[0] http://hmarco.org/bugs/CVE-2015-8370-Grub2-authentication-by...
The OP specifically said the login prompt was defeated by backspacing alone.
https://groups.google.com/forum/#!msg/muc.lists.bugtraq/5zYU...
In fact, the same principle can be used to reset and extract windows user passwords. Something I did many times as an IT support technician.
The exception these days is leveraging secure boot and the tpm to ensure the kernel and initrd being booted and asking for your dmcrypt password can be trusted. That's our next challenge to make the standard.
Also since I own a Mac as my primary laptop, I've just always used filevault there and it helps me sleep a lot at night. Means I am not concerned if it gets stolen, my derpy photos won't be in someone elses hand. I don't care so much about the hardware.
"The installer no longer offers the encrypted home option using ecryptfs-utils. It is recommended to use full-disk encryption instead for this release." https://wiki.ubuntu.com/BionicBeaver/ReleaseNotes#Other_base...
FDE with LUKS/dmcrypt has been an out-of-box installer-supported mode in all the major distros for a long time now.
Huh? The norm? For what sorts of users?
I mean, that's best practice, sure. But hardly the norm. Even, I bet, among HN users.
https://www.theguardian.com/technology/2014/oct/17/apple-def...
https://www.howtogeek.com/173592/windows-8.1-will-start-encr...
Both boxes had fairly recent hardware and were running Windows 10 Pro.
I have three laptops on my desk right now, one HP Probook and two different Lenovo Ideapads. All three are running Windows 10 Enterprise (2x LTSB 2016, 1x 1803).
NONE of them have FDE enabled or have ever asked asked me about it.
Given the bold claim "[FDE is] on by default for (...) Windows users" - without mention of caveats re: login account types, domain memberships, or hardware requirements - it seems the counterexamples just keep coming.
I can't say the same for Windows and Mac users.
Last two employers recommended FDE but made no strict requirements because apparently it was non-trivial for non-Linux users.
It's a no-brainer feature for any sufficiently fast portable device. If the installer supports it why would you disable it? I haven't had to worry about the data on my laptops should they be stolen for what must be over a decade now, GNU/Linux has supported it that long.
Me, I've been talking about PC users, generally. Not just Linux, and not just technical people. Sadly enough, I doubt that FDE is very common, let alone the norm.
And even worse, for many it'd likely be a curse. Inexperienced people don't do well at keeping track of complex passphrases, keys and so on. I've seen that over the years in forums where people plead for help to access TrueCrypt volumes. After losing passphrases, accidentally formatting, and so on.
I am only speaking to the prevalence of FDE among Linux users; it's not uncommon.
You're correct in that these are technical people. Most people running a GNU/Linux distro on bare-metal in their possession are at least somewhat technical, wouldn't you agree?
Doesn't this face the TSA Master Key problem?
"Last September, Apple said it had made changes to iCloud security and introduced a measure to stop software from making multiple automated guesses. While this is the case when trying to log in on a computer, unlimited guesses can be made using an iOS device, which is what this software pretends to be when accessing iCloud from a computer running it."
You really can’t go down your line of argument without answering thar
What does Apple do if they have this capability and China puts pressure on them to unencrypt some information on Chinese "dissidents"? China has incredible leverage over Apple, seeing as how all their devices are built there. Would Apple dare resist these requests from Chinese national law enforcement agencies?
Better to not have this ability at all, and thus never be put into this precarious situation.
1-https://apnews.com/699236946e3140659fff8a2362e16f43/ap-acros...
With this I agree completely.
Apple has this ability now, by installing an OS that allows bruteforcing the pin.
Imagine the conversation if Veedrac was running the show at Apple.
Saudi Police: "We need the key to this user's phone because they are suspected of having a video of their own gay sex and we want to prove it and if they are guilty of gay sex, we will give the user 60 lashes and then execute them and their partner by chopping off their heads with a sword."
Veedrac: "Oh, OK, yes here you go, here is a single secure key on a one time basis so you can get the user's video and kill them."
Do you really think this is a great scenario, that Apple wants to actively enable by spending money and effort on their designs to make it happen?
Let’s hear your approach then. Don’t be coy.
Aside from the many, many known cases where they are: http://legacydirs.umiacs.umd.edu/~tdumitra/papers/CCS-2017.p...
And having more mechanisms by which they can access user data is not something that ever should be encouraged.
That's an interesting technical problem. A lot of people dismiss it as impossible out of hand, but they are underestimating what you can do with modern cryptography.
You make it a distributed back door that requires several independent third parties to cooperate to use it.
You choose the third parties so that no particular warrant seeker will be able to get enough power or influence over enough of the third parties to force them to enable the back door unless they think the use is valid and just. (You can actually design it so that the warrant seeker does not know who the third parties are).
Some aspects of this may be too complicated to be practical, but it is not impossible.
All solution fundamentally boil down to someone has the keys required to decrypt all your content. This is ignoring the other technical costs (now your service has to record all ephemeral keys as well).
It doesn’t matter /who/ has that decryption key, the requirement is that access to the key is guarded only by policy.
You also resort to “with a warrant” but a NSL is effectively a warrant, and I’m fairly sure the DPRC has “warrants”. Who gets to request those keys? The position of the us government is that they have the right to access data from people in other countries, so can they provide a warrant to access that data? Can Germany ask for the data for someone in the US? What if someone travelled through another country - can that country now access those keys?
Note these all questions regarding /legitimate/ access, I’m completely ignoring police officers looking up people they stopped and stealing nudes, of people stealing the information and using that information to steal money, stalking, etc
I am sick and tired of people who say “modern cryptography is amazing, so it must be able to fulfill my unicorn dreams”. Either stop claiming nonsense or provide a prove that it is possible by designing a system that does what you say must be possible.
What happens when you’re investigating a criminal act sponsored by one of the governments you supposedly trust? What if they compel the lawyers in their countries to not provide the keys?
I generally dislike “what if” but given the problem space you do actually need to explain how your system works, and how it resolves these problems.
Remember there are plenty of countries with terrible human rights records, but they also still have regular crimes happen.
Then when people point out the problems, you don't answer. You make a lot of assertions that are flat out wrong.
Of course it matters. Apple already has nearly total power to modify their devices, and are clearly acting with caution. American courts are not going to give a warrant so an officer can steal nudes. There is no a priori reason that your phone should require a greater kind of warrant than your home or your bank account, and wanting zero access at all only makes sense if you think law enforcement has negative utility.
Personally I'd do something more like this: Print one code on the inside of each device, so as to make access strictly harder than physical access, store one code internally as per your other mission-critical keys, distribute one key each to choice governments, inside a physical module so as to prevent clumsy storage and reduce the chance of cloning (since singly-owned keys can just be revoked if stolen), perhaps with some protocol so multiple members are needed to agree, if you are particularly paranoid. That way you can only get access if Apple wills (either given a warrant or otherwise coerced), the court wills (either a genuine case or simply corrupt), and you had physical access to the device. Apple could not then backdate court keys, so can only be coerced by China into providing access for future phones exactly as they are already in the position to do, though of course OS updates means they already effectively have a backdoor.
Also: murderers and kidnappers don’t have to use broken cryptography. So again the only people who are harmed are people who aren’t criminals.
Also the statement from the Indiana police is extremely vague, and doesn’t make any details available about what they were doing.
Your foolishly conceived system does have any way to ensure that the several parties are not corrupt or evil. You would need to solve that problem first. Assuming it is solved does not work.
In the meantime, devices need to be designed to protect the human rights of users.
The problem is political, not technical. Apple can't be a fair intermediary for all the various governments and police departments of the world, so they use technology to cede control.