TrueCrypt User Held in Contempt of Court
forums.truecrypt.org
forums.truecrypt.org
Secondly, the fifth amendment of the US Constitution allows you to refuse to provide testimony which you feel may incriminate you. Generally encryption pass phrases do not count as testimony, the legal system treats them as keys. And that would be covered under the fourth amendment which says the government cannot compel to you to give access to your property for search unless they have probable cause.
If they do have probable cause, they get a warrant which gives them the power to do the search temporarily and only for what they think exists. So if you get a warrant to search your hard drive for something, you are compelled to give them the password just like you are compelled to let them into your house if they have a warrant to search for something like drugs or guns or counterfeit plush toys.
However sometimes the courts do see it as a fifth amendment issue [1] and that has been under debate for a while. (As far as I can tell the legal theory is similar to the police not being able to compel you to tell them where you left the body in a capital crime.)
Disclaimer I am not a lawyer this isn't legal advice, and I've not followed up the cited case to see if it made it to the supreme court or not. Any circuit level decision would not be binding on different circuits.
[1] http://news.cnet.com/8301-13578_3-9854034-38.html
Follow up on the Boucher case: https://secure.wikimedia.org/wikipedia/en/wiki/United_States...
Where the fifth amendment defense was overturned.
Plaintiff: "There was a dead-body in the toilet, but the defendant has been regularly flushing, thereby destroying the evidence and proving his guilt."
Judge: "Well, if you say it, it must be true!"
Wouldn't it be a violation of the 5th amendment to be compelled to provide that passphrase, because it is an admission against interest and therefore would be admissible if you disclosed it? Wouldn't it also serve to waive 5th amendment privilege, and possibly put you at risk of being forced to take the stand?
If it were an admission of a different crime, a court could grant you immunity on those unrelated charges, but if it is relevant to the crime the government is investigating by asking you to reveal your passphrase... how can anyone, luddite judge or not, separate "key" from "testimony" in that circumstance?
You do have the right to remain silent, however. That might be a stronger defense.
The evidence is what it is, the court is there to judge it.
There have in fact been a few instances where judges have determined that providing a password does constitute giving testimony.
http://www.easterndistrictblog.com/?p=57
and older
http://mises.org/Community/blogs/crypto/archive/2007/12/18/c...
Where did you put your ex-wife's body Mr Johnson, we know you killed her? Just point at the map, you do not even have to say anything.
You could have cat pictures encrypted with passphrase A and incriminating evidence (that stands up to the best forensic analysis currently available) encrypted with passphrase B and they wouldn't know which is which, if they unlocked ALL the data, or what.
Truecrypt is AMAZING and anyone holding onto stuff that might get them into trouble (esp. w/ foreign gov'ts) should use it.
http://en.wikipedia.org/wiki/Fifth_Amendment_to_the_United_S...
"If the government gives an individual immunity, then that individual may be compelled to testify. Immunity may be "transactional immunity" or "use immunity"; in the former, the witness is immune from prosecution for offenses related to the testimony; in the latter, the witness may be prosecuted, but his testimony may not be used against him. In Kastigar v. United States, 406 U.S. 441 (1972), the Supreme Court held that the government need only grant use immunity to compel testimony. The use immunity, however, must extend not only to the testimony made by the witness, but also to all evidence derived therefrom. This scenario most commonly arises in cases related to organized crime."
http://en.wikipedia.org/wiki/Use%E2%80%93mention_distinction
In the context of testimony, I'd argue (as a philosopher, not a lawyer) that a mention does not count as testimony and cannot be used against you. Obviously, an observation of the mention could lead the police to consider other avenues of investigation however.
I can see this as still incriminating himself no?
[1] https://secure.wikimedia.org/wikipedia/en/wiki/United_States...
Does US law require me to open the door of my house to the police if they have a warrant?
In lots of countries a warrant allows the police to search your house, but it does not require your cooperation. You may not actively hinder the police from doing their task, but you, e.g., do not need to open the door.
