8 ms·
Man jailed in UK for refusing to give police USB stick password
- deleted 13y ago[deleted]
- ceeK 13y agoCan anyone shed any light if deniable encryption (http://en.wikipedia.org/wiki/Deniable_encryption http://en.wikipedia.org/wiki/Deniable_encryption) would have been useful here?
- Zikes 13y agoFor all we know, it was.
- gejjaxxita 13y agoIt would be a bit crazy to use incriminating information as your innocuous message after going through all the trouble of using plausible deniability though?
- Zikes 13y agoActually that makes perfect sense. You couldn't very easily plausibly deny that you provided the correct decryption key if all they found was photos of kittens, right? Better to let them find something, as opposed to detailed plans about your terrorists plans or confederates.
- TheLoneWolfling 13y agoEh, depends on what you mean by "incriminating information". In this case? Yes. A bit crazy. But in general? If I was using a hidden volume for something "deep" I'd put stuff that was technically borderline illegal (or at least frowned upon / embarrassing) on the "visible" encrypted volume. ISOs of games I own with stripped DRM, (legitimate) ebook copies of adultish graphic novels, chat logs, that sort of thing. It would make it much more deniable that I had a hidden volume. Nothing that could get me sent to jail for too long, and (probably) nothing that would ruin things long-term, but things that would be relatively embarrassing if they got out.
- adrianoconnor 13y agoI doubt there are many UK lawyers specialising in this niche area of law stalking the HN forums right now. But you never know :) I wonder if a big part of the reason for his jailing is that he actually did give them the password in the end - making it less likely that he had forgotten it, and that he was deliberately trying to pervert the course of justice. Of course, it doesn't help that he did seem to have plenty to hide, and he wasn't in a great position anyway.
- vidarh 13y agoIt really annoys me with articles like this when the chronology is unclear. If we was given 4 extra months after he gave them the password, then that's quite different than if he was given 4 extra months before.
- toyg 13y agoThis guy had been arrested as part of internal terrorism investigations, i.e. the stick was handled by GCHQ. I bet that they can spot a TrueCrypt or similar scheme in a heartbeat (if anything because it's been a refrain in most pseudo-security fora ever since this law was passed). So no, I don't think it would have helped. That sort of deniability is only good for lighter situations.
- weavejester 13y agoMost drives encrypted with TrueCrypt don't have a hidden volume, and there's no way of directly determining that a hidden volume exists. If the normal encrypted volume looked particularly empty or unused, and the police knew the suspect used the drive regularly, they might be able to make a good case that a hidden drive must exist. But it's very dependent on the circumstances.
- detritus 13y agoIf he hadn't've already been convicted of being part of a terrorist cell planning on attacking the nation's infrastructure, I might've cared. Given that he doesn't share my ideals, or indeed, much like anything i might be open to considering, he can go fuck himself, if you'll excuse my language.
- hingisundhorsa 13y agoI tried to find where in the article it says anything that might back up "already been convicted of being part of a terrorist cell". The closest I found is where it says: "already in jail for being part of a cell that considered attacking a Territorial Army base in the town.". This sounds a bit like a thought crime to a laymen like me and the verbiage flags my weasel alarm. Also, could you clarify where you're getting the term "nation's infrastructure" because all I saw was: "discussing attacking the town's TA headquarters". If we accuse everyone who's pissed off at the town council / home association and starts talking about blowing them up of terrorism, then we'll need a much bigger prison system.
- Robin_Message 13y agoJust to note, TA is the territorial army, a fully trained reserve branch of the military, so probably reasonable to count as part of the national infrastructure/defence. I do agree that "considering attacking" does sound slightly weasely and like a thought-crime; hopefully they were seriously considering it.
- aqme28 13y agoIs it still terrorism if you attack the military, rather than civilians?
- ht_th 13y agoYes, in most definitions or terrorism, the key part is (trying) to create terror to further your goals. It doesn't really matter whom you'd attack, be they civilians, structures, organisations, armed forces, or whatever. The difference between terrorists and freedom fighters and (national) armies becomes blurred fast, though.
- staticelf 13y agoThis is horrible.
- adrianoconnor 13y agoExcept he eventually gave them the password, which means he didn't just 'innocently' forget his password. However, it looks like he was trying to cover up for fraud rather than terrorism, so maybe he decided that guilty fraudster was better than suspected terrorist.
- Zikes 13y agoIt's not impossible that he truly did forget the password for a period of time, especially at the beginning while he was still under a great deal of stress.
- callesgg 13y agoHe gave them the password after he had been jail 4 mounths for not remembering, if i got the article correct.
- DanielStraight 13y agoYou did not. He was in jail because he admitted to planning a bomb attack. He was not charged for failing to provide the password until he later made it clear that he either lied when he said he forgot or remembered later and failed to comply at the point when he remembered.
- walshemj 13y agoOr the fraud was to provide funds for terrorism as has been the case in a number of UK terrorist trials. Other UK based terrorists (PIRA and the UDA) are known to engage in criminal activities to fund themselves.
- _abcd123 13y agoSo he was already sentenced for plotting an attack to kill innocent people: http://www.bbc.co.uk/news/uk-22200133 http://www.bbc.co.uk/news/uk-22200133 He was responsible for another home made bomb and he is now a convicted thief and fraudster. There was a suspicion another attack is planned, what's horrible about police taking precautions. That's why we have laws - to protect us, and sure in some situations people may be wrongly accused and detained if society's interest is above and suspicion or crime exists but blame criminals who commit the crimes not the law.
- JensRantil 13y agoI wish the article would have stated what encryption he used for his data. Apparently not even GCHQ could crack (or so they say...).
- digitalengineer 13y agoHe chose his passwords well it seemed: $ur4ht4ub4h8 It's not entirely impossible to forget that is it? How are you tp prove you did in fact not forget it?
- girvo 13y agoIn Australia, even if you have forgotten it, they'll just jail you for contempt anyway.
- mortov 13y agoGiven the password is relatively simple - remember this is supposed to be one of the premier encryption cracking organizations in the world, GCHQ, here - I think there is a distinct lack of skill (or absence) by GCHQ. He's perhaps being jailed for showing them up. Alternatively (and more likely I suspect), these is some gamesmanship being played to get shiny new additional super-snooping laws passed because it's needed to cope with all this uncrackable terrorist encryption. See, here's the proof it exists ! [edit: sorry, this did not make it clear I'm suggesting it was cracked but found to be irrelevant to the terrorism case. I've expanded in a reply below.] The UK already has laws making it an offence to have 'have information' 'which may be of use to anyone planning a terrorist offence'. This is so broadly defined that railway enthusiast pictures of trains could fall into it (and have been questioned under it - http://www.telegraph.co.uk/news/uknews/road-and-rail-transport/4123672/Trainspotters-being-stopped-under-anti-terror-powers.html http://www.telegraph.co.uk/news/uknews/road-and-rail-transpo...) The UK's unwritten constitution is not worth the paper it's written on. Unfortunately the US written one seems to be about as useful in protecting peoples rights these days as the UK one. (See previous HN stories of your choice)
- DanBC 13y agoGCHQ giving the password is problematic when the case goes to court. GCHQ have considerable computing power. That probably has weird costings. Thus the cost of 48 hours to run this task is possibly costed at some huge amount that police forces cannot afford unless they know it is a significant target with a spectacular result.
- callesgg 13y agoIn my country(NOT UK) one is considered innocent unless proven guilty.
- aheilbut 13y agoThere is long-established precedent for compelling the provision of testimony and/or physical evidence within our legal system. Do people seriously think that USB sticks have some special privilege?
- toyg 13y agoThe UK legal system can be characteristically illiberal in many ways. This is one of them, yes.
- rayiner 13y agoIn what country can an accused not be compelled to furnish physical evidence?
- toyg 13y agoIn the US you have the right not to answer questions (yes, occasionally you don't, but in most cases you do). The police is free to take possession of everything you have, sure, but you can't be forced to answer questions about it, at least in principle. I believe this applies to other legal systems. No such luck in the UK, and not just about passwords.
- rayiner 13y agoIn the U.S. you can, under the threat of contempt of court, be forced to hand over keys to storage lockers, access to financial accounts, and things of that nature. Passwords are an unsettled issue in the U.S. On one hand, it's like furnishing the keys to a lockbox, which the police can compel you to do. On the other hand, it arguably involves testimonial actions, which the police cannot compel you to do.
- DanBC 13y agoI'd be interested in someone knowledgable writing a comparison of the UK & US systems. For example, do judges need to issue the paper work or can a senior police officer do it?
- toyg 13y agoIt looks like he refused to reveal the password because he knew it would have incriminated him for something unrelated to the original case. Once they got wind of his other activities, he realised the gig was up and disclosed the password. From a legal perspective, this is a troubling side-effect of a poorly-crafted law. His lawyer should have had the power to negotiate immunity from prosecution for unrelated charges that might have spurred from disclosure during the original process.
- avar 13y agoThat's the least troubling side of this law. The most troubling thing is that you can now be thrown in prison on no more evidence than the presence of a blob of random data on your computer that the police can just claim is encrypted data that you're refusing to give up.
- harryh 13y agoHow is that more troubling than: "you can now be thrown in prison on no more evidence than the presence of a few pieces of paper in a filing cabinet that the police can just claim is evidence that you're refusing to give up" ?
