This is exactly my setup with GrapheneOS. The default / main profile is patriotic, with a sterilized Telegram account, state-adjacent banks and apps, etc. The second profile (that uses a separate PIN) is not so patriotic: it has foreign bank apps, crypto apps, password manager, 2FA app, personal records, and an alternate Telegram account that I use to discuss any potentially unpatriotic topics with potentially unpatriotic people.
It would be cool if there's a third PIN that can wipe the unpatriotic profile whilst showing the patriotic one.
So you use 1st pin for normal use, 2nd for downloading your flight details on patriot mode, and 3rd for unlocking to patriot mode whilst silently nuking unpatriotic data.
Or a PIN that just nukes the data for certain apps (Signal, Telegram, WhatsApp, E-mail) etc. Feds can read my Slack messages all day.
1. Never ever have Signal installed on the phone during border crossing. The presence of the app itself may trigger them (speaking from first-hand experience).
2. Having an empty Telegram account may look suspicious. My recommendation is to have two separate Telegram accounts, with the "unpatriotic" one in the separate profile only.
3. Never ever use WhatsApp for anything "unpatriotic". It's way of deleting messages leaves traces ("This message has been deleted") which may rise suspicions.
As for email, I just don't have any email clients installed on my "patriotic" profile. They all go to the "unpatriotic" one.
There's no PIN for deleting a particular profile, but you can quickly delete it manually, assuming that you have some private time available – for example, when you are stopped at passport control and told to wait in the waiting area.
They would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security.
Also they can plant evidence if you unlock the phone.
It would be cool if there's a third PIN that can wipe the unpatriotic profile whilst showing the patriotic one.
So you use 1st pin for normal use, 2nd for downloading your flight details on patriot mode, and 3rd for unlocking to patriot mode whilst silently nuking unpatriotic data in case of seizure.
Yep, full agreement here. The amount of hoop-jumping is ridiculous. However, I live in Russia so I have to do all that, plus some more (e.g. the work to protect my own self-hosted VPN after Roskomnadzor issued the recommendation for big Russian online services to sniff out and report user's VPN settings).
I spent two weeks thinking about my new setup on Graphene OS and Windows, but it was time well spent. Before that, my checklist for pre-border-crossing cleanup required about 8 hours of work. With the new setup, I can complete the cleanup in about an hour, and restoring takes even less.
This is extremely hard to implement in a non-superficial way that would be hard to detect.
Android switched from block device encryption to filesystem-based encryption (with encryption data and metadata). This provides many security improvements, such as per-file encryption keys and per-profile keys.
However, this also means that the main file system is readable and you could enumerate the available users. If you would encrypt/obscure that information, you could still infer the presence of other profiles from file system block allocations.
(Disclaimer: not an expert, but I read the relevant Android docs at some point.)
I had this on a Xiaomi, maybe 10 years ago? Very cool feature! I hope they still do it. I think the wipe feature is also very cool, but not used in this way.
They would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security.
Also they can plant evidence if you unlock the phone.
Ok so what you're saying is Android doesn't have this feature. Xioami does. Type in a different pin and access a second space. Not the same as profiles, obviously
They would like to have something like that but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security.
Also they can plant evidence if you unlock the phone.
And wipes the main partition in the background at the same time
Also too patriotic is sus. Better to keep some minor offenses (that give you a fine or a week of jail at most) on that partition so they will think that this is the thing that made you so nervous during the search