How hard would it be to admin-allow some apps to work across barriers. E.g., wallet apps work, airline tickets work, but email/socials do not.
the issue is that when a phone is unlocked, they can just plug in a USB device and scrape everything off it. The TSA agent may not be eyeballing a facebook account so much as plugging in an exfiltration software stack or malware.
That's useless if the backup account and the main account use different keys for the home partition.
VeraCrypt (used to?) have this. It was called a hidden volume. One volume, but two keys, two passwords, and two different containers full of data. Technically, the second volume is written into the partition "from the back" using key 2, while the first volume is written "from the front" using key 1.
Fun fact, there's no protection against writing over data in the other volume if volume 1 + volume 2 exceed the size of the partition - and there can't be, otherwise the volume wouldn't be hidden.
https://nitter.net/GrapheneOS/status/2082153517234676150#m
A pin that boots into a dummy account, full of benign messages, photos, innocent web browsing, etc. is going to get you a pass. They'll flip through everything and get bored after a minute of not finding anything.
Far less likely to aggravate them than wiping your phone
It's not possible unfortunately due to low level SSD architecture[1] and other reasons:
https://nitter.net/GrapheneOS/status/2082153517234676150#m
Then have some planned means of restoring the backup when it's safe to do so.
Being caught with a honeypot looks much worse than being caught with a new phone. You can always say you bought a cheap "travel" phone if asked.
Good times.
https://nitter.net/GrapheneOS/status/2082153517234676150#m
https://nitter.net/GrapheneOS/status/2082153517234676150#m