Mobiflage: Deniable Storage Encryption for Mobile Devices 3

Total Page:16

File Type:pdf, Size:1020Kb

Mobiflage: Deniable Storage Encryption for Mobile Devices 3 TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING 1 Mobiflage: Deniable Storage Encryption for Mobile Devices Adam Skillen and Mohammad Mannan Abstract—Data confidentiality can be effectively preserved through encryption. In certain situations, this is inadequate, as users may be coerced into disclosing their decryption keys. Steganographic techniques and deniable encryption algorithms have been devised to hide the very existence of encrypted data. We examine the feasibility and efficacy of deniable encryption for mobile devices. To address obstacles that can compromise plausibly deniable encryption (PDE) in a mobile environment, we design a system called Mobiflage. Mobiflage enables PDE on mobile devices by hiding encrypted volumes within random data in a devices free storage space. We leverage lessons learned from deniable encryption in the desktop environment, and design new countermeasures for threats specific to mobile systems. We provide two implementations for the Android OS, to assess the feasibility and performance of Mobiflage on different hardware profiles. MF-SD is designed for use on devices with FAT32 removable SD cards. Our MF-MTP variant supports devices that instead share a single internal partition for both apps and user accessible data. MF-MTP leverages certain Ext4 file system mechanisms and uses an adjusted data-block allocator. These new techniques for storing hidden volumes in Ext4 file systems can also be applied to other file systems to enable deniable encryption for desktop OSes and other mobile platforms. Index Terms—File system security, Mobile platform security, Storage Encryption, Deniable encryption ✦ 1 INTRODUCTION AND MOTIVATION plaintext can be recovered by decrypting with the true key. In the event that a ciphertext is intercepted, and the Smartphones and other mobile computing devices are user is coerced into revealing the key, she may instead being widely adopted globally. For instance, accord- provide a decoy key to reveal a plausible and benign ing to a comScore report [2], there are more than decoy message. The Rubberhose file system for Linux 119 million smartphone users in the USA alone, as (developed by Assange et al. [4]) is the first known of Nov. 2012. With this increased use, the amount of instance of a PDE-enabled storage system. personal/corporate data stored in mobile devices has Some real-world scenarios may mandate the use of also increased. Due to the sensitive nature of (some PDE-enabled storage—e.g., a professional/citizen jour- of) this data, all major mobile OS manufacturers now nalist, or human rights worker operating in a region include some level of storage encryption. Some vendors of conflict or oppression. In a recent incident [5], an use file based encryption, such as Apple’s iOS, while individual risked his life to smuggle his phone’s micro others implement “full disk encryption” (FDE). Google SD card, containing evidence of atrocities, across inter- introduced FDE in Android 3.0 (for tablets only); FDE national borders by stitching the card beneath his skin. is now available for all Android 4.x devices, including Mobile phones have been extensively used to capture tablets and smartphones. and publish many images and videos of recent popular While Android FDE is a step forward, it lacks deniable revolutions and civil disobedience. When a repressive encryption—a critical feature in some situations, e.g., regime disables network connectivity in its jurisdiction, when users want to provide a decoy key in a plausible PDE-enabled storage on mobile devices can provide a vi- manner, if they are coerced to give up decryption keys. able alternative for data exfiltration. With the ubiquity of Plausibly deniable encryption (PDE) was first explored smartphones, we postulate that PDE would be an attrac- by Canetti et al. [3] for parties communicating over a tive or even a necessary feature for mobile devices. Note, network. As it applies to storage encryption, PDE can be however, that PDE is only a technical measure to prevent simplified as follows: different reasonable and innocu- a user from being punished if caught with contentious ous plaintexts may be output from a given ciphertext, material; an adversary can always wipe/confiscate the when decrypted under different decoy keys. The original device itself if such material is suspected to exist. This work is the extension of an NDSS 2013 publication [1]. Several existing solutions support full disk encryption • A. Skillen is currently with the Carleton Computer Security Lab at with plausible deniability in regular desktop operating Carleton University, Ottawa, Canada, and was at Concordia University, systems. Possibly the most widely used such tool is Montreal, Canada when performing this research. TrueCrypt [6]. To our knowledge, no such solutions E-mail: [email protected] • M. Mannan is with the Concordia Institute for Information