Live data from Hacker News

HiddenVM – Use any desktop OS without leaving a trace

github.com

21–30 of 44 posts

Re: HiddenVM – Use any desktop OS without leaving a trace

#21

> Imagine you're entering a country at the airport. The border agents seize your laptop and force you to unlock it If this concerned me I would just wipe the drive and/or factory reset the device before travelling, and restore it later, rather than try to experimentally figure out what games I can and can't play with the customs authorities.

This is the approach that people I trust recommend. Some go further: not only should you not take sensitive data across borders physically, you shouldn't rely on your devices (or undeveloped film, for that matter) not getting wiped at the airport.

FWIW, I have a colleague who worked at an office collaboration software firm that applied a "no company tech into China" to everyone.

Re: HiddenVM – Use any desktop OS without leaving a trace

#22

I’m not following what this gives you that Veracrypt's inbuilt hidden+decoy OS feature doesn't already? It seems they require you to manually set up a veracrypt hidden partition for anything to be "hidden" anyway. How is booting your encrypted partition in a VM within Tails more secure than booting it directly?

> How is booting your encrypted partition in a VM within Tails more secure than booting it directly? There will be no proof of an operating system existing at all, just random data. If you use VeraCrypt along with a hidden partition normally, you would still have the VeraCrypt bootloader or an apparent Windows installation on the drive.

After truecrypt 7.1a (I think), the canary vanished. After that, didn’t it become veracrypt? Did they ever add a canary or has there been research in showing it’s not backdoored?

Re: HiddenVM – Use any desktop OS without leaving a trace

#23

Earlier quoted context omitted.

> How is booting your encrypted partition in a VM within Tails more secure than booting it directly? There will be no proof of an operating system existing at all, just random data. If you use VeraCrypt along with a hidden partition normally, you would still have the VeraCrypt bootloader or an apparent Windows installation on the drive.

After truecrypt 7.1a (I think), the canary vanished. After that, didn’t it become veracrypt? Did they ever add a canary or has there been research in showing it’s not backdoored?

While it’s never been officially proven, there is a interesting story behind truecrypt. It was allegedly written by one guy (Paul Le Rou) who was a programmer turned cartel boss/gun/drug runner.

But back to your question, truecrypt was professionally audited and deemed “secure”, some issues were found but none that were back doors or significant. Shortly after(might have even been during) the audit truecrypt deleted all old versions and posted a weird message telling people to use bitlocker.

After some time veracrypt picked up the torch and has continued developing what was truecrypt.

Re: HiddenVM – Use any desktop OS without leaving a trace

#24

Nice one. I’ve been using Veracrypt for many years now, after the whole Truecrypt fiasco. Just one friendly advice… always have a decoy partition or decoy OS, otherwise it seems very suspicious to have a disk filled with random data ;-)

> otherwise it seems very suspicious to have a disk filled with random data ;-) You could always argue that the drive was previously "securely erased" and filled w/ random data and/or that it was "securely encrypted" with a key that was then destroyed?

There was an interesting talk at one edition of CCC that boiled down to saying those techniques work only if you have the right to remain silent. Which depends on the country you're in. And I heard that in the USA, even though you have the right to remain silent, they still have the right to put you in jail if you refuse to give out your key.

Re: HiddenVM – Use any desktop OS without leaving a trace

#27

  A CRYPTO NERD'S IMAGINATION:

  HIS LAPTOP'S ENCRYPTED.
  LET'S BUILD A MILLION-DOLLAR CLUSTER TO CRACK IT.

  NO GOOD! IT'S 4096-BIT RSA!

  BLAST! OUR EVIL PLAN IS FOILED!"
----

  WHAT WOULD ACTUALLY HAPPEN:

  HIS LAPTOP'S ENCRYPTED.
  DRUG HIM AND HIT HIM WITH THIS $5 WRENCH UNTIL HE TELLS US THE PASSWORD.
Note1: xkcd/538

Note2: I'm missing images on hacker news. I understand why they are absent here though

Re: HiddenVM – Use any desktop OS without leaving a trace

#29
post #24

Earlier quoted context omitted.

> otherwise it seems very suspicious to have a disk filled with random data ;-) You could always argue that the drive was previously "securely erased" and filled w/ random data and/or that it was "securely encrypted" with a key that was then destroyed?

There was an interesting talk at one edition of CCC that boiled down to saying those techniques work only if you have the right to remain silent. Which depends on the country you're in. And I heard that in the USA, even though you have the right to remain silent, they still have the right to put you in jail if you refuse to give out your key.

You're thinking the RIP Act in the UK where the police can get an order from a judge for you to turn over a key/passphrase and you need to either prove you don't know it or face up to two years in jail (five for cases of child abuse or national security).

I'm not American but I'm pretty sure no law like that in the US would be upheld at appeal, it's pretty directly conflicting with the 5th amendment.

Post reply on HN