5 ms·
If they've linked specific hashes to known CP content, then presumably they have those files available. They can still present that as evidence, then have the e
by alethiophile 9y ago
If they've linked specific hashes to known CP content, then presumably they have those files available. They can still present that as evidence, then have the experts testify that those specific files are known to have been on the drive.
Going to the Supreme Court specifically on the forced-decryption issue sends a pretty strong signal that that's what they actually care about.
- louithethrid 9y agoThere could be hash-colissions of entirely diffrent files. Hashes are not proof enough.
- alethiophile 9y agoIf it's a hash without known collision vulnerabilities, then it's 2^80 proof at least. This is definitely "beyond a reasonable doubt". Even if there were, what's the threat model? "Government creates colliding images one CP and one not, seeds the non-CP versions widely in torrents or something, then uses the hash collision to accuse anyone who downloaded of CP"? That's way more roundabout than governments will bother with; a dirty prosecutor will just fabricate evidence entirely, or have witnesses lie. (Plus, just producing the innocuous colliding image and demonstrating the collision would be an easy and ironclad defense.)
- manicdee 9y agoThe threat model is "antagonist creates colliding image which is CP, claims original unviewable file was CP." So you, the protagonist, have an encrypted volume full of the names and addresses of people helping evacuate Jews from Nazi-controlled Europe / blockade the construction of a new mine which was approved through bribery and corruption. The antagonist claims you are a CPer and produces a list of known hashes on files on your disk, and a sample of really awful images that conveniently have the same hashes. So the end game is either bust your information out to assist prosecution of the anti-government activists, or land you in the slammer as a CPer thus dragging your cause into the mud.
- alethiophile 9y agoIf the original files weren't under the control of the adversary, that's a preimage attack, not a collision attack. No hash that's ever used for file authentication, even MD5, is vulnerable to second preimage. If they were, then first off you should have been more careful about putting untrusted data on the same drive as anything actually important, but secondly it's usually obvious when a file is constructed as part of a collision attack, and there would be no good reason for the government's exhibits to show those markers. Really, this whole discourse is silly anyway. In accordance with the usual XKCD, if the government really wants to railroad you, they won't bother with cryptographic vulnerabilities; they'll just lie and/or plant evidence. Creating and exploiting a hash collision isn't something you do by accident; it's conscious, outright evidence manipulation, and if they're willing to do that they can do it much easier ways.
- jo909 9y agoTechnically, the defendant is the one going to the Supreme Court. Of course they somewhat forced his hand by putting him in jail. IANAL, but probably he could have abandoned his fifth amendment defense strategy much earlier, which is the only thing currently before the Supreme Court, go back to the original judge and raise the "I forgot the password" defense there. Under the assumption that he could have done that, and again IANAL so I'm sorry if that is wrong, he is the one forcing the issue at the Supreme Court. Of course the prosecution has nothing to loose here, so why would they do anything (if they could, I don't believe they play any role in this part), and the judge that made the contempt of court ruling that is the basis of all of this is unlikely to just give in and admit he was wrong, and also probably pretty interested to get a final judgment on what he believes is his legal right to do. And you make it sound like getting the highest courts opinion is a bad thing. Either way, then we know, and I'm glad I'm not the one that has to wait it out in jail.
- alethiophile 9y agoI am also not a lawyer, but if the government really just wanted their conviction of this one guy, the obvious path seems to be to abandon the court order to decrypt the drive, and just move forward with trial based on the forensic evidence from the system root. Slapping him with contempt on this, and continuing to sweat him out in jail while he files higher and higher appeals, is the government's decision. Getting the Supremes' opinion on this is kind of a superposition of states: if they decide in favor of right-to-encrypt, that's great, as suddenly the government will (presumably) stop using these kinds of court orders; but if they find against, then it's worse than the current uncertain situation, as orders to decrypt will then become an accepted tool. If the Supremes would find in favor of compelled decryption, then I'd prefer it never go to them, and remain in the current legal limbo.
- jo909 9y ago"The government" as such is not involved here. I'm not going to pretend the separation of powers is as clean cut as what one learns in school, but first and foremost this is a ruling of a single and independent judge that the defendant is challenging. I fail to see any motivation for the judge to back down on his contempt of court order. I fail to see any motivation for the prosecution to try to continue the trial faster without the drives (which would be a much weaker case). Just because they are good people and have any problem with somebody they believe to be very guilty sitting in jail? They send people to jail all day long. And I for myself, owner of many encrypted drives, prefer to know and not having to fight that fight myself while sitting in jail.