Remix.run Logo
GrapheneOS protections against data extraction from locked devices(discuss.grapheneos.org)
104 points by Cider9986 5 hours ago | 39 comments
rzk 3 hours ago | parent | next [-]

I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password.

On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.

[1] A US man is being prosecuted after allegedly using a GrapheneOS duress PIN to wipe his Pixel during a border searchhttps://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...

[2] A Journalist had his mobile phone seized. Did using GrapheneOS protect his data?https://www.computerweekly.com/feature/Journalist-Richard-Me...

microtonal 2 hours ago | parent | next [-]

citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.

Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to get to BFU).

podocarp 18 minutes ago | parent | next [-]

What about using decoy profiles? Say before the border crossing you switch to another user. Does that expose keys or anything for other users?

0-_-0 13 minutes ago | parent [-]

You would need to hide the existence of the original profile while in the decoy profile for this to work, which GrapheneOS considers too complex to implement

msh an hour ago | parent | prev [-]

I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.

choo-t 42 minutes ago | parent | next [-]

Because you may need the data in the data during/after your travel and lack clean way to access safely, securely and anonymously remotely.

dugite-code 40 minutes ago | parent | prev [-]

Probably because everything seems to be an "app" these days. Even when it has no business being one.

Tanoc 2 hours ago | parent | prev [-]

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.

microtonal 2 hours ago | parent [-]

This is why it is important to continue iterating everywhere that device security is important for everyone. iPhone has nearly the same level of protection and we also do not see it as 'criminal by default'.

Secondly, it is important to get as many people to use GrapheneOS as possible, including non-tech people. The more widespread it becomes, the harder it will become to paint this picture.

prmoustache 2 hours ago | parent | prev | next [-]

What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf of my plane tickets, take the plane and cross the border with a smartphone with very little but real personal data they already know and be able to provide my PIN/password to law enforcement if they ask for it, abiding with law if such a law exist (which is the case in my home country), than using a duress and risk prosecution.

Sure that doesn't protect your data from any other attack vector but it allows you to travel with less risk of getting detained by law enforcement of a country you are visiting. You get asked your password, you can give it, and they see a phone that is used like a dumbphone. If you get questioned for that a simple "my phone died yesterday, a friend just gave me his old pixel". If you need more stuff/information during your travel you would basically only need to remember the passphrase to access a password manager or a remote ssh server but you can restore only the stuff you need when travelling and and wipe again at any moment.

Having said that maybe it is better to set this up some way but not have it builtin so that law enforcement doesn't expect that any grapheneos user would have his data on an sftp server somewhere by default. Otherwise we are back to point 0 where they would ask to connect to it and restore to a phone they own. Oh and have a dummy google account you only used to purchase a couple of silly stuff on amazon, aliexpress and shein and random subscription of various "non risky subjects" on youtube. The gmail address would quickly be filled with enough spam to look genuine.

I am travelling abroad in 3 weeks for a month and I am seriously considering wiping up my grapheneOS phone before flying. I am wary that I could be targeted at a border just for having a google pixel with grapheneOS. Or maybe I should just leave my main phone at home and only travel with a new empty 150€ phone with only my main family emergency contacts. I don't remember ever being asked to show my smartphone at a border but you never know when it will happen. Thanksfully until you reboot it there is nothing that shows from the lockscreen that it is not running the regular google pixel android.

microtonal 2 hours ago | parent | next [-]

A replacement for SeedVault is planned:

https://grapheneos.org/features#encrypted-backups

https://github.com/GrapheneOS/os-issue-tracker/issues/4687#i...

Voklen 2 hours ago | parent | next [-]

> the project has been taken over by another group of people not sharing our goals or approach

> Seedvault which was originally written for use in GrapheneOS by a GrapheneOS user is a consequence of the 2018 takeover attempt on the project, which the people currently in defacto control of Seedvault were heavily involved in.

Seedvault is currently maintained by the CalyxOS team but I've never heard about this stuff. Does anybody know what happened?

flexagoon 2 hours ago | parent [-]

There has been a lot of conflict between Calyx and GrapheneOS a while ago.

prmoustache an hour ago | parent | prev [-]

Neat, I didn't realize it was still included. I thought it had been abandonned.

So basically one needs a webdav server somewhere or an usb flash drive.

Helmut10001 an hour ago | parent [-]

I use local seedvault backup and then sync via round sync daily trigger to my Nextcloud WebDav Server (native seedvault was not able to use this, for some reason).

cromka an hour ago | parent | prev | next [-]

I think more useful would be to be able to boot into another data partition with a different password, which, in turn, would hide the other "daily" partition. I believe LUKS is capable of that. The storage dump looks like a random set of data and only a valid password can find and decrypt a matching hidden partition.

Ideally this should also work on lock screen, e.g. if you type in a non-standard PIN, it would boot from the "dummy" partition in the background, with a slight delay perhaps.

This way you don't have backup anything (I mean you should, but for normal purposes) and have a plausible deniability whenever you get randomly inspected, not just at border crossings that you anticipate.

hahn-kev 2 hours ago | parent | prev [-]

Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.

prmoustache 2 hours ago | parent | next [-]

A lot of people are still using their smartphone pretty much as a dumbphone with a web browser.

skitsofrandom an hour ago | parent [-]

Yeah but if you're a normal guy strolling through every time with a phone that has nothing- no pictures, no signed in email, no history of messages, 4 contacts. That's abnormal, no way of spinning it as "but I just don't use my phone much" will make that seem normal. The average person has their phone glued to their body 24/7 now. Implying that you don't is abnormal.

hamper653 an hour ago | parent [-]

"I only ever cross borders with a blank phone because I don’t want you invading my privacy" is a perfectly valid answer. You can also add that it is your employer’s policy and/or your government official recommendation.

