Hacker News new | past | comments | ask | show | jobs | submit

GrapheneOS protections against data extraction from locked devices

https://discuss.grapheneos.org/d/40700-grapheneos-protections-against-data-extraction-from-locked-devices
I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password.

On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.

[1] A US man is being prosecuted after allegedly using a GrapheneOS duress PIN to wipe his Pixel during a border searchhttps://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...

[2] A Journalist had his mobile phone seized. Did using GrapheneOS protect his data?https://www.computerweekly.com/feature/Journalist-Richard-Me...

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.
loading story #49056332
loading story #49057891
He’s a “surveillance expert” so the language is not at all surprising. These are the people who always bring up the appeal to emotion, associating a benign act with something unpalatable, criminal, terrorist, think of the children.

When your job depends on not understanding and all that.

I'm fairly certain the person being quoted is saying the opposite of what you've implied - i.e. he thinks it is concerning THAT GrapheneOS is automatically associated with criminality.
You’re right, I misinterpreted but now that you mention it it’s like those ambiguous figure images, irreversibly collapsed on the proper interpretation. In this case I can only assume my interpretation of “surveillance expert” is also completely off. Can’t edit, flag away.
loading story #49057205
loading story #49061867
citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.

Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to get to BFU).

loading story #49056385
loading story #49056760
{"deleted":true,"id":49057379,"parent":49055956,"time":1785068325,"type":"comment"}
What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf of my plane tickets, take the plane and cross the border with a smartphone with very little but real personal data they already know and be able to provide my PIN/password to law enforcement if they ask for it, abiding with law if such a law exist (which is the case in my home country), than using a duress and risk prosecution.

Sure that doesn't protect your data from any other attack vector but it allows you to travel with less risk of getting detained by law enforcement of a country you are visiting. You get asked your password, you can give it, and they see a phone that is used like a dumbphone. If you get questioned for that a simple "my phone died yesterday, a friend just gave me his old pixel". If you need more stuff/information during your travel you would basically only need to remember the passphrase to access a password manager or a remote ssh server but you can restore only the stuff you need when travelling and and wipe again at any moment.

Having said that maybe it is better to set this up some way but not have it builtin so that law enforcement doesn't expect that any grapheneos user would have his data on an sftp server somewhere by default. Otherwise we are back to point 0 where they would ask to connect to it and restore to a phone they own. Oh and have a dummy google account you only used to purchase a couple of silly stuff on amazon, aliexpress and shein and random subscription of various "non risky subjects" on youtube. The gmail address would quickly be filled with enough spam to look genuine.

I am travelling abroad in 3 weeks for a month and I am seriously considering wiping up my grapheneOS phone before flying. I am wary that I could be targeted at a border just for having a google pixel with grapheneOS. Or maybe I should just leave my main phone at home and only travel with a new empty 150€ phone with only my main family emergency contacts. I don't remember ever being asked to show my smartphone at a border but you never know when it will happen. Thanksfully until you reboot it there is nothing that shows from the lockscreen that it is not running the regular google pixel android.

loading story #49059865
A replacement for SeedVault is planned:

https://grapheneos.org/features#encrypted-backups

https://github.com/GrapheneOS/os-issue-tracker/issues/4687#i...

> the project has been taken over by another group of people not sharing our goals or approach

> Seedvault which was originally written for use in GrapheneOS by a GrapheneOS user is a consequence of the 2018 takeover attempt on the project, which the people currently in defacto control of Seedvault were heavily involved in.

Seedvault is currently maintained by the CalyxOS team but I've never heard about this stuff. Does anybody know what happened?

There has been a lot of conflict between Calyx and GrapheneOS a while ago.
loading story #49057744
Neat, I didn't realize it was still included. I thought it had been abandonned.

So basically one needs a webdav server somewhere or an usb flash drive.

loading story #49057793
I use local seedvault backup and then sync via round sync daily trigger to my Nextcloud WebDav Server (native seedvault was not able to use this, for some reason).
I use Seedvault to create a backup locally on my phone, and then sync it to my backup server with Syncthing
It's been planned for years...
loading story #49057765
I think more useful would be to be able to boot into another data partition with a different password, which, in turn, would hide the other "daily" partition. I believe LUKS is capable of that. The storage dump looks like a random set of data and only a valid password can find and decrypt a matching hidden partition.

Ideally this should also work on lock screen, e.g. if you type in a non-standard PIN, it would boot from the "dummy" partition in the background, with a slight delay perhaps.

This way you don't have backup anything (I mean you should, but for normal purposes) and have a plausible deniability whenever you get randomly inspected, not just at border crossings that you anticipate.

loading story #49057812
loading story #49058421
loading story #49060863
loading story #49058126
loading story #49058689
loading story #49059809
Remind us what happened when you do cross.
Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.
A lot of people are still using their smartphone pretty much as a dumbphone with a web browser.
Yeah but if you're a normal guy strolling through every time with a phone that has nothing- no pictures, no signed in email, no history of messages, 4 contacts. That's abnormal, no way of spinning it as "but I just don't use my phone much" will make that seem normal. The average person has their phone glued to their body 24/7 now. Implying that you don't is abnormal.
"I only ever cross borders with a blank phone because I don’t want you invading my privacy" is a perfectly valid answer. You can also add that it is your employer’s policy and/or your government official recommendation.
You can also point out that other countries want to search phones too.

"I have to do this because of country X, you know that they're like, amirite?"

loading story #49058163
It's one that will get you denied entry, or detained indefinitely.
I have worked for employers that required taking a burner phone to certain countries without any accounts logged in, etc. (so mostly for calls, maps, and web browsing) and nobody has ever been detained or denied entry. Some countries know that this is just standard procedure when they are visited for business trips. Probably different for the US though.

(Not legal advise of course, just observation. Always check with the legal department of your employer, etc.)

> Probably different for the US though.

After cornering themselves into being labeled an unsafe destination (long overdue imho), the US are gonna have to learn being treated as such.

loading story #49059017
Denied entry, why not. But detained?
loading story #49059033
loading story #49058162
loading story #49057984
loading story #49058145
Even more of a reason for good and easy backup and restore.

Before travel back up the real contents and restore a dummy travel backup with random games, stock photos etc. Then restore back to real contents.

loading story #49058073
Sure but there'd be nothing there.

If the regime is going to just start taking people then nothing will stop that, but the goal is to stop the usefulness of this sort of thing as an intimidation measure - or at least drag it to the forefront and overthrow the regime.

The easiest way to avoid suspicion is to have a phone filled with cat and family pictures, dumb apps and games.

You don't avoid scrutiny by being wierd and hiding things, but by hiding in plain sight by being ultra boring.

loading story #49057810
On the other hand, if everything about you is boring, that in itself may begin to seem suspicious. "I borrowed this old phone from my stepson because my own phone got run over by a steamroller at a vintage vehicle show" is the sort of thing an actual spy or criminal would never say.
loading story #49058183
[flagged]
> So you plan to (1) actively/proactively conceal your data/evidence

I am not concealing data/evidence as it doesn't exists. I don't know of any law in any country that force you to hand out the key of your home to a remote state so that they can enter your country and do a search.

> and then (3) constantly restore from cloud backups?

Why constantly? Only and only if I need to access specific data (that may be available remotely without restore anyway). Full restore only when going back in my own country.

It's been normal operating procedure for many employees that travel to the US. You think they're all criminals?
Border officials don't have the right to search all of your data.

You are also not under any obligation to have it on your phone at all times.

loading story #49058092
[flagged]
> Correct! Furthermore, border officials have no requirements to allow you into their country either, unless you’re a citizen there,

I'd rather have them tell me to turn back and go home than being jailed there only because I don't want them to fap at the picture of my daughters.

Unfortunately, it'll most likely go something like this: https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...
Being prosecuted because your smartphone has been setup yesterday is not the same as being prosecuted because you gave a password that wipe your phone in front of law enforcement.

In the past I have had my smartphone die a couple of days before travelling and quickly buying a smartphone so I could have a mobile line in case of emergency while travelling. This is not a totally uncommon case to have a smartphone with very little data. A lot of people never setup any cloud backup and lose all their data every so many years.

Yeah, the lesson is: do not travel to countries that treat people such in a shitty way. This has always been true. Unfortunately, for many foreigners this also applies to the US nowadays.

I guess that you are out of luck if you are a US citizen and need to return to your own country.

Do the requirement to put your social account public when applying for a US Visa still applies? I guess the USA do not have that many non US visitors these days because I don't know a lot of women who would agree to that. Almost all my female friends have been experiencing stalking from jealous ex, former colleagues/clients/patients so putting their social media account public would be a complete no-go for them.

How is the tourism industry going?

There was some comment here somewhere arguing that 16 characters for a password is too little, but that he used the pattern lock. Looks like it was deleted.

Anyway. The pattern lock in Android provides Log2(389112) =~ 18.57 bits of entropy. This is less than 3 random characters, or 4 lowercase letters, or a decimal PIN digit password of 6 characters.

Granted, you could use mnemonics for long passwords, but how convenient is to input those long passwords?

I wonder why don't they just allow for longer passwords and just use a hash digest when it's too long, rather than just disallowing people from using strong passwords that they will remember. This pushes people to reuse passwords, send them to themselves, and other bad practices.

loading story #49059706
loading story #49057662
loading story #49058966
Maybe because it was mistaken. I just set my grapheneos to a 35 character password to test it and it didnt seem to have any issue.
loading story #49057242
loading story #49057159
It's really comical when you want to have same security guarantees as you get on apple devices you are a criminal. Search more: "apple devices automatically restart", "apple device full encryption", "apple lockdown mode".

edit: this was a response to another comment opps.

loading story #49060773
although it is wonderful to know that there exists a piece of hardware in the world that is not conspiring against its users, the outcome of entering a duress password should be indistinguishable to the user that grabs hold of the mobile phone. The duress password should wipe off the real user account information but present the kidnappers with a full-fledged operating system populated with real-looking content to entertain the police officers with polite meaningless e-mails saying things like

> > On Apr 11, 2015, at 5:45 PM, Jim Steyer Hey John, > > > > We know you're a true master of cuisine and we have appreciated that for > years ... > > > > But walnut sauce for the pasta? Mary, plz tell us the straight story, > was the sauce actually very tasty? > > > > > Jim

loading story #49061210
loading story #49059792
loading story #49057655
That email chain sounds exactly like the TV show Severance
Does it protect it in After First Unlock mode? I often use my device and if I lock it before LE or another bad actor catches it then it's kind of useless if it doesn't protect my data in after first unlock (locked) mode. Especially with LE agencies having tools like Cellebrite at their station for same day analysis. Most people probably won't have time to reboot their device.

Similar to how I use Veracrypt, but I leave my PC running, because I hate spending time booting up again. So LE could decrypt my stuff using RAM extraction stuff.

Does anyone know if the Motorola partnership is still on with GrapheneOS or how long until a phone is made available from them?
loading story #49057591
I always leave my phone and laptop off when going through TSA or Passport Control. I don't think in the US you an be compelled into giving up your password. They are free to confiscate the device but with it powered down good luck trying to break the password.
loading story #49058901
Relevant xkcd https://xkcd.com/538/
I hate this meme.

The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

loading story #49058144
loading story #49059026
loading story #49058015
loading story #49056254
Relevant news story: https://www.androidauthority.com/grapheneos-duress-pin-us-pr...

  According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone.
It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm surprised they didn't back up the device first.
loading story #49056041
loading story #49056274
loading story #49060780
loading story #49056218
loading story #49059824
loading story #49056262
loading story #49056780
loading story #49057093
loading story #49056007
Here's an idea: soft duress PIN that wipes a list of apps of your choice however doesn't make it obvious it's done so.

Or restores app data to a restore point of your choosing making it seem like everything is fine.

Make it untraceable you had it setup and it'll help deal with any potential legal issues.

loading story #49060716
loading story #49058848
{"deleted":true,"id":49056089,"parent":49055169,"time":1785056209,"type":"comment"}
{"deleted":true,"id":49056077,"kids":[49056228],"parent":49055169,"time":1785056111,"type":"comment"}
{"deleted":true,"id":49056228,"parent":49056077,"time":1785057808,"type":"comment"}
[flagged]
loading story #49057975
loading story #49058017
It's fairly easy to open up a phone and probe inner circuitry.

I suspect that'll be the next step for malicious actors. I doubt very much the phone is fully resistant to having malicious data injected onto various busses.

loading story #49059068
loading story #49059804
This is also relevant if you get the phone back. There could be some nasty hw modifications that could leak data out of the phone in AFU state. Hopefully people in these kinds of situations take this into account. IMO all phones and computers should be treated as unsafe to unlock after they've been seized.
loading story #49059833
loading story #49058216
loading story #49058084