[Dshield] Fw: [ISN] Judge: Man can't be forced to divulge encryption passphrase

Jim McCullough jim.mccullough at gmail.com
Tue Dec 18 01:35:07 GMT 2007


I wasnt refering to back doors, but to agencies that have the hardware and
ppl with enough knowledge to actually break the encryption.  Another ethics
issue I would guess.   As long as there is some road block, human nature
will push to ypass it or to plow right through.   It poses some thought on
what possible paths the future of forensics might take.  I was not referring
to back doors per say, but in general ppl  trying to get past a wall.

On Dec 17, 2007 8:14 PM, Brad Tilley <brad.tilley at vt.edu> wrote:

> There will be no back doors. OpenPGP is a IETF standard (rfc-2440 &
> rfc-4880). There is also
> a FSF/GNU implementation called Gnupg (http://gnupg.org/). The
> corporate implementations may have backdoors, they may in fact have
> them now, who knows? If you are concerned about this, use Gnupg.
>
> Also, look at TrueCrypt's 'Plausible Deniability' option... it
> addresses this very scenario. In many countries, the opposite is true
> to this ruling... one can be held in contempt of court and jailed for
> not disclosing encryption pass phrases (UK). With plausible
> deniability, one can give the fake password to their encrypted 'tax
> documents' while never disclosing the password to the secret, hidden
> volume that contains the criminal material.
>
> On Dec 17, 2007 6:15 PM,  <aihomes at comcast.net> wrote:
> > This case has some pretty far reaching implications.
> >
> > If a precedent like this survives higher appeals court scrutiny, does
> this spell doom for future forensic investigations of any kind because PGP
> or other encryption solution is implemented by the bad guys?
> >
> > Maybe I'm reading this wrong...
> >
> > Even more critical, will PGP take cues and start building a backdoor
> into later releases of their solution?
> _________________________________________
> SANS Security 2008 in New Orleans!! January 11-19 2008. Why freeze up
> north if you can be in New Orleans.  http://www.sans.org/info/15826
>



-- 
Jim McCullough

A friend is someone who will help you move. A real friend is someone who
will help you move a body.
 - Unknown


More information about the list mailing list