Or maybe they already have this?
Or maybe they already have this?
Although file-hosted TrueCrypt volumes (containers) do not contain any kind of "signature" either (until decrypted, they appear to consist solely of random data), they cannot provide this kind of plausible deniability, because there is practically no plausible explanation for the existence of a file containing solely random data. However, plausible deniability can still be achieved with a file-hosted TrueCrypt volume (container) by creating a hidden volume within it.
It's impossible to tell an encrypted volume header apart from random data. It's very much "try, and if you fail, you either have the wrong key or the volume doesn't exist".
Page: http://iq.org/~proff/rubberhose.org/
Description: http://iq.org/~proff/rubberhose.org/current/src/doc/maruguid...
As to proving anything, my understanding is that it is theoretically impossible to prove, but sometimes bugs in the implementation or various user mistakes mean that you can, in practice, sometimes get a good indication that something is hidden,
As for the data loss, if you only enter the first password, it will let you overwrite the space where the hidden encrypted volume is stored yes. How else would it work? If it didn't let you do this, it would be obvious that a hidden container exists...
Edit: OK now I have found evidence to prove myself wrong. At some point in the past I though I had read of a court case where a judge ruled that a defendant had to reveal a password. But a more recent case says otherwise: http://www.usatoday.com/tech/news/techpolicy/2008-02-07-encr...
Depending on the country, the symmetric set difference between the police and "evil criminals" is quite small.
And even then when the police can't torture your officially, they can have ways of torturing you un-officially. They can lock you up with a group of gang members who are on the un-official "payroll" of the police. They rape and torture you until you reveal the password. The case in the media will come out as "my cellmate confessed in a moment of weakness and here is the password".
Pressed by Police, Even Innocent Confess in Japan
http://www.nytimes.com/2007/05/11/world/asia/11japan.html
Also:
Japan is unique among democratic countries in that confessions are obtained from 95% of all people arrested, and that its courts convict 99.9% of all the suspects brought before them. (...) It is how the police obtain these confessions that troubles human-rights activists. A suspect can be held for 48 hours without legal counsel or contact with the outside world. After that, he or she is turned over to the public prosecutor for another 24 hours of grilling. A judge can then grant a further ten days of detention, which can be renewed for another ten days.
That doesn't make either of those right, there is no mistake about that, but the UK police is amongst the most professional forces in the world. Not quite the RCMP but to suggest that they'd torture inmates to get a password is simply nonsense.
http://en.wikipedia.org/wiki/Guildford_Four_and_Maguire_Seve...
http://www.inthenews.co.uk/news/health/crime/death-at-g20-po...
http://www.people.com/people/article/0,,1085543,00.html
http://www.timesonline.co.uk/tol/news/uk/crime/article646643...
http://www.google.ch/webhp?hl=en#hl=en&safe=active&b...
Really? Police in the rest of the world must beat down old ladies for quarters.
What are the laws in the US on this?
Anything that ever touches an ISP is a totally separate issue though. In that case, in the US, any information stored by an ISP can be retrieved without a warrant 6 months (I'd need to confirm its not 120 days) after the incident. Those cases fall under the interpretation of a message overheard. In 5th Amendment cases, if you say a message in a crowded room, you don't have a reasonable expectation of privacy and this is how any message on the internet is interpreted legally. There was also a court case this spring where the DoD sued an ISP to give over IP addresses sooner than the 6 month (120 days?) limit (anyone got a link?). The DoD dropped the case though.
Could the NSA cooperate with the FBI? Yes. Will they? Not if it means they can't spy on Russia anymore.
On the other hand maybe it would be better to create disinformation that they have cracked all kinds of ciphers or at least their popular implementations? Maybe it will lead enemies to try to implement their own or use alternate implementations that are actually less secure. This will be similar to Airforce's disinformation related to captured UFO tech in the 50s and 60s...
The NSA don't merely employ scores of cryptanalysts to sit around all day to try to break ciphers (though I expect they do this too). Exploiting mistakes is their bread and butter.
Can anyone name one case where the NSA has ever testified for the prosecution?