Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years
bleepingcomputer.com
bleepingcomputer.com
The only problem I have with this argument is that if it is such compelling evidence why not send the case to trial and let a jury decide?
See https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...
Source: https://arstechnica.com/tech-policy/2017/03/man-jailed-indef...
A relavent paragraph:
In Fisher, however, the Court also articulated the “foregone conclusion” rule, which acts as an exception to the otherwise applicable act-of-production doctrine. Fisher, 425 U.S. at 411. Under this rule, the Fifth Amendment does not protect an act of production when any potentially testimonial component of the act of production—such as the existence, custody, and authenticity of evidence—is a “foregone conclusion” that “adds little or nothing to the sum total of the Government’s information.” Id. For the rule to apply, the Government must be able to “describe with reasonable particularity” the documents or evidence it seeks to compel. Hubbell, 530 U.S. at 30.
Note that the issue with this question is the "existence, custody, and authenticity" of the evidence not its actual contents.
1. https://arstechnica.com/wp-content/uploads/2017/03/rawlsopin...
(Of course if he was lying about the failure of his memory, that assertion might have gotten him into more hot water -- it would potentially be a perjury charge. But we should not say definitely "he was lying when he said that to police" but just "he didn't make that case for himself at court," if I'm reading these court documents right.)
Just to give the relevant excerpts, the supplemental order that the judge issued to explain his reason for the contempt order states that he's using a well-established legal framework for figuring out memory-failure type contempt cases, quoting one of those cases directly as:
> A civil contempt proceeding on a witness' asserted memory loss requires a three-step analysis that shifts the burden of production to the witness, but always leaves the burden of proof with the government. First, the government must make a prima facie[1] showing of contempt; i.e., that it made an authorized request for information, that the information was relevant to the proceedings, that the information was not already in the possession of the government, and that the witness did not comply. Second, once the government has presented its prima facie case, the witness must provide some explanation on the record for his failure to comply. If the witness fails to meet this "burden of producing evidence," the government's prima facie case is sufficient to meet its burden of proof for a finding of contempt. The witness may meet his burden, however, where, as here, he testifies that he does not remember the events in question. Finally, if the witness meets his burden of production by claiming a loss of memory, the government must carry its burden of proof for a finding of contempt by demonstrating that the witness in fact did remember the events in question, thereby establishing a willful failure to comply.
Note that testifying "I don't remember the password" is enough to activate part two. The supplemental order then goes on to apply this in the only obvious way,
> [first, ] the Government's prima facie case of contempt was largely, if not entirely, uncontested ... [second, ] at the September 30th Contempt Hearing, Mr. Rawls did not testify or call any witnesses, he did not offer any documentary or physical evidence into the record, and the only evidence he elicited was in the form of cross-examination of the Government's witnesses. Crucially, Mr. Rawls offered no on-the-record explanation for his present failure to comply with the August 27th Order... [therefore, ] in light of the Government satisfying its burden of proof, the Court adjudged Mr. Rawls to be in civil contempt of court.
[1] prima facie is a phrase which one might not be familiar with unless one has a philosophy or legal background; it means "at first glance" -- i.e. the government's showing might at a deeper stage be questioned but it has to "look like" contempt in order to start the process.
> Note that testifying "I don't remember the password" is enough to activate part two.
"Bleeping Computer users have pointed out that you cannot match file hashes to encrypted content. The article was updated with a link to court documents from where the prosecution's statement was cited."
And what if you genuinely forget the password to one of your encrypted drive. Couldn't it be used to incriminate you on whatever charge?
https://arstechnica.com/tech-policy/2017/03/man-jailed-indef...
From that article:
> The court also noted that the authorities "found [on the Mac Book Pro] one image depicting a pubescent girl in a sexually suggestive position and logs that suggested the user had visited groups with titles common in child exploitation." They also said the man's sister had "reported" that her brother showed her hundreds of pictures and videos of child pornography. All of this, according to the appeals court, meant that the lower court lawfully ordered Rawls to unlock the drives.
And then this from Rawls' public defender:
> "The fact remains that the government has not brought charges," Donoghue said in a telephone interview. "Our client has now been in custody for almost 18 months based on his assertion of his Fifth Amendment right against compelled self-incrimination."
There are numerous quotes from Comey and many others in the FBI and DOJ who have argued that forced decryption is necessary to catch the bad guys. But here the argument is the exact opposite: the evidence they have is so overwhelming that it is a "foregone conclusion" that more of the same incriminating evidence is on the encrypted drive.
The fact that hey have so much evidence and yet they still prefer to lock him up in jail until he decrypts the drive rather than convict him makes me believe this case is intended to provide jurisprudence in order to force other people to unlock encrypted devices in much more dubious cases.
Not unlike the "locked iPhone" case where terrorists had destroyed all the devices that could be of interest and yet the FBI went against Apple because the case appeared very good to get support in the public eye (it's to catch terrorists!).
Or, they prefer to have actual images to use against him in the child porn case they intend to bring, rather than being forced to explain cryptographic hash functions to a jury.
Honest question: It's hard to do risk assessment at my level of ignorance so where can I find major cases where common people have been screwed by the overarching tentacles of govt surveillance in the developed world? Any noteworthy cases I should read about to raise my level of alertness?
Your question is loaded though, because of course the common person will follow the law & avoid going on the internet.
I'm looking for documented cases where common people have been harmed so I can feel more impacted by it (and I have better examples when talking about these subjects with friends and family).
It's not fair to unload these research needs on HN so I'll do more googling to find a catalogue of cases I can refer to.
Again, I'm not dismissing any issues. I'm 100% acknowledging them and hoping to increase my own level of alertness based on concrete facts that I can relate to (or are closer to my reality vs. basing my rights on the rights of pedophiles and terrorists being impacted). I hope that clarifies my perspective.
https://www.thenation.com/article/how-clerical-error-barred-...
https://www.propublica.org/article/fbi-checked-wrong-box-rah...
Some highlights:
* it was revealed in the lawsuit that she was put on the no-fly list due to a clerical error
* the government used nearly every tactic available to keep the details of her lawsuit secret in the name of national security, meaning a) they were actively trying to cover up embarrassment of the clerical error, b) the DOJ actually don't have an easy way to know why someone is on the no-fly list, or c) they have a way but have little to no interest in finding out. None of those are good options for a democratic developed country.
* this interrupted her Ph.D. studies at Stanford.
* this interrupted her ability to appear in court for her own lawsuit (because her name remaining on the no-fly list prevented her from travelling back to the U.S.)
* this cost millions of dollars in attorneys fees and what looks like years of time for her
* there is no evidence that the administration of the no-fly list has improved since then, and indeed has only grown (almost certainly a link from the Intercept that backs this up, but you're not paying me to research this and I am now bored and hungry)
Edit: just so it's clear-- the reason she kept reappearing in the list is because the nature of wide-net surveillance databases is that they sprawl across multiple agencies that often don't have the ability to communicate well with one another. Further, no congressperson in their right mind is going to publicly take up the cause of "cleaning up the no-fly list" because the moment there is anything resembling a terrorist attack an opponent will beat them by calling them "soft on terrorism."
One final edit: Question: be honest, if she had lost this lawsuit and I had included her story as an example of common people being impacted by wide-net surveillance, would you have found it convincing?
I think a good argument against all of this massive surveillance for common people is that governments are usually pretty incompetent and a bureaucratic mess... it's a very asymmetric battle with massive blob holding a lot of information about you vs. you without few resources and picking up clues here and there about what might or might not help you in a lawsuit.
Thanks again, much appreciated.
Similarly, the cases where wide-net surveillance has had a detrimental effect on people-- the case of the Stanford student who accidentally got added to the U.S.'s no-fly list comes to mind-- there was probably nothing at all the person could have done to prevent getting screwed.
Waiting for a case to make its way to court would take far too long. Police will search through seized evidence and immediately start trying to identify the children in the images; working out if the images are new; and working out where the images were created.
They'd also want to see if there are any images of abusers in there too, and if those abusers are already known to police, and if those abusers are the same person as the alleged possessor of images of child sexual abuse currently being detained by police.
To be clear (and I am pretty sure the public defender knows this, but is just phrasing it like this for public perception), the prosecution's position is that the Fifth Amendment is irrelevant because they're compelling him to do an act under the All Writs Act and not to testify about anything (produce a password, produce files, etc.). The approach they're taking is that he's a person in a position to do something to let the government access evidence, and it doesn't matter that he's the person they want evidence against, instead of a third party (as with New York Telephone Co., or more recently Apple), and he's in prison for refusing compliance with the writ.
It's totally unclear that this legal strategy should work in a just/ideal society, but, at least for now, the courts are allowing it.
1. There is an unbreakable safe
2. The judge believes he has the key to the unbreakable safe
3. They know there is evidence inside the safe
4. They ask him to unlock the safe
5. He refuses to do so, so they try to force him by jailing him
They do not ask him to testify about the safes contents or even to hand over the key, just to "insert and turn the key". And their argument is that he can not refuse that by pleading the fifth. In a physical world they would be able to seize the key from him by force even if he gets hurt in the process (within some limits).In the end he will probably be able to argue that he does no longer have the key, and they will not be able to proof he still has. But _at the moment_ this is not whats being argued about.
(Not saying I find anything about that right or just or moral, but I do not find it completely without reason)
Deciphering the letter would mean he writes down the cleartext version, or reads it out aloud or something like that, which could much more obviously be argued as "being witness against himself". Their position is that this is exactly NOT what they are trying to force him to do, so the fifth does not apply.
When we use the safe analogy, well safes are easy to open, no big deal. The government opens them all the time. Why is that such a huge leap? Using the incorrect analogy muddies the real issue here IMO.
1) Giving up the decryption key is clearly not analogous to deciphering the letter. When you decrypt a drive, it’s the computer does the actual deciphering operation.
