The foundation behind the ultra-secure Android-based OS is speaking out after an activist was indicted for using a ‘duress password’ to prevent federal agents from searching his phone.

  • Lytia @lemmy.today
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    2
    ·
    6 days ago

    This is a very common complaint, and the main reason is that it’s way more complicated than it sounds. The duress feature is designed to immediately erase any chance to recover the unencrypted data from the phone by destroying part of the data used to derive the decryption keys (the other part being your pin/password, which can’t be destroyed for obvious reasons). Any attempt to boot into a fake OS would be obvious to anyone familiar with the OS, thus making it effectively security theater. Not to mention the waste of space maintaining a fake OS, which would require fully featured apps and settings, all of which would have to be designed to pass verified boot, which means you can’t actually destroy the original OS the way they do.

    There’s currently no known way to extract data from a locked GrapheneOS device, especially once it’s in BFU, unless you’ve heavily reduced the default security measures, so the duress pin/password is likely unnecessary unless the danger of someone accessing the data is greater than the punishment for destruction of the data.

    Also, the “big flashy rebooty show” is less of a feature and more of an unintended happenstance caused by the device immediately losing critical data and being forced to restart. The articles make it sound flashier than it is. It looks more like the device is powering on but the screen keeps disconnecting for a second, before going black.

    • Venia Silente@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      This is a very common complaint, and the main reason is that it’s way more complicated than it sounds. The duress feature is designed to immediately erase any chance to recover the unencrypted data from the phone by destroying part of the data used to derive the decryption keys

      Sure, but IIRC that does not help if the attacker can retain the device or clone it, yes? Once they have a copy of the raw data they can just throw a datacenter at it, for any future amount of time.

      • Lytia @lemmy.today
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        Let’s assume they successfully extract all the remaining data after you enter the duress pin. Which, while not impossible, extracting the data on most GrapheneOS devices would require physically desoldering the SSD from the phone and dumping the data.

        With the data extracted, assuming they attempt brute force, they’re not brute forcing your password, they’re brute forcing the entire decryption key, which is a mix of your password and a key generated when you first set up the OS (the latter of which was destroyed when the duress pin was entered). At that point, the phone owner, their entire lineage, and realistically the entirety of the universe itself will be long dead unless some breakthrough in cryptanalysis weakens AES256 such that it can be brute forced before all of humanity dies. That is to say, after the duress pin is entered, no one on Earth, even the device owner, can decrypt the data on the device.

    • Auli@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      5 days ago

      Wouldn’t he have been better off to just refuse to unlock it?

      • Lytia @lemmy.today
        link
        fedilink
        arrow-up
        1
        ·
        5 days ago

        In his case, probably. Depending on how the case plays out, it might be better that the officer wiped the device.