cross-posted from: https://lemmy.world/post/49853131

Feels to me like GrapheneOS did exactly what it should, passing the US border test with flying colours!

Funny part about this lawsuit: “With a little planning ahead of time, you can always download the data you need once you get to where you’re going,”

you are viewing a single comment's thread
view the rest of the comments
[–] 165 points 2 months ago (20 children)

this was a streisand effect for me because i didn't have duress password set up on my grapheneos phone (security & privacy => device unlock) before but i do now! :D

  • source
  • hideshow 20 child comments
  • [–] [S] 39 points 2 months ago (15 children)

    best promotion ever haha What is it? FU-123?

  • source
  • parent
  • hideshow 15 child comments
  • [–] 47 points 2 months ago* (14 children)

    I imagine the best duress PIN is something you'd actually see a "normal" person set as a PIN, like their birth year or something innocuous and easy to remember (and easily believed by whoever's demanding your PIN), while their real PIN would be longer or more abstract.

  • source
  • parent
  • hideshow 14 child comments
  • [–] 19 points 2 months ago* (6 children)

    Honestly I would use a stupid basic one that someone might try and use if they were guessing. Like a duress pin of 1-1-1-1, 1-2-3-4 or 2-4-6-8. It gets the people who take the device and then try and break into it without your permission as it's almost certain they will at least try one of those three.

    Worst case scenario they ask you and you say what it is and they give you a blank stare of "really?..." it's not like they wouldn't try a pin you gave them.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 24 points 2 months ago (3 children)

    I don't recommend a duress password of 1-1-1-1, because that could be set off accidentally.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 7 points 2 months ago (1 child)

    Or those common dumb ones could be attempted by someone just trying to snoop on your phone.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 3 points 2 months ago*

    that's sort of the point of it being super basic. The intent is you want it to be tried before they somehow manage to get your actual pin, or give up and try to force you to provide it.

    if they put the pin in before you tell them a pin the argument for destroying evidence is weakened heavily as it isn't a you initiated thing.

  • source
  • parent
  • [–] 3 points 2 months ago (2 children)

    Sounds dumb to give it out, but mine is my normal 8-digit pin, just backwards. It's easy to remember and seems like a legitimate PIN.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 26 points 2 months ago* (3 children)

    On GrapheneOS, you can also set a "second factor PIN" in the unlock settings under "Fingerprint Unlock", so that to unlock your screen you need to first use the fingerprint unlock and then separately enter your PIN. This means BOTH are required every time you unlock. Your phone can't be unlocked unless it's your finger AND unless you enter the PIN that only you know.

    And under the Screen Lock settings you can also enable "Scramble PIN input layout", so that the number buttons on your unlock screen will be out of order, so people watching you or recording you can't just make note of the shape your index finger is making when touching the numbers to unlock your phone(like people looking over your shoulder or recording on store security cameras).

  • source
  • parent
  • hideshow 3 child comments
  • [–] 3 points 2 months ago (2 children)

    What I find foolish is there's no pin only to unlock (no biometrics), but biometrics available when unlocked

    Plenty of my apps have biometric verification I'd love to take advantage of, but I don't need or want one to unlock the phone itself

  • source
  • parent
  • hideshow 2 child comments