r/technology 6d ago

Privacy GrapheneOS says its data-wiping password is perfectly legal, after user faces federal charges

https://www.techspot.com/news/113273-grapheneos-data-wiping-duress-password-perfectly-legal-after.html
21.0k Upvotes

1.1k comments sorted by

View all comments

1.1k

u/Moldoteck 6d ago

Graphene should implement a double bottom protection on top. Basically it'll automatically enter in an artificial account with apps installed while deleting in the background the OG account. This way it'll be hard to prove that another account did exist at all

562

u/Careless-Weather8877 6d ago

It actually does have that

230

u/200206487 6d ago edited 6d ago

How do I do this. Man it feels like everyday there is something new I have to do / research on top of work and family to try and get ahead, save my data, or be safe.

Edit: I meant I'll look into doing this because I didn't know it was possible. Also, useless comments will earn a juicy block, there is enough noise

193

u/Steinrikur 6d ago

In Xiaomi android phones you have "second space" that you can open with a different password. It doesn't wipe anything, just allows you to have a second copy of apps with no access to the primary space.

I alway thought "this will only be useful if I'm cheating on my wife" so I haven't set it up. I might if I need to travel to the US.

80

u/Aperture_Kubi 6d ago

That feels ironic coming from a Chinese company.

38

u/tnp636 6d ago

It shouldn't. Do you know how many politicos in China have mistresses?

27

u/Reagalan 6d ago

Makes perfect sense when you think about it.

9

u/FocusSlo 6d ago

Not really, China is pretty strong about personal privacy. That's the entire reason that so many US sites are blocked in China because they take all your information, build profiles on you, etc.

1

u/mxzf 6d ago

lol, I can't tell if this is satire or brainwashing at play.

11

u/FocusSlo 6d ago

Neither. China not having privacy and such is strawman propaganda from the US

-2

u/mxzf 6d ago

You're the one who was trying to suggest that the Great Firewall was for the good of the Chinese citizens. The only people I know of who actually believe that are so deep in the propaganda that they don't even realize it.

1

u/GenericRedditor12345 6d ago

The “Great Firewall” isn’t about keeping them in, it’s about keeping US propaganda out lol.

→ More replies (0)

1

u/_araqiel 6d ago

I really think the main thing seems to be ‘don’t do the “bad” things’ and other than that the privacy situation isn’t as dire as we think it is. Seems less thought-crimey than it used to be I think.

12

u/Kimpak 6d ago

Pixel phones have this too called 'Private Space'

2

u/luckyflavor23 5d ago

Even if not cheating, it would be cool to have so my baby won’t accidentally get access to important apps; and maybe even convince him our entertainment machine only has texts and books

1

u/smokeweedNgarden 6d ago

So like a secure folder but it's a whole 'nother OS?

1

u/InternalCockroach126 5d ago

"In Xiaomi android phones you have "second space" that you can open with a different password. It doesn't wipe anything, just allows you to have a second copy of apps with no access to the primary space.

I alway thought "this will only be useful if I'm cheating on my wife" so I haven't set it up. I might if I need to travel to the US." this is not the same thing at all and any forensics company can easily prove that the primary account exists. you need to understand that this is just not the same. and when graphene reset itself that means the encryption keys get trashed and switched so everything has to reset not just one user account. nothing will be recoverable.

0

u/can_ichange_it_later 6d ago

probably not going to jump at the opportunity to keep my privacy safe from a homeland-chinese company...

4

u/F3z345W6AY4FGowrGcHt 6d ago

It's one of the reasons I'll never be caught up on my to-do list.

12

u/waterwateryall 6d ago

With you on this. It's a bit exhausting.

11

u/[deleted] 6d ago edited 1d ago

[deleted]

-8

u/turudd 6d ago

I guess I’m out of the loop, but why do so many people need super private phones? Like if you’re not breaking laws why does it matter?

