Slashdot Mirror


'Sorry, I've Forgotten My Decryption Password' is Contempt Of Court, Pal - US Appeal Judges (theregister.co.uk)

Thomas Claburn, reporting for The Register: The US Third Circuit Court of Appeals today upheld a lower court ruling of contempt against a chap who claimed he couldn't remember the password to decrypt his computer's hard drives. In so doing, the appeals court opted not to address a lower court's rejection of the defendant's argument that being forced to reveal his password violated his Fifth Amendment protection against self-incrimination. In the case under review, the US District Court for the Eastern District of Pennsylvania held the defendant (referred to in court documents as "John Doe" because his case is partially under seal) in contempt of court for willfully disobeying and resisting an order to decrypt external hard drives that had been attached to his Mac Pro computer. The defendant's computer, two external hard drives, an iPhone 5S, and an iPhone 6 Plus had been seized as part of a child pornography investigation.

522 comments

  1. Contempt of the court... by ruir · · Score: 5, Insightful

    I do not even know any of the passwords I use either at home or work....random passwords+2FA. I could not even remember them, even if my life depended on it.

    1. Re:Contempt of the court... by Midnight_Falcon · · Score: 4, Insightful

      But you have some way to summon them through a password manager, and a Court would simply order you to release those credentials.

    2. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Then start learning them right now. Get off Slashdot right now and learn them! RIGHT NOW!!!

    3. Re:Contempt of the court... by Mashiki · · Score: 2

      Under stress, and my poor memory due to my job, I can't remember the password. I write it down, but I seem to have lost it.

      --
      Om, nomnomnom...
    4. Re:Contempt of the court... by ArchieBunker · · Score: 1

      Well say hello to a jail cell then. You can be help for contempt for a very long time.

      --
      Only the State obtains its revenue by coercion. - Murray Rothbard
    5. Re:Contempt of the court... by Anonymous Coward · · Score: 1

      that's exactly the problem, you're trying to apply a technical "fix" to a legal problem. a court/judge does not give a fuck how many layers of technobabble you added, you locked the drive, you can unlock it...

    6. Re:Contempt of the court... by sims+2 · · Score: 1

      Sounds like someone's never heard of asymmetric cryptography you can encrypt files without having the ability to decrypt them. Of course that's not usually the type of encryption used to secure entire drives.

      --
      Minimum threshold fixed. Thanks!
    7. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Technically, Contempt can only be used as long as its an effective way for the court to get someone to produce something. The idea being the person in contempt has the keys to his own freedom.

      After some period of time in jail, most people just go crazy, at which point the court cant really keep them in Jail, however there are cases of up to 17 years in jail for contempt on something that did not exist (money lost in bad stock trades, could not be proven to exist, but the court felt he was good at hiding the money).

      He could be in Jail for a long time because of this ruling.

    8. Re:Contempt of the court... by Mashiki · · Score: 4, Interesting

      All you need is a lawyer who's willing to argue that police lost evidence of this during arrest/warrant sweep. Happens quite often and there's a lot of case law on it.

      --
      Om, nomnomnom...
    9. Re:Contempt of the court... by edeefelt · · Score: 2

      I could see a case for contempt if it can be "proven" one is lying about forgetting the password, or has some other way to access the password; refusing to share it. I do not understand calling contempt for forgetting something.

    10. Re:Contempt of the court... by Anonymous Coward · · Score: 0, Insightful

      Technically, Contempt can only be used as long as its an effective way for the court to get someone to produce something. The idea being the person in contempt has the keys to his own freedom.

      After some period of time in jail, most people just go crazy, at which point the court cant really keep them in Jail, however there are cases of up to 17 years in jail for contempt on something that did not exist (money lost in bad stock trades, could not be proven to exist, but the court felt he was good at hiding the money).

      He could be in Jail for a long time because of this ruling.

      this is true up to but not including the point where the court violates the fourth and fifth amendment rights of the person in question. You can form the argument any way you want (as the Trump administration tends to do, and the Bush administration before it... But ... but TERRORISM! But but.. The Children! but but.. ) The court cannot violate the constitutional rights of anyone. They are using this as a way to take advantage of the ignorance of the law of the people in question. If it were me, I would move for a mistrial because clearly there is no way this court is going to hold to the letter of the law and the constitution. Good luck getting it to stick though if the judge is going to play fast and loose with the rules. This is what you get guys.. when you vote Republican! Go ahead and mod me down and prove me right!

      Just because you don't like a fact does not magically make it not true all of a sudden. This is why most of the world looks at the election of Trump and thinks that Americans are idiots. They forget the majority of us voted for Hillary. We are on a slippery slope here!

    11. Re: Contempt of the court... by Anonymous Coward · · Score: 2

      You have to be joking that the rest of the world would have thought highly of another President Clinton.

    12. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Written on paper. Paper burns. Always keep lots of candles on desk for credible story of how the accident happened. The people entering your house without knocking scared you and you dropped the notebook into the candle.

    13. Re: Contempt of the court... by Calydor · · Score: 3, Insightful

      A friggin' mole hill would still be higher than what the rest of the world thinks of Comrade Trump.

      --
      -=This sig has nothing to do with my comment. Move along now=-
    14. Re:Contempt of the court... by Anonymous Coward · · Score: 0, Insightful

      This is what you get guys.. when you vote Republican!

      Why didn't Obama and the dems clear this up (since that was an appeal)? Right, because it has nothing to do with political parties.
      I mean you led with the repetition of logical thought from other posts, but then you let the crazy slip out and lost any sense of credibility or surprise. Whoops.

    15. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      you are going to claim that you used someone else's public key to encrypt your entire hard drive? Good luck with that.

    16. Re:Contempt of the court... by Altrag · · Score: 3, Insightful

      Well someone, somewhere needs to have the ability to decrypt them. They're rather useless otherwise and you may as well just delete the files. And if you have a way to decrypt them at all, then they could easily extend this ruling of contempt to include any intermediate steps required.

      The only way "I don't know how to decrypt them" really holds up even in a hypothetical is if you were using an asymmetric key to generate the encrypted files for an anonymous third party that you have no direct contact with, and they managed to get you at just the right time between purging your local copies and shipping off the encrypted ones.

      And even then, you'd have to have some way to get the data to said third party which means a trail of some sort (albeit possibly a cold trail if it leads out of the country or something.)

      Sadly your best bet in a situation like this is to appeal to the constitution.. somewhere between the 4th and 5th amendments in this case.. but even that's on shaky ground as the courts are still trying to figure out how (or even if) 200 year old laws should be applied to modern digital devices.

    17. Re:Contempt of the court... by mi · · Score: 2, Interesting

      asymmetric cryptography [with which] you can encrypt files without having the ability to decrypt them

      Irrelevant.

      Of course that's not usually the type of encryption used to secure entire drives.

      Of course, it is not — and the judge is well aware of it. He had these large drives attached to your computer. They both agree, he accessed the data on them with a password. He claims, he no longer remembers the password — well, the judge happens to not believe him.

      This is not a Constitutional question — the guy is not asked to testify against himself. What he is to say is not under oath and will not be used against him. What is demanded of him is a key to the premises, for which a perfectly valid search-warrant has already been issued.

      That the key happens to be a word — rather than something tangible like a metal key or a thumb-print — is irrelevant and does not magically add a Constitutional protection.

      --
      In Soviet Washington the swamp drains you.
    18. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      I've got a stack of hard drives at home that I can't remember passwords for the encryption on, they are so old. I guess I better through them out.

    19. Re: Contempt of the court... by nobuddy · · Score: 0

      thought better of than Trump and thought highly of are not the same thing.

      If Hillary had taken a steaming shit on the Resolute Desk and declared that President, the world would view it higher than Trump.

    20. Re:Contempt of the court... by nobuddy · · Score: 3, Interesting

      No, but you can set your encryption to scramble the key if there are (X) false attempts. Or even to scramble if a certain password is entered instead of the real one. And, if you used reasonably secure encryption, once that is done, its toast. I cannot ever be decrypted with today's technology. And likely can never be decrypted, ever.

      judge won't like it. Prosecution won't like it. But it is easy to prove that this is a fact.

    21. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Yeah I don't understand how this works if you don't actually memorize passwords. WTF. Just because the judge is an idiot and uses passwords he can remember doesn't mean the rest of us do.

    22. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      That assumes they have the password safe.

    23. Re: Contempt of the court... by Anonymous Coward · · Score: 5, Informative

      No, you cannot "set your encryption" to do that. Your shit will be imaged.

    24. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Here's my question, is it jail, or prison? Because this could generally work out very favorable. Jail is preferable over prison, and time held in jail counts towards imprisonment time. If they can't put you in prison and just hold you in jail indefinitely for something that would see you in prison for a very long time, this is a winning strategy.

    25. Re: Contempt of the court... by sims+2 · · Score: 1

      The device erase if password entered incorrectly x times has been used to limited success by apple with their secure enclave.

      They keep finding new ways to break it tho.

      --
      Minimum threshold fixed. Thanks!
    26. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Here in Canada, we were hoping that Hillary was going to collapse and die any time soon. Satan would have been a better choice than her.

    27. Re: Contempt of the court... by reboot246 · · Score: 0

      You're full to the max with hate. Trump doesn't give a damn about what you or the rest of the world thinks. He's there and you're not. Get over it.

    28. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Post it note sticked under the keyboard! How come forensic lost the post it note?

    29. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      You have to be joking that the rest of the world would have thought highly of another President Clinton.

      It is either facts or fake news. You cannot have both. If the American people are so easily fooled by that narrative, then we do not deserve the nation we have.

    30. Re:Contempt of the court... by Dread_ed · · Score: 4, Informative

      We don't need to mod you down. Just present facts. Not that I am a Trump supporter, but I can tell from how you write that you are unhinged due to rampant bias. It is affecting your mind. Specifically, but not limited to, your ability to process data, form correct opinions, and see facts as they are.

      Case in point:

      District Judge: Honorable L. Felipe Restrepo

      He is an Obama appointee who made the original ruling and whose ruling the third circuit court of appeals upheld.

      Please tell me how an Obama appointee is part of a vast right wing republican conspiracy to attack Americans.

      --
      When the only tool you have is a claw hammer every problem starts to look like the back of someone's skull.
    31. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      This is what you get guys.. when you vote Republican!

      Why didn't Obama and the dems clear this up (since that was an appeal)? Right, because it has nothing to do with political parties.
      I mean you led with the repetition of logical thought from other posts, but then you let the crazy slip out and lost any sense of credibility or surprise. Whoops.

      Clearly you borrow from the political strategy of doing something nefarious and then blaming your opponent of doing what you did. There was never any opportunity for Obama to do anything with this. As for this having to do with political parties, Republicans do this kind of bait and switch crap all the time and the low end models (like yourself) eat it up and repeat it again and again until they believe it.

      You said that I let crazy slip out? I was simply pointing out what they did, What republicans do and what you just did. You have a very broad definition of crazy.
      Breaks over, Get back to your greeter job at WalMart before you get fired and blame it on Obama!

    32. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      A legal problem that does not, in theory, exist. A hard drive is nothing more than a pad of paper, made out of metal, and written to using magnets. And it is not my job to teach police how to read the fictional language I used when writing to that pad of paper.

    33. Re:Contempt of the court... by by+(1706743) · · Score: 1

      Even if it was destroyed/burned entirely on purpose, would that be contempt-able? From other posts it sounds like that would no longer fall under contempt (though perhaps it's another crime...?).

    34. Re:Contempt of the court... by Dread_ed · · Score: 1

      "That the key happens to be a word — rather than something tangible like a metal key or a thumb-print — is irrelevant and does not magically add a Constitutional protection."

      Oh yeah, well what if his passkey is "I attest under penalty of perjury that I rape lots of kids"?

      Ta da! (I am joking of course)

      --
      When the only tool you have is a claw hammer every problem starts to look like the back of someone's skull.
    35. Re:Contempt of the court... by Highdude702 · · Score: 1

      I see you have never been to Jail or Prison, Ive been to both. I would rather do a year in prison than 6 months in jail.

    36. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Sounds like destruction of evidence, to me.

    37. Re: Contempt of the court... by Highdude702 · · Score: 1

      sounds like a winner there.. lol i could see that working "ok i dont want to go to jail, the password is written on a sticky note under the keyboard... then you just have to be smart enough to stick to the story

    38. Re:Contempt of the court... by fustakrakich · · Score: 1

      No state has the right to compel assistance in one's own prosecution, constitution or no. But in these dark time times, the bill of rights is going up in smoke anyway, so it doesn't really matter.

      --
      “He’s not deformed, he’s just drunk!”
    39. Re:Contempt of the court... by slashrio · · Score: 1

      If you have illegal content on them, then you better shred them completely.

      --
      "Trump!!", the new Godwin.
    40. Re:Contempt of the court... by Alan+R+Light · · Score: 1

      He may be in jail a long time ... and considering these particular (and unlawful) laws, he is better off being in jail on the contempt charges.

      Funny how the law never addresses the fact that many courts deserve nothing but contempt.

    41. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      I could not even remember them, even if my life depended on it.

      Authoritarians: *Click* How about now? Do you remember those passwords now?

      You: No.

      Authoritarians: *BANG*

      - The Future.

    42. Re:Contempt of the court... by hackwrench · · Score: 1

      If I understand you correctly, you are simultaneously arguing that the court is both currently violating and cannot violate this person's Constitutional rights. Nice, I guess.

    43. Re:Contempt of the court... by Anonymous Coward · · Score: 1

      This guy has been labeled a defendant which means he has been officially charged with a crime and the trial has been started. It sounds like they are in the discovery phase. A court warrant has been produced. A search warrant targeting the contents on a digital device is no different than a warrant served to search a suspect or defendants house, car, place of business, bank records, and safety deposit boxes,

      If the guy continues to refuse the court order I suspect the government's next move will be to decrypt the contents themselves using both in house and 3rd party technical resources.

      "world looks at the election of Trump and thinks that Americans are idiots"
      And since when do Americans give a shit about what foreigners think? And this state of events has been around since way before Trump was elected. Those who have railed against the US for years while also stereotyping Americans helped get Trump elected. The US has been damned if they do and damned if they don't so why shouldn't Americans support a foreign policy where everyone starts paying their share if they want to live under the security umbrella? Isn't it a bit ironic that people love to denigrate the US non-stop while at the same time raising a fuss because they cannot get into the country. Even government officials from around the world who love to complain about the US have toned down their complaints because the current US President might take offense? Even China has toned down their criticisms because they cannot reliably predict what Trump may do. The US has followed a predictable foreign policy for years. So predictable that it's enemies and rivals know exactly what the US response would be in a given situation. Russia's is busy annexing Eastern Europe while China is trying to annexing the entire South China sea. Terrorist know they can live to fight another day as long as they plant themselves in the middle of woman and children. Russia got away with carpet bombing large cities in Syria. If the US had did the same thing you would never hear the end of it from the people who adamantly refuse to acknowledge that the US is not the only country on the planet. You would think the US runs the only foreign intelligence agencies in the world. Let's closedown the CIA and NSA and just let the FSB do anything they want especially if it harms the US>

    44. Re:Contempt of the court... by rtb61 · · Score: 3, Informative

      It's the law, innocent until proven guilty. So the judge failed to prove the person did remember the password, hence the judge is in contempt of justice. In order to prosecute for failure to remember and state a password, the court must prove the defendant does remember it, otherwise they a just fucking guessing because that is what they want, a really horrific corruption of the justice system.

      Think of the ramifications, the court claims you saw something with no evidence of proof of that claim, you say you did not and they imprison you until you say what they want you to say. You can not legally force memory, to force people to remember and just to be clear, how many you idiots got 100% on every exam you ever took, well, according to shit for brains judge, you put down the incorrect answer on purpose. Courts are not for fucking guessing, want to make a fucking claim, then fucking prove it.

      --
      Chaos - everything, everywhere, everywhen
    45. Re: Contempt of the court... by Anonymous Coward · · Score: 1

      The rest of the world? You mean Muslims, weak Eurodhimmis, and the envious Chinese? Fuck them.

    46. Re:Contempt of the court... by ShanghaiBill · · Score: 2

      I would rather do a year in prison than 6 months in jail.

      I have never been to prison, but I was in jail, and I didn't think the experience was so bad. It was far better than what I expected from watching TV. Most people were polite and cooperative, and it was a great opportunity to practice my conversational Spanish. Even the guards were friendly. The only big downside was the food. I am a vegetarian, and most meals were baloney sandwiches. They also had peanut butter, but that got really monotonous.

      This was the Santa Clara County Jail in San Jose, California, so it is probably a nicer than average jail.

    47. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      The difference is that those are physical things that the court can have opened without the defendant doing anything. An encrypted file is only useful if the defendant interprets the contents for the court by providing the passphrase.

    48. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      The 5th Amendment doesn't just apply to testimony in a court of law. It applies to all interactions with law enforcement that are both verbal and non verbal. The 5th Amendment prevents citizens from having to engage in any self incriminating interactions with law enforcement.

      Sure that can turn into a very long stint behind bars due to being found to be in contempt of court but if you're looking at spending life in prision or something close to that anyway why not hold out even if it takes 17 years? You can attempt to appeal and get the contempt charge thrown out or simply make law enforcement look bad by showing that they can't bring charges but for information that may not even be on the device to begin with.

      I'd be willing to bet that at some point the prosecution or the judge would be willing to deal just to come to a resolution and once that happens you've got time served on your side. I fail to see how even a long contempt of court ruling leaves you worse off if you know that you're looking at 25 years to life if the government gets to the data on your device and that you may not even be able to be charged if they can't get to that data.

    49. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Hillary is a steaming shit with the blood of thousands on her hands.

    50. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      If Hillary had taken a steaming shit on the Resolute Desk and declared that President, the world would view it higher than Trump.

      Yes, Trump Derangement Syndrome is a strange, pitiable condition isn't it? I hope for their own sakes they can figure out how to get over it before the stress of 8 years of perpetual outrage drives them into an early grave. (CNN BREAKING NEWS: RACIST NAZI RACIST TRUMP FAN ISSUES RACIST DEATH THREATS AGAINST ALL NON-RACISTS)

    51. Re:Contempt of the court... by dougmc · · Score: 5, Insightful

      This is not a Constitutional question — the guy is not asked to testify against himself. What he is to say is not under oath and will not be used against him.

      It is indeed a Constitutional question. He's accused of a crime, and he's being asked, er forced to aid the prosecution. What happened to his right to remain silent, his right against self-incrimination?

      And yes, I do believe it is the goal of the prosecution to use any passwords he provides to find stuff that *will* be used against him. They are *demanding* that he aid their prosecution of him by divulging secrets ... how is that not testifying against himself? Next, are they going to waterboard him for the passwords?

      What is demanded of him is a key to the premises, for which a perfectly valid search-warrant has already been issued.

      If they were demanding a physical key, he could refuse to tell them where that is too. That said, without that ... they'll just knock down the door.

      Also ... has a search warrant been issued to search his brain?

      This stinks to high heaven. I thought that it was already established by case law that you did not have to say anything to aid the prosecution in any way, that your right to remain silent was absolute in a criminal case?

    52. Re:Contempt of the court... by Highdude702 · · Score: 1

      yea im from vegas, and jail here sucks prison isnt so bad honestly way more freedom. But the important part is i changed my life afterwards, so i guess you can say it worked.

    53. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      I can't remember my god-damned four-digit ATM PIN unless I'm standing right in front of the fucking ATM. Nor can I remember my god-damned four-digit alarm code unless I'm standing in front of the fucking alarm panel.

      Human memory is shit, and it is entirely plausible that this person forgot their password(s).

    54. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Stop lying.

      Say what?! You are asking that of a Trump supporter? You may as well ask the sun to stop shining.

    55. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Please tell me how an Obama appointee is part of a vast right wing republican conspiracy to attack Americans.

      It's all obvious, Trump's playing (3i+7)^e Dimensional Gregorian Inverse Suicide-Jack Hopscotch. If your feeble mind can't keep up with his moves, I'm afraid I can't help you.

    56. Re:Contempt of the court... by n329619 · · Score: 1

      Just state you never knew your passwords from the start, because today's magic made it you never need to. You just face roll around the keyboard and Voila! It unlocks! It's just black magic.

      Tell them that even Microsoft has some weird dark magic that if you stare at the screen long enough it unlocks.

      The court will either believe you because they probably believe it's black magic too, or they will just write you off as insane. Both are win-win.

    57. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      You have to be joking that the rest of the world would have thought highly of another President Clinton.

      "The rest of the word, not counting Russia, would have thought highly of another President Clinton." There you go.

      And yes, by a yuge margin, we would have.

    58. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Funny how the law never addresses the fact that many courts deserve nothing but contempt.

      Because you can only have contempt for that which you don't understand? The road to Auschwitz begins with lack of respect for the judicial system.

    59. Re:Contempt of the court... by Zemran · · Score: 1

      I am a cantankerous old git with a bad memory. I have forgotten more than you have learnt. I honestly forget passwords all the time. I cannot get into my Skype account and will need to create a new one as I no longer have the email account that goes with it. I could be innocently saying I cannot remember my password and be telling the truth.

      --
      I love stacking my barbecues in the shed at the end of summer - you can't beat a bit of grill on grill action.
    60. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Just tell them that you reset the password every day using some random procedure and the police destroyed or lost the scrap of paper where you write it down during their search and seizure. Then it's on the police for destruction of evidence.

    61. Re:Contempt of the court... by HiThere · · Score: 1

      That would be destruction of evidence...if done by the accused. After a warrant was served.

      OTOH, if it's set to do this after n failed attempts, then it could quite likely be done by inept police, who didn't bother to image the disk before working on it. And then it's the police who destroyed the evidence...if such it was.

      That said, I really doubt that applies in this case. But I know *I've* forgotten passwords, and had to reinstall, and recover from backups. So "I've forgotten the password" sounds possible, though unconvincing.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    62. Re:Contempt of the court... by skids · · Score: 1

      I might still have a partition sitting somewhere where I played with drive encryption and then forgot the passphrase. Nothing on it but a stock Linux install, but these days you never know when some random baseless accusation is going to fly your way.

      I guess we're all legally required to never forgot a drive password now. Feh.

      Then again, now any disgruntled tech support guy can sabotage any PHB by just putting an encrypted partition on their desktop. They can tell the judge they didn't know it was there, and don't know the password, but I guess tough luck for them.

    63. Re: Contempt of the court... by Mashiki · · Score: 1

      Canada would have voted for Hillary Clinton at around 80%. Stop lying.

      Major cities likely would, Toronto, Vancouver, Ottawa. Get outside of them however, and not a chance. Keep in mind that nearly 1/3 of the population of Canada lives in the GTA(Toronto) area. There's a reason why the liberal party both federally, and in Ontario are suffering badly. Why Trudeau Jr's suddenly "great canada tour" became very quiet in the media when he went out west, while it was touted as the second coming in Southern Ontario. But it was only the second coming in the big cities where he went. He didn't go to small towns/cities like Woodstock, St. Thomas, Smith Falls(those are all blue collar cities FYI) or anything. I'll let you put the pieces together, it's not hard.

      --
      Om, nomnomnom...
    64. Re:Contempt of the court... by HiThere · · Score: 1

      Sorry, but that's not true. I know I've forgotten my own password a few times. I had to reinstall and recover from backups. (I really don't like sudo, and I also don't like logging in as root, and a decade or so ago I forgot the root password twice. It was really annoying, but not a real problem as one of the times I'd been thinking about switching distros anyway. The other time was more annoying, but I had the original CDs, and there hadn't been THAT many updates. [I said it was over a decade ago. I think it was while I was using Red Hat Professional edition, before I switched to KRUD Linux.])

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    65. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      I wouldn't want him running my country, but I'm glad he's running yours.

    66. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      You mean how hillary style feminism has no problem with kangaroo courts where the accusation is the evidence?

    67. Re:Contempt of the court... by sjames · · Score: 1

      Not necessarily. I have an encrypted filesystem on my HD for testing purposes. Nobody, including me, has the password. I created it, threw some copies of data in it and unmounted it. I may or may not ever be able to read it back (it's looking more like may not).

    68. Re:Contempt of the court... by epyT-R · · Score: 1

      That's ok, death is preferable in such authoritarian shitholes.

    69. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Require third party (internet, TPM, enclave, your own eyeballs, etc) to provide part of decrypt key. Tell party to destroy key on incorrect password.

      You only need to make sure third party cannot be compromised, which is not trivial.

    70. Re:Contempt of the court... by mi · · Score: 1

      What happened to his right to remain silent, his right against self-incrimination?

      As I said — it is not testimony. The jury will not hear it. The 5th Amendment protects him from being compelled to be a witness against himself.

      Also ... has a search warrant been issued to search his brain?

      The search warrant has been issued for his disks. He is in a position to deny the police entrance to what they are lawfully allowed to search. If, as seems likely, he is doing that deliberately, then he really is in contempt of the judge, that issued the warrant.

      that your right to remain silent was absolute in a criminal case?

      I don't know about case law, but there is no "right to remain silent" in the Constitution. You don't have to be a witness against yourself.

      --
      In Soviet Washington the swamp drains you.
    71. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      No, you cannot "set your encryption" to do that. Your shit will be imaged.

      Valid point. It is certainly possible to create hardware that resists standard imaging and such, by making encryption at the heart of the drive and having the drive's built in controller cryptographically married to the specific motherboard. Any attempt to use it elsewhere would just create a new encryption key, not unlock the existing drive. You might be able to use that specific PC to image it, but there is where your secure boot comes in handy, particularly if you can set it to only boot your current OS.

      Whether or not they will allow such hardware to be sold is another matter, but I could see it as being the next step in Laptop security. I'd be glad to get rid of our current wde solution at work. Slow piece of crap. Still, this level of paranoia likely won't be supported for awhile.

    72. Re:Contempt of the court... by ChrisMaple · · Score: 1, Insightful

      This is what you get guys.. when you vote Republican!

      Lying under oath is standard operating procedure for leftists. So is abusing public office and flouting the law. Some of it can even be found in leftist strategy books like "Rules for Radicals".
      Just take a look at the two rejections of Trump's executive orders on entry to the US, both of which were based on the judges opinion of Trump's statements and were completely unrelated to law.

      --
      Contribute to civilization: ari.aynrand.org/donate
    73. Re: Contempt of the court... by Fwipp · · Score: 1

      You don't really sound like a lawyer.

    74. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Vote satan. Why vote for the lesser evil...

    75. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      And what exactly counts as encryption? For examale, if a prostitute keeps a spreadsheet of allife her clients but encrypts the names with RSA encryption I imagine the court would rule she must decrypt them. But what if she instead gives them nicknames? That is also a kind of encryption. But it feels a lot more like self incrimination to make her identify who is who ..

    76. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      It isn't "I don't know how" it is "I forgot the passphrase". You cannot be held in contempt for something your incapable of doing. Unless they can prove he is lying about forgetting the passphrase, he should be released (at least from the contempt charges and punishments).

    77. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Ah, once again, ChrisMaple demonstrates the capacity to lie and deceive, because of a mistaken belief in its effectiveness. You've been pulling this crap about "Rules for Radicals" so long that you forget that Machiavelli and others already trod that path.

      Seriously, though Trump's own intentions undoubtedly colored is actions, both orders were blocked because of simple and obvious defects and illegalities based on their implementation, and no matter how much Trump rages at the so-called judges, his fuming won't accomplish anything, they don't answer to him.

      They saw the sudden wave of chaos. They learned about the misguided detentions. And they know that the INS makes mistaken identifications quite often.

    78. Re: Contempt of the court... by amiga3D · · Score: 1

      He can't do it. In his world everyone hates Trump and Hilliary is the second coming of Mother Teresa. I still don't know what to think about Trump, but I have no doubts about Hilliary. Hilliary and her minions hate me and everything I care about. Given that I grabbed onto Trump like a drowning man to a log. I see his flaws but he's the only hope I have.

    79. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      The real reason for the judgement was the fact that he is manipulating images using a Mac Pro, and has the audacity of owning not one but two iPhones. That fruity bastard!

    80. Re:Contempt of the court... by gnasher719 · · Score: 2

      He may be in jail a long time ... and considering these particular (and unlawful) laws, he is better off being in jail on the contempt charges.

      When he gets out from the contempt charges, the same judge will ask for the password again.

    81. Re: Contempt of the court... by Xest · · Score: 4, Funny

      No man, you just tell your encryption don't take that shit, don't let yourself be imaged, encryption. Stand firm in the face of these fascists, encryption, and do right by me man.

    82. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      There is a simple solution for the memory-challenged: Don't use passwords and you will be fine.

    83. Re:Contempt of the court... by gnasher719 · · Score: 1

      Think of the ramifications, the court claims you saw something with no evidence of proof of that claim, you say you did not and they imprison you until you say what they want you to say.

      You see, the analogy breaks down at the point where evidence was found on his Mac, and the two encrypted drives were connected to his Mac. If you show me a random encrypted disk drive, I have no idea what the password is. If you show me an encrypted disk drive that was connected to my Mac, either I know the password, or it's stored in the keychain of the Mac so you can access it with the keychain password.

      And that's the situation this man is in. They ask for the password to an encrypted drive that he has been using.

    84. Re:Contempt of the court... by gnasher719 · · Score: 1

      Oh yeah, well what if his passkey is "I attest under penalty of perjury that I rape lots of kids"?

      That's a rather stupid password, but there is no evidence whatsoever that the password is a true statement, so it cannot be held against you.

    85. Re:Contempt of the court... by gnasher719 · · Score: 1

      No state has the right to compel assistance in one's own prosecution, constitution or no.

      Sure they do. For example, if the police comes to your home with a search warrant, you have to assist them by opening the door. In that particular situation, the police doesn't mind if you don't assist and you will not be prosecuted; they feel that having to pay for a broken door that stopped them for five seconds is enough punishment.

      You have to provide keys or code for a safe if they have a warrant. You have to unlock encrypted drives if they have a warrant. What you don't have to do is give evidence against yourself. Unlocking an encrypted drive that they already know was used by you is not giving evidence against yourself.

    86. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Which will make you guilty not only of contempt, but of destroying evidence as well.

    87. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Under stress, and my poor memory due to my job, I can't remember the password. I write it down, but I seem to have lost it.

      Doesn't matter. The authorities will use any excuse to legally ass-rape you and skull-fuck you into compliance.

    88. Re: Contempt of the court... by Carewolf · · Score: 1

      No, you cannot "set your encryption" to do that. Your shit will be imaged.

      You could get around that with hardware support. I think the newer iPhones have a key in some unreadable part which is all you passwords unlocks.

    89. Re:Contempt of the court... by tehcyder · · Score: 1

      I see you have never been to Jail or Prison, Ive been to both. I would rather do a year in prison than 6 months in jail.

      Could you explain to us non-Americans the distinction? Here in the UK we use the two words more or less interchangeably for any place where you're incarcerated.

      --
      To have a right to do a thing is not at all the same as to be right in doing it
    90. Re:Contempt of the court... by tehcyder · · Score: 1

      "The dog ate my homework" type excuses don't go down very well with judges.

      --
      To have a right to do a thing is not at all the same as to be right in doing it
    91. Re: Contempt of the court... by Marful · · Score: 1

      He shouldn't have to be for logic and reason to prevail.

      If a court wants to assert something you have to provide evidence to that assertion. Otherwise it's guilty until proven otherwise which is a farce.

    92. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Leave this pervert in a room with those encrypted drives and a device to read/view the content. Sooner or later he will decrypt those drives to jerk off to porn on those disks. Problem solved

    93. Re:Contempt of the court... by William+Baric · · Score: 3, Insightful

      If you show me an encrypted disk drive that was connected to my Mac, either I know the password, or it's stored in the keychain of the Mac so you can access it with the keychain password.

      People who call me because they have forgotten the password of their own computer and who want me to reset it is not unusual. Do you think those people are lying and they only call me to hear my beautiful voice? Don't get me wrong, I'm pretty sure the guy remembers his password, but a justice system where someone can be put in prison only because I'm pretty sure of something, without any kind of evidence, is not something I want.

    94. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Look at the size of Trump's rally crowds versus Clinton's rally crowds... The irrefutable evidence is all over Youtube - Trump's crowds were several times larger than Clinton's crowds - which means FAR MORE people support Trump than Clinton - yet still there are idiots like you who believe the lies of the controlled media.

      The Jew controls the media
      And the media controls you.

    95. Re:Contempt of the court... by ixidor · · Score: 2

      jail is where you go typically for short term storage before and during court proceedings. Prison is where you go after convicted, Jail, was locked in a grey small box 23 hours a day with nothing but a toilet. Prison, generally have several hours out of cell, access to things like tv, weights, phones, books.

    96. Re:Contempt of the court... by wiredog · · Score: 1

      Have fun in jail.

    97. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      I forgot the name for it but there is an encryption method where you have two plaintext messages encrypted together in one blob using two different keys. If the first key is used to decrypt the blob the first plaintext message is retreived, if the second key is used the second plaintext message is decrypted instead.

      Just encrypt an innocent and an incriminating plaintext together and when they ask you for the key give them the one for the former.

    98. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Actually, the first thing that any competent person would do is copy the information to prevent corruption of data.

    99. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Ah yes. The password was written on a note stuck to the device, the old glue didn't hold up very well . . .

    100. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      On the other hand, if we could put (l)users in jail for not remembering their passwords...

      Next step, how do we make the same apply to clicking on .exe e-mail attachments?

    101. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Do you think those people are lying and they only call me to hear my beautiful voice?

      You might be joking, but I've dealt with two people who have commented on me having a beautiful voice and have had higher than average problems with passwords.

    102. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Christ you're a dolt.

    103. Re:Contempt of the court... by AmiMoJo · · Score: 3, Insightful

      Trump's travel bans ran into difficulty because Trump himself said that they were Muslim bans and targeted at Muslims. After the first one failed his staff started talking about how they could make minor, cosmetic changes that meant it was still a Muslim ban but addressed the very narrow point in law that the first ruling was based on. Naturally, the courts didn't fall for it, especially as all this was said in public.

      Trump's executive orders keep failing because he is an idiot, surrounded by idiots, and none of them know how to run a government or write a legally sound executive order. Nothing to do with the judges' opinions of Trump, and everything to do with the fact that he basically argued the plaintiff's case for them outside the court so they could simply submit his speeches and tweets as their evidence.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    104. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Lying under oath is standard operating procedure for politicians.

      FTFY.

    105. Re:Contempt of the court... by AmiMoJo · · Score: 2

      You need to create plausible deniability. Keep a broken USB flash drive around. When asked for the password, tell them you use a keyfile on the USB drive instead. Oh, too bad, they broke the flash drive, now there is no way to decrypt it any more.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    106. Re:Contempt of the court... by ezdiy · · Score: 1

      Compared to rest of neckbeard libertarian drivel in here, you seem to argue well the "common sense" side typically used by law (no mod points, bummers). So let me ask you something instead, any idea what would happen in case of a dead man switch?

      Ie the moment somebody attempts to manipulate with the hardware without knowing a secret disengagement procedure, they would irrevocably destroy the data.
      Obviously, there would be substantial proof that such a mechanism indeed existed (and it's not all made up), and that it indeed triggered.

    107. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      I don't know if there is a term for that but there is at least one program that does that exact thing - TrueCrypt (actually, two - there is a successor to TrueCrypt). It has a "plausible deniability" feature that has two passwords and stores two sets of data in the same encrypted volume. I won't explain it in too much detail but it works by interleaving the two sets of encrypted data throughout the drive. It's quite clever.

    108. Re:Contempt of the court... by mi · · Score: 1

      the moment somebody attempts to manipulate with the hardware without knowing a secret disengagement procedure, they would irrevocably destroy the data

      I guess, police might accuse the owner of Destruction of Evidence — perhaps, even a conspiracy to do so, if he used somebody's help to implement it.

      The accusations should be easy to fight, because such security measures may have a number of perfectly valid and legal uses. A particularly dirty prosecutor may resort to locking the accused up anyway and let it be known (unofficially), what the accusations are — counting on the rest of the prison population to "pressure" the innocent victim of his zeal.

      But there will be no "contempt of court" — both because there'd be no point (nothing left to unlock), and because the deed was done (or set in motion) long before any "court" convened.

      --
      In Soviet Washington the swamp drains you.
    109. Re: Contempt of the court... by vtcodger · · Score: 1

      As one of the few Americans who actually knew there was a Canadian election in 2015, it seemed to me that Canadians were mostly tired of Stephen Harper rather than enthused about Justin Trudeau. And keep in mind that if polls have any validity most Americans loathed (and, still loath) both major party candidates and would have welcomed a clone of either of those guys instead of the two godawful options we were presented with.

      --
      You can't see ANYTHING from a car, You've got to get out of the goddamned contraption and walk...Edward Abbey
    110. Re:Contempt of the court... by Bob+the+Super+Hamste · · Score: 1

      For example, if the police comes to your home with a search warrant, you have to assist them by opening the door.

      I don't believe that is the case. I believe that they can just bust down the door if they want. Also I believe that I am not allowed to interfere with their search while they are executing a warrant. Similar situation for keys or combination to a safe, they can ask, I could tell them to piss off, they then rummage through my shit looking for it or go get a drill. Then again IANAL so what do I know but am fascinated by the law.

      --
      Time to offend someone
    111. Re:Contempt of the court... by Z00L00K · · Score: 1

      After enough time in jail the hard disk may be corrupt and the mind of the jailed may be corrupted to the level best described in this picture:
      https://s-media-cache-ak0.pini...

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    112. Re:Contempt of the court... by Z00L00K · · Score: 1

      The decryption key isn't a password, it's a key file stored on a RAM disk that was wiped when you turned off the computer.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    113. Re:Contempt of the court... by Z00L00K · · Score: 1

      Just make sure you have plausible stuff on the plausible deniability partition as well.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    114. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      This is not a Constitutional question — the guy is not asked to testify against himself. What he is to say is not under oath and will not be used against him. What is demanded of him is a key to the premises, for which a perfectly valid search-warrant has already been issued.

      That the key happens to be a word — rather than something tangible like a metal key or a thumb-print — is irrelevant and does not magically add a Constitutional protection.

      If I have a safe or a locked tool shed, can I be held in contempt of court if I don't remember the combination for the lock? The fact that we're dealing with a password to a digital equivalent of a safe does not magically mean you don't have any rights.

    115. Re:Contempt of the court... by ezdiy · · Score: 1

      I guess, police might accuse the owner of Destruction of Evidence [uslegal.com] — perhaps, even a conspiracy to do so, if he used somebody's help to implement it.

      I see, for example if there would be conspiring human third party (in different country), with instructions to unlock the machine remotely only as long some canary signal didnt happen (box being offline suddenly and unexpectedly..).

      The accusations should be easy to fight, because such security measures may have a number of perfectly valid and legal uses.

      You're indeed right about legitimate uses - I'm asking about commercial system actually in use (heavy duty FIPS 140) - chassis intrusion, tripping it will nuke TPM state. Disarming it physically is very difficult (akin to disarming a sophisticated bomb).

      As for destruction of evidence, I'm assuming the typical DC procedure where imaging/seizure attempt is made without prior notification to the owner (normally sensible thing, to prevent tipoffs). But if the owner is present during the raid, would he have to mention presence of the tripwire, or keeping the mouth shut is ok?

      A particularly dirty prosecutor may resort to locking the accused up anyway and let it be known (unofficially), what the accusations are — counting on the rest of the prison population to "pressure" the innocent victim of his zeal.

      Care to elaborate? You mean as means of torture to make sure there indeed are no backups somewhere (making a TPM key backups somewhere and simply omitting to mention it exists to anyone is indeed the sensible thing to do with canary/DMS setups).

    116. Re: Contempt of the court... by Bob+the+Super+Hamste · · Score: 1

      There are procedures for handling drives when conducting forensic examinations. Any examiner worth their salt would do the following:
      1. document their receiving of the drive, tag it, and photograph it
      2. bring it to their secure test bench and remove the physical drive from its enclosure
      3. connect the physical drive to a write blocker
      4. begin imaging the drive to 2 separate drives just to make sure you have a valid copy (dd is an acceptable tool and is preferred)
      5. compute a hash of the data on the original drive
      6. compute a hash of the images that were created
      7. disconnect the original drive
      8. put the original drive back into its enclosure
      9. lock the original drive up in the evidence locker with the computed hash of the drive
      10. document what was done
      11. Begin work on trying to decrypt one of the images using known hardware. If you screw it up you clone from the other copy you made
      12. document what was done.

      Also to further prevent questions about the handling of the drive steps 2-9 would likely be recorded so that it can be shown that there wasn't tampering. At this point your deadmans' switch means nothing as they will be working with forensic copies of the data. A process like this needs to be repeatable and expect the defense to attempt to question everything you did if you find something so you better use widely available tools and common accepted practices for this or be able to explain in detail what you did, how it works and why you did it. Also expect the defense to also pull an image of the drive using their forensic experts and they will also compute hashes so you better hope the drive isn't damaged by your activities. There is all sorts of procedures for handling equipment to ensure that it hasn't been tampered with or damaged that you will also need to follow. Yes I know a fair amount about this as I took a computer forensics class (a real semester long course for real college credit and not some bullshit seminar) a while back at one of the local universities that was populated mostly with current or future cops. It was a fascinating course.

      --
      Time to offend someone
    117. Re:Contempt of the court... by Bob+the+Super+Hamste · · Score: 1

      This is the reason why I don't have my /. account from '98

      --
      Time to offend someone
    118. Re:Contempt of the court... by houghi · · Score: 1

      Next, are they going to waterboard him for the passwords?

      If he remembers it then it does not mean he knows it know. If he does not give it, it does not mean he doesn't know it. Perhaps he knows and he doesn't give it. Perhaps he really doesn't know.
      That is also the reason torture is a shit way of investigating people.

      I know I have forgotten essential passwords and lost data due to it. It is one of the reasons I DON'T use HD encryption.

      --
      Don't fight for your country, if your country does not fight for you.
    119. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Yea, Obama just appointed the judge, so sure, he couldn't do anything about it. Blindly defending a political party is no way to go through life.

    120. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      The more he embarrasses America and pisses off our allies, the worse things will be when we work with them later.

      He is building a pile of anti-American sentiment abroad that we will have to pay for eventually.

    121. Re:Contempt of the court... by Wulf2k · · Score: 1

      "The search warrant has been issued for his disks"

      The police are currently able to search his disks as much as they'd like. The numbers and letters on it just don't make a whole lot of sense.

      If he had a cardboard box filled with a bunch of papers that were in some other language that nobody could recognize, could the judge order him to sit down and translate those letters for the prosecution?

    122. Re:Contempt of the court... by sh00z · · Score: 1

      I can't remember my god-damned four-digit ATM PIN unless I'm standing right in front of the fucking ATM. Nor can I remember my god-damned four-digit alarm code unless I'm standing in front of the fucking alarm panel. Human memory is shit, and it is entirely plausible that this person forgot their password(s).

      And, I would venture to guess, highly dependent on the individual. I can still recall my high school locker combination from 35 years ago, the Michigan Driver's license number I gave up when I moved to Texas 30 years ago, and the phone numbers of my childhood friends. I never understood the "counting sheep" approach to insomnia; if I'm having trouble getting to sleep, I go through my teachers (in order) in my head. I typically nod off somewhere in the college years.

      I also have a history of dementia on my mother's side of the family. I'm hoping that regularly reviewing memories is some form of "exercise."

    123. Re:Contempt of the court... by Wulf2k · · Score: 1

      What do the actual contents matter?

    124. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Not this Canadian. Saw her for what she was many years ago.

    125. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      If this guy murdered someone and buried the body in the middle of a forest, should he be compelled to provide the location of the body?

    126. Re:Contempt of the court... by EndlessNameless · · Score: 1

      Trump's statements and were completely unrelated to law

      Statements outside of court are admissible as evidence in court hearings.

      And if the court considered those statements inappropriately, the Trump administration could appeal based on that error. First to the federal circuit, and then to the Supreme Court if need be.

      If they don't bother, they are basically admitting that either (A) the court was right in the first place or (B) the ban isn't important enough to fight for.

      Since most knowledgeable legal commentators believe the court's decision will hold on appeal, your point of view is most likely wrong. The statements are, in fact, relevant to the legal matter.

      --

      ---
      According to the latest ruleset, this post should be modded as Vorpal Flamebait +5.
    127. Re:Contempt of the court... by fustakrakich · · Score: 1

      They gave themselves the power and authority. They still don't have the right to compel anything from the accused. Unfortunately resistance is nil.

      --
      “He’s not deformed, he’s just drunk!”
    128. Re:Contempt of the court... by PoopJuggler · · Score: 1

      Lying under oath is standard operating procedure for all the shitty leaders we elect, regardless of political party because we have no pride or self-respect as a country. You sound like a dipshit when you say the left does it but the right doesn't.

    129. Re:Contempt of the court... by PoopJuggler · · Score: 1

      Well said.

    130. Re:Contempt of the court... by dougmc · · Score: 1

      As I said — it is not testimony. The jury will not hear it. The 5th Amendment protects him from being compelled to be a witness against himself

      The courts have generally held the 5th Amendment protections to be wider than that. For example, are you denying that people have the right to remain silent when being questioned by police? Why is there a distinction between being questioned by the police and by the court here?

      As for encryption passwords, the Supreme Court hasn't ruled on such a case yet, but they have given hints on how they would rule. Maybe this will actually be the case that goes all the way?

      I don't know about case law, but there is no "right to remain silent" in the Constitution. You don't have to be a witness against yourself.

      Rights do not *only* come from the Constitution. Case law is indeed important, and there's a lot of case law around one's right to remain silent.

    131. Re:Contempt of the court... by mi · · Score: 1

      But if the owner is present during the raid, would he have to mention presence of the tripwire, or keeping the mouth shut is ok?

      No, I don't think, there is a legal requirement to actively cooperate with police, however lawful their purpose. Even if they flat-out ask him about it, he can remain silent — leaving them to draw their own conclusions from it. Even if his silence is later determined to have been contemptuous, locking him up for such contempt will be pointless because the disks will already have been destroyed.

      You mean as means of torture to make sure there indeed are no backups somewhere

      Yes, as torture — both as punishment as well as to extract evidence. The evidence does not need to be backup — the victim may incriminate himself to stop being daily raped... I'm not at all certain, such things are actually in common practice — but we've all heard horror stories...

      --
      In Soviet Washington the swamp drains you.
    132. Re: Contempt of the court... by michael.schade.666 · · Score: 1

      I'll second and third that sentiment...I'll take convicts over thugs any day. And I'm not even talking politics :-) Seriously, though, when you can be held in contempt bc the judge SUSPECTS you are lying, I have to ask: why bother with a trial at all? Every SUSPECT protests their innocence, and obviously they are ALL lying, right? So let's just hold them all in contempt. Think how much money the courts could save in a year, just in pitiful jury fees... TL; DR: What happened to presumed innocent until PROVEN guilty...whine about the mess in DC, but fail to stand for American values. Sounds like y'all are definitely part of the problem.

    133. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      correct opinions

    134. Re:Contempt of the court... by EndlessNameless · · Score: 1

      No state has the right to compel assistance in one's own prosecution, constitution or no.

      The state doesn't have any rights; it only has powers.

      And the state of PA has the power to hold defendants in contempt and impose sanctions for spoliation when evidence is deliberately withheld or destroyed.

      The question is whether the judge believes this is a deliberate ploy. The incarceration for contempt implies that he does.

      --

      ---
      According to the latest ruleset, this post should be modded as Vorpal Flamebait +5.
    135. Re:Contempt of the court... by Highdude702 · · Score: 1

      Correct plus the food is a lot better.

    136. Re:Contempt of the court... by EndlessNameless · · Score: 1

      If you implement a dead man's switch after becoming aware that the issue may end up in court, then you're going to hurt a lot when they demonstrate that fact. I.e., tampering with evidence, destruction of evidence, spoliation.

      If you implement it beforehand, you might be in the clear. But you have an obligation not to destroy evidence---and that extends to passively-operated mechanisms that you control or know about.

      Until there is an actual case with a dead man's switch, there is no precedent and thus no way to be absolutely sure how the court would view it. I suspect they would take a dim view if you could have disabled the mechanism or warned the handlers---and then chose not to do so.

      --

      ---
      According to the latest ruleset, this post should be modded as Vorpal Flamebait +5.
    137. Re:Contempt of the court... by NonUniqueNickname · · Score: 1

      I don't remember the exact case, but this point has already been addressed by a court. The ruling was a suspect CAN NOT be held under "tell us your password so we can inspect your data", but CAN be held under "unlock your phone/drives/whatever yourself so we can inspect your data". A technicality.

    138. Re:Contempt of the court... by Oligonicella · · Score: 1

      Republicans do this kind of bait and switch crap all the time

      "If you like your doctor..."
      "If you like your insurance plan..."
      "We'll have to vote for..."

      Want another rock for that last unshattered glass wall?

    139. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Next, are they going to waterboard him for the passwords?

      This is a big part of why the Fourth Amendment exists. Saying "no waterboarding people" doesn't work, as we've seen. Lawyers and authoritarians find a way to smarm around it. You must remove the incentive.

    140. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      so, in other words, you have no idea how law works in the USA?

      Yes, your 'rights' as you read them, get violated all the time. Try walking up to a cop and telling him you are going to kill him, you will be arrested because your 1stt amendment right to freedom of speech has been breached because you made a death threat (illegal).

      Try carrying a firearm without any permit, any where you like, and you will discover that the exact words of the 2nd amendment have no weight in your case.

      Try stating that the police have no right to frisk you after they arrest you for carrying that firearm (see above) and you will find your 5th amendment is violated.

      Case law over the centuries has limited all the rights contained in the Bill of Rights quite a lot over what had been intended by the framers, all based upon how society has changed. This is why he (and his lawyer) simply didn't claim the 5th.

      But you are too stupid to understand, say, are you one of those dumbass Sovereign people?

