All this would do is make you appear in a worse light to the deciding judge when it comes to trial or get your other kneecap shattered in a not so civil situation.
All this would do is make you appear in a worse light to the deciding judge when it comes to trial or get your other kneecap shattered in a not so civil situation.
Neither of them know anything about me.
It reminds me of the Trezor hardware wallet that allows you to have multiple passwords into your account. If your forced to give access you can log into the version with little in it. Nobody knows that you have secondary accounts with more in it...
AFAIK if you actually get detained and questioned at airports, your drive will already get imaged before any password is even tried. You may be able to get away with this on a mobile device where this feature isn't generally expected (because who uses Linux on a smartphone in the first place).
I always wonder at what scenarios like these are supposed to be about. If saying no is not an option, pissing off your captors by giving them fake info probably isn't either.
I don't know what law enforcement would be looking for on my work drive, but if saying no is no longer an option, my encryption password isn't worth getting shot over.
They don't keep it from being applied.
The duress credentials are meant to create plausible deniability of non-compliance, by giving the appearance of a genuine login which just reveals nothing.
Or you could just be dealing with someone who DGAF. This ultimately seems to be a chief characteristic of many situations in which strong crypto is proposed. It's the breakdown of civil liberties, rights, and rule of law which might be the true ur-problem here.
Keep in mind that the duress credentials serve several purposes.
1. Give the appearance of compliance. It's possible that the investigator will be satisfied and abandon further search attempts. Wrench averted.
2. Provide the opportunity to perform a duress action, without the immediate appearance of doing so. This has a wide range of possibilities, including removing or disabling access to information, triggering warnings or notices to allies or supporters, revealing innocuous content, enabling a set of additional countermeasures (e.g., attacks from within the investigator's own space or network, or against the investigator's own tools, see Signal's response to Celebrite: https://signal.org/blog/cellebrite-vulnerabilities/). Note that a protocol which denies the investigation subject access to a device would prevent this. The presumption that a subject would provide an access password provides opportunity for defences.
Whether or not the pipe wrench (or any analogous or equivalent means of coercion) is applied is almost a moot point. With a duress password, you're largely assuming it will be. The objective isn't to prevent the wrench. It's to render it ineffective.
Or at least that's the way I read it.
Then I'll just use a script that doesn't make it look like I deleted everything.
Bad guy types in honeypot password
A new update to Docker is available.
Restart now to apply the update
or subscribe to a Pro account
to delay this update.
"Oh, bugger."The “real” problem is either: (a) You know the authorities want access to your data because <x>, and you travel across a border with it. (b) You possess sensitive information and are not aware of law enforcement’s desire to get it; (c) You’re swept up at random; (d) You’re a criminal, or carry a paper trail of potential illegal activity.
Solutions:
(a) Means you are stupid. The only way to win is not to play.
(b) Means you either didn’t follow your employer’s security guidelines or aren’t aware of the risks associated with whatever is on your device. You can’t solve that problem without understanding that.
(c) You should use discretion re: what you cross a border with and either accept the risk or do something else.
(d) Don’t really care. See (a).
Good luck doing that on 2016ff MacBook Pro's (they all have soldered storage) or any Windows 10 laptop with TPM-backed Bitlocker encryption.
In a jurisdiction that doesn’t adhere to the rule of law you are already screwed.
What people often don’t seem to comprehend is that if you get picked up by a “secret police” in the middle of the night it’s pretty much game over already.
If it’s the FBI then fearing for your life isn’t exactly part of the equation really.
And these days, it’s common for the decryption keys to exist only in a Secure Enclave type thing that makes extracting those keys many orders of magnitude more difficult that asking you for your password while they hit you with a wrench.