5 ms·
Thank you. I hadn't heard of this concept before. I think it could be relevant here. If the encryptor offers multiple inputs, one a dummy "sure, here is my pas
by examancer 9y ago
Thank you. I hadn't heard of this concept before. I think it could be relevant here.
If the encryptor offers multiple inputs, one a dummy "sure, here is my password, officer" HTML and passphrase, the other the sensitive one this scheme could work. Hiding both in a single blob, plus some noise, could work in the browser too. Seems it might offer some degree of plausible deniability. Some investigation of the decrypted dummy HTML might reveal it isn't large enough to account for the size of the blob. This doesn't seem like an insurmountable obstacle though. If the tool hides an arbitrary number of inputs in blobs that are indistinguishable you'd seem to have a great deal of deniability.
- zyx321 9y agoOne might still reasonably expect that the person who created the file has passwords that decrypt 100% of it.
- ColanR 9y agoRight; the point is that when you're the interrogator holding your 'rubber hose', when do you know to stop asking for more passwords? There might be 2, there might be 20. Your suspect will put up the same resistance (theoretically) for each password. Edit: of course, sucks for the suspect if the interrogator doesn't consider their life valuable.