• bambooEnglish
      arrow-up
      40
      arrow-down
      0
      ·
      9 months ago
      link
      fedilink

      IANAL but withholding evidence from a court order can hold you in contempt of court. I remember hearing a story of a person who was accused of having CSAM on an encrypted hard drive, and refused to decrypt it, and is in jail until he decrypts it. Just because you’re a person doesn’t mean you can ignore a warrant.

      • originalucifer
        arrow-up
        46
        arrow-down
        0
        ·
        9 months ago
        link
        fedilink

        information itself is a liability. best to have a policy of ‘we keep no IPs in logs, so are happy to hand over whatever’ dump data the moment you dont require it

        • Tangent5280English
          arrow-up
          29
          arrow-down
          0
          ·
          9 months ago
          link
          fedilink

          yeah, this sounds like a much more sustainable solution. Do it the way signal does it. Collect as little as necessary, and delete it as soon as you dont need it.

        • cmnyboEnglish
          arrow-up
          10
          arrow-down
          1
          ·
          9 months ago
          link
          fedilink

          Just store what logs you need on a ram drive. The logs will be gone the instant the server shuts down and there is no way to recover them.

          • nevemsenkiEnglish
            arrow-up
            8
            arrow-down
            0
            ·
            9 months ago
            link
            fedilink

            Downsides include : if any intrusion happens on the server, red team just needs to reboot it to wipe evidence.

            • PerhyteEnglish
              arrow-up
              5
              arrow-down
              0
              ·
              9 months ago
              edit-2
              9 months ago
              link
              fedilink

              If they have the root access typically needed to reboot a server1 they could also just wipe the logs without rebooting.

              1: GUIs typically have a way to reboot without such privileges, but those are typically not installed on machines just used as servers.

      • Davel23
        arrow-up
        7
        arrow-down
        0
        ·
        9 months ago
        link
        fedilink

        I looked into that guy somewhat recently, he was in jail for something like five years then eventually released. Kind of a sickening situation all around.

      • RaiEnglish
        arrow-up
        4
        arrow-down
        1
        ·
        9 months ago
        link
        fedilink

        Imagine contempt of court but you don’t live in the US

    • essersteinEnglish
      arrow-up
      1
      arrow-down
      0
      ·
      9 months ago
      link
      fedilink

      With the federation does that also mean that the ip records are replicated? Because that would be a lot of parties that can be threatened, with only one required to give in

      • sir_reginaldEnglish
        arrow-up
        2
        arrow-down
        0
        ·
        9 months ago
        link
        fedilink

        I could be wrong, but I believe you only disclose your IP to your Lemmy instance.