Fooling Experts and Judges – Digital Evidence turns into digital Evil Dance

Eric Filiol

44CON 2024 · Day 3 · Main

Overview

In this groundbreaking talk, "Fooling Experts and Judges – Digital Evidence turns into digital Evil Dance," Eric Filiol, a seasoned expert in mathematics, cryptography, and forensic analysis, unveils a novel approach to manipulating digital evidence through what he terms encryption synthesis. The presentation challenges the fundamental trust placed in digital evidence within legal systems worldwide, demonstrating how seemingly irrefutable cryptographic proofs can be crafted to present multiple, contradictory realities. Filiol's work, developed since 2021, introduces a new form of deniable cryptography that allows a single ciphertext, when decrypted with different short keys, to yield entirely different, yet equally plausible, plaintexts.

Watch on YouTube

Visual summary for Fooling Experts and Judges – Digital Evidence turns into digital Evil Dance by Eric Filiol
Visual summary for Fooling Experts and Judges – Digital Evidence turns into digital Evil Dance by Eric Filiol

Key moments

  1. 0:00 Introduction: Manipulating cryptography and justice with deniable crypto
  2. 4:00 Questioning digital evidence and introducing encryption synthesis
  3. 4:50 Legal frameworks: Common law vs. civil law's view on evidence
  4. 7:40 Contrasting justice principles: Blackstone vs. 'hang him' quote
  5. 9:50 Defining digital evidence and cryptography's 'probative' power
  6. 11:20 Expert limitations: Simple techniques and poor crypto implementations

Fooling Experts and Judges – Digital Evidence turns into digital Evil Dance

Speakers: Eric Filiol

Conference: 44CON

YouTube: https://www.youtube.com/watch?v=8ifGeeumKak

Overview

In this groundbreaking talk, "Fooling Experts and Judges – Digital Evidence turns into digital Evil Dance," Eric Filiol, a seasoned expert in mathematics, cryptography, and forensic analysis, unveils a novel approach to manipulating digital evidence through what he terms encryption synthesis. The presentation challenges the fundamental trust placed in digital evidence within legal systems worldwide, demonstrating how seemingly irrefutable cryptographic proofs can be crafted to present multiple, contradictory realities. Filiol's work, developed since 2021, introduces a new form of deniable cryptography that allows a single ciphertext, when decrypted with different short keys, to yield entirely different, yet equally plausible, plaintexts.

Filiol, drawing from over two decades of experience in military cryptoanalysis and forensic expertise for terrorism cases, illuminates the critical vulnerabilities in how legal systems, judges, and even forensic experts perceive and interpret digital artifacts. He argues that the concept of "digital evidence" is far from simple and can be subtly yet profoundly manipulated by various actors, from defendants to state intelligence services. The talk is particularly timely given the ongoing global debates around cybercrime conventions and the balance between national security, law enforcement, and fundamental human rights, including the right to strong encryption.

This research carries immense weight for the cybersecurity community, legal professionals, and policymakers. It forces a re-evaluation of forensic methodologies, highlights the need for deeper cryptographic expertise among legal experts, and underscores the potential for abuse in both democratic and authoritarian regimes. By presenting concrete technical demonstrations of how digital evidence, including encrypted data and metadata, can be synthesized and subverted, Filiol issues a stark warning about the fragility of trust in the digital age and the urgent need for critical thinking when assessing any form of digital proof.

Background

▶ Watch: Introduction: Manipulating cryptography and justice with deniable crypto (0:00)

The concept of digital evidence, while seemingly concrete, operates within complex and often divergent legal frameworks across the globe. Eric Filiol begins by dissecting two primary legal systems: common law, prevalent in English-speaking nations, where law evolves through judicial precedent and places a heavy "burden of proof" on both prosecution and defense; and civil law, common elsewhere, which relies on codified statutes. A critical distinction lies in the principle of reasonable doubt in common law, where a defendant can be acquitted if they introduce sufficient doubt about their guilt. This contrasts sharply with some non-democratic states or even specific jurisdictions like France, where a judge's "personal conviction" can override presented evidence, granting immense power to the judiciary and making the introduction of convincing narratives paramount. Filiol illustrates this with the Blackstone formulation ("better to acquit ten guilty persons than to condemn one innocent") versus historical and contemporary authoritarian approaches that prioritize conviction.

