Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

231–240 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#231
post #21

Earlier quoted context omitted.

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.

This is why it is important to continue iterating everywhere that device security is important for everyone. iPhone has nearly the same level of protection and we also do not see it as 'criminal by default'. Secondly, it is important to get as many people to use GrapheneOS as possible, including non-tech people. The more widespread it becomes, the harder it will become to paint this picture.

GrapheneOS is good enough to have an entire column dedicated to it in Cellebrite's support matrix, and if I remember correctly the device could break into iPhones but not phones running GrapheneOS.

Re: GrapheneOS protections against data extraction from locked devices

#232

Earlier quoted context omitted.

IIRC it was the only one that Cellebrite couldn't break, but this was based on quite old news.

There are more recent leaks. The last release of GrapheneOS they've been able to exploit on locked device is still from 2022 as of a couple months ago. They take longer to break into iPhones than stock Pixels but that may largely be due to Google giving much earlier access for public testing. They have a far shorter window to prepare for a new iOS release before it's in production as a regular update for users.

> The last release of GrapheneOS they've been able to exploit on locked device is still from 2022 as of a couple months ago.

That's impressive!!

Re: GrapheneOS protections against data extraction from locked devices

#233
post #34

Earlier quoted context omitted.

citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted. Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to ge…

I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.

Remove and securely overwrite, otherwise the data can still be recovered from the disk image. We have not made privacy easy.

Re: GrapheneOS protections against data extraction from locked devices

#235
post #209

Earlier quoted context omitted.

That isn't truly hidden and can be detected as a low level from the SSD.

No it can't. The the thing, it's obfuscated.

I'm gonna trust the grapheneos HN account on this one.

Re: GrapheneOS protections against data extraction from locked devices

#236

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

> I am wary that I could be targeted at a border just for having a google pixel with grapheneOS. Is that likely to happen at all in a civilized (Western) country?

Yes, see https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro... . The OP is a response to this, as has been pointed out several times here in this discussion.

Re: GrapheneOS protections against data extraction from locked devices

#237
post #19

Earlier quoted context omitted.

I hate this meme. The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

The United States has famously shot and killed protesters in the Vietnam war era. They have dedicated torture facilities for people suspected, not even convicted, of terrorism. Police officers use lethal violence for no reason every month and rarely get more than a talking to. In a perfect society, your point makes sense, but I don't see why the authorities in the real world would need to care about committing a wors…

They have killed ice protestors in the open, murderers weren't even investigated.

Re: GrapheneOS protections against data extraction from locked devices

#238

Earlier quoted context omitted.

> I am wary that I could be targeted at a border just for having a google pixel with grapheneOS. Is that likely to happen at all in a civilized (Western) country?

Yes, see https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro... . The OP is a response to this, as has been pointed out several times here in this discussion.

No. Not even close.

The headline of that article ("US government targets Cop City protester over phone operating system") rests firmly in the lies category of clickbait.

They were targeted for secondary inspection upon their return to the US because they were on a terrorist watchlist, not because they have a phone that runs GrapheneOS.

At least some of what investigators did during that inspection seems likely to be illegal (and the courts will decide if it was, or was not). Meanwhile, the grounds for being on a watchlist to begin with seem dubious at best, as is often the case with such lists.

But none of this was instigated by the presence of GrapheneOS on their phone.

GrapheneOS didn't enter the picture until the person who was already detained and being investigated (and being refused access to a lawyer) provided the phone's duress PIN to nuke the device (by erasing the crypto keys and rebooting) instead of the normal PIN.

Re: GrapheneOS protections against data extraction from locked devices

#239
post #238

Earlier quoted context omitted.

Yes, see https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro... . The OP is a response to this, as has been pointed out several times here in this discussion.

No. Not even close. The headline of that article ("US government targets Cop City protester over phone operating system") rests firmly in the lies category of clickbait. They were targeted for secondary inspection upon their return to the US because they were on a terrorist watchlist, not because they have a phone that runs GrapheneOS. At least some of what investigators did during that inspection seems likely to be…

You're re-stating what the headline says.

Re: GrapheneOS protections against data extraction from locked devices

#240
post #238

Earlier quoted context omitted.

No. Not even close. The headline of that article ("US government targets Cop City protester over phone operating system") rests firmly in the lies category of clickbait. They were targeted for secondary inspection upon their return to the US because they were on a terrorist watchlist, not because they have a phone that runs GrapheneOS. At least some of what investigators did during that inspection seems likely to be…

You're re-stating what the headline says.

> You're re-stating what the headline says.

I've done no such thing.

Post reply on HN