cross-posted from: https://lemmy.world/post/49853131

Feels to me like GrapheneOS did exactly what it should, passing the US border test with flying colours!

Funny part about this lawsuit: “With a little planning ahead of time, you can always download the data you need once you get to where you’re going,”

  • jas [they/any]@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    161
    arrow-down
    1
    ·
    2 days ago

    this was a streisand effect for me because i didn’t have duress password set up on my grapheneos phone (security & privacy => device unlock) before but i do now! :D

    • obvs@lemmy.world
      link
      fedilink
      English
      arrow-up
      26
      arrow-down
      1
      ·
      edit-2
      1 day ago

      On GrapheneOS, you can also set a “second factor PIN” in the unlock settings under “Fingerprint Unlock”, so that to unlock your screen you need to first use the fingerprint unlock and then separately enter your PIN. This means BOTH are required every time you unlock. Your phone can’t be unlocked unless it’s your finger AND unless you enter the PIN that only you know.

      And under the Screen Lock settings you can also enable “Scramble PIN input layout”, so that the number buttons on your unlock screen will be out of order, so people watching you or recording you can’t just make note of the shape your index finger is making when touching the numbers to unlock your phone(like people looking over your shoulder or recording on store security cameras).

      • Justifier@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 day ago

        What I find foolish is there’s no pin only to unlock (no biometrics), but biometrics available when unlocked

        Plenty of my apps have biometric verification I’d love to take advantage of, but I don’t need or want one to unlock the phone itself

        • db_null@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          10
          arrow-down
          1
          ·
          1 day ago

          But there is

          Settings > Security & Privacy > Device Unlock > Fingerprint and there you can toggle to use the fingerprint for device unlocking and/or verification in Apps

      • volore@scribe.disroot.org
        link
        fedilink
        English
        arrow-up
        45
        ·
        edit-2
        2 days ago

        I imagine the best duress PIN is something you’d actually see a “normal” person set as a PIN, like their birth year or something innocuous and easy to remember (and easily believed by whoever’s demanding your PIN), while their real PIN would be longer or more abstract.

        • Pika@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          19
          ·
          edit-2
          2 days ago

          Honestly I would use a stupid basic one that someone might try and use if they were guessing. Like a duress pin of 1-1-1-1, 1-2-3-4 or 2-4-6-8. It gets the people who take the device and then try and break into it without your permission as it’s almost certain they will at least try one of those three.

          Worst case scenario they ask you and you say what it is and they give you a blank stare of “really?..” it’s not like they wouldn’t try a pin you gave them.

          • obvs@lemmy.world
            link
            fedilink
            English
            arrow-up
            21
            ·
            2 days ago

            I don’t recommend a duress password of 1-1-1-1, because that could be set off accidentally.

            • Pika@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              edit-2
              10 hours ago

              that’s fair, I don’t know if graphene supports press enter to submit but, I usually have that setting enabled on my devices

              • Pika@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                3
                ·
                edit-2
                9 hours ago

                that’s sort of the point of it being super basic. The intent is you want it to be tried before they somehow manage to get your actual pin, or give up and try to force you to provide it.

                if they put the pin in before you tell them a pin the argument for destroying evidence is weakened heavily as it isn’t a you initiated thing.

        • ITGuyLevi@programming.dev
          link
          fedilink
          English
          arrow-up
          3
          ·
          1 day ago

          Sounds dumb to give it out, but mine is my normal 8-digit pin, just backwards. It’s easy to remember and seems like a legitimate PIN.

          • Pika@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            2
            ·
            edit-2
            10 hours ago

            that would throw me for a loop longer than I would like to admit, it took me like 10-15 seconds to process what mine would be backwards and mine is only 4 digits lmao