We are the electoral proving grounds for US/UK/CA laws.
It's totally coming for you if you think this is some silly Australian thing.
I deleted a bunch a of old veracrypt drives that I've lost the passwords for and clung onto hoping I'd work it out one day after the laws came in, they've done incredibly well to make encryption seem criminal, it's terrifying and China-esque.
Just like Australia's Gun Ban is unconstitutional under the 2nd Amendment
Second, the protection doesn't apply if you're given immunity (because, again, it's not about blocking access to evidence). So if the court provides immunity and then orders you to reveal the password and you claim you can't because you don't know... the 5th amendment will not help you.
This slope is arbitrary and slippery. There's a reason to stand on the extreme principle here. There are very few violations into a person's right to remain silent that cannot be weaponized.
I'd rather not empower the next arbitrary group of political appointees to wield that kind of power just because you think "the justice system is entitled to" evidence.
That sort of short term thinking without long term consequences does massive damage. Think harder.
Of course, where the line is blurry, is as you rightfully note, beyond a point no justice system can be certain that the defendant really still has access to whatever evidence, be it some part of their mind's contents (so a memory, the location of a body, a password, a face), and even if somehow we know they had access but now they don't it'll be impossible to determine intent. (So destruction of evidence cannot really stand when it comes to forgetting things. Unless, maybe if the defendant caused brain damage to themselves intentionally.)
This phrase doesn't sit well with me. They cannot establish the existence of evidence without having found it. They can't find it without a proper search. They can't execute a proper search with a warrant or reasonable suspicion.
The existence of evidence is established once it's found and documented.
Edited to add: if they can arbitrarily establish the existence of evidence, and then don't find it, then "obviously" the suspect is a no good dirty rotten evidence destroyer.
It's not arbitrary. It depends on other pieces of legal proof, like statements from witnesses, other material evidence, etc. For example in case of hidden partitions people usually get busted because forensics find data directly referring to it (eg. in caches, metadata, logs, thumbnails).
The judge has the power to let them search your property.
Nobody has the power to let them search your mind, and they can only do so by imprisoning you or otherwise depriving you of your rights.
The distinction between a search warrant and self incrimination is a big one. You should always have the right to say nothing.
If forensics and data know for sure you did something, the stuff in your mind is unnecessary. Either they have the weapon or not, so to speak. You shouldnt be placed in a position where the justice department "is entitled to" the knowledge in your head.
Warrants dont establish existence of evidence. they just authorize the state to override your rights, because they convinced a judge. All of this is weaponizable.
The way to establish evidence is to have evidence. If you dont have evidence you haven't established it. Forcing you to divulge something in your head is to force you to give up evidence against yourself, and the ultimate trespass.
I can't think of a situation I'd authorize someone else to do that.
I'm not agreeing with the practice, I just explained it, how pieces of evidence (and testimony) can legally establish that there's evidence that the defendant has ways to produce.
I dont want to live in your society. I don't want to empower anyone to do that to me, even if they claim they're only going to do it to criminals and bad guys.
The terms of service change.
No the purpose of the 5th amendment was to prevent people from being forced to be a witness against themselves, that is why the 5th amendment says
"nor shall be compelled in any criminal case to be a witness against himself"
Forcing to revel what is in your mind (aka a password) is a clear and obvious violation of the 5th amendment, and I do not expect it to be over turned
>Second, the protection doesn't apply if you're given immunity
If they give you immunity then is no longer a case for which they can compel you to give up anything in the first place. Unless they are going after someone else in which case the 5th amendment did not apply in the first place.
I fail to see while this relevant to the discussion.
Also known as a "forced confession"?
> If they give you immunity then is no longer a case for which they can compel you to give up anything in the first place. Unless they are going after someone else in which case the 5th amendment did not apply in the first place.
Two people committing a crime together.
Honestly and fully testifying against one's partner in a jointly commissioned crime would constitute a confession. Immunity allows that testimony.
Not really -- you could be compelled to testify against yourself and not confess to a specific crime, the very fact there is even a trial presupposes one plead "not guilty".
There's already established case law that the 5th protects case combinations; this is the reason why American safes use combinations while those everywhere else in the world use physical keys. Encryption keys are very similar on the face.
The owner is not liable for withholding evidence, even if they know the combination as they are under zero legal requirement to tell the police the combination
I find it completely natural that cannot put people in jail just for possessing something which may possibly be an unbreakable safe just because unbreakable safes happen to exist.
Even then, most encrypted data is indistinguishable from random data. Doing dd bs=1024 count=12345678 < /dev/urandom > childporn.aes on your own machine should not be an one-way ticket to jail. (and not to mention the cases where you have forgotten the password)
It's not just about forced confessions. It's about not putting people -- including innocent people -- into a situation where they have a powerful incentive to lie because silence is prohibited. Even innocent people may have secrets they don't want in the public record, and allowing them to say nothing is better for all parties than dishonesty. Revealing a password is no different. It saves everybody a lot of trouble and crime and immorality to be able to say nothing than to make up some nonsense about how the device belongs to some fictional person that law enforcement would then have to waste resources trying to track down, or worse yet some real innocent person who the person being compelled to testify would then have the incentive to divert blame to.
Moreover, the 5th amendment regularly does block access to evidence which the justice system is otherwise entitled to. If you're accused of committing a murder then the body of the murder victim is evidence which the justice system is otherwise entitled to. They can get a warrant to search your property and seize it if they find it. But the 5th amendment still doesn't allow them to compel you to tell them where it is.
> Second, the protection doesn't apply if you're given immunity (because, again, it's not about blocking access to evidence). So if the court provides immunity and then orders you to reveal the password and you claim you can't because you don't know... the 5th amendment will not help you.
Immunity has very little to do with not knowing. It makes no logical sense that providing immunity could allow you to tell them something you don't actually know. Consequently it makes no sense that providing immunity should allow them to punish you for not knowing. It could allow them to require you to tell them that you don't know, but what then? How do you expect them to prove that you didn't actually forget?
Here's a hypothetical example: you are accused of murdering your ex-lover. You witnessed the crime and know that the real killer is the chief of police. While disclosing those details could potentially implicate him, they will certainly prove that you know details of the crime, which implicates you. You don't think anyone will believe you, and the other evidence against you is weak (you didn't do it, after all), so you don't want to say anything until you're acquitted.
Technically true but misleading. It's true in the same sense as "if I plant evidence to frame you for murder, you could be found guilty of murder". I mean, sure, but that skips over the bit where the prosecution has to prove to a jury, beyond reasonable doubt, that you did actually commit the murder. Or in this case, that the hard drive is filled with encrypted data and that you have the key to it.
In particular, the implication that if the police find some random data that they think is encrypted, you can be convicted just on the assumption that it's encrypted and that you have the key to it (unless you can prove otherwise) is false. If there's enough evidence to raise a question about whether you have the key to something that could be encrypted data, the burden of proof is on the prosecution to prove you do have the key to it (and therefore that it is encrypted data) beyond reasonable doubt: s.53(3) http://www.legislation.gov.uk/ukpga/2000/23/section/53
(to be clear I definitely do agree it's a bad law, just not for burden-of-proof-reversal reasons)
The result is that either the law has no practical effect because anybody can claim they forgot, or the courts fudge the requirement to prove that beyond a reasonable doubt in order to give the law effect, and then you put innocent people behind bars because they really did forget.
They'd ask you to provide actual readable files, pictures, etc, or else would reject your "decryption".
If you intend K to provide "perfectly readable output", then
(1) if you actually produced the contents of D yourself to hide data, then you need to come up with some scheme so that K provides "perfectly readable output" and some alternative V provides D XOR V (or another decryption scheme) that gives you your actual secrets. I don't think it's that easy to have "perfectly readable data" on D XOR K plus have your secrets with another key. Except if you mean through steganography, but then K is not needed at all.
(2) if you were just send a random noise drive to "frame you" then you need access to the drive to come up with a K so that D XOR K decrypts to valid data.
If the format schemes are indistinguishable that's good news.
If it is indistinguishable then you run the risk of losing data in the nested container if you copy enough data (accidentally) on the outer container.
Not sure which is the case with veracrypt though.
IE the first amendment is still solid protection against this kind of insanity.
... and I would say you're falling down on the job ...
There are too many examples in the US and Australia where LEOs ignore all norms, seeing them as an unjust limit on just power, and manipulate the (asymmetrically well-known) law to retroactively justify any action. Even when LEOs are legally challenged (a rare enough act of courage, and risks further victimization) and time and again get away with it anyway.
And yet, the people who should be clamoring for stricter, fairer justice against LEOs are LEOs, because every time they get away with it, they win the battle but lose the war for legitimacy. When LEOs lose legitimacy, it leads to a cynical world where laws like this password one are expected to be pushed to their absolute limit by LEOs, and it will be, once again, up to the courts to enforce the norm.
I fear that the modern smartphone is just too big of a temptation for centralized authority, because of their universal appeal and potential for as close to a (retroactive AND realtime!) panopticon as we can get without the palantírs from the Tolkien universe.
