Allegation: Philly Cops Leaned Suspect Over Balcony To Obtain Password
An anonymous reader writes with this news from Ars Technica: If you want access to encrypted data on a drug dealer's digital device, you might try to break the crypto—or you might just try to break the man.
According to testimony from a police corruption trial currently roiling the city of Philadelphia, officers from an undercover drug squad took the latter route back in November 2007. After arresting their suspect, Michael Cascioli, in the hallway outside his 18th floor apartment, the officers took Cascioli back inside. Although they lacked a search warrant, the cops searched Cascioli's rooms anyway. According to a federal indictment (PDF), the officers 'repeatedly assaulted and threatened [Cascioli] during the search to obtain information about the location of money, drugs, and drug suppliers.' That included, according to Cascioli, lifting him over the edge of his balcony to try to frighten out of him the password to his Palm Pilot. That sounds like a good time for a duress password.
According to testimony from a police corruption trial currently roiling the city of Philadelphia, officers from an undercover drug squad took the latter route back in November 2007. After arresting their suspect, Michael Cascioli, in the hallway outside his 18th floor apartment, the officers took Cascioli back inside. Although they lacked a search warrant, the cops searched Cascioli's rooms anyway. According to a federal indictment (PDF), the officers 'repeatedly assaulted and threatened [Cascioli] during the search to obtain information about the location of money, drugs, and drug suppliers.' That included, according to Cascioli, lifting him over the edge of his balcony to try to frighten out of him the password to his Palm Pilot. That sounds like a good time for a duress password.
I remember it being done in a few movies — by the good guys — without anybody in the audience cringing. Nor do I remember any calls to boycott a movie over such things.
So, if popular culture approves of and encourages it, can't blame the cops too much for doing it despite it being merely illegal...
In Soviet Washington the swamp drains you.
Obligatory https://xkcd.com/538/
https://xkcd.com/538/
Bam! My first obligatory post on Slashdot.
Someone has probably posted it while I typed this though...
BlameBillCosby.com
The idea is that if you beat somebody with a rubber hose, that does not leave any mark.
Also, stop the nonsense about duress-passwords. They do not work. Really not and no, your smart idea for any movie-like device that makes them work is just that: Movie-like but not real. On the other hand, trying to be smart with a duress password procedure can easily get you killed or worse.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
At least none that can be seen. You cannot demand keys for something you don't know of. If there's a container with a "please enter pass phrase" lock on top of it, it begs for a key.
Unused space on your hard drive that looks like it contains old data from before you last partitioned, though...
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
something about a $5 wrench?
Sometimes deliberate jokes are deliberately stupid.
I think the more interesting story is undercover drug unit goes and terrorizes numerous drug dealers for illegal profit. But I guess that story is already months old. http://articles.philly.com/201...
"After investing $1 billion in behavior detection techniques and training since 2007, the Transportation Security Administration has little to show for its efforts, the New York Times stated in a new report. According to the newspaper, critics of the TSA’s attempt to read body language claim there’s no evidence to suggest the agency has been able to link chosen passengers to anything beyond carrying drugs or holding undeclared currency, much less a terrorist attack. In fact, a review of numerous studies seems to suggest that even those trained to look for various tics are no more capable of identifying liars than normal individuals. 'The common-sense notion that liars betray themselves through body language appears to be little more than a cultural fiction,' Maria Hartwig, a psychologist at John Jay College of Criminal Justice in New York City, told the Times."
http://rt.com/usa/tsa-spent-billion-body-language-937/
We know where leadership by an anti-intellectual "strongman" who scapegoats minorities and likes boisterous rallies goes
Funny, the most interesting part of this story was the mention of his Palm Pilot. /me wonders what model it was.
And to answer your question, yes I still use a Palm Pilot.
It is pitch black. You are likely to be eaten by a grue.
Duress passwords are fine for stuff that the adversary doesn't know about. If three letter agents bust in on you and they have network logs or other surveillance showing what you've been up to then no, the duress password is not going to get you anywhere.
On the other hand, if you had a laptop with some Tienanmen square videos on it that you wanted to bring to China, I think it's perfectly viable approach to simply load up the dummy container with videos of yourself doing a little soft S&M or something, just in case. Really, I would like to hear your explain why you think showing some slightly annoyed (but not suspicious of anything in particular) Chinese officers videos of tanks rolling around in Tienanmen would be safer and preferable to showing them your wife tying you to a bedpost. I would say that the latter approach is at least worth a shot.
Of course, it's usually better to go the extra mile and use headerless solutions in such a way that it would take someone with a fair bit of expertise to notice even the possibility of encrypted material, with no way to conclusively prove whether it's there or not. I mean, if the phrase "please enter your password" appears at any point, you have already done something extremely stupid and lazy. The criminal or cop who has just busted in and is holding the gun to your head almost certainly does not have the knowledge or tools necessary to realize that the device might not be fully decrypted.
If you're worried about getting "killed or worse" by an adversary who is going to first detain you for days while the device is subject to extensive forensic analysis then you're a terrorist and/or you plan on visiting some rather unpleasant countries and doing some fantastically stupid things.
They are supposed to be discouraged from this though, because in practice 'reading body language' very often turns into 'everyone who isn't white is acting shifty.'
I wish Hollywood's influence was limited to the simple-minded "masses." When you get a chance, go ask Justice Scalia about his hero, Jack Bauer.
quiquid id est, timeo puellas et oscula dantes.