Plausibly deniable encryption (2020)
spacetime.dev
spacetime.dev
Sorry this is only in German but maybe you can find English sources about it
https://de.m.wikipedia.org/wiki/Wiener_Neust%C3%A4dter_Tiers...
On the other hand prison works rehabilitated in to society.
> Not sure I feel comfortable with celebrating breaking the law.
I don’t know where you live, forgive me if this comes off condescending.
In the US, celebrating activism with illegal techniques is part of the fabric of our culture, institutional and even foundational. Approximately everyone is taught about:
- the Boston Tea Party, and the Revolutionary War which that and similar actions ultimately precipitated
- the Underground Railroad and other actions to smuggle slaves to their (relative) freedom
- various illegal actions in the Civil Rights movement, from sit ins at segregated businesses to Rosa Parks’ refusal to sit in the back of the bus to Freedom Riders crossing all sorts of state/county lines to help ensure others’ access to polls
There are of course other illegal actions which are less taught/known but nevertheless shaped our society in ways few could disagree with. We have strikers and work saboteurs to thank for the 5-day/40-hour work week. We have the Black Panthers to thank for breakfast and child care programs in schools, as well as the proliferation of community health clinics.
Some of these were not non-violent actions, some of the actions taken in these contexts and others which moved us as a society forward were morally complicated. But at least from my historical perspective, I cannot justify deference to the law as a moral imperative. Sometimes, often even, it’s the law which is morally unacceptable. And the moral imperative is to go beyond it.
Edit: I don’t want to trivialize that courage either. Challenging power can be an incredible risk. Most people under most circumstances will choose to limit their risk no matter what the moral question. I’m honest enough to say, even though I’m not proud to, I haven’t taken all of the risks I wish I had.
Things can be right regardless of the law, history is filled with false and immoral legislation.
Original poster made it seem like there is some unique American culture of anti establishment and celebration of courage and activism. Then goes on to enumerate examples that are now obviously celebrated.
My point is that it's a survivor biased argument. It's very easy _now_ to celebrate past activism that ended up on the good side of history. There's nothing special in American culture about that.
We are talking about a country that started wars on false premises, tortured prisoners, incarcerated whistle-blowers, economically bullies most of its competitors, elected an ultra conservative president, have one of the worst immigration integration policy, etc etc.
> In the US, celebrating activism with illegal techniques is part of the fabric of our culture, institutional and even foundational.
I'm sorry but that just strikes me as plain.. . Maybe that's how Americans see themselves, but get back to earth, 99% of the world would roll on the floor at this.
Most of the activism enumerated in the comment is actually a minority's activism against social problems that only existed in the US in the first place. It requires a very twisted argument to celebrate US activism on issues that the US created for itself.
It’s odd to frame actions by some in the US to right wrongs in our country as “issues that the US created for itself”. I mean yes, as a country slavery is a horrible stain on our history. But the abolitionists who fought it since before the US even existed and continue to this day are not implicated in that. And that’s my point: rejection of immoral laws and power structures is valid, and equating legality with morality is sometimes and even often wrong.
I can’t say I lose a seconds sleep over the “victims”, they are weak minded crybabies
EDIT: Not that I'm defending any particular prison system or making a moral statement here. In many countries the prison system is horrible and probably not even very optimal at preventing offences. It's just that in my mind the prison has one main purpose; to act as a deterrent for crime, and most of the time, for most of the population, it somewhat works for that purpose.
I am curious if the getting a job using the A-level, reduced your likelihood of reoffending, at the risk of your current job ?
Dear John Doe,
Please inform us when and where you plan to infringe the law again. Thank you in advance.
Sincerely,
your government
I found the "Seek first to understand, then to be understood" rule in the 7 Habits book illuminating.
If only government, lawmakers, and the electorate in general, understood it.
The intent was for the intimidation to work, so regardless of how sturdy the character. Its hardly a victimless crime.
Marching and demonstrating maybe not as effective, but I find it hard to celebrating trying to harm another person, regardless of how ineffective. Non-violence is a good way to change unjust laws, intimidation is not just.