Its a good question, you are required to co-operate with the authorities in the lawful execution of their job. The term 'lawful' is, of course, subject to legal interpretation.
Police have arrested people for filming them arresting others, typically the scenario is "They ask the person filming to stop while they are doing their job, person doesn't, they arrest them for interfering with an officer." (sister-in-law is a public defender, I get to hear all the excuses). So far the California lower courts are still fumbling around this issue. I expect it to make it to the ninth circuit sometime later this year or early next year.
The question of "Can you make a house that the police can't search without your co-operation?" is a good one, and I'll ask my lawyer friends if that approach has been taken yet. Generally a subpoena is the court ordering you to co-operate and generally you must (or be held in contempt of court).
So I expect such cases would go "give us your hard drive" followed by "give us the key", followed by a refusal, followed by a subpoena, followed by another refusal, followed by being in jail for contempt.
If you did shred your key so that you literally cannot decrypt the drive, then I would expect you to spend a few days in jail (so that the prosecutor could prove to themselves you are serious) and then they would return your drive after re-formatting it. How they would justify that I do not know but I know that they would try.
does not make much sense to me...
If I delete all of my email today, I'm not committing a crime. But if I find out that my company is being sued for breach of a contract that I was working on, deleting email becomes suspicious.
Then, do just that.
If a civil or criminal case is brought against you the law says you must stop any routine houskeeping tasks like that to preserve evidence, but the most you'd have then is 4 weeks worth. Much better than 4 years.
There are two ways to avoid this, either build a house with no doors, or don't have one.
Since hidden volumes are an optional feature and - again, in theory - cannot be proven to exist, you can always claim that this is the only password. Even if the judge/attorney knows a thing or two about true crypt.
1: https://secure.wikimedia.org/wikipedia/en/wiki/Plausible_den...
You might also be missing something about TrueCrypt: plausible deniability. You can have different passphrases that unlock different things. You could provide them with a passphrase the only unlocks innocent documents when really you have CP stored using a DIFFERENT pass phrase -- any this would stand up to any cryptographical analysis -- they simply cannot PROVE that the CP exists or even that more encrypted data exists.
The analogy to a key isn't quite valid here; it's more like the doors in that hallway in the matrix. If you use key A in the door, you will get content A. However, you can use a different key, open the door, and it'll go somewhere else entirely. Also, if you rip the door off the wall, there is just the wall behind it. Crazy stuff, that.
For instance, if it's child porn, he'd be labeled a sexual predator for life. If it's state secrets, he'd be facing treason and espionage charges. If it's mp3s.. financial ruin on top of the felony charge..
"nor shall be compelled in any criminal case to be a witness against himself"
This situation stinks, for sure. If you want to protect yourself, use shadow volumes. Far better solution than questionable legal arguments.
As for shadow volumes, that's a whole other kettle of fish. I'm sure it won't be quite that simple - if your VLC history has a link to /shadow-volume/pirate_movie.avi then they may be able to compel you to decrypt it.
Granted, if we were working for the prosecutor we would be able to put 2 and 2 together ... but ... these are the same morons who just a few days ago grabbed an entire rack instead of one server, not being able to tell the difference.
You're giving them too much credit.
Anyway, as of right now, cops/prosecutor only get real excited if there's naked children involved ... and frankly, you shouldn't be doing that sort of shit anyway. Just jerk off to normal porn like everybody else, problem solved.
> Just jerk off to normal porn like everybody else, problem solved.
sigh
First they came for those accused of pedophilia, and I said nothing because I wasn't accused of pedophilia.
The FBI agents who did that are very much not prosecutors (and we still don't know why the FBI did that; it may have been intentional).
Can I go to federal prison if the police ask to me translate some paper in foreign language I happen to have in my pocket and i refuse/don't know the language?
I myself may not know how to read what is on the paper
If you think things are confusing now, wait until merely sticking electrodes on someone's head and making them think about certain things by talking to them, without requiring any voluntary response, can generate usable evidence.
