Man convicted after preventing counter-terrorism police search
news.met.police.uk
news.met.police.uk
This was very clearly politically motivated to hamper the efforts of CAGE; a UK based group which lobbies of behalf of young Muslim men who have been detained without charge it gitmo, harassed by the security services etc.
Regardless of whether readers like CAGE's politics (which are considered inflammatory by the government), this raises a worrying precedent.
It's also worth noting that given the UK's recent authoritarian laws, he got off lightly --- this could easily have been spun to possessing encrypted data (while being unwilling or unable to decrypt upon command), which carries a two year sentence, IIRC five if the magic word "terrorism" is conjured.
Is... a crime? Woah.
Absurd nonetheless.
Almost everyone with an internet connected device possess encrypted data.
Not to mention that with digitization, every file is "just a number" anyway. Top secret document leaked? Naked photos of an ex posted for all to see? "Hey, I just shared a binary number on the internet" doesn't really hold water.
It might be politically abhorrent to persecute people for such things, but absurd it is not.
You have no idea if a file contains something needed as part of a decryption process, or if the file itself contains encrypted informations.
So basically, having a "pad" file incriminate you.
You really shouldn't be able to access /dev/urandum until you have been cleared by a reputable Alphabet company. This is for our security and that "obviously" trumps individual rights (whatever that means).
Root cause of all this is, of course, "bad thoughts" and "bad information", which IMHO should also be made illegal and only permitted in designated "free and error prone thought" areas and participants monitored by physicians from the Ministry of Error Free Thought.
Plausible deniability by allowing you to decrypt with one of two different passwords. One gives you access to the volume with your data, the other opens a shadow volume that contains random non-senstive data.
jeeeeesus
(Not disbelief or concern trolling, I'd like to find out more about this case.)
Well, it depends. Though some information there might be protected by "attorney-client privilege" today's verdict doesn't seem to support it
> IIRC five if the magic word "terrorism" is conjured.
Well, there is another way, but when people are more preoccupied with the rights of outspoken jihadists (not saying it's the case here) and not appearing racist in reporting crimes pressure shifts to those who have less connections to wrongdoings
How does this work with things like DRM? What if you have media on your phone from something like Spotify or Netflix that's presumably encrypted or protected in some way, that you cannot decrypt if your subscription expires...
I could have a file filled with /dev/random and the law would still apply.
Suddenly the Minister[0] possessed a file which he couldn't decrypt on demand. Would he consider amending the Bill to remove penalties for such eventualities? Of course not, nothing was changed.
If you possess the bytes you'll do the time. Delete everything that is unnecessary as soon as its usefulness has expired - big corps learned that lesson, for other reasons, in the early 2000s.
[0] well one of his staff
While I entirely sympathise with this idea abstractly, so much of law depends on the context of actions where it's easy to dismiss this stunt. Merely having encrypted data in your possession is technically not within the scope of the law if the context is "as part of a counterterrorism investigation" and if the person could reasonably be expected to decrypt it (which would imply they were both the person to encrypt in the first place AND with the means to decrypt it - as this politician clearly wasn't).
Wrongful convictions and dragnet searches are the serious consequence of these laws, yes, but the real test comes when it's hateable/despicable people at risk. The problem with these laws isn't that it's fundamentally or potentially arbitrary, it's that it's wrong even when it's not arbitrary. And the mere fact of a police investigation or allegation is not sufficient to cross that line.
People should have the right to encrypt anything they want without being coerced into decrypting it. There are more than enough means for police in our modern technological era to convict terrorists/criminals and prevent conspiracies without having total access to all data. And the costs of removing that right is much higher than the rewards of a few extra convictions.
It then becomes a grey area between having been sent encrypted data, and having used the previously mentioned scheme to avoid decryption.
I also wonder how this interacts with the new 5-tap SOS function on iPhones.
