Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

251–260 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#251
post #209

Earlier quoted context omitted.

No it can't. The the thing, it's obfuscated.

I'm gonna trust the grapheneos HN account on this one.

An unmounted, hidden veracrypt volume is pretty much undetectable with the typical forensics, if the OS hasn't leaked anything that would expose it. I don't know what their official account was alluding to with that wildcard statement.

Re: GrapheneOS protections against data extraction from locked devices

#252

Earlier quoted context omitted.

"I'm here for business and my employer requires it" is an acceptable excuse. "I don't like government surveillance" is not.

"I'm self-employed and my SOC 2 compliance consultant requires it."

Would the same sentence not work for a self employed person too?

Re: GrapheneOS protections against data extraction from locked devices

#253
post #196

Earlier quoted context omitted.

This may feel like a good idea as a “gotcha” justification but it just doesn’t matter. It’s still extremely abnormal and you will stick out. The only way to protect yourself is by blending in, not sticking out.

i am familiar with a number of the security team personnel, so i can give you the inside perspective. the reaction you provoke at a border crossing, or an LEO encounter is almost entirely based on what profile you fit. the vehicle, the state/contents of the vehicle, what you say, even how you move, are being evaluated for consistency with a profile.

This reads so vague it does not add anything beyond what 2 minutes of common sense thinking can produce.

Re: GrapheneOS protections against data extraction from locked devices

#254

Earlier quoted context omitted.

Well why are you showing up at a border crossing if you don't want to cross the border?

You may wish to cross the border but not at all costs.

But you already knew the country invades your privacy.

Re: GrapheneOS protections against data extraction from locked devices

#255

Earlier quoted context omitted.

A replacement for SeedVault is planned: https://grapheneos.org/features#encrypted-backups https://github.com/GrapheneOS/os-issue-tracker/issues/4687#i...

Neat, I didn't realize it was still included. I thought it had been abandonned. So basically one needs a webdav server somewhere or an usb flash drive.

It also supports the Android Storage Access Framework, so other forms of network "cloud" storage are also supported as long as the client ("cloud storage app") implements the correct api, so not only webdav

Re: GrapheneOS protections against data extraction from locked devices

#256
post #108

Earlier quoted context omitted.

> The iPhone Probably the latest models. Cop told me they have problems cracking those. Older models not so much, that's pretty common knowledge.

Is this because of vulnerabilities baked in the HW (or bootROM or any other unpatchable area)? What’s the situation on older Pixels? Are they generally safer than an iPhone for HW issues? It’s expected that given a few years some vulnerabilities will crop up for most hardware. So then the best chance for security is to stay up to date with everything, including the latest HW model. At least this gives an attacker a w…

I heard that the MIE is giving them trouble.

Re: GrapheneOS protections against data extraction from locked devices

#257

Earlier quoted context omitted.

You may wish to cross the border but not at all costs.

But you already knew the country invades your privacy.

This country may, or may not, ask me to hand over my burner phone for inspection. Then it may, or may not, deny me entry.

Re: GrapheneOS protections against data extraction from locked devices

#258
post #48

There was some comment here somewhere arguing that 16 characters for a password is too little, but that he used the pattern lock. Looks like it was deleted. Anyway. The pattern lock in Android provides Log2(389112) =~ 18.57 bits of entropy. This is less than 3 random characters, or 4 lowercase letters, or a decimal PIN digit password of 6 characters. Granted, you could use mnemonics for long passwords, but how conven…

GrapheneOS supports up to 128 character passwords to support using diceware passphrases. Using a strong passphrase avoids depending on the secure element. A random 6 digit PIN is secure due to the secure element rate limiting. Only a total of 20 attempts are permitted so even a random 4 digit PIN would be fine. GrapheneOS adds the option to set a 2nd factor PIN for fingerprint unlock to make using a strong passphrase…

Perhaps bad/naive ideas, but consider these options for unlocking where the requirements changes after one incorrect entry.

- After an incorrect key, require two (or more) consecutive valid key entries.

- After an incorrect key, no longer accept that nominal key until a secondary key is supplied.

Re: GrapheneOS protections against data extraction from locked devices

#259

Earlier quoted context omitted.

No one is stopped from backing up important data. It is, in fact, kind of boneheaded to keep all "valuables" on a single device. I don't understand the scenario of not trusting a device to safely access the Internet or the telephony grid while also insisting that they need a PHONE to keep all their stuff on where they're going, and at the same time somehow trust that both themselves and their possessions are perfectl…

Personally I just got grapheneos to replace my normal phone. It's nice, it works for the user instead of the advertiser, and its security features help block antiuser features in apps

I personally run iOS but have given GrapheneOS an extended run on a development phone I use for work, and I have to say it really is a much tidier, less distracting, smoother and more responsive experience than any other Android setup I've used before.

Re: GrapheneOS protections against data extraction from locked devices

#260
post #251

Earlier quoted context omitted.

I'm gonna trust the grapheneos HN account on this one.

An unmounted, hidden veracrypt volume is pretty much undetectable with the typical forensics, if the OS hasn't leaked anything that would expose it. I don't know what their official account was alluding to with that wildcard statement.

That's on HDDs, phones don't use HDDs. We already did this [1]?

[1] https://news.ycombinator.com/threads?id=Cider9986#49058421

https://veracrypt.io/en/Trim%20Operation.html

https://veracrypt.io/en/Wear-Leveling.html

Post reply on HN