    141. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      That the key happens to be a word — rather than something tangible like a metal key or a thumb-print — is irrelevant and does not magically add a Constitutional protection.

      I am not a lawyer, but I am more of one than you are. That the key happens to be a word absolutely does "magically" add a Constitutional protection. Possibly.

    142. Re:Contempt of the court... by Binestar · · Score: 1

      have you tried hunter2?

      --
      Do you Gentoo!?
    143. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      Right. Jail. Another arm chair idiot that will break after 5 minutes with the authorities. Tough talk. Cowards always do.

    144. Re:Contempt of the court... by ruir · · Score: 1

      Now that you talk about it...that is the reason I no longer have my two former slashdot accounts too. The passwords are long gone.

    145. Re:Contempt of the court... by Anonymous Coward · · Score: 1

      It's the law, innocent until proven guilty. So the judge failed to prove the person did remember the password, hence the judge is in contempt of justice. In order to prosecute for failure to remember and state a password, the court must prove the defendant does remember it, otherwise they a just fucking guessing because that is what they want, a really horrific corruption of the justice system.

      Think of the ramifications, the court claims you saw something with no evidence of proof of that claim, you say you did not and they imprison you until you say what they want you to say. You can not legally force memory, to force people to remember and just to be clear, how many you idiots got 100% on every exam you ever took, well, according to shit for brains judge, you put down the incorrect answer on purpose. Courts are not for fucking guessing, want to make a fucking claim, then fucking prove it.

      Everything you say is correct and logical. But some judges are willfully dishonest and choose to knowingly misinterpret the law to further their own nefarious agenda. That seems to be so in this case. Obviously the judges cannot KNOW if the man remembers the password, even if they strongly suspect that he PROBABLY does. But they have chosen to violate the law and to violate their oaths of office because they think that their cause is just. (Or possibly for some other less inspiring reason.)

      Hopefully a higher court will overturn this crooked ruling. Until then maybe it's time to remember what Thomas Jefferson and George Washington did when George the Third acted in a tyrannical manner.

    146. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      "The dog ate my homework" type excuses don't go down very well with judges.

      The difference is that teachers are in loco parentis over minors. Judges are subject to the Constitution and due process of law.

    147. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      you locked the drive, you can unlock it...

      And you know this beyond reasonable doubt because...?

    148. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      I don't use a password manager; it's a security threat.

    149. Re:Contempt of the court... by 0111+1110 · · Score: 1

      I think it depends on your psychology. Some people just can't deal with being confined like that. I was in a holding cell for only 12-15 hours and it was one of the worst things that has ever happened to me. I used to keep birds in cages sometimes, but now I would NEVER do that. Never. I really consider locking someone in a cage or bare room to be a form of torture. It certainly was for me. I paced/limped back and forth in my cell for pretty much the entire time I was there. I could only stop moving briefly. And that was on a badly injured leg and with broken ribs and a bloody battered face. The psychological effect of being confined was actually more powerful than all of my injuries were and my injuries were pretty bad.

      --
      Quite an experience to live in fear, isn't it? That's what it is to be a slave.
    150. Re:Contempt of the court... by beastofburdon · · Score: 1

      We don't know if they found evidence on his Mac or not. The article says they found a single picture of a pubescent girl. That could be anywhere from a 10yo to a grandma, it doesn't specify, and they may not even know how old the person in the picture is themselves. Also, never assume that police or prosecutors are telling the truth. They are allowed by law to lie as much as they want as long as it is not under oath. They also routinely get away with lying under oath and know that they can get away with it.

    151. Re: Contempt of the court... by Anonymous Coward · · Score: 0

      A well

    152. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      This is what you get guys.. when you vote Republican!

      Lying under oath is standard operating procedure for leftists. So is abusing public office and flouting the law. Some of it can even be found in leftist strategy books like "Rules for Radicals".

      Just take a look at the two rejections of Trump's executive orders on entry to the US, both of which were based on the judges opinion of Trump's statements and were completely unrelated to law.

      Treason is standard procedure for the Right: Reagan and Bush who were both arms smugglers and drug dealers. Then War Criminals Bush II & co forged intelligence information to start a war with Iraq.

      And as far as the Cheeto is concerned: he's a confessed con-man, (But you haven't read his book), and a McCarthyist who hired Roy Cohn who was not only McCarthy's lawyer, but also a Mafia Lawyer. And the right has gone full blown Nazi with the hiring of white-supremacist and proud Bannon.

    153. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Ditto - I've signed up for things on stressful jobs where a few months later I couldn't even remember the name of the service, let alone my password. All that remains is a vague recollection that I signed up for "something" to help me with "something else", and that's all that remains. Seems particularly bad when I am forced to multitask.

    154. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      Obstruction of Justice, aka Destruction of Evidence, or several other similar crimes. If you're unlucky, those just get tacked on to the rest of the charges. If only slightly unlucky, they determine that you did dispose of evidence of a crime, and only jail you for that. If totally lucky, and you get rid of it perfectly, they don't realize what you just got rid of WAS evidence, or that it existed.

      Welcome to the wonderful world of, "I'm probably guilty, let me dig this hole I'm in deeper for you." Frequently the cover-up gets you in more trouble than the original crime.

      Best legal advice ever for people who find themselves on Police Procedural TV shows. Ask for a lawyer, and don't say anything. Gloating about how they don't have enough evidence is never a good idea.

    155. Re: Contempt of the court... by Highdude702 · · Score: 1

      I've been saying that the entire time. Same with any issue here on slashdot. take for instance the telecom posts. one day they will say death to all big business especially telecom. The next day they say, well dont get rid of my telecom company I want to use it still..

    156. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      This is not a Constitutional question -the guy is not asked to testify against himself. What he is to say is not under oath and will not be used against him. What is demanded of him is a key to the premises, for which a perfectly valid search-warrant has already been issued.

      That the key happens to be a word -rather than something tangible like a metal key or a thumb-print -is irrelevant and does not magically add a Constitutional protection.

      And therein lies the rub. In the real world, You do not have to provide the key to your door, or the combination to your safe.

      If the government has probable cause / a warrant, they can break the door down, or get a locksmith to pick it for them. In the digital world, they would need a hacker, some software, and some (possibly a lot) of time on a S3 instance.

      It is a cost/benefit decision: just lock him up, vs spend the money to get the proof they need to lock him up... Which does make it a constitutional issue -he is being denied due process.

    157. Re:Contempt of the court... by Anonymous Coward · · Score: 0

      But some judges are willfully dishonest and choose to knowingly misinterpret the law to further their own nefarious agenda.

      That's absolutely what's happening here. Congress can pass no law infringing freedom of speech - so Congress can not give a court the authority to coerce speech. It's a contradiction in the legal system - and contradictions are always unethical practice of law. That makes this a violation of the 9th Amendment right to ethical practice of law as well as the 1st and the 5th - and a violation of the Constitutional requirement of good behavior. Then there's the 9th Amendment right to privacy.

      If Congress want the authority to coerce speech, there is an amendment process they can follow. Even then, arguably, it can be asserted that the 9th Amendment limits the amendment process.

      This is criminal kidnapping: the persons involved are impersonating government officials, since the moment they violated theirs oaths to uphold the law, they disqualified themselves from holding any position of public trust or responsibility. The government is required to enforce the law without violating the law.

      Further, as another consequence of the 9th Amendment right to ethical practice of law, it is not within the legal authority of government to grant immunity or right to pardon to government officials who violate rights arising under the 9th Amendment - if they could grant such, then there could be no rights retained by the people - another contradiction.

      Unfortunately, in practice the government is more concerned with the illusion of compliance with the Bill of Rights than the reality - and the US legal profession (with a few exceptions) cheers them on, because it creates long term business for them (and because any suggestion that the public has any say over ethical conduct in law is anathema).

    158. Re:Contempt of the court... by ShanghaiBill · · Score: 1

      I was never in a cell. I was in an open dormitory like area with about 50 other guys, and there was an eating/TV/Reading area that we could use anytime we wanted. We had to spend about an hour every morning cleaning, and since I was a "new guy" I was assigned the toilets. But otherwise we could spend our time doing whatever we wanted ... watching TV, playing cards, reading books, etc.

    159. Re:Contempt of the court... by robinsc · · Score: 1

      So all he had to do was convert his muslim ban to a laptop ban and that seems to do the trick :)

      --
      Linkedin http://in.linkedin.com/in/robinsaikatchatterjee
    160. Re:Contempt of the court... by robinsc · · Score: 1

      Or you had 2 Factor authentication and forgot to pay your phone bill due to which they disconnected the phone number so you can't reset your password anymore.

      --
      Linkedin http://in.linkedin.com/in/robinsaikatchatterjee
    161. Re: Contempt of the court... by Mashiki · · Score: 1

      You're actually spot on. It was more of a case of over a decade of Harper in power, and people were wanting a change. He did some shit things, did some good things too. Hell he did more as leader of a minority parliament then the liberals have done with the majority they now have. The real problem is people are seeing the Liberals doing now, what they did back in the 90's and caused their asses to be thrown out for in the first place. Hell Trudeau Jr, is the first PM to be officially investigated for ethics violations while holding the active role.

      --
      Om, nomnomnom...
    162. Re: Contempt of the court... by Mashiki · · Score: 1

      In an alternate reality, Hillary is president and likely nuclear war has already happened. She was an absolute war hawk, and pressed for active attacks against Russia in Syria multiple times. Yeah that wouldn't turn out well at all.

      --
      Om, nomnomnom...
    163. Re:Contempt of the court... by Dread_ed · · Score: 1

      Yes, I know it seems a bit over-accusatory to mention "correct opinions" and maybe even a misnomer. Everyone is entitled to their own opinion, right?

      This is a bit of an inside joke, sorry. Try replacing it with the idea of "not even wrong" if you are familiar with that.

      If you are not familiar with it look here: https://en.wikipedia.org/wiki/...

      In this particular parlance "form correct opinions" refers to using data that directly contradicts your conclusion as supporting information. It belies a level of ignorance, blindness, or uninformed cogitation resulting from attaching their opinion to their self worth. For those who do this the supporting information does not need to be true, correct, or even exist in some cases. They will forcefully project their unsupported opinion into discussions because their ego requires it. I have noticed people suffering from partisanship do this quite a bit.

      --
      When the only tool you have is a claw hammer every problem starts to look like the back of someone's skull.
    164. Re:Contempt of the court... by Squiddie · · Score: 1

      At the risk of being late to the party, I've always thought of decryption as interpretation. The police have the hard drives and they may search them. Just because it looks like trash data, doesn't mean they do not have the data in question. Asking for decryption is asking for the data to be interpreted, something which they do not have the power to do.

    165. Re: Contempt of the court... by Whorhay · · Score: 1

      You could sabotage that process in advance by using some kind of custom firmware on the control board for the disk, I imagine. Though doing that could be very difficult to do without being disastrously obvious. Specifically I'm thinking your new firmware expects a handshake of some sort but doesn't initiate that and behaves like it's full of corrupted data for reads, and whenever it's instructed to read without having received the handshake it takes the opportunity to overwrite the existing data.

      Unless the write blocker sits between the control board and the drive it'd be useless in that scenario. They could swap the control board for another from an identical drive but they'd have to realize they needed to do that in the first place before any evidence is destroyed. And it seems improbable that Law Enforcement agencies would swap control boards preemptively on hard drives because the logistics of keeping enough boards on hand would be incredible.

    166. Re: Contempt of the court... by K.+S.+Kyosuke · · Score: 1

      Trump doesn't give a damn about what you or the rest of the world thinks

      So Hillary is evil incarnate, but Trump is better because he completely ignores people? And here I was thinking that this was the very definition of sociopathy...

      --
      Ezekiel 23:20
    167. Re: Contempt of the court... by K.+S.+Kyosuke · · Score: 1

      Technically, they can decrypt it, in exactly the same way that they can find evidence during a search: with luck.

      --
      Ezekiel 23:20
  2. Rubber-hose cryptanalysis by Midnight_Falcon · · Score: 1
    ...should be expected by anyone who wants to hide data from a force as significant enough as a sovereign entity. Indefinite jailing based on contempt of court sounds a lot like a gentler, longer version of rubber-hose.

    Perhaps some type of expiry after 30-60 days of non-use for sensitive encrypted drives might protect against this, since there's no way the person could decrypt the drive after that threshold.

    1. Re:Rubber-hose cryptanalysis by WhiteKnight07 · · Score: 2

      Obligatory: https://xkcd.com/538/ XKCD gets it right yet again.

      --


      We're going to make information free Mr. Anderson, whether you like it, or not.
    2. Re:Rubber-hose cryptanalysis by sims+2 · · Score: 2

      How do you implement the timeout assuming the attacker will have possession of the device in question?

      Apple has been dealing with something similar with their 10 try then wipe password limitation they keep figuring out new ways to bypass it.

      --
      Minimum threshold fixed. Thanks!
    3. Re: Rubber-hose cryptanalysis by sethmeisterg · · Score: 1

      This is exactly why truecrypt (or similar) unstructured volumes should be used-- they provide deniability that there is even a volume present on a given device since the "data" appears to be just a bunch of random bytes.

    4. Re: Rubber-hose cryptanalysis by nobuddy · · Score: 1

      I wanted to look in to nesting this so that one passowrd unlocks the data, another password unlocks a 'blank' drive.

    5. Re: Rubber-hose cryptanalysis by Anonymous Coward · · Score: 0

      Truecrypt does that

    6. Re: Rubber-hose cryptanalysis by networkBoy · · Score: 1

      Nested volumes on TC does this nicely.

      --
      whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
    7. Re: Rubber-hose cryptanalysis by PReDiToR · · Score: 1

      Since the canary died ... Are we still onboard with TC (7.1a) or is it out of favour?
      Is there a replacement, yet?

      --

      Do not meddle in the affairs of geeks for they are subtle and quick to anger
    8. Re:Rubber-hose cryptanalysis by Anonymous Coward · · Score: 4, Interesting

      As a victim of a rubber hose attack by the American government I can offer some insight into how it works and how everyone looks at the issue wrong. The government usually gets it hands on you somehow and threatens you with some ridiculous mandatory minimum prison sentence. Its a somewhat civilized approach to the rubber hose attack.

      You go hire a big buck attorney who starts to work on the case. Next thing you know the government is offering you immunity for whatever is on your computer in exchange for the passwords. Of course your attorney says give them the passwords and this thing will likely go away. You hand over the passwords and it goes away, the statute of limitations ticks off a few years later.

      Now if you are the main target of their interest they will wait until they can nail you to the wall and do this step to anyone they think may be able to help.

      A better approach would be to use a wifi accessible ssd hidden in a wall or elsewhere it wont be found. Most of the time they are in and out of your house in under a hour, it is very rare, without an informants telling them all of your opsec secrets that anything well hidden will be found.

      Cops are humans, most humans are lazy and have mixed feelings about their job, remember that. Encrypted disks in the hands of the government should be treated as the starting point in negotiations.

    9. Re: Rubber-hose cryptanalysis by Golddess · · Score: 1

      "Hey, there's nothing incriminating here. You must be using a hidden volume!"

      But really, you weren't. You only had the one password. Now the beatings will continue until you die, since you cannot prove you don't have a hidden volume.

      --
      "I'm not sure I like the fugnutish tone you used in your post!" -RogL (608926)-
    10. Re: Rubber-hose cryptanalysis by infolation · · Score: 1

      7.1a:

      Source code audit and formal cryptanalysis led by Matthew Green showed no catastrophic weaknesses. Bruce Schneier claims he's still using it.

      The various security services revelations indicate the weakness is a compromised operating system or firmware not the encryption itself. Peronally I favour TAILS and LUKS, running on a computer with Libreboot, although that can also read TrueCrypt containers.

    11. Re: Rubber-hose cryptanalysis by fisternipply · · Score: 0

      TC is compromised.

    12. Re: Rubber-hose cryptanalysis by infolation · · Score: 1

      Sometimes hidden volumes are called 'inception volumes' because they don't have to stop at the second level. There is an argument that if there's free space on the drive, or no incriminating files, that is somehow suspicious.

      But in my view, free space can be explained as not inherently incriminating in the same way that free space on a regular hard drive is not incriminating ('I created a big encrypted container because I wasn't sure how big it needed to be'), and important personal files that would be useful to an identity thief (bank records, accounting records, passport scan etc) can be placed in the higher decoy volume.

    13. Re:Rubber-hose cryptanalysis by Kjella · · Score: 1

      How do you implement the timeout assuming the attacker will have possession of the device in question? Apple has been dealing with something similar with their 10 try then wipe password limitation they keep figuring out new ways to bypass it.

      Same principle as the attempt counter, except it's not a fixed counter but a running clock. Wrist watches run for years on about a microwatt, a cell phone battery would last forever if you keep some in reserve and never drain it completely. Cut the power = wipe encryption key. Timer reaches zero = wipe encryption key. You could probably do enough on-chip capacitators to allow for battery swaps without a wipe so it wouldn't be that user unfriendly. Since they can't clone it they'd need a hack ready, they can't store it for months waiting for one to show up. And if it expires there's no coming back so they got no legitimate reason to keep you in jail. And if you know you're passing through a danger zone you can set a very tight margin so that if you're caught they probably won't get it to a computer expert in time. It's not perfect, but it would certainly make it more difficult for the attacker.

      --
      Live today, because you never know what tomorrow brings
    14. Re: Rubber-hose cryptanalysis by duke_cheetah2003 · · Score: 1

      Are we still onboard with TC (7.1a) or is it out of favour?

      I'm still using 7.1a.

      Is there a replacement, yet?

      VeraCrypt is supposedly it's replacement, but given that 7.1a was given a pass during analysis, I'm wary of migrating to an unknown.

    15. Re:Rubber-hose cryptanalysis by Chrontius · · Score: 1

      Store some very important nonce, or part of the decryption key, in volatile, battery-backed (capacitor-backed?) memory. If the password is not entered, the charging circuit will not activate, and it is indeed connected to the erase line on the RAM. Thus, if someone tries to bypass the charging limiter, they zeroize the key store. Use other standard anti-tampering mechanisms to prevent chip-shaving and all the other physical attacks secure crypto-processors have been using for decades.

      But that's how you'd implement a self-destruct timer.

    16. Re: Rubber-hose cryptanalysis by Golddess · · Score: 1

      But in my view, free space can be explained as not inherently incriminating in the same way that free space on a regular hard drive is not incriminating

      Can, but I suspect that someone who is willing to resort to "rubber-hose cryptanalysis" probably doesn't care about things like that.

      --
      "I'm not sure I like the fugnutish tone you used in your post!" -RogL (608926)-
    17. Re:Rubber-hose cryptanalysis by dougmc · · Score: 3, Interesting

      .Perhaps some type of expiry after 30-60 days of non-use for sensitive encrypted drives might protect against this, since there's no way the person could decrypt the drive after that threshold.

      You aren't imagining the defendant's computer in a nice neat room with his drives plugged in and a cop sitting at it trying to guess the password, are you?

      No, the drives will have been imaged through a hardware device that blocks all attempts to write, and their work will be on their own computers running their forsensic software against the images of his drives, with his original drives safely in the evidence lockup.

      And if criminals start using drives with custom firmware to foil this (they've already read the first GB sequentially? return gibberish and erase everything!), the cops will then be removing the control boards and subsituting their own before they do the imaging.

      "Self destructing crypto" will just be something else for them to work around. It might foil the local police department, but if the FBI/NSA/CIA/etc. really wants your data, that's not going to foil them any more than straight strong crypto will.

    18. Re: Rubber-hose cryptanalysis by Anonymous Coward · · Score: 0

      Proof or GTFO.

    19. Re:Rubber-hose cryptanalysis by epyT-R · · Score: 2

      Why would you want to live in such a society? Have we really fallen so far that citizens now support such insane shit?

    20. Re:Rubber-hose cryptanalysis by wierd_w · · Score: 1

      I recall reading about some experimental cryptography schemas that create purposeful decryption collisions between two different filesystems. One that is a dummy filesystem that contains nothing interesting, and another that is the active filesystem you want to hide.

      Depending on the key provided to the decryption system, it returns one or the other data stream from the encrypted data.

      Something like that would work very well even against disk imaging attacks, since you could provide a valid key, and the cops would succeed in decrypting the data, only to find nothing of interest.

    21. Re: Rubber-hose cryptanalysis by Bob+the+Super+Hamste · · Score: 1

      Personally I switched to VeraCrypt once these issues were disclosed even though it appears they weren't as serious as initially thought. the fact that VeraCrypt has been patched against issues found in the TC audit and against the Google disclosed issues makes it seem like a better choice at this point. I stuck with TC 7.1a for quite a while until I found a reason to switch since with security it is good to stick with a known quantity until something else has a good track record or a serious flaw is discovered in the original. For me it was the 2 google issues, for someone else it may have been the minor issues from the audit or the combination of the google issues and the audit but that is something that needs to be decided on individually until there is a very clear reason to switch.

      --
      Time to offend someone
    22. Re:Rubber-hose cryptanalysis by green1 · · Score: 1

      In brief, yes.

      The people in power keep using the "if you have nothing to hide" argument, while grabbing more and more power.
      The people who aren't in power are too busy watching some random sporting event, or the Kardashians to care because they falsely believe that those in power are keeping them safe from the boogeyman... errr.. "terrorists" and "child pornographers"

    23. Re: Rubber-hose cryptanalysis by Anonymous Coward · · Score: 0

      TrueCrypt does this, not sure if it would fool three letter agencies since they know it can do this, but it's better than single file system encryption.

    24. Re: Rubber-hose cryptanalysis by fisternipply · · Score: 1
  3. What if by markdavis · · Score: 4, Insightful

    >"upheld a lower court ruling of contempt against a chap who claimed he couldn't remember the password to decrypt his computer's hard drives"

    I am not saying that is the case here, but what if a defendant really doesn't remember the password? Throw him in jail forever? Some devices don't need a key/password UNLESS they are disconnected or reset, and it is very plausible someone might have been using something for a long time without knowing.

    1. Re:What if by Anonymous Coward · · Score: 1

      I have one image of a CD encrypted with E4M many years ago that I'm failed in decrypting myself. I've tried all passwords I could think of having used back then to no avail.

      I have two archives encrypted with Kremlin Encrypt (v1 as well as v2 I think) which I'm unable to decrypt as well. Believe me I've tried, considering they contain photos taken together with two separate previous girlfriends.

      To jail I go, apparently.

    2. Re:What if by Carewolf · · Score: 1

      >"upheld a lower court ruling of contempt against a chap who claimed he couldn't remember the password to decrypt his computer's hard drives"

      I am not saying that is the case here, but what if a defendant really doesn't remember the password? Throw him in jail forever? Some devices don't need a key/password UNLESS they are disconnected or reset, and it is very plausible someone might have been using something for a long time without knowing.

      Yeah. I don't know the pincode for my SIM-card, I only ever need it when the phone updates the operating system, and it is separate from the code used to lock the phone. So if my phone is powered down, I have no way of unlocking it without traveling back to my home country out of US reach to get the printed copy of the pincode.

    3. Re: What if by Anonymous Coward · · Score: 0, Interesting

      This is a case pertaining childâ pornography, So...yes, in order to make a example of him and/or set a precedent (more likely the latter imo).

    4. Re: What if by Anonymous Coward · · Score: 0

      I have a similar concern, however I wonder if the fact he previously argued he shouldn't be compelled to give up the password undermines his argument that he can't remember it in the judges eyes... I keep trying to work out a fool proof way of probably losing access out of interest but other than making yourself reliant on data being destroyed it's tricky. The best I could think of is to have access be reliant on a 3rd party outside the jurisdiction of the court, they could then register to comply or actively destroy the data needed to access (part of the description key that you don't have direct access to) when you are potentially compromised.

    5. Re:What if by computational+super · · Score: 1

      What if it isn't even actually encrypted? "I see a lot of files on here that aren't .mp3, .jpg or .gif files, they have weird extensions like .class. They're obviously encrypted, decrypt them and show us the illegal stuff they're encrypted as!"

      --
      Proud neuron in the Slashdot hivemind since 2002.
    6. Re:What if by haruchai · · Score: 1

      Believe me I've tried, considering they contain photos taken together with two separate previous girlfriends.

      To jail I go, apparently.

      Decrypted or not, you were going to jail; only difference would be on what charges.

      --
      Pain is merely failure leaving the body
    7. Re:What if by Marc_Hawke · · Score: 1

      Maybe he said it with a snarky attitude.

      But, I had the same question...if you're not allowed to 'forget' something...what if you actually do?

      --
      --Welcome to the Realm of the Hawke--
    8. Re: What if by Anonymous Coward · · Score: 0

      "You disconnected the USB RAM stick from its keeper battery when you seized my stuff. The key doesn't exist anymore"

      Of course this works only if you actually possess a USB RAM stick.

    9. Re: What if by Anonymous Coward · · Score: 4, Funny

      Perjury, obviously, for claiming to be a Slashdot reader with a girlfriend.

    10. Re:What if by ShanghaiBill · · Score: 4, Interesting

      what if a defendant really doesn't remember the password? Throw him in jail forever?

