Live data from Hacker News

GrapheneOS and forensic extraction of data (2024)

discuss.grapheneos.org

41–50 of 208 posts

Re: GrapheneOS and forensic extraction of data (2024)

#41
post #35
post #24

Earlier quoted context omitted.

Aside from the fact that there's a subjective definition problem here (how do we decide what people "need"?), I think this an unrealistic view. By this definition, every government that has ever existed or ever will exist is a "bad" government because no government can ever tackle every single problem 100% of the time. Many problems are extremely difficult to solve (e.g. global warming), and others simply cannot be s…

> Sure, you can tax more up to a point, but eventually that tap runs dry and you're forced to reallocate existing resources. Since the 1980s, we have been consistently taxing less. If the tap is dry, it isn't because of over-taxation - it's because there's a reservoir of wealth hoarded by the relatively few. A even cursory glance at the trajectory of wealth distribution will make that clear.

> Since the 1980s, we have been consistently taxing less

Who is "we"? We're talking about governments in general ("good" vs "bad" ones), and I have no idea what jurisdiction you are referring to.

In any case, I didn't say the tap is dry. I said if you keep raising taxes it will eventually run dry. Or to put it another way, taxes are not an unlimited resource that you can keep increasing as much as you'd like. At some point you'll hit a ceiling where raising taxes any further doesn't produce additional tax revenue.

For example, as you raise income tax rates, people have less incentive to advance their careers (e.g. by chasing promotions or improving their skills), and people have more incentive to leave the jurisdiction and go somewhere with lower taxes. Up to a point, the increase in tax rates produces a net extra revenue for the government. Above a certain point, the number of people who stop paying taxes (e.g. by leaving or by working less) outweighs the gains from those who continue to pay. This is why you'll rarely see any government with excessively high top-bracket tax rates (e.g. 60 - 100%), because it results in tax losses.

Re: GrapheneOS and forensic extraction of data (2024)

#42

I really love Graphene OS but I _wish_ there was a version in which you could get a root shell and extract private data of apps you install when verified as the user. The developers are on record as saying that root blows a hole in their security model (it does!) but if there was _some_ way of doing it safely, so I can modify applications I as the user wish to, it would be my ideal OS. I know I could download and sel…

I wish this as well. I make a userdebug build myself to get adb root, which isn't difficult, but would be a lot nicer if it were officially supported.

Re: GrapheneOS and forensic extraction of data (2024)

#43
post #36

This feels like countering insinuations on the Internet with insinuations on the Internet. Cellebrite doesn't publicly publish the latest support matrix so we have no real idea what progress if any they've made against recent iPhones and iOS versions, nor any real detail on how something like Lockdown Mode influences outcomes for their software. Nor does this show anything about Pixel 9 or Pixel 10 and the newest var…

There is someone who leaks Cellebrite's support matrix to GrapheneOS dev's and it confirms that they are still unable to exploit it.

"Their documentation has explicitly listed GrapheneOS for years due to the high demand from their customers for breaking into it. It shows they were last able to exploit a GrapheneOS release with a 2022 or earlier patch level.

We have their June 2025 documentation and could obtain the newer documentation if we ask for it, but we have much bigger priorities than that right now and we would have been contacted by the main person providing it if anything relevant changed."

https://x.com/GrapheneOS/status/1965464817914831070

Re: GrapheneOS and forensic extraction of data (2024)

#44

Earlier quoted context omitted.

They've clearly explained here. I'm not sure how many people would keep asking the same question without even doing a simple web search. https://grapheneos.org/faq#future-devices

Someone clearly replied with the same link. I'm not sure how many people would keep replying the same thing without even doing a simple thread search.

They posted within a minute of each other, so likely did not see the the response and were typing theirs as the other got posted.

Re: GrapheneOS and forensic extraction of data (2024)

#45
post #36

This feels like countering insinuations on the Internet with insinuations on the Internet. Cellebrite doesn't publicly publish the latest support matrix so we have no real idea what progress if any they've made against recent iPhones and iOS versions, nor any real detail on how something like Lockdown Mode influences outcomes for their software. Nor does this show anything about Pixel 9 or Pixel 10 and the newest var…

Documents have been leaked at the beginning of this year: https://osservatorionessuno.org/blog/2025/03/a-deep-dive-int... which do include the Pixel 9. They show GrapheneOS being pretty secure in comparison to other vendors at the very least, with GrapheneOS being marked as unsupported if patched beyond 2022. They also show GrapheneOS beating the stock Google firmware.

