Irish police to be given powers over passwords
bbc.com
bbc.com
- An officer can use these requirements on anyone who "appears to him or her to have access". They don't appear to need any evidence beyond that. The person does not need to be a suspect or, it appears, the subject of a warrant, just a person present at the location subject to the search warrant.
- It applies not just to access to information on the device, but information "which can be accessed by the use of that computer", and thus presumably includes information that is on other machine, or potentially not even in Ireland or the EU.
- It allows officers to freely operate computers on site during a search (this seems like horrible forensic practice?), and use passwords found on the site to try to access any information accessible from the computer.
- It does not just include disclosing passwords. It includes "any password or encryption key", and anything "to otherwise enable [the officer] to examine the information accessible by the computer".
- It even appears that it allows officers to compel people not just to disclose passwords but to actually operate the device for them so as to enable information access, and "to produce the information in a form in which it can be removed".
- It is not clear to me that there is any restriction on the scope of information, so long as it is in some way accessible.
- Head 17 appears to allow even legally (or otherwise) privileged information to be seized, so long as "the confidentiality of the material can be maintained pending the determination by the court of the issue as to whether the material is privileged material".
Combining these powers would seem to be able to result in ridiculous situations, for example, forcing a person to take data from a US server using an SSH key on their laptop, potentially violating US law by doing so, and for the person to do all the work necessary to do this themselves.
Presumably the warrant defines the scope of the search. Of course the judges issuing the warrants aren't technical and generally cooperate with investigations, so I would expect vague and over-broad warrants to be the rule.
Well that's handy then, the "helpful roomate" tries his best to enter the password, but didn't realise that after 3 wrong tries it wipes the device!
The way it's written makes it sound like the officers would be rifling through the computers and phones on site trying passwords they've found, themselves, or standing over the shoulder of people being forced to do so. It specifically talks about forcing someone to make information "visible and legible" and about copying documents, rather than just making forensically secure images of devices.
But let’s be serious here it has to be at a place where a warrant is issued right? Tech folks are super paranoid. Like, try to make sure no warrants are out for you and your cousins and you should be fine. If you’re in the wrong place at the wrong time: sucks to be you anyway!
Easy enough to booby trap discreetly to delete things if not accessed the 'correct' way.
Maybe this is to show that this approach is so crazy that it could never work (hence the written reports to gather data), and that they do actually need <insert some crazy power> here in order to do it properly because "we tried to do it the nice way and it didnt work"
Exactly! If I had anything to hide, I'd make sure to give them the 'correct" password that will wipe out selected data from the device.
Can it be done by giving them one wrong password which will trigger a disc erasure?
Serious question, as I wouldn't know how to do that.
For example, insert your filesystem-nuke (perhaps with an attempts counter) around line 78 of main.rs here https://github.com/akermu/rlock
Actually wiping the disk would take way too long. Assuming that you're running Linux and that all connected drives are fully encrypted: overwrite all keyfiles in a secure manner (ie flushing all caches and etc), write random garbage to the entirety of RAM, and trigger the equivalent of `halt -ff` (note the double --force).
Potentially of interest: `__noreturn machine_real_restart` in reboot.c (https://github.com/torvalds/linux/blob/5bfc75d92efd494db37f5...)
Bonus points for additionally finding a way to trigger the "secure erase" firmware feature of all attached devices as part of the above sequence. That's likely to prove a bit tricky though since that feature is generally locked out (for obvious reasons) once you leave the bootloader.
The contents of RAM in this scenario shouldn't be particularly vulnerable. If they're trying random passwords on the actual machine without any attempt to preserve the disks beforehand there's zero chance they're about to take the machine apart and extract what's left in RAM before it's gone.
>Potentially of interest: `__noreturn machine_real_restart` in reboot.c
Just write "b" to /proc/sysrq-trigger, it'll immediately trigger an ungraceful reboot without trying to unmount filesystems or flush the cache.
Better just to buy a bunch of USB sticks, wipe 'em all with random noise, use a couple for mundane files, and use a couple for sensitive files — deniably encrypted so as to look like random noise. Then, you can plausibly deny that they contain any sensitive files.
