cross-posted from: https://lemmy.world/post/49853131

Feels to me like GrapheneOS did exactly what it should, passing the US border test with flying colours!

Funny part about this lawsuit: “With a little planning ahead of time, you can always download the data you need once you get to where you’re going,”

  • jas [they/any]@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    131
    ·
    23 hours ago

    this was a streisand effect for me because i didn’t have duress password set up on my grapheneos phone (security & privacy => device unlock) before but i do now! :D

    • obvs@lemmy.world
      link
      fedilink
      English
      arrow-up
      18
      ·
      edit-2
      9 hours ago

      On GrapheneOS, you can also set a “second factor PIN” in the unlock settings under “Fingerprint Unlock”, so that to unlock your screen you need to first use the fingerprint unlock and then separately enter your PIN. This means BOTH are required every time you unlock. Your phone can’t be unlocked unless it’s your finger AND unless you enter the PIN that only you know.

      And under the Screen Lock settings you can also enable “Scramble PIN input layout”, so that the number buttons on your unlock screen will be out of order, so people watching you or recording you can’t just make note of the shape your index finger is making when touching the numbers to unlock your phone(like people looking over your shoulder or recording on store security cameras).

      • Justifier@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 hours ago

        What I find foolish is there’s no pin only to unlock (no biometrics), but biometrics available when unlocked

        Plenty of my apps have biometric verification I’d love to take advantage of, but I don’t need or want one to unlock the phone itself

        • db_null@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 hour ago

          But there is

          Settings > Security & Privacy > Device Unlock > Fingerprint and there you can toggle to use the fingerprint for device unlocking and/or verification in Apps

      • volore@scribe.disroot.org
        link
        fedilink
        English
        arrow-up
        34
        ·
        edit-2
        21 hours ago

        I imagine the best duress PIN is something you’d actually see a “normal” person set as a PIN, like their birth year or something innocuous and easy to remember (and easily believed by whoever’s demanding your PIN), while their real PIN would be longer or more abstract.

        • ITGuyLevi@programming.dev
          link
          fedilink
          English
          arrow-up
          3
          ·
          8 hours ago

          Sounds dumb to give it out, but mine is my normal 8-digit pin, just backwards. It’s easy to remember and seems like a legitimate PIN.

        • Pika@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          13
          ·
          edit-2
          15 hours ago

          Honestly I would use a stupid basic one that someone might try and use if they were guessing. Like a duress pin of 1-1-1-1, 1-2-3-4 or 2-4-6-8. It gets the people who take the device and then try and break into it without your permission as it’s almost certain they will at least try one of those three.

          Worst case scenario they ask you and you say what it is and they give you a blank stare of “really?..” it’s not like they wouldn’t try a pin you gave them.