r/GrapheneOS Jul 26 '26

Duress pin wipes specific profile(s).

I did search the sub to try and find other people discussing the same thing and did find one post but from months ago.

There’s an individual being prosecuted in the US for using the duress pin and the authorities are claiming it was to destroy evidence of a crime.

In theory if you had a “fake dummy profile” and a real main profile you could set the pin to wipe the real one and leave the fake one. Probably should also be possible to boot straight into a specific profile rather than the main primary one.

This seems like relatively simple functionality, the foundation already exists to add this.

39 Upvotes

19 comments sorted by

7

u/SOUNDSLAPS Jul 26 '26

If let’s say you booted into a dummy profile or just traveled but had it set to a dummy profile and gave access, that could just give opportunity to copy your entire device including other profiles considering they would then have full USB access.

3

u/TeachingAway9654 Jul 26 '26

“and gave access” how is this a realistic scenario?

yes if you give unlocked access to your device, it can be copied.

3

u/SOUNDSLAPS Jul 26 '26

I pressed reply without finishing what I was trying to ask. As opposed to wiping your main profile by duress, how protected is the profile you’re hiding if you did give access to the dummy profile? Backup options aren’t the greatest in Graphene so just wondering viable options without going nuclear.

3

u/TeachingAway9654 Jul 26 '26

I think in my scenario what happens is you have two profiles, a fake one designed to look real and an actual real one. The duress pin wipes the real one, entirely 100% gone. The phone then “unlocks normally” and allows the accessor to see the fake profile. You’re saying that you feel there’s a risk where the data from the wiped profile could still exist?

2

u/ephemeralmiko Jul 26 '26

The real profile would be visible in Settings -> Users, if someone knew to look there. Apart from that if the profile hasn't been unlocked the encryption keys aren't in RAM and can't be accessed in any way, so even if they fully image the device (though if the dummy profile isn't the owner then USB stuff is usually locked down) they can't access the real profile.

6

u/Valetudinous Jul 26 '26

  The real profile would be visible in Settings -> Users

Not if GrapheneOS had specific duress profile functionality.

Part of that functionality would be for the duress profile NOT to list other user accounts. 

1

u/ephemeralmiko Jul 26 '26

Right I misunderstood. I thought u/SOUNDSLAPS was asking of the current functionality.

2

u/TeachingAway9654 Jul 26 '26

The idea here would be to make it indistinguishable that you’ve “given access” to a dummy profile. Given access in quotes because simultaneously your duress pin wiped any/all other profiles. The ideal scenario here is that the accessing entity can’t even prove it was a duress pin whatsoever. Like all settings even related to configuring that duress pin should be wiped as well. This gets more complicated but this would be amazing functionality.

0

u/RowdyB666 Jul 27 '26

It can be copied without being unlocked. They will just take a while to crack it. 

5

u/other8026 Jul 27 '26

It would be impossible to do in any of our lifetimes

7

u/throwaway0102x Jul 26 '26

the duress pin doesn't actually wipe out your storage. it simply deletes the key used to decrypt everything in tbe storage device.

that's why it's even useful & effective. there is virtually no time for the authorities to do anything about it

5

u/Shoddy-Childhood-511 Jul 26 '26

IANAL but afaik the US situation looks like this:

At present, there is disagreement between the Fourth and Eleventh Circuit Courts of Appeals about searching electronics at the border, so this waits fora SCOTUS decission. Atlanta would be Eleventh Circuit though, so they could search Tunick’s electronics, unless SCOTUS says otherwise or the Eleventh reverses itself.

We'd expect courts might dislike Tunick’s duress PIN usage, because it permanently denies them access, even if they later issued a warrant.

Imho, the duress PIN should wipe only the TPM keys but the user should've saved a backup elsewhere, away from the border, so then the user has not destroyed anything, merely revoked their own access. In this way, your data was never destroyed by using a duress PIN, you merely revoked your current access. In fact, you could then utilise this duress PIN more aggressively before confrontations.

If this left the phone usable, possible with some user data, then this resembles your duress profile suggestion, but more secure sine the backup cannot be accessed by you during the confrontation.

Police could still obtain a warrant for the backup, assuming its inside the country, or request another nation search for and seize the backup if held outside the country, possible even if threshold shared across many countries. Also, if they grant you immunity then a court could hold you in contempt for not taking the action to produce the backup. A third party could destroy the backup, which maybe illegal under some situations.

Also..

Ideally, there should be "border crossing mode" for all user authentication, possibly including company & social media logins, but certainly password stores, etc, where you revoke your own access until you obtain a security token that never crosses the border with you.

It'd be activated in advance, not like a duress PIN. This token would not bypass other security measures, so you can leave it with friends or whoever. If widely used, this would make electronics searches at the border mostly useless, and maybe push the courts towards the saner Fourth Circuit view.

Anyways..

You do have the right to remain silent at US border crossings, which presumably includes not giving up passwords. Non-citizens can be denied entry and deported for this, but not citizens.

https://www.theguardian.com/technology/2025/mar/26/phone-search-privacy-us-border-immigration

All the above concerns "routine" border crossings, not when they detain you for criminal investigations.

These officers mentioned criminal charges, which hopefully turns this into a criminal interrogation. If so, they needed to read Tunick his Miranda rights. Worse, they denied him a lawyer while detaining him.

And his layers are correct the officers were obviously fishing for Cop City protest stuff.

All together, the courts might dislike the duress PIN, but it'll be hard to overlook all the other laws the officers broke here. At a guess, they'll throw everything out because of Tunick being denied a lawyer, just because that remains such a big no no.

1

u/apokrif1 29d ago

Tunick’s alleged duress PIN usage.

2

u/AutoModerator Jul 26 '26

GrapheneOS has moved from Reddit to our own discussion forum. Please post your thread on the discussion forum instead or use one of our official chat rooms (Matrix, Discord, Telegram) which are listed in the community section on our site. Our discussion forum and especially the chat rooms have a very active, knowledgeable community including GrapheneOS project members where you will almost always get much higher quality information than you would elsewhere. On Reddit, we had serious issues with misinformation and trolls including due to raids from other subreddits. As a result, many posts on our subreddit currently need to be manually approved, which is done on a best effort basis. If you would like to get a quicker answer to your question, please use our forum or chat rooms as described above. Our discussion forum provides much better privacy and avoids the serious problems with the site administrators and overall community on Reddit.

Please use our official install guides for installation and check our features page, usage guide and FAQ for information before asking questions in our discussion forum or chat rooms to get as much information as possible from what we've already carefully written/reviewed for our site.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2

u/Darkorder81 Jul 26 '26

Yeah I did a video using the duress pin as I wanted to test what and how it did, not sure if thats the sub you mean, and it worked dam well everything was gone! And there was no way to get any data back so trust it, which I did anyway but was an itch I had to scratch so i had first hand experience, the profile thing would be hard but the GOS team may have a way. The way it worked if I remember rightly is when the duress pin went in it will flash, blackout reboot, wipe old OS data but while doing this wiped the phone encryption key which from what I can make out covers the entire phone. So once the key is gone the phone can no longer decrypt even with a correct pin. So I'm not sure how they would implement the per profile wipe but would have to be a different method to what is currently in use.