13 ms·
Show HN: HiddenVM – Use any desktop OS without leaving a trace
- aforensics 7y agoHello HN, We're finally sharing our github with the world. This post is the first announcement of our project apart from our thus-far non-populated subreddit. No one's discovered us yet. We've only told one person in the world before right now. We're new to developing and we're very humble and willing to learn, so any suggestions and help is welcome. What we aren't as humble about is the potential we think this application has. HiddenVM allows full-scale anti-forensic use of any desktop OS. (No longer just Tails.) If you place your installed files inside good deniable encryption like VeraCrypt, it means that no digital trace of your chosen OS is left on your hard drive or can be forensically proven to exist. That is significant. There are many reasons why you may want to use HiddenVM. Some use cases include: - You're a spy protecting national security and you need to leave no digital trace on the hard drive of the computer you just used. - Law enforcement agents conducting sensitive investigations. - Diplomats, politicians, and military personnel. - Whistle-blowers needing to safely carry their information in any situation. - Activists, dissidents, political asylum seekers, and journalists in need of stronger protection of their information from corrupt governments when their equipment is forcibly seized. (We know that the risk of the rubber hose remains a complex problem and limitation of encryption.) Now that you can use Windows once you set it up inside Tails, keeping your data private could become easier for you. Border agents forcibly invade our privacy and potentially steal our secrets with no respect to who we are or what our rights are. We need tech solutions to protect our data. More use cases include: - Lawyers carrying sensitive client information. - People in business protecting their IP or trade secrets. - Tactics in fighting against corporate espionage. It could be expensive or impossible to sue for someone's unlawful intrusion into your data. Easier to technologically prevent them in the first place. - Protect your basic privacy and dignity for any of the one thousand other reasons why privacy matters. - You travel a lot and you want to use Windows/macOS/Linux in a way that prevents malware code from being forcibly installed inside your operating system simply because you entered a country. - Digital currency: store a more private Bitcoin wallet. Secure your assets against unwanted and unwarranted access. When data literally is money you have a lot to lose. - Domestic violence victims, and people in other dangerous situations in life. Data privacy is a human right. If you don't want someone searching your naked body and violating your dignity in that way, why should your data be any different? Airport border agents not only perform a full digital strip search, but they're also potentially stealing your data or implanting spyware and malware without you knowing. It is a devastating act. Using Tails should never be reason to suspect you are a criminal or a spy. It also protects basic data privacy and democracy. Tails should become a standard USB that anyone who values their digital safety carries around in their briefcase, bag, purse or wallet. We hope our application increases the size of the Tails user base. Thank you for your interest. We invite you to rip apart our assertions and code (but with courtesy), try out HiddenVM, and contribute to our project. Sincerely, aforensics
- smashah 7y agoHi, very cool project! I'm getting more into security so apologies if this is a stupid question. Is the veracrypt drive, and therefore the HVM, linked to my specific instance of tails or can it be accessed by anyone with a tails usb and my veracrypt authentication details? Also, is it possible to have tails on one usb and a veracrypt drive on a seperate USB drive? How would that effect deniability at, say, a border?
- aforensics 7y ago> Is the veracrypt drive, and therefore the HVM, linked to my specific instance of tails or can it be accessed by anyone with a tails usb and my veracrypt authentication details? If someone has your VeraCrypt volume password, the volume can be unlocked by them using via any Tails stick but potentially any other operating system. What HiddenVM does is reduce digital forensic evidence of using that volume quite fundamentally. > Also, is it possible to have tails on one usb and a veracrypt drive on a seperate USB drive? Yes. It may be faster if you make your computer's internal SSD to be one entire partitionless hidden VeraCrypt volume. > How would that effect deniability at, say, a border? We want to be careful about making claims about deniability, and it's still a field we have a lot to learn about at HiddenVM. Someone more knowledgeable might dare to answer this. We already give two examples on the github page. Your situation is unique and only you can know what deniability strategy works best.