- deleted 13y ago[deleted]
- gambiting 13y agoBecause with a pendrive you can't even prove that the paper is there. It could literally be random data, and the police could be insisting that you give them a password. If you did a full wipe of a pendrive with random data,and didn't create a filesystem, you would now have a device that could be used to incriminate you, even thought it really, really isn't encrypted. But you can't prove that. So I guess that if I were to use your analogy, the police would look through your cabinet, find a few pieces of paper,and then demand that you tell them how to read that invisible ink that you used on the paper. What ink? - you might ask. But it's irrelevant, you can still go to jail for not telling, even though there really is no ink.
- nottrobin 13y agoIn America, wouldn't the 5th ammendant protect you in this case?
- warmwaffles 13y agoNot when you are associated with Terrorism. But in a way, yes. As long as you are not associated with terrorism, then you can not be compelled to testify against yourself. I am not a lawyer, but I do remember reading about a case where a judge said the defendant had to give up his password. So in this case, a deniable encryption scheme would probably suffice. Again, not a lawyer.
- hippich 13y agocourt still has right and can force you to reveal password
- dutchbrit 13y agoCan you say unibrow?
- gonvaled 13y agoSo now am I supposed to give my passwords for my encrypted bitcoin wallets, and all my banking access codes? And be happy and relaxed when the police tells me that they will not steal anything?
- toyg 13y agoThey already have access to your banking data, they won't need your codes. They would probably be entitled to asking for your wallet password, yes. Of course they can steal your stuff; it happens with physical evidence (fairly routinely, in many areas - do you really think all that sequestered ganja gets destroyed?), so it can happen with digital stuff too. There are laws and rules about this, but no physical impediment afaik.
- mortyseinfeld 13y agoThey would probably be entitled to asking for your wallet password, yes. No, they shouldn't be entitled.
- hakunamatata 13y agothe dude looks like a terrorist. glad they got the password
- gannimo 13y agohttps://en.wikipedia.org/wiki/Die_Gedanken_sind_frei https://en.wikipedia.org/wiki/Die_Gedanken_sind_frei Unfortunately not.
- toyg 13y agoIn many ways this is actually good news: GCHQ couldn't crack the drive. As Snowden said, cryptography still works: trust the math. As long as you can bear the consequences (i.e. up to 2 years in jail if the Police thinks you're up to no good), you can safely save data that nobody else will ever read.
- Lagged2Death 13y agoHow interesting that they report an irrelevant hyper-detail (the password itself) but not the specifics of what "sophisticated encryption technology" that "GCHQ ... were unable to crack." Also interesting that a password based on word-and-number games, an approach that has been criticized lately as vulnerable to new attacks using common password fragments, seems to have flummoxed the pros in this case anyway. Here's one point that I think should be referenced more prominently, maybe in the headline somehow: Police accessed the memory stick [as part of a counter-terrorism operation] and found it contained ... nothing relating to terrorism or national security. That is: We convicted this guy of a crime for obstructing a terror investigation, even though he wasn't actually doing that. We used our special emergency terrorism powers to push someone around and make demands that were potentially impossible, but it turned out to be just another false alarm. Of course, the guy we pushed around is a certified scumbag and he doesn't look like the sort of white-bread upstanding citizen that most readers of the article imagine themselves to be, so we can count on you to not get too worked up about the whole thing.
- jmackinn 13y agoThis was not a special emergency power, this is simply a case of failing to comply with a court order the same as refusing to comply with a search warrant.
- thirsteh 13y ago> Also interesting that a password based on word-and-number games, an approach that has been criticized lately as vulnerable to new attacks using common password fragments, seems to have flummoxed the pros in this case anyway. If you're talking about the Ars Technica article that showed that crackers are using common passages from books and movies, it's worth nothing that it's not some kind of issue with passphrases, just the construction of them. It is not a bad thing to use a passphrase (the Ars article implied that by saying "your long password isn't safe either," or something to that effect.) It is a bad thing to use a passphrase that is not randomly constructed. It's just the same for passwords, and, indeed, cryptographic keys. It's a numbers game. If it's not random, there's a pattern/bias. If there's a bias, an attacker can exploit that. If there's no bias--i.e. the words of a passphrase were truly randomly selected--then there is no method to crack it more effective than brute force.
- jbb555 13y agoThis seems reasonable to me. It seems like there was a reasonable reason to suspect that the drive might contain actual information that was needed for a serious crime, and a proper procedure was followed to get a court order to get at it. It's like searching your house. The police should not have the ability to simply decide they want to. But if you were already in prison for terrorist related crimes it hardly seems unreasonable to give them the right to do so. This wasn't some random abuse.