Daniel McNaughton

1.2K posts

Daniel McNaughton

Daniel McNaughton

@mcnaughton42

Katılım Kasım 2024
69 Takip Edilen50 Takipçiler
Daniel McNaughton
Daniel McNaughton@mcnaughton42·
@GrapheneOS Would you consider adding a sort of 'self wipe timer' config? Where I can set it on a 2-hour delay and if I fail to enter my unlock pin it'll trigger the same mechanism as the duress pin? That might be a cleaner legal option as an end user vs giving a cop a duress pin.
English
0
0
1
326
GrapheneOS
GrapheneOS@GrapheneOS·
x.com/niemerg/status… This proposal wouldn't hide that a wipe occurred and would help adversaries exploit and recover data from the device. It isn't a new idea and people have proposed variations of this hundreds of time for years. These proposals wouldn't hold up against widely available forensic software. Giving an attacker access to a decoy profile would make it far easier for them to exploit the device. Without a shut down or reboot, a device was previously in After First Unlock state would be very vulnerable to having data extracted. GrapheneOS has strong protection against data extraction without depending on a duress PIN/password. The default enabled protections combined with a strong passphrase and 2nd factor fingerprint PIN would have provided fantastic protection for the data on the device. Reducing the device auto-reboot timer would be even better. The secure element would have protected the data with only a random 6 digit PIN instead of a passphrase in practice too. All of our features are designed to work against adversaries aware of GrapheneOS. Our duress PIN/password is no different. Adversaries aware of GrapheneOS face a dilemma about whether a PIN/password provided by the user is going to unlock the device or wipe it. It wasn't designed around being a secret resulting in an unpleasant surprise for an adversary. We also plan to provide it as part of secure element rate limiting on future devices built to run GrapheneOS to prevent bypassing it with an OS exploit. Triggering our duress PIN/password feature wipes both hardware keystores, the secure element as a whole and disk encryption metadata. Each of these 3 steps is enough on their own to reliably wipe material needed to obtain the key encryption keys for disk encryption. It happens nearly instantly and it wouldn't be secure if it took a bunch of time or depended on actually erasing any of the encrypted data. Shutting down the device triggers clearing sensitive data from RAM and registers to complete the process. It's necessary to clear a lot of sensitive data from memory and registers including decrypted encryption keys in TEE memory. Giving an adversary access to a profile on the device instead of shutting down or rebooting would be very problematic. It would give them an immense amount of attack surface for exploiting the device to recover sensitive user data. If the Owner user is in After First Unlock state, the adversary has given massive attack surface for exploiting the device to obtain all of the data from the main user. It would be the extreme opposite of the attack surface reduction and exploit protections provided by GrapheneOS. GrapheneOS and apps running on it could continue to function indefinitely after the key derivation material is wiped. It already has disk encryption keys loaded into Trusted Execution Environment memory and is using those for inline disk encryption via wrapped keys. Only functionality depending on hardware keys would be broken. If there were profiles in After First Unlock state those would still be available. An attacker exploiting the device would recover the same data as before wiping the key encryption keys. Forensic data extraction companies have access to GrapheneOS and we don't have access to their software. We cannot rely on security through obscurity or knowing how their software works including which vulnerabilities they exploit. Fooling widely available forensic software into believing a decoy profile is the Owner user isn't feasible. It would need to provide a fully functional Android Debug Bridge (ADB) environment which is completely impractical. People should consider the fact that they likely haven't thought about this nearly as much as us. There are good reasons for why we designed this feature the way we did and it's working as intended in the real world. The feature becoming widely known about is a requirement for it to work as intended by creating a dilemma for adversaries. The main thing we need now is secure element support for it which we can get implemented for future devices as part of our Motorola Mobility partnership and future OEM partnerships.
Allan@niemerg

“duress” password is incorrectly designed—it shouldn’t be apparent to the attacker that it was triggered and should instead open to an innocuous and data free home screen while nuking everything in the background

