[Cryptography] Rubber-hose resistance?

Patrick Chkoreff patrick at rayservers.net
Tue Dec 26 11:15:20 EST 2017


Nico Williams wrote on 12/22/2017 12:26 PM:
> On Thu, Dec 21, 2017 at 06:54:46PM -0500, Patrick Chkoreff wrote:
>> I think you have to physically destroy the device.  It's the only way to
>> be sure.  Carry only a disposable device, as Nico and Jeremy have
>> discussed, such as a Raspberry PI and SD card.  I think you can just
>> destroy the SD card, as I suspect no traces of information will remain
>> on the PI itself, discounting 4 degree Kelvin attacks on RAM.
> 
> Why on Earth would you carry the SBC _powered_ through a border?  Or
> even _at all_?  It's not a smartphone.  If you're not using it, you just
> don't power it.  You don't sleep it.  You don't hibernate it.  You just
> halt it, remove power, and put it away.


Of course I wouldn't carry it powered up.  I merely threw in the "4
degree Kelvin" comment as an afterthought, just in case anyone helpfully
pointed out that some RAM contents might be teased out even after being
powered down for a couple of hours on the way to the airport.  If that's
possible, and if that's your threat model, then you have to destroy the
RAM too.


-- Patrick


More information about the cryptography mailing list