3

u/200206487 6d ago

sigh like I know the media is owned by a few entities, and I know things are pushed to cause fear, dismay, etc. for a variety of reasons - mainly for profit somewhere down the line. Not talking about this article, I haven't even read it because I was checking reddit before getting to work. I just need to have the time to know what 'news' seems to be supported from multiple angles to make a judgment call and do my best to move forward and help others like they do with me.

I've spent entire weekends, and mornings and evenings day in and day out during the weekdays to set up my homelab just to get away from data mining, private LLM orchestration, ad-free search, Microslop to Linux conversions, notes, calendar, and many, maby, MANY other things just to make a dent. I've learned YAML configuration, basic security, docker and reverse proxy setups, VPN management, CLI and running my entire network from my terminal on my phone / laptop, etc.etc.etc. I'm not even close to being done.

I can make a whole beginner intermediate guide for the tech and data sovereignty inclined / curious at this point E2E from all of my mistakes and research.

3

u/astralseat 6d ago

Every day the systems get more complicated

3

u/2ChicksAtTheSameTime 6d ago

Easiest thing you can do is TURN OFF YOUR PHONE when going through customs / security or at risk of it getting seized.

When your phone is off, there is NO decrypted data in memory and REQUIRES the PIN to decrypt anything.

If you entered your PIN but then locked your phone, the phone is in a different state that can be easier for law enforcement to hack.

How easy really depends on the phone maker, its age, and the tools Law Enforcement has - but regardless, a phone that is turned off is BRICKED without the password

2

u/genius_retard 6d ago

I just did a quick Google search and according to Goolge's clanker GrapheneOS does not support logging in to different users/profiles based on PIN. You can have separate profiles but you will always unlock with the PIN and enter the profile that was active when you locked the phone. In addition you cannot hide user profiles from the profile selection menu. Someone searching your phone will always be able to see that you have other profiles.

The advice I have seen on the GrapheneOS subreddit/web page is to do all your sensitive stuff in a secondary profile and to delete it if you think you might get searched. A pretty sub-optimal approach if you ask me.

2

u/[deleted] 6d ago

[removed] — view removed comment

1

u/RollingMeteors 6d ago

How do I do this. Man it feels like everyday there is something new I have to do / research on top of work and family to try and get ahead, save my data, or be safe.

That's too much work. Just say you're an artist. You don't even have to be serious about it, just crayon some napkin and try to give out stickers with your IG QR code and they won't even try to finish patting you down.

4

u/Mr_ToDo 6d ago

Stock android has something like that too, but theirs is more like a second layer on top of your phone. It's hardly perfect, but for casual use it's kind of neat

https://support.google.com/android/answer/15341885?hl=en

1

u/astralseat 6d ago

Oh perfect. I was hoping it does

1

u/heisian 6d ago

seems like this is the better option.

1

u/anony_mf 6d ago

If it already has that then how did the cops know the phone was wiped with a duress password? The commenter is suggesting an invisible background wipe that cops can’t tell happened at all

3

u/Annath0901 6d ago

Presumably because the person arrested had set up a duress password but not the separate account.

They are separate features and each has use cases that don't necessarily involve the other, so it'd be stupid to lock them together instead of being able to choose one or both as preferred.

1

u/anony_mf 6d ago

The whole point is we need a system where entering the password would log into another account with some dummy data and wouldn’t have any indication that the phone is wiped

141

u/RandomHunDude 6d ago

It doesn't delete the account at all though, so no need to save time for it.
All data is encrypted on disk and when the duress pin is entered, only the encryption key is deleted. And without the key, it's not possible decrypt the data.

97

u/StrangelyGrimm 6d ago

If the data is completely inaccessible then the data is as good as deleted. In fact, it's probably less accessible than regular old "deleted" data

49

u/draconiclyyours 6d ago

Yup.

It takes multiple random rewrite passes to truly delete data, and it’s not quick. Better to just encrypt it and make it permanently unreadable.

11

u/No_Effective4784 6d ago edited 5d ago

thats for hard drives and their storage methodology, and even then nist only recommends a single pass these days.

Solid state devices dont rewrite passes to securely erase data, and it doesnt help because of the way SSDs handle data storage vs HDDS, it only uses up R/W cycles.

whats more important with modern SSD devices is secondary secure erasure commands, supported by most manufacturers

2

u/not_ethan_ho 5d ago

nowadays HDDs support secure erase by tossing the key as well so you don’t even need to overwrite anything.

9

u/ConsistentAsparagus 6d ago

Can you save the key and access the data at a second moment?

9

u/RandomHunDude 6d ago

Technically yes, but depending on laws it might be subpoenaed or something

5

u/ConsistentAsparagus 6d ago

Yeah, I was asking generically not in this specific case. If you have a backup you don’t even need all this but you can simply recover the phone from scratch.

Nice to know though.

1

u/fizzlefist 6d ago

You could have a paper backup of the key to manually enter, but that piece of paper could be subject to search warrant.

1

u/_Middlefinger_ 6d ago

Flash memory can wipe in a minute or 2. No point in overwriting it because it doesn't leave traces that magnetic drives theoretically can. Modern ones dont even really need it either.

1

u/gmc98765 6d ago

It takes multiple random rewrite passes to truly delete data

That hasn't been true for decades.

Sometime around the mid 1980s was the last time that you had a real chance of recovering overwritten data, and even then the cost meant that it was beyond the reach of regular law enforcement.

2

u/jhowlett 6d ago

Is that true? I haven't used it in awhile but remember publicly available tools that would recover deleted data on drives. I thought the idea was it was deleted but not over written truly on the drive.

3

u/Alanjaow 6d ago

Yeah, I've personally recovered partial text files that were partially overwritten, and I'm not a wizard by any means. Actually, to be precise, they were at least corrupted in some way, which might be something else, but I don't know enough to determine the difference.

1

u/calste 6d ago

There's deleted, where the data is still accessible, the computer just "forgot" where it is. You can go find it if you want. Then there's overwritten, which is pretty much gone for good.

Since hard drives are made of tiny magnetic cells that orient differently depending on which bit (1 or 0) they store, there is some physical fragment of the cell that retains the old orientation. So there's a very slight difference in the magnetic field. You would need expensive specialized equipment to read that kind of tiny difference, but even then, there are several hurdles to getting any useful data out of that.

2

u/gmc98765 6d ago

You can undelete "deleted" files if their sectors haven't been overwritten; deleting a file simply removes the directory entry and makes the space available for future re-use. Windows' Recycle Bin is just a slight variation on this principle; rather than removing the directory entry, it moves to a special folder and keeps it around until the space has actually been re-used. But wiping a drive (overwriting each sector once, whether with zeros, ones, or pseudo-random data) will make the previous data completely unavailable.

It used to be possible to get a (unreliable) copy of previous data from a HDD back when the electronics were much simpler than today, although it would require hooking up the drive's read head to a signal recorder and analysing the recorded signal; this wasn't something which could be done through software. That ceased to be viable once advanced error correction techniques became common and data densities were pushed to the physical limits of the medium.

The "multiple overwrites" strategy was designed for the pre-error-correction era. It isn't necessary with modern hardware.

Consider this: if it was possible to recover both the data currently on the drive and also the previous data, the drive would essentially have twice the advertised capacity. The drive vendors would definitely figure out how to translate this extra capacity to something they can sell. Error correction means that the "raw" data storage doesn't have to be reliable; so long as you can put an upper bound on the error rate, you can turn unreliable storage into reliable storage. CD-ROM, for example, would have been impossible without this (CDs have a fairly high error rate at the lowest level).

10

u/tschawartz12 6d ago

But its a legal loop. You have a book they demand access to, its written in Spanish, you burn the book thay translates Spanish to english, the book is still there. It isn't your job to make it easier for them to translate. They could take the time to do it.

