6 ms·
Would the plausible deniability that comes with using a technique like TrueCrypt's hidden volumes help in a situation like?
by jschneiderhan 13y ago
Would the plausible deniability that comes with using a technique like TrueCrypt's hidden volumes help in a situation like?
- jwr 13y agoAny good symmetric encryption algorithm produces data that looks random. You can't tell whether it's just noise or encrypted data. I'd expect a sane judge to treat cases like these as circumstantial evidence — e.g. the police thinks that random data is really encrypted data, but has no proof. From what I know, it is difficult (though not impossible) to land in jail based on circumstantial evidence. I guess if you use encryption tools that add unencrypted metadata headers (as in "this is a file encrypted using AES-256 in CBC mode"), then the evidence is stronger.
- shabble 13y agoNot quite what you're talking about, but there was recently a couple of posts by the 'binwalk' author about differentiating encrypted vs compressed data (presumed header-less): http://www.devttys0.com/2013/06/differentiate-encryption-from-compression-using-math/ http://www.devttys0.com/2013/06/differentiate-encryption-fro... http://www.devttys0.com/2013/06/encryption-vs-compression-part-2/ http://www.devttys0.com/2013/06/encryption-vs-compression-pa...
- gknoy 13y agoWow! That was really interesting. Thanks for sharing those; have you considered submitting one of them as a story?
- shabble 13y agoThe first was submitted a couple of weeks ago at https://news.ycombinator.com/item?id=5871927 https://news.ycombinator.com/item?id=5871927 but didn't seem to take root. Hopefully there'll be a part 3 that gives an excuse to resubmit :)
- ansgri 13y agoIt's exactly the opposite: any random noise could be assumed to be encrypted data and therefore you can be jailed for being unable to decrypt the noise.
- shawabawa3 13y agoTechnically any random noise could be encrypted data. You could just store a 1 time pad somewhere that decrypts it to cat pictures
- marcosdumay 13y agoThat. If you have that 1GB file that simply can't explain, just xor it with some cat photos.
- drostie 13y agoIt might, but to be perfectly honest most people don't keep partitions of random-looking data, or large files containing what looks like it. Your plausible deniability would be of the form, "I was getting ready to make a hidden volume there, filled it with random bits etc., but I never got around to actually making it." I'm not actually sure that TrueCrypt lets you separate these two aspects of creating a hidden drive, but Linux's tools do. With LVM (to create volumes in volumes) you could create a partition which exists within an encrypted partition, so that it's full with random data to begin with -- but then you could plausibly have forgotten to do anything with it after your computer was up and running. Large random-looking files are a bit different; if someone were to ask "what's this 10 gig file of random data doing on your hard drive?" it would seem hard to answer them. The only thing that I know people use that much random data for is testing an RNG for its statistical properties.
- Tomdarkness 13y agoA normal (i.e non hidden) TrueCrypt volume is also by default filled with random data. With a hidden volume you first create the normal volume, which as part of that fills the file with random data, then create the hidden volume inside the normal volume. One password decrypts the normal volume and another decrypts the hidden volume. However, with just the normal volume password you can't determine the existence of the hidden volume (as long as you take some precautions to prevent leaking of information about the hidden volume)
- drostie 13y agoAh, yes! Sorry, I'd forgotten that those existed as well. I never really saw a deep potential for those -- the problem being that you cannot open the outer drive for writing without providing the password which enables the inner drive's reading, which means that you're constantly leaking that information whenever you're using the outer drive (which ideally would be relatively frequent, so as to justify that it's not masking a hidden drive. So I'd just totally forgotten that TrueCrypt could do that. My mistake.
- weavejester 13y ago