Two-Factor Authentication and the Police State
shkspr.mobi
shkspr.mobi
That's only partially accurate. RIPA also allows 'them' to demand that you make the plain text content available.
Not having the keys doesn't help you if you have had the keys, or 'they' think that you can get the keys. Thus, the wikileaks files are safe for me because there's no reasonable expectation that I can get access to the plaintext content. But if I have a bunch of encrypted files on my computer and encryption software and etc they are going to claim that I have access to the plain text data.
(http://www.legislation.gov.uk/ukpga/2000/23/contents)
Note that while the law talks about keys it also talks about "intelligible content" - (http://www.legislation.gov.uk/ukpga/2000/23/contents)
> that it is not reasonably practicable for the person with the appropriate permission to obtain possession of the protected information in an intelligible form without the giving of a notice under this section,
See also (http://wiki.openrightsgroup.org/wiki/Regulation_of_Investiga...)
Although, given how much lawyers charge by the hour, I'm nt sure I could afford to log in to Twitter any more :-)
You can work out a protocol with your 3rd party (e.g. lawyer) ahead of time that requires you to state where you are, and there's all sorts of coding available to you for that. He'll give up the token regardless, but might be able to start action on your behalf if he detects that you're not where you should be.
See, for example, http://mobile.nytimes.com/blogs/bits/2013/08/12/lavabit-foun...
The second factor is something you have. You'll normally travel with the "thing you have", and since many sites implement 2-factor differently, you'd have to change the setup for all of those sites before you travel.
Instead, what about not knowing the password?
This is pretty easy to do, and it's also good personal security generally.
Use a password manager (like KeePass or LastPass), and set all passwords to unique random strings of 16 characters or so. If the password manager enters the passwords into websites for you, you'll never type them (and thus never memorize them).
Then you just need a way to not know the keyphrase that unlocks your password manager datastore... that's easier to change quickly before you travel (or let your partner manage this, or use 2-factor on LastPass, etc. -- it's an easier problem, because it's just one thing).
Use TrueCrypt volumes on USB sticks (encrypted data). Put puppet scripts on there to bootstrap your system.
Ship both separately and confirm receipt of YubiKey before shipping the USB stick.
Travel with unencrypted, freshly imaged hardware with no sensitive data (perhaps run an OS from a read-only file system).
Arrive, insert USB stick and YubiKey... now enter password (something you know)... and bootstrap your system to use it.
This is all a big pain in the arse, but leaves you travelling with nothing likely to get you into trouble.
Just ship the data and use a commodity device at the other end.
[1] This a DB I wrote myself, is sideloaded (i.e. isn't in an app store), and syncs data between my phone, laptop and desktop.
You'd verify each bit before you proceeded to travel.
I really don't have any idea what the response to that would be. But I'd rather have my laptop with full disk encryption taken away than to give access to emails. (and in practice to all other services via password resets)
For phones without a full disk encryption, you can reasonably easily back everything up, leave a copy online and restore on arrival, so that's not a big deal either. You can still use it as a phone in the meantime, just make sure it's completely wiped and has no connected accounts.
You could carve out some exceptions for things you need while traveling that the bad guys who think they are good guys would already know.
I suppose they image it, use the password on the actual machine, and if something goes wrong or self-destructs, they'll always have the image (it just takes a little more time to convince Windows to load).
Idea for a new service; trusted tor homed token vendor (a la dpr or similar bonded agency), takes advantage of the trusted third party model whlist providing a jackboot-thug resistant party to verify the full transaction. For bonus points add duress challenges which will fail authentication in a non obvious way or provide fake but plausible data instead of the real thing.
That way the state doesn't have just one additional third-party target for getting access, they have to go after a group of hopefully decentralized people en masse.
Wasn't Mr. Miranda's cell phone confiscated as well? That's what I understood from the news reports, they took his laptop and his phone, and required his passwords. So your regular Google/Facebook two factor authentication is useless if you've lost your phone.
The alternative - and much more practical suggestion - is not to travel with the codes. You run the risk of not being able to connect to the service - but at least no-one else can.
The most practical way to use this for non-2fa sites would be to have an overly long, random password and save it in the browser's password manager. Delete the Firefox profile before you travel, and you can't be compelled to reveal the password you could never remember.
An easier alternative might be using Deniable Encryption (http://en.wikipedia.org/wiki/Deniable_encryption)
By destroying the OTPs you are a: provably preventing access to the content (2 year or 5 year jail sentence)
I doubt the law is that strict. Do you know what level of suspicion or proof for the court to apply jail time?
However after reading about section 49 for the last few minutes I did not spot what the burden of proof is for non-compliance, the range of penalties for non-compliance nor how it scales with offense, and I do not now what "on reasonable grounds", a requirement to use section 49, means in UK law.
Another interesting quote is that inorder to issue a notice you "must describe the protected information to which the notice relates;" What counts as describe in UK law? I would hope that authorities would not just beable to guess at the structure. I would hope they are require to have some other evidence that would allow them to describe the information they are seeking.
I genuinely do not know anymore.
I knew that anti-terror laws were being broken every day in this country.
I never imagined it was going to be as flagrant as detaining the husband of a journalist as he changed airplanes in the UK.
Don't travel with anything you wish to loose. On return reclaim saved passwords.
1. Install OATH Toolkit. 2. Encrypt Swap space using eCryptFS. 3. Create a TrueCrypt file system with your 2FA keys in it. 4. Every time you need the code, mount (3), run(1), umount(3)
Again, this assumes the service provider doesn't provide the access directly to the bad guy.
I'm not trying to invoke the literally worse than Hitler meme, because it isn't, but there was a notable geek activist who committed suicide recently under the threat of such. Certainly quite ominous.
> Something you know (e.g. a password).
> Something you have (e.g. a smart card)
> Something you are (e.g. a fingerprint)
> rather than sending an SMS to his phone, it sent it to his partner's phone. Every time he wanted to log in to Facebook, he would have to ring his partner and ask for the one-time code.
New CloudSystems' Four Factor Authentication. The first factor stops your spouse. Then the second factor stops your boss. The third factor stops a random crackhead after he grabs your laptop out of your car. And finally, the fourth factor stops the NSA and GCHQ for up to nine hours.
Four Factor Authentication: Because -- You'll believe anything.
(Based on SNL's Triple Trac Razor parody. https://en.wikipedia.org/wiki/List_of_Saturday_Night_Live_co... )
The only way is encrypting your disk and not knowing the password. Sounds impractically, and it is. But maybe your phone could use geofencing to look whether you reached your destination and then display the password on the lock screen? But you should hope nobody steals your notebook and phone and travels to this location xD
The only problem is that if you KNOW how to unlock the devices, you're required to unlock them. So really, you have to NOT know how to do the unlock (geo-fencing doesn't help--you'd be expected to tell them about the fence and how to pass).
The point of the third-party 2FA is that you can tell them exactly what has to be done.
The only winning move is not to play.
1 clone drive
2 force you give password
3 if no sensitive data show up use $5 pipe wrench and go to step 2.