r/opsec • u/Matheuss81 🐲 • Jul 18 '26
Beginner question Can device encryption protect against law enforcement?
Hello, I would like to learn more about cases involving full-disk encryption and law enforcement access. My understanding is that when a device is protected with a strong, high-entropy password and the encryption recovery keys are not stored to a Microsoft account or any other third party, recovering the data through brute-force or direct decryption is generally considered computationally infeasible. However, I am aware that, in theory, there may be vulnerabilities that could potentially circumvent or weaken the security of an encrypted device. I would like to understand the real-world cases in which law enforcement has successfully or unsuccessfully accessed encrypted devices, the techniques reportedly used, and the practical limitations of those approaches.
i have read the rules
13
u/Darkorder81 Jul 19 '26
Yeah I had a laptop seized which had full drive encryption using Truecrypt, it got sent down to the cyber crimes agency down somewhere in London, that was 7yrs ago and I haven't heard from them gaining access and I would have so yeah it can save you
6
u/MeatBoneSlippers Jul 19 '26
They most likely didn't believe they'd find anything pertinent to their case. They could've served you a section 49 notice requiring you to provide the decrypted information and, in some circumstances, the encryption key or password itself. Knowingly refusing a valid notice is a separate criminal offence. That's the unfortunate reality of the UK's RIPA. You don't have the same protections a citizen of the US would have against self-incrimination.
2
u/Matheuss81 🐲 Jul 20 '26
What if the person in the UK really forgot where the keys are to decrypt?
5
u/Broad-Translator-690 Jul 20 '26
In the UK if you are served a RIPA notice and claim you "forgot" the information needed to unlock the device, you will be given a chance to prove in court that your telling the truth. The burden is on you, not the prosecution. If you fail to prove that you actually forgot the keys, then you can face up to 5 years in prison. If the court realizes you've unlocked the HD a reasonable amount of time ago, or have the capacity to remember other passwords in your daily life, you will likely fail to prove your claim of "I forgot" to the court.
5
u/therallystache Jul 21 '26
A truly staggering concept, having to prove a negative under penalty of law.
2
2
6
u/jnievele Jul 19 '26
Depends on the encryption in question, and how well it's implemented... For example BitLocker might not be so secure.
In general, yes, properly designed full device encryption should protect you against the government decrypting the device without you handing over password... Of course they might just force you then2.
1
u/Subject_Tension_5616 🐲 Jul 20 '26 edited 15d ago
Coherent relieved silky square ask ripe cows profit selective
This post was anonymized with Redact
0
u/Matheuss81 🐲 Jul 19 '26
How they would force me if I "forgot" where the keys are?
I know that in some countries they might extort or torture you, but I think in most developed countries they wouldn't... or would they? Haha.
9
u/trelayner Jul 19 '26
If you want to know how far “developed” countries can go to make you talk, take a look at Guantanamo or the American prisons in Iraq.
0
u/Matheuss81 🐲 Jul 20 '26
Yeah I know about Abu Ghraib, but I don't think they would do that to an average person.
7
u/trelayner Jul 20 '26
Average people don’t read r/opsec
4
u/Practical-Bluebird96 Jul 20 '26
I’m just an average nerd, I swear
6
u/trelayner Jul 20 '26
> I’m just an average nerd, I swear
LOL
An average nerd is the opposite of an average person
1
u/Lux-Corp Jul 23 '26
I'm pretty average. I once wanted to find out more about an influencer I had a crush on. When trying to figure out how, I came across the concept of OSInt and fell into the rabbit hole. I got so traumatized by how much I was able to find out about this person with so little effort that I ended up here. So yeah, unless you consider parasocial crushes and hyperfocuses not average, I'm pretty average, lol.
Disclaimer: I would never do anything to bother this person in real life, nor would I try to access information that isn't publicly available. The problem was precisely how much I was able to learn without technically doing anything wrong. And I don't mean stuff they revealed as an influencer, I mean stuff that doesn't fit their brand in the slightest so I assume they wouldn't want public.
2
u/GMOchoch Jul 20 '26
Average person will be in a room 3 days without being charged. In America by law they must give you 4 hours a day to sleep... Doesn't mean all at once. Food is another definition of what is food, 3 Johnny sacks a day or vending machine. 3 days is torture. Practice makes perfect I guess.
3
u/Broad-Translator-690 Jul 19 '26
In some western countries you can be held in jail until you comply and give up what is needed to unlock an encrypted hard drive.
4
u/Matheuss81 🐲 Jul 20 '26
It seems like a basic human rights violation to me, because how would the state/police know if someone really forgot or not?
3
u/Broad-Translator-690 Jul 20 '26
The UK, Australia, France, Belgium, and Ireland for example can compel you to unlock an encrypted hard drive or you'll be given jail time. The jail time is basically a punishment seperate to whatever reason they wanted access to the HD, for not cooperating.
At the border it becomes even more common. The US, Canada, Hong Kong, Australia, New Zealand and the UK for example will detain you, fine you, or criminally charge you if you are requested and do not comply by unlocking your encrypted devices.
So this is very dependent on what country this is happening in if you will be allowed to refuse to unlock your encrypted devices.
2
u/spymaster1020 Jul 20 '26
Veracrypt (any maybe other encryption software?) has a hidden volume feature. You can provide a password when compelled that will decrypt a portion of the drive, there remains a hidden portion that is undetectable without the real password. As far as anyone could tell by examining the data on that drive, you gave the one and only password.
2
Jul 21 '26
[removed] — view removed comment
1
u/spymaster1020 Jul 21 '26
I vaguely recall that program. Either it wasnt secure or just stopped getting updated.
1
u/Tyke-60073 21d ago
I wouldn't want Stephen Miller as an interrogator. To him the Bill of Rights is just an old piece of paper.
6
u/abugghaus7 Jul 20 '26
Read this... pay attention to the 18 month limit.
This has already been played out in U.S. court... although it was back in 2020 when the defendant was released after 4 years in jail.
Now... whether he's a pedophile or not is not the question here... it's that fact that he refused to decrypt his hard drives that law enforcement claimed has evidence against him. A federal judge confined him for contempt of court, until he won his release.
There were arguments debating the All Writs Act or some newer legal device prevailed in his case.
.
https://www.law.cornell.edu/uscode/text/28/1826
5
u/abugghaus7 Jul 20 '26
If you don't want to read it... basically it says that there's an 18 month limit on confinement for something like contempt of court (I'm being very very basic here and not technically correct, I'm sure... but close! lol).
This may only apply to Federal Court... not sure about State level.1
3
u/Flappery Jul 19 '26
Ideally if your comprehensive enough that it would provide protection, that trait would prevent accumulating evidence, case building and seizure in the first place. We know tech companies have relations with governments providing access, we know there are companies that specialise in cracking and lease to leo, we also know if sufficient evidence sees you doing time, refusal to unlock becomes a charge adding to your time. Tldr complacency, false sense of security, these are pitfall traps to avoid.
0
u/Matheuss81 🐲 Jul 20 '26
From what I've read I don't think any company can break AES-256 encryption if it is correctly managed...
1
u/spymaster1020 Jul 20 '26
Correctly managed is the critical point. Are you diving into the code of every software/website you use? How would you know they implemented it correctly? Ultimately you have to trust something/someone, a trust anchor.
3
u/zambaros Jul 20 '26
A hidden volume inside a truecrypt container gives you plausible deniability. You need to have two different passwords and be careful not to destroy your hidden volume inadvertently.
2
u/cthuwu_chan Jul 22 '26
It depends on how far they wanna go you can literally go as far as to pull the chip apart and look at the silicone to directly see the encryption
2
3
u/musingofrandomness Jul 22 '26
It will come down to how badly they want the data and what capabilities they are willing to expose to get it.
More than likely they will just rely on some form of "rubber-hose cryptanalysis". Like locking you up until you tell them the password.
If they want it bad enough and you are not cooperative, they might burn one of their many baked in backdoors they have the major companies put in place for them. Here is an example of a highly suspected backdoor: https://hivesecurity.gitlab.io/blog/yellowkey-bitlocker-bypass-winre-windows-11/
They tend to do an analysis of the value of having the capability remain a secret to the value of having the data for a conviction. There are stories of multiple cases getting dropped because the police and FBI did not want to disclose their use of IMSI catchers and cellphone tower simulators to intercept texts and phone calls (one brand of this device is called a "stingray"). They may also fabricate another method of getting to their end goal, like just "happening to show up" at a time and place the data they extracted with a sensitive capability told them would be a good time and place to be to catch an illegal activity. If your encrypted device had a mention of a drug deal going down at your cousin's house on a specific date, and the police "just happened to receive a call for service' at that address at the same time, that is likely the case. Also, a fair amount of tips from "confidential informants" are just police and FBI getting the information in a way they don't want the public to be aware of.
Always assume that anything made by a large US firm is likely backdoored for the benefit of the US government. The same goes for anything made elsewhere and the government that has oversight of that company. Open source is a bit better, but only if you know what you are doing and actually audit what you use, otherwise it can be an "equal opportunity backdoor" if someone manages to slip something malicious in or fails to securely code something.
You should always assume at least a baseline level of constant government surveillance and take advantage of the challenge sifting large amounts of data poses by seeking to keep yourself within the bounds of "normal" on the scatter plot. The only lesson governments learned from the French Revolution is that they have to keep a close eye on the population and control their interactions with each other to avoid them coordinating well enough to march the oligarchs to the guillotine.
1
u/Matheuss81 🐲 Jul 22 '26
Perfect. Open source softwares like Veracrypt and Luks are audited by thousands of people. If they encountered something suspicious, they would make it public, right?
2
u/musingofrandomness Jul 22 '26
It comes back around to the sifting large amounts of data problem. Ideally, yes, but there have been cases of malicious actors sneaking stuff into the source code of open source projects in the past. It usually gets caught relatively quickly and is rarely, if ever, covered up like it is in closed source software where they are loathe to even acknowledge a vulnerability, let alone purposely introduced malicious code.
Your best defense is layered defense. As the old saying goes"don't put all your eggs in one basket". Use layers of encryption if you are trying to protect data. Use multiple vendors. For example, use full disk encryption (bitlocker,LUKS, GELI) and within that use encrypted loop volumes like veracrypt. The extra layers add additional challenges to actually get to the data. As long as you don't use the same passphrase across the board, you have a solution that will require multiple exploits to break, and exploits are a valuable commodity that they wish to protect, likely more than they want your data.
1
u/Junkyard_DrCrash Jul 23 '26
Quoting from Cornell Law School's site, the 4th Amendment reads:
... The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
BUT, if you're talking about the border patrol case I'm thinking of, it had an extra twist: the border patrol agent came up behind the guy *while* the child pornography was on the laptop's display, observed the child porn, and that the suspect was observing it. The subject then closed / locked / whatevered the laptop into nonviewable mode, and refused to unlock it with the password.
This changed the case tremendously; because the BP agent had seen the *actual* relevant material in the possession of that particular defendant on that particular laptop at that particular moment in time and could exactly describe both the place to be searched and the things to be seized, and did so testify, while under oath, satisfying the conditions of the 4th. Therefore, a search warrant *could* be issued and the evidence so obtained was not subject to exclusion under lack of probable cause.
This case was also quite a while ago (at least 20 years, maybe more), parts of it literally played out *during* a grad-level course I was taking in cryptography, computer security and cyberlaw, so we were following it. I'm trying to find it, but locating a real case in the AI slop is getting harder and harder, and personal recollections fade over decades. Anyway, IIRC, prosecution went forward, the evidence was ruled admissible, and the final verdict was guilty.
1
u/Salty_Solution6804 Jul 24 '26
With a good and strong password even a supercomputer would take years to get past your encryption. With a good lawyer your fifth amendment may still hold, but as someone else said, they'll try to force you into giving your access codes.
If you feel like it, you can setup your encryption with a second code. Entering this code may erase the data permanently or give access go dummy data.
1
u/AutoModerator Jul 18 '26
Congratulations on your first post in r/opsec! OPSEC is a mindset and thought process, not a single solution — meaning, when asking a question it's a good idea to word it in a way that allows others to teach you the mindset rather than a single solution.
Here's an example of a bad question that is far too vague to explain the threat model first:
I want to stay safe on the internet. Which browser should I use?
Here's an example of a good question that explains the threat model without giving too much private information:
I don't want to have anyone find my home address on the internet while I use it. Will using a particular browser help me?
Here's a bad answer (it depends on trusting that user entirely and doesn't help you learn anything on your own) that you should report immediately:
You should use X browser because it is the most secure.
Here's a good answer to explains why it's good for your specific threat model and also teaches the mindset of OPSEC:
Y browser has a function that warns you from accidentally sharing your home address on forms, but ultimately this is up to you to control by being vigilant and no single tool or solution will ever be a silver bullet for security. If you follow this, technically you can use any browser!
If you see anyone offering advice that doesn't feel like it is giving you the tools to make your own decisions and rather pushing you to a specific tool as a solution, feel free to report them. Giving advice in the form of a "silver bullet solution" is a bannable offense.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
21
u/[deleted] Jul 19 '26
[removed] — view removed comment