Man jailed over computer password refusal
bbc.co.uk
bbc.co.uk
As a practical matter, I've wondered what would happen if someone simply claimed they couldn't remember the password. Especially if one could make it look like the encrypted files hadn't been accessed in over a year.
TrueCrypt's Plausible Deniability (http://www.truecrypt.org/docs/?s=plausible-deniability) makes these issues even more complicated.
But yeah: by simply refusing, you'd be thrown in jail for contempt and your only way out would be appellate review of the order. You'd have to challenge the contempt citation on the basis that the original order was unlawful.
http://en.wikipedia.org/wiki/United_States_v._Boucher
On February 19, 2009, Judge Sessions reversed the
magistrate's ruling and directed Boucher "to provide an
unencrypted version of the Z drive viewed by the ICE agent.It'd be similar to confessing to murder, telling the cops where the body is, and then invoking your right to remain silent, and expecting them not to look for the body under "fruit of the poisonous tree" logic.
This is really common advice, but I'm not sure it's the best option.
Yes, there are going to be gray areas. But if Bob has one computer in his house with his and only his finger prints all over it, wear that indicates that the computer has been used extensively, and the computer hard drive is filled with an encryption scheme wrapped around otherwise useless gigabytes of random data, then I am sure beyond a reasonable doubt that there is encrypted data on the hard drive and Bob has the key.
1. Bob has mischievous friends, or worse, enemies at school. He leaves his laptop unattended/exposed where someone installs the encryption then wipes their fingerprints, or perhaps has worn gloves. Bob takes his laptop home and tries to regain access to the computer.
2. Bob unwittingly acquires the laptop from a criminal (he may have bought it, or maybe he fixes computers) who encrypted the drive and wiped away all fingerprints. Bob tries to gain access to the computer.
To be free from self-incrimination Bob can simply refuse to answer any questions about the laptop in question at all.
>One of the earliest attempts to quantify reasonable doubt was a 1971 article by Rita Simon and Linda Mahan, "Quantifying Burdens of Proof: A View from the Bench, the Jury, and the Classroom." In a later analysis of the question ("Distributions of Interest for Quantifying Reasonable Doubt and Their Applications," 2006[10]) , three students at Valparaiso University presented a trial to groups of students. Half of the students decided the guilt or innocence of the defendant. The other half recorded their perceived likelihood, given as a percentage, that the defendant committed the crime. They then matched the highest likelihoods of guilt with the guilty verdicts and the lowest likelihoods of guilt with the innocent verdicts. From this, the researchers gauged that the cutoff for reasonable doubt fell somewhere between the highest likelihood of guilt matched to an innocent verdict and the lowest likelihood of guilt matched to a guilty verdict. From these samples, they concluded that the standard was between 0.70 and 0.74.
Remember; reasonable doubt is not just the production of an alternate theory, it requires legitimate evidence to verify.
Both the example theories you cite would usually be easy to disprove as well. The first because you could look at various aspects of activity on the computer either side of the creation of the encrypted file and show that it resembles their usual activity (for example, there are numerous other ways to do it).
Now, this is where it gets clunky. I'm speculating here, but from direct experience so... take it with caution.
If you're under investigation for something and refuse to hand over a password then you're unlikely to automatically go to jail over it. The case that probably exists is that there is evidence to support the accusation, but no actual images/material. The latter is needed for a prosecution to succeed. I've never seen a case that looks like a blank go as far as demanding encryption keys - unless you are insanely careful there will always be traces left outside the encrpted file.
(BTW, Pro Tip - if you want to be secure from investigation, scrap windows (it logs way too much) and switch to Linux. Much of the forensics stuff is Windows focused so you instantly throw the [get the right file system and the main forensic tools won't even recognise it...]. Couple that with encrypted containers and you're on to a winner)
Since this was before 911 - the 'terrorists' in question were presumably the IRA, not sure they had much of an online presence back then.
You do know that 9/11 was not the first terrorist attack on the US by Islamic extremists, do you?
The fact that their plans would be written in a foreign language (never mind a foreign alphabet) would have been more than adequate to keep it secret from British intelligence.
ps. You do know that we have been having terrorist attacks for almost a century.
This is one of the stupidest statements I have ever seen.
Plus, in my experience, Arabic is a difficult language for people who grew up speaking romance languages to learn. Perhaps not as difficult as Japanese, but still much more difficult than German or French.
That's probably where they get them.
We may have a stifling bureaucracy and an overstretched military, but at least the British Foreign Office actually has local knowledge and people who speak the language.
