Live data from Hacker News

"Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

cryptome.org

21–30 of 62 posts

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#21
post #5

Page 16 has some wonderful lines: • “Fruit of the poisonous tree” can be circumvented • The use of backdoors cannot be detected or proven • Vendors are legally and commercially prevented from acknowledging their backdoors. Defense will not be able to prove their existence • The files can be described as “forensically obtained”

...but how is the prosecution able to prove the files exist on someone's device if they don't have to disclose how they determined that the files were present? If all they have to do is assert that the files exist and were "forensically obtained" then why bother with the backdoor in the first place?

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#23
post #7
post #2

Wouldn't any backdoor used in a criminal prosecution have to be disclosed to the defense?

Scroll down a bit; all they have to disclose is that the files "were forensically obtained."

I saw that, but I still don't see how that works in a trial. Said evidence will need to be introduced in court. When the witness tries to be cute by giving a vague answer, can't the defense just ask the witness to explain further?

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#24

Worth mentioning that truecrypt volumes can be hidden inside playable video files. Yes, it's security through obscurity, but hey, it makes me feel a little safer. http://keyj.emphy.de/real-steganography-with-truecrypt/

Mentioning a steganographic technique implies that you use it, negating the point.

*speaking hypothetically of course.

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#25

Worth mentioning that truecrypt volumes can be hidden inside playable video files. Yes, it's security through obscurity, but hey, it makes me feel a little safer. http://keyj.emphy.de/real-steganography-with-truecrypt/

Mentioning a steganographic technique implies that you use it, negating the point.

Not completely. How many video files does he have? Where is it stored?

I'm curious now though, do Truecrypt volumes have a magic number, in which case it's still easy to find, or are they fully crypographically random in appearance, making this a known-needle in a large haystack problem?

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#27
post #13

This really doesn't sound legit. I suspect they might be thinking of backdooring the truecrypt client , which, really wouldn't make it much of a feat. The container format itself is really just a giant mathematical mess -- there really isn't anything to backdoor there. And then the client doesn't exactly dial-out to anything when you mount an encrypted volume. Therefore I would suggest that this is probably a matter…

> The container format itself is really just a giant mathematical mess -- there really isn't anything to backdoor there.

The container itself can actually be 'backdoored' by a malicious client by eg saving a duplicate of the master key, or generating a master key using a deliberately weak RNG.

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#28
post #13

This really doesn't sound legit. I suspect they might be thinking of backdooring the truecrypt client , which, really wouldn't make it much of a feat. The container format itself is really just a giant mathematical mess -- there really isn't anything to backdoor there. And then the client doesn't exactly dial-out to anything when you mount an encrypted volume. Therefore I would suggest that this is probably a matter…

user: xarball created: 2 minutes ago Any reason you're using a throwaway?

Israel hires pro-government internet commenters, it'll come out that the US does as well soon, just like everything Israel does "first"

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#29
The reference to the names "Detective Stu Pitt" and "Detective Laughlin Foo" on the last page has me wondering about this. They both really, really sound like joke names. The similarity to the presenter's name (first slide) from the real North Dakota State Attorney's Association (NDSAA) presentation (http://www.ndsaa.org/Computer_Forensics_for_Prosecutors.pdf) also seems suspicious.

It has the look that somebody took the real NDSAA presentation, tweaked it up, and released it as a hoax.

Edit:

Here's a site that seems to be hosting the same PDF as part of an article dated 1 April 2013: http://www.techarp.com/showarticle.aspx?artno=770

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#30

A few gems in here besides the TrueCrypt statement, mainly that Apple iCloud and Dropbox are named, and the legal framework is touched upon. All cloud stored content are automatically hash-scanned and image-analyzed by their service providers and infringing content reported to NCMEC (p16) Mobile content are automatically scanned when they are synced with cloud storage like Apple iCloud or Dropbox. Mobile devices that…

They also said image-analyzed. This person uploaded photographs he took himself to his private Skydrive, and got his account flagged, so what does that tell you:

http://wmpoweruser.com/microsoft-monitoring-censoring-skydri...

Post reply on HN