The real issue here is that we shouldn't need to use these sorts of measures. No one will do this unless they're a software professional with something to hide, and "having nothing to hide" doesn't mean you're not still entitled to privacy.
That depends entirely on how exactly you do it. And knowing something and being able to prove it are two very different things.
You're creating a situation where you have a set of encrypted and non-encrypted devices that are indistinguishable, and expecting the police to let you off. But there's nothing stopping someone with only encrypted devices to claim the same thing. I'd be worried that approach would fail either by 1) the police calling your bluff, or 2) indefinitely holding you in jail for contempt of court until you decrypt a drive that has un-decryptable random data.
Encryption with plausible deniability will not have readable headers. It will appear to be completely random data.
"Don't worry about my large collection of seemingly encrypted USB sticks officer, it's actually just random noise I filled them with for the lulz! No sensitive files here."
I see no flaws with this plan.
Usually when you encrypt a drive there's a telltale header, so the disks wouldn't be "seemingly encrypted" at all — and wiping disks clean with noise isn't especially uncommon. It's as plausibly-deniable as it gets, and it'd certainly fly in court.
Not necessarily.
https://www.truecrypt71a.com/documentation/plausible-deniabi...
2. Until decrypted, a TrueCrypt partition/device appears to consist of nothing more than random data (it does not contain any kind of “signature”).
Or both.
Otherwise this will degenerate into police being allowed to sneeze devices and operate them away from their owner's presence.
Make it possible to "lock in" a single biometric profile and not permit adding a second profile without automatically wiping all data.
1. they can be compelled by force,
2. they can be physically collected, unbeknownst to the owner,
3. they share all the risks of digital passwords, including being leaked,
4. they can't ever be changed, even when known to be compromised by 1, 2, or 3.
Much better to have 2+ passwords for deniable secrets.
A unlocks the device. Most people only have this one "normal" password.
B unlocks the device plus secret b, maybe some extra kinky porn so people feel they've found your real secret.
C unlocks the device plus secret c, your real secret, maybe Bitcoin wallets or that novel you've been working on forever.
If there's software on the device that does this, it's only evidence that 1+ secret dirs might exist. It should be impossible to tell that c exists, let alone compel its disclosure via C. But if b is quite stale, that's at least a hint that c might exist.You can go on forever with this stuff, especially if you have root on the device. Which gives you some clues about the true purpose of laws like this and who thinks they are useful.
Also make software self-destructing with a warning, i.e. if the user chooses it at installation time, all data will be destroyed automatically by the OS if they move the device off-premises. Make the setting unchangeable after installation time.
Police won't want to destroy evidence, so they'll have no choice but to leave it on premises.
I'm not trying to enable criminals, but rather enable whistleblowers and to not succumb to unreasonable new laws, and keep unethical searches for bad reasons in check.
This is not how forensic analysis works. Data is copied to read-only supports before any attempt of access is made.
(For twins they're more likely to have different usernames than different biometrics.)
This kid couldn't write a paper let alone a police report. Boggles my mind why they'd ever let someone like that be a cop. I guess they value people skills over knowing people have rights.
Of all the jobs available, how many people really want a job that is historically known for low pay, long hours, and on more than occassionally requested to put your life on the line? How long did you personally contemplate that as an option? Of all of the people left that didn't say hellznah, fill the positions you have open on your police force. Policing is like politics in this one manner: those who want/seek the job, tend to be those that should never have the job.
Folks, keep your information AT HOME where it belongs. Don’t dirty the streets with those ugly snaps no one wants to see (unless there’s a cat filter) :)
Except they can take your key, search your house, take your work key from there and drive with your car to you workplace and search everything there you can access, as well. So metaphorically as well as actually (home server etc.), your home is not safe.
* Pockets may contain items that are dangerous to an arresting officer, or to other arrestees. Emptying pockets serves the purpose of removing that danger. Data stored on a phone are not dangerous to nearby people, and so there is no corresponding danger that needs to be removed.
* Pockets can be verified to be empty, and so it can be verified that the person has complied with the order. There is no way to verify that all information accessible from a computer has been revealed. A police officer can demand that a suspect produce passwords that they don't have, then use the "noncompliance" as a way to add additional charges.
