23 ms·
Judge: Fifth Amendment doesn't protect encrypted hard drives
- thereallurch 15y agoAny technologies exist that let you have multiple encrypted OS's on multiple keys? For example, 1 key could boot up one OS and another key could boot up a different OS. Seems like it'd be difficult to prove that you booted one or the other...
- ge0rg 15y agoYes. The term for that is plausible deniability. It is implemented (probably among others) in truecrypt: http://www.truecrypt.org/docs/?s=plausible-deniability http://www.truecrypt.org/docs/?s=plausible-deniability
- sp332 15y agoPlausible deniability is a much larger concept than that. Also if they know you're using Truecrypt, the "deniability" of the existence of a 2nd (or 3rd or 4th) OS goes down significantly.
- ge0rg 15y agoIt does indeed. However, what are they going to do? Torture you until you give them the "other" password? How can they distinguish whether you just cleaned your hard drive or if you gave them the wrong key?
- bdg 15y agoThe solution is of-course a honey-pot OS to boot.
- gte910h 15y agoNo it's doesn't. Truecrypt ALSO does full disk encryption...which is a very very good security precaution corporations everywhere are implementing.
- drostie 15y agoI'm not so sure. TrueCrypt is first and foremost an encryption program. The fact that you have it might suggest that you encrypted something somewhere, but it doesn't directly suggest that you took the time to use its advanced "hidden volume" capabilities. So even if the police can say "hey, this looks encrypted, and you've got nothing else which looks similar, decrypt it for us," they are still stuck on "hey, we didn't find the evidence we were looking for -- maybe you have a hidden volume?". You say "I don't" and the judge says "GRR ARG DECRYPT IT NOW" and you say "I can't, it doesn't exist, I really am innocent, please get the scary men away from me."
- baddox 15y agoThe deniability doesn't diminish at all. You can even testify in court that the drive is encrypted using TrueCrypt and that TrueCrypt has plausible deniability. The whole point of TrueCrypt's plausible deniability is even when you know about the feature, you simply can't mathematically prove whether or not it's being used.
- dedward 15y agonot directly, but their faq pretty clear about a bunch of secondary ( out of band, internet updates duplicated, etc) correlations that could lead to good evidence that the second system exists. pulling that off is noeasy task.
- deleted 15y ago[deleted]
- talmand 15y agoI can see the legal issues that would be forthcoming if you refused to share the key to allow for access or agree to type it in yourself. Obstruction and all that. I'm wondering what the legal ramifications might be if you set a secondary key that would wipe the drive in the most secure method possible and then provide that key. Or even the alternate boot sequence as suggested.
- mc32 15y ago>I'm wondering what the legal ramifications might be if you set a secondary key that would wipe the drive Destruction of evidence. http://en.wikipedia.org/wiki/Spoliation_of_evidence http://en.wikipedia.org/wiki/Spoliation_of_evidence
- talmand 15y agoOh, I get that, I'm not saying it's a way to avoid the ramifications, I'm just wondering what they are. I have to say that I somewhat agree with the ruling because there are similar situations with physical objects, not true one-to-one but they are there. I'm just wondering how the courts would react to the destruction of digital evidence that was not directly initiated by the defendant, but indirectly by preparing for the possibility.
- Simucal 15y agoThese "wipe the drive" decoy password scenarios would never work in real life unless their forensics team was really inept. There would be copies made and the drive that has the encrypted volume would likely be accessed with a "Write Blocker" forensic device, or in a virtual environment, etc. This technique would only tip your hand that the volume contents changed after entering the password.
- slowpoke 15y agoA technical solution to this might be a form of encryption the requires a writable disk to actually decrypt anything. I don't know if that is possible, but it would effectively prevent these safeguards to work. And remember, you don't need to wipe the entire drive. Changing a few random bits in the decryption key would already forever turn the drive contents into unreadable garbage.
- dhechols 15y agoI foresee Truecrypt-ception. An encrypted OS within an encrypted OS within an encrypted OS. They'll never find my porn/plans to take over the world/illegal software/hacked secret government cables NOW!!!