Not quite; the bar is not as high as an existing 'terrorism' investigation. To quote RIPA (2000)[0], if anyone authorized has the belief (upon reasonable grounds), that
(3) A disclosure requirement in respect of any protected information is necessary on grounds falling within this subsection if it is necessary—
(a) in the interests of national security;
(b) for the purpose of preventing or detecting crime; or
(c) in the interests of the economic well-being of the United Kingdom.
It is very very easy to imagine how this could be abused. Saying that you'd like to slap POTUS or May on Twitter could conceivably meet grounds for (2), and (3) is so broad that it's possible to imagine it could be triggered by something like being Alexandra Elbakyan of SciHub, or Sundae of The Pirate Bay. Depending on the mood of the press and the 'authorized persons', why not any old person caught using BitTorrent, or cracking DRM?[0]: http://www.legislation.gov.uk/ukpga/2000/23/pdfs/ukpga_20000...
Interesting point, but I think in this situation they'd be putting pressure on the media provider to decrypt it for them (since the media provider is the one in control of the encryption, not the consumer). That's assuming said media provider is in a jurisdiction that the relevant govt has some control over, and/or media provider is compliant.
Here's a thought experiment: suppose ISIS (or your preferred terrorist organisation of the day) set up a media service for users to share videos (or other media) that are protected by DRM. The media service can disable the viewing of said content on a whim. A person using this service has their phone/computer confiscated, but the authorities are powerless to gain access to the content due to the DRM. Is this person liable under these laws, even though the encryption is outside their control?
How can you even defend yourself?
For Police work, time is "relative", as an example the cop that is held in the US for contempt of the Court for not revealing the password to his drives is suspected of possessing child pornography, whether he is kept in jail because he won't reveal them or because as the sheer moment he reveals them he will be proved guilty doesn't change things much (there is anyway other evidence against him).
Here it is not a "Police" case, but rather a "counter-intelligence" one, in these cases time is everything, a delay of hours, or at the most days in gathering the information is vital.
AFAIK Mr.Rabani NEVER revealed the password(s), he refused revealing it/them on 20/Nov/2016, now, almost one year later, he is found guilty of obstructing the search, still there is no evidence that he is or was - even tangentially - connected with terrorism.
So, £620+12 months' conditional discharge seem to me a lot of time/a very severe punishment if he was in good faith attempting to protect some sensitive data for his non-governement organization, and nothing if he was in bad faith or however protecting terrorism related info.
In any case, whatever the Police expected to find on the device(s) they didn't access it/them, and much worse than that they didn't access it/them in a timely fashion (and no charges of terrorism or connections to it were made against Mr.Rabani in almost one year) so - besides seeming more a petty vengeance than anything else - it is not like it helped in ANY way the counter-terrorism.
It isn't supposed to make sense. it's suppose to reinforce the "you do whatever the police ask you or face the consequences." Apparently the law backs them....
I meant "make sense" as a deterrent for next occasion AND useful for counter-terrorism.
If you are "innocent" and refuse to give away your passwords, you now know that you have serious chances to be punished in a non-trivial way.(losing your electronic device + fine + 12 months conditional)
If you are "guilty" (of terrorism or contiguity with it) you now know that you can refuse to give away your password, effectively preventing the police to read your data and maybe in one year time you will get a slap on the wrist (when compared to the punishments for actual being part of a terrorist plot).
So, "real" terrorists will surely continue not giving away their passwords to the Police, whilst most innocent people will be giving them - fearing the punishment[1].
The net effect will be that Police will have not access to relevant terrorism related material but it will lose a lot of time on analyzing gigabytes of - say - lolcat videos.
[1] a few innocent people will anyway refuse to give away the passwords for this or that principle, so among the "non-answering" will be both innocent and possibly guilty people, so it doesn't even work as a "screening" method.
Actually I think is why the law was passed, so the cops can keep harassing the people on a likely terrorist cell hoping they slip. Time and time again. Slap on a wrist? Not if it's one after the other. It's not like London doesn't have the police manpower
>Whether the government can compel decryption in this manner depends on a legal doctrine called “foregone conclusion” that was first articulated in a 1976 Supreme Court ruling relating to paper documents in a tax fraud case.
