Suspect jailed indefinitely for refusing to decrypt hard drives
arstechnica.co.uk
arstechnica.co.uk
As a lawyer, my advice is always to stay as far away from police as possible. Do not volunteer anything. Do not participate. Online, always work under the assumption that you are the target of an investigation. Encrypt everything. Use VPNs, preferably overseas VPNs by default and Tor where necessary. If asked, never speak to any investigator without first talking to an attorney. Do no rely on some lay interpretation of a constitution. That document is not the friend people make it out to be.
Edit for the downvote. The video has 6mio views and is considered good advice.
Don't discuss your own votes. Don't even mention them.
Do not interrupt the discussion to meta-discuss the scoring system.
It won't stop them from throwing you in jail, but if your detention is bullshit, and someone on the outside knows it, that is supposed to get you out.
If local judges were more interested in upholding the ideals of justice than in keeping their calendars tidy, ordinary people would be more engaged with the system, and more inclined to trust in the results.
Actually surprised that arstechnica didn't call this out - maybe they knew their audience was sufficiently technical to get the implication.
The real issue here is that the legal system is then treating this guess itself as a sort of actual evidence for jailing the suspect.
Like, the line of questioning could be, did you find any images on the computer, did you find any evidence of techniques used to obscure information on the computer, could the images that so and so observed be stored using those techniques. It isn't confirmation that the images are there, but it is more than guessing out of thin air that there might be images there.
> State: you are under arrest on suspicious of possession of child pornography. You have the right to remain silent, anything you say can and will be used against you in a court of law. Do you understand your rights?
> Defendant: yes
> Witness: I saw what he has it in that computer
> State: now reveal the password
> Defendant: I invoke the right to remain silent. Have charges been pressed or am I free to go?
> State: no charges pressed, you are detained until you reveal the password
Here is how that could play differently in the future:
> State: you are under arrest on suspicious of murder. You have the right to remain silent, anything you say can and will be used against you in a court of law. Do you understand your rights?
> Defendant: yes
> Witness: I saw what he did to the victim
> State: now reveal the whereabouts of the body
> Defendant: I invoke the right to remain silent. Have charges been pressed or am I free to go?
> State: no charges pressed, you are detained until you reveal it
If the All Writs Act allows the government to do the first it also allow the government to do the second.
But the difference here is, can the state prove the drives are encrypted? Probably. I'd assume that's the case (forensic examination could reveal file names, logs, etc that provide evidence of that volume having been decrypted, the vast majority of encryption systems are readily identifiable)
Can the state prove he is capable and unwilling, rather than willing but incapable, of decrypting the drives? I don't think that could ever happen. What if he genuinely forgot the password? What if he never knew it (was storing them for someone else, a common lie/excuse to give to police but something that could be true, any number of other reasons)?
Does every person have to be able to provide access to all encrypted data on their devices if served with a warrant, with the consequences of being unable to do so indefinite imprisonment? Is forgetting or losing a password in unlucky combination with an false accusation of wrongdoing grounds for a life sentence?
When I do this it is more of a flag to remind my self that I have, in fact, finished scrubbing the device.
The first case allows police to make a search they couldn't make before.
The second is... I don't even know what. I would expect if you wanted them to be equivalent, you'd make the second more like: "We know you hid the body in your yard. Unlock your gate so we can enter and find it."
In the case of the hard drives, providing the decryption key establishes only that the drives belong to him or that he at least has access to the information they contain.
In the second case showing the police where a body is located is in itself strong evidence that he was involved in the crime.
The burden of proof is on the accuser. The accused bears no burden of proof. This principle goes back almost 2,000 years, across multiple cultures, includes the Universal Declaration of Human Rights, predates and includes the American culture as well. [1]
> Given a (encrypted) file named "bank_account_password'.txt", can you guess its contents?
Based on the current reasoning, the "expert" would say:
> Yes! It contains the password to a bank account!
The defendant could then "decrypt" the file and show that it was instead a JPEG picture of a bird. Case closed.