Within these systems, digital evidence is defined as any probative information capable of proving a fact. For many experts and judges, cryptography often holds a near-sacred status; a ciphertext, an algorithm, and a key yielding a plaintext is often taken as absolute proof with a probability of one. Similarly, metadata, temporary data, and erased data are considered highly probative. However, Filiol points out that the current state of forensic expertise, particularly in cryptography, is often insufficient. Experts frequently rely on rudimentary techniques such as guessing weak passphrases, exploiting poor implementations (e.g., reuse of keys in stream ciphers or OFB mode), or identifying unencrypted temporary files. Tools like the library developed by Filiol can exploit vulnerabilities in Microsoft Office suite encryption, and Open Source Intelligence (OSINT) is increasingly used to find leaked passwords. Major countries maintain specialized departments (like ZQ in the UK, FBI in the US, or specific units in France) dedicated to cryptographic evidence, though their methods are often undisclosed, creating a "gray area" where evidence is presented without full transparency.

The talk then introduces the various actors in a legal trial and their inherent biases and interests: the defense attorney and defendant aiming for acquittal; the judge and prosecutor seeking conviction (often representing state interests); and forensic experts, who, despite their role, can be manipulated, corrupted, or simply lack the necessary deep expertise, especially in advanced cryptography. Beyond these, "rogue actors" like intelligence services or organized crime often possess superior skills and operate with different ethical norms. This complex interplay of interests creates fertile ground for manipulation.

A significant concern raised is the proposed UN Cybercrime Convention, pushed by non-democratic countries like Russia and China. Filiol warns that this convention, if adopted, risks enforcing a global "Cloud Act" equivalent, severely jeopardizing human rights and forcing cybersecurity professionals to reveal sensitive information. This context underscores the urgency of understanding how digital evidence can be manufactured or subverted, as it could become a tool for state-sponsored oppression rather than justice. The ongoing struggle to balance citizens' right to strong encryption with the need to combat criminal use of cryptography (e.g., EncroChat, Phantom Secure, ANOM operations) further complicates the landscape, making Filiol's work on manipulating cryptographic evidence highly relevant to this global debate.

Key Findings

▶ Watch: Legal frameworks: Common law vs. civil law's view on evidence (4:50)

The central and most impactful finding of Eric Filiol's talk is the successful development and demonstration of encryption synthesis, a novel form of deniable cryptography. This breakthrough directly addresses a long-standing open problem in the field: how to generate multiple, distinct, and intelligible plaintexts from a single ciphertext using short, deterministic keys, without relying on the impractical one-time pad (OTP). Filiol's work proves that this is not only theoretically possible but practically achievable with a custom C framework.

Key findings include:

  1. Challenging Trust in Digital Evidence: The talk fundamentally undermines the common perception that digital evidence, especially cryptographic evidence, is inherently trustworthy and irrefutable. Filiol demonstrates that virtually any digital artifact – metadata, erased data, and critically, encrypted data – can be deliberately crafted and forged to create misleading or contradictory narratives.
  2. Encryption Synthesis Concept: Filiol introduces "encryption synthesis" as a method where, given an arbitrary random sequence (a ciphertext), a deterministic algorithm can be designed. This algorithm, when combined with different short keys (e.g., 128-bit, 256-bit, not OTP length), can produce multiple distinct and plausible plaintexts. This effectively means a single "encrypted" file can simultaneously "contain" different, even contradictory, messages depending on which key is used for decryption.
  3. Solving the Single-File Deniable Encryption Problem: While systems like Rubberhose, Shufflecake, and TrueCrypt/VeraCrypt offer deniability for entire file systems or hidden partitions, the problem of achieving plausible deniability for a single encrypted file was largely considered open and challenging. Filiol's encryption synthesis provides a solution, enabling the creation of a single file that can legitimately decrypt into multiple plausible plaintexts, thereby offering strong deniability.
  4. Resistance to Cryptanalysis: The developed encryption synthesis framework is designed to be resistant to common cryptographic attacks. Analysis of the algorithm itself should not reveal the presence of deniable cryptography. Furthermore, even if one plaintext and the ciphertext are known, it is computationally intractable to retrieve the other possible plaintexts or keys. This ensures that forensic experts, unless possessing advanced cryptanalytic capabilities specifically tuned to detect this form of deniability, would be fooled.
  5. Plausible Deniability in Legal Context: Filiol connects his technical work directly to the legal concept of plausible deniability, which allows one to deny anything believably, even in the face of apparent evidence. Encryption synthesis provides a powerful tool to generate such "believable lies" by producing counter-proofs or alternative interpretations of digital evidence, thereby introducing reasonable doubt in legal proceedings.

