Live data from Hacker News

HiddenVM – Use any desktop OS without leaving a trace

github.com

41–44 of 44 posts

Re: HiddenVM – Use any desktop OS without leaving a trace

#41
post #31

Earlier quoted context omitted.

You're thinking the RIP Act in the UK where the police can get an order from a judge for you to turn over a key/passphrase and you need to either prove you don't know it or face up to two years in jail (five for cases of child abuse or national security). I'm not American but I'm pretty sure no law like that in the US would be upheld at appeal, it's pretty directly conflicting with the 5th amendment.

I heard it specifically for the USA in at least two occasions. I don't remeber the first, but the latter was in the Brett Jonson's show: in an episode, he talked about another criminal that had some encrypted material and refused to give out the key. He was put in jail until he decided to give it, and at that point IIRC he got an even longer sentence due to the proof he gave them access to. But now that I think about…

I remember a case too. They were 100% certain a hard drive contained CSAM but could not get the password. I'm pretty sure he was jailed for contempt until it was given out. Definitely inside the USA.

This might be it, I might be misremember the finer details:

https://www.bbc.com/news/technology-36159146

Re: HiddenVM – Use any desktop OS without leaving a trace

#42
post #38

Nice one. I’ve been using Veracrypt for many years now, after the whole Truecrypt fiasco. Just one friendly advice… always have a decoy partition or decoy OS, otherwise it seems very suspicious to have a disk filled with random data ;-)

Does full disk encryption not look like random data?

Basically yes. But as I understand it this is the reason why some border guard might ask you to boot up your machine to show him your system as a used and "lived in" installation. You might want to avoid arousing suspicion by lugging around a piece of dead metal (a laptop with unusable bit noise on its discs) or by presenting a fresh and empty OS.

Re: HiddenVM – Use any desktop OS without leaving a trace

#43
You can get microsd cards and even nanosd card that are so small that hiding somewhere on your person is easy.

Encrypt everything you need on it.

They are, should it be required, easy to quickly and discreetly swallow as a last resort. (To get rid of it. I have no idea what would happen to a nano sd card travelling through your body, but I presume that it, or at least the ability to read the data on it, would be destroyed.

Then carry a regular laptop with you, with all the regular applications and regular behavior of them. Boring.

Using tails as the main operating system on a computer you fear might be inspected by customs or secret agents is screaming:

"I have something to hide and you cant find it"

Re: HiddenVM – Use any desktop OS without leaving a trace

#44
post #24

Earlier quoted context omitted.

There was an interesting talk at one edition of CCC that boiled down to saying those techniques work only if you have the right to remain silent. Which depends on the country you're in. And I heard that in the USA, even though you have the right to remain silent, they still have the right to put you in jail if you refuse to give out your key.

You're thinking the RIP Act in the UK where the police can get an order from a judge for you to turn over a key/passphrase and you need to either prove you don't know it or face up to two years in jail (five for cases of child abuse or national security). I'm not American but I'm pretty sure no law like that in the US would be upheld at appeal, it's pretty directly conflicting with the 5th amendment.

"prove you don't know"

It might be my lack of coffee, but how would that work? You can prove you know something, but how would you prove you don't?

Post reply on HN