Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

281–284 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#281
post #275

Earlier quoted context omitted.

> you need to get the guy across from you to not find you suspicious. What? No, who cares about that? Let him find you suspicious, what matters is that he doesn’t access your data. And it is not suspicious to cross borders (esp. US borders) with burner phones. As others have said, it is standard practice.

Clearly someone who probably never been on the receiving end of those kind of situations turned bad.

[dead]

Re: GrapheneOS protections against data extraction from locked devices

#282

Earlier quoted context omitted.

Good luck making it work again remotely after a long power outage.

Not sure what do you mean? If that is a concern, there are solutions for this. Like UPSes and backup cellular connections.

That may not even be a power outage, a simple bug or anything that may hang or reset the smartphone and the scrcpy session can't be started again.

Unless you have a trustable person who has keys to your home and is available to power on and make sure a kvm setup is on you can't self host and just assume that what is running at home will be up all the time when you are abroad compared to a managed datacenter with redundancy, remote access and personel available.

Re: GrapheneOS protections against data extraction from locked devices

#283
post #3

Earlier quoted context omitted.

Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr... According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone. It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm sur…

From what I understand he was not formally arrested at the time, just interrogated at the border. I am not familiar with US laws but from what I understand the device was not (yet?) considered evidence in an investigation. I imagine backing up might not be as easy an option without tearing down the device as the memory chip is no the device mainboard, so not something you can necessarily do on the side of the road or…

>I imagine backing up might not be as easy an option without tearing down the device as the memory chip is no the device mainboard, so not something you can necessarily do on the side of the road or at a border

Oh you sweet innocent child. US Customs and Boarder agents, every federal agency, and most local law enforcement agencies all have Cellebrite, Oxygen, or an equivalent tool which can perform a full device extraction on basically any phone expect for a pixel running Graphene OS with the current updates and a new model iPhone also running it's current updates. Every other phone on the market in the US can be cracked and extracted by cellebrite simply by plugging in a usb-c cable. Even a stock pixel, Samsung, iPhone, etc. Typically they would absolutely need a warrant to perform a device extraction but the supreme court has ruled that at boarder crossings, a person is not actually in the US until allowed entry by an agent and by not being in the US, US law and constitutional rights dont apply. If you are a US citizen, they can not deny you entry but that can keep your phone and attempt to extract it at a later time when exploits may be uncovered to break the encryption or bypass it completely

Re: GrapheneOS protections against data extraction from locked devices

#284
post #262

Earlier quoted context omitted.

In fairness, an adversarial challenge can be useful in pointing out weaknesses (and possible mitigations) to a particular technical approach. It's not clear that all of those objections are substantive or insurmountable. "The USB port may have died" might be one possible response. (Not technically a lie, and hence defensible in court.) Or just silence. Alternatively, some way of directing such probes to the decoy par…

>"The USB port may have died" might be one possible response. (Not technically a lie, and hence defensible in court.) Or just silence. That's about as convincing as "wow this phone just decided to experience catastrophic hardware failure after entering your totally-not-duress pin". Not to mention there's wireless adb. >Alternatively, some way of directing such probes to the decoy partition and presenting a sufficient…

You seem to be assuming a perfect adversary who is infinitely technically capable? That seems... unlikely?

And why would wireless ADB be enabled? Disable it.

And why would any of this get you sent to prison? If my phone not having wireless ADB or a working USB port, or some set of partitions has become a thing I can go to prison for, then this is totalitarianism and we have already lost by existing?

Once again, you don't seem very interested in opposing this kind of tyranny?

Post reply on HN