Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.



1000 posts

Ultimate Geek


Topic # 114320 15-Feb-2013 16:32 Send private message

I am interested in hearing from someone involved in criminal 'cyber' law or any related fields and/or computer forensics professionals.

I also expect a few IANAL posts too ;-)

I was wondering about encryption the other day and am interested to know how New Zealand law would or has handled cases in which alleged computer criminals have encrypted their hard drives with TrueCrypt or something similar.

Can (or has) a judge compel a person provide the keys required to decrypt the contents of the hard drive assuming it was evidence or potentially evidence?

How well would a "lol, I forgot da password" defence go down with a court? Is there really any way to punish someone (e.g. contempt of court) if it is impossible to tell whether they are lying or not?

As with many crimes of an electronic nature, if the evidence is on the encrypted drive in a computer and you have 'forgotten' the password would the case have to be dropped?

I remember reading about this case in which the police went to incredible lengths to secure an offender's computer while it was on and decrypted so they were able to analyse its contents. Would this mean a judge could not have ordered the drive's decryption or simply that the police wanted an easier time gathering evidence?

My interest is based on the rising number of crimes being committed online, from hacking to child pornography to copyright infringement, and the technical inability to crack such encryption systems when administered correctly.

TIA for any insight :)




Workstation: Intel DH67CL ~ i5-2500 ~ 4GB Corsair RAM (x2) ~ Intel X25-M 80GB SSD

Laptop: Dell Inspiron 1564 ~ i5-520M ~ 4.00GB RAM ~ 500GB SATA HDD ~ Win7 Home Premium x64

Common misconceptions.

View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2 | 3Next
395 posts

Ultimate Geek

Subscriber

  Reply # 763291 15-Feb-2013 23:40 Send private message

A judge has an awful lot of power! If they issue a warrant ordering you to comply and you refuse or fail to comply - then you will be held in contempt. At that point, they have significant leeway to deal with you for failing to comply with the warrant. They are also not best known for their sense of humour!

In the circumstance that you refer to, whilst the case that might depend on the content of an encrypted disk might fail due to lack of evidence, that may not actually help you, because the consequences of the failure to comply with the warrant will probably be worse than the original issue.

Cheers Mike

2155 posts

Uber Geek


  Reply # 763304 16-Feb-2013 00:43 Send private message

As part of the Search and Surveillance Bill you are required to give up your encryption keys (or else!)..
SO yeah, great, thanks National for slipping that one through..

See http://techliberty.org.nz/jailing-people-for-remaining-silent/


23 posts

Geek


  Reply # 765223 18-Feb-2013 15:58 Send private message

kyhwana2 is correct.

See section 130 of the Search and Surveillance Act. 



57 posts

Master Geek


  Reply # 765607 19-Feb-2013 10:08 Send private message

Don't we have like a fifth amendment equivalent here in NZ?

1298 posts

Uber Geek

Subscriber

  Reply # 765619 19-Feb-2013 10:28 Send private message

kyhwana2: As part of the Search and Surveillance Bill you are required to give up your encryption keys (or else!)..
SO yeah, great, thanks National for slipping that one through..

See http://techliberty.org.nz/jailing-people-for-remaining-silent/



Very true.

Thats why truecrypt has the "Hidden Volume" feature:

As far as I know its not possible for anyone to determine if the encrypt volume has a hidden volume or not.

It may happen that you are forced by somebody to reveal the password to an encrypted volume. There are many situations where you cannot refuse to reveal the password (for example, due to extortion). Using a so-called hidden volume allows you to solve such situations without revealing the password to your volume.


The principle is that a TrueCrypt volume is created within another TrueCrypt volume (within the free space on the volume). Even when the outer volume is mounted, it should be impossible to prove whether there is a hidden volume within it or not*, because free space on any TrueCrypt volume is always filled with random data when the volume is created** and no part of the (dismounted) hidden volume can be distinguished from random data. Note that TrueCrypt does not modify the file system (information about free space, etc.) within the outer volume in any way.


http://www.truecrypt.org/docs/

So you give them the password to the normal volume which contains stuff like your CV, etc..




Offense can never be given, only taken ...

571 posts

Ultimate Geek


  Reply # 765639 19-Feb-2013 10:58 Send private message

russelo: Don't we have like a fifth amendment equivalent here in NZ?


The US one hasn't stopped people being compelled to give up their passwords.

622 posts

Ultimate Geek

Subscriber

  Reply # 765649 19-Feb-2013 11:18 Send private message

I have a few that I have genuinely forgotten the passwords to (not that there was anything bad on there, just email backups). What happens then, I'm held in contempt for something that I have no ability to comply with?

Sadly, there is no way to prove that I don't remember so I have to wait until the Judge changes his mind?


2100 posts

Uber Geek

Trusted
Subscriber

  Reply # 765652 19-Feb-2013 11:29 Send private message

dolsen: I have a few that I have genuinely forgotten the passwords to (not that there was anything bad on there, just email backups). What happens then, I'm held in contempt for something that I have no ability to comply with?

Sadly, there is no way to prove that I don't remember so I have to wait until the Judge changes his mind?



Correct; if you've genuinely forgotten, you're stuffed: otherwise 'I forget' would just get everyone off scott free.




iPad + iPhone 4S + 2degrees 3G data 4tw!

These comments are my own and do not represent the opinions of 2degrees.

167 posts

Master Geek

Trusted
TUANZ

  Reply # 765655 19-Feb-2013 11:31 Send private message

We lost the "right to remain silent" as such many years ago, following the 911 attacks in the US.