Requiring someone to reveal a passphrase or access procedure to reveal encrypted or otherwise secured evidence, external to the brain, is the tip of the iceberg.
But we have never held, as the Supreme Court of Ohio did, that the privilege is unavailable to those who claim innocence. To the contrary, we have emphasized that one of the Fifth Amendment's "basic functions ... is to protect innocent men ... 'who otherwise might be ensnared by ambiguous circumstances.' " Grunewald v. United States, 353 U. S. 391, 421 (1957) (quoting Slochower v. Board of Higher Ed. of New York City, 350 U. S. 551, 557-558 (1956)) (emphasis in original). In Grunewald, we recognized that truthful responses of an innocent witness, as well as those of a wrongdoer, may provide the government with incriminating evidence from the speaker's own mouth. 353 U. S., at 421-422.
-- Supreme Court in Ohio v Matthew Reiner, http://caselaw.lp.findlaw.com/cgi-bin/getcase.pl?court=US...
The fifth protect you from having to compel a statement, since you can then be declared guilty for either: any invented crime you testify you did (if you testify as they want you to); perjury (if you testify, but not what they want you to say); contempt of court (if you refuse to testify).
Let's not jump to conclusions just yet. He was arrested on April 14th. Find out the full case history, what was said, what he's accused of, etc.
It's entirely reasonable to assist anyone who's rights are being violated. But keep that separate from what he's accused of.
Searching on the address finds some info, but the names do not match up. There is a phone number listed however. Im not calling it though.
I guess they can't prove that there is a hidden volume, but I thought with Truecrypt they could not prove whether a file was actually a Truecrypt volume in the first place?
I'm not saying plausible deniability is bad, just that it would be better not to rely on technical arms races to protect fundamental rights.
The Passive Aggressive Award will go to the guy who freely gives the real password to the feds when subpoenaed, but claims it is just a hidden volume password.
If you do accidentally tell them, it's a bad thing. Generally, you should only take advantage of this if 1) the punishment for whatever you have in the hidden volume is bad enough that the addition of perjury charges would be like adding a single spike to an atomic bomb, or 2) you are absolutely sure that they're not going to figure out the existence of it from anything you have lying around or other people.
This is not legal advice, I'm not a lawyer.
>There is an article about all the small things to watch on the Truecrypt website.
There is an article about all the tricky things to watch for. They're not any smaller than any other booleans on your system, and with software like encase, such inconsistencies will be found.
> I recommend creating a hidden volume in any encrypted container...
Do you not want the recommendees to enjoy plausible deniability? After all, if they always create a hidden volume, they could reasonably be held in contempt for refusing to give two passwords for every volume.
The law here says that you must assist the police to access data if ordered by a magistrate. The magistrate must be satisfied that you can provide that assistance, but he doesn't ask you before issuing the order - he makes the decision based on what the police tell him. Once that order is issued you commit an offence if you don't comply with it. Your reasons for not complying are irrelevant. (I'm not a laywer, etc...)
Did he forget his TrueCrypt password?
Maybe he was using keyfiles?
In most European countries (that do not have specific crypto laws) you neither need to give the judge any information (except your name and address), nor help the prosecutor (i.e., the judge cannot order you to open a safe, but of course he can try to break the safe hismelf).
To answer your question directly: No, it applies to all methods of communication.
http://en.wikipedia.org/wiki/Right_to_silence#United_States
"...the U.S. District Court for Vermont ruled that because the defendant had already cooperated as far as he had and already potentially incriminated himself, by stating his ownership of his laptop and providing law enforcement with partial access to it prior to his arrest, that he must now surrender complete access to all information on that laptop, even encrypted and potentially self-incriminating or confidential information.[20] Because the defendant had cooperated in part already, the Court ruled that the defendant must continue cooperation and provide the decrypted and potentially harmful information to the government..."
It is. That's what I meant by being in custody (arrested).
or
Ignoring the details of this case, what if the court is ordering you to decrypt something that isn't even encrypted? It's just random data? They assume it is. You assume it isn't.
