View Single Post
Estel's Avatar
Posts: 5,028 | Thanked: 8,613 times | Joined on Mar 2011
#1173
Originally Posted by Saturn View Post
On the other hand, if the phone can be unlocked by just changing the SIM why did you put the lock code in the first place?
Because data from mounted TrueCrypt partition are accessible to everyone, even the thief - and we need it to be mounted, to allow normal usage (so, for example, our SMS'es, mails, contacts, photos work as usual, despite being on encrypted partition).

Yet, when lock code kick in, someone need to turn device off to remove lock code - either by flashing, or *if* SMSCON option would work like we expected it to (so, changing simc would disable lock code). This (reboot) makes truecrypt partition unmounted again, with password/keyfiles prompt on new boot.

This way, if someone boot my device, but fail to provide lock code and keyfiles, she/he is presented with device without my contacts, messages, mails, passwords, etc.

Originally Posted by foobar View Post
My idea is this:
* set a lock code in the settings, but disable autolock (which includes boot-time check)
* at boot time, have smscon check for SIM change
* if known SIM found, enable autolock (if wanted), possibly checking lock code before continuing boot process
* if unknown SIM found, keep locking disabled (if wanted)

* at shutdown, have smscon disable autolock so the lock code is not checked by the system at next boot

A thief, after changing the SIM, would not be asked for the lock code and (hopefully) would not flash the device. We could try to recover it using smscon. Our data is hopefully encrypted and safe.
Does that make any sense?
It makes sense, but suffer form what I've written above - this way - without lock code kicking in every few minutes, our encrypted, yet mounted TrueCrypt partition's content is exposed to everyone.
---

I just hope, that we'll be able to found a way, that will address people that, at the same time. care about their private files/contacts/etc, and value their device.

/Estel
__________________
N900's aluminum backcover / body replacement
-
N900's HDMI-Out
-
Camera cover MOD
-
Measure battery's real capacity on-device
-
TrueCrypt 7.1 | ereswap | bnf
-
Hardware's mods research is costly. To support my work, please consider donating. Thank You!
 

The Following User Says Thank You to Estel For This Useful Post: