Live data from Hacker News

GrapheneOS and forensic extraction of data (2024)

discuss.grapheneos.org

161–170 of 208 posts

Re: GrapheneOS and forensic extraction of data (2024)

#161
post #4

There is no such thing like "bad government" and "good government". I mean - it really depends on people's views, therefore we must not blissfully put our data into govt hands because "they will protect us from terrorists and child rapists". What they will do, actually, is that for sure they will abuse innocent citizens at some point of time. They will. Even if they don't, they will. Or maybe they are doing it right…

> There is no such thing like "bad government" and "good government". Of course there is, compare the government of Finland to that of North Korea. Just because there are shades of grey and human institutions are generally susceptible to corruption greed an power politics doesn't mean there aren't governments that are different not only in degree but in kind.

Finland will approve shit like chat control, age verification or covid lockdowns against civil rights.

Whataboutism is bullshit. Power corrupts. It doesn't matter if you idealize a government, it's still composed of people who get compromised by money, power and general corruption.

Re: GrapheneOS and forensic extraction of data (2024)

#162

I really love Graphene OS but I _wish_ there was a version in which you could get a root shell and extract private data of apps you install when verified as the user. The developers are on record as saying that root blows a hole in their security model (it does!) but if there was _some_ way of doing it safely, so I can modify applications I as the user wish to, it would be my ideal OS. I know I could download and sel…

You can enable root on GrapheneOS. It will erase your data, however, so make a backup before you do. But if you really want root you can save your data, root, restore, and leave root on.

Re: GrapheneOS and forensic extraction of data (2024)

#163

Earlier quoted context omitted.

This is why most desktops and servers are comparably much less secure. Check why Qubes OS was developed.

The user has real dom0 root on qubes.

Is Qubes resistant to forensics? I think its selling point is multi-level security and lateral movement prevention, not safeguarding data on a stolen laptop.

Re: GrapheneOS and forensic extraction of data (2024)

#164
post #139

Earlier quoted context omitted.

What's your threat model for this kind of security?

1 - My main phone has a bunch of work stuffs on it and all my authenticator stuffs and etc 2 - I've been raided by the FBI before in my past (used to be blackhat in my 20s but now im whitehat :)) 3 - I lose my phone sometimes. far better to lose a dinky burner phone VS my main phone.

What is your main phone and setup?

Also — how well/bad Graphene plays with Play Store (esp wrt safety net checks) apps?

Re: GrapheneOS and forensic extraction of data (2024)

#165

Earlier quoted context omitted.

My last pixel (4a) started falling apart after about a year and a half. Is there an android device that's a bit more hardy? I switched back to apple as I was able to use an SE for YEARS. Would love to try running GrapheneOS, though.

My wife uses her Pixel 4a to this day. I moved on from mine after some problems, but a factory wipe of the 4a actually fixed all of the problems with mine too. And you know what else is cool? If the screen gets cracked or something doesn't work, you can take it to an independent repair shop and they can fix it.

The sad part is even security updates stopped for my pixel 5a.

Re: GrapheneOS and forensic extraction of data (2024)

#166

Those considering a switch from iOS to GrapheneOS might be interested in this migration guide and review: https://blog.okturtles.org/2024/06/the-ultimate-ios-to-graph...

Surely there are competent Apple Photos and Google Photos alternatives like Ente. There are more.

Re: GrapheneOS and forensic extraction of data (2024)

#167
post #49

Earlier quoted context omitted.

> A root access is a big hole How so? On Linux, I can add an account to the sudoers list, and have the flexibility to configure the level of security appropriate for my use case. I have yet to experience any security issues (that I'm aware of). Why isn't this possible on my mobile device as well? This absolute stance is not right. Security is not binary, but a spectrum. I should be allowed to have full control over m…

How so? Root can access absolutely everything. Malware capable of getting root can access / exfiltrate anything, use your network, flash your firmware, can persist permanently, can use you as a vector. Shellshock, log4j, Heartbleed. Hundreds of the big profile vulnerabilities that can be exploited on the system in an attempt to obtain root. And then you're cooked. You really think a malware with the root access can't…

Yes but root still exists in phones just like it does in servers. It's just not accessible by the user. The OS does run processes as root and it needs it for things like updates.

Also, the user having root access doesn't mean that every process they run has root rights. For rooted phones there's apps to control what it's used for. Anything else just runs with the limited rights as before.

Of course those 'sudo' apps would be an attack vector but a pretty niche one.

Re: GrapheneOS and forensic extraction of data (2024)

#168
post #139

Earlier quoted context omitted.

1 - My main phone has a bunch of work stuffs on it and all my authenticator stuffs and etc 2 - I've been raided by the FBI before in my past (used to be blackhat in my 20s but now im whitehat :)) 3 - I lose my phone sometimes. far better to lose a dinky burner phone VS my main phone.

What is your main phone and setup? Also — how well/bad Graphene plays with Play Store (esp wrt safety net checks) apps?

I use it. No issue

The only app so far I've found that won't work is ParkMobile and you can just use their website

Re: GrapheneOS and forensic extraction of data (2024)

#169

Earlier quoted context omitted.

I want to get a Pixel just for GrapheneOS as well but Google is incapable of selling those things worldwide despite being a trillion dollar corporation.

I had issues buying my Pixel from Google. My memory is fuzzy, but I think after I activated my account they said great, We'll let you purchase in a month... A really cautious security model I suppose. I gave up and bought it on Amazon.

What account? You can just walk into a Google store and buy one. Most big cities in the U.S. have one.

Re: GrapheneOS and forensic extraction of data (2024)

#170
post #108
post #84

Earlier quoted context omitted.

Requiring people to watch a 1hr+ video to understand your argument is a big red flag.

Why's that? A topic as big as this takes quite a lot of refuting. If you're interested in finding the truth, then you'll at least begin watching it to see if it offers any promise.

The trouble with videos is you can just... choose not to include stuff that obviously refutes your argument.

The reality is that global warming is definitely happening, and also the Earth is definitely not flat. But it's pretty easy to make a super convincing argument that the Earth is flat - you just don't mention any of the math behind why the Earth is round and then you can have a 5 hour long video filled to the brim with evidence the Earth is flat.

And it's not even lying. We're not saying anything that's not true. We're just choosing to omit data and evidence that proves us wrong. We can even include fake data and evidence, if we want, and refute that - ie build a strawman.

Post reply on HN