3 ms·
Having team members in different (mutually distrusting) jurisdictions is a good way to allow organisations/projects to avoid legal coercion, so you're thinking
by dane-pgp 4y ago
Having team members in different (mutually distrusting) jurisdictions is a good way to allow organisations/projects to avoid legal coercion, so you're thinking along the right lines. You seem to be suggesting, though, that the files themselves would be split between the locations, rather than just parts of the keys, and I don't think think there is any technical or legal benefit to the former over the latter.
The thought experiment you really need to think about is "What legal jeopardy could I face if I held an encrypted copy of an illegal file, but the only copy of the key was held by my friend in a non-extradition country?". Lawyers would probably say "It depends", but I'm guessing that a judge would interpret that situation as if you had 99% of an illegal file, and then they would round it up to 100%, especially if the prosecution could show that you had knowledge of (and/or intent to possess) what the (pre-encryption) contents of the file were.
A better thought experiment, though, would be "What would happen if large numbers of strangers were all using a protocol which allowed fixed size blocks of random-looking data to be hosted on each other's behalf?". Someone using this system might take a pre-existing random block (call it "P") and XOR it with an illegal file ("Q", padded to the right length), then upload the resulting block ("R"). They could then communicate out-of-band to someone that they only need to download P and R to recreate Q. However, if someone else found this property of (the seemingly random data in) P and R, the creator of R could claim that someone must have downloaded their R and generated P from it using Q (since XOR is reversible like that), which the accused could claim to have no knowledge of.
An idea similar to this, using XOR, was actually implemented and was called the Owner-Free File System[0]. I can't vouch for how effective it was at any of its goals, and I don't endorse it, but it's a useful way to think about things like plausible deniability. Also, to pre-empt the objection that just running such a "block sharing/hosting" application would itself be evidence of malicious intent, it's worth considering the liability of Tor nodes (especially exit nodes) and people running BitTorrent clients that make their computer contribute towards the operation of a distributed hash table.[1]
[0] https://en.wikipedia.org/wiki/OFFSystem https://en.wikipedia.org/wiki/OFFSystem
[1] https://en.wikipedia.org/wiki/Mainline_DHT https://en.wikipedia.org/wiki/Mainline_DHT
- wmf 4y agoHaving team members in different (mutually distrusting) jurisdictions is a good way to allow organisations/projects to avoid legal coercion I come to the opposite conclusion. If you have one person in the US, the US may claim jurisdiction over the entire thing. If you have one person in China or even with family in China, China may "ask" them for a "favor".
- dane-pgp 4y agoIt may not be good for the person in the malicious jurisdiction, but the idea is that the team members in the other jurisdictions can route around them if they start acting suspiciously. What that means in practice differs from project to project, but some good examples would be a software project where the main developers want to sign a release as being official (i.e. not having a backdoor mandated by any individual government), or a team of people who can decide when (and to whom) to reveal some whistleblower's information (without the danger of a secret warrant compelling unwanted disclosure).