For non-graphene users (eg. Boring iPhone people like me).
So there’s a feature called Duress PIN which as explained through some comments means you put a different pin which intentionally wipes the phone. It’s not auto wipe or wipe after several failed attempts but intentional wipe of device. (Worth explanation as the current title nor the article doesn't easily explain this was made by the US citizen providing the alternative passcode)
For more technical details:
> GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).
PIN to wipe seems suspicious. How about a PIN where it login to a patriotic profile and phone looks like normal android.
This is exactly my setup with GrapheneOS. The default / main profile is patriotic, with a sterilized Telegram account, state-adjacent banks and apps, etc. The second profile (that uses a separate PIN) is not so patriotic: it has foreign bank apps, crypto apps, password manager, 2FA app, personal records, and an alternate Telegram account that I use to discuss any potentially unpatriotic topics with potentially unpatriotic people.
It would be cool if there's a third PIN that can wipe the unpatriotic profile whilst showing the patriotic one.
So you use 1st pin for normal use, 2nd for downloading your flight details on patriot mode, and 3rd for unlocking to patriot mode whilst silently nuking unpatriotic data.
Or a PIN that just nukes the data for certain apps (Signal, Telegram, WhatsApp, E-mail) etc. Feds can read my Slack messages all day.
Regarding Signal, Telegram, and WhatApp:
1. Never ever have Signal installed on the phone during border crossing. The presence of the app itself may trigger them (speaking from first-hand experience).
2. Having an empty Telegram account may look suspicious. My recommendation is to have two separate Telegram accounts, with the "unpatriotic" one in the separate profile only.
3. Never ever use WhatsApp for anything "unpatriotic". It's way of deleting messages leaves traces ("This message has been deleted") which may rise suspicions.
As for email, I just don't have any email clients installed on my "patriotic" profile. They all go to the "unpatriotic" one.
There's no PIN for deleting a particular profile, but you can quickly delete it manually, assuming that you have some private time available – for example, when you are stopped at passport control and told to wait in the waiting area.
It would be cool if there's a third PIN that can wipe the unpatriotic profile whilst showing the patriotic one.
So you use 1st pin for normal use, 2nd for downloading your flight details on patriot mode, and 3rd for unlocking to patriot mode whilst silently nuking unpatriotic data in case of seizure.
It's absurd that you have to do this and/or be so careful. But if you live in Russia, China, or another dictatorship, then I understand.
Yep, full agreement here. The amount of hoop-jumping is ridiculous. However, I live in Russia so I have to do all that, plus some more (e.g. the work to protect my own self-hosted VPN after Roskomnadzor issued the recommendation for big Russian online services to sniff out and report user's VPN settings).
I spent two weeks thinking about my new setup on Graphene OS and Windows, but it was time well spent. Before that, my checklist for pre-border-crossing cleanup required about 8 hours of work. With the new setup, I can complete the cleanup in about an hour, and restoring takes even less.
This is extremely hard to implement in a non-superficial way that would be hard to detect.
Android switched from block device encryption to filesystem-based encryption (with encryption data and metadata). This provides many security improvements, such as per-file encryption keys and per-profile keys.
However, this also means that the main file system is readable and you could enumerate the available users. If you would encrypt/obscure that information, you could still infer the presence of other profiles from file system block allocations.
(Disclaimer: not an expert, but I read the relevant Android docs at some point.)
I had this on a Xiaomi, maybe 10 years ago? Very cool feature! I hope they still do it. I think the wipe feature is also very cool, but not used in this way.
Fascinating. It seems the feature is called "Second Space"
https://www.mi.com/global/support/faq/details/KA-492586/
Profiles are a standard Android feature, nothing special to Xiaomi. GrapheneOS even extends and improves them in a lot of ways.
It's just not possible to hide them in a good way that would faze knowledgeable people or software.
Ok so what you're saying is Android doesn't have this feature. Xioami does. Type in a different pin and access a second space. Not the same as profiles, obviously
not accessible just by typing another pin on stock Android though.
And wipes the main partition in the background at the same time
Also too patriotic is sus. Better to keep some minor offenses (that give you a fine or a week of jail at most) on that partition so they will think that this is the thing that made you so nervous during the search
Impossible to implement securely, so they chose not to
That's a nice feature, every OS should have that.
I believe the old TrueCrypt had two passwords, each revealing a different set of files. You'd put e.g. your tax forms in one, so if forced to decrypt your drive, you could cooperate and do so.
It's not illegal to delete your own vacation photos. So to prove this guy guilty of destruction of evidence, does the government need to prove there was actual evidence in the phone?
It zeroes out the vault where the volume key is stored.
leaving the actual evidence files untouched...
Sounds like a feature that under right circumstances can land you in Guantanamo for 5 years where eventually you get cleared once the real terrorist gets caught.
The real terrorist were the cops.
Then you stay in Guantanamo indefinitely