Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> forced to turn over your passwords

Forced, how? Threat of detention beyond the 9 hour window?

If so, it's easy to speculate I would call their bluff and refuse. But in the situation, probably not so easy.

What about using a hidden volume in TrueCrypt for plausible deniability? [1]

I suppose that would work effectively for documents. There's no plausible deniability for stuff like Facebook and Gmail. They can easily see if you gave them access to the real/full thing, or not.

However given the revelations David Miranda of all people would have to assume his Gmail, FB, et al have _already_ been compromised.[2] So the only interesting, still-private stuff would be any documents.

[1]: http://www.truecrypt.org/docs/plausible-deniability

[2]: Not that this makes it right to demand the passwords at LHR.



> Threat of detention beyond the 9 hour window?

No, the threat of 2 years in jail.

"The Regulation of Investigatory Powers Act 2000 (RIPA), Part III, activated by ministerial order in October 2007, requires persons to supply decrypted information and/or keys to government representatives. Failure to disclose carries a maximum penalty of two years in jail."(http://en.wikipedia.org/wiki/Key_disclosure_law#United_Kingd...).

TrueCrypt is no escape if they have reasonable suspicion there is a hidden volume. And you will have to prove that there isn't one.


Yesterday I made the observation that the document he was given in detention said:

"You must answer all questions and hand over any data or documents requested" and

"If you fail to comply you could be prosecuted under ..Terrorism Act."

You have no rights. You will disappear in a very deep, dark hole for a very long time if you try to call their bluff.

Welcome to the Patriot Act/Terrorism Act world.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: