UK law says provide key to encrypted data or go to jail
itworld.com
itworld.com
"Neuroscience Meets Cryptography: Designing Crypto Primitives Secure Against Rubber Hose Attacks"
https://crypto.stanford.edu/~dabo/pubs/abstracts/rubberhose.... (summary; full paper (PDF): http://bojinov.org/professional/usenixsec2012-rubberhose.pdf)
Abstract:
"Cryptographic systems often rely on the secrecy of cryptographic keys given to users. Many schemes, however, cannot resist coercion attacks where the user is forcibly asked by an attacker to reveal the key. These attacks, known as rubber hose cryptanalysis, are often the easiest way to defeat cryptography. We present a defense against coercion attacks using the concept of implicit learning from cognitive psychology. Implicit learning refers to learning of patterns without any conscious knowledge of the learned pattern. We use a carefully crafted computer game to plant a secret password in the participant's brain without the participant having any conscious knowledge of the trained password. While the planted secret can be used for authentication, the participant cannot be coerced into revealing it since he or she has no conscious knowledge of it. We performed a number of user studies using Amazon's Mechanical Turk to verify that participants can successfully re-authenticate over time and that they are unable to reconstruct or even recognize short fragments of the planted secret."
The scheme/system is bound to be imperfect; but it is a nice angle of approach, so to speak, and hopefully we'll have more stuff of this kind in the near future.
edit / P.S.: from the paper / intro section:
Readers who want to play with the system can check out the training game at brainauth.com/testdriveI was probably thinking something along the lines of, [this proposed system] + a way for the user to discretely convey to the auth/security system the info that they are being coerced, and the system authenticating them to a bogus user account / set of sensitive data. But this would be cumbersome and very difficult to implement given the design in question, probably.
It would have probably been more relevant to mention encryption systems with plausible deniability - e.g. TrueCrypt's hidden volumes [1] and Rubberhose FS [2].
[1]: http://www.truecrypt.org/hiddenvolume
[2]: http://en.wikipedia.org/wiki/Rubberhose_%28file_system%29
If 'system' (in your last sentence) means 'user system' ('has' -> keylogger etc), it's not that simple afaik. There's no way for any eavesdropper (between client and server) to know (from the auth game data the server sends) which parts of the data/exchange signify the password. I think they partly addressed possible password/data correlation attacks over multiple logins -> sets of data, but not sure if in this paper, it's been a while. It's not that trivial as far as I take it.
Even so, you can give the password by playing the game, which is why I would prefer to keep it in some form even I can't read and which is easy to be accidentally destroyed by the police when they seize your stuff.
July 13, 2012
A few of us kicked and shouted about this when this was proposed. If you'd like an example of how this is being abused, El Reg has a good article from 2009: http://www.theregister.co.uk/2009/11/24/ripa_jfl/I was drawing the distinction between that type, which are simply archaic, and this type, which have been designed to incriminate everyone.
It was to do with encrypting random data for physics or a game or something and the government got hold of it but because the data was encrypted one way he couldn't give them a key and he was going to go to prison for two years.
I've heard nothing about it since though with all this PRISM stuff and people encrypting their emails I'm surprised it hasn't resurfaced sooner.
Refusing to provide encryption keys is the same thing. There might be illegal data, there might not be. It's the duty of the police to prove it, not the accused.
Innocent until proven guilty? Not in the UK.
from http://en.wikipedia.org/wiki/Right_to_silence_in_England_and... (and cite-note 15)
The case concerns a claim that it was injust to make inferences as to the guilt of the appellant based on their choice to remain silent before the police and court. This appeal under Art.6 ECHR failed (though a claim of preventing access to an attorney succeeded). The court finding that there was no undue inference made, that any inferences as to guilt that had arisen out of the defendants failure to break silence were allowable.
I'm not sure this really helps so much as it seems as it appears to allow the [partial] curtailment of presumption of innocence.
Of course we don't (completely) trust trust the judicial system. That's the point of half the Bill of Rights, for one.
In the US courts are split on the issue. Some say giving an encryption key is testifying, an act of the mind, and you can't force someone to testify against themselves under the 5th. Others say its like handing over a regular key, which you can be forced to do, because the 5th covers testimony, not everything incriminating. It was intended to prevent forced confessions.
Once you're in front of a court you don't get to keep secrets, with the exception of some narrow protections. This has always been the case in the Anglo-American system.
You are not necessarily obligated to testify to that fact for the police, and unless they can demonstrate that the drive belonged to you (or you had access) through some other means, the production of an encryption key is tantamount to forcing that confession.
It's much like if there were a lock on a gun they found on the street: if they can't link the gun to you already, they can't demand you turn over the combination for the lock, because knowing such a combination would be a tacit admission to knowing about the gun.
> He returned to Paddington Green station as appointed on 2 December, and was re-arrested for carrying a pocket knife.
FTR, carrying a pocket knife is perfectly legal in the UK (assuming it was within a certain size).
> Officers bearing sub-machine guns broke down the door of JFL's flat. He rang local police before realising CTC had come for him. [...] JFL maintained his silence throughout the one hour time limit imposed by the notice. He was charged with ten offences under section 53 of RIPA Part III, reflecting the multiple passphrases needed to decrypt his various implementations of PGP Whole Disk Encryption and PGP containers. [...] In his final police interview, CTC officers suggested JFL's refusal to decrypt the files or give them his keys would lead to suspicion he was a terrorist or paedophile.
And my favourite paragraph:
> "There could be child pornography, there could be bomb-making recipes," said one detective. "Unless you tell us we're never gonna know... What is anybody gonna think?" JFL says he maintained his silence because of "the principle - as simple as that".
