More
140 posts
Join Date:Joined: Oct 2015
Less
Okay, I guess I find I'm slowly turning into more and more of a scientist and so I come up with really whacky theories and really whacky ideas of things to try. I'm knowledgeable about security practices, so some things I'd like to see... (I've been on Android 5, so it is possible at least one of these was already added to 7)
Add the ability to make LineageOS demand the device password (or PIN) once per day. Fingerprint readers are handy for quick lock/unlock, but your fingerprints are readily available. If one was to end up in state custody you likely don't want them to access your private data. As such, I'd like the ability for devices to lock once per day and require the password (or PIN) to unlock.
Include some extra support for smart-cards. One neat thing about smart-cards is they're rather more difficult to tamper with than normal data on a phone. If one's phone ended up in the hands of authorities and they really wanted to unlock it, they'd be able to get at the hashes in flash-memory. If the key for encrypting the userdata area was instead stored on a smart-card, they have a great deal more difficulty getting at it.
It would also be interesting to support OpenPGP cards and using a olde phone as an extra layer of security protecting one's PGP keys.
Okay, hopefully not too whacky for you.