Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

11–20 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#11

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

[flagged]

Border officials don't have the right to search all of your data.

You are also not under any obligation to have it on your phone at all times.

Re: GrapheneOS protections against data extraction from locked devices

#12

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

A replacement for SeedVault is planned:

https://grapheneos.org/features#encrypted-backups

https://github.com/GrapheneOS/os-issue-tracker/issues/4687#i...

Re: GrapheneOS protections against data extraction from locked devices

#13
post #11

Earlier quoted context omitted.

[flagged]

Border officials don't have the right to search all of your data. You are also not under any obligation to have it on your phone at all times.

[flagged]

Re: GrapheneOS protections against data extraction from locked devices

#14
post #4

I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password. On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where ke…

citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.

Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to get to BFU).

Re: GrapheneOS protections against data extraction from locked devices

#15
post #3

Relevant xkcd https://xkcd.com/538/

Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr... According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone. It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm sur…

My trick there is not travelling to the US.

I carry a burner phone when travelling most of the time anyway. It has access to email only, 99% of which is in offline folders anyway.

Re: GrapheneOS protections against data extraction from locked devices

#16

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.

Re: GrapheneOS protections against data extraction from locked devices

#18

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

A replacement for SeedVault is planned: https://grapheneos.org/features#encrypted-backups https://github.com/GrapheneOS/os-issue-tracker/issues/4687#i...

> the project has been taken over by another group of people not sharing our goals or approach

> Seedvault which was originally written for use in GrapheneOS by a GrapheneOS user is a consequence of the 2018 takeover attempt on the project, which the people currently in defacto control of Seedvault were heavily involved in.

Seedvault is currently maintained by the CalyxOS team but I've never heard about this stuff. Does anybody know what happened?

Re: GrapheneOS protections against data extraction from locked devices

#19

Relevant xkcd https://xkcd.com/538/

I hate this meme.

The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

Re: GrapheneOS protections against data extraction from locked devices

#20
post #19

Relevant xkcd https://xkcd.com/538/

I hate this meme. The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

You end up getting hit by a wrench though, that doesn't sound like it ends well for you.
Post reply on HN