Live data from Hacker News

Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock

github.com

21–30 of 120 posts

Re: Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock

#21

Neat idea. I remember way back in the day, there was some question as to the legality of compelled unlocking of devices; IIRC, it’s been deemed legal to compel a fingerprint, but illegal (under the first amendment?) to compel entry of a password—IIRC, as long as that password hasn’t been written down anywhere. I gather this is written to that end primarily? Or is there some other goal as well?

Take it to the logical end - you can tie up / handcuff / sedate / restrain an individual in order to get their fingerprint (or, ahem, way worse) but you cannot extract a password from someones brain.

Re: Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock

#22

PSA to iOS users: if you tap the lock button 5x it forces password-only unlocking. Useful at protests or any precarious situations with law enforcement.

This still leaves your device in an AFU (after first unlock) state, with user data decrypted, and should not be treated as secure. The only thing you can do (to protect your data from forensics, etc) is to return it to BFU by shutting it off.

Better than nothing and keeps them from having unlocked access. You can do it fast in your pocket.

Re: Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock

#23

PSA to iOS users: if you tap the lock button 5x it forces password-only unlocking. Useful at protests or any precarious situations with law enforcement.

This still leaves your device in an AFU (after first unlock) state, with user data decrypted, and should not be treated as secure. The only thing you can do (to protect your data from forensics, etc) is to return it to BFU by shutting it off.

Correct. This is a classic security vs convenience tradeoff. I mention that trade off on the landing page, PanicLock vs Shutdown

> Use shutdown when you can, PanicLock when you can't. Shutting down is the most secure option—but when you need your Mac locked now and you'll be back in five minutes, PanicLock is your answer.

*PanicLock* - Fast "oh shit" button - Lid closed when in transit. - Instant lock (1 second). Disables Touch ID immediately - Preserves your session - Back to work in minutes

*Full Shutdown* - Maximum security - Purges encryption keys - Fully locks FileVault - Takes time to shutdown & restart - Kills your session

Re: Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock

#24

Neat idea. I remember way back in the day, there was some question as to the legality of compelled unlocking of devices; IIRC, it’s been deemed legal to compel a fingerprint, but illegal (under the first amendment?) to compel entry of a password—IIRC, as long as that password hasn’t been written down anywhere. I gather this is written to that end primarily? Or is there some other goal as well?

[deleted]

Re: Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock

#25

Neat idea. I remember way back in the day, there was some question as to the legality of compelled unlocking of devices; IIRC, it’s been deemed legal to compel a fingerprint, but illegal (under the first amendment?) to compel entry of a password—IIRC, as long as that password hasn’t been written down anywhere. I gather this is written to that end primarily? Or is there some other goal as well?

Take it to the logical end - you can tie up / handcuff / sedate / restrain an individual in order to get their fingerprint (or, ahem, way worse) but you cannot extract a password from someones brain.

If it's in scope to "way worse" someone to get their fingerprint, I'm sure I can be very persuasive in getting their passwords.

Re: Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock

#26

Neat idea. I remember way back in the day, there was some question as to the legality of compelled unlocking of devices; IIRC, it’s been deemed legal to compel a fingerprint, but illegal (under the first amendment?) to compel entry of a password—IIRC, as long as that password hasn’t been written down anywhere. I gather this is written to that end primarily? Or is there some other goal as well?

While it's true that the legality of law enforcement forcing passwords in unclear, courts can absolutely force you to enter a password even if it's not written down by holding you in contempt indefinitely.

>courts can absolutely force you to enter a password even if it's not written down by holding you in contempt indefinitely.

This is not true outside of a narrow exception. Indeed this is the core point of the 5th Amendment, to protect you from having to be witness against yourself. It's just as binding on the judicial branch as it is on the executive. Ordinarily, a court may not compel a defendant to testify or say something that could incriminate them.

The narrow exception is the "foregone conclusion doctrine", which allows compelling testimony about specific evidence the government legally knows exists, knows the defendant controls access to, and knows is authentic. All of which has a bunch of caselaw around it. The textbook example is somebody has a device open, and an officer directly witnesses illegal material on it, but before they can seize it the person manages to turn it off and now it cannot be accessed without a password. So the government can say "we witnessed this specific illegal material, and this device is owned by the defendant and we can prove from video that they have accessed the device, and we want access to that specific material". But if you're just crossing the border with a locked device, they cannot compel the password just to search through it, or even if they're suspicious of something specific. They need actual knowledge, either through their own evidence or because the person foolishly talks and confesses something.

Otherwise they can definitely physically seize the device for a time (which could be very inconvenient/expensive depending) but that's it.

Re: Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock

#27

Neat idea. I remember way back in the day, there was some question as to the legality of compelled unlocking of devices; IIRC, it’s been deemed legal to compel a fingerprint, but illegal (under the first amendment?) to compel entry of a password—IIRC, as long as that password hasn’t been written down anywhere. I gather this is written to that end primarily? Or is there some other goal as well?

Take it to the logical end - you can tie up / handcuff / sedate / restrain an individual in order to get their fingerprint (or, ahem, way worse) but you cannot extract a password from someones brain.

> cannot extract a password from someones brain.

May I introduce you to XKCD Number 538.

https://xkcd.com/538

Re: Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock

#28
This would be perfect if it could monitor the force with which the lid is closed (macs have accelerometers after all, either this info or an acceptable proxy could be derived?).

Gently close? no action.

Stronger, faster action? Disable touch ID

Slam shut in full panic? yeah disable all biometrics, lose all state, even wipe the ram and the filevault key if it's an option

Re: Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock

#29
post #25

Earlier quoted context omitted.

Take it to the logical end - you can tie up / handcuff / sedate / restrain an individual in order to get their fingerprint (or, ahem, way worse) but you cannot extract a password from someones brain.

If it's in scope to "way worse" someone to get their fingerprint, I'm sure I can be very persuasive in getting their passwords.

You can get the fingerprint of a dead person... you cannot extract a password from a dead person.

Re: Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock

#30
post #25

Earlier quoted context omitted.

If it's in scope to "way worse" someone to get their fingerprint, I'm sure I can be very persuasive in getting their passwords.

You can get the fingerprint of a dead person... you cannot extract a password from a dead person.

Of course not. You extract it right before.
Post reply on HN