Hacker News new | ask | show | jobs
by Condition1952 963 days ago
>I had to give up any passwords to my devices. It was a criminal offence not to do this.

It is a real atrocity that most devices are unable to lie for us when a wrong password is typed and create a mock profile to waste time

5 comments

You can absolutely do this with Xiaomi phones. You can set up a second password in order to access what is virtually a completely different phone.

You can even set a different fingerprint so that different fingers unlock different profiles.

The feature is called Second Space

Somehow, I find it ironic that you have to buy a Chinese phone to get this feature.
I believe some Android ROMs do come with passwords that when entered wipe out everything on the device.
This is possible on many devices.

Though I’m not sure I want it.

The possibility of no-trace hidden partitions I can’t disprove the existence of does not seem like it would serve me well in the backroom of some government facility where my rights have been revoked.

"Here's my unlocked phone, officer!" - "There are no calls, emails or any history in this phone. Are you claiming you have not used this phone to call anybody or interact with any social media?" - "Yes, officer, I never did!" - "Excellent, here are records from your phone company, showing this phone ID making $CRAPTON of calls, and here are records from social media companies showing the IP assigned to this phone accessing your accounts. You just lied to a government agent, and we have a proof of it right here with us, we don't even have to do any work for it. Welcome to hell!".

Or, if you get smart - "Oh yes, officer, I did, but I just reset this phone this morning, because I forgot the password!" - "Too bad, but then you won't object us seizing this phone for further investigation, given that there's nothing on it. There's nothing on it, right? No tricky OSes, no double partitions, no secret codes, nothing like that?" - "Oh yes, officer, absolutely nothing like that!" - "OK, our forensic team would be glad to hear that". In a week: "Our forensic team discovered the presence of Hide My Real Data Super Secure Double Password Toolkit on the phone. You have lied to a government agent and now are under indictment for it. Welcome to hell!".

the only software I recall doing this was TrueCrypt?
You can get sort of a hidden volume by messing with the alignment of a LUKS partition as well.

However, it may not be very smart to do this. Law enforcement aren't dumb, they'll see the signs of your hidden partition, and you can end up in prison for up to two years for your little stunt.

Unless you're hiding something much more incriminating, cooperation is probably your best bet.

I think the most self-respectful and secure way is to have some encrypted cloud in a jurisdiction which doesn't cooperate with the country you afraid of. Wiping all data from the device and restoring it back after border control.

Hidden partition are definitely more dangerous. Also if these people took your device out of your view point, you need to sell the device and buy a new one before restoring anything.

but this still requires trusting a third party to not change their policies, or to not be hacked or coerced into releasing the data and a myriad other options that a state-backed actor has at their disposal
GrapheneOS has profiles, maybe that's the key. Google refuses to sell me a Pixel, though and I got tired
What do you mean "google refuses to sell me a Pixel?"