Now that i am thinking about it, There should be nothing stopping you from mapping a specific finger to either wipe data or load into a decoy. I’ll look into this.
EDIT: Confirmed, the reader gives the ID of which print was matched, so a userspace implementation for per finger macros should be possible, this goes beyond unlocking or duress too, in theory any script could be called from a specific finger?
Yah, but you better be damn sure it’s bulletproof recognition, especially for the wipe variant, although, being Linux a good backup strategy is a viable option, maybe gate it behind a successful restore. Seems like it could be easy to just use the wrong finger too, perhaps your subconscious hates you today. Still, options are always good.
I have touched the fingerprint reader on accident with the incorrect finger when picking the device up or something because it’s on the side with the power button, but I have never had an issue where I’ve meant to unlock my device with the correct finger and used the wrong finger instead.
I have used the wrong finger on purpose in order to press the power button in order to bring up my lock screen without actually unlocking the phone to see the time or whatever, though so perhaps a 3 strikes your out rule would be best where if you hit the fingerprint reader with the wrong finger 3 times in a row it would then wipe
Let’s say my pointer finger is the registered finger for the reader. If I want to unlock my phone, I’ll just touch the fingerprint reader with my pointer finger and the phone is unlocked. If I wanted to say interact with a running media file, or check the time, I would deliberately press the power button with my middle finger, that way it registers it as a press to bring up the lock screen, but does not unlock the phone. And then, when I want into the phone next time, I would touch the fingerprint reader with my pointer finger to unlock it. If I am picking my phone up off of a table, for example, and my ring finger just happens to touch the fingerprint reader, it’s obviously not going to recognize, and then once I get the phone in my hand properly, I would use my pointer finger to unlock it.
This is why I think perhaps a three-time rule might work, where if you deliberately touch the fingerprint reader three times within a short period of time with the incorrect finger, it would initiate a wipe.
I think a good decoy feature would be to insert a specific pass phrase to not reset the entire device, but to permanently delete specific (pre-specified) folders on the phone such as chat logs, documents, and specific apps.
GrapheneOS wipes the device, and that’s apparently enough to get people in trouble in the US. If the phone kept on working as normal without notifying anyone of anything unusual, but deleted sensitive documents behind the scenes, that would be really cool for these types of situations.
I’m not sure fingerprints would be useful for this. You can always just enter a pass phrase instead, and it would be very annoying to trigger it by accident which would almost certainly happen to some people. It would be neat if different fingerprints could be used to load different user profiles.
Now that i am thinking about it, There should be nothing stopping you from mapping a specific finger to either wipe data or load into a decoy. I’ll look into this.
EDIT: Confirmed, the reader gives the ID of which print was matched, so a userspace implementation for per finger macros should be possible, this goes beyond unlocking or duress too, in theory any script could be called from a specific finger?
Sounds like a cool feature!
Yah, but you better be damn sure it’s bulletproof recognition, especially for the wipe variant, although, being Linux a good backup strategy is a viable option, maybe gate it behind a successful restore. Seems like it could be easy to just use the wrong finger too, perhaps your subconscious hates you today. Still, options are always good.
Well that’s not really under my control as i don’t make the sensor, but it does expose an accuracy value, so the user can set their own threshold.
Not implying it was, just pointing out the foot shooting scenario.
Thanks again for the great work.
I have touched the fingerprint reader on accident with the incorrect finger when picking the device up or something because it’s on the side with the power button, but I have never had an issue where I’ve meant to unlock my device with the correct finger and used the wrong finger instead.
I have used the wrong finger on purpose in order to press the power button in order to bring up my lock screen without actually unlocking the phone to see the time or whatever, though so perhaps a 3 strikes your out rule would be best where if you hit the fingerprint reader with the wrong finger 3 times in a row it would then wipe
Let’s say my pointer finger is the registered finger for the reader. If I want to unlock my phone, I’ll just touch the fingerprint reader with my pointer finger and the phone is unlocked. If I wanted to say interact with a running media file, or check the time, I would deliberately press the power button with my middle finger, that way it registers it as a press to bring up the lock screen, but does not unlock the phone. And then, when I want into the phone next time, I would touch the fingerprint reader with my pointer finger to unlock it. If I am picking my phone up off of a table, for example, and my ring finger just happens to touch the fingerprint reader, it’s obviously not going to recognize, and then once I get the phone in my hand properly, I would use my pointer finger to unlock it.
This is why I think perhaps a three-time rule might work, where if you deliberately touch the fingerprint reader three times within a short period of time with the incorrect finger, it would initiate a wipe.
I’m thinking maybe like within 10 seconds.
Could probably also make it a sequence of several fingers to reduce risk even further.
I think a good decoy feature would be to insert a specific pass phrase to not reset the entire device, but to permanently delete specific (pre-specified) folders on the phone such as chat logs, documents, and specific apps.
GrapheneOS wipes the device, and that’s apparently enough to get people in trouble in the US. If the phone kept on working as normal without notifying anyone of anything unusual, but deleted sensitive documents behind the scenes, that would be really cool for these types of situations.
I’m not sure fingerprints would be useful for this. You can always just enter a pass phrase instead, and it would be very annoying to trigger it by accident which would almost certainly happen to some people. It would be neat if different fingerprints could be used to load different user profiles.
Oooh that’s cool! Thumb for normal unlock, index finger for launch camera, middle finger for duress would be neat.
Good thinking on the camera launch, and middle finger for duress is just… :chefskiss:
give them the middle finger!!