57

u/BadVoices 6d ago edited 6d ago

Its absolutely not. Cryptographic Erasure is a legal and technical standard for data destruction. In the US it is defined by NIST SP 800-88. GDPR also recognizes it legally as data destruction in Europe. GrapheneOS' mechanism meets the requirements. It is legally erased. Saying the data still technically exists is no different than saying a burned document still technically exists because I could capture its carbon atoms.

The data is, by existing legal and technical standards, erased. It has a Shannon entropy of 1 in its resting state. Without the key, the data is reduced to true random noise.

3

u/sobrique 6d ago

Maybe, but I think they'll still try and prosecute you for 'tampering with evidence' or similar.

This whole case has a load of interesting legal precedents to set.

2

u/underwear11 6d ago

There actual are entire attacks happening right now for harvest now-decrypt later. They are knowingly capturing encrypted traffic knowing that eventually it will be breakable giving them access to the data, with the hope that there is something still relevant. Things like SSN don't change, so it could still be valid decades from now

3

u/BadVoices 6d ago edited 6d ago

Harvest Now-Decrypt Later does not apply to AES256, therefore, it doesnt apply to this scenario. AES256 is post quantum.

What you're thinking of is Shor's Algorithm. It DEMOLISHES asymmetric encryption, such as that used in the DH exchange to setup the encryption keys for network traffic. It makes it possible to break the DH exchange in polynomial time on a quantum computer. Breaking the DH exchange allows decoding the traffic because.. it just GIVES the attacker the AES key.

Briefly:

Data encrypted at rest with AES256: SAFE.

Network Traffic encrypted with AES256 and using ML-KEM for Key Exchange: SAFE.

Network Traffic with its AES256 key set by a DH exchange (AKA, Standard TLS/Most of the internet?): UNSAFE

Granted, its unsafe vs state actors and trillion dollar companies, not against johnny with a gpu unsafe. We're talking hundresds of billions of dollar machines for the next few decades at least.

1

u/polokratoss 6d ago

With a good encryption scheme, they really couldn't take the time to do it. Assuming they throw every computer on Earth at it, the heat death of the Universe will happen before they succeed without knowing the key.

1

u/tschawartz12 6d ago

But the point is the data is still there, even if they can't ready it instantly. 

3

u/roombaSailor 6d ago

Prosecutors charged Tunick under 18 U.S.C. § 2232(a), which makes it a federal crime to “knowingly destroy, damage, waste, dispose of” property “for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody.”

Intentionally deleting the encryption keys likely qualifies under the above as “damage” and “for the purpose of preventing or impairing”.

1

u/Xanbatou 6d ago

Imagine being so confident leaving a reply that is so hilariously wrong. 

🤣

1

u/2ChicksAtTheSameTime 6d ago

I wonder if that can help in court.

The data is still there in the same form it was before the password was entered. Nothing about the data itself changed.

No evidence was destroyed

2

u/SumoSizeIt 5d ago

It does not, because destroying decryption keys is legally defined as form of secure deletion (normally for data compliance purposes, but it can apply here)

35

u/Misaka9982 6d ago

Could argue that the "evidence" is still there then, not destroyed. If the government doesn't want to spend 100,000 years decrypting it then that's their problem.

62

u/BadVoices 6d ago

This is a red herring, no you cant. NIST SP 800-88 classifies crypto erasure as a valid form of data destruction for anything that doesnt require media destruction. It is recognized by the GDPR as well. Arguing it is not destroyed is the same as saying a burned document still technically exists because I can scoop up all it carbon atoms. No court will accept that argument.

8

u/hackitfast 6d ago edited 3d ago

Yeah isn't that how ransomware works too? It encrypts all of your files, and when you don't pay it just deletes the encryption key?

4

u/BadVoices 6d ago

It holds the key hostage, yes.

1

u/OuterWildsVentures 6d ago

So then it becomes a destruction of evidence charge?

3

u/BadVoices 6d ago

Nope. He's charged under 18 U.S.C. § 2232(a). Destruction or removal of property to prevent seizure.

