Summary

  • The Marion County Record newsroom in Kansas was raided by police, who seized two cellphones, four computers, a backup hard drive, and reporting materials.

  • A computer seized was most likely unencrypted. Law enforcement officials hope that devices seized during a raid are unencrypted, as this makes them easier to examine.

  • Modern iPhones and Android phones are encrypted by default, but older devices may not be.

  • Desktop computers typically do not have encryption enabled by default, so it is important to turn this on manually.

  • Use strong random passwords and keep them in a password manager.

  • During the raid, police seized a single backup hard drive. It is important to have multiple backups of your data in case one is lost or stolen.

  • You can encrypt USB storage devices using BitLocker To Go on Windows, or Disk Utility on macOS.

  • All major desktop operating systems support Veracrypt, which can be used to encrypt entire drives.

Main Take-aways

  • Encrypt your devices, drives, and USBs.

  • Use strong random passwords and password manager.

  • Have multiple backups.

11 points

Offsite backup

permalink
report
reply
14 points

If you encrypt your device, and dirty cops like these decide they want in, they’ll just toss you in the slammer and forget about you until you either cough up the password or die of dehydration. Either way works for them.

permalink
report
reply
17 points

Similarly when you cross a border… you don’t have to give them you password, but they can just keep you for a few days. Also note:

Currently, police officers have the authority to demand that you unlock your mobile phone using face recognition and fingerprint identification. When unlocking your phone, police officers have no right to demand that you disclose your passcode or pattern.

https://esfandilawfirm.com/can-police-unlock-your-phone/

permalink
report
parent
reply
19 points

They can also kill you where you stand with total impunity, so I’m not sure I see how these limitations of their supposed rights are at all meaningful.

permalink
report
parent
reply
2 points

It’s layers on an onion. Every extralegal step they take provides a possible mitigation if you go to trial.

Obviously, if they straight up murder somebody, that’s a whole different problem. But in general, you should invoke your rights at every step of the process, so that if they trample over those rights you’ll have an argument in court to get evidence or charges thrown out.

permalink
report
parent
reply
4 points

should have complied

permalink
report
parent
reply
3 points

No I won’t give the password

permalink
report
parent
reply
10 points
9 points

Make the authentication a biological indicator of consensual, free, unhindered existence.

“Sorry officers I literally can’t unlock this computer while I’m in your custody. Unless you can find a way to make me want to be here, that is”

“Well then we’ll just torture you”

“Nope, as you can see pain I experience burns this fuse here. Once the fuse is consumed, data begins to progressively degrade”

permalink
report
parent
reply
13 points

Bitlocker only support win 10/11 pro or above, most devices are shipped with win 10/11 home which doesn’t have the capability. Linux supports full drive encryption using LUKS.

permalink
report
reply
2 points

Yup, my win10 and win11 have bitlocker on. They dual boot with Linux, FDE on them too.

permalink
report
parent
reply
1 point

Well, you can work on a Veracrypt partition.

permalink
report
parent
reply
27 points

Even if everything is encrypted when powered off, and decrypted while running, if you get raided while everything is running, it’s irrelevant. If you’re logged in and someone can just sit down at your computer and see everything, all the security in the world is meaningless.

Unless you have a giant electromagnet in your server rack, remote connection only from your local machine to that rack, and a panic button that fries the whole damned thing should your door be busted down, I’m not sure what else the answer is.

Even if your security is perfect, they can waterboard your ass until you give up the keys, and no court will ever call it misconduct, because they can just declare you a domestic terrorist or an enemy combatant, giving them carte blanche.

Problem #1: and this has been the prime problem for 22 fucking years: The Patriot Act. Every. Single. Bit. Of. It. Must. Be. Repealed. The harm it’s caused and the power it’s given the government is incalculable.

Problem #2: the rising tide of fascism

Problem #3: general apathy, and general lack of understanding of how computing works. We are rapidly accelerating backward in the general public’s understanding of computing principles. Hell, even just how to navigate a file system. The proliferation of locked down devices and walled gardens has driven our collective computing knowledge into the fucking stone age. You won’t get most people to adopt gpg since most mobile mail clients don’t support it. You won’t get people to encrypt their computer’s filesystem because they either don’t have a general purpose computer anymore, can’t be bothered to do so, or the idea of installing an OS that supports it is just fantastical.

Problem #4: third-party privacy services (encrypted chat apps, VPNs, etc) have a profit motive that will eventually override any other motivation.

Problem #5: cloud computing is just someone else’s computer that you don’t control.

permalink
report
reply
9 points

Even if everything is encrypted when powered off, and decrypted while running, if you get raided while everything is running, it’s irrelevant.

Well, you can hit the power switch. The local constabulary isn’t gonna be smart enough to plunge the computer into liquid nitrogen and work on extracting the symmetric key from the frozen memory (although, federal authorities might be).

permalink
report
parent
reply
9 points

It’s not meaningless.

I know that it’s pretty easy to pick the lock on my front door. Or to break the window and get in. But still, there are a non-zero number of burglars who would be stopped by that lock. Same with my bike lock, which is a bit harder to pick but still possible. Nevertheless, the lock itself does deter and prevent some non-zero number of opportunistic thefts.

There are a non-zero number of law enforcement agencies that would be stopped by full disk encryption, even if the device is powered on and the encrypted media is mounted. There are a non-zero number of law enforcement agencies that would be stopped by all sorts of security and encryption strategies. And I’d argue that simple best practices would stop quite a few more than you’re seeming to assume: encrypt any data at rest on any devices you control, and then use e2e encryption for any data stored elsewhere.

You don’t even have to be that technically sophisticated. For Apple devices, turn on FileVault (as it is by default if you log into an Apple account when you set up the device), turn off iCloud. For Windows devices, use Bitlocker. For Android, turn on the “Encrypt Phone” setting, which is on by default. If you’re messing around with your own Linux devices, using LUKS isn’t significantly more difficult than the rest of system administration.

permalink
report
parent
reply
11 points

The FBI are going to copy your data before it’s re-encrypted but these hill-billy sheriffs would unplug them and haul them off.

permalink
report
parent
reply
10 points

So encryption really matters, totally agree. Protection at all times.

But I’m also curious about this story. Why are the police raiding a newspaper and seizing computers? That is sketchy as hell.

permalink
report
reply
12 points

The paper was investigating the police chief.

permalink
report
parent
reply
16 points

Short version:

  • Police chief was accused of sexual impropriety, and the newspaper was investigating.

  • A prominent local restaurant owner got caught in a DUI and the newspaper got a tip and investigated. On investigation, they decided the story was not newsworthy.

  • Police raided the newspaper claiming that the DUI tip was the result of illegal computer hacking, and that they had to confiscate the computers to analyze for evidence of hacking.

  • The judge who signed the search warrant also had a history of DUI.

  • Critics believe that the police used this hacking claim as a thinly veiled excuse to cripple the newspaper and check to see what they really had on the chief.

  • Critics have also suggested that the police themselves may have leaked the information to set up the flimsy excuse for the search.

permalink
report
parent
reply
3 points

Thanks for the summary.

That is kind of what I suspected which is:

  • There was some conflict between the newspaper and local government
  • Government found some flimsy excuse to attack the newspaper

Overall that’s bad news. It implies the government’s gloves are coming off.

permalink
report
parent
reply

Technology

!technology@beehaw.org

Create post

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Community stats

  • 2.7K

    Monthly active users

  • 2.9K

    Posts

  • 53K

    Comments