Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

21–30 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#21
post #4

I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password. On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where ke…

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.

Re: GrapheneOS protections against data extraction from locked devices

#22
post #3

Relevant xkcd https://xkcd.com/538/

Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr... According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone. It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm sur…

It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm surprised they didn't back up the device first.

The duress password does not wipe the phone. It wipes the encryption keys from the secure element. The phone's storage is the backup, but it is worthless, unless law enforcement has an attack against AES that does not require a brute force attack (unlikely).

Re: GrapheneOS protections against data extraction from locked devices

#23
post #11

Earlier quoted context omitted.

Border officials don't have the right to search all of your data. You are also not under any obligation to have it on your phone at all times.

[flagged]

Unfortunately, it'll most likely go something like this: https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...

Re: GrapheneOS protections against data extraction from locked devices

#24

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.

A lot of people are still using their smartphone pretty much as a dumbphone with a web browser.

Re: GrapheneOS protections against data extraction from locked devices

#25
post #3

Relevant xkcd https://xkcd.com/538/

Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr... According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone. It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm sur…

This is really an interesting case. Hope to see a ruling here. The edge cases are really interesting as well, like the fake pin on the back of the phone. I also wonder generally about the 'destruction' of data Wouldn't the government need to prove that there is no backup, because just making it more difficult (like hiding) would probably not call for the paragraph. Unfortunately for the rest of us the defence is based on more proven grounds. I guess only plausible deniability is helpful: I e.g. would love to see my trusted android space being empty/recreated on false password.

Re: GrapheneOS protections against data extraction from locked devices

#26

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

[flagged]

> So you plan to (1) actively/proactively conceal your data/evidence

I am not concealing data/evidence as it doesn't exists. I don't know of any law in any country that force you to hand out the key of your home to a remote state so that they can enter your country and do a search.

> and then (3) constantly restore from cloud backups?

Why constantly? Only and only if I need to access specific data (that may be available remotely without restore anyway). Full restore only when going back in my own country.

Re: GrapheneOS protections against data extraction from locked devices

#27
post #11

Earlier quoted context omitted.

Border officials don't have the right to search all of your data. You are also not under any obligation to have it on your phone at all times.

[flagged]

> Correct! Furthermore, border officials have no requirements to allow you into their country either, unless you’re a citizen there,

I'd rather have them tell me to turn back and go home than being jailed there only because I don't want them to fap at the picture of my daughters.

Re: GrapheneOS protections against data extraction from locked devices

#28
post #23

Earlier quoted context omitted.

[flagged]

Unfortunately, it'll most likely go something like this: https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...

Yeah, the lesson is: do not travel to countries that treat people such in a shitty way. This has always been true. Unfortunately, for many foreigners this also applies to the US nowadays.

I guess that you are out of luck if you are a US citizen and need to return to your own country.

Re: GrapheneOS protections against data extraction from locked devices

#29
post #21
post #4

I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password. On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where ke…

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.

This is why it is important to continue iterating everywhere that device security is important for everyone. iPhone has nearly the same level of protection and we also do not see it as 'criminal by default'.

Secondly, it is important to get as many people to use GrapheneOS as possible, including non-tech people. The more widespread it becomes, the harder it will become to paint this picture.

Re: GrapheneOS protections against data extraction from locked devices

#30
post #23

Earlier quoted context omitted.

[flagged]

Unfortunately, it'll most likely go something like this: https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...

Being prosecuted because your smartphone has been setup yesterday is not the same as being prosecuted because you gave a password that wipe your phone in front of law enforcement.

In the past I have had my smartphone die a couple of days before travelling and quickly buying a smartphone so I could have a mobile line in case of emergency while travelling. This is not a totally uncommon case to have a smartphone with very little data. A lot of people never setup any cloud backup and lose all their data every so many years.

Post reply on HN