3 ms·
Hopefully stress means that you won't be able to do it properly anyway, which means coercion is useless. The real problem is the device stores the password, so
by Robin_Message 14y ago
Hopefully stress means that you won't be able to do it properly anyway, which means coercion is useless.
The real problem is the device stores the password, so the real defence is the tamperproof-ness of the device, not whether you can be tricked or coerced into outputting the sequence.
- mrsebastian 14y agoYeah, the research paper notes that they need to implement 'coercion detection'. From page 12: "Since our aim is to prevent users from effectively transmitting the ability to authenticate to others, there remains an attack where an adversary coerces a user to authenticate while they are under ad- versary control. It is possible to reduce the effective- ness of this technique if the system could detect if the user is under duress. Some behaviors such as timed re- sponses to stimuli may detectably change when the user is under duress."
- dasil003 14y agoThat's more of a bug than a feature when you're the one under duress.
- PotatoEngineer 14y agoWhat if you're running late to do something, or you are anxious to get access to the data behind the authentication for some other non-duress reason? Duress-detection will be tricky (but I look forward to them doing it!).
- adventureful 14y agoThe problem with using coercion is, the people using it never believe it's useless regardless of what's coming out of your mouth.
- woobles 14y agoI would personally prefer to have my password at any time, rather than have to get in the "zone" to authenticate into my computer.
- napillo 14y agoYeah, I imagine if you had a stroke or perhaps are suffering muscle fatigue you wouldn't do very good at all. The security provided isn't better than a 9 character all lowercase password.