Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

271–280 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#271

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

GrapheneOS includes an encrypted backup system covering far more data than Google cloud backups. It backs up data for apps opting out of cloud backups with allowBackup="false" since it operates in the device-to-device transfer mode. The backup system supports arbitrary sync services with a compatible API. Backups are per-profile so you can test it by restoring to a secondary user. We plan to entirely overhaul the bac…

It's great to know this exists! It's one of a few reasons I switched back to iOS after trying grapheneos.

Back then, you were still using Google's backup thing, and it was the year when they intentionally broke it to encourage people to move to unencrypted cloud services for important data.

Re: GrapheneOS protections against data extraction from locked devices

#272
post #180

Earlier quoted context omitted.

That still doesn't prevent other means that developers have to thwart backups. Chrome and vanadium has a custom backup agent that only dumps out settings, so browsing history and bookmarks aren't backed up at all. I believe firefox is similar unless they changed something recently. Same goes for other apps like signal. Browsers, messengers, and camera are the top 3 categories of apps I use on my phone, and the built-…

Vanadium will add more data to the device-to-device backups but we haven't gotten to it yet. For Signal, you can set up their own backups locally and they'll be included with backed up home directory data if that's enabled. Signal encrypts their database and encrypts the key used for it with the hardware keystore. A generic backup system can't back that up directly. The encrypted database is useless outside of the cu…

I wish they had a toggle for this. I'd much rather just have one backup system. Per-app backups is a pain to keep track of, and signal data is by far less sensitive than other stuff on my phone.

Re: GrapheneOS protections against data extraction from locked devices

#273

Earlier quoted context omitted.

Apple can at any time push a hostile "upgrade" that will remove or disable the claimed security features. You don't control the operating system, and can't trust that it isn't backdoored, especially given Apple's record[0]. [0] https://en.wikipedia.org/wiki/PRISM

This is true at least with cloud services as they disabled ADP in the EU.

Edit: UK

And people had to press a button to disable it or their iCloud accounts would be disabled.

Making apple disable ADP is mass surveillance at its finest.

Re: GrapheneOS protections against data extraction from locked devices

#274
post #108

Earlier quoted context omitted.

> The iPhone Probably the latest models. Cop told me they have problems cracking those. Older models not so much, that's pretty common knowledge.

Is this because of vulnerabilities baked in the HW (or bootROM or any other unpatchable area)? What’s the situation on older Pixels? Are they generally safer than an iPhone for HW issues? It’s expected that given a few years some vulnerabilities will crop up for most hardware. So then the best chance for security is to stay up to date with everything, including the latest HW model. At least this gives an attacker a w…

What he told me is all I know. If you look at the various devices that are sold to LE they clearly state which models can be hacked. Did a deep dive in to those devices after that conversation and if I remember correctly they openly state which models can be attacked. Some devices (old ones) you can get on ebay.

Re: GrapheneOS protections against data extraction from locked devices

#275
post #115

Earlier quoted context omitted.

> a perfectly valid answer Makes no difference at all in the real world. You don't have to give valid answers, you need to get the guy across from you to not find you suspicious. That phrase is going to put a red flag on you, valid or not.

> you need to get the guy across from you to not find you suspicious. What? No, who cares about that? Let him find you suspicious, what matters is that he doesn’t access your data. And it is not suspicious to cross borders (esp. US borders) with burner phones. As others have said, it is standard practice.

Clearly someone who probably never been on the receiving end of those kind of situations turned bad.

Re: GrapheneOS protections against data extraction from locked devices

#276
post #19

Relevant xkcd https://xkcd.com/538/

I hate this meme. The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

It's nowadays a $10 wrench.

Re: GrapheneOS protections against data extraction from locked devices

#277
post #157

Earlier quoted context omitted.

Not if it’s encrypted and self-hosted. Your doomerism is silly. “The government” is not all-powerful, or they wouldn’t need to pester people for PINs at the border.

Encryption in this case is irrelevant. If they get the encrypted backup they can already charge you if you don't decrypt it. Self-hosting is the way obviously

[dead]

Re: GrapheneOS protections against data extraction from locked devices

#278
( roughly copying my post from another thread)

A few things:

#1. The download and restore backup method would work for people in general- except it doesn't capture what people would need. Exmaple: I have some thermal cameras that rely on old 32 bit apps that do not run on anything android 12 onwards- If i wipe those old phones, and restore- the apps often wanted to reach out to a server for initial activation- they would fail upon reinstall and i'd be out of the apps that are required to control my cameras and related equipment,which is worth thousands and thousands and thousands. And it'd be all dead weight and rendered useless.

(and competitors today do not compete- for example try finding a 640*480 30 hz or better form factor thermal camera that attaches to phones - they dont exist anymore)

\The solution is full imaging- but there isnt a way to fully image phones and restore backups today. There used to be it seems- but not really with the latest stuff at the time of this post

.

On another note:Veracrypt- The weakness of truecrypt and veracrypt, the hidden OS option only worked if you converted your computer to MBR, which means you can't have a hard drive too large. Making a UEFI hidden OS has not been done yet.

And the Hidden Volume option- isn't 'as' useful, and of course, your OS might make a copy and put it somewhere, you have to be careful. As a example: Any time I open a file, using the software tool Everything to search and confirm this- you can easily see Windows makes copies and temp files and whatnot in randomly named locations- that's the sort of behavior that would screw people over

We need fully image-backup capable Phones. I mean fully. Not just backing up some apps- as this refuses to backup apps you have that are no longer on app stores, or that Play Protect doesn't like, etc.

Next- Plausible deniability is a way forward- but you need multiple profiles, that are cryptographically indistinguishable, along with the phone being hardened so GreyKey /Cellebrite won't be able to exploit a way in. This needs to be built this way from the ground up ideally, eventually.

There has been research about making devices that treat all block space the same way so you can't tell if someone has 1, or 50 profiles or partitions, etc- and even stuff that overlaps. Often it needs to be fixed size partitions, but it is apparently NOT impossible to create. I am aware of Shufflecake attempting to make a solution for Linux, and yes, a Hidden OS option that is forensic- invisible.

But nothing has come out - and especially, for phones.

I hope Graphene OS or another group, eventually works on this for phones. I do wonder if it would require a Linux phone, or something built from the ground up rather than current phone architecture.

It would be nice to see the day where, if you travel to a hostile country, you can tell them you have just one profile, and if they ask, you could theoretically mention a 2nd, and then show it- but you might have 3 more - and they'd all be immune to forensic inspection if the system is built right.(Yes, there's often issues you have to be careful of ,like setting this up so you dont destroy data when in other profiles,)

This is how you solve this problem in the long run-make computing devices impossible to analyze, but standard.

Re: GrapheneOS protections against data extraction from locked devices

#279
post #266

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

"my phone died yesterday, a friend just gave me his old pixel" - please don't do this. That's lying to law enforcement and they can prosecute. Just say it's your travel phone.

[dead]

Re: GrapheneOS protections against data extraction from locked devices

#280

Earlier quoted context omitted.

GrapheneOS includes an encrypted backup system covering far more data than Google cloud backups. It backs up data for apps opting out of cloud backups with allowBackup="false" since it operates in the device-to-device transfer mode. The backup system supports arbitrary sync services with a compatible API. Backups are per-profile so you can test it by restoring to a secondary user. We plan to entirely overhaul the bac…

One clarification: > It backs up data for apps opting out of cloud backups with allowBackup="false" This is untrue for older apps targeting API 30 (Android 11) and earlier. As I understand it, allowBackup is still respected for them, preventing their backup even in D2D mode. https://github.com/GrapheneOS/os-issue-tracker/issues/1112#i... Those apps are slowly going extinct since the Play Store stopped accepting updat…

In general, it's a very bad sign if an app isn't targeting a recent API level. It's largely not because apps are abandoned but rather to abuse weaker privacy and security protections for older target API levels. We'll likely move the standard warning when launching an app for the first time to the install process and will make it more prominent with an actual explanation of the risks.
Post reply on HN