2) Focusing on how easy the safe is to break without the key cuts against your position. We can jail people for not providing the key to a regular safe, even though the cops could break into it. But we can’t jail people for not providing the key to an encrypted drive, even though the cops likely have no other way to get the evidence they know is in there. Isn’t that precisely backward? Shouldn’t the cops have more power in the situation where they have no alternatives?
The computer cannot decipher the drive without the decryption key. The computer doing it is just automation. Using that logic killing someone with a car isn't the person's fault since the car did the actual killing. It's about who is controlling the thing, not the actual thing itself.
>We can jail people for not providing the key to a regular safe, even though the cops could break into it.
That is true with physical keys, but not combinations. It doesn't matter to police whether a suspect provides a key or not because the cops can work around that. In the case of encryption, they cannot. A cypher is a combination more so than a key.
Here is an article on revealing a combination of a safe vs. a key. In it, judges agree that revealing a combination delves into the mind while a physical key does not. A distinct difference when dealing with self incrimination. Collecting evidence from the mind (a combination) is self incrimination.
http://blogs.denverpost.com/crime/2012/01/05/why-criminals-s...
>Shouldn’t the cops have more power in the situation where they have no alternatives?
Perhaps in a dictatorship.
We do not disagree with the dissent that “[t]he expression of the contents of an individual’s mind” is testimonial communication for purposes of the Fifth Amendment. … We simply disagree with the dissent’s conclusion that the execution of the consent directive at issue here forced petitioner to express the contents of his mind. In our view, such compulsion is more like “be[ing] forced to surrender a key to a strongbox containing incriminating documents” than it is like “be[ing] compelled to reveal the combination to [petitioner’s] wall safe.”
Being compelled to reveal the combination to a wall safe they consider a violation of the 5th amendment. Revealing the combination to a wall safe is much more like revealing a password than surrendering a key.
As you suggested, compulsory key disclosure can be a violation of the Fifth Amendment, and here the court referred to an example of that in In re Grand Jury Subpoena Duces Tecum Dated Mar. 25, 2011, 670 F.3d 1335 (2012)[2]. The difference was that in In re Grand Jury Subpoena, there was no evidence that the TrueCrypt volumes contained any data, and no evidence that the suspect could actually decrypt them.
[1]: https://supreme.justia.com/cases/federal/us/425/391/case.htm...
[2]: https://scholar.google.com.au/scholar_case?case=201586737907...
What makes these things similar to an encryption key and different from other types of testimony is that they only unlock information that already exists outside of the witnesses's head so they aren't subject to the same prohibitions under the 5th amendment.
We do not disagree with the dissent that “[t]he expression of the contents of an individual’s mind” is testimonial communication for purposes of the Fifth Amendment. … We simply disagree with the dissent’s conclusion that the execution of the consent directive at issue here forced petitioner to express the contents of his mind. In our view, such compulsion is more like “be[ing] forced to surrender a key to a strongbox containing incriminating documents” than it is like “be[ing] compelled to reveal the combination to [petitioner’s] wall safe.”
Of course, the Supreme Court hasn't ruled on it as far as I know, but it's an interesting case. I'd like the SCOTUS to rule on it.
"know" implies a fact. The determination of fact is up to the jury.
And again the current argument is not about whether he knows the pin or not, just whether he can refuse to enter it by arguing that this would be "being witness against himself", i.e. protected by the fifth.
It might exploit a loophole, though (and I also think there's a lot of room to argue over whether that analogy is actually the right one).
The one thing that's different with computers is that usually the police can just break into your house (or a safe, or something like that) if you refuse to give them the key, and encrypted drives have no other alternate route in. So you wouldn't be kept in prison indefinitely for refusing to comply with a warrant; you'd just get your door knocked down.
Can you be compelled to labor to help the prosecution?
What if I had a huge stone vault. To get to the inside of it would take the fed 7 years of digging. The crime they have a warrant for has a statute of limitations of 5 years. If I help them dig, they can get there in 4 years. Can they force me to dig with them?
Now, in response to the use of the All Writs Act about iPhone decryption, a couple of people raised the argument that the 13th Amendment, which prohibits "involuntary servitude," might prevent the government from just telling you what your job is (even if you're paid for it). I don't know that any court has had an opinion on the validity of this argument.
Also, I think the All Writs Act only applies to things that the Western legal system considers "writs," which is not clearly defined in statute anywhere. So you'd have to ask an actual lawyer who understands Western caselaw about whether "decrypt your hard drive," "write and sign firmware for an iPhone that doesn't lock you out on incorrect passcode attempts," and "dig stone for four years" count as writs. I have no idea.
Out of curiosity, is there any case law establishing this (i.e. a document written in code)? With a document in gibberish, I can't see any reasonable reason to believe that it means something (unless, say, the defendant was suspected for espionage). In this case, however, there is other compelling evidence to believe this drive is encrypted and has data on it. It would be curious to see if something like this has been prosecuted before.
This isn't really new with computers. People have been writing in code since time immemorial. What would have happened two hundred years ago if some defendant had been using a book cipher and the police don't know which page of which book is the key?
I'm guessing that they would have brute-forced it. The complexity is much lower than the modern case as is the number of potential keys. I can imagine someone spending a fair bit of time in jail for contempt during this procedure, but it would not be indefinite. I can also just see the police calling in a code breaker and not bothering with the court order to tell them the key.
In an era before digital computers?
That still isn't any different. Nothing stops the police from hiring someone to break the encryption. They may not be able to do it but that is no different than before. Many ciphers that are broken today were not broken decades or centuries ago -- good luck brute forcing even 56-bit DES in 1975. It's completely plausible that AES will be considered insecure some years in the future even if nobody can break it today.
Code breaking predates computers by millennia.
EDIT: To be clear, it's not that I feel he should necessarily be compelled, but rather that a fifth amendment defense is weak in this case, since it's not a testimony at all, but rather revealing already existing material (as opposed to compelling the defendant to write a confession).
How are you distinguishing one from the other? What makes compelling someone to speak the password aloud different from compelling them to type it with a keyboard?
[1]: https://arstechnica.com/tech-policy/2017/01/court-rules-agai...
EDIT: Worth pointing out that line in that case is really "physical evidence" vs. "knowledge". The court argues that the fingerprint unlocking the smartphone is closer to a blood sample than a testimony. However, I could definitely see a court seeing this as "it's ok to make someone unlock" because they didn't just collect the physical evidence, but made him take the action of unlocking the phone.
EDIT: Scratch that, you can hold someone in jail as long as they are in contempt of court, apparently.
Note the "nor shall be compelled in any criminal case to be a witness against himself" telling him to decrypt that hard drive is still in effect forcing him to be a witness against himself.
These judges saying the fifth amendment doesn't apply should be sued for constitutional violations.
Yes, because of the first two words of the entire amendment - "No person" that 100% excludes any qualifying status and grants everyone immunity from testifying in any effect against themselves.
The Third Circuit punted in the legal question, stating that even if the 5th Amendment applied to being forced to hand over a decryption key, the guy couldn’t invoke his Fifth Amendment right here because of legal technicalities (see Kerr’s analysis in the link above).
If I've forgotten the password, wouldn't I no longer be in a position to aid in obtaining the evidence?
Would the burden of proof be on the fed to prove that I have not forgotten the password?
If I lost the physical keys to a vault, could in be held for not being able to open it?
I think Child pornography / abuse is one of the worst offenses possible, but in this case, they need to find another way to convict him if he is guilty.
It appears the disk wasn't fully encrypted (since they found hashes of individual files), so they likely know when the computer was last used and possibly when the data in question was last decrypted. I don't think the former being very recent should be enough to establish that he hasn't forgotten the password, but the latter sure seems like a good standard.
There is simply no way to prove he is knowingly withholding a password vs simply forgetting it.
My dislike for police is eclipsed by my dislike for pedophiles. So I'm biased here.
It isn't about childporn, or whatever this guy is accused of doing. This is about "you are not doing as you are told, citizen, and we will fuck you up for that".
It is about control, in the same way that security theater at airports isn't about security.
So if "foregone conclusion" is the criteria that must be met, I have to ask how the contents of this man's external hard drive could be conclusively a foregone conclusion. Maybe he did download thousands of images. What if he no longer possess them? He could have deleted them. The police have been known to make mistakes and have made high profile mistakes' i.e., the Atlanta Olympics bombing when they all but destroyed Richard Jewell.
What if he decrypted it and there was no child porn but there were records of say a store selling drugs etc on the dark net? Then he would have incriminated himself for something they had zero knowledge about because the court issued this writ.
The government states that his sister acknowledges him showing her many explicit photos. Did she turn in her brother? Why would a man show his sister pornographic images? Did she tell anyone around the time this happened that this occurred? Seems to me to be unusual at the least for the government to hang their hat on something uncorroberated. If the sister had access to the computer' who is to say that she did not download the images. He could have seen them and deleted them. Seems that a mere he said -she said is enough to have the government invade your privacy and demand you willingly set aside your consistutional protections or risk going to jail when you have not been charged with, let alone convicted of, a crime.
We have to be very careful when we start seeing civil liberties and constitutional protections erode. Tech companies have been under siege from the government's use of the All Writs Act in the last two decades and as long as they are successful, I do not foresee them changing their methods.
If that's the case he should give the FBI the key. That way he'll prove he wasn't possessing child pornography.
Or maybe he believes that damn pesky constitution (sarcasm) applies to everyone including the government when it comes to search and seizure, and to himself when it comes to right to due process of law, and the protection against self incrimination to name just a few.
Or maybe there is child pornography on there and he does not want to charged and tried and vilified in the court of public opinion. Right now he can stand on "higher ground" by making a constitutional law argument than exposing a secret that he may be ashamed of (guessing here).
