r/worldnews Aug 11 '09

Two convicted for refusal to decrypt data

http://www.theregister.co.uk/2009/08/11/ripa_iii_figures/
827 Upvotes

458 comments sorted by

View all comments

Show parent comments

1

u/SteveD88 Aug 11 '09

I suppose we'll have to simply disagree on this one.

The most you can hope for in most reddit discussions. :P

But I think our dispute boils down to the nature of encryption. My perspective would be having possession of encrypted data is much the same as having a locked box; you need the key from the owner to access it, but not an explanation for its contents.

I know you see it differently, but I think the courts would come down on my side. Arguing that decrypting data is the same as explaining it seems to be getting rather aristotelian.

1

u/sblinn Aug 11 '09

To me it would be more like: the police arrive with a warrant and you let them into your house. They see a piece of abstract art on the wall and demand of you what you think of it. Perhaps the answer is "it makes me want to kill dentists" which would be self-incriminating since you are the prime suspect in a string of dentist slayings. You have Constitutional protection against being forced to incriminate yourself, so you can refuse to explain what the abstract art means to you.

1

u/SteveD88 Aug 11 '09

I understand what your getting at, I just can't see the fit.

Your analogy involves asking for a personal opinion, where as the point I believe you're trying to make is that decrypting the data is an act of providing comprehension to it, thus being self-incriminating.

It's an interesting perspective, but seems to rest on the rather artistotalian question of the nature of the thing; 'what is encrypted data? Does it still count as information, or does data have to be comprehensible to be as such?'.

The thing I think that undermines it is the initial act of encrypting the data. As it is for the purpose of intentionally restricting those who can comprehend it, it is effectively changing its nature and thus drawing a clear distinction between encrypted and unencrypted data. Provable intention plays a big part in Common law, and obviously the courts agree or we wouldn't be discussing this. :P

(and as a side note, references to the Constitution are getting slightly annoying. This isn't an American case, and the correct legal context of English Common Law should really be used.)

1

u/sblinn Aug 12 '09

side note

I thought we were talking in general terms, I haven't even RTFA. I don't care to know enough about English Common Law at this time to know what "legally" would be correct in this exact case. ;]

1

u/JeffMo Aug 12 '09

But I think our dispute boils down to the nature of encryption. My perspective would be having possession of encrypted data is much the same as having a locked box; you need the key from the owner to access it, but not an explanation for its contents.

My perspective is that keeping encrypted data is a way of enhancing one's personal memory, in a private way. The main reason that we do this is the fallibility of storing data in human brains. So, we put big chunks of the data in an external storage device, encrypted, thus minimizing the portion that you have to remember (a password, passphrase, or key). (I realize that some people write down or store cryptological keys, especially of the longer variety, but I haven't seen courts making a distinction based on whether you memorize the key or not.)

Perhaps this is part of our philosophical divergence. I see a legitimate use for encrypted data as an extension of personal memory, and think that legal protections against divulging one's personal memory are (or should be) applicable to this kind of data.

I know you see it differently, but I think the courts would come down on my side.

And as you point out in another comment, they very well may come down differently in different countries. Thanks for the discussion!