Remix.run Logo
amelius 5 hours ago

Someone should write a disk formatting utility that randomizes the bits on your drive.

Now you can claim that any encrypted drive (which just looks like pure noise if done correctly) is a drive that was just formatted.

fhdkweig 5 hours ago | parent | next [-]

Be careful in countries like UK which have laws requiring the decryption of any data they find. There are people sitting in jail because they couldn't decrypt the "random noise" on their computers.

amelius 3 hours ago | parent | next [-]

This is exactly the point. If storing random data was the norm (formatting utilities would offer it) then it would be hard to make a case against it.

And it actually _does_ make sense for formatting utilities to offer it, as this is a good way to ensure that data is really gone after formatting (writing all 0s or all 1s could leave information at the physical layer; and any intermediate layer could not compress random data much so the data must be overwritten).

NikolaNovak 5 hours ago | parent | prev | next [-]

Fair warning; any links to specific cases (not the law itself)?

fhdkweig 4 hours ago | parent [-]

This lists two unnamed individuals.

https://edri.org/our-work/edri-gramnumber7-16decrypt-data-ca...

ErroneousBosh 5 hours ago | parent | prev | next [-]

> There are people sitting in jail because they couldn't decrypt the "random noise" on their computers.

No, there isn't.

monster_truck 4 hours ago | parent | prev [-]

There literally are not. Anyone competent enough to be an expert witness will be able to plainly explain to everyone else how statistical analysis obviously delinates the difference between truly random noise and an encrypted volume.

monocasa 4 hours ago | parent | next [-]

If there's a difference visible, that's a weakness in the encryption algorithm.

Encrypted data should be statistically indistinct from random noise.

It's an information theory thing. Everything in the ciphertext should be sitting at maximum entropy.

pixl97 4 hours ago | parent | prev | next [-]

Loll, you have a lot of faith in the legal system that I do not. Expert witnesses are commonly full of shit.

giancarlostoro 3 hours ago | parent [-]

I heard one argue that "zooming" on an image by adding pixels with an algorithm is normal, and he's had such "evidence" used in court before. I was a little horrified as someone who has worked on digital forensic software at a former employer. Adding pixels to an image is not evidence, you're fabricating something out of thin air, especially if its drastically smaller, its even more likely to be BS.

fhdkweig 4 hours ago | parent | prev | next [-]

Even if that is true, I have better things to do with my time and money than pay a expert witness to explain: see, I wasn't breaking the law, I just wanted the cops to think I did. That just seems like a really bad idea.

ThePowerOfFuet 2 hours ago | parent | prev [-]

> the difference between truly random noise and an encrypted volume

A LUKS volume with a detached header is indistinguishable from random data.

giantg2 4 hours ago | parent | prev | next [-]

Sounds a lot like stenography.

https://github.com/dishather/steganodisk

tptacek 4 hours ago | parent [-]

The security track record of steganography is not great.

giantg2 3 hours ago | parent [-]

Isn't the same true of consumer grade encryption? In a perfect world, they should be used together.

tptacek 2 hours ago | parent [-]

Depends on what you mean, but my subtext was that a lot of steganographic designs have turned out to be detectable; it's a design-level concern, where most consumer encryption problems are implementation issues.

ErroneousBosh 5 hours ago | parent | prev [-]

That would just be dd if=/dev/urandom of=/dev/path/to/device