diff --git a/static/features.html b/static/features.html
index e4cf1b53..bb5e2458 100644
--- a/static/features.html
+++ b/static/features.html
@@ -111,6 +111,9 @@
Broad carrier support without invasive carrier access
LTE-only mode
Private screenshots
+ PIN scrambling
+ Supports longer
+ passwords
Improved user profiles
@@ -503,6 +506,27 @@
it to be useful.
+
+
+
+ GrapheneOS adds a toggle for enabling PIN scrambling to raise the
+ difficulty of figuring out the PIN being entered by a user either due to
+ physical proximity or a side channel.
+
+
+
+
+
+ GrapheneOS supports setting longer passwords by default: 64 characters
+ instead of 16 characters. This avoids the need to use a device manager to
+ enable this functionality.
+
+ This feature allows users to make use of diceware passwords if they don't
+ want to depend on the security of the secure element which provides very
+ aggressive throttling and offers a high level of security even for a random 6
+ digit PIN.
+
+
@@ -563,14 +587,11 @@
- Improved user visibility into persistent firmware security through version
and configuration verification with reporting of inconsistencies and debug
features being enabled.
- - Support for longer passwords by default (64 characters instead of 16)
- without requiring a device manager
- Stricter implementation of the optional fingerprint unlock feature permitting
only 5 attempts rather than 20 before permanent lockout (our recommendation is
still keeping sensitive data in user profiles without fingerprint unlock)
- Support for using the fingerprint scanner only for authentication in apps
and unlocking hardware keystore keys by toggling off support for unlocking.
- - PIN scrambling option
- Per-connection MAC randomization
option (enabled by default) as a more private option than the standard
persistent per-network random MAC.