Apparently, this situation is not yet resolved, but is currently being tested.
http://cyb3rcrim3.blogspot.com/2009/03/5th-amendment-bummer....
http://cyb3rcrim3.blogspot.com/2010/04/passwords-and-5th-ame...
I agree though - the entire thing is an absurdly mucky business. Apparently however the English law doesn't have much like that in the way of loopholes, or he simply refused to decrypt it outright.
This has been floated in the US before, but it has not gotten good PR. As it stands now, it is a Constitutional law issue -- does the fifth amendment mean that you can't be compelled to get up in the witness box and talk, or does it mean that you don't have to assist the prosecution in any way? Right now, the courts seem to be split 50/50, but I feel that practicality dictates that you don't have to give up your key. First they have to accuse you of a crime and bring it to trial, then you have to refuse to decrypt the key, then the first trial has to stop, then the government has to prove that you know the key, then you have to be convicted and sentenced, then you can go back to the original trial after analyzing all of the decrypted "evidence". If encryption becomes widespread, this just isn't practical. It's easy to prove that you sell drugs; someone goes up to you and buys them. It's not easy to prove that you didn't forget your encryption key, because we have no way to observe someone's mind. Laws that prohibit crimes that can't be proved tend not to do well.
While it's a dubious law in may ways, when you hear a UK politician calling for longer detention without trial and stating needing to break encryption you can at least point to this law and say that their claims about longer detention are nonsense.
This is a really subtle point, but in the US this is not (usually) the case, because this is still self-incrimination. You see, by entering the password, you are demonstrating that you have access to the encrypted information, and demonstrating that you have that power is technically self-incrimination. The password is one piece of information that you can't be compelled to divulge, and the fact that you have the password is a separate piece of information, and you cannot be compelled to reveal either. This is also a really important piece of information too, because in order to stick you with any legal consequences associated with the encrypted information, they generally have to prove that you have control over or access to the information. If a file is encrypted it is still possible to reasonably doubt that you have access to its contents despite having access to the physical drive it is on.
While it is (currently, as far as I am aware) untested in the court of law, it may be possible to compel someone to use or divulge their password if this does not incriminate the person to do this. I can think of two ways this could happen: a) access/control to the encrypted information has already been proven, so the testimony is of null value b) the prosecution is not allowed to use the fact that you know the password in court, and takes the gamble that they can prove access/control some other way (possibly by using contents of the information).
This is, of course, assuming that passwords are classified as "testimony" and therefore protected by the 5th Amendment. If the password is ever recorded on a physical medium such as a piece of paper, that piece of paper is probably not testimony, but rather evidence. This means that, like the key to a safe, it is protected by the 4th Amendment rather than the 5th, and you can be compelled to give up the paper via a warrant. This presents quite a quandary in deciding which is more secure: a 16-character semi-mnemonic memorizable sequence, or a 128-character random sequence that must be stored on a USB stick?
(IANAL, but I've studied the topic as a layman)
Considering that the record for number of decimal places memorized for Pi appears to be 67,890 I'd argue memorizing a 128-character random sequence would be both possible and most secure. ;)
"but the Court has never on any ground, personal privacy included,
applied the Fifth Amendment to prevent the otherwise proper
acquisition or use of evidence which, in the Court's view, did not
involve compelled testimonial self-incrimination of some sort."
"The taxpayer cannot avoid compliance with the subpoena merely by
asserting that the item of evidence which he is required to pro-
duce contains incriminating writing, whether his own or that of
someone else"
"The existence and location of the papers are a foregone conclu-
sion and the taxpayer adds little or nothing to the sum total of
the Government's information by conceding that he in fact has the
papers. Under these circumstances by enforcement of the summons
'no constitutional rights are touched. The question is not of
testimony but of surrender.'"
Fisher largely overturned the earlier (1886) Boyd decision. The court did not expand the Fisher limits until 2000, when the Hubbell decision expanded the testimonial aspect of production and limited the scope of the "foregone conclusion" rationale. For more on the act of production privilege, see http://www.georgemasonlawreview.org/doc/17-3_Cowen.pdfBut this all relies on a particularly narrow reading of the role of the password in these questions. You have no right (Boyd being long overturned) to withhold physical evidence that may incriminates you.
Anyway, this is an interesting area of law and definitely worth watching.
Or maybe they already have this?
What are the laws in the US on this?
