Live data from Hacker News

"Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

cryptome.org

51–60 of 62 posts

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#51
post #19

A few gems in here besides the TrueCrypt statement, mainly that Apple iCloud and Dropbox are named, and the legal framework is touched upon. All cloud stored content are automatically hash-scanned and image-analyzed by their service providers and infringing content reported to NCMEC (p16) Mobile content are automatically scanned when they are synced with cloud storage like Apple iCloud or Dropbox. Mobile devices that…

You missed a big one there. Mobile devices that are not cloud-synced can be accessed by their respective vendors Essentially; iOS and Android have a remote backdoor available to the US government.

I think they're speaking about system dumps at the manufacturer level.

For example, I'm fairly confident that the data on Motorola devices can be read completely using USB from bootloader mode without any data modification (using tools like RSD Lite or sbf_flash). By itself that wouldn't get past OS-level encryption, though. That bootloader is entirely Motorola's with functionality and communication protocols dating back to before the pre-Android razr flip phones (from what I could tell back when I was doing battle with the XT720).

On the other hand, passphrases for boot security on mobile devices are often extremely weak (pin or what-have-you) and easy to brute force (assuming there is a backdoor to access the TPM contents or whatever it's called on ARM/OMAP/etc if it uses that sort of thing)

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#52
post #19

Earlier quoted context omitted.

You missed a big one there. Mobile devices that are not cloud-synced can be accessed by their respective vendors Essentially; iOS and Android have a remote backdoor available to the US government.

With regards to FileVault for Mac, some friends who used to work as Geniuses at the Apple Store have mentioned having to request special software from corporate that would fix or recover FileVault in some way - they weren't clear and said it was not something they were supposed to talk about. Obviously I'd take the info with a grain of salt, but based on the news lately...

I had an conversation regarding FileVault with the geniuses recently too.

    > Oh we see [your MacBook] has a password, would you be able to write it down here?
    Haha, nope!
    > Any, uh, reason not to?  
    Nope. 
From a conversation later on, apparently not many people opt not to give up their keys. I'm not sure why they pushed me to give it up either, the geniuses know full well that they can just boot their diagnostics disk without the password anyway.

Bear in mind that the default setup for Apple's FileVault also sends a copy of the encryption key to Apple too (associated with your AppleID), where presumably there is access granted to the US government also (willing or unwilling).

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#53

Anybody ever heard of the "zSearch" software mentioned in the pdf? After some more digging, found this document: http://www.ndsaa.org/Computer_Forensics_for_Prosecutors.pdf Which states: Free product by SA Eric Zimmerman Random Access Memory Analysis: * FBI - Salt Lake City, UT * Distribution - eric[at]feeble-industries.com * Plug-in live triage via USB * Virtualization, encryption, mass storage, P2P, Gigatribe, pict…

There is more regarding zSearch: "... computer search tool called osTriage/zSEARCH. The search tool allows investigators to find child pornography without damaging the forensic integrity of a computer." http://attorneygeneral.utah.gov/PR_122011.html

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#56
post #41

Are we all just going to take this seriously? It's pretty obviously a fake. Just look at the names at the end. Detective Laughlin Foo? Stu Pitt? Neither of which, incidentally, return anything in google aside from this presentation. There's also a clear divergence in style on the backdoor slides, and it reads like a parody. But the most obvious problem: if the NSA or whoever had a backdoor to truecrypt and Android an…

Incessantly cynical distrust of the government is the new blind patriotism.

It is impossible to overmistrust the State. If you could imagine the lows they will go to, you'd be working for them by now.

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#57
post #5

Page 16 has some wonderful lines: • “Fruit of the poisonous tree” can be circumvented • The use of backdoors cannot be detected or proven • Vendors are legally and commercially prevented from acknowledging their backdoors. Defense will not be able to prove their existence • The files can be described as “forensically obtained”

This is of course, completely false in every way. No prosecutor would ever be dumb enough to say any of this.

Could it happen in some off-the-beaten-path courtroom that isn't being watched as closely, and whose defendants are less likely to know that? The title page of the document shows a county in Oregon, and the link at the end to the previous year's presentation points to North Dakota.

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#58

Earlier quoted context omitted.

...but how is the prosecution able to prove the files exist on someone's device if they don't have to disclose how they determined that the files were present? If all they have to do is assert that the files exist and were "forensically obtained" then why bother with the backdoor in the first place?

They are required to disclose everything. This slide reads like it was written by someone whose knowledge of criminal procedure comes from TV.

The title page credits the document to a presentation by a detective in Oregon. Have any journalists tried to verify the source and accuracy of this document? It's unclear from the article submission why it was submitted or how the submitter found it.

Edit: I just read the current top comment listing the names of the supposed presenters.

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#59

Earlier quoted context omitted.

Incessantly cynical distrust of the government is the new blind patriotism.

It is impossible to overmistrust the State. If you could imagine the lows they will go to, you'd be working for them by now.

Is it really impossible? Do you think there is literally really no limit to what they can do or what they will do?

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#60

Earlier quoted context omitted.

Mentioning a steganographic technique implies that you use it, negating the point.

Not completely. How many video files does he have? Where is it stored? I'm curious now though, do Truecrypt volumes have a magic number, in which case it's still easy to find, or are they fully crypographically random in appearance, making this a known-needle in a large haystack problem?

Truecrypt claims an encrypted volume is indistinguishable from random data. I do not know if this is the case though. Obviously don't give it the file a stupid name or extension like "encryptedfiles.tc" or leave it open in your file history, etc.

It's also pretty suspicious if someone has a file of megabytes of random data.

Post reply on HN