DIY privacy and security, the rights of the individual against the intrusive state.

Aug 01, 2019 Last reply: 6 years ago 47 Replies

I've been giving some thought as to how to protect one's privacy from the ever growing snoopings of the Brit monarchy and all its lapdogs and subordinate dogs' dinners such as GCHQ, the MIxs and the po lice, and to kill off RIPA and the sending of innocent people to jail for not revealing their passwords and security keys to the plodderies.


  1. In case of computers being seized, you have to guard against previous data being scattered around the disk in various deletions. The solution here would be to store all data in an indexed data base file of such a size that it won't be moved willy nilly by the OS. Then, by overwriting records at fixed and known locations, previous data can be guaranteed to be deleted.


  1. When receiving encyphered messages, the one-time key is to be the previously received message, giving only one opportunity to read your message before it takes the place of the previously received message at the fixed location in the indexed data base.

  2. Still working on data that has to be kept indefinitely, watch this space.

Not answering the above, but on an associated topic there must be many people, like myself, who do some consultancy work that is wholy dependent on computers. There's a small but finite chance that innocent people might get their systems seized and my understanding is that it may take months or years to get the hardware and data back. In such a case, they are instantly out of business *unless* they have all their data backed up in the cloud, in which case it is just a case of buying a new laptop and carrying on.

Now, I don't mind having my contacts and calendar together with my spotify playlist in the cloud. Email is already there. But *some* of my client data can't go there.

Gareth's stuff above is a bit tinfoil hat to me, but my scenario seems to me to be a real (if low probability) threat. If you keep an off-site backup that you don't declare to the police, presumably you are committing an offence.

Write a program that writes 55H to every byte of every unallocated sector?

To easy to corrupt and lose the thread

Civil liberties, my dear chap.

But you raise an interesting concern, and that it the tendency of the plodderies to seize all computers and phones on the merest pretext and thereby completely destroying your well being in a digital world.

There has to be a way of maintaining one's well being despite the unwarranted attacks by the plodderies.

newshound snipped-for-privacy@stevejqr.plus.com> posted

No, I don't think so. You're not generally obliged to answer police questions after arrest, and there is of course no law requiring disclosure of all backups *before* arrest.

cross backup strategies with neigbours and friends

Create a hidden partition on an encrypted disk like you can with TrueCrypt.

It is an interesting question. I would demand carbon copies of the working drives seized since without them the job stops. I wish them luck finding anything recognisable in my highly compressed chess databases.

The first thing they should do after seizure is bitwise clone the original drives so if they make an extra copy at that point I'd be happy. Annoying to have hardware taken away but not a show stopper.

Having all the backups and email archives seized and unavailable would be much more of an annoyance. And their sheer volume would tie up a lot of resources to scan though even with automatic tools.

Won't the police insist on locking that down too and inspecting it?

Otherwise all anyone needs do is keep their dodgy stuff in the Cloud or encrypted on a server hosted in some lawless region of the internet.

I no longer use hard encryption routinely since I think the security services need all the help they can get. Back when the USA was persecuting Phil Zimmerman for PGP I routinely exchanged emails with like minded tech folk with the hardest encryption then available. I stopped after 9/11.

That would immediately raise their suspicions. "Hidden" partitions are not very hidden from digital forensics.

Various obscure forms of steganography might work though if the proportion of data you wanted to hide was relatively modest and you don't mind slightly degrading your digital media.

This technique of hiding things in plain sight goes back a long way:

formatting link

All of which techniques are well known to the plodderies and their ilk from which knowledge they can demand the keys.

No harm in that...

While I understand the desire, these are far from trivial problems to solve, and your suggestions in 1 and 2 above suggest you are currently sufficiently out of your depth in this particular domain, as to make any solutions less than useful.

Most people are capable of devising a security system so good that they themselves could not break it... alas that does not mean it is free from flaws or of any practical use, or that a security researcher or cryptanalyst would not compromise it in five minutes.

Retired software engineer with digital electronics background; relatively trivial programming exercise for me.

That kind of reinforces the point. Security is a system wide and procedural issue, not just a technical programming one. Many notionally secure systems are routinely compromised even when using recognised crypto systems, simply down to procedural flaws, or lack of understanding of parts of the system that the designer had no awareness of.

For example, even if your database is not "moved" by the OS, how do you ensure that fragments of it are not held in currently unused and non accessible pages of an SSD being managed by a wear levelling algorithm? Or in a reallocated sector of a hard drive? Or that the powers that be are not able to infer what you are typing with a covert listening device? Or see your non tempest secured screen remotely? Or are able to simply attack the other less security aware party you are communicating with?

The list is nearly endless!

What about virtual machines? How can the police (or anyone) sieze them? The *physical* machine is owned by someone else and may even be in a different country.

It is interesting to visit Bletchley Park and try your hand at an Enigma code cracking crib diagram. Traffic analysis can get you a long way and if you know that "0600 weather report" (or some other crib) is in the plaintext it cuts down the number of possibilities enormously.

Reading a classic CRT was astonishingly easy with relatively simple radio astronomy kit. Modern LCDs would put up more of a fight.

You don't think gchq doesn't know how to find that?

It would be more accurate to say ?involuntarily retired software engineer?, and even more accurate to say ?unemployable for decades?. HTH.

True but you might be interviewed under caution after a seizure. You could of course decline to answer any questions at that stage but if you did "fail to disclose" that might be a black mark if you were actually guilty.

Especially if forensic investigation found a batch file of the form

Copy <really dirty stuff> to <secret location>

Delete and overwrite <really dirty stuff>

Some years ago a friend of mine, who was an Independent Financial Advisor, heard a knock at the door and a dozen or more police burst in. They confiscated his computers, excorted him to his business premises and confiscated the ones there.

He had backups and was able to buy a few more machines and get everything up and running again, but it cost him days of lost work.

The regulator then banned him and his company from most of his work, relaxing it after a few weeks, but leaving him banned from dealing with pensions - the main part of his business.

He was questioned under caution and remained on police bail for 18 months, although the regulator allowed him to start dealing with pensions again after about four months.

Eventually the regulator and police agreed he'd done nothing wrong.

What had happened was that he and another company had been recommending a third company for private pensions, but unknown to them, the third company was involved in a kick-back deal with some other financial advice companies and so they were suspected of being part of it.

It is as easy as that to be accused and have vital computers and data taken away.

That probably depends upon the data. You don't have to answer any questions the police ask, so you don't have to reveal the whereabouts or even the existence of a backup. However you are open to having new machines immediately confiscated if the data itself is suspected of being illegal.

SteveW

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required