The foundation behind the ultra-secure Android-based OS is speaking out after an activist was indicted for using a ‘duress password’ to prevent federal agents from searching his phone.

  • LibertyLizard@slrpnk.net
    link
    fedilink
    arrow-up
    24
    arrow-down
    2
    ·
    edit-2
    1 day ago

    Not sure there’s a realistic way they don’t notice. It takes time to wipe things and then the phone is empty. I feel like they’ll figure it out.

      • nymnympseudonym@piefed.social
        link
        fedilink
        English
        arrow-up
        19
        ·
        edit-2
        1 day ago

        I just realized there are ways you could do plausible deniability.

        What if we keep a decoy partition ready to go? Pre-populate it with some AI-generated slop Facebook account, photos, etc. Keep A small random sample of music files. etc. Something that looks as plausible and bland as possible.

        This is a feature that could get better & better over time. Don’t just wipe my old data; make my adversary unaware that there was anything worth wiping.

        • Bytemeister@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          11 hours ago

          What if you were able to pick apps/accounts that mirrors to the decoy partition? Then you have real data, but all the private stuff stays locked away.

          • BottleBoardBakon@lemmy.ml
            link
            fedilink
            arrow-up
            1
            ·
            7 hours ago

            You can already make hidden spaces in graphene!

            Although I think this guy should’ve just had an alt user active during the search and turned off usb data transfer.

            He shouldn’t have been searched, but he should’ve realized that he probably would be and prepared his device better.

        • coolman@lemmy.world
          link
          fedilink
          arrow-up
          3
          ·
          14 hours ago

          I could absolutely see this being a thing, veracrypt has an option to create a hidden volume, and the two different passwords open up to two different encrypted volumes. Also if you start writing information to the non-hidden volume, it will start overwriting the hidden volume and corrupting files without any guardrails which is nice

    • usrtrv@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      19
      arrow-down
      3
      ·
      1 day ago

      Android supports multiple user profiles. They could have a duress code login to a more sanitary profile while data get wiped in the background. This has been discussed on the forums I believe.

      • Lytia @lemmy.today
        link
        fedilink
        arrow-up
        5
        arrow-down
        1
        ·
        1 day ago

        The wiping in the background is very fast, and would in turn take out the profile. The only thing a decoy profile would achieve in that case would be a slight splash of color before the phone shuts down.

          • Lytia @lemmy.today
            link
            fedilink
            arrow-up
            1
            ·
            11 hours ago

            That would reduce the security of the duress pin significantly, and would require rewritting how the feature works in the first place.

            The duress pin shreds the decryption keys to the entire OS, which is much much faster than erasing the data itself, and arguably more secure. If you’re worried about getting caught wiping the device, just don’t wipe it. There is no known way to get into a phone running an up to date GrapheneOS install (or anything post Q3 2022) unless you have significantly reduced the security of the phone.

    • TipRing@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 day ago

      If the phone is encrypted already you really just need to destroy the key. Of course then it needs to be reimaged to be used again which isn’t very user friendly.

      • Sidyctism II.@discuss.tchncs.de
        link
        fedilink
        arrow-up
        9
        ·
        1 day ago

        From the gOS website description of the feature, thats exactly what happens. It also says that reimaging isnt needed, only the initial setup