Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

161–170 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#161
post #157

Earlier quoted context omitted.

Not if it’s encrypted and self-hosted. Your doomerism is silly. “The government” is not all-powerful, or they wouldn’t need to pester people for PINs at the border.

Encryption in this case is irrelevant. If they get the encrypted backup they can already charge you if you don't decrypt it. Self-hosting is the way obviously

Can the border guard go to your house and retrieve something, bring it to the checkpoint, and ask you to do something with it before entry? No. This is out of their legal authority.

Also, you could set up a system where the phone cannot restore the backup on reentry. Perhaps a single use restore key that you use at your original destination, so the restore cannot be performed again until you return home and generate a new code. This evades the (flimsy) charges that were applied in this case.

The best option, however, is to bring a blank disposable device, restore from backup at your destination, then discard the device before you cross the border again.

Re: GrapheneOS protections against data extraction from locked devices

#162
post #116
post #33

Earlier quoted context omitted.

The easiest way to avoid suspicion is to have a phone filled with cat and family pictures, dumb apps and games. You don't avoid scrutiny by being wierd and hiding things, but by hiding in plain sight by being ultra boring.

Add some dickpicks because who doesn't have something on their phone that they don't want others to see.

Multiple decoy accounts, heh. First one: cat pics. Second one: dick pics. Third one: conversations with an imaginary mistress. Fourth one: porn that's illegal in Korea. Fifth one: ....

completely impractical obviously

Re: GrapheneOS protections against data extraction from locked devices

#163
post #48

There was some comment here somewhere arguing that 16 characters for a password is too little, but that he used the pattern lock. Looks like it was deleted. Anyway. The pattern lock in Android provides Log2(389112) =~ 18.57 bits of entropy. This is less than 3 random characters, or 4 lowercase letters, or a decimal PIN digit password of 6 characters. Granted, you could use mnemonics for long passwords, but how conven…

GrapheneOS supports up to 128 character passwords to support using diceware passphrases. Using a strong passphrase avoids depending on the secure element. A random 6 digit PIN is secure due to the secure element rate limiting. Only a total of 20 attempts are permitted so even a random 4 digit PIN would be fine. GrapheneOS adds the option to set a 2nd factor PIN for fingerprint unlock to make using a strong passphrase…

Thank you for your service.

Re: GrapheneOS protections against data extraction from locked devices

#164

It's fairly easy to open up a phone and probe inner circuitry. I suspect that'll be the next step for malicious actors. I doubt very much the phone is fully resistant to having malicious data injected onto various busses.

I would not think it is fairly easy. The only real physical attack I can think of is to somehow to remove the delay throttles and brute force unlocking the device. This would be feasible for digits PIN, but not if you include characters. I am curious if you had something else in mind.

[deleted]

Re: GrapheneOS protections against data extraction from locked devices

#165

although it is wonderful to know that there exists a piece of hardware in the world that is not conspiring against its users, the outcome of entering a duress password should be indistinguishable to the user that grabs hold of the mobile phone. The duress password should wipe off the real user account information but present the kidnappers with a full-fledged operating system populated with real-looking content to en…

That's called a decoy password rather than a duress password, btw

Re: GrapheneOS protections against data extraction from locked devices

#166
post #111
post #19

Earlier quoted context omitted.

I hate this meme. The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

Doesn't have to be a literal wrench right? A government can trivially and legally make you miss the itinerary that made your holiday possible that you've saved up for the rest of the year with no restitution that I'm aware of in any jurisdiction. They can confiscate 'evidence' (any computer and (backup) storage media in your house) for years. They can do a heck of a lot that's more annoying than medium amounts of wre…

Missing a holiday is usually not such a bad price to save you from whatever the government is considering doing to you.

Re: GrapheneOS protections against data extraction from locked devices

#167

It's fairly easy to open up a phone and probe inner circuitry. I suspect that'll be the next step for malicious actors. I doubt very much the phone is fully resistant to having malicious data injected onto various busses.

Rate limiting is implemented by a high quality secure element hardened against physical tampering. It isn't implemented by the regular SoC, RAM or the OS. It's not simple to bypass the throttling making a random 6 digit PIN secure.

GrapheneOS adds support for a strong passphrase to avoid depending on the secure element. It also adds the option to set a 2nd factor PIN for fingerprint unlock to make using a strong passphrase convenient via fingerprint+PIN secondary unlock while in After First Unlock state. Only 5 fingerprint unlock attempts are permitting and an incorrect 2nd factor PIN counts towards it so it's hardly a making the device protection weaker. Our PIN scrambling and the duress PIN features can also both be used with the 2nd factor PIN.

Re: GrapheneOS protections against data extraction from locked devices

#168

It's fairly easy to open up a phone and probe inner circuitry. I suspect that'll be the next step for malicious actors. I doubt very much the phone is fully resistant to having malicious data injected onto various busses.

I would not think it is fairly easy. The only real physical attack I can think of is to somehow to remove the delay throttles and brute force unlocking the device. This would be feasible for digits PIN, but not if you include characters. I am curious if you had something else in mind.

Rate limiting is implemented by a high quality secure element hardened against physical tampering. It isn't implemented by the regular SoC, RAM or the OS. It's not simple to bypass the throttling making a random 6 digit PIN secure.

GrapheneOS adds support for a strong passphrase to avoid depending on the secure element. It also adds the option to set a 2nd factor PIN for fingerprint unlock to make using a strong passphrase convenient via fingerprint+PIN secondary unlock while in After First Unlock state. Only 5 fingerprint unlock attempts are permitting and an incorrect 2nd factor PIN counts towards it so it's hardly a making the device protection weaker. Our PIN scrambling and the duress PIN features can also both be used with the 2nd factor PIN.

Re: GrapheneOS protections against data extraction from locked devices

#169

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

> I am wary that I could be targeted at a border just for having a google pixel with grapheneOS.

Is that likely to happen at all in a civilized (Western) country?

Re: GrapheneOS protections against data extraction from locked devices

#170
post #3

Relevant xkcd https://xkcd.com/538/

Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr... According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone. It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm sur…

The alleged charges seem nonsense - destruction of property to prevent seizure? First no property was destroyed, and second they could still seize it. But US courts are a coin toss so it may still work for the government.
Post reply on HN