6 ms·
I think that is hard to do securely - wiping the phone implies wiping the keys from secure storage, and those cannot be restored by design.
by ulrikrasmussen 25d ago
I think that is hard to do securely - wiping the phone implies wiping the keys from secure storage, and those cannot be restored by design.
- amenhotep 25d agoThen perhaps this entire security model is less useful for normal people who have to exist in the world than it is for secret agents in movies. If you're carrying around the nuclear secrets on your phone then being able to irrecoverably lock it with a simple button combo when the enemies are about to capture you is great! No matter how many of your limbs they cut off you'll never be able to give up the secrets! In the real world, though, the biggest threat is governments and the biggest interactions with them are planned ones at border security and they're perfectly happy to imprison you if you don't behave in the way they want, so it would really be nice to be able to smoothly and frictionlessly plan ahead for these foreseeable interactions by replacing sensitive data on the phone with uninteresting data that can be fully exposed when you're forced to unlock it, while being able to restore the real data later.
- ulrikrasmussen 25d agoNo it isn't, this is also the security model that prevents those same agents from cloning your phone before giving it back to get access to all services you are logged in to, including any SSH keys or government identity apps you may have installed.
- purpleidea 24d agoIn case you haven't heard, the government is cloning everyone's phones. In theory our hardware and software would protect us, but in practice the phone companies keep it proprietary enough and with enough backdoors and bug doors that Celebrite and similar products can clone almost anything. And cold boot attacks are basically unstoppable and easy to achieve these days too.