• arc99@lemmy.world
    link
    fedilink
    English
    arrow-up
    23
    ·
    11 hours ago

    If the duress pin makes obvious it’s the duress pin then it’s not really doing its job. It should instead open a profile with not much in it while erasing the other profile and files in the background.

    • Techno-rat@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      9 hours ago

      They asked to unlock his phone, he entered the wipe instead personal pin, and the wipe starts, with no possible reversal.

      I mean yeah they discover it when he hands them the phone and it shows something other than an unlocked screen… But he is still in detention? Making a fake homescreen will fool them for like 30 secs tops until they open literally any app and sees it’s either completely empty or that it doesn’t work.

      What would that solve? It just drags out the procedure

      • arc99@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        16 minutes ago

        The purpose of a duress code is plausible deniability. There is an encryption product for Windows called VeraCrypt (formerly TrueCrypt). You can create a hidden volume which is the decoy and a real outer volume which has all your stuff in it. The inner volume is imperceptible because the entire volume is encrypted. And when mounted an observer cannot tell the difference between the hidden volume and the real volume since they are mounted the same way with different passcodes. You can still put files in the decoy and you probably want to put things in there that you would want to plausibly hide but not the things you actually want to hide.

        The same should be true of a duress code in a phone. It should be possible to put files, apps and stuff in the decoy that show activity so a border guard demanding to open the phone sees stuff like email, pictures etc. Providing the other profile is wiped or corrupted while this screen is showing then there is no immediate way of proving it was a duress code.

        It may be necessary to do this similar to VeraCrypt with outer and inner volumes and the means for somebody to occasionally log into the decoy to simulate activity, but that’s the proper way to do this.

      • Typotyper@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        6
        ·
        8 hours ago

        Empty apps or no apps aren’t necessarily a sign of guilt, but they will look at you like you are because its not normal.

        Companies often have travel laptops which are a clean install and no private corporate info exposed.