5 ms·
This is why we need not only password locks and full encryption but panic passwords and hidden logins on every piece of electronics we own. That no mobile OS of
by monochr 12y ago
This is why we need not only password locks and full encryption but panic passwords and hidden logins on every piece of electronics we own. That no mobile OS offers these yet is pathetic.
When twitter and facebook don't let you connect anonymously from tor, this is what the result is. If you have a major website that is used by dissidents and journalists in countries such as Mexico or Iran and you don't have a plain html form to fall back on and insist on javascript being on all the time you really do have blood on your hands.
- coldtea 12y ago>This is why we need not only password locks and full encryption but panic passwords and hidden logins on every piece of electronics we own. Yeah, that would have saved her against Mexican drug cartels and a $50.000 dollars reward.
- monochr 12y agoYes, it literally would have since they found out who she was by looking through her phone after kidnapping her for an unrelated death of a cartel member. Try and read the article before you comment.
- coldtea 12y agoYeah, I read TFA. And since I follow those stories for years, what I wanted to say was that the fact that this particular instance happened in this way doesn't mean it's the only way this thing can happen. It's naive to think so. The reward and their "research facilities" would have gotten to her sooner or later. You do know that they also employ very talented hackers (of the Kevin Mittnick sense)? And that of course anybody who knew her identity could have snitched sooner or later? It was just a matter of how badly they wanted to get to her...
- monochr 12y agoEven if a system can fail in many ways you still should make every failure mode as difficult as possible. What you're saying makes as much sense as not improving seat belts in cars because the airbags might fail and you would still die.
- coldtea 12y agoThat assumes equal probability of those events, which is not in the least the case. It's more not like not improving anti-bacterial coating in car seats, when there are 200+ others way you can die in a car.
- girvo 12y agoRead the article yourself, that is quite possibly disinformation. The situation over there is very complex, and nothing is pure truth. Unless she practiced OPSEC above and beyond what most untrained people are capable of, it was always a high risk that it'd end this way. I've got nothing but respect for her. Her execution and the violence and organised crime is abhorrent. I wish there was something I could do.
- vacri 12y agoUnless she practiced OPSEC above and beyond what most untrained people are capable of Even security researchers don't practice it to that level. I went to a security conference last year, and one of the speakers was talking about his wifi sniffing box. Time came to demo how it worked... and it turns out that the wifi for the venue had crashed, and the security delegates in the main conference room behind him all attached to his box for net access - he was able to demo skimming hundreds of accounts, apparently. There was another speaker who mentioned that the security industry throws up so many 'best practice' recommendations that even security specialists can't cover them all.
- cynicalkane 12y agoSo in your theory, bloodthirsty murdering cartels are going to kidnap people, but let them go if they hit the panic encryption button on their phones or happen to be using a secret password. This is an interesting view of how drug cartels work. Personally, I don't know what the penalty for "contempt of drug cartel that just kidnapped you" is, but it seems unlikely to lead to a positive outcome.
- monochr 12y agohttps://www.usenix.org/legacy/event/hotsec08/tech/full_papers/clark/clark_html/ https://www.usenix.org/legacy/event/hotsec08/tech/full_paper... 3.1 Security Assumptions Our threat model is based on four pragmatic assumptions. Kerckhoffs' principle: The details of the authentication system that is in place is public information and known to all participants, including Oscar. Alice and Bob retain a shared secret (e.g., a password or set of passwords) that is both private and the foundation upon which the security of the system rests. Observational principle: Alice communicates with Bob over a semi-private channel that can be observed by Oscar prior to the password being secured (i.e., encrypted or hashed). Namely, Oscar can observe the password(s) used by Alice and could even enter in Alice's password himself, after coercing her into revealing it. Iteration principle: Unless explicitly prevented by the underlying system, Oscar is not bound to a single instance of coercion against Alice. He may force Alice to authenticate multiple times. Combined with the observational principle (Assumption 2), Oscar can force Alice to use a different password each time. Forced-randomization principle: Oscar can choose to eliminate any strategy Alice may employ through the order in which she reveals the passwords she knows. For example, Oscar may force Alice into writing down a set of passwords so that he can randomly choose the order in which to iterate through them. The assumption is that this option is available to Oscar, not that he will necessarily employ it.
- chaostheory 12y agoDidn't they let the other medical workers go?
- icpmacdo 12y agoIt would be interesting if you could have 2 codes to two different user accounts on the phone so she could give them the passcode "5555" and have it link to a harmless twitter/FB and then have another one to use for a private user account.
- x0x0 12y agohow in the hell would a password have helped? The sort of people who kidnap folks and shoot them in the head won't hesitate to cut a finger off or use 120v to ask your password.
