24 ms·
PAM Duress – Alternate passwords for panic situations
- delgaudm 5y agoIf I understand correctly, this appears to be Linux only?
- raziel2p 5y agoIt's based on PAM (pluggable authentication module) which should exist on MacOS and BSDs as well.
- solatic 5y agoI mean, that's pretty cool, but who enables password logins for SSH anymore? If I'm an attacker, I'm going to wonder why my target of duress is giving me a password and not a private key; most likely if I have access to my target of duress, then I have access to some kind of client / endpoint that my target uses to connect to the network, and that client will have the SSH private keys likely already loaded into ssh-agent. Maybe a more modern concept would be to both a) have a duress private key, that triggers duress scripts in the same way, b) an implementation of ssh-agent that adds the duress private key when a duress password is entered?
- jstanley 5y agoI don't think this is specific to SSH. You could just as easily use this on your client machine and have it delete your private keys if you try to login with the duress password.
- tyingq 5y agoPam is for more than just ssh. This could wipe data on a Linux machine for a local login, gdm, sudo, and so on.
- taneliv 5y agoYes, and perhaps _not_ use pam_duress for remote logins, in case you want to keep your duress password simple (think "password" or something similar, actually memorable in a duress situation).
- wowaname 5y agoI use an authentication PGP subkey for SSH so I have to unlock it with a passphrase before using it. Normal SSH keys can be encrypted similarly, and either gpg-agent or ssh-agent can save your passphrase in memory for an amount of time.
- ChrisMarshallNY 5y agoIt's a very cool idea, but I think it would be most useful if applied to things like phones. I suspect most people pressed for passwords, are using a GUI system.
- luismedel 5y agoExactly. It would be great to have a secondary pin (or my middle finger fingerprint, for example) in my phone to enter in a dummy environment with a few games, some family pics and so.
- ChrisMarshallNY 5y agoIt would need to be baked into the OS. With FaceID, I guess I could use eyes crossed, as a queue.
- anigbrowl 5y agoI do not understand why any security concerned person would use biometric identification for anything, ever.
- dredmorbius 5y agoIf that's what's mandated, you may have little choice.
- bonzini 5y agoSomebody mandates using biometric identification instead of a PIN?!?
- dredmorbius 5y agoBiometric passports: https://www.dhs.gov/e-passports https://www.dhs.gov/e-passports Face ID: https://support.apple.com/en-us/HT208109 https://support.apple.com/en-us/HT208109 Fingerprint Readers: https://www.samsung.com/us/support/answer/ANS00082563/ https://www.samsung.com/us/support/answer/ANS00082563/ These are extant, and either part of or required within numerous presently-used systems.
- f1refly 5y agoThere's always a big issue with systems like this: Any sophisticated attacker will have an image of the machine he's trying to get into at hand to stop exactly what this pam module is trying to achieve from happening. All this would do is make you appear in a worse light to the deciding judge when it comes to trial or get your other kneecap shattered in a not so civil situation.
- t0mas88 5y agoLawenforcement yes, but I'm not sure most criminals are digital enough. Especially if it all looks just normal logged in, but in the background deletes some hidden files.
- f1refly 5y agoPeople who would want the data of someone knowledgable enough to install a custom pam module and write a script to utilize it are most likely also sophisticated and informed enough to know what to look for. This is not some street thug, it's most likely either law enforcement or organized crime who know very well what they want and that it's supposed to be on your machine.
- intellix 5y agoSo you're saying if I'm held at gunpoint or forced to surrender my password at the US airport that a password to clear my account of anything would be useless? Neither of them know anything about me. It reminds me of the Trezor hardware wallet that allows you to have multiple passwords into your account. If your forced to give access you can log into the version with little in it. Nobody knows that you have secondary accounts with more in it...
- jeroenhd 5y agoIf you're held under gunpoint, that script that wipes your entire hard drive will only make your day worse. AFAIK if you actually get detained and questioned at airports, your drive will already get imaged before any password is even tried. You may be able to get away with this on a mobile device where this feature isn't generally expected (because who uses Linux on a smartphone in the first place). I always wonder at what scenarios like these are supposed to be about. If saying no is not an option, pissing off your captors by giving them fake info probably isn't either. I don't know what law enforcement would be looking for on my work drive, but if saying no is no longer an option, my encryption password isn't worth getting shot over.
