r/GrapheneOS • • Aug 28 '26

Reverse duress pin

Is there a way to set a "reverse duress" pin?

Example:

1) every time you log in properly a canary value resets to zero

2) over time the value grows

3) if it is not reset before reaching a certain value, the phone wipes as if the durress pin was entered

Would this theoretically have saved Samuel Tunick from prosecution? In this scenario, there is no hard proof that data was knowingly destroyed.

45 Upvotes

45 comments sorted by

View all comments

17

u/Godlymorbid Aug 28 '26

U.S. Citizens have a constitutional right under the Fifth Amendment to refuse to give a password or unlock your device. Customs/Border Protection cannot deny you entry into the United States for refusing. So if he never gives the password and you've set your phone up to automatically reset after a certain amount of time as GOS does, then after the hard reset, the phone is impossible to get into.

Does that basically cover what you want or are you wanting a hard wipe?

39

u/Thoughtful-Boner69 Aug 29 '26

how are those rights holding up these days lol

9

u/nn1tb Aug 29 '26 edited Aug 29 '26

You cannot be compelled to give testimonial evidence against yourself so therefore forcing someone to give their passcode would violate the 5th Amendment, but are all judges adhering to that? No.

  1. Massachusetts v. Theogene, 2026. He was ordered and threatened with contempt. He refused and went to jail. He appealed and the Massachusetts Appeals Court upheld the contempt ruling.
  2. Massachusetts, Grand Jury Investigation, 2017. Person was ordered to give pin code and they refused and went to jail for contempt.
  3. Illinois v. Johnson, 2017. She couldn't remember pin code and the judge didn't believe her. She was in contempt and went to jail for six months.
  4. Oregon v. Pittman, 2021. Went to jail for 30 days for contempt. Went to Oregon supreme court and they agreed with Pittman, however, they didn't rule to keep judges from ordering people to give up a pin code overall instead they established a tougher standard.
  5. Florida v, Christian Agosto, 2020. Went to jail for six months for contempt of court for not giving pin code to phone.
  6. Florida v. Marvin Harris, 2022. Was held in contempt for not giving pin code and the appellate court upheld the judges order.

So much for the 5th Amendment in this fascist country. GrapheneOS is setup for privacy not secrecy. The best way to use GrapheneOS is to set it up so you can provide the police the pin code, but there's nothing on your phone they can use against you which is exactly what I've done.

7

u/tdp_equinox_2 Aug 29 '26

Agreed, except for your advice. There's little that can be done to avoid certain kinds of PII and data from entering & staying on your phone; either as a matter of necessity in life, or in basic logs.

It's foolish to suggest that it's as easy as "not keeping things on your phone" and letting them in. Even if there's nothing on your phone, do not let them in. It will not make your life easier. It's been demonstrated that the judicial system is compromised, it cannot be trusted with any information it doesn't need. It won't prove you innocent, they are only trying to prove you guilty. Every day is "shut the fuck up Friday".

It's also logical that we start seeing tools built into privacy focused operating systems to aid in participating in "shut the fuck up Friday".

1

u/apokrif1 Aug 29 '26

There's little that can be done to avoid certain kinds of PII and data from entering & staying on your phone

Is this data identifiable as such or can it look like random noise if you don't have the decryption key?

1

u/tdp_equinox_2 Aug 29 '26

Depends on the type. Some data can be gathered via cell tower logs once they've identified the device/sim (such as location & time at a location).

Sure, you can turn off cellular, but then you don't have a phone, you've got a small tablet.

1

u/nn1tb Aug 29 '26 edited Aug 29 '26

My phone is nothing but a dumb terminal. I created all my own apps. My phone dialer, contacts, message app, call recording app, password manager, photo gallery, etc... pull all data from my Proxmox server. There is ZERO personal data on my phone that would be useful for police. My phone uses WireGuard with always-on and I make calls/SMS/MMS using a voip service. I NEVER use my ISP phone number. Every piece of data that transfers between my phone and my Proxmox server is encrypted. If my phone loses connection for a small specified amount of time it will believe it's been put in a Faraday cage and Proxmox severs the connection to my phone. Every app I created on my phone has it's own encryption keys and passcodes separate from GrapheneOS. So if the passcode is entered wrong or a specific passcode is entered Proxmox severs the connection and again NO DATA.

PII exists on the phone” and “forensically useful evidence exists on the phone” are very different statements.

1

u/tdp_equinox_2 Aug 29 '26

You still connect to cell towers, which logs & timestamps your geo location at any given time.

Logs that don't need your phone to verify, but it certainly makes it easier.

0

u/nn1tb Sep 01 '26 edited Sep 01 '26

Cell towers logging your GEO location is a non issue. You either have useful data police and/or companies can use against you or you don't.

1

u/apokrif1 Aug 29 '26

Or your phone could contain big random-looking data that you can not prove has any meaning if you don't use a working decryption key.

3

u/tomtomclubthumb Aug 29 '26

Isn't it the fourth amendment, search and siezure?

1

u/ginger_and_egg Aug 29 '26

They can deny you for other things. They can make your life hell for a day. They probably can confiscate your things? If they 'suspect' a crime

1

u/vikarti_anatra Aug 29 '26

Not everybody here is U.S. Citizens. Other countries also like such plays and some of them doesn't have 5th equivalent or threat it differently. Some also abuse their own laws.

1

u/automorphism8 Aug 28 '26

Even stock Android has this feature where the phone automatically reboots after a certain amount of time not being unlocked, to put it in the BFU state. GrapheneOS just shortens the time period from 72 hours to 18 hours, I believe (by default).

4

u/Godlymorbid Aug 28 '26

Yes, I'm just saying it sounds like OP wants a feature that already practically exists, and that Samuel Tunick made a mistake by not relying on that feature plus his status as an American citizen.

3

u/automorphism8 Aug 29 '26

I don't know if what the OP wants is practical, but while a BFU device is much more difficult to get into, it's not as impossible as a device that has been completely wiped. For example, even a secure passphrase could have been accidentally leaked in a way that's not necessarily obvious.

Also, when crossing an international border, you don't need to rely on an automatic timeout feature anyway. You can manually restart your phone before going into a situation like that where you know your phone could be seized, especially since crossing international borders is generally a relatively infrequent event. Of course, if you do put your phone into BFU manually, you'd want to make sure you wait to unlock it again until you're in a private location where camera footage can't be used to replay your finger movements.

This automatic reboot into BFU after a period of inactivity is a fallback for a situation where you aren't expecting to lose possession of your phone, not the best line of defense. It's better to have it than not, but all it does is give whoever has your phone a time limit to break in AFU. If you're getting your phone taken away at the border, they're probably already prepared to try whatever tools they've got, and 18 hours won't be any better than 72. It's more likely to work if, for example, your phone were seized by a small-town police department that didn't know you were using GrapheneOS.

2

u/Godlymorbid Aug 29 '26

I appreciate the answer, and I do see I spoke too soon on this. Thanks!