You can probably already use situations/automagic for much better results for implementing deniable deadman’s switch, I don’t believe sfos needs this specific implementation at OS level, the gos implementation is so blatant and primitive to be useless when actually facing gov employees, instead have some triggers that replace your contactsdb/messagedb/whatever with phony ones (or the other way around, actually that would be preferable, by default you enter the mom-dad-grandma phone state, second hidden pin for actual data, can’t even blame your for data deletion if it remains second stage encrypted), if you haven’t performed a certain action within 15-30seconds after unlock, even if they figure out something happened you complied (gave them pin), bricking/wiping on duress pin entry is just too obvious/blatant
I think it’s less senseful when having troubles with cops but can be very senseful in context of e.g. robbery or blackmail. So imho it would be senseful to implement it.
Probably also in cases of robbery/blackmail (you mean kidnapping with goons with guns to your head? Not sure how blackmail comes in with duress pin) you also want to not be blatant you just destroyed the data, if it was the thing they kidnapped you for I would expect a BANG right after
Not a must have for me. I mentioned earlier that I’ll never again enter the US with a mobile device. But it’s impressive that the feds couldn’t (so far) recover any data from the Graphene OS after the user wiped it. Assuming that’s true, it seems logical that lower tier threats won’t have an easy time with it.
I don’t know about other jurisdictions, but in the US there would be a “battle of the experts,” where the prosecutor would bring an expert to testify that it ain’t just Linux being kooky and the defendant would bring their witness to the contrary… and the judge or jury would go with the one who’s more charismatic, irrespective of facts. I wouldn’t be surprised to learn it works the same way in many other jurisdictions that SFOS works in. Perhaps a European lawyer here can chime in on that. I don’t have a lot of confidence in plausible deniability and my primary interest is my data.
But in any case that wouldn’t erase the facts that Graphene has the feature, that Graphene is avail here in Europe where I reside, that Graphene is getting a ton of free publicity out of this that has put Graphene front and center to many people who never heard of it, and that it’s driven interest from people like me in learning whether SFOS has it or will develop it because I’m not going to buy a Pixel and I’m not going to use Graphene.
Yes. The commenter I responded to said this: “We need such a feature but one that loads some default content for plausible deniability to not get in trouble like the guy from the original article.”
As I mentioned to another commenter along these lines: I’ll happily take a bullet to my head rather than lead the attacker to my fam and friends through my phone.
I think this thread is getting a little de-trailed here…
So, I didn’t even know this kind of feature before this year. I probably don’t ever need this kind of thing. Would I set it up if natively integrated? Probably. But I see why for some it would bring sense of security and peace of mind. So let’s give them room to wish the feature while thinking best way to have it. Jolla probably could do it, but I’m sure it won’t get on top of list they need to do. So community PR or other way is probably fastest route.
Feature like this isn’t probably that must have in Europe for average Sven, which is one of the safest places in World. But I have friends from not so nice part of Latin America for example, where I know they would love this kind of feature (+in the USA). But as Americas aren’t the market area, at least for now, I encourage for community dev effort here.
Graphene got a ton of free PR over this incident, that’s certain.
And I agree with everything you said.
Ah with the PR I meant Pull Request. Which is fancy software term that someone makes the work and then asks Jolla to review/accept it.
Many thanks; I’m a first time poster, and not a dev myself ![]()
Yeah, me neither, took some time for me also to understand what it means ![]()
I don’t see how that means Jolla somehow assumes risk. The better implementation is multiple accounts anyway.
SailfishOS has settings - factory reset , not the same as duress password but may be helpful and better than nothing in case.
A fully functional backup and restore process, along with a factory reset, may indeed have worked in the situation described by the OP better than a duress password.
One could simply reset the phone before crossing an international border and then rsync everything back afterward.
nobody does this, let’s stop pretending it is a viable solution
The whole thread is people who never does this giving dream advices how people who’d need it should do (but never will do)
I’m literally required by company policy to do that with some devices (not phones, though), so “nobody does this” is a bit of a generalization.
It’s not a dream advice, here you have root, you can do whatever your heart desires, graphene gives you a set of predefined options and that’s it, you’re stuck with them, if graphene devs consider logging into a fake account with a duress pin somehow more obvious than a reboot and greeting you with: hello lets set up your phone; that’s it, enjoy gettig banned from their forum for doubting their leader. Fact is even border grunts in US can catch on their current implementation of duress pin, so the fake account being too obvious argument doesn’t really hold water, but bam, it’s been decided and as gos user you have nothing else to do or say as you cannot be trusted with root, literally night and day vs sfos, where if you’re paranoid enough you can write your own systemd services that no grunt will recognize
Cool, you might as well just ask them to pull the trigger right away, if the alternative option is your phone rebooting into ‘hello, lets setup your phone’ screen, with alternate profile they might think the data is still there somewhere, with obvious ‘yup it’s been reset, whatcha gonna do about it, pull the trigger?’ why even waste time?