Anything that ever touches an ISP is a totally separate issue though. In that case, in the US, any information stored by an ISP can be retrieved without a warrant 6 months (I'd need to confirm its not 120 days) after the incident. Those cases fall under the interpretation of a message overheard. In 5th Amendment cases, if you say a message in a crowded room, you don't have a reasonable expectation of privacy and this is how any message on the internet is interpreted legally. There was also a court case this spring where the DoD sued an ISP to give over IP addresses sooner than the 6 month (120 days?) limit (anyone got a link?). The DoD dropped the case though.
Could the NSA cooperate with the FBI? Yes. Will they? Not if it means they can't spy on Russia anymore.
The NSA don't merely employ scores of cryptanalysts to sit around all day to try to break ciphers (though I expect they do this too). Exploiting mistakes is their bread and butter.
Can anyone name one case where the NSA has ever testified for the prosecution?
On the other hand maybe it would be better to create disinformation that they have cracked all kinds of ciphers or at least their popular implementations? Maybe it will lead enemies to try to implement their own or use alternate implementations that are actually less secure. This will be similar to Airforce's disinformation related to captured UFO tech in the 50s and 60s...
As to proving anything, my understanding is that it is theoretically impossible to prove, but sometimes bugs in the implementation or various user mistakes mean that you can, in practice, sometimes get a good indication that something is hidden,
Although file-hosted TrueCrypt volumes (containers) do not contain any kind of "signature" either (until decrypted, they appear to consist solely of random data), they cannot provide this kind of plausible deniability, because there is practically no plausible explanation for the existence of a file containing solely random data. However, plausible deniability can still be achieved with a file-hosted TrueCrypt volume (container) by creating a hidden volume within it.
It's impossible to tell an encrypted volume header apart from random data. It's very much "try, and if you fail, you either have the wrong key or the volume doesn't exist".
Page: http://iq.org/~proff/rubberhose.org/
Description: http://iq.org/~proff/rubberhose.org/current/src/doc/maruguid...
As for the data loss, if you only enter the first password, it will let you overwrite the space where the hidden encrypted volume is stored yes. How else would it work? If it didn't let you do this, it would be obvious that a hidden container exists...
Edit: OK now I have found evidence to prove myself wrong. At some point in the past I though I had read of a court case where a judge ruled that a defendant had to reveal a password. But a more recent case says otherwise: http://www.usatoday.com/tech/news/techpolicy/2008-02-07-encr...
Depending on the country, the symmetric set difference between the police and "evil criminals" is quite small.
And even then when the police can't torture your officially, they can have ways of torturing you un-officially. They can lock you up with a group of gang members who are on the un-official "payroll" of the police. They rape and torture you until you reveal the password. The case in the media will come out as "my cellmate confessed in a moment of weakness and here is the password".
Pressed by Police, Even Innocent Confess in Japan
http://www.nytimes.com/2007/05/11/world/asia/11japan.html
Also:
Japan is unique among democratic countries in that confessions are obtained from 95% of all people arrested, and that its courts convict 99.9% of all the suspects brought before them. (...) It is how the police obtain these confessions that troubles human-rights activists. A suspect can be held for 48 hours without legal counsel or contact with the outside world. After that, he or she is turned over to the public prosecutor for another 24 hours of grilling. A judge can then grant a further ten days of detention, which can be renewed for another ten days.
That doesn't make either of those right, there is no mistake about that, but the UK police is amongst the most professional forces in the world. Not quite the RCMP but to suggest that they'd torture inmates to get a password is simply nonsense.
http://en.wikipedia.org/wiki/Guildford_Four_and_Maguire_Seve...
http://www.inthenews.co.uk/news/health/crime/death-at-g20-po...
http://www.people.com/people/article/0,,1085543,00.html
http://www.timesonline.co.uk/tol/news/uk/crime/article646643...
http://www.google.ch/webhp?hl=en#hl=en&safe=active&b...
Really? Police in the rest of the world must beat down old ladies for quarters.
In all these scenarios, you're screwed the moment you find yourself in court (actually probably long before then when you convince some law enforcer that you're doing something wrong) Judges and lawyers aren't going to be hip to this hypothetical plausible deniability game.
A drive isn't an extension of your brain or your relationship with your wife. It's physical evidence. The only thing that makes it different than say a really big lock on the door of your house or a safe is the effort it takes to circumvent when a court agrees to admit the evidence. Almost never is that evidence used alone.
There are subtle issues to the meaning of the evidence provided, like you might not need to give up the password and thus decrypt everything else encrypted with it, you might just need to decrypt the data in question in a convincing manner to the court. Being able to decrypt the drive doesn't have to prove that you are responsible for the contents.
