5 ms·
It doesn't strike me as a good road to go down to require judges to guess as to whether or not a defendant is being honest about whether or not he or she can re
by biff 13y ago
It doesn't strike me as a good road to go down to require judges to guess as to whether or not a defendant is being honest about whether or not he or she can remember a password on an encrypted volume.
Especially considering that it's possible to be wrong about a volume being encrypted.
- kijin 13y agoI don't think the defendant is claiming to have forgotten the password in this case. Nonetheless, I agree with you that every once in a while, FBI would seize a hard drive that is (a) not encrypted but filled with random-looking bytes, or (b) encrypted but the owner has forgotten the password. When I sell a used hard drive, I usually fill it with random data. Sometimes I do this by creating a TrueCrypt volume that takes up the entire drive. (This destroys all the data on every partition, as well as the MBR, so the drive appears unformatted to the buyer.) But suppose the FBI suspects me of downloading CP and buys my drive as part of a sting operation. They'll think my drive contains CP. After all, it has the typical signature of a TrueCrypt volume! But guess what, I wasn't intending to store anything on that drive, so I threw away the password as soon as I typed it into TrueCrypt. How do you prove that I cannot possibly remember the password? With a physical safe, at least it's possible to prove that I don't have the key in my possession.
- alan_cx 13y ago"With a physical safe, at least it's possible to prove that I don't have the key in my possession." Immediate, on the person, maybe. But you cant prove you cant get hold of it. That's the old proving a negative thing. In fact, even if they search you, all it proves is that they didn't find it, not that you don't have it. When governments start expecting us to prove we didn't do or don't have something, you might as well give up. Its a line no one should be able to cross, not least governments.
- fosap 13y ago>After all, it has the typical signature of a TrueCrypt volume! TC tries to avoid a "typical signature". TC volumes do not have any header. The only signature is high entropy.
- talmand 13y agoNot that I'm very familiar on TC, but wouldn't high entropy without a header be considered a typical signature? It may not be proof but it's at least a good indicator.
- gradys 13y agoIt's identical to the drive being overwritten by actual random bits, which some people do, so I would say that doesn't count as a signature.
- loup-vaillant 13y agoUse Bayes theorem. Out of all the hard drives owned by private citizens, how many are encrypted (E), and how many contain a significant chunk of random bits (R)? Let's say you picked a hard drive at random, and noticed a significant chunk of seemingly random bits. Is it encryption, or not? Well, given what you know, the best you can do is assign E÷(E+R) probability for the drive being encrypted. Now change the problem, where you suspect the owner of the drive may have reasons to encrypt it (suspicion of child porn fits perfectly). Random chunks are now even more suspect. Personally, I suspect that the vast majority of seemingly random chunks of bits are in fact encrypted data (meaning, E÷(E+R) is quite close to 1). So, while it's not proof, while it's not a signature, while for various reasons it's not something we want courts to use as an argument, it's still damn strong evidence that encryption is going on.
- talaketu 13y agoSo, you are evaluating the probability that this drive is encrypted by taking the ratio of E/(E+R), where E and R are frequencies? This is simple probability, and does not involve Bayes Theorem at all. But how do you determine the frequencies E and R (or their ratio)? Perhaps you could sample the population of drives (E+R) and decide which of these are encrypted, and which are just randomized. And how to decide? Oh... you can't.
- 13y ago
- stuckintraffic 13y agoThis is exactly what worries me, especially if the government legislates this and makes the do-you-remember issue an affirmative defense, which shifts the burden of proof onto the defendant. I recently forgot the very complicated passphrase I used on a months-old encrypted USB thumb drive. And I'm a doctor (implying that I should generally be good at remembering stuff). In many criminal cases, months or years pass between evidence seizure and the criminal trial. Seems very easy to forget the decryption key. Or not have access to the 2-factor token anymore. Lot's of edge cases with very serious side effects.
- mhurron 13y agoWouldn't exercising your 5th amendment rights remove the need for you to lie about not remembering?
- maskedinvader 13y agoBut in March 2010, a federal judge in Michigan ruled that Thomas Kirschner, facing charges of receiving child pornography, would not have to give up his password. That's "protecting his invocation of his Fifth Amendment privilege against compelled self-incrimination," the court ruled (PDF). from the article, it looks like a judge in 2010 agrees edit: edited for formatting
- darkarmani 13y agoNot using the arguments of prosecutors. That's the problem.