Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

181–190 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#181
post #108

Earlier quoted context omitted.

[flagged]

> The iPhone Probably the latest models. Cop told me they have problems cracking those. Older models not so much, that's pretty common knowledge.

Is this because of vulnerabilities baked in the HW (or bootROM or any other unpatchable area)? What’s the situation on older Pixels? Are they generally safer than an iPhone for HW issues? It’s expected that given a few years some vulnerabilities will crop up for most hardware.

So then the best chance for security is to stay up to date with everything, including the latest HW model. At least this gives an attacker a window of only ~1 year to find and exploit a vulnerability.

Re: GrapheneOS protections against data extraction from locked devices

#182
post #157

Earlier quoted context omitted.

Encryption in this case is irrelevant. If they get the encrypted backup they can already charge you if you don't decrypt it. Self-hosting is the way obviously

Can the border guard go to your house and retrieve something, bring it to the checkpoint, and ask you to do something with it before entry? No. This is out of their legal authority. Also, you could set up a system where the phone cannot restore the backup on reentry. Perhaps a single use restore key that you use at your original destination, so the restore cannot be performed again until you return home and generate…

That's not my point. Rather that any self-hosted solution would. Encryption is completely optional and can be illegal in some places. As long as you trust the endpoint you only care about encryption in transit.

If your devices are seized having encrypted data can pose extra risk.

Deniable encryption exists and burden of proving that you haven't used it can be put on you.

Basically I'm trying to say "it depends". I'm not a fan of "let's just slap a(nother) layer of encryption on it" security model. My home servers aren't encrypted and I see no reason to do so. Sensitive data is encrypted based on the sensitivity.

> The best option

The best option is the one that is most convenient to the user and fits the task at hand.

If you are on a demonstration and need to broadcast status live then you don't have a luxury of bringing in a blank phone and restoring backup before each transmission

Re: GrapheneOS protections against data extraction from locked devices

#183
post #111
post #19

Earlier quoted context omitted.

I hate this meme. The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

Doesn't have to be a literal wrench right? A government can trivially and legally make you miss the itinerary that made your holiday possible that you've saved up for the rest of the year with no restitution that I'm aware of in any jurisdiction. They can confiscate 'evidence' (any computer and (backup) storage media in your house) for years. They can do a heck of a lot that's more annoying than medium amounts of wre…

The wrench attack is still far weaker than a push-button attack.

In the wrench attack you are aware that you have been attacked, and you're aware of what data the attacker gains.

Additionally there are schemes like deniable encryption which can mitigate the outcomes of such an attack or serve as a red herring.

Furthermore it's dependent on physical intimidation which is expensive to scale and can be met with your own physical intimidation. In order for a wrench attack to scale to an entire society you have to send the gestapo to everyone's house whereas push-button attacks scale by default unbenownst to the victims and enable more nefarious systems to be built on top of them. In the USA this would mean interrogating some well armed citizens.

Lastly, you aren't forced to give up the key by any means. They can torture you to death and there is nothing they can do if you don't want to give up the key. There are some secrets in the game of love and war that are worth taking to - it's why spies are equipped with cyanide pills.

Re: GrapheneOS protections against data extraction from locked devices

#184

Earlier quoted context omitted.

> Is that a success? Definitely. > Maybe, if your data really is that valuable and a successful border crossing isn't. Even if my data consisted entirely of cat pictures, it would be more valuable than successfuly crossing the border into a country that actively tries to invade my privacy.

Well why are you showing up at a border crossing if you don't want to cross the border?

To cross said border with my burner phone in my pocket and do whatever I need to do on the other side, why else? You do realise that is by far the most likely outcome, yes?

Re: GrapheneOS protections against data extraction from locked devices

#185
post #102

Earlier quoted context omitted.

This is why it is important to continue iterating everywhere that device security is important for everyone. iPhone has nearly the same level of protection and we also do not see it as 'criminal by default'. Secondly, it is important to get as many people to use GrapheneOS as possible, including non-tech people. The more widespread it becomes, the harder it will become to paint this picture.

Perhaps GrapheneOS should just be an ASOP release with implicit security features that makes it hard to notice it is anything different. If people think it is a vanilla Android install, it would give them no reason to imply criminal activity.

Google is never going to put their administrative access in a restricted sandbox.

That is diametrically opposed to their interests in data collection.

Re: GrapheneOS protections against data extraction from locked devices

#186
post #19

Earlier quoted context omitted.

I hate this meme. The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

You end up getting hit by a wrench though, that doesn't sound like it ends well for you.

If you're that much of a coward, you won't get hit by a wrench anyways because you will give your keys up immediately. But you will force your enemy to exert additional effort.

It works for the same reason locks on houses work against cops or criminals, despite the existence of lockpicking and locksmiths. There are various layers of physical security, and while no layer can prevent an attack absolutely they each increase the cost of an attack.

The system is only as secure as it's weakest layer.

So in a mixed information/physical system like a smartphone why should we allow the weak point to be the information system? To improve the information system we need only to rewrite the software, so the per-unit cost is nothing in the large.

Re: GrapheneOS protections against data extraction from locked devices

#187

It's fairly easy to open up a phone and probe inner circuitry. I suspect that'll be the next step for malicious actors. I doubt very much the phone is fully resistant to having malicious data injected onto various busses.

Rate limiting is implemented by a high quality secure element hardened against physical tampering. It isn't implemented by the regular SoC, RAM or the OS. It's not simple to bypass the throttling making a random 6 digit PIN secure. GrapheneOS adds support for a strong passphrase to avoid depending on the secure element. It also adds the option to set a 2nd factor PIN for fingerprint unlock to make using a strong pass…

What if the supplier backdoors the secure element? It would be better to just encourage the user to use a high-entropy key, and not bother with the secure element at all.

Re: GrapheneOS protections against data extraction from locked devices

#188
post #182

Earlier quoted context omitted.

Can the border guard go to your house and retrieve something, bring it to the checkpoint, and ask you to do something with it before entry? No. This is out of their legal authority. Also, you could set up a system where the phone cannot restore the backup on reentry. Perhaps a single use restore key that you use at your original destination, so the restore cannot be performed again until you return home and generate…

That's not my point. Rather that any self-hosted solution would. Encryption is completely optional and can be illegal in some places. As long as you trust the endpoint you only care about encryption in transit. If your devices are seized having encrypted data can pose extra risk. Deniable encryption exists and burden of proving that you haven't used it can be put on you. Basically I'm trying to say "it depends". I'm…

> If your devices are seized having encrypted data can pose extra risk.

I don’t think you can even set up an iPhone anymore without encryption. It’s just “on”, not even “on by default”.

> My home servers aren't encrypted and I see no reason to do so. Sensitive data is encrypted based on the sensitivity.

If you do sensitive work, you should be concerned about someone breaking in and running off with your storage. It’s unfortunate but that’s just how it is. Encryption adds very little overhead on modern hardware.

> If you are on a demonstration and need to broadcast status live then you don't have a luxury of bringing in a blank phone and restoring backup before each transmission

That’s not crossing a border then, is it? The case under discussion was about a border crossing, where (apparently?) Constitutional rights are suspended. A used phone adds little to the cost of an international trip.

Re: GrapheneOS protections against data extraction from locked devices

#189

Earlier quoted context omitted.

You end up getting hit by a wrench though, that doesn't sound like it ends well for you.

Sounds like something a coward would say, honestly.

Everyone thinks they're brave until they get punched in the face. The fact that a handful of terrorist attacks decades ago were all it took to push society into voting for control freaks who built a worldwide surveillance state to nanny them tells me all I need to know about how brave people really are.

Re: GrapheneOS protections against data extraction from locked devices

#190
Does it protect it in After First Unlock mode? I often use my device and if I lock it before LE or another bad actor catches it then it's kind of useless if it doesn't protect my data in after first unlock (locked) mode. Especially with LE agencies having tools like Cellebrite at their station for same day analysis. Most people probably won't have time to reboot their device.

Similar to how I use Veracrypt, but I leave my PC running, because I hate spending time booting up again. So LE could decrypt my stuff using RAM extraction stuff.

Post reply on HN