Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hopefully stress means that you won't be able to do it properly anyway, which means coercion is useless.

The real problem is the device stores the password, so the real defence is the tamperproof-ness of the device, not whether you can be tricked or coerced into outputting the sequence.



Yeah, the research paper notes that they need to implement 'coercion detection'. From page 12:

"Since our aim is to prevent users from effectively transmitting the ability to authenticate to others, there remains an attack where an adversary coerces a user to authenticate while they are under ad- versary control. It is possible to reduce the effective- ness of this technique if the system could detect if the user is under duress. Some behaviors such as timed re- sponses to stimuli may detectably change when the user is under duress."


That's more of a bug than a feature when you're the one under duress.


What if you're running late to do something, or you are anxious to get access to the data behind the authentication for some other non-duress reason? Duress-detection will be tricky (but I look forward to them doing it!).


I would personally prefer to have my password at any time, rather than have to get in the "zone" to authenticate into my computer.


The problem with using coercion is, the people using it never believe it's useless regardless of what's coming out of your mouth.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: