Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
British authorities demand encryption keys in case with “huge implications” (theintercept.com)
124 points by jackgavigan on April 2, 2016 | hide | past | favorite | 87 comments


I am not sure how this would be a precedent. People have already gone to jail in the UK under this law [1]

I wonder if "I don't remember it" is a defense against this law. How can a court send someone to jail for not remembering a password?

[1] https://en.wikipedia.org/wiki/Key_disclosure_law#United_King...


One lesser-known fact about laptop hard drive encryption (the kind that's built in to the SATA firmware) is that the passphrase used to encrypt the disk is often not the passphrase that you type in to the BIOS. On Lenovo laptops, for example, the passphrase is generated by a complex calculation that was only known to Lenovo until someone reverse-engineered it: https://jbeekman.nl/blog/2015/03/lenovo-thinkpad-hdd-passwor...

If you remove the disk from the laptop (perhaps because the laptop breaks) you are unable to decrypt it (or remove the encryption key to reuse it as a blank disk, for that matter) unless you can reproduce not just the passphrase that you type in, but also the algorithm that the BIOS used to set the password on the disk. If you no longer have the laptop that you originally used to encrypt the disk then it's going to be difficult to decrypt the disk even if you do know the password.

Imagine the conversation:

"What's the encryption password for this disk?"

"'changeme'"

"Hmm. That doesn't seem to work with hdparm..."

"Well, that's what I typed into the laptop to unlock the disk, but it may not be what the laptop sends to the disk. I have no knowledge of the algorithm that <laptop supplier> uses, and no longer have the original laptop."

"Ok. Wait there while we talk to the laptop supplier."


Security by obscurity, it's useless. It must be some kind of known key derivation function. If it's something home-grown then actually that's much worse as I doubt Lenovo employs world-class cryptographers who can design something better than e.g. bcrypt or scrypt.


I don't buy that. For stuff like key derivation, there are loads of ways you could vary the process without compromising security.

For example, a normal disc encryption system with the caveat that the password is XORed with a secret before the key derivation algorithm is used (where the secret is unique to the exact laptop model) would effectively stop all decryption in its tracks until you knew the exact laptop model, but would not compromise security at all.


Where are you suggesting to keep the "secret" (to be XORed with)? It must be stored somewhere in the firmware or on the disk, right? Then I'm afraid it's not a secret, it's just a second salt (which KDF functions already have one) and can be easily read. I just don't see the point.


The point is if you no longer have the laptop and hadn't previously extracted the "second salt", thus out of luck

And you are probably unaware of why your password doesn't work.

Were you aware of this issue before GP posted ? I wasn't.


There would be lists of per-model salts shared online in days.


It could be a per-device salt.


And it could be stored in a tamper-proof chip on the device itself...


It's useless if the only method. If it slows down potential attack then it's just as effective as, say, multiple encryption cycles.


I have a password with multiple special characters and no dictionary word which I type on my laptop everyday and yet I genuinely don't remember it. It's called muscle memory[1].

I haven't tried it, but I guess there are all the chances that I will "forget" the password after a couple of weeks once I'm not typing it daily.

[1] https://en.wikipedia.org/wiki/Muscle_memory


That's ok, they'll give you a keyboard.


I can, eventually and with many attempts, sit down in front of a keyboard and type out passwords that I last used regularly twenty years ago. Don't sell your muscle memory short. If it's a password that you are typing in multiple times per day you aren't going to forget it in just a few weeks.


More than once I have forgotten the pattern to unlock my phone. The very pattern I draw on the screen more than a dozen times a day. I usually remember it after a few hours without thinking about it, but sometimes I just can't recall it.

Shouldn't this law take into consideration that some people have terrible memories?


You aren't permanently forgetting it though, you're just temporarily forgetting it, and you're blanking on it worse than most people do.

Law enforcement isn't going to care if it takes you a little bit of time to get past your mental block and come up with the password. It's a much bigger deal if you truly forget it and can't reconstitute it at all.


