Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« The Iowa Caucus Experience in Madison County: Cameras Not a Factor | Main | E-Discovery Decision Demonstrates Need For Effective Retention Practices: A Great Case Study For E-Discovery Training »

Privacy, The 5th Amendment And PGP Passwords

While doing some encryption research I ran across this Vermont ruling made on November 29, 2007.

It provides some good lessons about computer forensics and investigation and password management.

Magistrate Judge Jerome J. Niedermeier for the U.S. District Court for the District of Vermont ruled that a criminal defendant's compliance with a grand jury subpoena requesting the PGP encryption password that protected a laptop computer's contents would violate the Fifth Amendment privilege against compelled self-incrimination.

According to Niedermeier, "A password, like a combination, is in the suspect's mind, and is therefore testimonial and beyond the reach of the grand jury subpoena."

Here's an excerpt from the court ruling that provides the background:

"On December 17, 2006, defendant Sebastien Boucher was arrested on a complaint charging him with transportation of child pornography in violation of 18 U.S.C. § 2252A(a)(1). At the time of his arrest government agents seized from him a laptop computer containing child pornography. The government has now determined that the relevant files are encrypted, password-protected, and inaccessible. The grand jury has subpoenaed Boucher to enter a password to allow access to the files on the computer. Boucher has moved to quash the subpoena on the grounds that it violates his Fifth Amendment right against self-incrimination."

Basically, the agent caught Boucher with the laptop turned on and unsecured, and when the agent examined it, he found a lot of porn photos and videos, many that appeared to be underage children. When taking Boucher into custody, the agent shut down the computer. Subsequently when turning the computer back on and trying to re-access the porn files, he was prompted for the PGP password.

In this case regarding the Fifth Amendment's self-incrimination issue, the court considered whether the communication of the PGP password would be a) compelled, b) testimonial in nature, and c) incriminating.

The subpoena established compulsion, and the content of the computer drive was incriminating. The judge then had to consider whether the subpoena for the PGP password would be considered a testimonial communication.

The government cited Doe II v. United States, a case that involved a subpoena that forced a criminal suspect to sign a form requesting his bank records from banks in the Cayman Islands and Bermuda. The government argued that the password in this case was non-testimonial, pointing out that the U.S. Supreme Court determined the form did not require the suspect to make a statement about the existence of, or control over, any bank accounts.

The judge said this case was different.

"Entering a password into the computer implicitly communicates facts. By entering the password Boucher would be disclosing the fact that he knows the password and has control over the files on drive Z. The procedure is equivalent to asking Boucher, “Do you know the password to the laptop?” If Boucher does know the password, he would be faced with the forbidden trilemma; incriminate himself, lie under oath, or find himself in contempt of court. Id. at 212. Unlike the situation in Doe II, Boucher would be compelled to produce his thoughts and the contents of his mind. In Doe II, the suspect was compelled to act to obtain access without indicating that he believed himself to have access. Here, when Boucher enters a password he indicates that he believes he has access."

Quite an interesting analysis of when a suspect can and cannot be forced to reveal a password, such as for a PGP key.

So, even though the agent had actually seen the porn images on the laptop, because he shut down the computer and could not get back into the porn files, he could not force Boucher to enter the password for them.

This situation and accompanying decision was related solely to Boucher trying to get the court to quash the subpeona forcing him to reveal his PGP password.

However, as I read this I wondered about a couple of the other aspects of the case...

* The agent who shut down the computer was apparently not well-trained for computer forensics or the proper procedures to take to preserve evidence. Why the heck did he turn off the computer?

* Did anyone perform a search for the password? Most people write down their passwords,including PGP passwords, somewhere on something. Did the investigators check for sticky notes on the computer case? In the car? In Boucher's home? Stored on his cell phone? Etc...

Of course the full investigative details were not provided in this very small slice of a view into this case, but it does make you wonder.

Does your organization have a team of folks trained in performing sound computer forensics activities?

Do your personnel write down their passwords and keep this documentation where others can find them?

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/619

Comments

Hello Rebecca,

In June of 2007 you came to speak to the Norwich MSIA students. I was among those individuals.

I don't know if you have access to Norwich's Yahoo discussion group, but we had a really great discussion on this very topic. I think you may find the reading beneficial, but I believe you may want to talk to Mich Kabay about access (that's if you don't have access).

Kevin

Thanks for your note, Kevin!

And, thanks for the pointer; I will look into it. :)

BTW, you've got a nice site!

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.