Suspect can’t be compelled to reveal “64-character” password, court rules
arstechnica.com
arstechnica.com
Francis Rawls has been for years now.
There are too many examples in the US and Australia where LEOs ignore all norms, seeing them as an unjust limit on just power, and manipulate the (asymmetrically well-known) law to retroactively justify any action. Even when LEOs are legally challenged (a rare enough act of courage, and risks further victimization) and time and again get away with it anyway.
And yet, the people who should be clamoring for stricter, fairer justice against LEOs are LEOs, because every time they get away with it, they win the battle but lose the war for legitimacy. When LEOs lose legitimacy, it leads to a cynical world where laws like this password one are expected to be pushed to their absolute limit by LEOs, and it will be, once again, up to the courts to enforce the norm.
I fear that the modern smartphone is just too big of a temptation for centralized authority, because of their universal appeal and potential for as close to a (retroactive AND realtime!) panopticon as we can get without the palantírs from the Tolkien universe.
Why don't we force people to put cameras in every room of their home with full access given to the law enforcement? And if you resist this, do you have something to hide? I think it's interesting how strong this argument is, even in it's most obviously oppressive form. Coming up with an equally satisfying counter-argument is our #1 priority as privacy advocates.
Claim to have forgotten the password to a forum that you haven't used in a very long time? That's quite believable.
Claim to have forgotten the password to, say, your password manager that you successfully have typed from memory several times a day every day for the last 10 years? That's a lot less believable.
The whole point is that they can not be allowed to apply it to your head.
This is the slippery slope of law where basically if they want to get you then they will get you for something.
Of course there is a simple solution. If you have "super secret" type files then you need to encrypt those files then upload them through TOR to a cloud hosting service. Of course per standard opsec protocol make sure you don't use a e-mail that is connected to you (make the e-mail account through TOR). This is how you prevent from being put in a situation where you are compelled to basically release a password.
Every step along the path of doing something anonymously online is difficult. There's nothing simple about it.
Cryptocurrency, Visa/Master Card Gift Cards, "Free" Hosting (things like GitHub Pages), Free Cloud Storage Accounts....
There's probably ways to do it, but I wager they're not "simple" at all. All these companies usually are required by law to make sure they can trace their customers in one way or another (Know Your Customer) and are further incentivized to prevent anonymous usage because such usage is usually done by abusive actors who'll cause problems to the platform.
I'd be very curious to see someone who did it, write up the steps they took (that anyone else could take) to actually host anything online in a truly anonymous and _simple_ manner.
Know your customer is a banking law that banks have to follow for money laundering purposes
I'm not pretending to know every platform out there and every laws, but I think it's fair to say that accomplishing the things GP said is not simple, and that most service provider will need some form of ID somehow. Even ProtonMail will require you to make a payment or provide your phone number if you try to create an account from Tor.
We are the electoral proving grounds for US/UK/CA laws.
It's totally coming for you if you think this is some silly Australian thing.
I deleted a bunch a of old veracrypt drives that I've lost the passwords for and clung onto hoping I'd work it out one day after the laws came in, they've done incredibly well to make encryption seem criminal, it's terrifying and China-esque.
Just like Australia's Gun Ban is unconstitutional under the 2nd Amendment
Second, the protection doesn't apply if you're given immunity (because, again, it's not about blocking access to evidence). So if the court provides immunity and then orders you to reveal the password and you claim you can't because you don't know... the 5th amendment will not help you.
This slope is arbitrary and slippery. There's a reason to stand on the extreme principle here. There are very few violations into a person's right to remain silent that cannot be weaponized.
I'd rather not empower the next arbitrary group of political appointees to wield that kind of power just because you think "the justice system is entitled to" evidence.
That sort of short term thinking without long term consequences does massive damage. Think harder.
Of course, where the line is blurry, is as you rightfully note, beyond a point no justice system can be certain that the defendant really still has access to whatever evidence, be it some part of their mind's contents (so a memory, the location of a body, a password, a face), and even if somehow we know they had access but now they don't it'll be impossible to determine intent. (So destruction of evidence cannot really stand when it comes to forgetting things. Unless, maybe if the defendant caused brain damage to themselves intentionally.)
This phrase doesn't sit well with me. They cannot establish the existence of evidence without having found it. They can't find it without a proper search. They can't execute a proper search with a warrant or reasonable suspicion.
The existence of evidence is established once it's found and documented.
Edited to add: if they can arbitrarily establish the existence of evidence, and then don't find it, then "obviously" the suspect is a no good dirty rotten evidence destroyer.
It's not arbitrary. It depends on other pieces of legal proof, like statements from witnesses, other material evidence, etc. For example in case of hidden partitions people usually get busted because forensics find data directly referring to it (eg. in caches, metadata, logs, thumbnails).
The judge has the power to let them search your property.
Nobody has the power to let them search your mind, and they can only do so by imprisoning you or otherwise depriving you of your rights.
The distinction between a search warrant and self incrimination is a big one. You should always have the right to say nothing.
If forensics and data know for sure you did something, the stuff in your mind is unnecessary. Either they have the weapon or not, so to speak. You shouldnt be placed in a position where the justice department "is entitled to" the knowledge in your head.
Warrants dont establish existence of evidence. they just authorize the state to override your rights, because they convinced a judge. All of this is weaponizable.
The way to establish evidence is to have evidence. If you dont have evidence you haven't established it. Forcing you to divulge something in your head is to force you to give up evidence against yourself, and the ultimate trespass.
I can't think of a situation I'd authorize someone else to do that.
I'm not agreeing with the practice, I just explained it, how pieces of evidence (and testimony) can legally establish that there's evidence that the defendant has ways to produce.
I dont want to live in your society. I don't want to empower anyone to do that to me, even if they claim they're only going to do it to criminals and bad guys.
The terms of service change.
No the purpose of the 5th amendment was to prevent people from being forced to be a witness against themselves, that is why the 5th amendment says
"nor shall be compelled in any criminal case to be a witness against himself"
Forcing to revel what is in your mind (aka a password) is a clear and obvious violation of the 5th amendment, and I do not expect it to be over turned
>Second, the protection doesn't apply if you're given immunity
If they give you immunity then is no longer a case for which they can compel you to give up anything in the first place. Unless they are going after someone else in which case the 5th amendment did not apply in the first place.
I fail to see while this relevant to the discussion.
Also known as a "forced confession"?
> If they give you immunity then is no longer a case for which they can compel you to give up anything in the first place. Unless they are going after someone else in which case the 5th amendment did not apply in the first place.
Two people committing a crime together.
Honestly and fully testifying against one's partner in a jointly commissioned crime would constitute a confession. Immunity allows that testimony.
Not really -- you could be compelled to testify against yourself and not confess to a specific crime, the very fact there is even a trial presupposes one plead "not guilty".
There's already established case law that the 5th protects case combinations; this is the reason why American safes use combinations while those everywhere else in the world use physical keys. Encryption keys are very similar on the face.
The owner is not liable for withholding evidence, even if they know the combination as they are under zero legal requirement to tell the police the combination
I find it completely natural that cannot put people in jail just for possessing something which may possibly be an unbreakable safe just because unbreakable safes happen to exist.
Even then, most encrypted data is indistinguishable from random data. Doing dd bs=1024 count=12345678 < /dev/urandom > childporn.aes on your own machine should not be an one-way ticket to jail. (and not to mention the cases where you have forgotten the password)
It's not just about forced confessions. It's about not putting people -- including innocent people -- into a situation where they have a powerful incentive to lie because silence is prohibited. Even innocent people may have secrets they don't want in the public record, and allowing them to say nothing is better for all parties than dishonesty. Revealing a password is no different. It saves everybody a lot of trouble and crime and immorality to be able to say nothing than to make up some nonsense about how the device belongs to some fictional person that law enforcement would then have to waste resources trying to track down, or worse yet some real innocent person who the person being compelled to testify would then have the incentive to divert blame to.
