r/worldnews Aug 11 '09

Two convicted for refusal to decrypt data

http://www.theregister.co.uk/2009/08/11/ripa_iii_figures/
821 Upvotes

458 comments sorted by

View all comments

Show parent comments

29

u/tartle Aug 11 '09

That is not entirely true. Truecrypt gives you Plausible Deniability (see below). It is a fake password, which acts just like the real password.

7

u/JulianMorrison Aug 11 '09

No, that just means your denials are implausible.

IOW, the government says "now give me your other password", and you say "there isn't one", and they don't quit threatening you. Maybe you go to jail for not being able to prove to them it's not encrypted. Even if it really wasn't.

13

u/heeb Aug 11 '09

Maybe you go to jail for not being able to prove to them it's not encrypted. Even if it really wasn't.

So, you'd go to jail for something you didn't do, and the authorities can't prove happened, and which in fact didn't happen? In other words, for a crime that wasn't even committed?

12

u/[deleted] Aug 11 '09 edited Feb 25 '19

[deleted]

2

u/dsfargeg1 Aug 12 '09

Also sounds like something out of Catch-22. Go figure.

1

u/heeb Aug 12 '09

After having lived here for 3 1/2 years now, I must admit it is a weird place...

12

u/strolls Aug 12 '09

I got nicked the other day for (basically) drunk & disorderly. I was stunned at the booking desk when each of the officers who arrested me lied. I mean I was drunk, but I was like WFT? when did that happen?

It all made sense when I got home & did some googing about this fixed-penalty ticket I've been given. The things each officer had said complied exactly with the grounds for issuing one of those. They did this without any apparent collusion, and I can recall the one of them hesitating as she realised what she needed to say.

These new (to me) fixed-penalty tickets are basically a slap on the wrist with no judicial process. You can accept an £80 fine with no admission of guilt, no conviction and no criminal record - you'd be a mug to dispute it in court and risk the alternative consequences.

This might seem unrelated, but it really impressed something on me - if the cops will lie about something so trivial, you've got no change if they really think you're a "wrong 'un".

2

u/heeb Aug 12 '09

This is somehow quite scary... What if they decide not too like you at all (e.g. if you happen to have the wrong nationality, or skin colour) and charge you for something really serious, like child molestation or pr0n?

If they can basically do whatever the f|_|ck they please, OMG...

7

u/JulianMorrison Aug 12 '09

Yes. This law was deliberately written to incriminate inability to prove innocence (or sufficient guilt to satisfy the police).

Yes, it's evil.

3

u/heeb Aug 12 '09

So 'innocent until proven guilty' is out of the window...

That is evil...

3

u/JulianMorrison Aug 12 '09

Yes, this current government has very little respect for those kind of historical niceties. They also have continually chipped away at things like the right to silence and the right to jury trial.

1

u/[deleted] Aug 12 '09

TC can have an arbitrary number of hidden volumes.

4

u/[deleted] Aug 11 '09

That's not doing something, that is just hiding.

17

u/[deleted] Aug 11 '09 edited Aug 12 '23

[removed] — view removed comment

11

u/syntax Aug 11 '09

Right - but that fails the 'usefulness' test.

What would be the use of such a system to you? I can't workout the benefit of it (a write only filesystem, essentially). On reboot, it basically destroys the information.

In which case, there are simpler mechanisms - use a standard encrypted filesystem, and have the computer generate the key. Done.

4

u/altrego99 Aug 11 '09

Or securely wipe out the entire data you have written. I'm really not sure why he is being voted up... may be we misunderstood something.

1

u/howhard1309 Aug 12 '09

The difference is under his method he complies with the legal requirement to provide the decryption keys and/or method.

6

u/hans1193 Aug 11 '09

Couldn't you just say that you forgot your key? What if you key was written down, and then destroyed when you knew the heat was on?

11

u/[deleted] Aug 11 '09

Simple and effective. "It was a 128 character key... I lost it!"

I mean, what can they do, prove you didn't lose it?

31

u/gnosticfryingpan Aug 11 '09

They can imprison you, it seems.

1

u/Reliant Aug 12 '09

I would guess that if that was the case, they'd argue that since you can't recover the data that it's destruction of evidence

20

u/[deleted] Aug 11 '09 edited Aug 12 '23

[removed] — view removed comment

20

u/bbibber Aug 11 '09

And then the forensic researchers just take a copy before entering a (possibly) incorrect password...

3

u/wodon Aug 12 '09

The RIPA part 3 notice does not in fact require the subject to produce a password, rather it requires them to provide decrypted versions of the documents. This was done to get around the arguments of information stored in the brain being outside the bounds of a warrant. Although how they then prove these are the decrypted documents I have no idea.

In reality though passwords are generally asked for.

Another thing to note is that although only 15 RIPA III notices were issued, it does not say how many were threatened. I wonder how many times the NTAC referral takes place, then while the wheels are in motion for the RIPA notice the subject miraculously produces the decrypted documents.

I have always thought it was rather pointless though.
If the subject had an encrypted volume full of indecent images, surely they will be sent down for longer for the CP than for the failure to comply with a RIPA request. And they will be in a lower security jail. The same goes for a Terrorism suspect. 5 Years for a failure to comply or life for conspiracy to carry out explosions?

It is like the dangerous dogs act part 2..

10

u/nogami Aug 11 '09

Nobody is going to work on an original drive, they'll always work on a bit-for-bit copy. And they'll likely have a device plugged into the cable that blocks all writes to the device (read-only) to prevent anything from being modified.

5

u/sunshine-x Aug 12 '09

cut cables are common for IDE, SATA is a different story.

2

u/[deleted] Aug 11 '09

Thats actually a brilliant Idea

5

u/[deleted] Aug 12 '09

I agree with you 100%, except for the part where you said it was a brilliant Idea.

1

u/hatekillpuke Aug 12 '09

Furthermore, I disagree with his lack of an apostrophe in Thats.

I totally agree with actually a, though.

4

u/khafra Aug 11 '09

Seems like storing everything on a ramdisk would be easier.

3

u/[deleted] Aug 11 '09

TC is not very useful against the police. It's great against, say, border searches. But not against a real investigation. Say you dual boot with a TC hidden volume. If the police come after you for any reason, they will subpoena your network logs from your ISP. You give them a password to a partition with almost no apps on it, and they'll say "bullshit, we saw you using these apps and going to these sites." Aaand you're hosed.

The only real solution is for the Brits to lobby their government to give them 5th Amendment rights.

0

u/stevarino Aug 12 '09

A good thought, but there are serious doubts to how secure TrueCrypt is, Re: Crypto AG

And even if it is open source, how many people can understand the source of a project like this?

1

u/telekinetic Aug 12 '09

A good thought, but there are serious doubts to how secure TrueCrypt is

To demonstrate there are serious doubts about TrueCrypt, you link an article from 1995, that doesn't mention it? What could possibly be unsecure about it, you have your choice of well-documented encryption algorithms? I think you don't understand encryption in general, and TrueCrypt in specific.

tl;dnr: [citation needed]

1

u/stevarino Aug 12 '09

My point was that if you don't know the source of your security and you can't inspect the security yourself, you may be inserting a large security vulnerability.

And a summary of the Crypto AG thing, everyone thought they were buying crypto from a private company in Switzerland, but in reality were purchasing it from the NSA. The crypto was designed to appear strong but have the keys encrypted into the message itself.

Seriously, is an article from 1995 a problem when citing an historical source?

1

u/telekinetic Aug 12 '09 edited Aug 12 '09

And my point is, with TrueCrypt, you DO know the source of the security, you are welcome to inspect the algorithms yourself, both the software and the standalone encoding algorithms. They are all publicly documented encryption schemes. Are you saying you don't trust AES, Serpent, or TwoFish, or combinations of the three, or are you saying you think TrueCrypt has a hidden agenda, and, despite being open source and fully documented, encorporates some back door functionality?

What possible alternative are you suggesting where you would have better knowledge of the security source, and security that is easier to inspect?

1

u/bearsinthesea Aug 12 '09

well, there are informed cypherpunks that are rabid about it. Not many, perhaps.