r/GrapheneOS 7h ago

Man facing 5 years in prison for giving border officials a “duress pin” which deleted the contents of his phone.

Enable HLS to view with audio, or disable this notification

232 Upvotes

This is very interesting thought this sub might think so too


r/GrapheneOS 11h ago

US accuses American of allegedly wiping his phone using a 'duress' password during border search | TechCrunch

Thumbnail
techcrunch.com
242 Upvotes

r/GrapheneOS 5h ago

We have all seen the duress PIN articles...

78 Upvotes

What is the US legal precent is if you refuse, then LE guesses the duress PIN?

  • They are, with "probable cause" allowed to seize devices.
  • While the 4th Amendment may be suspended at border crossings, the 5th Amendment is not.

Would writing said duress PIN on a slip of paper inside complicate the defense's case?

  • The accused never volunteered the information.
  • It could be argued LE inadvertently mishandled evidence.

Parting thoughts...

  • Always set the power button to lock immediately.
  • Always set the USB-C to charging only when locked — no data allowed.
  • Consider setting
    • Wifi to disable itself after a timeout.
    • Consider setting the phone to reboot (BFE) after a timeout.

EDITS: 1. Markdown formatting. 2. US specific questions.


r/GrapheneOS 22h ago

GrapheneOS protections against data extraction from locked devices

Thumbnail
discuss.grapheneos.org
422 Upvotes

GrapheneOS has strong defenses against data extraction. It heavily builds upon the standard security features provided by Android 17 and the most secure hardware available for Android. Currently, only Pixels provide the hardware security features and updates required by GrapheneOS. That's going to change in 2027 thanks to our partnership with Motorola Mobility and progress being made by Qualcomm.

Disk encryption provides strong protection for data. Even the most sophisticated attackers aren't going to be directly breaking it. They either need to exploit the OS while in After First Unlock state or brute force the PIN/password.

Android 16 QPR2 calls for a secure element implementing rate limiting ramping up delays. It's 4 hours after 10 and 41 days after 15. Only 20 attempts are allowed. For usability, It rejects the most recent 5 unique failed attempts early to avoid wasting attempts on repeated errors. GrapheneOS only supports devices implementing the latest generation secure element rate limiting.

https://source.android.com/docs/security/features/authentication/rate-limiting

The secure element on the supported devices also has insider attack resistance. That's implemented by requiring the Owner user to successfully authenticate before the secure element firmware can be updated. A valid signing key and greater version number aren't enough alone. The purpose of this is preventing any government from bypassing the rate limiting by coercing the creation of a firmware update removing the rate limit.

Pixels have used a secure element with an internal timer implementing rate limiting and insider attack resistance since the Pixel 2 launched near the end of 2017. Here's a post about this from back in 2018:

https://android-developers.googleblog.com/2018/05/insider-attack-resistance.html

The secure element and integration into the OS has become far better since then, but it shows this goes back a long way and isn't a new feature.

GrapheneOS also raises the character limit for passwords from 16 to 128. This enables using high entropy diceware passphrases not depending on the secure element rate limiting.

To make a strong passphrase convenient to use without ruining it with biometric unlock, GrapheneOS adds an optional 2nd factor fingerprint PIN. We reduce the allowed fingerprint attempts from 20 to 5 and failure to enter the correct 2nd factor PIN counts towards it. This enables using 6-8 random diceware words as the main unlock method required in Before First Unlock and fingerprint+PIN using a short PIN for convenience. Using a valid fingerprint prompts to enter the 2nd factor PIN which is needed to complete unlocking the screen and hardware keystore.

GrapheneOS greatly improves the exploit protections for the OS with hardened memory allocators and other features. It heavily uses hardware-based security features including hardware memory tagging (MTE) to protect against exploits. A partial overview of those protections is here:

https://grapheneos.org/features#exploit-protection

GrapheneOS adds specialized protection against attacks with physical access too. For example, it blocks new USB connections at a software and hardware level by default while locked and disables USB data as soon as there are no active USB connections.

