European Union dedicated questionnaire on the Encryption of Data
blog.lukaszolejnik.com
blog.lukaszolejnik.com
High Five for the final answer:
> 11. Are there other issues that you would like to raise in relation to encryption and the possible approach to these issues? Please share any relevant national experience or considerations arising from your practice that need to be taken into account.
> Yes. A regulation to prohibit or to weaken encryption for telecommunication and digital services has to be ruled out, in order to protect privacy and business secrets.
Go Germany!
[1] https://www.asktheeu.org/en/request/3347/response/11727/atta...
Recently they created a new institution supposed to help decrypting messages. They never explained what that actually means. (I mean you simply can't decrypt properly designed crypto systems.)
Germany isn't the privacy paradise that some people in the international debates sometimes like to see in it.
The UK has no such safeguard due to governmental structure.
In comparison with pretty much everyone else, it is.
Luckily most deployed crypto isn't properly designed :)
Could you give me more info about it?
BSI? They're not new
BSI's job generally is ensuring IT security, not breaking it.
Even the weirder jobs they're tasked with, such as certifying backdoor software for LEAs, it's not about ensuring its operation as a backdoor, but that it only does the designated job (and in particular doesn't bring additional capabilities that are outside their charter)
> BSI's job generally is ensuring IT security, not breaking it.
Unfortunately that's also not true. The role of the BSI is very mixed and they have a role as both being offensive and defensive. Which is one of the problems. They're not trustworthy.
The BND/BSI split as implemented in Germany is relatively unique precisely to separate offensive and defensive concerns. The biggest issue IMHO is that they both report to the same federal office.
I suspect something similar happened here: BKA and some contractors build the trojan software. BVerfG requires that these tools are limited in their impact, and lawyers would also have a field day in court with any case where the software was used, if it can be shown to create security issues and so the BKA requests a security audit from the BSI (that's part of their charter) and gets it. That might have meant some code (in form of patches) flows back, but given that it's the BSI we're talking about, I doubt it.
Unfortunately the BSI is chartered to do security reviews for federal software, so they can't simply refuse. Meanwhile BSI officials are paranoid because they know (from the SINA/ISP surveillance FUD) what public reception of such a job looks like and tries to do PR management (and fails, which surprises probably no-one).
The full answers are here: https://www.asktheeu.org/en/request/input_provided_by_ms_on_...
I'm encrypting my disk now, but I'll give the password to police if they have a search warrant. I'm encrypting so if somebody steals my computer they won't read my data. I think that almost everybody is like me.
Weakening that encryption doesn't help me and doesn't help investigators. Sure, seeing strong encryption over the wire will ring alarms and identify sender and recipient. That works if they actually decrypt all the data sent over the Internet. The workaround for the tenaciuos criminals will be steganography. Narrower band but good enough in most cases. All that effort and damage to honest citizens for nothing.
That’s not right. In most countries, you don’t need to incriminate yourself. Before making wrongheaded decisions, contact a lawyer.
Not all authentication methods are equal it appears. Fingerprint, facial recognition, other bio-metrics aren't considered the same as if you need to "speak" your password to someone. In other words, they can make you scan your finger or look into a camera, but they can't force you to tell them your password.
The former can be forced (e.g. I must provide my safe key) and the latter cannot (e.g. I don't have to reveal my password).
The line gets blurry: keyed lock vs combination lock, password vs SSH key.
Surely you don't need to participate in the activity? They are just allowed to take and use it, I assume?
You must unlock your door, and you must unlock your safe, if it is within the scope of the warrant.
https://www.quora.com/Can-a-search-warrant-compel-me-to-unlo...
Things that you ARE (such as fingerprints, DNA, hair color, photo, sample) can be compelled by a court order (e.g. a warrant) because they aren't the contents of your mind but physical aspects of your existence.
That's why the use of a strong passphrase that isn't tied to a biometric is important if you're worried about this sort of thing.
They can certainly open the safe. They just can't compel you to TESTIFY to something.
The contents of your mind are sacrosanct. If they can compel you to divulge a combination, then they can also discern that you had access to that safe by virtue of possession of the combination. Not allowed by our laws.
I imagine it gets murky around things like SSH keys, which are technically a kind of password, but too big for a human to remember - and therefore must be "instantiated" in a physical device somewhere.
