12 ms·
UK anti-encryption law
- Zenst 14y agoI stand by my argument that you can have a encryption key that is say 2000 characters long. Print it out 1 character per page and submit that in advance at your local police station, getting a receipt. You are then within the law. Now question is - compression can be views as encryption. How does that pan out if you use a non-standard form of compression that does not require a key as the compression formula is the key in itself!
- nathan_long 14y ago>> You are then within the law. What good does your maneuver do? Now you have to work with that key, and if they really care, they can laboriously type it in. All you've done is tick them off, right?
- Zenst 14y agoPoint being that there is a good posibility they will misfile it and in that case you have extingished your liability. Ticking of the police is not against the law and if enough people do it then the sillyness of things starts to stand out. That all said you can have a trusted friend who lives in another counry maintain your key and vice versa, then things get messy. Sad part about all this is criminals will find a way to get around the law, and in many cases they will way up the aspect of what charge they would get from the decrypted data compared to a maximum 5 year one and pick the easiest option.
- nathan_long 14y agoThis is silly. If they misfile it, they'll ask for it again. If you say "I already gave it to you but you lost it, nyah nyah," they'll find you in contempt of court. For that matter, if you're in the middle of trial and give them what they asked, but in the most massively inconvenient way you can think of, they'll find you in contempt of court. Judges are not (usually) stupid.
- Zenst 14y agoThere is nothing saying you can't then use the defence of you forgot the encryption key. Having previously provided it your obligation to the law is extinguished. Judges are not stupid, not the easiest job to get and takes alot of work. They may not be experts in every feild they have to deal with though and in that they depend on expert witness's. The point being that it is a silly flawed law and the approach I outlined is one which is just as silly, yet still compitulates with the letter of the law fully. Now if your in a situation were you are having to defend raw random encrypted looking data that is just raw data, then is the onus upon yoruself to prove it's just random data and if not anybody could say its not encyrpted its random data, could they not? Question is how should the law actualy handle the situation were some data from a criminal activity is encrypted and would requitre 1000 years to brute force? This law was a way to cover those situations. It's not perfect and in many respects is down right offencive. But it's like this - if you have nothing to hide then why should you be made to feel like a criminal. That is the real crux of the matter, though some people may view it entirely differently. Heck a badly spelt/grammer document could be deemed as hiding encrypted data when it is just bad spelling/grammer or it could actualy be encypted/obfiscated data hidden within the document. you just can't tell and that is were it starts to get realy realy messy.
- rmc 14y agoTicking of the police is not against the law No, but wasting police time is.
- Zenst 14y agoVery true but not when they waste there own time. Personly it is a silly law made out of panic and in that is flawed. My approach just highlights the sillyness of the law in itself. I love the police but there again I don't break the law. The point being that whilst your obligated to provide the key, there is nothing saying how that key is provided and that is another flaw in a flawed law. Though some people are taking it too literaly I suspect. Until there is a case of this law being used to actualy procecute somebody unfairly and unjustly then it is hard to argue it's flaws, but we all see those flaws and shortcommings, like many things in life. Nothing is perfect.
- lamby 14y agoThe legal system is not a computer program.
- Zenst 14y agoNobody said it was and in that things are not always black and white and as clearcut as they could be. the case of random data - is it random data or is it encrypted being the case in point. This is why we have resonable doubt in the UK and innocent until proven guilty. In France they have guilty until proven innocent and such a law as this over there would be alot more painful to defend in that respect. Personaly I like the Scottish system of Innocent until proven Guilty but with the added verdict of not-proven, this covers things were it is not entirely clear that your innocent and there are doubts, though not enough to convict a guilty verdict. That too me is a fairer system on balance.
- DanBC 14y ago> Now question is - compression can be views as encryption. How does that pan out if you use a non-standard form of compression that does not require a key as the compression formula is the key in itself! GCHQ aren't idiots, and would be able to "decrypt" such toy crypto schemes. But, even if they couldn't be bothered to do so the law doesn't require only a key, but either a key or to make the data intelligible.
