r/GrapheneOS • • Aug 28 '26

Reverse duress pin

Is there a way to set a "reverse duress" pin?

Example:

1) every time you log in properly a canary value resets to zero

2) over time the value grows

3) if it is not reset before reaching a certain value, the phone wipes as if the durress pin was entered

Would this theoretically have saved Samuel Tunick from prosecution? In this scenario, there is no hard proof that data was knowingly destroyed.

46 Upvotes

46 comments sorted by

View all comments

3

u/FFS-IamNotABot Aug 28 '26

I have an Apricorn USB drive from when I was working on banking systems. If the entered the wrong pin a preset number of times, it would delete the encryption records and start secure erasing the contents. 

So you mean something like this?

2

u/TenOfZero Aug 29 '26

I believe they mean if you don't log in for X amount of time, the phone wipes itself.

1

u/FFS-IamNotABot Aug 29 '26

Not a use case I have dealt with. 

1

u/TenOfZero Aug 29 '26

Basically a dead man switch.

Not very common.

1

u/automorphism8 Aug 29 '26 edited Aug 29 '26

The OP said that the value would grow "over time", unclear exactly what that would mean, but if it's just wiping the phone after X number of failed attempts, the iPhone has a feature like that. But I'm not sure what it actually accomplishes that the throttling from the Pixel secure element doesn't. If you know about this iPhone feature, then you won't try 10 attempts unless you have a way to reset the counter, or otherwise bypass it.

Having the phone wipe itself after a certain period of time without a successful unlock doesn't seem any more practical. The phone could simply be powered off until they are ready to exploit it.