[Edit] I stand corrected, decryption keys are apparently mostly 256bitAES

I still think is not realistic to remember them.

If it is just a password to a wallet of keys or an OS then authorities are more than capable of cracking them - just like FBI vs Apple.

[edit] disagree ? -- Read the court filing , they assert exactly what is on each disk.

https://www.documentcloud.org/documents/2781972-Lauri-Love-c...

If they already know the disk contents then it is not unreasonable to assume :

[Edit] IMHO this fits with the trend of sending chilling effects to journalists - as when they send police with angle grinders to chop up computers and hard drives to the Guardian newspaper ( who then moved to America ).


A decryption key is more likely to be a 256bit AES key, which can be a hash of a strong password. There is no need for public key when encrypting a drive.


Can you remember a 256bit AES key, though ?


Again you don't need to. You need to remember a password, and the hash of that password will be your encryption key.


It gets more interesting when someone has written random data to a disk to wipe it, and authorities assume it's some form of encryption.


Good encryption is indistinguishable from random data.

But RIPA has so far required no proof, only prosecutor assertion.

RIPA is neither cricket nor Queensbury but shameful.


When you write random data to the disk, you will also destroy the boot mount (that little partition that is not encrypted so you can boot the PC and show the password dialog). If you don't overwrite this partition, they police might believe that there is actual data on that disk. And I don't see any reason why you would not erase that part.

Furthermore, if the encrypted AES keys are not stored in that boot partition, and you overwrite them, the algorithm might detect that the keys are corrupted and refuse to decrypt them with the given password. This once happened to me when a disk failed and corrupted the section where these keys were apparently stored. I don't know how truecrypte (the software used to encrypt the hard drive) handles drive encryption, though, so my information might not be accurate.


"When you write random data to the disk, you will also destroy the boot mount"

Except for when you don't... It would be perfectly reasonable for somebody to just overwrite the partition containing the encrypted data, and not the entire disk.

Some people stick their /boot/ partition on external storage which they carry on their person to make Evil Maid attacks more difficult. The drives on those peoples laptops will only contain encrypted data.


I think if you could show eg brain injury that you'd have some ability to fight the order.

http://www.legislation.gov.uk/ukpga/2000/23/part/III

> (4) [...] and the time specified for the purposes of paragraph (f) must allow a period for compliance which is reasonable in all the circumstances

...but it's probably a bad idea to rely on "I forgot the passphrase".


But this would imply you have a legal obligation to remember something under the penalty of jail time (and people have been sentenced to more than a year under this law). How can it be enforceable? It's a bit like telling me I have the legal obligation to run a marathon under x hours. My body may allow me to do so, or maybe not. But how can it be a legal obligation?

[edit] actually reading the actual law, the wording is being "in possession of a key", and the police has to prove that you are in possession beyond any reasonable doubt. Can a word in someone's brain be characterised as being in possession? And how can the police prove that someone remembers something?

For the purposes of this section a person shall be taken to have shown that he was not in possession of a key to protected information at a particular time if—

(a) sufficient evidence of that fact is adduced to raise an issue with respect to it; and

(b) the contrary is not proved beyond a reasonable doubt.


The same things happens everywhere, but just through a different route (contempt charges, etc.) The court, and by proxy the rest of us, usually finds it interesting that for some reason you were able to remember this password on a daily basis while conducting your alleged crimes, but now you suddenly have a memory problem. We have children too, and recognize this pattern...

You can claim to not remember the password. We can choose not to believe you.


They may not believe me but how can they prove it?

[edit] plus forgetting a password is the most common thing in the world. My work password changes every 3 months. When I go on holiday for 2 weeks, half of the time when I come back I forgot what the latest password is. Now imagine you have been arrested, slept in jail, had rough questioning, being under intense stress. Forgetting a password in these conditions could very well happen in good faith.

The other things is that many of my passwords are stored in my "muscle memory", if I am in front of my usual keyboard I would type them without really thinking about it. But if I am in a room with no computer, I could easily not even remember them.

In any case I don't see how there cannot be a reasonable doubt if someone claims to have forgotten a password.


They don't have to "prove it", the judge or the jury just has to come to the conclusion that you are not telling the truth and you go to jail.


I am not a lawyer but the law does say the contrary is not proved beyond a reasonable doubt. Which is a reasonable burden for sending someone to jail.


Doesn't this mean the prosection makes an assertion and the defendant has to prove the contrary ?

The context for the bit you quote says the defendant must prove the contrary (their innocence).

It does say evidence is required and states that evidence is an assertion of the date and details of the file, nothing more.

This is not a law to be prosecuted but an investigtory power, an obstruction of justice , there is no jury, the judge decides, like contempt of court.

This then imposes a "disclosure requirement" , no further proof is required to jail someone who non-compliant, no jury is involved.

IMHO the standard of proof is no more than prosecutorial assertion of file contents & date so to my mind it guilty by accusation until proven innocent - a travesty.

IMHO the standard of proof is so low, file contents & date that it really seems one is guilty until proven innocent


No, the quote from s 53(3)(b) refers to a defence. You are not in possession of the password if sufficient evidence is adduced to raise an issue (https://en.wikipedia.org/wiki/Evidential_burden), and the contrary (ie. that you were in fact in possession) is not proved beyond reasonable doubt. Typically you would discharge the evidential burden by giving sworn evidence that you have forgotten the password. The prosecution would then have to adduce evidence that proves the contrary beyond reasonable doubt, for example evidence that you had used the password every day for the past few years.

Secondly, this is a 'law to be prosecuted' in the sense that s 53 creates an ordinary criminal offence. Section 49 creates the investigative power to issue a notice compelling someone to disclose a password, and s 53 makes it a criminal offence not to comply with the notice.


So the defendant must expicitly deny it before proper proof is presented ?

What sort of thing could possibly prove innocence ? A coma or merely a denial ?

The text of RIPA49 states the only defense is to produce the documents and prove you were entitled to them - which is very different.

The law does state that the initial proof is only content description and date which seems a lower standard than beyond reasonable doubt.

So it creates a criminal offense, does that mean the proof must be beyond a reasonable doubt and is that a jury trial ?

What proof was presented in the previous 3 RIPA49 jailings ?

IP addresses, footage or testimony that the guy was using that computer at that time, i.e. means and opportunity ?

My guess is not but I really hope you can show I mistaken and British Justice still stands.


RIPA trumps proof & only requires prosecutorial assertion.

Under RIPA there is no presumption of innocence.

Unbelievable yet sadly true.

[Edit] -- disagree? Well so far this has been how it has played out in practice - if you disagree I challenge you to show me where proof was presented in the other three cases ?

It is requirement by court order, one is then held in contempt of court - it is entirely up to the judge - no jury involved.

We shall see whether any proof is offered, none is in the court filing, though they assert exactly what each file contains:

https://www.documentcloud.org/documents/2781972-Lauri-Love-c...

Or we won't see because this is a secret trial - as the article and court filing state !


Yup reading the law clearly show the only proof is the prosecution states the contents and date as they do in the filing.

The filing contains what they call proof, I believe it better characterised as an assertion.

No jury, just a judge decides if Lauri goes to jail and the only thing that can prevent it is if he proves the contrary.

Ever try and prove a negative ?

Decryption showing no file won't necessarily be sufficient, as the document could still be on a double decrypt in the salt.

They want named documents, the defendant gives them up or goes to jail.

Interesting to note one of the documents is "pirate" movies. (The court filing literally says "pirate", wtf does that even mean). Suppose the movie was crap and he deleted it.

IMHO RIPA 49 is a travesty should not be legal.

Quite possibly isn't, we shall see when it gets to the human rights court - though if I had to put money on it the govt. knows its dodgy and won't let it go that far.


