• modem_down@thebrainbin.org
    link
    fedilink
    arrow-up
    5
    ·
    9 hours ago

    @GrapheneOS@grapheneos.social

    It would be trivially detected by widely distributed standard forensic software including the non-Premium variant of Cellebrite able to run on a laptop.

    By “duress profile”, I mean that if user has enabled a “duress profile” feature in Settings, then entering the duress PIN would:

    1. Erase (the encryption key for) all profiles and storage outside the duress profile; then
    2. Unlock the duress profile.

    So, how would forensic software detect that the unlocked profile is a duress profile?

    • GrapheneOS@grapheneos.social
      link
      fedilink
      arrow-up
      2
      ·
      33 minutes ago

      @modem_down @beep @Semi_Hemi_Demigod The software walks the person using it through enabling Android Debug Bridge and extracting data with it. It’s either not going to work or will be able to see many signs of what happened. GrapheneOS is well known to the forensic data companies and they make a point of trying to support it. They haven’t had much success with locked GrapheneOS devices but they can certainly handle detecting it and detecting if a feature like this was used via ADB.