Comment by grapheneos
2 hours ago
US law enforcement is well aware of it.
They're also now well aware of the GrapheneOS duress PIN/password feature. It was designed to work against an attacker aware of it by acting as a deterrence. If they're aware of the feature, it discourages them from trying to coerce a PIN/password and attempt to unlock with it. We aren't fond of features depending on an attacker being unaware of them and this isn't one of those.
Pixels have a high quality secure element enforcing a maximum of 20 unique attempts to derive the encryption keys for each separately encrypted profile. There's also very aggressive rate limiting between the attempts. It filters out duplicate attempts by temporarily remembering the previous 5 unique attempts to make the rate limiting more usable. A misremembered PIN/password repeatedly entered over and over will only use up 1 attempt.
Android does have standard support for enabling wiping after N attempts and an open source app can be used to set a configurable limit rather than specifically after 10.
No comments yet
Contribute on Hacker News ↗