Live data from Hacker News

UK Police Charge Activist for Refusing to Hand Over Passwords

motherboard.vice.com

1–10 of 47 posts

Re: UK Police Charge Activist for Refusing to Hand Over Passwords

#2
Follow up from previous HN submitted article: https://news.ycombinator.com/item?id=14340137

Surprised more app developers are not creating solutions to this kind of thing - e.g. some form of multisig authorisation to access certain files or 2FA that relies on the second factor only being available at times access is genuinely needed.

Re: UK Police Charge Activist for Refusing to Hand Over Passwords

#3
post #2

Follow up from previous HN submitted article: https://news.ycombinator.com/item?id=14340137 Surprised more app developers are not creating solutions to this kind of thing - e.g. some form of multisig authorisation to access certain files or 2FA that relies on the second factor only being available at times access is genuinely needed.

I guess the challenge is one of UX; if you're hiding features behind specific sign-in patterns (to avoid security services) then you're also hiding them from a proportion of your users

Re: UK Police Charge Activist for Refusing to Hand Over Passwords

#4
post #2

Follow up from previous HN submitted article: https://news.ycombinator.com/item?id=14340137 Surprised more app developers are not creating solutions to this kind of thing - e.g. some form of multisig authorisation to access certain files or 2FA that relies on the second factor only being available at times access is genuinely needed.

I'm not a lawyer, but I very strongly doubt deliberately making yourself unavailable to give the password on demand is going to be perceived by a court as as cute a way around this law as you believe it to be.

There's no technological solutions to things like this, only political ones.

Re: UK Police Charge Activist for Refusing to Hand Over Passwords

#5
post #4
post #2

Follow up from previous HN submitted article: https://news.ycombinator.com/item?id=14340137 Surprised more app developers are not creating solutions to this kind of thing - e.g. some form of multisig authorisation to access certain files or 2FA that relies on the second factor only being available at times access is genuinely needed.

I'm not a lawyer, but I very strongly doubt deliberately making yourself unavailable to give the password on demand is going to be perceived by a court as as cute a way around this law as you believe it to be. There's no technological solutions to things like this, only political ones.

You're right but if this kind of security becomes the norm rather than the edge case, it becomes far more acceptable.

Re: UK Police Charge Activist for Refusing to Hand Over Passwords

#6
post #4
post #2

Follow up from previous HN submitted article: https://news.ycombinator.com/item?id=14340137 Surprised more app developers are not creating solutions to this kind of thing - e.g. some form of multisig authorisation to access certain files or 2FA that relies on the second factor only being available at times access is genuinely needed.

I'm not a lawyer, but I very strongly doubt deliberately making yourself unavailable to give the password on demand is going to be perceived by a court as as cute a way around this law as you believe it to be. There's no technological solutions to things like this, only political ones.

There are no political solutions to things like this either - not that any of us talking about it here have any meaningful hope of accomplishing, anyway. We might as well try whatever technical fixes we can come up with, since it's better than the nothing we'll get if we wait for the politicians to deal with it.

Re: UK Police Charge Activist for Refusing to Hand Over Passwords

#7
post #4
post #2

Follow up from previous HN submitted article: https://news.ycombinator.com/item?id=14340137 Surprised more app developers are not creating solutions to this kind of thing - e.g. some form of multisig authorisation to access certain files or 2FA that relies on the second factor only being available at times access is genuinely needed.

I'm not a lawyer, but I very strongly doubt deliberately making yourself unavailable to give the password on demand is going to be perceived by a court as as cute a way around this law as you believe it to be. There's no technological solutions to things like this, only political ones.

The tech solution might be giving partial keys to someone in another legal jurisdiction.

e.g. I send a partial key to my cousin and grandmother which live in another country. When crossing borders I then logout and cannot log back in without their part of the key. A local judge will not be able to compel someone in another country to cooperate - and my grandmother's local judge will not be able to compel her since the request is being made in another country.

Kind of hokey - but maybe it works?

Re: UK Police Charge Activist for Refusing to Hand Over Passwords

#8
post #4
post #2

Follow up from previous HN submitted article: https://news.ycombinator.com/item?id=14340137 Surprised more app developers are not creating solutions to this kind of thing - e.g. some form of multisig authorisation to access certain files or 2FA that relies on the second factor only being available at times access is genuinely needed.

I'm not a lawyer, but I very strongly doubt deliberately making yourself unavailable to give the password on demand is going to be perceived by a court as as cute a way around this law as you believe it to be. There's no technological solutions to things like this, only political ones.

I agree. In addition, if you pull a stunt like that, expect to have the book thrown at you to make an example of you. Part of the reason Ross Ulbricht's sentence was so harsh was to send a message.

Re: UK Police Charge Activist for Refusing to Hand Over Passwords

#9
post #4

Earlier quoted context omitted.

I'm not a lawyer, but I very strongly doubt deliberately making yourself unavailable to give the password on demand is going to be perceived by a court as as cute a way around this law as you believe it to be. There's no technological solutions to things like this, only political ones.

The tech solution might be giving partial keys to someone in another legal jurisdiction. e.g. I send a partial key to my cousin and grandmother which live in another country. When crossing borders I then logout and cannot log back in without their part of the key. A local judge will not be able to compel someone in another country to cooperate - and my grandmother's local judge will not be able to compel her since th…

That only works if you have a grandma in a non-extraditing country

Re: UK Police Charge Activist for Refusing to Hand Over Passwords

#10
post #4
post #2

Follow up from previous HN submitted article: https://news.ycombinator.com/item?id=14340137 Surprised more app developers are not creating solutions to this kind of thing - e.g. some form of multisig authorisation to access certain files or 2FA that relies on the second factor only being available at times access is genuinely needed.

I'm not a lawyer, but I very strongly doubt deliberately making yourself unavailable to give the password on demand is going to be perceived by a court as as cute a way around this law as you believe it to be. There's no technological solutions to things like this, only political ones.

We need security mechanisms that prevent such overreach being possible at all, just like Apple is doing with their hardware.
Post reply on HN