Rooting is now far more difficult unfortunately, and isn't even available mostly; but I don't see a real method to do a full proper image backup of phones today.
139 karma · joined January 3, 2021
In my spare time, I am a bit of a infosec and Privacy geek, constantly exploring what privacy means and how to make private systems and model privacy and security for situations!
Currently delving into Debian playing with things like signing drivers, Secure Boot ,Docker and getting comfy- while also slaying telemetry in Windows for laughs. Also currently picking up Python, having come up on C and Java in the past.
I can be reached (current for June 2025) at lwir dot voltage385@slmails dot com
[I do rotate the contact email i use on Here for privacy/spam reasons every now and then)
[When I respond ,I will email you back from a protonmail email address of mine ]
[Ask me in email for my full non-modified resume!] Here is a modified updated non-full resume link as of June 2025 https://ibb.co/tpqYm7nF
Rooting is now far more difficult unfortunately, and isn't even available mostly; but I don't see a real method to do a full proper image backup of phones today.
But also, things like the hidden OS, or shufflecake - they're building these so they're would be no traces. Which is why I said this sort of thing needs to be standardized - if every phone or device naturally gets extremely high levels of security, and it's built in by default to all of them- it's not unusual anymore, is suspicious. And stems the overall ongoing data collection on everyone that you highlighted.
#1. The download and restore backup method would work for people in general- except it doesn't capture what people would need. Exmaple: I have some thermal cameras that rely on old 32 bit apps that do not run on anything android 12 onwards- If i wipe those old phones, and restore- the apps often wanted to reach out to a server for initial activation- they would fail upon reinstall and i'd be out of the apps that are required to control my cameras and related equipment,which is worth several thousand, and has no equivalent spec wise and form factor today in 2026. And it'd be all dead weight and rendered useless.
( competitors today do not compete now- for example try finding a 640*480 30 hz or better form factor thermal camera that attaches to phones - they dont exist anymore)
\The solution is full imaging- but there isnt a real way to fully image phones and restore backups today. There used to be it seems- but not really with the latest stuff at the time of this post
.
On another note:Veracrypt- The weakness of truecrypt and veracrypt, Their strongest counter, the hidden OS option only worked if you converted your computer to MBR, which means you can't have a hard drive too large. Making a UEFI hidden OS has not been done yet, but all computers are this now.
And the Hidden Volume option- isn't 'as' useful, and of course, your OS might make a copy and put it somewhere, you have to be careful. As a example: Any time I open a file, using the software tool Everything to search and confirm this- you can easily see Windows makes copies and temp files and whatnot in randomly named locations- that's the sort of software and OS behavior that will screw people over.( The year of the Linux desktop isn't here yet..)
Solution:We need fully image-backup capable Phones. I mean fully. Not just backing up some apps- as this refuses to backup apps you have that are no longer on app stores, or that Play Protect doesn't like, etc. We need to be able to fully image a device, a forensic image backup, for phones that people can use, then encrypt and upload so they are good if they lose a phone.
Next- Plausible deniability is a way forward- but you need multiple profiles, that are cryptographically indistinguishable, along with the phone being hardened so GreyKey /Cellebrite won't be able to exploit a way in. This needs to be built this way from the ground up ideally, eventually.
There has been research about making devices that treat all block space the same way so you can't tell if someone has 1, or 50 profiles or partitions, etc- and even stuff that overlaps. Often it needs to be fixed size partitions, but it is apparently NOT impossible to create. I am aware of Shufflecake attempting to make a solution for Linux, and yes, a Hidden OS option that is forensic- invisible.
But nothing has come out yet - and especially, nothing in this vein for phones.
It would be nice to see the day where, if you travel to a hostile country, you can tell them you have just one profile, and if they ask, you could theoretically mention a 2nd, and then show it- but you might have 3 more - and they'd all be immune to forensic inspection if the system is built right.(Yes, there's often issues you have to be careful of ,like setting this up so you dont destroy data when in other profiles, but that's not as important)
This is how you solve this problem in the long run-make computing devices impossible to analyze, but standardized.