- Zenst 14y agoNobody is saying GCHQ are idiots and I fail to see why you mention them. This is not about some "toy encryption schemes" it is a observation that as this law stands it there is no real way to say what is random and what is encrypted or in the case I point out - compressed. Now the whole argument of making the data intelligible is a completely different argument and gets back to how do you prove random data is actualy just that. You can't. Good encyption with have entropy akin to random data. Also a compressed file will have the entropy of poorly encypted data. Data is just that, data. Intelligble data is information and is not data. Big difference and in that any data set is random without meaning/interpritation.
- DanBC 14y agoYou say this: > Now question is - compression can be views as encryption. How does that pan out if you use a non-standard form of compression that does not require a key as the compression formula is the key in itself! You then ask why I mention GCHQ. I mention GCHQ because they control NTAC (National Technical Assistance Centre) - this is who will attempt to decrypt the data. This will happen in parallel to RIPA notices being issued. If a person uses a non-standard form of compression and the police are interested there are two actions from police: 1) GCHQ trivially 'break the crypto' 2) A RIPA notice to make the data intelligible is issued, forcing the user to un-compress the data. > Now the whole argument of making the data intelligible is a completely different argument No, it really isn't. If you've encrypted it or compressed it or used steganography or used some simple code system to hide data they issue a notice and you have a limited amount of time to make the data intelligible. > and gets back to how do you prove random data is actualy just that. You can't. This is a different argument, and is not what you said.
- nathan_long 14y agoHis argument is: 1) They can lock you up for refusing to decrypt something. 2) Encrypted data looks exactly like random noise. 3) Encrypted data can be hidden in any file. 4) Therefore, they can allege that nearly anything is encrypted and lock you up on that basis. I'd say that's terrifying. Another thought: doesn't this make it possible to frame someone by writing random data to their hard drive?
- mjhall 14y agoThe argument isn't totally correct. The Police can't just make allegations and force you to surrender keys - they have to convince a judge that the allegations are true, and that getting the keys to your random noise will produce evidence. RIPA is objectively flawed legislation, but it definitely doesn't "outlaw encryption" by anything less than a very long stretch of the imagination (as appears in this article).
- nathan_long 14y ago>> they have to convince a judge that the allegations are true, and that getting the keys to your random noise will produce evidence You are correct. However, suppose you encrypt some data and forget the key, or you store some radio noise in a file, or whatever. Later, you are accused of a crime. The judge issues a warrant. The data/noise is now evidence against you. You are presumed guilty, and it is impossible to prove your innocence.
- freehunter 14y agoI have to wonder if this would ever hold up in court. I don't know much about the UK justice system, but in America it would be pretty rare to be convicted of a crime that they can't actually prove you committed. You could be jailed for refusing to comply with a court order to decrypt the file, but if you can prove it's not actually encrypted, they can't do anything about it.
- omaranto 14y agoHow do you prove something is not encrypted?
- DanBC 14y agoIn theory the accused is innocent until proven guilty, and thus should only need to suggest that the data is random, and pass the burden of proof back to the prosecution, who now have to prove the random data is encrypted. File headers, existence of cryptography software and manuals, etc might be useful. Admission that the data is encrypted is stronger. (http://www.computerweekly.com/blogs/the-data-trust-blog/2009/11/ripa-tears-up-the-right-to-rem.html http://www.computerweekly.com/blogs/the-data-trust-blog/2009...)
- nathan_long 14y ago>> if you can prove it's not actually encrypted But that's the thing: you can't prove that. You're saying: "prove that there does not exist any decryption method or key that will turn this blob into incriminating data." You can never prove that such a decryption method doesn't exist. In fact, maybe it does exist? Given a blob of random data and infinite time, couldn't you find a way to "decrypt" that into pre-defined data? (I'm not really sure of that.)
- adrianN 14y agoYou can decrypt random data to anything if you want to. Say R is your random data and M is the message you want. Compute Key=R+M, then decrypt R-Key=M.
- ivanmilles 14y agoSo, now Random actually /is/ Resistance? http://www.youtube.com/watch?v=aE6RtzwVdHI http://www.youtube.com/watch?v=aE6RtzwVdHI
- pavel_lishin 14y agoEvery time I listen to that song, I imagine a movie in my head where that is the theme song for a resistance movement. Never really thought about how terrifying that might be in reality.
