Hacker News new | past | comments | ask | show | jobs | submit
I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password.

On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.

[1] A US man is being prosecuted after allegedly using a GrapheneOS duress PIN to wipe his Pixel during a border searchhttps://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...

[2] A Journalist had his mobile phone seized. Did using GrapheneOS protect his data?https://www.computerweekly.com/feature/Journalist-Richard-Me...

In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.
This is why it is important to continue iterating everywhere that device security is important for everyone. iPhone has nearly the same level of protection and we also do not see it as 'criminal by default'.

Secondly, it is important to get as many people to use GrapheneOS as possible, including non-tech people. The more widespread it becomes, the harder it will become to paint this picture.

I'm not sure that I agree that iOS devices have equal protection.

The recent Darksword exploit should give everyone pause in asserting that iOS is secure:

https://www.malwarebytes.com/blog/mobile/2026/03/a-darksword...

I trust iOS with my banking and financial apps in a way that I would never trust Google, but I am under no illusion that any architecture can be completely secure.

On the Linux side, I have found SELinux maddening at times in forcing me to the syslog to enable and permit what I need the machine to do.

I have never seen anything this obstreperous in a BSD, but perhaps I have not looked with sufficient depth.

In any case, the Trust / SELinux / Enforcing status is a sizable advantage against iOS.

sounds to me like iphone isnt actually that safe otherwise it wouldnt make sense. maybe we are missing some critical information
loading story #49057570
Perhaps GrapheneOS should just be an ASOP release with implicit security features that makes it hard to notice it is anything different. If people think it is a vanilla Android install, it would give them no reason to imply criminal activity.
loading story #49060161
loading story #49058131
{"deleted":true,"id":49057891,"parent":49056256,"time":1785071672,"type":"comment"}
He’s a “surveillance expert” so the language is not at all surprising. These are the people who always bring up the appeal to emotion, associating a benign act with something unpalatable, criminal, terrorist, think of the children.

When your job depends on not understanding and all that.

I'm fairly certain the person being quoted is saying the opposite of what you've implied - i.e. he thinks it is concerning THAT GrapheneOS is automatically associated with criminality.
You’re right, I misinterpreted but now that you mention it it’s like those ambiguous figure images, irreversibly collapsed on the proper interpretation. In this case I can only assume my interpretation of “surveillance expert” is also completely off. Can’t edit, flag away.
{"deleted":true,"id":49057205,"parent":49057090,"time":1785066991,"type":"comment"}
citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.

Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to get to BFU).

I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.
loading story #49056614
loading story #49057210
loading story #49056605
What about using decoy profiles? Say before the border crossing you switch to another user. Does that expose keys or anything for other users?
loading story #49056789
The Guardian story discussed on HN: <https://news.ycombinator.com/item?id=49024436>.

(The Computer Weekly item was submitted but saw no significant discussion.)

{"deleted":true,"id":49057379,"parent":49055956,"time":1785068325,"type":"comment"}