A few things:
#1. The download and restore backup method would work for people in general- except it doesn't capture what people would need. Exmaple: I have some thermal cameras that rely on old 32 bit apps that do not run on anything android 12 onwards- If i wipe those old phones, and restore- the apps often wanted to reach out to a server for initial activation- they would fail upon reinstall and i'd be out of the apps that are required to control my cameras and related equipment,which is worth thousands and thousands and thousands. And it'd be all dead weight and rendered useless.
(and competitors today do not compete- for example try finding a 640*480 30 hz or better form factor thermal camera that attaches to phones - they dont exist anymore)
\The solution is full imaging- but there isnt a way to fully image phones and restore backups today. There used to be it seems- but not really with the latest stuff at the time of this post
.
On another note:Veracrypt- The weakness of truecrypt and veracrypt, the hidden OS option only worked if you converted your computer to MBR, which means you can't have a hard drive too large. Making a UEFI hidden OS has not been done yet.
And the Hidden Volume option- isn't 'as' useful, and of course, your OS might make a copy and put it somewhere, you have to be careful. As a example: Any time I open a file, using the software tool Everything to search and confirm this- you can easily see Windows makes copies and temp files and whatnot in randomly named locations- that's the sort of behavior that would screw people over
We need fully image-backup capable Phones. I mean fully. Not just backing up some apps- as this refuses to backup apps you have that are no longer on app stores, or that Play Protect doesn't like, etc.
Next- Plausible deniability is a way forward- but you need multiple profiles, that are cryptographically indistinguishable, along with the phone being hardened so GreyKey /Cellebrite won't be able to exploit a way in. This needs to be built this way from the ground up ideally, eventually.
There has been research about making devices that treat all block space the same way so you can't tell if someone has 1, or 50 profiles or partitions, etc- and even stuff that overlaps. Often it needs to be fixed size partitions, but it is apparently NOT impossible to create. I am aware of Shufflecake attempting to make a solution for Linux, and yes, a Hidden OS option that is forensic- invisible.
But nothing has come out - and especially, for phones.
I hope Graphene OS or another group, eventually works on this for phones. I do wonder if it would require a Linux phone, or something built from the ground up rather than current phone architecture.
It would be nice to see the day where, if you travel to a hostile country, you can tell them you have just one profile, and if they ask, you could theoretically mention a 2nd, and then show it- but you might have 3 more - and they'd all be immune to forensic inspection if the system is built right.(Yes, there's often issues you have to be careful of ,like setting this up so you dont destroy data when in other profiles,)
This is how you solve this problem in the long run-make computing devices impossible to analyze, but standard.
#1. The download and restore backup method would work- except it doesn't capture what people would need. Exmaple: I have some thermal cameras that rely on old 32 bit apps that do not run on anything android 12 onwards- If i wipe those old phones, and restore- the apps often wanted to reach out to a server for initial activation- they would fail upon reinstall and i'd be out of the apps that are required to control my cameras and related equipment,which is worth thousands and thousands and thousands. And it'd be all dead weight and rendered useless.
(and competitors today do not compete- for example try finding a 640*480 30 hz or better form factor thermal camera that attaches to phones - they dont exist anymore)
\The solution is imaging- but there isnt a way to fully image phones and restore backups today. There used to be it seems- but not really with the latest.
Veracrypt- The weakness of truecrypt and veracrypt, the hidden OS option only worked if you converted your computer to MBR, which means you can't have a hard drive too large. Making a UEFI hidden OS has not been done yet.
I am aware of Shufflecake attempting to make a solution.
And the Hidden Volume option- isn't 'as' useful, and of course, your OS might make a copy and put it somewhere, you have to be careful. Any time I open a file, using the software tool Everything to search and confirm this- you can easily see Windows makes copies and temp files and whatnot in randomly named locations- that's the sort of behavior that would screw people over
We need fully image-backup capable Phones. I mean fully. Not just backing up some apps- as this refuses to backup apps you have that are no longer on app stores, or that Play Protect doesn't like, etc.
Next- Plausible deniability is a way forward- but you need multiple profiles, that are cryptographically indistinguishable, along with the phone being hardened so GreyKey /Cellebrite won't be able to exploit a way in. This needs to be built this way from the ground up ideally, eventually.
There has been research about making devices that treat all block space the same way so you can't tell if someone has 1, or 50 profiles or partitions, etc- and even stuff that overlaps. But nothing has come out - and especially, for phones.
