Slashdot Mirror


Merely Cloaking Data May Be Incriminating?

n0g writes "In a recent submission to Bugtraq, Larry Gill of Guidance Software refutes some bug reports for the forensic analysis product EnCase Forensic Edition. The refutation is interesting, but one comment raises an important privacy issue. When talking about users creating loops in NTFS directories to hide data, Gill says, 'The purposeful hiding of data by the subject of an investigation is in itself important evidence and there are many scenarios where intentional data cloaking provides incriminating evidence, even if the perpetrator is successful in cloaking the data itself.' That begs the question: if one cloaks data by encrypting it, exactly what incriminating evidence does that provide? And how important is that evidence compared to the absence of anything else found that was incriminating? Are we no longer allowed to have any secrets, even on our own systems?"

17 of 418 comments (clear)

  1. Other types of cloaking... by fonik · · Score: 5, Insightful

    What about using a rare file system? If I want to put all of my stuff on ZFS and the FBI can't read it will they ship me off to Gitmo?

    1. Re:Other types of cloaking... by fonik · · Score: 5, Insightful

      Offtopic? I think this is a perfect question to ask. Why is it incriminating simply to have something in a format that investigators might not understand? What if I decide to keep all of my documents in Mandarin instead of English? Is that incriminating?

      Also, The linked article is on local vulnerabilities in two common forensic software packages and doesn't even mention data "cloaking" techniques. If anything is offtopic here, it's the article or the headline.

  2. Why even ask? by nurb432 · · Score: 4, Insightful

    "Are we no longer allowed to have any secrets, even on our own systems?"

    Why do you even have to ask? As private citizens we arent allowed to hide anything from the government. Its labeled as obstruction of justice and we get tossed in the can if we dont cough up the keys. Even if we have nothing to hide.

    --
    ---- Booth was a patriot ----
    1. Re:Why even ask? by Ice+Wewe · · Score: 5, Insightful
      Rock on, Hyde!

      I'd just like to point out, that if creating loops in NTFS is incriminating, does having an encrypted file system mean we have something to hide? Or, for that matter, wouldn't DRM be an obstruction, since it prevents access to content? Oh, right, DRM isn't bad, because it has large, multi-national corporations giving large campaign contributions-- err, I mean, supporting it.

      Hooray for capitalism!

    2. Re:Why even ask? by sjames · · Score: 5, Insightful

      Yep, there you have it. Police are allowed to look at anything in plain sight but need probable cause to look at anything else. Of course, that means nothing when simply having something not in plain sight is considered probable cause.

    3. Re:Why even ask? by Evilest+Doer · · Score: 5, Insightful

      does having an encrypted file system mean we have something to hide?
      Of course you have something to hide. You have your tax returns, financial statements, personal journals, and other private files to hide from malicious hackers and people who might run off with your laptop. If you are in the financial industry, you have other people's private information to hide (or, at least, that's what you should do). The problem is the absurd assumption that, since we are using encryption, we have something illegal to hide.
      --
      I feel like death on a soda cracker.
    4. Re:Why even ask? by mlts · · Score: 5, Insightful

      I use encryption for exactly what the parent poster described. On my laptop, why allow what would be "just" a hardware theft with use of encryption turn into a hardware, data, and possibly identity theft? This is why I use some form of whole disk encryption (BestCrypt Volume encryption, PGP WDE, WinMagic MySecureDoc, etc.)

      There is a definite need for encryption, and more than just the tired (and flawed) logic of "hiding from forensics", or "hiding illegal stuff" that a lot of people state.

      For most companies, physical theft of equipment or media is a valid concern. For example, if someone steals a backup tape that is part of an encrypted backup set (or storage pool, depending on the terminology of the backup system), the company owning the tape can hire some private investigators to quietly hunt down the tape. Without encryption, it can mean serious losses (or prison time)if the info on the tape was any way sensitive, and SOX, HIPAA, or other corporate regulations get violated.

  3. Good luck... by Penguinisto · · Score: 4, Insightful
    If the one and only bit of evidence on hand is the fact that someone uses an encrypted filesystem, good luck getting a conviction in criminal trial, especially if the defendant has a credible (-sounding) reason for doing so (e.g. "I've been bitten by viruses enough to want to protect myself from identity theft and I certainly don't trust a prosecutor that is obviously persecuting me right now, etc")

    Absent any other damning evidence (other concrete evidence found at the defendant's house, financial records at banks and such pointing straight to the suspect, witness testimony, etc), the prosecutor is pretty much fscked if he thinks a jury (dumb as they may be) is going to buy any counter-argument to even a halfway cogent alibi. Everyone knows that Windows is insecure. Everyone knows someone who got a virus. Everyone knows that identity theft is a Bad Thing(tm).

    Sorry, but I somehow don't see how a whole case could hinge on just one bit of evidence: "well, he has an encrypted filesystem, and he keeps invoking the 4th/5th amendments(?) in order to not unlock it, so you must convict..."

    Then there's the whole "evidence of absence is not absence of evidence" bit.

    Not much left to be useful after all that...

    /P

    --
    Quo usque tandem abutere, Nimbus, patientia nostra?
  4. The police mindset by Pig+Hogger · · Score: 5, Insightful
    One has to take account of the police mindset. The police will not trust anyone at all . Period.

    And the police expect total control of any given situation. Whenever one does not cooperate with the police, the police no longer is in total control and will take whatever measures are necessary to regain total control.

    Adding those two points simply will make that anyone who hides stuff from the police is automatically an ennemy that has to be controlled at once.

    As a matter of fact, one cannot never win against the police. In a courtroom, yes, maybe, but not against the police.

    So the obvious solution is that everyone should perform maximum obfuscation/encrypting of data, the idea being that one cannot jail a whole country.

    1. Re:The police mindset by drgonzo59 · · Score: 3, Insightful
      Great point.


      One has also to keep in mind that policemen are not policemen because they all have PhD's in Quantum Physics and refused tenure-track faculty positions at top universities to go and "serve and protect". To put it more bluntly, many of them are not very bright. And when people with guns who are not very bright lose control, it's not pretty (regardless on which side of the law they are). The trick is then not to only encrypt data but to encrypt it hide it altogether -- yes, steganography. Want to hide your data, then really "hide" it, don't just put it in super secure "safe" but leave the safe right in the middle of the living room. The not-so-bright people with guns have many ways of "persuasion" where they will make you give them the key eventually.

  5. Re:4th Amendment by nurb432 · · Score: 4, Insightful

    Yes, the 4th applies until you are ordered to by a judge. ( you cant just turn down a search warrant when the cop is at the door waving it at you ). Once the judge hands down the order you dont have a choice, unless perhaps you try to plead the 5th, and i still bet that wont apply if you refuse to hand over 'documents' that were authorized to be seized by the warrant..

    --
    ---- Booth was a patriot ----
  6. Encrypt everything by J'raxis · · Score: 3, Insightful

    Encrypt everything, hide everything. Then they can't point to this-or-that encrypted file and say that that's the one that must contain the incriminating evidence. The fact that most people do indeed only hide stuff when they "know they're doing something wrong" only helps the bastards build their cases.

  7. Zonk should know better by now. by Anonymous Coward · · Score: 5, Insightful

    While languages DO evolve over time, simply using a phrase incorrectly is not evolution, even if the mistake is common.

    Furthermore, when you start multiplying the meanings that a word or phrase can have, you start reducing its usefulness. When it cannot make a specific idea clear, in contexts where the meaning may be ambiguous one now has to use even more words to get their idea across.

    Anyway, this specific mistake has been pointed out many times on slashdot. Zonk really should know better by now.

  8. The Matter of Privacy by Genda · · Score: 4, Insightful

    There is no promise of Privacy in the Constitution, and even if there ever had been, we'd have ground that right down to a bloody stump by now with the growing power of technology on one side and the exploding power of government and big business on the other. It's hard to even say that in a world with accelerating technology and the ability to grow weapons of mass destruction in your own garage or basement, that there isn't some justifiable need for privacy to give way to greater security.