>Under the “foregone conclusion” doctrine as applied to digital documents, handing over files is not considered testimony if the government already knows that the files exist and what machines they live on. And when there is no testimony, the protection of the Fifth Amendment’s self-incrimination clause is not available. Prosecutors with specific information about the existence and location of files on encrypted hard drives are more likely to convince a court to order a suspect to decrypt them.
1. http://www.slate.com/articles/technology/future_tense/2012/0...
Or, the third option: he is not protecting anything or anybody but merely feels this law is unjust and one should stand up against it on principle.
In fact this man was arrested without cause and convicted only of refusing to give up the passwords and data of his devices. This law renders our spies and police above the law and able to intercept the communications of anyone they choose without a warrant.
For a more informative take on the arrest see this intercept article
https://theintercept.com/2017/09/25/muhammad-rabbani-guilty-...
In Britain people have been sent to jail for tweeting or posting facebook statuses.
http://www.thedailybeast.com/can-a-tweet-put-you-in-prison-i...
> the Supreme Court has clearly and repeatedly confirmed that the border search exception applies only at international borders and their functional equivalent (such as international airports)
but that line cites https://en.wikipedia.org/wiki/United_States_v._Martinez-Fuer..., which is weird because it says the opposite.
For example, I live on the border - pretty much. I'm just a short drive to Canada. Border Patrol can't actually stop me and search my car, search my house, or anything like that - unless I'm going through the border.
If I'm not going through the border, they need a warrant. There are no checkpoints other than at the border, but those would be functionally equivalent (in the eyes of the court). I believe temporary checkpoints also count as functional equivalents but that's a guess - I'm not sure if that's been tested in court yet.
Other than those checkpoints and the border, you retain your rights as you would elsewhere. Or so precedent and SCOTUS say - except I speculate that they include temporary checkpoints along with permanent checkpoints.
The ACLU disagrees and says all the CPB needs is probable cause.
>8 U.S.C. § 1357(a)(3) addresses CBP officials’authority to stop and conduct searches on vessels, trains, aircraft, or other vehicles anywhere within “a reasonable distance from any external boundary of the United States.” Without further statutory guidance, regulations alone expansively define this “reasonable distance” as 100 air miles from any external boundary of the U.S., including coastal boundaries, unless an agency official sets a shorter distance.1CBP agentscan also even enter private property without a warrant (excepting dwellings) within 25 miles of any border. In this 100-mile zone, CBP has claimed certain extra-constitutional powers. For instance, Border Patrol claims the authority tooperate immigration checkpoints. Agents, nevertheless, cannot pull anyone over without "reasonable suspicion" of an immigration violation or crime (more than just a "hunch"). Similarly, courts have determined that outside of Ports of Entry Border Patrol cannot search vehicles in the 100-mile zone without a warrant or "probable cause" (a reasonable belief, based on the circumstances, that an immigration violation or crime has occurred). In practice, Border Patrol agents routinely ignore or misunderstand the limits of their legal authority, violating the constitutional rights of innocent people. Although the 100-mile border zone is not literally "Constitution-free," CBP frequently acts like it is.
https://www.aclu.org/other/aclu-factsheet-customs-and-border...
The defendant tried arguing 4th amendment privacy protections over the information obtained in property that implicated him, but the judge said that didn't apply unless he admitted to owning the property which would equally incriminate him if he did, haha.
very narrow protection
Generally, the Fifth Amendment provides protections against producing documents only if the very act of producing them would be incriminating. The relevant term is the foregone conclusion doctrine. The government has to show evidence that the documents they want you to produce exist and that you are able to produce them. For more information, see http://federalevidence.com/blog/2013/january/applying-forego...