- mootothemax 14y agoIn the section of the act mentioned (Regulation of Investigatory Powers Act 2000, part III), two of the defined terms are: “key”, in relation to any electronic data, means any key, code, password, algorithm or other data the use of which (with or without other keys)— (a)allows access to the electronic data, or (b)facilitates the putting of the data into an intelligible form; -- and -- “protected information” means any electronic data which, without the key to the data— (a)cannot, or cannot readily, be accessed, or (b)cannot, or cannot readily, be put into an intelligible form; http://www.legislation.gov.uk/ukpga/2000/23/part/III http://www.legislation.gov.uk/ukpga/2000/23/part/III At first, I thought the argument in this article was nonsense. However, whilst I'd hope common sense would prevail, the definitions above seem broad enough that a policeman could make one's life difficult for a while.
- excuse-me 14y agoIt was being discussed well before this, in the early 90s i went to a computer lab seminar about this and we asked - we have Tb of data in our detector system that is either truely random (ie part of a Monte Carlo sim) or is essentially random (the detector noise), how do we prove this isn't encrypted. Oh don't worry, said the nice man from the police computer unit - it's only going to be used against terrorists.
- Zenst 14y agoThat is in practice the intention, though as it is a law on the book's it is open to be abused down the line against non-terroists. As a rule the UK police tend to have alot of common sence, but they are also human. That all said the whole blackberry encryption affair recently arising due to the riots does highlight further shortcommings. Still this law was instigated prior to 9/11 and in that you do wonder what it would look like if it was instigated after the event and how it may of looked.
- sdoering 14y agoWell, if I remember right, the UK had their "fair share" of terror (IRA), long before the US suffered from 9/11. So this argumentation does not strike me so extraordinary. But that does not change the point, that this law really has the possibility to be misused.
- deleted 14y ago[deleted]
- 16s 14y agoIt is impossible to prove a PRNG'ed file is or is not encrypted data. TrueCrypt volumes look identical to `dd if=/dev/urandom of=file.bin bs=512`. Create a few of each and then evaluate them using ent to see this for yourself. Edit: Link to ent http://www.fourmilab.ch/random/ http://www.fourmilab.ch/random/ You could prove the file is encrypted if it is indeed encrypted and you have the passphrase and the program to decrypt it, but outside of that, it's simply not possible to say with any level of confidence that the bits are really encrypted. BTW, I wrote TCHunt in 2007, a program that attempts to seek out encrypted TrueCrypt volumes and I have a FAQ that covers much of this. Here's the link for anyone interested in reading more about it: http://16s.us/TCHunt/ http://16s.us/TCHunt/ And, there is usually much more to it than randomish bits in a file on a disk. The government agents usually have other evidence that suggests the person in question is doing illegal things and may have cause to use encryption. Finding actual encrypted data is normally just icing on the cake to them.
- excuse-me 14y agoThe original UK phrasing of the law was even sillier. They had taken into account codes as well as cyphers. You could be forced to explain the meaning of any other messages such as "the geese fly south for the winter" . But the wording was ridiculous, something about any hidden or private meaning in any otherwise innocuous text. So if you happened to have a book of poetry around the police could compel you to explain the symbolism! Heaven help you if you had a Torah and they asked you to explain any "hidden meanings"
- Jabbles 14y agoThe wonderful thing about TrueCrypt is that you have plausible deniability. If one were worried about having to provide a key, you could provide one that revealed pictures of cats without revealing anything you wish to remain hidden, or indeed if there was anything further to reveal. This makes this attempt at a law look even sillier.
- deleted 14y ago[deleted]
- theaeolist 14y agoIsn't TrueCrypt's 'hidden volume' feature enough to make this law pointless? Just have two encoded sets of information in the same file. When you are asked to give the key it is up to you the key of which one you give. http://www.truecrypt.org/docs/?s=plausible-deniability http://www.truecrypt.org/docs/?s=plausible-deniability
- omh 14y agoOr perhaps after giving the key to the main volume the police will insist that you give them the key to the hidden volume. If you deny that there is a hidden volume then they'll just say that you're refusing to decrypt and prosecute you anyway.
- theaeolist 14y agoJust put a hidden volume inside a hidden volume inside a hidden volume. There.
- DasIch 14y agoIt still requires you to give up data for which it makes sufficient sense to be encrypted otherwise someone might get the idea that you are using this feature. While this is a solution it is certainly not as easy a solution as it might seem to be.
