rzk
7 hours ago
I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password.
On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.
[1] A US man is being prosecuted after allegedly using a GrapheneOS duress PIN to wipe his Pixel during a border search – https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...
[2] A Journalist had his mobile phone seized. Did using GrapheneOS protect his data? – https://www.computerweekly.com/feature/Journalist-Richard-Me...
Tanoc
6 hours ago
In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.
microtonal
6 hours ago
This is why it is important to continue iterating everywhere that device security is important for everyone. iPhone has nearly the same level of protection and we also do not see it as 'criminal by default'.
Secondly, it is important to get as many people to use GrapheneOS as possible, including non-tech people. The more widespread it becomes, the harder it will become to paint this picture.
mycall
2 hours ago
Perhaps GrapheneOS should just be an ASOP release with implicit security features that makes it hard to notice it is anything different. If people think it is a vanilla Android install, it would give them no reason to imply criminal activity.
Cider9986
2 hours ago
Not worthwhile or feasible. The OS is not designed to hide its identity.
kungito
3 hours ago
sounds to me like iphone isnt actually that safe otherwise it wouldnt make sense. maybe we are missing some critical information
Cider9986
3 hours ago
GrapheneOS seems to be consistently the hardest to exploit AFU based on various Cellubrite leaks. iPhones have better protection than all other Androids except Pixels.
microtonal
3 hours ago
I might be wrong, but I get the impression that the GrapheneOS folks generally recommend GrapheneOS > iOS > Pixel >> everything else.
It might have to do with e.g. Apple having rolled out MIE at a broader scale than Google rolling out MTE on PixelOS, where AFAIK it is still largely opt-in (not 100% sure, I always wipe a Pixel immediately).
Cider9986
3 hours ago
Agree. I didn't mean to say stock pixels are better than iPhones.
K3V1N_FLYNN
2 hours ago
Correct, they have a hard on for that garbage.
K3V1N_FLYNN
3 hours ago
The iPhone is still more secure than graphene, otherwise it wouldn’t be the only device that NATO approves carrying around information related to them. I also highly doubt it was a coincidence that the iPhone was the device of choice for the Artemis astronauts.
Cider9986
2 hours ago
Perhaps the fact that iPhones are run by a multi trillion dollar company while GrapheneOS is an open source project with less employees than an Apple store has something to do with NATO approval. They are not going to approve a device that people have to install the OS themselves. I would base the security of an OS based on expert security researchers, not certain government agencies decisions.
iPhones are probably the most secure off the shelf phones you can buy, but based on leaked documents it's clearly inferior real-world security compared to a Pixel running GrapheneOS. Apple and Google have copied many security features from GrapheneOS like the reboot timer.
GrapheneOS is built from the ground up with a primary priority placed on security. GrapheneOS has much more robust USB port hardening. You can see the full list of features added on their website. Apple bolts on some additional security features in lockdown mode but they are mostly fixes to Apple's services which have large attack surface like iMessage. Additionally they are all built together and not on by default which makes the users willing to use it way lower.
stef25
2 hours ago
> The iPhone
Probably the latest models. Cop told me they have problems cracking those. Older models not so much, that's pretty common knowledge.
K3V1N_FLYNN
2 hours ago
Sorry, you don’t get to move the goals posts because you don’t like the answer, the iPhone is still more secure than a pixel running graphene, end of story.
Cider9986
2 hours ago
Source: I made it up
close04
4 hours ago
He’s a “surveillance expert” so the language is not at all surprising. These are the people who always bring up the appeal to emotion, associating a benign act with something unpalatable, criminal, terrorist, think of the children.
When your job depends on not understanding and all that.
ChoosesBarbecue
18 minutes ago
I'm fairly certain the person being quoted is saying the opposite of what you've implied - i.e. he thinks it is concerning THAT GrapheneOS is automatically associated with criminality.
microtonal
7 hours ago
citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.
Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to get to BFU).
msh
6 hours ago
I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.
dugite-code
5 hours ago
Probably because everything seems to be an "app" these days. Even when it has no business being one.
inigyou
5 hours ago
Exactly. Everything must be switched to Service as a Software Substitute. It's for your own safety, you see.
xnickb
4 hours ago
So delete messengers, email apps and other comms?
Delete the contact book? Clear calendars?
Where exactly should one stop?
daneel_w
an hour ago
You're misinterpreting. They mean that there are additional options next to only keeping these things on your phone.
choo-t
5 hours ago
Because you may need the data in the data during/after your travel and lack clean way to access safely, securely and anonymously remotely.
daneel_w
an hour ago
No one is stopped from backing up important data. It is, in fact, kind of boneheaded to keep all "valuables" on a single device. I don't understand the scenario of not trusting a device to safely access the Internet or the telephony grid while also insisting that they need a PHONE to keep all their stuff on where they're going, and at the same time somehow trust that both themselves and their possessions are perfectly safe from seizure and extortion in the very same location.
kotaKat
4 hours ago
This is where we need "cloud phones as a service" / "selfhosting a cellphone at home with some kind of remote access system".
Not even kidding here, it's time to bring out thin client computing to cellphones. Let the spicy stuff sit somewhere else. I could bootstrap a Tailscale or Netbird signin remotely, install the access client, and remote back into the 'normal phone'.
Would be then funny to map that to lockscreen PINs - enter a PIN to unlock the device, be remoted into "phone A", enter another pin and be remoted into "phone B", enter another PIN and you're on the 'local device' session. (Or duress-PIN kill "phone A" if someone attempts to bruteforce PINs, etc, etc...)
mystifyingpoi
2 hours ago
> "selfhosting a cellphone at home with some kind of remote access system
You can use TeamViewer for that. Or maybe scrcpy could be coerced into working in a similar way.
podocarp
5 hours ago
What about using decoy profiles? Say before the border crossing you switch to another user. Does that expose keys or anything for other users?