3 ms·
It's a massive swing and a miss that GrapheneOS has a religious opposition to a VeraCrypt-style hidden volume arrangement that allows different passwords to unl
by _2pou 8d ago
It's a massive swing and a miss that GrapheneOS has a religious opposition to a VeraCrypt-style hidden volume arrangement that allows different passwords to unlock different OS volumes.
It would be vastly superior to their current solution, which basically guarantees contempt charges.
I hope they change their mind soon!
- UncleOxidant 8d agoThis. There should be a password that unlocks to a fairly minimal, but not too minimal configuration that wouldn't have anything of interest on it.
- SoftTalker 8d agoWhat do you imagine being on your phone that is "of interest" to CBP at a border crossing?
- projektfu 8d agoPerhaps a screenshot of a politically-incorrect social media post. https://news.ycombinator.com/item?id=49759504 https://news.ycombinator.com/item?id=49759504
- PaulKeeble 8d agoThe problem is it will be detectable and detected and then the password demanded and a failure to provide it will result in charges. I think unfortunately the answer is the phone has to be plausibly empty when crossing the US border, they should focus their efforts on being able to store the full state of the phone remotely and encrypted and being able to restore it easily.
- mixdup 8d agoWould it be detectable to some goon at the border? Probably not. They'd put in the sanitized password, see nothing, and let the person go. If it gets seized and an FBI or CIA analyst gets ahold of it, then yeah the smart guys are going to see it but you'd be in that situation anyway, so why not have an out that may avoid it?
- _2pou 8d agoHidden volumes are impossible to detect, even with the password to the 'clean' volume and full device access.
- Cider9986 8d agoYes. https://news.ycombinator.com/item?id=49399927 https://news.ycombinator.com/item?id=49399927. In the US you don't have key disclosure laws so the best course of action is to shut the fuck up [1]. [1] https://reddit.com/r/funny/comments/olecn5 https://reddit.com/r/funny/comments/olecn5
- _2pou 8d agoHidden volumes are not detectable and impossible to prove, even with the password to the clean volume and device access. That's the entire point.
- kmoser 8d agoMy understanding is that wear-leveling on SSDs leaves forensic traces which allows hidden volumes to be detected.
- slaymaker1907 7d agoThe trick around that is to use some form of oblivious block storage. That would completely remove those traces, though it is very performance intensive to anything obliviously. However, that would clearly make your phone look suspicious from forensic analysis. To counteract that, you have two hidden volumes leaving you with three total systems: your insecure system (first password), the honeypot volume for “clever” actors to find, and then the truly secure volume. I think one honeypot would be ideal. It needs to be convincing and have data that seems sensitive which would take a lot of effort. Put your nude photos there or something.
- Cider9986 8d agoIt's a bad idea because of the increased attack surface even if it was possible and it's not possible according to Veracrypt [1]. It would quickly become a known feature document in guides regularly updated and handed to law enforcement. Forensic tools would also add detections. https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=by%3Agrapheneos%20ssd&sort=byDate&type=comment https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... [1] https://veracrypt.io/en/Wear-Leveling.html https://veracrypt.io/en/Wear-Leveling.html https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Trim%20Operation.html