← Back to context

Comment by dredmorbius

1 day ago

Those are ... relatively minor concerns.

Firing off as part of a duress key entry, and removing itself (from the decoy partition) as its work is done, would suffice.

ADB / forensic tools would be ineffective if USB access is denied (as discussed elsewhere in this thread).

>ADB / forensic tools would be ineffective if USB access is denied (as discussed elsewhere in this thread).

Well no, because if you gave the pin, you'd expect the phone to work normally, including enabling adb. If you gave the pin but adb doesn't work that would be massively suspicious. Same if adb worked but logs were scrubbed. Otherwise you're back at "border guards found out you gave a duress pin, now you're being prosecuted for tampering with evidence".

  • It doesn't feel like you're very interested in solving this problem - you seem more interested in defending the status quo

    • In fairness, an adversarial challenge can be useful in pointing out weaknesses (and possible mitigations) to a particular technical approach.

      It's not clear that all of those objections are substantive or insurmountable.

      "The USB port may have died" might be one possible response. (Not technically a lie, and hence defensible in court.) Or just silence.

      Alternatively, some way of directing such probes to the decoy partition and presenting a sufficiently coherent impression of a valid partition might be another approach.

      Much of this comes down to risks presented and costs of mitigation (or of getting mitigations wrong).

      1 reply →