@SomeAnoTooter@mastodon.online
2026-09-03 05:25 UTC
Replies (1)
-
@tomgag@infosec.exchange 2026-09-03 09:28
@SomeAnoTooter@mastodon.online @mattblaze@federate.social @GrapheneOS@grapheneos.social before AOSP started to become trash, and Google removed full disk encryption and replaced it with file-based encryption in order to have the LOAD-BEARING feature of alarm clock, screensaver and other LIFE-SAVING amenities even when the phone has just rebooted, it was possible to have TWO unlock mechanisms: one, usually more secure, at boot (e.g., a long passphrase after a reboot), and one, more convenient, for screen unlock (PIN or biometrics). This was very useful if your phone didn't have (or you didn't want to rely on) a TPM, because that's the whole security layer nowadays: a TPM makes guessing even a short PIN unpractical (at the cost of rooting the phone). https://gagliardoni.net/#android_dual_cryptfs_dec_2020 Not a good security model nowadays anyway: PIN + Graphene OS is best we can reasonably get against searches on mobile. Until we get all implanted with mind-controlled chips driving an NFC emitter of course. Looking forward to that!