Comment by floathub
11 hours ago
According to the article, he was actually using GrapheneOS and gave the border official the Duress PIN. So I guess technically it was the official that erased the data :-)
11 hours ago
According to the article, he was actually using GrapheneOS and gave the border official the Duress PIN. So I guess technically it was the official that erased the data :-)
Not how the law works. If I put a bomb in a box. It will explode if a certain pin is put in. And you ask ”can I open the box? What is the pin?” And I say ”here is the pin to open it” and the bomb explodes. Do you think I can claim they blew up themselves ?
I'd guess the smiley indicates that op meant it as a joke.
Yes. Because law enforcement assumes there's bombs in boxes by default and defers to the bomb squad to understand the box before they touch it.
Why would the bomb squad trust the box owner to help them defuse it? To understand the issue, you have to construct a proper analog.
Sure, you're right that this analogy is bad, because that would never happen.
But if it did, you'd still be on the hook for the bomb, even though technically the LEO set it off through incompetence.
I never told you it is a box with a bomb. You just asked if you can have the pin. You can do another example where you give false information with the intent of making another person take an action that they don’t wanna take and would not take unless you had provided false information. You are causing the action to happen. Just like if you yell fire in a theater. You didn’t stamped anyone to death. But your words caused it.
1 reply →
A better feature would be a 2nd PIN that unlocks the phone to a secondary profile, which you would leave pretty bare for situations like these.
I wonder whether it'd be better for a duress PIN to delete existing data and also create a semi plausible artificial profile to hide the deletion event.
This discussion was raised last time this story was discussed. I was among its advocates: <https://news.ycombinator.com/item?id=49060716> (from the grapheneos HN account directly).
I think for the case we're talking about here, though, it would be doable. This doesn't need to thwart deep forensic analysis. It just needs to survive a border agent thumbing through the contents of your phone for a bit. If the fake profile data looks plausible, and doesn't raise any flags, the agent gives the phone back and you're on your way.
Hell, I think a setup that doesn't wipe anything, but just drops you into a sanitized, isolated profile for the border agent to look at, would be fine for many users. Certainly you wouldn't want to use this in truly high-stakes situations where it's likely that your device will be confiscated no matter what, and analyzed to death, but for the simple "border agent wants to snoop on my data for a few seconds" case, it's likely sufficient.
(As always, risk analysis can be hard, humans are often bad at it, and not everyone's threat model is the same.)
Thanks for sharing - I get the concerns people have raised in those threads, however I still feel something in this space could be useful.
Even a duress PIN which triggers predefined deletion of certain folders, messages and apps could reduce law enforcement exposure significantly.
5 replies →
Maybe it could cause the phone to "randomly" bootloop or something? "Oh no, my phone is broken again, last time this happened I needed to do a factory reset"
> I wonder whether it'd be better for a duress PIN to delete existing data
Reliably deleting data at the scale of the whole data partition, a secondary user or a Private Space is fully supported but requires a reboot or shutdown to truly complete it.
After wiping key derivation material needed to obtain the key encryption keys in multiple ways and wiping the encrypted disk encryption keys, the OS can still access the data. It still has data in the page cache, in registers and elsewhere. There are still a bunch of system processes with data tied to what was removed. The OS is still fully functional after the nearly instant wipe of everything needed to recover the data again. It can still access all data other than what's encrypted with hardware keystore keys and not currently decrypted.
The wiping process for the duress PIN/password is completed with a shutdown which tears down everything, zeroes memory and provides at least a small time window where the hardware is powered off too. A reboot would also work and the boot process has explicit zeroing of memory, registers, etc.
We decided to use shutdown for the duress PIN/pasword but a reboot is a valid approach too. Our locked device auto-reboot timer feature we first shipped in 2021 relies on the zeroing done by GrapheneOS for both the process of the OS tearing down and then again during booting to return the device to Before First Unlock state.
> also create a semi plausible artificial profile to hide the deletion event.
It isn't feasible to fool forensic software so it largely wouldn't work against state actors. It nearly certainly wouldn't have helped in this situation in the news. They aren't reliant on a non-technical person sifting through a phone. They'll just hook it up to a laptop and follow the data extraction procedure which involves enabling ADB. The software is aware of GrapheneOS can guide people through dealing with anything different about it. They've had a lot of trouble with extraction via ADB for GrapheneOS since the vulnerabilities they exploit via ADB keep getting patched or blocked it exploit protections but it isn't realistic to block extraction with them having the PIN/password. They could just enable the encrypted backup service in the OS instead and then use CLI tools to extract the data from there with the seed phrase. They don't do that because they want everything rather than only nearly all app data. They also have special code to deal with apps such as Signal with their own layer of data encryption since the data taken from their app data directory is nearly all useless by itself.