After all, if you travel to a hostile country, you can tell them you have just one profile, and if they ask, you could theoretically mention a 2nd, and then show it- but you might have 3 more - and they'd all be immune to forensic inspection if the system is built right.(Yes, there's often issues you have to be careful of ,like setting this up so you dont destroy data when in other profiles,)
This is how you solve this problem -make computing devices impossible to analyze
Open to Remote: Yes
Willing to Relocate: Yes
Technologies: C, Java, Python, RHEL, Operations, Bash, Windows Server, Vmware, VirtualBox ,AIX, , RHEL, Debian ,Docker
Where I come from: I've worked for NASA , as a System Administrator and Operational Test Conductor,helping to run field ops as well as maintain security , provision and administer their launch systems.
I've helped run operations involving multiple sites and multiple groups around the Country to that involved testing aspects of space hardware ,software involving multiple various teams and groups.
I currently am part of the requirement testing process for NASA's Launch Control Software and help design tests,and ensure the software is up to spec , and validate requirements for Artemis 2 and 3 actually putting the software through it's paces.
I'm a team-orientated, friendly, detail focused technologist with a eye towards expanding and delving more into the development side of tech, leveraging my experience in administration and operations over, and getting a little deeper to working with the innards that make things tick and being able to tweak them,.
I can be reached at lwir.voltage385@slmails dot com
Aside from https://web.archive.org/web/20250914062843/https://portswigg... , there haven't been really many goes at going for plausible deniability with modern systems, and I see the segment about a Hidden OS feature in work as well.
Hoping this succeeds. Funny, eventually Shufflecake, after it gets fully capable on Linux, might have to look at making versions for Windows and Mac
But aside from one or two experimental attempts, also presented at BlackHat https://web.archive.org/web/20250914062843/https://portswigg...
- the consumer has nearly lost access to high end plausible deniability
(See: https://old.reddit.com/r/Briar/comments/gxiffy/what_exactly_...
https://news.ycombinator.com/item?id=43363031 }
Anyway, -Question: I take it Murmur is end to end encrypted fully? Also, just curious if this is open source?
This could become SUPER useful- having a actual mesh networking Bluetooth app , if it's open source/E2EE!
Open to Remote: Yes
Willing to Relocate: Yes
Technologies: C, Java, Python, RHEL, Operations, Bash, Windows Server, Vmware, VirtualBox ,AIX, , RHEL, Debian ,Docker
Where I come from: I've worked for NASA , as a System Administrator and Operational Test Conductor,helping to run field ops as well as maintain security , provision and administer their launch systems.
I've helped run operations involving multiple sites and multiple groups around the Country to that involved testing aspects of space hardware ,software involving multiple various teams and groups.
I currently am part of the requirement testing process for NASA's Launch Control Software and help design tests,and ensure the software is up to spec , and validate requirements for Artemis 2 and 3 actually putting the software through it's paces.
I'm a team-orientated, friendly, detail focused technologist with a eye towards expanding and delving more into the development side of tech, leveraging my experience in administration and operations over, and getting a little deeper to working with the innards that make things tick and being able to tweak them,.
Stripped version of my resume at https://ibb.co/tpqYm7nF I can be reached at lwir.voltage385@slmails dot com
Speaking as somebody, who owns some mid-grade thermal cameras that stopped production in the past few years after a decade run, that depended on and are solely controlled and run on apps that were removed from the app store or no longer can run on modern phones because they are in 32-bit format ; this sort of thing would further punish that type of software and only speed up its demise.
When you spend thousands and thousands and thousands and of dollars and resources into getting unique capabilities like that, that can only be controlled through Android apps often, and is the only way to get that capability for some (this will apply to multiple and I imagine with niche capabilities that only have one or two methods of Access)
- this hurts a lot of opportunity, and this type of dark anti-pattern is far too blunt
seeing the latest (leaked?) Cellebrite info from 2024 Summer- BFU State[Before First Unlock state] after posting on, modernimoPuxelsiPhones on the latest OS, and graphene devices see moto be the hardest to get into.
