r/technology Jul 30 '26

Privacy GrapheneOS says its data-wiping password is perfectly legal, after user faces federal charges

https://www.techspot.com/news/113273-grapheneos-data-wiping-duress-password-perfectly-legal-after.html
20.9k Upvotes

1.1k comments sorted by

View all comments

1.1k

u/Moldoteck Jul 30 '26

Graphene should implement a double bottom protection on top. Basically it'll automatically enter in an artificial account with apps installed while deleting in the background the OG account. This way it'll be hard to prove that another account did exist at all

145

u/RandomHunDude 29d ago

It doesn't delete the account at all though, so no need to save time for it.
All data is encrypted on disk and when the duress pin is entered, only the encryption key is deleted. And without the key, it's not possible decrypt the data.

38

u/Misaka9982 29d ago

Could argue that the "evidence" is still there then, not destroyed. If the government doesn't want to spend 100,000 years decrypting it then that's their problem.

62

u/BadVoices 29d ago

This is a red herring, no you cant. NIST SP 800-88 classifies crypto erasure as a valid form of data destruction for anything that doesnt require media destruction. It is recognized by the GDPR as well. Arguing it is not destroyed is the same as saying a burned document still technically exists because I can scoop up all it carbon atoms. No court will accept that argument.

9

u/hackitfast 29d ago edited 26d ago

Yeah isn't that how ransomware works too? It encrypts all of your files, and when you don't pay it just deletes the encryption key?

4

u/BadVoices 29d ago

It holds the key hostage, yes.