Live data from Hacker News

GrapheneOS and forensic extraction of data (2024)

discuss.grapheneos.org

21–30 of 208 posts

Re: GrapheneOS and forensic extraction of data (2024)

#21

[flagged]

So you were called out over on Nostr by Final regards the Tor app which you mistakenly took to be integrated when they simply showed the app and it running on the OS, not IN it and decided to come to HN for an anti-Graphene sympathetic ear?

The reply you were called out for, for other people's benefit: It's not bundled. It isn't going to be bundled. This is a post showing a work in progress beta app that most users have not seen before. This app is developed officially by Tor to hopefully replace Orbot, it is informational content.

"GrapheneOS has long been suspicious about the revenue values it receives." GrapheneOS Foundation is a registered Canadian non profit that declares it's accounts and has filed accounts registered against them for this year and last year too. Nothing is suspicious.

From a forensic perspective? You don't provide ANY forensic basis or evidence for anything you claim.

You prefer Chinese devices? Suggesting people use something known to be objectively less secure on a technical level and known to be closely tied to the Chinese government/military and not legally able to refuse their requests is strange. Even if US gov is the only threat you consider, this makes little to no sense. Especially when it has been revealed that forensic analysis firms used by the US LE agencies have revealed that they see GrapheneOS Pixel devices to be the hardest if not impossible to extract especially in BFU state. There is a reason European LE agencies and their media have gone to extra lengths to smear users as criminals due to how stymied they are in extracting data. A job you want to make easier by making ludicrous hypersensationalised claims based solely in the realm of fantasy.

Re: GrapheneOS and forensic extraction of data (2024)

#23
post #7

Earlier quoted context omitted.

The 50s~70s are idealized by many as an American golden age, despite higher reported crime. Law enforcement back then did not have AI-powered surveillance camera networks, widely deployed IMEI stingrays, private data-brokers, or the ability to remotely activate any phone's microphone with 0-click RCE.

What's the 0-click RCE thing?

A type of exploit (Remote Code Execution) that can be used to secretly infect your device with spyware without requiring any interaction from you (0-click).

Re: GrapheneOS and forensic extraction of data (2024)

#24
post #4

There is no such thing like "bad government" and "good government". I mean - it really depends on people's views, therefore we must not blissfully put our data into govt hands because "they will protect us from terrorists and child rapists". What they will do, actually, is that for sure they will abuse innocent citizens at some point of time. They will. Even if they don't, they will. Or maybe they are doing it right…

No. When the government fails to delivery what people need (not necessarily wants), you have a bad government. When gangs and bandits (or drugs, or diseases, or whatever) takes on the street, it's not about people's view, it's just bad stuff that the government need to address or there's no point on having a government.

Aside from the fact that there's a subjective definition problem here (how do we decide what people "need"?), I think this an unrealistic view. By this definition, every government that has ever existed or ever will exist is a "bad" government because no government can ever tackle every single problem 100% of the time. Many problems are extremely difficult to solve (e.g. global warming), and others simply cannot be solved without creating other problems.

For example, people "need" access to healthcare, but there's essentially an unlimited amount of money you could spend to keep improving healthcare (e.g. opting for increasingly expensive treatments with diminishing returns on health outcomes). The more money you allocate to healthcare, the less you have available to spend on other things that people "need". Sure, you can tax more up to a point, but eventually that tap runs dry and you're forced to reallocate existing resources.

As another example, people "need" criminals to be punished in order to be able to live in a safe a crime-free society. People also "need" to not be put in prison when they are innocent. But you can never be 100% sure that a convicted criminal actually committed the crime. Locking up criminals implies by necessity that you will also lock up some innocent people. No government can solve both of these problems simultaneously which means they are all "bad".

Even the most competent "good" government ultimately has to select among which "bad" things it is going to allow to continue and which it will solve.

Re: GrapheneOS and forensic extraction of data (2024)

#25
post #4

There is no such thing like "bad government" and "good government". I mean - it really depends on people's views, therefore we must not blissfully put our data into govt hands because "they will protect us from terrorists and child rapists". What they will do, actually, is that for sure they will abuse innocent citizens at some point of time. They will. Even if they don't, they will. Or maybe they are doing it right…

It's an interesting argument in theory, but in practice the government in my country of origin actively searches through people's phones to find evidence of wrongthink (e.g. donations or incriminating social media activity), for which they sentence people to incredibly long prison terms.

The latest example: https://en.zona.media/article/2025/08/27/irin

That said, no matter how secure GrapheneOS may be, for this particular threat a permanently clean phone is a necessity.

Re: GrapheneOS and forensic extraction of data (2024)

#28
post #7

Earlier quoted context omitted.

The 50s~70s are idealized by many as an American golden age, despite higher reported crime. Law enforcement back then did not have AI-powered surveillance camera networks, widely deployed IMEI stingrays, private data-brokers, or the ability to remotely activate any phone's microphone with 0-click RCE.

What's the 0-click RCE thing?

Pegasus [0] and the like — commercial spyware updated with the latest exploit chains, developed in-house or purchased from markets like Zerodium, sold as terrorism-prevention tools to such trustworthy states as Russia, UAE, and Hungary.

[0] https://en.wikipedia.org/wiki/Pegasus_(spyware)

Re: GrapheneOS and forensic extraction of data (2024)

#29

I've always found it strange that GrapheneOS only runs on Google hardware. Can anyone explain this choice?

They've clearly explained here. I'm not sure how many people would keep asking the same question without even doing a simple web search.

https://grapheneos.org/faq#future-devices

Re: GrapheneOS and forensic extraction of data (2024)

#30

I've always found it strange that GrapheneOS only runs on Google hardware. Can anyone explain this choice?

AFAIK the Pixel devices are the only ones that reliably allow bootloader unlocking / re-locking, that is required to perform custom os installs.

There are others e.g. Motorola ones or Fairphone, that also allow this but it's a good idea to focus on a specific set of devices keeping maintenance as low as possible and security focus as high as possible.

There are alternatives like /eOS/ or CalyxOS supporting more devices and I experienced exactly this "no longer supported" issue with my Xiaomi A2, which suddenly disappeared from the list of supported devices (see https://calyxos.org/news/2021/03/29/mi-a2-ten-firmware/).

Post reply on HN