- theaeolist 14y agoSome very nasty (legal) porn should do it.
- jakeonthemove 14y agoDamn, the UK is pretty f'ed up - the list of things that British citizens can't enjoy compared to a lot of other countries (even developing ones) is growing every day. Meanwhile, a criminal could easily just store everything on an encrypted microSD card, then eat it if anything goes wrong - the oldest trick in the book still works in the digital age :-D...
- theklub 14y agoAdd this to putting missiles on top of apartment blocks for the Olympics and I really have to agree with you.
- koenigdavidmj 14y agoBeen a while since we've had a case reminding us why we actually need the Third Amendment in the US.
- mibbitier 14y agoI think you guys need to stop believing everything you read.
- DanBC 14y agoThe missiles are stationed in 6 areas in London. Whether they'll be used is another matter. People were asking "what's the difference between a plane that has been crashed into London and a plane that has been shot down over London?", to which the reply is "a plane that is shot down is, effectively, disintegrated and burnt in the air, leaving small fragments to scatter." http://www.bbc.co.uk/news/uk-18766547 http://www.bbc.co.uk/news/uk-18766547
- ktizo 14y agoWell, it was confirmed by the MOD.
- pavel_lishin 14y agoIf they know you have it, destroying it is not really different in the eyes of the law than refusing to provide a key.
- shill 14y agoEvery digital storage device on earth should contain a randomly sized random data file called RANDOM-DATA. The user of said device could optionally replace this file with encrypted data. Once critical mass is achieved, states that do not respect individual liberty would have no way of determining the nature of every RANDOM-DATA file that they obtain by eavesdropping, theft or force. I know the answer to this is 'easier said that done'. Certainly hardware and OS vendors can't be trusted with this task. Maybe FOSS installers could educate users and optionally create the file? How can we make this happen? I want to wear a t-shirt that says 'random numbers save lives.'
- adamt 14y agoI don't like or support the legislation - but I think this is a bit of an over-reaction. The law as I understand it says that if you've got data (and the context of the law is in focussed primarily on targeting terrorism, child-porn etc) that you've encrypted but refuse to give over the encryption keys to; then if the police then convince a judge that there is valuable evidence in the encrypted data, and you still refuse, then you could ultimately go to prison. Is this really any different to a digital search warrant? Sure this law, like many others, could be abused. But I don't see it as anything to get to wound up about. P.s. what kind of person has a 32GB file of satellite noise to generate random numbers with?!
- DanBC 14y ago(http://www.computerweekly.com/blogs/the-data-trust-blog/2009/11/ripa-tears-up-the-right-to-rem.html http://www.computerweekly.com/blogs/the-data-trust-blog/2009...) > Police argue the files "could be child pornography, there could be bomb-making recipes." Note that he was in prison -serving a sentence- but has since been transferred to a secure mental health hospital where he can be detained under the MHA until he is well. I don't know if he had an appropriate adult with him at any police interviews. I don't know if he had any legal representation at any time. These are weaknesses in the UK system.
- adamt 14y agoFrom that article: he Missed bail; traces of explosives; carrying home made rockets; had a stash of encrypted storage drives with him and the authorities wanted to see what was on them. In such cases the person is still innocent but the authorities have a duty to investigate. Don't get me wrong I am a hacker and someone who has written lots of crypto code, but i don't see this as an example to support the case against the legislation.
- SoftwareMaven 14y agoThis is the reaction that is going to destroy all of our civil liberties. "It's only a problem if you're guilty." what kind of person has a file of random (or near enough to not be able to tell without 32gb of them) numbers? Any cryptographer? Many astronomers? Physicists? Better lock them all up!
- Albuca 14y agoThis reminds me of this American Case: http://www.wired.com/threatlevel/2012/02/forgotten-password/ http://www.wired.com/threatlevel/2012/02/forgotten-password/ But on the whole, the whole article is scary and slightly unsettling. On the upside I dont live in the UK - But if we were to be traveling through the UK with our encrypted HardDrives, would we be targeted by the law?
- antoinevg 14y agoRoll on dual encryption. One key renders a dissertation on kittens, the other renders the original clear-text. Next problem?
- LarrySDonald 14y agoIt'll get more complicated later I'm sure, but yeah, that's the current patch. Except replace "dissertation on kittens" with "gay porn collection" (or "straight porn collection" if you're publicly gay. or whatever else makes good sense to encrypt, but is still perfectly legal).
