GrapheneOS protections against data extraction from locked devices

196 points · 112 comments on HN · read original →

Points and comments are a snapshot, not live.

GrapheneOS details its secure element rate limiting and insider attack resistance against data extraction from locked devices.

GrapheneOS builds on Android 17 and Pixel hardware security features. The secure element implements rate limiting that ramps up delays: 4 hours after 10 attempts, 41 days after 15, with 20 total allowed. Insider attack resistance requires owner authentication before secure element firmware can be updated, preventing governments from bypassing rate limiting via coerced updates. GrapheneOS also raises the password character limit from 16 to 128 and adds a second-factor fingerprint PIN with reduced attempts. A locked device auto-reboot timer (default 18 hours) returns the device to Before First Unlock state, zeroing memory. USB connections are blocked by default while locked.

What commenters are saying

Commenters focused on a real-world legal case where a man used a GrapheneOS duress PIN at a US border search, which allegedly wiped his Pixel phone. Many noted the border agents effectively wiped the device themselves. Some questioned whether backup would have been possible, noting the encryption keys are wiped from the secure element, making storage worthless without the keys. A journalist's case was also cited where the 18-hour auto-reboot feature protected sources. One commenter suggested that widespread adoption of GrapheneOS would make it harder to portray such security as criminal.