Key disclosure law
Key disclosure laws, also known as mandatory key disclosure, is legislation that requires individuals to surrender cryptographic keys to law enforcement. The purpose is to allow access to material for confiscation or digital forensics purposes and use it either as evidence in a court of law or to enforce national security interests. Similarly, mandatory decryption laws force owners of encrypted data to supply decrypted data to law enforcement.
Nations vary widely in the specifics of how they implement key disclosure laws. Some, such as Australia, give law enforcement wide-ranging power to compel assistance in decrypting data from any party. Some, such as Belgium, concerned with self-incrimination, only allow law enforcement to compel assistance from non-suspects. Some require only specific third parties such as telecommunications carriers, certification providers, or maintainers of encryption services to provide assistance with decryption. In all cases, a warrant is generally required.
Theory and countermeasures
Mandatory decryption is technically a weaker requirement than key disclosure, since it is possible in some cryptosystems to prove that a message has been decrypted correctly without revealing the key. For example, using RSA public-key encryption, one can verify given the message (plaintext), the encrypted message (ciphertext), and the public key of the recipient that the message is correct by merely re-encrypting it and comparing the result to the encrypted message. Such a scheme is called undeniable, since once the government has validated the message they cannot deny that it is the correct decrypted message.[1]
As a countermeasure to key disclosure laws, some personal privacy products such as BestCrypt, FreeOTFE, and TrueCrypt have begun incorporating deniable encryption technology, which enable a single piece of encrypted data to be decrypted in two or more different ways, creating plausible deniability.[2][3] Another alternative is steganography, which hides encrypted data inside of benign data so that it is more difficult to identify in the first place.
A problematic aspect of key disclosure is that it leads to a total compromise of all data encrypted using that key in the past or future; time-limited encryption schemes such as those of Desmedt et al.[1] allow decryption only for a limited time period.
Criticism and alternatives
Critics of key disclosure laws view them as compromising information privacy, by revealing personal information that may not be pertinent to the crime under investigation, as well as violating the right against self-incrimination and more generally the right to silence, in nations which respect these rights. In some cases, it may be impossible to decrypt the data because the key has been lost, forgotten or revoked, or because the data is actually random data which cannot be effectively distinguished from encrypted data.
A proactive alternative to key disclosure law is key escrow law, where the government holds in escrow a copy of all cryptographic keys in use, but is only permitted to use them if an appropriate warrant is issued. Key escrow systems face difficult technical issues and are subject to many of the same criticisms as key disclosure law; they avoid some issues like lost keys, while introducing new issues such as the risk of accidental disclosure of large numbers of keys, theft of the keys by hackers or abuse of power by government employees with access to the keys. It would also be nearly impossible to prevent the government from secretly using the key database to aid mass surveillance efforts such as those exposed by Edward Snowden. The ambiguous term key recovery is applied to both types of systems.
Legislation by nation
Antigua and Barbuda
The Computer Misuse Bill, 2006, Article 21(5)(c), if enacted, would allow police with a warrant to demand and use decryption keys. Failure to comply may incur "a fine of fifteen thousand [East Caribbean] dollars" and/or "imprisonment for two years."[4]
Australia
The Cybercrime Act 2001 No. 161, Items 12 and 28 grant police with a magistrate's order the wide-ranging power to require "a specified person to provide any information or assistance that is reasonable and necessary to allow the officer to" access computer data that is "evidential material"; this is understood to include mandatory decryption. Failing to comply carries a penalty of 6 months imprisonment. Electronic Frontiers Australia calls the provision "alarming" and "contrary to the common law privilege against self-incrimination."[5]
The Crimes Act 1914, 3LA(5) "A person commits an offence if the person fails to comply with the order. Penalty for contravention of this subsection: Imprisonment for 2 years."[6]
Belgium
The Loi du 28 novembre 2000 relative à la criminalité informatique (Law on computer crime of 28 November 2000), Article 9 allows a judge to order both operators of computer systems and telecommunications providers to provide assistance to law enforcement, including mandatory decryption, and to keep their assistance secret; but this action cannot be taken against suspects or their families.[7][8] Failure to comply is punishable by 6 months to 1 year in jail and/or a fine of 130 to 100,000 Euros.
