[Cryptography] stegophone

John Denker jsd at av8n.com
Thu Mar 30 17:59:34 EDT 2017


> * Michael Marking:
> 
>> Sadly, the hardware is a big problem. No one as far as I know
>> makes phones with a separate, isolated, unlocked computer side.

On 03/30/2017 02:14 PM, Florian Weimer replied:

> I think most smartphones have this capability (with multiple 
> implementations within the same phone, actually), but the device 
> makers do not use it in the way you want.

The blackphone offers, as an advertised feature, the ability to
switch from one "space" to another.  This is advertised as a way
to keep your work life separate from your personal life:
  https://www.silentcircle.com/products-and-solutions/devices/silent-os/#spaces

So it seems some existing platforms do what is needed, or pretty
close.  This includes the hardware and the open-source OS.


On 03/30/2017 01:00 AM, Dave Howe wrote:

>> Presume you can back up everything to an
>> encrypted OTG device, then before you enter the airport remove the
>> device, reinit the phone as blank/empty with no password at all, and put
>> the OTG in your wallet or something.  If asked, say you were issued a
>> clean, unused device for the trip because it's Company Policy not to
>> carry customer data though customs.
>> 
>> Once at your hotel or whatever, reinstall the app from the internet and
>> restore the phone from the OTG. should be easy enough to make the OTG
>> look like an unformatted micro sd card in case they demand to go though
>> your wallet too.


That's fine if you know you are going to the airport.  But here's
a riddle:

Q:  What's the difference between the Border Patrol and the Boy Scouts?

A:  The Boy Scouts have adult supervision.

I mention this because although not all ICE agents are alike, some of
them seem to think they have unlimited authority in their self-defined
"border zone" extending 100 miles from any land or sea border of the US.
They have been repeatedly slapped down by the courts, but they don't
care ... and in the last couple of months they have grown markedly
bolder.  Note that 2/3rds of the US population lives within this 100
mile zone.

Therefore it is an essential part of the stegophone specification that
it can enter "sanitized" mode at any moment, even under duress, with
no detectable action required of the user.  I'm sure the situation in
other parts of the world is much, much worse.



More information about the cryptography mailing list