Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

261–270 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#261
post #60
post #21

Earlier quoted context omitted.

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.

He’s a “surveillance expert” so the language is not at all surprising. These are the people who always bring up the appeal to emotion, associating a benign act with something unpalatable, criminal, terrorist, think of the children. When your job depends on not understanding and all that.

It was the article author's choice to include that language without wider context. People say things that can undermine their own position all the time, and it's those that present those statements that influence whether that happens or not. Think about how I soloed that quote out of the wider article for example.

Re: GrapheneOS protections against data extraction from locked devices

#262

Earlier quoted context omitted.

It doesn't feel like you're very interested in solving this problem - you seem more interested in defending the status quo

In fairness, an adversarial challenge can be useful in pointing out weaknesses (and possible mitigations) to a particular technical approach. It's not clear that all of those objections are substantive or insurmountable. "The USB port may have died" might be one possible response. (Not technically a lie, and hence defensible in court.) Or just silence. Alternatively, some way of directing such probes to the decoy par…

>"The USB port may have died" might be one possible response. (Not technically a lie, and hence defensible in court.) Or just silence.

That's about as convincing as "wow this phone just decided to experience catastrophic hardware failure after entering your totally-not-duress pin". Not to mention there's wireless adb.

>Alternatively, some way of directing such probes to the decoy partition and presenting a sufficiently coherent impression of a valid partition might be another approach.

That won't work because they'd notice the adb logs don't correspond to actions taken on the actual phone.

>Much of this comes down to risks presented and costs of mitigation (or of getting mitigations wrong).

Right, which is why grapheneos didn't bother implementing it, because it's a huge effort and it's not worth giving users a false sense of security (eg. thinking that the decoy works when it doesn't), and them getting sent to prison for it.

Re: GrapheneOS protections against data extraction from locked devices

#263
post #4

I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password. On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where ke…

I’m still curious if they “weren’t inside the U.S.”, how they are being charged with a law that is only applicable to…the U.S.

Some U.S. laws are extraterrestrial, such as murder, crimes against children, tax laws, etc.

Re: GrapheneOS protections against data extraction from locked devices

#264
post #248
post #221

Earlier quoted context omitted.

Well the activity generator is going to have to be very careful to not accidentally overwrite data on the hidden volume, and somehow able to hide itself from adb or forensic tools that it's enabled.

The activity generator may be a tool on your PC which is well aware of the hidden partition's presence. All it has to do is changing partition size before writing anything, then restoring it. It may also generate using your real data, which you explicitly ack. Some safe communication with your grandma and mother, some messages from your employer, banks, other recent 2FA codes. You white flag contact names and it does…

The problem with pre-generated activity is that it must cut off at (or shortly in the future of) generation time, to be plausible.

Otherwise that activity would be suspicious due to either a lack of recent records, or of presumably implausible future ones.

Generating data in advance and applying or updating timestamps later, on an ongoing basis, or when a duress code is entered is a possible way of mitigating this. There's the question of how convincing such data would have to be. White-flagging and generating (or appropriating from public sources, e.g., business or institutional entities) contacts for this might be a part of it. This is similar to but not entirely the same as data fuzzing, which is generally seen as applying to a primary data trail.

Re: GrapheneOS protections against data extraction from locked devices

#265

Earlier quoted context omitted.

Restoring from remote backup when you reach your destination, then wiping again before you cross borders. Or shipping the (encrypted) data separately and picking it up after safe arrival.

The government can easily get your remote backup, of course. It's just that border control won't know you have one.

If the government could easily get the remote backup they would have already done it.

Re: GrapheneOS protections against data extraction from locked devices

#266

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

"my phone died yesterday, a friend just gave me his old pixel" - please don't do this. That's lying to law enforcement and they can prosecute. Just say it's your travel phone.

Re: GrapheneOS protections against data extraction from locked devices

#267

Earlier quoted context omitted.

[flagged]

Apple can at any time push a hostile "upgrade" that will remove or disable the claimed security features. You don't control the operating system, and can't trust that it isn't backdoored, especially given Apple's record[0]. [0] https://en.wikipedia.org/wiki/PRISM

This is true at least with cloud services as they disabled ADP in the EU.

Re: GrapheneOS protections against data extraction from locked devices

#268

It's fairly easy to open up a phone and probe inner circuitry. I suspect that'll be the next step for malicious actors. I doubt very much the phone is fully resistant to having malicious data injected onto various busses.

This is one of the laziest false comments that I have ever read.

Re: GrapheneOS protections against data extraction from locked devices

#269
post #185
post #102

Earlier quoted context omitted.

Perhaps GrapheneOS should just be an ASOP release with implicit security features that makes it hard to notice it is anything different. If people think it is a vanilla Android install, it would give them no reason to imply criminal activity.

Google is never going to put their administrative access in a restricted sandbox. That is diametrically opposed to their interests in data collection.

They'd also have to update all their phone spec sheets -- not having the sandbox doubled graphene's battery life on my Pixel 6 Pro (in practice and vs. advertised specs).

Re: GrapheneOS protections against data extraction from locked devices

#270

Earlier quoted context omitted.

I’m still curious if they “weren’t inside the U.S.”, how they are being charged with a law that is only applicable to…the U.S.

Some U.S. laws are extraterrestrial, such as murder, crimes against children, tax laws, etc.

Also the US CLOUD act: If you do business in the US, you have to give American authorities access to warrantlessly search any device not in the US that you have access to.

(I heard Europe and China passed the same laws. The EU has intelligence sharing agreements with the US, so I guess American authorities can just have the EU pull the data for US citizens in the US and forward it back home. I'm not a lawyer. It'd be nice if I'm wrong.)

Post reply on HN