I suppose in this case, the fact that the someone of authority already saw unencrypted contents gives them enough reason to be confident the drive is encrypted and the defendant has the ability to decrypt it.
Google searches for '"Matthew Bumgardner" arrest' or '"Matthew Bumgardner" truecrypt' were unhelpful. It appears that this story hasn't had any media attention.
But this is why the RECAP project exists - to jail-break the PACER documents you pay for: https://www.recapthelaw.org/
What you're trying to do here is obvious, and I don't like it one bit. Everyone is innocent until proven guilty. You're trying to introduce bias, and shame on you for doing it.
The fact of the matter is that even if the first sentence of his message stated that he was being held on child pornography charges, I would still back his right to not have to reveal his key. That's ridiculously lazy policing.
However, the omission of what his charges are from such a thorough message is extremely conspicuous. I could pretend to be a string parsing robot and only act on what the message itself contained... Or I could use my full brain like a human and make some reasonable assumptions. He's probably been accused of something pretty bad to leave it out like he did.
It's funny that in then contest to appear dispassionate and just people, even in an intelligent community such as this, handicap themselves. We're not better for having done so.
First, the guy could be accused of choking babies to death with child porn and that wouldn't make a damn bit of difference as far as his, and the rest of our, fundamental rights are concerned.
Second, accused (or even indicted) is absolutely different than convicted, which itself bears an indirect relationship to 'true'.
Third, courts typically don't post private proceedings on the internet - you'd be amazed how many things you wouldn't be able to "find anything" about via a google search. If he's being held for contempt in relation to a case that he's not actually a defendant in, I imagine it'd be really bloody difficult to find a whole lot about that online, and in either case I can't imagine any sane lawyer giving him the green light to post on the internet details about a case for which he's already being held in contempt.
But by all means, don't let me stop you from impugning the integrity of a man you admit to knowing nothing at all about.
I can't imagine a lawyer giving him the green light to post on the internet asking people who don't know anything about the case to spam the judge and prosecutor, either.
In fact, he states that he doesn't have a lawyer.
If he expects people to write letters, he needs to explain WHY they need to write letters. That requires telling us what the case is actually about.
A self-destroying drive would likely get you a conviction for obstructing justice, just like shredding the contents of a safe would.
What level of data protection counts as contempt or obstruction? What if I have provided the courts with all of the data, but for some reason they suspect there's more that I'm hiding? What if I honestly can not remember the password for some of my old data? Do I go to jail because my memory is gone?
Encrypted data isn't so clear cut. It's trivial to make a datastore that has several encryption keys, so that you could give out one key, and it'd "decrypt" to some boring stuff, whilst keeping the real data, and the alternate key, secret.
It'd also be trivial to devise a decryption algorithm, and key, which "decrypts" anyones hard drive to reveal illegal images even when none are really there...
So I don't think it's a good analogy. It's quite obvious when you have successfully got into a safe, but how do you know when you have successfully decrypted something, to the real stuff that is important and being hidden in it?
If we assume the courts can order you to decrypt the drive (and without debating that point) - one has to consider that the court may be fully aware that the system has multiple hidden volumes, either by eyewitness testimony, 3rd party evidence (check out truecrypt's warnings on their site about full system encryption and what to watch out for. Things like finding the same windows installation doing every update twice. There are all kinds of information leaks that COULD pop up.
I'm not saying it's impossible - just as strong cryptography, which is easy and is all over, doesn't mean all our data is secure, neither would a more complex system like this protect someone from the legal system.
You can use one algorithm to encrypt/decrypt the original content. But you can use a different algorithm (with a different key) that would output a different output.
The secondary algorithm would be one that given a some text (ciphertext from the original encryption) along with the desired output, would return a suitable key. The most basic example to prove the point would be XOR.
If you give a password, the cops will know what algorithm they must use (2 trials at most). Even if they don't know before hand which algorithm points to the real data, they can notice that it doesn't use all data.