There are three essential protections included in the double jeopardy principle, which are:
- being tried for the same crime after an acquittal
- retrial after a conviction, unless the conviction has been reversed, vacated or otherwise nullified
- being punished multiple times for the same offense
London and Wales repealed prohibition against double jeopardy in 2003, so if you live there, you can indeed be tried for the same crime twice.
this wouldn't be double jeopardy. It would be a second instance of him refusing to turn over the passwords. Just as you can be tried twice for murder twice if there are two separate murders, you could be tried twice in this situation.
Assaulting the same person twice would still be two different assaults. Stealing a truck, getting caught and punished, and stealing the same truck again would, to my understanding, not be risk-free, legally speaking. I suspect the same would probably apply here, though given how unintuitive the law is, especially in this area, I may well be dead wrong.
Edit: To clarify, my point is that if the law amounts to "Refusal to turn over requested passwords => jail time", this would seemingly constitute a second refusal, even if the requested password was the same.
The courts aren't run by robots. If it's substantially the same instance of the offence, he couldn't be tried again.
They would send you a letter to go serve in the military, You would go to where you where assigned, You objected because of your conscience, They would then send you to a force labor camp or mental institution for a few years, The hard work, unhealthy food and living conditions, lacking health care, medical experiments, and violence among convicts would often destroy your physical and mental health, Then when you where released, They would send you a letter to serve in the military. … Unless, naturally, your conscience would no longer object to serving in the military…
Note that double jeopardy still applies in all but the most serious cases -- rape, murder, and comparable -- and AIUI charges cannot be brought again unless substantial new evidence comes to light.
[1] http://www.guardian.co.uk/politics/2010/may/27/theresa-may-s...
I wondered what would have happened if he refused to type in the password.
The request to enter a password should be treated as a impolite request, which you should politely deny.
In the US, "customs" typically refer to ICE and TSA, both are enforcement functions of the United States Department of Homeland Security.
Has this been tested yet, out of curiosity?
I remember reading they can deny you entry/exit to the USA if customs can't read your laptop but never heard anything like local/FBI.
If not, I hope it doesn't go before this particular supreme court.
http://www.usatoday.com/tech/news/techpolicy/2008-02-07-encr...
What I hate about all these cases is it comes down to child porn which makes it impossible to defend. Why can't it be something mundane that actually shows why this is a REALLY bad idea.
I just saw a scary university lecture on youtube on why you should NEVER talk to to the police, even to "explain things", even if you know you are 1000% not guilty of whatever they are after. So now it makes perfect sense to me that if they want to go trolling across your hard drive, they are doing exactly that - you are testifying against yourself for whatever charges they want to invent afterwards.
In broader terms yes the system has a way to inflict random punishment on you for disobidience.
In other countries they will just start breaking your fingers, your loved ones fingers, and so on. So the password problem is solved a lot "easier" then.
Obstruction of justice can only be committed by officers of the court or elected officials.
> Or charge you with "contempt of court" and just jail you based on that.
This seems very unlikely given the (1) the 5th amendment and (2) only judges can issue contempt of court citations.
Not true. The same legal term seems to be overloaded and used by state laws. For example from the Commonwealth of Virginia Laws (http://leg1.state.va.us/000/cod/18.2-460.HTM):
> § 18.2-460. Obstructing justice; penalty.
A. If any person without just cause knowingly obstructs a judge, magistrate, justice, juror, attorney for the Commonwealth, witness, any law-enforcement officer, or animal control officer employed pursuant to § 3.2-6555 in the performance of his duties as such or fails or refuses without just cause to cease such obstruction when requested to do so by such judge, magistrate, justice, juror, attorney for the Commonwealth, witness, law-enforcement officer, or animal control officer employed pursuant to § 3.2-6555, he shall be guilty of a Class 1 misdemeanor.
Notice it says "any person" not just elected official.
> This seems very unlikely given the (1) the 5th amendment and (2) only judges can issue contempt of court citations.
Actually it is very likely because of (2).
http://www.reddit.com/comments/afib1/truecrypt_and_the_fifth...
Edit: further evidence for this being a fake:
* This supposedly happened in Februrary 2004, back when TrueCrypt was version 1.0a and barely known.
* His story suggests that his laptop's system drive was encrypted. TrueCrypt added system disk encryption in version 5.0 in 2008.