Can no longer edit this but sjy is correct , they accuse and accused denies it they get a jury trial :

http://www.bbc.co.uk/news/uk-25745989 Luton terrorist forced to decrypt USB stick by RIPA.


We have a legal obligation to remember many things, like what road signs mean or when to send tax form to IRS. How is requiring to remember password any different?


Those are things that when you forget them, you can take steps to re-learn them, because the information is publicly available.

On the other hand, I am absolutely certain that I have truecrypt volumes on old backup drives somewhere that I haven't the foggiest idea what the corresponding passphrase is anymore.


The former things are all public information, meant to serve a public function. Personal passwords are not that. Going to jail for forgetting, is like going to jail for losing a physical key - not even a key for an important public function, but anyone's key that was used for any personal purpose.

One could assert that legally you will be punished for this, like the UK have done here, but it's quite a barbaric thing to do without any precedent even in historic infamously-authoritarian regimes.


Road signs is bogus. People sign up for extra responsibilities via the licensing process.

The tax one is a little more interesting, you don't have to file if you don't make any money. If you make more, the payer is supposed to report as well.

Everything i can think of, where you're compelled to do something, there's at least one other person involved.


Your two examples are rules that are public information, and forgetting them can indeed have legal consequences.

A password is a piece of private information, and requiring people to remember stuff they generate in their own head seems just a tad draconian.


> I am not sure how this would be a precedent. People have already gone to jail in the UK under this law

Lauri may well be planning to appeal the matter all the way to the European Court of Human Rights.


"I don't remember it" is not a defense and that's why my grandma would to jail after her PC gets infected with ransomware.


Just another law that exists to arbitrarily criminalize people as far as I'm concerned.

If a government agency claims that you have indecent images on your hard drive and opens an investigation, you can be forced to give up your keys.

It doesn't matter if you're innocent - your data is out there now. Forever.


> you can be forced to give up your keys.

The one 'escape' from RIPA key demands is in section 53:

  unless it is shown that the key was not in his possession 
  after the giving of the notice and before the time by 
  which he was required to disclose it.
So, for example, if the keys were automatically destroyed by a dead-man's switch which the subject could not access due to being held in custody.

Usual caeavts apply: IANAL etc


So basically it's either a game of coming up with ridiculous schemes to skirt the law, or lying.

I'd rather have a judge say to me 'we think you're the wrong sort, go directly to jail' than have to sit there and say 'no, you will not have my keys, because I will not allow you to violate me in that way'.

I'm sure there are other bits of the legal system that are just as smelly. This is just one I'm familiar with technically.

It really feels like a manifestation of some dystopian novel.

I can't imagine being in that situation, it feels so utterly absurd. I can move some numbers through some wires, knowingly or unknowingly, or be arbitrarily targeted, and then somehow society/the state decides that I have to now do their tasks.

Meh. If it comes to it, I'll spend my time watching waves crashing at the beach until you decide to lock me in a box.

RIPA is psychological torture. Give us the keys or we'll take away your life. This is the society I live in. Bankrupt.


Probably even better to arrange it so that any removal of any storage media destroys the very contents. And have some safe backups far away. After all, that's just basic theft prevention. Who knows what burglars could fate deal you?


Here are some previous cases involving charges of failing to comply with a s 49 notice, under s 53 of the Regulation of Investigatory Powers Act 2000. Unfortunately I don't know of any good comprehensive free source for recent English cases, but I have provided the media neutral citations.

* Padellec [2012] EWCA Crim 1956. The accused's computer was seized and there was evidence that files had been deleted with filenames that suggested they were child pornography. He refused to provide a password to an encrypted volume and pleaded guilty to a s 53 offence. The Court of Appeal said that the accused's self-serving account of what would have been found on the encrypted volume should not have been accepted for sentencing purposes.

* Cutler, Morrison, Parratt & Freeman [2011] EWCA Crim 2781. This was an appeal against sentence by four members of a paedophile ring who pleaded guilty to s 53 offences.