Canada
Canada implements key disclosure by broad interpretation of "existing interception, search and seizure and assistance procedures";[9] in a 1998 statement, Cabinet Minister John Manley explained, "warrants and assistance orders also apply to situations where encryption is encountered — to obtain the decrypted material or decryption keys."[10]
Finland
The Coercive Measures Act (Pakkokeinolaki) 2011/806 section 8 paragraph 23[11] requires the system owner, its administrator, or a specified person to surrender the necessary "passwords and other such information" in order to provide access to information stored on an information system. The suspect and some other persons specified in section 7 paragraph 3 that cannot otherwise be called as witnesses are exempt from this requirement.
France
Loi no 2001-1062 du 15 novembre 2001 relative à la sécurité quotidienne, article 30 (Law #2001-1062 of 15 November 2001 on Community Safety) allows a judge or prosecutor to compel any qualified person to decrypt or surrender keys to make available any information encountered in the course of an investigation. Failure to comply incurs three years of jail time and a fine of €45,000; if the compliance would have prevented or mitigated a crime, the penalty increases to five years of jail time and €75,000.[12]
India
Section 69 of the Information Technology Act, as amended by the Information Technology (Amendment) Act, 2008, empowers the central and state governments to compel assistance from any "subscriber or intermediary or any person in charge of the computer resource" in decrypting information.[13][14] Failure to comply is punishable by up to seven years imprisonment and/or a fine.
New Zealand
New Zealand Customs is seeking Power to compel Key disclosure.[15]
Poland
In relatively few known cases in which police or prosecutor requested cryptographic keys from those formally accused and these requests were not fulfilled, no further consequences were imposed on the accused. There's no specific law in this matter, as e.g. in the UK. It is generally assumed that the Polish Criminal Procedure Code (Kodeks Postępowania Karnego Dz.U. 1997 nr 89 poz. 555.) provides means of protecting against self-incrimination, including lack of penalization for refusing to answer any question which would enable law enforcement agencies to obtain access to potential evidence, which could be used against testifying person.[16]
South Africa
Under the RICA Act of 2002, refusal to disclose a cryptographic key in your possession could result in a fine up to ZAR 2 Million or up to 10 years imprisonment. This requires a judge to issue a decryption direction to a person believed to hold the key.
Sweden
There are currently no laws that force the disclosure of cryptographic keys. However, there is legislation proposed on the basis that the Council of Europe has already adopted a convention on cyber-crime related to this issue. The proposed legislation would allow police to require an individual to disclose information, such as passwords and cryptographic keys, during searches. The proposal has been introduced to make it easier for police and prosecutors. The proposal has been criticized by The Swedish Data Inspection Board.[17][18]
The Netherlands
Article 125k of the Wetboek van Strafvordering allows investigators with a warrant to access information carriers and networked systems. The same article allows the district attorney and similar officers of the court to order persons who know how to access those systems to share their knowledge in the investigation, including any knowledge of encryption of data on information carriers. However, such an order may not be given to the suspect under investigation.[19]
United Kingdom
The Regulation of Investigatory Powers Act 2000 (RIPA), Part III, activated by ministerial order in October 2007,[20] requires persons to supply decrypted information and/or keys to government representatives with a court order. Failure to disclose carries a maximum penalty of two years in jail. The provision was first used against animal rights activists in November 2007,[21] and at least three people have been prosecuted and convicted for refusing to surrender their encryption keys,[22] one of whom was sentenced to 13 months' imprisonment.[23]
United States
