This won’t stop the cops from hacking into your phone with celebrite, but android has a feature called lockdown mode that will disable facial recognition, fingerprints, and voice ID until your phone is unlocked via PIN. I need to unlock my phone quickly throughout the day, so I use fingerprint - but I use lockdown if I get pulled over or am going through security, etc. It isn’t perfect, but it’s better (for me) than having to enter a long PIN every time I need to unlock my phone.
Once you enable it in settings, you can take your phone to the power off/restart menu and enable lockdown.
Using Tasker, you could probably disable quick unlock when outside of your house, etc.
Do a restart (even if you have to hold the power button for 10 seconds). Because at initial boot state, the contents of your phone are encrypted. Any unlocks after the initial unlock, your phone is decrypted and the key is in RAM. Only a password/pin (no fingerprint/FaceID/etc) can be used to decrypt your data.
In lockdown mode, my understanding is that you’re simply disabling biometrics (but not encrypting anything).
Using lockdown is the same thing as restarting, it puts it into a BFU state.
Evidence/source? My understanding is you inherently cannot go back to BFU (before first unlock) state once you’re in AFU unless you reboot.
Again, I’m not talking about simply disabling biometrics unlock – BFU = your decryption key is not in memory yet (at all).
https://discuss.grapheneos.org/d/14081-what-does-the-lockdown-option-do
this seems to confirm what you’re saying.
Thank you. I say it because I was genuinely asking the person who replied to me, in case I was wrong. In the context of privacy, it’s extremely important to know for sure.
But none of that is going to stop them from detaining you until you give them the pin.
US citizens might have it a little easier. But foreigners are certainly going to regret their choices if anyone ‘close’ to the border has an issue with them.
It’s about USA.
Thanks. I wasn’t planning to go there anyway…
It’s annoying how the title throws such a general open question and then they don’t clarify this at all… there isn’t even a single match for “USA” or “America” in the whole article, you have to sort of guess.
I carry a second phone with nothing on it but pictures taken with my “real” phone and some GPS/Travel apps to look “legit.” Some might think it a bit of a PITA but I bulk edit the EXIF data of photos to say they were taken with the “decoy” phone before transferring them over. Granted, I only cross the border between US/Canada and US/Mexico and turn off and hide my “real” phone before entering the border queue. It has only been an issue once and they took the decoy away for all of 15 minutes while I waited in my truck and then brought it back and said “Thank you for your cooperation, have a nice day” and then I immediately factory reset then wiped it again and installed LineageOS to clear any spyware they might have put on it.
deleted by creator
Use GrapheneOS and switch to PIN authentication didabling fingerprint auth, especially when travelling abroad.
If I had a phone set up like that, and, say, ICE or TSA took it, what would they be able to get from it? And I know that legally they can’t make you give up your PIN, but what’s to keep them from just beating it out of you? Cops of any stripe rarely if ever face consequences for their actions, especially in the US.
Pretty sure they can. Or at least, they can deny you entry into the country if you decline to unlock it for them.
If a government has you in the nebulous situation where you technically aren’t in the country yet and they want your phone, it doesn’t really matter what security system you have on there. You either give them access or go to a black site.
That’s why every company of “moderate” size ends up adopting a policy of “DEVICE for foreign travel”. You don’t take your actual work laptop/phone/whatever. You take a burner (except they hate the term “burner”) that can remote in but stores little to no data locally. And you realize that any good remote access software has logic to detect if you are accessing it from a security checkpoint and flag you…
So what does that mean for you, an individual?
- A super locked down device is just gonna get your ass beat… if you are lucky.
- A completely clean factory wiped device? That is going to raise a bunch of red flags (kind of rightfully) and more or less equate to the above
Like almost all things privacy/security related: Nothing is easy if you actually need it. A good friend of mine is a journalist and they semi-regularly do the kinds of stories that get a person “investigated”. And the reality is that there is nothing they can do, in software, to protect themselves. So what they instead do is have completely separate devices that are never in the same physical location. So, unless they are communicating with a sensitive contact, they always have a device that “looks real” because… it is. Texts from the partner about a dinner party next week, spam from facebook, etc.
And if they need to access something sensitive while on foreign travel or otherwise unable to get back to their “private” devices? Either buy a cheap laptop at a best buy equivalent or use one of their burner emails/accounts.
If I had a phone set up like that, and, say, ICE or TSA took it, what would they be able to get from it?
Depends on what state it’s in. If it’s in lockdown mode, nothing. GOS blocks all access to data via the USB. If it’s unlocked, everything that’s not locked by further authentication.
but what’s to keep them from just beating it out of you
Nothing. That doesn’t mean you should willingly consent to it.
IDKWhatUsernametoPutHereLolol ( IDKWhatUsernametoPutHereLolol@lemmy.dbzer0.com ) English
4·1 year agodeleted by creator
I was concerned about this while crossing the border from mexico this past weekend and pleased that they didn’t even ask any questions just to see passport then through.
Its a great article
deleted by creator