    That said, Govenment and big Business have proven beyond any shadow of a doubt that they cannot be trusted to wield the power of absoute intrusion with intelligence, dignity, or even a modicum of good taste. Microsoft is planning to turn your personal computer into their data tap in your home, a private spy on your desk... and what about our government, just today, four men falsely accused of murder in Boston by the FBI (two of whom died in prison and two others who spent 30 year behind bars), just got record making settlements of $102,000,000.00 for malicious prosecution and false imprisonment. Are these really the folks you wants to be watching every atom of your transparent life day in and day out? God help you if it becomes in their political or financial interest to have you made into "Soylent" (pick a color.)

    So if we're going to live in a transparent society, where every person is;

    • Videod from the time they leave their front door to the time the get back in the evening,
    • Having every network packet they send or receive deep scanned for content, ownership, recipients, and legality,
    • Running a computer with hardware and software providing virtually total exposure to data collecting agent both benign and malignant,
    • And ultimately where every appliance, every room, every space will be filled with intelligent sensors recording every action, preference, habit, activity, and affiliation that any of us might have,
    then we are clearly far overdue for the creation of a new Bill of Rights. We must begin to think about the implications of our technology, and how the clear and unbridled abuse of that power by a loathsome few endangers all of us. If the world is to become transparent, then we must be assured that the eyes that see us, are fair, impartial, and dedicated to the sanctity of our humanity, and our dignity. In short those eyes cannot be human. They can be programmed by humans (who are themselves seen transparently by all), so that the tools that insure our safety, our comfort, ease, and efficiency, aren't used against us by greedy, power hungry, or despotic men. The temptation for misuse is simply too great, we must relenquish the process of watching people to ever smarter machines who have been programmed to act in our best interest. We need to make the breaking of these laws or personal protections prunishable by the most draconian measures. We need to watch the watcher and perhaps even watch those. We need to give people the blessings of infinite information without robbing them of every last shred of their humanity.

    In the end, this may indeed be the greatest challenge of the twenty first century

  9. You Don't Even Have to Actually Cloak Any Data... by SwashbucklingCowboy · · Score: 5, Insightful
    From http://news.com.com/Minnesota+court+takes+dim+view +of+encryption/2100-1030_3-5718978.html

    A Minnesota appeals court has ruled that the presence of encryption software on a computer may be viewed as evidence of criminal intent.

    So, according to the morons on that court, even if you haven't actually encrypted any data, the fact that you had the tools to encrypt data was enough to judge criminal intent, sort of like possession of burglary tools. The problem, of course, is that encryption software has legitimate uses.

    I wonder if any of those judges had Microsoft Office on their computers - if they did then they possessed encryption software and could be viewed as having criminal intent.

  10. Guilty until proven innocent by TapeCutter · · Score: 5, Insightful

    "I think this is a perfect question to ask."

    I agree, technically speaking all data is "encrypted", it's the strength of the encryption that varies. Are we to assume that if forensics can't understand it then it is automatically incriminating? - That's nothing short of "guilty until proven innocent", under that policy the suspect can be locked away until he gives the investigators the non-existant key to unscramble the random sequence of bits found in the free sectors of his HDD.

    "Also, The linked article...."

    As is the custom on /. I didn't RTFA before shooting my mouth off.

    --
    And did you exchange a walk on part in the war for a lead role in a cage? - Pink Floyd.
    1. Re:Guilty until proven innocent by javaman235 · · Score: 4, Insightful

      technically speaking all data is "encrypted", it's the strength of the encryption that varies.

      Really good point. Any compression system might be viewed as encryption if you don't know how to decompress it.

      I actually had to throw together an encryption system today to store some archival material online. I wrote a one time pad in python where my pad was just a jpeg of a mountain I had lying around. I contend that my ciphertext is art, a picture of a mountain combined with some literature. Who's to say it isn't?

      When it gets to he point where you can blame other people for your inability to understand what they are saying when they weren't speaking to you, the deaf and mentally disabled will rule the world.

      --
      -The art of programming is the pursuit of absolute simplicity.