Why don't we force people to put cameras in every room of their home with full access given to the law enforcement? And if you resist this, do you have something to hide? I think it's interesting how strong this argument is, even in it's most obviously oppressive form. Coming up with an equally satisfying counter-argument is our #1 priority as privacy advocates.
Claim to have forgotten the password to a forum that you haven't used in a very long time? That's quite believable.
Claim to have forgotten the password to, say, your password manager that you successfully have typed from memory several times a day every day for the last 10 years? That's a lot less believable.
This very much depends on the jurisdiction. Outside the US, some require you to provide electronic keys unconditionally in which case "I forgot" isn't a valid defense. Some let you off the hook if you forgot, but only if you can convince them that it's really true.
Then there's the US. Here, AFAIU the court can require you to hand over physical objects which it is certain actually exist. Failure to comply is contempt, and most states don't have a maximum for that (https://psmag.com/news/a-most-uncivil-contempt-3464).
For a password that's not written down, "I forgot" is indeed a valid defense here last I checked. Note that it doesn't apply if the court has a convincing reason to believe you were lying, which they would have in this case obviously.
However! It's more complicated that that here. Whether the court can demand things you know (ex passwords) as opposed to physical objects has historically been contentious. The trouble is that the fifth amendment protects you from being required to testify against yourself, and verbally providing a password seems an awful lot like testimony as it will presumably be used to incriminate you. It's gone both ways, and at some point the Supreme Court stated that a password was roughly equivalent to a physical key and so didn't qualify for protection. This ruling goes against (?) that, stating that it's equivalent to incriminating testimony and so can't be compelled.
The Ars article being discussed is actually where I read that. However, upon attempting to find the original case it looks like SCOTUS hasn't yet heard such. From this Lawfare post, (https://www.lawfareblog.com/fifth-amendment-decryption-and-b...), SCOTUS Fisher v. United States is relevant but doesn't actually involve passwords. Also from that page, the Eleventh Circuit seems to think that government knowledge of incriminating device contents permits forced decryption while the Third Circuit argues that merely knowing you possess the password is sufficient.
In both cases the precedent is that you can be forced to turn over a password; it's only the details of the prerequisite government knowledge that are under debate. As far as I can tell, the current PA case goes against that.
Referenced PA Supreme Court case: https://law.justia.com/cases/pennsylvania/supreme-court/2019...
Related PA Superior Court case that was appealed: https://law.justia.com/cases/pennsylvania/superior-court/201...
This is the slippery slope of law where basically if they want to get you then they will get you for something.
Of course there is a simple solution. If you have "super secret" type files then you need to encrypt those files then upload them through TOR to a cloud hosting service. Of course per standard opsec protocol make sure you don't use a e-mail that is connected to you (make the e-mail account through TOR). This is how you prevent from being put in a situation where you are compelled to basically release a password.
Every step along the path of doing something anonymously online is difficult. There's nothing simple about it.
Cryptocurrency, Visa/Master Card Gift Cards, "Free" Hosting (things like GitHub Pages), Free Cloud Storage Accounts....
There's probably ways to do it, but I wager they're not "simple" at all. All these companies usually are required by law to make sure they can trace their customers in one way or another (Know Your Customer) and are further incentivized to prevent anonymous usage because such usage is usually done by abusive actors who'll cause problems to the platform.
I'd be very curious to see someone who did it, write up the steps they took (that anyone else could take) to actually host anything online in a truly anonymous and _simple_ manner.
Know your customer is a banking law that banks have to follow for money laundering purposes
I'm not pretending to know every platform out there and every laws, but I think it's fair to say that accomplishing the things GP said is not simple, and that most service provider will need some form of ID somehow. Even ProtonMail will require you to make a payment or provide your phone number if you try to create an account from Tor.
Francis Rawls has been for years now.
This seems like a natural but dangerous argument to make in a world where we are attempting to determine the states of people's minds externally. Even if we could tell the difference between lying and ignorance, is nothing sacred?
There are still good reasons to object. Not going mind diving willy nilly has many other reasons, said invasiveness is both horrifyingly abusable and unduly stressful to the subject.
The whole point is that they can not be allowed to apply it to your head.
second, how many recovery processes actually protect the challenge/response information and even require it to generate a new password?
now this won't work for devices secured by password that don't have an outside reset but for online accounts want prevents law enforcement from spoofing the system?
The power to subpoena evidence from the service is powerful and the tool likely to be reached for in such a case. Unless you mean an online account storing encrypted info?