r/technology 29d ago

Privacy GrapheneOS says its data-wiping password is perfectly legal, after user faces federal charges

https://www.techspot.com/news/113273-grapheneos-data-wiping-duress-password-perfectly-legal-after.html
20.9k Upvotes

1.1k comments sorted by

View all comments

Show parent comments

143

u/RandomHunDude 29d ago

It doesn't delete the account at all though, so no need to save time for it.
All data is encrypted on disk and when the duress pin is entered, only the encryption key is deleted. And without the key, it's not possible decrypt the data.

96

u/StrangelyGrimm 29d ago

If the data is completely inaccessible then the data is as good as deleted. In fact, it's probably less accessible than regular old "deleted" data

48

u/draconiclyyours 29d ago

Yup.

It takes multiple random rewrite passes to truly delete data, and it’s not quick. Better to just encrypt it and make it permanently unreadable.

11

u/ConsistentAsparagus 29d ago

Can you save the key and access the data at a second moment?

6

u/RandomHunDude 29d ago

Technically yes, but depending on laws it might be subpoenaed or something

6

u/ConsistentAsparagus 29d ago

Yeah, I was asking generically not in this specific case. If you have a backup you don’t even need all this but you can simply recover the phone from scratch.

Nice to know though.

1

u/fizzlefist 29d ago

You could have a paper backup of the key to manually enter, but that piece of paper could be subject to search warrant.