The foundation behind the ultra-secure Android-based OS is speaking out after an activist was indicted for using a ‘duress password’ to prevent federal agents from searching his phone.
The foundation behind the ultra-secure Android-based OS is speaking out after an activist was indicted for using a ‘duress password’ to prevent federal agents from searching his phone.
Yes, how it currently works. But you could do a targeted wipe of the profile and leave the rest of the phone untouched with a secondary profile. Here’s one such discussion from a year ago warning of basically exactly this happening: https://discuss.grapheneos.org/d/21122-setting-up-a-secondary-passcode-that-opens-a-dummy-profile
That would reduce the security of the duress pin significantly, and would require rewritting how the feature works in the first place.
The duress pin shreds the decryption keys to the entire OS, which is much much faster than erasing the data itself, and arguably more secure. If you’re worried about getting caught wiping the device, just don’t wipe it. There is no known way to get into a phone running an up to date GrapheneOS install (or anything post Q3 2022) unless you have significantly reduced the security of the phone.
Android supports per profile encryption. You can just erase the encryption keys for the other profile.
That’s not the point of the duress pin.
Deleting the owner profile in the first place would make the device unusable for the same reasons you can’t end the owner session and go to another profile. If your data is in a secondary profile, so you can delete it without compromising the integrity of the OS, you can make your own profile duress feature by using an app with device admin to wipe the device (which will only wipe the profile) when you trigger it. There are plenty of duress keyboards with this feature.