Moreover, the 5th amendment regularly does block access to evidence which the justice system is otherwise entitled to. If you're accused of committing a murder then the body of the murder victim is evidence which the justice system is otherwise entitled to. They can get a warrant to search your property and seize it if they find it. But the 5th amendment still doesn't allow them to compel you to tell them where it is.
> Second, the protection doesn't apply if you're given immunity (because, again, it's not about blocking access to evidence). So if the court provides immunity and then orders you to reveal the password and you claim you can't because you don't know... the 5th amendment will not help you.
Immunity has very little to do with not knowing. It makes no logical sense that providing immunity could allow you to tell them something you don't actually know. Consequently it makes no sense that providing immunity should allow them to punish you for not knowing. It could allow them to require you to tell them that you don't know, but what then? How do you expect them to prove that you didn't actually forget?
Here's a hypothetical example: you are accused of murdering your ex-lover. You witnessed the crime and know that the real killer is the chief of police. While disclosing those details could potentially implicate him, they will certainly prove that you know details of the crime, which implicates you. You don't think anyone will believe you, and the other evidence against you is weak (you didn't do it, after all), so you don't want to say anything until you're acquitted.
Technically true but misleading. It's true in the same sense as "if I plant evidence to frame you for murder, you could be found guilty of murder". I mean, sure, but that skips over the bit where the prosecution has to prove to a jury, beyond reasonable doubt, that you did actually commit the murder. Or in this case, that the hard drive is filled with encrypted data and that you have the key to it.
In particular, the implication that if the police find some random data that they think is encrypted, you can be convicted just on the assumption that it's encrypted and that you have the key to it (unless you can prove otherwise) is false. If there's enough evidence to raise a question about whether you have the key to something that could be encrypted data, the burden of proof is on the prosecution to prove you do have the key to it (and therefore that it is encrypted data) beyond reasonable doubt: s.53(3) http://www.legislation.gov.uk/ukpga/2000/23/section/53
(to be clear I definitely do agree it's a bad law, just not for burden-of-proof-reversal reasons)
The result is that either the law has no practical effect because anybody can claim they forgot, or the courts fudge the requirement to prove that beyond a reasonable doubt in order to give the law effect, and then you put innocent people behind bars because they really did forget.
They'd ask you to provide actual readable files, pictures, etc, or else would reject your "decryption".
If you intend K to provide "perfectly readable output", then
(1) if you actually produced the contents of D yourself to hide data, then you need to come up with some scheme so that K provides "perfectly readable output" and some alternative V provides D XOR V (or another decryption scheme) that gives you your actual secrets. I don't think it's that easy to have "perfectly readable data" on D XOR K plus have your secrets with another key. Except if you mean through steganography, but then K is not needed at all.
(2) if you were just send a random noise drive to "frame you" then you need access to the drive to come up with a K so that D XOR K decrypts to valid data.
If the format schemes are indistinguishable that's good news.
If it is indistinguishable then you run the risk of losing data in the nested container if you copy enough data (accidentally) on the outer container.
Not sure which is the case with veracrypt though.
IE the first amendment is still solid protection against this kind of insanity.
... and I would say you're falling down on the job ...
This very much depends on the jurisdiction. Outside the US, some require you to provide electronic keys unconditionally in which case "I forgot" isn't a valid defense. Some let you off the hook if you forgot, but only if you can convince them that it's really true.
Then there's the US. Here, AFAIU the court can require you to hand over physical objects which it is certain actually exist. Failure to comply is contempt, and most states don't have a maximum for that (https://psmag.com/news/a-most-uncivil-contempt-3464).
