Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

61–70 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#61
post #3

Relevant xkcd https://xkcd.com/538/

Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr... According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone. It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm sur…

So, technically, the border agents wiped the phone. I wonder how specific their request was of Tunick when they asked for the password.

Re: GrapheneOS protections against data extraction from locked devices

#62
post #48

There was some comment here somewhere arguing that 16 characters for a password is too little, but that he used the pattern lock. Looks like it was deleted. Anyway. The pattern lock in Android provides Log2(389112) =~ 18.57 bits of entropy. This is less than 3 random characters, or 4 lowercase letters, or a decimal PIN digit password of 6 characters. Granted, you could use mnemonics for long passwords, but how conven…

Maybe because it was mistaken. I just set my grapheneos to a 35 character password to test it and it didnt seem to have any issue.

Re: GrapheneOS protections against data extraction from locked devices

#63
post #3

Earlier quoted context omitted.

Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr... According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone. It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm sur…

From what I understand he was not formally arrested at the time, just interrogated at the border. I am not familiar with US laws but from what I understand the device was not (yet?) considered evidence in an investigation. I imagine backing up might not be as easy an option without tearing down the device as the memory chip is no the device mainboard, so not something you can necessarily do on the side of the road or…

Border searches are special case in US law where the 4th amednment protections aren't as strong. See the EFF page about it for more:

https://www.eff.org/issues/border-searches

Re: GrapheneOS protections against data extraction from locked devices

#64
post #62
post #48

There was some comment here somewhere arguing that 16 characters for a password is too little, but that he used the pattern lock. Looks like it was deleted. Anyway. The pattern lock in Android provides Log2(389112) =~ 18.57 bits of entropy. This is less than 3 random characters, or 4 lowercase letters, or a decimal PIN digit password of 6 characters. Granted, you could use mnemonics for long passwords, but how conven…

Maybe because it was mistaken. I just set my grapheneos to a 35 character password to test it and it didnt seem to have any issue.

Did ypu test using random characters after 30 chars?

Re: GrapheneOS protections against data extraction from locked devices

#65

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

Remind us what happened when you do cross.

Re: GrapheneOS protections against data extraction from locked devices

#66
post #33

Earlier quoted context omitted.

Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.

The easiest way to avoid suspicion is to have a phone filled with cat and family pictures, dumb apps and games. You don't avoid scrutiny by being wierd and hiding things, but by hiding in plain sight by being ultra boring.

On the other hand, if everything about you is boring, that in itself may begin to seem suspicious. "I borrowed this old phone from my stepson because my own phone got run over by a steamroller at a vintage vehicle show" is the sort of thing an actual spy or criminal would never say.

Re: GrapheneOS protections against data extraction from locked devices

#67

although it is wonderful to know that there exists a piece of hardware in the world that is not conspiring against its users, the outcome of entering a duress password should be indistinguishable to the user that grabs hold of the mobile phone. The duress password should wipe off the real user account information but present the kidnappers with a full-fledged operating system populated with real-looking content to en…

That email chain sounds exactly like the TV show Severance

Re: GrapheneOS protections against data extraction from locked devices

#68
post #60
post #21

Earlier quoted context omitted.

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.

He’s a “surveillance expert” so the language is not at all surprising. These are the people who always bring up the appeal to emotion, associating a benign act with something unpalatable, criminal, terrorist, think of the children. When your job depends on not understanding and all that.

[deleted]

Re: GrapheneOS protections against data extraction from locked devices

#69
post #54

Earlier quoted context omitted.

"I only ever cross borders with a blank phone because I don’t want you invading my privacy" is a perfectly valid answer. You can also add that it is your employer’s policy and/or your government official recommendation.

It's one that will get you denied entry, or detained indefinitely.

Denied entry, why not. But detained?

Re: GrapheneOS protections against data extraction from locked devices

#70
post #34

Earlier quoted context omitted.

citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted. Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to ge…

I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.

So delete messengers, email apps and other comms?

Delete the contact book? Clear calendars?

Where exactly should one stop?

Post reply on HN