news.volyx.in

GrapheneOS protections against data extraction from locked devices (discuss.grapheneos.org)

448 points by Cider9986 · 32 days ago · 257 comments on HN

Article summary

A US man is being prosecuted for allegedly using a GrapheneOS duress PIN to wipe his phone during a border search, which wiped the encryption keys from the secure element. The discussion revolves around the technical details of how GrapheneOS protects against data extraction from locked devices. The case raises questions about the balance between individual privacy and law enforcement's ability to access data. The use of duress PINs and other security features is being debated in the context of border searches and device seizures.

Main themes

  • GrapheneOS security features
  • Border searches and device seizures
  • Data protection and privacy
  • Law enforcement access to data
  • Duress PINs and security protocols

What commenters say

  • The use of a duress PIN to wipe a device can be an effective way to protect data from unauthorized access, but it may also have legal consequences.
  • GrapheneOS's security features, such as the duress PIN and auto-reboot, can provide strong protection against data extraction, but may not be foolproof.
  • Border searches and device seizures raise concerns about individual privacy and the balance between national security and personal freedoms.
  • The use of physical intimidation, such as the 'wrench attack', to extract data from devices is a concern, but some argue that it is a weaker attack than push-button attacks.
  • Some argue that carrying sensitive data on a device during border crossings or other high-risk situations is unnecessary and that alternative solutions, such as remote access or cloud storage, should be used instead.
  • The development of new technologies, such as 'cloud phones as a service' or self-hosted cellphones with remote access, could provide new solutions for protecting data and maintaining privacy.
  • The prosecution of the US man for using a duress PIN to wipe his phone raises questions about the legality and ethics of using such security features to protect data.
  • Some argue that the focus on individual privacy and security measures is misguided, and that a more effective approach would be to address the root causes of surveillance and data collection, such as government overreach and corporate data harvesting.