For a password that's not written down, "I forgot" is indeed a valid defense here last I checked. Note that it doesn't apply if the court has a convincing reason to believe you were lying, which they would have in this case obviously.
However! It's more complicated that that here. Whether the court can demand things you know (ex passwords) as opposed to physical objects has historically been contentious. The trouble is that the fifth amendment protects you from being required to testify against yourself, and verbally providing a password seems an awful lot like testimony as it will presumably be used to incriminate you. It's gone both ways, and at some point the Supreme Court stated that a password was roughly equivalent to a physical key and so didn't qualify for protection. This ruling goes against (?) that, stating that it's equivalent to incriminating testimony and so can't be compelled.
The Ars article being discussed is actually where I read that. However, upon attempting to find the original case it looks like SCOTUS hasn't yet heard such. From this Lawfare post, (https://www.lawfareblog.com/fifth-amendment-decryption-and-b...), SCOTUS Fisher v. United States is relevant but doesn't actually involve passwords. Also from that page, the Eleventh Circuit seems to think that government knowledge of incriminating device contents permits forced decryption while the Third Circuit argues that merely knowing you possess the password is sufficient.
In both cases the precedent is that you can be forced to turn over a password; it's only the details of the prerequisite government knowledge that are under debate. As far as I can tell, the current PA case goes against that.
Referenced PA Supreme Court case: https://law.justia.com/cases/pennsylvania/supreme-court/2019...
Related PA Superior Court case that was appealed: https://law.justia.com/cases/pennsylvania/superior-court/201...
This seems like a natural but dangerous argument to make in a world where we are attempting to determine the states of people's minds externally. Even if we could tell the difference between lying and ignorance, is nothing sacred?
There are still good reasons to object. Not going mind diving willy nilly has many other reasons, said invasiveness is both horrifyingly abusable and unduly stressful to the subject.
second, how many recovery processes actually protect the challenge/response information and even require it to generate a new password?
now this won't work for devices secured by password that don't have an outside reset but for online accounts want prevents law enforcement from spoofing the system?
The power to subpoena evidence from the service is powerful and the tool likely to be reached for in such a case. Unless you mean an online account storing encrypted info?
But I think criminals being interrogated aren’t really of sound mind.
I think the point (which bears repeating) is that suspects are not criminals until proven so in a court, and it's important to be careful in our language, especially in our modern times where the court of public opinion operates swiftly and without due process.
While police are allowed to lie, are they allowed to lie to you with regards to what rights you may or may not have? Naively, it would seem so but I'm not aware of any language explicitly allowing deceit on the part of police.
If the contents of the disk are a foregone conclusion (and assuming the article’s framing of the “foregone conclusion” idea is correct, and I’m not even close to being a lawyer so I have no idea) then it seems like a slam dunk that they would be able to compel him to produce the incriminating contents of the disk - but not the password that unlocks the entire disk, presumably including things that don’t have that “foregone conclusion” status. Or they could likely just use his statement as evidence of the content of the disk. Either of those would almost certainly get the conviction they want with far less drama.
It also would've been better had he not been a pedophile and yet... we are here.
https://www.nytimes.com/2011/08/21/opinion/sunday/sex-offend...
When we encrypt information with a key known only within our mind, we are creating a cyborg like extension of our own mind.
It is further impossible to distinguish between won't and can't unlock.
Even if believed that you can subpoena the content of your skull you arrive at a situation where every criminal "can't remember"
The article didn't really argue something like that. It only reported on a court case and really didn't say if they agree with the decision or not.
To simplify it, let's imagine a one time pad encryption. Does the information exist, or does it only exist in potentia? I think there is a good argument in favor of defining it only in terms of potential information as any one time pad can represent any information of the same length (or smaller if we accept padding).
With Schrödinger's cat experiment we could create a similar setup for the journal but it's questionable if we can still apply the perspective that the journal only exist in potentia. From the cat's perspective it knows if it exists or not. The encrypted information however has a more metaphysical environment and it is more questionable if it can be said to have a similar perspective.