The Fifth Amendment to the United States Constitution protects witnesses from being forced to incriminate themselves, and there is currently no law regarding key disclosure in the United States.[24] However, the federal case In re Boucher may be influential as case law. In this case, a man's laptop was inspected by customs agents and child pornography was discovered. The device was seized and powered-down, at which point disk encryption technology made the evidence unavailable. The judge held that it was a foregone conclusion that the content exists since it had already been seen by the customs agents, Boucher's encryption password "adds little or nothing to the sum total of the Government's information about the existence and location of files that may contain incriminating information."[25][26]
In another case, a district court judge ordered a Colorado woman to decrypt her laptop so prosecutors can use the files against her in a criminal case: "I conclude that the Fifth Amendment is not implicated by requiring production of the unencrypted contents of the Toshiba Satellite M305 laptop computer," Colorado U.S. District Judge Robert Blackburn ruled on January 23, 2012.[27] In Commonwealth v. Gelfgatt,[28] the court ordered a suspect to decrypt his computer, citing exception to Fifth Amendment can be invoked because "an act of production does not involve testimonial communication where the facts conveyed already are known to the government...".[29]
However, in United States v. Doe, the United States Court of Appeals for the Eleventh Circuit ruled on 24 February 2012 that forcing the decryption of one's laptop violates the Fifth Amendment.[30][31]
The Federal Bureau of Investigation may also issue national security letters that require the disclosure of keys for investigative purposes.[32] One company, Lavabit, chose to shut down rather than surrender its master private keys.
Since the summer of 2015, cases were fought between major tech companies such as Apple over the regulation of encryption with government agencies asking for access to private encrypted information for law enforcement purposes. A technical report was written and published by MIT Computer Science and Artificial Intelligence Laboratory, where Ronald Rivest, an inventor of RSA, and Harold Abelson, a computer science professor at MIT with others, explain the technical difficulties, including security issues that arise from the regulation of encryption or by making a key available to a third party for purposes of decrypting any possible encrypted information. The report lists scenarios and raises questions for policy makers. It also asks for more technical details if the request for regulating encryption is to be pursued further.[33]
See also
References
- 1 2 Desmedt, Yvo and Burmester, Mike and Seberry, Jennifer. Equitability in Retroactive Data Confiscation versus Proactive Key Escrow. Florida State University Department of Computer Science 206 Love Building FL 32306-4530 Tallahassee USA. Lecture Notes in Computer Science: Public Key Cryptography, pp.277-286. 2001. (Postscript), (Postscript 2)
- ↑ Plausible Deniability
- ↑ TrueCrypt - Hidden Volume
- ↑ Antigua and Barbuda: The Computer Misuse Bill, 2006
- ↑ Electronic Frontiers Australia. Privacy Laws in Australia: Security / Cybercrime. Retrieved 2010 November 8.
- ↑ AG. "Crimes Act 1914". www.comlaw.gov.au. Retrieved 2016-04-30.
- ↑ Loi du 28 novembre 2000 relative à la criminalité informatique: Article 9. 2000 November 28. Retrieved 2010 November 9.
- ↑ Code d'instruction criminelle. Livre II, titre I, Art. 156. 1808 November 19. Retrieved 2010 November 9. (in French)
- ↑ The Digital Economy in Canada: Summary of Canada’s Policy on Cryptography. Industry Canada. Last modified 2009-02-11. Retrieved 2010 November 19.
- ↑ The Digital Economy in Canada: Speaking Notes for John Manley: Canada's Cryptography Policy. Presentation to the National Press Club, Ottawa. October 1, 1998. Industry Canada. Last modified 2009-02-11. Retrieved 2010 November 19.
- ↑ "Coercive Measures Act (Pakkokeinolaki)" (in Finnish). Retrieved 2016-04-30.
- ↑  Articles 30–31, loi no</sup> 2001-1062 du 15 novembre 2001 relative à la sécurité quotidienne (in French)
- ↑ Information Technology (Amended) Act, 2008 (PDF); Government of India – Ministry of Law, Justice and Company Affairs (Legislative Department); XI (69) pp. 27–8.
