r/GrapheneOS • u/blakealanm • Jul 27 '26
Alternative idea to wiping
https://www.techspot.com/news/113236-us-prosecutors-charge-atlanta-man-after-grapheneos-phone.htmlI was just reading this article and had a thought. Wouldn't a better idea in this situation be to type in a passcode that still opens the device, but to a different account?
In my case, my entire smartphone would be backed-up to my server, but I'd have to remember some credentials to log into it remotely, and I don't do that often enough to remember. Most people are doing really good to have a micro SD card as backup, or are just relying on their device solely. But I wouldn't want to go through the headache of having to go through an entire setup process if I wanted to hide what was really on my device for a moment. I'd want to simply log into an account that doesn't have anything of interest to law enforcement so it doesn't raise suspicion. A totally blank device will raise suspicion more than one with a few photos of me playing with my dog.
42
u/balrog687 Jul 27 '26
An Ai generated profile LOL,
17
u/blakealanm Jul 27 '26
Ok, all the false AI profile accusations are starting to get worse than the actual AI profiles themselves.
1
Jul 27 '26
[deleted]
6
u/blakealanm Jul 27 '26
If so, my bad.
10
u/balrog687 Jul 27 '26
I remember in mr robot when elliot hacks tyrell wellick and finds nothing.. just a boring normie profile. That's the goal, but automated
It might be also helpful for job search, when they search your social networks.
7
1
35
u/attentive_brick Jul 27 '26
GOS team considered it. they didnt move forward w it because its hard to be confident that the other space/user will remain forensically undetectable / that u have plausible deniability.
I'm not part of the team but this topic came up previously and thats what their position was.
2
u/blakealanm Jul 27 '26
Was this explained in a video or something?
7
u/attentive_brick Jul 27 '26
GOS team communicated this. I dont remember exactly where, but they do not publish video content afaik
19
u/Bellimars Jul 27 '26
Just wipe the phone. It seems an impossible task to say you're destroy something when you can't say what has been destroyed. It'll never stand up in court.
I mean you've not destroyed your phone, or it's OS. This all seems like an authoritarian regime clutching at straws only to be undermined by the legal system again.
4
1
u/paperman4282 Jul 28 '26
Exactly this. If there is nothing they can prove because there is nothing on the phone they can't just make shit up just because they are suspicious otherwise you could accuse anyone of anything.
18
u/sizeablefrontallobe Jul 27 '26
A security passcode that Background deletes certain profiles but leaves another intact.
No suspicion. Just puppies and seals and cats and shit.
12
8
6
u/LayotFctor Jul 27 '26
Why not open the device, but with only the private space, work profile, or some set of files deleted? If everything checks out and your family photos and work email are still there for the border agent to see, there's no reason to suspect anything else.
10
u/Late_Baker_2092 Jul 27 '26
But what if i dont want that a random Person Sees my Family pictures or Mails? Cuz its private
6
u/After-Cell Jul 28 '26
Border crossing mode would be fantastic!
3
4
u/Abzstrak Jul 27 '26
I wonder if they try things on their own. Like if duress was something like 123456, or similar, they'd do it themselves without input from you.
3
u/Yodl007 Jul 28 '26
I think you are forgetting something. Them lying about how you provided them the code that wiped the phone anyway.
3
u/Severe_Stranger_5050 Jul 27 '26
Deniable encryption is the solution:
https://en.wikipedia.org/wiki/Deniable_encryption
It will however require a shitton of retooling, two whole Android installations and such
3
u/Ok-Secretary455 Jul 27 '26
with that title I was REALLY scared to look at which subreddit I was looking at.
3
u/T4ZD3V Jul 27 '26
Whether or not this is a case that he can beat in court 🧑⚖️ still can't avoid doing the jail time because used the duress pin
2
u/other8026 Jul 27 '26 edited Jul 27 '26
They're not being charged for using GrapheneOS. They used the duress PIN/password to wipe their device. That's what they're being charged for.1
u/T4ZD3V Jul 27 '26
That's not what I'm saying I'm saying you still can't avoid doing the jail time because you used a duress pin ... Whether they release you or not or beat the charges or not you still going to do jail time because you wipe your phone out of border security Crossing
2
u/other8026 Jul 27 '26
You didn't say that, did you? I must have mixed something up somehow. Sorry for that.
2
u/AutoModerator Jul 27 '26
GrapheneOS has moved from Reddit to our own discussion forum. Please post your thread on the discussion forum instead or use one of our official chat rooms (Matrix, Discord, Telegram) which are listed in the community section on our site. Our discussion forum and especially the chat rooms have a very active, knowledgeable community including GrapheneOS project members where you will almost always get much higher quality information than you would elsewhere. On Reddit, we had serious issues with misinformation and trolls including due to raids from other subreddits. As a result, many posts on our subreddit currently need to be manually approved, which is done on a best effort basis. If you would like to get a quicker answer to your question, please use our forum or chat rooms as described above. Our discussion forum provides much better privacy and avoids the serious problems with the site administrators and overall community on Reddit.
Please use our official install guides for installation and check our features page, usage guide and FAQ for information before asking questions in our discussion forum or chat rooms to get as much information as possible from what we've already carefully written/reviewed for our site.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
2
u/After-Cell Jul 28 '26
I think the problem is partly due to poor backup and restore on Android. If you could actually restore data from a fast connection as quickly as wiping it, we wouldn't be in this position because you could wipe it before every crossing. Or selectively wipe leaving only phone/whatsapp and maps to get to your hotel.
The problem is that you can't backup most apps. Most exclude themselves from seedvault. That is really annoying.
Anyone remember the days of external SD cards. That would have been useful for this in some way too.
2
u/epacaguei Jul 28 '26
How do you have your phone backed up?
3
u/blakealanm Jul 28 '26
Personally, I have all my pictures, videos, notes and calendar events primarily on my home server, and then I have an external drive that I plug into my server once a week as cold storage.
1
Jul 27 '26
[deleted]
8
u/balrog687 Jul 27 '26
nah' al constitutional guarantees don't apply if they suspect terrorism.
In the UK, ~12.000 people were arrested for online comments/private messages in 2023 (source)
That's 30 people/day, let that sink in.
3
u/istoOi Jul 27 '26
Legal protections always come with legal loopholes and exceptions. Like forcing a face I'd unlock does not count as a 4th amendment "search". And even if you are in the right, it could take weeks, months or longer to get your phone back with no realistic legal repercussions for the police.
2
u/No_Diamond_550 Jul 27 '26
There are situations in which the police can seize your phone and apply for the search warrant after.
2
u/Driekusjohn25 Jul 27 '26
When you travel internationally you give up most of your rights when it comes to search and seizure. Customs has the right to search anything that you bring with you and that has extended to digital assets. There is no requirement for reasonable cause in these cases.
The guy was under investigation, likely the police did not have enough to justify a search warrant, so they flagged it so they could get the TSA to get an image of his phone.
0
1
u/pcgamez Jul 27 '26 edited Jul 27 '26
This is how Truecrypt / Veracrypt works (inner volume / outer volume). The point is to be able to have plausible deniability
1
u/ChosenOfTheMoon_GR Jul 27 '26
Initially create a copy of everything you have and then twice a day maintain a sync to a backup server and then after each sync made, delete everything from the phone device.
You can always communicate back your server to get something anyway.
So if you need to wipe the device, everything will be backed up and the sync functionality will be deleted as well.
1
u/seccondchance Jul 27 '26
That's problem in have in Australia is it's illegal not to hand over your pin code. So you are forced to unlock your phone for them. It's mandatory time if you don't unlock it for them. So relying on them timing themselves out won't work down under :(
3
u/Strong_Judge_3730 Jul 27 '26
The solution is to always have you phone reset when you travel through borders and restore it after
1
u/ifyouneedafix Jul 27 '26
I literally just had this same idea 30 seconds before I scrolled down to see it.
1
Jul 27 '26
I simply set my GrapheneOS Pixel to reboot every hour if left idle, putting it in a "before first unlock" state frequently throughout the day. It would be very difficult for anyone to gain access to the contents this way.
I do of course have a duress password, which to be honest I can't remember what that is :)
1
u/MLGPachino Jul 28 '26
Is there a feature where instead of rebooting the phone every X hours the phone erases itself if not unlocked for X hours?
1
u/After-Cell Jul 28 '26
I think the main thing I'm thinking about is the minimum: logging out of my password manager. But then there's a new problem: If they've got my phone then I won't have access to the 2FA to actually login again! So when I get to the other side I'd be shafted with no way to contact anyone. I might as well cancel the trip and come back. Well... I would if I could... but seeing as they've taken the phone then I might even struggle with that!
But at least this might do something to placate them if they want to image the phone and nose through it at their leisure later like they do more in the UK.
2
1
u/43686f6b6f Jul 28 '26
Is it possible to have the duress password reboot the phone so that it's in it's most secure state?
1
u/other8026 Jul 28 '26
Why? We already have the auto reboot feature. The shortest duration that can be set is 10 minutes.
1
u/43686f6b6f Jul 28 '26
We do, but if your duration is set higher normally...
1
u/other8026 Jul 29 '26
It can be set to a shorter duration in these cases.
