Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

201–210 of 239 posts

Re: I recommend against using biometric identification

#201

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

Fuck, that is absolutely nauseating. What's worse is that trustworthy deniable encryption - which would solve this - is practically non-existent now that TrueCrypt is gone.

Eh... The prosecution claims, and the judge believes, that they have a list of files they expect to find on the drive. If he gives them a password and those files don't appear, the judge will conclude he gave them the wrong password, and he will stay put until the right password is produced.

Re: I recommend against using biometric identification

#203
post #149

Earlier quoted context omitted.

I think, at some point it gets to the Supreme court which will decide whether it's covered by the 5th amendment or not.

The answer is probably no. Requiring a person to unlock a device is not prohibited by the Fifth Amendment simply because the device contains incriminating information that would otherwise be inaccessible to police. If the police have a valid warrant to search your safe, you are generally required to unlock it for them, even if the safe contains evidence that incriminates you. If you are issued a valid subpoena to pro…

What checks exist to prevent police from planting a USB hard drive on an enemy of the state that's encrypted and then claiming the defendant won't decrypt the hard drive? The state would have a really easy time imprisoning him/her because the defendant would never be able to provide a key to decrypt it.

Re: I recommend against using biometric identification

#204

Earlier quoted context omitted.

Fuck, that is absolutely nauseating. What's worse is that trustworthy deniable encryption - which would solve this - is practically non-existent now that TrueCrypt is gone.

Eh... The prosecution claims, and the judge believes, that they have a list of files they expect to find on the drive. If he gives them a password and those files don't appear, the judge will conclude he gave them the wrong password, and he will stay put until the right password is produced.

So you mean, if he floats, he's a witch, and they burn him, and if he sinks, he's innocent but he drowns?

Re: I recommend against using biometric identification

#205

Earlier quoted context omitted.

Fuck, that is absolutely nauseating. What's worse is that trustworthy deniable encryption - which would solve this - is practically non-existent now that TrueCrypt is gone.

Eh... The prosecution claims, and the judge believes, that they have a list of files they expect to find on the drive. If he gives them a password and those files don't appear, the judge will conclude he gave them the wrong password, and he will stay put until the right password is produced.

That's not how this works. With deniable encryption, it is entirely possible that there doesn't even exist a hidden volume to find. They will be unable to prove he has a hidden volume and surely a judge will not compel him for not producing something he may not be able to at all.

Re: I recommend against using biometric identification

#206
post #163
post #107

Earlier quoted context omitted.

That man may still be in prison, but that drive is still encrypted. If you are unwilling to give something you know to someone, no amount of force can take it from you. Had that drive been encrypted using facial biometrics, they could have just knocked him out, glued his eyes open, and taken what they wanted. What works, and what has been deemed legal, as you probably already know, are not mutually exclusive.

Why do people assume that deniability results in more whacking? Technology can easily be used to encrypt a hard drive to reveal different things for different passwords. TrueCrypt does it. Plus you can have cryptographic keys stored with friends or beacons that signify you are safe. For example you hide files on your phone before a flight, and to unhide them you need your host's wifi at your destination. Until the fr…

> Why do people assume that deniability results in more whacking?

Contempt?

Re: I recommend against using biometric identification

#207
post #149

Earlier quoted context omitted.

The answer is probably no. Requiring a person to unlock a device is not prohibited by the Fifth Amendment simply because the device contains incriminating information that would otherwise be inaccessible to police. If the police have a valid warrant to search your safe, you are generally required to unlock it for them, even if the safe contains evidence that incriminates you. If you are issued a valid subpoena to pro…

What checks exist to prevent police from planting a USB hard drive on an enemy of the state that's encrypted and then claiming the defendant won't decrypt the hard drive? The state would have a really easy time imprisoning him/her because the defendant would never be able to provide a key to decrypt it.

Nothing but morale prevents it, just like planting any other evidence.

Re: I recommend against using biometric identification

#208

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

Perhaps there could be a way to instantly delete all iphone data with a voice command.

Something like "siri delete my iphone code alpha nine x."

Or even an undetectable command like "silly sausages" for example.

Might that stop a judge from being able to send you to prison indefinitely?

Re: I recommend against using biometric identification

#209

Earlier quoted context omitted.

Eh... The prosecution claims, and the judge believes, that they have a list of files they expect to find on the drive. If he gives them a password and those files don't appear, the judge will conclude he gave them the wrong password, and he will stay put until the right password is produced.

That's not how this works. With deniable encryption, it is entirely possible that there doesn't even exist a hidden volume to find. They will be unable to prove he has a hidden volume and surely a judge will not compel him for not producing something he may not be able to at all.

Check out, for example, the case of Martin Armstrong, held for 7 years in contempt of court for not producing items he said he didn't have. Eventually he had to enter a plea agreement and serve an additional 5-year term.

Re: I recommend against using biometric identification

#210
post #50

Earlier quoted context omitted.

Ehh... it's not the same as a username. It's more like fingerprints are door locks. Any determined thief can get around it. But it protects you from people who aren't really all that determined. And for most people door locks are sufficient. But if you are a major crime lord, protecting something extremely valuable, or just really into security then door locks are not enough.

The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…

It's a sad state. I've heard wealthy and influential investors talk about how they don't think real 2FA is worth anything, because they just want to use their finger for everything. No matter how easy or hard it is to steal, the major problem is that you only have 10 fingers. If all of them gets compromised we still need something else.
Post reply on HN