• GMac@feddit.org
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      5
      ·
      edit-2
      3 days ago

      Loading any profile allows the operating system access to root privileges, and opens potential for user privilege escalation.

      • FauxLiving@lemmy.world
        link
        fedilink
        English
        arrow-up
        16
        ·
        3 days ago

        The profiles are independently encrypted with a key derived from the user’s profile PIN. If the other profiles are not logged in then their keys are not in RAM (and they get zeroed beforehand so they can’t be read out of unallocated memory).

        Even if the bad guys get root via a LPE in a dummy account there are no keys to find and the profiles’ storage are not mounted.

        You couldn’t trust the device after that however, who knows what kind of persistent spyware they could have installed.

        • GMac@feddit.org
          link
          fedilink
          English
          arrow-up
          13
          ·
          edit-2
          3 days ago

          That would be an interesting proposition… under duress load profile x and delete all other profiles, apps, settings and keys.

          • kaotic@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            11 hours ago

            I like this option, save a snapshot and restore that snapshot deleting everything else. So it looks like a regular profile but won’t contain anything you want to remain private.

          • grrgyle@slrpnk.net
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            3 days ago

            Or maybe a lighter version of the duress pin that just loads the fake profile (or alternate profile) but leaves the other(s) intact.

            If you’re just handing your phone over for a border pig to swipe through before waving you through that might be adequate.

            • GMac@feddit.org
              link
              fedilink
              English
              arrow-up
              2
              ·
              2 days ago

              Border pigs have cellebrite, assume they can access anything left intact.

              If it botherw you, wipe it, if it doesnt, you dont really need a duress pin. But login to one profile and cellebrite can get the rest.

            • iopq@lemmy.world
              link
              fedilink
              English
              arrow-up
              5
              ·
              3 days ago

              It depends on whether you believe forensics can recover the data when handed over. So make it a setting

              • grrgyle@slrpnk.net
                link
                fedilink
                English
                arrow-up
                2
                ·
                3 days ago

                Yeah I was thinking of this as a half measure. But less secure than just wiping