you are viewing a single comment's thread
view the rest of the comments
[–] 25 points 1 day ago (2 children)

@modem_down @beep @Semi_Hemi_Demigod It would be trivially detected by widely distributed standard forensic software including the non-Premium variant of Cellebrite able to run on a laptop.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 35 points 1 day ago (2 children)

    The point isn't to make it forensically undetectable, but to prevent the room temperature IQ cop from noticing what happened. If they "unlock" the phone and don't see anything that looks out of the ordinary they won't make a big deal out of it and there's a chance they'll let you go.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 11 points 1 day ago*

    The room temperature IQ cop is going to plug the phone into a system that will do that forensic detection. Using commercial or special software.

    Room temperature IQ cop knows how to plug the cord into the phone and the cord into the laptop.

  • source
  • parent
  • [–] 6 points 21 hours ago (1 child)

    @GrapheneOS@grapheneos.social

    It would be trivially detected by widely distributed standard forensic software including the non-Premium variant of Cellebrite able to run on a laptop.

    By "duress profile", I mean that if user has enabled a "duress profile" feature in Settings, then entering the duress PIN would:

    1. Erase (the encryption key for) all profiles and storage outside the duress profile; then
    2. Unlock the duress profile.

    So, how would forensic software detect that the unlocked profile is a duress profile?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 12 hours ago

    @modem_down @beep @Semi_Hemi_Demigod The software walks the person using it through enabling Android Debug Bridge and extracting data with it. It's either not going to work or will be able to see many signs of what happened. GrapheneOS is well known to the forensic data companies and they make a point of trying to support it. They haven't had much success with locked GrapheneOS devices but they can certainly handle detecting it and detecting if a feature like this was used via ADB.

  • source
  • parent