English
95
300
3.7K
239.2K
Daniel McNaughton
Daniel McNaughton@mcnaughton42·
@trash196053474 @KC_Invests This is my read, they're waiting till it's close enough to the election both in the US and Israel (October). Best time to put the political squeeze via oil prices and desal plants is the week or two leading up to Israeli Knesset election. I hope I'm wrong and this all ends soon.
English
0
0
3
21
Oilfield Trash1960
Oilfield Trash1960@trash196053474·
@KC_Invests My concern is that they are waiting about eight weeks out to do something Trump cannot fix by the election.
English
2
0
4
112
KC Invests
KC Invests@KC_Invests·
If Iran knows that oil prices are the breaking point for the US admin, due to rates, bond yields, etc. Why are they allowing the oil prices to be so suppressed by jawboning and social media posts? Their focus should be on increasing oil beyond an imaginable level
English
69
2
139
11.7K
🏴‍☠️
🏴‍☠️@calvinfroedge·
If oil is down 7% again tomorrow I'm flying to West Texas
English
49
21
834
39.4K
Mashtery
Mashtery@MashteryYT·
@tenyearsnow Mark Kelly seems like a cool guy. I wish he would run for office, but I honestly don’t think a Democrat could win statewide in Arizona. I could see him returning to NASA in a few years.
English
1
0
7
179
Daniel McNaughton
Daniel McNaughton@mcnaughton42·
@Le_happy_can @rekdt Use data backups or personal sync tools to push your data off the device and onto a secure remote storage system. Whether that's a NAS or an S3 bucket. Mobile phones are not durable storage systems for critical data, too much risk of total loss or damage.
English
0
0
1
266
Le happy can
Le happy can@Le_happy_can·
@rekdt That also risks a random person wiping your phone, or someone who hates you. In my freshman year of highschool, kids would decide to guess my pin for absolutely no reason
English
3
0
23
1.4K
rekdt
rekdt@rekdt·
GrapheneOS should really add a time wipe feature if a pin is not entered within a defined amount of time, the device is wiped Hypothetically this takes the burden of allegedly destroying evidence away from the defendant
English
114
118
3.7K
128.8K
Daniel McNaughton
Daniel McNaughton@mcnaughton42·
@EWess92 They're fundamentally different elections. The governor's primary election happened already. This special nomination is happening later this month for the November election.
English
3
0
1
3.4K
Daniel McNaughton
Daniel McNaughton@mcnaughton42·
@katagious2 @ediblesticker @JamesSurowiecki @5suomynona It's pretty simple, this is for a different election. He filed to run on the primary election earlier this year for governor, this is an entirely different election since it's a different election day. He never filed for the November election so nothing stopping him.
English
0
0
0
47
Kat
Kat@katagious2·
@ediblesticker @JamesSurowiecki @5suomynona It doesn't seperate the two in the law, but that may be the argument they attempt. He's filed as a candidate twice. "A person may not file as a candidate for more than one federal, state or county office at any election." 21-A M.R.S. §331(3)(A)
English
7
0
6
987
Kat
Kat@katagious2·
GOP Rep. James White (Maine) points out that Troy Jackson may not legally be eligible to be the nominee for Senate.
Kat tweet mediaKat tweet media
English
111
242
1.5K
730.6K
Daniel McNaughton
Daniel McNaughton@mcnaughton42·
@IkeNotabot @realtimsharp Most wireless protocols like WiFi and Bluetooth use static identifiers they broadcast in the clear to connect to other devices. Think of it as walking around always shouting your social security number. These scanners pick that up and build a database to track you.
English
1
2
4
116
Desire Is Mimetic
Desire Is Mimetic@IkeNotabot·
Someone please help me understand more. When these devices identifies a key finder, phone, headphones, etc. are they finding "generic" signals of technologies commonly used in those devices... or is it more specific?Can it determine that a person is using headphones vs other bluetooth devices? Brand? Make/model? A single specific device?
English
6
2
3
1.6K
Tim Sharp 🍊 🍊 🇺🇸
Tim Sharp 🍊 🍊 🇺🇸@realtimsharp·
