Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If a judge or policeman orders you to hand over your password, you can plausibly say that you don’t actually know it

Surely for this system to help in allowing you to plausibly say that, you'd have to reference this system (or equivalent) and demonstrate that it is indeed used for the authentication the police want access to. And in that case, surely the police could just say "in that case, please authenticate for us"?



Hopefully stress means that you won't be able to do it properly anyway, which means coercion is useless.

The real problem is the device stores the password, so the real defence is the tamperproof-ness of the device, not whether you can be tricked or coerced into outputting the sequence.


Yeah, the research paper notes that they need to implement 'coercion detection'. From page 12:

"Since our aim is to prevent users from effectively transmitting the ability to authenticate to others, there remains an attack where an adversary coerces a user to authenticate while they are under ad- versary control. It is possible to reduce the effective- ness of this technique if the system could detect if the user is under duress. Some behaviors such as timed re- sponses to stimuli may detectably change when the user is under duress."


That's more of a bug than a feature when you're the one under duress.


What if you're running late to do something, or you are anxious to get access to the data behind the authentication for some other non-duress reason? Duress-detection will be tricky (but I look forward to them doing it!).


I would personally prefer to have my password at any time, rather than have to get in the "zone" to authenticate into my computer.


The problem with using coercion is, the people using it never believe it's useless regardless of what's coming out of your mouth.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: