Hacker News new | ask | show | jobs
by biot 3596 days ago
It's much simpler than that. A judge orders you to give police access to your account. Regardless of whatever labyrinthian setup you use to unlock the actual credentials, and barring a stay of the order pending appeal, if you do not give police access you will be held in contempt of court and you may be sent to prison until such time as you comply with the court order. Claims of "but technically I don't actually know the password" are going to impress a judge as much as an argument of "but technically it was the bullet that murdered him" would.
2 comments

But what if you set your system up with plausibly deniable encryption? Say you encrypt two data sets, one with perfectly legal data, the other with the secret incriminating stuff. How will law enforcement be able to tell you gave them the key to the innocent data only? Block cipher output is indistinguishable from pseudorandom numbers. Deniable encryption is not a new thing in any way.

Edit: How would this be different from police saying "we know you've gone out and buried something, a neighbor saw you leave with something heavy and a shovel", and then you give them a location where you've buried something innocent (a long way away from your secret criminal stuff)?

You could setup a complicated series of plausibly deniable encryption, steganography, and so on and I suppose that might work. But you need to maintain perfect opsec as well as hope they don't already have sufficient evidence that you possess the information they're after. They might have already installed a keylogger plus covert video surveillance and your denials are now contempt of court plus obstruction of justice.

In your burial scenario, they might already possess video surveillance of you dragging a body into the woods, then leaving 30 minutes later but they'd like you to provide an exact location to avoid an extensive search. Telling them you went to the beach with your metal detector won't bode well.

What if you "forogt" how to gain access to your account?
Also, what if you forgot how to gain access to your account?
Are you drunk?