With your method, you can at best cast doubt: is the data not extracted real data encrypted differently (algorithm or key), or random data that the software insert by default to give everyone plausible deniability?
http://en.wikipedia.org/wiki/The_Mystery_of_Al_Capone%27s_Va...
How trivial? Remember that the whole hard drive must be consistent, including a file system. Fifty gigabytes of garbage followed by a 2-megabyte photograph followed by fifty more gigabytes of noise is not plausible.
Well the revealed images could not be significantly larger in size than then the "key material" you supplied plus the most concise description of the algorithm. http://en.wikipedia.org/wiki/Kolmogorov_complexity
Disclaimer: I am not a lawyer. Most of what I know about this is from the last twenty minutes of googling.
In 2007 a federal judge ruled that passwords aren't like keys to a safe, and that the government can't force somebody to hand them over. (United States v. Boucher http://news.cnet.com/8301-13578_3-9834495-38.html )
However, that decision was partially overruled in 2009. ( http://www.bennettandbennett.com/node/5608 ) The judge ruled that the defendant didn't have to provide his password, but he did have to provide the contents on the hard drive. In other words, if the defendant happend to have an unencrypted copy of the hard drive hidden away somewhere he could have offered that in place of the password.
Using your safe analogy, it would be like saying that you don't have to provide the government with the key to the safe, but you do have to provide them with an identical copy of everything contained within the safe.
Now, like me you're probably wondering how the government could prove that the contents you provide from a secondary source really matches up with what's on the encrypted drive. The Boucher case mentioned above was unique because border control agents had already viewed the contents of the guy's laptop in unencrypted form, so they knew what to expect. (In his case, child porn.)
From what I can find, there don't appear to be any laws in the U.S. (and no case law) which specifically require people to hand over their passwords at the government's request.
Here are two more links I found which were helpful: http://volokh.com/files/BoucherDCT.1.pdf and http://en.wikipedia.org/wiki/United_States_v._Boucher
That data, would of course be the actual key used to encrypt the drive.
It seems that the primary contention here is whether a password constitutes physical evidence, which must be supplied upon the production of the correct edicts, or whether it constitutes "testimony", which I interpret to mean non-recorded ideation or mental processes. Supposedly the same argument could apply to a safe combination, hence a defendant cannot be compelled to reveal a combo but can be compelled to open the safe. But how do we prove that the defendant has access to the safe? And how do we prove that the defendant has access to the encrypted files?
IANAL but this question particularly is of course interesting to me. At first glance it seems that the 5th Amendment guarantee against self-incrimination would preclude decrypting drives and I've read several proclamations to that effect, but when we consider the rules surrounding surrender of physical evidence, including evidence contained in a safe, it does become less clear where information cryptography fits.
If a defendant handwrites letters in a custom cipher, can he be compelled to reveal the cipher or decode the letter? Perhaps that's a better analog than the safe in our situation.
Can the defendant even be compelled to open a safe? Suppose you have a case in which the defendant has either specifically disclaimed ownership of the safe in question or disclaims any knowledge of the combination or has flatly refused to either confirm or deny ownership of the safe or knowledge of its combination on fifth amendment grounds. I'm no lawyer, but I suspect the standard procedure in such cases is that the judge issues a warrant that permits police to access the contents of the safe and no burden is placed on the defendant to do anything at all. Rather, because they have a warrant for the contents of the safe, the police are entitled to open it and they do just that, using a locksmith or mechanical means to force it open. The analogous situation with respect to encrypted data would be that the police are welcome to crack the encryption themselves by whatever means they deem appropriate, but the defendant isn't required to do their work for them.
* Existence of a lawful order
* The contemnor's knowledge of the order
* The contemnor's ability to comply
* The contemnor's failure to comply
It seems to me that the prosecutor cannot prove the contemnor's ability to comply, in the case of a forgotten password.Simple as that, right? They can't compel you to remember information you never had in memory. It's probably too late, as he's likely admitted to remembering the password. Dumb move.
