Adding a “duress” password with PAM Duress (2021)
lwn.net
lwn.net
It must be as old as passwords, meaning as old as language, relatively straightforward to implement in any kind of software, yet I've never seen it actually implemented in all this time. Closest has been the single triggered action to wipe everything after n failures.
The practical issue here is that a secret password to release the hounds or whatever is only useful if someone is able to use it at the appropriate time. It's hard to memorize a password you don't use. The number of cases where a "release the hounds" password is going to be usable and useful where a "log into admin account which has a 'release the hounds' button" wouldn't be is going to be very low.
Is it though? I thought some intelligence agencies have the ability to bypass the tries counter. In that case, the password would still trigger the wipe. That's not as easy to defeat because they don't know what password to avoid during the attempt, as opposed to knowing that after 10 tries it will wipe.
In the 90's I had a Visual Basic addon which was an AI that monitored the keyboard typing pattern. It could identify who was typing at the keyboard, so you could use it as a backup to lock the system if someone had discovered the password. That app could also be used to encrypt files independently, and only decrypt files when the typing pattern matched the username and password.
Not the only thing which could be used to decide if someone is the genuine user, some users might have tic's like tourettes, but involve unusual mouse movements or clicks. Or they could be things like having to switch on the NumLock on a keyboard in order to type in a numerical password. These are all very subtle behaviours which might not be spotted by someone after the password to get into a system.
Edit So windows has had AI built into its gui since at least Windows 200, really noticeable in XP, its the benign sounding Mouse Properties "Enhance pointer precision", but this can also be used to work out who is using the windows GUI by comparing the operation of the GUI, things like do windows get resized or maximmised, do some programs tend to be use on a particular monitor (if a multimonitor setup), and how on target is the user when closing a window, ie where do they consistently hit the big red X close button in the top right of a window and how quickly do they do this. All this is meta data to further workout who is actually using the computer or not. Linux AFAIK doesnt have this so you have more privacy with Linux in some respects.
If you use Linux, you'll see how twitchy the mouse pointer is compared to windows.
[1]: https://en.wikipedia.org/wiki/Key_disclosure_law [2]: https://www.reuters.com/article/uk-britain-security-password...
As for people going to prison I know how fascist the UK state can be, I've had it all my life since primary school and they go on about the Uighurs in China! LOL. Reminds me of the IRA petrol bombs and the Ukrainian Petrol bombs going on today.
I've had court request letters telling me to go to the wrong courts in the hope they can convict me of speeding in my absence, if I wasnt aware of court procedures which isnt my day job.
I'm well aware you dont run a country by being nice.
Have some imagination.
Even if configured as sef-destruct (in cases where you value system security more than your life), it's still better than a basic panic button (ideally you want both). You can point a gun at someone and tell them to keep their hands away from a button, but eventually you'll need to have them open a locked door for you and in that moment they are free to type anything on the keypad, be it "open door and call the cops" or "blow up the whole building" and you won't know what they typed until it's too late to stop them.
I tought this was quite a clever feature for e.g. giving your phone to your children with an isolated profile.
Personally, I'm wondering why ATMs don't have this feature.
So remembering a PIN that most people will never need to use in a stressful situation? Unlikely to be useful for the majority of people.
EDIT: This should be coupled with a "secret" icon that is shown (or a specific order of the 9 icons you have to chose from) to prevent MITM/Phishing attacks. If you realize the icon/order is not the one you are used to, you are being phished.
This is familiar.
I had a bank that, when you set up your PIN, required you to also pick an icon. There was a flower, and a cat, and a dog, and some other generic pictures.
When you put your card in the ATM and entered your PIN, you also had to pick the right icon.
I wonder if this was the start of a duress system the bank was setting up. The bank ended up getting eaten by another bank and then another bank, and the icon selection system went away.
For some reason I don't associate it with a bank (they have a personal phrase they include in official messages), but do with one of the SSO accounts I had, and feel pretty confident it wasn't Google.
Maybe Yahoo?
The duress code could also mean instant warning sent to the police. This would deter some bad guys too if it was widely known.
In the mid-90's, my father's bank would let him specify a withdrawal amount down to the cent. He could take out $53.17, and the machine would spit out $53 in bills, and 17 cents would roll down a chute into the coin tray.
In the late 90's, I had a bank that allowed almost any withdrawal amount. I know I took out $700 once for an emergency car repair.
I think a big reason the banks limit the amount of money you can take out is so they don't have to refill the machines as often. It's a cost-saving measure for them.
Usually there’s a “rich people” account with different limits and services. I knew somebody once who could call their guy have money delivered by courier in NYC.
