Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

101–110 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#101

[flagged]

>it was already pretty much impossible to get an encrypted device past US Customs more than 15 years ago

B-but I did it many times? Or do you mean that it's impossible to refuse providing the decryption key and still pass? That's pretty obvious.

Re: GrapheneOS protections against data extraction from locked devices

#102
post #21

Earlier quoted context omitted.

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.

This is why it is important to continue iterating everywhere that device security is important for everyone. iPhone has nearly the same level of protection and we also do not see it as 'criminal by default'. Secondly, it is important to get as many people to use GrapheneOS as possible, including non-tech people. The more widespread it becomes, the harder it will become to paint this picture.

Perhaps GrapheneOS should just be an ASOP release with implicit security features that makes it hard to notice it is anything different. If people think it is a vanilla Android install, it would give them no reason to imply criminal activity.

Re: GrapheneOS protections against data extraction from locked devices

#103

Earlier quoted context omitted.

Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.

Even more of a reason for good and easy backup and restore. Before travel back up the real contents and restore a dummy travel backup with random games, stock photos etc. Then restore back to real contents.

This is never going to happen for the same reason Apple and Google won’t let you use different backup/restore methods.

Re: GrapheneOS protections against data extraction from locked devices

#104

It's fairly easy to open up a phone and probe inner circuitry. I suspect that'll be the next step for malicious actors. I doubt very much the phone is fully resistant to having malicious data injected onto various busses.

If it was that easy, we'd just do that to get access to our own data on these devices. The OEM unlock toggle is a much-desired feature for a reason

Re: GrapheneOS protections against data extraction from locked devices

#105
post #11

Earlier quoted context omitted.

[flagged]

Border officials don't have the right to search all of your data. You are also not under any obligation to have it on your phone at all times.

Just like a regular cop, all they need is probable cause.

Re: GrapheneOS protections against data extraction from locked devices

#106
post #90

Earlier quoted context omitted.

Neat, I didn't realize it was still included. I thought it had been abandonned. So basically one needs a webdav server somewhere or an usb flash drive.

The problem is that most apps opt out of backup, so it's effectively useless.

Yeah I don't even understand why this is even a thing. It should be user's choice, not app vendor/developer's choice.

Re: GrapheneOS protections against data extraction from locked devices

#107

Earlier quoted context omitted.

Yeah but if you're a normal guy strolling through every time with a phone that has nothing- no pictures, no signed in email, no history of messages, 4 contacts. That's abnormal, no way of spinning it as "but I just don't use my phone much" will make that seem normal. The average person has their phone glued to their body 24/7 now. Implying that you don't is abnormal.

"I got on pickpocketed on my last vacation, so now I travel with an old backup phone instead"

This may feel like a good idea as a “gotcha” justification but it just doesn’t matter. It’s still extremely abnormal and you will stick out. The only way to protect yourself is by blending in, not sticking out.

Re: GrapheneOS protections against data extraction from locked devices

#108

Earlier quoted context omitted.

GrapheneOS seems to be consistently the hardest to exploit AFU based on various Cellubrite leaks. iPhones have better protection than all other Androids except Pixels.

[flagged]

> The iPhone

Probably the latest models. Cop told me they have problems cracking those. Older models not so much, that's pretty common knowledge.

Re: GrapheneOS protections against data extraction from locked devices

#109
post #43

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

I think more useful would be to be able to boot into another data partition with a different password, which, in turn, would hide the other "daily" partition. I believe LUKS is capable of that. The storage dump looks like a random set of data and only a valid password can find and decrypt a matching hidden partition. Ideally this should also work on lock screen, e.g. if you type in a non-standard PIN, it would boot f…

Having different data partition forces you to hide stuff, which can be unlawful in some juridictions.

Not having the data in the first place in some specific contexts (like crossing borders) is easier.

Re: GrapheneOS protections against data extraction from locked devices

#110
post #102

Earlier quoted context omitted.

This is why it is important to continue iterating everywhere that device security is important for everyone. iPhone has nearly the same level of protection and we also do not see it as 'criminal by default'. Secondly, it is important to get as many people to use GrapheneOS as possible, including non-tech people. The more widespread it becomes, the harder it will become to paint this picture.

Perhaps GrapheneOS should just be an ASOP release with implicit security features that makes it hard to notice it is anything different. If people think it is a vanilla Android install, it would give them no reason to imply criminal activity.

Not worthwhile or feasible. The OS is not designed to hide its identity.
Post reply on HN