Comment by raxxorraxor
8 hours ago
We probably need honey pod fake OS systems that boots up if not properly handled displaying some stars & stripes as background image and having the US national anthem playing for any sound the OS is trying to play.
8 hours ago
We probably need honey pod fake OS systems that boots up if not properly handled displaying some stars & stripes as background image and having the US national anthem playing for any sound the OS is trying to play.
A phone with a backup account, unlocked with duress pin makes sense to me.
How hard would it be to admin-allow some apps to work across barriers. E.g., wallet apps work, airline tickets work, but email/socials do not.
the issue is that when a phone is unlocked, they can just plug in a USB device and scrape everything off it. The TSA agent may not be eyeballing a facebook account so much as plugging in an exfiltration software stack or malware.
> the issue is that when a phone is unlocked, they can just plug in a USB device and scrape everything off it
That's useless if the backup account and the main account use different keys for the home partition.
VeraCrypt (used to?) have this. It was called a hidden volume. One volume, but two keys, two passwords, and two different containers full of data. Technically, the second volume is written into the partition "from the back" using key 2, while the first volume is written "from the front" using key 1.
Fun fact, there's no protection against writing over data in the other volume if volume 1 + volume 2 exceed the size of the partition - and there can't be, otherwise the volume wouldn't be hidden.
Yep, and there is also no way to tell if a hidden volume exists, because a volume without a hidden volume would fill that space with random data indistinguishable from a hidden volume.
For now the courts in the US have set a different barrier for automated extraction and hand searches. For now.
Why does the USB port need to even work anyways? It could just be designed to look like a USB port but fry whatever expensive and proprietary phone hacking device they bought from some scuzzy Israeli ‘security’ company when it’s plugged in.
It has to be a once-only effect tho. If it's repeatable, they've got you for some string of felonies.
2 replies →
This would unironically probably work pretty well. The bullies in airports don't have that much time to investigate a phone which "looks good".
Right, these goons are hand searching through phones specifically to find something, anything, they can use to make your life suck and detain you further.
A pin that boots into a dummy account, full of benign messages, photos, innocent web browsing, etc. is going to get you a pass. They'll flip through everything and get bored after a minute of not finding anything.
Far less likely to aggravate them than wiping your phone
I would prefer to backup and wipe my phone before travelling.
Then have some planned means of restoring the backup when it's safe to do so.
Being caught with a honeypot looks much worse than being caught with a new phone. You can always say you bought a cheap "travel" phone if asked.
Its such a shame Android's backup/restore is such a mess, even more so in GrapheneOS. I remember the era before Google and manufacturs started cracking down on bootloaders and custom ROMs - I used an app that could do effective, actually full backup and restore in single click.
Good times.
It's hard to justify an iPhone Pro Max as a "cheap travel phone" though so you might actually need to buy a cheap travel phone.
Don't forget to have the Official Social Media of the President of the United States(tm) installed, with an account following the correct list of truthtellers and rightthinkers.