The $5 Wrench Attack, Revisited

XKCD made it famous: no amount of encryption survives a $5 wrench and someone willing to use it.

If an attacker physically coerces you — at gunpoint, with a kidnapping, through threats to your family — you WILL give up your password. This is the correct response. Your life is worth more than any amount of money.

But what if the password you give them isn't the real one? What if entering a specific password triggers a completely different set of actions?

Why Duress Features Need Specialist Design

A duress credential can create serious personal-safety risks if it is unreliable, discoverable, or mistaken for a guaranteed emergency signal. ZeroLatch does not offer a duress password, local wipe, location transmission, or instant trigger. Do not represent an ordinary login or check-in flow as one.

Use the Right Tool for Urgent Safety

ZeroLatch is designed for planned continuity, not real-time emergency response. Its current customer-facing check-in intervals begin at 1 day and may use no additional safety period, but lifecycle processing still runs daily rather than continuously. For travel, coercion, kidnapping, or immediate personal-safety risks, use a dedicated monitored safety service, local emergency channels, and an agreed human escalation plan.

A ZeroLatch delivery may complement that plan with longer-term instructions for a trusted contact, but it must not be the only emergency control. Test the flow with non-sensitive sample material and obtain qualified security and legal advice for high-risk situations.

Questions before adopting any duress feature

Who monitors the signal? How quickly must they respond? Can the user cancel a false alarm safely? What happens without power, connectivity or location permission? Could an attacker discover the alternate credential or force repeated unlocks?

If the vendor cannot answer those questions with documented operations and realistic tests, the feature may add danger. Reduce asset exposure, separate travel devices from long-term custody and prioritise the person's safety over an automatic technical response.