Or smashed the window, smashed the barrel and collected your car into it's parts and re-sold.
HN user
marysol5
I still don't trust that sort of thing. And I don't think I ever will.
Had that in /old job/ years ago, every security report would list off a load of packages that needed updating. Problem was, not only were they not actual vulnerabilities but they were all for some legacy software that was in the process of being removed.
Was always fun to purge a load of systems from old shit, and watch the counter drop.
"Shit why is everything dead"
Alternatively, you might shrug and wait to see which of these will get a logo and catchy name in the next few weeks and then try to focus on those.
hehehe
Another approach might be to sit back, have a nice cup of zen, and just always pull all updates and then update your entire fleet of systems on a weekly basis, which, yes, I sure would like to be able to do, but reality keeps getting in my way.
Am I the only one that gets concerned about the laissez-faire approach to security that a LOT of people take. I get that some exploits are not like the others, but some of the shit I've seen in places....
Maplin A08CQ (red ports only) 7 2.0 0409:0059 2008 2011
Jesus, that was a blast from the past
No doubt it's just a spray painted OEM product from China.
They are hidden if one of the "sources" to find them is only known to the user.
You would need to re-engineer this to not have an SD card. And you'd also need the MCU where you can't just read off the firmware and decompile it to see the encryption routing.
Also there is patches for luksOpen that destroys the key if you give a "duress" key. Not that would work in proper forensic operations.
VeraCrypt exists
You know that defence can bring in an expert witness too right?
None of which are what OP is claiming
Why do people just invent this absolute bullshit.
No there isn't. even people who have been prosecuted for refusing to decrypt data, it takes a lot of working by the prosecution to PROVE it's encrypted and not just "random data".
I'm from the UK and have been in court with encrypted data myself.....
You do not do any writes in a forensics scenario. Especially if you want to make it stand in court.
You have to always keep a clean hashed copy, and then work on copies from there.
It does, but it's extremely unusual for the feature to be in use on modern hardware.
FAT is a filesystem, it isn't hardware. They're talking about the table storing numbers of bad sectors/blocks.
The system you just described is exactly what TrueCrypt did, where if you overwrote the capacity and into the "hidden" data, you'd end up killing the hidden partition.
A cursory X-Ray would show the internal SD. This product needs a hardware re-design (which I've seen other projects do) to have onboard flash instead.
Saying that, any proper investigation would read the firmware from the flash and identify the decryption routing anyway
The military really doesn’t have "much smarter people", the intelligent people are all in private industry, then LEO, THEN the military.
The military is stuffed full of grunts who are just there for the pay, and in many cases, conscription.
You can throw all the money you want at something, it doesn't make it work, just look at the US military
In court I had to explain how a TPM works, to the prosecution.....
FBI = legal
Yeah the SD card is going to be glaring for anybody with actual investigation into this device.
But saying that, the sheer amount of fake flash storage out there now, that's just a glorified USB-SD reader in a box.
I'm confused here, what are you trying to detect?
You're not going to get the uA level of detection to be able to decipher between a R/W operation and some sort of crypto in the CPU with these cheap components.
laughs in that flash drive I have that just gets hot instead of working
I found a 8GB USB drive in my pocket after doing the washing the other day (RIP).
I'd been using it to boot the debian installer from.
Another day, another one of these projects.
With Phantomdrive, hopefully you’ll slip past authoritarian government representatives, corrupt police, and anyone else that doesn’t respect basic encryption rights.
Apart from the SD card on the board making it obvious something is going on, and the iron bar comes out
And the amount some people throw on products just because they're reps.
£15K rolex for £2k, yeah no thanks.
Also Amazon very intentionally structures it's business to allow these activities to happen.
Like stock mixing.
No, 10-15% higher in the US, even when they have lower quality and consume higher amounts of it.
Very much so, nothing was done to even give them opportunities to get work anywhere else either. And then on top of that the Tories destroyed everything else.
The other side of that is where there was a factory for the villagers to work in, and everybody had a wage, and a community.
The factory is now all robots, and only 3 people have a job there.