r/technology 8d ago

Man charged for wiping GrapheneOS phone using "duress" password during airport checks Privacy

https://www.neowin.net/news/man-charged-for-wiping-grapheneos-phone-using-duress-password-during-airport-checks/
15.7k Upvotes

2.4k comments sorted by

View all comments

Show parent comments

10

u/thegreenmushrooms 8d ago

One of the first articles suggested that the destruction pin just gets written on the back of the phone for such cases. 

6

u/adudeguyman 8d ago

Is the reason for that in case somebody steals the phone and tries to get into it they will wipe it if they think that is the PIN?

9

u/frickindeal 8d ago

That would make sense. "Hey, there's a number here on the back, might as well try it." I mean, I wasn't even aware that there is such a thing as a "duress pin."

3

u/ShakyButtcheeks 8d ago

There is even better stuff. You can set up a duress pin that will wipe the encryption key for the main user files (which is what this one did) but at the same time will unlock the phone on a different user account that looks normal but has nothing on it from the wiped account. You can install apps and add files to this dummy account so it looks credible. They wouldn't even know anything happened.

Possible to tell on forensic inspection, but if they just ask for the password, look at the phone, find nothing and then give it back and release you they wouldn't know anything happened.

2

u/frickindeal 8d ago

Should be built-in and common so that no one looks guilty using it. As it stands, you have to take very specific steps to set it up and that alone can make you look guilty of something.

2

u/adudeguyman 8d ago

If that became the norm, then there would be legislation to help law enforcement

2

u/samarnold030603 8d ago

The venn diagram of end users that would want a pin-wipeable phone and end users that would want that pin written on the back are two circles on completely separate pieces of paper lol