4 ms·
> The best way to get someone's password isn't phishing, it's threatening to hit them in the head with a wrench. But what if you need to combine that person's
by dane-pgp 4y ago
> The best way to get someone's password isn't phishing, it's threatening to hit them in the head with a wrench.
But what if you need to combine that person's password with passwords that are in the heads of 5 out of 7 other people, who are all in undisclosed locations in different jurisdictions?
Perhaps a sufficiently resourced adversary could create a realtime deepfake of you, to attend the property transfer online digital ceremony, but the adversary who imprisoned you would also have to convince all of your friends that you had gone on holiday so that they didn't raise the alarm to warn those keyholders that you are under duress.
- cryptonector 4y ago"Oh, right, so tell us the names of the seven others whose password shares we need?", then proceeds to arrest and beat at least five of those seven others.
- alchemist1e9 4y agoNah I’ll just handover the password to the decoy distress wallet. I’ve paid 45 sats per week to a sentinel service which watches for any transactions from the distress address. I also walk around with latest Apple watch that sends out my last know position every 10 seconds. The sentinel service sees a distress transaction and locates local authorities. If you don’t think this is realistic then perhaps you don’t have a home security system with alarm monitoring. It has a distress code that disarms the system so any attacker believes it is safe but instead simultaneously sends a hostage alert to the local police station. It works well because once I accidentally tested it by accidentally putting in my distress code when I had traveled for 48 hours and was extremely tired. 3 mins later local police had silently approached my home and were looking in the windows with guns drawn.
- dane-pgp 4y agoDid you miss where I said "in undisclosed locations in different jurisdictions"? The other seven people would be known only by their public key, and you'd make contact with them through some onion-routed service. You'd never see their face, and all you'd know is that they were based in a different jurisdiction, where presumably the authorities that are after you don't have strong judicial connections. If your threat model includes an adversary that is willing and able to kidnap and torture 5 innocent people from different countries around the world in order to get to you, then you're literally OBL or the leader of IS, in which case you have bigger problems than securing your passwords.