Remix.run Logo
▲ Cider9986 5 hours ago

For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.

GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.

On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.

If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.

[1] https://strongphrase.net give memorable ones which is cool.

▲iamnothere 5 hours ago | parent | next [-]

Never use a website to generate a password for something important like this. You can print out diceware passwords and roll dice.

▲throw0101c 38 minutes ago | parent | next [-]

> You can print out diceware passwords and roll dice.

Or on the CLI:

* https://packages.debian.org/search?keywords=diceware

* https://packages.debian.org/search?keywords=pwgen

▲fluidcruft 3 hours ago | parent | prev [-]

You can just take a picture of a pile of dice, a pile of rice, or a tree, patch of grass, etc, and compute a secure hash/whatever and base six it to get the rolls.

▲Brybry 2 hours ago | parent | next [-]

Are you saying to take a hash of a picture and convert that to base 6 for your dice rolls to plug into a word list for creating a passphrase?

Is that actually better (in practice, not in terms of entropy) than /dev/urandom? I have a lot less trust in my ability to successfully scrub a picture from my phone that deterministically created my passphrase.

▲lisper 2 hours ago | parent | next [-]

> Is that actually better (in practice, not in terms of entropy) than /dev/urandom?

It offers protection in the event that your /dev/urandom is compromised. Otherwise no.

(Of course, if your /dev/urandom is compromised then whatever process you use to compute a hash of a photo is likely compromised as well.)

▲Matumio 2 hours ago | parent | prev [-]

If you're concerned about that, you can concat your JPEG with a few bytes from /dev/random and you'll get the security of whichever is stronger. In practice none of this will be your weakest link.

▲theendisney 2 hours ago | parent | prev | next [-]

If you have a computer do something you cant know if it really did what you wanted.

▲cj 2 hours ago | parent | prev [-]

I actually have a lava lamp next to my desk for this reason. Snap a photo, compute a hash!

▲theendisney 2 hours ago | parent [-]

Count the bubbels with your fingers while you count from 0 to 9. Every x fingers you write down the number.

Extra points if you hold you face really close and count in a dead language. You can also make ordered hand gestures in stead of counting on your fingers. Be a wizard about it!

▲cheschire an hour ago | parent [-]

Yer a cryptographer, Harry!

▲fluidcruft 3 hours ago | parent | prev | next [-]

Why not automatically power down if any unknown USB device is attached?

▲eli 3 hours ago | parent [-]

So like you connect it to your computer for the first time and it shuts off?

▲sellmesoap 2 hours ago | parent | next [-]

Could request unlock and reboot if no valid pass is accepted within n minutes.

▲83 2 hours ago | parent | prev | next [-]

that doesn't seem unreasonable. You only have one first time. Maybe two if you upgrade your computer more often than your phone.

▲isoprophlex 2 hours ago | parent | prev | next [-]

Better wire it up to a thermite charge just to be sure. Untrusted USB device? Hope you enjoy 1400 degree molten iron

▲usern20260720 an hour ago | parent | prev | next [-]

1. disable shutting down. 2. connect device and fingerprint it. 3. enable shutting down

▲olyjohn 2 hours ago | parent | prev | next [-]

Yeah... that could be an option you configure.

▲nkrisc 2 hours ago | parent | prev [-]

Or it’s not enabled by default.

▲burningChrome an hour ago | parent | prev | next [-]

>> then a fingerprint with a second factor pin as the secondary unlock

Unless you have a 4 or 4XL which are pretty popular with graphene os users. The weird thing is the 4 and 4XL are the only models without fingerprint because Google was pushing its #D Face Unlock System at the time.

The funny part is Graphene by default now disables face unlock on newer Pixel models.

▲dylan604 5 hours ago | parent | prev | next [-]

> On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase

Why do you call out just one OS? It's a good idea for any OS.

