11 ms·
My USB Drive Has a Hidden Encrypted Vault
- jrexilius 2mo agoGood stuff! If I remember correctly there was company at Defcon selling memory cards that had this feature built into them a couple years ago?
- JoeBOFH 2mo agoI miss TrueCrypts alt boot option. You enter a specific password it boots an alt OS so you could have an automatic alternative thing if under duress.
- tptacek 2mo agoIf you're using off-the-shelf "hidden" encrypted volume schemes, you're not going to be evading state-level adversaries; if you can find these projects and conveniently use them, state vendors can and will write scanners that find them. They're paid to do it; new detections are how they get to charge for maintenance and new versions. Then you're down to two issues: (1) Concealing an encrypted volume jacks suspicion way up; whatever pickle you were going to be in if you just kept an encrypted DMG on your desktop, you're trebly in now. (2) Your actual security comes down to the strength of the encrypted volume, and this is 20-year-old encryption. He can't use a memory-hard KDF because of his BOM, which, like, fair enough, but that doesn't change the fact that this KDF is probably ~50x faster than standard bcrypt hardness and on realistic human passwords is probably crackable in minutes-to-hours on a dedicated rig. I winced particularly at the observation that the hardness was set where it is because of how long it takes to open the encrypted volume on this hardware, because whatever scheme is being used to run the KDF now, an attacker won't bother; they'll just copy the bits and attack them on serious hardware. Point (1) isn't meaningful if your adversaries aren't states. It might make sense to have a hidden encrypted volume for the same reason you'd want an encrypted safe. But point (2) applies to everybody.
- johnnyApplePRNG 2mo ago>If you're using off-the-shelf "hidden" encrypted volume schemes, you're not going to be evading state-level adversaries; This would evade 99% of them. Most "state-level" adversaries are just high school dropouts working border jobs told to "investigate suspicious things". I once had a police officer literally raid my room for drugs during a massive party we were throwing in university, for example. They took everything. They found everything. Everything except for the $1,000 piece of drug paraphernalia I had sitting right out in open view in the middle of the apartment... the Volcano vaporizer. It didn't look like anything they had seen before so they didn't think anything of it. Same would be true with this USB drive in 99% of border crossing privacy invasions... plug in USB, ask for password, read it/copy it/whatever... they're not taking it apart and performing open heart surgery on a $5 USB drive at the border. They might throw it out... or keep it or something... sure... but in general... this is a hell of a lot better than a regular USB drive imho.
- matheusmoreira 2mo ago> It didn't look like anything they had seen before so they didn't think anything of it. You will miss your government's incompetence when they start rectifying these failures. I know I do. They are the tyrants who oppress us with a clean conscience. They never rest and have infinite money. Their occasional episodes of bumbling incompetence is the only respite, but those won't last. Especially now with AI to think for them.
- matheusmoreira 2mo agoPlausible deniability requires people to believe that you don't know about any so called "hidden" volumes. That goes out the window once you buy Hidden Drive from Hidden Drive Company.
- jp191919 2mo agoProbably better just to use a veracrypt hidden volume, and preferably not a SSD.
- megous 2mo agoRule no. 1: you don't announce your security by obscurity methods :)
- jmclnx 2mo agoA very interesting solution! If you can do without Windows, I would say formatting a USB with a first partition as an 8 gig DOS partition and a 2nd partition as Linux LUKS may work just a good. But a few people may know about Linux. So if on OpenBSD, you can create a second OpenBSD encrypted partition. I think that will probably look like garbage to 99.999% of the people you may be hiding from. Be aware, if dealing with a sophisticated Gov agency, all bets are off.
- mixmastamyk 2mo agoHmm, a partition of any sort has mapped the territory.
- deleted 2mo ago[deleted]
- ted_dunning 2mo agoBut this partition would be visible. The OP had a version that is invisible.
- jmclnx 2mo agorue, but I think if crossing a border, this would be enough to get by. I doubt the border guards would know what fdisk is showing and you can say "that was there when I bought it". But the big question would the guards even know about fdisk type utilities ?
- monster_truck 2mo agoMight as well be rot13. If you rented 8 MI300X's or the nvidia equivalent, I don't even think an unreasonably long password would matter. It should finish quickly enough that you would be upset with all of the money you have now wasted by having to commit to a month of utilization
- felooboolooomba 2mo agoIf you need 8 MI300X's for a month to do ROT13, then you're doing it wrong.
- charcircuit 2mo ago>Let’s now assume our attacker has a really powerful machine, has gotten your salt and now will compute their own “table”. You should be using a TPM so such an attack is impossible. The TPM should be what is rate limiting the guesses. You don't need a KDF here.
- Retr0id 2mo agoThere are other issues with AES-CTR - an attacker can flip bits at chosen offsets in the plaintext without knowing the key. For example, if they know (or can guess/infer) what offset the relevant portion of the `sudo` binary is at, they could flip the branch instruction responsible for password checking. This can be done in one step, as opposed to the multi-step plaintext recovery attack described in the article. With XTS, the attacker is forced to completely garble a whole block at a time.
