Hacker Newsnew | past | comments | ask | show | jobs | submit | LWIRVoltage's commentslogin

( roughly copying my post from another thread)

A few things:

#1. The download and restore backup method would work for people in general- except it doesn't capture what people would need. Exmaple: I have some thermal cameras that rely on old 32 bit apps that do not run on anything android 12 onwards- If i wipe those old phones, and restore- the apps often wanted to reach out to a server for initial activation- they would fail upon reinstall and i'd be out of the apps that are required to control my cameras and related equipment,which is worth thousands and thousands and thousands. And it'd be all dead weight and rendered useless.

(and competitors today do not compete- for example try finding a 640*480 30 hz or better form factor thermal camera that attaches to phones - they dont exist anymore)

\The solution is full imaging- but there isnt a way to fully image phones and restore backups today. There used to be it seems- but not really with the latest stuff at the time of this post

.

On another note:Veracrypt- The weakness of truecrypt and veracrypt, the hidden OS option only worked if you converted your computer to MBR, which means you can't have a hard drive too large. Making a UEFI hidden OS has not been done yet.

And the Hidden Volume option- isn't 'as' useful, and of course, your OS might make a copy and put it somewhere, you have to be careful. As a example: Any time I open a file, using the software tool Everything to search and confirm this- you can easily see Windows makes copies and temp files and whatnot in randomly named locations- that's the sort of behavior that would screw people over

We need fully image-backup capable Phones. I mean fully. Not just backing up some apps- as this refuses to backup apps you have that are no longer on app stores, or that Play Protect doesn't like, etc.

Next- Plausible deniability is a way forward- but you need multiple profiles, that are cryptographically indistinguishable, along with the phone being hardened so GreyKey /Cellebrite won't be able to exploit a way in. This needs to be built this way from the ground up ideally, eventually.

There has been research about making devices that treat all block space the same way so you can't tell if someone has 1, or 50 profiles or partitions, etc- and even stuff that overlaps. Often it needs to be fixed size partitions, but it is apparently NOT impossible to create. I am aware of Shufflecake attempting to make a solution for Linux, and yes, a Hidden OS option that is forensic- invisible.

But nothing has come out - and especially, for phones.

I hope Graphene OS or another group, eventually works on this for phones. I do wonder if it would require a Linux phone, or something built from the ground up rather than current phone architecture.

It would be nice to see the day where, if you travel to a hostile country, you can tell them you have just one profile, and if they ask, you could theoretically mention a 2nd, and then show it- but you might have 3 more - and they'd all be immune to forensic inspection if the system is built right.(Yes, there's often issues you have to be careful of ,like setting this up so you dont destroy data when in other profiles,)

This is how you solve this problem in the long run-make computing devices impossible to analyze, but standard.


A few things:

#1. The download and restore backup method would work- except it doesn't capture what people would need. Exmaple: I have some thermal cameras that rely on old 32 bit apps that do not run on anything android 12 onwards- If i wipe those old phones, and restore- the apps often wanted to reach out to a server for initial activation- they would fail upon reinstall and i'd be out of the apps that are required to control my cameras and related equipment,which is worth thousands and thousands and thousands. And it'd be all dead weight and rendered useless.

(and competitors today do not compete- for example try finding a 640*480 30 hz or better form factor thermal camera that attaches to phones - they dont exist anymore)

\The solution is imaging- but there isnt a way to fully image phones and restore backups today. There used to be it seems- but not really with the latest.

Veracrypt- The weakness of truecrypt and veracrypt, the hidden OS option only worked if you converted your computer to MBR, which means you can't have a hard drive too large. Making a UEFI hidden OS has not been done yet.

I am aware of Shufflecake attempting to make a solution.

And the Hidden Volume option- isn't 'as' useful, and of course, your OS might make a copy and put it somewhere, you have to be careful. Any time I open a file, using the software tool Everything to search and confirm this- you can easily see Windows makes copies and temp files and whatnot in randomly named locations- that's the sort of behavior that would screw people over

We need fully image-backup capable Phones. I mean fully. Not just backing up some apps- as this refuses to backup apps you have that are no longer on app stores, or that Play Protect doesn't like, etc.

