So, doesn't this just mean that border agents will force you to write down your password, key it in themselves to verify that it works, then walk away with the phone to image it?
So, doesn't this just mean that border agents will force you to write down your password, key it in themselves to verify that it works, then walk away with the phone to image it?
My guess is this somehow foils or mitigates the workaround that the Israeli company sold to the FBI after the San Bernadino phone issue.
Edit: No seriously. See https://en.wikipedia.org/wiki/Making_false_statements. Refusing to unlock your device is one thing. Claiming that you did unlock it but in fact just used a "duress passcode" is a lie and can land you in jail.
On the other hand, a "duress fingerprint" that locks out TouchID wouldn't be misrepresenting anything. But it wouldn't surprise me if they could still get you in trouble some other way for knowingly locking out the device after it's been confiscated.
Refusing to unlock your phone would be equivalent. Unlocking fake data would not.
What does work is putting the wrong finger on your sensor until it tells you TouchID is disabled and needs your passcode (which is 5 times) or rebooting your device without logging in.
"I just entered my duress pass code, the device is now wiped".
Can they charge you with destruction of evidence when they have no idea if/what evidence was on the phone?
If you go the US citizen route, be prepared to never get your phone back and many future border crossings to be 4+hr affairs where they confiscate most of your things.
As a US citizen they have to let you in.
True, and of course they can arrest you the instant they let you in.
Can't wait for iOS to have the deniability factor of having different passwords unlock different things :)
For the sensitive stuff, have periods of time that require several computers to solve cryptographic challenges in order to unlock the phone. Some of which may be your friends' devices. If they don't hear from you and your intended hosts in a certain amount of time, phone stays locked.
Or one of the devices can be an NFC or Wifi hotspot in a certain area, and one at home. If you don't reach it, phone stays locked.
Even if you give up all your passwords they can still keep beating you to get the "real" pass.
In this case, a blank phone probably means no entry and not actually harming you. So, there's that, I guess.
And your "solution" is to share this experience with your friends by tying their devices to yours and setting up a device in such a manner that that actor would not be able to verify if they indeed have access to the real data stored on it.
This is a recipe for a one way ticket to a very dark place for you and your friends.
For the most part the number one rule of actual data safety is that never implement protection that would put your well being or the well being of others at risk, unless you are protecting the nuclear launch codes no data is worth being physically harmed for.
What if you’re just protecting the location of your daughter/sister from her physically abusive ex? Not worth enduring some violence for?
The user controls their device to the exact same extent now. You have to trust the apps and OS you use. And iOS isn't exactly open source either.
I am saying the user can choose to select beacons to unlock their phone during a trip somewhere. The user CHOOSES to lock their phone in a way that requires things additional to the password, things that represent having made it safely past the security lol.
To be adequately effective, though, all back-up activities would require the full authentication credentials for all verification factors, which might only be possible with, say, a fingerprint scanner (touchbar) equipped laptop, or additional external hardware peripherals for other types of systems.
Nothing beats a strong password.