Conversation

Jonathan Corbet

GrapheneOS has a "duress code" feature that will wipe the device if it is used in an attempt to unlock it. A potentially useful feature, but the US is now trying to prosecute somebody for having given the duress code to an officer demanding the unlocking of his phone.

https://www.theguardian.com/us-news/2026/jul/23/cop-city-protester-phone
26
299
252

@corbet
> In Catalonia, Spain, police have been profiling people with Google Pixel phones, assuming they have GrapheneOS installed and are drug dealers or gang members.

1
0
0

@corbet Next step: code which will switch to harmless account, while erasing main one first.

1
0
0

@corbet
He wasn't given his Miranda rights, so he wasn't under arrest. Which should mean that he was perfectly free to do whatever he wanted with his phone, including erase it.

But realistically he'll probably be put away for life anyway. This country needs a revolution.

0
0
0

@corbet The feature worked as intended.

0
0
0

@corbet What's extra fun is how this means they were not following procedure.

Cause if they were, they would have already had a backup of the device, making the durress code a big nothingburger.

1
0
0
Yeah, I remember there are some distributions that allow configuring two different drives to the same physical partition, one for each password. The trick is having a standard, innocent desktop on one, and the actual secrets in the other, while ensuring you don't go overboard with the storage space of either (as the "empty data" from one drive is the working data from the other).
0
0
0

Li ~ Crystal System

Edited yesterday

@corbet person was under duress, they shared the durress code. lol feature works

0
0
0

@Epic_Null @corbet not sure how the hell your supposed to make that backup but ok

2
0
0

@Li @corbet you ever see a harddrive copying machine? Those things don't process the data, they just make bitwise duplicates.

2
0
0

@corbet

Should have never given up any code in the first place without a warrant.

1
0
0

@corbet

Nice feature, but what if the cops do a bit-per-bit copy of the device before entering the code ?
I mean, they'd still have the copy, only the original will have been erased...

2
0
0
@lienrag As a general rule you have to unlock the phone before you can image it — and the contents of the drive are encrypted. If the phone is in the before-first-unlock state, especially, getting at its contents will be hard.

There are, naturally, forensics tools out there meant to bypass these protections. I have no way to know how effective they are on a GrapheneOS install.
0
0
4

@Epic_Null @corbet phones dont have hard drives...

1
0
0
@lienrag @corbet

> what if the cops do a bit-per-bit copy of the device before entering the code

how? USB won't work until the code is put in. They'd have to rip out the flash chips to copy the data
2
0
0
@corbet destroying evidence to prevent the cops from getting their hands on it has long been illegal, the state is probably on solid ground on with that argument.
0
0
0

@corbet This is like "putting your PIN into the ATM backward" only it actually works!

1
0
0

@feld @lienrag @corbet And they will do that sort of thing only after actual arrest, which this apparently wasn't.

0
0
0

@SpaceLifeForm @corbet pff 'just come back when you have permission from the other guy to hurt me' or just.. yknow.. defend yourseelf ..

0
0
0

@Li @corbet Not of the same type used in laptops and desktops, but the foundational technology is pretty close. Most of the data on your phone still lives in a chip that can be seperated and read.

I did a quick search to verify what I know, and while chip extraction is one of the most risky methods, there are also methods which utilize access to the bootloader (which would be unlocked in any pixel with graphine, because that's how graphine got on there in the first place). Once a cop has boot, they can absolutely make a bitwise copy.

There are other, more invasive methods as well, but the important part is that entering the user's passcode before to back up the phone using any of the specialized tools to do just that is a MASSIVE error that shouldn't just be happening, and indicates a process failure. Especially when you recognize that cops need access to the bitwise copy to check for things like deleted messages.

2
0
0

@feld

Which is something they certainly can do.
It adds friction, even a lot of it, and we know that friction is important and can dissuade many people.
But friction isn't enough to prevent bad things to happen.
So yes, GrapheneOS measure is good, but one needs to understand its limits.