The way programs detect if the encryption is successful is usually by looking at the first bits of information with the assumption that random collisions are unlikely to produce an expected pattern. Not all decryption systems does this however and some just give you the data as produced by the given key.
Both are however just technical details in how to turn the potentia of the random-like encryption data into information.
If it's just random bits that you need a one-time pad to decode, then there isn't any information without the decryption key.
If you're encrypting a hard drive, most encryption methods give you full certainty that you've correctly decrypted the text, in the same way that you'd have full certainty that you've correctly opened a safe and found the journal inside.
I was thinking about mention it before when I wrote the above comment but it was already becoming a lengthy comment.
Truecrypt (now Veracrypt) is one of the more popular disk encryption software and was part of at least one US lawsuit in regard to revealing passwords. Truecrypt support a technique called hidden drives. The technique use the fact that free space is indistinguishable from encrypted data, so an attacker can never be fully certain if they have decrypted the whole data or just part of it.
A older and similar concept was/is utilized by Freenet project. Here the data get one-time pad encrypted using existing encrypted data blocks of same size. Each encrypted block then becomes both the key and data from the perspective of the encryption scheme, and the same block can be reused multiple times as one side of the operation for any given number of decrypted data. In order to decrypt a given file you need to first download the map that identify which blocks represent both sides of the one-time pad encryption, then the blocks which combined are twice the size of the decrypted data, and then do the operation. Freenet theorized that since any block could be the key/data for any other block you could never be certain of what information you have stored by looking at a single block. The block is just information in potentia.
It is also important to understand that its not the journal itself that get subpoena. In the later case it is the wall case, with the government arguing that all locked wall cases must contain an unlocked wall case. The conclusion of the existence of an unlocked wall case is thus a forgone conclusion, with the content within being irrelevant to the argument.
The court in this case looked at this and said "The Commonwealth is seeking the password, not as an end, but as a pathway to the files being withheld". This basically mean that they don't accept the argument that the government can request the password based on the simple fact that an encrypted disk exist. Thus the focus is changed away from the container and onto the information within, and here the court do not think the government has enough information to prove a forgone conclusion.
I don't see why a machine organ would be any different.
If it were possible to do it with some sort of scan (reliably!), eventually courts would order those scans.
I mean, that's one of the things we've been doing human experiments with for 30+ years now, via the wireless phone network and wifi. "Hold this radiation emitter next to your brain!" "New radiation patterns for the masses!"
The right to mental privacy will be a great battle of the 21st century.
That's exactly what our computers are. However, it's a mistake to think the government cares or can be persuaded to care.
People in power simply cannot tolerate the notion that something is out of their reach. Encryption is just mathematics but it can render entire governments and militaries powerless. The fact common citizens have access to something like this is an affront to their power.
What's happening in practice is a politico-technological arms race: governments make laws, people make technologies that neutralize those laws. With every iteration, the state must become more invasive and tyrannical in order to maintain the same amount of control over its population.
This is yet another reason why I avoid biometrics for authentication, and I'm glad that the court backed up my assumption that it is more secure. In this particular case, I hope this perpetrator is convicted regardless (assuming he's guilty, that is), but I'm glad the courts agree that nobody should be compelled to give up information. This is a big win for privacy.
So I can choose:
- Unlock my phone with ease for 10’s of years and then quickly lock it once - Struggle to unlock it for 10’s of years to avoid having to quickly lock it once
After which you will need your passcode/word to unlock the device. Handy if you foresee a time you won’t be able to reach your device and tap the unlock button 5 times.
A good habit anyway: you don't want them to be able to poke the ram.
You'd need to do it quickly before the cuffs come on. And make sure the officer doesn't mistake you reaching for your pocket as you grabbing your gun.
