Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

111–120 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#111
post #19

Relevant xkcd https://xkcd.com/538/

I hate this meme. The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

Doesn't have to be a literal wrench right? A government can trivially and legally make you miss the itinerary that made your holiday possible that you've saved up for the rest of the year with no restitution that I'm aware of in any jurisdiction. They can confiscate 'evidence' (any computer and (backup) storage media in your house) for years. They can do a heck of a lot that's more annoying than medium amounts of wrench swinging

And as for street thugs, sure it won't be a wrench, more likely they'll flash a knife and unkindly suggest you remove the lock screen

Taken as a metaphor rather than a literal wrench, you don't think it's accurate?

Re: GrapheneOS protections against data extraction from locked devices

#112

Earlier quoted context omitted.

Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.

A lot of people are still using their smartphone pretty much as a dumbphone with a web browser.

Like how many ?

Re: GrapheneOS protections against data extraction from locked devices

#113

Earlier quoted context omitted.

Even more of a reason for good and easy backup and restore. Before travel back up the real contents and restore a dummy travel backup with random games, stock photos etc. Then restore back to real contents.

This is never going to happen for the same reason Apple and Google won’t let you use different backup/restore methods.

I looked at snapseed a few hours ago and backup must be done per profile.

So you can totally have different profiles with different backup servers/credentials and decide to nuke one before flying or crossing a border.

Obviously you can't expect having 2 whatsapp or signal accounts on same number but you can always have several SIMs.

The good thing is with profiles you can totally seed a profile for a few weeks before travelling.

Re: GrapheneOS protections against data extraction from locked devices

#114

Earlier quoted context omitted.

A lot of people are still using their smartphone pretty much as a dumbphone with a web browser.

Yeah but if you're a normal guy strolling through every time with a phone that has nothing- no pictures, no signed in email, no history of messages, 4 contacts. That's abnormal, no way of spinning it as "but I just don't use my phone much" will make that seem normal. The average person has their phone glued to their body 24/7 now. Implying that you don't is abnormal.

[deleted]

Re: GrapheneOS protections against data extraction from locked devices

#115

Earlier quoted context omitted.

Yeah but if you're a normal guy strolling through every time with a phone that has nothing- no pictures, no signed in email, no history of messages, 4 contacts. That's abnormal, no way of spinning it as "but I just don't use my phone much" will make that seem normal. The average person has their phone glued to their body 24/7 now. Implying that you don't is abnormal.

"I only ever cross borders with a blank phone because I don’t want you invading my privacy" is a perfectly valid answer. You can also add that it is your employer’s policy and/or your government official recommendation.

> a perfectly valid answer

Makes no difference at all in the real world. You don't have to give valid answers, you need to get the guy across from you to not find you suspicious. That phrase is going to put a red flag on you, valid or not.

Re: GrapheneOS protections against data extraction from locked devices

#116
post #33

Earlier quoted context omitted.

Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.

The easiest way to avoid suspicion is to have a phone filled with cat and family pictures, dumb apps and games. You don't avoid scrutiny by being wierd and hiding things, but by hiding in plain sight by being ultra boring.

Add some dickpicks because who doesn't have something on their phone that they don't want others to see.

Re: GrapheneOS protections against data extraction from locked devices

#117
post #77
post #45

Earlier quoted context omitted.

Because you may need the data in the data during/after your travel and lack clean way to access safely, securely and anonymously remotely.

This is where we need "cloud phones as a service" / "selfhosting a cellphone at home with some kind of remote access system". Not even kidding here, it's time to bring out thin client computing to cellphones. Let the spicy stuff sit somewhere else. I could bootstrap a Tailscale or Netbird signin remotely, install the access client, and remote back into the 'normal phone'. Would be then funny to map that to lockscreen…

> "selfhosting a cellphone at home with some kind of remote access system

You can use TeamViewer for that. Or maybe scrcpy could be coerced into working in a similar way.

Re: GrapheneOS protections against data extraction from locked devices

#118

Earlier quoted context omitted.

GrapheneOS seems to be consistently the hardest to exploit AFU based on various Cellubrite leaks. iPhones have better protection than all other Androids except Pixels.

[flagged]

Perhaps the fact that iPhones are run by a multi trillion dollar company while GrapheneOS is an open source project with less employees than an Apple store has something to do with NATO approval. They are not going to approve a device that people have to install the OS themselves. I would base the security of an OS based on expert security researchers, not certain government agencies decisions.

iPhones are probably the most secure off the shelf phones you can buy, but based on leaked documents it's clearly inferior real-world security compared to a Pixel running GrapheneOS. Apple and Google have copied many security features from GrapheneOS like the reboot timer.

GrapheneOS is built from the ground up with a primary priority placed on security. GrapheneOS has much more robust USB port hardening. You can see the full list of features added on their website. Apple bolts on some additional security features in lockdown mode but they are mostly fixes to Apple's services which have large attack surface like iMessage. Additionally they are all built together and not on by default which makes the users willing to use it way lower.

Re: GrapheneOS protections against data extraction from locked devices

#119

It's fairly easy to open up a phone and probe inner circuitry. I suspect that'll be the next step for malicious actors. I doubt very much the phone is fully resistant to having malicious data injected onto various busses.

I would not think it is fairly easy. The only real physical attack I can think of is to somehow to remove the delay throttles and brute force unlocking the device. This would be feasible for digits PIN, but not if you include characters. I am curious if you had something else in mind.

Re: GrapheneOS protections against data extraction from locked devices

#120
post #108

Earlier quoted context omitted.

[flagged]

> The iPhone Probably the latest models. Cop told me they have problems cracking those. Older models not so much, that's pretty common knowledge.

[flagged]
Post reply on HN