Especially considering that it's possible to be wrong about a volume being encrypted.
Especially considering that it's possible to be wrong about a volume being encrypted.
In many criminal cases, months or years pass between evidence seizure and the criminal trial. Seems very easy to forget the decryption key. Or not have access to the 2-factor token anymore. Lot's of edge cases with very serious side effects.
from the article, it looks like a judge in 2010 agrees
edit: edited for formatting
Nonetheless, I agree with you that every once in a while, FBI would seize a hard drive that is (a) not encrypted but filled with random-looking bytes, or (b) encrypted but the owner has forgotten the password.
When I sell a used hard drive, I usually fill it with random data. Sometimes I do this by creating a TrueCrypt volume that takes up the entire drive. (This destroys all the data on every partition, as well as the MBR, so the drive appears unformatted to the buyer.) But suppose the FBI suspects me of downloading CP and buys my drive as part of a sting operation. They'll think my drive contains CP. After all, it has the typical signature of a TrueCrypt volume! But guess what, I wasn't intending to store anything on that drive, so I threw away the password as soon as I typed it into TrueCrypt. How do you prove that I cannot possibly remember the password? With a physical safe, at least it's possible to prove that I don't have the key in my possession.
Immediate, on the person, maybe. But you cant prove you cant get hold of it. That's the old proving a negative thing.
In fact, even if they search you, all it proves is that they didn't find it, not that you don't have it.
When governments start expecting us to prove we didn't do or don't have something, you might as well give up. Its a line no one should be able to cross, not least governments.
TC tries to avoid a "typical signature". TC volumes do not have any header. The only signature is high entropy.
Let's say you picked a hard drive at random, and noticed a significant chunk of seemingly random bits. Is it encryption, or not? Well, given what you know, the best you can do is assign E÷(E+R) probability for the drive being encrypted.
Now change the problem, where you suspect the owner of the drive may have reasons to encrypt it (suspicion of child porn fits perfectly). Random chunks are now even more suspect.
Personally, I suspect that the vast majority of seemingly random chunks of bits are in fact encrypted data (meaning, E÷(E+R) is quite close to 1). So, while it's not proof, while it's not a signature, while for various reasons it's not something we want courts to use as an argument, it's still damn strong evidence that encryption is going on.
This is simple probability, and does not involve Bayes Theorem at all.
But how do you determine the frequencies E and R (or their ratio)?
Perhaps you could sample the population of drives (E+R) and decide which of these are encrypted, and which are just randomized. And how to decide? Oh... you can't.
My point was just that to me, noticing in a hard drive a big seemingly random chunk of bytes is very strong Bayesian evidence that the disk holds encrypted data. And if there is encrypted data, the owner of the disk is more likely than not able to access it.
> But how do you determine the frequencies E and R (or their ratio)?
Just ask people in non-adverse situations. With enough effort, that should get you a decent probability distribution over the possible frequencies of E and R.
However, her probability is not affected by her taking the test: she takes the test for a reason, so merely taking actual action doesn't give her any meaningful information. Only the result of the test will tell her anything.
Similarly, if we're talking about your wife, you most likely know when she has sex (because it's with you), and maybe she tells you about her period and such. In this case, merely learning that she took a pregnancy test doesn't tell you anything you don't know.