so, my normal code might be 123456, but if someone asks what my code is and I say 345678, then the phone does a data wipe that isn't obvious from the outside, and just deletes all credentials, cookies, history, documents, etc.
Is this workable?
so, my normal code might be 123456, but if someone asks what my code is and I say 345678, then the phone does a data wipe that isn't obvious from the outside, and just deletes all credentials, cookies, history, documents, etc.
Is this workable?
Investigators are going to take a very dim view of such events, and probably didn't get to the point of demanding access without having documented sensible reason to believe the evidence is there - and may very well have actionable proof that you destroyed evidence, which will not turn out in your favor.
Your doubt tells us that your PIN is not a palindrome. The second most common PIN is 1-1-1-1, followed by 0-0-0-0 (says http://www.datagenetics.com/blog/september32012/ ), and looking at the top 20 numbers, over 10% of the people have a palindromic PIN. (If selected randomly, that should be 2%.)
So either the police get called a lot, or there's some special flag that say "palindrome PIN - false alarm" (and it must be supported for international cards) ... or it's simply not true.
The same place also had a security system for a critical data center room: Opening the door from the outside (i.e. entering) would increment a counter by one, opening it from the inside would decrement it. If the room, according to that counter, was supposed to be empty, any movement within would trigger the same silent alarm. The system worked safely up to the point where two people entered together, one of them left the room and the other one's badge had a temporary malfunction. We were quite impressed with how quickly a large assortment of police would show up, guns blazing and all ;-)
So patent examiners cannot just look at something and say, "this is crap, no patent for you". They have to prove a patent application invalid. There are many ways to do this, but the most common is by showing sufficient prior art. If they cannot find one or more previously published works that disclose each and every element of the claim, they must allow it. Apparently the examiner could not find evidence of somebody thinking of this before, and so it was allowed, regardless of how novel it appears to us now.
Another way to find an application invalid is to show that it does not disclose enough detail about how to implement the invention. That is probably why this patent (and most others) are really long-winded.
I think of touch UIs and the patents there, for example Apple's rubber-band scrolling patent[2]. Sure, it's quite probable that no one thought of this before if they weren't designing touch UIs. And even if they were, they might have thought of that, plus several other ideas, while developing. Why should this make any difference?
For instance, no one has made scrolling that intentionally segfaults if you scroll fast enough (or insert other silly thing here). You won't find prior art on this. Should it be eligible for a patent just because it's novel? There should be some sort of criteria where the effort required to invent something is taken into account. If it's likely to come about merely as a result of playing in the space, then what does the public gain by issuing a patent?
What knowledge is contained in the "reverse PIN dials cops" that merits protection? Even if nobody had that idea before (or bothered to document it), what does that matter? If you patent can be constructed just by asking a simple question ("think of some ways to alarm when being robbed at an ATM"), well that should be grounds for it not being valid.
Edit: Another example. Things like algorithms. Look at a simple database indexing system: ISAM. Sort your data, sample every so often to form an index. Repeat if the index is too large. Ta-da. Going back far enough, this was very novel. But any worker that had to figure this problem out would arrive at the same solution. It's nearly as fundamental as binary search.
1: https://en.wikipedia.org/wiki/Inventive_step_and_non-obvious...
2: http://patft.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=H...
One line of reasoning is that there are not enough people "merely playing in some space" to find more solutions to problems. This is not just theoretical. There is empirical evidence based on historical data that showed how the introduction of patent protection to previously ineligible arts influenced innovation. It finds there was more innovation in areas where previously protection was not available or where it was too easy for competitors to rip off your inventions. See http://www.jstor.org/stable/4132712 for instance.
> If you patent can be constructed just by asking a simple question...
Many scientists, mathematicians and engineers will tell you that the best way to solve a difficult problem is by framing it correctly. Put another way, you have to first ask the right questions. The solution may become obvious then, but it may be very hard to first ask the right question. And hindsight is a very powerful bias. What may seem like a simple question today may not actually have been so before it was posed.
This is also one of the many problems with requiring effort as a criteria. Besides being difficult to quantify in general, how do you measure the effort required to formulate the right question? How do you quantify flashes of insight? Maybe a person has 20 years of experience in some field X, but sees a problem and reaches a solution in 20 seconds. Was the effort required 20 seconds or 20 years?
Wells Fargo and a couple others allow anywhere from 8-16 as their maximum, though I reduced mine to 12 because some ATM's were kind of finicky at the longer lengths.