Does anyone know why it is important that a password can be more than 64 characters? Is he just saying "which makes it very hard to remember", or is there some legal significance to very long passwords?
(good point though, +reply, -op though.)
See: Cool Hand Luke http://www.imdb.com/title/tt0061512/
To anyone reading this thread-if you want a quicker response to your
comments or questions, send them to me at:
Matthew Bumgardner
Santa Rosa County Jail
P.O. Box 7129
Milton, FL 32572
Right now it takes about 3 weeks for a post on this forum to get to me,
receive an answer, then have the answer sent back to my sister so she can
post it here.
This is Matthew Bumgardner, the one in jail. I have given this note to my
sister so that it can be posted. Obviously I have no access to email, so this
is the best I can do. Eventually I will get a copy of the posts in this thread
and I will respond when I can. My sister should have already posted the letter
I wrote. Every word is true. There are a few things I would like to add. First,
this jail could generate some serious money for a decent civil rights attorney.
They are already being sued for their mail policy. Inmates can only write on
postcards. They can only send letters to attorneys, members of the media and public
officials. If you were in here and wanted to write a family member, all you could
send was a post card.
The jail also denies access to legal materials. Their policy states that
"inmates will be afforded reasonable access to the courts. This is accomplished
by way of your attorney or public defender." This is a joke, since some inmates
wait 6 months or moe to see their public defender. The policy goes on to state
that pro se inmates must obtain a court order granting them pro se status in
order to get access to the Law Library.
I am a pro se inmate. I have obtained a Court Order granting me pro status.
I have provided that document to the jail staff, and I am still being denied access.
I have filed a new motion requesting an Order to allow me access to the Law Library
and I have also written the judge. I am waiting to see what happens there. I also
ahe a problem getting copies made. When I give my documents to the person making copies,
I inform them that I need them returned immediately. The past two times it has taken
several days fro the copies to be made. This is intentional. Since I am a Federal
inmate the Government pays the jail or me to be here. They make decent money off of
so, so there is no incentive for them to assist in my release.
Although it may seem unnecessary to complain about the jail, it is actually important.
The US attorney and judge that put me here knew exactly what they were doing. They
figured that the constraints imposed by the jail would allow them to maintain their
secrecy. They are wrong. It certainly slows things down, but I will not remain
silent about this.
This issue is more important that you might realize. Right now, this US
Attorney and US District Judge think that holding people in contempt is the way to
deal with encryption. If you read this and still do nothing, then you are telling
them that they are right. You are telling tem that the 5th Amendment is no longer
needed, and that they can issue supoenas that compel acts which are oppressive,
unreasonable and not possible.
I am not asking for my own personal army to help fight this. If you think that
you are my army, you misunderstand this situation. I am your army in this battle.
If you use encryption, or any password protected file, then this issue affects you.
You could be thrown in jail and denied civil rights at the whim of the government.
I am fighting this battle on my own, and I am willing to continue to do so. The
outcome is going to possibly affect many more people. To me, it seems like more
people should be getting involved.
At the very least write the attorney and judge and tell them that what they did
was wrong. Tell them that True Crypt can use more than just a password. Tell them
that a password can be 64 characters long. Tell them they have no right to hold
someone in contempt for failing to produce documents they have never seen. Tell
them that the precedent in US vs. Hubbell and In Boucher II proves that they
are wrong.
The addresses are:
David L. Goldberg
Assistant U.S. Attorney
21 E. Garden Street, Suite 400
Pensacola, FL 32502
Lacey A. Collier
Sr. U.S. District Judge
United States Courthouse
One NOrth Palafax Street
Pensacola, FL 32502
If you don't have time to write a letter, at the very least please forward this
to everyone you now. E-mail it to any media outlet you can think of. If enough
people e-mail tis, a major media outlet might pick up the story.
The Government can only do this in secrecy. If more people know about this it
never would have happened.
Thanks i advance for any assistance you can provide.