PAM Duress – Alternate passwords for panic situations
github.com
github.com
It started as a simple weekend project based on an off-hand comment someone made in a security professional chat I'm in. I had used duress words in military and translating the concept to a PAM seemed like a fun exercise. Also supports my current shift towards swapping careers from pure software engineering to cyber-research or cybersecurity generally. So in the end, it was a weekend project that served a dual purpose as a resume stamp.
The design use case I had in mind was more benign; such as corporate espionage or journalists getting their devices confiscated (maybe keep a sticky note on the laptop that has a duress password on it as a red-herring). Comments to the effect that law enforcement would image a device are very relevant as any competent law enforcement agency should have their staff trained to get the device fully powered off and hand it to someone that can maintain a chain of custody and get a golden image for use in potential criminal charges.
One thought I had was to apply this to SSH auth for honeypots and if a rockyou.txt password is attempted it runs some routines that aid in crafting the honeypot before the intruder drops to a shell prompt. Another even more light-hearted implementation could be you have password X is the one you login to normally and your "duress" password Y just clears your browser history and is the one you give your spouse for when they log into your computer :). I'm sure there's use cases in the full spectrum and with it being a relatively simple implementation with user generated scripts, it'd be easy to extend to any potential use case.
In any case I'm glad it prompted such a good discussion. Feel free to submit issues if there are particular feature requests or bugs that one might run across. Additionally if there's a PR up, I'm currently the only dedicated dev on the project and welcome anyone that wants to review my PRs; always prefer a 3rd person review even on my own projects. I created a demo video using Pushover and in the process of doing the demo uncovered some bugs that I patched as well as some fixes to the documentation. Again, glad you all found this interesting and humbled it fostered such a good discussion.
I once worked in a place with a keypad duress code on the security system. If you prefixed your security PIN with NN-, it was the duress version of the code and would trigger a silent alarm.
This was setup long-ago, and not communicated. One night, the keypad was acting glitchy. Partially out of frustration (countdown is running), and partially to test, I ended up accidentally engaging the duress code by tapping a convenient corner number, which resulted in NNNNNNNNN-PIN.
After law enforcement had surrounded the building, a quick chat and search alongside a few officers got it all sorted.
(a) begins recording your microphone and webcam video immediately upon login
(b) Aggressively try the hell out of every passwordless Wi-Fi network it can detect, then use headless chrome to aggressively smack every button to get past the stupid login pages
(c) Stream that video and audio to a server that saves it.
https://play.google.com/store/apps/details?id=com.threesixty...
If your camera has an activity light, this might inadvertently worsen your situation.
Thanks, I'm cured.
1) A lot of laptops are sealed with glue. "Just disconnecting the light" would involve prying layers apart.
2) Companies may frown upon that if you should try to modify a company issue laptop.
3) Disabling a recording indicator may be illegal where you live.
2) Don't do personal stuff on your company laptop. If the company doesn't let you modify it, joke's on them, only company files will get leaked. Your personal stuff shouldn't be on that laptop.
3) Fuck that, if there are photons you can collect them
Worst case just do the microphone only.
I guess the system worked and I never forgot the correct prefix after that.
Did the same thing myself my first week in college. Got the police. Told them what I did and I could hear the eye-roll on the other end of the line, and was told I was the third person that day.
[1]: https://en.wikipedia.org/wiki/Rotary_dial#/media/File:New_Ze...
There was another reason for this as it was common, many, many years ago, to restrict the possibility to make phone calls by using a little lock on the dial, like this:
https://www.ebay.it/itm/402554995319?hash=item5dba25c277:g:~...
it was placed on the #3 hole, so that you could dial 112 or 113 even when the lock was on.
Did you introduce the EU emergency number as the national one? If so - good choice.
In France we have the plethora of numbers (15, 17, 18 - I actually do not know what 16 does), and also 112.
We are still teaching "18" as the primary number (you get the firemen who will either come for a fire, or for an accident, or dispatch). We could go for 112 (and keep the older number for a generation, redirecting them to 112) and not rely on people to know which number to call.
UPDATE: I just asked my 17 yo son which number he would call in an emergency and he said 112. So there is hope :)
Also, the GSM system (so almost all mobile phones, world wide) must support 112.
TL;DR Running out of numbers and putting in temporary measures requiring the 16 as prefix. Measures that likely didn't scale as well as expected since we moved on to a different system within basically 10 years.