* Emptied pockets can be returned to their original state. If my pockets contain a driver's license, $5 and lip balm, those items can be returned to me. If I reveal a password, the reveal of that password cannot be undone, and that account must be assumed to be compromised.
* (For the US only) I have the enumerated right for my papers and effects to be secure against unreasonable search and seizure. A full investigation of accounts to which I have access, done at the site of an arrest, by untrained officers, with no checks for data security, no limits on the breadth of the search, with no basis of reducing external harm, and no right to contest the disclosure until after it has occurred, is entirely unreasonable.
I agree with your conclusions, that information security is important and should be more widely practiced. I disagree strongly with how you reached that conclusion, as a physical search of pockets is entirely unlike a search of one's phone or connected devices.
But it wouldn't matter: documents and archives of the state are inviolable no matter where they are. And the property of a diplomatic mission must remain free of search and seizure.
So... basically the entire internet, then?
- Stage a crime scene next door to the targeted machine.
- Ask for a warrant for the location.
- Knock on the door and ask the person to give the password for the Bitcoin.
I can see it now: "I'm sorry, Officer, but my company's Data Loss Prevention (DLP) policy will not allow this document to be copied to any removable media or emailed outside of the company. I can make a request to Compliance for an exception but they take 7-10 days to respond!"
> Security sources said the person refusing to surrender their password would have to be a suspect in a crime and trying to obstruct the investigation of that core offence before they would be convicted over the password refusal.
It’s annoying that media coverage (by the “newspaper of record”) would rather cite speculation by anonymous sources rather than link directly to the text of the actual Bill. It’s only when I check the discussion on Hacker News that the source is directly referenced.
On the other hand, the state broadcaster does not even deem this proposed change to Irish law to be newsworthy enough to warrant coverage on its news website².
Somewhat Off Topic: The typesetting of the Bill itself is woeful and really impacts on readability of the text. It seems like the content was copied and pasted from multiple sources into MS Word without any consistent styling or indentation to reflect the hierarchy of bullet pointst.
1. https://www.irishtimes.com/news/crime-and-law/new-garda-powe...
Normal people, on the other hand, do not have these kind of (mental, time) resources. They will be forced to unlock their phones and something incriminating (for instance regarding "hate speech" or "intellectual property rights" or just "traffic violations") will be found. I consider this approach one step more in the direction of keeping every citizen an on-demand criminal. There are so many, sometimes incomprehensible, laws nowadays that pretty much everyone is not compliant.
But yea, your high profile criminal doing the real bad stuff is not going to be walking around with it on something that keeps a record.
I think your point is valid, especially the part about normal people, but you might be overestimating the intelligence of most criminals.
There are hundreds of criminals who are not tech savvy (or not tech savvy enough) who will not have any of the mechanisms you postulate, who are frequently caught by the police and are very much "proper criminals".
I don't agree with this law but to say it doesn't do anything against proper criminals is patently false.
'What's the point of a law against breaking and entering? A criminal will break and enter anyway!'
To give a trivial example, killing someone would be an example of a Criminal law and you would be right. But tearing down a supporting wall in a block of flats to expand the living room would be an example of a law that needs to be written down because it's not obvious and clear to everyone.
No that's what I was arguing against.
Laws are about justice not prevention.
Other laws are enforced without the criminals cooperation or consent. For example you stab some one, cop finds the knife with your finger prints and the victims blood case closed your off to jail.
This law would be like the cops requiring you to hand over the bloody knife and if you say no then the cops will have no evidence and little recourse but to arrest you for the lesser crime of lying to the police, not very effective.
It’s not false, we see this with gun control laws 100% of the time. Handguns being illegal in Chicago yet it being rather easy to get one. The laws are followed by noncriminals but criminals don’t care and only get caught after they do something. If at all. So the laws reduce freedoms for noncriminals and criminals just get charged with something else when/if they’re caught. And mind you the criminals don’t care what or how many crimes they’re charged with. At best it deters law abiding citizens, nothing more.
I oppose such a law, as it appears to be very poorly written, but it's pure fantasy that criminals won't do crime via their phones, or will use some sort of advanced steg. Maybe some very talented criminals will do such things, but most criminals are just people: they either don't understand technology well, or else simply engage in risky behaviors.