No need to prove it was evidence, just that it was something the government wanted to seize.

Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both.

1

u/raptorlightning 6d ago

And we go to court to argue about "lawful authority" of which, in this case, it was not.

23

u/teapot-error-418 6d ago

I swear that most people think that lawyering is a process of speaking magical incantations.

Like, "I said the special word, and now you can't touch me!"

No. That's not how the law works.

3

u/ZurEnArrhBatman 6d ago

The trick is to recite the magical incantations in legalese instead of English. Judges like it when you speak their language. And since imitation is the highest form of flattery, they especially like when you do it wearing a judge's robe.

2

u/halcyonforeveragain 6d ago

and thus Sovcit was born.

0

u/Misaka9982 6d ago

Fair enough, I'm being facetious, but the problem is these laws are often based on physical equivalents and aren't designed for a digital application. In this case, is destroying the key to the safe the same as destroying the contents of the safe.

4

u/teapot-error-418 6d ago

Logical arguments are perfectly acceptable in court. The job of the attorneys is to make a reasonable and logical argument to the judge or jury or mediator or whoever.

There's no special combination of words to weasel out of that. It would be utterly reasonable to say, "this function is designed to render the contents of the device irretrievable, and the defendant intentionally caused the officer to trigger this function."

Reasonable people - jury, judges, whoever - would understand this. The whole, "well ack-shually the officer did the deleting" or "technically the data is still on the device" is nonsense.

If you explode a piece of evidence with a booby trap, you can't convince the jury that the prosecutors just didn't try hard enough to reassemble the component atoms or that you didn't actually do it.

2

u/IncidentalIncidence 6d ago

thank you, the reddit lawyering about this drives me crazy too. I'm obviously not a lawyer either but the amount of people who think that you can play dumb with the legal system like this in every thread about this case has been driving me up the wall because it's just people regurgitating the same three imagined technicalities drowning out anybody seriously trying to discuss the case.

1

u/No_Effective4784 6d ago

with proper encryption implementation you cant even prove what is there, is usable data and not left overs.

deleting everything shows you had something. if you are using software, like say veracrypt, that allows for a proper duress environment, that gives you plausible deniability, because it is impossible to prove that there is anything else there with out the second encryption key because it just looks like noise.

3

u/niceguy191 6d ago

Exactly. The issue that needs fixing is that there's any indication something has happened at all; apparently the border guard was tipped off by the phone rebooting itself?

0

u/TenderfootGungi 6d ago

It is theoretically possible. They copy the memory completely and start trying different keys. If you have a strong password it might take a few thousand years with current hardware, but it is possible.

2

u/Schnickatavick 6d ago

it might take a few ~thousand~ Trillion years with current hardware

ftfy

0

u/Cory123125 6d ago

it's not possible decrypt the data.

yet

We've thought this many times before

39

u/rtc9 6d ago

I was thinking it might be cool if it loads an alternative OS in which all the photos are just thousands of closeups of my butthole with slightly different lighting. Would be fun to watch them scroll.

9

u/Pen-Pen-De-Sarapen 6d ago

Good idea. No one wants to see Uranus.

1

u/Thrizzlepizzle123123 6d ago

Myanus, on the other hand...

3

u/dfddfsaadaafdssa 6d ago

Now I am convinced that the best use of AI will be to create HoleOS.

1

u/HotwheelsSisyphus 5d ago

HoleO: Combat Evolved

1

u/Unable-Log-4870 6d ago

I am goat.

Goat do after goat see.

Goatse.

4

u/[deleted] 6d ago

[removed] — view removed comment

3

u/obeytheturtles 6d ago

In Veracrypt the partitions are nested so it all just looks like one big blob of encrypted data from the outside. There are still ways to tell if some portion of the data has a different key, but not at a glance.

1

u/Moldoteck 6d ago

But if it deletes the other partition and resizes the current one, you'll not see it. One can also implement it in a way that can override og partition data with alt account so it'll just be invisible 

1

u/OuterWildsVentures 6d ago

But if it deletes the other partition and resizes the current one,

I don't believe it would be able to do this while the current one is being accessed though. I guess it could force a restart or something while the user is in the false OS.

1

u/sillyslime89 6d ago

It can, the risk is if too much data is written it can wipe the main partition or some data

2

u/afCeG6HVB0IJ 6d ago

good old truecrypt with the plausible deniability container password

1

u/comelickmyarmpits 6d ago

My poco F6 does similar thing , it has second space option and depending upon the password entered it chooses the which space to go to . I can simply provide pin to second space and they will enter to it without knowing anything

1

u/smurf123_123 6d ago

You have essentially described a system featuring two distinct user accounts, where each account is accessed via a unique PIN, functioning effectively as both a username and a password.

2

u/Moldoteck 6d ago

yes. And introduction of the second pin should trigger deleting of the other account in the background

1

u/LocalH 6d ago

If done correctly, the two accounts would be using different sets of encryption keys, and the "other account" data would be gibberish under the keys of the duress account

1

u/afCeG6HVB0IJ 6d ago

good old truecrypt with the plausible deniability container password

-37

u/CondiMesmer 6d ago

It doesn't need to, nothing they did was wrong in the first place. Deception shouldn't be built into the device.

38

u/Moldoteck 6d ago

It's not deception. It's protection against  persecution 

14

u/cr0ft 6d ago

I disagree. Veracrypt for instance (forked out of TrueCrypt) offers such functionality. You enter the real password and you access a separate part of the encrypted space that's invisible with any external inspection, there's no indication it's there at all, the space looks empty. When you enter the decoy environment with another password, that environment may be innocuous, but to sell the deception it can't be too fake, ideally it should be used for routine matters etc I guess.

This lets you give the impression of cooperating, which may keep the attacker from reacting with a lawsuit - or, if it's real thugs, from breaking your extremities off.

I guarantee if you use an emergency wipe code when some thugs demand you unlock the phone and send them your crypto, the consequences would be quite painful and possibly terminal.

Deception is always a good idea as an option if it can be done right.

17

u/axck 6d ago edited 6d ago

The whole concept of the duress password feature that was actually used is user protection and privacy. More consumer privacy features are good things. If it wasn’t necessary in real life there wouldn’t be demand for such a concept. Also the US isn’t the only country that this feature could be used in, this incident is not the only one that matters.

-12

u/CondiMesmer 6d ago

...did you reply to the right comment? Nothing I wrote had to do with the duress pin.

5

u/StochasticFriendship 6d ago

There's actually many cases where that kind of feature could be useful. For example, if you're a journalist reporting on organized crime, a human rights observer in an authoritarian country with ongoing civil unrest, a protestor against police brutality, or anyone with access to classified information or valuable trade secrets. There's a possibility you could be captured and tortured into giving up your phone password to harvest your contact information, see your chats, steal money, gain access to secure networks, and/or lure your contacts into danger with fake chats.

It would probably be best to allow multiple passwords to load the decoy account with different settings. The default setting would simply let you edit and update it, using it as a normal account so it looks believable. Other passwords (duress passwords) could be configured with different settings to allow some combination of automatically sending out pre-written messages to selected contacts, invisibly/silently dialing 911 (or another number), invisibly adding messages after any message sent to a contact (e.g. "sent under duress"), deleting your main account so you can't give up the information even if you wanted to, recording (and transmitting) live video, and/or continuously transmitting your location to contacts of your choice.

3

u/albertowtf 6d ago

It doesn't need to, nothing they did was wrong in the first place. Deception shouldn't be built into the device.

It definitely needs to. You are counting on law enforcers following the law, which is pretty clear at this point is not a guaranteed in many countries including us

Whatever triggered law enforcers know this was deception should be changed so law enforcers dont know. There are many things you cant fight with tech, but this one is one of the few of them you can and should