- amalcon 15y agoThe technology for this does exist, but it's pretty annoying to use in practice. You need to use the "decoy" OS regularly -- preferably most of the time. After all, it's implausible that you haven't used your web browser in six months, etc, and your adversary would notice this. The problem there is that the "hidden" OS is (by definition) undetectable from within the "decoy" OS. Therefore, you risk accidentally overwriting it. Some encryption software has workarounds for this, but that typically leaves you exposed while it's in use. Whole-disk encryption is great for protecting credit card numbers, embarrassing information, and trade secrets from someone who should happen to steal your laptop. If you actually have anything so secret that you're worried about being coerced into decrypting it, I don't know how to help you.
- showerst 15y agoJust out of curiosity, what's the case-law like if she had encoded these documents and stored them on paper? I certainly don't want to see mandatory decryption, but at the same time it doesn't make sense to let an accused completely skip out on discovery by simply truecrypt-ing the evidence either.
- mikeash 15y agoTo me, the most convincing argument is, what if you legitimately forget your password? If that alone gets you thrown in jail, then you're going to be jailing a lot of innocent people. On the other hand, if that does not get you thrown in jail, then one can simply claim to have forgotten the password without repercussion. Personally, I'd rather let people hide evidence by encrypting it than jail people for being forgetful, since those seem to be the only two choices.
- grecy 15y agoI agree 100% I'm thinking about the case where a person never even knew the key to what they have. The example is a business laptop being carried through customs, that was encrypted by someone else, who will decrypt it upon your arrival (or something similar)
- tedunangst 15y ago1. If there's no evidence that you know the password, that's possibly a reasonable defense. When the police have a recording of you saying "don't worry, the files are on my encrypted partition", it's less reasonable. 2. I would seriously reconsider the decision to carry unknown contents through customs.
- jrockway 15y ago2. I would seriously reconsider the decision to carry unknown contents through customs. My ISP does this billions of times per day.
- 15y ago
- tedunangst 15y agoYesterday's link, to the original source: http://news.ycombinator.com/item?id=3502850 http://news.ycombinator.com/item?id=3502850
- fab13n 15y agoTo counter this, you need an encryption method with these properties: - you can be banned or self-banned, irrevocably, from accessing your data; - you can prove to the judge that you can't access your data; - even with full forensic copies of your disk, you can't be un-banned. You can do that by having part(s) of the key on server(s) online. Give yourself, a couple of trusted friends and optionally a script, the ability to wipe those keys: it will irrevocably seal your disk's content. Obviously, pick servers under foreign jurisdictions which dislike to collaborate. Even better, there's no proof that you're the one who destroyed the keys: you can't be charged with evidence tempering.
- mahyarm 15y agoCan someone else be charged with it? Will you have to go through a long court case with it?
- SamReidHughes 15y ago> Even better, there's no proof that you're the one who destroyed the keys: you can't be charged with evidence tempering. How much do you want to bet?
- koenigdavidmj 15y agoMaybe add a dead man switch? If you don't log on every week, then destroy the server side of the key.
- fab13n 15y agoThat's a possibility, but the risk of having your data inadvertently destroyed is much higher. Moreover, you must trust your ability to stall inquiries for up to a week. It really depends on the relative cost of having your data destroyed vs. having your data published, but I'm sure there are cases with a dead man switch is a good compromise.
- gte910h 15y ago>Even better, there's no proof that you're the one who destroyed the keys: you can't be charged with evidence tempering. The court doesn't really work this way. Just because you cross your fingers when you do something doesn't mean you aren't going to be charged with destruction of evidence.
- AndyKelley 15y agoDid anybody see this? But the police had recorded a phone call between Fricosu and her husband in which she seemed to acknowledge ownership of the laptop and to reference incriminating material on it. I'd like more details about this - without any clarification, this sounds extremely scary.
- Harkins 15y agoWithout any clarification, this sounds like perfectly normal wiretapping. Is there any reason to think the police didn't obtain a warrant?
- lukev 15y agoPresumably the phone call surveillance was under warrant. It's also worth noting that they would have needed a warrant to seize the computer itself to begin with. The question is whether, having been seized, they can require her to decrypt it for them.