Systems exist for any mainstream mobile OSes, although PDE Engineering at Concordia University, Montreal, Canada. support is apparently more important for these systems, E-mail: [email protected]. as mobile devices are more widely used and portable than laptops or desktops. Also, porting desktop PDE 2 TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING solutions to mobile devices is not straightforward due intensive applications. We also perform file system to the tight coupling between hardware and software benchmarks to determine the impact of our mod- components, and intricacies of the system boot proce- ified Ext4 driver. In a Nexus S device, our imple- dure. For example, in Android, the framework must be mentation appears to perform almost as efficiently partially loaded to use the soft keyboard for collecting as the default Android 4.x encryption for the ap- decoy/true passwords; and the TrueCrypt bootloader is plications we tested. However, the Mobiflage setup only designed to chainload Windows. phase takes more time than Android FDE, due to a We introduce Mobiflage, a PDE-enabled storage en- two-pass wipe of the storage (our Nexus S required cryption system for the Android OS. It includes coun- almost twice as long; exact timing will depend on termeasures for known attacks against desktop PDE the size and type of storage). implementations (e.g., [7]). We also explore challenges more specific to using PDE systems in a mobile envi- 2 THREAT MODEL AND ASSUMPTIONS ronment, including: collusion of cellphone carriers with an adversary; the use of flash-based storage as opposed In this section, we discuss Mobiflage’s threat model and to traditional magnetic disks; and file systems such as operational assumptions, and few legal aspects of using Ext4 (as used in Android) that are not so favorable to PDE in general. The major concern with maintaining PDE. Mobiflage addresses several of these challenges. plausible deniability is whether the system will provide However, to effectively offer deniability, Mobiflage must some indication of the existence of any hidden data. be widely deployed, e.g., adopted in the mainstream Mobiflage’s threat model is mostly based on past work Android OS. As such, we implement our Mobiflage on desktop PDE solutions (cf. TrueCrypt [6]); we also prototype to be compatible with Android 4.x. include threats more specific to mobile devices. Threat model and operational assumptions. Our contributions include: 1) Mobiflage must be merged with the Android code 1) We explore sources of leakage inherent to mobile stream, or a widely used custom firmware based on devices that may compromise deniable storage en- Android (e.g., CyanogenMod1) to ensure that many cryption. Several of these leakage vectors have not devices are capable of using PDE. Then an adversary been analyzed for existing desktop PDE solutions. will be unable to make assumptions about the pres- 2) We present the Mobiflage PDE scheme based on ence of hidden volumes based on the availability hidden encrypted volumes—the first such scheme of software support. We do not require a large for mobile systems to the best of our knowledge. user base to employ PDE; it is sufficient that the 3) We introduce two variants of Mobiflage to address capability is widespread, so the availability of PDE several challenges specific to different Android will not be a red flag. Similar to TrueCrypt [6], all hardware profiles. Mobiflage for devices with re- installations of Mobiflage include PDE capabilities. movable SD cards (MF-SD) avoids PDE-unfriendly 2) The adversary has the encrypted device and full features of the Ext4 file system by storing hidden knowledge of Mobiflage’s design, but lacks the PDE volumes within the FAT32-based external partition. key and password. The existence and location of the Devices, such as the Nexus S, which use an internal hidden volume is therefore also unknown. eMMC partition to emulate removable SD storage 3) The adversary has some means of coercing the are also supported by MF-SD. Newer devices, such user to reveal their encryption keys and passwords as the Nexus 4 and HTC One, have neither physical (e.g., unlock-screen secret), but will not continue to nor emulated external storage. Instead, they rely on punish the user in vain. To successfully provide the media transfer protocol (MTP) and share a single deniability in Mobiflage, the user is expected to Ext4-formatted partition for both the (internal) app refrain from disclosing the true key. storage and (external) user data storage. To support 4) The adversary can directly access the device’s stor- these devices, we present MF-MTP, by making sub- age, and can have root-level access to the device tle changes to the Ext4 file system. For the remainder after capturing it. The adversary can then manip- of the document, the term Mobiflage will refer to the ulate disk sectors, including encryption/decryption high level design. The terms MF-SD and MF-MTP under any decoy keys learned from the user; this can will refer to the specific implementation variants.