Next- Plausible deniability is a way forward- but you need multiple profiles, that are cryptographically indistinguishable, along with the phone being hardened so GreyKey /Cellebrite won't be able to exploit a way in. This needs to be built this way from the ground up ideally, eventually.

There has been research about making devices that treat all block space the same way so you can't tell if someone has 1, or 50 profiles or partitions, etc- and even stuff that overlaps. But nothing has come out - and especially, for phones.

After all, if you travel to a hostile country, you can tell them you have just one profile, and if they ask, you could theoretically mention a 2nd, and then show it- but you might have 3 more - and they'd all be immune to forensic inspection if the system is built right.(Yes, there's often issues you have to be careful of ,like setting this up so you dont destroy data when in other profiles,)

This is how you solve this problem -make computing devices impossible to analyze


Location: Central Florida region

Open to Remote: Yes

Willing to Relocate: Yes

Technologies: C, Java, Python, RHEL, Operations, Bash, Windows Server, Vmware, VirtualBox ,AIX, , RHEL, Debian ,Docker

Where I come from: I've worked for NASA , as a System Administrator and Operational Test Conductor,helping to run field ops as well as maintain security , provision and administer their launch systems.

I've helped run operations involving multiple sites and multiple groups around the Country to that involved testing aspects of space hardware ,software involving multiple various teams and groups.

I currently am part of the requirement testing process for NASA's Launch Control Software and help design tests,and ensure the software is up to spec , and validate requirements for Artemis 2 and 3 actually putting the software through it's paces.

I'm a team-orientated, friendly, detail focused technologist with a eye towards expanding and delving more into the development side of tech, leveraging my experience in administration and operations over, and getting a little deeper to working with the innards that make things tick and being able to tweak them,.

I can be reached at lwir.voltage385@slmails dot com


.... This deserves it's own posts , on HN, just for awareness-

Aside from https://web.archive.org/web/20250914062843/https://portswigg... , there haven't been really many goes at going for plausible deniability with modern systems, and I see the segment about a Hidden OS feature in work as well.

Hoping this succeeds. Funny, eventually Shufflecake, after it gets fully capable on Linux, might have to look at making versions for Windows and Mac


What sucks about this, is due to implementation,Windows is the only way to achieve some stuff in Veracrypt. For example: doing full system partition encryption, and the Hidden OS install that only Veracrypt can do- requires Windows with the computer set to MBR rather than UEFU. I had hoped we'd see more of the plausible deniability tech at the OS level

But aside from one or two experimental attempts, also presented at BlackHat https://web.archive.org/web/20250914062843/https://portswigg...

- the consumer has nearly lost access to high end plausible deniability


> Windows is the only way to achieve some stuff in Veracrypt

On the other hand, if you get rid of Windows you don't even need Veracrypt.


Okay, this is neat! A true mesh networking bluetooth app- The other one that's notable, Briar is super impressive - but i think it doesn't actually have proper mesh capability due to difficulties with how devices handle things

(See: https://old.reddit.com/r/Briar/comments/gxiffy/what_exactly_...

https://news.ycombinator.com/item?id=43363031 }

Anyway, -Question: I take it Murmur is end to end encrypted fully? Also, just curious if this is open source?

This could become SUPER useful- having a actual mesh networking Bluetooth app , if it's open source/E2EE!


It's AES128 encrypted with a key derived from the group password.


I'll try this app because Briar never worked between any of my devices (all Androids)


Location: Central Florida region

Open to Remote: Yes

Willing to Relocate: Yes

Technologies: C, Java, Python, RHEL, Operations, Bash, Windows Server, Vmware, VirtualBox ,AIX, , RHEL, Debian ,Docker

Where I come from: I've worked for NASA , as a System Administrator and Operational Test Conductor,helping to run field ops as well as maintain security , provision and administer their launch systems.

I've helped run operations involving multiple sites and multiple groups around the Country to that involved testing aspects of space hardware ,software involving multiple various teams and groups.

I currently am part of the requirement testing process for NASA's Launch Control Software and help design tests,and ensure the software is up to spec , and validate requirements for Artemis 2 and 3 actually putting the software through it's paces.