These findings collectively represent a significant advancement in the understanding and manipulation of cryptographic systems, with profound implications for digital forensics, legal systems, and the broader debate on privacy, security, and human rights.

Technical Deep Dive

▶ Watch: Contrasting justice principles: Blackstone vs. 'hang him' quote (7:40)

At the heart of Eric Filiol's presentation is the revolutionary concept of encryption synthesis, which redefines how we perceive and interact with encrypted data. To grasp this, it's crucial to first understand the traditional definition of a cryptosystem. As Filiol explains, a cryptosystem isn't just the encryption algorithm; it encompasses all components: the keys, the ciphertext, the plaintext, and the algorithm itself. In a standard cryptosystem, fixing the plaintext, algorithm, and key uniquely determines a single ciphertext. Filiol's innovation lies in relaxing these constraints, introducing degrees of freedom that allow for manipulation.

The core problem Filiol set out to solve was: given an arbitrary random sequence (a ciphertext C of length N), is it possible to design a deterministic algorithm E that, when used with different short keys (e.g., 128 or 256 bits, unlike the message-length keys of a one-time pad), can produce two or more distinct and intelligible plaintexts (e.g., P1 and P2)? The answer, previously an open problem until 2021, is a resounding "yes" with encryption synthesis. This means a single ciphertext can convincingly decrypt into P1 (e.g., proving innocence) with Key1, and into P2 (e.g., proving guilt) with Key2.

Filiol elaborates on the concept of plausible deniability, distinguishing its legal and cryptographic interpretations. Legally, it's the ability to "lie in a believable, convincing way" by building probative evidence while simultaneously disproving counter-proofs. Cryptographically, as defined by Canetti et al. in 1996, it aims to "undermine the attacker's confidence that the data is encrypted or that a given plaintext really exists." Existing deniable encryption systems, such as Rubberhose (Julian Assange's early work) and Shufflecake (from Kudelski Security), primarily focus on file systems or hidden partitions (like TrueCrypt and VeraCrypt). However, these systems have known weaknesses; research has shown it's possible to detect the existence of hidden partitions in VeraCrypt/TrueCrypt containers, proving the presence of multiple keys, thus compromising perfect deniability. Filiol's work specifically tackles the more challenging problem of deniability for a single file, without these detectable artifacts.

The general structure of encryption synthesis is based on stream ciphers, but crucially, it avoids the weaknesses of linear feedback shift registers (LFSRs) by employing nonlinear feedback shift registers (NLFSRs). The initial state of these NLFSRs is derived directly from the short key. The output of these NLFSRs, combined through an 8-bit combining function, then undergoes further transformation using substitution boxes (S-boxes) to increase nonlinearity and cryptographic strength. This process generates a pseudorandom sequence (keystream) that is then combined (typically XORed) with the ciphertext to produce the plaintext. The ingenious part is how the design of the NLFSRs, combining functions, and S-boxes allows the same ciphertext to be combined with different keystreams (generated from different keys) to yield different, pre-determined plaintexts.

Filiol's custom C framework is designed to generate these deniable encryption algorithms on purpose. The algorithms produced are deterministic and intended to be publicly analyzable, meaning they contain no hidden secret elements that would betray their deniable nature. The security of this approach is rigorously evaluated against various attack scenarios:

  • Key Recovery: Given P1, P2, and C, it is computationally intractable to retrieve Key1 and Key2.
  • Plaintext Discovery: Given P1 and C (or P2 and C), it is impossible to find the other plaintext (P2 or P1).
  • Deniability Detection: Crucially, analyzing the encryption algorithm itself should not allow an expert to suspect the presence of plausible deniability.

This framework extends beyond two plaintexts, allowing for a finite number of different plaintexts to be embedded within a single ciphertext. Filiol highlights a broad range of applications, including sophisticated malware attacks that decrypt differently based on detection of analysis environments (e.g., an innocent-looking program vs. a malicious payload) and anti-forensic techniques. The use of NLFSRs is key here, as they offer a vast mathematical space for constructing diverse feedback functions, making the underlying mechanism complex and difficult to reverse-engineer or detect.

Demo / Proof of Concept

▶ Watch: Defining digital evidence and cryptography's 'probative' power (9:50)

Eric Filiol's presentation moved from theory to compelling practical demonstrations, showcasing the power of encryption synthesis in manipulating digital evidence. He emphasized that these demos, performed with a compiled C framework, illustrate real algorithms designed to convince judges and experts in a forensic setting, where cryptographic proofs are often considered unassailable.

The demonstrations were structured around three illustrative cases:

  1. Multiple Plaintexts from a Single Ciphertext:
  • Scenario: Filiol presented a single, seemingly random ciphertext file.
  • Execution: Using his custom encryption synthesis program, he first applied a "most secret" password (a short key, slightly over 128 bits). The program successfully decrypted the ciphertext to reveal a perfectly intelligible plaintext in French.
  • Manipulation: Immediately after, using the same ciphertext file and the same program, but with a different "less secret" password (another short key), the ciphertext decrypted into an entirely different, yet equally coherent, plaintext, this time in English.
  • Implication: This demo vividly illustrated the core capability of encryption synthesis: generating multiple, distinct, and believable narratives from a single piece of encrypted data, depending solely on the key used. Filiol noted that this could be extended to three or four different plaintexts, expanding the potential for deception.
  1. Transforming VeraCrypt Containers with Different Cryptographic Properties and Metadata:
  • Scenario: This demo focused on manipulating VeraCrypt containers, which are commonly used for plausible deniability through hidden volumes. Filiol aimed to show how an "official" VeraCrypt container could be transformed into a "secret" one, complete with different cryptographic algorithms and manipulated metadata.
  • Execution:
  • An initial VeraCrypt container (named container0.vc) was presented. When mounted with its specific password ("password container zero"), its properties showed a cryptographic configuration of Serpent-Twofish-AES with SHA-512 for HMAC. Inside, an Excel file was found with specific author metadata (Joseph Jacob Kalakal and Scott, as read from the transcript).
  • Filiol then used his custom program with a "secret" short key (e.g., "another secret," slightly over 128 bits) to process the container0.vc file. This generated a new VeraCrypt container (target_file.vc).
  • When target_file.vc was mounted with its specific password ("password container one"), its properties were dramatically different: Keltic-Twofish for encryption and Triog for HMAC. This demonstrated that the same initial data could be made to appear as a container encrypted with entirely different, plausible algorithms.
  • Crucially, when the Excel file within this newly generated target_file.vc was opened, its author metadata had changed to "Colin Pin and Donald Trump."
  • Implication: This demo highlighted the ability to not only change the perceived content but also the underlying cryptographic parameters and even the metadata of files within encrypted containers, making forensic analysis extremely challenging and susceptible to misinterpretation. It demonstrated how an expert could be led to believe they are analyzing one type of container with specific algorithms, while an entirely different, hidden reality exists.
  1. From Innocent-Looking File to Secret VeraCrypt Container:
  • Scenario: This final demo, described as the "most perverse," showed the reverse process: transforming an innocuous file (a PDF) into a VeraCrypt container that, with a specific key, revealed secret information.
  • Execution:
  • An ordinary scientific PDF paper was shown, appearing as a standard, unencrypted document.
  • Using the encryption synthesis program with a "one more secret" key, this PDF file was processed to generate a target_file.vc (a VeraCrypt container).
  • When this target_file.vc was mounted with the appropriate password, it revealed a "secret" PDF document, which, as Filiol humorously noted, was a document alleging a US attack on French presidency computers.
  • Implication: This demonstrated the ultimate potential for stealth and deniability. An attacker could disseminate an innocent-looking file that, unknown to most, functions as a highly deniable container for sensitive or incriminating data. This technique could be used to hide communications, operational plans, or even evidence of wrongdoing in plain sight.

Filiol also briefly mentioned the role of Open Source Intelligence (OSINT) in crafting believable scenarios for these demos. For instance, using a defendant's secret mistress's surname as a hidden password, or employing leaked passwords from databases, could strengthen the "probative power" of the forged evidence, making it even more convincing to an expert or judge. The demonstrations underscore Filiol's core message: digital evidence is inherently manipulable, and absolute trust in its veracity is dangerously misplaced.

Defensive Implications

▶ Watch: Expert limitations: Simple techniques and poor crypto implementations (11:20)

Eric Filiol's work on encryption synthesis and the manipulation of digital evidence carries profound implications for defenders, necessitating a fundamental shift in how digital forensics and legal processes are approached. The primary defensive implication is a stark warning: digital evidence, particularly cryptographic proof, can no longer be blindly trusted as absolute truth.

  1. Re-evaluate Digital Evidence & Forensic Methodologies: Defenders, whether in law enforcement, corporate security, or human rights advocacy, must adopt a mindset of extreme skepticism towards any digital artifact presented as evidence. This includes metadata, temporary files, erased data, and especially encrypted content. Forensic methodologies need to evolve beyond simple decryption or metadata analysis to incorporate advanced cryptanalytic techniques capable of detecting subtle manipulations or the presence of deniable cryptography. The assumption that a decrypted plaintext is the only possible plaintext is now fundamentally challenged.
  2. Enhance Cryptographic Expertise: The talk explicitly highlights a critical gap: "many forensic experts are not competent enough in some areas, for example, cryptography." This needs to change. Law enforcement and forensic labs must invest heavily in training and hiring experts with deep knowledge of cryptanalysis, not just crypto-tool operation. These experts need to understand the mathematical underpinnings of modern cryptography, including nonlinear feedback shift registers, combining functions, and S-box design, to potentially identify Filiol's encryption synthesis or similar techniques. Without this, they remain vulnerable to being "easily fooled."
  3. Awareness of Actor Capabilities and Intent: Defenders must recognize that various actors – from sophisticated criminals and state-sponsored groups to prosecutors in certain legal systems – may employ advanced techniques to manipulate evidence. This awareness is crucial when assessing the provenance and authenticity of digital evidence, especially in cases with high stakes or political implications. The UN Cybercrime Convention, as highlighted by Filiol, presents a future where states might legally compel access or generate "evidence," making this capability even more dangerous.
  4. Strengthen Digital Chain of Custody and Integrity Verification: While encryption synthesis allows for multiple interpretations of a single file, robust digital chain of custody and integrity verification mechanisms (e.g., cryptographic hashing, digital signatures, blockchain-based notarization) remain vital. However, even these might be subverted if the initial "innocent" file is already a product of synthesis. Therefore, the focus must shift to verifying the process of evidence collection and analysis for any signs of tampering or the introduction of synthesized data.
  5. Advocate for Strong, Transparent Cryptography: Filiol, a "strong defender of free crypto," emphasizes the dilemma: how to guarantee freedom for citizens using strong crypto while managing its criminal use. Defenders must continue to advocate for the fundamental right to use strong, transparent, and auditable cryptographic tools that are free from backdoors or intentional vulnerabilities. The danger of governments enforcing backdoors is that these will inevitably be exploited by criminals and malicious actors first, thereby weakening the entire security ecosystem.
  6. Public and Citizen Education: The talk concludes with a call to action at the "citizens' level." Individuals must be educated about the importance of strong cryptography for protecting human rights and freedom. At the same time, they must understand the dual-use nature of crypto and the potential for its misuse. This public awareness is essential to push back against restrictive policies (like the UN Cybercrime Convention) that could undermine privacy and facilitate evidence manipulation by authoritarian regimes.
  7. Proactive Research into Counter-Techniques: Filiol's ongoing work on mathematical backdoors in encryption (e.g., his Black Hat 2017 AES-like algorithm with a backdoor) suggests that the research community needs to proactively investigate such vulnerabilities. Understanding how to build these sophisticated manipulation techniques is the first step towards developing robust detection and counter-measures. This includes exploring detection methods for deniable cryptography in single files and adapting existing tools like TC hunt/TC file detector for new forms of deniability.

