Instead of wiping and rebooting, it should wipe while showing a lame spreadsheet application, or possibly a grocery list.
Instead of wiping and rebooting, it should wipe while showing a lame spreadsheet application, or possibly a grocery list.
Leaked documents from mobile forensics companies, such as Cellebrite or XRY confirm this. It's impossible to crack a Pixel with GrapheneOS in BFU state. See https://grapheneos.social/@GrapheneOS/112462758257739953 and https://grapheneos.social/@GrapheneOS/112826067364945164
id expect that youd be ordered to retain the data though, if an investigation is being done
But this stance amounts to giving up. Within the wiggle room a system gives us there are still ways to widen cracks or attach a lever, however small they may be.
Do, I guess the cops will continue to beat me until I produce a valid passcode.
Government overreach cannot be solved with technical solutions.
The duress wipe feature shuts the device down to let RAM discharge, this is an important step to remove any components of decryption before they can be lifted.
For GOS to consider it, it would likely need to be backed by the secure element.
Duress PIN is deemed acceptable to implement in the OS because it is expected that the user is the one to enter it, so it has not fallen into the hands of attackers who may bypass it. Once attackers have it, you are effectively gambling. Account for that in your threat model and do not let it get to that point.
Doesn't really matter if the reboot timer is triggered if the thugs have beaten your code out of you.
It shouldn't be this way, but oh well.