* He slips up and says he used AES encryption; this is noticed in the comments and he edits it out (I assume).
Personally I am inclined to believe.
Meanwhile, here's a much more reputable source (pointed out elsewhere in these comments) that indicates that this issue is not yet resolved and is currently being tested.
http://cyb3rcrim3.blogspot.com/2009/03/5th-amendment-bummer....
http://cyb3rcrim3.blogspot.com/2010/04/passwords-and-5th-ame...
As an analogy, if you had a safe that contained incriminating evidence and you hid the key, you could be compelled by the court to reveal the location of the key.
* As far as I know (IANAL) whether or not giving up a computer password is considered self-incrimination or not is still undecided.
If they want to take your hard drive or take your computer as evidence they can take it by issuing a warrant. They can argue that your encrypted stuff is really dangerous because it is encrypted but I think they shouldn't be able to make you talk and divulge the encrypted info.
Now that is what "I think" should happen. I believe there will occur some high profile case, that will lead to creation of laws that will either force key escrow, ban encryption, or force you to divulge the password under threat of jail time or very high fines.
Likewise, if you are going to be using the internet for devious purposes drive around and use a neighbor's open wireless network access point, which highly reduces the chances that anything can be traced back to you. Or set up your own unsecured wireless network point and suggest to officers that illegal use came from an outside source.
Not that I want to condone illegal activities, or condone lying to police officers, but to the hacker in me these seem like simple, sensible steps to take that will be more dependable than even a 50 character password.
Of course, IANAL, but that's how I'd do it if I ruled the world...
The modern equivalent is a whole bunch of destroyed media - thumb drives, flash cards or hard drives.
"Sir, we see from your blood sample that you have recently digested some silicon wafer..."
So in summary, I seriously doubt that you can be held responsible for another person's use of your pipe.
But my goal is not to be a smart criminal. My goal is to have a right to privacy to my own stuff.
That said, I don't see why the well-established precedents of opening locked doors and safes shouldn't apply to computers. If you subpoena my safe, I have to open it for you. Otherwise, I certainly won't.
Authorities are very aware of this. One reason for "raids", no knock warrants, arresting you on the road, at work, away from home, etc.
The TrueCrypt section on data leaks (http://www.truecrypt.org/docs/data-leaks) talks about them and how to get round them.
But if you're really serious about these things it's more complex than not storing things on your local drive or even using encryption.
seems like a good reason to have "innocent until proven guilty". drive could contain anything, or nothing.
"TrueCrypt Boot Loader"
No expert is needed to prove that you are using TrueCrypt whole disk encryption. It has a huge stamp right up front.
tom@ubuntu:~$ gpg -v --list-packets flag.png.gpg
:symkey enc packet: version 4, cipher 3, s2k 3, hash 2
salt eae60ad4255dc4e2, count 65536 (96)
gpg: CAST5 encrypted data
OpenPGP encrypted data is easy to find too. It even tells you the algo used. The example is symmetrically encrypted, but it works the same with asymmetric keys. Even shows who it is encrypted for. Edit: formatting.tom@ubuntu:~$ gpg -v --list-packets file.gpg
:pubkey enc packet: version 3, algo 16, keyid 63E6E0BBB9FEE3A5
data: [2045 bits]
data: [2047 bits]
gpg: public key is B9FEE3A5
gpg: using subkey B9FEE3A5 instead of primary key 7A997B0AThen say I notify the cops about your 'illegal' activities.
I'm wondering ... Person A refuses for - pure principle (and maybe some ripped DvD's) Person B refuses for - let's say child pornography and a dirty bomb manual
Both will get the same jail time?
Who here trusts the police to not disclose their HIV status?
If you're in the Unites States, the data is probably protected by HIPAA, the Health Insurance Portability and Accountability Act[1]. HIPAA includes a clause stating that the Attorney General or their designee may issue a subpoena compelling your SO to disclose that information, but only to someone investigating a Federal health care offense.
I've searched through the rest of HIPAA for keywords such as "law enforcement", "criminal", and "disclosure", but I couldn't find anything about being compelled to disclose HIPAA-protected information to law enforcement in any other circumstance than investigation of a Federal health care offense. However, I did not thoroughly read HIPAA, and there might be something in another section of the US Code that's relevant.
Hopefully someone more knowledgeable about this can let me know if I've missed something.
Edit: My understanding of HIPAA was incorrect.
45 C.F.R 164.512:
A covered entity may use or disclose protected health information without the written consent or authorization of the individual... in the situations covered by this section, subject to the applicable requirements of this section.
