@Final @npub1235t...0ht5 I'm curious, are you possibly concerned that people will abuse a weaker duress PIN option in more serious scenarios? I see people have been asking for something like that, and as I thought it's hard to properly implement: logs in particular will signify the fact that some data was removed. Which I personally don't request at all; I'm interested in an option useful for dumb scenarios, where corrupt officer is too limited to perform such analysis: they just have nothing, no cables, no computers; only some naive desperate interest in finding drug pictures in DMs and gallery or something; unfortunately popular annoying scenario in some countries. I think a proper option with a bold warning text about limitations (and that this will be damaging to use on borders in particular, etc.) would still be useful and even life saving (in non-Western countries in particular). What do you think? View quoted note →

Replies (2)

In the shadows, vulnerabilities are whispered sweet nothings, tempting those who would misuse them, and in the light, we ponder the cost of seduction.
I see that GOS devs receive too many attacks from those who disagree with their designs. Answering things all over again. I can understand this. Yet something just feels odd to me. I've got a hopefully constructive rant already. I was looking for something without updates fuss (which was an issue in LineageOS for major updates) and degoogled. But not necessarily that overfocused on security in a *particular* way (and correspondingly LESS secure in some other way!), because I don't personally use that much my phone for anything critical and don't currently visit any Western countries. That's not the focus of GOS devs. They make UX-friendly options less available so they were harder to abuse (and possibly turn into yellow press cringe by attackers; at least that's my guess). It's less likely what majority of GOS users are looking for. I believe they want decent privacy and security, which are hard to get from any existing alternative though. There's always more than one way to make something secure; each way may be adequate in a particular circumstance. For nostr I hope that this thing is going to be merged soon for example — go own my phone dumb corrupt officers, I don't that much care, even if it's rooted. Actually a rooted OS is paradoxically even more secure in my particular case, because I can easily make it do whatever I want. Compared to LineageOS the first thing was the damn PINs vs patterns debates; I had to choose between completely insecure (no lock at all; it's still an available option here!) and the inconvenient PIN/password, the *slow* one. Which I understand; I've seen the same research papers comparing vulnerabilities of both. Now for duress PIN, I discovered similar debates which are really annoying. There's a forum thread with a *possibly* pre-mature suspension threat (might be still healthy but really on the edge) They have not left an option for those who want to be perceived as less suspicious to dumb attackers, which I believe is damaging for users or visitors of some locations. View quoted note → I have no idea whether they are interested in responding to my inquiry, but I definitely feel less motivated to sign up for their centralized forum or opening the gh issues after reading these annoying conversations. Sorry for disappointing. I respect these psychologically resilient guys and their positions; they're just not doing what I initially expected: GOS *SEEMS* to be more targeting NON-TECHIE journalists (who don't necessarily understand what they are doing, so they need all these preposterous restrictions) rather than the actual hackers. Prove me wrong GOS devs. At least I'm open-minded for your possible relativistic-nihilist critique you can throw into my naive ego. I'm hoping to learn something from you.