@corbet

1
0
0

@Epic_Null @corbet sigh and this is why i should be the root of trust on my own fucking devices- so the cops can just not have my private key, and cant get shit,

but wait, you could store part of the key in a hardware crypto engine; and then the durress code could still wipe this, making any copy made before useless;

(basically, it could be like, .. key = bigmac_encrypt(sha256(user_pass)) .. or something; and then -- this wouldn't work. akko_shrug

1
0
0
@lienrag @corbet ok, so they ripped out the flash chips.

but all they have is encrypted data.

So now what? they'd have to be able to get the key out of memory
1
0
0

@feld

Obligatory XKCD : https://xkcd.com/538/

They have a copy, they know that it's an erasure code, so they can now ask for the actual decryption code.

Yes, there are situations when people can choose not to give the code even under duress.
And it's good to offer them the technical option to.

Again, I'm just saying that people need to understand the limits of this measure.

@corbet

0
0
0

@Li @corbet While I will not pretend it's impossible for the mouse to win this game, what you describe seems a few noches above what Graphine probably provides.

The point I make is less "The victim couldn't make this a problem" and more "The cops complaining they were given a durress code is a sign that they were already breaking the law and procedure".

2
0
0
@Epic_Null @Li The first step after a GrapheneOS install is to lock the bootloader again so no, it's not unlocked.
1
0
3

@corbet
I have often thought something like that would be quite useful. I guess it's soon going to be criminal to have any device without an official government back door

0
0
0

@corbet Just repeat after me: Do not travel to the USA! Under no cicumstances, at least until the current administration is gone!

1
0
0

@corbet bloody good on him, kept other protestors safe, destroyed information about himself. This common misconception that you have to be a drug dealer or criminal to secure your own device is a wild take. Wanting privacy, shouldn't label you a crook.

0
0
0

@corbet there’s no justifiable legal basis for that. If there’s a law, it’s unconstitutional. Freedom of speech would obviously dictate that you have the right to speak the duress code

Our court system has been corrupted and we need to stop tolerating these clear violations of the constitution

1
0
0

@corbet I couldn't possibly comment here.

0
0
0

@bugaevc @corbet yes the reason i hate it is definitely that I sit on mountains of cocaine and not the fact that I think my private life is none of their goddamn business. totally.

0
0
0

@Epic_Null @Li @corbet I keep getting the feeling that people haven't read the article.

0
0
0

@Epic_Null @Li @corbet It is not "a few notched above what Graphine [sic] provides". It is exactly what GrapheneOS does.

0
0
1

@corbet "Additionally, the agents produced no warrant and did not read Tunick his rights"
18 U.S.C. § 2232 a) "...the Government's lawful authority to take such property"

The government had no lawful authority absent a search warrant, thus 18 USC § 2232 shouldn't apply.

0
0
0

@corbet won't be long before broligargy and its minions in the governments pass a law saying any device not running the corporate overlords software unaltered is a crime, then don't even have to bother to unlock to see supposed unlawful content in it to put one in jail and throw away the key.

0
0
0

@corbet

GrapheneOS should incorporate fingerprint unlock as a method of initiating the "duress code". That way, you can just continue telling them "No. Stop. Don't." and when they press your finger on the screen anyway it will be 100% their own doing.

Side note: I can only imagine saying it with the same enthusiasm as Willy Wonka telling Mike Teavee not to climb into the Wonkavision.

1
0
0

@corbet Love how federal agents can break the law with impunity but then turn around and prosecute someone for something that *they* ultimately caused by doing something illegal..

0
0
0

@corbet @Epic_Null @Li

Correct, that’s one of Graphenes big advantages and one of the reasons why it only runs on Pixels because the hardware allows this.

0
0
0
@Epic_Null @Li @corbet I wonder if GrapheneOS provides full-disk encryption and whether it is broken or not.

