Remix.run Logo
br0ceph 16 hours ago

if u read the grapheneos tweet about this, any form of minimal account puts all ur other accounts at risk. agents should never get any form of code execution on ur device, even from a sandbox account. the linux kernel is not secure, and they can just hold the device till the next public disclosure or use one of their existing cellebrite attacks.

duress password to shutdown instead of wipe could be an option.

duress password to restore to snapshot, effectively wiping all data after snapshot, is another option, as it would be hard to know what happened. all the now "free space" gets overwritten with prng.

when entering the duress password, maybe grapheneos needs to put some UI theatre, like saying battery low, shutting down... so the agents think the phone is just shutting down due to low battery.

another theatre could be a fake shutdown, that appears to not startup again... just wipe and kexec a fake kernel that just mimics a dead phone, till the batter actually dies. any attempts by the agents to charge the phone , is met with a fake boot and a charging error. This is just a phone with a bad battery, nothing to see here.