A likely interpretation might be: an SSH key without a keyphrase is like a physical key, and you must hand it over, while a key with a keyphrase is like a combination lock, where you must hand it over but you are not required to state the keyphrase.
Also, UK: don't give your password, go to prison. Indefinitely.
The point is that you look exactly the same as an innocent person.
You are taking the only possible pathway to being proved innocent.
It'd be like if I were to say "It doesn't matter what you do. The police are corrupt anyway, and will take you out back and shoot you no matter what. Guilty or innocent, if you get accused of a crime, you are dead."
And if they are going to lock you up no matter what, then you may as well use multiple plausible deniability keys. As you said, it doesn't matter what you do, the outcome stays the same.
Well, prosecution needs to have a legally convincing argument that indicates it is likely you have another encrypted partition you're not giving up keys to.
In fact, the situation is no different from this: say you're a murder suspect and a neighbour saw you carrying several large heavy sacks into your car and you drove away. Say what really happened is that you went and buried some bags of toxic waste in some location, and then went and buried a dead body in another location. When asked by prosecution, you confess to burying toxic waste and tell them where. The rest of the outcome of the trial depends entirely on whether you've successfully convinced them that you just buried the toxic waste.
If you are truly innocent, the prosecution might claim "oh they have extra keys that they haven't given up", and there is nothing you can do to prove them wrong.
Which is it? Does encryption allow you to hide from the law, or can innocent people just be proclaimed that they are hiding something and that they have to give up keys that don't exist?
It is one or the other, because encryption plus multiple keys makes you 'indistinguishable' from an innocent person who truly cannot give you a key that doesn't exist.
The tactic might work, but how well it would work would depend on what other evidence was presented that you do have another encrypted area. For example, if they analyse the partition you gave them the key to and show that it hasn't been booted in 18 months; they cross-reference the cached DHCP leases with the times you were known to have been online using that machine and find discrepancies; they might even have secretly imaged your disk a month earlier and show that a large amount of supposedly free space has changed content in the meantime.
(Maybe they even have you recorded telling someone that you have a second encrypted area on the machine.)
If there's no such evidence, then it ought to be pretty hard to convict you.
I.e. if the defendant can reasonably claim that there are no further encrypted volumes on their device, I don't believe they would be imprisoned under this rule.
First of all, a truly careful criminal can use this method to comply with the law while still hiding what they are really after -- negating the usefulness to some extent.
Secondly, once law enforcement catches on to this, they can then claim that someone that does disclose a password actually gave them a plausible deniability or duress key, and they haven't actually given up the real key, and thus the innocent person could potentially be convicted for not giving up a password that doesn't even exist.
He got an additional four months for the failure to disclose the passphrase, on top of five years three months for Terrorism Act offences.
BBC also reported on a teenager getting 16 weeks (http://www.bbc.co.uk/news/uk-england-11479831).
In both cases it seems they were jailed purely for failure to disclose passwords and not in conjunction with any other offence.
[1] https://en.wikipedia.org/wiki/Key_disclosure_law#United_King...
Not trying to be a hard ass, but I don't think HN benefits from people spreading "legal facts" (c.f. indefinite imprisonment) with an authoritative written tone but without citing legal precedent, or a detailed analysis of the statute in question.
I'm not a lawyer but I imagine if you were taken in front of the same Magistrate's Court or Crown Court, refused to decrypt the _same_ data a second time, were convicted under RIPA, sentenced, you'd have a damn good argument at appeal and it would very likely be quashed. IANAL.
To put more substance behind this opinion, we can look at the Sentencing Council, which when drawing up sentencing guidance, frequently uses the term "fair and proportionate" [1] which is something of a cornerstone remark about how the judiciary should go about dealing with infractions of the law. Reasonable humans would say going to prison twice for the same thing is neither fair, nor proportionate.
[1] https://www.sentencingcouncil.org.uk/news/item/new-sentencin...
Now I checked Wikipedia about those laws, it appears France (my country) has a similar law since 2001. Bummer, I guess.
Identifinitely? I think even for terrorist charges you can only be held for so long?
You have 1 partition/password with the stuff you actually want to hide, and you have a second password/partition that just contains your porn collection.
"Yes officer, I just use encryption to hide this stuff. Nothing illegal here. It is just embarrassing. Thats why I hide it."
Thats really good plausible deniability.
In any reasonable legislation there shouldn't be a difference between not providing a password and not admitting you have anything encrypted at all (because no one can prove the difference anyway).