- ↑ Paper – 6 : Information Systems Control and Audit (PDF) 10 pp. 42–3. Study Material - Final (New) The Institute of Chartered Accountants of India.
- ↑ "Customs downplays password plan". Stuff. Retrieved 2016-04-30.
- ↑ Webhosting.pl - W jaki sposób służby mogą uzyskać dostęp do zaszyfrowanych danych
- ↑ "DI kritiserar nya it-regler". Publikt (in Swedish). 2013-09-26. Retrieved 2016-04-30.
- ↑ "Remiss av betänkandet Europarådets konvention om it - relaterad brottslighet (SOU 2013:39)" (PDF) (in Swedish).
- ↑ "wetten.nl - Regeling - Wetboek van Strafvordering - BWBR0001903". wetten.overheid.nl. Retrieved 2016-04-30.
- ↑ Kirk, Jeremy (October 1, 2007). "Contested UK encryption disclosure law takes effect". Washington Post. PC World. Retrieved 2009-01-05.
- ↑ Ward, Mark (2007-11-20). "Campaigners hit by decryption law". BBC News. Retrieved 2009-01-05.
- ↑ Oates, John (6 October 2010). "Youth jailed for not handing over encryption password". The Register.
- ↑ Williams, Christopher (24 November 2009). "UK jails schizophrenic for refusal to decrypt files". The Register.
- ↑ Varma, Corey. "Encryption vs. Fifth Amendment". www.coreyvarma.com. Retrieved July 28, 2015.
- ↑ "In re Grand Jury Subpoena to Sebastien Boucher, Memorandum of Decision" (PDF). The Volokh Conspiracy. February 19, 2009. Archived from the original (PDF) on July 16, 2014. Retrieved 2009-08-29.
- ↑ McCullagh, Declan (December 14, 2007). "Judge: Man can't be forced to divulge encryption passphrase". CNET. Retrieved October 19, 2014.
- ↑ Kravets, David (January 23, 2012). "Judge Orders Defendant to Decrypt Laptop". WIRED.
- ↑ Commonwealth v. Gelfgatt (Report) 468. Supreme Judicial Court of Massachusetts. June 25, 2014. p. 512. Retrieved October 19, 2014.
- ↑ Farivar, Cyrus (June 26, 2014). "Massachusetts high court orders suspect to decrypt his computers". Ars Technica. Retrieved October 19, 2014.
- ↑ Hofmann, Marcia; Fakhoury, Hanni (February 24, 2012). "Appeals Court Upholds Constitutional Right Against Forced Decryption". Electronic Frontier Foundation. Retrieved October 19, 2014.
- ↑ Lee, Timothy B. (February 25, 2012). "Appeals court: Fifth Amendment protections can apply to encrypted hard drives". Ars Technica. Retrieved October 19, 2014.
- ↑ "Lavabit appeals contempt of court ruling surrounding handover of SSL keys". Naked Security. 2014-01-29. Retrieved 2016-04-30.
- ↑ Keys Under Doormats: Mandating insecurity by requiring government access to all data and communication (PDF). MIT Computer Science and Artificial Intelligence Laboratory (Technical report). 6 July 2015.
Further reading
- Bert-Jaap Koops. Bert-Jaap Koops homepage: Crypto Law Survey: Overview per country. Version 26.0. Universiteit van Tilburg. July 2010.
- Stephen Mason, gen ed, Electronic Evidence (3rd edn, LexisNexis Butterworths, 2012) Chapter 6 Encrypted data
- Palfreyman, Brendan M. (2009). "Lessons from the British and American Approaches to Compelled Decryption". Brooklyn Law Review 75 (1): 345.
- Fakhoury, Hanni (2012). "A combination or a key? The Fifth Amendment and privilege against compelled decryption". Digital Evidence and Electronic Signature Law Review 9: 81–87.