Thanks for reminding me :)
112 Carabinieri (one of the two national "police" corps)
113 Polizia (the other national police corps)
115 Pompieri (Fire Brigade)
118 Ambulanza (Ambulance)
In Italian it is a common phrase "roba da chiamare il 112" o "roba da chiamare il 113" (something that needs a call to 112 or 113) as a synonym of "a serious emergency" and of course if you called those numbers they would anyway forward the call to the appropriate service (like ambulance, fire brigade, etc.).
The EU emergency number is slowly being introduced (some regions have it already, some not yet), but the 112 is already well in the minds of anyone.
You may know "gendarmerie" from the Louis de Funes movies (Le gendarme de St Tropez, ...) - this is a military unit that mostly works in the countryside.
The "police nationale" is an entity attached to the ministry of interior and does more or less the same things, but more in the cities.
There is a history of hatred between these organizations - yes, this is how stupid we are. They share competencies (the most well known being the elite units - GIGN and RAID)
When you want to call the police, you dial 17 and you get the right one, depending on where you are.
If you have a health problem, you call the 18 (firemen), or the 15 (ambulance).
If there is a fire, you call the 18.
This is why having a single 112 number is easier to teach to children and tourists.
It is a good question.
It depends.
There may be territorial choices or also "political" ones.
Typically Carabinieri have more presence in the country/villages/small towns whilst Police have more presence in larger cities (but there are Carabinieri there as well and - additionally - the local police, which were once called Vigili Urbani and now are called Polizia Municipale, and there is also the Polizia Regionale, to the joy of foreigners that do have a really hard time to understand the subtleties), highways and main roads are typically Police only (Polizia Stradale), but minor roads are usually patroled by the Carabinieri.
So usually you call (called) 112 or 113 depending on where you are (where the emergency happens).
The "political" part is even more subtle.
The Carabinieri are a branch of the military, whilst the Police are "civil", people leaning to the right tend to trust the Carabinieri (whose motto is "nei secoli fedele" i.e. "faithful in centuries") more than Police, whilst people leaning to the left tend to trust the Police as being more independent.
Until not so many years ago if you (or your family) had some relationship/contacts with some (left side) parties or association you would have not been allowed to join the Carabinieri (whether this was official policy or simply what happened is another thing).
The popular perception was (is) that the Carabinieri operate strictly by the Law, whilst Police is a little more "giving/flexible" (on minor things).
On the other hand, once it was easier to join the Carabinieri with a lower level of school/education than to join the Police, so we have here all the jokes about stupidity/ignorance targeting the Carabinieri (the same ones that traditionally in the UK are about the Irish or the Polish).
The old overhead telephone lines could knock against each other in the wind, producing a pulse which (to the system) appeared to be a 1. This could easily happen three times in a row, resulting in an unwanted call to the emergency services.
> The 9-9-9 format was chosen based on the 'button A' and 'button B' design of pre-payment coin-operated public payphones in wide use (first introduced in 1925) which could be easily modified to allow free use of the 9 digit on the rotary dial in addition to the 0 digit (then used to call the operator), without allowing free use of numbers involving other digits
There's a citation, but it's a book from 1950, so not particularly easy to verify.
https://en.wikipedia.org/wiki/999_(emergency_telephone_numbe...
Perhaps it needs the 1 for long distance? (No, it doesn't, the software knows better.) Perhaps it needs a 9 for an outside line? (No, the modem already has an outside line, it doesn't go through the phone system.)
I'm sure you can see what he did.
As part of a duress protocol — where your extortioner is likely observing you — law enforcement would be required to go through the motions of arresting you and taking you offsite. You can expect to be held for X hours regardless of whether they believed you had simply made a mistake.
Long and unavoidable administrative delays make it much harder for villains to subvert protocols. See also time-delay bank vaults and mandatory two-week vacations for pension fund managers, where they are locked out of corpnet.
All orgs should consider locking out all employees for at least one uninterrupted week a year. Very easy way to shake out all sorts of problems.
Could you give some examples?
As a simple example, it's very easy, when starting a company, to issue personalized email addresses to early employees and then people communicate using those email addresses. It's perfectly fine to email the CTO at first-name@example.com, because everyone knows everyone else and it works.
As you grow large, it becomes important for people to address roles rather than individuals. This way, if people leave their role, they can (semi-transparently) be replaced by someone else taking that role who will then continue to receive all of the same emails, be able to respond to them, etc. So then it becomes important to have e.g. a cto@example.com address. When the CTO takes a vacation, their email gets routed to someone taking over their duties, you don't need to communicate to everyone to start emailing somebody-else@example.com instead.
But sometimes it's not just about cooking the books: the last "SSL cert expiration" fire I lived through happened because the person who had credentials to Digicert had to take sick leave. It was never a documented/defined process because "just flip Tim an email" was always sufficient, Tim didn't mind doing the work, and Tim didn't like going on vacation.
Two week lockouts mean there's no chance of shadow IT/back channel work happening, and forces you to document your processes.
[1]: https://www.fdic.gov/news/financial-institution-letters/1995...
It certainly did shake out lots of problems...
(My point is that after having had that happen to me, if it EVER happens again and isn't cleared up within minutes, the sonic boom you hear will be my tactical resume deployment. I dismissed the warning signs as "minor glitches". Never again. However, if it is something planned and I agreed to it beforehand, I guess that's OK. On second reading, you might have been describing something like that.)
Kind a hard word to use for an arrest. In many places police can arrest you for some period if they suspect you have committed a crime. This is no different. No need for sensational language.
And “imprison” and “arrest” are pretty darn close. In the US, when you are arrested, you are usually searched, fingerprinted, and a mugshot is taken.
The mugshot can become a public record. There are websites that match mugshots to names, and make money by being paid to take mugshots down.
Nobody wants the google result for their name to be a mugshot.
If US is doing stupid shit then US is doing stupid shit. What else can we expect a third world country to do? In civilized world you are processed yes, but since you are just arrested and not accused you will just be held until the pre-investigation has concluded
> What else can we expect a third world country to do?
We can criticise the largest economy in the world as much as we want inside a browser developed mostly in the US on infrastructure (the internet) whose large parts were developed in the US talking on a website created and owned by a US based company investing capital in one of the largest tech markets in the world (the valley).
That said - the fact they have police/healthcare/tuition problems does not in fact make it a third-world county.
A developing country ("third world") is typically one with low human development index (HDI) (the US is "very high"). Low economic output (the US is the largest economy) etc.
Imprisoning is a much later step after being arrested. When you're arrested you may end up in a holding cell, or you may not.
For a silent/duress alarm it's easy to cross reference the person at the door with a list of personnel authorized to be in the facility. Security in a scenario like that would normally ask for an ID, radio it back to their security office to validate the person is on the access list for that office/building/facility/etc and then do a quick walk-around.
I mean it happens, the security company sent out a van already (as they should) and called to confirm. They charge a fee (just over €100 I believe? Or €250? I forgot) for false alarms, but that's fair enough. Better safe than sorry.
Anyway, a DIY store with at most 100K in the safe (weekly takings at the time, most of that was probably electronic) is probably a lot less serious than whatever you were working for, to have it surrounded by law enforcement.
I kinda just thought to turn that concept into a PAM as a thought-experiment mostly but there are some edge case security examples where something like this could be useful, say for journalists or when dealing with corporate espionage.
I.e. when you are being selected for random questioning entering US as a non-US citizen, you'd benefit from steganography-like approach: you give a password, and relatively bland, non-personal stuff shows up, giving appearance of full access to a system.
If you only care about your privacy, the next one is to have a destroy-everything script (and it's not that hard: usually, passphrases are only used to decrypt the actual encryption keys, so overwriting those keys should be super fast). This would also work against unsophisticated attacks which are not going to really cost you your life.
If there is a potential for you to be a target of a sophisticated attack and the attacker does not care about taking your life, the biggest benefit is to have a way to inform someone of your whereabouts while you are actually giving access, ideally in a way that buys you time (eg. "webcam has detected stress on your face, please wait another 6 hours before trying to log in again" — sorry, company mandated software, when it happens usually, we call support).
I'm not sure if it's really that simple with modern flash storage. There might be no guarantee that attempting to overwrite some data will actually affect the particular memory cells where it is stored. You would probably have to trigger a secure erase to reset all memory cells and hope that it is correctly implemented by the storage device's firmware.
Is there a practical way to implement this today with Linux? I know VeraCrypt supports hidden operating systems, but I think only Windows?
Recently I had a CBP officer at SFO ask to search photo gallery when returning from vacation.
https://www.americanbar.org/groups/business_law/publications...
Do one of these things at the beginning of any custodial situation.
