Friday, January 27, 2017

Interesting Idea - Add Duress Code to prevent forced unlocking of devices




From the Article:

A key observation from these cases is that the police can compel you to hand over a fingerprint, but cannot order you to tell the police which finger is used to unlock the device. This would be tantamount to ordering you to provide a passcode.

In the short term, Apple and Google can take steps to alleviate this threat by adding duress codes into their access control mechanisms. For instance, scanning anything but your right index finger might force a password-only lock.

In the long term, we need to rethink deploying deniability as a set of strategies for helping users evade coercion in general. What is similarly important is that all devices must have some sort of deniability baked-in, full stop





For more details:
http://www.mit.edu/~specter/articles/17/deniability1.html