It would be trivially detected by widely distributed standard forensic software including the non-Premium variant of Cellebrite able to run on a laptop.
By “duress profile”, I mean that if user has enabled a “duress profile” feature in Settings, then entering the duress PIN would:
Erase (the encryption key for) all profiles and storage outside the duress profile; then
Unlock the duress profile.
So, how would forensic software detect that the unlocked profile is a duress profile?
@modem_down@beep@Semi_Hemi_Demigod The software walks the person using it through enabling Android Debug Bridge and extracting data with it. It’s either not going to work or will be able to see many signs of what happened. GrapheneOS is well known to the forensic data companies and they make a point of trying to support it. They haven’t had much success with locked GrapheneOS devices but they can certainly handle detecting it and detecting if a feature like this was used via ADB.
@GrapheneOS@grapheneos.social
By “duress profile”, I mean that if user has enabled a “duress profile” feature in Settings, then entering the duress PIN would:
So, how would forensic software detect that the unlocked profile is a duress profile?
@modem_down @beep @Semi_Hemi_Demigod The software walks the person using it through enabling Android Debug Bridge and extracting data with it. It’s either not going to work or will be able to see many signs of what happened. GrapheneOS is well known to the forensic data companies and they make a point of trying to support it. They haven’t had much success with locked GrapheneOS devices but they can certainly handle detecting it and detecting if a feature like this was used via ADB.