- SEMW 14y agoWhile it is obviously a bad law, it's not quite as bad as he's making out. s.53(3): "For the purposes of this section a person shall be taken to have shown that he was not in possession of a key to protected information at a particular time if— (a) sufficient evidence of that fact is adduced to raise an issue with respect to it; and (b) the contrary is not proved beyond a reasonable doubt." In other words, if there's evidence for there to be 'an issue' about whether you actually do have a key (or whether e.g. it's just random noise), it's up to the prosecution to prove beyond reasonable doubt that it is actually data, and you do have the key. So the flowchart is: - If the police can prove they have reasonable grounds to believe that something is encrypted data that you have the key to, then - That raises an evidential presumption that you do have it, which you can rebut by - adducing evidence that just has to raise an issue about whether you have a key (inc. whether it's encrypted data at all), in which case the police have to - Prove beyond reasonable doubt that it is encrypted, and you do have the key. (IANAL)
- SoftwareMaven 14y agoThis would still concern me. It isn't hard to imagine the police assuming any file they don't understand is that way because it is encrypted and, being that they are police and not scientists or engineers, that number could be quite high. So now, you may actually know what's in that file. Great, no problems (other than the headache of dealing with explaining files in the first place). The real danger is what if you don't know about the file, either? "I have no clue" is not going to cause reasonable doubt. The problem here is the law starts from a presumed guilt, which is problematic if you are, in fact, innocent. But it really does come down to how the first clause of the law gets interpreted. Is it reasonably interpreted or not? I have lost faith in any chance of governments sticking to reasonableness when it comes to their threat of terrorism, protecting their "children", etc.
- SEMW 14y ago> It isn't hard to imagine the police assuming any file they don't understand is that way because it is encrypted True, but they have to prove they have reasonable grounds for believing, not just that it's encrypted, but also that you have the key to it. > "I have no clue" is not going to cause reasonable doubt It doesn't need to cause reasonable doubt, it just has to raise an issue about whether or not you have they key. In which case the police have to prove you do beyond reasonable doubt. But you are right - it is ambiguous, and that evidential presumption is in danger of being interpreted in a very anti-defendant way. But: > I have lost faith in any chance of governments sticking to reasonableness Thankfully, it's not up to the government to interpret legislation, it's up to the courts. And they have to interpret criminal legislation (a) in favour of the defendant (common law principle), and (b) compatibly with the human rights act. That second one is powerful, and has resulted in anti-defendant statues being interpreted almost out of all recognition by a court happy to interpret stuff compatibly with the HRA right to a fair trial. See e.g. http://www.guardian.co.uk/uk/2001/may/18/lords.politics http://www.guardian.co.uk/uk/2001/may/18/lords.politics .
- mistercow 14y ago>Yes, this is where the hairs rise on our arms: if you have a recorded file with radio noise from the local telescope that you use for generation of random numbers, and the police asks you to produce the decryption key to show them the three documents inside the encrypted container that your radio noise looks like, you will be sent to jail for up to five years for your inability to produce the imagined documents. Of course, if you have access to the files, you could just XOR the noise with some innocuous documents, and send the result to the police saying it's a one-time-pad.
- qxcv 14y agoHell, you could say the key is head -c `wc -c secret_file` /dev/urandom and they wouldn't be able to argue. It's turtles all the way down if they ask you to decrypt the result.
- baby 14y agoA scary article that forgot already many "stupid" or "vague" laws exist and are never used or always used in the right context.
- MRonney 14y agoI was watching 'Garrow's Law' yesterday. He said that "Laws which are passed in times of fear, are rarely removed from the statute books". Terrorists always win, because every time they attempt to strike the Government removes our basic liberties under the guise of protecting us.
- biomechanica 14y agoWell, Norway is dealing with their attack quite well.
- vy8vWJlco 14y agoWe are have begun to outlaw privacy. This is wrong. Speak up, while you still have a voice. http://archive.org/details/the_hangman_1964 http://archive.org/details/the_hangman_1964 https://www.youtube.com/watch?v=keZlextkcDI https://www.youtube.com/watch?v=keZlextkcDI https://en.wikipedia.org/wiki/The_Drumhead https://en.wikipedia.org/wiki/The_Drumhead
- shocks 14y agoHidden volumes. Volume one contains hardcore porn, volume two contains bank job plans. Neither can be proved to exist with their keys. When asked, hand over the porn keys. Plausible deniability.
