20 hours ago
- Hidden or stealthy duress modes are not viable because forensic software is aware of GrapheneOS and would detect them.
- GrapheneOS's duress PIN/password is designed to be obvious, creating a dilemma for adversaries about whether the input will unlock or wipe the device.
- The wipe occurs nearly instantly by destroying hardware keystores, secure element, and disk encryption metadata, followed by clearing RAM via shutdown.
- Granting access to a decoy profile would increase attack surface for exploits, making data extraction easier.
- The feature relies on deterrence through awareness, not secrecy, and is intended to protect against coercion rather than hidden data extraction.