- deleted 12y ago[deleted]
- wfunction 12y ago> This is why we need not only password locks and full encryption but panic passwords and hidden logins on every piece of electronics we own. http://xkcd.com/538/ http://xkcd.com/538/
- monochr 12y agoThank you for not reading my post: https://www.usenix.org/legacy/event/hotsec08/tech/full_papers/clark/clark_html/ https://www.usenix.org/legacy/event/hotsec08/tech/full_paper...
- seandhi 12y agoIt's still quite naive to think that if this were common practice that the torturers would not torture you until they were convinced that you gave them the _real_ password. Or they might give you the option of giving the real password the first time and make whatever final decision the "quick" or "painless" version rather than the long, drawn-out, most painful version.
- monochr 12y agoAgain thank you for not reading my post and the links therein: Kerckhoffs' principle: The details of the authentication system that is in place is public information and known to all participants, including Oscar. Alice and Bob retain a shared secret (e.g., a password or set of passwords) that is both private and the foundation upon which the security of the system rests. Observational principle: Alice communicates with Bob over a semi-private channel that can be observed by Oscar prior to the password being secured (i.e., encrypted or hashed). Namely, Oscar can observe the password(s) used by Alice and could even enter in Alice's password himself, after coercing her into revealing it. Iteration principle: Unless explicitly prevented by the underlying system, Oscar is not bound to a single instance of coercion against Alice. He may force Alice to authenticate multiple times. Combined with the observational principle (Assumption 2), Oscar can force Alice to use a different password each time. Forced-randomization principle: Oscar can choose to eliminate any strategy Alice may employ through the order in which she reveals the passwords she knows. For example, Oscar may force Alice into writing down a set of passwords so that he can randomly choose the order in which to iterate through them. The assumption is that this option is available to Oscar, not that he will necessarily employ it.
- dobbsbob 12y agoEncryption and password locks are pointless against a cartel, presumably they will employ rubber hose cryptanalysis to get any information they want. Seems like one solution would be to have a web browser that keeps no history, and use that to log into Twitter and report about cartels instead of an app that automatically logs you in or keeps history, or gives away the fact you have a twitter account they will demand to know about. There's also schemes like this which could be helpful to at risk journalists https://www.ccsl.carleton.ca/~askillen/mobiflage/ https://www.ccsl.carleton.ca/~askillen/mobiflage/ unless you are kidnapped while in PDE mode. If it's any small comfort, whoever was seen involved in this kidnapping is now a liability, as this case has brought a lot of heat so they were almost certainly finished off in the desert by their own cartel compadres to avoid potential snitching. The blog borderlandbeat has countless posts of mass executions the cartels do on their own guys as everybody except the capos are disposable. edit: Likely cartels have employees at telecoms in Mexico to look up logs for them, there's prob no easy solution. It wouldn't be expensive for them to hire anybody to exploit journalists with old carrier builds that are never updated either http://nakedsecurity.sophos.com/2014/09/16/shocking-android-browser-bug-could-be-a-privacy-disaster-heres-how-to-fix-it/ http://nakedsecurity.sophos.com/2014/09/16/shocking-android-...
- malandrew 12y agoIt's also a reason why we need to be able to delete our online activity permanently. Everyone who ever corresponded with felina's twitter account via private messages that didn't hide their own identity adequately is at risk. Before the account was suspended, I'm certain they went through the data. I wouldn't be surprised if they exported all her facebook data as well, which IIRC includes content marked "deleted".
- logn 12y agoHN also makes it hard to connect from Tor... "Prove you're legit" and the captcha never lets you through, even after solving it right. This is a common problem with Cloudflare sites. Cloudflare is an enormous security hole as it is and it's making it worse by actively working against Tor and making SSL certs largely untrustable (if they weren't already).
- dang 12y agoAre you sure you're up to date on that? Captcha for new account creation on HN is either mostly turned off or completely so, and last I tested it, Google had made RECAPTCHA doable by humans again. HN's restrictions on Tor IPs are only for brand new accounts. That's because of past abuses by trolls. Even then, we routinely override the restriction for accounts that are obviously legit. Anyone who sees a case of this (i.e. legit noob comments that are dead) should email us. In most cases we fix them immediately.
- logn 12y agoIt's happened while I've been logged in too. However, I've also taken other measures to randomize user agent, screen size, etc and to set referrer to the site's root (and disable Google Analytics). I thought I tested it without those extra mods but I'll double check and reply to my comment when I can confirm. Aside from HN however, I am positive that Cloudflare completely blocks vanilla Tor browsers from many of their properties.
- dang 12y agoSounds good. But please email hn@ycombinator.com as well if you have findings you want to make sure we see. Replying in a comment is fine, of course; it's just hit-and-miss as far as bringing something to our attention goes.
- logn 12y agoTor works OK on HN. It was one of the other unique browser settings I had that was triggering captcha.