Protection against what? Your lack of the threat model is tripping you up. If all you want is protection against a Fappening, you don’t need steganography, just encrypt images to binary blobs and you’re done.
If someone is suspicious enough that they steal your images
Why steal? Imagine a scenario: you’re drove to Canada from the US for a weekend and when you’re returning, a polite TSA officer asks for your phone and plugs it into a gizmo. The gizmo displays some blinkenlights, beeps, and the polite officer tells you that your phone is likely to have hidden encrypted information and would you mind stepping inside that office to have a conversation about it?
Encrypting your images has obvious benefits, but what exactly do you gain by keeping them inside other images as opposed to random binary files?
I specifically outlined the three primary attack types: fusking, stolen-phone, targeted attacks.
Imagine a scenario...
In that scenario, I would hope the “beyond a reasonable doubt” standard would apply (which this protocol passes). But if we’re assuming an evil government that doesn’t stick to that standard, the same hypothetical gizmo can be used to detect any encrypted data.
what exactly do you gain by keeping them inside other images as opposed to random binary files?
Convenience, a deterrent against attacks, and moderate protection.
Convenience: the iPhone doesn’t provide any sort of file system for you to store random binary files, and no supported protocol by which to transmit them anywhere. It does, however, have a very robust photo storage and transmission system and GUI.
Deterrent: In low-threat situations where potential attackers only have visual access to your images, there are no visual methods by which to distinguish your decoy pictures from normal pictures, and therefore make you a target.
Moderate protection: Any further compression or alteration of the decoy image will mung the data. Most (not all) means of transmitting images from an iPhone (social networking apps, email apps, online image storage services, etc.) will compress the image before sending/storing, which as mentioned will mung the encrypted data. Obviously this should not be relied on because there are means (albeit less convenient) of transmitting the data from your phone without compression.
In that scenario, I would hope the “beyond a reasonable doubt” standard would apply
No need for hope here. “Beyond a reasonable doubt” is a legal standard that applies to evidence presented in criminal prosecutions. It does not apply to investigations or, for example, things like being put on the no-fly list. Or the “next target for the drone assassination” list.
Moreover, at a border crossing the Fourth Amendment basically does not apply, too. A border control official can search all your belongings including your electronic devices without needing to show any cause, never mind about “reasonable doubt”. At the border, TSA can trawl through your laptop or phone at will.
Relevant quote: “[I]f we’re assuming an evil government that doesn’t stick to that standard, the same hypothetical gizmo can be used to detect any encrypted data.”
Protection against what? Your lack of the threat model is tripping you up. If all you want is protection against a Fappening, you don’t need steganography, just encrypt images to binary blobs and you’re done.
Why steal? Imagine a scenario: you’re drove to Canada from the US for a weekend and when you’re returning, a polite TSA officer asks for your phone and plugs it into a gizmo. The gizmo displays some blinkenlights, beeps, and the polite officer tells you that your phone is likely to have hidden encrypted information and would you mind stepping inside that office to have a conversation about it?
Encrypting your images has obvious benefits, but what exactly do you gain by keeping them inside other images as opposed to random binary files?
I specifically outlined the three primary attack types: fusking, stolen-phone, targeted attacks.
In that scenario, I would hope the “beyond a reasonable doubt” standard would apply (which this protocol passes). But if we’re assuming an evil government that doesn’t stick to that standard, the same hypothetical gizmo can be used to detect any encrypted data.
Convenience, a deterrent against attacks, and moderate protection.
Convenience: the iPhone doesn’t provide any sort of file system for you to store random binary files, and no supported protocol by which to transmit them anywhere. It does, however, have a very robust photo storage and transmission system and GUI.
Deterrent: In low-threat situations where potential attackers only have visual access to your images, there are no visual methods by which to distinguish your decoy pictures from normal pictures, and therefore make you a target.
Moderate protection: Any further compression or alteration of the decoy image will mung the data. Most (not all) means of transmitting images from an iPhone (social networking apps, email apps, online image storage services, etc.) will compress the image before sending/storing, which as mentioned will mung the encrypted data. Obviously this should not be relied on because there are means (albeit less convenient) of transmitting the data from your phone without compression.
No need for hope here. “Beyond a reasonable doubt” is a legal standard that applies to evidence presented in criminal prosecutions. It does not apply to investigations or, for example, things like being put on the no-fly list. Or the “next target for the drone assassination” list.
Moreover, at a border crossing the Fourth Amendment basically does not apply, too. A border control official can search all your belongings including your electronic devices without needing to show any cause, never mind about “reasonable doubt”. At the border, TSA can trawl through your laptop or phone at will.
Relevant quote: “[I]f we’re assuming an evil government that doesn’t stick to that standard, the same hypothetical gizmo can be used to detect any encrypted data.”