There's also quite a difference between wiping and rebooting into a not very plausible environment with decoy data set up by the user in advance compared to not properly wiping and giving access to a decoy profile. Bear in mind the OS can still access nearly all data after the wipe until a reboot. It could make a best effort attempt at purging as much as possible from memory, but the OS is not designed to continue functioning with all of the data disappearing. It can't just wipe all loaded encryption keys without crashing and rebooting anyway. It also has a ton of data still around in caches and elsewhere. We don't want to just do a best effort job cleaning up as much as we can but rather reliably prevent recovering any of the deleted data.
We could definitely add a duress PIN/password which wipes only specific secondary profiles, reboots and has the device still functional with whatever data was in the main user still there. That's a feature we can add, but it's important to note that it will not hide that there was deletion of data. It's easy to detect, and it's not feasible to hide that it happened. Many steps can be taken to make it less obvious, but it will still be easy for software aware of it to detect. Even a massive overhaul designed to perfect it would not address the SSD itself giving away what happened for more advanced analysis.
We aren't going to add a decoy profile compromising the security of the device and providing a way to recover data in a state where it isn't at all unrecoverable yet. We did already plan to consider a 2nd duress PIN/password which only wipes specific secondary profiles, but we need to make it clear that it cannot stealthily wipe them to users.
Just wanted to say I appreciate your comprehensive comments in this thread. Learned a lot.
Or put a dead man's switch on there
Interesting. So is this GrapheneOS indeed operationally good for keeping one‘s data private?
I mean, it sounds like it would be even better if the duress response was more subtle.
A duress code might let me wipe my phone when someone holds a gun to my head and demands I unlock it. Problem is, there’s still someone holding a gun to my head.
He had an e-reader and phone. My solution would be set the phone's duress pin to the e-reader's actual pin then consent to the e-reader search providing its pin and see what happens.
The actual solution is cloud backup + re-image after the border.
Yes if you don’t mind getting arrested by our fascist border police
I don’t think that would fly as a defense in court.
He’ll just have to pray the scene wasn’t recorded and his real PIN was one digit off
>I don’t think that would fly as a defense in court
but that's not the point, the point is to not wind up in court by presenting a phone that no long contains evidence but seems plausibly like your phone so doesn't arouse suspicion
> by presenting a phone that no long contains evidence
Evidence Tampering
https://xkcd.com/1494/
7 replies →
No, to my knowledge, they ask you to enter your PIN/password yourself. They don't enter it for you. I believe he entered it himself, at which point the erasure began. The erasure process was witnessed by the officer.
From https://arstechnica.com/gadgets/2026/07/activist-charged-wit...
> Tunick provided this code to an agent, who entered it on the phone, after which “the screen went blank, flashed several times and the phone appeared to restart.”
[dead]
So the real problem in the end is that your duress system should not put a big message "erasing all data" but "loading" slowly and just look mostly empty.
[flagged]
There is a difference between exploding a bomb and deleting your data. One is a crime.
>There is a difference between exploding a bomb
Mines (in wars, as implied by "solider") aren't illegal. Also even for the first example there are certainly improvised explosives you can set up that isn't criminal to create or set off, fireworks for instance. Same with a barrel of gasoline. It's certainly a crime to use it to kill someone, but that's my point. By OP's logic it's not the person who set it up's fault, it's the person who triggered it.
1 reply →
Intentional destruction of evidence is also a crime. Now, whether this applies to this scenario I suppose will have to be determined by the courts.
Destroying potential evidence before suspicion is not a crime. Destroying it once under suspicion is a crime. So anyone can destroy their data at their hotel room even just before entry even if the data contains evidence of crimes. Of course the courts could take that into evidence to support the argument that there were crimes but it would not be a crime in and of itself.
2 replies →
Deleting your data is absolutely a crime when you know the authorities could've wanted whatever it was you deleted -- even if they haven't told you yet. It stands to reason that providing a duress PIN that deletes your data when entered would be a crime as well, if said data is of interest.
Not to say that I personally agree with either of those cases. But what is considered crime can get pretty unfair when it comes to the authorities thinking you did something wrong.
20 replies →