this post was submitted on 27 Jul 2026
327 points (98.8% liked)

Technology

86695 readers
3663 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] modem_down@thebrainbin.org 6 points 3 days ago (1 children)

@GrapheneOS@grapheneos.social

It would be trivially detected by widely distributed standard forensic software including the non-Premium variant of Cellebrite able to run on a laptop.

By "duress profile", I mean that if user has enabled a "duress profile" feature in Settings, then entering the duress PIN would:

  1. Erase (the encryption key for) all profiles and storage outside the duress profile; then
  2. Unlock the duress profile.

So, how would forensic software detect that the unlocked profile is a duress profile?

@modem_down @beep @Semi_Hemi_Demigod The software walks the person using it through enabling Android Debug Bridge and extracting data with it. It's either not going to work or will be able to see many signs of what happened. GrapheneOS is well known to the forensic data companies and they make a point of trying to support it. They haven't had much success with locked GrapheneOS devices but they can certainly handle detecting it and detecting if a feature like this was used via ADB.