So he was jailed for remaining silent.
There is no '5th Amendment' in the UK, no right of silence and no Miranda rights. There never have been. We do have our own limitations on the rights of police officers conducting an investigation though. If officers have the proper warrants, I think it's reasonable that they are entitled to access to computer records in much the same way they are entitled to access to any other part of someone's property, business and private records.
He was willfully obstructive and obtuse, and suffered the consequences for it, but no more than that. The sectioning is of course a matter for concern, but it requires proper medical oversight and bearing in mind his previous history of mental illness there's no particular reason to believe it was malicious.
However, specific inferences can be drawn from your silence in some circumstances. For example not mentioning something in you statement to police that you later rely on for your defence in court can be taken into account.
So we don't have an absolute right to remain silent, and doing so under suspicious circumstances can get you in trouble, but you can't be prosecuted just for not making a statement.
The UK consists of England, Wales, Scotland and Northern Ireland. 3 different legal systems (though England and Wales and Northern Ireland are similar).
Scotland is radically different with many things being criminal offences in Scotland but are perfectly legal in the other 3 countries, e.g. certain types of violent pornography are serious jail time in Scotland but legal elsewhere in the UK. Plus the knife thing, obviously. Children of 8 years are criminally responsible [i.e. /are/ prosecuted] in Scotland but it is older elsewhere in the UK.
> It is illegal to [...] carry a knife in public without good reason - unless it’s a knife with a folding blade 3 inches long (7.62 cm) or less, eg a Swiss Army knife.
(it doesn't mean what you're saying is untrue!)
But there is nothing in the law stopping you from saying up front "the only reason I would revoke my encryption key without explanation is if I'm legally obliged to by the cops under the Regulation of Investigatory Powers Act". And when you do so, anyone with a brain can draw the relevant inference...
It might be prudent to start campaigning against the most egregious provisions of RIPA.
Considering how close UK and US are, it could go like this: raise public awareness about PRISM and the like, prompting people to encrypt their stuff. Now, imprison everyone who has encrypted files.
It's like adding a fluorescent agent in a medium to highlight bacteria.
Incidentally this is the same law that is also being used to legally justify GCHQ's Tempora operation (the UK's PRISM), according to this Guardian article[1] and discussed on HN previously.
[1] http://www.guardian.co.uk/uk/2013/jun/21/gchq-cables-secret-...
It is a sufficient defence in law to state that you do not have access to the key file. The only requirements being that you can show some backing and that the prosecution cannot prove beyond a reasonable doubt that you do have access to it.
How do you prove you don't have access to a key to data that isn't actually encrypted? Do you need to keep sets of fake keys for sensor data that you lose, so you have a defense?
Ideally, encrypted data is indistinguishable from random data, otherwise known as "noise". Sensor data, radio telescope data and so forth often contain lots of that: it's just a LARGE file of bits that seem uncorrelated. No one can prove that a multi-gigabyte file of recorded data contains that, as opposed to them having renamed super-secret.tar.gz to sensor-logs.tar.gz.
Since no one can tell the difference, there's a pretty reasonable fear that police could see data related to your hobby (dumping ROMs, analyzing data, etc) and say, "You need to decrypt this so that we can see that it doesn't have $(illegal stuff) in it".
I'm not trying to be mean, by the way, I'd honestly like to know. ^^;
I would so go to jail.
Bit of a liability though, if I ever come under suspicion of anything. I just can't bear to nuke them though.
I'd expect a sane judge to treat cases like these as circumstantial evidence — e.g. the police thinks that random data is really encrypted data, but has no proof. From what I know, it is difficult (though not impossible) to land in jail based on circumstantial evidence.
I guess if you use encryption tools that add unencrypted metadata headers (as in "this is a file encrypted using AES-256 in CBC mode"), then the evidence is stronger.
http://www.devttys0.com/2013/06/differentiate-encryption-fro...
http://www.devttys0.com/2013/06/encryption-vs-compression-pa...
Hopefully there'll be a part 3 that gives an excuse to resubmit :)
You could just store a 1 time pad somewhere that decrypts it to cat pictures
If you have that 1GB file that simply can't explain, just xor it with some cat photos.
I'm not actually sure that TrueCrypt lets you separate these two aspects of creating a hidden drive, but Linux's tools do. With LVM (to create volumes in volumes) you could create a partition which exists within an encrypted partition, so that it's full with random data to begin with -- but then you could plausibly have forgotten to do anything with it after your computer was up and running.
Large random-looking files are a bit different; if someone were to ask "what's this 10 gig file of random data doing on your hard drive?" it would seem hard to answer them. The only thing that I know people use that much random data for is testing an RNG for its statistical properties.
One password decrypts the normal volume and another decrypts the hidden volume. However, with just the normal volume password you can't determine the existence of the hidden volume (as long as you take some precautions to prevent leaking of information about the hidden volume)
I never really saw a deep potential for those -- the problem being that you cannot open the outer drive for writing without providing the password which enables the inner drive's reading, which means that you're constantly leaking that information whenever you're using the outer drive (which ideally would be relatively frequent, so as to justify that it's not masking a hidden drive. So I'd just totally forgotten that TrueCrypt could do that. My mistake.
Your denial would be "When I last reformatted the drive, I used random overwriting."
what is the even the fucking point in having a password if the state can just ask you for it?
Encryption is there to protect against thieves, hackers, and other unlawful surveillance. Using encryption isn't ever going to make you impervious to the legal discovery process.
no it's not, bad analogy. in the US the state can't put you in jail for not giving a password (remaining silent).