Luckily (hah) working for a US company so I don't get enough time off to actually go overseas, so it's never been something I had to worry about.
Edit: It doesn't seem so weird anymore either. I used to get questions all the time from Cashiers, like "Wow, I didn't know your PIN could be longer than 4". But I haven't been asked about it in 1-2 years.
There was a case a few years back (discussed on HN) where a gang had software installed on everyone's phone that caused a remote wipe when activated. The cops did a big raid, and even though they took everyone's phone someone they hadn't caught yet was able to wipe them.
The cops changed their SOP so that when they get ahold of your phone the first thing they do is yank the battery.
Depends on the situation. If it's a raid due to software piracy - then probably. If they pulled you over for speeding and arresting you - they probably won't or even know what to look for.
And I really can't think of a way to clone a device like an Android device without unlocking it. ADB now a days requires your explicit permission from a prompt. And if you are like "oh they have ways" I would be very interested in that because that sounds like whatever they are doing are using an exploit or some sort of back door.
The link is a few years old. No idea if there is a current version that works on modern phones, but it seems reasonable to assume there would be.
The first part talks about bluetooth pairing with the device - which requires unlocking. The second page talks about unlocking an iPhone with plist files from a synced computer. So it's not a matter of some magical device that can backdoor a phone - but rather using interfaces that already exist.
I found this company [2] and it has the usual marketing ploy - but a quick google search doesn't reveal any actual reviews of people using it. I can paragraphs of marketing spin but no one actually saying "we used this to get into cell phones that were password protected".
I'm not saying it's not possible - I just find it hard to believe without it making modifications to the underlying software (ie flashing a ZIP on android that zeros out the pin password or something).
[1] http://arstechnica.com/tech-policy/2011/04/michigan-state-po...
[2] http://www.cellebrite.com/Mobile-Forensics/Products/ufed-tou...
No, they don't need to use any kind of exploit. They have hardware that allows them to clone the the device's memory. I doubt it has to be on at all.
There's no way to secure a device if the attacker has physical access. The best you can do is secure the data with encryption.
But what I wonder is how they circumvent the entire trust mechanic when the phone is locked. When the phone is locked most of the storage is encrypted too.
I've always thought the way to deal with this is to use a OTP scheme. If you have a one time pad that's as large as your data set (assuming we're talking about some reasonably small number of critical documents here), you could generate the cyphertext from your key and then generate another key that translates your cyphertext into something innocuous - grocery lists or whatever.
There's no way the court could prove the key you gave them isn't the right key.
It would only take seconds to use, but you would need to be prepared for the specific phone model.
Maybe you could even have a CNC machine preloaded with the data for a wide variety of phone models. You put the phone down on the work surface, key in the model, and the CNC machine deftly cuts through the right power lead. Less portable, but would require less precise planning.
If they can copy the HSM, that wouldn't help, but in that case, it doesn't really seem like they need your help getting the PIN in the first place.
That's something I hadn't considered. Is it set up that you can create and destroy the keys but never get access to them?
More important to the issue at hand, I believe that in at least one case the reason for the passcode/phrase being "testimony" isn't so much that you're revealing what's in the locked container, but that you're demonstrating that you have access to/control over its contents. So entering your erasecode would undermine this point. A courier could not know a passphrase yet be deputized to erase the contents, but that is going to be an uphill argument.
What we really want is a proper layered steganographic filesystem, with an arbitrary number of unlockable levels. But we need an OS and apps that play nicely with that as well.
A judge isn't a robot. If you say "I hit an emergency button to reformat my hard drives as the cops were breaking down the door, because I was preparing to sell those drives on ebay and needed to clean them up", the judge is not obligated to respond "Shoot, I can't prove otherwise, you're free to go."
This seems like one of those laws that sounds good at first but makes a lot of normal behavior illegal, thus allowing the legal system to be able to pick and choose who gets punished.
The only marketable purpose for an instant erasure system like that is protection of information (personal or commercial). To build that, you'd make something that zeros all the files and deletes them, deletes and overwrites all the contacts, and such.
But the structures left after that don't look like a brand new device. They look like you had a bunch of things and then erased them. Cops won't know what you erased, but they'll know you handed them a phone that was recently erased.
