Remix.run Logo
rzk 3 hours ago

I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password.

On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.

[1] A US man is being prosecuted after allegedly using a GrapheneOS duress PIN to wipe his Pixel during a border searchhttps://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...

[2] A Journalist had his mobile phone seized. Did using GrapheneOS protect his data?https://www.computerweekly.com/feature/Journalist-Richard-Me...

Tanoc 2 hours ago | parent | next [-]

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.

microtonal 2 hours ago | parent | next [-]

This is why it is important to continue iterating everywhere that device security is important for everyone. iPhone has nearly the same level of protection and we also do not see it as 'criminal by default'.

Secondly, it is important to get as many people to use GrapheneOS as possible, including non-tech people. The more widespread it becomes, the harder it will become to paint this picture.

close04 15 minutes ago | parent | prev [-]

He’s a “surveillance expert” so the language is not at all surprising. These are the people who always bring up the appeal to emotion, associating a benign act with something unpalatable, criminal, terrorist, think of the children.

When your job depends on not understanding and all that.

microtonal 3 hours ago | parent | prev [-]

citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.

Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to get to BFU).

msh 2 hours ago | parent | next [-]

I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.

dugite-code an hour ago | parent | next [-]

Probably because everything seems to be an "app" these days. Even when it has no business being one.

inigyou 42 minutes ago | parent [-]

Exactly. Everything must be switched to Service as a Software Substitute. It's for your own safety, you see.

choo-t an hour ago | parent | prev [-]

Because you may need the data in the data during/after your travel and lack clean way to access safely, securely and anonymously remotely.

podocarp an hour ago | parent | prev [-]

What about using decoy profiles? Say before the border crossing you switch to another user. Does that expose keys or anything for other users?

0-_-0 an hour ago | parent [-]

You would need to hide the existence of the original profile while in the decoy profile for this to work, which GrapheneOS considers too complex to implement