One reason GrapheneOS fights these threads is by doing what Google doesn't want to do out of user friendliness, like disabling USB in AFU mode. Unlike Google, Samsung, or Apple in non-lockdown mode, GrapheneOS doesn't need to deal with upset users when they need to unlock their phone before hooking it up to their car/display/flash drive/3.5mm jack converter/etc.

GrapheneOS also enables security features when compiling the OS that have a performance impact but mitigate security risks. They end up with a slower phone with less battery life that's protected better against extremely uncommon attack vectors.

GrapheneOS explained how these security features would've prevented at least one targeted attack from leading to exploitation: https://grapheneos.social/@GrapheneOS/114081909020398165

We don't know the current state of Celebrite's capabilities, but the fact they struggled for at least three years last time intel leaked out does paint a good picture for GrapheneOS. I'm sure the GRU and NSA have exploits that can hack even GrapheneOS, but at least they're not the type that makes it into commercially available exploit kits as of now.

Re: GrapheneOS and forensic extraction of data (2024)

#46
post #32

I've always found it strange that GrapheneOS only runs on Google hardware. Can anyone explain this choice?

Curious if you've already read the comprehensive FAQ entry and are trying to imply something?

Kind of. I don't use grapheneOS and I'd like to, but de-googling your phone by buying a Google phone seems a bit sketchy. I don't want to take away from a privacy focused project. I'm super thankful for this option and I can't stand android or iPhone. But in the back of my mind I wonder if I'm being tricked.

Re: GrapheneOS and forensic extraction of data (2024)

#47

As long as the USB port of your phone is used, you can not stop it. This is the backdoor the governments want without having to be tethered. Vote for privacy. Vote against the police state. Vote for freedom. Libertarian rant aside. Governments fund these kinds of operations in secret so they can "effectively do their jobs". There's a ton of subcontractors working on AWS platforms that do analysis of this UFED "dump".…

> As long as the USB port of your phone is used, you can not stop it. According to TFA GrapheneOS can disable the USB port too

Which is the only defense when law enforcement takes your phone. GrapheneOS is the only ones that will let you.

Re: GrapheneOS and forensic extraction of data (2024)

#48
post #4

There is no such thing like "bad government" and "good government". I mean - it really depends on people's views, therefore we must not blissfully put our data into govt hands because "they will protect us from terrorists and child rapists". What they will do, actually, is that for sure they will abuse innocent citizens at some point of time. They will. Even if they don't, they will. Or maybe they are doing it right…

> There is no such thing like "bad government" and "good government". Of course there is, compare the government of Finland to that of North Korea. Just because there are shades of grey and human institutions are generally susceptible to corruption greed an power politics doesn't mean there aren't governments that are different not only in degree but in kind.

It is strange how folks are refusing to admit they can even _evaluate things_ in a bunch of cases. We're seeing that here, but I've also noticed it in other posts on HN: a disagreement with the position of the article is framed not as a distinct examination which comes to different conclusions, but instead commenters claim the post author was foolish in even attempting to evaluate the thing the post is about.

To some degree it feels like bits and pieces of anti-intellectualism getting into folks brains: rejecting the idea that folks can think about things at all.

Re: GrapheneOS and forensic extraction of data (2024)

#49

I really love Graphene OS but I _wish_ there was a version in which you could get a root shell and extract private data of apps you install when verified as the user. The developers are on record as saying that root blows a hole in their security model (it does!) but if there was _some_ way of doing it safely, so I can modify applications I as the user wish to, it would be my ideal OS. I know I could download and sel…

You can't have a cake and eat it. A root access is a big hole, there's no way mainline will support it. As for the possible way, you answered yourself already (custom keys and images) :)

> A root access is a big hole

How so?

On Linux, I can add an account to the sudoers list, and have the flexibility to configure the level of security appropriate for my use case. I have yet to experience any security issues (that I'm aware of). Why isn't this possible on my mobile device as well?

This absolute stance is not right. Security is not binary, but a spectrum. I should be allowed to have full control over my device without this being a security risk.

Re: GrapheneOS and forensic extraction of data (2024)

#50
post #4

There is no such thing like "bad government" and "good government". I mean - it really depends on people's views, therefore we must not blissfully put our data into govt hands because "they will protect us from terrorists and child rapists". What they will do, actually, is that for sure they will abuse innocent citizens at some point of time. They will. Even if they don't, they will. Or maybe they are doing it right…

Maybe we should have no government, because they always have some information on us which can be abused
Post reply on HN