logoalt Hacker News

Cider9986yesterday at 11:47 PM3 repliesview on HN

Not physically possible[1] to be deniable and a bad[2] idea.

[1] https://veracrypt.io/en/Wear-Leveling.html

https://veracrypt.io/en/Trim%20Operation.html

[2] https://nitter.net/GrapheneOS/status/2082153517234676150#m


Replies

Borealidtoday at 12:59 AM

I don't understand how wear leveling makes deniability impossible. You just have to overwrite sectors in the false partition at the same rate as ones in the true partition. Since both the true and false partitions are encrypted, their contents are mathematically indistinguishable from randomness when viewed without the decryption key.

I also wish that GrapheneOS link didn't say a duress PIN forces the attacker to think twice about entering a PIN, knowing it could wipe the device. It doesn't do that for anyone aware of its existence, since of course the attacker can prevent the secure element from sending a delete command to the flash chip. Obviously if you know the device could attempt to delete itself you would break that feature before sending the code to the secure element...

krautsauertoday at 12:10 AM

Question on a detail: It's not necessary to have deniability on the fact that you did wipe your device, just on the fact that you did it after you entered the border? Or said differently, if he'd wiped the device before entering the border, it'd be all fine?

(That of course only takes down the "physically impossible" part.)

show 1 reply
cortesofttoday at 1:58 AM

You don’t need it to delete anything, anyway. The encrypted second partition is indistinguishable from random data, so you don’t need to delete it.