In practice, courts have generally allowed manual, cursory searches of electronic devices (such as looking at recent photos) as being similar to a search of luggage. However, courts have disagreed on how intrusive the search can be and whether a more invasive search at the border can be conducted without some additional suspicion.
Is that from apps like WhatsApp and Telegram? And SMS? What about email?
What happens if you'd say that you can't, because it's your employer's laptop and data, and it's confidential?
"Oh, I don't use Whatsapp."
So UserA:regularPassword would be one’s usual account, but UserA:obviousToGuess123 would actually log into UserB, and UserA:ohshithelp would log into UserC which has a startup script to secretly call police or whatever.
I mean yeah, a blank laptop looks suspicious, but they can't keep you for having a blank laptop.
edit: not a lawyer, this is not legal advice. The US puts people in dehumanizing concentration camps without due process.
DO NOT DO THIS UNDER ANY CIRCUMSTANCE unless you have first talked with a lawyer about this idea.
18 USC 1001 says (in part):
> whoever, in any matter within the jurisdiction of the executive, legislative, or judicial branch of the Government of the United States, knowingly and willfully falsifies, conceals, or covers up by any trick, scheme, or device a material fact shall be fined under this title [and] imprisoned not more than 5 years
Prosecuting lies to federal agents is a very common technique used by US Attorneys to essentially bootstrap felony charges[1], and federal courts have stretched "materiality" pretty far[2] so saying "oh, I didn't have anything illegal on the 'secret partition'" might not save you.
IANAL, but this looks awfully close to a felony.
[1] https://www.popehat.com/2010/02/26/rule-2-go-re-read-rule-1/
[2] https://www.justice.gov/archives/jm/criminal-resource-manual...
> Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed under title 11, or in relation to or contemplation of any such matter or case, shall be fined under this title, imprisoned not more than 20 years, or both.
I mean, you’re not seeking to obstruct anything other than a federal agent looking at your personal pictures, which they explicitly do not need to fulfill their duty.
Now if you were removing evidence of your crimes.
Anyway, I know it doesn’t work that way, but I think it should.
Similar case law exists in this context, but for actions like running from the police.
IANAL but play one on tv
An attorney will tell you what is legal. An excellent attorney will tell you what you can get away with.
Strong language I know, but prisons are full of innocent people.
The simplest example is asking “Do you know why I pulled you over?”. Typically, people spontaneously confess to speeding, sometimes they break down and admit that someone is wrapped up in a rug in the trunk.
The courts have consistently ruled that customs is different and you can be searched without a warrant. Don’t cross borders with contraband or evidence of criminal acts/dissident identity/your email correspondence with foreign agents/etc.
1. The probability of your being in a stressful situation without the option to leave is high - you probably arrived via plane, so you can't simply go back, and you don't know the local laws well.
2. You usually know that a customs checkpoint is upcoming.
So, in that case, it's far better to prepare (i.e. don't bring things you don't want searched/compromised) and cooperate.
I was once "detained" whilst going from France to England while the customs official searched my bag.
I complained to the UK immigration and the same customs officier called me back, searched my bag again, and said "unless you agree to withdraw your complaint, we are going to have to continue searching your bag until the train departs and you miss it".
i.e. costing me about £150 in expenses.
As expected, I withdraw it and went on my way.
However I now make a point to record the name / number of custom officials I make a complaint to -- in case they turn out to be jerks like the UK one was.
"It may harm your defence if when questioned you fail to mention something you will later rely on in court".
Failure to answer can seriously harm your defence and I've heard of people I personally know (though I wasn't in the courtroom) where the prosecution hammered the point that they "came up with a plausible sounding story" after the arrest.
Obviously Border Patrol is not the same as being arrested; but this is an important caveat for the video posted.
Talk to british police. If you feel like lying, keep your story straight or give basic facts.
As even the Wikipedia article on it[1] notes:
> If this failure occurs at an authorised place of detention (e.g. a police station), no inferences can be drawn from any failure occurring before the accused is allowed an opportunity to consult a legal advisor.
The "Don't talk to the police" is not the full point made in that video, it's "Don't talk to the police… until you've spoken to your legal advisor and not without a legal advisor present".
So, *don't talk to the police*, they're not your friends and they don't have your best interests at heart and it's their job to get evidence against you, not yours.
[1] https://en.wikipedia.org/wiki/Right_to_silence_in_England_an...