Rehabilitating someone with "radical" ideas would involve acknowledging and challenging their ideas. That's not how rehabilitation really works even in theory - most rehabilitation is taking criminals who aren't ideologically motivated and solving the much simpler problems of educating them so that they can work.
Reading this, I'd bet £1000 to spat out sweet you are US-American?
Because elsewhere, most of the civilised world treats prison as rehabilitation.
* Retribution ("a punishment")
* General prevention ("a jailed person cannot keep hurting others and prison threat is a deterrent")
* Special prevention (rehabilitation)
Last time I looked, most countries are mostly for general prevention with a pinch of special prevention. Retribution is not currently defensible philosofically or technically, though some people errounesly think it's the basis of the system.
I look with envy at how they do a lot of things.
I would assume that rehabilitation does not focus on changing people's ideological values.
Am I wrong? Is that a thing in other countries?
Few countries in Western and/or Northern Europe? That's a very narrow definition.
Even without the spelling or the previous reference to GBP, I could have guessed nationality from your tone.
As far as I understand it, lengthy sentences don't work -- the likelihood of getting caught does. (I mean in a statistical sense. But I might have read this before the replication crisis, so caveat lector.)
... but also: Do you have any evidence of your claims? Literally any evidence of being who say you are?
This.
Many crimes are barely enforced; I'm thinking of some kinds of moving-traffic offences such as using a phone while driving. Because it's not enforced, people keep doing it; so the government increases the fines.
But increasing the fines has zero effect, if everyone knows the law isn't enforced.
I kept asserting my rights until the cops threatened my wife, then I told them they could write down whatever they wanted and I would sign it. Took 7 years of being in jail before that piece of paper got in front of a judge and he threw it out, though.
The ironic thing is that the police waited about 2 years after they seized the laptop to ask me for the pass phrase. I’m not sure I even actually remembered it as it was so long. PGP Whole Disk Encryption ftw. At the time WDE wasn’t available on the mac and the police got loads of data from my pals text editor temporary files. No one got anything from mine hahaha
"Tell me, what's your password?" says the adversary, "It's 'kissmybloodyhemorrhoidsassyoudumbshithahaha!', all lowercase, no space, ended with a exclamation point".
The password is cryptographically secure too since it's long. And it's easy to remember, relatively easy to type in. All around, simply a good password.
If there's no way to 100% establish that all the money has been extracted, an attacker might keep going indefinitely to see if there's more.
That creates an interesting game theory situation though, where nobody has any incentive to disclose anything, since it wouldn't change the outcome anyway, which ends up negating the whole point of torture: the victim needs to believe that the tormentor will stop if they disclose the truth.
(Unfortunately, the real world isn't a game theory problem…).
Anyway, you're right that the real world isn't a game theory problem, but I do think that if someone is faced with being tortured for information, they should at least attempt to ask the torturer "How do I know that you will stop when I give you the information?". Or, perhaps less incriminatingly, "I don't have that information, and it doesn't matter because you'll keep torturing me regardless".
You may not be able to convince the torturer to give up on the torture (much less convince them to let you go free), but you might at least be able to convince yourself that there is no point talking or trying to come up with a lie. Having said that, it's also instructive to look at the example of Marcus McDilda who was tortured by the Japanese for information about atomic bombs, about which he knew nothing.[2] His lies may have saved not just his own life, but millions more.
[0] https://en.wikipedia.org/wiki/Rubberhose_%28file_system%29
Anyone who will torture you for information is going to include this in your torture now, just fyi. Might as well just ask them to let you go.
Include what? If there's some convincing proof that the torturer can give that they will stop, I would be interested to hear it.
If you hand over 3 guns at the door no one expects you to have a fourth.
You need your proverbial money clip with $50 that you can throw and run when you're being mugged.
STREET SMARTS!
She could claim that the key for those books has been lost or forgotten.
I wonder if this "I forgot" defense is more accepted now that there are stories of people having forgotten the password to their multi-million dollar cryptocurrency wallets.Boy, did the universe pull a monkey's paw on him for that.
https://catless.ncl.ac.uk/Risks/16/87#subj3
(This is an article I wrote for Risks digest in 1995 regarding a proposed law that would have made it illegal to transmit pornography over the internet.)
