From: test532@codingninjas.org
To: dm-crypt@saout.de
Subject: Re: [dm-crypt] cryptsetup, LUKS, plausible deniability
Date: Mon, 14 Sep 2009 20:04:48 -0400 [thread overview]
Message-ID: <200909142004.49035.test532@codingninjas.org> (raw)
In-Reply-To: <slrnhatlce.qfd.Mario.Holbe@darkside.dyn.samba-tng.org>
> Arno Wagner <arno@wagner.name> wrote:
> > On Mon, Sep 14, 2009 at 01:25:48PM +0200, Mario 'BitKoenig' Holbe wrote:
> >> and the system gives you the ability to plausibly deny the existence of
> >> more keys. Just in the hope they stop cutting your extremities after the
> >
> > I would say plausible deniability has the potential to make
> > them continue even after you have given them everything, after
>
> Of course. For me (if I'd be in that business) just the presence of a
> system offering plausible deniability capabilities would be enough to
> simply assume they are used and thus continue pressing out keys of the
> suspect :)
That is the beauty of a dm-crypt that supported even just the very elegant
external luks header feature that Rick mentioned. dm-crypt comes with
practically every linux. Therefor, having dm-crypt installed on one's system
means nothing. Potentially, even only with the feature that Rick came up with,
dm-crypt would be better at plausible deniability than TrueCrypt. This is
because having TrueCrypt installed on your system pretty much guarantees that
you have an encrypted volume. Having dm-crypt on your system means nothing.
Probably less than a percent of people with dm-crypt installed actually use
it, since at least my distro (SuSE) installs it by default.
>
> However, not offering such capabilities is only one strategy in the game
> - and not a very cooperative one: it exposes the users of systems that
> *do* offer such capabilities. Thus, the other way around is more
> cooperative: if all major products would support plausible deniability,
> the fact that some suspect uses one specific system loses this
> indication.
>
>
> regards
> Mario
>
next prev parent reply other threads:[~2009-09-15 0:06 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-09-12 21:53 [dm-crypt] cryptsetup, LUKS, plausible deniability Ivan Stankovic
2009-09-12 22:22 ` Arno Wagner
2009-09-13 8:56 ` Tommaso
2009-09-13 9:07 ` [dm-crypt] OT: spam? Tommaso
2009-09-13 9:12 ` Rick Moritz
2009-09-13 10:00 ` Heinz Diehl
2009-09-13 18:37 ` Arno Wagner
2009-09-13 18:36 ` [dm-crypt] cryptsetup, LUKS, plausible deniability Arno Wagner
2009-09-13 19:44 ` Ivan Stankovic
2009-09-14 3:32 ` Arno Wagner
2009-09-14 7:28 ` Rick Moritz
2009-09-14 21:04 ` Arno Wagner
2009-09-13 18:04 ` Sven Eschenberg
[not found] ` <4AACA98F.2060002@redhat.com>
2009-09-13 18:28 ` Arno Wagner
2009-09-13 18:52 ` Milan Broz
2009-09-14 1:21 ` Sitaram Chamarty
2009-09-14 11:25 ` Mario 'BitKoenig' Holbe
2009-09-14 20:56 ` Arno Wagner
2009-09-14 23:45 ` Mario 'BitKoenig' Holbe
2009-09-15 0:04 ` test532 [this message]
[not found] ` <6842.57094185359$1253045311@news.gmane.org>
2009-09-16 19:32 ` Mario 'BitKoenig' Holbe
2009-09-16 21:41 ` Debian User
2009-09-17 18:26 ` test532
2009-09-18 1:20 ` Arno Wagner
2009-09-18 4:00 ` test532
[not found] ` <20090915200808.2DD0F4250006@tansi.org>
2009-09-15 20:32 ` Arno Wagner
2009-09-16 19:41 ` Mario 'BitKoenig' Holbe
2009-09-16 21:30 ` Arno Wagner
2009-09-16 1:50 ` Moji
2009-09-16 19:50 ` Mario 'BitKoenig' Holbe
2009-09-16 21:05 ` test532
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200909142004.49035.test532@codingninjas.org \
--to=test532@codingninjas.org \
--cc=dm-crypt@saout.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.