Hacker News new | ask | show | jobs
by MrDisposable 4 days ago
This is exactly my setup with GrapheneOS. The default / main profile is patriotic, with a sterilized Telegram account, state-adjacent banks and apps, etc. The second profile (that uses a separate PIN) is not so patriotic: it has foreign bank apps, crypto apps, password manager, 2FA app, personal records, and an alternate Telegram account that I use to discuss any potentially unpatriotic topics with potentially unpatriotic people.
4 comments

It would be cool if there's a third PIN that can wipe the unpatriotic profile whilst showing the patriotic one.

So you use 1st pin for normal use, 2nd for downloading your flight details on patriot mode, and 3rd for unlocking to patriot mode whilst silently nuking unpatriotic data.

Or a PIN that just nukes the data for certain apps (Signal, Telegram, WhatsApp, E-mail) etc. Feds can read my Slack messages all day.

Regarding Signal, Telegram, and WhatApp:

1. Never ever have Signal installed on the phone during border crossing. The presence of the app itself may trigger them (speaking from first-hand experience).

2. Having an empty Telegram account may look suspicious. My recommendation is to have two separate Telegram accounts, with the "unpatriotic" one in the separate profile only.

3. Never ever use WhatsApp for anything "unpatriotic". It's way of deleting messages leaves traces ("This message has been deleted") which may rise suspicions.

As for email, I just don't have any email clients installed on my "patriotic" profile. They all go to the "unpatriotic" one.

On Whatsapp, you can "Delete this message for everyone", then "Delete this message for me" and it removes the "This message has been deleted" remnant.
There's no PIN for deleting a particular profile, but you can quickly delete it manually, assuming that you have some private time available – for example, when you are stopped at passport control and told to wait in the waiting area.
They would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security.

Also they can plant evidence if you unlock the phone.

https://nitter.net/GrapheneOS/status/2081471477174456340#m

It would be cool if there's a third PIN that can wipe the unpatriotic profile whilst showing the patriotic one.

So you use 1st pin for normal use, 2nd for downloading your flight details on patriot mode, and 3rd for unlocking to patriot mode whilst silently nuking unpatriotic data in case of seizure.

It's absurd that you have to do this and/or be so careful. But if you live in Russia, China, or another dictatorship, then I understand.
Yep, full agreement here. The amount of hoop-jumping is ridiculous. However, I live in Russia so I have to do all that, plus some more (e.g. the work to protect my own self-hosted VPN after Roskomnadzor issued the recommendation for big Russian online services to sniff out and report user's VPN settings).

I spent two weeks thinking about my new setup on Graphene OS and Windows, but it was time well spent. Before that, my checklist for pre-border-crossing cleanup required about 8 hours of work. With the new setup, I can complete the cleanup in about an hour, and restoring takes even less.