Live data from Hacker News

Deniability and Duress

mit.edu

11–20 of 124 posts

Re: Deniability and Duress

#11
iPhones require the password(/code) when turned on and (IIRC) under certain other conditions.

But I believe this isn't enough considering recent developments. They write:

    It’s important to note that deniability refers to the
    ability to deny some plaintext, not the ability to deny 
    that you’re using a deniable algorithm.
It's now common for border agents in the US to demand login credentials for social media accounts, and search all electronic devises. I can't think of anything more invasive than someone going through my photos and messages. Yet many people are required to visit the US (or countries only reachable via the US). We need methods to separate data into two parts, one being highly private and completely hidden from someone given access to our devises.

And while I would welcome a technical solution, it's important not to discount the power of the law. Such invasions of privacy would be illegal in the EU, and contrary to the cynics, laws are generally respected in the developed world. The current news are making me hopeful that (parts of) the US population are also starting to be sympathetic to some rights of foreigners even when they're applying for the privilege of crossing the border.

Re: Deniability and Duress

#12

iPhones require the password(/code) when turned on and (IIRC) under certain other conditions. But I believe this isn't enough considering recent developments. They write: It’s important to note that deniability refers to the ability to deny some plaintext, not the ability to deny that you’re using a deniable algorithm. It's now common for border agents in the US to demand login credentials for social media accounts,…

> It's now common for border agents in the US to demand login credentials for social media accounts, and search all electronic devises.

Can you define common?

Re: Deniability and Duress

#13
post #8

Earlier quoted context omitted.

Why shouldn't it have any apps on it? From my understanding, the point is that the crucial subset of user data is not available in that usage mode.

The malicious actor would find it very suspicious (especially if/when these features are in popular platforms and thus widely known), breaking the deniability.

It's your own responsibility to tailor this "clean" state to your liking and make it look like you use it.

Re: Deniability and Duress

#14

iPhones require the password(/code) when turned on and (IIRC) under certain other conditions. But I believe this isn't enough considering recent developments. They write: It’s important to note that deniability refers to the ability to deny some plaintext, not the ability to deny that you’re using a deniable algorithm. It's now common for border agents in the US to demand login credentials for social media accounts,…

> It's now common for border agents in the US to demand login credentials for social media accounts, and search all electronic devises. Can you define common?

The ESTA form asks for social media accounts (though not passwords, and ostensibly providing the accounts is "optional"): https://esta.cbp.dhs.gov/esta/

Re: Deniability and Duress

#15

iPhones require the password(/code) when turned on and (IIRC) under certain other conditions. But I believe this isn't enough considering recent developments. They write: It’s important to note that deniability refers to the ability to deny some plaintext, not the ability to deny that you’re using a deniable algorithm. It's now common for border agents in the US to demand login credentials for social media accounts,…

> It's now common for border agents in the US to demand login credentials for social media accounts, and search all electronic devises. Can you define common?

Requesting account names is already common practice: http://www.politico.com/story/2016/12/foreign-travelers-soci.... That does not include passwords, and it's "voluntary". But having filled out US immigration forms a few times (and watched others doing it), the process is quite intimidating and many will be pressured into providing that data. Why else would they? There is no upside to the US gov having that data for me.

With regards to passwords, I don't have numbers, but have seen a few dozen reports over the years without actively looking for them and knowing someone personally to whom it happened (he refused and was allowed entry after a few hours). And whatever is currently discussed would probably include it, considering the San Bernadino case they cite as justification involved information shared with strict privacy setting:

https://www.google.de/search?client=safari&rls=en&q=us+askin...

Re: Deniability and Duress

#16
post #9

The worst thing to do, when facing rubber hoses, or legalistic equivalents thereof, is to lie. Especially if you're not a well-trained lier. And especially if there may be independent evidence that would trip you up. The best option is having nothing to hide. When crossing hazardous borders, sensitive stuff should be securely in the cloud. And when coercion is likely, a third party should control access to it.

Except that travellers may be (and sometimes are being) asked for login credentials to online accounts.

Re: Deniability and Duress

#17
post #16
post #9

The worst thing to do, when facing rubber hoses, or legalistic equivalents thereof, is to lie. Especially if you're not a well-trained lier. And especially if there may be independent evidence that would trip you up. The best option is having nothing to hide. When crossing hazardous borders, sensitive stuff should be securely in the cloud. And when coercion is likely, a third party should control access to it.

Except that travellers may be (and sometimes are being) asked for login credentials to online accounts.

I don't mean normal online accounts. I mean something like the WikiLeaks upload site.[0] Once stuff is uploaded, you don't have control, or even access.

0) http://wlupld3ptjvsgwqw.onion

Re: Deniability and Duress

#18
The takeaway for me: US law enforcement can compel you to provide a fingerprint to unlock your phone, but cannot compel you to provide a password.

In particular, a recent precedent-setting court case in Minnesota has decided that fingerprints used for access control can be taken from a suspect without violating his fifth amendment rights. The logic of the decision [...] is that fingerprints are tantamount to similar evidence that is taken from suspects in the course of an investigation such as blood samples, handwriting samples, voice recordings, etc., all of which have been deemed by the Supreme Court to not be protected under the Fifth Amendment.

Re: Deniability and Duress

#19
post #18

The takeaway for me: US law enforcement can compel you to provide a fingerprint to unlock your phone, but cannot compel you to provide a password. In particular, a recent precedent-setting court case in Minnesota has decided that fingerprints used for access control can be taken from a suspect without violating his fifth amendment rights. The logic of the decision [...] is that fingerprints are tantamount to similar…

> US law enforcement can compel you to provide a fingerprint to unlock your phone, but cannot compel you to provide a password.

This may be true for normal law enforcement, but if you're at (or perhaps near) the border, the rules are different.

Re: Deniability and Duress

#20

iPhones require the password(/code) when turned on and (IIRC) under certain other conditions. But I believe this isn't enough considering recent developments. They write: It’s important to note that deniability refers to the ability to deny some plaintext, not the ability to deny that you’re using a deniable algorithm. It's now common for border agents in the US to demand login credentials for social media accounts,…

I wish EU and other non-US countries would offer "US-border treatment" to all US citizens when they enter, and normal border control when they leave.

That way they could maybe get an idea on how unfriendly, impolite, invasive and denigrating it actually is. And then when leaving get the idea that border agents can be helpful and friendly too.

Edit: And oh yes, all communication and paperwork is done in the language of the destination country.

Post reply on HN