Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Maybe also shows that the duress PIN feature could be implemented better. Booting into a completely fresh phone is suspicious. There also shouldn't be any visual or other indicators of that happening.

In the old TrueCrypt containers you could set an optional second password that would decrypt a different volume. The size of the container file was always the same, a decrypted volume always showed the full container size, the portion not occupied by the data in the main volume was filled with noise, and the data on the non-loaded volume was not protected (so you could erase it without warning by storing too much on the loaded volume), making it practically impossible to prove the existence of a second volume either way in a search situation. I guess there was a reason why the project was stopped.



Not possible to be robust unfortunately due to low level SSD architecture[1] and other reasons:

https://nitter.net/GrapheneOS/status/2082153517234676150#m

[1] https://veracrypt.io/en/Trim%20Operation.html

https://veracrypt.io/en/Wear-Leveling.html




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: