GrapheneOS Now Supports a Duress Reset PIN (grapheneos.social)
from aa1@lemm.ee to privacy@lemmy.ml on 03 Jun 2024 21:50
https://lemm.ee/post/33731911

GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).

The wipe does not require a reboot and cannot be interrupted. It can be set up at Settings > Security > Duress Password in the owner profile. Both a duress PIN and password will need to be set to account for different profiles that may have different unlock methods.

Note that if the duress PIN/Password is the same as the actual unlock method, the actual unlock method always takes precedence, and therefore no wipe will occur.

Source: grapheneos.org/features#duress

#privacy

threaded - newest

mypasswordis1234@lemmy.world on 03 Jun 2024 23:01 next collapse

That may be useful

DmMacniel@feddit.de on 03 Jun 2024 23:16 next collapse

Mhm i can imagine that GrapheneOS will be marked as an illegal OS once Interpol and others get wind of this kill switch.

ryannathans@aussie.zone on 04 Jun 2024 00:29 next collapse

Doubt it, wouldn’t they just clone the flash first?

refalo@programming.dev on 04 Jun 2024 02:04 collapse

irreversibly wipe the device

And for anyone to actually go through the trouble of cloning a flash chip, you’d have to be an extremely high profile target.

[deleted] on 04 Jun 2024 07:03 next collapse
.
Onihikage@beehaw.org on 04 Jun 2024 15:25 next collapse

Not at all - you could just be a US citizen coming back from a brief trip across the border.

A few congress critters have been trying to get bills passed to curtail this overreach for almost a decade, but unless I missed the news, none of them have succeeded.

ryannathans@aussie.zone on 04 Jun 2024 16:13 collapse

Interpol aren’t the border agents… we are talking about interpol, not random seaches

boldsuck@scribe.disroot.org on 04 Jun 2024 19:40 collapse

TBH, in order to be forced to unlock your phone under duress, you’d have to be a pretty high profile target.

Why, that can happen to anyone at the airport when entering the USA, UK, Australia, etc. Or if you have been in a car accident, your cell phone will be confiscated in Germany, for example. Or when you were forced to unlock the phones and banking apps at gunpoint: cbsnews.com/…/robbers-unlock-phones-banking-apps-…

ryannathans@aussie.zone on 04 Jun 2024 16:11 collapse

Who the fuck do you think interpol are targeting? Lmao

999999999@lemmy.ml on 04 Jun 2024 02:56 next collapse

did not some custom ROM fo android had the same fate?

boldsuck@scribe.disroot.org on 04 Jun 2024 20:01 collapse

The people Interpool is after don’t need Duress. They simply refuse to give out their password. Current Pixel and iPhones phones cannt be cracked with forensic tools. …grapheneos.org/…/12848-claims-made-by-forensics-…

ryannathans@aussie.zone on 04 Jun 2024 00:28 next collapse

Long overdue

ResoluteCatnap@lemmy.ml on 04 Jun 2024 14:59 collapse

Why didn’t you contribute this feature sooner then?

ryannathans@aussie.zone on 04 Jun 2024 16:09 collapse

I’m maxed out on open source contributions myself right now as maintainer of a large project

MachineFab812@discuss.tchncs.de on 05 Jun 2024 09:36 collapse

… and I’ve been told I’m demanding and entitled, but here’s some jackass who downvoted one(@ryannathans) who is doing the work. You or I can never do enough to be worthy to request certain features or bug-fixes be given higher priority.

These people need to go back to Spez’s, Musk’s, or Zuck’s playground, since they love having no say so much.

possiblylinux127@lemmy.zip on 04 Jun 2024 01:33 next collapse

That’s actually pretty cool. I just wish they would take a stance against proprietary software.

refalo@programming.dev on 04 Jun 2024 02:18 next collapse

something something destruction of evidence

autonomoususer@lemmy.world on 04 Jun 2024 03:06 next collapse

What evidence?

Jolteon@lemmy.zip on 04 Jun 2024 07:02 next collapse

Alternately, it could unlock the phone while also erasing specific parts of it, like message history and call logs, potentially replacing them with something you’d set up previously.

Edit: and obviously it would disable the duress pin and set the unlocking pin to it.

DetectiveSanity@lemmy.world on 04 Jun 2024 07:37 collapse

Depends on what you did! Say for example they’re using Graphene to harass/paedophilia then they already have a copious amount of evidence on hand since they are there.

For organising peaceful protests that seems less of an issue and the other end of the chats is the weak link.

yeehaw_cosmonaut@reddthat.com on 04 Jun 2024 03:56 next collapse

Cool feature, I wonder if a duress fingerprint will be introduced in the future?

Jolteon@lemmy.zip on 04 Jun 2024 07:00 collapse

I feel like that would be a lot easier to accidentally trigger.

yeehaw_cosmonaut@reddthat.com on 04 Jun 2024 13:30 collapse

You’re not wrong, but like the duress pin, it would be a nice feature to have. Not everyone would have to set a duress fingerprint, just the people who find value in it.

Kayel@aussie.zone on 04 Jun 2024 14:12 collapse

You would not believe how much I have lost from being obsessed with high-threat modeling for my low-threat life. $10k and family videos for a start.

Sometimes it’s a good idea to protect the community from itself lol.

laughterlaughter@lemmy.world on 05 Jun 2024 09:46 collapse

Don’t leave us hanging. How did it happen?

Kayel@aussie.zone on 05 Jun 2024 13:09 collapse

Writing down a crypto wallet key in a self hosted password manager on a highly encrypted self hosted drive which degraded. Pretty much the same with the photos, if I didn’t encrypt my backups I would have been able to recover more files.

laughterlaughter@lemmy.world on 06 Jun 2024 09:19 collapse

Oh yikes.

I got out of crypto stuff long ago. But I was so paranoid with losing wallet keys that I’d put them everywhere in chunks, like a medieval quartered body spread all over Scotland.

sic_semper_tyrannis@lemmy.today on 04 Jun 2024 06:38 next collapse

Very nice

smileyhead@discuss.tchncs.de on 04 Jun 2024 09:33 collapse

Wonder if this say a big “WIPING…” and shows a blank profile then.

Because it would be much more useful if this would erase real profile and then quickly switch to some fake profile looking real.

Andromxda@lemmy.dbzer0.com on 08 Jun 2024 14:48 collapse

It doesn’t say anything. It shuts the device down almost instantly, and simulnateously wipes the encryption keys from the secure element, ensuring that the data stored on the SSD can’t be decrypted.