Live data from Hacker News

US citizen charged after GrapheneOS phone wipes during airport search

techspot.com

901–910 of 1001 posts

Re: US citizen charged after GrapheneOS phone wipes during airport search

#901

Instead of a PIN that wipes the device, it would be much better to setup a special PIN that logs the user into a sanitized, completely separate profile with generated content of no practical value. This would create plausible deniability, and be sufficient to allow low-level border agents to look through a phone and pass any checks without raising these kinds of alarms. The wipe PIN should still be an option, but sho…

They would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security.

Also they can plant evidence if you unlock the phone.

https://nitter.net/GrapheneOS/status/2081471477174456340#m

Re: US citizen charged after GrapheneOS phone wipes during airport search

#902

Wiping could be the last resort. Instead how about auto creating a new profile! As far as I remember Android profiles isolate apps, files, and system data and providing a fresh environment without erasing the device. To make it feel more authentic there could also be an option to automatically install a few commonly used apps by default. Thats it. (assuming the officials don't have time for an thorough inspection)

They would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security.

Also they can plant evidence if you unlock the phone.

https://nitter.net/GrapheneOS/status/2081471477174456340#m

Re: US citizen charged after GrapheneOS phone wipes during airport search

#903
post #358

By raising the profile of airport seizures all it means is that serious criminals will wipe their devices prior to travelling and restore afterwards/buy a new device for travel. The powers of investigators special rights and abilities rely on them being used very rarely. Last thing the terrorism investigators want is media coverage exposing their tactics.

They are trying to make buying a burner phone illegal as well. Pushing a rule to require an ID to buy any SIM.

You don't need a phone number to use a phone.. It's not secure messaging at all anyway.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#904

Earlier quoted context omitted.

PIN to wipe seems suspicious. How about a PIN where it login to a patriotic profile and phone looks like normal android.

I had this on a Xiaomi, maybe 10 years ago? Very cool feature! I hope they still do it. I think the wipe feature is also very cool, but not used in this way.

They would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security.

Also they can plant evidence if you unlock the phone.

https://nitter.net/GrapheneOS/status/2081471477174456340#m

Re: US citizen charged after GrapheneOS phone wipes during airport search

#905

For non-graphene users (eg. Boring iPhone people like me). So there’s a feature called Duress PIN which as explained through some comments means you put a different pin which intentionally wipes the phone. It’s not auto wipe or wipe after several failed attempts but intentional wipe of device. (Worth explanation as the current title nor the article doesn't easily explain this was made by the US citizen providing the…

PIN to wipe seems suspicious. How about a PIN where it login to a patriotic profile and phone looks like normal android.

[deleted]

Re: US citizen charged after GrapheneOS phone wipes during airport search

#906

For non-graphene users (eg. Boring iPhone people like me). So there’s a feature called Duress PIN which as explained through some comments means you put a different pin which intentionally wipes the phone. It’s not auto wipe or wipe after several failed attempts but intentional wipe of device. (Worth explanation as the current title nor the article doesn't easily explain this was made by the US citizen providing the…

PIN to wipe seems suspicious. How about a PIN where it login to a patriotic profile and phone looks like normal android.

They would like to have something like that but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security.

Also they can plant evidence if you unlock the phone.

https://nitter.net/GrapheneOS/status/2081471477174456340#m

Re: US citizen charged after GrapheneOS phone wipes during airport search

#907

Earlier quoted context omitted.

PIN to wipe seems suspicious. How about a PIN where it login to a patriotic profile and phone looks like normal android.

This is exactly my setup with GrapheneOS. The default / main profile is patriotic, with a sterilized Telegram account, state-adjacent banks and apps, etc. The second profile (that uses a separate PIN) is not so patriotic: it has foreign bank apps, crypto apps, password manager, 2FA app, personal records, and an alternate Telegram account that I use to discuss any potentially unpatriotic topics with potentially unpatr…

They would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security.

Also they can plant evidence if you unlock the phone.

https://nitter.net/GrapheneOS/status/2081471477174456340#m

Re: US citizen charged after GrapheneOS phone wipes during airport search

#908
post #595

Earlier quoted context omitted.

So I guess what you really want is a duress PIN that loads into a fake innocent profile.

My solution to this on GrapheneOS is having the primary user as the dummy. I have some random apps, photos, a copy of my password manager and 2fa app on there. Enough to look valid if not boring. I do all my day to day on another profile that can easily be deleted, with my password and 2fa I can easily setup the apps I use again later.

If you give an adversary access to one profile they can see any others exist or traces of it if it's been deleted.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#909
post #449

Earlier quoted context omitted.

Yes I thought this was the standard solution? People have been doing this since way back in the TrueCrypt days - IIRC you could configure it to run a whole fake version of Windows if you wanted without easily revealing your actual main volume. Most hardware crypto wallets also have a "duress wallet" feature where you keep a low balance for the same reason. Wiping is obviously extremely suspicious and asking for troub…

We noted in the border search guide that lying to the agents in response to their questions is potentially a crime in its own right (even if it's not done in order to hide anything illegal). We thought that this made hidden volumes quite tricky, particularly if one's intent was to pretend to comply with a question or request while actually not complying.

It's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security.

https://nitter.net/GrapheneOS/status/2081471477174456340#m

Re: US citizen charged after GrapheneOS phone wipes during airport search

#910
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

can you use a faked account that looks like you but hides all the important information so when your phone is in search mode you just show the agent that, giving them something to work on and protecting your privacy
Post reply on HN