Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

51–60 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#51
post #3

Relevant xkcd https://xkcd.com/538/

Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr... According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone. It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm sur…

I'm not sure it would have been that easy for them to back it up.

Depending on his settings.

You can disable the usb port entirely if you like, so that it is only possible to charge the device by switching it off. Or enable charging only when unlocked etc.

Or if his device had rebooted I don't think it would be possible to extract anything.

Re: GrapheneOS protections against data extraction from locked devices

#52

Earlier quoted context omitted.

citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted. Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to ge…

What about using decoy profiles? Say before the border crossing you switch to another user. Does that expose keys or anything for other users?

You would need to hide the existence of the original profile while in the decoy profile for this to work, which GrapheneOS considers too complex to implement

Re: GrapheneOS protections against data extraction from locked devices

#53
post #34

Earlier quoted context omitted.

I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.

Probably because everything seems to be an "app" these days. Even when it has no business being one.

Exactly. Everything must be switched to Service as a Software Substitute. It's for your own safety, you see.

Re: GrapheneOS protections against data extraction from locked devices

#54

Earlier quoted context omitted.

Yeah but if you're a normal guy strolling through every time with a phone that has nothing- no pictures, no signed in email, no history of messages, 4 contacts. That's abnormal, no way of spinning it as "but I just don't use my phone much" will make that seem normal. The average person has their phone glued to their body 24/7 now. Implying that you don't is abnormal.

"I only ever cross borders with a blank phone because I don’t want you invading my privacy" is a perfectly valid answer. You can also add that it is your employer’s policy and/or your government official recommendation.

It's one that will get you denied entry, or detained indefinitely.

Re: GrapheneOS protections against data extraction from locked devices

#55

Earlier quoted context omitted.

It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm surprised they didn't back up the device first. The duress password does not wipe the phone. It wipes the encryption keys from the secure element. The phone's storage is the backup, but it is worthless, unless law enforcement has an attack against AES that does not require a brute force attack (unlikely…

Oh please. That's not a real distinction. The phone as a unit, flash plus enabling chips, is wiped in an unrecoverable way. And the primary copy is not a backup.

It might be a real legal distinction, but probably not.

Re: GrapheneOS protections against data extraction from locked devices

#56
post #54

Earlier quoted context omitted.

"I only ever cross borders with a blank phone because I don’t want you invading my privacy" is a perfectly valid answer. You can also add that it is your employer’s policy and/or your government official recommendation.

It's one that will get you denied entry, or detained indefinitely.

I have worked for employers that required taking a burner phone to certain countries without any accounts logged in, etc. (so mostly for calls, maps, and web browsing) and nobody has ever been detained or denied entry. Some countries know that this is just standard procedure when they are visited for business trips. Probably different for the US though.

(Not legal advise of course, just observation. Always check with the legal department of your employer, etc.)

Re: GrapheneOS protections against data extraction from locked devices

#57
although it is wonderful to know that there exists a piece of hardware in the world that is not conspiring against its users, the outcome of entering a duress password should be indistinguishable to the user that grabs hold of the mobile phone. The duress password should wipe off the real user account information but present the kidnappers with a full-fledged operating system populated with real-looking content to entertain the police officers with polite meaningless e-mails saying things like

> > On Apr 11, 2015, at 5:45 PM, Jim Steyer Hey John, > > > > We know you're a true master of cuisine and we have appreciated that for > years ... > > > > But walnut sauce for the pasta? Mary, plz tell us the straight story, > was the sauce actually very tasty? > > > > > Jim

Re: GrapheneOS protections against data extraction from locked devices

#58

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.

Even more of a reason for good and easy backup and restore.

Before travel back up the real contents and restore a dummy travel backup with random games, stock photos etc. Then restore back to real contents.

Re: GrapheneOS protections against data extraction from locked devices

#59

Earlier quoted context omitted.

It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm surprised they didn't back up the device first. The duress password does not wipe the phone. It wipes the encryption keys from the secure element. The phone's storage is the backup, but it is worthless, unless law enforcement has an attack against AES that does not require a brute force attack (unlikely…

Oh please. That's not a real distinction. The phone as a unit, flash plus enabling chips, is wiped in an unrecoverable way. And the primary copy is not a backup.

This site is called Hacker News :), people might just want to learn how it works technically, so I think it is worth mentioning technical differences.

Also, it does make a small difference in practice. Erasing keys is pretty much immediate, while erasing storage can take some time (especially for phones with larger storage), so the attacker could still try to power down the device in some way to avoid all storage gets wiped.

Re: GrapheneOS protections against data extraction from locked devices

#60
post #21
post #4

I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password. On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where ke…

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.

He’s a “surveillance expert” so the language is not at all surprising. These are the people who always bring up the appeal to emotion, associating a benign act with something unpalatable, criminal, terrorist, think of the children.

When your job depends on not understanding and all that.

Post reply on HN