I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password. On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where ke…
GrapheneOS protections against data extraction from locked devices
21–30 of 284 posts
Re: GrapheneOS protections against data extraction from locked devices
#22Relevant xkcd https://xkcd.com/538/
Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr... According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone. It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm sur…
The duress password does not wipe the phone. It wipes the encryption keys from the secure element. The phone's storage is the backup, but it is worthless, unless law enforcement has an attack against AES that does not require a brute force attack (unlikely).
Re: GrapheneOS protections against data extraction from locked devices
#23Earlier quoted context omitted.
Border officials don't have the right to search all of your data. You are also not under any obligation to have it on your phone at all times.
[flagged]
Re: GrapheneOS protections against data extraction from locked devices
#24What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…
Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.
Re: GrapheneOS protections against data extraction from locked devices
#25Relevant xkcd https://xkcd.com/538/
Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr... According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone. It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm sur…
Re: GrapheneOS protections against data extraction from locked devices
#26What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…
[flagged]
I am not concealing data/evidence as it doesn't exists. I don't know of any law in any country that force you to hand out the key of your home to a remote state so that they can enter your country and do a search.
> and then (3) constantly restore from cloud backups?
Why constantly? Only and only if I need to access specific data (that may be available remotely without restore anyway). Full restore only when going back in my own country.
Re: GrapheneOS protections against data extraction from locked devices
#27Earlier quoted context omitted.
Border officials don't have the right to search all of your data. You are also not under any obligation to have it on your phone at all times.
[flagged]
I'd rather have them tell me to turn back and go home than being jailed there only because I don't want them to fap at the picture of my daughters.
Re: GrapheneOS protections against data extraction from locked devices
#28Earlier quoted context omitted.
[flagged]
Unfortunately, it'll most likely go something like this: https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...
I guess that you are out of luck if you are a US citizen and need to return to your own country.
Re: GrapheneOS protections against data extraction from locked devices
#29I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password. On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where ke…
In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.
Secondly, it is important to get as many people to use GrapheneOS as possible, including non-tech people. The more widespread it becomes, the harder it will become to paint this picture.
Re: GrapheneOS protections against data extraction from locked devices
#30Earlier quoted context omitted.
[flagged]
Unfortunately, it'll most likely go something like this: https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...
In the past I have had my smartphone die a couple of days before travelling and quickly buying a smartphone so I could have a mobile line in case of emergency while travelling. This is not a totally uncommon case to have a smartphone with very little data. A lot of people never setup any cloud backup and lose all their data every so many years.