Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

121–130 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#121
Here's an idea: soft duress PIN that wipes a list of apps of your choice however doesn't make it obvious it's done so.

Or restores app data to a restore point of your choosing making it seem like everything is fine.

Make it untraceable you had it setup and it'll help deal with any potential legal issues.

Re: GrapheneOS protections against data extraction from locked devices

#122
post #108

Earlier quoted context omitted.

> The iPhone Probably the latest models. Cop told me they have problems cracking those. Older models not so much, that's pretty common knowledge.

[flagged]

Source: I made it up

Re: GrapheneOS protections against data extraction from locked devices

#123
post #52

Earlier quoted context omitted.

What about using decoy profiles? Say before the border crossing you switch to another user. Does that expose keys or anything for other users?

You would need to hide the existence of the original profile while in the decoy profile for this to work, which GrapheneOS considers too complex to implement

I mean, so does everyone.

https://veracrypt.io/en/Wear-Leveling.html

Re: GrapheneOS protections against data extraction from locked devices

#124
post #43

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

I think more useful would be to be able to boot into another data partition with a different password, which, in turn, would hide the other "daily" partition. I believe LUKS is capable of that. The storage dump looks like a random set of data and only a valid password can find and decrypt a matching hidden partition. Ideally this should also work on lock screen, e.g. if you type in a non-standard PIN, it would boot f…

Not possible to have a robust implementation with the current tech unfortunately.

https://veracrypt.io/en/Wear-Leveling.html

Re: GrapheneOS protections against data extraction from locked devices

#125

Earlier quoted context omitted.

It's been planned for years...

TTS has also been planned for a while and they released it recently. Donating or helping out is going to do more than complaining on HN.

[flagged]

Re: GrapheneOS protections against data extraction from locked devices

#126

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

A complete backup is solution that can be stored on my own encrypted servers and restored with a click of a button is really needed.

I always dread the possibility of my GrapheneOS phone being damaged or stolen and having to spend hours reinstalling and reconfiguring everything that Seedvault missed, as well as losing access to accounts that are locked by the secure element keys.

Re: GrapheneOS protections against data extraction from locked devices

#127
post #70
post #34

Earlier quoted context omitted.

I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.

So delete messengers, email apps and other comms? Delete the contact book? Clear calendars? Where exactly should one stop?

You're misinterpreting. They mean that there are additional options next to only keeping these things on your phone.

Re: GrapheneOS protections against data extraction from locked devices

#128
post #45
post #34

Earlier quoted context omitted.

I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.

Because you may need the data in the data during/after your travel and lack clean way to access safely, securely and anonymously remotely.

No one is stopped from backing up important data. It is, in fact, kind of boneheaded to keep all "valuables" on a single device. I don't understand the scenario of not trusting a device to safely access the Internet or the telephony grid while also insisting that they need a PHONE to keep all their stuff on where they're going, and at the same time somehow trust that both themselves and their possessions are perfectly safe from seizure and extortion in the very same location.

Re: GrapheneOS protections against data extraction from locked devices

#129

Here's an idea: soft duress PIN that wipes a list of apps of your choice however doesn't make it obvious it's done so. Or restores app data to a restore point of your choosing making it seem like everything is fine. Make it untraceable you had it setup and it'll help deal with any potential legal issues.

Not possible to be forensically safe. They aren't gonna implement a plausible deniability solution that isn't robust because it will give people a false sense of security and put them in danger.

Re: GrapheneOS protections against data extraction from locked devices

#130
post #87

I always leave my phone and laptop off when going through TSA or Passport Control. I don't think in the US you an be compelled into giving up your password. They are free to confiscate the device but with it powered down good luck trying to break the password.

Powering down or restarting is ideal because BFU is much more secure.

Although, based on the latest Cellubrite leaks, GrapheneOS can't be exploited in AFU either.

There's also the reboot timer which brings the device to a BFU state. GrapheneOS implemented it and then Google and apple implemented their own version with fixed timers. GrapheneOS's is configurable down to 10 minutes, the default is 18 hours. On iPhones and Androids it's fixed at 72 hours.

One thing I wish they had in GrapheneOS was a faster shortcut to shutdown. Afaik currently you need to press physical button and then confirm on screen.

Post reply on HN