- t0mas88 5y agoYou could set this up with three possible passwords, #1 for normal login, #2 for what looks like normal login but deletes most sensitive things and #3 that wipes the disk encryption keys and reboots. If forced by criminals or a not so free government enter #2 and pretend everything is normal. If pressured by the US or EU government with your lawyer present enter #3, see it fail and claim you forgot the encryption keys to make it boot (which is technically true, just never admit you made it delete them since that's illegal in most places)
- loup-vaillant 5y agoUsing #3 could land you in jail indefinitely in the UK I believe: if they don’t believe you forgot the password, they can interpret that as a refusal to give them the password (or unlock the computer), and jail you for this… until you give them the password. Which you can’t, because there is no password at this point. So either you admit that you just wiped your computer with the panic password, or you can shut up and rot in jail until you die. You need a way to make them believe you. Covertly wiping your computer is probably not going to end well.
- jrockway 5y agoDepends on the crime, I guess. If you face execution for murder or treason because of the data on your hard drive, life in prison is an upgrade.
- akerl_ 5y agoThis is why I don’t keep evidence of committing murder/treason on my computer.
- dredmorbius 5y agoEvidentiary tests may change.
- drexlspivey 5y agoSo in the UK they can put you in prison for life without being charged or found guilty of any crime unless “they believe you”? Any source on that?
- aymendjellal 5y agoI remember Kali Linux had a patched LUKS implementation for full disk encryption with self destruction password https://www.kali.org/blog/emergency-self-destruction-luks-kali/ https://www.kali.org/blog/emergency-self-destruction-luks-ka...
- idlewords 5y agoReal password: woD3PRBgELFHH9nuABH]ksD Duress password: duress123
- t0mas88 5y agoDuress password "1234", just make sure you have a very good backup and disable SSH password login. Anyone trying to snoop around is going to trigger it.
- bredren 5y agoThis is a joke, but the person under duress also has to sell that they are under duress. This isn't something you can really "train" the average person to do on command. It reminds me a bit of Jon Lovitz Pathological Liars Anonymous bit. "Okay! Here's the password...ya that's the ticket." https://youtu.be/hV85E2S-Idw?t=45 https://youtu.be/hV85E2S-Idw?t=45
- xaduha 5y agoI think it should be pretty trivial to have a hidden dualboot, let's say you have some plain boring Windows that takes 10% of you drive and 90% is unassigned. In reality that's encrypted LVM disk with bootloader on a flash drive that is easily tossed away if necessary. Or zapped in a microwave if you watched too much of Mr. Robot.
- mszcz 5y agoI think VeraCrypt already enables this. It's called Hidden OS or something like that.
- sodality2 5y agohttps://veracrypt.eu/en/docs/hidden-operating-system/ https://veracrypt.eu/en/docs/hidden-operating-system/ Not sure if there's a linux alternative.
- LargoLasskhyfv 5y agohttps://github.com/bwalex/tc-play https://github.com/bwalex/tc-play
- zeusk 5y agoor you know, just a vm disk image that is deleted with the duress password.
- rafael859 5y agoNice, pretty cool stuff. In high-school I worked on something similar (https://github.com/rafket/pam_duress https://github.com/rafket/pam_duress), though this seems to have a somewhat cleaner implementation which is nice to see, and hopefully a more eager maintainer.
- codetrotter 5y agoI’m reading the readme of your project, and got to the part where it says > for example a mail could be automatically sent from his computer to a rescuer, a script could delete sensitive files in his hard-disk or a certain Rick Astley song could be appropriately played And I’m just imagining someone having set two duress passwords; one for kidnapping situations and one that they put there as a joke. And then they get kidnapped and they try to input the one supposed to call for help, but they misremember so they input the rickroll trigger instead. And the kidnappers are like “hey what the hell, you think this is funny man? turn that off” and the kidnapped person cries for having messed up their one chance at calling for help.
- qorrect 5y agoWas a good story :).
- wowaname 5y agoThere are some issues with nuvious' pam-duress that allow for untrusted string inputs when handling scripts with system() call, and I sent a patch to them via E-mail in an attempt to highlight the issues and provide a basis for a better way to handle it.
- nuvious 5y agoHey, just found that patch in my email. Will try to get that encoded into a formal issues on the project. If you have time yourself feel free to that or any other issue yourself. Also looking for 3rd party reviews on the PR's I have open now and into the future.
- mgerdts 5y agoThe company that was pitching my employer retina scanners on data center doors 20 years ago had an idea like this. Left eye gets you in, right eye gets you in and alerts security.
- tazjin 5y agoAs long as the sides are the employee's choice (i.e. the threat actor needs to not be able to know which eye is the duress one).
- hanniabu 5y agoGood point, that's a very important requirement
- HomeDeLaPot 5y agoAnd you'd want to hide the eye choosing/scanning process so nobody could just watch an employee to figure out their preference.
- Verdex 5y agoScanner is something you look in with both eyes. And then while your eyes are completely hidden you close one eye. Heck. You could set it up so that it scans both eyes and then does a second scan where you choose what your ok signal is (both eyes, right only, left only, no eyes).
- Draken93 5y agoYeah i think technicaly it could work. But I actually think that is a terrible idea. Humans have a lot less self control then we think. This will lead to many false alarms.
- LeonM 5y agoThis is also very typical for regular alarm systems with a keypad. A PIN disarms the alarms system, the same PIN + 1 disarms the alarm system and notifies security.
- awinter-py 5y agoyeah there's that one guy who tried to cross the border from canada and got blocked for having scruff on his phone https://www.huffingtonpost.ca/2017/02/22/canadian-man-customs-gay-app_n_14928858.html https://www.huffingtonpost.ca/2017/02/22/canadian-man-custom... 5 years on we're somehow all managing our own crypto keys, the phone is the key to unlock our digital lives, so we're all in the counterintelligence game. more tools like this.
- yhoneycomb 5y agoGood old US. Land of the free. Canadian border agents are equally bad, in my experience. Guess it's just part and parcel with living in the Anglosphere.
- nuvious 5y agoThis is suddenly relevant to me. I'm gay and plan to travel to Canada in the near future XD.
- als0 5y agoWhat I never quite understand is how this can work in practice. When someone is under real duress, they do not always behave in a logical way and may be too stressed to remember certain details like a password that they never use...
- C19is20 5y agoPractise.
- joefife 5y agoDon't be that person, especially when you're wrong. Both forms are acceptable. "In Australian and British English, 'practise' is the verb and 'practice' is the noun. In American English, 'practice' is both the verb and the noun."
- bonzini 5y agoI thought he wrote that reply as a suggestion, i.e. that you should practise typing the duress password beforehand.
- salawat 5y agoI thought he was demonstrating how. Make your password a very unlikely but relevant typo of your actual one. Now tge real question is, was the poster in a state of duress when thy typed that response?
- brokenmachine 5y agoI'm Australian. Never seen "practise", only "practice".
- MonadIsPronad 5y ago'In practice' is correct, no?
- 5y ago
- DangitBobby 5y agoThis could result in serious personal harm if the individual(s) causing the duress sense something is up, which they almost certainly will if things start magically disappearing or locking up. You better make sure that whatever you are protecting with this is more important than your personal safety.
- bredren 5y agoI think they would be more likely to notice that you did not put up enough fight. Most people are not great actors. Also, if you're being physically compelled to provide a passwords it seems your personal safety is already compromised.
- DangitBobby 5y agoYour safety is compromised, but that does not mean the danger cannot be escalated. If you are mugged at gunpoint, are you going to hand over all your cash and keep your hands up as much as possible or are you going to swiftly cut up your credit cards?
- nuvious 5y agoFor sure; there's risk/benefit to this kind of mitigation. One thing to note is all the actions occur before the user drops into a shell (or for desktop login the desktop rendering). If one is simply getting rid of LUKS containers or deleting VPN credentials it wouldn't take very long at all. One could even write in a routine that removes the duress module entirely so it's a one-shot duress password that cleans up sensitive data, notifies anyone who needs it and then immediately removes all evidence that pam-duress was employed. But you are right this is a tool with risks/benefits and the risks changed based on what's being protected and the context of the coercion.
- ascar 5y ago> This is transparent to the person coersing the password from the user as the duress password will grant authentication and drop to the user's shell. I would assume the user shouldn't understand that he was given a duress password, so is transparent the right term here?
- oasisbob 5y agoTraining is very important in duress systems. I once worked in a place with a keypad duress code on the security system. If you prefixed your security PIN with NN-, it was the duress version of the code and would trigger a silent alarm. This was setup long-ago, and not communicated. One night, the keypad was acting glitchy. Partially out of frustration (countdown is running), and partially to test, I ended up accidentally engaging the duress code by tapping a convenient corner number, which resulted in NNNNNNNNN-PIN. After law enforcement had surrounded the building, a quick chat and search alongside a few officers got it all sorted.