- gruez 2mo ago>Many places don’t respect privacy laws, in certain situations you may be forced to unencrypt your media, or worse, assumed to be guilty. A Veracrypt hidden volume is useful in the former situation, but not the latter. > ... >Due to AI demand the cost of eMMC memory is unusually high, so I chose to go with an SD card for memory. Someone will find your SD card if they tear it apart, but of course everything is encrypted. So which one is it? It sounds like this is trading off between "having veracrypt installed on your computer" vs "having a custom usb drive". In other words, hiding something in software vs hardware. I'm not really convinced hardware is better. The hardware device is going to get discovered if the x-ray it, not least because of the super suspicious embedded sd card reader. Even if we concede that hiding in hardware is better, surely you can just use whatever trick to hide the software (eg. putting in a secret password mounts a second drive with veracrypt)? That way you don't run into the crypto issues that the parent poster mentioned.
- ronsor 2mo agoCould've at least sealed the SD card in an epoxy blob.
- sandworm101 2mo agoDude. Veracrypt. Hidden volumes. This is an old and well-solved problem set.
- NetMageSCW 2mo agoHidden volumes aren’t that hidden if Veracrypt can find them.
- loneboat 2mo agoiirc it's even invisible to veracrypt until it has your correct password in hand. The hidden volume headers are indistinguishable from random bytes (which Veracrypt fills the volume with on creation).
- marysol5 2mo agoThey are hidden if one of the "sources" to find them is only known to the user.
- maxprimes 2mo agoJust a heads-up, your blog post has a broken link for > As for the security of the device, I’ve verified things with functional tests like this Otherwise great project!
- sscaryterry 2mo agoEncrypted USB drives, there are definite legal uses, but like others have said, it raises suspicion.
- NetMageSCW 2mo agoThe whole point is you are unable to detect that the drive is encrypted because it is only visible to USB once the password is written.
- sscaryterry 2mo agoThe whole point is asking what is so sensitive.
- daneel_w 2mo agoIn this case you can just crack it open and see that the SD card inside is larger than the 8 GB block device exposed.
- russfink 2mo agoCould use an Opal or Pyrite drive connected to a USB caddy and sedutil-cli to manage it.
- tlhunter 2mo agoI want something like this in a keyboard: a completely hidden drive that the OS cannot see until I type in a certain string of characters (password) to activate it with a separate string of characters to deactivate it.
- jrexilius 2mo agoThat is actually what my company built. The primary purpose was for encrypted messaging, but it also acted as secrets store and password manager. The great thing about it being built into the keyboard is there is no chance for a rooted host to intercept passwords/messages etc. https://www.anomie.tech/ https://www.anomie.tech/
- deleted 2mo ago[deleted]
- pessimizer 2mo agoCan this be done on boards with the same layouts as known commercial USB keys i.e will imaging just show this to be what it is?
- marysol5 2mo agoYou would need to re-engineer this to not have an SD card. And you'd also need the MCU where you can't just read off the firmware and decompile it to see the encryption routing.
- imglorp 2mo agoIt might make more sense to embed the encrypted volume in some generic USB device. Require some condition to be true before the volume appears to the host, otherwise it's doing power or camera stuff. A drive would draw more scrutiny than a camera or powerbank or even a cable. https://shop.hak5.org/products/omg-cable https://shop.hak5.org/products/omg-cable
- tim-projects 2mo agoReading this made me think that a good solution would be to write your own filesystem as a mod if an existing system. It just needs to differ enough from existing recognised systems. Then nobody would be able to read except you and the encrypted data effectively doesn't exist. It just would show up as an unreadible partition.
- dolmen 2mo agoNot very practical for an USB device used to move data from one computer to another.
- purpleidea 2mo agoThis only makes sense if the underlying thing that gets exposed after you put in the password is a block device... I'd want to then be able to have that encrypted with LUKS myself, I don't want to rely on this homebrew stuff.
- rsingel 2mo agoJust chiming in that there are lots of threats that aren't state level attackers. In fact for most people the threat is never gonna be the border guard. It's your parents, an abusive partner, a sibling, a school admin or an employer. Just because something does work vs the NSA or the FBI, that doesn't make it useless
- mrloopex 2mo ago[dead]
- marysol5 2mo agoAnother day, another one of these projects. >With Phantomdrive, hopefully you’ll slip past authoritarian government representatives, corrupt police, and anyone else that doesn’t respect basic encryption rights. Apart from the SD card on the board making it obvious something is going on, and the iron bar comes out
- dzhiurgis 2mo agoWhy not decouple the special card reader from SD card instead then? I mean it's unsuspecting already, but it probably even less sus since readers are cheap and never a target.
- Dwedit 2mo agoWe know that crooks are selling fake drives where the size is over-reported. Shouldn't something that tries to be sneaky under-report the size instead? Not just in the partition.
- Schlagbohrer 2mo ago> "Many places don’t respect privacy laws, in certain situations you may be forced to unencrypt your media, or worse, assumed to be guilty. A Veracrypt hidden volume is useful in the former situation, but not the latter. This is why I made Phantomdrive." Can someone explain to me how this project is different than a Veracrypt hidden volume and also what he means that Veracrypt wouldn't help if you are assumed to be guilty? I thought Veracrypt hidden volumes aren't visible.