| ▲ | qurren 11 hours ago | |
Would it have been wiser if that person had, as a US citizen, just refused to provide a PIN? At the most they'd just confiscate the phone, and it'd be encrypted anyway. No actual destruction of anything. On another note, maybe GrapheneOS should add some kind of feature where the phone involuntarily destructs if a correct PIN isn't entered for 48 hours (or whatever the user sets at installation time, and changing the value should not be permitted). That way the trigger for the wipe is the confiscation, not the act of entry of a duress PIN. You could disclose the mechanism to the officials who intend to confiscate, and also say (truthfully) that you have no control over the feature. | ||
| ▲ | microtonal 10 hours ago | parent | next [-] | |
Would it have been wiser if that person had, as a US citizen, just refused to provide a PIN? Purely technically it would also depend on the state of the phone. Phones can be read out/exploited more easily after first unlock (AFU) than before first unlock (BFU). So, a middle path would be putting the phone in BFU. Much harder to use exploits against the phone and biometric authentication doesn't work. One way of fairly reliably doing this is setting the reboot timer to 10 minutes or turning off the phone in critical situations. It's also relevant to take into account that he wasn't protecting himself by wiping the phone, but fellow activists. So, he may have taken the risk of potential legal issues by wiping the phone to project others. | ||
| ▲ | chii 11 hours ago | parent | prev [-] | |
This is a form of legal evasion similar to warrant canaries imho : https://en.wikipedia.org/wiki/Warrant_canary i m not sure how legal a protection it is, and whether the courts would interpret your choice of OS as complicit in evidence destruction. | ||