Citi's World Wallet program delivers money by courier or FedEx, depending on where in the world you happen to be when you order.
At least it did before COVID. Considering how Citi has cut branches and services since 2019, it might be different now.
The duress code could do any number of things, too. Trigger a silent alarm, for example, at the bank branch and/or police. Show a randomized, lower available balance. Mark the dispensed bills.
Fact of the matter is that banks don't care; it's not "their" money when someone steals from you at an ATM. That's why you never see any sort of anti-robbery systems in ATM lobbies.
Cops don't care either. If you're lucky they write a report.
But...steal from the bank and every cop in town will hunt you down.
Head of Theranos was found guilty of defrauding investors who did no real due dilligence, but not patients.
Certainly a pattern
These duress passwords seem to be for kind of contrived scenarios, to me. Either your threat model is "someone breaks into my hotel room and steals my laptop", in which case it's useless, or "The $OpposingSideSecretService got me and hits me until I give them my password" in which case it seems to be equally useless.
No home theif is going to take the time to move your machine while it's running so having all the drives locked should be good.
If you're using pam, some section of the drive is unlocked.
The question is does it matter if they know you have a duress module running?
You're not really obligated to give your password in the US. (Not a lawyer but that's how I understand it)
And in situations where they know are they going to beat you after youve erased your data?
If you're worried about a machine being moved while on, you're probably best to check a canary that tells it about it's environment. ARP for a specific MAC, or DNS entry that only resolves on your LAN, SSID scan, maybe just lock all drives if the LAN interface flaps.
I suppose this would be good for airport travel and more mobile situations.
1. A journalist who has a legal right to protect their sources from discovery
2. A check on your encrypted electronic device at the border
3. A snooping housemate or someone else logs into your machine
That was in <30 seconds of thought on this problem.
If asked you MUST unlock your phone and computer. So if you’re travelling here or leaving — citizen or not — you best be prepared to have your data searched for arbitrary reasons.
I hate it.
Longer explanation: https://www.youtube.com/watch?v=w3_0x6oaDmI and https://www.youtube.com/watch?v=LkH2r-sNjQs
You can't hack a container filled with pieces of paper.
Obviously the usefulness of measures like this is likely pretty low if your dealing with tech-savvy adversaries, but if some random border guard or police officer forces you to log into your computer and — I don't know, I'm not very well-versed in these scenarios — show your Facebook messages or your password vault, you could use your duress password to clear cookies and other stuff to show that you don't have a Facebook account or a password manager ... or whatever, you get the general idea.
Or you could use it to not change anything but simply log in and additionally alert your work place that you're under duress and they can cut off your access to critical systems. Provided that you have some sort of internet access of course...
I could see a solid usecase for a duress script that clears all these and requires 'standard' reauth, so that at least you're back to a 'defence in depth' style. Also, in the 'Pushover' example, I can't imagine many attackers waiting to plug the thing in before starting the ~pipe wrench~ credentials discussion.
Plausible deniability may help, but only if you really can convince them that you do not have and cannot somehow access the data they want.
Oh boy. Don't do this. No matter how much trouble you're in, erasing the proof will make it worse. If you're innocent too, then you're really in a bad situation.
Invasive and surveillance-based legislation.
If you wipe your already clean device, you've now engaged in real criminality, and will end up creating charged out of thin air for yourself.
Any professional organization will be examining your data in a forensic environment that doesn’t allow data self destruction.
Deniable encryption is the better solution here.
So when you're travelling somewhere heavy, you backup your whole phone to a trusted server (I hate even saying 'cloud' here) and wipe it (or better yet, "duressify" it, e.g. you put in grandma's number and a little porn and thats it) and be on your merry way. Restore your backup at your destination.
Of course for this to be effective you should just purchase it in-person in a mall or something, and ideally don't provide any identifying information so they can't "customize" the device just for you, otherwise all bets are off and at that point it indeed becomes more secure to just bring your own and not let it out of your sight.
One preinstalled mitm cert, or sketch CA, is within the realm of feasibility.
In contrast, bulk shipments of imported devices are not usually tampered with in the same way[2]. Some countries do have similar restrictions on data import, but they can't mess with or spy on that data because you actually have end-to-end encryption in that case.
[0] I have heard reports of immigration officers demanding device passwords in such a case, but it's rare. If you're really paranoid, enough to want to do this when crossing US borders, I should point out that you should never live within 100 miles of them. Anything 100 miles or closer to a US border gives the US government power to demand your papers; furthermore, the people in border control treat this as a blank check to search for anything they want.
https://www.aclu.org/other/constitution-100-mile-border-zone
[1] I have yet to hear reports of iPhone users getting their phones searched.