In essence, Filiol's work demands that defenders move beyond superficial analysis and develop a deep, critical understanding of cryptographic principles and their potential for subversion. The "digital evil dance" he describes is a complex ballet of manipulation, requiring an equally sophisticated and vigilant defense.

Key Takeaways

  • Digital Evidence is Not Absolute: The talk fundamentally challenges the assumption that digital evidence, especially cryptographic proof, is inherently trustworthy. It can be deliberately crafted and manipulated.
  • Encryption Synthesis is Real: Eric Filiol has developed and demonstrated "encryption synthesis," a novel form of deniable cryptography that allows a single ciphertext to decrypt into multiple, distinct, and plausible plaintexts using different, short, deterministic keys.
  • Single-File Deniability Solved: This work solves the long-standing problem of achieving plausible deniability for a single encrypted file, unlike previous methods that focused on entire file systems or hidden partitions.
  • Exploiting Forensic Gaps: Many forensic experts lack sufficient cryptographic expertise, making them vulnerable to being fooled by sophisticated manipulation techniques involving metadata, erased data, and encryption synthesis.
  • Profound Implications for Justice: The ability to generate contradictory yet convincing digital evidence can introduce "reasonable doubt" in democratic legal systems or be weaponized for framing individuals in authoritarian regimes.
  • Call for Criticality and Strong Crypto: There's an urgent need for critical thinking when assessing digital evidence, enhanced cryptographic expertise in forensics, and a continued defense of strong, free, and transparent cryptography for citizens. The UN Cybercrime Convention poses a significant threat to these principles.

About the Speaker(s)

Eric Filiol is a distinguished figure in the fields of mathematics, cryptography, and cybersecurity. He possesses a unique blend of theoretical expertise and practical implementation experience, stating, "I'm fond of mathematics but from Theory until implementation because it's very funny to to try to find mathematical solution and then to implement that and to to observe that it works very well."

His extensive background includes:

  • Mathematical Engineering: He developed the core work on encryption synthesis for a mathematical engineering company in 2021.
  • Forensic Expertise: Filiol has served as a forensic expert for the Paris SC (Court of Appeals), particularly in cases related to terrorism, giving him direct insight into how digital evidence is handled in legal contexts.
  • Military Cryptoanalysis: He spent over 20 years in the French Army, where he was involved in military cryptoanalysis. This experience has deeply informed his research and understanding of cryptographic systems and their vulnerabilities.

Filiol's work, as demonstrated in this talk, draws heavily from his practical experience in analyzing and breaking encryption, as well as his deep theoretical understanding of mathematics. He is a strong advocate for free and strong cryptography but also acknowledges the complex challenges posed by its criminal use. His research extends to areas like mathematical backdoors in encryption, having previously published on an AES-like algorithm with a backdoor at Black Hat 2017.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Filiol presents original, working research on single-file deniable cryptography — a problem that was genuinely open — and connects it directly to forensic and legal real-world consequences with live demos. The theoretical contribution is solid, the attack surface is underexplored, and the implications for digital forensics are serious enough that this talk deserves a room.

Heather Calloway (CISO) — WEAK

Filiol presents genuine cryptographic research with real legal implications, but the talk is structured as a technical showcase rather than an operational brief. The institutional and governance consequences — who is accountable, what policies need to change, what forensic labs should do Monday morning — are gestured at but never made actionable for the people who most need to hear this.

→ Top-rated talks at 44CON 2024

All talks from 44CON 2024