6 ms·
Could this be accomplished at the storage level instead of at the camera level? Could an SD card have an onboard encryption engine? We have cards with built-in
by devb 10y ago
Could this be accomplished at the storage level instead of at the camera level? Could an SD card have an onboard encryption engine? We have cards with built-in wifi already.
- heartbreak 10y agoWe also have professional cameras that can be tethered to a laptop and record directly to the encrypted disk. Encrypted camera storage sounds cool, but the filmmaker of Citizen Four could have just tethered to her MacBook.
- Edward16 10y agoYou need a savvy hacker,one who specializes in Expunging Criminal Records and Change of University Grades. Contact edwardsnowcare@gmail.com One who would be able to carry out and successfully execute hacks on your behalf while keeping it all discrete and under the radar.
- rlpb 10y ago> could have just I thought the days of wandering around with a camera while having a recorder on a shoulder strap were left behind in the eighties.
- Joeboy 10y agoExternal recorders are still normal for professional video work, but not so much for run and gun documentary stuff.
- falcolas 10y agoBut it wouldn't be locked out until the MacBook was shut down. Until then, the keys would be available in memory, and effectively unencrypted. Not much protection against immediate physical seizure.
- cuckcuckspruce 10y agoStandard procedure here would be to have the computer plugged into AC power with no battery so you can yank the power the moment anything remotely like a raid to seize happens.
- falcolas 10y agoHow do you do this with something without a removable battery, like your average (modern) macbook?
- cuckcuckspruce 10y agoObviously, you wouldn't do this on a Macbook, and not just because the battery is not removable. IIRC FileVault stores a "forgot my disk" password with iCloud, which is likely subject to subpoena. That assumes there's no law enforcement/nation-state investigative service backdoor in FileVault. The built-in, OS level disk encryption is likely insufficient, so why use a Mac at all here? You could just offboard the footage to a machine running a Free version of Linux running LUKS and then after shooting and in a secure location and manner give the files to somebody to do the video editing on the Mac.
- Bud 10y agoNo, that's not correct. FileVault does not store any password with iCloud unless you tell it to. Otherwise, it generates a 24-character password that you have to write down, and that is the only key, other than the user's password, of course. The disk encryption is actually quite adequate on a Mac. We also have no evidence of any backdoors in the encryption in Apple products, and quite a bit of recent evidence that there are no such backdoors.
- cuckcuckspruce 10y agoTake a look at Snowden, Poitras, and Greenwald's communications and the recording of the footage for Citizenfour as an example here. They had all already stopped relying on any closed system to keep their communications secure. They were all using Tails to communicate through Tor without leaving a minimal unencrypted footprint. At the point where you are relying on Tor to communicate and are explicitly using Tails to keep your communication secret then why would you start relying on a Macbook, running a proprietary OS, with non-open crypto, to hold your secrets if you're already scared the neo-Stazi are going to break down the door and steal your unlocked, decrypted Linux machine that you have all of the trust in the world in? For that reason alone you would skip the Mac.
- m_eiman 10y agoYou would need to enter a password, somehow...
- azdle 10y agoWould you though? I could easily see a card with a crypto accelerator that only has a public key to encrypt one-off random AES keys for each photo/video/file. You set it up at home, leave the private key there, go do your filming/photographing. Now no one can decrypt your files except you after you get home download your encrypted files and run them through some trivial decryption program.
- b3lvedere 10y agoIt might even be possible to use multiple key-combos and select one depending on the circumstances. Perhaps this way the adversary gets some info and sets you free again.
- SomeStupidPoint 10y agoYou could do something like key off image size/type, and have all your RAW format encrypted to a hidden volume while any of the JPEG settings saved to a normal volume. Then high quality, professional shots are hidden while the kind of photos you might take as a tourist are sitting there openly. It'd be detectable if you knew what to look for, but a) you likely can use more subtle activation techniqies (photo knocking?) and b) a lot of security checks aren't that sophisticated.
- deleted 10y ago[deleted]
- digi_owl 10y agoWell i could have sworn that the S in SD stands for Secure, and involves locking a card to a device. Back when Microsoft rolled out Windows Mobile 7, they made use of this automatically. This caught many a new user off guard, and hilariously the only devices that could non-destructively unlock said cards were Nokia Symbian phones.
- tantalor 10y ago"A host device can lock an SD card using a password of up to 16 bytes, typically supplied by the user." https://en.wikipedia.org/wiki/Secure_Digital#Card_password https://en.wikipedia.org/wiki/Secure_Digital#Card_password I don't know what degree of protection that gives you. Looks like SecureMMC supports actual encryption, not just password protection.
- lb1lf 10y agoI was thinking the same thing; would make for simple retrofit to any camera currently in existence. Also, while some enterprising card supplier is at it, they might as well implement a TrueCrypt-style hidden volume solution. That, methinks, would be most useful (for a very, very small subset of their customer base). After all, as has been pointed out already - chances are the people who can inspect your camera would also have ways(tm) to make you come up with the password.