Or maybe he truly does not know the password? Despite the governments best efforts they have not been able to crack it so it must be quite secure/complicated.
The thing with the law and rights is, is that they are the same for everyone. Eroding them for this guy also erodes them for you.
Don't you think its wrong to be able to hold someone forever without evidence? Isn't one of your rights that you don't have to incriminate yourself?
Or do you think that some people should have less or more rights than yourself?
Who is defending him? I cannot in good conscience call him a perp as he has not been charged with, let alone convicted of, a crime. I am only pointing out that there are a myriad of possibilities one of which is that there is child pornography on the drive. However, we do not know that for a fact.
But just as I said, he may fear decrypting the drive because of what is on it (only he knows at this point). He may think it is better to be seen as the little guy being bullied by big brother than to be vilified by those who will presume him guilty of having "CP on that drive" and becoming "the perp" without due process.
Forgive me if I am incorrect but don't our laws apply equally regardless of the crime one is suspected of commiting?
The All Writs Act is a law, and it allows exactly what is happening here. The question at hand is about whether that is in conflict with the fourth and fifth amendments. Equal protection is an entirely different thing and not at issue here.
The practical thing happening here is that the prosecution almost certainly could build a case on the evidence they have, but in practice they don't have to because the judge is willing to hold the guy in jail on procedural grounds.
Again, I'm saying there is a good argument that this was a bad decision and that the All Writs Act shouldn't be construed to allow this. But that's an academic point. In the real world, chances are very near zero that there is any "injustice" going on in this particular case.
Once more: this was a practical decision by prosecutors to deliver as much justice as they could given limited resources. It seems all but certain (yes, in the "beyond a reasonable doubt" sense) that there is no objective injustice involved in holding this guy.
Probability isn't sufficient, in this philosophy, because it's a trap. Of course probably he has on these drives what prosecutors claim, or worse, evidence of his direct involvement. And the trap is the injection of lack of sympathy into the decision making process; of course any reasonable person will say, eww he's almost certainly a creep therefore I'm not sympathetic to his indefinite incarceration. But that's exactly what the philosophy was supposedly designed to avoid, any possibility that innocent people get jailed; not preventing guilty people going free.
This is why you see a lot of effort by prosecutors defending against introduction of new evidence to prove innocence; because proving innocence well after a guilty verdict, itself shows the possibility of jailing innocents. It taints the system. And then you get these ever more perverse notions that executing those who later prove themselves innocent is not an unconstitutional execution when that person had received a free and fair trial finding them guilty of a capital crime. http://www.businessinsider.com/antonin-scalia-says-executing...
As I said earlier I am not taking a position on whether what he did was right or wrong or on the moral aspects of the subject matter but here in the US the government must have a warrant to search electronic devices and that warrant must name the material they are seeking. If they list images related to child pornography, child molestation, etc they cannot go looking for evidence of drug dealing per se. But let's assume they find evidence of drug dealing, do you not think they will simply broaden the scope of their investigation and go looking in every corner of s life to now prove something they previously were unaware of before they hypothetically gain access to the drive.
Which makes more sense to me...I believe it is unlikely that hash values would remain intact through encryption.
[1] https://arstechnica.com/wp-content/uploads/2017/03/rawlsopin...
That said, it's entirely possible still he forgot the passwords to the drives.
(Insert memeface)
I read the article to mean that the police have proof that hashes of known child pornography were downloaded and are not on the computer so they are assuming that they were downloaded to the external hard drive. How can they see what files are sitting on a password protected encrypted drive? Who is to say that it is this external hard drive these files were download onto?
I just believe that more is needed to meet the "foregone conclusion" threshold.
https://arstechnica.com/wp-content/uploads/2017/03/rawlsopin...
Specifically the top paragraph on page 7. If you can get through that paragraph and still give him the benefit of the doubt, then you are more open minded than I am.
Prisons are overcrowded enough and it costs a pretty penny to house prisoners without us starting to house people indefinitely who have not been charged with a crime.
They know he downloaded files which have the same hash values as known images of child sexual abuse.
They arrest him and search him. They can't find these images but they find an encrypted hard drive.
In some countries (England) they can ask for the keys, and not handing over the keys is its own offence (with 2 or 5 year sentence depending on the supposed contents).
I have no idea what the legal situation is in any other countries.
Seems easily defeated by a technical adversary, but probably good enough for most police work.
On an encrypted drive? Sounds like bullshit to me.
If the disk is encrypted how can they match file hashes? Do they encrypt known CP files with the FileVault key and then compare? If so, isn't that enough to convict him?
> The Forensic examination also disclosed that Doe had downloaded thousands of files known by their “hash” values to be child pornography.[3] The files, however, were not on the Mac Pro, but instead had been stored on the encrypted external hard drives. Accordingly, the files themselves could not be accessed.
If he's downloading them or storing them by some content-addressable system (torrents, something rsync-like that generates hashes before syncing them, etc.), I can easily believe that there's forensic evidence on the internal hard drive that the files were copied, including the hash of the plaintext, but the files themselves aren't present in plaintext.
This is clearly enough evidence to convict the guy, so I imagine they're holding him for some political reason (like generating jurisprudence for violating the 5th amendment in the future).
Isn't the point of encryption that it doesn't create a reliable hash - that 2 identical files will appear different while encrypted, as part of the larger encrypted drive?
Or are encrypted-hash collisions possible when small files are encrypted individually?
Secondly, when you have two files that are exactly the same and encrypt both with the same key, method and parameters then both will have the same hash. ( Though I could imagine Apple doing stuff with padding, and other parameters to make this not happen)
"Investigators said content stored on the encrypted hard drive matched file hashes for known child pornography content."
I read it like this: They figured out that the disk had some incriminating files, as I described in another comment of this thread. To make this work hashes are of no use, they need the original files. For various reasons they might not want to admit that they are in possession of the original files, hence the cryptic and vague phrasing.
I'm sure law enforcement has lists with hashes of incriminating files, but I'm not sure if they are allowed to keep the original files. Even if they are, maybe they just want to avoid public discussion about it.
The claim is bogus.
You do realize that MD5, SHA-1, and SHA-256 are all hashing algorithms? I highly doubt you meant a cipher built from a hash function (easy to do with Feistel net, though nobody does that), especially that IPsec doesn't define any such thing, from what I remember.
Given that you apparently don't understand how encryption and hashing work and relate to each other, you're not in a position to question the technical aspects of the story.
Agents from the Department of Homeland Security then applied
for a federal search warrant to examine the seized devices.
Doe voluntarily provided the password for the Apple iPhone 5S,
but refused to provide the passwords to decrypt the Apple Mac Pro
computer or the external hard drives. Despite Doe’s refusal,
forensic analysts discovered the password to decrypt the Mac Pro
Computer, but could not decrypt the external hard drives.
Forensic examination of the
Mac Pro revealed an image of a pubescent girl in a sexually
provocative position and logs showing that the Mac Pro had
been used to visit sites with titles common in child
exploitation, such as "toddler_cp," "lolicam," "tor-childporn," and “pthc.”
The Forensic examination also disclosed that Doe had downloaded thousands
of files known by their “hash” values to be child pornography.
The files, however, were not on the Mac Pro, but instead had been
stored on the encrypted external hard drives. Accordingly,
the files themselves could not be accessed.
So it looks like they got the hashes from logs/forensic evidence collected from an decrypted Mac Pro.This shouldn't work because if they had the key (which should be encrypted with the password) then they could also just decrypt the rest.
Somebody on IRC said that maybe the encrypted filesystem saves hashes of the files unencrypted, but not sure if Apple's FileVault does this.
Edit: So two people have downvoted me without explanation. Is what I'm saying wrong?
Sadly, that is the new normal for HN (and, I'll be downvoted for saying something like this)
On a similar note, I wonder if this will spur interest in a kind of file-doping program to confuse hashes of drive contents. A few pixels won't make a difference if you're planning on just viewing some images.
You might have to do more than change a few pixels here and a unicode character or meta tag there. I even suspect things like color grading and, say, something like batching multiple images or text files together into one file, could be accounted for.
Not to mention, such a doping program would preferably alter files in an imperceptible (aka, less mutated) fashion.
I am a bit of an audiophile with my music and go to great lengths to rip high-quality, lossless, perfectly-encoded tracks for the sake of historical preservation. I imagine some pedophiles feel the same way about their data and the thought of tampering with the data's original state is abhorrent.
Even a colorshift or one or two changed pixels might make it worthless in their eyes, much like a bad rip with barely perceptible clicks or an altered noise floor is worthless to me.
They usually aren't using SHA (maybe they are in this specific case).
"It works by converting the image to black and white, re-sizing it, breaking it into a grid, and looking at intensity gradients or edges."
Pretty cool piece of technology. Seems like it covers the obvious bases. I imagine it also ignores meta tags as part of the hashing process, and operates directly on the pixel information.
Perhaps one way to circumvent detection without making perceptual modifications (which would have to be somewhat significant to thwart the above method) could be a program that losslessly converts all of your images' pixel data to a generated file type only understandable by a program with a specific key in memory, which either directly displays the image or creates temporary files that could be used by a regular image viewer? The files could possibly be signed by more than one party for extra protection. I know it sounds just like encryption but I'm thinking of something a little different. Sort of a singular encrypted file that can be securely transferred to any file system.
Sounds like a fun and challenging project but I'd hate for it to be so successful that it leads to child pornographers getting off the hook.
"In December 2016, Facebook, Twitter, Google and Microsoft announced plans to use PhotoDNA to tackle extremist content such as terrorist recruitment videos or violent terrorist imagery."
Dear lord, that is a stupendously slippery slope.
This is an attack, which contemporary block based FDE doesn't really protect you well from. Bitlocker, FileFault, TrueCrypt, VeraCrypt basically operate on one disk block at at time and this means they cannot hide data patterns well. Or as Thomas Ptacek put it in his article "You Don't Want XTS" [1]
>It’s ECB-like. It can’t do a perfect job of providing privacy.