THIS image is an image of Signal Trace from a company called Leonardo. SignalTrace is not separate from license plate reader surveillance, it is built to work with license plate readers. By pairing plate reads with signals from phones, watches, headphones, vehicles, key finders, and other electronics, it can create an “electronic fingerprint” tied to a vehicle or person and continue identifying them even when a plate is hidden, changed, missing, or unreadable. That means a Flock, Motorola, Axon network can become a people tracking network capable of revealing where someone travels, who they travel with, and which homes, workplaces, protests, churches, medical offices, or political events they visit. 6 degrees of separation track EVERYONE. In the wrong hands, this is not just traffic enforcement, it is the infrastructure for warrantless mass surveillance, guilt by association, and a permanent record of innocent people’s movements. There needs to be an ordinance with steep fines with criminal penalties for adding devices onto public power poles or poles without labeling. Right now, any company, private or public can come in and put sniffing devices on anything and get away with it. They can track the Mayor, track The police Chief, sports figures or other dignitaries that come to town, including all of us.
Tim Sharp 🍊 🍊 🇺🇸 tweet media
English
289
3.2K
7.4K
282.9K
Daniel McNaughton
Daniel McNaughton@mcnaughton42·
@ericlaw Offboarding a BYOD device should involve a reinstall of the OS. Just better for both parties.
English
0
0
5
4.5K
Daniel McNaughton
Daniel McNaughton@mcnaughton42·
@ckumral_ @jealkeja The guy who used the LLM to solve it was a mathematician. Not a random non-expert asking ChatGPT to "solve quantum mechanics."
English
0
0
138
1.5K
Daniel McNaughton
Daniel McNaughton@mcnaughton42·
@Zoya_ki_batein Plenty of people with illnesses like cancer and Huntingtons who are serving lengthy sentences for drug possession, but this actual predator and danger to society basically walks free. Insanity.
English
0
0
5
1K
Zoya🕊️
Zoya🕊️@Zoya_ki_batein·
A 36 year old man named Shaun Mckenna who violently raped a 13-year-old girl at a Highlands campsite, has been spared jail due to his life-limiting medical condition. He was diagnosed with the degenerative condition Huntington's Disease in 2022. The 13-year-old child was on holiday with her family in 2020. She was alone when he came in and pinned her down, lay on top of her, and raped her. The girl tried to fight him off, but he told her, "to stop crying and screaming as well as to shut up.” He said if she told anyone, “he would do it worse." McKenna also committed sex crimes against two other children before that. The judge said each offence on its own was a reason to go to jail, but did not feel prison would meet McKenna's specialised needs. He will instead be supervised at his care home in Kinross, where he is not allowed to leave on his own. This is beyond fucked up. Every man who rapes a child deserves to spend his life in prison
English
941
3.8K
26.4K
1.7M
Benny M.
Benny M.@ziotimscabin·
@JakeSherman You cover the House, admittedly, but Arizona currently has a Dem governor and two Dem senators
English
5
0
10
1.3K
Bobby
Bobby@trustless_nyc·
@calvinfroedge Is this intentional sabotage by the admin or what? Trying to see the silver lining
English
1
0
0
242
Oliya Scootercaster 🛴
Oliya Scootercaster 🛴@ScooterCasterNY·
Not sure who's press car keeps parking on top of the blood stain that's part of the vigil in Biddeford
Oliya Scootercaster 🛴 tweet media
English
53
39
513
37K
Milo Zoey 🪷
Milo Zoey 🪷@2nd_zoeyy·
I need to know who here is still an actual human. Say something human.
English
13.2K
651
25.4K
1.1M
Amazon MGM Studios
Amazon MGM Studios@AmazonMGMStudio·
Drop a TV show character that is your idol.
English
489
11
82
71.3K
Mikey Dem
Mikey Dem@MichaelDavLange·
@nikicaga I think Trump’s (tenth % baked) plan is to try to get enough dem senators removed from office, and replaced by republicans who would vote to get rid of the filibuster to pass the SAVE Act?
English
5
0
118
8.6K
stupid tech takes
stupid tech takes@stupidtechtakes·
"E2E encrypted via HTTPS"
CoolKoon@coolkoon

@stupidtechtakes You have no idea what you're talking about. Yes, sending password to the server (E2E encrypted via HTTPS) in plaintext IS the norm.

English
25
15
1.3K
82.4K
Daniel McNaughton
Daniel McNaughton@mcnaughton42·
@HunterEKozak This sort of thing was common as hell in the 90s/00s. Kids read a ton of books. Sad to see how a 300 page book is seen as crazy for a kid to read now.
English
0
1
19
361
Hunter Kozak 🧦🇺🇦🏳️‍🌈
I read the seventh Harry Potter cover to cover the same day I got it. I was 11. This isn’t to say I’m some savant. Kids are fully able to grasp and read and think on their own if you don’t clip their wings.
English
19
240
4.8K
49.2K