▲rtkwe 5 hours ago | parent | next [-]

This seems specific to GrapheneOS (unique as far as I know though I'd be happy to learn otherwise) where you could set a very long first unlock passphrase and have a shorter less cumbersome fingerprint plus pin option for subsequent unlocks. I wouldn't want to have to enter a long passphrase every time I unlock but once a day isn't so bad.

▲dylan604 5 hours ago | parent | next [-]

I don't run GrapheneOS, but I have an >15 character passphrase that must be used before biometrics can be used after reboot. I haven't used a 4-digit pin since the option to not use it was available.

▲rtkwe 4 hours ago | parent [-]

The specific extra that grapheneOS adds is that you can have a required Fingerprint + PIN with a shorter easier to enter pin while also having a long first unlock passcode. Only a first unlock passcode then biometrics is not secure in the US if your device is in the AFU/biometric-only (after first unlock) state because you can be easily and legally compelled to provide a biometric unlock.

https://threecats.au/two-factor-pin-fingerprint-unlock-graph...

▲dataflow 4 hours ago | parent | prev [-]

The option was there in Cyanogenmod back during the OnePlus One days. It was such a step backwards when it was removed. You almost had to wonder if it was deliberately done at the request of some TLA to prevent users from using too strong of a password for decryption.

▲rtkwe 4 hours ago | parent [-]

I doubt it, mostly because phones were a lot easier to crack back in those days already so I doubt a TLA needed to push for it to be removed.

▲Cider9986 5 hours ago | parent | prev | next [-]

Yes, in fact on GrapheneOS it's less necessary and it's only necessary if you don't want to rely on the secure element rate limiting.

GrapheneOS allows using a passphrase with more convenience because of the fingerprint plus second factor pin (I don't think you can just have a pin as a secondary unlock). You don't need to enter the passphrase every time you unlock with this setup, only when first starting up.

The official opinion: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

▲subscribed an hour ago | parent | prev [-]

Because apart of the IOS, according to GrayKey and Cellebrite, GrapheneOS on Pixels is the only phone where it even makes sense (realistically).

▲23ahGa17 5 hours ago | parent | prev [-]

People believed the reboot feature last time GrapheneOS was mentioned. It is of course nonsense.

Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.

▲Cider9986 5 hours ago | parent | next [-]

> Shut down the phone in areas with a high snatch risk.

Yes this is of course safer. What evidence do you have that it doesn't work on GrapheneOS, though?

https://www.computerweekly.com/feature/Journalist-Richard-Me...

▲1298436 5 hours ago | parent [-]

Medhurst has no evidence that it worked either. He hasn't tweeted since August 24th, I hope he is well and at liberty.

▲markus_zhang 5 hours ago | parent | prev | next [-]

To add an extra layer of safety. Bring a secondary phone when travelling by airplanes, especially to other countries. You should also use it frequently, maybe with some side apps to make it look like it's your daily phone.

▲ryandrake 4 hours ago | parent [-]

Or, just don't bring a phone if you're particularly vulnerable. What are they going to do? Deny you entry because you don't carry a phone? If we're really at that point, where merely not having some item is suspicious, we're in deep shit.

▲altruios 4 hours ago | parent | next [-]

I wouldn't want to be the one to test this. That's an indication of how deep we dug ourselves in.

▲midas89 3 hours ago | parent | prev [-]

if you don't know yet, we are in deep

▲3128128 an hour ago | parent | prev | next [-]

GrapheneOS is critical infrastructure. Questioning it is not like criticizing Neovim. People can get detained, killed and more.

Perhaps the reflexive genius downvoters can explain what happened to Richard Medhurst? After his phone was snatched and the authorities pretended not to be able to decrypt it, he went on a GrapheneOS promotion spree on X and wanted to write a book about computer security.

Now he has disappeared for nearly 6 weeks. How many more people do you want to get in trouble with your false promises?

▲stefan_ 5 hours ago | parent | prev [-]

The internet exists and can transfer your data with no customs and borders, so if you are at risk of being snatched, the correct choice is to not carry a phone (or laptop, or..) at all.

▲Someone 4 hours ago | parent | next [-]

https://en.wikipedia.org/wiki/Great_Firewall:

“The Great Firewall operates by checking transmission control protocol (TCP) packets for keywords or sensitive words. If the keywords or sensitive words appear in the TCP packets, access will be closed. If one link is closed, more links from the same machine will be blocked by the Great Firewall. The effect includes: limiting access to foreign information sources, blocking popular foreign websites and mobile apps, and requiring foreign companies to adapt to domestic regulations. Due to the Great Firewall, China has one of the lowest cross-border internet traffic rates in the world. Usage of foreign apps in China is minuscule; Asia Society estimated in 2026 that foreign apps blocked by the Great Firewall have extremely low traffic, particularly compared to domestic apps; the top five domestic apps saw traffic that was 1,000 times more than the top five foreign apps.”

▲oasisaimlessly 4 hours ago | parent [-]

The Great Firewall doesn't restrict SSH, so you can functionally ignore it (assuming using e.g. `ssh -D` is second-nature to you).

▲wat10000 an hour ago | parent [-]

Last time I tried it (which was quite a while ago, but I'd be surprised if they became less restrictive) ssh was fine for interactive use, but they did some sort of traffic analysis to kill connections that got used for tunneling other traffic like that.

When I was there last year, it took some doing to get a VPN working. Mullvad was pretty good but it would take a few tries to find an endpoint I could connect to. The simplest escape hatch is to have a cellular connection from another country, but that's either expensive or slow.

▲alkh-qrt 4 hours ago | parent | prev [-]

If you live in the UK and travel to the US and are afraid of state actors, leaving your hardware at home seems like a bad idea, too.

▲gambiting 4 hours ago | parent [-]

Despite all the nonsense that's posted about UK on the internet, British agencies do require a warrant to enter your home. TSA on the other hand does not require a court order to confiscate and mirror your device before giving it back to you.

Edit: Just to be perfectly clear - Border Force in the UK can do the exact same thing to you once you return, British citizen or not. Leaving your device at home is still the safest choice.

▲Cider9986 4 hours ago | parent [-]

I believe it's CBP that does this, not TSA. Therefore Americans don't have to worry about it during domestic flights.

> Despite all the nonsense that's posted about UK on the internet

How is it nonsense? I'm not debating the warrant thing, but it's very reasonable to assume the UK has terrible protections for these sorts of things.

https://en.wikipedia.org/wiki/Key_disclosure_law#:~:text=Uni...

https://eylenburg.github.io/countries.htm

▲gambiting 3 hours ago | parent [-]

I mean in a broad sense if you read any news about the UK it might looks like a dystopian surveillance state where you get arrested for criticising the king(I kid you not - I've had multiple American coworkers ask me if this is true).

And yes, UK has some awful laws around this. Yes it has put people in jail just for planning a protest before. Yes you can go to jail for not disclosing your passwords. But what you read on the internet is almost laughably out of proportion - no, you won't get arrested for posting a meme about the king.

▲nostrademons 2 hours ago | parent | next [-]

FWIW the same applies to flying in the U.S. as long as you're not a person that the government cares about. I haven't had any issues with either TSA or CBP since 2011 (when, apparently, being multiracial with facial hair made me look Middle-Eastern and looking Middle-Eastern is a cardinal sin at U.S. ports of entry). Neither has anyone I've observed at the airport, and that's thousands of people per flight, and I fly about 3-4 times per year. There's plenty of stories on the Internet, and I don't doubt the stories are true, but the Internet can easily make a 1-in-a-million occurrence happen every day (indeed, given the sheer numbers, a 1 in a million occurrence does happen every day, it's just that it's unlikely to happen to you).

▲subscribed an hour ago | parent | prev | next [-]

Yeah, it's true, you should go back to your coworkers and straighten it up.

6 people got arrested for trying to say "Not my king!" BEFORE his coronation: https://londondaily.com/not-my-king-anti-monarchy-protesters...

Before they had a chance of protest. After months of discussing the planned protest in details and getting a green light from the Met Police: https://www.bbc.co.uk/news/uk-65542558

It's not like Republicans in the UK are a violent group, unlike far right coddled by the same Met police.

52 people were arrested DURING the coronation, for example for holding a placard "not my king": https://londondaily.com/over-52-anti-monarchy-protestors-arr...

Police arrested despite KNOWING it's baseless and frankly illegal: https://novaramedia.com/2025/03/11/police-officer-who-arrest...

Tell me some more how it isn't arresting for criticising the king. Oh, well, technically he wasn't a king yet.... but that's even worse to be fair.

▲dmitrygr 3 hours ago | parent | prev [-]

> news about the UK it might looks like a dystopian surveillance state where you get arrested for criticising

Might it "seem" that way because it is that way?

https://www.forbes.com/sites/steveforbes/2025/09/09/people-a...

https://www.telegraph.co.uk/news/2026/08/22/britain-has-beco...

https://freespeechunion.org/news/more-than-62-000-people-hav...

Oh, and your government itself openly states it on record, too: https://hansard.parliament.uk/lords/2025-07-17/debates/F807C...

▲gambiting 3 hours ago | parent [-]

How many of those people got arrested for criticising the king?

Not that this is some kind of great bar to clear, but if you're going to argue with what I said, argue with what I actually wrote.

▲dmitrygr 3 hours ago | parent [-]

Ok then. Soviet Union had free speech too. Nobody got arrested for criticizing Reagan or Churchill.

Clearly the point is clear. Why nitpick pointlessly?

▲gambiting 2 hours ago | parent [-]

You've missed my point entirely, by a country mile.

Someone above asked me how it was nonsense. I responded that people parotting the point about getting arrested for criticising the king is nonsense - like for instance, my American coworkers asking if that's true, because they read it somewhere on the internet. That is nonsense.

If you want to argue with this point please do, but also please observe the rest of my comment and especially the parts that I haven't actually said.

▲subscribed an hour ago | parent | next [-]

Let me repeat reports about these arrests here as well, for your convenience.

6 people got arrested for trying to say "Not my king!" BEFORE his coronation: https://londondaily.com/not-my-king-anti-monarchy-protesters...

Before they had a chance of protest. After months of discussing the planned protest in details and getting a green light from the Met Police: https://www.bbc.co.uk/news/uk-65542558

52 people were arrested DURING the coronation, for example for holding a placard "not my king": https://londondaily.com/over-52-anti-monarchy-protestors-arr...

Police arrested despite KNOWING it's the member of public doesn't commit any offence: https://novaramedia.com/2025/03/11/police-officer-who-arrest...

I'm afraid you unwittingly misled your coworkers.

▲Dylan16807 an hour ago | parent | next [-]

They already said you can get in trouble for [planning] protesting. They said you won't get in trouble for online criticism. Your links about protests aren't proving anything.

▲subscribed 37 minutes ago | parent [-]

It's not in the comment I'm responding to,

>> Someone above asked me how it was nonsense. I responded that people parotting the point about getting arrested for criticising the king is nonsense

Protesting against the king is criticising the king IMO. I didn't see his quantifier, since I would agree that online critique of the king in particular is not yet penalised.

Not surprising you're implying bad faith though, if we're splitting the hair this thin.

(and this specific planning of the protest was so heavy handed, because it belong to one of the two naughty protests, environmental. The second naughty one is protesting against the genocide. The rest is okay)

▲gambiting an hour ago | parent | prev [-]

I'm aware you are still going to twist what I said to prove your point, but I really don't fancy repeating the exact same point for the third time just so you can say something unrelated.

▲2ahg7 38 minutes ago | parent | prev [-]

Yes, and no one mentioned parroting the king in this thread. Journalists under known observation from the state, which the UK does arrest from time to time, were mentioned however.

You can use other European countries like The Netherlands, which is a lawless police state with a liberal cover, as well.