* S & A [2008] EWCA Crim 2177. The Court of Appeal rejected a challenge to the validity of s 53 based on the privilege against self-incrimination. Available on BAILII: http://www.bailii.org/ew/cases/EWCA/Crim/2008/2177.html


The Court of Appeal judgment is very interesting but also very questionable.

If I understand it correctly, they claim that the encrypted data exist outside of the defendant's brain and is in possession of the police, therefore it is tangible evidence, the key is merely a way to access it. And the police can force a defendant to provide access to tangible evidence like a DNA sample or a pubic hair. And therefore non self-incrimination does not apply to that evidence.

It is very questionable as one could argue that the decryption key is a segment of the data, and that the data only becomes meaningful, and therefore evidence if the file is complete. The police is therefore trying to get additional evidence (the missing data segment, the key) to build a case, and then we are 100% in the realm of self-incrimination.

I am struggling to understand #25. It seems to imply that the only reason for the defendant to refuse to provide the key can only be because the data would contain incriminating evidence, and therefore it would somehow weaken the defense against self-incrimination. First there may be other reasons to refuse to give access to the data (privacy for instance, it might be embarrassing for a religious person to acknowledge watching gay porn!). But mostly the idea that the defense against self incrimination is weakened because complying with the request from the police would incriminate oneself is I think completely circular and defeats the whole purpose of non self-incrimination.

I also find it very concerning that the justice applies extremely fuzzy concepts like "the stability of society" to challenge basic liberties.


US jail sentences are crazy. But ... I think the UK approach here is not all that crazy. In a world with encryption, where does the balance lie between the need to investigate crimes and the need to stop a country becoming a police state?

NSA style "own it all" is clearly too far towards the police state end. But then preventing any and all investigations that involve a computer seems like an over-reaction towards the other end; targeted high-effort investigations have always been possible.

And if you want to make that be the balance and allow specific, warrant-based human-driven investigations possible but block mass surveillance, then trying to regulate the details of the technology is a bad idea. Regulators won't be able to do that. It's the wrong approach. It's like the Clipper chip, the law specifying too much stuff. A law that says "you have to decrypt your files when asked" is at least simple and it doesn't scale to mass surveillance.


Well, it does scale: Just put a guy at the airport that scans all computers passing the check. You got nothing to hide, so why worry? The law clearly states that you need to hand over any password / key when asked.

That is as bad or even worse then mass surveillance, because with mass surveillance you can at least try to be "safe" offline. With this "law", they could get to your data whenever they want. Much more of a police state that mass surveillance (at least in my opinion).


Here's the law: http://www.legislation.gov.uk/ukpga/2000/23/contents

Here's the bit we're talking about: http://www.legislation.gov.uk/ukpga/2000/23/part/III

You say

> Just put a guy at the airport that scans all computers passing the check.

This fails almost every step of the law.

The person doing the asking is probably not authorised to do so; the information found isn't found as the result of a statutory instrument; the person doesn't have the reasonable belief that key disclosure is necessary to exercise a statutory instrument; it's not proportionate.

> Much more of a police state that mass surveillance (at least in my opinion).

If your attacker is a well funded Government you're fucked. This law provides some protections against abuse.


Scan and possibly install something for everyone who handed admin level credentials.


As DanBC has pointed out, you're making assumptions about what the law says that aren't actually valid. There are quite a few safeguards in this law - it represents a compromise position.


> But then preventing any and all investigations that involve a computer seems like an over-reaction

Refusing demands for encryption keys does not "prevent any and all investigations that involve a computer". It doesn't even prevent all investigations that involve a computer with an encrypted drive.

> A law that says "you have to decrypt your files when asked" is at least simple and it doesn't scale to mass surveillance.

I don't think even that much is reasonable, for exactly the same reason that you cannot be compelled to testify against yourself.


Suppose I exchange letters with people on dead trees, but encrypt them first (using Solitaire [0], for example). Now that no computer is involved, do you still want to require I hand over this key?