Terr_ 43 minutes ago | parent [-]

You can also point out that other countries want to search phones too.

"I have to do this because of country X, you know that they're like, amirite?"

XorNot an hour ago | parent | prev | next [-]

Sure but there'd be nothing there.

If the regime is going to just start taking people then nothing will stop that, but the goal is to stop the usefulness of this sort of thing as an intimidation measure - or at least drag it to the forefront and overthrow the regime.

izacus an hour ago | parent | prev [-]

The easiest way to avoid suspicion is to have a phone filled with cat and family pictures, dumb apps and games.

You don't avoid scrutiny by being wierd and hiding things, but by hiding in plain sight by being ultra boring.

muyuu 32 minutes ago | parent | prev | next [-]

There was some comment here somewhere arguing that 16 characters for a password is too little, but that he used the pattern lock. Looks like it was deleted.

Anyway. The pattern lock in Android provides Log2(389112) =~ 18.57 bits of entropy. This is less than 3 random characters, or 4 lowercase letters, or a decimal PIN digit password of 6 characters.

Granted, you could use mnemonics for long passwords, but how convenient is to input those long passwords?

I wonder why don't they just allow for longer passwords and just use a hash digest when it's too long, rather than just disallowing people from using strong passwords that they will remember. This pushes people to reuse passwords, send them to themselves, and other bad practices.

londons_explore 27 minutes ago | parent | prev | next [-]

It's fairly easy to open up a phone and probe inner circuitry.

I suspect that'll be the next step for malicious actors. I doubt very much the phone is fully resistant to having malicious data injected onto various busses.

robotswantdata 3 hours ago | parent | prev | next [-]

Relevant xkcd https://xkcd.com/538/

ris 2 hours ago | parent | next [-]

I hate this meme.

The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

moffkalast 2 hours ago | parent [-]

You end up getting hit by a wrench though, that doesn't sound like it ends well for you.

XorNot an hour ago | parent [-]

Liberty is given up in inches, not miles.

The offenses of a regime at its apex would've led to it being stopped had they started out that way, but they didn't.

What you've hit on is the basic problem of treating privacy as a means to an end though: no level of it protects you from fascism, but it is a means by which fascism can be opposed - in many cases at personal cost to yourself.

In theory I have no secrets, and the contents of my phone or life if public would be of no consequence to me. In practice, when the regime starts flustering itself that I have no secrets for them to reveal the hopefully people will oppose it - or I get a decent warning that it's time to bail.

bigyabai 3 hours ago | parent | prev [-]

Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr...

  According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone.
It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm surprised they didn't back up the device first.
prmoustache 2 hours ago | parent | next [-]

From what I understand he was not formally arrested at the time, just interrogated at the border. I am not familiar with US laws but from what I understand the device was not (yet?) considered evidence in an investigation. I imagine backing up might not be as easy an option without tearing down the device as the memory chip is no the device mainboard, so not something you can necessarily do on the side of the road or at a border without a formal warrant/investigation.

jcul 15 minutes ago | parent | prev | next [-]

I'm not sure it would have been that easy for them to back it up.

Depending on his settings.

You can disable the usb port entirely if you like, so that it is only possible to charge the device by switching it off. Or enable charging only when unlocked etc.

Or if his device had rebooted I don't think it would be possible to extract anything.

cryo32 2 hours ago | parent | prev | next [-]

My trick there is not travelling to the US.

I carry a burner phone when travelling most of the time anyway. It has access to email only, 99% of which is in offline folders anyway.

riedel 2 hours ago | parent | prev | next [-]

This is really an interesting case. Hope to see a ruling here. The edge cases are really interesting as well, like the fake pin on the back of the phone. I also wonder generally about the 'destruction' of data Wouldn't the government need to prove that there is no backup, because just making it more difficult (like hiding) would probably not call for the paragraph. Unfortunately for the rest of us the defence is based on more proven grounds. I guess only plausible deniability is helpful: I e.g. would love to see my trusted android space being empty/recreated on false password.

Terr_ 38 minutes ago | parent [-]

> The edge cases are really interesting as well, like the fake pin on the back of the phone.

"Your honor, I have the real pin memorized because I use it all the time, but since I can never use the duress code, I had to keep it somewhere handy."

Or

"Pickpocketing and phone-snatching is a real problem overseas, I put it there so that criminal would wipe the phone trying to get in, denying them access to things like my bank account."

Heck, those aren't just plausible, they might be a good idea.

microtonal 2 hours ago | parent | prev | next [-]

It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm surprised they didn't back up the device first.

The duress password does not wipe the phone. It wipes the encryption keys from the secure element. The phone's storage is the backup, but it is worthless, unless law enforcement has an attack against AES that does not require a brute force attack (unlikely).

Dylan16807 an hour ago | parent [-]

Oh please. That's not a real distinction. The phone as a unit, flash plus enabling chips, is wiped in an unrecoverable way.

And the primary copy is not a backup.

imkac 2 hours ago | parent | prev [-]

Backup is useless without security chip.

2 hours ago | parent | prev [-]
[deleted]