Live data from Hacker News

Deniability and Duress

mit.edu

31–40 of 124 posts

Re: Deniability and Duress

#31

Android had user profiles for a while. If you associate different fingerprints or different pin codes with different accounts, you can have your sneaky account with all the warcrime photos and the "open" account which is full of dick pics and selfies, as per usual. Almost no new technology required. This all assumes the border guard is simply going to go through texts, pictures and maybe open up a facebook or similar…

'had'? My android device has user profiles.

Re: Deniability and Duress

#32
post #30

> Scanning a pinky (or some other fingerprint / combination of fingerprints) might cause the phone to factory reset, or unlock and trigger deletion a specified portion of user data. IANAL, but AFAIK there is a strict line between not providing incriminating evidence (legal, protected under 5th Amendment) and destroying evidence (criminal).

My iPhone forces password entry after 5 failed attempts at TouchID unlock. If you can quickly thumb the sensor a few times, you can render fingerprint unlock impossible.

Better to disable anyway, but it's an option.

Re: Deniability and Duress

#33
post #30

> Scanning a pinky (or some other fingerprint / combination of fingerprints) might cause the phone to factory reset, or unlock and trigger deletion a specified portion of user data. IANAL, but AFAIK there is a strict line between not providing incriminating evidence (legal, protected under 5th Amendment) and destroying evidence (criminal).

I immediately thought the same thing upon reading. One thing that comes to mind is: automatically triggered data destruction. If laptop or the phone detects non-owner access attempts and destroys data on its own, is it destruction of evidence? Owner did not do it, and it was there just to protect from the real bad guys: corporate spies, identity thieves.

Re: Deniability and Duress

#35
post #30

> Scanning a pinky (or some other fingerprint / combination of fingerprints) might cause the phone to factory reset, or unlock and trigger deletion a specified portion of user data. IANAL, but AFAIK there is a strict line between not providing incriminating evidence (legal, protected under 5th Amendment) and destroying evidence (criminal).

If you are a terrible person with really weird requirements you might prefer the charges related to destruction of evidence to the charges related to the evidence itself.

(if you are a terrible person without really weird requirements you avoid capturing or destroy the evidence on an ongoing basis, not after you are caught)

Re: Deniability and Duress

#36
I travel to the US semi-regularly. I never have trouble. Though it's a shame to have to mention it, I was born in the UK and have white skin. My colleague, who was also born in the UK but has darker skin, was detained for half an hour last time we crossed the border.

I'm a classic "nothing to hide". But I am seriously considering taking no electronics with me next time I cross the border. Might make work more of a hassle, but I'm sure it's doable.

Re: Deniability and Duress

#37

iPhones require the password(/code) when turned on and (IIRC) under certain other conditions. But I believe this isn't enough considering recent developments. They write: It’s important to note that deniability refers to the ability to deny some plaintext, not the ability to deny that you’re using a deniable algorithm. It's now common for border agents in the US to demand login credentials for social media accounts,…

I wish EU and other non-US countries would offer "US-border treatment" to all US citizens when they enter, and normal border control when they leave. That way they could maybe get an idea on how unfriendly, impolite, invasive and denigrating it actually is. And then when leaving get the idea that border agents can be helpful and friendly too. Edit: And oh yes, all communication and paperwork is done in the language o…

i feel sympathy for the idea, but it kinda undermines the case against these practices. If we're saying "terrorism" isn't enough of a reason for wide-scale privacy invasion, how could "getting the US to change its policy" ever be enough? Additionally, it's an individual's rights being infringed, almost none of whom have influence on policy beyond voting, and the vast majority of whom, belonging to the subset of Americans traveling to Europe, didn't even vote for Trump.

Re: Deniability and Duress

#38
post #9

The worst thing to do, when facing rubber hoses, or legalistic equivalents thereof, is to lie. Especially if you're not a well-trained lier. And especially if there may be independent evidence that would trip you up. The best option is having nothing to hide. When crossing hazardous borders, sensitive stuff should be securely in the cloud. And when coercion is likely, a third party should control access to it.

> securely in the cloud isn't this a contradiction? Given how the NSA and co have backdoors in the cloud and such, and can order the operators of said cloud service to release information from their users. If you have sensitive stuff, best not to cross any borders I'd say. Stay away from the US.

Consider SpiderOak or similar things that encrypt data on the client side and never upload the key.

Re: Deniability and Duress

#39
post #18

The takeaway for me: US law enforcement can compel you to provide a fingerprint to unlock your phone, but cannot compel you to provide a password. In particular, a recent precedent-setting court case in Minnesota has decided that fingerprints used for access control can be taken from a suspect without violating his fifth amendment rights. The logic of the decision [...] is that fingerprints are tantamount to similar…

> US law enforcement can compel you to provide a fingerprint to unlock your phone, but cannot compel you to provide a password. This may be true for normal law enforcement, but if you're at (or perhaps near) the border, the rules are different.

It's been pointed out recently that "near the border" is "100 miles from the border" and the coastline counts as border, so the rules are different for most places in the USA where people actually live.

Re: Deniability and Duress

#40

FTA: > If it isn’t baked-in to the operating system, the fact that the journalist was using some out-of-the-ordinary software itself, which may or may not have undeniable tells, would likely be a red flag and induce liberal use of the rubber hose. This is in fact a thought that I've had about Truecrypt/Veracrypt: given a user, it seems the probability of them having a hidden volume is high. It might be deniable in th…

Yes, that's why everyone should be using it.
Post reply on HN