That’s not right. In most countries, you don’t need to incriminate yourself. Before making wrongheaded decisions, contact a lawyer.
That’s not right. In most countries, you don’t need to incriminate yourself. Before making wrongheaded decisions, contact a lawyer.
Not all authentication methods are equal it appears. Fingerprint, facial recognition, other bio-metrics aren't considered the same as if you need to "speak" your password to someone. In other words, they can make you scan your finger or look into a camera, but they can't force you to tell them your password.
I imagine it gets murky around things like SSH keys, which are technically a kind of password, but too big for a human to remember - and therefore must be "instantiated" in a physical device somewhere.
A likely interpretation might be: an SSH key without a keyphrase is like a physical key, and you must hand it over, while a key with a keyphrase is like a combination lock, where you must hand it over but you are not required to state the keyphrase.
Things that you ARE (such as fingerprints, DNA, hair color, photo, sample) can be compelled by a court order (e.g. a warrant) because they aren't the contents of your mind but physical aspects of your existence.
That's why the use of a strong passphrase that isn't tied to a biometric is important if you're worried about this sort of thing.
They can certainly open the safe. They just can't compel you to TESTIFY to something.
The contents of your mind are sacrosanct. If they can compel you to divulge a combination, then they can also discern that you had access to that safe by virtue of possession of the combination. Not allowed by our laws.
The former can be forced (e.g. I must provide my safe key) and the latter cannot (e.g. I don't have to reveal my password).
The line gets blurry: keyed lock vs combination lock, password vs SSH key.
Surely you don't need to participate in the activity? They are just allowed to take and use it, I assume?
You must unlock your door, and you must unlock your safe, if it is within the scope of the warrant.
https://www.quora.com/Can-a-search-warrant-compel-me-to-unlo...
Also, UK: don't give your password, go to prison. Indefinitely.
Identifinitely? I think even for terrorist charges you can only be held for so long?
He got an additional four months for the failure to disclose the passphrase, on top of five years three months for Terrorism Act offences.
BBC also reported on a teenager getting 16 weeks (http://www.bbc.co.uk/news/uk-england-11479831).
In both cases it seems they were jailed purely for failure to disclose passwords and not in conjunction with any other offence.
I.e. if the defendant can reasonably claim that there are no further encrypted volumes on their device, I don't believe they would be imprisoned under this rule.
The point is that you look exactly the same as an innocent person.
You are taking the only possible pathway to being proved innocent.
It'd be like if I were to say "It doesn't matter what you do. The police are corrupt anyway, and will take you out back and shoot you no matter what. Guilty or innocent, if you get accused of a crime, you are dead."
And if they are going to lock you up no matter what, then you may as well use multiple plausible deniability keys. As you said, it doesn't matter what you do, the outcome stays the same.
Well, prosecution needs to have a legally convincing argument that indicates it is likely you have another encrypted partition you're not giving up keys to.
In fact, the situation is no different from this: say you're a murder suspect and a neighbour saw you carrying several large heavy sacks into your car and you drove away. Say what really happened is that you went and buried some bags of toxic waste in some location, and then went and buried a dead body in another location. When asked by prosecution, you confess to burying toxic waste and tell them where. The rest of the outcome of the trial depends entirely on whether you've successfully convinced them that you just buried the toxic waste.
If you are truly innocent, the prosecution might claim "oh they have extra keys that they haven't given up", and there is nothing you can do to prove them wrong.
Which is it? Does encryption allow you to hide from the law, or can innocent people just be proclaimed that they are hiding something and that they have to give up keys that don't exist?
It is one or the other, because encryption plus multiple keys makes you 'indistinguishable' from an innocent person who truly cannot give you a key that doesn't exist.
The tactic might work, but how well it would work would depend on what other evidence was presented that you do have another encrypted area. For example, if they analyse the partition you gave them the key to and show that it hasn't been booted in 18 months; they cross-reference the cached DHCP leases with the times you were known to have been online using that machine and find discrepancies; they might even have secretly imaged your disk a month earlier and show that a large amount of supposedly free space has changed content in the meantime.
(Maybe they even have you recorded telling someone that you have a second encrypted area on the machine.)
If there's no such evidence, then it ought to be pretty hard to convict you.
First of all, a truly careful criminal can use this method to comply with the law while still hiding what they are really after -- negating the usefulness to some extent.
Secondly, once law enforcement catches on to this, they can then claim that someone that does disclose a password actually gave them a plausible deniability or duress key, and they haven't actually given up the real key, and thus the innocent person could potentially be convicted for not giving up a password that doesn't even exist.
[1] https://en.wikipedia.org/wiki/Key_disclosure_law#United_King...
Not trying to be a hard ass, but I don't think HN benefits from people spreading "legal facts" (c.f. indefinite imprisonment) with an authoritative written tone but without citing legal precedent, or a detailed analysis of the statute in question.
I'm not a lawyer but I imagine if you were taken in front of the same Magistrate's Court or Crown Court, refused to decrypt the _same_ data a second time, were convicted under RIPA, sentenced, you'd have a damn good argument at appeal and it would very likely be quashed. IANAL.
To put more substance behind this opinion, we can look at the Sentencing Council, which when drawing up sentencing guidance, frequently uses the term "fair and proportionate" [1] which is something of a cornerstone remark about how the judiciary should go about dealing with infractions of the law. Reasonable humans would say going to prison twice for the same thing is neither fair, nor proportionate.
[1] https://www.sentencingcouncil.org.uk/news/item/new-sentencin...
Now I checked Wikipedia about those laws, it appears France (my country) has a similar law since 2001. Bummer, I guess.