Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

31–40 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#31
post #18

Earlier quoted context omitted.

A replacement for SeedVault is planned: https://grapheneos.org/features#encrypted-backups https://github.com/GrapheneOS/os-issue-tracker/issues/4687#i...

> the project has been taken over by another group of people not sharing our goals or approach > Seedvault which was originally written for use in GrapheneOS by a GrapheneOS user is a consequence of the 2018 takeover attempt on the project, which the people currently in defacto control of Seedvault were heavily involved in. Seedvault is currently maintained by the CalyxOS team but I've never heard about this stuff. D…

There has been a lot of conflict between Calyx and GrapheneOS a while ago.

Re: GrapheneOS protections against data extraction from locked devices

#32

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

[flagged]

It's been normal operating procedure for many employees that travel to the US. You think they're all criminals?

Re: GrapheneOS protections against data extraction from locked devices

#33

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.

The easiest way to avoid suspicion is to have a phone filled with cat and family pictures, dumb apps and games.

You don't avoid scrutiny by being wierd and hiding things, but by hiding in plain sight by being ultra boring.

Re: GrapheneOS protections against data extraction from locked devices

#34
post #4

I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password. On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where ke…

citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted. Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to ge…

I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.

Re: GrapheneOS protections against data extraction from locked devices

#35

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.

Sure but there'd be nothing there.

If the regime is going to just start taking people then nothing will stop that, but the goal is to stop the usefulness of this sort of thing as an intimidation measure - or at least drag it to the forefront and overthrow the regime.

Re: GrapheneOS protections against data extraction from locked devices

#36
post #19

Earlier quoted context omitted.

I hate this meme. The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

You end up getting hit by a wrench though, that doesn't sound like it ends well for you.

Liberty is given up in inches, not miles.

The offenses of a regime at its apex would've led to it being stopped had they started out that way, but they didn't.

What you've hit on is the basic problem of treating privacy as a means to an end though: no level of it protects you from fascism, but it is a means by which fascism can be opposed - in many cases at personal cost to yourself.

In theory I have no secrets, and the contents of my phone or life if public would be of no consequence to me. In practice, when the regime starts flustering itself that I have no secrets for them to reveal the hopefully people will oppose it - or I get a decent warning that it's time to bail.

Re: GrapheneOS protections against data extraction from locked devices

#37
post #23

Earlier quoted context omitted.

Unfortunately, it'll most likely go something like this: https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...

Yeah, the lesson is: do not travel to countries that treat people such in a shitty way. This has always been true. Unfortunately, for many foreigners this also applies to the US nowadays. I guess that you are out of luck if you are a US citizen and need to return to your own country.

Do the requirement to put your social account public when applying for a US Visa still applies? I guess the USA do not have that many non US visitors these days because I don't know a lot of women who would agree to that. Almost all my female friends have been experiencing stalking from jealous ex, former colleagues/clients/patients so putting their social media account public would be a complete no-go for them.

How is the tourism industry going?

Re: GrapheneOS protections against data extraction from locked devices

#38

Earlier quoted context omitted.

Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.

A lot of people are still using their smartphone pretty much as a dumbphone with a web browser.

Yeah but if you're a normal guy strolling through every time with a phone that has nothing- no pictures, no signed in email, no history of messages, 4 contacts. That's abnormal, no way of spinning it as "but I just don't use my phone much" will make that seem normal. The average person has their phone glued to their body 24/7 now. Implying that you don't is abnormal.

Re: GrapheneOS protections against data extraction from locked devices

#39
post #3

Earlier quoted context omitted.

Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr... According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone. It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm sur…

It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm surprised they didn't back up the device first. The duress password does not wipe the phone. It wipes the encryption keys from the secure element. The phone's storage is the backup, but it is worthless, unless law enforcement has an attack against AES that does not require a brute force attack (unlikely…

Oh please. That's not a real distinction. The phone as a unit, flash plus enabling chips, is wiped in an unrecoverable way.

And the primary copy is not a backup.

Re: GrapheneOS protections against data extraction from locked devices

#40

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

A replacement for SeedVault is planned: https://grapheneos.org/features#encrypted-backups https://github.com/GrapheneOS/os-issue-tracker/issues/4687#i...

Neat, I didn't realize it was still included. I thought it had been abandonned.

So basically one needs a webdav server somewhere or an usb flash drive.

Post reply on HN