An important thing that is often forgotten is that most many aren't challenged for encrypted contents in criminal cases but civil lawsuits where the burden of proof is (also) on the defendant because there is no "beyond reasonable doubt" . In that situation, the mere existence of e.g. a file transfer log with the movie file name + an encrypted disk is enough to end up with massive damages. In that situation you would be very interested to show your unencrypted data if you don't have the file in question.
What if the police are wrong? Or like in Canada the police were trying to find the sources of journalists who wrote about corrupt police. And maybe in the US Trump's hate of journalists could mean something similar.
My desire for personal privacy doesn't mean I am hiding anything. Maybe I don't want anyone to read my poetry or see family pictures nothing illegal but certainly private.
"Give me six terabytes of data from the most honest of men and I will find something in them which will hang him. Probably before I make it past the boot sector." - Cardinal Richelieu
I may be taking the word "everyone" too literally, but I think that part of the problem is that most people don't think like you and don't really understand the benefits of encryption and why it's a practical tool for absolutely everyone, not just terrorists, pedophiles, and drug dealers. There's a very big educational gap when it comes to encryption, and I don't think that most people can even cover the basics of it very well, which makes it extremely difficult at times to tell if law enforcement and politicians even understand the implications of what they propose beyond the immediate benefit to their operations.
However, I do think that your position is probably the best that can help people to begin to understand why encryption is important; there still is a disconnect where most people don't understand that encryption is an all or nothing ordeal, or if they do, they accept the rationalization that the weakening of encryption is important for the security of the nation, whichever nation that may be.
But in general, encryption is a problem because it operates in a blackbox for the majority of people, and it's incredibly easy for talking heads to say just about whatever they want on it without being challenged. It feels to me like strong encryption is one of those lessons that people are going to have to learn the hard way, much like how a lot of people learn about backing up data only after having a hard-drive go with important data on it. Though it would likely be difficult to prove, I think it's going to require that a government exploit or something intentionally weakened by a governmental actor be utilized by criminals to harm the public at large before people really get the idea on what government-approved encryption really means.
How do you handle cases where data appears to be encrypted but it isn't?
Or, the data is encrypted but the suspect has forgotten the password?
Solving offenses without 100% certain evidence is by no means a new problem.
Nonetheless, given your context of "there is no encryption going on at all" I argue does not necessarily hold for a backdoor - or at least not at the outset and if done properly. If the govt backdoor is a key for which huge amount of care is taken to protect and take the extreme example of the govt encrypting the only copy of the key and firing it off in one direction into space - there is a backdoor but this is not necessarily equivalent to "no encryption at all".
In what way, exactly? Europe is farther down this path than the US is currently.
They're as meaningless as the American versions, only randomly ensnaring companies that sell to a doubleplus ungood entity. They don't do anything to stem the flow of crypto information or open source software to all parts of the globe.
And that NIST thing happened possibly once. It's not a common ongoing occurrence.
(So yes, to the broader point that all the Wassenaar countries implement very similar restrictions).
And, of course, the US's treatment of cryptography as munitions predates Wassenaar (the PGP case was previous to it, for instance), not sure about how everyone in Europe handled it prior to the agreement.
http://www.theverge.com/2016/11/23/13718768/uk-surveillance-...
They've actually had a law requiring you to decrypt on demand since 2007:
http://arstechnica.com/tech-policy/2007/10/uk-can-now-demand...
Nothing like that in the US at all. So, further down the path. France and Germany want similar laws.
http://www.reuters.com/article/europe-attacks-france-germany...
And other countries are joining in the call:
https://www.geektime.com/2016/11/26/5-eu-states-demand-bette...
DES was weakened in a much more prosaic manner: the effective key size was reduced to 56 bits.
The man is a living legend.
Edit: 12 million views on the abstract topic of Net Neutrality.
That's what I would call a feat indeed:
Almost comical how easily and predictably we stay on track in terms of bread and circuses politics/media - almost comical - if it weren't all real and there wouldn't be far reaching and dire consequences.
Let's not get played but stick together FFS.
Fighting cybercrime has different obstacles: it's usually cross-border, and its victims are usually common people. Nobody cares terribly much when a commoner loses $100. Even when there's a thousand of them.
What you need to take on cryptography, is "to snoop". Why would you need that, huh?
