Live data from Hacker News

Deniability and Duress

mit.edu

1–10 of 124 posts

Re: Deniability and Duress

#2
I like the idea of using a sequence to unlock the phone, or specific finger to wipe the phone, and a different finger to load into a "clean" environment. That would be a usable mix of secret knowledge, physical security, and convienience.

Re: Deniability and Duress

#3

I like the idea of using a sequence to unlock the phone, or specific finger to wipe the phone, and a different finger to load into a "clean" environment. That would be a usable mix of secret knowledge, physical security, and convienience.

A system like that would need to do more than provide a clean slate. It wouldn't be plausible that someone would be using a worn phone without having installed any apps on it. Also, I don't know how the phone would be able to obscure the contents of a micro-SD card, for example.

Re: Deniability and Duress

#6

I like the idea of using a sequence to unlock the phone, or specific finger to wipe the phone, and a different finger to load into a "clean" environment. That would be a usable mix of secret knowledge, physical security, and convienience.

A system like that would need to do more than provide a clean slate. It wouldn't be plausible that someone would be using a worn phone without having installed any apps on it. Also, I don't know how the phone would be able to obscure the contents of a micro-SD card, for example.

Why shouldn't it have any apps on it? From my understanding, the point is that the crucial subset of user data is not available in that usage mode.

Re: Deniability and Duress

#7
Android had user profiles for a while. If you associate different fingerprints or different pin codes with different accounts, you can have your sneaky account with all the warcrime photos and the "open" account which is full of dick pics and selfies, as per usual. Almost no new technology required.

This all assumes the border guard is simply going to go through texts, pictures and maybe open up a facebook or similar. If forensics get hold of it you're screwed.

Re: Deniability and Duress

#8

Earlier quoted context omitted.

A system like that would need to do more than provide a clean slate. It wouldn't be plausible that someone would be using a worn phone without having installed any apps on it. Also, I don't know how the phone would be able to obscure the contents of a micro-SD card, for example.

Why shouldn't it have any apps on it? From my understanding, the point is that the crucial subset of user data is not available in that usage mode.

The malicious actor would find it very suspicious (especially if/when these features are in popular platforms and thus widely known), breaking the deniability.

Re: Deniability and Duress

#9
The worst thing to do, when facing rubber hoses, or legalistic equivalents thereof, is to lie. Especially if you're not a well-trained lier. And especially if there may be independent evidence that would trip you up. The best option is having nothing to hide. When crossing hazardous borders, sensitive stuff should be securely in the cloud. And when coercion is likely, a third party should control access to it.
Post reply on HN