Yes - right now, there are people being held indefinitely for not decrypting hard drives the US [1]. The law used is: "All Writs Act (28 U.S.C. § 1651)". As one judge said, "We don't want your password - we just want the hard drives in unencrypted state."
https://www.bleepingcomputer.com/news/legal/man-who-refused-...
However, the story you linked is about a _police officer_ who was suspected of child pornography. His sister reported him to the police and 'content stored on the encrypted hard drive matched file hashes for known child pornography content'.
How can you look in the mirror and think he should go free without the evidence being examined? I couldn't live in a world where a suspect could say "Well, I forgot the password" and walk away Scott-free on such an ugly crime.
This is the price we pay for an imperfect world, I'd rather a few murderers walk than many innocent men be imprisoned. Your balanced, nuanced idealism simply doesn't work at scale, you cannot assume that every judge, jury, and LEO will be good, so you've got to give the criminals rights even if you're pretty sure they're criminals.
As a judge or LEO I'd have a much harder time looking in the mirror knowing I stole an innocent man's life than knowing that I might not have stopped every criminal.
While circumstantial evidence would suggest the cop who is being asked to decrypt his computer is in fact guilty of at the very least looking at child porn, we don't know concretely, yet he is being jailed until the judge decides that he really won't release the password. Imagine a less scrupulous judge and a more innocent man, maybe he's trying to protect the identity of source, suddenly it doesn't seem fair that the man should be jailed, yet in a world where we can compel you to release the password both cases are the same.
If that's evidence enough to hold him in jail indefinitely then it's evidence enough to convict him. So convict him using it. There's no need to force him to self-incriminate.
If it's not evidence enough then the alternative to this is do good police work that doesn't require holding suspects in jail indefinitely until they incriminate themselves.
>I couldn't live in a world where a suspect could say "Well, I forgot the password" and walk away Scott-free on such an ugly crime.
What if it was a slightly different scenario. What if instead of encrypting the child porn he deleted it right before the police came in. Would it be ok if he was held in jail indefinitely until he confessed? What if we just hold all suspects in jail indefinitely until they confess?
> However, the story you linked...
Freedom only works when it also protects things you don't like. Because of that, the specifics of any one case are totally, completely irrelevant.
> I am a privacy advocate and understand the the law can...abuse a forced decryption law.
There is no sentence after that that justifies having a forced decryption law unless "I am a privacy advocate" is a lie, I'm sorry. You don't have to be a privacy advocate, that's fine, but don't wear that mantle if you're not willing to actually advocate for privacy. The entire point is that it doesn't matter what is being kept private.
Upvoted because while I disagree with your thought process it seems like a good-faith question.
Sounds like BS to me, how can they match hash of encrypted content without the key?
I can only surmise that this means that they scanned the content of the hard drives and found data sequences that matched some file hashes of known child pornography.
If they matched the hashes to data on the drive, the files are already on there unencrypted. Could be some space left by a now-deleted unencrypted partition, or maybe some leftover data in a temporary location where the data is saved before being encrypted.
Together with the witness testimony, that seems pretty compelling.
Right!? This sounds like, "We know you have it and we can see it, we just want the password to prove it was _you_ who did it."
Also, whilst I'm here, it does strike me as very odd that the justice system in the United States has such a raging evangelicalism about getting to the truth, that it will impose against a person's rights, just to get at that truth.
To refer to the old Eddie Izzard joke:
"If you commit perjury, I don't care. Don't give a shit. I don't think you should because you grade murder. You have Murder One and Murder Two. You realize that there can be a difference in the level of murder.
So there must be a difference in the level of perjury. Perjury One is when you're saying there's no Holocaust when, you know, 10 million people have died in it, and Perjury Nine, is when you said you shagged someone and you didn't."
The whole precept of the truth being this infallible end-gaol, which must be attained - no matter what, is just as abusively dehumanising as the phrase, "Well, if they weren't doing anything wrong..."
Sorry, wrong meeting... I'll see myself out.
Also, "content stored on the encrypted hard drive matched file hashes for known child pornography content" - this sounds like BS (but do feel free to correct me please), I am not aware of any full-disk-encryption software that stores the unencrypted hash of whole unencrypted files.
This is not novel. It’s always been the rule that the police can force you to turn over evidence in your possession, even though they can’t force you to serve as a “witness” against yourself. The idea that turning over a password is like forcing someone to testify against himself because it involves a mental recollection is already a very stretchy interpretation of the 5th amendment. Extending that even further to situations that aren’t testimonial in any way (Face ID or Touch ID) is hard to defend as a matter of Constitutional interpretation (even if you think it is good policy).
The background principle of the law is that courts are entitled to all the evidence so they can find the truth. The amendments are exceptions to those rules created for specific purposes. But they are exceptions; they are not the rule. To the extent that anyone is trying to “bypass” something, folks reading those amendments unreasonably broadly are trying to bypass the general rule in favor of discovering evidence.
the concept of privacy, outside of say, what a married couple do in the bedroom, didn’t really exist when the constitution was created.
devices that are essentially extensions to ones “self” in the digital world couldn’t even have been imagined, let alone the rights required to make that one as as free as the america that was being created.
And the 4th amendment did protect those things. But those protections also had limits. The police couldn’t get your diary from your desk without a warrant. But they were entitled to it with a proper warrant. The fact that you recorded your deepest thoughts and intimate affairs on a phone rather than a dairy or private correspondence shouldn’t change that.
additionally, one would have to prove an entry in a diary was written by the person that allegedly wrote it. or even that it was owned by that person.
i feel you’re being disingenuous with regard to how much of our lives get recorded, either directly or implicitly, on our devices. concerns on this level simply didn’t exist. giving law enforcement access to your phone is allowing for some level of intrusion into your mind.
i doubt the founding fathers were thinking about how your strava runs could be used to “testify” against yourself, if you happened to be in the wrong place at the wrong time.
It's a bit of a stretch, but I don't think it's _wholly_ without merit.
Amendment IX
The enumeration in the Constitution, of certain rights, shall not be construed to deny or disparage others retained by the people.
Amendment X
The powers not delegated to the United States by the Constitution, nor prohibited by it to the States, are reserved to the States respectively, or to the people.
Moreover, the 4th amendment is usually applied against state police. But the bill of rights originally didn’t apply to the states (until some clever interpretation of the 15th amendment). The state governments are not ones of explicitly enumerated powers. It makes no sense to interpret the 10th amendment to keep states from doing something because it’s not explicitly enumerated in the Constitution, when the whole point is that powers not enumerated are reserved to the States by default.
Unlocking a phone is just another fruit of the forbidden tree.
If you look at the last 20 years, giving law enforcement additional competency didn't improve anything.
If you have evidence of a crime on your phone, it must be part of the process.
There's nothing remotely unlawful about search of property so long as there is merit, oversight, warrant etc..
Ultimately, this will be no different than searching your car.
Now, the cops doing it without a warrant, shenanigans at the border, searchings stuff they should not be - this is all another matter entirely.
There will be some weird scenarios around people 'forgetting' passwords etc. but otherwise, it's just a new angle on the same old thing.
Those who would like to see better judicial reform I think should look elsewhere, into such issues as why/how warrants are issued, the transparency around them, etc..
With fingerprints or face scanning, neither of these is an issue. You put your fingerprint on the device, or you scan your face.
So, I think that forcing someone to reveal a secret that is purely in their head is fundamentally different than compelling other forms of access (physical keys, fingerprint scans, face scans, etc.). The physical access methods can be verified to either work or not. That's not true for mental secrets.
If that is the case then there should be no problem convicting him.
In a filesharing seneario it is common for feds to see what you got before the raid that grabs the physical drive.
The law is actually that physical features/etc can be compelled because they are not testimonial.
“[i]t is compulsion of the accused to exhibit his physical characteristics, not compulsion to disclose any knowledge he might have.”
United States v. Wade
"“the task that Diamond was compelled to perform—to provide his fingerprint—is no more testimonial than furnishing a blood sample, providing handwriting or voice exemplars, standing in a lineup, or wearing particular clothing.”"
State v. Diamond (This is a state case but applying the federal constitution).
Note also that fingerprints are almost always taken at booking, etc. They just aren't transferable in a way that lets the police use them to unlock the phone.
Passcodes, on the other hand are often testimonial. Entering the combination to a safe proves you probably had ownership/control of the safe, for example.
In those situations, generally the government has to be able to prove that you own it. If they can, you will be forced to open the safe.
In the case of phones, the only interesting intermediate cases are phones where ownership can't be proven easily by other evidence.
(Note:I don't necessarily agree with these doctrines, but that is the current law)
Is this not also true for face/fingerprint ID? Proving the face/fingerprint ID proves you probably had ownership control of the device.
We treat biometrics like a secret (i.e. password), but really it's not much better than public information (i.e. username).
:I
Forcing a suspect to divulge information that is directly incriminating will not stand constitutional review, regardless of the nature of the information.
You have the right to remain silent.
Or what if a suspects fingerprint was taken without his consent by the police, and compared against a fingerprint taken from the murder weapon? Is that self incrimination?
I'm not seeing the "self incrimination" angle for face or fingerprint scans here. For classical passwords yes, but not for biometrics.
It is admittedly a weaker argument from a pure physical standpoint but the law doesn't operate based upon that anyway. Any judge would throw out a request in discovery for the defendant to produce a recording confessing their guilt even for legitimate comparative purposes and many other requests or demands that would be unduly prejudicial for 5th amendment reasons.
If they have a warrant to check the phone, and if taking fingerprints of the arrested without consent has already been found constitutional, I just don't see a problem.
Consider the password case, you can't be compelled to give your password, but the government is allowed to throw all of their hacking prowess against your device to crack that password. They can even ask you about the name of your first pet to get through security questions. Though they can't compel you to answer truly regarding the name of your first pet.
Even if your encrypted laptop contains evidence, you cannot plead the fifth if the prosecutors know it’s there. As long as they can get a warrant and when they get the data say “see your honor? Here is the evidence we knew was there!”, it doesn’t fall under the fifth.
Self incrimination would be if you are charged with tax fraud and proof is on your encrypted drive and the prosecution knows this, but also on that drive is records of money laundering, a separate crime they do not know about. This is when pleading the fifth would apply. By decrypting the laptop, you would incriminate yourself in a second crime, that you were not being charged with. Presumably if you were coerced into decrypting the laptop in this case, you could use the argument that the money laundering evidence can not be admitted into court because it was obtained inappropriately.
IANAL and this ain’t legal advice. Stay in school kids.
It depends on what you are charged with.
In a case of say, possession of stolen information, the laws of possession applied to contraband such as drugs would likely apply.
Since the information wouldn't be in your actual possession(literally in your hands or on your person), then they would fall under constructive possession laws.
In most states, constructive possession has 3 parts --
1) You must have knowledge of the presence of the contraband
2) You must know of the contraband's illicit nature
3) You must have the ability to exercise dominion and control over the contraband.
If I slip an encrypted thumb drive full of stolen trade secrets into your suitcase at the airport, you're not automatically in possession of those things because, absent any other information, none of the rules above could be satisfied.
But, if you knew the encryption key to the thumb drive, then that is evidence against you and that knowledge would be protected under the 5th amendment.
If police find a random iPhone in your house that you share with a roommate, they would have to prove constructive possession to tie anything found on that device to you. Knowledge of the password, regardless of what the password is, would be protected under the 5th amendment.
In both cases, the authorities could not compel you to incriminate yourself by forcing you to disclose your knowledge of the password to the device.
IANAL either. If you are ever in such a situation, be prepared to sit in prison for 10 years while you work your way through the appellate courts, because you're in for a long battle.
That sounds like the 'foregone conclusion' doctrine.
When it is a 'foregone conclusion' that the data is present on a device, you can be compelled to produce that data by decryption. However, if you are so compelled, the fact that you were able to decrypt that data can't be used against you. So they will need another way to tie you to the data.
An example is if police saw you had classified documents on your computer (by e.g. a video camera) and later confiscate the computer and find it to be encrypted.
Usually, though, they are going to be after what the password is protecting. If you try to invoke the 5th claiming that admitting knowledge of the password itself would be incriminating, prosecutors can grant you immunity over that and that greatly reduces your 5th Amendment protections with regard to that particular subject.
Police: "We have a warrant for your apartment, let us in"
Suspect: "Sorry, I lost the key when I went hiking in the Rocky Mountains, there's no way in. Oh, and be aware that if you try to force your way in more than 5 times, the apartment will catch fire and destroy everything inside"
What would happen in this case? Can the suspect be held in contempt?
Nominally, the reason they check your bag at the airport is for security. But in the process they can find all sorts of other stuff that isn't dangerous to fly with but is illegal, e.g. marijuana. So the whole thing becomes an avenue to warrantless search.
