you are viewing a single comment's thread
view the rest of the comments
[–] 62 points 4 weeks ago* (1 child)

GrapheneOS should update the duress passcode to load a dummy profile like Only Key’s Plausible Deniability Feature.

  • source
  • hideshow 2 child comments
  • [–] -1 points 4 weeks ago* (2 children)

    Loading any profile allows the operating system access to root privileges, and opens potential for user privilege escalation.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 16 points 4 weeks ago

    The profiles are independently encrypted with a key derived from the user's profile PIN. If the other profiles are not logged in then their keys are not in RAM (and they get zeroed beforehand so they can't be read out of unallocated memory).

    Even if the bad guys get root via a LPE in a dummy account there are no keys to find and the profiles' storage are not mounted.

    You couldn't trust the device after that however, who knows what kind of persistent spyware they could have installed.

  • source
  • parent
  • [–] 10 points 4 weeks ago (1 child)

    Then it should delete the data while loading a dummy profile

  • source
  • parent
  • hideshow 2 child comments
  • [–] 13 points 4 weeks ago* (2 children)

    That would be an interesting proposition... under duress load profile x and delete all other profiles, apps, settings and keys.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 2 points 3 weeks ago

    I like this option, save a snapshot and restore that snapshot deleting everything else. So it looks like a regular profile but won’t contain anything you want to remain private.

  • source
  • parent
  • [–] 2 points 4 weeks ago (2 children)

    Or maybe a lighter version of the duress pin that just loads the fake profile (or alternate profile) but leaves the other(s) intact.

    If you're just handing your phone over for a border pig to swipe through before waving you through that might be adequate.

  • source
  • parent
  • hideshow 4 child comments