- jcahill 7y agoCopy notes: 1. Pictures. > What we aren't as humble about is the potential we think this application has. So you're not humble? Ditch the marketing goofiness. You think it has major potential. Be humble or don't. It's inessential to conveying what HiddenVM is. > Like Tor, Tails, or Whonix, HiddenVM can be used for bad purposes Unnecessary. You're already on the back foot. > - You're a spy This isn't a normatively 'good' reason. > Activists, dissidents, political asylum seekers, and journalists (like Laura Poitras) Don't cite a specific person unless that person is endorsing the product. > Using Tails should never be reason to suspect you are a criminal or a spy. It protects basic data privacy and democracy. Don't lead with a user story that exactly matches the stereotype, then. You're walking right into it.
- jstanley 7y ago> The VM will even connect to full-speed pre-Tor Internet by default, while leaving the Tor connection in Tails undisturbed. This doesn't strike me as a selling point? Surely the default should be to have the VM traffic all go over Tor? Cool project though.
- aforensics 7y agoWell, the idea is that you don't have to be limited by Tor's speed or handicaps like being IP blocked when web browsing, if you don't want that by default. We love Tails' amnesia for anti-forensics, but we prefer Whonix's more secure Tor anonymization, if you want to be anonymous. Now you can easily combine both benefits.
- norswap 7y agoI think the point is to make a decoy OS that you can boot into if forced to unlock your laptop. Running on Tor would be highly suspicious. The point of running this on Tails is to prevent the use of forensic tools inside the decoy OS to unearth what's underneath.
- joosters 7y agoIf using Tor is suspicious, then having Tails on your computer is also going to be suspicious. I'm certain that no border agent will be swayed by your "but I don't actually use this Tor I have installed" arguments.
- norswap 7y agoI assumed that tails is normally invisible and must be logged into using some secret handshake at boot time. Otherwise it's pretty silly, even if the partition is wholly encrypted.
- lovetocode 7y agoSo does Tails run as the root OS but displays a separate OS in a VM? For example, does it look like your booting into Windows when really it’s just a VM inside Linux? If so, does that Windows VM or whatever it is you choose act like what is essentially a read only OS?
- aforensics 7y agoYes and yes. No, the VM is not read-only. (But you can run a VM as read-only.)
- lovetocode 7y agoInteresting, thank you for sharing.
- unnouinceput 7y agoOr, or..hear me out, swap your HDD with a gaming one so when a smart guy takes a look at your HDD will find only benign games. You think customs agencies does not have smart people who can look past a simple boot screen? Think again
- incompatible 7y agoOr just wipe the HDD and install a fresh OS? I have to admit that I'm uncertain exactly what the goal is.
- unnouinceput 7y agoGithub says the goal is to hide your privacy from customs agents. That's the honorable use of this. But is a tool, and just like any tool can be used for both bad or good things. A scammer or spammer will have use of this faster then a person facing customs agents.
- saagarjha 7y agoA fresh OS is pretty suspicious.
- incompatible 7y agoA zeroed drive and a stock OS install, surely unlikely to have any hidden data.
- Insanity 7y agoIt takes almost no time to reinstall an OS, install a few games from steam. If you want you don't even need to wipe your install and have a bit more time to spend, you can dual boot and remove the other boot option temporarily from GRUB / MBR or whatever the windows equivalent was. Or fetch out a few github repos if you don't want to install steam games. :)
- saagarjha 7y agoI'm not sure I understand your response. Am I missing something in my original comment?
- walrus01 7y agoIf your laptop is getting inspected at the border of an actual authoritarian police state: https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis
- dmos62 7y agoWhat countries do this? I saw a mention of Australia.
- chupasaurus 7y agoAny, if they would really want the data.
- dmos62 7y agoAll borders don't have privacy protection laws? Hard to believe.
- kube-system 7y agoThat just raises the bar for how much they need to want it. It doesn’t eliminate it.
- duxup 7y agoDepends on the border / country.
- IggleSniggle 7y agoAll things are fungible
- Turing_Machine 7y agoAs far as I know, every country asserts the right to thoroughly inspect anything that crosses its border. There may be a few exceptions, and it may not matter in a practical sense for situations like (e.g.) within the EU, where you don't actually have to go through customs when you cross the border, but in the general case, it's true.