Anyway- , with computers - this was a solved problem from a technical standpoint- Yes I'm talking Truecrypt then, and today Veracrypt. The Hidden Container feature is impressive- but the Hidden OS feature allows for a truly hidden OS behind the scenes that can't be found at all. However, there's a unfortunate weakness that makes this hard to use today- it's limited to MBR , not UEFI [GPT]systems- so unless you like your computer not being able to have more than 2 Tb - and only 4 partitions (so good luck If you do a lot of stuff from dualbooting to other whatnot) We need a Veracrypt Hidden OS equivalent for UEFI systems that's truly undetectable.(That also will work for Linux and maybemeMac not just Windows as Veracrypt currently does - you can only make the Hidden Volumes on the non Windows versions of VC) There was one project to do it - and there were articles and a black hat presentation on 'Russian Doll Steganogrpahy" for a OS- but it didn't go anywhere from what I can tell, and everyone is now wide open .... Unless you have a MBR system. I also think I've heard UEFI is more easily secured than MBR in general and for the foreseeable future...
https://portswigger.net/daily-swig/russian-doll-steganograph...
https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Schaub-Perfectl...
This is an issue I face- I have a collection of thermal cameras that use apps to control them- after every install onto a phone, they then reach out t oa server to authenticate.
Here's the issue- though I have a few older phones- these apps are 32 bit ones, so no modern phone after Android 13 will run them. And they are all now not on the app store anymore,as they all came out about around 2016. i did use a APK extractor to pull the APKs to store them - but the native backup functionality wouldn't capture that authorization in the future, I might rob myself of my ability to use some extremely expensive, and long-term invested capable hardware, by backing up and restoring-
I suspect a full image would solve this problem, but I don't think one can do that outside of things like TWRP- but that requires unlocking the bootloader, and if you do that it wipes your device- AND is more vulnerable to Custom's usage of Cellebrite and etc, to my undertanding.
I don't have this issue with laptops ,as I can fully image them and wipe and restore ahavend have a perfect replica/ no issues. But my thermal cameras do not run off of PC and th eform factor wouldn't work if they did
We need a similar solution for UEFI- that allows for truly hidden, foolproof hidden OS installs.
I don't know if other bootloaders outside GRUB have a silent/hidden start option, as well in a similar vein that would require you to hit a key in that first second to get the menu to appear, or else it just boots up normally
I wonder about the other approach, just going into the BIOS nad changing the order so Windows boots first, which should be doable in some setups. Lock the BIOS with a password, and you're in not bad shape. (Not sure if Secure Boot being enabled could also help here - probably couldn't hurt)
This is an issue I face- I have a collection of thermal cameras that use apps to control them- after every install onto a phone, they then reach out t oa server to authenticate.
Here's the issue- though I have a few older phones- these apps are 32 bit ones, so no modern phone after Android 13 will run them. And they are all now not on the app store anymore,as they all came out about around 2016. i did use a APK extractor to pull the APKs to store them - but the native backup functionality wouldn't capture that authorization in the future, I might rob myself of my ability to use some extremely expensive, and long-term invested capable hardware, by backing up and restoring-
I suspect a full image would solve this problem, but I don't think one can do that outside of things like TWRP- but that requires unlocking the bootloader, and if you do that it wipes your device- AND is more vulnerable to Custom's usage of Cellebrite and etc, to my undertanding.
I don't have this issue with laptops ,as I can fully image them and wipe and restore ahavend have a perfect replica/ no issues. But my thermal cameras do not run off of PC and th eform factor wouldn't work if they did
Here's the issue- though I have a few older phones- these apps are 32 bit ones, so no modern phone after Android 13 will run them. And they are all now not on the app store anymore,as they all came out about around 2016. i did use a APK extractor to pull the APKs to store them - but the native backup functionality wouldn't capture that authorization in the future, I might rob myself of my ability to use some extremely expensive, and long-term invested capable hardware, by backing up and restoring-
I suspect a full image would solve this problem, but I don't think one can do that outside of things like TWRP- but that requires unlocking the bootloader, and if you do that it wipes your device- AND is more vulnerable to Custom's usage of Cellebrite and etc, to my undertanding.
I don't have this issue with laptops ,as I can fully image them and wipe and restore ahavend have a perfect replica/ no issues. But my thermal cameras do not run off of PC and th eform factor wouldn't work if they did
I will probably eventually cave and use my main account from one of those companies since creating true secondary accounts can be difficult(they end up tied back to your main account on the backend usually, So if something happens to one or the company does something- it'll affect everything and building separation is not easy.) - But I dislike that sort of design.
