Live data from Hacker News

GrapheneOS protections against data extraction from locked devices

discuss.grapheneos.org

91–100 of 284 posts

Re: GrapheneOS protections against data extraction from locked devices

#91
post #33

Earlier quoted context omitted.

Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.

The easiest way to avoid suspicion is to have a phone filled with cat and family pictures, dumb apps and games. You don't avoid scrutiny by being wierd and hiding things, but by hiding in plain sight by being ultra boring.

The easiest way to avoid suspicion is to have a phone filled with cat and family pictures, dumb apps and games.

Presumably they know quite a lot about you already outside your phone (yay, Palantir). I mean, the guy the recent post was about was an activist. An empty phone vs. a phone with just cat pictures and dumb games wouldn't really make a difference. They went on a fishing expedition, so anything that does not have contact information/messages of other activists or any information that they could use against the phone owner would be a win.

(F-you Palantir for reading this message and adding it to my online record.)

Re: GrapheneOS protections against data extraction from locked devices

#92
post #43

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf…

I think more useful would be to be able to boot into another data partition with a different password, which, in turn, would hide the other "daily" partition. I believe LUKS is capable of that. The storage dump looks like a random set of data and only a valid password can find and decrypt a matching hidden partition. Ideally this should also work on lock screen, e.g. if you type in a non-standard PIN, it would boot f…

>I believe LUKS is capable of that

Booting into a 30 GB partition on a 128GB phone is going to be mega suspicious, even if the remaining data is random.

Re: GrapheneOS protections against data extraction from locked devices

#93
post #21
post #4

I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password. On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where ke…

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.

[deleted]

Re: GrapheneOS protections against data extraction from locked devices

#94

Earlier quoted context omitted.

GrapheneOS seems to be consistently the hardest to exploit AFU based on various Cellubrite leaks. iPhones have better protection than all other Androids except Pixels.

I might be wrong, but I get the impression that the GrapheneOS folks generally recommend GrapheneOS > iOS > Pixel >> everything else . It might have to do with e.g. Apple having rolled out MIE at a broader scale than Google rolling out MTE on PixelOS, where AFAIK it is still largely opt-in (not 100% sure, I always wipe a Pixel immediately).

Agree. I didn't mean to say stock pixels are better than iPhones.

Re: GrapheneOS protections against data extraction from locked devices

#96
post #80

Earlier quoted context omitted.

sounds to me like iphone isnt actually that safe otherwise it wouldnt make sense. maybe we are missing some critical information

GrapheneOS seems to be consistently the hardest to exploit AFU based on various Cellubrite leaks. iPhones have better protection than all other Androids except Pixels.

[flagged]

Re: GrapheneOS protections against data extraction from locked devices

#97

Earlier quoted context omitted.

GrapheneOS seems to be consistently the hardest to exploit AFU based on various Cellubrite leaks. iPhones have better protection than all other Androids except Pixels.

I might be wrong, but I get the impression that the GrapheneOS folks generally recommend GrapheneOS > iOS > Pixel >> everything else . It might have to do with e.g. Apple having rolled out MIE at a broader scale than Google rolling out MTE on PixelOS, where AFAIK it is still largely opt-in (not 100% sure, I always wipe a Pixel immediately).

[flagged]

Re: GrapheneOS protections against data extraction from locked devices

#99

Earlier quoted context omitted.

A lot of people are still using their smartphone pretty much as a dumbphone with a web browser.

Yeah but if you're a normal guy strolling through every time with a phone that has nothing- no pictures, no signed in email, no history of messages, 4 contacts. That's abnormal, no way of spinning it as "but I just don't use my phone much" will make that seem normal. The average person has their phone glued to their body 24/7 now. Implying that you don't is abnormal.

"I got on pickpocketed on my last vacation, so now I travel with an old backup phone instead"

Re: GrapheneOS protections against data extraction from locked devices

#100
post #19

Relevant xkcd https://xkcd.com/538/

I hate this meme. The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

The point of the comic is pretty obviously to make fun of the expectations of cryptography geeks; you know, the sort of people who use 4096 bit RSA keys for the coolness factor. It is a stretch to imply it is suggesting that encryption is somehow futile.
Post reply on HN