Recommended publications
  • Mobiceal: Towards Secure and Practical Plausibly Deniable Encryption on Mobile Devices
    2018 48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks MobiCeal: Towards Secure and Practical Plausibly Deniable Encryption on Mobile Devices Bing Chang∗, Fengwei Zhang†, Bo Chen‡, Yingjiu Li∗, Wen-Tao Zhu§, Yangguang Tian∗, Zhan Wang¶ and Albert Ching ∗School of Information Systems, Singapore Management University, {bingchang, yjli, ygtian} †Department of Computer Science, Wayne State University, [email protected] ‡Department of Computer Science, Michigan Technological University, [email protected] §Data Assurance and Communications Security Research Center, Chinese Academy of Sciences, [email protected] ¶RealTime Invent, Inc. i-Sprint Innovations Abstract—We introduce MobiCeal, the first practical Plausibly searched and copied when he was crossing a border, and he Deniable Encryption (PDE) system for mobile devices that can was inspected for seven times during five years [26]. defend against strong coercive multi-snapshot adversaries, who The existing PDE systems on mobile devices [21], [34], may examine the storage medium of a user’s mobile device at different points of time and force the user to decrypt data. [35], [43], [27], [20] are not resilient against such multi- MobiCeal relies on “dummy write” to obfuscate the differences snapshot attacks since they hide sensitive data in the ran- between multiple snapshots of storage medium due to existence domness initially filled across the entire disk. By comparing of hidden data. By incorporating PDE in block layer, MobiCeal storage snapshots at different points of time, a multi-snapshot supports a broad deployment of any block-based file systems on adversary may detect any unaccountable changes to the ran- mobile devices.
    [Show full text]
  • PV204: Disk Encryption Lab
    PV204: Disk encryption lab May 12, 2016, Milan Broz <[email protected]> Introduction Encryption can provide confidentiality and authenticity of user data. It can be implemented on several different layes, including application, file system or storage device. Application encryption examples are PGP or ZIP compression with password. Encryption of files (inside filesystem or through independent layer like Linux eCryptfs) provides more generic solution. Yet some parts (like filesystem metadata) are still unencrypted. However this solution provides encrypted data with private key per user. (Every user can have own directory encrypted by own key.) Encryption of the low-level storage (disk) is called Full Disk Encryption (FDE). It is completely transparent to the user (no need to choose what to encrypt – the whole disk is encrypted). The encrypted disk behaves as the same as a disk without encryption. The major disadvantage is that everyone who knows the password can read the whole disk. Often we combine FDE with another encryption layer. The primary use of FDE is to provide data confidentiality in power-down mode (stolen laptop does not leak user data). Once the disk is unlocked, the main encryption key remains in system, usually directly in system RAM. Exercise II will show how easy is to get this key from memory image of system. Another disadvantage of FDE is that it usually cannot guarantee integrity of data. Encryption is fully transparent and length-preserving, the ciphertext and plaintext device are of the same size. There is no space to store any integrity information. This allows attacks by direct modification of ciphertext.