- dheera 5y agoAn interesting way to use this PAM-Duress system would be to write a program that (a) begins recording your microphone and webcam video immediately upon login (b) Aggressively try the hell out of every passwordless Wi-Fi network it can detect, then use headless chrome to aggressively smack every button to get past the stupid login pages (c) Stream that video and audio to a server that saves it.
- unglaublich 5y agoor use a cellular network
- dredmorbius 5y agoUse Emergency SOS on your iPhone https://support.apple.com/en-us/HT208076 https://support.apple.com/en-us/HT208076
- bredren 5y agoThe "guy with the gun" narrative comes up a lot, so this seems to counter that? I love the concept. It seems like something that would work well in a movie but fail miserably in real life.
- simonlc 5y agoThis is really good, I've had a gun pointed at my head more than enough times with all my bitcoins wiped, finally a solution to my every day problem.
- bredren 5y agoI got a chuckle out of this. Only the paranoid HODL.
- nuvious 5y agoAuthor here and I wasn't really thinking of this as a useful use case either. Most of my consideration was say corporate espionage or journalists working in authoritarian countries where killing the person would create a highly visible incident. Mostly was just a thought-experiment turned into a real implementation. With any tool like this the risks/benefits should always be considered.
- deleted 5y ago[deleted]
- flenserboy 5y agoWould love this as a standard option for phones / desktop logins.
- sleavey 5y agoThe Hello World example shows echoing to stdout from the duress script. Seems like a bad idea. I don't want to get beaten or shot when some rm -rf fails with an I/O error, alerting the attacker to what's going on. It seems like it would be more sensible for the module to suppress all output by design.
- nuvious 5y agoHey, saw this as mentioned earlier and incorporated your feedback and one other commenter that pointed out a privilege escalation vulnerability. If you have a spare moment would appreciate your critique on the resolution to your concern and/or any other issues you see generally with the codebase. Just a request though, regardless thanks for your feedback! https://github.com/nuvious/pam-duress/pull/19 https://github.com/nuvious/pam-duress/pull/19
- dheera 5y agoJust do this in your script rm -rf /secret/files > /dev/null 2>&1 That pipes STDOUT to /dev/null and redirects STDERR to STDOUT.
- sleavey 5y agoSeems like this should be baked in to the module. There don't seem to be any circumstances where you would want stdout/stderr from duress.d scripts to appear.
- necovek 5y agoThere are multiple levels of protection one might want. I.e. when you are being selected for random questioning entering US as a non-US citizen, you'd benefit from steganography-like approach: you give a password, and relatively bland, non-personal stuff shows up, giving appearance of full access to a system. If you only care about your privacy, the next one is to have a destroy-everything script (and it's not that hard: usually, passphrases are only used to decrypt the actual encryption keys, so overwriting those keys should be super fast). This would also work against unsophisticated attacks which are not going to really cost you your life. If there is a potential for you to be a target of a sophisticated attack and the attacker does not care about taking your life, the biggest benefit is to have a way to inform someone of your whereabouts while you are actually giving access, ideally in a way that buys you time (eg. "webcam has detected stress on your face, please wait another 6 hours before trying to log in again" — sorry, company mandated software, when it happens usually, we call support).
- mimimi31 5y ago>usually, passphrases are only used to decrypt the actual encryption keys, so overwriting those keys should be super fast I'm not sure if it's really that simple with modern flash storage. There might be no guarantee that attempting to overwrite some data will actually affect the particular memory cells where it is stored. You would probably have to trigger a secure erase to reset all memory cells and hope that it is correctly implemented by the storage device's firmware.
- IgorPartola 5y agoThis would happen inside the TCM no?
- Nursie 5y agoThis is something TPMs are good for I guess.
- amelius 5y agoOf course James Bond would have an unlock + wait 10 seconds + explode option ...
- yosito 5y agoComments are full of gunpoint scenarios, but I think a far more likely scenario for most HN readers is law enforcement / customs agents asking you to unlock your device during travel or some other random checkpoint so they can scan it. In that case, I doubt the officer would even have a clue about the use of a duress password to selectively and silently delete some private data. I think the biggest risk would be that a scan of your device could detect the PAM config and duress script which could be a flag to monitor you more closely, or might possibly be considered illegal itself in some jurisdictions.
