Live data from Hacker News

PAM Duress – Alternate passwords for panic situations

github.com

251–260 of 358 posts

Re: PAM Duress – Alternate passwords for panic situations

#251

Training is very important in duress systems. I once worked in a place with a keypad duress code on the security system. If you prefixed your security PIN with NN-, it was the duress version of the code and would trigger a silent alarm. This was setup long-ago, and not communicated. One night, the keypad was acting glitchy. Partially out of frustration (countdown is running), and partially to test, I ended up acciden…

I found out the hard way that a job I had once (DIY store) had a hidden panic button under the counter. I was just fidgeting while we were closing up, hands found it and did their exploration thing.

I mean it happens, the security company sent out a van already (as they should) and called to confirm. They charge a fee (just over €100 I believe? Or €250? I forgot) for false alarms, but that's fair enough. Better safe than sorry.

Anyway, a DIY store with at most 100K in the safe (weekly takings at the time, most of that was probably electronic) is probably a lot less serious than whatever you were working for, to have it surrounded by law enforcement.

Re: PAM Duress – Alternate passwords for panic situations

#252
post #216

Earlier quoted context omitted.

I'd always assumed (UK) that 9 was a deliberate choice to make it easier to dial the emergency number, 999, because you can just mash 9 until something happens. I guess if it's the same number in all other countries who have a range of emergency numbers, then that might not be the reason.

My working theory is that in old times phones had rotary dial instead of key pad. Number 1 was the longest to dial, 9 was the shortest (as I remember from childhood days). Thus, fastest way to dial 3 digit code was to use numbers with as much as 9 as possible (997,998,999).

[deleted]

Re: PAM Duress – Alternate passwords for panic situations

#253
post #249

Earlier quoted context omitted.

Is it legal for them to arrest you simply to keep up the appearance? You haven’t done anything illegal.

Not from the US, but here at a bank I worked with: If you trigger the silent alarm they'd have reason to suspect you are threatened and would take you to custody to make sure you are safe and release you once it's sorted out (probably an hour or so).

That makes sense. Sorting things out takes time. But trying to create an illusion that no alarm was triggered to prevent criminals from gaining knowledge: not a reason to imprison an innocent person.

Re: PAM Duress – Alternate passwords for panic situations

#254
post #75

There are multiple levels of protection one might want. I.e. when you are being selected for random questioning entering US as a non-US citizen, you'd benefit from steganography-like approach: you give a password, and relatively bland, non-personal stuff shows up, giving appearance of full access to a system. If you only care about your privacy, the next one is to have a destroy-everything script (and it's not that h…

I'd only bring a burner device, keep code and the like (company secrets) on HQ's server, and memorize some passwords.

I mean yeah, a blank laptop looks suspicious, but they can't keep you for having a blank laptop.

edit: not a lawyer, this is not legal advice. The US puts people in dehumanizing concentration camps without due process.

Re: PAM Duress – Alternate passwords for panic situations

#255
post #70

Earlier quoted context omitted.

Why would being security conscious automatically disqualify biometrics? Security is all about threat models, and I can imagine quite a few scenarios where biometrics might fare better than passwords. Shoulder surfing and trivial passwords/PINs come to mind, for example. And who said that it's biometrics vs. anything else? It's quite advisable to combine authentication factors.

Shoulder surfing and weak passwords are both something you can control at any time. Biometric identification can be exploited involuntarily by someone literally using force to apply your finger to a device or similar. I shouldn't need to say this, it's so obvious that it's a common plot device in action movies.

> Shoulder surfing and weak passwords are both something you can control at any time.

How, exactly? And "require users to watch out for shoulder surfing and use strong passwords" does not count.

Any chance you are thinking about pretty specific circumstances here (security-aware, technical employees generally not having to enter passwords in public spaces)?

Re: PAM Duress – Alternate passwords for panic situations

#256
post #249

Earlier quoted context omitted.

Not from the US, but here at a bank I worked with: If you trigger the silent alarm they'd have reason to suspect you are threatened and would take you to custody to make sure you are safe and release you once it's sorted out (probably an hour or so).

That makes sense. Sorting things out takes time. But trying to create an illusion that no alarm was triggered to prevent criminals from gaining knowledge: not a reason to imprison an innocent person.

>imprison an innocent person.

Kind a hard word to use for an arrest. In many places police can arrest you for some period if they suspect you have committed a crime. This is no different. No need for sensational language.

Re: PAM Duress – Alternate passwords for panic situations

#257

Earlier quoted context omitted.

So you're saying if I'm held at gunpoint or forced to surrender my password at the US airport that a password to clear my account of anything would be useless? Neither of them know anything about me. It reminds me of the Trezor hardware wallet that allows you to have multiple passwords into your account. If your forced to give access you can log into the version with little in it. Nobody knows that you have secondary…

If you're held under gunpoint, that script that wipes your entire hard drive will only make your day worse. AFAIK if you actually get detained and questioned at airports, your drive will already get imaged before any password is even tried. You may be able to get away with this on a mobile device where this feature isn't generally expected (because who uses Linux on a smartphone in the first place). I always wonder a…

> AFAIK if you actually get detained and questioned at airports, your drive will already get imaged before any password is even tried.

Good luck doing that on 2016ff MacBook Pro's (they all have soldered storage) or any Windows 10 laptop with TPM-backed Bitlocker encryption.

Re: PAM Duress – Alternate passwords for panic situations

#258

Earlier quoted context omitted.

And with a little bit more force they beat the password out of me anyway regardless which system I use...

If you are so easily swayed, you would probably not be in an adversarial situation with a government anyway. But this article is about a system for giving up passwords under duress without necessarily compromising all your security, such that your antagonist has no way of knowing or showing that there's another password concealing more important information.

> If you are so easily swayed, you would probably not be in an adversarial situation with a government anyway.

Complying in the face of threats of physical violence is equivalent to "being easily swayed"?

You seem to have a pretty specific threat/defense model that you didn't clarify. I wouldn't generalize from that to "biometrics are bad for all users in all situations".

Re: PAM Duress – Alternate passwords for panic situations

#259
post #75

There are multiple levels of protection one might want. I.e. when you are being selected for random questioning entering US as a non-US citizen, you'd benefit from steganography-like approach: you give a password, and relatively bland, non-personal stuff shows up, giving appearance of full access to a system. If you only care about your privacy, the next one is to have a destroy-everything script (and it's not that h…

I'd only bring a burner device, keep code and the like (company secrets) on HQ's server, and memorize some passwords. I mean yeah, a blank laptop looks suspicious, but they can't keep you for having a blank laptop. edit: not a lawyer, this is not legal advice. The US puts people in dehumanizing concentration camps without due process.

US can deny non-US citizens entry for any arbitrary reason. Blank laptop might be one of them.

Re: PAM Duress – Alternate passwords for panic situations

#260

I hate when my bank calls me about something and then asks to confirm my identity prior to giving out details about my account. Even when I think I know what it is about (e.g., a transaction with my card was declined just before the phone call), I feel very strange giving out any information to an inbound caller. One thing I have thought about doing is providing mistaken information to the caller and see if they go a…

> Does anyone else have any ideas for how to authenticate a BigCorp caller whose corporate policies do not allow them to provide any account information to the people they are calling? I mean, it's really their problem, isn't it? If you need something from them, call their customer line and ask. If they need something from you, then they'll figure it out. I had a financial institution call me one time and ask "Is thi…

Banks themselves tell you not to give out their info, so that scenario plays out more often than you think. I've had it happen and they just sent a letter by mail instead.
Post reply on HN