    [Show full text]
  • Self-Encrypting Deception: Weaknesses in the Encryption of Solid State Drives
    Self-encrypting deception: weaknesses in the encryption of solid state drives Carlo Meijer Bernard van Gastel Institute for Computing and Information Sciences School of Computer Science Radboud University Nijmegen Open University of the Netherlands [email protected] and Institute for Computing and Information Sciences Radboud University Nijmegen Bernard.vanGastel@{,} Abstract—We have analyzed the hardware full-disk encryption full-disk encryption. Full-disk encryption software, especially of several solid state drives (SSDs) by reverse engineering their those integrated in modern operating systems, may decide to firmware. These drives were produced by three manufacturers rely solely on hardware encryption in case it detects support between 2014 and 2018, and are both internal models using the SATA and NVMe interfaces (in a M.2 or 2.5" traditional form by the storage device. In case the decision is made to rely on factor) and external models using the USB interface. hardware encryption, typically software encryption is disabled. In theory, the security guarantees offered by hardware encryp- As a primary example, BitLocker, the full-disk encryption tion are similar to or better than software implementations. In software built into Microsoft Windows, switches off software reality, we found that many models using hardware encryption encryption and completely relies on hardware encryption by have critical security weaknesses due to specification, design, and implementation issues. For many models, these security default if the drive advertises support. weaknesses allow for complete recovery of the data without Contribution. This paper evaluates both internal and external knowledge of any secret (such as the password).
    [Show full text]
  • Omegakey Manage Your Device at the Management Module
    Welcome to use our latest version of Lost Mode How to Start to Use it Bluetooth tracker. Detect the distance between the device and Bluetooth Tracker module your phone under the lost mode .Turn on the Step 1: Download the latest version App(version 1.6.0) from Apple App store. omegakey Manage your device at the management module. alarm at alert whether the device is lost, there Step 2: Open the Bluetooth and App. are two levels of lost alarm mode. Select the Thank you for purchasing omegakey Freely set and remove your device here. Step 3: Tap the Beacon for 3-5 times on hard surface, and the Beacon will be connectable when you Double-click the “call” button to find your device. alarm mode you want from the device. Phone hear a buzz. alarm, and both ends alarm. Step 4: Click the Beacon in the App which you want to configure and enter a name to connect it. Step 5: Now, you can configure and use the Beacon normally. NEXT Note: If you're having trouble with the Bluetooth, we recommend you completely remove the battery from the unit for 10 sec and reinsert it. There are many apps you can download some are better than others, we have linked just click on the apple / android icons on the first page Once you have selected the app you like download it and follow the on screen instructions ATTACH BLUETOOTH BEACON EXTERNALLY FOR MAX PERFORMANCE Found mode More View the alarm location or item's last location Find the device under the find mode according p.s make sure your Bluetooth is on and your phone is compatible with 4.0 Bluetooth to the strength of the signal.
    [Show full text]
  • A Future-Focused Forensic Imager Designed to Streamline Evidence Collection Processes
    A Future-Focused Forensic Imager Designed to Streamline Evidence Collection Processes Extremely fast forensic imaging speed surpassing 50GB/min. Clone PCIe to PCIe at speeds above 90GB/min Image to/from Thunderbolt™ 3/USB-C external storage enclosures with an optional I/O card. Image and verify from up to 5 source drives up to 9 destinations simultaneously Create a logical image to capture only specific files needed Concurrent Image+Verify greatly reduces duration of image plus verification process Two 10GbE connections provide fast network imaging performance Network capture feature to capture network traffic, VOIP, internet activity Multi-task. Image from multiple sources simultaneously FEATURES n The Falcon®-NEO achieves imaging speeds when imaging directly to large capacity Thunder- n Image from a Mac® computer with USB-C ports surpassing 50GB/min and can clone PCIe to PCIe bolt 3 RAID storage enclosures for evidence data using a USB-C to USB-A cable and Target Disk at speeds at over 90GB/min. collection. The card connects to the Falcon-NEO’s Mode or use Logicube’s USB boot device to n Image and verify to multiple image formats; 2 write-blocked source I/O ports or 1 destination I/O image a source drive from a Mac computer on the native copy, .dd, dmg, e01 and ex01. The Falcon- port. The I/O card does not currently support imaging same network without booting the Mac computer’s ® NEO provides MD5, SHA1, SHA256, and dual hash in TDM from Mac systems, refer to the Falcon-NEO native OS. The Falcon-NEO supports imaging from ® authentication at extremely fast speeds.
    [Show full text]
  • A Plausibly Deniable Encryption Scheme for Personal Data Storage Andrew Brockmann Harvey Mudd College
    Claremont Colleges Scholarship @ Claremont HMC Senior Theses HMC Student Scholarship 2015 A Plausibly Deniable Encryption Scheme for Personal Data Storage Andrew Brockmann Harvey Mudd College Recommended Citation Brockmann, Andrew, "A Plausibly Deniable Encryption Scheme for Personal Data Storage" (2015). HMC Senior Theses. 88. This Open Access Senior Thesis is brought to you for free and open access by the HMC Student Scholarship at Scholarship @ Claremont. It has been accepted for inclusion in HMC Senior Theses by an authorized administrator of Scholarship @ Claremont. For more information, please contact [email protected]. A Plausibly Deniable Encryption Scheme for Personal Data Storage Andrew Brockmann Talithia D. Williams, Advisor Arthur T. Benjamin, Reader Department of Mathematics May, 2015 Copyright © 2015 Andrew Brockmann. The author grants Harvey Mudd College and the Claremont Colleges Library the nonexclusive right to make this work available for noncommercial, educational pur- poses, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the author. Abstract Even if an encryption algorithm is mathematically strong, humans in- evitably make for a weak link in most security protocols. A sufficiently threatening adversary will typically be able to force people to reveal their encrypted data. Methods of deniable encryption seek to mend this vulnerability by al- lowing for decryption to alternate data which is plausible but not sensitive. Existing schemes which allow for deniable encryption are best suited for use by parties who wish to communicate with one another.
    [Show full text]
  • Ensuring Data Confidentiality Via Plausibly Deniable Encryption and Secure Deletion – a Survey Qionglu Zhang1,2,3, Shijie Jia1,2*, Bing Chang4 and Bo Chen5*
    Zhang et al. Cybersecurity (2018) 1:1 Cybersecurity SURVEY Open Access Ensuring data confidentiality via plausibly deniable encryption and secure deletion – a survey Qionglu Zhang1,2,3, Shijie Jia1,2*, Bing Chang4 and Bo Chen5* Abstract Ensuring confidentiality of sensitive data is of paramount importance, since data leakage may not only endanger data owners’ privacy, but also ruin reputation of businesses as well as violate various regulations like HIPPA and Sarbanes-Oxley Act. To provide confidentiality guarantee, the data should be protected when they are preserved in the personal computing devices (i.e., confidentiality during their lifetime); and also, they should be rendered irrecoverable after they are removed from the devices (i.e., confidentiality after their lifetime). Encryption and secure deletion are used to ensure data confidentiality during and after their lifetime, respectively. This work aims to perform a thorough literature review on the techniques being used to protect confidentiality of the data in personal computing devices, including both encryption and secure deletion. Especially for encryption, we mainly focus on the novel plausibly deniable encryption (PDE), which can ensure data confidentiality against both a coercive (i.e., the attacker can coerce the data owner for the decryption key) and a non-coercive attacker. Keywords: Data confidentiality, Plausibly deniable encryption, Secure deletion Introduction Spahr LLP: State and local governments move swiftly to Modern computing devices (e.g., desktops, laptops, smart sue equifax 2017); Third, it will directly violate regulations phones, tablets, wearable devices) are increasingly used like HIPAA (Congress 1996), Gramm-Leach-Bliley Act to process sensitive or even mission critical data.
    [Show full text]
  • Deniable Encryption Protocols Based on Probabilistic Public-Key Encryption
    ______________________________________________________PROCEEDING OF THE 20TH CONFERENCE OF FRUCT ASSOCIATION Deniable Encryption Protocols Based on Probabilistic Public-Key Encryption 1LNROD\Moldovyan1,$QGUH\Berezin2, $QDWRO\Kornienko3,$OH[DQGHUMoldovyan1 1SaintPetersburgInstituteforInformaticsandAutomationofRussianAcademyofSciences 2SaintPetersburgElectrotechnicalUniversity”LETI” 3PetersburgStateTransportUniversity St.Petersburg,RussianFederation [email protected],[email protected],{kaa.pgups,maa1305} Abstract—The paper proposes a new method for designing where P is a public key. At time of the coercive attack the deniable encryption protocols characterized in using RSA-like sender of the message can open a fake message m with another probabilistic public-key encryption algorithms. Sender-, receiver-, random value r =r such that c = EP (m, r ). The fake random and bi-deniable protocols are described. To provide bi-deniability value r can be computed with some faking algorithm FP , in the case of attacks perfored by an active coercer stage of entity parametrized with the public-key value P. The algorithm FP authentication is used in one of described protocols. is considered as a part of the DE scheme. Its input is the pair (c, m), i.e. r = FP (c, m). The fake message can be I. INTRODUCTION selected arbitrary at time when the sender and/or the receiver The regular encryption schemes provide very high security of the ciphertext are coerced. Examples of such design of against known-plaintext and chosen text attacks, therefore they the DE protocols are presented in papers [12], [13]. In that are widely used to protect information sent via telecommuni- protocols the secret message is encrypted consecutively bit by cation channels from unauthorized access.
    [Show full text]
  • Mobihydra: Pragmatic and Multi-Level Plausibly Deniable Encryption Storage for Mobile Devices?
    MobiHydra: Pragmatic and Multi-Level Plausibly Deniable Encryption Storage for Mobile Devices? Xingjie Yuy;z;\, Bo Chen], Zhan Wangy;z;??, Bing Changy;z;\, Wen Tao Zhuz;y, and Jiwu Jingy;z y State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, CHINA z Data Assurance and Communication Security Research Center, Chinese Academy of Sciences, CHINA \ University of Chinese Academy of Sciences, CHINA ] Department of Computer Science, Stony Brook University, USA Email: [email protected], [email protected], [email protected], [email protected], [email protected], [email protected] Abstract. Nowadays, smartphones have started being used as a tool to collect and spread po- litically sensitive or activism information. The exposure of the possession of such sensitive data shall pose a risk in severely threatening the life safety of the device owner. For instance, the data owner may be caught and coerced to give away the encryption keys so that the encryption alone is inadequate to mitigate such risk. In this work, we present MobiHydra, a pragmatic plausibly deniable encryption (PDE) scheme featuring multi-level deniability on mobile devices, to circumvent the coercive attack. MobiHydra is pragmatic in that it remarkably supports hiding opportunistic data without necessarily rebooting the device. In addition, MobiHydra favourably mitigates the so-called booting-time defect, which is a whistle-blower to expose the usage of PDE in previous solutions. We implement a prototype for MobiHydra on Google Nexus S. The evaluation results demonstrate that MobiHydra introduces very low overhead compared with other PDE solutions for mobile devices.
    [Show full text]
  • Deniable Encryption with Negligible Detection Probability: an Interactive Construction
    Deniable Encryption with Negligible Detection Probability: An Interactive Construction Markus Durmuth¨ ?1 and David Mandell Freeman??2 1 Ruhr-University Bochum, Germany [email protected] 2 Stanford University, USA, [email protected] Abstract. Deniable encryption, introduced in 1997 by Canetti, Dwork, Naor, and Ostrovsky, guarantees that the sender or the receiver of a secret message is able to “fake” the message encrypted in a specific ciphertext in the presence of a coercing adversary, without the adversary detecting that he was not given the real message. To date, constructions are only known either for weakened variants with separate “honest” and “dishonest” encryption algorithms, or for single-algorithm schemes with non-negligible detection probability. We propose the first sender-deniable public key encryption system with a single encryption algorithm and negligible detection probability. We describe a generic interactive construction based on a public key bit encryption scheme that has certain properties, and we give two examples of encryption schemes with these properties, one based on the quadratic residuosity assumption and the other on trapdoor permutations. Keywords. Deniable encryption, electronic voting, multi-party computation. 1 Introduction One of the central goals of cryptography is protecting the secrecy of a transmitted message. The secrecy property of an encryption scheme is usually formalized as semantic security [10], which guarantees that an adversary cannot gain even partial information about an encrypted message. The notion of semantic security has proven to be very useful in a large number of applications. However, there are some scenarios where semantic security is not sufficient. For example, semantic security does not ensure message secrecy if the adversary can coerce the sender or the receiver of a message to reveal the secret keys and/or the randomness that was used to form an encryption.