This is also why Thomas Ptacek and others are advocating that FDE is not a complete replacement for file based encryption.
> But that’s the big problem: sector-level encryption sucks. It’s messy, provides fewer security guarantees than conventional message encryption, and makes tradeoffs tailored to the challenges of encrypting disk sectors.
> Sector-level crypto is last-resort crypto.[1]
The Wikipedia article about ECB[2] (which is not used in current FDE) has a dramatic example where the image of the Linux penguin is clearly recognizable in the ciphertext.
[1] https://sockpuppet.org/blog/2014/04/30/you-dont-want-xts/
[2] https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation
1. I didn't claim XTS-mode AES is vulnerable to known-plaintext attacks.
2. I don't believe the investigators claim to have pulled off a known-plaintext attack. What is your source for this?
> Bitlocker, FileFault, TrueCrypt, VeraCrypt basically operate on one disk block at at time and this means they cannot hide data patterns well.
This is wrong, but you claimed it. In the context of this thread (matching files on an encrypted disk with known unencrypted files), that's a known-plaintext attack.
Maybe you weren't aware you were making this claim, but you did.
Possible? Try exceedingly likely. That's why it should be fought here, with an unpopular defendant.
If white supremacists had something nice to say, people wouldn't want the government to unlawfully silence them.
It doesn't feel good to protect the rights of suspected child pornographers, or white supremacists; but consider that we don't want a government empowered to unlawfully persecute those who do or say things we find morally repugnant because what the majority finds morally repugnant changes over time, but fundamental rights shouldn't.
Then people wonder why the country elects Trump to shake things up.
This guy should stand trial or be let go.
What harm does the contents of an encrypted disk do to society? It is not like he was going out and trying to legalize child abuse. If the person was involved in child abuse, we must try to convict him absolutely but we should be able to do that without what's on the hard disk.
Oh and while I have your attention I'd like the reader to look up something unrelated but still very important. Look up cfaa. If you're in the us, please help repeal it!
The root problem here is child abuse. Anybody abusing children, or financially supporting the abuse of children, is doing a seriously bad thing and this is what should be illegal.
I'm highly skeptical that images on a hard drive can cause the abuse of children. That's the same kind of logic people used back in the 1970s to argue that playing D&D and listening to Kiss were going to result in a whole generation of Satan-worshippers.
You could show a non-pedophiliac person the entire contents of that hard drive, and it wouldn't arouse them or make them want to go abuse children. Wouldn't make me go abuse kids. I'd probably cry a lot and go volunteer to help some kids[1]. So I am not convinced that the contents of this guy's hard drive are going to result in more kids being molested somehow.
If anything, I think the opposite may be more likely. Access to porn is correlated to a reduction in rape. I don't know if this extends to pedophiles, but it sure seems entirely possible: https://www.psychologytoday.com/blog/all-about-sex/201601/ev...
Would I want my kids hanging around somebody with a hard drive full of that stuff? Probably not, but I also wouldn't want them hanging around supporters of certain political parties either, and I don't think they should be rotting in prison indefinitely with no trial.
______
[1] I already do volunteer work; no need to send me illegal porn in order to get me off of my couch
I totally ignored the question of the harm that the continued availability of this pictures might do to the victims in the pictures.
The ramifications of "revenge porn" are well known; it can be really hurtful to the victims for that stuff to be out there. It is, essentially, an ongoing sexual assault. (Jennifer Lawrence is one celebrity who has spoken about this at length) So, it was wrong for me to ignore that very important aspect.
Of course, it's not a given that this guy was distributing porn - there's a difference between saving a picture on your hard drive, and distributing it. If it was a torrent download, obviously, then he did both. And there might not even be people involved -- aren't underage hentai comics considered child porn in many jurisdictions? Barf, I don't want to think about this.
Because this is the internet and words get turned around so easily, let me be super clear that sexual contact with minors is wrong and I'd like to see it eradicated.
I have known victims of childhood sexual abuse. The lifelong damage caused can be absolutely devastating.
My theory goes: if you're not a pedophile, I don't think stumbling upon child porn will make you one, just like watching violent movies won't make you a violent person. If you are a pedophile already then seeing child porn may be a way out of actually harming children, just like watching gore movies be a way out for some sexual fetish with corpses.
We should be going after abusers (obviously) and people who actually profit from distribution, which add an incentive for child abuse even for people who are not pedophiles, just desperate for money.
Having pictures on your computer without an intent that could cause harm should not be illegal.
https://upload.wikimedia.org/wikipedia/en/d/d4/TrangBang.jpg
If he's financially supporting the abusers by purchasing the pictures, then they should be prosecuted if there's proof, but is there really any harm done if the number of copies of a picture goes from 10,000 to 10,001?
https://www.washingtonpost.com/news/worldviews/wp/2016/05/06...
