Live data from Hacker News

US Government targets Cop City protester over phone operating system

theguardian.com

71–80 of 99 posts

Re: US Government targets Cop City protester over phone operating system

#71

Earlier quoted context omitted.

That would be a bad idea. GrapheneOS operates under the assumption that every attacker has encyclopedic knowledge of GOS at all times. This is by far not an unreasonable assumption. GrapheneOS does not add features relying on ignorance that they exist. The duress wipe feature shuts the device down to let RAM discharge, this is an important step to remove any components of decryption before they can be lifted.

What about a duress timer working as the reboot timer but it wipes if you don't unlock within the time period. Would that have any advantages for destruction of evidence or deniability?

That would not be viable because the hardware does not support it. It cannot be implemented in the OS because the OS can be turned off or exploited endlessly.

For GOS to consider it, it would likely need to be backed by the secure element.

Duress PIN is deemed acceptable to implement in the OS because it is expected that the user is the one to enter it, so it has not fallen into the hands of attackers who may bypass it. Once attackers have it, you are effectively gambling. Account for that in your threat model and do not let it get to that point.

Re: US Government targets Cop City protester over phone operating system

#72
post #50

Earlier quoted context omitted.

Note that "antifa" is now recognized as a terrorist organization by the current federal government. It will get much worse if they aren't stopped.

which they are you referring to? Antifa or the gov't?

The Trump administration.

Re: US Government targets Cop City protester over phone operating system

#73
post #65

Earlier quoted context omitted.

Easier solution: phone wipes itself if passcode is not entered every X hours

There's a problem with that too: it would often force the owner of the phone to input the code when outside a secure environment, so a simple video surveillance could obtain the code.

GrapheneOS has a feature to scramble the locations of the numbers on the passcode unlock screen to prevent this exact problem

Re: US Government targets Cop City protester over phone operating system

#74
post #65

Earlier quoted context omitted.

There's a problem with that too: it would often force the owner of the phone to input the code when outside a secure environment, so a simple video surveillance could obtain the code.

GrapheneOS has a feature to scramble the locations of the numbers on the passcode unlock screen to prevent this exact problem

That can be helpful only if surveillance cannot film the screen directly, and surveillance relies on the position of the fingers. Given modern 4k cameras it's unlikely the latter can be done but not the former.

Re: US Government targets Cop City protester over phone operating system

#76
post #24

This is a technical problem. Instead of wiping and rebooting, it should wipe while showing a lame spreadsheet application, or possibly a grocery list.

I don’t think a judge would be impressed by this. If anything it actually makes the legal case easier: there’s a legitimate use for a wiping feature on a phone (e.g. for theft or tampering), but actively producing false information demonstrates an intent to deceive or mislead.

Deceiving a kidnapper into thinking you complied with their order to unlock your phone would be a legitimate use.

Re: US Government targets Cop City protester over phone operating system

#78
post #52

Earlier quoted context omitted.

Have you considered living somewhere the Sword of Damocles does not constantly hang over your head? Most of the EU is lovely.

In America you can call politicians names. In Germany that's a criminal offense

I said _most_.

Re: US Government targets Cop City protester over phone operating system

#79

The technical problem here seems to be that GrapheneOS apparently doesn't support logging in to a partitioned empty OS for scanning purposes, also that it doesn't support such partitions at all, only one of which would be the real one.

It's not possible to create that feature because GrapheneOS operates under the assumption that an adversary has encyclopedic knowledge of the OS. Currently your suggestion would leave forensic traces so it wouldn't achieve the goal of deniability.

Re: US Government targets Cop City protester over phone operating system

#80

The technical problem here seems to be that GrapheneOS apparently doesn't support logging in to a partitioned empty OS for scanning purposes, also that it doesn't support such partitions at all, only one of which would be the real one.

It's not possible to create that feature because GrapheneOS operates under the assumption that an adversary has encyclopedic knowledge of the OS. Currently your suggestion would leave forensic traces so it wouldn't achieve the goal of deniability.

I find that line of thought to be hilarious and absurd, since even simple encrypted containers on mass-market Android devices work to shield the user. The forensic trace doesn't grant access to the container.
Post reply on HN