This could result in serious personal harm if the individual(s) causing the duress sense something is up, which they almost certainly will if things start magically disappearing or locking up. You better make sure that whatever you are protecting with this is more important than your personal safety.
I think they would be more likely to notice that you did not put up enough fight. Most people are not great actors. Also, if you're being physically compelled to provide a passwords it seems your personal safety is already compromised.
PAM Duress – Alternate passwords for panic situations
61–70 of 358 posts
Re: PAM Duress – Alternate passwords for panic situations
#62Re: PAM Duress – Alternate passwords for panic situations
#63Re: PAM Duress – Alternate passwords for panic situations
#64Earlier quoted context omitted.
Practise.
Don't be that person, especially when you're wrong. Both forms are acceptable. "In Australian and British English, 'practise' is the verb and 'practice' is the noun. In American English, 'practice' is both the verb and the noun."
Re: PAM Duress – Alternate passwords for panic situations
#65It's a very cool idea, but I think it would be most useful if applied to things like phones. I suspect most people pressed for passwords, are using a GUI system.
Re: PAM Duress – Alternate passwords for panic situations
#66There's always a big issue with systems like this: Any sophisticated attacker will have an image of the machine he's trying to get into at hand to stop exactly what this pam module is trying to achieve from happening. All this would do is make you appear in a worse light to the deciding judge when it comes to trial or get your other kneecap shattered in a not so civil situation.
If your attacker has a full image of your system why are they bothering with duress?
In a jurisdiction that doesn’t adhere to the rule of law you are already screwed.
What people often don’t seem to comprehend is that if you get picked up by a “secret police” in the middle of the night it’s pretty much game over already.
Re: PAM Duress – Alternate passwords for panic situations
#67Earlier quoted context omitted.
They can try their luck again at having you give access.
The duress login shouldn't reveal that anything is happening, so they have no reason to suspect you're using such a feature at all. Thus there would be no reason to ask you to log in again, and even if they do, you can simply use the duress credentials a second time.
Re: PAM Duress – Alternate passwords for panic situations
#68Re: PAM Duress – Alternate passwords for panic situations
#69Re: PAM Duress – Alternate passwords for panic situations
#70Earlier quoted context omitted.
It would need to be baked into the OS. With FaceID, I guess I could use eyes crossed, as a queue.
I do not understand why any security concerned person would use biometric identification for anything, ever.
Security is all about threat models, and I can imagine quite a few scenarios where biometrics might fare better than passwords. Shoulder surfing and trivial passwords/PINs come to mind, for example.
And who said that it's biometrics vs. anything else? It's quite advisable to combine authentication factors.