Designing Crypto Primitives Secure Against Rubber Hose Attacks
usenix.org
usenix.org
The problem with deniable cryptosystems that make it intractable to prove you've complied, like the old stegfs or the not-quite-as-old Marutukku (aka Rubberhose, which Julian Assange worked on by the way) is that it really sucks to be the keyholder! You can try to secure a system against duress disclosure, but you can't safeguard the people as well - it is possible to make wrench-resistant systems, but unfortunately not wrench-resistant kneecaps. I don't think any good solution exists for that: that's a physical/political/legal/OPSEC problem, not a technical one.
That and the disk-space penalty for the compartments (either fixed or stochastic) meant that, even in areas of potential forced key-disclosure, these systems didn't take off and are as far as I know mothballed and unmaintained.
The device you're authenticating must have the secret you're authenticating with in it in a retrievable format. So it can't be used for e.g. disk encryption, etc, because the attacker can just get the secret from the device and decrypt.
All it can be used for is authentication, and for that they require a human security guard to ensure it's actually a human playing the authentication game. If you were to attach a computer, its likely it could impersonate you. So almost completely useless (except for getting people's hopes up).
More discussion here : https://news.ycombinator.com/item?id=4266115
Hopefully doesn't apply to your businesses, but it sure delayed a lot of things in the 80s and 90s before the EFF/CDT/and so on helped settle a lot of the law that we take for granted now.
(No I do not work for the EFF, CDT, or any other TLA. I just think that programmers and painters both need to be cognizant of copyright)
To be honest, while this line of inquiry is satisfying intellectually, I don't expect it to have any practical value.
A computer that doesn't work when the users is stressed is still going to get defenestrated, though.
It would be interesting to see how their approach does against attacks against subconscious reactions that can nevertheless be measured by more sophisticated devices.
I think you'll find this is true of most academic research :)
For example, if you have a password algorithm that takes an input value (lets say a website name) and a seed that is stored on your system somewhere (that you don't have memorized), concats them together and then hashes the result to generate the password, the rubber hose attackers would to both beat the input value out of you and have physical access to the machine your seed is stored on to recover the password.
"Give me the password!" "Password to what?" {whack}