The drug dealers are probably just using whatever encrypted app they hear works well, which is why there was that big successful sting using an FBI controlled app recently.
The bright ones are not being caught and therefore not on the list of criminals.
Ex. "More than 70 percent of American adults have committed a crime that could lead to imprisonment."
https://www.politifact.com/factchecks/2014/dec/08/stephen-ca...
"A suspect was charged in 7.8% of crimes recorded in England and Wales in the year to March 2019, down from 9.1% the previous year".
Doesn't sound right to me; The intersection between criminals and people with good information opsec is tiny(mostly because the latter category is tiny anyway).
I agree the law is problematic, but not for that reason.
"in 2020, there were 1.8 million people in prison" [1]
"[in 2019,] the country’s total employed cybersecurity workforce is just 716,000" [2]
"There are about 465,000 open positions in cybersecurity nationwide as of May 2021" [3]
[1]: https://easyreadernews.com/why-are-so-many-americans-in-pris... [2]: https://www.csis.org/analysis/cybersecurity-workforce-gap [3]: https://www.cbsnews.com/news/cybersecurity-job-openings-unit...
tiny * tiny = very tinyHow did you arrive at that? Even a significant fraction of people I know who do security work would agree they don't in general have good info opsec, because it's a pain in the ass. Most of the technical people I know wouldn't even know how to do it properly.
"Criminals" is hard to define precisely, but some small integer percent is at least a reasonable lower bound. Afaics people who are actually good at info opsec don't number in the millions.
So even if we simplify by assuming the rough magnitude of both groups is the same, you still have the intersection of two small groups -> tiny. This is probably complicated a little bit because criminals have more incentive than average, if not more experience.
Lol now gatekeeping criminality!
Wow. What a phrase.
Edit- It reminds me this first amendment wonk who pissed off local police and was then ticketed for failure to register his bike: https://m.youtube.com/watch?v=28w6xvRj9EM
So if you can't prove that you don't have the password, you're in a bit of trouble!
-------------------------------------
16 (1).(e).(v) to require any person at that place who appears to him or her to have access to or to have under his power or control the information held in any such computer or which can be accessed by the use of that computer—
(I) to give to him or her any password or encryption key necessary to operate it,
(II) to otherwise enable him or her to examine the information accessible by the computer in a form in which the information is visible and legible,
(III) to produce the information in a form in which it can be removed and in which it is, or can be made, visible and legible
67 (2).(d) A person who fails to comply with a requirement under Head 9 (1), (2) or (3), or Head 16 (1). is guilty of an offence and is liable—
(i) on summary conviction, to a class A fine or imprisonment for a term not exceeding 12 months or both, or
(ii) on conviction on indictment, to a fine not exceeding €30,000 or imprisonment for a term not exceeding 5 years or both
IIUC The way this works in the UK and is being proposed here for Ireland is guilty until proven innocent. You need to prove that you don't know something, which is equally impossible.
Of course court rarely "proves" things. It is more aimed at "beyond a reasonable doubt" which does allow some chance for proving both ways. But I don't think that makes much difference to the fundamental issue.
This point of view also cleanly solves the "unlock the phone" debate. They can't make you type your password because they can't prove that you know the password, but they can make you touch the fingerprint reader because whether or not your fingerprint unlocks the phone is something that can be tested.
Of course the question of morality is important. Especially as we are sprinting towards a future where we have more and more visibility into people's brains. It would be nice to answer this question, and with the current direction that governments are moving it seems like the answer is going to be that accessing a suspect's mind is acceptable, which I have very mixed feelings about.
I imagine that the way this would have to work in practice is that the prosecution would seek to prove that the accused did in fact know the password, and seek conviction on those grounds, rather than forcing the accused to refute unfounded accusations. But how it actually ends up working would depend on how the Irish legal system works.
Wouldn't the presumption of innocence protect the accused from the impossibility of proving their ignorance? Wouldn't the prosecution need to produce clear evidence that the accused did in fact know a particular password (for instance, by demonstrating that they recently used the password to log into a particular system)? How badly could this actually be abused, in practice, in Ireland specifically?