Nice article with great points. I gave a talk about this in 2005 on why the more data intelligence agencies collect the worse their results if their analysis does not match their reach. It goes back to Quine and Shannon's ideas of salience as pre-agreed patterns of interpretation.
The talk was actually about a spooky phenomenon called "listening in readiness". Mediums/charlatans and other cold-reading hucksters used EVP (electronic voice phenomena) in the 1930's and 40s, when radio, Theramins and such-like were more woo-woo and barely understood by ordinary people. If you play what is essentially noise/static to people and _tell_ (or suggest) to them that voices are saying something - they will hear that.
The phenomenon is surprisingly reproducible. It works because the cochlea and auditory neural system (See a text like Nelken, King and Schupp's Auditory Neuroscience) can "listen in readiness". We have affective and sensory hairs and feedback loops in the cochlea that allow us to "tune" to what we _expect_ to hear. In simple words, people can hear what they expect/want to hear.
When we apply AI and adaptive filters to data, a similar thing is happening. False positives, indeed very elaborate misinformation can be derived in intelligence work based on unsupervised (arbitrary mass surveillance) when the gatherer starts with an a-priori idea of what they are looking for and sifts through chatter.
I am not sure exactly how yet, but I think this can be leveraged to some good use in privacy protection if, as in the Dissident scheme discussed in TFA, there is some "fuzzy" decryption and very many plausible but false decodings adjacent to cipher-text.
This leads to the idea of a cupher that is apparently very easy to crack, but yields a false plaintext. When you "can't remember" the password, your adversary finds a low hanging "trap password" and smugly thinks they defeated your poor opsec.
This isn't a chess match between equals. This is someone who can ruin your life just to make a point. Even keeping you in custody for a day or three can screw up a lot of people.
The Lockpicking Lawyer put it pretty well recently. The people who make locks are following rules that nobody else is beholden to follow. The designer looks at the parts and thinks about their purpose. Their design. The picker is looking at what they can make the thing do, not what it's 'meant' to do.
They are repurposing things, to circumvent the wishes of the manufacture and the consumer. That's where the wrench comes in. That's where cloning the device comes in. That's where giving the adversary a fictional win to regain your liberty comes in.
Real life scenario:
https://www.yahoo.com/now/dutch-bitcoin-trader-suffers-bruta...
If they know you're hiding something, for certain, they'll go to much further lengths to find that out compared to suspecting you might be hiding something and finding some other stuff you'd obviously like to hide. If you've got an envelope with 100k in your pocket and you get mugged throw your wallet at the dude as quickly as possible and just book it - chances are that the mugger will either: A) consider the risk/reward at this point to be too dangerous since they've already got a nice bit of cash or B) assume you're just scared and have nothing else. If you say "Hey, I just threw you 200$, I'm going to run off with this 100k now" you're definitely not going to have a good day.
It took 7 years of sitting in jail to get the judge to watch the video and throw shit out.
And that doesn't really apply to the CBP and the CBP equivalents of other countries. They're ruthless and can lock you up in cages, there isn't really the opportunity to start a "case" until you're past the CBP. If you aren't a citizen you sadly don't have access to a lawyer if the CBP wants to hit you with a $5 wrench, because you aren't even in the US yet.
These days there are established procedures and protocols that prevent this.
But this isn't plausible deniability. You still have a hard drive in your possession and it's still covered by random data. Better deniability: always use an external drive and then distance yourself from the drive. You want plausible deniability of the entire drive to the extent that no one even suspects you of being the owner. Or, have such little sensitive data that you can use steganography to hide it in an image or video file. Just don't put the steganography tools on the same computer as the hidden data.
Anything else is pretty much a joke.
TPM chips are useless because there's already tools available to listen on the SPI bus for encryption keys. [1] [2]
It's only a matter of time until other key formats (other than Bitlocker) are supported.
I think the only way to secure the drive is being able to write your own drive controller firmware. But even then HDD plates could be just "swapped into" another HDD.
There are lots of ways to hide encrypted data such that it is not obvious that there is any data at all to be found.
If I read it correctly, then the adversary might extract the data decrypted via the decoy key, and then reconstruct the encrypted payload using the extracted data and the decoy key. By comparing reconstructed encryption payload with the actual sample, it is easy for the adversary to figure out a better `m` to determine whether Alice is hiding something or not.
I assume the approach that the article is showing only works if the encrypted meaningful data is stored in a fix sized container (say a disk volume or a fix sized file) that is initialized with random data, so knowing the size of `n-m` doesn't matter.
> She could claim that,
It just don't work like this if the adversary knows that you have installed some encryption software on your system that allows you to decrypt different content with different passwords.
Just hide your real crypto wallet on one of your 10 years old HDD that still got Windows 7, Microsoft Office and Doom installed. Encrypt the wallet, then put it inside C:\Windows\System32 or similar and give it a system-like name such as `sysdump`.
After you've done that, make a fake crypto wallet and put it on a expensive USB drive, lock the drive in a safe, then hide the safe in a hole of your basement.
If so, do I need to disable TRIM? If yes, in Windows or the BIOS?
In practice, it depends on the level of paranoia that's needed for your situation. Trying to prevent your average thief from getting your bank info off your laptop? Probably not an issue. Hiding data from the NSA? Possibly a problem. I run TRIM on my SSDs, but I also live in a country where theoretically I don't have to give up the key. Admittedly, I'm not doing anything illegal, the only thing they'll find are a bunch of git repos, game installs, 2000's alternative rock, Scandinavian folk metal, and bad vacation pictures.
Surely the use of one-time pads gets around that? A OTP cyphertext can be decrypted to any desired plaintext by providing the appropriate key. It's trivial to generate a key from an OTP cyphertext that will turn that cyphertext into a collection of kitten photos, for example.
So Alice produces the kitten key under duress, and Mallory can't show that she also has a missile-secrets key that she hasn't disclosed. There's no unexplained "random" data, and no unused space on the storage medium.
Voila - Alice is off the hook (unless Mallory is the kind of person that enjoys pulling fingernails, and carries on with the $5-wrench thing anyway).
I have no option but to just use the BIOS SSD password encryption thingy instead of some Ubuntu LUKS or ecryptFS which are both slow AF.
Saying you want "actually competent encryption" and then resorting to using "BIOS SSD password encryption thingy" is kinda funny.
XKCD-538 has an implied third panel:
Right guy: Wait, we can use the $5 wrench? Why not just hit him until he confesses and names all his friends as co-conspirators as per normal?
Left guy: Yes, let's skip the geeky stuff entirely. We will be done before lunch.
People that use torture are not interested in any sort of objective truth. Otherwise they would not do that.
Right guy: Actually, why did we waste that $5 on a wrench when we can just forge a confession document?
Left guy: Yeah, and we can say that he also told us the names of his co-conspirators, who happen to be the people I owe money to, the annoying guy who lives next door to me, my ex-wife, and anyone I can think of from the minority group that I want to feel superior to.
All good encryption protocols will always create cyphertext that is indistinguishable from random noise, this is not an endorsement of any "good" protocols, but rather a general statement about encryption which must be true. You should not be able to infer anything about the data encoded in the cyphertext without the key.
(Of course, saltunnel [2] leaks bandwidth and timing information: a transport protocol which does not will surely have sufferable performance.)
[1] https://puree.cc
Or communicating via trading NFTs with the message encoded in slight differences between the images?
I'm sure there's at least 5 bits of data in the details of a single Bored Ape picture.
Freenet?
This motivated me to create PUREE (https://puree.cc). PUREE satisfies the "random-looking" goal, and in my (biased) opinion is easier to use than LUKS.
"Plausibile deniability" is a fuzzy, more complicated subject of which PUREE provides no claims.
But I think sometimes they do take it too far and use single letters when full names could exist.
This factors the reader's job and the writer's job fairly cleanly. The reader is responsible for mapping their intuition onto the objects being referenced, and the writer is responsible for demonstrating their relationship.