This is precisely why law enforcement doesn't need to weaken encryption nor weaken the rights of suspects and defendants. If there is a material crime, that crime has left a trail of evidence in the real world, especially a money trail.
And if you think Leviathan needs unbounded powers or you'll be left as a tasty morsel in the state of nature, physics has always bounded state power, and injustices happen when state power is pushed beyond natural bounds.
> Thanks to Bits of Freedom, those answers are now public. That's called transparency.
Another Dutch one I know is Privacy First. When elections come up we always have a vote advice website which is quite popular. You enter your opinion on some current topics (old example: joint strike fighter funding: continue or not?) and it computes which party's goals align the most. Privacy First had an interesting take on this: they looked at what parties pushed for in the past and matched that with what you would have wanted (focusing on privacy-related topics of course). Not looking at promises but at track record. Privacy First probably does other stuff as well, just like BoF, but I don't keep up.
I don't know about other countries unfortunately.
* How often do you encounter encryption? The most common answer is 'often'. Germany does not collect this statistic. Czech Republic and Hungary: 'rarely', Latvia has both 'often' and 'almost always' in bold, UK 'almost always'.
* Online encryption: most common one is e-comms (everywhere but Italy), followed by TOR (everywhere but Hungary and Poland). Denmark, Finland, Germany and the UK reported encountering all types of encryption on the form.
* Offline encryption: it's not very clear what is an encrypted device (it includes computers) and what is an encrypting application (they give disk encryption tools as examples), but all countries except Poland selected devices and all countries except Italy selected applications
* It sounds like the accused can only be compelled to disclose passwords or keys in the UK, but Italian LE would also like that very much, despite having reported that 'the current national law allows sufficiently effective securing of e-evidence when encrypted'.
* In Croatia, Latvia and Poland they consider that the current national laws don't allow effective securing of encrypted evidence. The answer to this question is not available for Czech Republic and the UK.
A few other interesting things I've noticed:
Croatia: 'There is no practical experience' regarding 'intercepting/monitoring encrypted data flow'; 'Tools for decryption are used in less complex case [...]. Foreign companies’ services were not used so far.'
Czech Republic: 'Additional intentional encryption is quite rare in most cases although encrypted mobile phones are more and more popular among members of certain organized crime groups.'
Denmark: 'The main issue with trying to decrypt encrypted data is of a technical nature. Furthermore the equipment needed to break encryption is costly and the process itself takes a lot of time.'; 'In general terms, we can inform you that commercial software is among the tools used to decrypt data'; 'Decryption typically requires large hardware resources (processing power) as the encryption offered by service providers is very strong.'
Estonia: 'The main problem is that communication or data are encrypted and if key is not available, it is not possible to decrypt them.'
Finland: 'In case of full-disk encryption, which is rare, we have to either use brute force attacks, or try to obtain the credentials some other way'; 'We do not usually use private sector companies for decryption purposes, but of course a large part of the software/hardware used are commercial products'; 'Wireless criminal intelligence gathering can be challenging, because the LE sector has limited legal rights to gather for example WIFI data'; 'Sometimes insufficient computational capacity of our password-breaking platforms make the decrypting process too lengthy'; In general they talk about C&C servers for botnets quite a lot.
Germany: Regarding intercepted encrypted comms: 'In many cases, analysis of actual communication content is not feasible.', 'A regulation to prohibit or to weaken encryption for telecommunication and digital services has to be ruled out, in order to protect privacy and business secrets.'
Hungary: it sounds like they gave the form to the wrong dept? 'Our unit is not dealing with decryption, therefore we do not have any practical experience in this field.', 'Our unit is not dealing with such techniques.'
Italy: covered in the OP
Latvia: 'LV sees as clear added value of EC3’s encryption/decryption platform; LV also highly values the availability of the Europol Platform for Experts.';
Poland: mostly covered in the OP, I'll add 'The specialised computers (GPU clasters[sic]) which can decrypt encrypted e-evidences are very expensive.'
UK: It reads like a polished PR piece, at least relative to the others. Provides non-answers. It's probably worth taking a closer look. For example to 'Under your national law, is it possible to intercept/monitor encrypted data flow to obtain decrypted data for the purposes of criminal proceeding?' they responded with 'Section 17 of the Regulation of Investigatory Powers Act 2000 prevents intercepted material from being used as evidence in legal proceedings.', which doesn't actually answer the question.