Live data from Hacker News

PAM Duress – Alternate passwords for panic situations

github.com

151–160 of 358 posts

Re: PAM Duress – Alternate passwords for panic situations

#151

Earlier quoted context omitted.

Using #3 could land you in jail indefinitely in the UK I believe: if they don’t believe you forgot the password, they can interpret that as a refusal to give them the password (or unlock the computer), and jail you for this… until you give them the password. Which you can’t, because there is no password at this point. So either you admit that you just wiped your computer with the panic password, or you can shut up an…

So in the UK they can put you in prison for life without being charged or found guilty of any crime unless “they believe you”? Any source on that?

A story from the US:

https://nakedsecurity.sophos.com/2016/04/28/suspect-who-wont...

Re: PAM Duress – Alternate passwords for panic situations

#152
post #63

Earlier quoted context omitted.

Somebody mandates using biometric identification instead of a PIN?!?

Biometric passports: https://www.dhs.gov/e-passports Face ID: https://support.apple.com/en-us/HT208109 Fingerprint Readers: https://www.samsung.com/us/support/answer/ANS00082563/ These are extant, and either part of or required within numerous presently-used systems.

Sure, but nobody can pre-emptively mandate you use facial recognition on your personal communications device, and then put sensitive information in there. I can see a situation in a repressive country where if you buy a phone they set it up with facial recognition in the store and make you activate it, but then you know not to store stuff there. You could just physically damage the camera at a later date and claim you weren't able to make use of that any more.

Re: PAM Duress – Alternate passwords for panic situations

#153
post #79

Earlier quoted context omitted.

An interesting way to use this PAM-Duress system would be to write a program that (a) begins recording your microphone and webcam video immediately upon login (b) Aggressively try the hell out of every passwordless Wi-Fi network it can detect, then use headless chrome to aggressively smack every button to get past the stupid login pages (c) Stream that video and audio to a server that saves it.

Use Emergency SOS on your iPhone https://support.apple.com/en-us/HT208076

There's also (for Aus users), Emergency+

https://play.google.com/store/apps/details?id=com.threesixty...

Re: PAM Duress – Alternate passwords for panic situations

#154
post #75

There are multiple levels of protection one might want. I.e. when you are being selected for random questioning entering US as a non-US citizen, you'd benefit from steganography-like approach: you give a password, and relatively bland, non-personal stuff shows up, giving appearance of full access to a system. If you only care about your privacy, the next one is to have a destroy-everything script (and it's not that h…

I love multiple accounts in Android. When at airport I can switch to non personal account and show anything they want

What do they ask you to show them at airports?

Re: PAM Duress – Alternate passwords for panic situations

#155
post #154

Earlier quoted context omitted.

I love multiple accounts in Android. When at airport I can switch to non personal account and show anything they want

What do they ask you to show them at airports?

Text messages, maybe photos

Re: PAM Duress – Alternate passwords for panic situations

#156
post #79

Training is very important in duress systems. I once worked in a place with a keypad duress code on the security system. If you prefixed your security PIN with NN-, it was the duress version of the code and would trigger a silent alarm. This was setup long-ago, and not communicated. One night, the keypad was acting glitchy. Partially out of frustration (countdown is running), and partially to test, I ended up acciden…

An interesting way to use this PAM-Duress system would be to write a program that (a) begins recording your microphone and webcam video immediately upon login (b) Aggressively try the hell out of every passwordless Wi-Fi network it can detect, then use headless chrome to aggressively smack every button to get past the stupid login pages (c) Stream that video and audio to a server that saves it.

> begins recording your microphone and webcam video immediately upon login

If your camera has an activity light, this might inadvertently worsen your situation.

Re: PAM Duress – Alternate passwords for panic situations

#157
post #154

Earlier quoted context omitted.

What do they ask you to show them at airports?

Text messages, maybe photos

Which countries do this? I am pretty sure TSA can only ask you to demonstrate the device functions as intended, usually by powering it on.

Re: PAM Duress – Alternate passwords for panic situations

#159

Earlier quoted context omitted.

Biometric passports: https://www.dhs.gov/e-passports Face ID: https://support.apple.com/en-us/HT208109 Fingerprint Readers: https://www.samsung.com/us/support/answer/ANS00082563/ These are extant, and either part of or required within numerous presently-used systems.

Sure, but nobody can pre-emptively mandate you use facial recognition on your personal communications device, and then put sensitive information in there. I can see a situation in a repressive country where if you buy a phone they set it up with facial recognition in the store and make you activate it, but then you know not to store stuff there. You could just physically damage the camera at a later date and claim yo…

I'm nowhere near that sanguine about this.

I've a device (Onyx BOOX) which apparently can only be password-secured if I create a vendor-based account on it. (I've been trying to see if this is bypassable, so far, no dice.) That's not biometrics, but it's a case of being strongly limited by a system architecture.

If you're using a device at the obligation of an employer, you may well find that it has, and/or organisational policy requires, biometrics.

It's increasingly difficult to find devices that don't include some form of biometrics-based functionality. The notion that that becomes the primary or only means of securing access is not entirely far-fetched.

Capabilities, possibilities, and dependencies have a really funny way of becoming hard requirements over time.

I could speak the Celtic of my ancient ancestors or communicate in cuneiform or ancient Egyptian hyroglyphics, if really wanted to. My ability to integrate and participate in modern life would be quite limited. The online and digital world are rapidly approaching this state.

Re: PAM Duress – Alternate passwords for panic situations

#160
post #106

Earlier quoted context omitted.

I don't know the legal implications, but if the duress password unlocks your device and simply deletes a directory or two, and the officer only asked you to unlock your device (without a warrant, by the way), how is that lying?

Even if it isn't lying, it's destruction of evidence. 18 U.S. Code 1519: > Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed u…

Not clear. You can argue you were afraid for your life or property in the case you did not expect the agent or courts to react reasonably to the now-concealed information. As well, they would need to prove you concealed or destroyed information.

Similar case law exists in this context, but for actions like running from the police.

Post reply on HN