See the below news article for context. It’s an admirable general security feature.
Yes and no.
You have a Guest user you can present to a searching agent.
There is also a setting to enable maximum failed attempts to unlock.
Some models (JP26) have a Factory Reset featue. You could come up with a way to trigger that in a panic situation (e.g. by putting it on the Lock Screen as a favorite).
You could also forcefully overwrite the beginning of the encrypted partition to destroy the keys stored there.
GrapheneOS has this duress password.
I don’t understand the use case.
If you’re an actual trafficker and need a solution in case you’re arrested in the middle of the day, this isn’t a phone for you.
If you’re a regular citizen, using the duress password will put you in big trouble with the authorities, plus it will destroy your vacation pictures forever. Just take an empty phone with you for the travel and upload your data to the cloud before reaching the airport. Wipe the phone from the hotel when everything is safe in the cloud, don’t wipe it in front of the Customs officers.
does somebody know what /usr/lib64/sailfish-devicelock/plugins is for?
would be pretty to have a duress pin that provides /home_encrypted_clean.img instead of /home_encrypted.img and then reboots, providing “clean” desktop for an eager border agent.
PS And no, it’s not some distant threat, it’s happening in many places and will happen more frequently.
you know the famous quote by Ben Franklin, right? Regular citizens have less and less freedoms with each passing year all in the name of children/safety/you-name-it.
…and it will only get worse. In the name of democracy.
imagine you are a political dissident or journalist, and your phone contains photos or info that may be opposed by the current political regime.
yea, you can get in trouble doing this, but you could, potentially, get into more trouble not doing it. the feature could be refined to give plausible deniability, like deleting only certain things like photos and e2ee chat logs (signal/etc).
yes, super evil people could use this feature too, but they can use any feature. i suspect that the criminals that are interested enough in cyber security would leave their crimes on their phone when crossing borders anyway.
your argument boils down to “if you are innocent you have nothing to hide”, which is, in a word, incorrect
https://en.wikipedia.org/wiki/Nothing_to_hide_argument
Bad guy steals your phone.
Discovers pin number in the phone’s case.
Types it in.
I don’t think it’s a compelling usecase but I can kinda understand it.
The use case isn’t limited to border incidents. Duress can present itself to you in the form of thieves or kidnappers who want access to your phone. Your phone which has data that may lead people to your loved ones, your client’s data, your employer’s data, etc.
As for the border scenario, it’s questionable whether the law criminalizes wiping the phone in this context. The article cites the opinion of experts that this may be a novel case.
It must also be said that it’s not against the law to build a phone with a wipe feature. And if the user commits an illegal act with the phone, the responsibility lies with the user, not the manufacturer. Fraud is committed over voice calls and text every day, but I see no one proposing to get rid of cellphones.
Lastly, history has shown (and is now showing) that not all laws are just. A great many horrors have throughout history been conducted under the umbrella of the law.
No that was a misunderstanding. I did not and do not advocate for showing the data to the authorities. I advocate (as mentioned in my message) to husband your data in a way you don’t have to use a duress password.
@J_Blend paints it as “an admirable general security feature”. Which it isn’t, it is a corner case. An overwhelming majority of users will never be remotely in the situation of using a duress password.
My advice to journalists and dissidents was in my first message. I’ll reformulate for easier reading:
- As shown in the link showed by @J_Blend, DO NOT USE THE DURESS PASSWORD, it will put your life in jeopardy. Instead, backup your contents to some cloud from the hotel (most countries have some sport of cloud access, even if a local anonymous email) and wipe your phone yourself before leaving to the airport. That way you don’t have to use the duress password, you give the normal password and the phone is clean.
- If you leave in the dangerous country permanently, consider alternatives. SFOS just wasn’t designed to protect dissidents from a hostile government.
From @moripeluka:
“An overwhelming majority of users will never be remotely in the situation of using a duress password.”
This is mere wishful thinking. It’s not a valid reason to fail to offer the feature.
“It will put your life in jeopardy.”
Not in all cases. And more lives than yours may be in jeopardy without it. If someone threatened take my life if I didn’t divulge my family’s data, then they’ll just have to take my life.
“Instead, backup your contents to some cloud from the hotel (most countries have some sport of cloud access,”
I won’t ever again enter the US with a mobile device of any kind. But neither this nor your proposal is a valid reason for refusing to develop a duress password.
“SFOS just wasn’t designed to protect dissidents from a hostile government.”
As mentioned, it’s not merely about dissidents. And that’s not a valid excuse for failing to develop a duress password.
I see no valid arguments here for failing to develop a duress password. Even ATMs have them. And a phone password can cough up a lot more than an ATM:
If you personally don’t want to use a durress password on Sailfish OS, then don’t. What difference does it make to you that others want to?
I won’t ever enter the US period. But it doesn’t change the fact that I think a duress password is a great idea - just because the government in my country isn’t hostile like theirs doesn’t mean things will remain that way. Just because I’ve never been robbed doesn’t mean it will remain that way.
Unfortunately, the world is becoming more and more unpredictable every day. I agree - having options is a nice thing.
I’m not against the feature. What I said, my first words, is that I don’t understand the use case for practical, existing SFOS users. I don’t think any of traffickers, spies, human right activists, journalists are using a Jolla phone.
SFOS is a hackable linux phone. Someone is making small musical instruments out of it, and others want to implement long-range walkie-talkie radiocommunications with a TOH attachment. It’s a great phone for hobbyists living in Europe. It enables fun electronics project, and SFOS also allows you to protect your privacy from GAFAM.
It’s not currently workable for activists. If the phone falls into the wrong hands, they don’t need to torture you for the lock code; they’ll break it: put the phone in recovery mode, extract a few bytes from the LUKS partition, and crack the encryption offline. If you’re using a 6 digit code, it’s broken in a second. Those companies that produce spying software probably implemented an automated workflow in their tools.
Now you can embrace my argument and say, indeed it’s not for existing SFOS users, it’s the first of a series of functionalities that would make SFOS more secure against hostile governments, and would enable Jolla to market the phone for journalists going to dangerous countries. I’m happy about that, but that isn’t a possible market. A Jolla-made phone is even difficult to make work in the USA (blacklisted by the operators). Someone said Sony Xperias are going to stop working in Australia because they blacklist phones not sold in the countries. What are your hopes to make it work in, say, Afghanistan, If you want to make a discreet human rights documentary? If you’re into this sort of things, you need to stay low profile and blend. Just take a common Android model and put Graphene on it.
Again, I’m not against extending the functionality to security, and here’s a list:
- integrate the patch that enables the lock code to be different than the encryption password. Such that we can use a complex encryption password that resist cracking, and a simpler lock code.
- make the passkey screen display more characters. Use the whole screen! Constantly swapping between the character screen and the symbol screen is cumbersome, so we can’t really use complex passwords.
- duress password…
not gonna work on community ports like Nagara. LUKS password is different from PIN.
So everything else is moot.
“SFOS is a hackable linux phone.”
What phone in the world, irrespective of the OS, isn’t hackable by somebody in the world? I don’t believe such a thing exists.
So unless you can point me to an impervious mobile OS and device config, we’re obviously talking about tiers of opsec that can be applied against various types of threats. I still see no reason to argue against the implementation of a duress password on SFOS that will frustrate all but top tier talented threats.
On the other hand: if you’re saying that it’s impossible for SFOS to include an effective duress password feature that will wipe the phone, because irrespective of the phone being wiped in such a manner, there’s something about SFOS and/or the Jolla phone that enables an actor to nevertheless acquire the data from the phone even after it’s wiped… then many thanks for pointing out the limitations of SOFS/Jolla vs. Graphene/Pixel, and I’ll withdraw my interest in SFOS and the Jolla phone until such time, if ever, that changes.
Are you saying that?
We need such a feature but one that loads some default content for plausible deniability to not get in trouble like the guy from the original article.
It’s not reasonable for Sailfish to guarantee that the use of a duress password will never confiict with the laws of any jurisdiction. I don’t propose that, and would argue against such a proposal.
The user should assume the risk of using a duress password.
We already have call recording, which also is illegal in some places, and needs informed consent in others - Jolla doesn’t guarantee that it is always legal.
Did anyone say anything else?
That sounds like what user switching, that we already have. Just some tweaking on how it is triggered…
You can (or will soon be able to) probably just plug in ‘rm -rf /home/defaultuser’ to the privacy switch, see The free association Privacy Toggle thread for community exploration of that feature. If you really need such a crucial ‘security feature’ and cross US border that often with incriminating data on your phone that it’s a must-have, I would not advise it by any chance. By ‘hackable’ moripeluka meant it’s user hackable, you can create any systemd service you want that will for example watch dbus signals after proper pin entry and then trigger self-destruct if you don’t do a weird combo of two bottom swipes then from the right and vol-down, it’s your choice and enjoy losing your data if you misswipe, but here you have root and full control, unlike on graphene where the duress pin is the only way and so well known guy is in trouble, with that hypothetical systemd watchdog the guy could claim: welp it broke, it’s linux
Edit: and it doesn’t have to self-destruct, you could overwrite the messages db with pre-prepared one to not make it obvious, sky’s the limit, like with zombocom you can do anything with root and a linuxbox (and instead of swipes could be a fake bt/wifi toggle, whatever, also you would be giving them real pin so that should help in court too (or if they force your finger), concentrating on duress pin because that one android rom has it is useless)