- leephillips 5y agoThat is a gunpoint scenario.
- Spooky23 5y agoIn the US, at minimum you’re lying to a federal agent. Never a good idea.
- yosito 5y agoI don't know the legal implications, but if the duress password unlocks your device and simply deletes a directory or two, and the officer only asked you to unlock your device (without a warrant, by the way), how is that lying?
- hirundo 5y agoEven if it isn't lying, it's destruction of evidence. 18 U.S. Code 1519: > Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed under title 11, or in relation to or contemplation of any such matter or case, shall be fined under this title, imprisoned not more than 20 years, or both.
- 5y ago
- stalkingvictim 5y agoIs my account still censored? Why?
- nickdothutton 5y agoI miss the SecurID stress PIN.
- michael-ax 5y agoperhaps i could use that as a screensaver password to share with my girlfriend? it would close spreadsheets, emacs, un-mount journals and personal drives. PAM's used to reauth from the screen-saver, right?
- mgbmtl 5y agoMight be easier to create a separate login? Some partners expect to share passwords as a trust thing, but my work does not allow it (and most personal devices have access to work stuff).
- wowaname 5y agoI don't understand why partners willingly share passwords.
- michael-ax 5y agowhy do passwords cover accounts not scopes? if passwords also covered account scopes -- which is what this tool enables one to monkey-patch into the OS, i could give you my password so you could gorge on my code without me having to worry about you reading my journals or abusing ~/.ssh other than that, i second your notion. I'm thrilled by the idea of using passwords to switch between the sorts of things i do without having to log-out.
- michael-ax 5y agoYes, those _are good, i have an Alt-F9 alternate desktop for guests, but a 2 letter password for her to bypass the screen-lock and change the music or something would in fact remove my sometimes duress, i think..
- wowaname 5y agoDepends on your locking program but yes, PAM can be used for that.
- michael-ax 5y ago
- ape4 5y agoI'd like an option like this for Password Safe
- withinboredom 5y agoIf your threat model is “guy with guns,” they’ll just follow you and snatch it when you think you’re safe and unlock the device. If your threat model is “government at border” just mail the device or data to yourself overnight. Don’t be that guy… I was flying into Atlanta (Intl) with “radioactive” rocks (not on purpose, just picked some up near a volcano, they looked cool) and they flipped their collective shit. I was taken to a separate area where they dumped my stuff next to another guy who got pulled into “routine” inspection. This other guy “forgot” his phone pin earlier that day… he was still there four hours later, after my four hours of reasonably straight forward BS.
- ttul 5y agoWe need this on iPhones.
- cortesoft 5y agoYou all live much more interesting lives than me
- pessimizer 5y agohttps://en.wikipedia.org/wiki/Rubberhose_(file_system) https://en.wikipedia.org/wiki/Rubberhose_(file_system)
- gnicholas 5y agoI hate when my bank calls me about something and then asks to confirm my identity prior to giving out details about my account. Even when I think I know what it is about (e.g., a transaction with my card was declined just before the phone call), I feel very strange giving out any information to an inbound caller. One thing I have thought about doing is providing mistaken information to the caller and see if they go along with it. I came up with this idea when one bank said they could send me a text message and I could read back the number to them (huge red flag). Does anyone else have any ideas for how to authenticate a BigCorp caller whose corporate policies do not allow them to provide any account information to the people they are calling?
- sReinwald 5y agoTell them you feel uneasy giving out details over the phone to an inbound caller, hang up and call their service line directly. The only way you can be sure you are talking to your bank is if you are calling them.
- gnicholas 5y agoYeah that works, but it's usually time-consuming to get to the specific department that actually called. I wish these companies could route your call to their fraud dept if their fraud dept had just called you, but sadly this doesn't seem to have caught on yet.
- solarengineer 5y agoIn Singapore, Banks send regular reminders that they will never ask us for our personal information over a phone call. It is slowly becoming "common knowledge" among the non-tech-savvy folk I meet in everyday life.
- GoblinSlayer 5y agoThen there's an antifraud scenario, when the bank still calls you and asks stuff, now you need precise classification what they can ask you and what you can tell them.
- Shmebulock 5y agoWhat does "PAM" mean?