No, you can’t prove a negative. Though some agencies may try lie detector tests, those have been proven fairly useless
EU Directive 2016/343 part 25 very clearly prohibits this kind of nonsense. Yes, the Irish state insists on pretending that EU law doesn't exist over and over and over again, but how wrong it is about that is documented by its endless appearances at the CJEU in Luxembourg and its 0% win record.
I also don't think it is that unique to the UK. It was a multi-national attack that broke EncroChat and the Australians breaking An0m (maybe with US help). Some countries love privacy at all costs like Germany and Scandinavia, some don't even assume they have privacy like Iran and China and those in the middle, like the UK, want to pretend they have privacy and are principled until they need to solve a crime and then it goes out the window!
Also, here's one of my favorite fairly relevant quotes:
> "We operate under the rule of law and are accountable for it. In some countries secret intelligence is used to control their people. In ours, it only exists to protect their freedoms."
- William Hague (UK Politician)
Edit: I wrote UK government... I was mistaken and thought of Northern Ireland instead of the Republic of Ireland.
0: https://en.wikipedia.org/wiki/Regulation_of_Investigatory_Po...
Unelected global institutions are rising, and their vision of the future is not promising.
https://mises.org/wire/no-privacy-no-property-world-2030-acc...
I always remember Pink Floyd’s Another Brick in the Wall Part 2 [0] and the story of how authoritarian British schools were. I guess there some sort of contingent for making lots of rules and demanding adherence.
There’s a pretty great book called Albion’s Seed [1] by Fischer that goes into the four groups of British people that founded America. The “border” peoples of Scotland/north England were pretty anarchistic and moved to the colonies fleeing British rule. And I think there was quite a bit of rule that resulted in the people who don’t follow rules leaving Britain for the US/Australia/other colonies. So after a few hundred years, that perhaps had an effect on the type of people who stayed.
And they ended up in Appalachia because even the other colonies couldn't stand them and kicked them out.
I don't consider Ireland to be a "British Isle" -- 26 counties out of 32 on the island are Irish.
How and ever -- we see the US in the same light. You're so hostile to privacy laws like GDPR and we aren't etc.
No one for a moment is suggesting that because of that you have to drink tea or invent the computer or anything else that is considered British.
Besides, to us 'English Channel' is a geographic term; in France it's La Manche ('the sleeve'). (Having said that we do say 'Irish Sea'.)
"British Isles" is the widely accepted term internationally in large part due to the historical dominance of the British Empire, coupled with the ongoing influence of the British state internationally (particularly in the anglosphere). It is however not a generally preferred term within Ireland, which is worth noting alongside any technical facts about geography.
You're arguing about an entirely different context. One involves private corporations, one involves the powers of the government. It's critical to make a distinction between those things, they are not the same issue at all.
Facebook, fortunately, doesn't have taxing authority, regulatory authority, law-passing authority or a private militia. I can banish Facebook from my existence, I can choose never to use their services, and I can legally use numerous options for blocking their ability to track me (and do so quite easily). Try doing that with a government that passes a very invasive law, just tell them to right piss off with their laws, refuse to obey their laws.
It's fine to argue for restrictions on privacy invasion re private corporations. However these are two separate matters to be argued, what should be allowed in the private sphere vs the public/government sphere.
What's used in public discourse and what's at large are two different groups.
If I had to guess, police has a hard time accessing anything on smartphones and PCs - which probably is a major holdback for them - and hardly anybody involved in the making of the legislature has enough technical understanding and/or political stake to defend the privacy side of things.
[0] https://www.heise.de/news/Cyberbunker-Klausel-in-StPO-Durchs...
Aside from sensitivity around the (technically correct but the status quo should always be open to question) term "British Isles", even accepting that term geographically, conflating the islands culturally demonstrates a certain level of ignorance on the subject.
>The British Isles are a group of islands in the North Atlantic off the north-western coast of continental Europe, consisting of the islands of Great Britain, Ireland, the Isle of Man, the Hebrides and over six thousand smaller islands.
It'd be hard to find any person using a smartphone whos phone is not "encrypted".