- pavelkaroukin 15y agoWhat if lawyer-based service is created, which allows to automate representation of client including when client need access to data on the his hard drive. Essentially, develop algorithm allowing external OTP authentication. And this lawyer, representing user, will have in agreement something like this "In case my client is under investigation or incriminated or ..." I will not be allowed to release OTP password. Of course, this service will be based in country which treat law as a law, not inconvenience. What I am missing? There are no such countries may be?
- tedunangst 15y agoIn my lay opinion, you are treading very close to making the lawyer complicit in the crime, at which point there is no privilege shield.
- pavelkaroukin 15y agoOnly if lawyer is USA based this might make him commit a crime. But what if lawyer based in the country where forcing to reveal password is unlawful?
- EchoAbstract 15y agoIn the USA it is not legal (in violation of the 5th amendment) for the court to compel you to reveal a password (if your read the brief the Judge says as much). However, if the court can prove by other means that you own the data on a drive, they can compel you to provide them with the unencrypted contents of the drive via a search warrant.
- bluedanieru 15y agoIf they can prove it, why do they need you to decrypt it for them?
- savramescu 15y ago
- rdl 15y agoI really hope this gets appealed.
- pavelkaroukin 15y agoBTW, hackers, if you did not see it yet, check out what EncFs offer you. Essentially, it allows you to have multiple passwords on the same repository, and only files decryptable with currently used password are shown (require special option during mounting to ignore incorrect password warning). Using that you can have any number of passwords and any number of "partitions" inside your folder. This is not like hidden partition in TrueCrypt, where you can not prove it exists at all.
- lukev 15y agoAn important clarification since some people seem to be confusing the issue: the police seized her computer already, presumably legally and with a warrant. So while this does present an interesting edge case in the fifth amendment (does evidence count as evidence if it's encrypted?), it shouldn't set off civil liberty alarm bells in your head nearly as badly as several other things currently going on in this country.
- mikeash 15y agoI disagree. If you can be jailed for refusing to decrypt data on a computer seized under a legitimate warrant, then you can be jailed for not having the password for encrypted-looking data on a computer seized under a legitimate warrant. A warrant does not imply guilt, so this means innocent people may be imprisoned.
- lukev 15y agoI agree completely. Just saying that a question of what a court can compel you to do as part of a trial (before sentencing) is a quite different than a fourth amendment issue of illegal search and seizure which it seems some people are conflating this with.
- thisischris 15y agoI forget my password for things all of the time...This situation would be no different.
- simonsarris 15y agoI have question to those who know more about these things: Instead of hidden volumes, wouldn't it be better to have an "under duress" password? The hard drive is encrypted and sensitive folders are identified by the user. When a password is given all contents are decrypted. When a "under duress" password is given the sensitive folders are permanently wiped and all the (remaining, innoculous) contents are decrypted. This stops them from finding hidden volumes or operating systems because there are none. Wouldn't that be a better model, and much harder to figure out?
- tedunangst 15y agoThen they restore the hard drive from the cloned image they made before entering the password and ask you once more for the password. This time, with feeling.
- harshreality 15y agoThey would also tack on extra charges for interfering with a police investigation by attempting to destroy evidence, and/or the court would find you in contempt.
- pyre 15y agoI don't think that contempt would apply. Either obstruction of justice or destruction of evidence.
- repsilat 15y agoThere might be a market for keeping your keys on some service "out there". Boot your computer, type in your password, your computer sends the password to the key service. If the password is correct they send back the key, if the password is the destruct codes they delete the key. No amount of hard-drive cloning will stop this. Paired with some other optional measures ("we delete the password unless you send an email every week" etc) and it's almost foolproof. You might still have a hard time arguing against destruction of evidence, though. I guess if your "don't delete the keys" email was "Please delete my encryption keys" you could be completely honest and they wouldn't believe you, resulting in your keys being deleted despite your complete cooperation.