Now maybe somebody will build an app tuned for obstruction of justice, so it tries to make the phone look brand new. And maybe you'll be very lucky and they'll get it working perfectly on your specific phone. But then you have to explain how you have a brand new phone that was actually purchased a year ago. And how it has no record of any of the calls that your phone carrier will have records of. The obvious conclusion is that you wiped it sometime after your last call and with special software that only appeals to people planning on hindering an investigation.
Is that enough to convict you for obstruction of justice? I have no idea; it probably depends on how much a prosecutor cares. But is it enough to convince cops you are vigorously hiding something? You bet.
No, there's no need for anything that complicated.
In principle, encrypting all data on a phone is really simple to implement. In practice, it's carefully thought out to avoid edge cases. The general idea is something like this:
when first activated, the
phone generates a random 256-bit AES key
phone uses this random AES key to encrypt
all data stored on the phone
phone retains this random key in a special
location, and encrypts this key by using
the user-provided PIN
To quickly erase all data on the phone, all that's necessary is to overwrite the key in the special location with random data. From that point on, there is no feasible way to recover anything on the phone. Period.It isn't necessary to erase an entire device. It's merely necessary to replace a 32-byte field (that contains the true AES key) with 32-bytes of random data.
From then on, it doesn't matter what the PIN is. Data on the phone is jibberish unless and until the proper 256-bit AES key is produced. That key no long exists, so from that point on the only way to recover the data is by brute forcing AES, by trying all possible 2^256 combinations.
They look like you had a bunch of things and then erased them
No, what remains is indistinguishable from the case where the correct PIN hasn't been provided. Having "things" on the phone is no evidence of guilt. There is absolutely no evidence that the phone was erased. All that is known is that the provided PIN isn't able to decrypt the data.
What we were discussing is abakker's proposal for something that "wipes the phone", and I think my comments are still relevant to that approach.
Of course, a suddenly unreadable phone is still suspicious, but if your plan were perfectly implemented, it might be impossible to prove obstruction of justice.
Similarly, did you know you can legally murder anyone by poisoning their food? You didn't make them eat the poison, they voluntarily ate the food. It gets ruled a suicide.
For more on this and other little-known facts about the law, please subscribe to my YouTube Guide to Being a Sovereign Citizen, only $199/month.
Perhaps some software that clears the phone when someone tries to break into the phone / copy data? A prudent security precaution for all sorts of reasons.
I could even see it with touch sensors, that being teaching it that the middle finger wipes the puppy.
With regards to the court decision, I am not sure it will stand in this context. The phones belong to the employer and not the employees. So how as an employer do you retain some access over your provided phones? I can see both sides here. To be honest as a company I don't think its worth the legal ramifications to have power over the content of the phone as it just opens a can of worms
Where I work we are required to pass code our phones if we access the corporate internet or exchange servers but we are not required to divulge our phone contents, passcode, nor place software on the phone giving the company any such ability.
There's no law against incompetence, true?
I know in the Windows Mobile/Blackberry days if you typed in the incorrect password so many times it would reset the device.
However, with many Android devices now a days have the ability to have a "guest mode" - that is activated using a different unlock code. This mode can be limited to not even be able to make/receive calls. Arguably most people won't know what this "mode" is and if they are in it.
The first layer contains something embarrassing but legal like gay porn, and the second layer contains the stuff you really want to hide.
You just unlock the first layer and act really embarrassed if forced and never acknowledge the existence of the second layer.
http://security.stackexchange.com/questions/9058/is-it-possi...
What do the proponents of these encryption laws expect the penalties to be for 'suspicion of possession of encrypted material'? I don't see any way to create effective deterrents here without making it easy to persecute anyone for any reason. Imagine cops planting USB keys with random bits on minorities they don't like, etc.
Edit: or worse, 15-year-olds planting USB keys with random bits on teachers they don't like and claiming it's CP and then watching them get fired and go to prison for 'refusal to decrypt' shudder
Just because something isn't proof, doesn't mean it isn't evidence. And if I am doing something my government disproves of, I'm going to try and be mindful of all evidence that can expose that. (Note that I'm NOT making any value judgements here) If an inner-hidden volume isn't as hidden as I thought it was, then that's a security risk to me.
a) 'forced decryption' legislation is toothless. That is, suspicion, but not proof that encrypted material exists and is within your power to decrypt is not enough to throw you in jail for contempt or some other charge.
b) It becomes extremely easy for bad actors like racist cops or asshole teenagers to frame anyone and everyone they want and put them in prison forever.