VeraCrypt, a source-available encryption program, supports this form of encryption, such that you can create an encryption file, say 1GB. You place a password on the "outer" volume, so that when you enter the password, it mounts the encrypted volume and it appears unencrypted. However, you also put into place an "inner" hidden volume. When you enter the password for the inner volume, it mounts a separate encrypted volume. Adversaries cannot detect this inner volume, and when they twist your arm to unlock the encrypted veracrypt file, you can enter the password for the outer volume, keeping the secrets of the inner volume safe.
If you are plausibly denying the existence of the inner volume, you mount the outer volume without the inner volume password. The driver happily overwrites the "free space" where the inner volume keeps its data. It is in fact unsafe to modify the outer volume at all without providing the inner volume password (if an inner volume exists).
[edit] VeraCrypt it seems only accepts the outer volume password when creating the hidden volume, but here's more about it: https://www.veracrypt.fr/en/Protection%20of%20Hidden%20Volum...
I have a very long passphrase that I only have to enter at machine boot up time. After entering the pw once the password manager remains open in cache and can be opened with a much shorter and easier to remember password. Because I do not restart my phone or devices frequently I don't need to enter my password often and so my very long complicated password isn't used often. My practice has been to automatically restart my phone whenever I am approached by a police officer. This has happened maybe once in the last year or 2.
If I live in Ireland, am I screwed when the stress of being detained causes me to forget my very long, complicated, and infrequently entered password?
Ultimately the password `fuck you cop I'll never tell` is a fun idea, but little value. Complying without appearing to comply might change up the game a bit, but you're still screwed.
_edit_ it is kind of fun to think of a password so offensive that it doesn't matter who asks you, they won't believe that's your password. Technically might buy you some time before they figure it out.
If they don't believe it's your password, then you haven't really avoided the punishment for not disclosing your password (although you might take some comfort from a kind of moral victory, having told the truth and complied with the letter of the law).
Instead of coming up with a password that offends the police, a better approach is to come up with one that interests them, specifically a detailed admission of a crime. For example, the password could be of the form "I killed John Doe, and buried the body in my garden".
Assuming your jurisdiction has protections against self-incrimination, and you can convince a judge that your password really does contain such information, they may have to choose between not learning your password, and giving you some sort of immunity deal.
Of course, if this approach leads to innocent citizens routinely committing crimes just to come up with a unique password (or worse, criminals baiting police into giving them immunity in return for access to dummy encrypted data) then the only law that will be followed is the Law of Unintended Consequences.
I think it's quite unlikely they'd give immunity, especially when they could just instruct you to unlock the device and hand it over without telling them the password
Ask me after a month/week/day/hour of course, but I hope I'd be strong enough to deal with this appropriately.
>"If I live in Ireland, am I screwed when the stress of being detained causes me to forget my very long, complicated, and infrequently entered password? "
As for this part, I've become a cynic after learning so much about how courts actually function on a daily basis. There really isn't anything stopping a judge from simply finding you in contempt of court - even if you legitimately did lose your password. Ultimately, if the judge wants to, they can easily drag you through the mud and you have virtually no recourse.
Edit: I know Apple has a feature that disables FaceID that acts like a 'panic' button. How do the courts deal with that?
Something like this should exist natively in Android and other operating systems, but obviously there would be a push back from governments.
In the United States (where I live) this seems risky. I think most here would prefer their phone to be on and readily available for filming in case they need to film the police encounter. We have a lot of cops spazzing out on people.
Some good analyses from actual informed Irish-based perspectives here:
There is little in the analysis that gives me comfort. FG are the law and order party but paradoxically they have a history of passing poorly conceived laws presumably because they don’t feel the downsides will ever apply to them, and to provide enough legal ambiguity for those well connected to wriggle free. Ambiguity also good for the legal folk that constitute the rank and file of their membership.
They are currently shored up in coalition with another establishment party (FF) and the greens so it’s conceivable that much of this could get through without challenge.
Of course it’s important to remember that it is kite flying season and there is a battle for hearts and minds with the main opposition party (Sinn Féin) so it might just be a matter of whipping up their conservative base.