Point taken though , the commenters who said that were ...obviously..anecdotal, -though possibly still more the norm...)
One would hope indeed- I do wonder on that ......
There's another observation though- Salt Typhoon compromised wiretap infrastructure - before Signal, there's no doub't some stuff like this occured over text messages- Because of everyone's efforts to go to Signal- even if it's for the message disappearing- with this, with military branches pushing it hard- with Sweden's Miltary pushing it, etc(for non sensitive stuff)- there's so much of that , that the attack surface overall is massively reduced. In short, if there's going to be stuff outside of vetted systems- running that sort of stuff Signal- likely still helps. (I'm reminded again, of the JD Vance interviews where he let slip that he'd been targeted ,and was informed about it by agencies- but that he was good because of his Signal usage. Now, I don't know what measures he takes to avoid zero day exploits and whatnot- the TLAs would inform him of that- but from what he was saying, it sounds like they were sure he wasn't compromised by that.)
(I'm aware a serious targeted effort would be more intricate than Salt Typhoon/ Trying to use the country's own general Wire tapping capability to target the VP)
Edit: Also, this reveals a bit about psyche- J.D.Vance somewhat ribbed the president- there is probably pressure TO use Signal, so a record of him criticizing the President can't be found out by the President or those more allied with the President who could then start retribution- I imagine dynamics like that, which are human behavior- -ultimately are what absolutely drive all of this.
..I noted Board Games(Secret Hitler, for example) require better opsec. So do card games- it's mindblowing to note this too...
[Main comment by me - technical outlook] This is not a surprise at all- there were reports that the first Trump administration was using Signal to communicate, and that it was a a risk as messages can be totally wiped and not kept for records keeping.
-From an infosec standpoint- this is more notable than I think people are giving it credit- the fact that the Vice President(Well, maybe not him, he notably admittted in interviews during the presidential campaign, that he'd been briefed by three letter agencies on Salt Typhoon tageting him, but that he was secure because he used Signal) - the director of national intelligence- and several others- use Signal.
it's one thing for Congress, Sweden's Military, and apparently our own military branches to push Signal heavily for non-sensitive stuff-
But when those around three letter agencies -and the groups that would be interested in finding compromises- are using it, that screams to me that it's considered not that easy to attack- which is a point towards Signal
So then the final thing to secure are the endpoints- and of course the risk is a zero day exploit targeting someone. As for subtle push app updates by Signal themselves being a vector- i'd think the Open Source nature of the app prevent that - if the infrastructure for pushing updates is open source as well especially.
Again though- if the White House is using Signal- they likely KNOW most of what their own Three Letter agencies can and can't do(to a point)- so when people in the know are using it- that is telling.
A lot of it may be for the auto disappearing messages, admittedly- but that's notable. And yes, I'm aware Mark Zuckerberg has been known to move conversations off of WhatsApp, to Signal - again, maybe for the disappearing messages(and lack of a report function which would send part of a convo to FB/Meta to my understanding)- but possibly, for the security and lack of meta data being better from a attack surface standpoint
500 feet outside was the test i did with a clear sightline- the inside of the plane was not quite as far, but the messages did go through - and we couldn't have passed the phone around when one family member was 5 seats behind me, the next was about 20 rows in front of me
I like the built in Bridge option as well, (when the app communicates over the internet) to help avoid revealing the traffic is Tor traffic.
I have been impressed by the range of Briar- with a clear line of site, easily hundreds and hundreds of feet- i tested it to well over 500 outside- and on the plane , my family was scattered, but that was no issue at all. (More recently though i've detected my own Bluetooth MotoTag trackers from my luggage in Cargo holds while on planes, so Bluetooth indeed works well on planes.)
-I have heard of but have never used BridgeFy, which I know was a well known famous Bluetooth app that competed with Briar in the past. To my understanding it isn't quite as secure or open source.
There is a informative post here https://old.reddit.com/r/Briar/comments/gxiffy/what_exactly_... where a developer noted Briar's capabilities at that time- it seems due to some changes on the OS/phone Hardware end, and whatnot- and due to the phones only passing messages to contact nearby - Briar is not a true mesh networking app. It is a shame- i feel a true Bluetooth mesh networking app would be unstoppable in availability -though it might be a bit of a battery drain.
