333

The foundation behind the ultra-secure Android-based OS is speaking out after an activist was indicted for using a 'duress password' to prevent federal agents from searching his phone.

you are viewing a single comment's thread
view the rest of the comments
[-] veniasilente@lemmy.dbzer0.com 1 points 2 days ago

This is a very common complaint, and the main reason is that it’s way more complicated than it sounds. The duress feature is designed to immediately erase any chance to recover the unencrypted data from the phone by destroying part of the data used to derive the decryption keys

Sure, but IIRC that does not help if the attacker can retain the device or clone it, yes? Once they have a copy of the raw data they can just throw a datacenter at it, for any future amount of time.

[-] LytiaNP@lemmy.today 1 points 1 day ago

Let's assume they successfully extract all the remaining data after you enter the duress pin. Which, while not impossible, extracting the data on most GrapheneOS devices would require physically desoldering the SSD from the phone and dumping the data.

With the data extracted, assuming they attempt brute force, they're not brute forcing your password, they're brute forcing the entire decryption key, which is a mix of your password and a key generated when you first set up the OS (the latter of which was destroyed when the duress pin was entered). At that point, the phone owner, their entire lineage, and realistically the entirety of the universe itself will be long dead unless some breakthrough in cryptanalysis weakens AES256 such that it can be brute forced before all of humanity dies. That is to say, after the duress pin is entered, no one on Earth, even the device owner, can decrypt the data on the device.

this post was submitted on 28 Jul 2026
333 points (100.0% liked)

Privacy

5940 readers
15 users here now

Welcome! This is a community for all those who are interested in protecting their privacy.

Rules

PS: Don't be a smartass and try to game the system, we'll know if you're breaking the rules when we see it!

  1. Be civil and no prejudice
  2. Don't promote big-tech software
  3. No apathy and defeatism for privacy (i.e. "They already have my data, why bother?")
  4. No reposting of news that was already posted
  5. No crypto, blockchain, NFTs
  6. No Xitter links (if absolutely necessary, use xcancel)

Related communities:

Some of these are only vaguely related, but great communities.

founded 2 years ago
MODERATORS