(a) Standard: Uses and disclosures required by law. (1) A covered entity may use or disclose protected health information to the extent that such use or disclosure is required by law and the use or disclosure complies with and is limited to the relevant requirements of such law.
This would seem to give court orders and criminal subpoenas the power to demand decryption of your hard drive regardless of whatever HIPAA data it contains.
1. HIPAA doesn't apply to you unless you're an employee of a covered entity, that is, a health care provider, health care plan, or a firm contracted by a member of the previous two categories to handle billing. You can hand out your private medical information to whomever you want without worrying about HIPAA.
2. Even if HIPAA did, it doesn't give you the power to refuse to disclose HIPAA data when such disclosure is required by law[1].
[1] 45 CFR 164.512 (a): http://www.publichealthlaw.net/Reader/docs/HIPAA.pdf
The whole law is ridiculous, it also includes unlimited spying by the security services with the bizarre Kafkesque part that you have to cooperate with the spys and it's a crime to inform anyone that you are being spyed on.
The law became a laughing stock when the government claimed it was necessary to fight international terrorism but then had to admit that there had been 1000s of intercepts by local school boards to investigate parents trying to get their kids into better school catchment areas, and city councils tracking cell phone locations to prosecute people for their dog's litter
Things like logs of all the external drives you connect, and links to recently opened files.
"I hate the boarder checks that my home country makes me go through each time I return from Europe!"
unless that was deliberate....
As an American, it seems a bit insane to me for someone to be jailed for refusing to help convict himself.
That said, I can't find such an article, so hopefully I'm making it up and we are indeed safe in our minds.
edit: 'they' being 'the authorities', not the NSA.
I would argue that all evidence is really just information. Once again, the old lines dividing one category from another become blurred.
It would be interesting to know if there was ever a hybrid case where there was a password-protected door with a numeric keypad, and someone refused to give the pw. I'd assume in a case like that, however, the cops would just smash shit out of it.
You're compelled to provide access. You could probably make a legitimate case for not actually revealing the password if you provided access for them.
The police will learn from this and avoid these 'oh dammit' moments by just keylogging everybody from now (or at least those suspected of having encrypted volumes).
Keylogging is the one real weakness of all the TrueCrypt/other encryption schemes (that and your password is in memory in the clear while the volume is mounted, and even afterwards depending on your settings).
As you can imagine, that last bit results in some very complicated situations. The laws governing paedophilia are quite different, with paedophiles having to sign a sex offenders register.
In the case of a sex offender being caught, it's easier to just take the RIPA sentence instead. This is what appears to have happened. I hope the guy's password is long enough otherwise regardless of his crime he's in for a world of pain.
What really happens is the investigators have to answer the 5-Ws (who,what,etc) and they "build" a case against you. If they have one piece, then they can go fishing for the rest. This is why it's important to shut your month when talking to the police. Anything you say at this point can really open you up to all types of crap later. They'll twist your words around, become your friend, good cop/bad cop, mention friends and family and all other types of tricks to get you to talk. Believe it or not, criminals willingly give up testimony about themselves. Some guy in a lab with half a shoeprint isn't what wins the case, you do.
If all the prosecution has is one piece of evidence then a competent barrister can shred it to pieces. This guy's job is to create FUD, and lots of it. The less evidence the prosecution has the easier his job is. But what he/she can't do is fix anything you say in front of the police while he isn't there. This is why it's important to shut up and ask a lawyer first.
Once your file / hidden partition is mounted, it's just another mounted volume. Anything which can read / write to a volume it's not on shouldn't notice a thing.
Also, it looks like it might just be Windows which gets the hidden-OS capability, as it requires a TC boot-loader on-disk or on an external booting device. Which means it should be possible for others as well, but it sounds like they haven't done it yet. http://www.truecrypt.org/docs/?s=hidden-operating-system
http://paulstamatiou.com/review-pgp-whole-disk-encryption-fo...
ISTM a virtual 'locked container of documents' would have the same legal status.
I'm not sure why so many techies go down the Walter-Mittyesque 'Enemy of the State' route when discussing this sort of thing. Mention the police in conjunction with encryption and suddenly everyone's a paranoid compound-dweller...
Let's be clear here - it is unlikely that this guy is making a stand for paranoid techies - it is much more likely that he's got pics and videos on his HDD of kids getting raped that he doesn't want the police to see.
Princess Leia: "The more you tighten your grip, Tarkin, the more star systems will slip through your fingers."