GrapheneOS It's not possible to provide anything close to plausible deniability for wiping profiles. A deleted profile leaves behind metadata proving it existed in the device encrypted and Owner profile encrypted storage. There are a whole bunch of different ways it can be shown that it existed. ADB can be easily used to identify a wipe occurred and when it occurred. The standard approach used by forensic tools is connecting via ADB and they can easily add support for detecting this. It would be easy for non-experts to figure out how to do it especially with the guidance of a decent LLM. It would put users at risk who believe they can perform a stealthy wipe despite it not being possible. We do not want to provide a feature which cannot come close to working properly.
@GrapheneOS , it is true that the deletion of a secondary profile can be detected programmatically. However, wiping the entire device can be detected with the naked eye! Not every adversary has the technical skills or specialized software needed to find traces of a deleted profile or determine when it was deleted, but almost every adversary have eyes and can see that the device has been wiped. Therefore, deleting a profile is not completely stealthy, but it is certainly more stealthy than wiping the entire device.
Deleting a profile also removes its data almost as irreversibly as wiping the whole device removes the device’s data. Some metadata related to the profile’s existence or activity may remain here and there in the system, but the most sensitive information, including chats, media files, and application data, is gone in both cases.
A feature does not have to be perfect to be useful. If it is better than the existing alternative, I believe that is enough to make it worth developing. And wiping the profile is better in stealthines and on par in irreversibility with wiping the whole device.
There are many scenarios in which such a feature could be useful. Numerous examples have been discussed in several threads, including this GrapheneOS forum discussion, this GitHub issue, and this account.
An adversary is not always perfectly prepared. They may have limited time, limited technical expertise, or limited access to forensic tools. In some situations, it may be sufficient for the device to pass a basic initial inspection and for its owner to appear cooperative. The adversary may then decide that a more thorough examination is not worth the time or effort. This often happens during border inspections, as described in this comment, and the personal experience of one of my friends supports that account.
Or attacker can have only $5 dollar wrench and will to beat you until you give you password and beat harder if you give the duress one and wipe the device. Gang members, corrupt police officers, or abusive partners - especially in poor countries - may have neither the expertise nor the forensic equipment required to detect traces of a deleted profile. Nevertheless, they can immediately notice that an entire device has been wiped.
On the other hand, there are many real-world cases in which users could not use a duress password because doing so would have been too dangerous. Examples include this case from Mexico and this case from Romania. I also had an experience in which I was searched by police officers. They did not have any forensic tools with them, and their search was relatively limited. Fortunately, my device ran out of battery quickly. However, I am certain that I would have been in serious trouble if I had refused to reveal my password or had wiped the device using a duress password. In my country, using a duress password is simply not a realistic option unless the information stored on the device is worth more than your life. Deleting only a secondary profile allows the user to appear cooperative, at least at first glance. In some situations, that alone may significantly reduce the risk and make the feature useful. I'm sure that it could help me in my situation.
I greatly appreciate your work, and I apologize if any of my words have sounded accusatory or impolite. GrapheneOS is an extraordinary achievement and a technological masterpiece. It saves lives and provides strong protection against malware and forensic tools such as Cellebrite. It works as a charm in jurisdictions where human rights and the rule of law are respected.
However, technical excellence alone is not always sufficient. It is also essential to consider the realities users may face outside a purely technical threat model. Unfortunately, in regions where human rights and the rule of law are least respected - and where GrapheneOS may be needed the most - the operating system still cannot protect its users against the $5 wrench attack.
I believe it is time to pay attention to this issue and listen to the users who have requested this feature for years because it could genuinely help them in real-world situations. It could be extremely helpful in my own situation as well. Please give users the ability to make an informed choice about which protective measures are most appropriate for the threats they personally face.