      Sure. Why not? The criteria is "reasonable doubt" not "certainty". In practice, the standard for "reasonable doubt" is not very high. When DNA evidence first became valid in court, the Innocence Project reviewed thousands of old cases, and determined that about 10% of them could not possibly have committed the crimes for which they were convicted. One case overturned was the Central Park Five, which EVERYONE, including our president, was absolutely certain were guilty. There are many, many other cases with no DNA evidence, but there is no reason to believe the false conviction rate is any lower for those.

      So if 90% certainly is good enough to lock up some poor black kids for life, why isn't it good enough for a rich white guy with a Macbook Pro?

    11. Re: What if by TWX · · Score: 1

      Then they charge you with destruction of evidence.

      It would be kind of interesting to see how that played out though. Would they have to argue that you intentionally set up a system to destroy evidence based on knowing that you were committing crimes?

      --
      Do not look into laser with remaining eye.
    12. Re:What if by TWX · · Score: 1

      He probably 'said' it through his attorney via filing, which I expect would be on-paper.

      While it's possible to be snarky on paper it requires both intent and a general finesse for language that most people don't have.

      --
      Do not look into laser with remaining eye.
    13. Re:What if by radarskiy · · Score: 2

      This question actually did come up in this case, as at one point the defendant claimed to have forgotten the passwords. However, the defendant undermined himself by at another time refusing to provide the passwords by which he proved that he did have them.

    14. Re:What if by sims+2 · · Score: 1

      What type of phone do you have that doesn't have to be restarted every few days?

      --
      Minimum threshold fixed. Thanks!
    15. Re:What if by Anonymous Coward · · Score: 0

      Or, you know, go online, find your PUK, and enter a new PIN.
      But whatever, a flight to a different country works too I guess.

    16. Re:What if by Altrag · · Score: 3, Informative

      Presumably by the time the courts are ordering decryption, the computer has gone through forensics by actual computer forensics people.

      Your possibility might apply to the cop who's beating down your door and just trying to get a quick takedown but if you refuse that initial step it will go to people who know what they're doing long before it goes to a judge.

    17. Re:What if by Altrag · · Score: 1

      While I'm sure there's no shortage of racism involved in that particular distinction, there could also be very valid reasons.. specifically witness testimony.

      Chances are you can find someone who will claim they witnessed an assault or saw some kid selling drugs or whatever.. possibly not accurate testimony since its been shown time and again that peoples' memories aren't terribly reliable in stressful situations, never mind the possibility of outright deceit. But you can often find someone to step forward.

      Compare that to some dude who's got CP on his computer. Chances are if there's witnesses at all, they will either be a) involved or b) the ones that reported it. I don't imagine there's a whole lot of "knew about it but just didn't care" in relation to this particular issue (and we'd probably say they're abetting anyway given how strictly we prosecute CP offenses.)

    18. Re:What if by nobuddy · · Score: 1

      Any Android phone. Who restarts their phone more than once or twice a year when forced by an update??

    19. Re: What if by nobuddy · · Score: 1

      fairly easy, you remembered the password when refusing to give it. Now, 6 months, 2 years, whatever later, you have forgotten it since you stopped using the password the day the system was seized.

    20. Re:What if by nobuddy · · Score: 1

      your honor, I would like to note for the record that every time the defendant says "forgot" he uses air quotes.

    21. Re:What if by sims+2 · · Score: 1

      Interesting from my own experience with working with accounts I haven't used in a few years I can only prove I have the password if I try it and it works.
      What I think or what I know the password is doesn't matter.
      I know the password is Password123 but at some point I changed it to Fragglerock123 and promptly forgot I did and didn't think to write it down because "I'll remember"
      Or your mind jumbles the words in between when you set the key and you need to use it and you end up with Rocklobster23.

      --
      Minimum threshold fixed. Thanks!
    22. Re: What if by Anonymous Coward · · Score: 0

      Even better, he claimed "two separate ... girlfriends", so we now know he's ambidextrous.

      With that dual hand job threat, he's going to be very popular in prison.

    23. Re:What if by liquid_schwartz · · Score: 1

      So if 90% certainly is good enough to lock up some poor black kids for life, why isn't it good enough for a rich white guy with a Macbook Pro?

      How about we work on improving justice for all without regard to socioeconomic status or race. Two wrongs don't make a right.

    24. Re: What if by PoopJuggler · · Score: 0

      Except you can't prove it's actually a case about child porn without the password.

    25. Re:What if by ccguy · · Score: 1

      Anyone with an Android phone that doesn't suck and get updates every month :-)

    26. Re:What if by ccguy · · Score: 1

      what if a defendant really doesn't remember the password? Throw him in jail forever?

      Sure. Why not? The criteria is "reasonable doubt" not "certainty". I

      You have it wrong. That's the criteria for not-guilty.
      Reasonable doubt (of not being guilty) => you walk.

    27. Re: What if by Anonymous Coward · · Score: 0

      I think he is referring to steganography. Certain encryption methods technically cannot ever be proven to be or not be encryption in the first place. If this very comment is code for a different message there is no way you would know and more importantly, no way I could disprove to you. This is why we have innocent until proven guilty but these days no one gives a shit about our rights.

    28. Re:What if by markdavis · · Score: 1

      >"So if 90% certainly is good enough to lock up some poor black kids for life, why isn't it good enough for a rich white guy with a Macbook Pro?"

      So it is suddenly about race or socioeconomics? I prefer to play my thought games with "everyone is equal in the eyes of the law" as a ground rule. And it is the rule in this country, even though it might not turn out that way sometimes, unfortunately. Two wrongs don't make a right. Address each problem separately.

    29. Re:What if by theArtificial · · Score: 1
      --
      Man blir trött av att gå och göra ingenting.
    30. Re:What if by Anonymous Coward · · Score: 0

      Unless he is NOT sure what the password is, then if he supplies what he thinks is the correct password but is not, then he can also be charged with interfering with justince and providing false testimony or purjury. In that case, isn't it better to state he doesn't know password?

      I have passwords I use every month that I cannot remember, rarely ever get correct on the first attempt, but eventually get correct after multiple tries. If I was required to provide correct password I would fail the first couple of attempts.

    31. Re:What if by Anonymous Coward · · Score: 0

      but i am running the lasted android update from verizon from 2015.

    32. Re:What if by serviscope_minor · · Score: 1

      Any Android phone. Who restarts their phone more than once or twice a year when forced by an update??

      Well my current (Nexus 6) and previous (Nexus 4) phone would start to run like shit every so often (fixed by a reboot) or just flat out forget how to connect to the cell network (in different ways)---also fixed by a reboot.

      --
      SJW n. One who posts facts.
    33. Re: What if by Anonymous Coward · · Score: 0

      I turn my phone off every night when I go to sleep, I guess that's strange?

    34. Re:What if by Anonymous Coward · · Score: 0

      My Android phone (Galaxy S4) randomly reboots itself on average once a week.

    35. Re:What if by Anonymous Coward · · Score: 0

      Ouch. You were doing so well, until you threw race into it. Too bad. The point was strong enough to stand by itself, but now you're just a SJW, and I don't care what else you have to say. :P

    36. Re:What if by ShanghaiBill · · Score: 5, Insightful

      How about we work on improving justice for all without regard to socioeconomic status or race.

      Sure. But if we fix it only for the rich white guys, then they no longer have any motivation to fix the system for others, and it is they that are empowered to do so. We should indeed fix it for everyone. But we need to start at the bottom.

    37. Re:What if by pla · · Score: 2

      All the responses to you so far have bragged about Androids... And make no mistake, I use both Android and iOS and am by *no* stretch of the imagination an Apple fanboy...

      But...

      I have owned my current iPhone for roughly 3 years. And in that time, I have rebooted it exactly once, for an OS upgrade. I force-shut it down one other time only because I was in the middle of nowhere, basically lost, and wanted to save the last 5% of battery for a 911 call if it became necessary.

      Put bluntly, it has never crashed. Ever. Period.

    38. Re:What if by Anonymous Coward · · Score: 0

      I have a password I've used every single day for the last 10 years, and I STILL have the occasional brainfart and must resort to the old stickynote.

    39. Re:What if by ShanghaiBill · · Score: 1

      Reasonable doubt (of not being guilty) => you walk.

      Sure. But in practice, "reasonable doubt" means that you are 90% sure that they did it. We can, and do, tolerate a false conviction rate of more than 10%. So if you believe that 9 out of 10 people that claim they forgot their password are lying, then you should be okay with throwing all 10 in jail. If you do NOT think that is okay, then you should be calling for broad reform of our criminal justice system, rather than just defending this guy.

    40. Re:What if by ShanghaiBill · · Score: 1

      So it is suddenly about race or socioeconomics?

      Have you ever looked at the demographics of America's prison population?
      Hint: It is about race and socioeconomics.

      Two wrongs don't make a right.

      Sometime two wrongs do make a right, especially if one of the people wrong is now motivated to fix the problem. You don't care about injustice for a poor black kid falsely accused of a gang murder, because you assume that such an accusation will never be directed at you. But a false accusation of child porn could actually happen to YOU, so you care. So now you are motivated to vote for the guy that wants to fix the justice system, rather than the guy that wants to build more prisons.

      Address each problem separately.

      No. That is exactly what we should NOT do. We should fix compelled self-incrimination for everyone, not just for those that know about encryption and can afford fancy lawyers.

    41. Re:What if by Dread_ed · · Score: 1

      I keep thinking his sister, who called the police and reported that he had shown her hundreds of images of child porn, could have encrypted his drives without him knowing.

      He tried to decrypt the drive with his normal password, it didn't work. Now she gets the inheritance, the house, family jewels, or maybe just gets back at him for the ol' frog in the cereal bowl trick he played on her when she was 5.

      Now, do I really believe this? No. However, that doesn't mean its not an easy way to get someone thrown in jail forever.

      --
      When the only tool you have is a claw hammer every problem starts to look like the back of someone's skull.
    42. Re: What if by Highdude702 · · Score: 1

      a lot of older people do this I noticed. I really dont understand it.

    43. Re:What if by Highdude702 · · Score: 1

      I have owned an iphone for about 3 years, I despise other apple hardware. but they got this one right. Even with jailbreak my iphone 6s is rock solid.

    44. Re: What if by Swave+An+deBwoner · · Score: 1

      Actually, as soon as the cops came and arrested me I got so stressed out that the password is completely gone. I can't remember it no matter how hard I try.

      And damn, that's brutal Man. My entire child pornography collection was on those hard drives.

    45. Re:What if by Highdude702 · · Score: 1

      i actually did forget my encryption password on my daily machine once. I forget exactly what happened exactly, but i think i had like a 6 month or so uptime on the pc and hadn't needed to use it and it was obnoxious like 38 character pass with truecrypt. I did end up figuring it out after about 6 hours. only because i use variations of things i will never forget and then combinations of that. But i was scared for a while that i was going to lose my entire system that wasnt backed up.

    46. Re:What if by markdavis · · Score: 1

      >" You don't care about injustice for a poor black kid falsely accused of a gang murder, because you assume that such an accusation will never be directed at you. But a false accusation of child porn could actually happen to YOU, so you care. So now you are motivated to vote for the guy that wants to fix the justice system, rather than the guy that wants to build more prisons."

      I hope you are using some type of metaphorical or hypothetical "you" in your postings. I most certainly do care about justice and equality on all levels and for all people. It has nothing to do with how likely some matter is to affect me. And if you are implying otherwise, I should be deeply offended except for knowing you can't possibly know much of anything about me, so why should I care?

    47. Re:What if by Anonymous Coward · · Score: 0

      That is idiotic.
      You've committed no crime, but you don't know the password.
      And then they can throw you in jail indefinitely.

      Even better, they can hand you a different drive, *guaranteeing* you cannot know the password.
      You are a worse than an idiot, you're an *dangerous* idiot.

    48. Re:What if by Highdude702 · · Score: 1

      well you're just old... that doesnt count

    49. Re: What if by Anonymous Coward · · Score: 0

      child pornography --- abracadabra! Carte Blanch!

      Put them in the iron maiden

    50. Re: What if by sims+2 · · Score: 1

      It charges better if it's turned off. While somewhat true if it's going to be plugged in overnight it hardly makes a difference.
      Also maybe they don't want to be disturbed by telemarketers in the middle of the night.
      Or to save power but it's a rather negligible amount.

      --
      Minimum threshold fixed. Thanks!
    51. Re:What if by Anonymous Coward · · Score: 0

      Your experience with the intelligence across various demographics of the US public is sorely lacking. And it shows.

      Most people couldn't tell you what they had for breakfast 3 days ago, and you expect a high degree of certainty for individuals to recall highly specific points of information seemingly at will? What was your password 19 months ago and 3 days, to your now closed Yahoo.com email account?!?

      I sure as hell hope you never serve jury duty. Your the kind of 'common man' who has seen WAY too much 'law and order' paraded on drama and reality TV.

      As for the 'race argument' you're making? That's about the worst case of Apples to fruit fly's I've ever come across. I don't even know where to begin other than to say, law enforcement jurisdictions are wholly not at all equivalent. If you think they are, please back it up with the some penology data. And if still think they are, that speaks greatly to you lack of experience in different demographics of society across the many regions of the US.

    52. Re:What if by Anonymous Coward · · Score: 0

      The test here is not reasonable doubt, this is a complying with a judicial order. Apparently the judge doesn't believe him. And the appeals court doesn't either.

      There's no bar here, you either do it or don't with consequences either way.

    53. Re:What if by sjames · · Score: 1

      Kinda like the arson experts that sent a guy away and then much later it was discovered that their "sure sign of arson" happens a lot in accidental fires as well?

    54. Re:What if by Raenex · · Score: 1

      So if 90% certainly is good enough to lock up some poor black kids for life, why isn't it good enough for a rich white guy with a Macbook Pro?

      1) Because you have a right not to testify against yourself in the 5th amendment.
      2) Contempt of court should not be a life sentence.

      There, done.

    55. Re:What if by Anonymous Coward · · Score: 0

      I am not saying that is the case here, but what if a defendant really doesn't remember the password? Throw him in jail forever? Some devices don't need a key/password UNLESS they are disconnected or reset, and it is very plausible someone might have been using something for a long time without knowing.

      It is not out of the question that the decision to encrypt a smartphone was done by the manufacturer, not the end user.
      If that is the case this ruling essentially means that you can be thrown in jail for forgetting your password.

    56. Re:What if by Anonymous Coward · · Score: 0

      Same here... i could not tell you the password if my life depended on it... it's all muscle-memory.... Switching to a new keyboard is hell.

    57. Re:What if by gnasher719 · · Score: 1

      What if it isn't even actually encrypted? "I see a lot of files on here that aren't .mp3, .jpg or .gif files, they have weird extensions like .class. They're obviously encrypted, decrypt them and show us the illegal stuff they're encrypted as!"

      That's why you have expert witnesses and lawyers. No expert witness would make such a claim, because they would never be an expert witness again, and no lawyer would let them get away with it.

    58. Re:What if by Carewolf · · Score: 1

      What type of phone do you have that doesn't have to be restarted every few days?

      It is an Android. By any of the high-end smartphones perform very well for long stretches.

    59. Re:What if by Anonymous Coward · · Score: 0

      "some poor black kids"... LOL.
      Sounds like you think white people are ruining the lives of black people who live in white countries.
      Why don't you suggest that the blacks GET AWAY from the evil white people, by living in Africa?

    60. Re:What if by Anonymous Coward · · Score: 0

      You have a phone that needs to be restarted every few days? I've never heard of such a thing. Just about every phone from the mid-90's can keep going for years without needing a restart, provided that you don't run the battery flat, remove the battery or swap SIM cards. What kind of phone do you have?

    61. Re:What if by Anonymous Coward · · Score: 0

      The criterion to have someone acquitted is reasonable doubt. The criterion to have someone convicted is to demonstrate beyond reasonable doubt that he is guilty.

      CAPTCHA: evident

    62. Re:What if by Anonymous Coward · · Score: 0

      I can't remember the last time I restarted my Windows Phone 8.1.

    63. Re:What if by Keith_Beef · · Score: 1

      My android phone, made by Foxconn, reboots itself every day or two, sometimes it will reboot three or four times in a single day. And that is without updates.

      In addition to that, I have to reboot it deliberately every now and again, or Android refuses to update apps; like a 27MB download refuses to install. "Out of memory", when the filemanager tells me "225MB free".

    64. Re: What if by green1 · · Score: 1

      You could certainly claim legitimate uses though.
      You're worried that if a thief breaks in and steals your stuff you didn't want them to have access to all your banking information too, so you set up the dead-man hardware to trigger as soon as anything is powered down or moved.
      Now there could be some claim that you should have told the police, but in many of these cases there's no time you really would have had the chance to do so as they likely took you out of the house before they started bagging everything.

    65. Re:What if by Anonymous Coward · · Score: 0

      my fiancée, her android Samsung locks up randomly so she restarts it multiple times per day. It is a note 4. about 2 years since she bought it, new.

    66. Re:What if by liquid_schwartz · · Score: 1

      How about we work on improving justice for all without regard to socioeconomic status or race.

      Sure. But if we fix it only for the rich white guys, then they no longer have any motivation to fix the system for others, and it is they that are empowered to do so.

      I suggested fixing the problem in general. How you moved from that to only fixing it for rich white guys is beyond me.

      We should indeed fix it for everyone. But we need to start at the bottom.

      Why not just fix it for everyone instead of a half ass measure of only fixing it for your chosen group? I get that you have an axe to grind with rich white guys. Even so the aim of actual justice should be to have an evenly applied and fair process. Not to have a process that only applies to your chosen group, regardless of it's rich white guys or poor black kids.

    67. Re:What if by Anonymous Coward · · Score: 0

      And that is why it violates the 5th Amendment. By providing the passwords he is not just providing access to the data, he is testifying against himself that he exercised control over the data, and the prosecution would use that as evidence, not just the data by itself.

    68. Re: What if by Highdude702 · · Score: 1

      My phone stays on, i use it for my alarm clock. but I keep it on silent and vibrate only 99% of the time.

    69. Re:What if by Anonymous Coward · · Score: 0

      one way to suss out a faker would be the last modified date on the encrypted drive, if one tells me that they forgot a password on a file that was recorded as modified the day of arrest or confiscation then I would tend not to believe them. that said it often takes months or a year to get to trial, give me your passwords should be part of the interrogation or perhaps it can be a motion filed at arraignment to write down or describe all means of accessing digital data, from the swipe pattern on the phone to what password, or even kind of encryption is employed on deivces like truecrypt or bit locker. In the interests of preventing destruction of evidence.

  4. Steve Martin to the rescue by turkeydance · · Score: 1
  5. That's not good law by Baron_Yam · · Score: 5, Insightful

    This amounts to "We know you're guilty even though we can't prove it so we're not going to bother with proof", and worse, they're using that to apply a potentially unlimited sentence.

    Just because the guy is accused of having a child porn collection doesn't mean the niceties of law shouldn't apply.

    I'm actually not so much for the right against self-incrimination, but I am very much for the right to a fair trial based on evidence and not what people 'know'. I'm also very much on finite sentences proportional to the needs of protecting society, punishing enough to scare the next guy, and attempting to reform the convicted if possible... but there shouldn't be a sentence at all without a just conviction.

    1. Re: That's not good law by Anonymous Coward · · Score: 0

      With a jury, it ultimately boils down to the jury's interpretation of the evidence. It's almost impossible in a real world scenario you have irrefutable evidence. Almost everything is arguabl due to lack of total information.

    2. Re:That's not good law by Anonymous Coward · · Score: 1

      *Eastern District of Pennsylvania*

      That is all you need to know. This is the same place where a Judge was filling up for-profit prisons for a kickback and they heavily use civil forfeiture.. they are practically a poster child AND where possession of pot sent way too many people to jail for decades

    3. Re:That's not good law by haruchai · · Score: 1

      Just because the guy is accused of having a child porn collection doesn't mean the niceties of law shouldn't apply

      Does the law distinguish between having, distributing or making these images? I consider those very different crimes.
      Also, since they know he visited the sites and downloaded *somethings*, they can nail him just for that crime and waive or suspend the contempt charge if he agrees to forfeit possession of the hard drives.

      --
      Pain is merely failure leaving the body
    4. Re:That's not good law by Falos · · Score: 1

      It's a bad law because it's literally leaning on "I said so."

      The power is ultimately in the owner's hands. Consider: Even under torture, access is technically only granted when the owner says. And so, like warrant canaries, this power will simply rearrange itself until it's out of reach again, until untouchable by infantile laws that are comparable to a child shouting about a supershield that blocks anything.

      Immediate example: The key distributes itself (perhaps via deadman) to a random, unknown recipient on a custom list, with instructions to not contact the owner until the "Unexpected Duress" has passed. You no longer HAVE the access, $5 wrench or not, thoughtcrime or not.

      It might even work with some trade/state secrets. Deal with it, law enforcement. "Because I said so." is what you say when your power is justified only by its own circular existence.

    5. Re:That's not good law by radarskiy · · Score: 1

      They had evidence and testimony that he had downloaded and viewed the material and also that he had transfered it to the encrypted storage. They just didn't have access to the encrypted storage to show what was still there. The defendant made no effort to refute any of that which is why producing the password is considered non-testimonial.

    6. Re:That's not good law by Anonymous Coward · · Score: 0

      Yes there is a difference, possession is the least as I understand it, distribution is the next up.. and production is the worst. I'm not sure what the sentences are but even distribution implies years... even with combined sentencing. I only know as someone I knew was charged with possession and distribution, I think he was torrenting stuff... as that is what he did with everything else as far as I understand.It was a very strange case... he turned himself in apparently? I'm not sure if blackmail was involved or what... very sad honestly that he ruined his life.

    7. Re:That's not good law by tsqr · · Score: 1

      This amounts to "We know you're guilty even though we can't prove it so we're not going to bother with proof", and worse, they're using that to apply a potentially unlimited sentence.

      Well, the forensic analysis of his laptop (whose encryption the authorities managed to break themselves) showed that he visited known child exploitation sites and downloaded "thousands of files with the same hash values as known child pornography files." (quote from TFA). The downloaded files weren't on the laptop, so they're assumed to be on the encrypted external drives. Also from TFA: "Authorities in Delaware investigating the case already had a sense of the contents of the drives because, according to court documents, the defendant's sister had told police investigators "that Doe had shown her hundreds of images of child pornography on the encrypted external hard drives." So apparently he was able to recall the passwords when he showed the files to his sister.

      Then again -- he may prefer a long stretch in prison for contempt of court, to a long term in general population with a child porn conviction stuck to his back like a "beat the shit out of me every day" sign.

    8. Re:That's not good law by Baron_Yam · · Score: 1

      Either they need the drive or they don't.

      If they need it... tough! (or at least it should be) - because they can't prove he hasn't genuinely forgotten the password.

      If they don't need it, the contempt charge is a disgusting act by the legal system to ignore its internal checks and balances. Just finish the trial with the evidence you have, get the conviction, and apply an appropriate sentence.

    9. Re:That's not good law by MrDoh! · · Score: 5, Interesting
      That was how the UK version of this law was made to look silly (even though it later passed of course).

      An admission of a crime was made, written up, encrypted, and put on a USB(CD maybe) and sent to the Home Secretary. The police were then contacted and informed that the Home Secretary has, in his possession, an admission of a crime that requires a custodial sentence.
      Technically, that he never had the keys to unlock it was irrelevant. He had an item that was an admission of a crime, he was duty bound to hand it over and unlock it, even though there's no way on earth he could. But the way the law was written, he was the one in trouble.

      If this is allowed to stand, we now have the way for someone/anyone to send you an encrypted file (email/cookies), that will then get you found in contempt of court as you are unable to prove you can't unlock it.

      --
      Waiting for an amusing sig.
    10. Re: That's not good law by SumDog · · Score: 1

      > "...There are no reproducible formulas that can be put into a machine and lead to the same results. Instead the fate of people in a free legal society are determined by the current interpretations of a judge or a jury, and quite possibly how they feel that particular day or what they ate for breakfast. ..."

      http://khanism.org/security/legality/

    11. Re:That's not good law by Anonymous Coward · · Score: 0

      Possession and Distribution are separate, but most are charged with both because in the digital age, downloading a file is copying it, thus reproducing/distributing -- especially if, like a torrent, it's seeded to others.

    12. Re:That's not good law by Anonymous Coward · · Score: 0

      Sounds like they don't actually need the password to convict the guy then, they're just trying to get precedent set regarding passwords in general.

    13. Re:That's not good law by Alan+R+Light · · Score: 1

      Is that the same district in Pennsylvania where public school employees were using the cameras on school-supplied and required laptops to spy on children in their own bedrooms, and the courts found that no crime had been committed?

      I agree, I wouldn't put much faith in Pennsylvania's legal system.

    14. Re:That's not good law by fustakrakich · · Score: 1

      a supershield that blocks anything.

      We really could use a bunch of those...

      --
      “He’s not deformed, he’s just drunk!”
    15. Re:That's not good law by Anonymous Coward · · Score: 0

      Not really, no.

