Tunick provided this code to an agent, who entered it on the phone, after which “the screen went blank, flashed several times and the phone appeared to restart.” All data on the phone was gone, but authorities confiscated it anyway.
They should be required to prove that such an OS was installed on the phone, that such a duress code was configured, and that it was the one provided, otherwise that was clearly a glitch in the phone, a cosmic ray bit flip, or the agent fumbling ¯\_(ツ)_/¯
Device profiles can also wipe a phone after failed attempts (among many other things). The most common way for this is signing into your work’s 365 and accepting to add the device. This is so company data is automatically or remotely wiped should anything go wrong.
Does the GrapheneOS data-wipe actually wipe ALL data including the OS (presumably bricking the phone), or does it just delete personal data (thus just boots back up and appears like any brand new phone awaiting setup)? If the latter, seems like they could still identify the OS fairly easily. At which point it just kinda follows that, yeah, the entered PIN was a duress code, which is a known feature of the OS. Of course, I’m no lawyer, so I’m not sure how hard the rest would be to prove after identifying the OS.
Duress PIN/Password
GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).
The wipe does not require a reboot and cannot be interrupted. It can be set up at Settings > Security & privacy > Device unlock > Duress Password in the owner profile. Duress PIN is solely used for PIN entry and duress password is solely used for password entry. Both a duress PIN and password are mandatory to enable the feature to account for different profiles that may have different unlock methods. Duress PIN will also wipe the device when entered as the two-factor fingerprint unlock PIN but not currently when entered as the SIM PIN.
Note that if the duress PIN/Password is the same as the actual unlock method, the actual unlock method always takes precedence, and therefore no wipe will occur.
Tunick provided this code to an agent, who entered it on the phone, after which “the screen went blank, flashed several times and the phone appeared to restart.” All data on the phone was gone, but authorities confiscated it anyway.
They should be required to prove that such an OS was installed on the phone, that such a duress code was configured, and that it was the one provided, otherwise that was clearly a glitch in the phone, a cosmic ray bit flip, or the agent fumbling ¯\_(ツ)_/¯
Can’t be responsible when it left his custody, right?
Yeah, they must have entered the wrong one
Device profiles can also wipe a phone after failed attempts (among many other things). The most common way for this is signing into your work’s 365 and accepting to add the device. This is so company data is automatically or remotely wiped should anything go wrong.
Does the GrapheneOS data-wipe actually wipe ALL data including the OS (presumably bricking the phone), or does it just delete personal data (thus just boots back up and appears like any brand new phone awaiting setup)? If the latter, seems like they could still identify the OS fairly easily. At which point it just kinda follows that, yeah, the entered PIN was a duress code, which is a known feature of the OS. Of course, I’m no lawyer, so I’m not sure how hard the rest would be to prove after identifying the OS.
Copy-pasted from GOS wiki
I was a bit talking out of my ass there. Also at this point not even being judicially right protects you I guess.
Looks like GrapheneOS remains clearly “installed” but requires you to use recovery to factory reset before it can boot.
Ah, fair enough.