If it's included and not broken, a bitwise copy would mean very little.
1
0
0

@corbet Ha ha ha, that's great! And my defense would be: "Oh, shit, I'm sorry, I was really nervous and I'm super-dyslexic, and darn if I didn't give you the wrong code. Sorry." 🙄

1
0
0

Abram Kedge🏴󠁧󠁢󠁳󠁣󠁴󠁿🇨🇦

@corbet it's worth noting that the article mentions that constitutional rights are suspended at International borders and international airports when questioned by immigration authorities.

What it doesn't mention is that recently the No Rights Zone has been extended to 100 miles from any border.

Most of the US population have lost most of their rights. You'd think someone would be challenging that policy.

0
0
0

@corbet since when is data property lol

0
0
0
@corbet how would they prove it was a duress code?
0
0
0

@elaterite @corbet making your duress code a single edit from your normal code seems like a high-risk/high-reward strategy.

1
0
0

@corbet it is also interesting the Spanish customs is targeting Google Pixel users for closer inspections. That's something that everyone without GrapheneOS might notice as well

0
0
0

@corbet One tactic to combat this kind of authoritarian persecution is to make an encrypted back up hosted remotely, wipe the device before crossing the border, and then restore the data when it's safe. If you're threatened into unlocking it, there would be a much lower risk of anything useful to the authorities being found, but you should always consider a device that's been seized or searched completely compromised and replace it.

But then you have to ask, will pigs start treating devices without your entire life on them as "evidence of criminal activity" because "only a criminal would factory reset their device"?
There will always be tools and tactics like this, but the actual solution to this shit is to abolish the institutions and structures that enable people to impose this "authority" over others.

0
0
0
@lispi314 @Epic_Null @Li @corbet I guess the best is to read their wiki:

https://grapheneos.org/faq#encryption

tl;dr more complicated than luks full disk encryption, but allowing the use of hardware security chip to store part of the security keys inside away from the storage disk, with protections against data extraction.
0
0
1

@Li @Epic_Null @corbet cops generally use Cellebrite UFED ( https://en.wikipedia.org/wiki/Cellebrite_UFED ) which can unlock & fully extract any phone, unless you have the latest iPhone or Pixel with GrapheneOS
See https://archive.org/details/cellebrite-device-unlocking-list-april-2024/ for leaked details from 2024

0
0
0

@IT_SME @corbet

Ain't that problematic cos you might end up triggering the finger print unlock by accident ?!

1
0
0

@agitatra @corbet

This got nothing to do with the current admin, the US has been doing this for quite some time !

1
0
0

@harib_murshidi @corbet I guess there is that risk. But in my case I prefer not to use fingerprint as an unlock feature so it would be easy for me to develop good habits around it.

In fact, I should be receiving two Yubikey Nanos in the mail today

My multifactor authentication will be combo Yubikey (something I have) + PIN (something I know). Combine that with a fingerprint initiated phone wipe and I'll be invincible!

1
0
0

@corbet unfortunately, the cops probably have it right on this one. You’re destroying evidence.

If it were normal police, the legal answer would be to refuse to answer any questions, including revealing any passwords. You can refuse to give up a code but you can’t refuse biometric data, which most people probably know by now.

Since it’s a border search you basically have no rights. Refusing the passcode is still probably the legal move but they can mess you around a lot.

0
0
0

@IT_SME @corbet
I still don't understand how it will work, the biometric/figerprint works in an instant for other apps ! unless you put in some kind of timer which will trigger the wiping operation (keep the finger on for 10 seconds) otherwise I can think of many ways how things can go awry !

0
0
0

@maxoakland Please let lawyers do the lawyering. The idea that freedom of speech can protect you from an obstruction of justice charge when you lie to a LEO about what your password is, resulting in the destruction of evidence, is just ludicrous.

@corbet

0
0
0

@aatch @elaterite @corbet That depends. How much data is stored *only* on your phone, and how long does it take you to re-flash it when you're back at your main computer?

0
0
0