Robert_White

joined 4 days ago
[–] Robert_White@lemmy.world 5 points 4 days ago

I really want people to know more about ways to preserve their privacy. We even built this product with our team.

[–] Robert_White@lemmy.world 7 points 4 days ago (1 children)

No, it was me. I use ai to make corrections to my english because i'm not native speaker

[–] Robert_White@lemmy.world 1 points 4 days ago

Good writeup, and the downside you flagged is the interesting bit. Profiles are enumerable. A dummy profile survives a glance at the screen and stops working the second someone can see profile 2 exists and asks you to open it.

The property you want on top of your setup is that the second thing can't be shown to exist at all, so it looks like random noise rather than a locked door. Then the dummy isn't a dummy, it's just the phone.

(I work on DeniableOS, which is built around that. Your profile setup is still the right free answer for most people and I wouldn't talk anyone out of it.)

[–] Robert_White@lemmy.world 1 points 4 days ago

That exists. The thing to watch is the difference between separate profiles and a hidden one.

Graphene gives you multiple profiles with their own passwords, but profiles are enumerable. Anyone poking at the device sees that profile 2 is there, so "open that one too" is the obvious next sentence.

The version you're describing works when the second environment can't be shown to exist at all, so it reads as encrypted random noise, which is what empty encrypted space looks like anyway. One PIN gets you a full boring phone, the other gets you your real one.

Only holds up if the boring phone is actually convincing though. Six apps and no photos fails on the spot.

(I work on DeniableOS, which does the hidden version, so weigh that how you like.)

[–] Robert_White@lemmy.world 2 points 4 days ago

You guys already spotted the hole in the burner plan. A clean phone and a wiped phone look identical from the other side of the desk, and both look like someone who planned ahead.

A burner only works if it's lived-in instead of clean. Real accounts, months of boring messages, photos of nothing in particular. That's a lot more effort than grabbing a spare handset the week before you fly, which is why hardly anyone does it properly.

Same idea with less upkeep: keep one genuinely lived-in phone and put the sensitive half behind a second PIN, stored so you can't show it's there. Then the thing you hand over isn't a prop, it's just your phone.

(I work on DeniableOS, which is that. Changes nothing about what CBP is allowed to do to you, and I'm not a lawyer.)

[–] Robert_White@lemmy.world 11 points 4 days ago (4 children)

The reboot isn't cosmetic, it's structural. The duress PIN nukes the key derivation material, and a device with no keys has nothing left to boot into. There's no quiet version of that.

But your instinct is right and worth pushing one step further. An empty phone has the same problem as a rebooting one. Nobody owns a phone with four apps and two weeks of messages, so it just takes them a bit longer to notice.

What you actually want is to quietly unlock into a phone that's full. Real apps, real photos, real history, and the sensitive half behind a second PIN stored so it reads as random noise, same as any unused encrypted space. Nothing gets destroyed, so there's nothing to reboot from and nothing to argue about afterwards.

Catch is the decoy has to be believable, and keeping one believable is a chore most people drop after a month.

(I work on DeniableOS, which does this, so grain of salt. Graphene's own statement this week made roughly your point, that wiping can carry physical or legal consequences.)

[–] Robert_White@lemmy.world 1 points 4 days ago

Because the reboot is not cosmetic. The duress PIN destroys the key derivation material, and a device with no keys has nothing left to boot into, so you get the restart and the blank slate. There is no version of that which looks quiet.

The thing worth adding to your instinct: quietly unlocking to an empty phone has the same problem as the flashy version. An empty phone is itself a statement. Nobody carries a device with four apps and a two week message history, so a careful look at an empty phone raises the same question the reboot does, just more slowly.

What answers your instinct properly is quietly unlocking to a phone that is full. A complete ordinary device, real apps, real photos, real message history, while the sensitive environment sits behind a separate credential and is stored so that it reads as encrypted random noise, which is what unused encrypted space looks like anyway. Nothing is destroyed, so the phone just unlocks and keeps working, and there is nothing afterwards for anyone to describe as destruction.

The honest catch is that the decoy has to be genuinely convincing, and keeping one that looks like a real life is ongoing work that most people quietly stop doing after a month. A thin decoy is worse than no decoy.

Disclosure: I work with DeniableOS, which is built around that approach, so weigh that accordingly. GrapheneOS is excellent, and their own statement this week says the same thing you are circling, that people should think hard about a wipe because it can carry physical or legal consequences.