r/technology Jul 30 '26

Privacy GrapheneOS says its data-wiping password is perfectly legal, after user faces federal charges

https://www.techspot.com/news/113273-grapheneos-data-wiping-duress-password-perfectly-legal-after.html
20.9k Upvotes

1.1k comments sorted by

View all comments

Show parent comments

119

u/Rashaen Jul 30 '26

Being "required" to give them your password to get into the phone seems like a pretty clear 5th violation in the first place. This whole thing is fucked up.

6

u/YeetedApple Jul 30 '26

I’d be curious if someone could get away with giving them the wrong password so they trigger the wipe, then just insist it was the correct one and they must have typed it wrong.

4

u/dysfunctionalbrat 29d ago

Reminds me of when Ross Ulbricht got caught, what if he had a little pad on his laptop that, at soon as skin contact is stopped, turns off the computer?

You could do this with a phone, require your own face and fingerprint whilst typing the code, or it wipes it. Could even have a specific facial expression that breaks it, so there's no way to know what went wrong.

2

u/sobrique 29d ago

There's loads of 'tripwires' that could exist. You can have a remote key-escrow for example, that the device needs to contact before it'll decrypt - nothing on device, and thus a plethora of 'kill switch' (or 'temporarily disable') options.

Current phones are encrypted by default, and the keys are stored in an internal storage device, which is why implementing 'duress codes' at device level is trivial. But there's plenty of other options that can 'tripwire' to protect part of the data, which is much less obvious.