What if, instead of using the well-published Solitaire method, I use one of my own devising? (Now we're approximating Apple's situation of actually having to do work oneself, rather than provide the government a relatively small bit of data for them to do work.)

0: https://en.wikipedia.org/wiki/Solitaire_(cipher)


Sure?

I feel like you're trying to point out some absurdity here but I don't see it. People are compelled to do things in investigations all the time.


On paper, this is more blatantly being demanded to write a self-incriminating document.


Not really, you're being asked to produce a self-incriminating document you already wrote. You'd have a better argument if you encrypted it in your head with a shared encryption key that your recipient also memorized before putting it in writing anywhere. Then it's like knowing a foreign language that the government can't read.

In the US, we already force public companies to store potentially self-incriminating electronic documents in case of an investigation later. It's not too much of a stretch to force individuals to have a retention policy, in case they need to be investigated. I imagine other countries have similar laws.

You could take a lesson from said companies and discuss anything remotely risky in-person rather than over monitored networks.


> Not really, you're being asked to produce a self-incriminating document you already wrote.

The (paper) document will be produced and turned over. It isn't my fault if anybody doesn't understand how to read it. A warrant isn't a guarantee that evidence will be found or understood.

> public companies

Corporations are created by the state; they do not have rights. The state can put additional requirements on their offer of limited liability. People have rights against self-incrimination.


> People have rights against self-incrimination.

Not in the UK.


The privilege against self-incrimination is based in English common law. Has there been recent legislation to abolish it?


Fittingly in 1984 the right to silence was changed so guilt could be inferred from silence.

For instance when arrested at a place, in England & Wales you must explain your prescence then and there.

That whole "...fail to give in evidence something which you later rely on in court..." English Miranda thing when they arrest you.

Not sure about Scottish or Northern Irish law.

Then when Blair removed Habeus Corpus pretty much the whole of Magna Carta was gone.

Really back to secret Star Chamber & Royal inquisitions of yore. (this is a secret trial)

The RIPA password law trumps all rights. It has not been taken to the European court of human rights.

Looks like it will now. This guy, Lauri Love, objects in principle to the law and is determined to go all the way for Justice.


The US Constitution has a right against self-incrimination to put a stop to forced confessions (like through torture). But revealing a password cannot possibly be a confession, because all it can do is reveal further evidence.

I suspect at some point US courts will rule that being compelled to hand over a password is not 'self incrimination' for the same reason that being compelled to let police search your property isn't. The abuses that rule was put in place to stop just wouldn't apply so interpreted the constitution in that way doesn't make much sense.

(and the UK has no equivalent rule against self incrimination ... not sure any country does actually)


So everyone would have to write their password of their computer in clear on a paper in case the police comes one day. Not only is this very Orwellian, but it will turn very nasty very quickly, data leaks will increase tenfold.


This mirrors the liberation of encryption.

Classified as a munition it could not be downloaded across borders - so no ecommerce , banking or safe logins could ever be possible.

The PGP code when recited from memory became free speech, a t-shirt of the speech was printed and worn on a flight to the UK.


The U.K. is already engaged in mass surveillance - see tempora.


Refusing to provide encryption credentials has been illegal in the UK for years, I believe. So what's different about this case?


The RIPA law was introduced in the year 2000. Since then there haven't been many cases that went to court, so bits of it haven't been thoroughly tested yet.

> So what's different about this case?

It is a case that's actually happening, which makes it newsworthy. These specific powers under RIPA just aren't used very often. (Unlike other bits, which are frequently used.

Wikipedia says 2 people have been prosecuted for not handing over their keys. (This doesn't tell us how many notices were issued. The Surveillance Commissioner probably has that information. I can't see anything in a quick scan of the annual reports.)

https://en.wikipedia.org/wiki/Regulation_of_Investigatory_Po...