      That might be what the letter of the law states, but any court would just toss that out in an instant as a complete waste of it's time, an potentially classify the perpetrator of the scam as a vexatious litigant.

    16. Re:That's not good law by Anonymous Coward · · Score: 1

      Send a random encrypted file to the JUDGE as a USB drive or DVD-R, then inform the police that the judge has received an encrypted DVD-R containing child pornography, then see how he likes it, since he will claim he doesn't know the password.

    17. Re:That's not good law by StormReaver · · Score: 1

      I'm actually not so much for the right against self-incrimination....

      You should be for it, because someday you may need it -- especially if you're falsely accused (which happens a LOT). The 5th Amendment isn't there to make life unnecessarily hard for two branches of government. It is there to protect the innocent from all three branches of government.

    18. Re:That's not good law by houghi · · Score: 1

      If this is allowed to stand, we now have the way for someone/anyone to send you an encrypted file (email/cookies), that will then get you found in contempt of court as you are unable to prove you can't unlock it.

      Lbh nyy ner abj haqre neerfg sbe univat fbzrguvat rapecgrq gung lbh jvyy ARIRE or noyr gb qrpelcg.

      --
      Don't fight for your country, if your country does not fight for you.
    19. Re:That's not good law by Falos · · Score: 1

      > Lbh nyy ner abj haqre neerfg sbe univat fbzrguvat rapecgrq gung lbh jvyy ARIRE or noyr gb qrpelcg.

      You are all now under arrest for having something encrpted [sic] that you will NEVER be able to decrypt.

    20. Re:That's not good law by Anonymous Coward · · Score: 0

      He still can deny it. Somebody hacked into his computer, or there was malware because he doesn't use anti-virus, or somebody else was using his wifi connection, etc.

      Anything else will ruin his life, make him register as a sexual predator forever, and he would never have a normal life again. it's his best interest to fight tooth and nail, unless he is completely innocent in which case I would hop he would decline to provide a password

    21. Re:That's not good law by Anonymous Coward · · Score: 0

      It's really sad how these days having sexual desire for the wrong type of person makes you a "predator."

      Predators are people who seek out victims to exploit. They use people for their own pleasure and have no conscience or empathy for the victims.

      That is very different from wanting to enjoy sex with a willing partner, even if they are legally barred from consenting.

      Hell, when I was 14 there were many girls my age I wanted to have sex with. I never got to, but I still think about them sometimes. Does that make me a "predator" just for having gone through puberty?

      Like the drug abuse problem, we're ineffectively treating this as a criminal matter when it's really a sociocultural issue.

  6. This is bullcrap by JustNiz · · Score: 1

    While I have less than zero sympathy for child pornographers, what about the 5th amendment? I thought it was to EXPLICITLY prevent the courts from obliging you to give information that may incriminate you.

    Also isn't the onus on the court to prove you're definately guilty before punishing you? I think its more than reasonable that someone could honestly forget their password, especially in a stressful situation such as a trial.

     

    1. Re:This is bullcrap by Anonymous Coward · · Score: 0

      it's closer to someone has documents in an office safe. it's long been established that you have to turn over the combination/key. this is no different.

    2. Re:This is bullcrap by Anonymous Coward · · Score: 0

      He's not being punished for child porn; he's being punished for contempt of court. And yes, we do punish people for things they do without intent--that's essentially the basis of the difference between manslaughter and murder.

    3. Re:This is bullcrap by fahrbot-bot · · Score: 1

      I thought it was to EXPLICITLY prevent the courts from obliging you to give information that may incriminate you.

      The password (like a key to a safe) itself isn't self-incriminating, even if the thing it's protecting may be.

      --
      It must have been something you assimilated. . . .
    4. Re:This is bullcrap by guruevi · · Score: 2

      It has been established that you can't be forced to turn over the numbers to your combination lock while you can be compelled to provide the physical key if you have it. The problem is that in cryptography, we call it a key but we mean combination lock, the judges here ruled a cryptographic "key" is something similar to a physical key, a piece of code/hardware you can give them to unlock your "safe" while it's actually a combination lock.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    5. Re:This is bullcrap by Anonymous Coward · · Score: 0

      And if you lost the key?

    6. Re:This is bullcrap by known_coward_69 · · Score: 1

      the fifth amendment is so the cops can't torture you to force you to confess like used to happen in Europe around the time it was written. I read an interesting book one time how they used to put you on the rack and break your bones until you confessed or they were sure you really didn't do it.

      the concept that the police can collect evidence and you have to give up evidence of your guilt has been around for a long time cause justice trumps your right to break the law

    7. Re:This is bullcrap by v1 · · Score: 2

      This is a case of secured evidence, not self-incrimination. If you have a locked safe that you won't give the combo to, they have the legal authority to break into your safe (and not compensate you for it), this is just an issue of where they are authorized to use force, but don't have sufficient force. (and this does indeed piss off the law / govt when it happens, they fancy themselves omnipotent and take enormous offense when proven otherwise)

      It really comes down to more of a case of getting the book thrown at you for not respecting their authority. Can they do it? Definitely. Should they do it? probably. but not definitely.

      Though this defense seemed to work for Ronald Reagan iirc? precedent by president!

      --
      I work for the Department of Redundancy Department.
    8. Re:This is bullcrap by Marc_Hawke · · Score: 4, Insightful

      The Courts (and Law Enforcement) have gotten really lazy, and it's confusing to me why they don't see it.

      During the San Bernardino iPhone stuff and other such stories, there were so many 'seemingly intelligent' people saying how encryption shouldn't be allowed because it made law enforcement difficult. Since when has it been easy? Wearing gloves makes it hard to pickup fingerprints. Should you outlaw gloves as well? However, these people are saying, "You should be forced to live in a way that makes it simple for us to track you all the time." "Papers Please!"*

      Two statements:
      "As more and more people are using encryption these days it's much more difficult for us to obtain evidence." - legitimate
      "As it impedes our abilities to gather evidence encryption in consumer devices should be restricted or should include a law enforcement backdoor." - completely not legitimate

      *(Actually with the 'papers please' that's more about proving you're allowed to be there, rather than checking to see if you shouldn't be there. So it really doesn't apply to the situation.)

      --
      --Welcome to the Realm of the Hawke--
    9. Re:This is bullcrap by WhiteKnight07 · · Score: 1

      Well the password itself isn't incriminating. Its just a string of gibberish characters. So he can be compelled to provide it. Now what it unlocks may be incriminating. But since the password is a key to a door and the evidence is on the other side of the door the key and the evidence are not the same thing. That line of separation means that the 5th doesn't apply to passwords.

      And when a judge orders you to do something in a trial, such as provide a password to your drive, and you decline, that's contempt of court. Simple as that. And the court has great power to punish contempt. (theoretically up to life in prison) Which is what is happening here. He is being punished for disobeying a judge. His guilt/innocence in the kiddie porn matter has not yet been determined.

      --


      We're going to make information free Mr. Anderson, whether you like it, or not.
    10. Re:This is bullcrap by JustNiz · · Score: 1

      So you're telling me that the Judge has power to order you to do literally anything during a trial? such as stick a knife in yourself or someone else? and if you refuse you are now in contempt and can go to prison for ever?

    11. Re:This is bullcrap by Anonymous Coward · · Score: 0

      >It's been long established
      No, it's been long interpreted that way. Despite the fact that that is 100% the opposite of what the constitution says.

      Sort of like how "The right of the people to keep and bear arms shall not be infringed" somehow means "the people don't have a right to keep and bear arms".

    12. Re:This is bullcrap by JustNiz · · Score: 1

      So if you make the password itself something that would be incriminating, you could legitimately withhold it?

    13. Re:This is bullcrap by Anonymous Coward · · Score: 0

      No, I think the real problem is this arbitrary distinction, in law, between a physical key and a non-physical key. A similar example would be the smartphone passcode vs. fingerprint unlock. Functionally they are the same damn thing, but legally they are treated very differently. This defies all common sense, and seems like just a bullshit excuse to go around the 5th amendment.

    14. Re:This is bullcrap by WhiteKnight07 · · Score: 1

      Well they are limited by the law. For the most part they can only order stuff that relates to the matter at hand. And the power to actually enforce their orders is in the hands of the executive branch, people who do not work for or answer to the judges. This is intentional, and for this very reason. This is also what the appeals process is for. A higher court can always throw out some crazy ruling by a lower court. But basically, yes. This is why appointments to federal judge positions are kind of a big deal, you don't want some crazy guy issuing court orders that make no sense.

      --


      We're going to make information free Mr. Anderson, whether you like it, or not.
    15. Re:This is bullcrap by Anonymous Coward · · Score: 0

      It really comes down to more of a case of getting the book thrown at you for not respecting their authority. Can they do it? Definitely. Should they do it? probably. but not definitely.

      Then I have to ask, if the police, lawyers, and judge himself do not need to follow the law - why does this guy, or any of us, have to follow it?

      It seems if our own court system and government claim breaking every law on the books is acceptable, then clearly breaking every law on the books is acceptable, including every last thing they are claiming he did that was illegal.

    16. Re:This is bullcrap by Anonymous Coward · · Score: 0

      A clever person might actually make the password into something that would be self-incriminating. Say I set my password to: "IRobbedRonaldMcDonaldOn20170101Of$100". Revealing that would definitely tend to incriminate me. So a password can both be protecting incriminating info and be incriminating info.

    17. Re:This is bullcrap by Hognoxious · · Score: 1

      the Judge has power to order you to do literally anything during a trial? such as stick a knife in yourself or someone else?

      Yes, it happens all the time. Don't they have Fox News where you live?

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    18. Re:This is bullcrap by Anonymous Coward · · Score: 0

      Tortuous logic. This is judicial branch legislation.

    19. Re:This is bullcrap by radarskiy · · Score: 1

      a) Forensics had already proven that he had downloaded and viewed material and then transfered it to the encrypted storage and the defendant did not deny any of that, so the defendant is already incriminated.

      b) Being jailed for contempt is not punishment for the crime, it's a sanction for refusing to follow the court order to supply the password. It's not even considered a punishment per se so "cruel and unusual punishment" arguements, like against the solitary confinement here, are hard to make.

    20. Re:This is bullcrap by sims+2 · · Score: 1

      They get a saw and cut your nice expensive safe open.

      --
      Minimum threshold fixed. Thanks!
    21. Re:This is bullcrap by Anonymous Coward · · Score: 0

      No, it has not been long established. In fact, it has not been established at allThere is a Supreme Court case (Doe v. U.S.) that makes this argument in a dissent> and a couple more that make passing reference to this dissent in dicta. That's it. There is zero binding precedent.

      Of course, I wouldn't expect the armchair Constitutional scholars here at /. to understand the difference.

    22. Re:This is bullcrap by JustNiz · · Score: 2

      It does seem ironic that the law/government makes the laws in the first place, so they can write whatever suits them, yet they still break them.

    23. Re:This is bullcrap by JesseMcDonald · · Score: 1

      The password (like a key to a safe) ...

      I think you mean "like a combination to a safe". Passwords aren't like physical keys—they're something you know, not something you have. And unlike physical keys, which can be seized with a warrant, there is no precedent for requiring a suspect to divulge the code to a combination lock.

      --
      "The state is that great fiction by which everyone tries to live at the expense of everyone else." - Bastiat
    24. Re:This is bullcrap by Anonymous Coward · · Score: 0

      You do realize here many of us are arguing that this particular order is contrary to the law right?

    25. Re:This is bullcrap by Obfuscant · · Score: 1

      So if you make the password itself something that would be incriminating, you could legitimately withhold it?

      "You are hereby granted immunity for any criminal act for which the password itself will incriminate you." There -- your password cannot be used against you in a court of law, even if it is "I killed JustNiz in the library with a hammer."

      I'm guessing this guy is buying himself an illusive and perhaps imaginary bit of safety by choosing contempt over a conviction for CP. His safety from other inmates lasts only as long as he claims he's in for "contempt of court". When it gets out that his contempt of court is because he's not revealing a password that hides CP he's a target.

    26. Re:This is bullcrap by Altrag · · Score: 1

      The trouble is not so much that it makes law enforcement difficult but frequently impossible.

      If you hide something in your safe, it can be difficult to get at. You need warrants and someone who knows how to drill a safe without setting off any safety features and whatever else. But its doable.

      If you hide something behind strong encryption on the other hand, it is literally impossible to get at without the key. There simply isn't enough computing power in the world to break strong encryption, in the general case.

      Now whether or not that warrants eroding the 4th and 5th amendments is definitely up for grabs. Especially when you consider that there are changes on the other side of the coin as well -- a safe could only hold so much stuff, so there was a limit to how much incrimination evidence may be found in a single safe. You average smartphone on the other hand provides your entire list of contacts, your browsing history, any files you've got stored.. The privacy invasion potentially goes much, much deeper when you gain access to a modern smartphone than when you gain access to a safe.

    27. Re: This is bullcrap by Anonymous Coward · · Score: 0

      Kinda like the Salem witch trials you mean ?

    28. Re: This is bullcrap by Anonymous Coward · · Score: 0

      If you want a "keep and bear arms", you are living in the past. Go build your own damn gate house inside the castle and take an axe to some poor bear, but leave me out of it. You have no right to force me to build one or kill one for you.

    29. Re:This is bullcrap by Altrag · · Score: 1

      In principle, sure.

      Of course we generally try to avoid appointing judges who would order such things, and if one ever did then the accused probably should hold themselves in contempt because that judge is going to get fired very quickly and the trial will start anew with a (presumably) saner judge, who would lift the contempt charges and everything resumes as normal.

      Our system is setup so that no one person is allowed to go too insane without some form of check on them.

    30. Re: This is bullcrap by PoopJuggler · · Score: 1

      The Hamburglar's identity is finally revealed!

    31. Re: This is bullcrap by Anonymous Coward · · Score: 0

      2nd amendment bro, check it out

    32. Re: This is bullcrap by PoopJuggler · · Score: 1

      There's really no way to procedurally generate illegal content into a hard drive, so that information has to come from the outside world at some point, meaning there exists physical evidence or testimony somewhere in the world. The police are just too lazy to hunt for it nowadays.

    33. Re:This is bullcrap by Anonymous Coward · · Score: 0

      The 5th protects one from having to testify as a witness against oneself. It doesn't protect against access to papers, effects, and otherwise sealed/hidden/guarded things being seized and revealed in court. Revealing an encryption key isn't testifying against oneself. It's merely handing someone a key to a locked safe full of files the court has ordered to be released to the prosecution.... which, by the way, has been done -- people have been held in contempt of court for not divulging the location of physical keys for physical safes. They're released upon either A) the safe was cracked or B) the key was found.

      The real issue is whether or not the person really knows the key. It's also true that one cannot be held indefinitely for not divulging what they do not have. If they encryption key existed on a thumb drive that has been destroyed or on paper that is gone -- or even simply in his/her memory that has faded, there is no reason for the court to hold them. One can't be compelled to give the court what one does not have. People have been held for contempt for not divulging combinations for locks and released later upon their testimony that they do not recall the combinations.

      Whether a combination or a digital key are treated like physical locks or instead like memories that can be forgotten depends on the court. What I want to know is how does a court establish whether or not the defendant HAS what the court has requested of them. How plausible is it that one has lost a physical key? How plausible is it that one has forgotten a combination? What about a 20 digit password that seeded a 256-bit encryption key? Even if the defendant was lying about having forgotten the encryption key... by NOW, he/she likely really has forgotten it! So, what now? Several years of languishing in jail with the inability to divulge the key even if one wanted to?!?!?

      I dislike that a defendant can be compelled to deliver a key which would open a vault of incriminating evidence, but I believe that is the way the law intended for this to play out. Back in 1776, there were no unbreakable locks and while primitive ciphers existed for correspondence, I doubt there was any issue with decrypting messages with or without a suspect's help. To say this is illegal and protected by the 5th is to say that just because we've created a better lock and safe by making them computerized and so complicated that only a magic word from the user can open the files, the defendant isn't obligated to say the magic word -- as if that is the same thing as testifying against oneself... which it isn't.

      The real issue is does the phrase "I do not recall." stand as a possibly true statement beyond a reasonable doubt -- which would make holding one in contempt nearly impossible... as one is complying with the court's request to the best of their ability. If the court compelled one to release their tax records from 5 years ago... and the person said they burned up in a fire... well... that's not necessarily contempt of court! If one has evidence there was indeed a fire, the court can't hold them in contempt. Even if there is no proof that those specific documents were destroyed in a fire... unless there's compelling evidence to the contrary, the court STILL can't hold them in contempt.

    34. Re:This is bullcrap by Anonymous Coward · · Score: 0

      5th Amendment only provides protection against testimonial incrimination, not evidentiary incrimination. Ruled on 5000 times by the courts.

    35. Re:This is bullcrap by Anonymous Coward · · Score: 0

      Your assertions are bullshit. The judge can tell me to fly like a bumblebee and I likely will not. I could have chosen a password string which in and of itself could constitute incrimination in some other matter -- The_answer_is_42!" for which I could assert a fifth amendment protection. This abuse of power will not stand on appeal.

    36. Re:This is bullcrap by DavidRawling · · Score: 1

      Then let them do the same thing here - that's what they DO with locks, and locked safes, and safe-rooms, and vaults, and anything else "physically secured" in that way. Oh - you're saying this is a Lonsdaleite lined safe and you only have cream cheese with which to cut it open? Sorry, not my problem. I'm with others above - either you don't have evidence (and you're fishing) or you do have the evidence, in which case I think the phrase is "crap or get off the pot".

    37. Re:This is bullcrap by Anonymous Coward · · Score: 0

      The password (like a key to a safe) itself isn't self-incriminating, even if the thing it's protecting may be.

      This is still widely contested, generally a key to a safe can be compelled because it is a physical object and that a passphrase cannot be because it only exists in someone's mind (unless you wrote it down somewhere in which case it counts as a physical object). My guess is this is a bold attempt by the court to set new precedent by ignoring the current one.

    38. Re:This is bullcrap by Etcetera · · Score: 1

      They get a saw and cut your nice expensive safe open.

      And then everyone whines and complains because Apple (or the encrypted device manufacturer) has the knowledge of how to use a saw to cut this type of nice, expensive safe open.

      Frankly, I think using the physical device analogy is good though. If the hard-coded decryption key is etched into silicon and only readable by physical access and some very expensive equipment then having an unlock brings us to almost exactly the same point: legal custody (whether of the safe or the device) means that eventually the authorities will be able to get into it with a warrant and/or subpoena.

    39. Re:This is bullcrap by sims+2 · · Score: 1

      Sure both safes and encryption only delay access one of it's good for a few hours and the other if it's good a few millennia at least.

      It's not impossible for apple to make their encryption where they can't break it in a timely fashion (more than a few years). IIRC the encryption itself is already to that point it's just apple's implementations that are breaking namely considering a a 4 digit pin secure and then trying to protect it with a 10 try limit that could work but only if you don't figure out a way to get unlimited tries which just so happens to be way easier than breaking the encryption.

      IMHO if apple can still break into it (in a timely fashion) they screwed up some where along the way of making their device secure.

      I always figured that since the os and all its background crap are usually still running you could just use a network vulnerability and get clear file system access that way but I haven't heard of anyone doing it that way so apparently it's not that easy.

      The big deal over the San Bernardino shooters iPhone wasn't really even about the encryption itself as it was about the weak pin number (I assume or short password) that had been used to protect it the Feds wanted unlimited tries to unlock the iPhone and they knew the password retry delay timer (and retry limit?) was just a software thing that apple could easily bypass. Apple didn't want to set precedent of being forced to make tools for the gov't to use less that become the status quo in the future.
      Anyhow the gov't found another company that could do it paid them an undisclosed sum unlocked the phone and found nothing.

      --
      Minimum threshold fixed. Thanks!
    40. Re: This is bullcrap by Anonymous Coward · · Score: 0

      No one is forcing you to do anything.

    41. Re:This is bullcrap by fyngyrz · · Score: 1

      They can just give you immunity for the "password crime", and there goes your 5th amendment protection right out the door.

      --
      I've fallen off your lawn, and I can't get up.
    42. Re:This is bullcrap by mark-t · · Score: 1

      Is it still contempt of court it *not* declining is beyond your ability? If you *do* forget your password and are asked to produce it by a judge, then the court cannot fairly still hold you in contempt unless they also believe (probably without having any actual evidence to substantiate it) that you are lying to them about having forgotten.

    43. Re:This is bullcrap by Anonymous Coward · · Score: 0

      Holding someone indefinitely without a trail sounds a lot like torture to me.

    44. Re:This is bullcrap by Ihlosi · · Score: 1
      The password (like a key to a safe) itself isn't self-incriminating,

      The location of where you dumped the body also isn't self-incriminating, even if the objects found there might be.

    45. Re:This is bullcrap by Anonymous Coward · · Score: 0

      Encryption isn't even a lock; it's a translation.

      If they raid my house and confiscate my papers, and they are all written in Urdu, does the court have the right to compel me to translate them to English?

      Not to defend the guilty, here, but IMHO when they have the computer and can access the files - encrypted or not - they have all the evidence the warrant authorizes. If you can break the encryption, more power to you. Otherwise I'm in no way obligated to translate a damn thing for you.

    46. Re:This is bullcrap by Anonymous Coward · · Score: 0

      Ah, so the password needs to be related to the content it is protecting! Genius!

    47. Re:This is bullcrap by Anonymous Coward · · Score: 0

      Perhaps that is something that needs fixing. Surely the state has a duty of care to its prisoners, and should be able to ensure their safety, whatever crime they have committed. Their punishment should be as per the sentence ruled by the judge and nothing more.

    48. Re:This is bullcrap by Bob+the+Super+Hamste · · Score: 1

      Sure both safes and encryption only delay access one of it's good for a few hours and the other if it's good a few millennia at least.

      If it is good encryption it will take more than a few millennia. While not everything can be a as heat death of the universe proof as one time pads, pushing the estimated energy requirements up to the mass energy of a star usually works pretty well and it wouldn't be all that difficult to push them up over the mass energy of the visible universe either. This would be applicable for an ideal quantum computer which fortunately is not something we are even close to building now.

      --
      Time to offend someone
    49. Re:This is bullcrap by Bob+the+Super+Hamste · · Score: 1

      The I don't remember is a perfectly valid defense if you are a politician. To be fair not only id Ronald Regan use it Hillary Clinton also used it quite deftly.

      --
      Time to offend someone
    50. Re:This is bullcrap by Anonymous Coward · · Score: 0

      And that's why I use a pyrotechnic safe. You saw it, it thermites the contents.

    51. Re:This is bullcrap by Anonymous Coward · · Score: 0

      The police should be able to break into a safe. With due process and a warrant, I'm basically fine with that. A safe is a thing, property.

      This is different. They are trying to break into a human being, as a way of breaking into a secured hard drive. They are also saying that they know the mind of the defendant.

      I'm a little troubled by both.

    52. Re:This is bullcrap by Anonymous Coward · · Score: 0

      True, but intentionally telling the prisoners of this would in my mind be a type of cruel or unusual punishment.

    53. Re:This is bullcrap by Anonymous Coward · · Score: 0

      a) If they already have evidence, then they don't need a password. Either they have enough for a conviction or they don't.

      b) The authority of the court is very broad, but no without limitation. The court MUST comply with the U.S. Constitution. The court does not have the authority to order the defense to do something that in effect would be testifying against himself. Claims to the contrary are not with standing.

    54. Re:This is bullcrap by gnasher719 · · Score: 1

      So if you make the password itself something that would be incriminating, you could legitimately withhold it?

      Possibly. Of course "I killed seven girls" as a password is not incriminating - it shows that you are a rather sick individual but not that you killed anyone. "Seven bodies are buried in my garden under the cherry tree" would be incriminating if it were true and the police checked.

      But a much more plausible case is when it is known that either you or your best friend is the owner of the encrypted drive, but it isn't known which one. Then providing the password would be _very_ incriminating and you wouldn't be required to provide it. And of course you couldn't be held in contempt because there's only a 50% chance that you are withholding the password.

    55. Re:This is bullcrap by gnasher719 · · Score: 1

      So you're telling me that the Judge has power to order you to do literally anything during a trial? such as stick a knife in yourself or someone else? and if you refuse you are now in contempt and can go to prison for ever?

      If you talk nonsense like that in court, then the judge hasn't just the right, but a legal obligation to stick a knife in your eye.

    56. Re: This is bullcrap by Altrag · · Score: 1

      They're too lazy to break the TOR protocol? They're too lazy to hack bitcoin? These are systems specifically designed to eliminate the evidence trail! That's their entire purpose for existing!

      And there are LOTS of people who are constantly looking for holes in these systems. And when they do find one, we don't sit there going "yay now privacy can be broached by anyone with enough resources!" we say "that's a scary bug it needs to be fixed ASAP!"

      Which is good, in general. Such systems are used to protect the privacy of dissenters in China and the Middle East and other places where "don't like the government" is considered a far worse and punishable crime than CP. If the cops here could simply be "not lazy" and break through those systems, so could the governments of oppressive nations.

