← Back to context

Comment by microtonal

2 days ago

citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.

Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to get to BFU).

I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.

  • Probably because everything seems to be an "app" these days. Even when it has no business being one.

    • Exactly. Everything must be switched to Service as a Software Substitute. It's for your own safety, you see.

  • So delete messengers, email apps and other comms?

    Delete the contact book? Clear calendars?

    Where exactly should one stop?

  • Because you may need the data in the data during/after your travel and lack clean way to access safely, securely and anonymously remotely.

    • No one is stopped from backing up important data. It is, in fact, kind of boneheaded to keep all "valuables" on a single device. I don't understand the scenario of not trusting a device to safely access the Internet or the telephony grid while also insisting that they need a PHONE to keep all their stuff on where they're going, and at the same time somehow trust that both themselves and their possessions are perfectly safe from seizure and extortion in the very same location.

      2 replies →

    • This is where we need "cloud phones as a service" / "selfhosting a cellphone at home with some kind of remote access system".

      Not even kidding here, it's time to bring out thin client computing to cellphones. Let the spicy stuff sit somewhere else. I could bootstrap a Tailscale or Netbird signin remotely, install the access client, and remote back into the 'normal phone'.

      Would be then funny to map that to lockscreen PINs - enter a PIN to unlock the device, be remoted into "phone A", enter another pin and be remoted into "phone B", enter another PIN and you're on the 'local device' session. (Or duress-PIN kill "phone A" if someone attempts to bruteforce PINs, etc, etc...)

      4 replies →

  • Remove and securely overwrite, otherwise the data can still be recovered from the disk image. We have not made privacy easy.

What about using decoy profiles? Say before the border crossing you switch to another user. Does that expose keys or anything for other users?

  • You would need to hide the existence of the original profile while in the decoy profile for this to work, which GrapheneOS considers too complex to implement

    • The only really plausibly deniable way to do it is for every graphene phone to come pre-partitioned for this. E.g. 128GB main + 128GB duress, random selection of whether partition 0 or 1 is the duress partition. But that means giving up half your storage.

      You can't even make them different sizes because that gives away which one is duress. You could have more partitions with a static split like 32+32+32+32+32+32+32+32 but then you have to manage so many independent partitions it isn't practical.

      2 replies →