In UK, Two Convicted of Refusing To Decrypt Data
ACKyushu clues us to recent news out of the UK, where two people have been successfully prosecuted for refusing to provide authorities with their encryption keys, resulting in landmark convictions that may have carried jail sentences of up to five years. There is uncertainty in that the names of the people convicted were not released; and without those names, the Crown Prosecution Service said it was unable to track down details of the cases. "Failure to comply with a section 49 notice carries a sentence of up to two years jail plus fines. Failure to comply during a national security investigation carries up to five years jail. ... Of the 15 individuals served, 11 did not comply with the notices. Of the 11, seven were charged and two convicted. Sir Christopher [Rose, the government's Chief Surveillance Commissioner] did not report whether prosecutions failed or are pending against the five charged but not convicted in the period covered by his report."
This means, you can be forced to do self-incrimination. What's next? Do we remove the right to remain silent? In dubio contra reo?
A hundred years ago today, if someone had a giant safe in their house, and they were suspected of any crime whatsoever, the legal authorities (of pretty much every country in the world, it would baffle me to hear about somewhere this would not be the case) would simply ask for the keys. If the person refused to hand them over, the person gets punished. The "punishment" can be of different forms - whether prison in itself, or just a lot more unfavourable treatment from a judge and the assumption of guilt going against you, but nothing at all? Never. The difference with encryption keys is not all that great.
Suppose I have TrueCrypt installed on my machine, but I don't have anything encrypted. What stops to police from accusing me of having encrypted files and demanding a key? How do I prove random bits of data on my HD are random bits of data and not super secret encrypted files?
I doubt I even need Truecrypt installed for the police to use this to get a guaranteed 2 or 5 year conviction.
It's an appalling piece of legislation for a number of reasons:
1. It makes forgetting your decryption key/passphrase/whatever illegal. Yes, seriously. The burden of proof is on the accused to show that they can no longer decrypt the data - how the hell do you prove you don't have something?
2. The people who it was originally intended to inconvenience - the real terrorists, if you like - aren't going to be even remotely concerned by it. They know full well that there is a risk they'll be caught and spend time in jail. If it's a choice between "reveal the decryption key, thus providing the police with the only evidence they're likely to find which implicates you and a number of others for so many criminal activities you'll be in prison for 20 years and when you get out you'll get a bullet in the head for the people who you dropped in it" or "keep your mouth shut, go to prison for two years", I wonder which one they'll chose?
The is so wrong. The logic of the law is that you are now legally liable for your memory. Can't remember something 5 years in prison, it is by far the most offensive legislation there is, hmm, what next death penalty for amnesiacs.
I have forgotten lots of passwords, I have had to rebuild data, redo secure OS installs, drop web accounts, have passwords reset and what some fucked up government and corrupt court decide that they want that information, my total by now 5 years at a time would be up around 250 years in jail. The law is bullshit, there is a profound difference between telling a lie and withholding the truth, conscious effort is required to tell the lie but withholding the truth simply requires a lapse of memory. How many people, failed to get every answer right in every test and exam they have taken, billions of people, it is the norm and in by far the majority of instances, they had been provided all the information required to get 100 percent on those tests and exams.
Now lets start holding politicians to the same standard, zero forgetfulness, zero lapses of memory, zero forgotten promises, 5 years jail for every offences, oh yeah, because it does affect national security.
Chaos - everything, everywhere, everywhen
They can claim that any bunch of random data on your disk is actually hiding something encrypted
This may be technically true, and the poor, random, but arrested sod may get away with the usual blank stares. Anyone using TC, Vsoft, or any of the full disk encryption software on the other hand, will have a hard time convincing me or anybody that the random stuff on your drive is not actually data if the boot loader pops up.
As for me, the wall in my study room also happens to be, ehm, decorated with some certificates for IT courses, photos and old entrance tickets from LAN parties etc. and I have books about technical/programming stuff lying around. How are you EVER going to convince anybody that you don't know how that 'random data' ended up on your hard drive?
Unless full disk encryption is enabled by default in future operating systems, blank stares or denying the obvious are not going to get us out of trouble.
MMO Vampire Role Playing
Item 2, terrorism is defined in UK law, and judges have to abide by that law. The definition is not "up to the authorities". It is made by Parliament. If you don't like the definition, write to your MP, join a political party or a pressure group (there are lots) and do something, don't just whine. And if you are a 16 year old posting from your bedroom, William Hague was addressing a Party conference at 16, and I was visiting Parliament several times a year at the same age. You have no excuses. We have senior MPs who get it - David Davis, Chris Huhne.
Item 3.Others have made the point that the UK has had animal rights activists every bit as bonkers and dangerous as US anti-abortion or anti-gun-control activists. But the point also needs to be made that law must be general and not have exceptions. Exceptions make bad law. If we start deciding who is or who is not a terrorist based on anything other than their actions and intentions, this is very dangerous for civil liberties.
Although I think this is an unfortunate law, it is difficult to see how it could be any different. What is your proposal to prevent organised crime using encrypted media to conceal their activities? Unless you can point to a workable alternative solution, you are just ranting.
From scarped cliff or quarried stone she cries "A thousand types are gone, I care for nothing, no not one."