At the time the new cyber-terrorism bill (as it was called) included a section on encryption that was passed into law without any problem whatsoever (only terrorists keep secrets, you see).

Judge David Harvey told me about it in 2003: No right to silence for computer users.

Basically it works like this:

Police officer (or similar) serves you with a warrant to search your PC.
Finds encrypted file in a drive somewhere.
Demands you decrypt it.
You say "beats me, I have no idea what that is".
Officer says "you must now accompany me to the station where you will be detained..." etc.

Great way to upset your buddies and get them locked up - install some encrypted file while they're not looking then dob them in. Hilarity ensues!

Compare this with a police officer serving a warrant in the real world.

Officer serves you with a warrant to search your house.
Officer searches your house, fails to find a secret room/locked cupboard/obvious collection of guns.
Officer leaves and you go on about your business.

There is no requirement that you incriminate yourself UNLESS you have a computer.

how ridiculous.



472 posts

Ultimate Geek


  Reply # 765670 19-Feb-2013 11:42 Send private message

Judge David Harvey told me about it in 2003: No right to silence for computer users.


I wish Judge Harvey was a member here on Geekzone, the guy is very smart and really sets the stage for how the legal system in NZ can embrace and understand technology.  If you ever have a chance, read his papers.

23 posts

Geek


  Reply # 765686 19-Feb-2013 11:59 Send private message

Just to play devil's advocate here for a bit -

Putting a piece of evidence into a safe will not generally put it beyond the reach of a search warrant.

Why should an encrypted disc be any different?

2100 posts

Uber Geek

Trusted
Subscriber

  Reply # 765693 19-Feb-2013 12:07 Send private message

muso: Just to play devil's advocate here for a bit -

Putting a piece of evidence into a safe will not generally put it beyond the reach of a search warrant.

Why should an encrypted disc be any different?


Because generally speaking in a democratic society, you cannot be forced to incriminate yourself. If you refuse to open a safe because it would incriminate you, the police can probably take to it with an oxy torch. If you refuse to unlock an encrypted volume [and it was done right] then there is in theory no chance it could be unlocked in less than the age of the universe.

In other words your cooperation is not needed to gain access to safe. It is needed to gain access to an encrypted file.




iPad + iPhone 4S + 2degrees 3G data 4tw!

These comments are my own and do not represent the opinions of 2degrees.

571 posts

Ultimate Geek


  Reply # 765695 19-Feb-2013 12:10 Send private message

muso: Just to play devil's advocate here for a bit -

Putting a piece of evidence into a safe will not generally put it beyond the reach of a search warrant.

Why should an encrypted disc be any different?


Beacause if you lose, or refuse to hand over, the key/combo to a safe, they can (if they really want to) brute-force it - lock picks, drills, dynamite, etc.
Brute-forcing decent encryption with current tech can take hundreds of years or longer, depending on how paranoid the encryptor is.

571 posts

Ultimate Geek


  Reply # 765696 19-Feb-2013 12:12 Send private message

SaltyNZ:

In other words your cooperation is not needed to gain access to safe. It is needed to gain access to an encrypted file.


OTOH - this: http://xkcd.com/538/ 

23 posts

Geek


  Reply # 765698 19-Feb-2013 12:19 Send private message

I'll rephrase: if you accept that the police are entitled to seize a safe (and the key, if its there, or if not, break the safe open), why shouldn't they be able to compel you to open an encrypted drive?

 1 | 2 | 3Next
View this topic in a long page with up to 500 replies per page Create new topic



Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when new jobs are posted to our jobs board:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:




News »

Trending now »
Hot discussions in our forums right now:

Fecked up religious people strike again :-(
Created by Mark, last reply by freitasm on 25-May-2013 08:44 (85 replies)
Pages... 4 5 6


Cannabis is illegal yet we have really strong 'legal highs' ?
Created by qwerty7, last reply by freitasm on 23-May-2013 23:20 (74 replies)
Pages... 3 4 5


A new project coming to Geekzone
Created by freitasm, last reply by l43a2 on 24-May-2013 23:02 (342 replies)
Pages... 21 22 23


HTC One (2013) owners' discussion
Created by Dingbatt, last reply by cathy88 on 26-May-2013 14:59 (1574 replies)
Pages... 103 104 105


Xbox One
Created by DjShadow, last reply by nathan on 26-May-2013 10:56 (78 replies)
Pages... 4 5 6


Monolithic Cement Sheet cladding mid 80s house - "leaky home" or not?
Created by joker97, last reply by mattwnz on 24-May-2013 23:46 (15 replies)

Orcon, Is this for real or a scam??
Created by old3eyes, last reply by DarthKermit on 22-May-2013 19:12 (29 replies)
Pages... 2


Entire house HTPC concept
Created by InfiniteLoop, last reply by darthmeow on 24-May-2013 12:19 (26 replies)
Pages... 2



Geekzone Jobs »
Most recent NZ jobs in technology:

Systems Consultant Project Manager
Posted 26-May-2013 14:28

Reporting & Payroll Manager
Posted 26-May-2013 13:28

Developer of interactive experiences
Posted 25-May-2013 21:28

Ambitious Project Coordinator
Posted 25-May-2013 19:28

Ambitious Project Coordinator
Posted 25-May-2013 19:28

Exceptional Senior Project Manager
Posted 25-May-2013 19:28

Multitalented Business Analyst
Posted 25-May-2013 18:28


Geekzone Live »
Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.