Hi everyone,
I would like to propose a feature that, in my opinion, would take GrapheneOS to an even higher level of security. Auto Reboot is already an exceptional feature because, after the time set by the user, it automatically restarts the phone and brings it back to the Before First Unlock (BFU) state. In this condition, the encryption keys have not yet been loaded and the device is much more protected. In my opinion, however, we could go even further. Even when the phone is in BFU, in fact, all the data is still present. It is protected by encryption, but it still exists inside the device. This means that the phone could remain in someone's hands for days, weeks, months, or even years, still giving them the opportunity to attempt forensic analysis, hardware attacks, or any other technique that does not exist today but might exist in the future. My idea is very simple. After the phone automatically enters BFU thanks to the Auto Reboot, a second countdown should start, which is completely configurable by the user. Everyone should be able to choose the time they prefer: 10 minutes, 30 minutes, 1 hour, 6 hours, 12 hours, 24 hours, or any other interval. If the correct PIN or password is not entered within that time, the phone should automatically initiate a complete and irreversible wipe. When I say complete, I mean truly complete. The system should delete any data present on the device: all encryption keys, all eSIMs, all user profiles, all applications, all photographs, all videos, all documents, all files, all settings, and any other information stored in the internal memory. In practice, the phone should return exactly to how it came out of the factory, completely empty, leaving no user data behind. In my opinion, this would represent the highest possible level of security. It does not matter if the phone is stolen, seized, or remains in someone's hands for months. Once the time set by the user has elapsed without entering the PIN, the device automatically wipes itself and there is absolutely nothing left to recover. It does not matter what technique is used, today or in the future, because the data to be analyzed simply will no longer exist. This function should be completely optional and designed exclusively for users who want the highest possible level of security. In my opinion, it would be a natural evolution of Auto Reboot and would add an additional layer of protection to an operating system that is already the gold standard in the field of security.
Thank you for your time and consideration. I would love to hear your thoughts on this.
Best regards,