1. Technical purpose of the “duress” PIN
The duress PIN is not meant to delete user files but to wipe the encryption keys that protect the data, rendering it unrecoverable without breaking the encryption.
“The duress password does not wipe the phone. It wipes the encryption keys from the secure element. … the data is worthless unless law enforcement cracks AES.” – microtonal
2. Legal & procedural risk at the border
Border officers have reduced Fourth‑Amendment protections, and simply giving a password can still result in prosecution, as shown by the case of Samuel Tunick.
“It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it.” – prmoustache
3. Need for backup, restore, or dummy‑profile tactics
Many users want a practical way to back up or switch to a harmless “decoy” profile before crossing a border, or to use remote/cloud‑phone setups.
“cloud phones as a service” / “self‑hosting a cellphone at home with some kind of remote access system.” – kotaKat
These three themes capture the main points of the Hacker News discussion: the cryptographic mechanics of GrapheneOS’ duress feature, the legal exposure when using it at a U.S. border, and the community’s call for practical backup or “clean‑phone” strategies.