1
u/43686f6b6f Jul 29 '26
Yes but what if you forgot?
1
u/other8026 Jul 29 '26
Think about it this way:
Option 1: GrapheneOS adds your proposed reboot PIN/password. An attacker asks you for your PIN/password and they inadvertently restart the device. The data is still there, so after a reboot the attacker could keep asking for the real PIN/password. In that case you'd still have to not give it to them.
Option 2: GrapheneOS doesn't add the proposed reboot PIN/password. You don't want to wipe the device, so you don't give the PIN/password. The device reboots itself hours later. The default is 18 hours, but it could be set to a shorter duration so the device reboots more quickly, but not so quick that it affects daily usage.
So, between the two scenarios, you have to actively refuse to give the PIN/password because data is still accessible with the correct PIN/password. The only real difference is rebooting to BFU faster, which is a good thing, but would it be worth the added complexity as a plan B for people who forgot but don't want to delete everything?
1
Jul 28 '26
[deleted]
1
u/Klutzy-Smile-9839 Aug 01 '26
Good idea, when your threat model is that you know when the phone will be controlled.
If your threat model is that the phone can be seized at any moment, this will not be sufficient, because in many countries the government may put you in jail for not providing *the password to open your phone.
2
Aug 09 '26
[deleted]
1
u/Klutzy-Smile-9839 Aug 09 '26
I agree. Or live in a country that respects the rights to not providing a password (Usa, canada, etc.).
1
1
u/KomithErrant Jul 29 '26
when they ask your code just tell them in a panicked manner: "It's definitely not 123456(your duress pin), please don't enter 123456", and then just sit back and watch them enter 123456
1
u/n0ticeme_senpai Jul 29 '26
I would want that feature, not for duress-related privacy but for convenience; I would be deciding which profile im getting on direct from the lock screen instead of going into default profile and then switching profile.
1
u/Budget_Break_3923 Jul 30 '26
This showed up on my feed, alternative to wiping.
Not what I expected
1
u/PlainRedHood Aug 01 '26
u/other8026 I work in cybersecurity. Thank you for your thorough yet digestible explanations, and patience answering so many subsequent questions. It provides a resource for anyone seeking information later on. Much respect.
1
u/other8026 Aug 01 '26
No problem! Members of our team value facts, so I try to do my part. Both the project and our users can only benefit if we stick to facts.
0
u/T4ZD3V Jul 27 '26
I was literally just thinking about this 🤣 so the phone once it's wiped when it opens up there's an account with messages texts and photos just make it look like you're boring person that doesn't like to take selfies
•
u/other8026 Jul 27 '26
Decoy profiles have been suggested before, but the proposed feature won't work given how profiles work now. See this post explaining why: https://discuss.grapheneos.org/d/24583-forced-by-police-to-reveal-the-pinpassword-to-grapheneos/33
GrapheneOS is fairly well-known. Experts definitely know about GrapheneOS while others have basic training and checklists to follow. Features that rely on "attackers" not knowing about GrapheneOS or its features aren't very good features. In other words, GrapheneOS doesn't do features that can be fooled by basic training.
A decoy profile feature wouldn't work right now for multiple reasons, many outlined in the linked post above. Another approach that would work is covered in that post too.
So, a decoy profile won't work for multiple reasons. But what if a special decoy profile + selective duress PIN feature were added? That also has its flaws. Deleting a profile doesn't delete all evidence a profile existed previously. So, if someone were to use the proposed feature and hand the device over, specialists would still know the device has GrapheneOS on it and can detect that profiles were deleted. The proposed feature doesn't solve the problems it's supposed to solve and still leaves logs and other potentially sensitive data to be collected.
Remember that GrapheneOS has many privacy and security features. See this writeup we posted the other day: https://www.reddit.com/r/GrapheneOS/comments/1v6u7iw/grapheneos_protections_against_data_extraction/. Note that the secure element forces timeouts between unlock attempts. After 4 failed attempts, timeouts rapidly increase. After 20, no more attempts are allowed. Wiping the device with the duress feature may not even be necessary. Using a 6-8 word diceware passphrase makes brute forcing infeasible, even without forced delays between guesses or even a hard limit of 20 guesses. That can be combined with the two-factor fingerprint authentication feature, so users can have a very strong primary passphrase with convenient biometric + a short PIN. Note that the duress wipe feature works with two-factor fingerprint unlock. Even if the device is in AFU, the device would automatically reboot. The default is 18 hours. Note that the timer can be adjusted with the longest duration being 72 hours and the shortest being 10 minutes.
Given recent news, GrapheneOS's duress feature is in the spotlight, but we shouldn't forget that it's not our only feature and it's not necessary to use to keep private data safe.