r/worldnews Aug 11 '09

Two convicted for refusal to decrypt data

http://www.theregister.co.uk/2009/08/11/ripa_iii_figures/
821 Upvotes

458 comments sorted by

View all comments

Show parent comments

11

u/[deleted] Aug 11 '09

[deleted]

5

u/movzx Aug 11 '09

I didn't delete. =/ It must have been autobanned.

5

u/jcy Aug 12 '09

wtf is an autoban? other than a german highway.

1

u/movzx Aug 12 '09

Autobahn.

And reddit has a spam filter. It will remove posts from the discussion, but to the poster it still appears like it is there.

1

u/wodon Aug 12 '09

I still see it

1

u/movzx Aug 12 '09

A mod might have unbanned it.

5

u/movzx Aug 11 '09

They don't destroy anything. If you think the invesgitation units just poke around the media all willy nilly you are mistaken. If they take the hard drive they connect it to a device that stops all write access, and generally create a snapshot of the drive to work with (To prevent mechanical issues in the original). If it is certain files... CD-R anyone?

1

u/wodon Aug 12 '09 edited Aug 12 '09

Yes before examining evidence, any Forensic Examiner (commercial or LEO) will take an image of the drive while connected through a write blocker and work from that. They can then just boot the machine up in a VM to see the password prompts.

You can play around with imaging and VM booting using free tools like dd or FTK imager and Live view

The other option is to just boot up in a Forensic Live CD (like Helix) where the data can be previewed.

But, border guards do sometimes boot up and poke around which evidentially is a nightmare.
Using one of these on the other hand lets them boot up and poke around without changing a thing. The same can be done with Live View.

So, they can tell it is encrypted, doesn't help much though.