5 ms·
"While the planted secret can be used for authentication, the participant cannot be coerced into revealing it since he or she has no conscious knowledge of it."
by pointernil 12y ago
"While the planted secret can be used for authentication, the participant cannot be coerced into revealing it since he or she has no conscious knowledge of it."
Quite interesting idea. But don't we now move from "rubber hose" to "Please sit down and authenticate here." territory?
- AlyssaRowan 12y agoUnless it somehow fails subconsciously when under duress, yes, so this has no practical applications I can think of. It's still fascinating research, though. The problem with deniable cryptosystems that make it intractable to prove you've complied, like the old stegfs or the not-quite-as-old Marutukku (aka Rubberhose, which Julian Assange worked on by the way) is that it really sucks to be the keyholder! You can try to secure a system against duress disclosure, but you can't safeguard the people as well - it is possible to make wrench-resistant systems, but unfortunately not wrench-resistant kneecaps. I don't think any good solution exists for that: that's a physical/political/legal/OPSEC problem, not a technical one.
- wcummings 12y agoIt's also impossible for the key holder to prove to his assailants that he has provided the correct keys, so there is little incentive to comply in some situations, since you will likely be killed / tortured, either way.
- tedunangst 12y agoThe best of both worlds. Tortured until you reveal your password, then tortured some more!
- AlyssaRowan 12y agoExactly. Valuable if you want to ensure the confidentiality of the data no matter what - but you'd better really mean that "no matter what", because if the eventuality arises where the system's properties might be desirable, those same properties essentially spell your own doom. That and the disk-space penalty for the compartments (either fixed or stochastic) meant that, even in areas of potential forced key-disclosure, these systems didn't take off and are as far as I know mothballed and unmaintained.
- mey 12y agoA time based quorum of knee caps would increase the complexity of the attack, providing deterrent and better protection.
- ZoFreX 12y agoYes - the paper does acknowledge this, and makes the assumption that the point of entry is physically secured, for example by a human guard standing watch. This means you couldn't kidnap someone, steal their TOTP token, beat the password out of them, and then go to the location and authenticate as them. It doesn't help in a situation such as being able to log in from any internet connected terminal.