• 0 Posts
  • 6 Comments
Joined 13 hours ago
cake
Cake day: July 29th, 2026

help-circle



  • That exists. The thing to watch is the difference between separate profiles and a hidden one.

    Graphene gives you multiple profiles with their own passwords, but profiles are enumerable. Anyone poking at the device sees that profile 2 is there, so “open that one too” is the obvious next sentence.

    The version you’re describing works when the second environment can’t be shown to exist at all, so it reads as encrypted random noise, which is what empty encrypted space looks like anyway. One PIN gets you a full boring phone, the other gets you your real one.

    Only holds up if the boring phone is actually convincing though. Six apps and no photos fails on the spot.

    (I work on DeniableOS, which does the hidden version, so weigh that how you like.)


  • You guys already spotted the hole in the burner plan. A clean phone and a wiped phone look identical from the other side of the desk, and both look like someone who planned ahead.

    A burner only works if it’s lived-in instead of clean. Real accounts, months of boring messages, photos of nothing in particular. That’s a lot more effort than grabbing a spare handset the week before you fly, which is why hardly anyone does it properly.

    Same idea with less upkeep: keep one genuinely lived-in phone and put the sensitive half behind a second PIN, stored so you can’t show it’s there. Then the thing you hand over isn’t a prop, it’s just your phone.

    (I work on DeniableOS, which is that. Changes nothing about what CBP is allowed to do to you, and I’m not a lawyer.)


  • The reboot isn’t cosmetic, it’s structural. The duress PIN nukes the key derivation material, and a device with no keys has nothing left to boot into. There’s no quiet version of that.

    But your instinct is right and worth pushing one step further. An empty phone has the same problem as a rebooting one. Nobody owns a phone with four apps and two weeks of messages, so it just takes them a bit longer to notice.

    What you actually want is to quietly unlock into a phone that’s full. Real apps, real photos, real history, and the sensitive half behind a second PIN stored so it reads as random noise, same as any unused encrypted space. Nothing gets destroyed, so there’s nothing to reboot from and nothing to argue about afterwards.

    Catch is the decoy has to be believable, and keeping one believable is a chore most people drop after a month.

    (I work on DeniableOS, which does this, so grain of salt. Graphene’s own statement this week made roughly your point, that wiping can carry physical or legal consequences.)