- Karunamon 14y agoMore people need to know about this. Unless you're quite foolish, this right here will stymie most government attacks. It's difficult to prove that a file full of random noise is actually an encrypted container (but possible, seeing that Truecrypt is installed and other factors), but it's damn near impossible to prove that a hidden volume exists in the same noise. Better yet, if you do anything with the outer volume without explicitly telling truecrypt about the existence of the inner volume, you will likely corrupt the inner volume and render it unusable anyways.
- javajosh 14y agoThe only problem with this is that people are really bad liars.
- epo 14y agoThis article is paranoid ill informed speculation, as are many of the Brit-bashing comments. The police have to show a judge they have good grounds to believe you are concealing evidence from them. Note also that if the powers that be are really determined to stitch you up then they will plant data on you, much simpler.
- Feoj 14y agoHow does/would this affect Freenet users? As far as I know, a Freenet user's 'deniability' claim comes from the idea that the user does not know the key to the encrypted content hosted on their machine.
- jiggy2011 14y agoAssuming this article is true (which I am pretty skeptical of, I live in the UK and never hear about people being jailed for not giving up an encryption key). What would happen if there is encrypted data on your system but you didn't set the key yourself? For example DRM systems usually work by encrypting data and trying their best to make sure you never acquire the key.
- jrabone 14y agohttp://www.theregister.co.uk/2009/11/24/ripa_jfl/ http://www.theregister.co.uk/2009/11/24/ripa_jfl/
- short_circut 14y agoSo does this imply that I could go to prison for having an executable file presuming I can't "decrypt" it back into its original source code?
- deleted 14y ago[deleted]
- zaroth 14y agoCan you say, "Who is John Galt?" Eventually the preposterous laws drive those with mobility to simply leave. Follow that to it's logical conclusion; the UK will make it difficult to impossible to leave with your assets intact. Loss of privacy is a just a precursor to loss of private property altogether.
- chris123 14y agoWelcome to the future (Orwell, Minority Report, Enemy of the State, Matrix, etc.).
- switch007 14y agoIt makes me really angry seeing protests about laws which have already passed! It seems to be lazy journalism - after Liberty et al have done the hard work while the bill passes through parliamentary stages, once it's passed, traditional media and others pick up on it and start complaining. Prevention is better than ranting after it's set in stone.
- prsutherland 14y agoEncryption isn't just about hiding your documents. It is also about securing your assets and providing identification. - The passwords on your bitcoin wallet give you the authority to spend your money. - Your encrypted signature requires your private key so other's know your message came from you. So, this law gives the government the ability to impersonate you and consume/use your assets in an unrecoverable way. While the government might not have the authority to impersonate you or spend your money, they do have the authority to acquire the means to do so. And then all it takes is one dishonest person working for the government to use that information maliciously.
- alan_cx 14y agoPlease forgive my technical ignorance, but can an encrypted cookie be dropped in to my browser cache by a web site? Could an encrypted image with hidden information on a web site end up in my cache? If so, millions of people could have terrorist data in their caches and never know, nor have the key to decrypt it. Also, who has that file Wikileaks published as "insurance". Any one got the key? Any one know whats in it?
- yason 14y agoThe difference with programmers/scientists/hackers and politicians/authorities/lawyers is that the former see instantly where seemingly small changes in laws and policies will ultimately lead whereas the latter will dismiss these potential problems by making remarks such as "It will only be used against bad guys", which translates to "We had a few hairy cases where this sort of law would have really helped, so we wrote one to cover similar circumstances in the future and while we don't really know how to think of what else goes out with the bathwater we will need something at our disposal."
- muyuu 14y agoI live in the UK and this is the first I hear about this. Interesting how seemingly important law passes so silently.
- rashomon 14y agoAnybody know where I can find a thermite-holding 5.25" bay?
- yyyt 14y agoThis makes me wonder why Brits prefer to courageously make jokes at Putin's regime (with which I'm fine, they're deserved), instead of just going to the Big Ben palace and giving a boot to the same kind of governors sitting there.