Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

131–140 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#131
post #48

There was some comment here somewhere arguing that 16 characters for a password is too little, but that he used the pattern lock. Looks like it was deleted. Anyway. The pattern lock in Android provides Log2(389112) =~ 18.57 bits of entropy. This is less than 3 random characters, or 4 lowercase letters, or a decimal PIN digit password of 6 characters. Granted, you could use mnemonics for long passwords, but how conven…

Modern Pixel phones have a TPM-like device that protects against brute-force attacks. Assuming the pattern is non-obvious, an attacker has 20 attempts before the supplementary key material is wiped and the encryption key is lost.

It's theorerically possible to use side channel attacks against the security chip to bypass this, of course, but that requires opening the device and some very precise, damaging operations, assuming the attacker has a known-working side channel attack in the first place.

Re: GrapheneOS protections against data extraction from locked devices

#132
post #19

Earlier quoted context omitted.

I hate this meme. The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

You end up getting hit by a wrench though, that doesn't sound like it ends well for you.

Sounds like something a coward would say, honestly.

Re: GrapheneOS protections against data extraction from locked devices

#133
post #54

Earlier quoted context omitted.

It's one that will get you denied entry, or detained indefinitely.

I have worked for employers that required taking a burner phone to certain countries without any accounts logged in, etc. (so mostly for calls, maps, and web browsing) and nobody has ever been detained or denied entry. Some countries know that this is just standard procedure when they are visited for business trips. Probably different for the US though. (Not legal advise of course, just observation. Always check with…

"I'm here for business and my employer requires it" is an acceptable excuse. "I don't like government surveillance" is not.

Re: GrapheneOS protections against data extraction from locked devices

#134
post #19

Relevant xkcd https://xkcd.com/538/

I hate this meme. The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

The United States has famously shot and killed protesters in the Vietnam war era. They have dedicated torture facilities for people suspected, not even convicted, of terrorism. Police officers use lethal violence for no reason every month and rarely get more than a talking to.

In a perfect society, your point makes sense, but I don't see why the authorities in the real world would need to care about committing a worse crime.

Re: GrapheneOS protections against data extraction from locked devices

#135
post #54

Earlier quoted context omitted.

It's one that will get you denied entry, or detained indefinitely.

Denied entry, why not. But detained?

In the USA border they detain people they think are lying until they think they are not lying.

Re: GrapheneOS protections against data extraction from locked devices

#136

It's fairly easy to open up a phone and probe inner circuitry. I suspect that'll be the next step for malicious actors. I doubt very much the phone is fully resistant to having malicious data injected onto various busses.

You don’t seem to know much about modern electronics or forensics. “Probing” the “circuitry” isn’t going to get you anything. The devices supported by GrapheneOS keep their encryption secrets in tiny, sealed chips that are strongly tamper-resistant and will erase themselves if you attempt to get to the actual memory cells without specialty equipment. The only labs that can extract information from chips like this are very rare, expensive, and slow, and success still isn’t guaranteed. Plus these labs are going to have a backlog of espionage and military cases; they aren’t going to be working on some random dude’s phone unless he’s a cartel boss.

Re: GrapheneOS protections against data extraction from locked devices

#138
post #60
post #21

Earlier quoted context omitted.

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.

He’s a “surveillance expert” so the language is not at all surprising. These are the people who always bring up the appeal to emotion, associating a benign act with something unpalatable, criminal, terrorist, think of the children. When your job depends on not understanding and all that.

I'm fairly certain the person being quoted is saying the opposite of what you've implied - i.e. he thinks it is concerning THAT GrapheneOS is automatically associated with criminality.

Re: GrapheneOS protections against data extraction from locked devices

#139
post #115

Earlier quoted context omitted.

"I only ever cross borders with a blank phone because I don’t want you invading my privacy" is a perfectly valid answer. You can also add that it is your employer’s policy and/or your government official recommendation.

> a perfectly valid answer Makes no difference at all in the real world. You don't have to give valid answers, you need to get the guy across from you to not find you suspicious. That phrase is going to put a red flag on you, valid or not.

> you need to get the guy across from you to not find you suspicious.

What? No, who cares about that? Let him find you suspicious, what matters is that he doesn’t access your data. And it is not suspicious to cross borders (esp. US borders) with burner phones. As others have said, it is standard practice.

Re: GrapheneOS protections against data extraction from locked devices

#140

Earlier quoted context omitted.

Denied entry, why not. But detained?

In the USA border they detain people they think are lying until they think they are not lying.

Lying about what? "I only bring a burner phone to border checks because I don’t want people like you to access my data“ is not a lie, and I fail to see how it could be interpreted as such.
Post reply on HN