But, how come there's been nothing else in the field? The only thing that appeared in the past decade to be more advanced on that front was this,
https://www.bankinfosecurity.com/rise-self-concealing-stegan...
https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Schaub-Perfectl...
https://portswigger.net/daily-swig/russian-doll-steganograph...
and there's been nothing since... It must truly be hard to make fully deniable encryption mechanisms..unfortunately....
People should get on a ship somewhere and build a colony with freedom as an ideal. Something like that.
Somebody tried that. Did not fare that much better [0].
[0] https://en.wikipedia.org/wiki/Mass_surveillance_in_the_Unite...
(j/k, kinda)
I do not think these warrant issuing procedures will be throughout, either way, would never trust it.
Which politicians are responsible for passing this into law?
Nobody will go protest in the streets over this.
But a couple 100 single of these shenanigans and the people will ask themselves how we ended up in this mess, and everyone will jump on the divide train and blame the "other" party, when it's really equally distributed usually.
Testimony to that is that nobody opposed this hard enough to bring it down.
The only bright side to this is, it appears the governments cannot easily access all things, despite five eyes and international collaboration.
I find if a case is bad enough for a warrant, then maybe deploying a keylogger or similar would be the better way. At least then it's handled by a specialist. But delegating this to police officers? Hellno
I don't really think Helen McEntee's maternity leave is relevant either because she's in the same party as Heather Humphreys, and they are in a three-party coalition government. There's no main partisan divide like there is in the US or UK.
The last election was basically a three way tie, with a significant vote share split across another handful of small parties and independents. It's way more complex than just FG v SF.
The enhancement here would be some little unencrypted portion/vm so the bearer can play FarmVille in transit.
Not saying its great, but at least they have to have an actual search warrant for it first.
It sounds like anything found at the at the address of the search warrant is a valid target, and you are legally required to assist no matter the reason that you or your device was there.
A search warrant is extremely powerful and should clearly spell out what it's searching for. If the police find something outside of the scope of the warrant, at very least they should be required to go back to the judge and justify why they should have access to it.
Just make sure that your device doesn't contain information incriminating other people who the government are trying to track down. That means not using real names, or metadata that connects pseudonyms with physical identities (e.g. phone numbers).
Disclaimer: UK resident who is NOT qualified in law ;-)
More importantly these are the Gardai not the PSNI -- despite the source being the BBC which may have thrown you off.
[0]: https://en.wikipedia.org/wiki/Regulation_of_Investigatory_Po...
[1]: https://www.newstatesman.com/blogs/the-staggers/2010/10/poli...
I wouldn't be too sure of that. I recall reading about some experiments where by monitoring brain activity the researchers could fairly reliably tell if a person shown a photo of a place had been to that place before.
I can't think of a way to adapt that to extracting a passcode or password, but it does suggest that the head is not as safe a storage place as we might have thought.
Isaac Asimov had some mystery short stories set in a future where there was a machine that could probe a mind and extract any information the subject knew, but there was a very small chance that a probing would drive the person incurably insane.
The way they balanced the right of privacy and the need to protect people from crime was to only allow any given person to be involuntarily probed once in their life. Of course this led to many criminals trying to arrange so that they would get involuntarily probed either over something they were actually innocent of or over something they did but that did not have too long a sentence. The criminals recognized that for really serious crimes juries would be reluctant to convict without probe evidence, so once you were probed you could take your criminal career much more safely to the next level.
Fuck giving testimony against yourself.
Simply falling over and breaking it on your keys would be enough to put you foul of this law?
I guess "Ah crap, it was on my keys earlier, I must have lost it - I can't do anything" would be a grey area!
If you were prepared to lose your device, it would be easier to ditch it than ditch the keys but, again, not all criminals think that far ahead. I read that they caught Dread Pirate Roberts because he thought he would never get caught (in a public library!)
Also, if you have a backup key somewhere, you haven't lost any data or your machine.
Or, once they exist, just carry a broken key with you for plausible deniability?
This actually is pretty bad. Password is not just for information revealing. It’s for proof of ownership and control of the accounts. Revealing the password means ceasing control of the accounts to police.
https://www.whitecase.com/publications/alert/european-court-...
If as another commentor has said, it is based on location, rather than specific devices, then I can't see a lot of these warrants holding up once it affects someone with a lot of classified stuff on there. Eg. You pop round a friends house from work, you do contracting work for the MOD and have your work laptop with you, turns out your friend is involved in some financial "bad stuff" and you happen to be there.
> "Irish police will have the power to compel people to provide passwords for electronic devices when carrying out a search warrant under new legislation."
This is not unique to Ireland, we see this here in the US as well.
I have some long passwords that I keep out of password managers for private stuff that I don't want to be leaked from a password manager leak or w/e. I can remember them, but had a really hard time remembering even the start of most of them after not using them for a few weeks.
That kind of timeframe isn’t abnormal for the speed of law.
This is only true when the revealed information is a "foregone conclusion", specifically when it "adds little or nothing to the sum total of the Government’s information."
Here is a good treatment on the subject: https://harvardlawreview.org/2021/04/state-v-andrews/
This seems to be an actively developing area of law around the world.
They might still have a way to image it though, depends on the day as the imaging software always gets thwarted
Also believe it depends on the model but the 12 pro does it like this and a few models before
I guess it will have to wait until this law is struck down, if ever.
What I want is a system that has two passwords that unlock two wholly separate partitions, one of which is anodyne and the other which is where I keep my private opinions about Big Brother.
Of course, astute investigators might wonder why the accessible partition only uses half the storage capacity of the device; you might wish to make your secret space very small and perhaps use some compression scheme as well. If you have a large amount of information that you wish to keep private, you're probably best storing it somewhere else entirely and only accessing it remotely.
Only if someone can prove the data was there in the first place.
If I put in my password and you get back a reset phone with no personal data whatever, then it's rather obvious that I've wiped it (eg my wallpaper picture has likely reset from my personal taste to the system default). So now you don't have the evidence to convict me of what you suspected me for, but you can bring another charge, and DoE charges will cause most people to assume that the original accusation/suspicion was well founded. If you are able to prove it by other means I'll get less sympathy from a jury and likely a much higher penalty.
I could see, "better than to reveal a secret", but that's not "conviction"
The Irish Council for Civil Liberties are in the process of analysing it https://twitter.com/ICCLtweet/status/1404417358135971841
Otherwise though, there has been widespread backlash. The govt. absolutely have the votes to push this through parliament if they want to, but public sentiment could definitely give them pause.
Given the scale of the bill, and it being accompanied by another related bill which apparently reduces oversight of the Garda (police), my suspicion is that this is a strategic strawman bill, with the intent being to push through a watered-down-but-still-pretty-terrible version of it after some "consultation" & amendments to remove the most publicly-objectionable highlights.
Off the top of my head, while the severity and scope of this is indeed surprising, the direction is not. Just as police authoritarianism has been on the rise internationally (notably in the misuse of vague anti-terrorist legislation in the US & UK to grant broad policing power in many areas unrelated to terrorism), the same trend has also been present to a certain degree in Ireland. FG have been in power for 10 uninterrupted years and have traditionally been the law and order party. Their idea of police reform when the Garda was hit with numerous misconduct scandals was to install a former-RUC officer as head of the Gardaí. So this is all ideologically in line with the ruling party at least.
Additionally, anti police sentiment has generally been on the increase in the past 2 years so this could be a response to that. Recently the country has been trying to open up post-covid by encouraging outdoor dining, events and gatherings (given doing so indoors is still prohibited), with many initiatives being heavily invested in by local city councils. Those initiatives have been completely undermined by riot police arriving to clear public spaces & incite street violence, seemingly with no communication or coordination with local councils (local councils typically being populated by representatives of parties who are in opposition at national gov level).
So... it could be a lot of things. Or it could be gangland killings.
Replace "hit him with this $5 wrench" with "put him in jail for contempt of court" and it amounts to the same thing.
Give us your password or we will do bad things to you.
Landlords have gotten Gardai to assist evictions multiple times, even without cause or paperwork being shown.
In contrast, a week ago or so it came out that Gardai were ignoring thousands of domestic abuse calls to emergency services - just deleting them without follow-up.
I could go on and on but let there be no doubt, these are not people you would want to trust with your phone - and if you are crossing them they absolutely will show up and stand by as you get pulled around by your ears by balaclavaed thugs, etc.