- 6510 7y agoI forget where I hear it or if it was my own idea (the shame, I know, I know!) but... cant you have an unknown number of username/password pairs that decrypt/unpack the same chunk of data into different things? Say you have the same OS 51 times, as clean installs the data shouldn't have to be all that much larger than 1. You install some games on one, some office apps on the next, put some downloaded movies on the 3rd. You could give them "all" 50 passwords and they could never find OS nr 51.
- lousyd 7y agoPerhaps you're thinking of this: https://en.wikipedia.org/wiki/Rubberhose_%28file_system%29 https://en.wikipedia.org/wiki/Rubberhose_%28file_system%29
- listic 7y agoI wonder why this wasn't adopted and maintained?
- jetrink 7y agoIt's not possible to encrypt 51GB of real-world data in 1GB space for the same reason that compression algorithms can't achieve 51x compression ratios. Given that, such a scheme presents some challenges if you want to maintain plausibility. Either, 1. Each filesystem lives within an allocated area and knows not to overwrite its neighbors' data. 2. Some filesystems (the real ones) are privileged and know their actual allocated area. Others (the decoys) think they own areas of the storage volume that contain hidden data and therefore have the potential to overwrite the hidden filesystems if they are written to. In the case of (1), you need to be able to explain why your computer has unallocated areas filled with pseudorandom data. That is never going to pass the plausibility test, imo. In the case of (2), a lot of effort needs to be put into making the decoys look normal while not letting them overwrite the hidden data. There are a number of strategies you could use here that would work, but it will never be as convenient or simple as dual-booting and the more convenient you try to make it, the less innocent a hard drive will appear under close inspection.
- 7y ago
- jstewartmobile 7y agoif i had reason to be this paranoid about doing something on the computer, i probably wouldn't do it on the computer... see what Ron Minnich amd Bunnie Huang have to say about the state of modern hardware and bios. that, and i believe AMT is still a thing
- Santosh83 7y agoMaybe good for hiding activity when you're already below the radar. If you're a person of interest for a large enough state then they can and will use all manner of dirty tactics to nail you and simply encrypting is not enough. You will have to flee like Snowden did. And once they bring in legislation that says a govt agent can ask for your decryption keys under reasonable doubt then everyone is in soup since encrypted data is easy enough to detect as such. One may have to shift to steganography of increasing sophistication. Basically this fight has to be clinched politically. While technology can help it can't ensure absolute privacy/security against an all-powerful state. The key question is if a state should be all-powerful at all in the first place...
- aforensics 7y agoIndeed. Software is a supplement to the physical world. But we do what we can, and at least in the realm of software, we can have freedom. It's possible Tor and Tails is dangerous software to use in certain states. But if they can safely use it, it's here for them.
- tuxxy 7y ago> everyone is in soup since encrypted data is easy enough to detect... This is only half-true. Any secure encryption is going to result in ciphertext that is indistinguishable from random data. In cases where the ciphertext is designated by a header or file format, then it's trivial to know that something is encrypted. Then there are cases where we can try to forensically determine that there's encrypted data via the existence of an encryption tool (e.g. VeraCrypt). If you wipe a disk with random data, for example, then it would be relatively difficult to determine whether or not the disk is encrypted (implying that there are no headers on it). In fact, one method of wiping disks is to generate a random encryption key and encrypt a stream from /dev/zero to fill the disk (https://wiki.archlinux.org/index.php/Dm-crypt/Drive_preparation#dm-crypt_specific_methods https://wiki.archlinux.org/index.php/Dm-crypt/Drive_preparat...). This tool is making use of a VeraCrypt hidden volume which is a rather really interesting application of plausible deniability in cryptography. Essentially, this let's you have two volumes where both are encrypted, but each has a different key. In this setup, you'd put some files on one of the volumes to make it appear that it's your "used" volume. On the other "hidden" volume, you'd place the real files you want to keep safe. In a case where the government is demanding that you release your encryption keys, you would give up the keys to the "fake" volume. Unless you divulge the keys to the "real" volume, the attackers wouldn't necessarily know that it exists. Unless there's evidence of you using one (maybe chat logs or google searches asking for help on using it, for example), there's no reason for anyone to suspect you use it. The VeraCrypt documentation explains the technical details (https://www.veracrypt.fr/en/Hidden%20Volume.html https://www.veracrypt.fr/en/Hidden%20Volume.html) well enough.