The discussion of biometrics is not advanced by parroting this hollow statement again and again. Please stop. There are compelling arguments why biometrics can be problematic. “It’s username not a password” is neither compelling nor truthful.
Your comment, however, has quite an aggressive feel. I don't think it was warranted.
Here's my take on it:
If you enter a passcode anyone close to you can see you enter it. It's much easier to figure out what you're typing on a smartphone than on a keyboard, and the oily residue on the touchscreen makes it even easier.
A fingerprint on the other hand cannot be observed. Someone has to follow you or already know where you live and take fingerprints off doorknobs or something like it. Takes a lot of time and failure rate is still high. Then they have to use it on your device, so they have to have access to the device as well.
Fingerprint scenarios make sense for _targeted_ attacks_ when you are way more likely to be hit by a scalable attack.
It is much easier to brute force your password on a non-proof website or to find it in leaked password database. It scales very well and needs no physical access where no 2FA is enabled.
One could argue that most users still will use weak passwords in combination with biometrics.
Still, it pushes them to at least have a password.
And if you're a more professional user the combination of a strong and random password in a password manager plus fingerprint for convenience seems like an okay trade-off, especially since you will know how to deactivate it temporarily (reboot device or press power button 10 times on iPhone for example).
This is not correct [1].
It won't be that long before someone gets around to training some sort of ML system to scour photographs to extract fingerprints and start building a database of everyone's fingerprints. These databases will only expand in coverage/accuracy and the quantity leaked will only increase. Fingerprints for authentication will not survive the next decade.
[1] https://www.csoonline.com/article/3268837/busted-cops-use-fi...
But I agree that ML scale attacks can definitely change what I wrote in the future. They could also be used for CCTV evaluations of people entering passcodes.
I also believe my comment was entirely warranted. This same misleading talking point comes up nonstop. It is unreasonable that dissent is expected to be buried under a pile of politeness. There was nothing particularly aggressive about the comment except that is was a clear statement of disagreement.
My geek half that believes in strong 4th and 5th Amendment tights and crypto thinks this is a fine decision. My forensics half bets this guy has gigabytes of atrocious child pornography on his system and that CP cases are the motivating factor for the police wanting to decrypt your hard drive in 99 out of 100 cases with a search warrant.
These cases are not abstractions; every pic is of a child who was abused and the perpetrators organize themselves into networks that include distributors and abusers/“content producers.” How is justice served if these networks can’t be rolled up due to full disk encryption?
I like encryption. I don’t want to be compelled to give up my password to a tyrannical government. But I think the tech community is quick to take an absolutist view of the right to strong crypto, and quick to discount that harm can happen as a result. I also don’t think that view is shared by most people... so it seems like a problem worth solving.
I think that demanding citizens incriminate themselves is an especially lazy form of justice.
https://www.schneier.com/academic/paperfiles/paper-keys-unde...
they can be. it just takes more law enforcement effort. they want their jobs to be as easy as possible, even at the expense of civil liberty.
How do you prove possession of CP if all the data is on encrypted drives? What sort of additional effort do you think is necessary?
The prosecution of these cases seems to look a lot like crimes of morality than crimes that directly impact someone else's life and happiness. Sometimes I've heard people say that the mere fact of media existing of a crime that they were in hurts them, and hurts them more when people watch it. But to me, prosecution of these cases, if anything makes one more aware of people watching media of these things, not less.
The thing that bugs me the most about these sorts of prosecutions of "thought crimes" is that the trail from the "thought criminal" to the actual crime is always hazy, and definitely not 1-1.
E.g Imagine someone who was really into collecting child porn as some kind of bizarre stamp collecting type of thing. They were never into it per-se, it was just some kind of messed up hobby. They'd trawl forums on the dark web and download every image they see, maybe write a script to do it. It would be very hard to trace a direct line to a victim there. More likely than not, particularly if no money ever changed hands, there probably wasn't a direct victim. Someone may have paid for it at some time in the past, but not the stamp-collector. It seems like these are crimes that convict people who hurt others, but also those who do not hurt others.
> "We store a wealth of deeply personal information on our electronic devices. The government simply should not put individuals in the no-win situation of choosing between disclosing a password—and turning over everything on these devices—or instead defying a court order to do so."
This is deeply baffling to me as applied to this case. The personal information being ‘protected’ is not his property.
> It’s 64 characters and why would I give that to you. We both know what’s on there. It’s only going to hurt me. No fucking way I’m going to give it to you.
It seems like a totally dumbass thing to say. The standard advice is politely declining to answer, and requesting an attorney.
But at least he didn't lie.
And yes, it's true that the content isn't likely his, in the sense that he generated it or that it's about him. But it would -- as he admitted -- incriminate him. And the court affirmed that he has the right to not incriminate himself.
What's especially interesting is that the court didn't agree that "We both know what’s on there." didn't moot protection against self-incrimination.
Disk encryption tends to use something like AES. Key derivation is usually built on top of hash functions, but a 64-character password has more bits than most people use for AES, so key derivation might not matter.
The implications for AES aren't known yet, beyond effectively reducing the key length[1]. You're probably thinking about prime factoring and RSA, which will be weakened by quantum computing.
[1]: https://security.stackexchange.com/questions/116596/will-qua...
you could argue that things encrypted today might be easily decrypted though
> We both know what’s on there
To be fair, they _could_ claim he's lying there, since neither of them know 100% "what's on there". There are certainly things on the disk that neither one of them are aware of. Sure, it's a technicality, but it's known that the authorities are perfectly happy to use such technicalities against suspects.
But it's pretty clear that he meant child porn. I mean, he even shared some of his favorite themes.
The point, though, is that he didn't need to say any of that.
If the computer required a physical key he would be forced to provide it.
The information being protected isn’t the pictures. It’s everything else on the PC.
Though I guess in this case it’s about providing information in his head?
It's literally self defeating - you could just as easily say that he has no right to privacy for the contents of the harddrive because the contents of his harddrive is "jUsT aN iNtEgEr" and no integers are secret.
Some patterns of bits are clearly and rightfully illegal.
If you take any reference to a concrete phenomenon - the extreme difficulty of policing private data storage and communications - and pigeonhole it into a simplistic caricature, then it's no wonder you see that everywhere?
If most child pornography enthusiasts are caught due to having their computer fixed at Best Buy, have you actually criminalized viewing child pornography, or would it be more appropriate to say that you've criminalized patronizing Best Buy? As stated, that's obviously hyperbolic as bona fide CP enthusiasts are an extreme minority. But we can imagine tripping up innocent people with the letter of the law (eg botnets, teen sexting, unregistered pornography), as well as similar dynamics around much more common "patterns of bits" like say pirated Hollywood movies.
I would say that this is true, the police should be free to try to brute-force his password or crack the encryption used via some other method that does not involve forcing said person to act (such as disclosing his password). Although in said world the police would not have any reason to attempt to decrypt said data as it would be legal.
I'd always argue the latter; as I can kill someone with a rock, but making rocks illegal seems unreasonable.
contents of his harddrive is "jUsT aN iNtEgEr" and no integers are secret.
Right, but the pattern is secret right? If someone happens to derive it by brute-force then, well, secret's out.
But could you give an example of what kind of string could self-incriminate someone?
You can conjure up the previous scenario but not one for this simple case?
“I am guilty of XYZ offense”
Seems like a pretty obvious example.
Go ahead and get arrested and say incriminating statements without context. Let us all know how it goes!
I think they got it right. And as long a prosecution didn’t base their whole case on getting the password, they probably will still prevail.
I assume the prosecution has evidence.
Which is the problem, they only try to push the boundaries on "indefensible" cases (because nobody cares about a pedophile) but then use their newly minted powers on everyone else.