• arc99@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    25 minutes ago

    The purpose of a duress code is plausible deniability.

    There is an encryption product for Windows called VeraCrypt (aka TrueCrypt). You can create a hidden decoy volume inside an outer encrypted volume which has all your stuff in it. When mounted an observer cannot tell the difference between the hidden volume and the real volume since they are mounted the same way with different passcodes. You can put files in the decoy for plausibility but not the things you actually want to hide.

    The same should be true of a duress code in a phone. It should be possible to put files, apps and stuff in the decoy that show activity e.g. email, pictures etc. Providing the other profile is wiped while this screen is showing then there is no immediate way of proving it was a duress code.

    It would have to at least convince the border guard, but it should withstand forensic analysis too. So it might be necessary to do what VeraCrypt does.