@modem_down@beep@Semi_Hemi_Demigod It would be trivially detected by widely distributed standard forensic software including the non-Premium variant of Cellebrite able to run on a laptop.
The point isn’t to make it forensically undetectable, but to prevent the room temperature IQ cop from noticing what happened. If they “unlock” the phone and don’t see anything that looks out of the ordinary they won’t make a big deal out of it and there’s a chance they’ll let you go.
@orclev Standard operating procedure is increasingly to extract data with standard forensics software. If it doesn’t go smoothly then they’ll likely detain people and get experts to deal with it.
It would be trivially detected by widely distributed standard forensic software including the non-Premium variant of Cellebrite able to run on a laptop.
By “duress profile”, I mean that if user has enabled a “duress profile” feature in Settings, then entering the duress PIN would:
Erase (the encryption key for) all profiles and storage outside the duress profile; then
Unlock the duress profile.
So, how would forensic software detect that the unlocked profile is a duress profile?
@modem_down@beep@Semi_Hemi_Demigod The software walks the person using it through enabling Android Debug Bridge and extracting data with it. It’s either not going to work or will be able to see many signs of what happened. GrapheneOS is well known to the forensic data companies and they make a point of trying to support it. They haven’t had much success with locked GrapheneOS devices but they can certainly handle detecting it and detecting if a feature like this was used via ADB.
@modem_down @beep @Semi_Hemi_Demigod It would be trivially detected by widely distributed standard forensic software including the non-Premium variant of Cellebrite able to run on a laptop.
The point isn’t to make it forensically undetectable, but to prevent the room temperature IQ cop from noticing what happened. If they “unlock” the phone and don’t see anything that looks out of the ordinary they won’t make a big deal out of it and there’s a chance they’ll let you go.
@orclev Standard operating procedure is increasingly to extract data with standard forensics software. If it doesn’t go smoothly then they’ll likely detain people and get experts to deal with it.
The room temperature IQ cop is going to plug the phone into a system that will do that forensic detection. Using commercial or special software.
Room temperature IQ cop knows how to plug the cord into the phone and the cord into the laptop.
@[email protected]
By “duress profile”, I mean that if user has enabled a “duress profile” feature in Settings, then entering the duress PIN would:
So, how would forensic software detect that the unlocked profile is a duress profile?
@modem_down @beep @Semi_Hemi_Demigod The software walks the person using it through enabling Android Debug Bridge and extracting data with it. It’s either not going to work or will be able to see many signs of what happened. GrapheneOS is well known to the forensic data companies and they make a point of trying to support it. They haven’t had much success with locked GrapheneOS devices but they can certainly handle detecting it and detecting if a feature like this was used via ADB.