This is literally approach pro-Trump voters want. They complaint is that system became weak and does not do power play like this often enough.
- We just "found" this encrypted drive in your apartment. Too bad you don't "remember" the password uh? The judge won't like it!
More like "the judge thinks". Which, we shouldn't be incarcerating people indefinitely for IMOP.
This case in particular is troublesome. There are lots of bogus claims by the prosecution like being able to confirm the CP via hashes despite the content being encrypted. If they truly had a strong case against this guy, they'd go to trial.
As someone who has forgotten passwords in the past: this is outrageous.
Put me in jail for a year or two and I'll probably lose access to everything I own.
> The government also said that Rawls doesn't have to provide them with his password anymore, as they only need him to perform the act of unlocking the hard drive.
Those two statements seem at great odds. If the government actually knows the password now, the only thing having the defendant himself unlock it does is make it some sort of testimonial fact. The prosecution will use the fact that the defendant unlocked the device himself a point to the jury.
But yes, I agree that I misunderstood what they were saying.
This is just the sort of hard case to set the right precedents about rule of law, you just can't lock someone up without trial. It goes against every know tenet of law.
If there is a rule of law that allows this, then it is basically not rule of law as we understand the word.
How on earth is this supposed to work? Unless they can decrypt the hard drives I am pretty sure that this is impossible to deduce.
Maybe he used freenet or something in his unencrypted hard drive?
This makes zero sense. It would have to be an utterly terrible encryption program for anyone to be able to see the hashes of the encrypted files.
[1] https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...
Can someone explain to me how it's possible to check file hashes in encrypted drive?
Given the legal grey area this all appears to be in and the potential upside of getting in to the HDDs this seems like something the authorities would be ok doing while the law catches up.
Why should this guy get a free pass on child pornography just because he encrypted his hard drive? Child pornography is terrible! Who cares if the guy encrypted his child pornography. He should be in jail either way. The only reason someone would rot in prison for 2 years is because he knows he's going to rot in there for a lot longer due to his child pornography if he unlocks his hard drive.
The point of the 5th ammendment is not that the government shouldn't be able to access concrete evidence. It's so that the government can't torture/imprison someone in order to get them to admit to a crime. The reason for this is that a forced confession isn't any indication that the person actually committed a crime.
Of course we will never know if the guy truly forgot his password, but chances are he's been counseled by his attorney to never give it up.
Honest question
1. Install a hardware keylogger (software keylogger wouldn't work) in the laptop.
2. Release the defendant.
3. Get a warrant for the arrest of the defendant for CP-related crime.
4. Decrypt the laptop with the password recovered from the keylogger.
All of this depends on the suspect using the laptop again, but I'm guessing they'd want to recover the contents on the laptop.
> Release the defendant: If this is judges decision, he can't be in court again for the same crime.
> Get a warrant for the arrest: Again? Isn't he released? As such, gov must not return laptop with backdoor either in hardware or software mode.
> Decrypt the laptop: Even if all above matched, you think he'd use the same laptop again? If he has a bit of brain, I think he wouldn't.
He hasn't been charged with a crime yet.
> "Again? Isn't he released? As such, gov must not return laptop with backdoor either in hardware or software mode."
Don't release him fully then. Release him on bail or some other form of conditional release.
> "Even if all above matched, you think he'd use the same laptop again? If he has a bit of brain, I think he wouldn't."
Admittedly this is the weakest part of the suggestion. It'd rely on the person being addicted to CP to impair his judgement.
* Detaining this individual indefinitely without charge.
* Charge based on limited anecdotal evidence.
* Release without charge.
Can you think of other suggestions? Which of the available options do you think is best? Best being a balance between the rights of the individual and the laws of the state.
What should happen in this case IMO is that they should charge him with whatever they have right this moment, and if it fails, release him. Infinite detaining of individuals should be impossible, no matter what. This is dangerous.
If all it takes to be a criminal that can't be charged for their online behaviour is to encrypt a hard drive, what ramifications does that have for our legal system?
Encryption, once you lose the key, effectively destroys data. If you wanna charge someone with destruction of evidence, then charge that.
Refusing to comply is not a valid reason to lock someone up forever. You can charge him with contempt to court if you need to.
Well there's the reasoning
Despite Doe’s refusal, f orensic analysts discovered the password to decrypt the Mac Pro Computer , but could not de crypt the external hard drives. [...] The Forensic examination also disclosed that Doe had downloaded thousands of files known by their “hash ” values to be child pornography. 3 The files, however, were not on the Mac Pro, but i nstead had been stored on the encrypted external hard drives. Accordingly, the files themselves could not be accessed.
IMHO, if they really wanted to charge him and take him to trial, they have plenty of evidence. I doubt a jury would be sympathetic to the "I forgot my password" argument and the logic would be that if the files _were not_ on the external drive then he would willingly decrypt it to prove as much.
This article talks about "data" related to Freenet and filenames:
http://www.philly.com/philly/news/20160908_Should_ex-Philly_...