I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password. On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where ke…
GrapheneOS protections against data extraction from locked devices
241–250 of 284 posts
Re: GrapheneOS protections against data extraction from locked devices
#242Earlier quoted context omitted.
> I am wary that I could be targeted at a border just for having a google pixel with grapheneOS. Is that likely to happen at all in a civilized (Western) country?
Yes, see https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro... . The OP is a response to this, as has been pointed out several times here in this discussion.
Re: GrapheneOS protections against data extraction from locked devices
#243I always leave my phone and laptop off when going through TSA or Passport Control. I don't think in the US you an be compelled into giving up your password. They are free to confiscate the device but with it powered down good luck trying to break the password.
Re: GrapheneOS protections against data extraction from locked devices
#244Earlier quoted context omitted.
Those are ... relatively minor concerns. Firing off as part of a duress key entry, and removing itself (from the decoy partition) as its work is done, would suffice. ADB / forensic tools would be ineffective if USB access is denied (as discussed elsewhere in this thread).
>ADB / forensic tools would be ineffective if USB access is denied (as discussed elsewhere in this thread). Well no, because if you gave the pin, you'd expect the phone to work normally, including enabling adb. If you gave the pin but adb doesn't work that would be massively suspicious. Same if adb worked but logs were scrubbed. Otherwise you're back at "border guards found out you gave a duress pin, now you're being…
Re: GrapheneOS protections against data extraction from locked devices
#245Earlier quoted context omitted.
>ADB / forensic tools would be ineffective if USB access is denied (as discussed elsewhere in this thread). Well no, because if you gave the pin, you'd expect the phone to work normally, including enabling adb. If you gave the pin but adb doesn't work that would be massively suspicious. Same if adb worked but logs were scrubbed. Otherwise you're back at "border guards found out you gave a duress pin, now you're being…
It doesn't feel like you're very interested in solving this problem - you seem more interested in defending the status quo
It's not clear that all of those objections are substantive or insurmountable.
"The USB port may have died" might be one possible response. (Not technically a lie, and hence defensible in court.) Or just silence.
Alternatively, some way of directing such probes to the decoy partition and presenting a sufficiently coherent impression of a valid partition might be another approach.
Much of this comes down to risks presented and costs of mitigation (or of getting mitigations wrong).
Re: GrapheneOS protections against data extraction from locked devices
#246Re: GrapheneOS protections against data extraction from locked devices
#247Earlier quoted context omitted.
This is why it is important to continue iterating everywhere that device security is important for everyone. iPhone has nearly the same level of protection and we also do not see it as 'criminal by default'. Secondly, it is important to get as many people to use GrapheneOS as possible, including non-tech people. The more widespread it becomes, the harder it will become to paint this picture.
GrapheneOS is good enough to have an entire column dedicated to it in Cellebrite's support matrix, and if I remember correctly the device could break into iPhones but not phones running GrapheneOS.
Re: GrapheneOS protections against data extraction from locked devices
#248Earlier quoted context omitted.
Who carriers around a phone that doesn't have any activity for months/years? An activity-generator might help address that.
Well the activity generator is going to have to be very careful to not accidentally overwrite data on the hidden volume, and somehow able to hide itself from adb or forensic tools that it's enabled.
Re: GrapheneOS protections against data extraction from locked devices
#249Earlier quoted context omitted.
This is also relevant if you get the phone back. There could be some nasty hw modifications that could leak data out of the phone in AFU state. Hopefully people in these kinds of situations take this into account. IMO all phones and computers should be treated as unsafe to unlock after they've been seized.
Im skeptical of what the average lab can do on modern day hardware, but it's not something I would ever want to test my luck on.