Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

141–150 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#141

Earlier quoted context omitted.

GrapheneOS seems to be consistently the hardest to exploit AFU based on various Cellubrite leaks. iPhones have better protection than all other Androids except Pixels.

[flagged]

Any independent reasons for your claim besides appeal to authority?

Re: GrapheneOS protections against data extraction from locked devices

#142
post #70

Earlier quoted context omitted.

So delete messengers, email apps and other comms? Delete the contact book? Clear calendars? Where exactly should one stop?

You're misinterpreting. They mean that there are additional options next to only keeping these things on your phone .

What am I misinterpreting? OP literally said they don't understand why a journalist would carry these data with them. As if the data is a file on your phone. Data can be a contact book on your phone, or a messenger with E2E encrypted messages. What would the alternative to that be? Sending pigeons?

Re: GrapheneOS protections against data extraction from locked devices

#143
post #111
post #19

Earlier quoted context omitted.

I hate this meme. The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

Doesn't have to be a literal wrench right? A government can trivially and legally make you miss the itinerary that made your holiday possible that you've saved up for the rest of the year with no restitution that I'm aware of in any jurisdiction. They can confiscate 'evidence' (any computer and (backup) storage media in your house) for years. They can do a heck of a lot that's more annoying than medium amounts of wre…

> A government can trivially and legally make you miss the itinerary that made your holiday possible that you've saved up for the rest of the year with no restitution that I'm aware of in any jurisdiction. They can confiscate 'evidence' (any computer and (backup) storage media in your house) for years.

This could be preferable to handing over private data about contacts, communications, sources, client information, etc. Especially if it has life-changing implications for yourself or other people!

Re: GrapheneOS protections against data extraction from locked devices

#144

Earlier quoted context omitted.

GrapheneOS seems to be consistently the hardest to exploit AFU based on various Cellubrite leaks. iPhones have better protection than all other Androids except Pixels.

[flagged]

Apple can at any time push a hostile "upgrade" that will remove or disable the claimed security features. You don't control the operating system, and can't trust that it isn't backdoored, especially given Apple's record[0].

[0] https://en.wikipedia.org/wiki/PRISM

Re: GrapheneOS protections against data extraction from locked devices

#145
post #142

Earlier quoted context omitted.

You're misinterpreting. They mean that there are additional options next to only keeping these things on your phone .

What am I misinterpreting? OP literally said they don't understand why a journalist would carry these data with them. As if the data is a file on your phone. Data can be a contact book on your phone, or a messenger with E2E encrypted messages. What would the alternative to that be? Sending pigeons?

Restoring from remote backup when you reach your destination, then wiping again before you cross borders. Or shipping the (encrypted) data separately and picking it up after safe arrival.

Re: GrapheneOS protections against data extraction from locked devices

#146
post #80

Earlier quoted context omitted.

sounds to me like iphone isnt actually that safe otherwise it wouldnt make sense. maybe we are missing some critical information

GrapheneOS seems to be consistently the hardest to exploit AFU based on various Cellubrite leaks. iPhones have better protection than all other Androids except Pixels.

IIRC it was the only one that Cellebrite couldn't break, but this was based on quite old news.

Re: GrapheneOS protections against data extraction from locked devices

#147
post #142

Earlier quoted context omitted.

What am I misinterpreting? OP literally said they don't understand why a journalist would carry these data with them. As if the data is a file on your phone. Data can be a contact book on your phone, or a messenger with E2E encrypted messages. What would the alternative to that be? Sending pigeons?

Restoring from remote backup when you reach your destination, then wiping again before you cross borders. Or shipping the (encrypted) data separately and picking it up after safe arrival.

The government can easily get your remote backup, of course. It's just that border control won't know you have one.

Re: GrapheneOS protections against data extraction from locked devices

#148
post #45

Earlier quoted context omitted.

Because you may need the data in the data during/after your travel and lack clean way to access safely, securely and anonymously remotely.

No one is stopped from backing up important data. It is, in fact, kind of boneheaded to keep all "valuables" on a single device. I don't understand the scenario of not trusting a device to safely access the Internet or the telephony grid while also insisting that they need a PHONE to keep all their stuff on where they're going, and at the same time somehow trust that both themselves and their possessions are perfectl…

Personally I just got grapheneos to replace my normal phone. It's nice, it works for the user instead of the advertiser, and its security features help block antiuser features in apps

Re: GrapheneOS protections against data extraction from locked devices

#149
post #48

There was some comment here somewhere arguing that 16 characters for a password is too little, but that he used the pattern lock. Looks like it was deleted. Anyway. The pattern lock in Android provides Log2(389112) =~ 18.57 bits of entropy. This is less than 3 random characters, or 4 lowercase letters, or a decimal PIN digit password of 6 characters. Granted, you could use mnemonics for long passwords, but how conven…

GrapheneOS supports up to 128 character passwords to support using diceware passphrases. Using a strong passphrase avoids depending on the secure element. A random 6 digit PIN is secure due to the secure element rate limiting. Only a total of 20 attempts are permitted so even a random 4 digit PIN would be fine.

GrapheneOS adds the option to set a 2nd factor PIN for fingerprint unlock to make using a strong passphrase convenient without the downsides of biometric-only unlock.

Pattern lock strongly encouraging using only a tiny subset of the possibilities so it's much worse than your analysis shows. It was removed from GrapheneOS years ago because it's far worse than simply generating and using a random 6 digit PIN despite appearing to be similar. It gives a false sense of security and we didn't want to add support for a duress pattern or random pattern generating alongside those planned features. Built-in random PIN and passphrase generation is still in progress but has been started and will be shipped.

Re: GrapheneOS protections against data extraction from locked devices

#150

Earlier quoted context omitted.

Restoring from remote backup when you reach your destination, then wiping again before you cross borders. Or shipping the (encrypted) data separately and picking it up after safe arrival.

The government can easily get your remote backup, of course. It's just that border control won't know you have one.

Not if it’s encrypted and self-hosted. Your doomerism is silly. “The government” is not all-powerful, or they wouldn’t need to pester people for PINs at the border.
Post reply on HN