Rubber-hose cryptanalysis
“[A] euphemism for the extraction of cryptographic secrets (e.g. the password to an encrypted file)”
A new term! I like this one. Like regular social engineering, but with a cruder toolkit.
(from wikipedia):
“…the rubber-hose technique of cryptanalysis. (in which a rubber hose is applied forcefully and frequently to the soles of the feet until the key to the cryptosystem is discovered, a process that can take a surprisingly short time and is quite computationally inexpensive)”
So please, take your shoes off & make yourself uncomfortable.


Comments(2)
Yeah I was reading an article a while ago about how whatever the elaborate security measures banks etc take, they are always going to be fallable because basically it comes down to a human and ultimately humans are a lot easier to get passwords out of than one likes to think!
Link rectified. I noticed it the first time I commented, thought “fuck. oh well, can’t be fucked to change it”. Then it auto-saved and each following comment I thought the same thing. But now you have pointed it all out and I had to do something about it!
Yeah – my passwords are often embarrassing given how much I should know better.
Vital stuff gets well hidden, though – no password files on my hdd, but I do keep them on a USB key. Anything particularly sensitive gets a long random string that I conciously avoid remembering, just cut & paste.
Nothing’s encrypted yet, though were my public profile to raise then things probably would.
So far as keeping private files hidden, MicroSD cards are frankly the pinnacle in my opinion. Why encrypt when you can just store it all on something the size of your little toenail? Hide one of those things with a little thought and it just isn’t going to be found unless you tell someone where. Much as the best “code breaking” is simple, so are the best privacy measures.
(Oh, also – I always want to be the weakest link in the chain. Frankly, if someone’s threatening to pull my fingernails out, I think we’re at the point where they can just take my porn if they need it that badly.)