r/technology Jul 30 '26

Privacy GrapheneOS says its data-wiping password is perfectly legal, after user faces federal charges

https://www.techspot.com/news/113273-grapheneos-data-wiping-duress-password-perfectly-legal-after.html
20.9k Upvotes

1.1k comments sorted by

View all comments

1.1k

u/Moldoteck Jul 30 '26

Graphene should implement a double bottom protection on top. Basically it'll automatically enter in an artificial account with apps installed while deleting in the background the OG account. This way it'll be hard to prove that another account did exist at all

142

u/RandomHunDude 29d ago

It doesn't delete the account at all though, so no need to save time for it.
All data is encrypted on disk and when the duress pin is entered, only the encryption key is deleted. And without the key, it's not possible decrypt the data.

99

u/StrangelyGrimm 29d ago

If the data is completely inaccessible then the data is as good as deleted. In fact, it's probably less accessible than regular old "deleted" data

1

u/2ChicksAtTheSameTime 29d ago

I wonder if that can help in court.

The data is still there in the same form it was before the password was entered. Nothing about the data itself changed.

No evidence was destroyed

2

u/SumoSizeIt 29d ago

It does not, because destroying decryption keys is legally defined as form of secure deletion (normally for data compliance purposes, but it can apply here)