      We've collectively gotten together and (for now) decided that the benefit to mankind as a whole is worth the cost of the occasional person getting away with downloading CP (presumably if they were creators, finding the victims would be more important than exposing the contents of their hard drives and there would be a significantly greater chance of non-digital artifacts existing and being findable.)

    57. Re:This is bullcrap by JustNiz · · Score: 1

      Interesting, I hadn't considered the multiple ownership angle. Even though it might technically be a legal barrier, I'll bet that still wont stop the judge from actually compelling you and as many of your friends as necessary to give it up or face contempt of court though.

    58. Re:This is bullcrap by JustNiz · · Score: 1

      I'm asking a hypothetical question, not standing in the dock right now.

    59. Re:This is bullcrap by v1 · · Score: 1

      This is different. They are trying to break into a human being, as a way of breaking into a secured hard drive. They are also saying that they know the mind of the defendant.

      Not quite. They ARE trying to break into a physical thing, an encrypted device. However, the key is no longer a physical thing. If it's a locked door, they don't force you to turn over the key, they simply break down the door. The key need not be involved.

      In the case of encryption, they need the key. So they turn to you.

      This becomes a question of "they are authorized to search it, and to use force if necessary, but in this case force isn't effective" They are then taking a step back to the purpose of the law, which is to allow them access to search for evidence. No one seems to be contesting this point, they are allowed, but they are also physically powerless. The route they need to take from there is not the route of force, but the route of key. And that leads them to YOU.

      So... it's now a question of "are we looking at the intent of the law, or the (outdated) description?" The kneejerk response is to say "we should follow the letter of the law, not make exceptions based on the intent", because that option appears to offer greater protection to the citizen, which is a good legal default. But this is also the opposite argument used in other cases like where police are charging citizens with federal wiretapping laws when they are filmed beating a suspect that's handcuffed. Now you want to look at the intent and not the words, again to offer better protection to the citizen.

      The problem is we can't have it both ways, so we have to pick (either as a whole, or on a case-by-case basis) whether to follow the letter or the intent. Case-by-case is sloppy and inconsistent, and as-a-whole is itself just as much a problem as going by the letter. I personally prefer "intent". In a democracy it's very rare for a badly-intended law to get on the books, but we're always having problems with badly-worded laws with good intentions getting on the books. It seems to happen continuously and certainly is a problem as laws age. So I conclude that "intent of the law" is the more appealing option. Our legal system with police and courts makes up both facets, the police enforce the letter, and those that pass that filter go to the courts where intent can be applied. Citizens can get out through either door, and so they should only successfully get prosecuted when both letter AND intent pass muster.

      I think if you want to make a defense here you're going to have to give up defending the key and look to defending the data. If you can get a court to believe that the data on the hard drive should be considered part of your fourth amendment protected status, you may have a case. If I think to myself "I wish my ex was dead", that's protected. Once I type it into a word document, suddenly my thoughts become searchable and admissible evidence. One can't be used to incriminate me, the other can. If you want to call the document protected, now what happens if I print it out? Is the printout protected too? What if I copy the file? Upload it somewhere? It's a difficult hair to split.

      A legal system that requires the assistance of the defendant to prosecute them is clearly going to experience failures. And that's what encryption is currently doing. "Contempt of court" seems to be getting a lot of use nowadays in cases where the law indeed does require the assistance of an uncooperative defendant - it itself is not a problem, but it IS a symptom OF the problem. I'm not against it for the sake of privacy, but I think when it becomes evidence, (and they have jurisdiction) they need access one way or another. This issue has been getting kicked around for quite awhile now and nobody's come up with an easy solution to it yet so I'm not holding my breath.

      --
      I work for the Department of Redundancy Department.
    60. Re: This is bullcrap by Squiddie · · Score: 1

      This made me chuckle. I've supported gun rights before, but I bought my first gun last November. Interesting stuff.

    61. Re:This is bullcrap by WhiteKnight07 · · Score: 1

      That entirely depends on if the judge believes your or not when you say "I cannot recall the password."

      --


      We're going to make information free Mr. Anderson, whether you like it, or not.
  7. Direct violation of the Constitution by nightfire-unique · · Score: 3, Insightful

    Nothing more to say, really.

    --
    A government is a body of people notably ungoverned - AC
    1. Re:Direct violation of the Constitution by Anonymous Coward · · Score: 0

      Congress, the courts and police have been violating the 1st, 2nd, 4th, and 5th amendments in the bill of rights for generations.

      McCain Feingold, the Gun Control Act, NYPD stop and frisk, Kelo vs New London...just a few examples.

    2. Re:Direct violation of the Constitution by mjwx · · Score: 1

      You keep saying that like it matters any more.

      --
      Calling someone a "hater" only means you can not rationally rebut their argument.
    3. Re:Direct violation of the Constitution by Anonymous Coward · · Score: 0

      I concur with you.

      It seems to me that being forced to give up your passwords is being forced to incriminate oneself.
      As you say a direct violation of the Constitution and this from a judge.

      Or can someone explain to me how my thinking on this is not correct?

    4. Re:Direct violation of the Constitution by Anonymous Coward · · Score: 0

      Nothing more to say, really.

      There's a lot more to say. This is basically the government saying they will screw over anybody that makes trouble. If you're the next Thomas Jefferson, or Martin Luther King - they'll get random data onto some system or medium, discover it in your possession, claim it's child pornography, and demand the password. Since you never knew the password, you can't provide it. Bingo! You're presumed guilty, in jail for life, no jury trial, no Bill of Rights, no possibility of parole - and a lot of stupid human beings we'll assume you must have been guilty.

      Plain and simple - this comes down to the government infringing a whole host of fundamental rights, not just the 1st Amendment, the 5th, the 9th, and the 10th.

  8. In fairness by HeckRuler · · Score: 5, Insightful

    So when are the politicians going to be charged with contempt of court when they "do not recall"?

    1. Re:In fairness by Anonymous Coward · · Score: 0

      most politicians are well informed prior to a court case and know exactly how far they can push the "do not recall" line, and to be fair in many cases it is a reasonable situation as often cases are years if not a decade or more after the situation occurred. I was on a Jury a couple of years ago for a murder trial and I could not count the number of people that answered "I do not recall", basically if you are not 100% certain then I do not recall is the correct answer. Many Politicians have been charged with Contempt for various offenses though.

    2. Re:In fairness by Anonymous Coward · · Score: 0

      So right about this. The things they are being asked to remember are much simpler than a long password made or random characters.

    3. Re:In fairness by Swave+An+deBwoner · · Score: 1

      Please. You are so biased you must be from the MSM.

      https://www.c-span.org/video/?c4659119/franken-sessions-exchange-russia

    4. Re:In fairness by kauaidiver · · Score: 1

      re. politicians Investigators can find different angles, albeit probably unsuccessfully. But this is a case of evidence that is just not there, well unless they can break the encryption, even then maybe it's still not there.

  9. Three strikes by Anonymous Coward · · Score: 0

    Strike one: male, under investigation for pedophilia
    Strike two: encrypted disks (not necessarily a pedo, might also be a Trump hacker/spy of some kind).
    Strike thee: knows about his constitutional rights... Cant have that! Lock him up already.

  10. I believe it by sizzlinkitty · · Score: 1

    In my personal experience, passwords that are > 24 characters, are easily forgettable if unused for a period of time. I struggle with remembering complicated passwords if I haven't used them in over a month. Not sure if it's because they're to complicated or if it's a neurological limit. I also suffer from ADD and have a history of radiation exposure.

    That being said, I completely understand how it's possible for someone to forget a password.

    1. Re:I believe it by computational+super · · Score: 1

      Shit. I had to reset my work login password just before going on vacation for a week. Couldn't remember what the heck I had reset it to when I got back, had to ask IT to reset it for me. I can absolutely believe that somebody could have forgotten a password.

      --
      Proud neuron in the Slashdot hivemind since 2002.
    2. Re:I believe it by haruchai · · Score: 1

      In my personal experience, passwords that are > 24 characters, are easily forgettable if unused for a period of time. I struggle with remembering complicated passwords if I haven't used them in over a month. Not sure if it's because they're to complicated or if it's a neurological limit. I also suffer from ADD and have a history of radiation exposure.

      That being said, I completely understand how it's possible for someone to forget a password.

      Obligatory xkcd - https://xkcd.com/936/

      --
      Pain is merely failure leaving the body
    3. Re:I believe it by DavidRawling · · Score: 1

      So let me see. Was it:

      • * correct horse battery staple
      • * correct horse staple battery
      • * correct donkey battery staple
      • * wrong horse battery staple
      • * maybe dolphin pen balloon
      • * cable muppet carriage piggy
      • * ...

      All the people pushing hard passwords and catchphrases should probably read this again. They're the top 5%-8% of the population. WE are the top 5%-8% of the population in this regard and we can't even get it right. What chance does your average tradie have - they may be experts and legends in their fields but in ICT they're ... well, normal. Have you watched most people type a password or email?

      I can't wait for Windows Hello or something similar on phones (Samsung have something I think, windows phones did/do?) to get better and better so that people can have stupidly complex passwords in a safe and use their faces to unlock on a daily basis (it's one thing to sign you into a game console, it probably should be another level entirely to unlock the nucular (sic) launch codes).

    4. Re:I believe it by Anonymous Coward · · Score: 0

      I have 50 different passwords to various sites (no two the same), and three work computer passwords that change every 60 days. The secure one has to be 15 characters and have a whole bunch of different rules. If I don't use it for a week, I easily forget it.

  11. Access/modification times by phorm · · Score: 1

    Self-incrimination issues aside:

    On these drives, are they completely encrypted preventing mounting or is it just the file contents?
    If it's the former, then one should be able to see the last time a file was changed. If it's a few days before the seizure, I'd call BS. If the last access/modification was a fair time ago then it becomes more reasonable to assume the "I forgot" defence is truthful

    1. Re: Access/modification times by jandrese · · Score: 1

      Full disk encryption, so it won't even mount without the password.

      --

      I read the internet for the articles.
    2. Re: Access/modification times by Khashishi · · Score: 1

      Well, then, they could probably get an estimate of "access time" from the amount of dust on the computer, skin oil on the keys, etc.

    3. Re:Access/modification times by Anonymous Coward · · Score: 0

      The external drives were encrypted, but not the laptop it connected to. It would be trivial to look at SMART data to determine drive access time, in addition to view various system logs which might indicate times of drive mount and decryption. Claiming he doesn't remember password when its obvious that he accessed the drives recently, would seem to justify the contempt charge.

    4. Re:Access/modification times by Anonymous Coward · · Score: 0

      If you have an encrypted container on Veracrypt, it defaults to not updating the modification times on the file. That will cause your container not to be updated by your backup program until you another full backup since the backup say for an incremental, "Nope, hasn't changed"

  12. Contemptible. by msauve · · Score: 5, Insightful

    I agree, it's contempt of court. As well it should be, since the court is contemptible. The right against self-incrimination is absolute - you don't have to testify against yourself, you don't have to unlock that (combination) safe, you don't have to decrypt files. You have the right to remain silent.

    That is, unless it's the physical key to a safe, or some hardware encryption key. That's physical, and subject to seizure. But a combination or encryption password is a product of the mind, and forcing it out is forcing self-incrimination.

    Sure, law enforcement has a right, with the proper warrant, to break into the safe or attempt to decrypt the contents themselves, but failing that, they're simply SOL.

    --
    "National Security is the chief cause of national insecurity." - Celine's First Law
    1. Re:Contemptible. by guruevi · · Score: 1

      Although the SCOTUS agrees with you, there hasn't been any legally binding decision made surrounding these issues, lower courts have typically established that providing some assistance to your own conviction is acceptable.

      The 'true' solution would be to create a password/passphrase that requires you to actively participate with your mind. Eg. - I can only unlock this password by doing some sort of obstacle course with each stop providing me parts of the passwords.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    2. Re:Contemptible. by Anonymous Coward · · Score: 0

      Puzzle locks are actually easier to manufacture than key locks. The problem is, -anyone- who can solve the puzzle, gets the key.

    3. Re:Contemptible. by Anonymous Coward · · Score: 0

      The federal courts once upheld the right to own slaves and the power of the government to detain Japanese-Americans until a year after World War 2 ended. The courts have always been the weakest link in the US system of government because they aren't even elected or subject to recall.

    4. Re:Contemptible. by houghi · · Score: 1

      So what if I do not have the key to a safe in my posession anymore? I lost the key.
      Same applies here. You can not hand over something that you don't have.

      --
      Don't fight for your country, if your country does not fight for you.
    5. Re:Contemptible. by chihowa · · Score: 1

      I don't think that he's saying that you can be compelled to produce a physical key, but that a physical key can be seized against your will if it can be found. Since a product of your mind can't (yet!) be seized without your cooperation, and you can't be compelled to cooperate, it is off limits.

      --
      If you want a vision of the future, imagine a youtube comments section scrolling - forever.
  13. Won't be disclosing anything that's new or unknown by innocent_white_lamb · · Score: 1

    My understanding of the logic behind attempting to force him to provide the passwords is that he won't be giving the government anything that they don't already know or have.

    That being the case, why do the need the passwords at all? If they already "know everything", then they can proceed with their prosecution. If they don't have everything that they need to proceed without the passwords, then they obviously don't know everything.

    Self-contradictory, isn't it?

    --
    If you're a zombie and you know it, bite your friend!
  14. Not to say "I told you so," but... by Anonymous Coward · · Score: 0

    I told you so.

    While it still (at the moment) seems unconstitutional to force a person to reveal their passwords, it is simple to get around this by ordering the person to enter the password themselves.

    So if you think you're going to evade the long arm of the government by memorizing all your passwords, think again or you too will be jailed.

    And remember kiddies, "I forgot" or "I don't remember" only works if you are part of the government itself ;)

    1. Re:Not to say "I told you so," but... by haruchai · · Score: 1

      I told you so.

      While it still (at the moment) seems unconstitutional to force a person to reveal their passwords, it is simple to get around this by ordering the person to enter the password themselves.

      So if you think you're going to evade the long arm of the government by memorizing all your passwords, think again or you too will be jailed.

      And remember kiddies, "I forgot" or "I don't remember" only works if you are part of the government itself ;)

      The Cheney defense although I'm sure it was used by others long before him

      --
      Pain is merely failure leaving the body
  15. Destroy code? by PCM2 · · Score: 3, Interesting

    Seems like encryption systems need to have two passwords; one that decrypts the volume and another that wipes the keys and images a fresh filesystem. When they compel you to enter your password, you enter the "destroy code."

    Sure, you could be charged with tampering with evidence if they realized what you'd done. But maybe that would be preferable to indefinite incarceration for contempt of court.

    --
    Breakfast served all day!
    1. Re:Destroy code? by mykepredko · · Score: 1

      Probably the best solution.

      But, could you really be charged with evidence tampering if the prosecution can't prove beforehand there was evidence there in the first place?

      I suspect it would be a long and expensive process to find out what the final outcome would be.

    2. Re:Destroy code? by Kardos · · Score: 5, Insightful

      No, it is not even fantasy to have a "destroy everything" password. Even a rookie investigator knows to make a copy first. If you provide self-destruct keys it'll be blatantly obvious.

    3. Re:Destroy code? by Anonymous Coward · · Score: 0

      The trick is to setup your hardware so that making an image of it automatically destroys the keys. That way you can give them the password because it's already useless.

    4. Re:Destroy code? by haruchai · · Score: 1

      Seems like encryption systems need to have two passwords; one that decrypts the volume and another that wipes the keys and images a fresh filesystem. When they compel you to enter your password, you enter the "destroy code."

      Sure, you could be charged with tampering with evidence if they realized what you'd done. But maybe that would be preferable to indefinite incarceration for contempt of court.

      I doubt that would work in this case as I'm sure LEO images the media and tries to decrypt the images.

      --
      Pain is merely failure leaving the body
    5. Re:Destroy code? by Khashishi · · Score: 1

      I think forensic analysts will mount your disks in read only before mucking with them.

      A better solution would probably be to have a password that decrypts only part of the drive which contains decoy data.

    6. Re:Destroy code? by silas_moeckel · · Score: 4, Interesting

      This is very hardware dependent. Plenty of systems out there that require a passkey to unlock but nuke themselves with a few bad tries. They are not clonable (unless you're the NSA and even then some go to lengths to prevent chip lapping and other methods from working). In essence it's a small computer that you can not practically copy with a hardened interface that stores the actual decryption keys.

      Even the TPM chips tied to hard drives should support that.

      --
      No sir I dont like it.
    7. Re:Destroy code? by Anonymous Coward · · Score: 1

      unless you have found some magic way to protect offline storage from being read how the fuck do you propose to do that besides some sort of electronic bomb which would probably get you in as much if not more trouble.

    8. Re:Destroy code? by AmiMoJo · · Score: 1

      The first thing try do when they take your computer is make forensic copies of all storage media.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    9. Re:Destroy code? by subanark · · Score: 1

      I think a time bomb would be better. An internal clock will count down 1 week, and if no key is given in that time it wipes the decryption key. The courts should be held up long enough to permit this too occur, if not you can reduce the time.

    10. Re:Destroy code? by phorm · · Score: 1

      And that's why clones of the media are made before any unlock attempt is made...

    11. Re:Destroy code? by JesseMcDonald · · Score: 1

      I doubt that would work in this case as I'm sure LEO images the media and tries to decrypt the images.

      You don't wipe the drive itself, you wipe the key stored in the TPM or equivalent (which is tamper-resistant and not easily cloneable). Even with the master password, no one can decrypt the contents of the drive without the active participation of the original TPM. An image of the encrypted drive will not help at all if the TPM can be persuaded to delete the sole copy of the decryption key, for example by providing it with a duress password.

      --
      "The state is that great fiction by which everyone tries to live at the expense of everyone else." - Bastiat
    12. Re:Destroy code? by Anonymous Coward · · Score: 0

      This is standard, hidden partition, in Veracrypt. Look it up, it does exactly that.

    13. Re:Destroy code? by Anonymous Coward · · Score: 0

      If you provide self-destruct keys it'll be blatantly obvious.

      Because the evidence you were hoping to find is not there? Or because the encrypted volume is gigabytes in size but when you've entered the decryption key, the volume turns out to be empty?

    14. Re:Destroy code? by Anonymous Coward · · Score: 0

      Hell, how about 10,000 destroy codes? Let them try to brute force the unlocking password without hitting a mine.

    15. Re:Destroy code? by Anonymous Coward · · Score: 2, Insightful

      One approach is to use a set associative cache for the device and then store the keys in the cache, but not in the associated blocks on the device. Only with the correct password can you figure out which sectors are safe to read and which ones take extra care.

      So any bulk read, overwrites the cache destroying the keys. The wrong password does the same thing.

      As someone else pointed out, most TPM chips require a password to decrypt the data, and if you give the wrong password more than a couple times in a row, they wipe themselves.

      So you are right, you can't destroy the data on protected offline storage, but as soon as someone tries to read it, it's no longer offline and can wipe itself.

    16. Re:Destroy code? by SumDog · · Score: 1

      You can only reasonably do this is the police use your bootloader. The destroy code would need to have the exact same wording ("Unlocking device" or whatever) and while actually writing random data over the disk and leaving you with "Unable to open volume."

      Now if the police had made a copy, they could tell between the two copies that one version zeroed the disk.

      In reality, the police would remove your disk and not use your bootloader. You would need to use an encrypted format that actually ran some application code as the result of a specific key, with that application code itself encrypted by said key. It would have to be integrated as part of the unlock process. LUKS doesn't provide any of these mechanisms by default.

    17. Re:Destroy code? by CrashNBrn · · Score: 1

      Perhaps something a little closer to the hardware, where a drive that has two or more partitions, requires a paired SecureKey (UBIKey) before it will report the existance of the additional partitions and/or the true size of the drive including the "extra partitions."

    18. Re:Destroy code? by Anonymous Coward · · Score: 0

      Sure, you could be charged with tampering with evidence if they realized what you'd done.

      They would have to proove, beyond a reasonable doubt, that there was actually something on the volume before you wiped it. For all intents and purposes, you will have simply complied with the demands of the court and unlocked what had always been an empty file system.

    19. Re: Destroy code? by Anonymous Coward · · Score: 0

      Drive is imaged.

    20. Re: Destroy code? by PoopJuggler · · Score: 1

      Except by the geniuses at the FBI in the San Bernardino investigation.

    21. Re:Destroy code? by AHuxley · · Score: 1

      The US gov can detect the use of hidden volumes. They may not want to tell the world they can decrypt consumer crypto.
      But they are happy to show a court that encryption was used to secure data.
      Can they detect how many volumes and the type of filesystem alteration that could be induced with a password?

      --
      Domestic spying is now "Benign Information Gathering"
    22. Re:Destroy code? by sims+2 · · Score: 1

      The iphone uses a secure enclave.
      It's a one way crypto chip it can be set but it can't be read.
      To unlock the phone the secure enclave must be queried and you've got 10 tries (if you enabled the wipe option) after which it erases it's stored encryption key for the primary storage.

      So even If you had the storage mirrored you would never be able to decrypt it later if it destroyed the keys even if you ended up with the password.

      Well that's how it's supposed to work anyway IIUC.

      AFAIK no one has discovered a way to recover keys from even an unlocked secure enclave but iirc they have managed to trick the system into forgetting tries so they get an unlimited number of password tries.

      --
      Minimum threshold fixed. Thanks!
    23. Re:Destroy code? by Anonymous Coward · · Score: 0

      Every single reply was wrong or lacking on details.

      They use something called a "write blocker" which physically goes between the drive and their computer. It by design disallows any writes to the drive, accidental or otherwise.

      So you should instead be searching for exploits on write blockers since they are known to exist.... Basically you reflash a drives firmware such that read commands at certain address ranges are actually writes and vise-versa. Then once a write blocker is connected and they read those addresses, the data is gone. They normally wouldn't expect this thus wouldn't protect against it in most circumstances.

      The write-blockers even have RAM and will send back the "altered" data upon a read so it appears to any software that the device is writeable but it's really mitm'ing the drive and keeping track of what changed elsewhere. This way you cannot specifically "test" for it either...

      Anyways, read about these and actual forensic work before commenting to others. Your Opsec Kung-Fu is No good!

    24. Re:Destroy code? by infolation · · Score: 1

      The US gov can detect the use of hidden volumes

      It's important to state that if the hidden volume within an encrypted container has been created correctly and is used correctly (see below) on a machine that does not have compromised OS or firmware, the presence of a hidden volume cannot be proven. The encrypted free space remaining after the main volume's data ends is as random as any other encrypted data (including hidden volume data).

      Care must be taken with backups. If two copies of the same volume exist (main plus backup) and the hidden partition of one has been altered while the other has not, then this can reveal the existence of a hidden volume.

    25. Re:Destroy code? by Anonymous Coward · · Score: 0

      They copy the drive...

    26. Re:Destroy code? by ThomasBHardy · · Score: 1

      I'd think the more flexible solution would be to build the encryption tools to have -optional- have two passwords for a volume. Each accesses a different file table. If you provide keys, noone can ever prove if the keys were to the "one volume I set up" or to the "hidden portion of the secure volume"

      Effectively a decoy keyset

      --
      Warning: Teh poster of this messaeg is lysdexic
    27. Re: Destroy code? by phorm · · Score: 1

      That was an iPhone, not a hard drive. While cloning flash memory isn't impossible, doing so on a mobile device would be more difficult than on most computer hard drives.

    28. Re:Destroy code? by Wulf2k · · Score: 1

      How long until the police realize that every single hard drive in existence has a secret OneTimePad that they can "brute force" that will prove it's full of child porn?

    29. Re:Destroy code? by gnasher719 · · Score: 1

      Seems like encryption systems need to have two passwords; one that decrypts the volume and another that wipes the keys and images a fresh filesystem. When they compel you to enter your password, you enter the "destroy code."

      What would be the use of that if you don't want to commit a crime and hide the evidence?

  16. Just give them a fake password by Anonymous Coward · · Score: 0

    When it doesn't work, just say, "whelp, I guess the drive is corrupted".

  17. dumbass by Anonymous Coward · · Score: 0

    Maybe if he hadn't filed for 5th amendment first this wouldn't have happened.
    > You can't make me tell you, it's against the law, and even if you could I've forgotten.
    Yeah, that's not suspicious at all.

  18. Dead-man switch it is, then. by Anonymous Coward · · Score: 0

    Operation of the device past a certain date, without entry of the password will cause all data to be irretrievably lost. Not sure how to set that up; but that looks like the way of the future.

    1. Re:Dead-man switch it is, then. by Anonymous Coward · · Score: 0

      I know a similar one. Password is fed to drive controller by a series of disk seek commands. If an attempt is made to read past the end of the boot partition before issuing the right password, the controller starts formatting. I prefer the variant where the controller uses its voltage pump to fry the attached SATA controller.

  19. Frame jobs made easy by Anonymous Coward · · Score: 1

    Slip your own encrypted disk into someone else's possession, send an anonymous tip to the cops, and they go to jail for the rest of their lives.

    1. Re:Frame jobs made easy by Anonymous Coward · · Score: 0

      Lol good tip. I hate my neighbor because of loud noise and almost drunk every night. I think I will give my neighbor an encrypted hard drive and then call the police.

    2. Re: Frame jobs made easy by Anonymous Coward · · Score: 0

      Too much effort. Just generate a large random number- say, 100 gigabytes long- anywhere in their possession, then claim:

      1) The random number is an encrypted partition
      2) You witnessed it mounted, and it contained illegal content

      He can't prove his innocence (the random number could be a truecrypt partition) and he is guilty until proven innocent.

  20. Re:Won't be disclosing anything that's new or unkn by msauve · · Score: 1

    The government's argument is that the passcode itself is not incriminatory. It's the protected contents which may be, and the person is not being asked to directly disclose those. But that ignores that showing the ability to access the files may itself be incriminatory.

    Anyway, his passcode is "1Admit1'mGuiltyAsH3ll.", so disclosing it would be self-incrimination.

    --
    "National Security is the chief cause of national insecurity." - Celine's First Law
  21. What court? by WillAffleckUW · · Score: 2

    Secret courts can pry my encryption keys out of my cold dead American hands!

    --
    -- Tigger warning: This post may contain tiggers! --
  22. Clearly violation of 5th amendment.. by evolutionary · · Score: 2

    The government has been violating the constitution in spirit and word for so long that nobody seems phased by this sort of nonsense. It sadly gives weight to Trump's phrase "so-called judge": Forcing anyone to incriminate themselves by compelling them to give information in their mind is blatant violation of the 5th amendment. It's upon burden of prosecution to provide evidence BEFORE trial, not compel someone being tried to give evidence during the trial. As has be proven many times, there are a various number of ways investigators can get around encryption with a little planning (the was that guy running the drug trading service from a library I remember, they did it smart and the charged individual was a bit smug/laid back). If you can't prosecute with out that data, it shouldn't have been brought to trial. and if you have proper evidence already, don't need anyone's password. It's creating a culture where proper policework is not done, but prosecution says "to blazes with proper evidence, we'll use circumstantial evidence and wing it in court because it's convenience to try to compel someone being tried to waive their 5th amendment rights. you give us everything we need to prosecute you, or we'll lock you up for contempt charges. That's just wrong. And given the huge data dragnet we already have controlled by the CIA (another unconstitutional program confirmed by the courts). they have other tools (even if unconstitutional less so) for using data in a court case. Putin claims our system is no better than Russia, and if we keep violating our supposedly most precious standards like this, we'll prove him right.

    --
    "Imagination is more important than knowledge" - Einstein
  23. Does this case fit the precedent? by nctritech · · Score: 4, Interesting

    There is precedent for this when the defendant has already decrypted the drive for authorities and then refuses to do so for the court. In that case, the contents are considered a "foregone conclusion" and there is no question that the defendant both acknowledges the encrypted volume and knows the key to decrypt it. This is a reasonable balance against Fifth Amendment protections.

    If he has not ever revealed the password to authorities, the Constitution absolutely prohibits this action by the court. A man cannot be compelled to self-incriminate, the court may not presume guilt (innocent until proven guilty), and the court can only establish guilt through due process of law (everything from investigation to conviction) and with equal protection under the law (the law is applied the same way to everyone). This ruling blatantly violates most of these basic rights if the contents of the drive are not a "foregone conclusion."

    1. Re:Does this case fit the precedent? by TheRealMindChild · · Score: 2

      A man cannot be compelled to self-incriminate

      Sure they can. Do this field sobriety/breathalyzer/blood test combo. Oh, you refuse? Don't worry, we'll use that as evidence against you in a criminal case because you broke a civil law!

      It is not different here. They are nailing the dude for contempt, not for not testifying against himself. There are always ways around that bush

      the court may not presume guilt (innocent until proven guilty), and the court can only establish guilt through due process of law (everything from investigation to conviction)

      See above.

      I'd like to also point out this isn't the only scenario where your "constitutional rights" are subverted by twisted perversion of the law

      --

      "When life gives you lemons, don't make lemonade. Make life take the lemons back!" -- Cave Johnson
    2. Re:Does this case fit the precedent? by nctritech · · Score: 4, Interesting

      They can't criminally charge you for not taking the sobriety field test. They can and will take your license away. That's not a criminal process, it's a regulatory one. Different states may have different variations but the song generally remains the same. Driving is legally considered a privilege, not a right. It isn't the same thing.

      I agree with your second part. Civil asset forfeiture is a blatantly unconstitutional thing that is constantly abused. It's still not a constitutional action, but the guys with the guns make the rules in the end.

    3. Re:Does this case fit the precedent? by Anubis+IV · · Score: 3, Informative

      Ruling that it's a "foregone conclusion" is exactly what happened here, but for different reasons.

      While the defendant hadn't provided the Mac Pro and hard drive passwords previously, the investigators managed to figure out the password to his Mac Pro and were able to use that access to determine that it had been used to visit child porn sites and download thousands of files that matched the hashes for recognized child porn files. Those files weren't found on the Mac Pro, but the defendant's sister testified "that Doe had shown her hundreds of images of child pornography on the encrypted external hard drives". Between the download history, hash matches, and testimony about the location of the files, the judge ruled that it's a foregone conclusion that the drives contain child porn and that turning over the password is not testimonial in nature as a result.

      I'm not sure that I necessarily agree with that assessment (it could be that providing the passwords is still testimonial in nature with regards to crimes they don't know about that his knowledge of the passwords would implicate him of), and the article points out that it's likely this case will go all the way to the Supreme Court.

    4. Re:Does this case fit the precedent? by Anonymous Coward · · Score: 0

      Thanks for the great example of an answer that will get you a failing grade on your upcoming first year criminal law exam.

      Please ask your professor or study group about the difference between testimonial and non-testimonial information. Also, be sure to review the jurisprudence on judges' contempt power with respect to failure to comply with a warrant supported by probable cause before submitting your next sample test to the study center.

    5. Re: Does this case fit the precedent? by Anonymous Coward · · Score: 0

      thats a good point and in that circumstance would be for sure.

    6. Re:Does this case fit the precedent? by Anonymous Coward · · Score: 0

      Just wait until the state uses your reasoning against you. "Owning property is a privilege, not a right."

    7. Re:Does this case fit the precedent? by nctritech · · Score: 1

      That's not "my reasoning." I didn't make that decision. Go be a sovereign citizen traveler somewhere else.

    8. Re:Does this case fit the precedent? by nctritech · · Score: 1

      Dear Keyboard First Year Law Student,

      I see that you've criticized something I've said but offered no information in response. Please enlighten us with detailed information to fill in the knowledge you feel is lacking. Feel free to provide the needed information on how to sign up for your newsletter while you're at it. I'm sure several readers would like to keep up-to-date on your current state of snark at any given time.

    9. Re:Does this case fit the precedent? by Ihlosi · · Score: 1
      ... and there is no question that the defendant both acknowledges the encrypted volume and knows the key to decrypt it.

      So now you're required to have perfect memory of each and every single password you ever used in your life?

    10. Re:Does this case fit the precedent? by nctritech · · Score: 1

      No, just the one you foolishly used to open it for law enforcement already. The lesson is "never decrypt for the cops in the first place."

    11. Re:Does this case fit the precedent? by Anonymous Coward · · Score: 0

      Then they have enough to prosecute, right?

      And if he gets away, either he keeps peddling in CP and they get another shot or he stops because he just got nearly caught and doesn't want to risk it again.

      Since the point of getting him incarcerated is to protect the children, the second one is actually by a long chalk the best result possible, given we have no time travel devices to undo the past.

    12. Re:Does this case fit the precedent? by Anonymous Coward · · Score: 0

      If it is so clear the the images are as to be a foregone conclusion then why do they even need to decrypt the hard drive. just convict him on the evidence you have.

    13. Re:Does this case fit the precedent? by Anubis+IV · · Score: 1

      I quite agree. In this situation, if you don't have enough to convict already, then how can it be a foregone conclusion? And if you do have enough to convict, then why do you need additional evidence? Convict him with what you have; don't use shady methods for procuring more evidence to try to make your case stronger.

    14. Re:Does this case fit the precedent? by grolaw · · Score: 1

      This is sloppy legal analysis. If the court was even remotely consistent then the vast number of times that I have had to deal with that answer (and, the followup objection by defense counsel: asked and answered) to subjects that the witness does not want to discuss in deposition would disappear in a puff of legal logic.

      On occasion I've let the weasel slide and during the body of the deposition I've inserted questions along the line of:
      Are your parents still living? When did your father pass? When did your mother pass?
      What was the address that you lived at when you left for college?
      Please state all of your past employers that paid you enough to require that you file a tax return?
      What is your wedding anniversary?
      What is the day and month of your spouse's birthday? (each of the kids follow)
      Who was your favorite college prof? What class or classes did you take? Do you remember your grade(s)?

      When did you receive the notice of this deposition?

      What did you have for breakfast?

      What color tie is your attorney wearing?

      I toss those in over 2-3 hours and then ask the question that the deponent could not remember (so conveniently).

      I draw two objections - asked and answered and argumentative.

      I always ask that we call the judge to get a ruling.

      I explain that I've just asked the deponent questions covering many decades about minutia that most people would not recall and the deponent has answered each question without objection from defense counsel. I wish to explore the "memory hole" and how only the fact critical to the case is the ONLY matter that the deponent cannot remember.

      Usually the judge gives me a little leeway - but, the record is clear - the deponent's memory is just fine until the fact that will hurt is brought up.

      Of course a 5th Amendment objection ends the inquiry (I'm a civil litigator).

      The willingness to tolerate the mendacity of poor memory on a daily basis in civil actions puts the lie to this "convenient" ruling.

    15. Re:Does this case fit the precedent? by Anonymous Coward · · Score: 0

      The courts are dancing around the issue. The constitution clearly gives us the right to travel. It doesn't say "unless it's unsafe" or "right to travel with a license". The argument that licenses are for safety are bull shit. Until about 1970 there were still states that had no written or driving test associated with the license. The drivers license was all about regulation- not safety. The courts have danced around the issue hindering people from utilizing these rights in flagrant disregard. Calling them privileges is a hostile violent attack and anybody reacting in self defence would be justified- even if doing so alone is insane. It's a right and the courts have blatantly and routinely violated our rights. Unfortunately the masses sit back and do nothing.

      http://www.freestateproject.org/ - those whom are fighting these things are moving to New Hampshire- people are getting arrested- they are winning cases. The driving cases are still in the courts... but a loss here won't end the fight. It's likely going to take a long time to overcome many of the obstacles that have been put in place that have taken aware our rights. But... at least there are people fighting. There are people disobeying. There have been some successes. And they're moving together to fight via any and every means available. From passing new laws (no more mandatory permits for concealed carry in NH for instance, etc) to court cases (we won the right to film government officials, etc) to regular civil disobedience protests (ever smoke pot on the state house steps? cause we do it every year and have- and NH while not yet legal- may become the first state to do total decrim).

    16. Re:Does this case fit the precedent? by Anubis+IV · · Score: 1

      I have nothing to add or respond with, other than a sincere Thank You for taking the time to respond. The rest of us are talking out of our asses based on a few sentences or a paragraph we read as a summarization of the issue, so it's nice to have someone with an informed perspective actually chime in. Thanks again!

  24. While we're at it... by xession · · Score: 2

    Why not just subject him to water boarding and other forms of "enhanced interrogation" techniques? At this point, what does it even matter? If we are so willing to break some of the most fundamental rights owned by our society, then what does the rest of it matter? You can argue day and night about whether there is still logic to the 2nd amendment; and lets be real, the logic falters when you exercise that right against a military as heavily funded as in the US. However, the existence of the 5th amendment is paramount to the freedom of our citizens.

    Why stop at compelling an alleged criminal to stand as witness of information against themselves? Why not violate the rest of the amendment and just retry every single case that we thought should have gone another way. Hell, why even bother with costly trials at all? We can just go full Idiocracy right now and just decide if a person is guilty by appearance and conjecture alone.

    Maybe we can avoid breaking the 5th amendment by violating the 4th instead and just require every person to subject themselves to a monthly screening of their house, vehicle and computer. Keys and Passwords would only be allowed to be administered by the state. Any time necessary, they state can perform an immediate screening of your property. Then no one has to stand as witness against themselves.

    Lets take away the annoying 6th amendment too. No need for a speedy trial in cases like this. If an assailant is so clearly guilty, regardless of obtained evidence, then maybe its just 'good enough' that the person be locked away. Maybe we can allow police officers to act as jury as well. They surely know the law better than the commoner. Maybe that would ensure speedy trials instead.

    Which brings us back to the 8th amendment and "enhanced interrogation" techniques in obtaining any necessary information that just can't quite be obtained in any other manner deemed reasonable by this modern governing style.

    No matter what this person really did, the ultimate sacrifice is made by our entire society by breaking the fundamental rules that were set up to prevent this exact thing from happening. The bill of rights is far more important to the whole than this one trial, even if the accused is so accused accurately.

    1. Re:While we're at it... by Anonymous Coward · · Score: 0

      "It is better that ten guilty persons* go free, than that one innocent party suffer."

      *unless they are guilty pedophiles

    2. Re:While we're at it... by Anonymous Coward · · Score: 0

      Why is this post not modded 5?

    3. Re:While we're at it... by moeinvt · · Score: 1

      " and lets be real, the logic falters when you exercise that right against a military as heavily funded as in the US. "

      Your logic falters because you're thinking about warfare only in conventional military terms. Do some reading about guerilla warfare.

      Consider Afghanistan, where an insurgency armed with rifles and IEDs was able to fight the U.S. military to a decade-long standstill. What makes you think that the U.S. military would do any better fighting a similar insurgency on U.S. soil? A place with 10x the population and 12x the land area(lower 48)?

      Tanks, jet fighters, cruise missiles, artillery and nukes aren't particularly useful when you're fighting an army that's indistinguishable from the civilian population. If 1% of the U.S. people were willing to engage in armed insurrection and 20% were willing to provide logistical support, the government would be destroyed in a war lasting less than 2 years.

    4. Re:While we're at it... by Anonymous Coward · · Score: 0

      I'm so glad you mentioned that.

      The U.S. Constitution protects all U.S. citizens all over the world and any non-citizen in U.S. territory from Cruel or unusual punishment.

      If the Constitution does not apply in those cases, then I have to wonder how a U.S. Judge thinks he can block President Trump's travel ban especially since it only involves non-Americans in other countries.

  25. Only one way out... by tinkerton · · Score: 5, Funny

    My password is "sorry I've forgotten my password". They won't be able to claim I didn't tell em!

    1. Re:Only one way out... by Anonymous Coward · · Score: 0

      lol, i have a computer with "iforgot" because that is usually my 1st thought to: Password?
      Not sure I don't have a damnitiforgot also on an old one ;)

      Might want to try: Ialreadytoldyou for your 2nd computer if you are expecting trouble....

      If the password to your child porn stash is: mychildpornstash can one claim against self-incrimination?!?

    2. Re:Only one way out... by tinkerton · · Score: 1

      No my other machines have 'What is your password' , 'Fuckyouclowns' and 'Seeyouincourt'.

    3. Re:Only one way out... by Anonymous Coward · · Score: 0
  26. Re:Won't be disclosing anything that's new or unkn by Megol · · Score: 1

    No the logic is the same as a suspect ordered to unlock a safe/hidden room/car etc. having to do that. If the locked space then contains something illegal it is valid evidence however the suspect isn't being forced to say there are illegal stuff there.

    Or to make the comparison even easier: if police have a search warrant they have to be provided access to a location, failure to give that access is in itself a criminal act. Here the police have a search warrant for the disks and aren't given access to them.

    The only way the analogy fails is that it is possible to genuinely forget a password. Well a key can be dropped too but it is easier to do a search of the suspects belongings than searching their memories...

  27. Ressurect different HDD Image? by mykepredko · · Score: 1

    Rather than destroy the contents it would be better to have a separate code that will show photos and videos of granny's 100th birthday.

    "Sir, why did you use password protection for such a purpose?"

    "Why wouldn't I use it to protect my memories of my G'Ma?"

    1. Re:Ressurect different HDD Image? by Bob+the+Super+Hamste · · Score: 1

      If going that route why not put some things that would give you better plausible deniability like a volume filled with bank statements, credit card statements, tax documents, copies of important other documents like insurance policies, title/deed documents, mortgage documents, birth certificates, etc. as these would be things that one would reasonably like to protect. Hell I have VeraCrypt volumes for that stuff and it makes backing things up easy as I can just copy them to a USB flash drive and keep a copy in my safe at home, on the music drive in car, and in my desk drawer at work as the chances of all 3 getting destroyed at the same time is slim to none and if something does happens where all 3 backups are destroyed well I'm probably a shadow burned into the ground anyway so I won't care and no one in a 30 mile radius would care either as they would all be dead too.

      --
      Time to offend someone
  28. Weighing the options... by Anonymous Coward · · Score: 0

    Either be held in contempt for a while in a jail cell, or go to prison for 20+ years. They could try to decrypt but even then, as long as it's the computer's hard drive, they have to prove it was intentional. That's how it honest to god works. Besides, if he downloaded them via Tor, it was probably from a website the FBI runs (ironically, the largest suppliers of child porn). That means, he may be able to wait things out and they'll drop the case anyway like they've done before because they may have to provide how they caught him. I know of two cases that have been dropped so far. They'd rather push child porn than strengthen Tor encryption. It's sad.

  29. I have to reset passwords all the time by Maxo-Texas · · Score: 1

    If there was no way to reset the password, I'd be screwed.

    --
    She was like chocolate when she drank... semi-sweet at first and then increasingly bitter.
  30. I can relate by AaronW · · Score: 3, Insightful

    I had a couple of encrypted partitions on my Linux setup that I rarely accessed that became inaccessible after a Linux update. In my case I did remember the password but Linux would not accept it. I eventually reformatted it and restored the data from a backup.

    Any time you are arrested you should always choose to remain silent and request an attorney even if you are innocent.

    --
    This post is encrypted twice with ROT-13. Documenting or attempting to crack this encryption is illegal.
    1. Re: I can relate by Anonymous Coward · · Score: 0

      Lol...the article contains "greatest country on the face of the Earth"...lolololol

      Americans are funny. How are those search and seizure and Free Speech Zones working out for you ? Lololololol

  31. iPhone by Anonymous Coward · · Score: 0

    iPhone?

  32. The beauty of this is by Anonymous Coward · · Score: 0

    That if he holds out long enough. A couple years tops. Those drives if spinning disks will be unreadable. You can not store data on magnetic platters for very long if the platters are not powered and continually getting the read/write head to maintain the integrity of the data.

  33. Self Destruct by Anonymous Coward · · Score: 0

    Encryption software should support and additional "self destruct" password that when enter zero's the drive...

  34. Re:Won't be disclosing anything that's new or unkn by Anonymous Coward · · Score: 0

    I have a locked cabinet that I do not know where the key is.
    It police/courts demand I unlock the cabinet am I in contempt because I don't have or know where the physical key is?

  35. Sorry... by XSportSeeker · · Score: 1

    No one wants to side with a potential child pornographer, but law is definitely taking a turn for the worse if something like this is allowed to happen... they can't force the accused to produce proof of the crime against himself so he's charged with something else? This is basically abuse of power.

    According to the original article, they have a testimonial from a sister, they have been able to figure out keys from other devices and forensics traced his traffic to known child pornography websites, so he most likely is the real deal. But justice still presumes innocence until proven guilty, and the justification for being this heavy handed does not work... as if cryptography becoming a prevalent thing justifies courts being able to force people to produce proof against themselves.

    Did criminals denying charges made torture legal for them to fess up? Because it's basically the same thing here.

    This is, again, a failure on persecuting the guy. They didn't have enough circumstatial evidence of what he did, so the court is forcing him to produce it himself at the risk of being framed for other crimes.

    Now, most of us might not care if he suffers other penalties or not, as he most likely deserves all this, but we might not want a justice system that feels it's ok to do stuff like that.

    1. Re:Sorry... by PCM2 · · Score: 2

      I've skimmed the judgment. It's a convoluted case. He asserted his Fifth Amendment rights at some point, but failed to do so again at his contempt of court hearing. When he was held in contempt, he appealed and this time he again asserted his Fifth Amendment privilege. But the court that was hearing his appeal of the contempt of court ruling couldn't weigh its ruling based on the circumstances of his original, criminal case ... it could only rule on the civil contempt of court hearing, in which the Fifth Amendment was never made an issue ... anyway, something like that. They're giving him a helluva run-around but it doesn't sound like any legal overreach is actually happening here. It's just the usual prosecutor shenanigans. The defense made errors ... small though they may be ... and got tripped up in the paperwork.

      --
      Breakfast served all day!
  36. Wait a sec your HONOR by Anonymous Coward · · Score: 0

    My password is 'sorry_I_have_forgotten_my_decryption_password'

  37. Why alway pedophiles? by Anonymous Coward · · Score: 0

    Couldn't we highlight something like trade secret theft, or something less horrendous? I'd be able to consider this more rationally.

  38. 2FA - might loose my OnlyKey/Yubikey by Anonymous Coward · · Score: 0

    2FA - might loose a few of my OnlyKey/Yubikey devices. Plus I don't know most of my passwords. That is what a password manager is for.

    In theory, there is a right to a speedy trial in the USA. In theory, though I've heard of others refusing being held in jail for over a year.

    I suppose having a convenient, but hidden, location for the OnlyKey which won't show access or damage would be smart?

    Of course, not doing illegal things would be a good first step too.

    1. Re:2FA - might loose my OnlyKey/Yubikey by HiThere · · Score: 1

      You are making the presumption that he is guilty. This may or may not be true. He might be innocent and actually have forgotten his password.

      OTOH, just consider, if he gives them his password, they will be able to implant any evidence they choose onto his disks. Whoops! Forging dates isn't that hard.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  39. Civil Contempt is Not Forever by Artagel · · Score: 1

    Ok, there is a fundamental misunderstanding of how civil contempt works here. Rather than address 100 different posts let me summarize:

    The whole idea here is that he has been ordered to do something, and is refusing to do it. The judge may order him held to persuade him to follow the order. Persuasion can take a while on something like this. The judge has a duty to monitor the situation and eventually determine that the defendant is unpersuadable.
    Once it becomes clear that the person is unpersuadable, then proceedings for criminal contempt of court should start.

    At that point, there are full criminal law protections and procedures. The standard becomes proof beyond a reasonable doubt, and the prosecution has the burden of proof on every issue of contention: i.e. whether he really forgot.

    So, to address many posts: (1) it is not forever; (2) if he continues to there will eventually be a criminal trial of at least civil contempt. This is a form of obstruction of justice, so the penalty can be severe.

    1. Re:Civil Contempt is Not Forever by HiThere · · Score: 1

      What you have said is, in theory, correct. There are, however, cases that cast a lot of doubt on how that theory is actually applied in practice. Naturally we probably only notice outliers, but those outliers *do* exist, so there is a definite chance that the judge could take a large number of years to decide that he's "unpersuadable".

      Now the standard of "beyond a reasonable doubt" also has a large number of counter-examples, especially when the accused is being accused of something that most people consider horrendous. In fact, if the accusation is vile enough, many people won't even consider whether the evidence has any validity, or whether it could have been faked, or....well, much of any mitigating factor. He is being accused of obstruction of justice, which may or many not be true, and he will be punished extensively before there's ever a trial at which he, presumably, will have a fair defense. Many, however, never receive a fair defense, or even an only moderately poor defense. And even if he's found not guilty he will already have been punished extensively.

      I don't know what an ideal way of handling things would be, but don't fantasize that we in the US have something even coming close to something fair to those who are poor or unpopular.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  40. LG G4 user here: only 1 non upgrade reboot by Anonymous Coward · · Score: 0

    Had it for close to 2 years now too.

  41. Somebody enlighten me by Anonymous Coward · · Score: 0

    I thought I'd read that if you possess something physical like a key or your own fingerprint that can be used for law enforcement to gain access to your data that a court can force you to give that up to law enforcement but if it's knowledge, like a password, then you can't be forced to give up information that would incriminate you due to your 5th admendment rights. Is that not true?

    1. Re: Somebody enlighten me by Anonymous Coward · · Score: 0

      Recently the court has allowed a way around that. If the agency in question can reasonably prove that they know what is in the encrypted payload. This was established in a case where someone had confessed to a crime and in an interview stated the proof was encrypted but later refused to decrypt it. The court was allowed to compel.

  42. Re: Happens quite often... by slashrio · · Score: 3, Interesting

    Like the sticker note with the password on the bottom of the laptop.
    "I don't know the pw, it's on the bottom of the laptop."
    Police: "..." Unless of course they filmed the whole arrest and house visit.

    And about the 'forgone conclusion' and the fact they aren't simply starting the trial based on the evidence that led to this conclusion:
    I think it's quite possible that law enforcement told the judges, confidentially, that they already have hacked the disks using a secret back-door or other procedure, but just can't (won't) make that public. In that case a trial wouldn't work either.