It is a shame Briar isn't on iOS also -
I also wish Signal would eventually consider communicating over any medium accessible- they would probably run into similar issue Briar has.
What will it take to get a Peer-to-Peer capable Bluetooth/Wifi/Celluar network using/(more possibly in the future)- proper optional mesh networking, Tor capable, VPN friendly, wholly end to end encrypted ,perfect forward secrecy including, fully open source App providing messaging (with the 'accounts' that Briar uses?), for Android and ios?(And Let's throw in PC Mac and Linux, so laptops could have a extremely user friendly user accessible way of doing this as well.)
Better yet, add Calling capability- i don't know how rough doing video calls would be over some methods like modern day Bluetooth- but even a rough capability would be used a little and be worth adding to the collection of things one could do(Briar is only Messaging at the time of this post- which is something notable for sure,as very few apps let you transmit solely thru Bluetooth<I have not heavily looked into the shared Wifi communication abilities of Briar at this point in time> - but more could be added in some form...I observe apps do exist that allow for Bluetooth calling or act like "Bluetooth" Walkie Talkies)
Open to Remote: Yes
Willing to Relocate: Yes
Technologies: C, Java, Python, RHEL, Operations, Bash, Windows Server, Vmware, VirtualBox, RHEL, Debian ,Docker
Where I come from: I've worked for NASA , as a System Administrator and Operational Test Conductor,helping to run field ops as well as maintain security , provision and administer their launch systems.
I've helped run operations involving multiple sites and multiple groups around the Country to that involved testing aspects of space hardware ,software involving multiple various teams and groups.
I currently am part of the requirement testing process for NASA's Launch Control Software and help design tests ,ensure the software is up to spec , and that it meets requirements for Artemis 2; putting the software through it's paces for our ultimate launch (and as the software comes along since future launches such as Artemis 3 and beyond will build directly from this). I'm also currently leading the effort to confirm Artemis 2's data connection links for launch.
I'm a team-orientated, friendly, detail focused technologist with a eye towards expanding and delving more into the development side of tech, leveraging my experience in administration and operations over, and getting a little deeper to working with the innards that make things tick and being able to tweak them,.
Stripped modified version of my resume at https://ibb.co/t3hhyL9
I can be reached at lwir . voltage 385@ slmails dot com (minus spaces)
when they got that court order that wanted them to retain logs, they , challenged it immediately- and the rulingcame down - and they won.
They can no longer be compelled to cooperate in cases of crimes in other countries that match crimes in Swiss laws, as happened here- and this happened because they fought back -it just took time for the ruling to come down.
https://www.msn.com/en-us/money/other/protonmail-wins-privac...
https://protonmail.com/blog/court-strengthens-email-privacy/
So they are in a good position on that aspect -most countries aren't as solid legally.
Open to Remote: Yes
Willing to Relocate: Yes
Technologies: C, Java, Python, RHEL, Operations, Bash, Windows Server, Vmware, VirtualBox, RHEL, Debian ,Docker
Where I come from: I've worked for NASA , as a System Administrator and Operational Test Conductor,helping to run field ops as well as maintain security , provision and administer their launch systems.
I've helped run operations involving multiple sites and multiple groups around the Country to that involved testing aspects of space hardware ,software involving multiple various teams and groups.
I currently am part of the requirement testing process for NASA's Launch Control Software and help design tests ,ensure the software is up to spec , and that it meets requirements for Artemis 2; putting the software through it's paces for our ultimate launch (and as the software comes along since future launches such as Artemis 3 and beyond will build directly from this) I'm also currently working the effort to confirm Artemis 2's communication links for launch!
I'm a team-orientated, friendly, detail focused technologist with a eye towards expanding and delving more into the development side of tech, leveraging my experience in administration and operations over, and getting a little deeper to working with the innards that make things tick and being able to tweak them,.
Stripped modified version of my resume at https://ibb.co/t3hhyL9
I can be reached at lwir . voltage 385@ slmails dot com (minus spaces)
" You can disable the auto-download. Settings > Data and storage > Media auto-download, you can choose what to auto download for mobile data/wifi/roaming."
So, that part is there, but my question is, it's still aissue when they manually download the image, right? Unless something never accepts images from someone they aren't expecting, who 's number or unique created ID has never been seen before