Copying from another comment I made on this:
#1. The download and restore backup method would work for people in general- except it doesn't capture what people would need. Exmaple: I have some thermal cameras that rely on old 32 bit apps that do not run on anything android 12 onwards- If i wipe those old phones, and restore- the apps often wanted to reach out to a server for initial activation- they would fail upon reinstall and i'd be out of the apps that are required to control my cameras and related equipment,which is worth several thousand, and has no equivalent spec wise and form factor today in 2026. And it'd be all dead weight and rendered useless.
( competitors today do not compete now- for example try finding a 640*480 30 hz or better form factor thermal camera that attaches to phones - they dont exist anymore)
\The solution is full imaging- but there isnt a real way to fully image phones and restore backups today. There used to be it seems- but not really with the latest stuff at the time of this post
.
On another note:Veracrypt- The weakness of truecrypt and veracrypt, Their strongest counter, the hidden OS option only worked if you converted your computer to MBR, which means you can't have a hard drive too large. Making a UEFI hidden OS has not been done yet, but all computers are this now.
And the Hidden Volume option- isn't 'as' useful, and of course, your OS might make a copy and put it somewhere, you have to be careful. As a example: Any time I open a file, using the software tool Everything to search and confirm this- you can easily see Windows makes copies and temp files and whatnot in randomly named locations- that's the sort of software and OS behavior that will screw people over.( The year of the Linux desktop isn't here yet..)
Solution:We need fully image-backup capable Phones. I mean fully. Not just backing up some apps- as this refuses to backup apps you have that are no longer on app stores, or that Play Protect doesn't like, etc. We need to be able to fully image a device, a forensic image backup, for phones that people can use, then encrypt and upload so they are good if they lose a phone.
Next- Plausible deniability is a way forward- but you need multiple profiles, that are cryptographically indistinguishable, along with the phone being hardened so GreyKey /Cellebrite won't be able to exploit a way in. This needs to be built this way from the ground up ideally, eventually.
There has been research about making devices that treat all block space the same way so you can't tell if someone has 1, or 50 profiles or partitions, etc- and even stuff that overlaps. Often it needs to be fixed size partitions, but it is apparently NOT impossible to create. I am aware of Shufflecake attempting to make a solution for Linux, and yes, a Hidden OS option that is forensic- invisible.
But nothing has come out yet - and especially, nothing in this vein for phones.
It would be nice to see the day where, if you travel to a hostile country, you can tell them you have just one profile, and if they ask, you could theoretically mention a 2nd, and then show it- but you might have 3 more - and they'd all be immune to forensic inspection if the system is built right.(Yes, there's often issues you have to be careful of ,like setting this up so you dont destroy data when in other profiles, but that's not as important)
This is how you solve this problem in the long run-make computing devices impossible to analyze, but standardized.
> 640*480 30hz or better form factor thermal camera that attaches to phones - they dont exist anymore
Huh. ITAR?
> It would be nice to see the day where, if you travel to a hostile country,
...or, returning to one.
We tech guys keep thinking of tech solutions, but as someone who reluctantly has to cross a border of an even more hostile country every now and then, you have to remember that border agents are not stupid and will mark you as suspicious if your open profile does not look real enough or there are traces of encryption on the device (when they connect the phone to forensic tools, they can easily see if something looks off). Being paranoid about security is a huge red flag.
The only thing you can do is travel with a clean device on which you maintain a completely innocuous social presence, such as chats with parents and non-foreign friends, and some social media with normie activity. Even that would not be enough if you're an activist or otherwise personally targeted, as your real accounts are already known in that case and your only option is not to travel at all, but it reduces your chances of getting in trouble (or arrested, depending on the target country). Though it still won't help in the long run as security services collect and organize more and more data about everyone.