It would be trivially detected by widely distributed standard forensic software including the non-Premium variant of Cellebrite able to run on a laptop.
By “duress profile”, I mean that if user has enabled a “duress profile” feature in Settings, then entering the duress PIN would:
Erase (the encryption key for) all profiles and storage outside the duress profile; then
Unlock the duress profile.
So, how would forensic software detect that the unlocked profile is a duress profile?
@GrapheneOS@grapheneos.social
By “duress profile”, I mean that if user has enabled a “duress profile” feature in Settings, then entering the duress PIN would:
So, how would forensic software detect that the unlocked profile is a duress profile?