The interpretation in favor of allowing the government to compell encryption under this doctrine would be that the government simply has to prove that the encrypted data exists and that you are able to unlock it, and they have to limit the scope of their search to specific documents.
[0] https://en.wikipedia.org/wiki/Article_10_of_the_European_Con...
In your link:
- the nameless chip shop employee doesn't even get named, let alone do we hear of any punishment given. Instead, we just get a couple of paragraphs about a tweet of his
- half a paragraph is spent on someone who got half a year in jail for using one word in a podcast; seems like more context would be valuable here
- two twitter users making threats fronted up to court, but we never hear what happened to them. Freedom of Speech doesn't extend to making threats.
- the Mandela-joke-maker supports the article's premise, yes
- more threats on twitter were responded to, one leading to an arrest
The only item that clearly supports the article's premise is the guy who made jokes about Mandela, but the whole article is written in a way that it's clear there's a lot of missing context. The one and only example that actually got jail time is only half a paragraph long and has feeble information available. Independently of whether or not you agree with the point it's making, this is a 'spun' article.
About the first case: he was a Rangers fan. He posted about the Celtic manager. Are you missing the sectarian violence[1] linked to Celtic and Rangers? Several people have been actually really killed and many others injured in stabbing and other violent crime.
That context is crucial to understanding his arrest.
Also, police weren't just searching for offensive football tweets. They were searching for evidence as part of a case about parcel bombing.
Finally, he wasn't convicted.
tl;dr I don't think much of your link if it misrepresents the case this badly.
EDIT: the second case wasn't just the use of the word "taig", he organised a harassment campaign against a woman
http://www.dailyrecord.co.uk/news/scottish-news/tv-comic-lim...
EDIT2: Your link totally misrepresents the criado-perez harassment. She was getting hundreds of direct, credible, threats of harm. One man was sending 50 messages an hour for 12 hours. Have a read of the sentencing remarks: https://www.judiciary.gov.uk/judgments/r-v-nimmo-and-sorley-...
tl:dr2 your link is shit.
You can be sent to jail in probably any country for Twitter/Facebook posts. Just ask Martin Shkreli[1]. I worked at a smaller social media company and a girl was pissed off at the politics of the governor of her state; she make a very specific threat (time, place, and action) and my company was required by law (and ethics) to report it to the local police.
[1] https://www.washingtonpost.com/news/business/wp/2017/09/13/m...
https://theintercept.com/2017/09/23/police-schedule-7-uk-rab...
Giving his age kind of adds context, but I don't understand the reason for publishing his date of birth. Odd.
I'm guessing that means that it's encrypted and, since he still hasn't given them the password, they are stuck.
The fine, the cost of a laptop and phone... altogether, I can't see this stopping terrorists, just making people's lives worse.
Beyond that simply removing the dive and putting it in another computer would bypass any switch except one in the drive firmware itself. Are there any software out there designed to do that?
Hilariously enough, an Intel Management Engine-esque system could come in handy here for nuking data.
IME could maybe be useful for this but it's hard to prevent the take the drive out and attach it to another machine without having firmware or a ME-like chip on the drive to make it wipe if it's connected to a different machine.
> The funny connector to nowhere is the connector to tap into the SSD. When the Apple connector is mounted (as supplied) it connects the CPU to the SSD. When removed the signals for the SSD can be accessed.
[0] https://www.ifixit.com/Teardown/MacBook+Pro+13-Inch+Touch+Ba...
PC Tariq Chowdhury, the officer who stopped him, said that he had never come across anyone refusing to give the passwords. Some people resisted initially but eventually complied with the order, he added.
A person who doesnt willfully provide passwords for their electronic devices.
/s
> argued incorrectly that this gave him the privilege of not sharing information with police
But that's not happening here, there is no balance being stuck. There is just "remove all characteristics of a legal system" (Rechtsstaatlichkeit) on the one side, and the gain is "have the means for absolute power".
