Earlier quoted context omitted.
What am I misinterpreting? OP literally said they don't understand why a journalist would carry these data with them. As if the data is a file on your phone. Data can be a contact book on your phone, or a messenger with E2E encrypted messages. What would the alternative to that be? Sending pigeons?
Restoring from remote backup when you reach your destination, then wiping again before you cross borders. Or shipping the (encrypted) data separately and picking it up after safe arrival.
GrapheneOS protections against data extraction from locked devices
151–160 of 284 posts
Re: GrapheneOS protections against data extraction from locked devices
#152Earlier quoted context omitted.
What about using decoy profiles? Say before the border crossing you switch to another user. Does that expose keys or anything for other users?
You would need to hide the existence of the original profile while in the decoy profile for this to work, which GrapheneOS considers too complex to implement
You can't even make them different sizes because that gives away which one is duress. You could have more partitions with a static split like 32+32+32+32+32+32+32+32 but then you have to manage so many independent partitions it isn't practical.
Re: GrapheneOS protections against data extraction from locked devices
#153Re: GrapheneOS protections against data extraction from locked devices
#154Earlier quoted context omitted.
I think more useful would be to be able to boot into another data partition with a different password, which, in turn, would hide the other "daily" partition. I believe LUKS is capable of that. The storage dump looks like a random set of data and only a valid password can find and decrypt a matching hidden partition. Ideally this should also work on lock screen, e.g. if you type in a non-standard PIN, it would boot f…
>I believe LUKS is capable of that Booting into a 30 GB partition on a 128GB phone is going to be mega suspicious, even if the remaining data is random.
Re: GrapheneOS protections against data extraction from locked devices
#155Earlier quoted context omitted.
Because you may need the data in the data during/after your travel and lack clean way to access safely, securely and anonymously remotely.
This is where we need "cloud phones as a service" / "selfhosting a cellphone at home with some kind of remote access system". Not even kidding here, it's time to bring out thin client computing to cellphones. Let the spicy stuff sit somewhere else. I could bootstrap a Tailscale or Netbird signin remotely, install the access client, and remote back into the 'normal phone'. Would be then funny to map that to lockscreen…
Re: GrapheneOS protections against data extraction from locked devices
#156Earlier quoted context omitted.
Restoring from remote backup when you reach your destination, then wiping again before you cross borders. Or shipping the (encrypted) data separately and picking it up after safe arrival.
What's the difference between this and wiping when under duress using the special PIN? If you aren't being checked you don't wipe and are gopd to go.
Just as the border guard can’t require you to fetch something from your house before entry, they can’t require you to restore from a remote backup that they don’t even know about.
Re: GrapheneOS protections against data extraction from locked devices
#157Earlier quoted context omitted.
The government can easily get your remote backup, of course. It's just that border control won't know you have one.
Not if it’s encrypted and self-hosted. Your doomerism is silly. “The government” is not all-powerful, or they wouldn’t need to pester people for PINs at the border.
Self-hosting is the way obviously
Re: GrapheneOS protections against data extraction from locked devices
#158Earlier quoted context omitted.
> a perfectly valid answer Makes no difference at all in the real world. You don't have to give valid answers, you need to get the guy across from you to not find you suspicious. That phrase is going to put a red flag on you, valid or not.
> you need to get the guy across from you to not find you suspicious. What? No, who cares about that? Let him find you suspicious, what matters is that he doesn’t access your data. And it is not suspicious to cross borders (esp. US borders) with burner phones. As others have said, it is standard practice.
Re: GrapheneOS protections against data extraction from locked devices
#159Earlier quoted context omitted.
"I got on pickpocketed on my last vacation, so now I travel with an old backup phone instead"
This may feel like a good idea as a “gotcha” justification but it just doesn’t matter. It’s still extremely abnormal and you will stick out. The only way to protect yourself is by blending in, not sticking out.
Re: GrapheneOS protections against data extraction from locked devices
#160Earlier quoted context omitted.
The easiest way to avoid suspicion is to have a phone filled with cat and family pictures, dumb apps and games. You don't avoid scrutiny by being wierd and hiding things, but by hiding in plain sight by being ultra boring.
The easiest way to avoid suspicion is to have a phone filled with cat and family pictures, dumb apps and games. Presumably they know quite a lot about you already outside your phone (yay, Palantir). I mean, the guy the recent post was about was an activist. An empty phone vs. a phone with just cat pictures and dumb games wouldn't really make a difference. They went on a fishing expedition, so anything that does not h…
Hello Palantir. I orchestrated 9/11. Please come and arrest me.