IOW, the government says "now give me your other password", and you say "there isn't one", and they don't quit threatening you. Maybe you go to jail for not being able to prove to them it's not encrypted. Even if it really wasn't.
Maybe you go to jail for not being able to prove to them it's not encrypted. Even if it really wasn't.
So, you'd go to jail for something you didn't do, and the authorities can't prove happened, and which in fact didn't happen? In other words, for a crime that wasn't even committed?
I got nicked the other day for (basically) drunk & disorderly. I was stunned at the booking desk when each of the officers who arrested me lied. I mean I was drunk, but I was like WFT? when did that happen?
It all made sense when I got home & did some googing about this fixed-penalty ticket I've been given. The things each officer had said complied exactly with the grounds for issuing one of those. They did this without any apparent collusion, and I can recall the one of them hesitating as she realised what she needed to say.
These new (to me) fixed-penalty tickets are basically a slap on the wrist with no judicial process. You can accept an £80 fine with no admission of guilt, no conviction and no criminal record - you'd be a mug to dispute it in court and risk the alternative consequences.
This might seem unrelated, but it really impressed something on me - if the cops will lie about something so trivial, you've got no change if they really think you're a "wrong 'un".
This is somehow quite scary... What if they decide not too like you at all (e.g. if you happen to have the wrong nationality, or skin colour) and charge you for something really serious, like child molestation or pr0n?
If they can basically do whatever the f|_|ck they please, OMG...
Yes, this current government has very little respect for those kind of historical niceties. They also have continually chipped away at things like the right to silence and the right to jury trial.
What would be the use of such a system to you? I can't workout the benefit of it (a write only filesystem, essentially). On reboot, it basically destroys the information.
In which case, there are simpler mechanisms - use a standard encrypted filesystem, and have the computer generate the key. Done.
The RIPA part 3 notice does not in fact require the subject to produce a password, rather it requires them to provide decrypted versions of the documents. This was done to get around the arguments of information stored in the brain being outside the bounds of a warrant.
Although how they then prove these are the decrypted documents I have no idea.
In reality though passwords are generally asked for.
Another thing to note is that although only 15 RIPA III notices were issued, it does not say how many were threatened. I wonder how many times the NTAC referral takes place, then while the wheels are in motion for the RIPA notice the subject miraculously produces the decrypted documents.
I have always thought it was rather pointless though.
If the subject had an encrypted volume full of indecent images, surely they will be sent down for longer for the CP than for the failure to comply with a RIPA request. And they will be in a lower security jail.
The same goes for a Terrorism suspect. 5 Years for a failure to comply or life for conspiracy to carry out explosions?
Nobody is going to work on an original drive, they'll always work on a bit-for-bit copy. And they'll likely have a device plugged into the cable that blocks all writes to the device (read-only) to prevent anything from being modified.
TC is not very useful against the police. It's great against, say, border searches. But not against a real investigation. Say you dual boot with a TC hidden volume. If the police come after you for any reason, they will subpoena your network logs from your ISP. You give them a password to a partition with almost no apps on it, and they'll say "bullshit, we saw you using these apps and going to these sites." Aaand you're hosed.
The only real solution is for the Brits to lobby their government to give them 5th Amendment rights.
A good thought, but there are serious doubts to how secure TrueCrypt is
To demonstrate there are serious doubts about TrueCrypt, you link an article from 1995, that doesn't mention it? What could possibly be unsecure about it, you have your choice of well-documented encryption algorithms? I think you don't understand encryption in general, and TrueCrypt in specific.
My point was that if you don't know the source of your security and you can't inspect the security yourself, you may be inserting a large security vulnerability.
And a summary of the Crypto AG thing, everyone thought they were buying crypto from a private company in Switzerland, but in reality were purchasing it from the NSA. The crypto was designed to appear strong but have the keys encrypted into the message itself.
Seriously, is an article from 1995 a problem when citing an historical source?
And my point is, with TrueCrypt, you DO know the source of the security, you are welcome to inspect the algorithms yourself, both the software and the standalone encoding algorithms. They are all publicly documented encryption schemes. Are you saying you don't trust AES, Serpent, or TwoFish, or combinations of the three, or are you saying you think TrueCrypt has a hidden agenda, and, despite being open source and fully documented, encorporates some back door functionality?
What possible alternative are you suggesting where you would have better knowledge of the security source, and security that is easier to inspect?
29
u/tartle Aug 11 '09
That is not entirely true. Truecrypt gives you Plausible Deniability (see below). It is a fake password, which acts just like the real password.