Comment by jvanderbot
10 hours ago
A phone with a backup account, unlocked with duress pin makes sense to me.
How hard would it be to admin-allow some apps to work across barriers. E.g., wallet apps work, airline tickets work, but email/socials do not.
the issue is that when a phone is unlocked, they can just plug in a USB device and scrape everything off it. The TSA agent may not be eyeballing a facebook account so much as plugging in an exfiltration software stack or malware.
> the issue is that when a phone is unlocked, they can just plug in a USB device and scrape everything off it
That's useless if the backup account and the main account use different keys for the home partition.
VeraCrypt (used to?) have this. It was called a hidden volume. One volume, but two keys, two passwords, and two different containers full of data. Technically, the second volume is written into the partition "from the back" using key 2, while the first volume is written "from the front" using key 1.
Fun fact, there's no protection against writing over data in the other volume if volume 1 + volume 2 exceed the size of the partition - and there can't be, otherwise the volume wouldn't be hidden.
Yep, and there is also no way to tell if a hidden volume exists, because a volume without a hidden volume would fill that space with random data indistinguishable from a hidden volume.
For now the courts in the US have set a different barrier for automated extraction and hand searches. For now.
Why does the USB port need to even work anyways? It could just be designed to look like a USB port but fry whatever expensive and proprietary phone hacking device they bought from some scuzzy Israeli ‘security’ company when it’s plugged in.
It has to be a once-only effect tho. If it's repeatable, they've got you for some string of felonies.
I wonder what would happen if it was every time, but you never told them it was a USB port
1 reply →