[HN Gopher] HiddenVM - Use any desktop OS without leaving a trace
       ___________________________________________________________________
        
       HiddenVM - Use any desktop OS without leaving a trace
        
       Author : paravirtualized
       Score  : 111 points
       Date   : 2024-03-21 10:16 UTC (12 hours ago)
        
 (HTM) web link (github.com)
 (TXT) w3m dump (github.com)
        
       | paravirtualized wrote:
       | See also: https://github.com/IncognitoIceman/HiddenVM
       | 
       | Unfortunately, it looks like this version is no longer
       | maintained.
       | 
       | "HiddenVM is a futuristic tool powered by KVM designed to combine
       | the powerful amnesic nature of Tails and the impenetrable design
       | of Whonix with the unbreakable strength of Veracrypt."
        
         | abathur wrote:
         | Can you elaborate on why to see it, also, since they look like
         | forks of the same project?
        
           | paravirtualized wrote:
           | I think that the focus of combining it with Whonix is
           | interesting and is what piqued my interest originally. Other
           | than that, nothing.
        
       | NKosmatos wrote:
       | Nice one. I've been using Veracrypt for many years now, after the
       | whole Truecrypt fiasco. Just one friendly advice... always have a
       | decoy partition or decoy OS, otherwise it seems very suspicious
       | to have a disk filled with random data ;-)
        
         | AdmiralAsshat wrote:
         | > otherwise it seems very suspicious to have a disk filled with
         | random data ;-)
         | 
         | You could always argue that the drive was previously "securely
         | erased" and filled w/ random data and/or that it was "securely
         | encrypted" with a key that was then destroyed?
        
           | exe34 wrote:
           | They could still try rubber-hose interrogation techniques
           | until you remember the key...
        
           | GTP wrote:
           | There was an interesting talk at one edition of CCC that
           | boiled down to saying those techniques work only if you have
           | the right to remain silent. Which depends on the country
           | you're in. And I heard that in the USA, even though you have
           | the right to remain silent, they still have the right to put
           | you in jail if you refuse to give out your key.
        
         | 0cf8612b2e1e wrote:
         | I am less convinced. If the GMan nabs you, sees you are using a
         | tool which heavily advertises a hidden partition, and
         | coincidentally your drive has a large unused block of random
         | data - they are unlikely to be fooled.
        
           | JohnFen wrote:
           | If your security concerns are about governmental intrusions,
           | then you have a security need that no single tool can resolve
           | anyway. You need to address overall behavior and habits,
           | which are likely to include things like not keeping sensitive
           | data on machines that can be easily accessed regardless of
           | the use of encryption or obfuscation.
        
       | ranger_danger wrote:
       | > complicated apt-get update wizardry that achieves our
       | VirtualBox-installing breakthrough.
       | 
       | yikes.
        
       | pvg wrote:
       | A big Show HN thread from four years ago:
       | 
       | https://news.ycombinator.com/item?id=22492343
        
       | tgkudelski wrote:
       | You might also want to have a look at https://shufflecake.net/
       | 
       | The current state is far from usable, but the final goal would be
       | to have multiple nested "hidden OSes" that can be booted and
       | managed concurrently, depending on the provided password.
        
       | shallmn wrote:
       | I'd be more concerned about what they could plant on my machine
       | versus what they find on it.
        
       | galdosdi wrote:
       | > Imagine you're entering a country at the airport. The border
       | agents seize your laptop and force you to unlock it
       | 
       | If this concerned me I would just wipe the drive and/or factory
       | reset the device before travelling, and restore it later, rather
       | than try to experimentally figure out what games I can and can't
       | play with the customs authorities.
        
         | wizzwizz4 wrote:
         | This is the approach that people I trust recommend. Some go
         | further: not only should you not take sensitive data across
         | borders physically, you shouldn't rely on your devices (or
         | undeveloped film, for that matter) not getting wiped at the
         | airport.
        
           | nxobject wrote:
           | FWIW, I have a colleague who worked at an office
           | collaboration software firm that applied a "no company tech
           | into China" to _everyone_.
        
       | ghostly_s wrote:
       | I'm not following what this gives you that Veracrypt's inbuilt
       | hidden+decoy OS feature doesn't already? It seems they require
       | you to manually set up a veracrypt hidden partition for anything
       | to be "hidden" anyway. How is booting your encrypted partition in
       | a VM within Tails more secure than booting it directly?
        
         | paravirtualized wrote:
         | > How is booting your encrypted partition in a VM within Tails
         | more secure than booting it directly?
         | 
         | There will be no proof of an operating system existing at all,
         | just random data. If you use VeraCrypt along with a hidden
         | partition normally, you would still have the VeraCrypt
         | bootloader or an apparent Windows installation on the drive.
        
           | _boffin_ wrote:
           | After truecrypt 7.1a (I think), the canary vanished. After
           | that, didn't it become veracrypt? Did they ever add a canary
           | or has there been research in showing it's not backdoored?
        
             | rOOb85 wrote:
             | While it's never been officially proven, there is a
             | interesting story behind truecrypt. It was allegedly
             | written by one guy (Paul Le Rou) who was a programmer
             | turned cartel boss/gun/drug runner.
             | 
             | But back to your question, truecrypt was professionally
             | audited and deemed "secure", some issues were found but
             | none that were back doors or significant. Shortly
             | after(might have even been during) the audit truecrypt
             | deleted all old versions and posted a weird message telling
             | people to use bitlocker.
             | 
             | After some time veracrypt picked up the torch and has
             | continued developing what was truecrypt.
        
       | Klasiaster wrote:
       | "The laptop probably has a HiddenVM. Drug and hit the person with
       | this 5$ wrench until we get access."
       | 
       | https://xkcd.com/538/
        
       ___________________________________________________________________
       (page generated 2024-03-21 23:01 UTC)