Advanced Deanonymization Attacks
whonix.org
whonix.org
When it comes to timing attacks in things like decryption or password comparisons, I thought random latency was a pointless addition as it only requires a bit more sampling before you can pull the underlying differences out.
Does it work in this instance just because the numbers involved are a few magnitude less would be with something like network requests?
For 'hardened' browsers I'd recommend a visual indication of this timeout (a pie chart which completes like a clock at a fixed rate while paused is the first concept that I think of).
But this still suppose that the attack is carried over the network. If the attacker can, e.g., monitor the electrical activity of the physical keyboard, then it's another thing entirely.
http://www.securiteam.com/securitynews/5UP0D2AAUK.html
Because of this, it is possible to measure keypress AND key release timings _very precisely_, for any console user of a machine we have an unprivileged account on.
Curious if this has changed recently to warrant this comment as the last course I took was a while ago.
At the start of the course they have you type the phrase once or twice to get your cadence and then take your picture afterwards.
Wasavi. It's a plugin to emulate a small vim-like window on top of text-fields. You just Ctrl+Enter and it opens up, and when you save it (like vim with :wq or ZZ) it populates the field beneath it. It's quite interesting. I wonder if taking this approach to the extreme wouldn't make a difference? If all text fields were abstracted from the website and then the text sent in one stream, for all users.
I unfortunately do not possess the knowledge to understand if this is plausible or absurd, but wanted to at least discuss it publicly.
Edit: Wasavi on Github: https://github.com/akahuku/wasavi
This behavior does also exist for those accustomed to Vimperator, Pentadactyl or It's All Text plugins, but opening your default editor outside of the browser.
Edit 2: Wasavi supports many text input fields (including passwords), and can be configured to be enabled automatically on field focus.
Unable to enrol with your keystroke dynamics.
So yes, I'm adding this to my security toolkit.
Edit: Test https://www.keytrac.net/en/tryout
Holy sh*t
How does it compare to Tails?
SCARY