(Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)
(Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)
Sadly this is automatic, which means regular people can't use it. You workspace admin got to enable MDM, and then phone will prompt you if you want a work profile when you try to install it.
Sadly it doesn't seem to work on all phones.
it works on most flagships nowadays, so if you've got an okay phone, you're likely good
https://informationsecurity.princeton.edu/sites/g/files/toru...
https://www.aclu.org/news/privacy-technology/can-border-agen...
Side note: The sibling comments talk about creating a work profile which is different in that it still lives within the same user account and is not fully isolated.
Setting a duress password is not tedious.
AFAIK the justification for them to say "don't rely on adblockers for security/privacy" is that you can be more easily fingerprinted and those adblock lists are a moving target, vs. having better sandbox capabilities in the browser.
The rest is conjecture I don't have the motivation to debate at the moment.
As for the rest of the article... just get a second phone if this is a major concern, or wipe the phone and have it be perfectly clean when you go through customs. The only thing you need to remember is the password + a single TOTP backup code (write that one down maybe) to restore your cloud password safe (which you should have) then you can get access to all your other data from there.
If they rely on phoning home, such as a comparison of requests on different access, that's some top notch log analysis. Expensive too, compared to just running JS.
There was a lot of talk about duress passcodes several years ago, but I don't think any phones ever got it. Sure would be nice to have
There's no way around the wipe at least and better hope the bugger installed is not persistent in some firmware.
We need a similar solution for UEFI- that allows for truly hidden, foolproof hidden OS installs.