[HN Gopher] HiddenVM - Use any desktop OS without leaving a trace
___________________________________________________________________
HiddenVM - Use any desktop OS without leaving a trace
Author : paravirtualized
Score : 111 points
Date : 2024-03-21 10:16 UTC (12 hours ago)
(HTM) web link (github.com)
(TXT) w3m dump (github.com)
| paravirtualized wrote:
| See also: https://github.com/IncognitoIceman/HiddenVM
|
| Unfortunately, it looks like this version is no longer
| maintained.
|
| "HiddenVM is a futuristic tool powered by KVM designed to combine
| the powerful amnesic nature of Tails and the impenetrable design
| of Whonix with the unbreakable strength of Veracrypt."
| abathur wrote:
| Can you elaborate on why to see it, also, since they look like
| forks of the same project?
| paravirtualized wrote:
| I think that the focus of combining it with Whonix is
| interesting and is what piqued my interest originally. Other
| than that, nothing.
| NKosmatos wrote:
| Nice one. I've been using Veracrypt for many years now, after the
| whole Truecrypt fiasco. Just one friendly advice... always have a
| decoy partition or decoy OS, otherwise it seems very suspicious
| to have a disk filled with random data ;-)
| AdmiralAsshat wrote:
| > otherwise it seems very suspicious to have a disk filled with
| random data ;-)
|
| You could always argue that the drive was previously "securely
| erased" and filled w/ random data and/or that it was "securely
| encrypted" with a key that was then destroyed?
| exe34 wrote:
| They could still try rubber-hose interrogation techniques
| until you remember the key...
| GTP wrote:
| There was an interesting talk at one edition of CCC that
| boiled down to saying those techniques work only if you have
| the right to remain silent. Which depends on the country
| you're in. And I heard that in the USA, even though you have
| the right to remain silent, they still have the right to put
| you in jail if you refuse to give out your key.
| 0cf8612b2e1e wrote:
| I am less convinced. If the GMan nabs you, sees you are using a
| tool which heavily advertises a hidden partition, and
| coincidentally your drive has a large unused block of random
| data - they are unlikely to be fooled.
| JohnFen wrote:
| If your security concerns are about governmental intrusions,
| then you have a security need that no single tool can resolve
| anyway. You need to address overall behavior and habits,
| which are likely to include things like not keeping sensitive
| data on machines that can be easily accessed regardless of
| the use of encryption or obfuscation.
| ranger_danger wrote:
| > complicated apt-get update wizardry that achieves our
| VirtualBox-installing breakthrough.
|
| yikes.
| pvg wrote:
| A big Show HN thread from four years ago:
|
| https://news.ycombinator.com/item?id=22492343
| tgkudelski wrote:
| You might also want to have a look at https://shufflecake.net/
|
| The current state is far from usable, but the final goal would be
| to have multiple nested "hidden OSes" that can be booted and
| managed concurrently, depending on the provided password.
| shallmn wrote:
| I'd be more concerned about what they could plant on my machine
| versus what they find on it.
| galdosdi wrote:
| > Imagine you're entering a country at the airport. The border
| agents seize your laptop and force you to unlock it
|
| If this concerned me I would just wipe the drive and/or factory
| reset the device before travelling, and restore it later, rather
| than try to experimentally figure out what games I can and can't
| play with the customs authorities.
| wizzwizz4 wrote:
| This is the approach that people I trust recommend. Some go
| further: not only should you not take sensitive data across
| borders physically, you shouldn't rely on your devices (or
| undeveloped film, for that matter) not getting wiped at the
| airport.
| nxobject wrote:
| FWIW, I have a colleague who worked at an office
| collaboration software firm that applied a "no company tech
| into China" to _everyone_.
| ghostly_s wrote:
| I'm not following what this gives you that Veracrypt's inbuilt
| hidden+decoy OS feature doesn't already? It seems they require
| you to manually set up a veracrypt hidden partition for anything
| to be "hidden" anyway. How is booting your encrypted partition in
| a VM within Tails more secure than booting it directly?
| paravirtualized wrote:
| > How is booting your encrypted partition in a VM within Tails
| more secure than booting it directly?
|
| There will be no proof of an operating system existing at all,
| just random data. If you use VeraCrypt along with a hidden
| partition normally, you would still have the VeraCrypt
| bootloader or an apparent Windows installation on the drive.
| _boffin_ wrote:
| After truecrypt 7.1a (I think), the canary vanished. After
| that, didn't it become veracrypt? Did they ever add a canary
| or has there been research in showing it's not backdoored?
| rOOb85 wrote:
| While it's never been officially proven, there is a
| interesting story behind truecrypt. It was allegedly
| written by one guy (Paul Le Rou) who was a programmer
| turned cartel boss/gun/drug runner.
|
| But back to your question, truecrypt was professionally
| audited and deemed "secure", some issues were found but
| none that were back doors or significant. Shortly
| after(might have even been during) the audit truecrypt
| deleted all old versions and posted a weird message telling
| people to use bitlocker.
|
| After some time veracrypt picked up the torch and has
| continued developing what was truecrypt.
| Klasiaster wrote:
| "The laptop probably has a HiddenVM. Drug and hit the person with
| this 5$ wrench until we get access."
|
| https://xkcd.com/538/
___________________________________________________________________
(page generated 2024-03-21 23:01 UTC)