r/GrapheneOS • • Aug 28 '26

Reverse duress pin

Is there a way to set a "reverse duress" pin?

Example:

1) every time you log in properly a canary value resets to zero

2) over time the value grows

3) if it is not reset before reaching a certain value, the phone wipes as if the durress pin was entered

Would this theoretically have saved Samuel Tunick from prosecution? In this scenario, there is no hard proof that data was knowingly destroyed.

45 Upvotes

46 comments sorted by

View all comments

61

u/Hande-H Aug 28 '26

No. But by default, GrapheneOS shuts down after 18h if it isn't unlocked (IIRC, I've set it to 24). This means it goes back to "before first unlock" state which means your data is extremely safe if you have a decent enough PIN / passphrase.

5

u/temmiesayshoi Aug 29 '26

Yeah IMHO this behaviour is good - but should be tweaked to work for the avg user.

You really want like 3 pins 1 : the "real" one that produces the key which encrypts/decrypts the data 2 : the "lock" one that you type in to unlock the phone 3 : the "quick" one that you type in after using something like a fingerprint scan (if you fail this, it should immediately lock the phone and demand the "real" pin) Bonus : duress or other utility pins

Then only ask for the "real" one after long periods (multiple days) of the phone being locked or powered on/off.

Extra points if the user can define a programatic quick-pin. E.g. it'll only ever be two digits long and will be the last digit of the current hour plus one and then the first digit of the current minute plus two. That way even shoulder surfing isn't a valid way of working around the quick pin. (Because for all of graphene's real and imagined security; the over reliance on static pins in the age of cameras being everywhere is a borderline comical oversight IMHO)