(It's useful to look at who is getting prosecuted under RIPA - corrupt police officers setting up illegal surveillance companies; councils wrongly using surveillance to see if families are in a school catchment area).

https://www.gov.uk/government/publications/annual-report-of-...

https://osc.independent.gov.uk/protected-electronic-informat...


I believe the precedent in this case is the accused says the file is random data.

The defendant has stated he can't provide decryption keys and states that this criminalises random data.

According to the article he says can't not won't.

Have the prosecutors proven what they want decrypted is encrypted and not random noise ?

It doesn't seem they have, but we cannot know because this is a 'closed' secret trial.

Anyway, Schneier says good encryption should be indistinguishable from random noise.

Thus if one plants random noise and make an accusation surely this becomes a blackmailer's charter ?

The burden should be on the authorities to prove that the bits are decryptable and that the accused has the keys.

Suppose I wrote the key wrong ? Misremebered ? On a post-it on your monitor lost in the raid ? Unreliable thumb drive ?

Losing data without backup is literally the most common problem ever.

Remember the very early bitcoin potential millionaire who had lost his keys - happens evey day.

Regardless he should be tried in the UK, American prosecutorial overreach is notorius and standard - especially when the authorities are embarrased.

The extradition damages threshold is based on false numbers - US hacking cases always pad the numbers.

The last similar case was Gary Mackinnon, who laughably 'hacked' the pentagon with remote desktop over dialup because port authorities had default password and allowed trusted military access from there - it was not sophisticated - he damaged nothing - was looking for UFO files, took only screenshots.

This was spun by US authorities as super sophisticated causing millions in damage.

The damages were almost entirely fees to fix the embarassingly large holes Gary had found.

These false damages are used to reach the thresh-hold for extradition.

The US seems to goto max kill when it is covering its own embarassing mistakes.

Funny that they can only catch unsophisticated attacks by UK youth but not Chinese spies.

What about suspicion of the old double decrypt ?

Is one off the hook if it decrypts but the authorities believe there is a second hidden decryption possible that would satisfy them more ?

What if the encryption was by one of those encrypt your files viruses ? What if it looked like that but the authorities didn't believe you.

What if you were to be the framed patsy, participating in minor crimes but cops tipped, your drives are encrypted by the framer as the door kicks in ?

Seems like this law is ripe for many abuses and presumes guilt.

With the greatest respect:

Oi US, catch some real troublemakers and stop trying to cover your incompetence by exaggerating tomfoolery and trying to lock up our native nascent talent !

I am sure the fear and terror wrought on this bright young man is already more than punishment enough.

Pretty much the definition of evil putting Aspies in solitary to cover ones rear.


> The burden should be on the authorities to prove that the bits are decryptable and that the accused has the keys.

It is.


[[edit] OK found a jury RIPA 49 trial against the Luton terror cell, so sjy, above is right, after the denial one gets a jury trial.

In this case the USB stick was in the guys possesion so it was cut and dried. http://www.luton-dunstable.co.uk/Terrorist-plotted-attack-Lu... https://p10.secure.hostingprod.com/@spyblog.org.uk/ssl/spybl...

He got 5 years for planning terrorism.

Seems RIPA 49 can be used succesfully.


I think this is exactly what TrueCrypts plausible deniability feature was made for. You should use it if it's possible you might end up in a situation like this.


Would it not raise eyebrows if you say, had a 512GB drive in the machine and when booted in the plausible deniability mode only showed a X<512GB partition?


The partition is the full size. It's just mostly empty.


That is why it didn't do that.


Seeing fat32 nowadays is a red flag by itself.


People should use smartcards more. When stuff hits the fan you can just destroy it.

https://github.com/philipWendland/IsoApplet


Then there's destruction of evidence, complete with a physical totem to illustrate your witchcraft - imho this idea is going the wrong way.

By their very nature (treacherous computing), smartcards will enable more user-hostile capabilities than user-empowering ones. Not that they can't be useful for some properties - a custom applet could implement a time-delay dead-mans switch iff you can count on them remaining secure against government thugs.

