Live data from Hacker News

Deniability and Duress

mit.edu

71–80 of 124 posts

Re: Deniability and Duress

#71
Hi, author here. Really happy (but somewhat surprised) to see this up on HN, and am generally interested in pursing this as a PhD thesis topic. If anyone has ideas or thoughts on novel systems in this arena I’d be very interested to hear about it!

Re: Deniability and Duress

#72

Earlier quoted context omitted.

I wish EU and other non-US countries would offer "US-border treatment" to all US citizens when they enter, and normal border control when they leave. That way they could maybe get an idea on how unfriendly, impolite, invasive and denigrating it actually is. And then when leaving get the idea that border agents can be helpful and friendly too. Edit: And oh yes, all communication and paperwork is done in the language o…

i feel sympathy for the idea, but it kinda undermines the case against these practices. If we're saying "terrorism" isn't enough of a reason for wide-scale privacy invasion, how could "getting the US to change its policy" ever be enough? Additionally, it's an individual's rights being infringed, almost none of whom have influence on policy beyond voting, and the vast majority of whom, belonging to the subset of Ameri…

> didn't even vote for Trump.

These practices mentioned by GP exist since well before 2017.

Following your logic, the question would be if they voted for Obama. And, if the vast majority didn't vote for Trump, they probably voted for Obama. So it actually would affect the "right" people.

(Not that I agree in any way with punishing citizens for what their government does)

Re: Deniability and Duress

#73

iPhones require the password(/code) when turned on and (IIRC) under certain other conditions. But I believe this isn't enough considering recent developments. They write: It’s important to note that deniability refers to the ability to deny some plaintext, not the ability to deny that you’re using a deniable algorithm. It's now common for border agents in the US to demand login credentials for social media accounts,…

On that topic, we've included some guides on crossing borders / going through airports / attending protests and loads of other physical/digital security stuff in Umbrella App. (Learn more or download at https://www.secfirst.org). The specific piece is available on our Github (all our stuff is open source or Creative Commons, so feel free to re-use or please add more!).

https://github.com/securityfirst/Umbrella_content/blob/maste...

Hope it's useful!

Re: Deniability and Duress

#74

The first two paragraphs of the article are about a journalist covering war crimes exiting a country and being searched. Fifth amendment distinctions between passwords and fingerprints aren't a solution to the problems in Egypt, China and Turkey as those countries aren't subject to US law. In that situation, from one perspective a duress code that wiped the phone might seem useful - it would establish that there's no…

In the kind of place where you have to worry about rubber hoses, it seems probable that you'd not want to be carrying a device that has the known purpose of secreting information.

Re: Deniability and Duress

#75

"However, the bad news is that hand-typed passwords are increasingly seen as the way of the past; hardware tokens and biometric sensing are considered to be far more usable, and will likely be employed more and more in the future." Anytime you sacrifice security for convenience or simplicity, you lose. That's why I have no intention of ever using anything other than good ol' alphanumeric passwords that must be entere…

Why not both? A password with a U2F security key seems hard to beat.

Re: Deniability and Duress

#76
post #75

"However, the bad news is that hand-typed passwords are increasingly seen as the way of the past; hardware tokens and biometric sensing are considered to be far more usable, and will likely be employed more and more in the future." Anytime you sacrifice security for convenience or simplicity, you lose. That's why I have no intention of ever using anything other than good ol' alphanumeric passwords that must be entere…

Why not both? A password with a U2F security key seems hard to beat.

I use this combo whenever possible, though the number of services yet supporting FIDO/U2F is still a bit disappointing. It's been incredibly convenient to be able to use my bitcoin hardware wallets to double as U2F keys wherever I need them. Given that any device I would use an OTP or text 2FA solution with already requires time to unlock, it's far less convenient on top of being more exploitable.

Re: Deniability and Duress

#77

The first two paragraphs of the article are about a journalist covering war crimes exiting a country and being searched. Fifth amendment distinctions between passwords and fingerprints aren't a solution to the problems in Egypt, China and Turkey as those countries aren't subject to US law. In that situation, from one perspective a duress code that wiped the phone might seem useful - it would establish that there's no…

I guess ideally a duress code would make it seem as though regular access was given, while silently either wiping sensitive data or keeping it hidden.

The most disseminated example is TrueCrypt's hidden volumes.

Re: Deniability and Duress

#78
post #75

"However, the bad news is that hand-typed passwords are increasingly seen as the way of the past; hardware tokens and biometric sensing are considered to be far more usable, and will likely be employed more and more in the future." Anytime you sacrifice security for convenience or simplicity, you lose. That's why I have no intention of ever using anything other than good ol' alphanumeric passwords that must be entere…

Why not both? A password with a U2F security key seems hard to beat.

Even better. My point was only that I will never use something that doesn't require an alphanumeric password. Anything added on top of that like two-factor just sweetens the pot.

Re: Deniability and Duress

#79
post #77

Earlier quoted context omitted.

I guess ideally a duress code would make it seem as though regular access was given, while silently either wiping sensitive data or keeping it hidden.

The most disseminated example is TrueCrypt's hidden volumes.

Can you (or others) elaborate here?

Re: Deniability and Duress

#80

Hi, author here. Really happy (but somewhat surprised) to see this up on HN, and am generally interested in pursing this as a PhD thesis topic. If anyone has ideas or thoughts on novel systems in this arena I’d be very interested to hear about it!

Two possible (partial?) solutions mentioned on this thread were:

- TrueCrypt's hidden volumes

- Two OS's on the same phone; you have the innocent one booted up, and the other encrypted.

What are your thoughts on these?

Post reply on HN