Live data from Hacker News

GrapheneOS and forensic extraction of data (2024)

discuss.grapheneos.org

181–190 of 208 posts

Re: GrapheneOS and forensic extraction of data (2024)

#181

I really love Graphene OS but I _wish_ there was a version in which you could get a root shell and extract private data of apps you install when verified as the user. The developers are on record as saying that root blows a hole in their security model (it does!) but if there was _some_ way of doing it safely, so I can modify applications I as the user wish to, it would be my ideal OS. I know I could download and sel…

You can enable root on GrapheneOS. It will erase your data, however, so make a backup before you do. But if you really want root you can save your data, root, restore, and leave root on.

How can I enable root?

Re: GrapheneOS and forensic extraction of data (2024)

#182
post #4

There is no such thing like "bad government" and "good government". I mean - it really depends on people's views, therefore we must not blissfully put our data into govt hands because "they will protect us from terrorists and child rapists". What they will do, actually, is that for sure they will abuse innocent citizens at some point of time. They will. Even if they don't, they will. Or maybe they are doing it right…

No. When the government fails to delivery what people need (not necessarily wants), you have a bad government. When gangs and bandits (or drugs, or diseases, or whatever) takes on the street, it's not about people's view, it's just bad stuff that the government need to address or there's no point on having a government.

This sounds extremely simplistic. Countries are isolated universes. Actions of a government in a country affect other countries. Some problems require multiple governments to work together (see global warming and supply chain issues). Different governments have different priorities at any given time even if they all have roughly the same absolute list of issues

Re: GrapheneOS and forensic extraction of data (2024)

#183
post #105
post #104

Earlier quoted context omitted.

Since the 1980s, we have been consistently taxing less. If the tap is dry, it isn't because of over-taxation - it's because there's a reservoir of wealth hoarded by the relatively few. A even cursory glance at the trajectory of wealth distribution will make that clear. Others have attempted to refute your above statement, but it's not really relevant. Your response does not really align with the parent post, because…

> Instead, they said "you cannot solve everything ever, and everything has tradeoffs", along with "because if you try, you run out of money no matter what". > This seems like a fair statement. Would you care to address that? Sure. That's like saying fire is hot and water is wet. The fact that tradeoffs obviously exist doesn't mean we can make meaningful changes to improve things.

I think you mean "doesn't mean we can't", but you seem to be hyper-focusing on the summary statement I wrote, of the original author's post. That summary statement was in place to explain why your original post wasn't addressing the issue.

But that statement was summarizing a portion of the original author's post. If placed back in the context it came from, you can see the original author was not saying we cannot make meaningful changes. At all.

Instead, the author was said:

Aside from the fact that there's a subjective definition problem here (how do we decide what people "need"?), I think this an unrealistic view. By this definition, every government that has ever existed or ever will exist is a "bad" government because no government can ever tackle every single problem 100% of the time. Many problems are extremely difficult to solve (e.g. global warming), and others simply cannot be solved without creating other problems.

Thus, they are not defining this as a "we cannot improve things", but instead "if we improve things, some will see that as bad" conjoined with "in other cases, we improve things, but not as fast/completely as desired".

As far as I can see, there is not a single point that the original author said we cannot improve things. They don't even hint at that.

Re: GrapheneOS and forensic extraction of data (2024)

#184
post #108
post #84

Earlier quoted context omitted.

Requiring people to watch a 1hr+ video to understand your argument is a big red flag.

Why's that? A topic as big as this takes quite a lot of refuting. If you're interested in finding the truth, then you'll at least begin watching it to see if it offers any promise.

Videos are a terrible way to convey logical arguments. It's much harder to skip back and forth, search for specific bits, etc ... . They're for entertainment, which encourages a suspension of critical thinking. If you're confident there's a solid argument to be made, make it in text so it can easily be analysed and challenged.

Re: GrapheneOS and forensic extraction of data (2024)

#185

> Cellebrite admits they can not hack GrapheneOS if users had installed updates since late 2022. So, how do I know that GrapheneOS is not a honeypot for the really big fish? At this point it seems if you really want to be safe, you have to add obscurity (in addition to conventional best practices). Like changing the pinout on your USB port so the exploit device can't connect.

I thought about this for a moment, reminds me of ANOM company. But isn't GraphaneOS open source?

Changing USB pins layout sounds like interesting idea.

Re: GrapheneOS and forensic extraction of data (2024)

#186
post #8

Earlier quoted context omitted.

> therefore we must not blissfully put our data into govt hands Extending this reasoning, we should not blissfully put our data into anyone's hands. Government mission at least have a veneer of public servants, as opposed to private hands whose only real motivation is fiduciary obligations towards the shareholders.

it's about the interests of each party. The interest of a government is to control its citizen, either now or at some point in the future. The interest of a private company is to make more money. Between the two, I certainly prefer a private company attempting to monetize my data rather than a government trying to control me either now or in the future. And let's stop the bs about "public servants", even in the EU wh…

You missed a spot:

In most situations, private companies will share any data they have about you with the government anyway. And can be compelled by law to do it.

So going private is net loss.

Re: GrapheneOS and forensic extraction of data (2024)

#187
post #184
post #108

Earlier quoted context omitted.

Why's that? A topic as big as this takes quite a lot of refuting. If you're interested in finding the truth, then you'll at least begin watching it to see if it offers any promise.

Videos are a terrible way to convey logical arguments. It's much harder to skip back and forth, search for specific bits, etc ... . They're for entertainment, which encourages a suspension of critical thinking. If you're confident there's a solid argument to be made, make it in text so it can easily be analysed and challenged.

I watched the first ten minutes. It's the standard boring exercise of cherry picking a few theoretical physicists who weigh in on climate science despite having little to no experience in it.

Re: GrapheneOS and forensic extraction of data (2024)

#188
post #57

This kinds of make me want to get a pixel and install GrafeneOS there. I'll admit that big companies may have some incentive to protect their users' privacy; but they are an easy legal target. If tomorrow the US or EU pass legislation that mandates a backdoor in all mobile devices, the entire world is screwed.

I want to get a Pixel just for GrapheneOS as well but Google is incapable of selling those things worldwide despite being a trillion dollar corporation.

Swappa.com, mail forwarding.

Re: GrapheneOS and forensic extraction of data (2024)

#189

I really love Graphene OS but I _wish_ there was a version in which you could get a root shell and extract private data of apps you install when verified as the user. The developers are on record as saying that root blows a hole in their security model (it does!) but if there was _some_ way of doing it safely, so I can modify applications I as the user wish to, it would be my ideal OS. I know I could download and sel…

You can't have a cake and eat it. A root access is a big hole, there's no way mainline will support it. As for the possible way, you answered yourself already (custom keys and images) :)

>You can't have a cake and eat it.

That is usually how it's done, yes.

Re: GrapheneOS and forensic extraction of data (2024)

#190
post #36

This feels like countering insinuations on the Internet with insinuations on the Internet. Cellebrite doesn't publicly publish the latest support matrix so we have no real idea what progress if any they've made against recent iPhones and iOS versions, nor any real detail on how something like Lockdown Mode influences outcomes for their software. Nor does this show anything about Pixel 9 or Pixel 10 and the newest var…

This is a post by a user on the GrapheneOS forum not associated with the project in any way from May 2024. Their post referenced April 2024 Cellebrite capabilities rather than the July 2024 data or later where they had fully caught up to recent iPhones and iOS. The post is from May 2024, they didn't have time travel.

GrapheneOS has access to recent Cellebrite Premium documentation from the past couple months which shows the state of things in the previous published documentation from earlier in 2025 along with the 2 snapshots published in 2024 has been carried over.

Post reply on HN