Edit: I feel that question leans too much into pure politics, and was hesitant answering. The link with HN is that the story is also about criminalizing encryption. Mein Kampf, not so much linked.
Though, I'm not really sure you can remove politics from the question and I doubt candidates and parties would not be involved, even if they have to force their way into the issue.
There is another twist here in that there isn't a precedent for them to ask for access to your network presence, they can ask you to 'unlock' hardware in their possession but it does them no good when there is nothing on it.
So it pushes them back to having to do things more traditionally (with a warrant).
In general it saddens me that we've come to this.
No kidding. It's a pretty sad state of affairs all around. The reason I mentioned this is that if the border patrol / the police / the feds / some random official are already aware of your linked accounts and you lie about it that you are in much hotter water than before.
https://www.theguardian.com/world/2013/aug/19/david-miranda-...
It's a shame UK doesn't have a real constitution. It would probably help prevent some of this bullshit. Maybe it's time the British people start asking for one.
What protects the constitution from those sworn from upholding it?
About the only reason changes aren't being made into law quicker is that this party in control is pushing some very polarizing/unpopular legislation/edicts.
Whereas, the British (and the Australians, who have one of the most embarrassing 'constitutions' of them all) seem to have been fine, all along, to just roll over and expose themselves to their masters, the ruling classes.
Nevertheless, these constitutions are nothing more than smart contracts. I'm wondering if anyone has done the UDHR as a smart contract .. seems that might be the right thing to ICO.
For example-- the Trump administration's initial travel ban executive order was blocked by the courts based directly on issues of consitutionality. Furthermore, if you read the text of that bill you can tell the authors were careful not to use the frank, unambiguous language that Trump used on the campaign trail as that would have been thrown out by the courts even more quickly.
So there you have it-- an example where the current administration did the opposite of ignoring the U.S. constitution, and a court system that blocked the executive order even though the administration tried to skirt the intent of the constitution (namely, the 1st amendment). Does this falsify your statement? If you don't think so, please give me an example of what you think would falsify it and I'll give that a shot.
If the first two aren't working, you take to the jury box, and when people are unjustly charged with crimes that are either misapplied laws or simply that which people deem to be unjust laws, they can find a defendant not guilty on any grounds they wish in the US. That's one of the more critical aspects of the courtroom that often goes overlooked. Jury nullification is rarely talked about but it's a crucial power of the people. Judges and law enforcement hate it because society can effectively nullify anything by refusal to return guilty verdicts. So even if someone is clearly guilty under the wording of a law but the jury determines it to be an unfair law or a law applied unfairly, they can find them not guilty. However, the reverse is not true. Guilty verdicts must be returned in accordance with the wording of the law and historical precedent, in conjunction with the guidance the judge provides.
In cases like this, though, things are more difficult because it's not just the charges that are levied, it's the entire way the government is conducting itself. That is much more difficult to solve is 1 and 2 don't work and why the 4th box is supposed to be used under only the most dire of circumstances.
Of course, I don't think the government is entirely to blame. People keep voting these scumbags back into office for some reason so apparently there are people out there who approve of what their representatives are doing. And yet, amazingly, everyone seems displeased at the results. It's fascinating, really. It's like everyone has this mentality of, "all these congresspeople are lying dirtbags...except for mine."
The UK has a real Constitution, even if it isn't in a single document; OTOH, it may not have the content you would prefer on this issue. But even if it did, a Constitution, like any set of laws, doesn't constraint behavior in the absence of people actually exerting effort to enforce it, it's just—absent enforcement—just words.
But it isn't; it isn't even as coherently defined as something like the common law of murder, where you can make a pile of statutes and legal precedents and get a fairly clear idea of where the boundaries are.
The constitution is very fuzzy indeed, and parts of it depend very much on how much political and media support someone can get when they point a finger and declare "unconstitutional!".
People have known this for awhile, but it seems like actual products suggesting security have been slow to adopt it.
Let's not mention it again.
But not having electronics is also grounds for suspicion.