4 ms·
It seems to me this English article does not reflect the actual decision of the court in French. See judgment here and attached PDF (in French) https://www.cou
by user5994461 4y ago
It seems to me this English article does not reflect the actual decision of the court in French.
See judgment here and attached PDF (in French) https://www.courdecassation.fr/toutes-les-actualites/2022/11/07/code-de-deverrouillage-dun-ecran-de-telephone-et-cryptologie https://www.courdecassation.fr/toutes-les-actualites/2022/11...
The case was a person who was arrested for drug possession and trafficking, they were requested to give their passcode to unlock 2 phones allegedly used for trafficking, they refused then were further charged for not giving their password.
1) 15th May 2018 - First court ruled on drug trafficking but rejected the charges for not giving the passcode to unlock the phone, considering that a screen passcode is not a cryptographic mean to make the data on the phone unreadable or inaccessible.
2) 11th July 2019 - Escalated to the court of Appeal, same result.
3) 13th October 2020 - Escalated to the cour de cassation, who ruled that the law was incorrectly applied and sent back the case to the court. The cour de cassation doesn't rule cases, it only rules on whether a specific law was correctly applied by the court. (A decision of the court de cassation, like this one, explains how a law is meant to be interpreted and applied by the courts).
4) 20th April 2021 - The court of Appeal, repeated the initial result (home screen passcode is not a cryptographic mean to protect data) and dismissed the charges AGAIN.
5) Yesterday - Escalated to the cour de cassation AGAIN, who ruled that the law was incorrectly applied AGAIN, and sent back the case to the court AGAIN.
6) Future - This is pending another trial, from the court of appeal.
My understanding of the cour de cassation explanations, the home screen may or may not constitute a cryptographic mean to make the data unreadable or inaccessible, that depends on the phone. The court needs to rule on whether it is for that specific phone in that specific case.
For the HN audience who is technical and some of you actually make the phones. Most modern phones including all Apple and most Android have cryptographic means to protect all the data on the phone, it's effectively not possible to access contacts, messages, photos, storage, etc without having the home screen password. (Please consider that historically, it was often possible to take out the sim card or the storage SD card or use other tools to read the content of the phone, but not anymore)
My understanding is that the next ruling will have to consider whether these technical protections render the data inaccessible to the police. If yes and the data is deemed required for a criminal investigation, the suspect is required by law to disclose their passcode, or risk up to 3 year of prison and 270 000 euros.
- mananaysiempre 4y agoWait, is refusing to give up your encryption keys actually a crime in France (not only the UK)? I thought (though it’s been several years since I’ve looked that up) it was only an aggravating circumstance if the encrypted material in question has been used to commit a different crime and you have been convicted of that.
- user5994461 4y agoIt can be, under the article 434-15-2 that is about that. The decision today is an explanation to French courts about how to interpret and apply this law. The context is a person formally arrested for drug possession and trafficking, who was formally requested under this law to unlock their phones (allegedly used for drug trafficking) and refused. Rough quick translation: "Is punished by 3 years of prison and 270 000 euros fine, the action, for whoever has the knowledge of the secret means to decrypt cryptographic means likely to have been used to prepare, facilitate or carry out a crime, to refuse to submit said ways to authorities or apply them, upon official request under II and III of criminal code. If refused, and providing or applying said means would have allowed to prevent a crime or reduce harm, punishment is increased to 5 years and 450 000 euro fines". French: "Est puni de trois ans d'emprisonnement et de 270 000 € d'amende le fait, pour quiconque ayant connaissance de la convention secrète de déchiffrement d’un moyen de cryptologie susceptible d'avoir été utilisé pour préparer, faciliter ou commettre un crime ou un délit, de refuser de remettre ladite convention aux autorités judiciaires ou de la mettre en oeuvre, sur les réquisitions de ces autorités délivrées en application des titres II et III du livre Ier du code de procédure pénale. Si le refus est opposé alors que la remise ou la mise en oeuvre de la convention aurait permis d'éviter la commission d'un crime ou d'un délit ou d'en limiter les effets, la peine est portée à cinq ans d'emprisonnement et à 450 000 € d'amende."
- folays 4y agoI'm from France, I read the Cassation ruling, and I'm law-savy. First, we wouldn't care of what the 1st court ruled. Nobody would consider a 1st court ruling as a new statu-quo. Content of the 7h November 2022 ruling : https://www.courdecassation.fr/decision/6368dc51f1ea8a7f744fbf98 https://www.courdecassation.fr/decision/6368dc51f1ea8a7f744f... > It says that's an iPhone 4... > the lower court (Cour d'Appel) ruled that the passcode is not a "cryptographic convention" (which both the Algorithm and Private Key would classify as), and consequently that the person is not guilty. > The general prosecutor, not happy with this verdict, appealed to the higher court (Cour de Cassation), arguing that the lower court violated the law by insufficiently researching IF on the concerned iPhone 4, does the passcode is a "cryptographic convention" Because when a Cour d'Appel applies a law, in this case, without not even research if this specific law is applicable to this specific element, it can be broken by the high court. The Cour d'Appel did not even have to be "right" or sufficiently technically competent. The Cour d'Appel only had to declare that it researched IF on this phone, the passcode was a "cryptographic convention". If the Cour d'Appel declared such a thing, EVEN IF IT WERE BLATANTLY FALSE (I'm not arguing myself for the correctness here of this statement), then the Cour d'Appel would be deemed to have stated its sovereign judgment on this matter. On such a task, The Cour d'Appel could not be overridden by the higher Cour de Cassation. (the Cour de Cassation cannot re-evaluate the sobering judgment of the Cour d'Appel). BUT, the Cour d'Appel intended to apply the "refusing to yield the cryptographic convention == bad" law, without even researching IF beforehand this was REALLY a "cryptographic convention". The general prosecutor leveraged this oversight by asking the Cour de Cassation to break the lower court jugement. He won. The Cour de Cassation break the lower court ruling, and sent them back to court again. The break ruling is : > By affirming that the passcode is not a "cryptographic convention", WITHOUT analysing the technical characteristics of the concerned iPhone4, yet essential to figure out a decision, the lower court insufficiently justified its decision ==== What I have to say on this matter It's an old iPhone. I'm a bit lazy to Google what's the passcode is doing on the range of iOS versions supported on such an old phone. A 4-8 digits passcode is not enough not be secure. That's weak as hell. That's only 10^8 possibilities, and the Private Key can be brute-forced in 1 second. Still, IF on this old iPhone the weak-as-hell passcode was the Private Key of encrypted data, then it could be deemed a "cryptographic convention", and the person could be deemeded guilty. On a RECENT iPhone, I think that this person could escape being guilty for not giving its homescreeen password or code. On RECENT iPhone, those weak (4-8 digits) are NOT part of a "convention de déchiffrement" The passcode is neither the crypto algorithm, nor the Private Key to the data. on recent iPhone, the password is ONLY a key to a safe : the Secure Enclave (T2 chip). The Secure Enclave, even in rescue mode, has an API, and only accepts ~10 passcode attempts. When you succeed, you are giving a mean to decipher data. I don't even know if : - the Secure Enclave yields back the Private Key - or just provides an hardware API to further decrypt data. What I mean is that on recent iPhone, the passcode is NOT part of the "cryptographic convention". It only unlocks a safe : the Secure Enclave. That would be the same thing as storing the Private Key in a safe. On iPhone4, probably the passcode IS used as a seed to regenerate the Private Key, and as such refusing to give it to police is breaching the law. On iPhone with Secure Enclave + T2, probably the passcode is not used as a seed, because that would be weak as hell. refusing to give it to police is possibly not a breach of law.