    And where is the proof that the files are actually on his HD and that he hasn't deleted them already?
    He could admit downloading them (out of curiosity), but erasing them immediately upon discovering their true nature.
    Which leaves the testimony of his sister to deal with, who must have been really pissed off by the pictures she's seen on his phone--maybe her own child was involved, that she witnessed against her own brother?

    --
    "Trump!!", the new Godwin.
  43. Re: In jail forever by slashrio · · Score: 1

    In earlier times, the English king could throw anybody in 'the Tower' if he didn't like him.
    I thought it was exactly to prevent this that the bill of rights was made, and now the judges are the new king?
    What if he really forgot the password?

    --
    "Trump!!", the new Godwin.
  44. Re: To jail you go by slashrio · · Score: 1

    Definitely if one of them was underage and you not.

    --
    "Trump!!", the new Godwin.
  45. What if I told you... by Anonymous Coward · · Score: 0

    That there was an encryption set that could hash N sets of files and decrypt based on passphase entered?

    1. Re:What if I told you... by Anonymous Coward · · Score: 0

      That is true. There are so many tools which can provide plausible deniability. Lets say you build your own encryption software which can hide an encrypted volume. And then it asks you for a series (lets say 20) different passwords which can decrypt specific folders (directories), you can provide one or two passwords which can decrypt two sets of directories. But all the other 18 passwords were kept secret and 18 main directories remain hidden and it is still encrypted.

      captcha: permute

  46. Re: Solitary confinement... by slashrio · · Score: 1

    Where did you get that?
    And maybe it's better for him to be solitarily confined in jail, then to be a CP offender in a shared prison cell.
    I guess his best chance is to sit in jail until the normal term for CP is over, then give his password, be trialled and set free because he spent already his term in jail.

    --
    "Trump!!", the new Godwin.
  47. I have no clear recollection of that information by Anonymous Coward · · Score: 0

    "I have no clear recollection of that information."
    "I don't answer questions."

    "Where's the beef?"

  48. Jail is too good by Anonymous Coward · · Score: 0

    He could be in Jail for a long time because of this ruling.

    Jail is too good for pedos like this. Plus it does nothing to refresh their memory.

    If they don't want to give their up passwords the easy way ... we should be using waterboarding or worse. Lets see how long it will take for this scum to "remember!"

    But the real problem here is the fact that courts just exist to keep people out of prison. Some crimes are so serious that we need to take lawyers right out of the equation and let LEO deal without having their hands tied up with legal niceties. No smoke without fire.

    1. Re: Jail is too good by Anonymous Coward · · Score: 0

      Courts don't exist to keep people out or put people in prison, they exist to determine guilt or innocence of a crime. No crime is too heinous as to not deserve a trial, once we determine that there is a select group of charges where people are automatically found guilty without public presentation of the evidence it stops being a prison and becomes a gulag. This country was founded to prevent things like that knowing full well that many people ARE monsters, at least this way the monsters without power are tried publically and fairly and the monsters with power can't abuse the system in order to smite those they wish to be gone.

    2. Re:Jail is too good by Anonymous Coward · · Score: 0

      Hope you never get incorrectly accused of something... Or maybe that would be good for you to change your viewpoint...

      Until someone is proven to be guilty they should not face a punishment, even if that would result in a few guilty people to go free...

      If someone on the other hand is found guilty without any type of doubt, like a video of him in the act, of some heinous act that caused physical harm to someone else i would be more than happy to see them sent off to some work camp for the rest of their lives. (imagine something similar to the movie "Escape from New York")

    3. Re:Jail is too good by Ihlosi · · Score: 1
      But the real problem here is the fact that courts just exist to keep people out of prison.

      Laws just exist to keep people of of prison. If there were no laws, the executive (in this case: the most violent group) could just lock up everybody else.

    4. Re:Jail is too good by Anonymous Coward · · Score: 0

      Which is morally worse: destroying someone's life by invading their home, rifling through their stuff, costing them their freedom, job, reputation, dignity?

      Or looking at some pictures?

    5. Re: Jail is too good by Anonymous Coward · · Score: 0

      ... You want to torture a person who may be innocent, in order to find out if they are innocent?

      Welcome to the Spanish Inquisition. You are next.

  49. Re: Happens quite often... by Mashiki · · Score: 3, Insightful

    Possibly. That's the real question here, while I've read the case info provided in the article there's a bunch of things that are unclear until I get a chance to read the initial case. But, local police forces which is what this case is doesn't usually have the resources to backdoor things like this unless they're commonly known exploits. And if I remember the cases correctly, if they were seized as part of evidence in the original warrant and they were able to get the information off the drives without his co-operation it wouldn't matter anyway. Since it would have already proven that he was in possession of CP. So that doesn't really matter, in the rare cases where something like this happens they can seal part of the court case to protect the disclosure of things like that which would lead to the compromising of on-going investigations.

    The real thing is is what you pointed out though, where the proof. There is none really. The prosecution states they have "known hashes" but that doesn't mean much beyond that. It's more likely that the sister saw actual CP, and that's it. That in itself leads weight to it, but it still doesn't mean too much without the actual evidence.

    I wouldn't be surprised if this keeps moving through the court system, or their lawyer simply tells them to take the contempt charge which he'll likely serve on weekends and get on with his life. The contempt charge itself could be an entirely new ball of wax especially if it's contested which wouldn't surprise me. The lawyer(s) in question could make their career defining case off of it. Since then the court will have to prove that he knowingly engaged in contempt.

    --
    Om, nomnomnom...
  50. Re: Solitary confinement... by radarskiy · · Score: 1

    "Where did you get that?"

    By reading the actual court ruling, along with some publicly available analysis by actual lawyers.. The Regitser has a copy of the ruling if you do not have a PACER account: https://regmedia.co.uk/2017/03...

  51. Destruction of Evidence by Anonymous Coward · · Score: 0

    So when a bank steals your retirement, the bankers should get off scott free because the evidence is encrypted? Destruction of evidence is a crime. This is exactly the intent of encryption.

  52. You're not hiding it well enough. by Anonymous Coward · · Score: 0

    Hidden volume on seperate partition and flag it as swap and never mount it. Or make it another file type and that oops now it's corrupted. The possibilities are endless just like the court's power to hold you indefinitely.

  53. Law is you don't have to provide *testimony* by raymorris · · Score: 1

    > I thought that it was already established by case law that you did not have to say anything to aid the prosecution in any way, that your right to remain silent was absolute in a criminal case?

    The law is you don't have to *testify* against yourself. Testimony is spoken evidence.

    Physical evidence can be compelled because it's not spoken.

    Words which are not evidence can be compelled - for example your name is not evidence, so a defendant can be compelled to give their name. Knowing the name may certainly aid the investigation, but your name is not itself evidence of any crime. Because it's not evidence, it's not testimony. The fifth amendment refers to testimony.

    So yeah you can be compelled to provide information which is not itself evidence, but does aid the investigation.

    One recent case has been cited in even more recent cases regarding passwords. That case ruled that if it's not proven that the drive is yours, stating "the encryption password is foobar" would be effectively testifying that it *is* your drive. That would be protected by the fifth. However, if it's not disputed that the device belongs to the defendant, the password is not evidence and is therefore not protected by the fifth amendment, the court ruled.

    As someone else posted here, if the password were "I admit I am guilty of ...", then the password itself would be testimony and therefore it seems it would be protected.

    1. Re:Law is you don't have to provide *testimony* by jaa101 · · Score: 1

      As someone else posted here, if the password were "I admit I am guilty of ...", then the password itself would be testimony and therefore it seems it would be protected.

      No. There's a difference between use and mention of a word or sentence. Saying "My password is 'I am guilty'" is not the same as saying "I am guilty." The first is mention, the second is use. Or put another way, the quotation marks matter.

    2. Re:Law is you don't have to provide *testimony* by ebvwfbw · · Score: 1

      Password is "this is not the porn you are looking for."

  54. Can you just tell them wrong passwords? by ackkamoto · · Score: 0

    Ok actual serious question, can you just provide them with random passwords that at the time you "think" are correct. The burden on the judge is that you provided a password, it doesn't have to actually work.

  55. A different crime if before subpoena by raymorris · · Score: 1

    If evidence is destroyed *after* it's been subpoenaed, that may be contempt of court, but more importantly it's tampering with evidence, if done with the expectation that a prosecution is likely.

    Tampering with evidence generally has a lesser sentence than child porn, so one might argue it makes sense to take a tampering conviction if it prevents a CP conviction.

    1. Re: A different crime if before subpoena by EndlessNameless · · Score: 1

      Tampering with evidence generally has a lesser sentence

      Maybe, except for the possibility of sanctions due to spoliation.

      The court can instruct the jury to infer that there is unfavorable evidence when someone has withheld or destroyed it.

      Not all states allow sanctions due to spoliation, but apparently PA does.

      If the contempt charge doesn't convince this guy to turn over his password, he could very well face a trial with that sanction/inference hanging over his head. It does not bode well when the judge finds him in contempt rather than simply accepting that he may have forgotten his password.

      The only question is whether the judge believes the circumstances of this case justify those sanctions. And of course, the appeals court weighs in if the guy is convicted and challenges the decision.

      --

      ---
      According to the latest ruleset, this post should be modded as Vorpal Flamebait +5.
  56. Quarters on a table... by Anonymous Coward · · Score: 0

    I always use this argument. What if I lay a stack of quarters on my table... then next to that another stack but with a different count... And of course this goes on lengthwise across a whole table.

    I could encode information in binary or another base number system and set this data out on the table. I'd need no computer to view it or change it. If it was OTP I could even do the math for XOR in my head.

    So if you get a warrant to come search my house. I *agree* that you get the right to see my stacks of quarters, collect them, or even swipe them all off the table into a bag.

    I do NOT AGREE that in any way shape or form, you can start laying penalties on me for not explaining to you, my methods for stacking quarters.

    The point is that *anything* could be used to hide data, not just computers. You are essentially asking me to explain inner workings of my mind which I do not believe I'm obliged to do. Go fuck yourself.

  57. People by Anonymous Coward · · Score: 0

    Who encroach upon constitutional rights with the argument of law enforcement should be mudered in their sleep.

  58. And this is going to be just awesome when..... by mark-t · · Score: 1

    .... wetware becomes a thing, and people start tying their passwords to their mental and emotional states, making it utterly impossible for someone to use that password to unlock a system unless they genuinely wanted to and not under any kind of duress to do so, whether by external coercion or drugs.

    And when failing to surrender such passwords to the court when requested is contempt of court, you can then be held in contempt of court only for what you are thinking.

    Yup, the 21st century's gonna be just great. Somebody call over the guy selling popcorn.

    1. Re:And this is going to be just awesome when..... by Anonymous Coward · · Score: 0

      Let me guess: You read a lot of science fiction, and don't have many friends.

    2. Re:And this is going to be just awesome when..... by OrangeTide · · Score: 1

      Man... who doesn't read a lot of science fiction? There are lots of opportunities to discuss SF with like minded people and make friends.

      Anyways, I think the courts will have to adapt with technology. They are usually pretty slow to adapt, so we'll see several years where folks are being treated unfairly before there is a course correction.

      --
      “Common sense is not so common.” — Voltaire
  59. In an ideal world (for the cops) yes by dbIII · · Score: 1

    In an ideal world (for the cops) yes - but resources and not always what you expect from television. The old Bruce Sterling non-fiction text "The Hacker Crackdown" (free download) is still apt after all these years. Back then the cops wanted the budget to buy an Amiga, now it's the budget for a computer forensic lab up to the quality of a guy running a hard disk recovery business out of his garage.

    1. Re:In an ideal world (for the cops) yes by dougmc · · Score: 1

      Even a lab "up to the quality of a guy running a hard disk recovery business out of his garage" is going to work on images of the disks rather than the disks themselves -- anything less will get all their cases thrown out of court by the defense ("how can you guarantee that you didn't alter the data yourselves?") *and* will get caught by "oh, you entered the wrong password? erase everything!" code. Maybe in 1992, but in 2017 ... that's law enforcement computer forensics 101, day 1. They absolutely will not be hooking up his computer and drives and working on that (unless they need to do so to figure something out, and even then -- it'll have copies of his drives rather than the originals.)

      If a police department can't even reach that level ... then they're probably either avoiding such cases entirely, or deferring them to some other, larger and better-equipped organization.

      Beyond that ... it becomes an issue of how badly they want the data. The local police department probably can't do too much, but the NSA/CIA/etc. can do a *lot* if they are properly motivated.

      (That said, this sounds like a case where they won't be going to any extraordinary technological lengths to get at the data. They certainly do seem to have some friends in the courts, however.)

      Now, back to "self-destructing crypto" ... if half the encryption key is on some remote server in Russia that self-destructs if not accessed at least every 30 days, then maybe. (That said ... people would lose their data often under such an arrangement.) If such services popped up and were being actively used, I imagine that the NSA and friends would be working on countermeasures (like compromising that box and looking for other vulnerabilities in the arrangement or simply installing keyloggers where needed), but that would probably foil the local police department's attempts to get the keys.

      Of course, simply refusing to tell them the password should also foil them, legally and technically. This ruling is bad, bad, bad ... but I guess fighting child porn is more important than the right to not self-incriminate to this court?

    2. Re:In an ideal world (for the cops) yes by dbIII · · Score: 1

      then they're probably either avoiding such cases entirely, or deferring them to some other, larger and better-equipped organization

      Yes, but there's also cutting corners or outsourcing them to the guy with a disk copying business.

      but the NSA/CIA/etc. can do a *lot* if they are properly motivated

      Once again "The Hacker Crackdown" applies - if things can be skewed to make something look like a headline grabbing crime that could lead to promotion there is motivation but not in a direction to the benefit of anyone other than the individuals putting together a high profile case. Justice often loses.

  60. There are no quotation marks in the password by raymorris · · Score: 1

    > > then *the password itself* would be testimony and therefore it seems it would be protected.

    > No. "My password is 'I am guilty'" is not the same as saying "I am guilty." The first is mention, the second is use. Or put another way, the quotation marks matter.

    You may notice there are no quotation marks in the password itself. Or put another way, quotation marks matter - you can't just insert them into my sentence without changing its meaning a bit.

    *The password itself* is evidence that at the time they chose that password, the declarant either believed they were in fact guilty of possessing child porn or at very least, when creating the encrypted volume they had child porn in mind. So it's evidence in words, aka testimony. It would be admissable under Uniform Rule 63(1), Prior Inconsistent Statements. See also California v. Green, 399 U.S. 149 (1970).

    On the other hand, adding quotation marks to get:
    My password is "I'm guilty of child porn"

    Is essentially the same as these alternative statements:
    When I created the encrypted drive, I had child porn in mind.
    I'm the type of sicko who chooses "I'm guilty of child porn" as his password.

    Both of the above statements are evidence of the declarant's intent and state of mind around the time of the act. As evidence, spoken, they are testimonial.

    1. Re:There are no quotation marks in the password by suutar · · Score: 1

      The latter may be indicative of a state of mind at the time of creating the password, but it is not (to me) indicative of actual intent to commit a crime. One of my past passwords was "iAmCh33seburger"; do you really think I think I'm a sandwich?

  61. Legit don't know one pass by Anonymous Coward · · Score: 0

    I made a Truecrypt container of chat logs and important emails of interest years ago on a laptop.
    Never having needed in to it, I've long since forgotten whatever retarded password I put in to it.
    I've tried brute-forcing it based on password schemes I used to and still use, no luck.

    I guess now that makes me a pedo terrorist that BLEW up a fucking planet!
    Star Wars - we'll be right back after these messages!

  62. Well.. by Anonymous Coward · · Score: 0

    "The password is written on a pink post-it note under my keyboard. Oh, it's not there? Thanks a lot for encrypting my stuff forever!"

  63. Just my opinion by Anonymous Coward · · Score: 0

    I don't throw away/destroy my old drives, which are encrypted, but since I don't use them anymore, I don't remember the passwords I set on them.
    So ... if cops seize them and I don't give them the passwords, which I honestly don't know anymore, I go to jail for life?
    What if those drives are rewritten with random junk? They can say it's encrypted, so ... jail for me again?

    My opinion is that if anyone does something bad, there is always enough evidence against him to convict him, so they don't need his testimony/passwords anyway.
    Also, I find throwing people in jail because they masturbate to weird stuff absurd. It's like throwing people in jail because they use drugs ... Sure, both is a problem, but it's not being solved by jailing the end-user.

  64. Modern HW crypto by DrYak · · Score: 1

    No, the drives will have been imaged through a hardware device that blocks all attempts to write, and their work will be on their own computers running their forsensic software against the images of his drives, with his original drives safely in the evidence lockup.
    And if criminals start using drives with custom firmware to foil this

    This is not a custom firmware.
    There is a thing on ATA protocols dating back when it didn't even have the initial "P" in front to contrast with SATA yet :
    HW access to the harddrive can be password protected.
    No password ? You can't even access the blocks on the device, it refuses to read them.
    I think I remember that the first X-Box did use something similar to try to protect the content of their disk.

    Probably most modern SSD drive should be able to do it.

    And if criminals start using drives with custom firmware to foil this (they've already read the first GB sequentially? return gibberish and erase everything!), the cops will then be removing the control boards and subsituting their own before they do the imaging.

    A long long time ago, it used to be possible to swap the control boards of spinning rust media and still get something remotely meaningful if you squint enough at it.
    (The only thing you'd be losing by doing that, would be the mapping from the physical sectors on the actual disk platter to the logical block addresses (LBA) as seen by the computer on SATA bus as handled by the SMART running on the controller to remap old defective sectors).

    With modern SSD, you'd be losing the layer of encryption that the controller board does on the fly when writing to the flash media (it's a standard protection feature of most controllers, with the exception of maybe a few dead-cheap no-names that you wouldn't be using for these kind of missions anyway), in addition to all the mapping (done by the flash-translation-layer, which is much more complicated than SMART because it handles all the wear levelling).
    Bascially a SSD, without the controller board that was used to write the data is just plain gibberish.

    And that's *another* layer of gibbersih in addition to the whole-drive encryption done by the OS.

    --
    "Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
    1. Re:Modern HW crypto by dougmc · · Score: 1

      I'm aware of ATA drive locking and their on-drive encryption, but that's not really what I was referring to.

      I was thinking more of organized crime and enemy governments and other well funded and well-planned enterprises -- it would not surprise me if they had custom drive firmware made that was designed to foil the drive being imaged for forensics. I don't know if this is actually being done yet (though I suspect it is), but if it was, law enforcement (well, the better-equipped offices, and especially things like the NSA) would adapt.

      And yes, you're right, such countermeasures would be a good deal harder to deal with on SSDs than spinning hard drives. Perhaps even approaching impossible without a lot of assistance from the drive manufacturer themselves.

      And no, I wouldn't expect any of this to be done by a guy who's simply got illegal porn on his computer. Really, just keeping it on an encrypted drive probably puts him ahead of most.

  65. Plausible deniability by Crookdotter · · Score: 1

    Truecrypt (before it went dead) has a plausible deniability option where you had two passwords. One would open your files, the other would open a different, dummy filesystem. As long as you used it recently (to show it was the real one, not a dormant clever ruse) no one could tell it wasn't decrypting the real system. Where are all the plausible deniability options in encrpytion tools these days?

  66. Self-incriminating password. by SharpFang · · Score: 1

    I wonder what about the self-incrimination rule if the text of the password itself is incriminating.

    Imagine I'm being charged with possession of child porn, but my password is "TheCorpseIsBuriedBehindTheGarage".

    Revealing it would be direct self-incrimination, regardless of the drive content, wouldn't it?

    --
    45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
    1. Re:Self-incriminating password. by SuiteSisterMary · · Score: 1

      I believe the legal counter to this which is slowly starting to emerge is 'We're not ordering you to divulge your password. We're ordering you to decrypt the drive. We quite specifically don't want, or need, your password, nor do we care if the drive is encrypted with a passphrase, biometrics, physical token, whatever. We're just ordering you to decrypt it.'

      Much like your 'papers' are immune to unreasonable search and seizure, but are subject to reasonable search and seizure, i.e. with a duly sworn out warrant and all that, so are your digital papers. I think this is the correct result.

      I believe that, if the cops find a file in a locked file cabinet, said file being labelled 'Plans to murder my wife' and full of, well, plans to murder your wife, you don't get to have them declared inadmissible under the fifth; you get to refuse to answer questions like 'did you create these plans' and 'did you carry out these plans.' Seems to me that a directory full of documents, said directory being labelled 'plans to kill my wife' would be treated the same.

      --
      Vintage computer games and RPG books available. Email me if you're interested.
  67. "ruling of contempt against a chap" by EnOne · · Score: 1

    apparently this court ruling happened during the roaring 20's

    --
    Calvin:Do you believe in the devil? Hobbes:I'm not sure man needs the help.
  68. You forgot a word by Anonymous Coward · · Score: 0

    I believe it's "beyond" a reasonable doubt. The criteria is not just "a reasonable doubt," but beyond it. Such that there is no reasonable doubt the person could be innocent. Hard to convince a jury of this without evidence.

    This is for a criminal case. Civil cases are (I forget the exact terminology) "more likely than not."

    1. Re: You forgot a word by Anonymous Coward · · Score: 0

      Preponderance of the evidence

  69. Re: To jail you go by green1 · · Score: 1

    For images it doesn't matter what his age was, only hers.
    For various "activities" the ages come in to play.

  70. 5th Amendment by Anonymous Coward · · Score: 0

    If he provided a password, the prosecution would say he exercised control over it which proves he was the owner of the data.

    In other words, they wouldn't just use the password to gain access, but would use the fact that he provided the password as evidence against him. he can't be compelled to do that, but as usual, the courts are violating his 4th, 5th and 6th Amendment rights.

  71. If it were at issue (insanity or drugs?) by raymorris · · Score: 1

    > One of my past passwords was "iAmCh33seburger"; do you really think I think I'm a sandwich?

    There is strong reason to believe you don't think you're a cheeseburger, despite the (weak) evidence that you have an interest in cheeseburgers. On the other hand, if through some strange set of circumstances your belief in your cheeseburgerness WERE at issue in a trial (something to do with insanity perhaps) the fact that you wrote "I am a cheeseburger" prior to the trial would be very weak evidence that you thought that. Not convincing evidence, probably, since also approximately nobody thinks they are a cheeseburger, but evidence nonetheless.

    The point here is that the fifth doesn't say "compelled in any criminal case to be a BELIEVABLE witness against himself"; it says "a witness against himself". Whether or not the testimony is credible doesn't limit the fifth amendment.

  72. How does the court know by Anonymous Coward · · Score: 0

    How does the court know whether or not he remembers? Sending a man to jail because one is merely "inclined" to doubt his word is hardly consistent with the basic tenets of justice. I agree his claim is improbable. But is that now the test for incarceration? Balance of probabilities?

    1. Re:How does the court know by Anonymous Coward · · Score: 0

      > But is that now the test for incarceration? Balance of probabilities?

      For juries, that has pretty much always been the case.

  73. Re: To jail you go by Anonymous Coward · · Score: 0

    The irony, of course, being that in order to determine your guilt, the authorities have to look at the same images you're going to jail for looking at.

  74. Keys to own cell by shentino · · Score: 1

    Add to this the convenient loophole that the defendant "has the keys to his own cell" and thusly that protections of due process don't apply.

  75. This is nothing new: Contempt of Court by DarthVain · · Score: 1

    While it involves encryption and passwords, the basic premise is nothing new. There needs to be perhaps a look at the powers of the court in the US in regards to the whole "Contempt of Court" charge.

    Many years ago there was a man who was getting divorced from his wife. During the proceedings his assets were being split up and half or whatever value was being given to the wife. The Wife accused that he husband had secret offshore bank accounts that contained millions. The Husband said he did not or perhaps even pled the 5th, or simply refused to divulge the information (I forget which). The judge found him in "Contempt of Court" and sentenced him to jail until such time as he released the information on his offshore bank accounts. He was in jail for many *years*, perhaps is still in jail.

    There are a couple things wrong with that. First is a sentence with no end, which is a problem. Second is being forced or "compelled" by court to release information he may not have. Considering the guy was or is in jail for years, either he doesn't have the information to release (or he does and it is a ton of money, and/or he really hates his wife, or possibly by doing so perhaps would convict himself of another crime if the money was illegal in some way, hence the 5th usage perhaps).

    At any rate the whole encryption/password thing is the technological component, but the basic idea predates that by quite a bit.

  76. There are a few passwords I have forgotten by Anonymous Coward · · Score: 0

    I have no clue what the PIN on my credit card is. I forgot it, because most places use tap. I have a NAS with a password protected partition that I can't remember the password for.

  77. Re: Happens quite often... by Agripa · · Score: 1

    Like the sticker note with the password on the bottom of the laptop.
    "I don't know the pw, it's on the bottom of the laptop."
    Police: "..." Unless of course they filmed the whole arrest and house visit.

    The password is encoded using the serial numbers of the bills in the envelope which are in ascending order of value. What do you mean the $100s are missing?

  78. Re: Happens quite often... by slashrio · · Score: 1

    Hehehe, genious! :)

    --
    "Trump!!", the new Godwin.