Live data from Hacker News

US Government targets Cop City protester over phone operating system

theguardian.com

81–90 of 99 posts

Re: US Government targets Cop City protester over phone operating system

#81

Earlier quoted context omitted.

It's not possible to create that feature because GrapheneOS operates under the assumption that an adversary has encyclopedic knowledge of the OS. Currently your suggestion would leave forensic traces so it wouldn't achieve the goal of deniability.

I find that line of thought to be hilarious and absurd, since even simple encrypted containers on mass-market Android devices work to shield the user. The forensic trace doesn't grant access to the container.

There's no problem with preventing access on GrapheneOS. It's one of, if not the most, secure operating systems for that purpose.

You said that there are no partitions. That's wrong. There are no hidden partitions, because they would be ineffective. You can have up to 32 user profiles with different unlock methods, and within them you can have private spaces which are basically the same as user profiles.

User profiles and private spaces are great because they can allow more of your OS to remain BFU, which is more secure than AFU. They are great for security, but they provide no plausible deniability.

>The technical problem here seems to be that GrapheneOS apparently doesn't support logging in to a partitioned empty OS for scanning purposes

Initially you suggest deniable partitions. I explain that it's not possible to achieve robust deniability that way, because it would leave forensic traces.

>since even simple encrypted containers on mass-market Android devices work to shield the user.

User profiles and private spaces are encrypted, isolated containers, and they exist on Android and are enhanced by GrapheneOS.

The forensic trace doesn't grant access to the container.

That is about security, which is already fine. We aren't talking about security; we are talking about deniability. Your suggestion to add fake partitions would not be effective for deniability because it would leave forensic traces. Deniability with hidden partitions is not currently possible on the flash storage used in Pixels and all modern phones, due to wear leveling and many other critical problems inherent to flash memory [1].

[1] https://veracrypt.io/en/Wear-Leveling.html

Re: US Government targets Cop City protester over phone operating system

#82

Earlier quoted context omitted.

I find that line of thought to be hilarious and absurd, since even simple encrypted containers on mass-market Android devices work to shield the user. The forensic trace doesn't grant access to the container.

There's no problem with preventing access on GrapheneOS. It's one of, if not the most, secure operating systems for that purpose. You said that there are no partitions. That's wrong. There are no hidden partitions, because they would be ineffective. You can have up to 32 user profiles with different unlock methods, and within them you can have private spaces which are basically the same as user profiles. User profile…

Are you saying that GrapheneOS has the means to allow a user to fully encrypt applications and their files? I mean while allowing login and access to the scanner where there is nothing to see.

> Initially you suggest deniable partitions.

That's nonsense because I never suggested a goal of complete deniability. You keep insisting I did, and attempting to bury the discussion on such grounds, but I never did.

Re: US Government targets Cop City protester over phone operating system

#83

Earlier quoted context omitted.

There's no problem with preventing access on GrapheneOS. It's one of, if not the most, secure operating systems for that purpose. You said that there are no partitions. That's wrong. There are no hidden partitions, because they would be ineffective. You can have up to 32 user profiles with different unlock methods, and within them you can have private spaces which are basically the same as user profiles. User profile…

Are you saying that GrapheneOS has the means to allow a user to fully encrypt applications and their files? I mean while allowing login and access to the scanner where there is nothing to see. > Initially you suggest deniable partitions. That's nonsense because I never suggested a goal of complete deniability. You keep insisting I did, and attempting to bury the discussion on such grounds, but I never did.

>Are you saying that GrapheneOS has the means to allow a user to fully encrypt applications and their files? I mean while allowing login and access to the scanner where there is nothing to see.

No I did not mean that. There's means to fully encrypt applications and files, like on any modern smartphone. There's also user profiles and private spaces which allow you to separate your data and encrypt them differently. Notice "private spaces" and user profiles. There's no "deniable spaces"

There's no means to allow decryption while hiding data. The only deniability feature I'm aware of is the duress password.

>"Initially you suggest deniable partitions."

>That's nonsense because I never suggested a goal of complete deniability.

>"The technical problem here seems to be that GrapheneOS apparently doesn't support logging in to a partitioned empty OS for scanning purposes"

This is what a form of plausible deniability would look like. GrapheneOS isn't going to implement a non-robust plausible deniability feature.

>You keep insisting I [suggested a goal of complete deniability], and attempting to bury the discussion on such grounds

I never insisted that you suggested a goal of effective deniability. I only explained that GrapheneOS isn't going to implement a non-robust implementation of that feature, which is the only implementation that is technically possible right now.

The reason I'm emphasising an effective plausible deniability solution is because that's the only solution that would actually help anybody. It's also the only solution that would ever be implemented. A non-robust solution would give people a false sense of security and would therefore help attackers.

Honeypot operating systems like Anøm are the ones that hide the OS within a calculator. GrapheneOS is not gonna do something stupid like that.

I'm just informing you of the real landscape of the feature you want. I thought it was a nice thing to do.

Re: US Government targets Cop City protester over phone operating system

#84

Earlier quoted context omitted.

Indeed. Hopefully the next administration will hold current officials accountable for such abuses of power.

Yeah, and then they’ll give everyone a pony

It’s up to the people. If you can convince enough people this is worth voting for, you might accomplish something.

It is not always obvious how necessary it is to get involved in politics, even if it is inconvenient, as Mr. Tunick demonstrates. I’m not American and don’t live in the US, so, what I can objectively do is very close to nothing- my advice is pretty obvious and far from unique.

It seems many countries have a general low opinion of politics, as something dirty you shouldn’t engage with. We need to overcome that.

Re: US Government targets Cop City protester over phone operating system

#85

Earlier quoted context omitted.

I don’t think a judge would be impressed by this. If anything it actually makes the legal case easier: there’s a legitimate use for a wiping feature on a phone (e.g. for theft or tampering), but actively producing false information demonstrates an intent to deceive or mislead.

Deceiving a kidnapper into thinking you complied with their order to unlock your phone would be a legitimate use.

My RSA app accepts a PIN before it generates a passcode. If I enter the wrong PIN, it’ll generate a wrong passcode.

Do, I guess the cops will continue to beat me until I produce a valid passcode.

Re: US Government targets Cop City protester over phone operating system

#86
post #35
post #26

Earlier quoted context omitted.

Better to die on ones feet than live on ones knees.

Some of us are on visa and have our online presence routinely scanned these days. Asymmetric vuln. If that's not you, why are you upset when it is acknowledged?

Also, a lot of us live outside the US and have no protected rights whatsoever when on US soil, at least according to the current regime.

So, I ask again: please, my American friends, fix the country. It’s a very nice one, I like it, and I miss visiting you. Your fellow contrypeople deserve better, even if this is what they vote for. I would love to be able to help, but I really can’t.

Re: US Government targets Cop City protester over phone operating system

#87
post #85

Earlier quoted context omitted.

Deceiving a kidnapper into thinking you complied with their order to unlock your phone would be a legitimate use.

My RSA app accepts a PIN before it generates a passcode. If I enter the wrong PIN, it’ll generate a wrong passcode. Do, I guess the cops will continue to beat me until I produce a valid passcode.

This feels like a rhetorical question but I'm not entirely sure. What do you mean?

Re: US Government targets Cop City protester over phone operating system

#88
post #85

Earlier quoted context omitted.

My RSA app accepts a PIN before it generates a passcode. If I enter the wrong PIN, it’ll generate a wrong passcode. Do, I guess the cops will continue to beat me until I produce a valid passcode.

This feels like a rhetorical question but I'm not entirely sure. What do you mean?

It was just an observation of a clever feature of my security token, as well as one on how futile it is if whoever wants a real passcode really wants it.

Re: US Government targets Cop City protester over phone operating system

#89
post #88

Earlier quoted context omitted.

This feels like a rhetorical question but I'm not entirely sure. What do you mean?

It was just an observation of a clever feature of my security token, as well as one on how futile it is if whoever wants a real passcode really wants it.

Oh ok, I misunderstood! Ledger wallet has a similar feature where you can assign a decoy wallet to a pin code.

Re: US Government targets Cop City protester over phone operating system

#90
post #24

This is a technical problem. Instead of wiping and rebooting, it should wipe while showing a lame spreadsheet application, or possibly a grocery list.

> This is a technical problem.

Government overreach cannot be solved with technical solutions.

Post reply on HN