this post was submitted on 11 Aug 2026
216 points (98.6% liked)

Technology

87079 readers
3339 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] melsaskca@lemmy.ca 1 points 5 hours ago

Even pre-tech there was lots of bad shit you could do (sugar in the gas tank), but we didn't (for the most part). Now bad shit is the norm and if you don't buy into my product I will fuck you up, motherfucker!! Def not Marketing 101.

[–] Passerby6497@lemmy.world 5 points 17 hours ago (1 children)

I'll stick to a Veracrypt full disk encryption with a hidden partition. All the benefits of a duress password, none of the data deletion that gets you V&

[–] digital_alchemist@discuss.tchncs.de 3 points 15 hours ago (1 children)

PSA: Veracrypt recommends against using hidden volumes on USB flash drives (source)

[–] 3abas@lemmy.world 5 points 5 hours ago

They don't recommend against it... It's a detailed guideline on doing it successfully.

[–] fubarx@lemmy.world 17 points 1 day ago (1 children)

If he had only spent an extra $0.50 and added a Microchip 608c (https://www.microchip.com/en-us/product/atecc608c) to the design, then you wouldn't have to deal with cleartext passwords in files. Instead, you could have elliptic-curve, asymmetric public-key encryption.

[–] Mister_Hangman@lemmy.world 7 points 21 hours ago

So you make a competitor then and I’ll buy it

[–] FrowingFostek@lemmy.world 49 points 1 day ago (2 children)

Nifty. I couldn't see a practical use for myself but, it's cool none the less.

[–] unexposedhazard@discuss.tchncs.de 62 points 1 day ago (1 children)

Very useful for getting any sort of private data through an airport that does not respect privacy. For example any US airport...

[–] timewarp@lemmy.world 4 points 1 day ago (5 children)

No it isn't. It will be treated like any other drive where encryption is nothing new. In fact, to look for a text file and then make something accessible means it is likely much easier to detect that something is off about it than regular encryption that just looks like random data. Whether it tries to hide it's true storage capacity or boots its own internal OS to present storage, people often think they're being clever when really they're just making themselves stand out.

[–] ColeSloth@discuss.tchncs.de 11 points 1 day ago

You misunderstood what is seen or how it works.

When the drive is checked, you can see files and whatever on what appears to be an 8GB flash drive.

You have to add the specifically worded txt file into that drive before the hidden drive shows up.

[–] JustEnoughDucks@feddit.nl 28 points 1 day ago* (last edited 1 day ago) (5 children)

Do you think TSA/CBP is going to check the flash data lines to see if the MCU is scanning the flash internally?

This isn't a standard USB flash controller... You would need to break the casing and physically probe it to figure out that something was off as far as I can tell. It's not like the MCU broadcasts that it is scanning to the USB port.

You would have to be hitting the stick pretty hard, not just a normal file scan to notice the timing being slightly too long in a small portion of the scans. The bigger problem would be that the flash drive would be brand-recognizable if it ends up being mass produced that they might auto-confiscate it, and of course the default file that it searches for being known.

[–] Dyskolos@lemmy.zip 2 points 1 day ago (2 children)

If I got it right, you could easily detect this drive by just creating password.txt. as the article says it creation is intercepted and skipped. Hence if there is no password.txt afterwards, you know what you're dealing with. Still, you have to know this AND care.

[–] AwesomeLowlander@quokk.au 23 points 1 day ago (1 children)

It's only skipping if your password matches. Otherwise it'll just be a normal file.

[–] Dyskolos@lemmy.zip 6 points 1 day ago* (last edited 1 day ago)

Ah okay, so then I retract my statement and better my reading-skills 😁

[–] BitUnWise@programming.dev 7 points 1 day ago (1 children)

It looks for a string "password:xyz" bring written to any file, where xyz is the password. If you get the password wrong it'll just write the file normally

[–] Dyskolos@lemmy.zip 1 points 1 day ago* (last edited 1 day ago) (1 children)

Ah okay, so then I retract my statement and better my reading-skills 😁

[–] BitUnWise@programming.dev 2 points 20 hours ago

No worries, I had to read stuff outside of the articles to get that information

load more comments (4 replies)
[–] unexposedhazard@discuss.tchncs.de 17 points 1 day ago (1 children)

You are yapping your ass off. This is a hardware mod, not a software package. Its literally a custom storage controller chip that only physically unlocks the secret storage once it detects a certain key file on the decoy storage. They would have to xray the drive individually at close range with high resolution and know a lot about electronics to even come close to figuring out that something is different.

[–] AwesomeLowlander@quokk.au 7 points 1 day ago

How would it be detected? It seems like the password detection and decryption is happening at the hardware level, and they take steps to have it show up as nothing more than a standard drive. I'm not an expert on this stuff though.

[–] evenglow@lemmy.world 4 points 1 day ago

Airport forensic team can't flag an encrypted drive it can't detect.

The article talks about this.

[–] Trilogy3452@lemmy.world 5 points 1 day ago

Saving important documents as an emergency backup without worrying about it getting stolen. I guess the hidden partition adds another layer against someone who might want to try and brute force it

[–] Fmstrat@lemmy.world 1 points 15 hours ago (1 children)

How is this better than a Veracrypt hidden partition on a standard thumb drive?

[–] Axolotl_cpp@feddit.it 1 points 4 hours ago (1 children)

IIRC Veracrypt is easier to detect since it does some trickery with the filesystem and software while this has 2 memory chips and one is phisically disconnected then it scan for a string that looks like "password:1234" inside a file called "password.txt" at every write and if the password is correct it will connect the chip again, so it's virtually undetectable unless you crack open the USB stick and know what you are looking at (which is an highly unrealistic scenario for an airport unless you are in a country that's in a war period)

[–] Fmstrat@lemmy.world 1 points 2 hours ago* (last edited 2 hours ago)

Not true. Veracrypt's hidden file system is random data on a preexisting partition that uses no software. You can only detect it if you install Veracrypt and guess the password.

https://veracrypt.io/en/Hidden%20Volume.html

[–] magnue@lemmy.world 17 points 1 day ago (2 children)

Why not just use veracrypt?

[–] ITGuyLevi@programming.dev 19 points 1 day ago (1 children)

That's what I would go with if I was inclined. Create a volume the size of the drive and add a hidden volume with a different password within like we've been doing for years (decades at this point maybe almost).

[–] ExLisper@lemmy.curiana.net 3 points 1 day ago (2 children)

I would upload encrypt file somewhere and download it when needed. If you're worried someone will actually access your USB stick looking for encrypted data, why carry it at all? It's cool if you want to pretend you're a spy or something but it's not very practical.

[–] IrateAnteater@sh.itjust.works 17 points 1 day ago (1 children)

That's assuming that wherever you are going to or coming from has an internet connection. It's likely that there will be a connection, but it's still not a guarantee. And if there is a connection, the size of the files you're carrying may make using that connection impractical.

[–] ExLisper@lemmy.curiana.net 2 points 1 day ago (2 children)

Yes, but you can just carry encrypted hard drive with you. Hiding encrypted data is useful pretty much only for legal reasons. You want to take it across border and are worried TSA agent will force you to decrypt it or something. What is safer in that case? Carrying a USB stick with hidden encrypted partition or not carrying anything at all and downloading the data later? I would say the latter. Smuggling encrypted data through custom checks into a war zone with limited internet access is the cool but unlikely spy games scenario I was talking about. Encrypted microSD card would be even more secure in that case.

[–] WhyJiffie@sh.itjust.works 1 points 22 hours ago

to a war zone? such inspections are done not only in unlikely scenarious like when going to "a war zone"

[–] village604@adultswim.fan 1 points 1 day ago

They'd probably just confincate the drive if it's obviously encrypted.

[–] magnue@lemmy.world 2 points 1 day ago (1 children)

I guess you might just want to carry all your passwords in there, but then generally the password file itself is encrypted so I don't see the point.

[–] WhyJiffie@sh.itjust.works 2 points 22 hours ago (1 children)

that's like saying "password managers require a password so I don't see the point"

[–] magnue@lemmy.world -1 points 21 hours ago

That is pretty much what I said yeah

[–] wreckedcarzz@lemmy.world 9 points 1 day ago (1 children)

Vault is visible and therefore obvious. If you need to be discreet, this sounds useful.

[–] yestalgia@lemmy.world 7 points 1 day ago (4 children)
[–] BitUnWise@programming.dev 4 points 1 day ago

That hides another volume inside another VeraCrypt volume, so it's obvious it's not a normal drive

load more comments (3 replies)
[–] StealthLizardDrop@piefed.social 7 points 1 day ago (1 children)

Does it actually do anything if i 'dd' entire disk? id be curious how compatible this is with linux

[–] MentalEdge@sopuli.xyz 7 points 1 day ago (1 children)

I mean, presumably this is all device-side on the stick.

It mounts the two partitions separately, and presents them separately. It doesn't need to pass through the actual SD card to the host system at all.

If you dd the decoy partition you only ever see the decoy partition. Because the decoy partition is presented as a complete device, not just a partition, to the host system.

Why would this be incompatible with linux? If this is done the way it seems it is done, it's not a filesystem trick.

It's two partitions on one SD card being presented as two separate devices by the microcontroller that has actual direct access.

The real vulnerability would be that you could just crack it open to find the SD card.

[–] mal3oon@lemmy.world 3 points 20 hours ago

you could just crack it open to find the SD card.

Funny enough, had the same thing once in an aliexpress usb.

load more comments
view more: next ›