[2] Yes I know "Tailored Access Operations" exist, but this usually involves shipping intercepts, not someone buying a device in a store.
Security is really hard. For every "obvious" solution there's always going to be a back door. For every known backdoor there's going to be a covert back door which you're not going to be aware of, or a honey trap which looks like a trusted independent solution but is really state owned.
If you want a truly secure solution you're probably going to have to wait for some kind of bio-linked technology where your personal data is embedded in your physical body, and forced access either wipes it, or kills you, or perhaps both, depending on the settings.
Some of us have only passing interaction with state actors, e.g. when visiting a foreign country for a short term, or when crossing the border into a nominally free society with legal privacy rights (cough TSA / ICE cough). There is thus in practice ample need for solutions not secure against an all-seeing surveillance state.
Then you basically have 3 partitions boot, system, data. encrypting and uploading "data" can be done. It still requires little manual work, i.e. i don't know if an app can do it.
But one of the ideas that I thought sounded like a good compromise was a duress PIN. The idea being that a customer could opt to set a PIN that would work exactly like their normal/“real“ PIN (dispense funds, etc.) except it would silently alert police. It didn’t happen, in the end. Partially because the banks were strongly opposed to the “overreach” and partially because the public outrage about the abduction died down before anything meaningful could happen in response.
It was a neat idea, though.
A friend of a friend got roofied at bar. In the morning, she found she'd withdrawn a large amount of cash from an ATM. (Could have been much, much worse.)
To add insult to injury, the bank produced a video of her drugged out and "voluntarily" entering her pin with a shadowy figure in a black hoodie behind her. The bank claimed this was proof the transaction was voluntary and non-fraudulent, and refused to cover the withdraw.
This was somewhere in Europe. I'm 99% sure the transaction would be refunded in the US, though I've never heard of such muggings here.
Could still be made useful in some cases perhaps as part of a larger “defense in depth” scenario, but if you’re actually afraid of rubber hose cryptography you should utilize methods that directly work against that (which may result in your death).
They aren't murdering everyone whos phone / laptop they check at a border. It would be perfectly fine to have an encrypted disk drive that presented different contents based on what password was used to unlock for instance.
And with something fully arbitrarily scriptable like this, it doesn't have to simply wipe stuff, it can do practically anything. It could fake having a dead battery, or suffering some kind of crash or other normal annoying service interruption. It could fake a Microsoft account login problem due to some problem with the wifi or borked corporate account control etc. You could increase the believability by pretending to have very common bad security habits like having the duress password written down somewhere on your person or with the machine.
If you are a spy and they have you in a hole, then your cover is already blown. They will remove and dissect the storage without even trying to boot it. But things like this could keep you from being noticed in the first place, and could sufficiently handle the vast majority of situations.
In Russia right now, they are stopping random people on the street to look for certain telegram groups on people's phones. The randos aren't spies and aren't specifically targeted. The police are really only doing it to scare everyone else away from accepting any communication about Ukraine from outsiders.
It would be exactly perfectly good enough if they simply didn't see what they were looking for.
If they are using the pipe, then anything that isn’t what they’re looking for will result in the pipe.
For such scenarios plausible deniability is what you want. Ideally, you need a whole parallel system which plausibly appears to attackers as if it is legitimately authorized/decrypted. StegFS is an example building block for such systems.
If they know you work on breeding war rabbits, you better have some fake files with records of failed attempts to breed war rabbits and your real files hidden in deeper layers.
An HSM can even enforce policies like rate limiting brute force attempts and/or erasing itself after too many attempts. It could even support a duress password which immediately erases the keys.
Without the ability to clone the HSM, the attacker doesn’t get a “second chance” if they attempt to use the duress password.
Assuming they will always have access to the underlying system being protected is missing out on a huge range of security issues.
Completely spitballing here just exploring the thought:
Like using duress pam to _only_ allow logins if a duress pw or authorized_key is used? Port knocking (https://en.wikipedia.org/wiki/Port_knocking) comes to mind as a simile. Could that even be done?
I doubt this is possible in modern hardware given the bandwidth & switching speeds they operate at.
I think that these aren't widely available because if you want someone's data you can email them and say "hey I'm the CEO and I need your password right now, I'm locked out of my account!" Much easier than engineering a 4GHz logic analyzer into a DDR4 form factor.
Recent example:
https://www.reddit.com/r/australia/comments/s1pvs3/customs_c...
After reading this I'll never travel with out a pre trip factory wipe and throw away accounts for the trip.
To be clear, there isn't anything to hide but I don't trust this government one bit and the cost of them scanning my password vault is way too high - it would take weeks to reset and clear old passwords.