I'm a team-orientated, friendly, detail focused technologist with a eye towards expanding and delving more into the development side of tech, leveraging my experience in administration and operations over, and getting a little deeper to working with the innards that make things tick and being able to tweak them,.

Stripped version of my resume at https://ibb.co/tpqYm7nF I can be reached at lwir.voltage385@slmails dot com


... These sorts of patterns do not help at all, and will hurt those who have critical need for apps without a lot of users.

Speaking as somebody, who owns some mid-grade thermal cameras that stopped production in the past few years after a decade run, that depended on and are solely controlled and run on apps that were removed from the app store or no longer can run on modern phones because they are in 32-bit format ; this sort of thing would further punish that type of software and only speed up its demise.

When you spend thousands and thousands and thousands and of dollars and resources into getting unique capabilities like that, that can only be controlled through Android apps often, and is the only way to get that capability for some (this will apply to multiple and I imagine with niche capabilities that only have one or two methods of Access)

- this hurts a lot of opportunity, and this type of dark anti-pattern is far too blunt


They don't give a fuck. Just like Microsoft doesn't give a fuck about casual users running older software, or Apple doesn't give a fuck about power users who don't need their hands held through everything on their goddamn computers.

All these gigafuck companies have a minimum viable user in mind: someone who has disposable income, free time, and wants to use their phone to shop for shit or endlessy scroll on whichever social they happen to like most, and that's what their products are designed to do. Everything else is ancillary.

Spoken as someone who works on a niche app for both platforms that works with hardware we make: we get NO support. Arbitrary system changes fuck up our app constantly, without notice, and we have no recourse but to fix it ASAP and tell people to not update.


All the manufacturer has to do is publish an APK on their website. If all apps did this, Google would have no power. It's very easy for a volunteer to host the APK somewhere in an archiving effort. Much easier that it ever has been on iOS.


Yeah, but if you're a new app, Google doesn't let you have your APK signing keys, so you either have to go through Google to get an APK you can publish (with all the resources), or users can't cross-upgrade because on phone storage is tied to the signing key.


What!? That is an evil move. No wonder I see so much negative sentiment around big G.


A Veracrypt style hidden OS profile that is forensically invisible would be a better option - This would allow one to enter a password and give another "profile" or OS- that unlike current alternate profile stuff- would be solid against Cellebrite and GreyKey snooping into the device, and it'd be impossible to tell there was a hidden user/etc on it


Does obtaining Global Entry minimize the chance of them deciding to harass a citizen crossing the border, I wonder? It is at the cost of your biometric - but data on your devices might be worth more, and as I note elsewhere in this thread, you can image a computer and back it up fully, but not a phone without some data loss, unfortunately. [ TWRP possibly can do it right perhaps, but it requires unlocking the bootloader (which wipes the phone), and once bootloader is unlocked, it's more vulnerable to Cellebrite and company, to my understanding, ]

seeing the latest (leaked?) Cellebrite info from 2024 Summer- BFU State[Before First Unlock state] after posting on, modernimoPuxelsiPhones on the latest OS, and graphene devices see moto be the hardest to get into.

Anyway- , with computers - this was a solved problem from a technical standpoint- Yes I'm talking Truecrypt then, and today Veracrypt. The Hidden Container feature is impressive- but the Hidden OS feature allows for a truly hidden OS behind the scenes that can't be found at all. However, there's a unfortunate weakness that makes this hard to use today- it's limited to MBR , not UEFI [GPT]systems- so unless you like your computer not being able to have more than 2 Tb - and only 4 partitions (so good luck If you do a lot of stuff from dualbooting to other whatnot) We need a Veracrypt Hidden OS equivalent for UEFI systems that's truly undetectable.(That also will work for Linux and maybemeMac not just Windows as Veracrypt currently does - you can only make the Hidden Volumes on the non Windows versions of VC) There was one project to do it - and there were articles and a black hat presentation on 'Russian Doll Steganogrpahy" for a OS- but it didn't go anywhere from what I can tell, and everyone is now wide open .... Unless you have a MBR system. I also think I've heard UEFI is more easily secured than MBR in general and for the foreseeable future...

https://portswigger.net/daily-swig/russian-doll-steganograph...

https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Schaub-Perfectl...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: