Earlier quoted context omitted.
I don't know the legal implications, but if the duress password unlocks your device and simply deletes a directory or two, and the officer only asked you to unlock your device (without a warrant, by the way), how is that lying?
Despite rumors to the contrary, the police aren’t stupid. They are trained to ask questions in ways that elicit a confession or falsehood. The simplest example is asking “Do you know why I pulled you over?”. Typically, people spontaneously confess to speeding, sometimes they break down and admit that someone is wrapped up in a rug in the trunk. The courts have consistently ruled that customs is different and you can…
PAM Duress – Alternate passwords for panic situations
211–220 of 358 posts
Re: PAM Duress – Alternate passwords for panic situations
#212There's always a big issue with systems like this: Any sophisticated attacker will have an image of the machine he's trying to get into at hand to stop exactly what this pam module is trying to achieve from happening. All this would do is make you appear in a worse light to the deciding judge when it comes to trial or get your other kneecap shattered in a not so civil situation.
Re: PAM Duress – Alternate passwords for panic situations
#213Earlier quoted context omitted.
Tell them you feel uneasy giving out details over the phone to an inbound caller, hang up and call their service line directly. The only way you can be sure you are talking to your bank is if you are calling them.
Yeah that works, but it's usually time-consuming to get to the specific department that actually called. I wish these companies could route your call to their fraud dept if their fraud dept had just called you, but sadly this doesn't seem to have caught on yet.
Re: PAM Duress – Alternate passwords for panic situations
#214Earlier quoted context omitted.
I had a similar false trigger trying to make an international call from our office phones. I didn’t know the exact incantation of the prefix, but knew it was 9 for an outside line and at home I used 011 then the country code. That didn’t seem to work, so I thought maybe I needed to drop the zero, resulting in me inadvertently dialing 911 and hanging up when that didn’t give me the dial tone I expected. I found the ri…
I always find it crazy when systems make you dial 9 for an outside line, for this very reason. Did the same thing myself my first week in college. Got the police. Told them what I did and I could hear the eye-roll on the other end of the line, and was told I was the third person that day.
Re: PAM Duress – Alternate passwords for panic situations
#215Training is very important in duress systems. I once worked in a place with a keypad duress code on the security system. If you prefixed your security PIN with NN-, it was the duress version of the code and would trigger a silent alarm. This was setup long-ago, and not communicated. One night, the keypad was acting glitchy. Partially out of frustration (countdown is running), and partially to test, I ended up acciden…
I had a similar false trigger trying to make an international call from our office phones. I didn’t know the exact incantation of the prefix, but knew it was 9 for an outside line and at home I used 011 then the country code. That didn’t seem to work, so I thought maybe I needed to drop the zero, resulting in me inadvertently dialing 911 and hanging up when that didn’t give me the dial tone I expected. I found the ri…
Re: PAM Duress – Alternate passwords for panic situations
#216Earlier quoted context omitted.
I always find it crazy when systems make you dial 9 for an outside line, for this very reason. Did the same thing myself my first week in college. Got the police. Told them what I did and I could hear the eye-roll on the other end of the line, and was told I was the third person that day.
I'd always assumed (UK) that 9 was a deliberate choice to make it easier to dial the emergency number, 999, because you can just mash 9 until something happens. I guess if it's the same number in all other countries who have a range of emergency numbers, then that might not be the reason.
Re: PAM Duress – Alternate passwords for panic situations
#217There are multiple levels of protection one might want. I.e. when you are being selected for random questioning entering US as a non-US citizen, you'd benefit from steganography-like approach: you give a password, and relatively bland, non-personal stuff shows up, giving appearance of full access to a system. If you only care about your privacy, the next one is to have a destroy-everything script (and it's not that h…
> I.e. when you are being selected for random questioning entering US as a non-US citizen, you'd benefit from steganography-like approach: you give a password, and relatively bland, non-personal stuff shows up, giving appearance of full access to a system. Is there a practical way to implement this today with Linux? I know VeraCrypt supports hidden operating systems, but I think only Windows?
Re: PAM Duress – Alternate passwords for panic situations
#218Earlier quoted context omitted.
I worked at a place where the duress code was ROT5: 1234 was your normal access code, 6789 lerted security.
You're supposed to ROT5 mentally while in a state of high stress?
Re: PAM Duress – Alternate passwords for panic situations
#219Earlier quoted context omitted.
I'd always assumed (UK) that 9 was a deliberate choice to make it easier to dial the emergency number, 999, because you can just mash 9 until something happens. I guess if it's the same number in all other countries who have a range of emergency numbers, then that might not be the reason.
My working theory is that in old times phones had rotary dial instead of key pad. Number 1 was the longest to dial, 9 was the shortest (as I remember from childhood days). Thus, fastest way to dial 3 digit code was to use numbers with as much as 9 as possible (997,998,999).
Re: PAM Duress – Alternate passwords for panic situations
#220I hate when my bank calls me about something and then asks to confirm my identity prior to giving out details about my account. Even when I think I know what it is about (e.g., a transaction with my card was declined just before the phone call), I feel very strange giving out any information to an inbound caller. One thing I have thought about doing is providing mistaken information to the caller and see if they go a…
I mean, it's really their problem, isn't it?
If you need something from them, call their customer line and ask. If they need something from you, then they'll figure it out.
I had a financial institution call me one time and ask
"Is this nucleardog?"
"Yes."
"Alright, this is reallyfastwords can we start by verifying your date of birth?"
"No. You called me. I didn't even catch who you are. What can I help you with."
"I'm with really fast words. I can't tell you anything until I verify your identity."
"You called me. You verify your identity first."
"If you don't verify, then I can't tell you why I called!"
"That's fine."
There was a loooong pause before she finally decided on "Okay, what _day_ in June of 1985 were you born?" and apparently that was satisfactory.