- ctdonath 15y agoIt's a variant of what's called "rubber hose cryptology": sometimes it's technologically a lot easier to just beat the password out of someone (smacking the soles of one's feet with a rubber hose apparently being a rather effective technique). I draw the line using a "rag doll" model. They can compel fingerprints, physical keys, DNA, etc. insofar as they can manipulate your limp unresitive (albeit uncooperative) body to take fingerprints, extract keys from pockets, snip a hair, extract a blood sample, etc. They cannot, however, compel you to act on their behalf and against your own interests - to wit, they cannot demand you speak (type, write, press buttons) words the whole point of which can and will be used against you. A fair argument may be made for compelling you to provide the key/combination to a safe, but only insofar as they CAN tear the safe apart with blowtorches & diamond saws if you don't cooperate. But when it comes to the state's evidence hinging entirely upon the defendant's cooperation, no - that's why we have the 5th Amendment (gov't cannot compel one to testify against self).
- rhizome 15y agoBut when it comes to the state's evidence hinging entirely upon the defendant's cooperation, no - that's why we have the 5th Amendment (gov't cannot compel one to testify against self). And really, doesn't that mean it (whatever is obscured by a lack of cooperation) shouldn't be considered a crime? Kind of by definition?
- dedward 15y agoNot if they find a way to get to it and it incriminates you. otherwise, lack of coooperation because you are exercising your rights is not supposed to be used as evidence of a crime. not letting the police into your home is not in any way considered valid criteria for a judge to issue a search warrant, as i understand it.
- nknight 15y agoThis is a very clear and compelling (so to speak) way of thinking about the problem, and one I don't think I've ever heard before. Is this an independent invention of yours or is there literature to be found on the "rag doll" model?
- orbitingpluto 15y agoClassical jibberish passwords are mostly muscle memory. I know I wouldn't be able to remember some of my mine of that sort after two weeks. If you were incarcerated and you knew you might have to comply with an order to decrypt a hard drive, it might be in your best interest to create and shadow type many alternate passwords until you actually forget the important one. Then (hopefully) you're just a polygraph away from a not guilty in an obstruction charge.
- SquareWheel 15y agoOf what I understand of the methodology used by polygraph, forgetting the password wouldn't help you out here. You'd still be intentionally misleading the police, and that would lead to the signs the polygraph attempts to detect.
- plasma 15y agoIt would be cool to have a "canary" system in encryption. For example, without having entered the 'everything is OK' password every week, the drive/encryption automatically destroys itself. So if the drive is ever compromised, or you are separated from it, etc, the fact that you do nothing should cause the protected data to be destroyed.
- deleted 15y ago[deleted]
- ROFISH 15y agoIt looks like they're not trying to decrypt the laptop for the fun of it, but judge has physical evidence that the laptop contains relevant information to the case. From the article: But the police had recorded a phone call between Fricosu and her husband in which she seemed to acknowledge ownership of the laptop and to reference incriminating material on it.
- tricolon 15y agoA recording of a phone call is now physical evidence of the existence of information somewhere else?
- MichaelApproved 15y agoEveryone is trying to figure out which encryption technique can bypass the law when it's already too late. The best solution for this type of case is to keep your damn mouth shut and don't talk about the contents of the drive. "the police had recorded a phone call between Fricosu and her husband in which she seemed to acknowledge ownership of the laptop and to reference incriminating material on it." Without that recording, the prosecutions case would be a lot weaker. Sure, encrypt your files, but keep your mouth shut about it!
- jimbishopp 15y agoNote to self: never acknowledge ownership of a laptop with incriminating material on it (encrypted or not); especially while on the phone or in the general vicinity of a recording device.
- jQueryIsAwesome 15y agoWhat happens if a friend of a suspect burns some papers that the jury suspects that those were incriminatory evidence? In this context: what would happen in the case the crypto software deletes all the data after not logging in for 1 week? (It would be too short for the trial to happen i guess)
- Groxx 15y agoMakes sense. Yes, dead-man switches and whatnot always come up with cases like this - that's not really part of this ruling. This case includes: a) they have record of the defendant stating the information exists on the machine, which she stated she owns, and b) they have (a very good) reason to believe the drive can be decrypted. All of this strikes me more as a search warrant than anything, in the same way that they can break locked doors if they have a warrant to search a location. That it's a cryptographic lock really has no bearing on the matter - if the documents were printed and put in a locked closet, they could be confiscated and searched. Why is this different?
- ck2 15y agoI used to think we didn't want these kinds of cases in front of the supreme court right now - but I am starting to change my mind. They are showing signs of intelligence.