this post was submitted on 26 Jul 2026
618 points (98.3% liked)

Technology

87649 readers
3291 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] arc99@lemmy.world 29 points 1 month ago (8 children)

If the duress pin makes obvious it's the duress pin then it's not really doing its job. It should instead open a profile with not much in it while erasing the other profile and files in the background.

[–] tutter@lemmy.blahaj.zone 5 points 1 month ago* (last edited 1 month ago) (7 children)

They asked to unlock his phone, he entered the wipe instead personal pin, and the wipe starts, with no possible reversal.

I mean yeah they discover it when he hands them the phone and it shows something other than an unlocked screen... But he is still in detention? Making a fake homescreen will fool them for like 30 secs tops until they open literally any app and sees it's either completely empty or that it doesn't work.

What would that solve? It just drags out the procedure

[–] arc99@lemmy.world 9 points 1 month ago* (last edited 1 month ago) (5 children)

The purpose of a duress code is plausible deniability.

There is an encryption product for Windows called VeraCrypt (aka TrueCrypt). You can create a hidden decoy volume inside an outer encrypted volume which has all your stuff in it. When mounted an observer cannot tell the difference between the hidden volume and the real volume since they are mounted the same way with different passcodes. You can put files in the decoy for plausibility but not the things you actually want to hide.

The same should be true of a duress code in a phone. It should be possible to put files, apps and stuff in the decoy that show activity e.g. email, pictures etc. Providing the other profile is wiped while this screen is showing then there is no immediate way of proving it was a duress code.

It would have to at least convince the border guard, but it should withstand forensic analysis too. So it might be necessary to do what VeraCrypt does.

[–] tutter@lemmy.blahaj.zone 4 points 1 month ago* (last edited 1 month ago)

Lol that's just str8 false in this case, the stated purpose of the duress pin in the article is a system wipe, not plausible deniability.

So whoever has you under duress cannot steal your data

It's not a 'get out of duress free'-card

load more comments (4 replies)
load more comments (5 replies)
load more comments (5 replies)