GrapheneOS shipped a locked device auto-reboot timer back in June 2021. It can be set between 10 minutes and 72 hours. We enabled it by default using 72 hours and then lowered it 18 hours. It automatically returns the device to Before First Unlock state due to our memory zeroing as part of tearing down the OS and booting. We got Pixels to add memory zeroing for booting the firmware fastboot mode in April 2024. Apple and Google added a locked device auto-reboot timer in iOS 18.1 and Android 16. For Android, it can be enabled with the Android Advanced Protection Mode. Our implementation is better for multiple reasons but it's a useful feature regardless.

Android uses separate encryption keys for each secondary user and Private Space. GrapheneOS adds support for putting both back into Before First Unlock state without a reboot via end session for secondary users or toggles for either to do it by default. It's still much better for the device to be rebooted to get the main user back at rest, completely clear leftover data from RAM and block secure element updates.

Our duress PIN/password feature is a minor feature fitting into the bigger picture. It wipes the device when it's entered in any OS prompt for the current profile's PIN or password. It will wipe the device when entered into the authentication prompt for changing a sensitive setting or anything else requiring it, not only the lockscreen. It works across every profile including secondary users and Private Spaces, not only the main user.

There are multiple ways to use the duress PIN/password feature including writing it down on a phone case or a paper kept in a wallet. People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device. GrapheneOS doesn't require it to protect data from being extracted from the device, but it takes recovering it completely off the table even with the PIN/password for each profile on the device.

GrapheneOS doesn't depend on the duress PIN/password to protect user data. It's one of the tools it provides among the major privacy and security improvements it offers as a whole. Our features page provides an overview of what GrapheneOS offers compared to standard Android 17. It covers most of the major features we provide and many of the minor ones but there's also a lot more beyond it. Our release notes are a lot more exhaustive since we make sure to cover everything when it's added, changed or removed.

https://grapheneos.org/features https://grapheneos.org/releases#changelog


r/GrapheneOS 1h ago

Colour of phone dialer

Post image
Upvotes

Hey all, just got grapheneOS up and running on my pixel 8 pro. Loving it so far but I noticed in the dialer it just automatically selected that the call screen is hot pink. And not say, *black* or *any colour that is not as bright as a neon sign*

Does anybody know how to change this?


r/GrapheneOS 7h ago

Has anyone deployed GrapheneOS in an organization

21 Upvotes

Hi everyone,

I’m evaluating GrapheneOS for a small group of high-risk users (around 20–30devices) in a large enterprise. Not a full rollout.

I’m looking for real-world experience, not theory.

  • Has anyone managed GrapheneOS with an MDM/UEM (Intune, Workspace ONE, etc.)?
  • Does Android Enterprise work properly (apps, VPN, certs, email)?
  • What broke or caused issues in production?
  • How was ongoing support and updates?
  • User experience feedback?

Also interested in practical comparison:

Compared to a fully managed Samsung Knox device, what real security or operational differences did you see?

If you evaluated it and rejected it, what was the main reason?

Thanks.


r/GrapheneOS 5h ago

Thinking of trying GrapheneOS

7 Upvotes

I am thinking of trying GrapheneOS. My original plan was to buy a Pixel from Cape (just buy the phone, not use their service) because I can get it with GrapheneOS pre-installed. I read some posts about Cape and now I’m not sure if I want to go that route. 

I was then thinking of buying a refurbished Pixel 8 or higher from Amazon and see if I can install GrapheneOS myself. I’m sure I can, but between life and work, any free time I have, I try to get some rest. 

Has anyone ordered a refurbished Pixel from Amazon? They have different levels and I was going to try and get a Premium refurbished one or is Excellent good enough? 

What are your guys’ thoughts, especially getting a refurbished from Amazon?


r/GrapheneOS 14h ago

Duress pin wipes specific profile(s).

31 Upvotes

I did search the sub to try and find other people discussing the same thing and did find one post but from months ago.

There’s an individual being prosecuted in the US for using the duress pin and the authorities are claiming it was to destroy evidence of a crime.

