HeadlinesBriefing favicon HeadlinesBriefing.com

GrapheneOS Defends Against Data Extraction Attacks

Hacker News •
×

XRY and Cellebrite confirm consent-based full filesystem extraction works on iOS, Android, and GrapheneOS once users provide lock credentials. Cellebrite's April 2024 documentation reveals they can exploit every non-GrapheneOS Android device both BFU and AFU, but cannot breach GrapheneOS with patch levels past late 2022. Only Pixel devices prevent brute-force attacks via secure element throttling.

Pixel 6 and later or latest iPhones are the sole devices where a random 6-digit PIN resists brute forcing. GrapheneOS recommends 6-8 diceware word passphrases for lasting security. Auto-reboot (default 18 hours, minimum 10 minutes) returns data to rest, while USB-C port control blocks new AFU connections after lock and disables USB data at hardware level when inactive.

GrapheneOS on 8th-gen Pixels benefits from hardware memory tagging. Recent social media attacks misrepresent consent-based extraction as compromise; GrapheneOS remains the only OS successfully defending against these exploits. Duress PIN/password implementation prioritizes guaranteed unrecoverable data over speed. Upcoming 2-factor fingerprint unlock with random passphrase generation aims to encourage stronger primary credentials.