    [Show full text]
  • Uncoercible Communication and Deniable Encryption, Or How to Lie with Impunity
    Uncoercible Communication and Deniable Encryption, or How to Lie With Impunity Matthew Kerner 3/4/2006 1 Introduction Use of some cryptographic protocols implies a commitment to the data operated on by those protocols. For example, a digital signature may ensure the property of nonrepudiation: the signer would be unable to claim that the signed document is a forgery. Similarly, encrypting data can form a kind of commitment to the data: the decryption process reveals the committed plaintext. In some scenarios, commitment to a plaintext may be undesirable. For example, in an election setting, we would like to prevent voters from being able to generate proof of their votes, ensuring that they cannot be coerced into voting a certain way, or rewarded for doing so. A secret agent may wish to be able to communicate with her sponsoring organization freely even if a coercive adversary is applying pressure to have her send a particular message. A corporate employee may wish to act as a whistle-blower without fear of management reprisal for having disclosed sensitive information. A variety of techniques have been developed in recent years to provide various cryptographic services, including privacy, without implying a commitment to the plaintext, even under coercive circumstances. We examine a variety of techniques in this vein. But first, we should establish some informal definitions. Coercion occurs when one party forces another, through physical threats, monetary or other rewards, legal action, or other pressure to follow certain be- havior. Coercion can occur before, during or after a transaction of interest. Multiple parties involved in a transaction may be coerced, by the same or dif- ferent adversaries, and each may be asked to follow different behavior.
    [Show full text]
  • Winter 2016 E-Newsletter
    WINTER 2016 E-NEWSLETTER At Digital Mountain we assist our clients with their e-discovery, computer forensics and cybersecurity needs. With increasing encryption usage and the recent news of the government requesting Apple to provide "backdoor" access to iPhones, we chose to theme this E-Newsletter on the impact data encryption has on attorneys, litigation support professionals and investigators. THE SHIFTING LANDSCAPE OF DATA ENCRYPTION TrueCrypt, a free on-the-fly full disk encryption product, was the primary cross-platform solution for practitioners in the electronic discovery and computer forensics sector. Trusted and widely adopted, TrueCrypt’s flexibility to perform either full disk encryption or encrypt a volume on a hard drive was an attractive feature. When TrueCrypt encrypted a volume, a container was created to add files for encryption. As soon as the drive was unmounted, the data was protected. The ability to add a volume to the original container, where any files or the folder structure could be hidden within an encrypted volume, provided an additional benefit to TrueCrypt users. However, that all changed in May 2014 when the anonymous team that developed TrueCrypt decided to retire support for TrueCrypt. The timing of TrueCrypt’s retirement is most often credited to Microsoft’s ending support of Windows XP. The TrueCrypt team warned users that without support for Windows XP, TrueCrypt was vulnerable. Once support for TrueCrypt stopped, trust continued to erode as independent security audits uncovered specific security flaws. In the wake of TrueCrypt’s demise, people were forced to look for other encryption solutions. TrueCrypt’s website offered instructions for users to migrate to BitLocker, a full disk encryption program available in certain editions of Microsoft operating systems beginning with Windows Vista.
    [Show full text]