- a_imho 7y agoIsn't downloading additional software defeats the purpose of inspecting the code?
- louwrentius 7y agoI wonder if it isn't easier to buy a laptop with two drives. Install a regular OS on the first, hide the second in the BIOS and nobody will notice. The people doing the cloning / data theft would have to know about your particular model. Obviously, you encrypt the second drive, that in itself contains a hidden partition in case they do discover it.
- raxxorrax 7y agoThe project here is quite neat. But I wonder if your idea would also work and ask myself how competent the forensic teams of airport security really are. Or even if they are, they certainly don't have a lot of time per device. IT specialists are expensive and it would be shame if we waste that on something benign as airport security which was mainly established by paranoia and the wish to save face. An what exactly are they targeting? Are they looking for howToBlowUpAnAirplane.txt? Just some industrial espionage? Just some display of authority? I don't really get what would prompt these measures. Was there ever anything they found on a device someone took on a plane?
- IanSanders 7y ago>An what exactly are they targeting? journalists, I heard
- nkrisc 7y agoIf you're only trying to slip by a cursory inspection, mount the second drive in your computer but don't attach any cables to it. Could be trickier depending on how drives are mounted in your laptop.
- bluesign 7y agoSafest way is to hack the SSD/HDD firmware, make it report its size half. Depending on some condition, make it use the selected half. (ex: some byte in first sector, some ATA command)
- flyGuyOnTheSly 7y agoAnd when they pull the hdd and realize it says 512gb when you're only showing 256gb?
- Someone1234 7y agoReplacing a SSD's sticker doesn't seem particularly challenging relative to modifying the firmware to misreport but make available storage.
- threatofrain 7y agoAny entity big enough to seize your laptop for analysis is also going to be able to look up the specification for any particular part in your laptop, and eventually this portion of the cat and mouse game will end.
- ArchReaper 7y agoThat's definitely not true, the article mentioned people traveling between countries - TSA/border patrol/airport police aren't going to send your laptop over to the NSA/KGB to have it cracked by an expert. That being said, actually encrypting the data is way more secure than fucking with HD self-reporting.
- johnlorentzson 7y agoIf you go so far as to modify the hard drive firmware, you probably already use full-disk encryption.
- Someone1234 7y agoThat's predicated on an all knowing adversary with unlimited time and budget. In other words it is a largely fictional problem. Most of the people we're talking about just run off the shelf forensics software and have minimum actual expertise (the government doesn't pay well enough for legitimate experts doing it by hand). But then again, very few people are crazy enough to modify computer hardware to protect their information. So both sides of this coin might be largely fictional.
- haunter 7y agoHow about running from RAMdisk? Feels like that would be the safest
- GekkePrutser 7y agoIt would be, but how do you go through the whole install every time you need it?
- kchr 7y agoPlease consider an acronym other than "HVM", which already has meaning in virtualization context (Hardware Virtualized Machine).
- paulcarroty 7y agoWill be interesting to also have macOS as guest with Vera Crypt & encrypted volume etc.
- deleted 7y ago[deleted]
- ThePowerOfFuet 7y ago> The VM will even connect to full-speed pre-Tor Internet by default Snatching defeat from the jaws of victory.
- hleszek 7y agoIt is kind of ridiculous to still use md5sum to check software for integrity.
- dangarbri 7y agoWhat's wrong with MD5?
- jedberg 7y agoIt's too easy to generate hash collisions.
- stingraycharles 7y agoNormally I would give people the benefit of doubt and say “it doesn’t matter for most practical cases”, but given the purpose of HiddenVM you really would expect them to do better than md5. They’re expected to be on the forefront of these technologies and should set the example, even for something as innocuous as zip file integrity checks.
- aforensics 7y agoThanks, we'll look into it.
- aforensics 7y agoAnd now fixed, moved to SHA512.
- ralphc 7y agoIf you want to use Tor in another country then come through a border, what's the advantage of HiddenVM over putting Tor on a bootable thumb drive, using it, then throwing away the drive before crossing the border? Just the persistence?