Cider9986
4 hours ago
For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.
GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.
On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.
If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.
[1] https://strongphrase.net give memorable ones which is cool.
iamnothere
3 hours ago
Never use a website to generate a password for something important like this. You can print out diceware passwords and roll dice.
fluidcruft
an hour ago
You can just take a picture of a pile of dice, a pile of rice, or a tree, patch of grass, etc, and compute a secure hash/whatever and base six it to get the rolls.
Brybry
32 minutes ago
Are you saying to take a hash of a picture and convert that to base 6 for your dice rolls to plug into a word list for creating a passphrase?
Is that actually better (in practice, not in terms of entropy) than /dev/urandom? I have a lot less trust in my ability to successfully scrub a picture from my phone that deterministically created my passphrase.
Matumio
7 minutes ago
If you're concerned about that, you can concat your JPEG with a few bytes from /dev/random and you'll get the security of whichever is stronger. In practice none of this will be your weakest link.
lisper
14 minutes ago
> Is that actually better (in practice, not in terms of entropy) than /dev/urandom?
It offers protection in the event that your /dev/urandom is compromised. Otherwise no.
(Of course, if your /dev/urandom is compromised then whatever process you use to compute a hash of a photo is likely compromised as well.)
cj
37 minutes ago
I actually have a lava lamp next to my desk for this reason. Snap a photo, compute a hash!
fluidcruft
an hour ago
Why not automatically power down if any unknown USB device is attached?
eli
an hour ago
So like you connect it to your computer for the first time and it shuts off?
sellmesoap
2 minutes ago
Could request unlock and reboot if no valid pass is accepted within n minutes.
83
34 minutes ago
that doesn't seem unreasonable. You only have one first time. Maybe two if you upgrade your computer more often than your phone.
isoprophlex
40 minutes ago
Better wire it up to a thermite charge just to be sure. Untrusted USB device? Hope you enjoy 1400 degree molten iron
nkrisc
20 minutes ago
Or it’s not enabled by default.
olyjohn
37 minutes ago
Yeah... that could be an option you configure.
dylan604
3 hours ago
> On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase
Why do you call out just one OS? It's a good idea for any OS.
rtkwe
3 hours ago
This seems specific to GrapheneOS (unique as far as I know though I'd be happy to learn otherwise) where you could set a very long first unlock passphrase and have a shorter less cumbersome fingerprint plus pin option for subsequent unlocks. I wouldn't want to have to enter a long passphrase every time I unlock but once a day isn't so bad.
dylan604
3 hours ago
I don't run GrapheneOS, but I have an >15 character passphrase that must be used before biometrics can be used after reboot. I haven't used a 4-digit pin since the option to not use it was available.
rtkwe
2 hours ago
The specific extra that grapheneOS adds is that you can have a required Fingerprint + PIN with a shorter easier to enter pin while also having a long first unlock passcode. Only a first unlock passcode then biometrics is not secure in the US if your device is in the AFU/biometric-only (after first unlock) state because you can be easily and legally compelled to provide a biometric unlock.
https://threecats.au/two-factor-pin-fingerprint-unlock-graph...
dataflow
3 hours ago
The option was there in Cyanogenmod back during the OnePlus One days. It was such a step backwards when it was removed. You almost had to wonder if it was deliberately done at the request of some TLA to prevent users from using too strong of a password for decryption.
rtkwe
2 hours ago
I doubt it, mostly because phones were a lot easier to crack back in those days already so I doubt a TLA needed to push for it to be removed.
Cider9986
3 hours ago
Yes, in fact on GrapheneOS it's less necessary and it's only necessary if you don't want to rely on the secure element rate limiting.
GrapheneOS allows using a passphrase with more convenience because of the fingerprint plus second factor pin (I don't think you can just have a pin as a secondary unlock). You don't need to enter the passphrase every time you unlock with this setup, only when first starting up.
The official opinion: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
23ahGa17
3 hours ago
People believed the reboot feature last time GrapheneOS was mentioned. It is of course nonsense.
Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.
Cider9986
3 hours ago
> Shut down the phone in areas with a high snatch risk.
Yes this is of course safer. What evidence do you have that it doesn't work on GrapheneOS, though?
https://www.computerweekly.com/feature/Journalist-Richard-Me...
1298436
3 hours ago
Medhurst has no evidence that it worked either. He hasn't tweeted since August 24th, I hope he is well and at liberty.
markus_zhang
3 hours ago
To add an extra layer of safety. Bring a secondary phone when travelling by airplanes, especially to other countries. You should also use it frequently, maybe with some side apps to make it look like it's your daily phone.
ryandrake
2 hours ago
Or, just don't bring a phone if you're particularly vulnerable. What are they going to do? Deny you entry because you don't carry a phone? If we're really at that point, where merely not having some item is suspicious, we're in deep shit.
stefan_
3 hours ago
The internet exists and can transfer your data with no customs and borders, so if you are at risk of being snatched, the correct choice is to not carry a phone (or laptop, or..) at all.
Someone
2 hours ago
https://en.wikipedia.org/wiki/Great_Firewall:
“The Great Firewall operates by checking transmission control protocol (TCP) packets for keywords or sensitive words. If the keywords or sensitive words appear in the TCP packets, access will be closed. If one link is closed, more links from the same machine will be blocked by the Great Firewall. The effect includes: limiting access to foreign information sources, blocking popular foreign websites and mobile apps, and requiring foreign companies to adapt to domestic regulations. Due to the Great Firewall, China has one of the lowest cross-border internet traffic rates in the world. Usage of foreign apps in China is minuscule; Asia Society estimated in 2026 that foreign apps blocked by the Great Firewall have extremely low traffic, particularly compared to domestic apps; the top five domestic apps saw traffic that was 1,000 times more than the top five foreign apps.”
oasisaimlessly
2 hours ago
The Great Firewall doesn't restrict SSH, so you can functionally ignore it (assuming using e.g. `ssh -D` is second-nature to you).
alkh-qrt
2 hours ago
If you live in the UK and travel to the US and are afraid of state actors, leaving your hardware at home seems like a bad idea, too.
gambiting
2 hours ago
Despite all the nonsense that's posted about UK on the internet, British agencies do require a warrant to enter your home. TSA on the other hand does not require a court order to confiscate and mirror your device before giving it back to you.
Edit: Just to be perfectly clear - Border Force in the UK can do the exact same thing to you once you return, British citizen or not. Leaving your device at home is still the safest choice.
Cider9986
2 hours ago
I believe it's CBP that does this, not TSA. Therefore Americans don't have to worry about it during domestic flights.
> Despite all the nonsense that's posted about UK on the internet
How is it nonsense? I'm not debating the warrant thing, but it's very reasonable to assume the UK has terrible protections for these sorts of things.
https://en.wikipedia.org/wiki/Key_disclosure_law#:~:text=Uni...
gambiting
2 hours ago
I mean in a broad sense if you read any news about the UK it might looks like a dystopian surveillance state where you get arrested for criticising the king(I kid you not - I've had multiple American coworkers ask me if this is true).
And yes, UK has some awful laws around this. Yes it has put people in jail just for planning a protest before. Yes you can go to jail for not disclosing your passwords. But what you read on the internet is almost laughably out of proportion - no, you won't get arrested for posting a meme about the king.
nostrademons
25 minutes ago
FWIW the same applies to flying in the U.S. as long as you're not a person that the government cares about. I haven't had any issues with either TSA or CBP since 2011 (when, apparently, being multiracial with facial hair made me look Middle-Eastern and looking Middle-Eastern is a cardinal sin at U.S. ports of entry). Neither has anyone I've observed at the airport, and that's thousands of people per flight, and I fly about 3-4 times per year. There's plenty of stories on the Internet, and I don't doubt the stories are true, but the Internet can easily make a 1-in-a-million occurrence happen every day (indeed, given the sheer numbers, a 1 in a million occurrence does happen every day, it's just that it's unlikely to happen to you).
dmitrygr
an hour ago
> news about the UK it might looks like a dystopian surveillance state where you get arrested for criticising
Might it "seem" that way because it is that way?
https://www.forbes.com/sites/steveforbes/2025/09/09/people-a...
https://www.telegraph.co.uk/news/2026/08/22/britain-has-beco...
https://freespeechunion.org/news/more-than-62-000-people-hav...
Oh, and your government itself openly states it on record, too: https://hansard.parliament.uk/lords/2025-07-17/debates/F807C...
gambiting
an hour ago
How many of those people got arrested for criticising the king?
Not that this is some kind of great bar to clear, but if you're going to argue with what I said, argue with what I actually wrote.
dmitrygr
an hour ago
Ok then. Soviet Union had free speech too. Nobody got arrested for criticizing Reagan or Churchill.
Clearly the point is clear. Why nitpick pointlessly?