I wouldn't have a desire to reveal that either.
The only non-encrypted drive I need are thumbdrives for playing thing on my media player (WD). But I'd love to close that gap should anyone market a reasonable media player that can handle encrypted drives.
The thing to be concerned about here is the ever more complicated legal theories being tested against really old laws.
Procedure and integrity are in play in almost every aspect in life. The problem is that when you give absolute power, the ones who aim to use it the most are the minority who seek to abuse the power.
Just combine them, and simply lie about false evidence instead of correct one. Since it is already obvious that the law is not considered binding if inconvenient, there really is no obstacle to overcome anymore.
But something like this could be created with three seconds in front of a terminal by a single individual. Here there's no evidence to dispute.
What this shows is that encryption does not lock justice out and that it's really no different than papers in a safe in a person's house. If prosecutors have a valid reason to access the information they can go to a judge, get a lawful court order and serve it against the person who owns the safe.
Encryption backdoors aren't about justice. They're about the government's ability to conduct fishing expeditions: to surveil massive numbers of citizens without their knowledge and without their right to a day in court.
This situation has actually come up before and it was ruled that while a person can be compelled to unlock a box with a physical key, a person cannot be compelled to provide the combination to a safe. [0] goes into a lot of depth on this.
[0] http://www.uclalawreview.org/the-fifth-amendment-encryption-...
That's a really bad analogy. Those papers actually exist. Without the key the unencrypted data is just a bunch of random nonsense. It does not exist in any real form.
A better analogy is the case where the papers might exist, but are hidden. Can a court compel someone to help the police look for evidence that can be used to incriminate them?
Um, no, I don't agree with that at all. The point of encryption is that the files are perfectly, 100% recoverable, but only with the key.
Your version is like saying, without the combination of the safe, the papers inside don't exist in any readable form.
By analogy: the government can compel me to open a safe, but it shouldn't be able to compel me to open something that—for all examinable intents and purposes—is a block of concrete with the facade of a safe door attached. I could certainly be held in contempt for refusing to open something that has been proved to be a safe; but holding me in contempt for refusing to open a concrete block, because they believe I have some magic power to turn it into a safe, is Kafkaesque.
That's just restating your analogy again without addressing my contention about random seeming data.
You cannot draw an analogy to any real world item locked up in some way, because in those cases a key could only ever reveal an item that already exists.
Yep. The big difference is in the case of a safe they have other options if you refuse - there's not much point in pissing off the judge only to have them call a locksmith and drill your safe.
Depending on exactly how the drive is encrypted, the state may not have a plan B if he refuses to comply.
In summary, if you are on freenet, you are not only requesting your own files, but files on behalf of others, some of which could potentially be illegal material.
If being on freenet and requesting a key (even for someone else) is enough to get a warrant, all people using freenet from a traceable IP should immediately get off freenet.
I don't know anyone who uses it, I thought tor superseded it, but this sets a very dangerous precedent. The defense should be reaching out to a computer scientist who can explain the fundamentals to the court.
The best argument I can come up with is that digital security simply isn't understood well enough for us to have solid evidence trails.
It's far too simple for an attacker (not necessarily law enforcement, a frustrated savvy neighbour is enough) to target someone and the consequences are so dire.
The War on Drugs criminalized the possession and transfer of physical objects, in the process providing convenient mechanisms by which to persecute undesirable individuals.
Laws against the transfer of information seem to provide the same loophole, but in a digital space. To me, that's far more worrisome.
With drugs, you can at least sometimes get off with proof that you didn't have intent.
Do you have a cite for the law? What you say isn't true for the England; I doubt it's true for the US.
EDIT: Here's the English law.
http://www.legislation.gov.uk/ukpga/2003/42/part/1/crosshead...
http://www.legislation.gov.uk/ukpga/1988/33/part/XI/crosshea...
> Where a person is charged with an offence under subsection (1) above, it shall be a defence for him to prove—
> (a)that he had a legitimate reason for having the photograph [F5or pseudo-photograph] in his possession; or
> (b)that he had not himself seen the photograph [F5or pseudo-photograph] and did not know, nor had any cause to suspect, it to be indecent; or
> (c)that the photograph [F5or pseudo-photograph] was sent to him without any prior request made by him or on his behalf and that he did not keep it for an unreasonable time.
I can't find the citation, but there was a case brought up in my uni it ethics/law module that noted that visiting a website that then downloaded something like that in the background was sufficient to disqualify that condition from applying, as there was a prior request to visit the webpage that delivered the image. even if the website wasn't visited with the intention of the image.
and the person involved was jailed. they may have gotten out on appeal mind, but again, i can't remember more details than that to verify
For child porn, meanwhile, every major "cloud storage" is continuously monitoring your files in a manner similar to YouTubes "content id".
http://documentmedia.com/article-permalink-1966.html says this, and http://www.austintexaslegal.com/Blog/child-pornography-laws-... as well.
But to play devils advocate, I don't think it would destroy the 5th Amendment to treat an encryption key the same as a physical key.
That hair is quite thick enough to be splittable.
In this case he isn't charged with anything, so I'm not sure the fifth applies? I want a lawyer friend lol.
The Electronic Frontier Foundation has weighed in on the suspect's plight, telling the circuit court in a friend-of-the-court brief (PDF) that "compelled decryption is inherently testimonial because it compels a suspect to use the contents of their mind to translate unintelligible evidence into a form that can be used against them. The Fifth Amendment provides an absolute privilege against such self-incriminating compelled decryption."
http://arstechnica.co.uk/wp-content/uploads/2016/04/effamicu...
But all of the above is purely theoretical these days. As you can see, our government can do whatever it wants with little to no consequences. The Constitution isn't worth the paper it was written on and talking about 'justice' in America is like some sort of sick joke (this has always been true in America's history except as it applies to small classes of highly privileged, rich, white people).
However audacious it is to deny (or not admit) ownership of something so obviously in his possession, it is his right.
The point is, the whole "lock" analogy is wrong. Encryption is not an unbreakable lock, nor is it a game-changer. It's been there for hundreds of years at least, as long as there have been cyphers.
Generally speaking, when being held in jail for contempt charges, you can be held indefinitely, so long as you remain in disobedience to a court order. That last part is important, since the idea is you "hold the keys" to your own release.
However, if it's physically impossible for you to comply with said court order, you no longer hold those "keys", and can no longer be held in contempt.
That said... they're not going to believe you just "forgot" your password. The courts don't look favorably at folks who try to game the system like that, and you'd have a hard time proving otherwise.
See Chadwick v. Janecka, where a man was held in contempt for 14 years (!) for refusing to disclose where he allegedly hid funds from an overseas bank account during a divorce proceeding. They eventually let him go after they decided that being held in jail had lost its coercive effect... but again, that took 14 years.
If they can't show that, and the file might not have been accessed since it was created years ago, then I think it's unquestionably wrong to ignore the fallibility of human memory.
Oh! I know. Waterboarding him for, say, one month should be enough to make sure he actually can't remember.
I'm curious how on Earth one arrives at that "guess" for an encrypted drive other than reasoning "why else would he not decrypt them?" In which case his expertise as a forensic examiner is irrelevant.
Edit: I'd love to see the original testimony, but I haven't been able to find it. This article has more information though: https://www.techdirt.com/articles/20160428/07395434297/so-mu...
> The government’s second witness was Detective Christopher Tankelewicz, a forensic examiner with the Delaware County District Attorney’s Office. He testified only that it was his “best guess” child pornography would be found on the hard drives. (Ex. J at 346). According to Tankelewicz’s understanding of the Freenet online network (in which he admits having no training), there were signs on an Apple Mac Pro computer seized with the hard drives of a user accessing or trying to access message boards with names suggestive of child pornography. (Ex. J at 306, 311-312, 339-340). In rather ambiguous testimony, Tankelewicz did not appear to say this meant any image traded over these boards was on the hard drives. (See Ex. J at 303-317, 336-340, 345-350). Instead, he identified a single image he believed there to be a “possibility” was on the drives. (Ex. J at 308-309)
However this appears to be the testimony in which the All Writs order (https://assets.documentcloud.org/documents/2783581/Granting-...) establishes the following:
> Here, the Affidavit of Special Agent David Bottalico, supporting the application for a Search Warrant, establishes that (1) the Government has custody of the electronic devices; (2) prior to the Government's seizure, Mr. Rawls possessed, accessed and owned all the electronic devices; and (3) there are images on the electronic devices that constitute child pornography. (Affidavit iii! 13-31.) Therefore, under the "foregone conclusion" doctrine, requiring Mr. Rawls to assist in the decrypting of those devices does not violate his privilege against selfincrimination.
In other words (in my understanding), under the foregone conclusion doctrine, the government needs to show that they know the document exists and what it contains. In this case I believe that would mean that they have to provide evidence that they know there is child pornography on the devices. And the testimony above seems to be the only thing they are putting forward as evidence to invoke the doctrine.
One of those cases where you kind of want the government to look inside the hard drive in this case (since the accused is only objecting under Fifth Amendment grounds, meaning there probably is legitimate evidence against him on those hard drives), but I can't support it because of the precedent it sets.
I have an encrypted filesystem from years ago that I've forgotten the password to, it has some vacation pictures on it that I'd like to retrieve, and every once in a while I try to guess the passphrase but so far I've been unable to.
Sure, the file might be unfortunately named, but, in this case maybe it was enough evidence to hold him?
There was a case a while back of a guy crossing a border. The LEO who inspected the laptop claims he saw CP, and somehow it was turned off before it could be preserved. In that case, they ruled that it wasn't protected by the 5th because it wasn't a search - they "knew" the evidence was there, they just couldn't access it.
USA v. APPLE MACPRO COMPUTER, et al. (E.D. Pa., case 2:15-mj-00850) http://www.plainsite.org/dockets/2nurkco28/pennsylvania-east...
USA v. APPLE MACPRO COMPUTER, et al. (3d Cir., case 15-3537) ????
I recognize that the contempt is prior to formal charging, and thus "during" evidence gathering. but I feel like this is equivalent to the government saying: "hey, so we have no proof you did anything, but we have these 107374182400 items that might prove something. So, we want you to produce 107374182400 completely different items that might incriminate you because, well.... we cant". seems weird.
this is obviously not the first case that this has happened in[1][2]. each invoking the 5th, but it still seems strange.
[1] http://www.wired.com/images_blogs/threatlevel/2012/01/decryp... [2]https://en.wikipedia.org/wiki/In_re_Boucher
This guy needs to be fired. How in the hell can you tell that it's even images or video let alone children if it's encrypted? I'd love to see a technical explanation of how he came to that conclusion. Can the defendant sue for such a statement given that it's almost entirely fabricated?
However, an expert could hypothetically have all sorts of clue about the contents of an encrypted drive. Keep in mind that encrypted files still probably have a "last modified date" maintained by the OS, and that many viewer/player apps keep a timestamped list of recent files. If they see that realplayer claims to have played "nude_12_year_old.avi" on a "z:\" drive on a certain date, and that an encryption app opened an encrypted file a little while before that.... You can't know, but an expert could, hypothetically, make an educated guess.
Again, not saying that's what the expert did here. Just saying that this sort of conclusion is theoretically possible in some cases.
If the judge cant see what is wrong with this "best guess" evidence, the judiciary has lost its marbles.
If the members of jury don't find it wrong, as society we have probably lost compassion and empathy and sense.
As marijuana legalization is probably foregone conclusion I think government is going to start with "war on sex" that will have same effects on society. New Hampshire recently passed laws that would make sex traffickers out of totally innocent people.
There's nothing bad about it.
Another question is whether the established legal system allowing for such measures is more harmful than beneficial.
So if his protection against self-incrimination is upheld by courts, can he turn around and sue for this blatant violation of his constitutional rights?