- harry8 5y agoPluggable Authentication Module https://en.wikipedia.org/wiki/Linux_PAM https://en.wikipedia.org/wiki/Linux_PAM
- deleted 5y ago[deleted]
- dclowd9901 5y agoI always thought it would be great if Apple allowed a duress iPhone faceid (say, you making a certain face) that could be used to erase the phone.
- Razengan 5y agoJust like how ancient games and screen savers had a “Boss Mode” shortcut that showed a fake screenshot of Excel or whatever, all modern devices should have an “Allow limited or fake access to someone else to avoid the socially awkward situation of saying No” option. Call it Duress/Panic/Boss/Jealous Boy//Girlfriend/Puritan Family Mode or whatever. iOS has something called Guided Access which sorta helps a little bit but is very obvious to the other party.
- yawaworht1978 5y agoDo not carry devices with sensitive data around if not necessary, simple as. All this hidden user stuff will go nowhere. Have the data encrypted on a server and access it remotely. Anything else is simply not safe at all or might cost you prison time, check the UK laws on this.
- thrwyoilarticle 5y ago>~/.duress A project that's 2 days old should be using $XDG_CONFIG_HOME. My home directory is where I need a clean slate, not your clutter.
- nubela 5y agoHow can I have a duress password for MacOSX that triggers a script on login?
- hannofcart 5y agoNice, this actually tries to mitigate XKCD's famous $5 security backdoor. https://xkcd.com/538/ https://xkcd.com/538/
- nuvious 5y agoNice XD
- unixhero 5y agoThis is highly unlikely, but; What is someone guesses your duress password and triggers your fail safe commands to delete everything?
- kuschkufan 5y agoThen everything worked as intended. Your privacy is still safe.
- new_guy 5y agoNice idea! I have this on my social site, people have two passwords, their regular one and an 'under duress' one that wipes their profile/locks it down. I always wondered why more services don't offer it. The reason we have it is it's a fairly political place (not by design, but when you offer 'free speech' you get everyone booted from every other place) and we've had a fair few members arrested, and I'd hate to think my site contributes to that so easy wipe.
- nuvious 5y agoHey, surprised to find myself here and appreciate all the discussion. I'm the author of the above project and wanted to shed some light on the inspiration for the project. It started as a simple weekend project based on an off-hand comment someone made in a security professional chat I'm in. I had used duress words in military and translating the concept to a PAM seemed like a fun exercise. Also supports my current shift towards swapping careers from pure software engineering to cyber-research or cybersecurity generally. So in the end, it was a weekend project that served a dual purpose as a resume stamp. The design use case I had in mind was more benign; such as corporate espionage or journalists getting their devices confiscated (maybe keep a sticky note on the laptop that has a duress password on it as a red-herring). Comments to the effect that law enforcement would image a device are very relevant as any competent law enforcement agency should have their staff trained to get the device fully powered off and hand it to someone that can maintain a chain of custody and get a golden image for use in potential criminal charges. One thought I had was to apply this to SSH auth for honeypots and if a rockyou.txt password is attempted it runs some routines that aid in crafting the honeypot before the intruder drops to a shell prompt. Another even more light-hearted implementation could be you have password X is the one you login to normally and your "duress" password Y just clears your browser history and is the one you give your spouse for when they log into your computer :). I'm sure there's use cases in the full spectrum and with it being a relatively simple implementation with user generated scripts, it'd be easy to extend to any potential use case. In any case I'm glad it prompted such a good discussion. Feel free to submit issues if there are particular feature requests or bugs that one might run across. Additionally if there's a PR up, I'm currently the only dedicated dev on the project and welcome anyone that wants to review my PRs; always prefer a 3rd person review even on my own projects. I created a demo video using Pushover and in the process of doing the demo uncovered some bugs that I patched as well as some fixes to the documentation. Again, glad you all found this interesting and humbled it fostered such a good discussion.
- nullc 5y agoSurprised to not see this mentioned here: https://en.wikipedia.org/wiki/Rubberhose_%28file_system%29 https://en.wikipedia.org/wiki/Rubberhose_%28file_system%29 And http://dmsteg.sourceforge.net/ http://dmsteg.sourceforge.net/ Alas, work in this space appears to be abandoned, too bad too because much could be done to improve robustness when writing with umounted aspects, or preserving security against attackers that can take images of the disk at different times. Not to mention: integrating the results in standard software so the mere presence of the software on your host doesn't harm the deniability.