You can't make the same argument about a computer or phone -- you can't bring down a plane or hurt anyone by having certain pictures on your hard drive. Anything you could do with a phone (e.g. trigger a bomb) would require some other physical infiltration, which hopefully would be caught by all the scanning and searching of people and baggage that we do already.
So I would hope that a sensible explicitly disallows this "airport loophole" in the process of bringing phone search into the normal legal process of warranted search... but I am doubtful. There are powerful people in the USA, UK, Australia, etc. would love the unfettered ability to search the phone of every air traveler.
I agree, the physical phone itself should be part of discovery. Authorities should be allowed to physically disassemble the phone and inspect its insides or run forensic tests on it.
The content on the phone is a matter of interpretation, subject to proper decryption. It is just an idea, no different from decoding ideas in somebody's journal. It makes no sense to talk about discovery of this.
A phone isn't a car. It's an extension of my brain. I use it to store memories that I offload from my brain. As an example I used to have 50 to 100 phone numbers memorized. Now I have zero because they are on the external part of my brain.
I see this as no different than having to decode the secret code in the ledger. You can see the encrypted data. I'm not required to decrypt it. (or am I? I don't know the law on coded ledgers)
Then access it. If you can't access, do good police work and (legally) acquire access to it. If the entire success of your case hinges on convincing someone to incriminate themselves by giving you the password, build a better case before arresting them or tipping them off to the investigation.
> Ultimately, this will be no different than searching your car.
This can be done 100% with the accused's intervention. A LEO can see something that gives them probable cause for a warrant. A locksmith can open the car or the LEO can simply break the window and unlock it.
Just because the police don't have the technical ability to get into a phone without the user's intervention doesn't mean that person should be forced to divulge information that could incriminate them.
But, unlocking a phone should come with a lot of paper work and checks and balances to ensure that it's done only when really required?
I imagine the situation with electronics will be similar. If a key to, say, an encrypted volume is stored on a flash drive then they may compel someone to produce it (analogous to a safe key). But if the drive is protected by a password, then the government cannot compel someone to provide the secret.
Another circuit will disagree with the 9th circuit and the supreme is forced to take the case, they wont uphold a novel 9th circuit ruling
There isnt an interpretation of the constitution possible for them to, and a the composition of the court makes this even more unlikely to pluck from thin air
NEVER use a fingerprint or an iris scan for a password. That's insane!
Just don't do it.
This idea that digital security is going to solve for physical violence is absurd unless you’re willing to die to protect your digital assets.
I feel like that's getting the threat model wrong. The mugger wants to spend as little time with you as possible. If a fingerprint is needed to make purchases, then it can actually be significantly better than a PIN, and even a PIN is a lot better than nothing because they have to memorize it.
But my response is to the belief that a security factor that cannot be directly taken by force is somehow more secure. If you’re guarding The Football, sure. You might actually be willing to die for that. If you’re willing to die rather than reveal your PIN to a mugger, though, your advice is not applicable to the vast majority of the population who value their lives more than their bank accounts.
I have noted that spiteful to lethal anti coercion measures seem surprisingly rare given the premium paid for security and even when a lesser value to human life is assigned. They would use ink bombs for robbers and not time delayed or remote triggered fragmentation bombs with the loot. I assume relative rarity and baseline risks (even military bases in hostile regions tend to restrict arms to the armory except for MPs, on duty soldiers, and maybe personal side arms for ranking officers who keep it holstered most of the time as opposed to readied) and margins are why even in places where security is tenuous enough that foreign businesses travel arrangements include at least one mercenary with an AK47 or its descendant as a guide, driver and bodyguard due to their guest being a relative king's ransom.
Theoretically ATMs could be fortress panopticons watched 24-7 and with a SWAT team readied to deal with compelled withdrawals but that just plain wouldn't be a sensible use of resources - cameras, willingness to write off or insure losses and policing makes far more sense.
edit: - sorry if it's annoying but for me it was a very graphical way to always remember this issue.
https://www.theregister.co.uk/2002/05/16/gummi_bears_defeat_...
(Edit: OK, I'm confused. There doesn't seem to be an option to disable the emergency trigger entirely, but there's an "Auto Call" slider whose relationship to the feature is unclear. This slider is turned off, yet the phone still went into emergency mode when I clicked the button a few times. What a half-assed feature, sadly typical of Apple's work lately.)
What a sentence.
Replace every instance of "New Biometric Tech" with "Social Security Number".