I was asked this once, after I read a hilarious reddit comment, and found myself in a similar situation. I looked at the cop and said "it's not because of the pot in my trunk is it?". "Step out and open your trunk, sir". He opened the trunk to find a crock pot I had just purchased. I could tell he was flipping through emotions from stifling laughter to being highly annoyed. They eventually let me go and told me to slow down with a half smirk.
I don't recommend doing this, and I have zero plans to ever do it again as it wasn't as simple as stepping out and showing my guilt/joke. I was detained, backup units showed up, even a K9. They didn't search the inside of my car, but they did inspect other items inside the trunk to make sure I wasn't pulling a fast one on them.
I was also pulled over once and accused of running a stop sign that I knew I didn't run, because I had seen the cop sitting there as I pulled up to the stop sign and made extra sure to completely stop. Due to the time of day, I believe he was (illegally) fishing for a DUI stop, and had considered filing a complaint with the department but never did.
>simply admitting
no your best option is not to say a GD thing. story time: i was once pulled over on the eastern shore by a cop that was barely my age. i didn't say a word to him for the 10 minute stop. that really messed with his mental state and I could tell his internal hard drive was returning a seek error. at the end he stammered out "o-okay, w-well you slow down and haveaniceday" then he quick walked back to his car and turned down a side road.
NEVER TALK TO COPS.
I'm sticking by what I said. As I clearly said in my post, I was only referring to minor traffic infractions where you know you're guilty. I guarantee I would have gotten some or even all of the tickets I got out of if I had blindly followed "NEVER TALK TO COPS" advice.
"Dr Heizenburg, do you know how fast you were driving?"
"No, but I know exactly where I am"
>"Dr Heizenburg, do you know how fast you were driving?"
>"No, but I know exactly where I am"
To which the police officer replies "You were driving at 145 km/h!"
Heisenberg whispers to his passenger, "Great Erwin, now thanks to this idiot we're lost". The officer overhears him, and angrily orders them out of the car. He searches their glove compartment, and then opens the car boot. He reels back in shock:
"Did you know there's a dead cat in your boot‽"
The passenger grumbles "Well, we do now…"
I would go as so far as to say that most border agent's that search phones are probably not even aware that this is a thing that people do. Sure they might have gotten training in a classroom for it, but as far as real world experience goes, maybe 1 out of every 5000 people has a setup like this.
This scenario was considered by the author
Then you could setup a dummy account that doesn't have too much of interest in it.
Combined with pam crypto to encrypt your home on login, the result is something that is reasonably private against casual inspection.
I used to use this back when I couldn't afford to travel with a disposable use laptop...
> Forensics agent pulls and mounts hard drive
> Agent sees /home/hiddenuser
> Government seeks search warrant for content
> DA demonstrates recent knowledge/use of /home/hiddenuser
> Judge holds you in contempt until you provide encryption keysConsider the alternative: You're not worse off than you would be if you didn't hide it.
Hiding your login is a good security practice against all kinds of potential coercion.
> Forensics agent pulls and mounts hard drive
Is this what the typical airport threat scenario looks like? How do they do this with soldered in drives? > Agent sees /home/hiddenuser
Or they see nothing, because your drive is encrypted. They come to ask you for the key, you comply they see $blandaccount with some seemingly important company data and a scary corporate message as the desktop background (as justification why there is even encryption). Bonus points if you complain about it yourself ("If you ask me all of this is a bit paranoid"). Afterwards you use the real key and see $realaccount, because you thought about plausible deniability and how to use it propperly – if you still trust the integrity of your device, that is.Probably good practice to take a phone from 'scratch' to 'setup' regularly anyway. Like restoring backups.
Heck. You could set it up so that it scans both eyes and then does a second scan where you choose what your ok signal is (both eyes, right only, left only, no eyes).
A PIN disarms the alarms system, the same PIN + 1 disarms the alarm system and notifies security.
Edit: made it make sense
It’s been done before: https://m.youtube.com/watch?v=rufnWLVQcKg
One thing I have thought about doing is providing mistaken information to the caller and see if they go along with it. I came up with this idea when one bank said they could send me a text message and I could read back the number to them (huge red flag).
Does anyone else have any ideas for how to authenticate a BigCorp caller whose corporate policies do not allow them to provide any account information to the people they are calling?
The only way you can be sure you are talking to your bank is if you are calling them.
I can understand this attack via land line, but who seriously has a land line in 2021? Even my 93 year old grandma has a mobile phone. (Albeit we did get her one that looks like a land line phone :D )
I also use a landline fairly often (mostly out of habit), and most companies only have my landline number as I don't want them contacting me while I'm out/busy.
You're right that it's a dwindling number, but it's certainly not at zero yet.
How hard is it really to redirect outgoing calls?
After 10 minutes in a verification tug-of-war, the rep escalated me to someone who did provide proof they were actually Google (using a field I updated in my account). All up it took 15 minutes and felt very fraudulent until they finally gave me some helpful context.
I hope you managed to communicate that you needed it to be able to independently verify that this number belonged to the purported caller. Eg, if it's from your "credit card company", the number should show up on the credit card company's website.
And they are starting to understand more and people know that too.
Typically banks, when challenged here in Australia, will ask you to hang up and call the number on the back of your card (debit or credit).
Normally they give you a reference number so when you are speaking with someone, you can bypass things and pick-up with the person you were originally speaking with.
I mean, it's really their problem, isn't it?
If you need something from them, call their customer line and ask. If they need something from you, then they'll figure it out.
I had a financial institution call me one time and ask
"Is this nucleardog?"
"Yes."
"Alright, this is reallyfastwords can we start by verifying your date of birth?"
"No. You called me. I didn't even catch who you are. What can I help you with."
"I'm with really fast words. I can't tell you anything until I verify your identity."
"You called me. You verify your identity first."
"If you don't verify, then I can't tell you why I called!"
"That's fine."
There was a loooong pause before she finally decided on "Okay, what _day_ in June of 1985 were you born?" and apparently that was satisfactory.They'll typically make it your problem by blocking a transaction or your account...
Definitely. Hang up the phone and call the phone number on the card associated with your account or look up the appropriate telephone number and call them back.
If they're legit, they will be perfectly fine with that. If not, they'll likely squawk about it.
Either way, the correct process begins with you hanging up without providing any information to the caller.
My bank will also send SMS "fraud alerts" with a request to confirm or deny a transaction. That's the same situation, IMHO and the right action is to call the known to be valid phone number for their customer service.
Perhaps there are other, fancier ways to do something like this, but as a general rule, scammers can't change the customer service phone number printed on your card, or hack third party services just to give you a fake phone number online.
Bank: Hey I'm calling from HSBC, want to verify it?
Me: Sure
Bank: Ok, so open you mobile app, and enter 637482
Me: Ok, cool thats given me 274893
Bank: Yep, that's all confirmed so ...I click the link and authenticate with my bank credentials or mobile auth certificate.
The CS rep gets my info, which is authenticated to be correct and we get on with our day.
Face ID: https://support.apple.com/en-us/HT208109
Fingerprint Readers: https://www.samsung.com/us/support/answer/ANS00082563/
These are extant, and either part of or required within numerous presently-used systems.
I've a device (Onyx BOOX) which apparently can only be password-secured if I create a vendor-based account on it. (I've been trying to see if this is bypassable, so far, no dice.) That's not biometrics, but it's a case of being strongly limited by a system architecture.
If you're using a device at the obligation of an employer, you may well find that it has, and/or organisational policy requires, biometrics.
It's increasingly difficult to find devices that don't include some form of biometrics-based functionality. The notion that that becomes the primary or only means of securing access is not entirely far-fetched.
Capabilities, possibilities, and dependencies have a really funny way of becoming hard requirements over time.
I could speak the Celtic of my ancient ancestors or communicate in cuneiform or ancient Egyptian hyroglyphics, if really wanted to. My ability to integrate and participate in modern life would be quite limited. The online and digital world are rapidly approaching this state.
Security is all about threat models, and I can imagine quite a few scenarios where biometrics might fare better than passwords. Shoulder surfing and trivial passwords/PINs come to mind, for example.
And who said that it's biometrics vs. anything else? It's quite advisable to combine authentication factors.
But this article is about a system for giving up passwords under duress without necessarily compromising all your security, such that your antagonist has no way of knowing or showing that there's another password concealing more important information.
If “those guys” are your adversary, you were fucked before you started.
Complying in the face of threats of physical violence is equivalent to "being easily swayed"?
You seem to have a pretty specific threat/defense model that you didn't clarify. I wouldn't generalize from that to "biometrics are bad for all users in all situations".
What I'm saying is that if such threats are unacceptable to a person, chances are they are not going to involve themselves in the sort of activities that require keeping secrets in the first place, or are sufficiently disciplined to have weak device security because they don't write anything down.
How, exactly? And "require users to watch out for shoulder surfing and use strong passwords" does not count.
Any chance you are thinking about pretty specific circumstances here (security-aware, technical employees generally not having to enter passwords in public spaces)?
Blackberry phones had this feature and it was pretty bulletproof.
[1] https://f-droid.org/en/packages/net.typeblog.shelter
[2] https://f-droid.org/en/packages/com.oasisfeng.island.fdroid
All this would do is make you appear in a worse light to the deciding judge when it comes to trial or get your other kneecap shattered in a not so civil situation.
Neither of them know anything about me.
It reminds me of the Trezor hardware wallet that allows you to have multiple passwords into your account. If your forced to give access you can log into the version with little in it. Nobody knows that you have secondary accounts with more in it...
AFAIK if you actually get detained and questioned at airports, your drive will already get imaged before any password is even tried. You may be able to get away with this on a mobile device where this feature isn't generally expected (because who uses Linux on a smartphone in the first place).
I always wonder at what scenarios like these are supposed to be about. If saying no is not an option, pissing off your captors by giving them fake info probably isn't either.
I don't know what law enforcement would be looking for on my work drive, but if saying no is no longer an option, my encryption password isn't worth getting shot over.
They don't keep it from being applied.
The duress credentials are meant to create plausible deniability of non-compliance, by giving the appearance of a genuine login which just reveals nothing.
Or you could just be dealing with someone who DGAF. This ultimately seems to be a chief characteristic of many situations in which strong crypto is proposed. It's the breakdown of civil liberties, rights, and rule of law which might be the true ur-problem here.
Keep in mind that the duress credentials serve several purposes.
1. Give the appearance of compliance. It's possible that the investigator will be satisfied and abandon further search attempts. Wrench averted.
2. Provide the opportunity to perform a duress action, without the immediate appearance of doing so. This has a wide range of possibilities, including removing or disabling access to information, triggering warnings or notices to allies or supporters, revealing innocuous content, enabling a set of additional countermeasures (e.g., attacks from within the investigator's own space or network, or against the investigator's own tools, see Signal's response to Celebrite: https://signal.org/blog/cellebrite-vulnerabilities/). Note that a protocol which denies the investigation subject access to a device would prevent this. The presumption that a subject would provide an access password provides opportunity for defences.
Whether or not the pipe wrench (or any analogous or equivalent means of coercion) is applied is almost a moot point. With a duress password, you're largely assuming it will be. The objective isn't to prevent the wrench. It's to render it ineffective.
Or at least that's the way I read it.
Then I'll just use a script that doesn't make it look like I deleted everything.
Bad guy types in honeypot password
A new update to Docker is available.
Restart now to apply the update
or subscribe to a Pro account
to delay this update.
"Oh, bugger."The “real” problem is either: (a) You know the authorities want access to your data because <x>, and you travel across a border with it. (b) You possess sensitive information and are not aware of law enforcement’s desire to get it; (c) You’re swept up at random; (d) You’re a criminal, or carry a paper trail of potential illegal activity.
Solutions:
(a) Means you are stupid. The only way to win is not to play.
(b) Means you either didn’t follow your employer’s security guidelines or aren’t aware of the risks associated with whatever is on your device. You can’t solve that problem without understanding that.
(c) You should use discretion re: what you cross a border with and either accept the risk or do something else.
(d) Don’t really care. See (a).
Good luck doing that on 2016ff MacBook Pro's (they all have soldered storage) or any Windows 10 laptop with TPM-backed Bitlocker encryption.
In a jurisdiction that doesn’t adhere to the rule of law you are already screwed.
What people often don’t seem to comprehend is that if you get picked up by a “secret police” in the middle of the night it’s pretty much game over already.
If it’s the FBI then fearing for your life isn’t exactly part of the equation really.
And these days, it’s common for the decryption keys to exist only in a Secure Enclave type thing that makes extracting those keys many orders of magnitude more difficult that asking you for your password while they hit you with a wrench.
> for example a mail could be automatically sent from his computer to a rescuer, a script could delete sensitive files in his hard-disk or a certain Rick Astley song could be appropriately played
And I’m just imagining someone having set two duress passwords; one for kidnapping situations and one that they put there as a joke. And then they get kidnapped and they try to input the one supposed to call for help, but they misremember so they input the rickroll trigger instead.
And the kidnappers are like “hey what the hell, you think this is funny man? turn that off” and the kidnapped person cries for having messed up their one chance at calling for help.
https://www.kali.org/blog/emergency-self-destruction-luks-ka...
I can absolutely see that.
The only way I can imagine remembering a duress passphrase is to make it slightly different in some way.
So that means I'd have to keep updating my duress passphrase alongside my regular passphrase.
Either way I love this idea and I might actually start using it. I'm just trying to figure out how to set a practical passphrase I will be able to remember. My passphrases generally are in muscle memory after having entered them for a few days.
Edit: A simple system I just came up with is to use one of the numbers in the passphrase and increment it by one to indicate each level of duress.
I was flying into Atlanta (Intl) with “radioactive” rocks (not on purpose, just picked some up near a volcano, they looked cool) and they flipped their collective shit. I was taken to a separate area where they dumped my stuff next to another guy who got pulled into “routine” inspection. This other guy “forgot” his phone pin earlier that day… he was still there four hours later, after my four hours of reasonably straight forward BS.
rm -rf /secret/files > /dev/null 2>&1
That pipes STDOUT to /dev/null and redirects STDERR to STDOUT.https://www.huffingtonpost.ca/2017/02/22/canadian-man-custom...
5 years on we're somehow all managing our own crypto keys, the phone is the key to unlock our digital lives, so we're all in the counterintelligence game. more tools like this.
Not sure if there's a linux alternative.
Anything else is simply not safe at all or might cost you prison time, check the UK laws on this.
Maybe a more modern concept would be to both a) have a duress private key, that triggers duress scripts in the same way, b) an implementation of ssh-agent that adds the duress private key when a duress password is entered?
You could just as easily use this on your client machine and have it delete your private keys if you try to login with the duress password.
And http://dmsteg.sourceforge.net/
Alas, work in this space appears to be abandoned, too bad too because much could be done to improve robustness when writing with umounted aspects, or preserving security against attackers that can take images of the disk at different times.
Not to mention: integrating the results in standard software so the mere presence of the software on your host doesn't harm the deniability.
Which you can’t, because there is no password at this point. So either you admit that you just wiped your computer with the panic password, or you can shut up and rot in jail until you die.
You need a way to make them believe you. Covertly wiping your computer is probably not going to end well.
https://nakedsecurity.sophos.com/2016/04/28/suspect-who-wont...
In a number of countries there is a defined offense, like in Australia if they don't believe you they can jail you for six months under the Cybercrime Act, 2001, or possibly 2 years (failure to obey a court order under the Crimes Act, 1914).
Real law enforcement agencies would also simply confiscate the device and hand it to a forensic team to pull a "golden image" from it to work with in lieu of a user session.
I always wondered why more services don't offer it.
The reason we have it is it's a fairly political place (not by design, but when you offer 'free speech' you get everyone booted from every other place) and we've had a fair few members arrested, and I'd hate to think my site contributes to that so easy wipe.
Call it Duress/Panic/Boss/Jealous Boy//Girlfriend/Puritan Family Mode or whatever.
iOS has something called Guided Access which sorta helps a little bit but is very obvious to the other party.
I would assume the user shouldn't understand that he was given a duress password, so is transparent the right term here?
woD3PRBgELFHH9nuABH]ksD
Duress password:
duress123
It reminds me a bit of Jon Lovitz Pathological Liars Anonymous bit. "Okay! Here's the password...ya that's the ticket."
A project that's 2 days old should be using $XDG_CONFIG_HOME. My home directory is where I need a clean slate, not your clutter.
Some partners expect to share passwords as a trust thing, but my work does not allow it (and most personal devices have access to work stuff).
if passwords also covered account scopes -- which is what this tool enables one to monkey-patch into the OS, i could give you my password so you could gorge on my code without me having to worry about you reading my journals or abusing ~/.ssh
other than that, i second your notion.
I'm thrilled by the idea of using passwords to switch between the sorts of things i do without having to log-out.
Also, if you're being physically compelled to provide a passwords it seems your personal safety is already compromised.
One could even write in a routine that removes the duress module entirely so it's a one-shot duress password that cleans up sensitive data, notifies anyone who needs it and then immediately removes all evidence that pam-duress was employed.
But you are right this is a tool with risks/benefits and the risks changed based on what's being protected and the context of the coercion.