Remix.run Logo
▲ dylan604 5 hours ago

> On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase

Why do you call out just one OS? It's a good idea for any OS.

▲rtkwe 5 hours ago | parent | next [-]

This seems specific to GrapheneOS (unique as far as I know though I'd be happy to learn otherwise) where you could set a very long first unlock passphrase and have a shorter less cumbersome fingerprint plus pin option for subsequent unlocks. I wouldn't want to have to enter a long passphrase every time I unlock but once a day isn't so bad.

▲dylan604 5 hours ago | parent | next [-]

I don't run GrapheneOS, but I have an >15 character passphrase that must be used before biometrics can be used after reboot. I haven't used a 4-digit pin since the option to not use it was available.

▲rtkwe 4 hours ago | parent [-]

The specific extra that grapheneOS adds is that you can have a required Fingerprint + PIN with a shorter easier to enter pin while also having a long first unlock passcode. Only a first unlock passcode then biometrics is not secure in the US if your device is in the AFU/biometric-only (after first unlock) state because you can be easily and legally compelled to provide a biometric unlock.

https://threecats.au/two-factor-pin-fingerprint-unlock-graph...

▲dataflow 4 hours ago | parent | prev [-]

The option was there in Cyanogenmod back during the OnePlus One days. It was such a step backwards when it was removed. You almost had to wonder if it was deliberately done at the request of some TLA to prevent users from using too strong of a password for decryption.

▲rtkwe 4 hours ago | parent [-]

I doubt it, mostly because phones were a lot easier to crack back in those days already so I doubt a TLA needed to push for it to be removed.

▲Cider9986 5 hours ago | parent | prev | next [-]

Yes, in fact on GrapheneOS it's less necessary and it's only necessary if you don't want to rely on the secure element rate limiting.

GrapheneOS allows using a passphrase with more convenience because of the fingerprint plus second factor pin (I don't think you can just have a pin as a secondary unlock). You don't need to enter the passphrase every time you unlock with this setup, only when first starting up.

The official opinion: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

▲subscribed an hour ago | parent | prev [-]

Because apart of the IOS, according to GrayKey and Cellebrite, GrapheneOS on Pixels is the only phone where it even makes sense (realistically).