• arc99@lemmy.world
    link
    fedilink
    English
    arrow-up
    31
    ·
    2 days ago

    If the duress pin makes obvious it’s the duress pin then it’s not really doing its job. It should instead open a profile with not much in it while erasing the other profile and files in the background.

    • Techno-rat@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      7
      ·
      edit-2
      2 days ago

      They asked to unlock his phone, he entered the wipe instead personal pin, and the wipe starts, with no possible reversal.

      I mean yeah they discover it when he hands them the phone and it shows something other than an unlocked screen… But he is still in detention? Making a fake homescreen will fool them for like 30 secs tops until they open literally any app and sees it’s either completely empty or that it doesn’t work.

      What would that solve? It just drags out the procedure

      • arc99@lemmy.world
        link
        fedilink
        English
        arrow-up
        9
        ·
        edit-2
        2 days ago

        The purpose of a duress code is plausible deniability.

        There is an encryption product for Windows called VeraCrypt (aka TrueCrypt). You can create a hidden decoy volume inside an outer encrypted volume which has all your stuff in it. When mounted an observer cannot tell the difference between the hidden volume and the real volume since they are mounted the same way with different passcodes. You can put files in the decoy for plausibility but not the things you actually want to hide.

        The same should be true of a duress code in a phone. It should be possible to put files, apps and stuff in the decoy that show activity e.g. email, pictures etc. Providing the other profile is wiped while this screen is showing then there is no immediate way of proving it was a duress code.

        It would have to at least convince the border guard, but it should withstand forensic analysis too. So it might be necessary to do what VeraCrypt does.

        • phutatorius@lemmy.zip
          link
          fedilink
          English
          arrow-up
          6
          ·
          edit-2
          1 day ago

          On the Linux box I travel with, my main account is not shown on the list of user accounts when you login. There is a dummy account on the list. When I log into that, it has a full complement of apps and data, and the online email account it connects to is a secondary account I use for travel bookings, random notifications and other throwaway purposes. Financial data, important passwords, personal correspondence, etc, are not on that account. Just the usual stuff a non-computer-savvy guy my age would have: browsing, email and Facebook. If they ever comment on it being Linux, I’ll just say “my son set it up for me, I kept having problems with Windows.” But so far, the most they’ve ever done is ask me to show that the laptop can boot up. There’s also full-disk encryption so scans won’t tell them anything worth knowing.

          The passwords I use are high-entropy. There’s no duress PIN, though I could set one up if so inclined. So far, I haven’t felt the need to.

        • Techno-rat@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          7
          ·
          edit-2
          2 days ago

          "The duress PIN doesn’t give you a second chance and will trigger anywhere you enter it: on the lockscreen, while enabling Developer options, or even while unlocking an app that requests authentication. And unlike a regular factory reset, a duress PIN will erase all encryption keys and your phone’s eSIM partition as well. This makes it impossible for an attacker to access my data just by having physical possession of your device and knowledge of the PIN.

          I think the real strength of GrapheneOS’ duress PIN lies in its subtlety. There are no confirmation prompts, no announcements, and no obvious signs that the wipe was intentional on your part. Of course, GrapheneOS is no longer a fringe operating system these days — it has even attracted the ire of law enforcement in some jurisdictions. In other words, a professional attacker might be aware of the existence of a duress PIN. But if you can enter it quickly enough, it achieves its intended effect: no data can be lifted from your phone."

          Pretty plainly stated:

          Main purpose - delete all data

          A nice bonus - the process is semi hidden, no way to confirm mistakes or not

          Purpose is NOT - Fool any attacker to think they have your phone even though it’s wiped

          So it’s most definitely doing it’s job. You think that job is not enough, fair, but it’s living up to it’s own stated purposes.

        • Techno-rat@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          4
          ·
          edit-2
          2 days ago

          Lol that’s just str8 false in this case, the stated purpose of the duress pin in the article is a system wipe, not plausible deniability.

          So whoever has you under duress cannot steal your data

          It’s not a ‘get out of duress free’-card

      • Typotyper@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        10
        ·
        2 days ago

        Empty apps or no apps aren’t necessarily a sign of guilt, but they will look at you like you are because its not normal.

        Companies often have travel laptops which are a clean install and no private corporate info exposed.