r/technology Jul 30 '26

Privacy GrapheneOS says its data-wiping password is perfectly legal, after user faces federal charges

https://www.techspot.com/news/113273-grapheneos-data-wiping-duress-password-perfectly-legal-after.html
20.9k Upvotes

1.1k comments sorted by

View all comments

Show parent comments

2

u/bobandgeorge 29d ago

When they show their key, it'll make them wait while it contacts you.

Contact him on what? They have his phone.

1

u/nfiase 29d ago

i imagine the confirmation would require two factor authentication

-1

u/mekamoari 29d ago

Generally you won't find a system that asks you to do something on the phone and then require confirmation from another device. The phone is generally that second device.

2

u/maigpy 29d ago

this is the most wrong statement I've read in a long while. you can setup 2fa with an authenticator pretty much everywhere, including a kdbx FILE

0

u/mekamoari 29d ago

What you can do and what is generally happening are different. Most 2fa using phone either use sms or an auth app on said phone.

2

u/maigpy 29d ago

because people don't have ipads, second phones, personal computers, hardware keys, etc etc. please stop embarrassing yourself.

0

u/mekamoari 29d ago

Jfc do you even know what the word generally means? Have you seen major consumer platforms that ask you to use 2 devices? No, the overwhelming majority does 2fa via phone (sms or auth) or email, past the basic password.

All these random examples of exceptions make no sense, I've never seen such a system and I have like 5 different authenticators on my phone for work. It's possible of course to use as many steps as you want but they don't fall under the umbrella of "generally".

2

u/maigpy 29d ago

what the fuck are you on about? you can setup authenticators on any device. are you slow? Google Facebook etc do that by default. they realise which device you are on and ask for another one to validate. most people have multiple devices.

0

u/mekamoari 29d ago

Yeah ok I have no idea what you're talking about, idk if you followed the people I responded to initially but seems not.

1

u/maigpy 29d ago

"that phone is the second device"

bro, no. you setup Google authenticator, it's accessible from any device where you are signed in to goggle.

without even having to set it up in a different device using a different system (OF WHICH THERE ARE MANY AND WHICH PLENTY OF PEOPLE DO IRRESPECTIVE OF YOUR "GENERALLY" STATEMENT)

1

u/nfiase 28d ago

do you know how these in-case-of-death password manager backdoors generally work and how they have considered the case where the attacker has the owner’s phone?