Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The whole point of login_duress is that you say "there's nothing you want on this machine" and give them the duress credential knowing that the thing they want will be deleted. Once it's deleted, you can't break and give it to them.


Yeah, I think this is where the meat is. csydas’s points have merit. Namely: 1. torturers will keep torturing until they get what they want, and 2. victims will eventually tell the torturer whatever the torturer wants to hear in order to stop the torturing. However, if you can employ your duress code, then you might be able to defeat the torturer (by preventing them from gaining access — they could still very well kill you) or by alerting the outside world about the duress scenario.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: