7/26/2026 at 8:32:14 AM
I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password.On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.
[1] A US man is being prosecuted after allegedly using a GrapheneOS duress PIN to wipe his Pixel during a border search – https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...
[2] A Journalist had his mobile phone seized. Did using GrapheneOS protect his data? – https://www.computerweekly.com/feature/Journalist-Richard-Me...
by rzk
7/26/2026 at 9:29:01 AM
In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.by Tanoc
7/26/2026 at 9:39:29 AM
This is why it is important to continue iterating everywhere that device security is important for everyone. iPhone has nearly the same level of protection and we also do not see it as 'criminal by default'.Secondly, it is important to get as many people to use GrapheneOS as possible, including non-tech people. The more widespread it becomes, the harder it will become to paint this picture.
by microtonal
7/26/2026 at 5:00:52 PM
I'm not sure that I agree that iOS devices have equal protection.The recent Darksword exploit should give everyone pause in asserting that iOS is secure:
https://www.malwarebytes.com/blog/mobile/2026/03/a-darksword...
I trust iOS with my banking and financial apps in a way that I would never trust Google, but I am under no illusion that any architecture can be completely secure.
On the Linux side, I have found SELinux maddening at times in forcing me to the syslog to enable and permit what I need the machine to do.
I have never seen anything this obstreperous in a BSD, but perhaps I have not looked with sufficient depth.
In any case, the Trust / SELinux / Enforcing status is a sizable advantage against iOS.
by chasil
7/26/2026 at 12:26:02 PM
sounds to me like iphone isnt actually that safe otherwise it wouldnt make sense. maybe we are missing some critical informationby kungito
7/26/2026 at 12:43:05 PM
GrapheneOS seems to be consistently the hardest to exploit AFU based on various Cellubrite leaks. iPhones have better protection than all other Androids except Pixels.by Cider9986
7/26/2026 at 12:56:52 PM
I might be wrong, but I get the impression that the GrapheneOS folks generally recommend GrapheneOS > iOS > Pixel >> everything else.It might have to do with e.g. Apple having rolled out MIE at a broader scale than Google rolling out MTE on PixelOS, where AFAIK it is still largely opt-in (not 100% sure, I always wipe a Pixel immediately).
by microtonal
7/26/2026 at 1:17:41 PM
Agree. I didn't mean to say stock pixels are better than iPhones.by Cider9986
7/26/2026 at 1:22:51 PM
Correct, they have a hard on for that garbage.by K3V1N_FLYNN
7/26/2026 at 4:26:28 PM
IIRC it was the only one that Cellebrite couldn't break, but this was based on quite old news.by inigyou
7/26/2026 at 6:26:57 PM
There are more recent leaks. The last release of GrapheneOS they've been able to exploit on locked device is still from 2022 as of a couple months ago. They take longer to break into iPhones than stock Pixels but that may largely be due to Google giving much earlier access for public testing. They have a far shorter window to prepare for a new iOS release before it's in production as a regular update for users.by grapheneos
7/26/2026 at 1:22:07 PM
[flagged]by K3V1N_FLYNN
7/26/2026 at 1:46:43 PM
Perhaps the fact that iPhones are run by a multi trillion dollar company while GrapheneOS is an open source project with less employees than an Apple store has something to do with NATO approval. They are not going to approve a device that people have to install the OS themselves. I would base the security of an OS based on expert security researchers, not certain government agencies decisions.iPhones are probably the most secure off the shelf phones you can buy, but based on leaked documents it's clearly inferior real-world security compared to a Pixel running GrapheneOS. Apple and Google have copied many security features from GrapheneOS like the reboot timer.
GrapheneOS is built from the ground up with a primary priority placed on security. GrapheneOS has much more robust USB port hardening. You can see the full list of features added on their website. Apple bolts on some additional security features in lockdown mode but they are mostly fixes to Apple's services which have large attack surface like iMessage. Additionally they are all built together and not on by default which makes the users willing to use it way lower.
by Cider9986
7/26/2026 at 4:06:56 PM
Any independent reasons for your claim besides appeal to authority?by curt15
7/26/2026 at 4:21:06 PM
Apple can at any time push a hostile "upgrade" that will remove or disable the claimed security features. You don't control the operating system, and can't trust that it isn't backdoored, especially given Apple's record[0].by drnick1
7/26/2026 at 1:39:14 PM
> The iPhoneProbably the latest models. Cop told me they have problems cracking those. Older models not so much, that's pretty common knowledge.
by stef25
7/26/2026 at 5:06:33 PM
Is this because of vulnerabilities baked in the HW (or bootROM or any other unpatchable area)? What’s the situation on older Pixels? Are they generally safer than an iPhone for HW issues? It’s expected that given a few years some vulnerabilities will crop up for most hardware.So then the best chance for security is to stay up to date with everything, including the latest HW model. At least this gives an attacker a window of only ~1 year to find and exploit a vulnerability.
by close04
7/26/2026 at 1:48:42 PM
[flagged]by K3V1N_FLYNN
7/26/2026 at 2:03:16 PM
Source: I made it upby Cider9986
7/26/2026 at 1:29:07 PM
Perhaps GrapheneOS should just be an ASOP release with implicit security features that makes it hard to notice it is anything different. If people think it is a vanilla Android install, it would give them no reason to imply criminal activity.by mycall
7/26/2026 at 5:16:15 PM
Google is never going to put their administrative access in a restricted sandbox.That is diametrically opposed to their interests in data collection.
by chasil
7/26/2026 at 1:39:43 PM
Not worthwhile or feasible. The OS is not designed to hide its identity.by Cider9986
7/26/2026 at 11:40:14 AM
He’s a “surveillance expert” so the language is not at all surprising. These are the people who always bring up the appeal to emotion, associating a benign act with something unpalatable, criminal, terrorist, think of the children.When your job depends on not understanding and all that.
by close04
7/26/2026 at 3:34:31 PM
I'm fairly certain the person being quoted is saying the opposite of what you've implied - i.e. he thinks it is concerning THAT GrapheneOS is automatically associated with criminality.by ChoosesBarbecue
7/26/2026 at 4:57:01 PM
You’re right, I misinterpreted but now that you mention it it’s like those ambiguous figure images, irreversibly collapsed on the proper interpretation. In this case I can only assume my interpretation of “surveillance expert” is also completely off. Can’t edit, flag away.by close04
7/26/2026 at 9:21:00 AM
citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to get to BFU).
by microtonal
7/26/2026 at 9:50:33 AM
I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.by msh
7/26/2026 at 10:31:51 AM
Probably because everything seems to be an "app" these days. Even when it has no business being one.by dugite-code
7/26/2026 at 11:13:59 AM
Exactly. Everything must be switched to Service as a Software Substitute. It's for your own safety, you see.by inigyou
7/26/2026 at 11:57:15 AM
So delete messengers, email apps and other comms?Delete the contact book? Clear calendars?
Where exactly should one stop?
by xnickb
7/26/2026 at 2:51:52 PM
You're misinterpreting. They mean that there are additional options next to only keeping these things on your phone.by daneel_w
7/26/2026 at 4:14:01 PM
What am I misinterpreting? OP literally said they don't understand why a journalist would carry these data with them. As if the data is a file on your phone. Data can be a contact book on your phone, or a messenger with E2E encrypted messages. What would the alternative to that be? Sending pigeons?by xnickb
7/26/2026 at 4:23:52 PM
Restoring from remote backup when you reach your destination, then wiping again before you cross borders. Or shipping the (encrypted) data separately and picking it up after safe arrival.by iamnothere
7/26/2026 at 4:30:28 PM
What's the difference between this and wiping when under duress using the special PIN? If you aren't being checked you don't wipe and are gopd to go.by xnickb
7/26/2026 at 4:32:55 PM
Because you show up with nothing on you, and there’s no way to prove that the backups even exist. Especially given how often people travel with blank/disposable phones.Just as the border guard can’t require you to fetch something from your house before entry, they can’t require you to restore from a remote backup that they don’t even know about.
by iamnothere
7/26/2026 at 6:50:54 PM
Wiping under duress is unlawful and could lead to prosecution in some juridictions.On the other hand I don't know of any juridiction that force you to carry all the personal data in a single device when crossing borders. It would moat likely not even be possible.
by prmoustache
7/26/2026 at 4:28:03 PM
The government can easily get your remote backup, of course. It's just that border control won't know you have one.by inigyou
7/26/2026 at 4:29:49 PM
Not if it’s encrypted and self-hosted. Your doomerism is silly. “The government” is not all-powerful, or they wouldn’t need to pester people for PINs at the border.by iamnothere
7/26/2026 at 4:33:00 PM
Encryption in this case is irrelevant. If they get the encrypted backup they can already charge you if you don't decrypt it.Self-hosting is the way obviously
by xnickb
7/26/2026 at 4:35:00 PM
Can the border guard go to your house and retrieve something, bring it to the checkpoint, and ask you to do something with it before entry? No. This is out of their legal authority.Also, you could set up a system where the phone cannot restore the backup on reentry. Perhaps a single use restore key that you use at your original destination, so the restore cannot be performed again until you return home and generate a new code. This evades the (flimsy) charges that were applied in this case.
The best option, however, is to bring a blank disposable device, restore from backup at your destination, then discard the device before you cross the border again.
by iamnothere
7/26/2026 at 5:06:33 PM
That's not my point. Rather that any self-hosted solution would. Encryption is completely optional and can be illegal in some places. As long as you trust the endpoint you only care about encryption in transit.If your devices are seized having encrypted data can pose extra risk.
Deniable encryption exists and burden of proving that you haven't used it can be put on you.
Basically I'm trying to say "it depends". I'm not a fan of "let's just slap a(nother) layer of encryption on it" security model. My home servers aren't encrypted and I see no reason to do so. Sensitive data is encrypted based on the sensitivity.
> The best option
The best option is the one that is most convenient to the user and fits the task at hand.
If you are on a demonstration and need to broadcast status live then you don't have a luxury of bringing in a blank phone and restoring backup before each transmission
by xnickb
7/26/2026 at 5:21:15 PM
> If your devices are seized having encrypted data can pose extra risk.I don’t think you can even set up an iPhone anymore without encryption. It’s just “on”, not even “on by default”.
> My home servers aren't encrypted and I see no reason to do so. Sensitive data is encrypted based on the sensitivity.
If you do sensitive work, you should be concerned about someone breaking in and running off with your storage. It’s unfortunate but that’s just how it is. Encryption adds very little overhead on modern hardware.
> If you are on a demonstration and need to broadcast status live then you don't have a luxury of bringing in a blank phone and restoring backup before each transmission
That’s not crossing a border then, is it? The case under discussion was about a border crossing, where (apparently?) Constitutional rights are suspended. A used phone adds little to the cost of an international trip.
by iamnothere
7/26/2026 at 6:53:17 PM
No you just chose to ignore other cases that OP mentioned and focused on this oneby xnickb
7/26/2026 at 8:02:21 PM
A protest is a completely different situation. In that situation I’d recommend a burner phone that you can afford to lose or throw away. Ideally the cheapest one available. And never log in to your primary accounts on it.by iamnothere
7/26/2026 at 10:30:11 AM
Because you may need the data in the data during/after your travel and lack clean way to access safely, securely and anonymously remotely.by choo-t
7/26/2026 at 2:53:06 PM
No one is stopped from backing up important data. It is, in fact, kind of boneheaded to keep all "valuables" on a single device. I don't understand the scenario of not trusting a device to safely access the Internet or the telephony grid while also insisting that they need a PHONE to keep all their stuff on where they're going, and at the same time somehow trust that both themselves and their possessions are perfectly safe from seizure and extortion in the very same location.by daneel_w
7/26/2026 at 4:28:47 PM
Personally I just got grapheneos to replace my normal phone. It's nice, it works for the user instead of the advertiser, and its security features help block antiuser features in appsby inigyou
7/26/2026 at 12:15:05 PM
This is where we need "cloud phones as a service" / "selfhosting a cellphone at home with some kind of remote access system".Not even kidding here, it's time to bring out thin client computing to cellphones. Let the spicy stuff sit somewhere else. I could bootstrap a Tailscale or Netbird signin remotely, install the access client, and remote back into the 'normal phone'.
Would be then funny to map that to lockscreen PINs - enter a PIN to unlock the device, be remoted into "phone A", enter another pin and be remoted into "phone B", enter another PIN and you're on the 'local device' session. (Or duress-PIN kill "phone A" if someone attempts to bruteforce PINs, etc, etc...)
by kotaKat
7/26/2026 at 4:32:44 PM
You can already do most of that with GrapheneOS or even an iPhone. My contacts, files, photos, etc. are on my home server, accessed through a VPN. My GrapheneOS phone only runs a handful of open source apps. If I were to lose the phone, I would simply revoke the Wireguard key and there wouldn't be anything valuable left on it.by drnick1
7/26/2026 at 1:45:43 PM
> "selfhosting a cellphone at home with some kind of remote access systemYou can use TeamViewer for that. Or maybe scrcpy could be coerced into working in a similar way.
by mystifyingpoi
7/26/2026 at 6:51:55 PM
Good luck making it work again remotely after a long power outage.by prmoustache
7/26/2026 at 7:43:58 PM
Not sure what do you mean? If that is a concern, there are solutions for this. Like UPSes and backup cellular connections.by mystifyingpoi
7/26/2026 at 10:54:14 AM
What about using decoy profiles? Say before the border crossing you switch to another user. Does that expose keys or anything for other users?by podocarp
7/26/2026 at 10:58:47 AM
You would need to hide the existence of the original profile while in the decoy profile for this to work, which GrapheneOS considers too complex to implementby 0-_-0
7/26/2026 at 4:30:37 PM
The only really plausibly deniable way to do it is for every graphene phone to come pre-partitioned for this. E.g. 128GB main + 128GB duress, random selection of whether partition 0 or 1 is the duress partition. But that means giving up half your storage.You can't even make them different sizes because that gives away which one is duress. You could have more partitions with a static split like 32+32+32+32+32+32+32+32 but then you have to manage so many independent partitions it isn't practical.
by inigyou
7/26/2026 at 6:14:09 PM
Deniable encryption has gotten way more advanced than this, though - the state-of-the-art is to have a bunch of independently unlockable data stores along with a mechanism to add chaff data that doesn't decrypt with any key. That's how bunnie's Betrusted project works, and it's the same idea as PhonebookFS from yesterdecade.The main problem with any deniable encryption system is that while your adversary might not be able to prove if you gave them the decoy or real data, they can at least force you to wipe anything you fail to decrypt. In your partitioning scheme, that would mean wiping any partition that doesn't decrypt with the set of PINs you gave them. In the more advanced granular scheme that Betrusted devices use, that would mean border control unlocking all the basis keys you dared to give them, and then them running the storage reclaim tool that wipes all other keys.
In either case, it would probably be easier (and less suspicious!) to pre-wipe your device and then redownload a backup after you pass through border control... assuming you can get access to an untampered Internet connection after the fact, AND assuming your backup is actually complete. Like, I'm pretty sure most apps exclude their login tokens from backup, because every time I do wind up restoring a backup, I have to log into everything again, which makes me wonder what the point of the backup even is?
by kmeisthax
7/26/2026 at 6:23:36 PM
That requires a whole new OS from scratch. It won't work to support Android. Even if it did, would you unlock your duress partition every time you used your phone to prevent overwriting?by inigyou
7/26/2026 at 2:06:29 PM
I mean, so does everyone.by Cider9986
7/26/2026 at 8:00:01 PM
The Guardian story discussed on HN: <https://news.ycombinator.com/item?id=49024436>.(The Computer Weekly item was submitted but saw no significant discussion.)
by dredmorbius