apply "innocent until proven guilty" there is to only convict if they know what the encrypted contents are, and if they can already prove that beyond a reasonable doubt, why do they even need you to decrypt them for you? Conversely, if they don't know the contents, then they may well be innocent, and the password innocently forgotten.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#97
post #45

Earlier quoted context omitted.

These "wipe the drive" decoy password scenarios would never work in real life unless their forensics team was really inept. There would be copies made and the drive that has the encrypted volume would likely be accessed with a "Write Blocker" forensic device, or in a virtual environment, etc. This technique would only tip your hand that the volume contents changed after entering the password.

A technical solution to this might be a form of encryption the requires a writable disk to actually decrypt anything. I don't know if that is possible, but it would effectively prevent these safeguards to work. And remember, you don't need to wipe the entire drive. Changing a few random bits in the decryption key would already forever turn the drive contents into unreadable garbage.

Even then, there would be nothing stopping an adversary from making a bit-for-bit copy of the data and attempting to decrypt the (writable) copy.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#98
post #57

It's a variant of what's called "rubber hose cryptology": sometimes it's technologically a lot easier to just beat the password out of someone (smacking the soles of one's feet with a rubber hose apparently being a rather effective technique). I draw the line using a "rag doll" model. They can compel fingerprints, physical keys, DNA, etc. insofar as they can manipulate your limp unresitive (albeit uncooperative) body…

But when it comes to the state's evidence hinging entirely upon the defendant's cooperation, no - that's why we have the 5th Amendment (gov't cannot compel one to testify against self). And really, doesn't that mean it (whatever is obscured by a lack of cooperation) shouldn't be considered a crime? Kind of by definition?

Not if they find a way to get to it and it incriminates you. otherwise, lack of coooperation because you are exercising your rights is not supposed to be used as evidence of a crime.

not letting the police into your home is not in any way considered valid criteria for a judge to issue a search warrant, as i understand it.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#99

Earlier quoted context omitted.

TrueCrypt does exactly that. The problem is that everyone knows about it; so the police will always suspect there is a second hidden section.

From what I gathered Truecrypt provides plausible deniability through hidden volumes that appear to be random data. AFAIK it doesn't allow you to have a partition that when you decrypt with a certain password transforms to alternate content. So if the feds know you have something encrypted you might be in trouble.

well, it lets you have a fully functional alternate system (both systems are encrypted) that will show up if the correct password is used, with no direct forensic way to prove it exists at all, by design. There indirect ways, outlined intheir faqs quite well, that could beused to suggest you have multiple instqnces, like multiple windows updates for thesame updates from th same system, that kinda thing..... but with enough diligence you could pull it off. there are also some write restrictions iirc - may enim wrong but i think if you write to the alternate system you cansquash data inadvertently from the primary as thesecondary can have no knowledge of thereal system in any way, makingn this unavoidable.

pulling this off would require a level of diligence most people justdonthave, andthere are easierways to hide your data.

Re: Judge: Fifth Amendment doesn't protect encrypted hard drives

#100

I have question to those who know more about these things: Instead of hidden volumes, wouldn't it be better to have an "under duress" password? The hard drive is encrypted and sensitive folders are identified by the user. When a password is given all contents are decrypted. When a "under duress" password is given the sensitive folders are permanently wiped and all the (remaining, innoculous) contents are decrypted. T…

I was thinking along the same lines, but instead of wiping the file, it changes the password to a randomized 20 character string. If you're doing anything that risks getting pinched, it's probably better to take the obstruction rap than whatever it is you're being investigated for.

or use a better method to keep your data unknown to the world that doesnt requre as much precision handling...

or like, dont break the law, or dont get caught.

Post reply on HN