The right way is to implement and encourage popular operating systems to adopt n-volume steganographic storage. Then there's no discernible difference between a truthful and lying "I've given you all my keys". While this won't really help your low-status undesirable that the government is just looking for justification to purge, it will cause social change when upper class people are in the same position.

(The common retort to steganography of "then they just torture you" is really just a reversion to the underlying truth from the dawn of society, exposing the modern farce of "the rule of law". Which means things either actually get reformed, or we have another bog-standard revolution to overthrow the unaccountable thugs.)


People should use smartcards more in general, regardless of circumstances and for perfectly legal stuff. It's not hard.


I thought they didn't even need RIPA, I thought that it was contempt of court to not decrypt the drive/unlock the safe when the judge asks you to?


Ridiculous to pursue this in any country. I feel for the UK. They're more behind the US in terms of educating their representatives and public about how encryption works and the fact that it's impossible to guarantee government access to everything, no matter what sentences are imposed.


Should not have sued them bro. Always let sleeping dogs lie.


It might cost you personally, but not always. Sometimes you have to drive crazy things to the point of lunacy that is their logical conclusion, to make a point.

The case of encryption heavily underlines the nature of information itself which also lends to the nature of intellectual property, the idea where bits have colors. This is all uncharted territory so far for the general society. (The laws of information are crystal clear as interpreted by the hacker mindset but it's not at all crystal clear whether the society at large ever wants to accept the hacker mindset.)

Demanding encryption keys is followed by dozens of logical consequences that are anything but obvious for the uninitiated. Several have been mentioned in this discussion already. For example, how to prove random data isn't an encrypted blob? What are the liabilities of carrying random data? What if you did encrypt it but with a throwaway password which you obviously don't remember? How can bits possibly be so dangerous to warrant jailtime for you unless you choose to reveal them? But if you store the same information in your head, you're not required to reveal it. Then how is storing the passphrase in your head any different from storing all the information in your head, albeit easier?


And we can push the argument to the absurd. I can draw a little symbol on a post it, and that little symbol may mean something to me, it's a form of cipher. Now can the court force me to tell them what this little symbol means, should I really go to jail if I don't?

The other thing is that although the 5th amendment is an American concept, I suppose there must be a provision against self incrimination in UK law. I can't be forced to testify against myself. In France I know this how it works, a defendant is entitled to lie or refuse to answer at his own trial. If we follow that logic I don't see how one can force someone to speak a password.


Yes, the privilege against self-incrimination is part of the English common law (originally the defendant could not testify at all in common law courts!).


> For example, how to prove random data isn't an encrypted blob?

It is for the prosecution to prove that the random data is actually encrypted (or more accurately, to prove that you possess the 'key' to some electronic data).

> What if you did encrypt it but with a throwaway password which you obviously don't remember?

It is for the prosecution to disprove your sworn statement to this effect.

> How can bits possibly be so dangerous to warrant jailtime for you unless you choose to reveal them?

There could be reasonable grounds for believing that the bits are being used to encrypt child pornography, or some other serious crime.


This guy wants to challenge the validity of the RIPA law in the European court of human rights.

Lauri Love, the accused, is a journalist and this strikes at the heart of the Freedom of The Press.

"It’s a presumption of guilt for random data.” - Lauri Love.

With a neutered Legislature & Compliant Judiciary the fifth estate is the last hope for the balance of powers a healthy Democracy requires.

Arguably the UK government has crossed this line for quite some time, e.g. :

The UK govt physically destroying the Guardian Newspapers computers last year - prompting their exodus to New York.

The harrasment of Glen Greenwald's husband at Gatwick.

The right to remove embarrasing links in google & censor the press, seemingly mostly used by embarrased footballers and malpracticing doctors.

The overuse of D-Notices, notice there is no coverage by the BBC of the recent oil bribery scandal, D-notice !

The shameful & inhuman confinement of the 21st Centuries most important journalist, Julian Assange, to prevent & curtail Wikileaks work exposing secrets.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: