Deniability and Duress
71–80 of 124 posts
Re: Deniability and Duress
#72Earlier quoted context omitted.
I wish EU and other non-US countries would offer "US-border treatment" to all US citizens when they enter, and normal border control when they leave. That way they could maybe get an idea on how unfriendly, impolite, invasive and denigrating it actually is. And then when leaving get the idea that border agents can be helpful and friendly too. Edit: And oh yes, all communication and paperwork is done in the language o…
i feel sympathy for the idea, but it kinda undermines the case against these practices. If we're saying "terrorism" isn't enough of a reason for wide-scale privacy invasion, how could "getting the US to change its policy" ever be enough? Additionally, it's an individual's rights being infringed, almost none of whom have influence on policy beyond voting, and the vast majority of whom, belonging to the subset of Ameri…
These practices mentioned by GP exist since well before 2017.
Following your logic, the question would be if they voted for Obama. And, if the vast majority didn't vote for Trump, they probably voted for Obama. So it actually would affect the "right" people.
(Not that I agree in any way with punishing citizens for what their government does)
Re: Deniability and Duress
#73iPhones require the password(/code) when turned on and (IIRC) under certain other conditions. But I believe this isn't enough considering recent developments. They write: It’s important to note that deniability refers to the ability to deny some plaintext, not the ability to deny that you’re using a deniable algorithm. It's now common for border agents in the US to demand login credentials for social media accounts,…
https://github.com/securityfirst/Umbrella_content/blob/maste...
Hope it's useful!
Re: Deniability and Duress
#74The first two paragraphs of the article are about a journalist covering war crimes exiting a country and being searched. Fifth amendment distinctions between passwords and fingerprints aren't a solution to the problems in Egypt, China and Turkey as those countries aren't subject to US law. In that situation, from one perspective a duress code that wiped the phone might seem useful - it would establish that there's no…
Re: Deniability and Duress
#75"However, the bad news is that hand-typed passwords are increasingly seen as the way of the past; hardware tokens and biometric sensing are considered to be far more usable, and will likely be employed more and more in the future." Anytime you sacrifice security for convenience or simplicity, you lose. That's why I have no intention of ever using anything other than good ol' alphanumeric passwords that must be entere…
Re: Deniability and Duress
#76"However, the bad news is that hand-typed passwords are increasingly seen as the way of the past; hardware tokens and biometric sensing are considered to be far more usable, and will likely be employed more and more in the future." Anytime you sacrifice security for convenience or simplicity, you lose. That's why I have no intention of ever using anything other than good ol' alphanumeric passwords that must be entere…
Why not both? A password with a U2F security key seems hard to beat.
Re: Deniability and Duress
#77The first two paragraphs of the article are about a journalist covering war crimes exiting a country and being searched. Fifth amendment distinctions between passwords and fingerprints aren't a solution to the problems in Egypt, China and Turkey as those countries aren't subject to US law. In that situation, from one perspective a duress code that wiped the phone might seem useful - it would establish that there's no…
I guess ideally a duress code would make it seem as though regular access was given, while silently either wiping sensitive data or keeping it hidden.
Re: Deniability and Duress
#78"However, the bad news is that hand-typed passwords are increasingly seen as the way of the past; hardware tokens and biometric sensing are considered to be far more usable, and will likely be employed more and more in the future." Anytime you sacrifice security for convenience or simplicity, you lose. That's why I have no intention of ever using anything other than good ol' alphanumeric passwords that must be entere…
Why not both? A password with a U2F security key seems hard to beat.
Re: Deniability and Duress
#79Re: Deniability and Duress
#80Hi, author here. Really happy (but somewhat surprised) to see this up on HN, and am generally interested in pursing this as a PhD thesis topic. If anyone has ideas or thoughts on novel systems in this arena I’d be very interested to hear about it!
- TrueCrypt's hidden volumes
- Two OS's on the same phone; you have the innocent one booted up, and the other encrypted.
What are your thoughts on these?