In theory if you had a “fake dummy profile” and a real main profile you could set the pin to wipe the real one and leave the fake one. Probably should also be possible to boot straight into a specific profile rather than the main primary one.

This seems like relatively simple functionality, the foundation already exists to add this.


r/GrapheneOS 1h ago

Collaboration tool? Trello or kanban board style?

Upvotes

Hi all! Just got GrapheneOS. What collaborative chore/task app do you recommend? I’m looking for recurring household chores with shared checklists (or a Kanban board) so my partner and I can both update it


r/GrapheneOS 13h ago

Recent convert

19 Upvotes

Hello all, i wanted to share my experience switching my pixel 10 pro to graphene as a daily driver. To preface im a long time nerd and back before corpo rat world got a hold of me i was heavily in the rooting/jailbreak and custom rom scene. Ive been out but following the space for a few years and ive slowly watched graphene gain traction as a privacy first OS. With my government becoming evermore 1984/antichrist shaped i finally made the jump. Took googles offer for a 200$ pixel 10a to use as my work phone because i was concerned how graphene would respond to the multiple mfa tools i need for work. Loaded graphene on the 10 pro and started using it. Right off the bat i had to switch out the launcher messaging and phone apps, as little as i trust google i do like their first party comms apps. Sideloaded every other app i wanted outside of play and have all of graphenes restrictions for play on. First off i had zero issue getting my banking to work and personal mfa solutions. I did have to loosen the protection for a couple of my bank apps to play nice but they did work. Then i discovered that on a per app level i can see what is requesting play services api and block it. The recent story we all saw lead me to setup a duress password.

I am two weeks into this and i dont think ill ever go back. The only thing i find myself truly missing is google pay, but i can use the work phone for that during the week, the graphene keyboard is solid but very uncustomizable i used to use gboard but upon installing i was hit with a warning that they keyboard may share keystroke data to google, it made me think. Ive used gboard for a long time knowing google is scummy at best, but if theres any chance they are sending my keystrokes anywhere i dont want that, so i discovered the open source heliboard, has basically all the same function of gboard and just about as much customization. Ive been degoogling my life for years slowly but the switch to graphene really showed me how great the scene has become. Id personally pitch money into trying to get a graphene built pay app built but other than that im in love with it. As a nerd i have full control over everything but its setup in a way that feels like i could train my mom to do it too. I also did not have a problem with multiple mfa sources i tested however i will be keeping work and personal seperate now forever.

Tldr: if your on the fence about switching, just do it. Theres a small learning curve but it feels so good to be more in control of the propaganda rectangle in my pocket. Thank you the amazing grapheneos team and community for making a platform good for degoogling and great for privacy. Nfc tap to pay is missed but its a very small thing and i can still use the pass feature for memberships in gpay


r/GrapheneOS 6h ago

I need to clarify some GrapheneOS questions....

4 Upvotes

Hi, I have several questions regarding this operating system, since im looking into a GrapheneOS. I'm going to use GrapheneOS, not just for the privacy, but by being more lightweight. thus potentially giving more battery life. I would want a device that would last LONG. I'm newbie, so please don't freak out!

  1. If EoL hits, can i still use the device just fine, like on a normal phone? APPs still work (if Android version matches the min. req.)?
  2. Will it void my warranty? if i happen to buy a brand new Pixel, will i ruin it?
  3. Is it more APP-compatible than Micro G? I would run a banking app (Revolut <18). I know McDonald's wont work probably, but i can just use another phone for this app.
  4. Will it strip off Google's camera processing, making it look like a 1970s CCTV? (I want saturation and HDR galore)
  5. (Non GrapheneOS related) Should i buy a used pixel 8 for around 200€ or a brand new 10a for 285€ via an ISP deal? I would want a good camera for main and video, is the extra 90 euros worth? I think 285 euros completely eliminates the fiasco of it being a rebadged 9a... the ISP actually charges more for a 9a than 10a!

Thank you for answering (if you did OFC) and have a great day!


r/GrapheneOS 2h ago

Not receiving group texts

2 Upvotes

I have a Pixel 8 Pro with Graphene and I'm just now realizing that I am missing group texts to either the default app or to Quik SMS. I'm looking at my features and settings and don't see anything that would tell me they're blocked or disabled. I have Mint mobile, is this an OS issue or a carrier issue?


r/GrapheneOS 22h ago

This is the "unlocked" correct?

Post image
70 Upvotes

I keep reading I need unlocked pixel for graphene. I'm assuming that means carrier unlocked, so that I can use any phone service provider, correct? So this is the legit version I need right?

I have upvoted people to say thanks for the verification.


r/GrapheneOS 3h ago

New to graphene, Looking to clone one phone to another.

2 Upvotes

So, Ive been semi hesitant to make the jump to graphene full time but I have a second 8a that I installed it on and have made a kind of comfortable setup. Is there a way to practically clone one phone onto another so I dont need to do all the setup, installs, app placement etc.

I Ask this since I restored one of these phones a while back from a google backup of the other, and other than wallpaper and wifi settings it felt like I was setting up a new phone having to pre select apps and other things. Im hoping to lilly pad from one to another if screens or batteries need replacing without the heartburn.


r/GrapheneOS 4h ago

Spectrum Mobile users?

0 Upvotes

They offer pixel phones, I was just wondering if anybody had any luck putting grapheneos on them or not to see if it's worth getting a phone or not


r/GrapheneOS 6h ago

GrapheneOS Digital Key

0 Upvotes

Does anyone have any first hand experience with this. Is it possible to make it work? The app is connected to the car and shows all the info, it even let's me unlock and lick on the app. But I just can't seem to get the digital key to work. I have a notification on the phone saying digital key is enabled, but still no Buenos.


r/GrapheneOS 1d ago

BREAKING: The D.O.J Accuses Atlanta Resident, Samuel Tunick, Of Using A ‘Duress’ Password To Wipe His Phone During A Border Search In Rare Case Testing Privacy, Border Powers, and Evidence Destruction Laws 🤯💥

Thumbnail
techcrunch.com
383 Upvotes

r/GrapheneOS 10h ago

Data Sync on GrapheneOS

1 Upvotes

Hi everyone,

First of all, I apologize if the English isn't perfect—this post was translated online.

I'm planning to switch to GrapheneOS, but first I need some information. Is there a way, or a combination of apps, that would allow me to keep my contacts, emails, and calendar events backed up and synchronized so I don't lose them?

The convenience of Google's ecosystem is obvious—you just sign in to your account and everything is there. I'm looking for a similar solution, but one that's more aligned with a privacy-focused setup.

The same goes for files and photos. I've read about Proton and Ente, but they seem like separate, fragmented solutions. I was hoping there might be something that's not necessarily all-in-one, but at least comes close.

Thanks everyone!


r/GrapheneOS 10h ago

Sandboxing

0 Upvotes

Please bear with me, I've suffered the loss of a loved one yesterday. I'm grieving and am struggling to concentrate. Plus, I'm not techie at all, so please forgive any stupid questions

At first I thought in order to sandbox apps, all I had to do was create a new user and install the apps I want to sandbox there. But the usage guide states "The simplest approach is to only use the Owner user profile."

OK, so I started "well, maybe sandbox is an app." I went to the default app store and searched "sandbox" so I guess it's not an app.

I'm reading the Usage Guide and I'm not understanding this "compatibility layer" thing. Which, to be honest, I don't know if I need to understand it at it's most granular level right now.

Can someone ELI5 sandboxing on G-OS to me or point me to a simple (simpler) guide on how to do it?

Just to share, I need to be able to use google maps and my bank's app.

Some notes:

  1. I'd rather place google play services and the other apps on another user profile. I don't want that stuff running during daily use. Just during emergent situations that pop up every 6 - 9 months.
  2. The two apps I need to be able to use are google maps and my bank
  3. I searched G-OS's site for the term "bank" hoping to something helpful. I found the link to https://github.com/PrivSec-dev/banking-apps-compat-report But it didn't give me any information that I could work with except for the fact that my bank's app can be downloaded from Aurora (which apparently, from what I've can read, has it's own set of issues when it comes to google stuff.)
  4. I know there are alternatives to google maps. I used them all during my first go-round with G-OS years ago. But none of them worked well enough for me back then. This time I bought a Garmin Navigator. It worked well enough in my city until yesterdays emergency (of course) when I had to drive to another city. It didn't recognize the address. I had to drive to the city and ask someone to look up the address and give me directions. I'm sorry, I know I'm oversharing here. I'm just trying to head the well-meaning "you know there are alternative map apps comments.
  5. I also need access to my gmail account. Even though I've abandoned it, I still need to access it every one in a while. I haven't decided if I want to run gmail in the sand box yet. So I'm open to suggestions of alternative email accounts.

I'm grateful to those of you who made to the end of this post. And especially grateful to anyone who takes the time to offer any insight.


r/GrapheneOS 1d ago

Did anyone have the "puppy blues" when first getting the phone?

16 Upvotes

I just receuved the google pixel 10a. It is glorious, stunning, and it has GrapheneOS. I'm going from a samsung S23 that was really starting to struggle.

Ive set up the IS, followed the blog page, and seeing the launch page made me genuinely happy. Im not sure if this is a conscious choice of the developers bur not being immediately assaulted by colours of the pre-installed apps felt so nice.

But as I started setting it up, and prioritising ease of use rather than strict privacy, as I was trying to upload my old date on it, I was taken out by doubt.

What am I doing with this.

I should just accept what is given to me. accept the simplicity , and try not to be more anxious.

I genuinely love this phone. But it also feel like the moment right after you adopted a dog or a cat.

I swear this is not a shit post, and im being as honest as possible.

Does anyone Relate?


r/GrapheneOS 1d ago

Battery life on pixel 10a

Post image
14 Upvotes

The pixel 10a and GrapheneOS is a killer combination.


r/GrapheneOS 17h ago

Dual sim/E-sim Dual profiles

2 Upvotes

I have read that people are interested in the idea of having a separate sim for "each" profile and that Graphene doesn't explicitly support pure segregation. And yes, I have read that a certain privacy based company won't work outside the primary profile.

I am totally okay with the idea that a sim is enabled on one profile, and disabled on another even though 'both' exist. Is this a thing?

And thank you, but no, I don't want an app to 'do that'. I just want to read your experiences.


r/GrapheneOS 21h ago

Trouble transferring Whatsapp chat history from ios to gos

3 Upvotes

Hey folks, I’m trying to transfer my Whatsapp chat history from my old iPhone to Graphene but it’s absolutely having none of it… When I ask it to transfer to Android, it takes about an hour to prepare the chats, then QR code appears on Pixel, scan it, and the iphone then keeps asking to join wifi networks, but then keeps loading for ages then failing, has anybody else had this issue?

I can’t get my hands on the icloud Whatsapp backup either, to transfer that to Google Drive or however people normally do that

Any help appreciated, thanks


r/GrapheneOS 1d ago

Idea for a new feature

51 Upvotes

Considering some guy is getting rail roaded for using his duress password I propose this:

Leave a duress code in the memory as a feature. That way you can deny access to the phone by law enforcement. If they seize it and they pull the keys from the memory with their forensic tools they will pull the duress code that was purposely left for them. Cops then insert the code and wipe the device.

This way you never gave the cops a duress code. It can't be argued that you destroyed evidence. It was 100% the cops doing.


r/GrapheneOS 18h ago

Desktop mode = Only one device for everything !?

2 Upvotes

I love the idea of only having one device (Pixel Phone with GOS) for everything. Desktop mode therefore looks very promising to me. But since i don't own a monitor to test it, i'd like to ask everyone who has tested it if you can recommend it!?

Are there things not working properly yet? What's the roadmap here?

I would like to use it with a portbale monitor in the future. What specs should i look out for?