For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.
GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.
On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.
If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.
You can just take a picture of a pile of dice, a pile of rice, or a tree, patch of grass, etc, and compute a secure hash/whatever and base six it to get the rolls.
Are you saying to take a hash of a picture and convert that to base 6 for your dice rolls to plug into a word list for creating a passphrase?
Is that actually better (in practice, not in terms of entropy) than /dev/urandom? I have a lot less trust in my ability to successfully scrub a picture from my phone that deterministically created my passphrase.
If you're concerned about that, you can concat your JPEG with a few bytes from /dev/random and you'll get the security of whichever is stronger. In practice none of this will be your weakest link.
Count the bubbels with your fingers while you count from 0 to 9. Every x fingers you write down the number.
Extra points if you hold you face really close and count in a dead language. You can also make ordered hand gestures in stead of counting on your fingers. Be a wizard about it!
is there a comparison? i would assume depending on the limits you set yourself while playing scrabble (min 5letter words, selected for beauty) this can be alleviated
I just wonder whether that could be too annoying for Android Auto / Car Play. But to be fair wireless is an option.
The other downside I guess is that a thief would just plug a USB drive in to disable device tracking. But they could just wrap the damn thing in foil so dunno if that should matter.
It's either that, or maintain a database of trusted USB devices...which seems iffy, at best.
And by that I mean, using the database itself is simple. But when it exists, then a list of targets for an attacker to emulate also exists.
Those boys at Cellebrite aren't dummies, at all, and they've been doing this stuff for quite a long time. They're a formidable opponent.
We used to use their kit to clone personal data between very different devices back in the dumb phone days. They were the only ones to get it right out of a sea of others that were also evaluated.
I should mention: Cellebrite's methods would tend to walk completely around whatever the phone thought was a normal, good idea.
When the usual manufacturer-prescribed method for reading contacts said to take some long-winded steps to put the phone into a special mode, Cellebrite's hardware just usually skipped that shit and read the data very directly without any fuss.
Plug it in, push the button, and the Cellebrite box just did the appropriate magic. It then interpreted the data and munged it into a useful form to shove into the next phone.
After that: The recovered personal data was pushed right up into the ass of the next phone with the same lack of consent. It was succinct and brutal in operation.
And: It worked. It was so dead-nuts simple that a cell phone salesperson could run it with ease. I stopped getting phone calls from the field about transfer problems when we started using Cellebrite kit.
Nothing else did this stuff with that measure of resolute nonchalance.
So at this point they've been uniquely hooning with cell phones for decades. It's kind of their schtick.
If we can speculate that something like the the USB-C charge rate negotiation on a given phone can open a pathway into the system, then it can be safe to say that Cellebrite is already using that method to get things done -- and that a person at the border can exploit it even if they're "not a tech person".
> And by that I mean, using the database itself is simple. But when it exists, then a list of targets for an attacker to emulate also exists.
Recognize USB devices by serial numbers, not the manufacturer ID. Even if they could get their hands on the serial number of my car stereo, that's going to be after the same warrant delay this thing protects against.
Is that because it cannot know your computer without you telling it every time, or is it just Android providing that default and not having a way to change that default?
People believed the reboot feature last time GrapheneOS was mentioned. It is of course nonsense.
Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.
To add an extra layer of safety. Bring a secondary phone when travelling by airplanes, especially to other countries. You should also use it frequently, maybe with some side apps to make it look like it's your daily phone.
Or, just don't bring a phone if you're particularly vulnerable. What are they going to do? Deny you entry because you don't carry a phone? If we're really at that point, where merely not having some item is suspicious, we're in deep shit.
It's standard for many multinationals and universities to provide blank secondary devices for travel to China that are synchronized with data after getting past the border. They are then erased after one gets back, because Chinese intelligence has broken into hotel rooms and installed keyloggers before.
Adding the USA to the list of countries where this is done would increase costs but it wouldn't be some nightmarish unprecedented problem.
Not bringing a phone looks suspicious, though. Maybe they will ask you to open all of your suitcases and such, which is annoying at least. Since they just want to do their job, better give them an excuse to wrap up quickly and go to the next one.
The internet exists and can transfer your data with no customs and borders, so if you are at risk of being snatched, the correct choice is to not carry a phone (or laptop, or..) at all.
“The Great Firewall operates by checking transmission control protocol (TCP) packets for keywords or sensitive words. If the keywords or sensitive words appear in the TCP packets, access will be closed. If one link is closed, more links from the same machine will be blocked by the Great Firewall. The effect includes: limiting access to foreign information sources, blocking popular foreign websites and mobile apps, and requiring foreign companies to adapt to domestic regulations. Due to the Great Firewall, China has one of the lowest cross-border internet traffic rates in the world. Usage of foreign apps in China is minuscule; Asia Society estimated in 2026 that foreign apps blocked by the Great Firewall have extremely low traffic, particularly compared to domestic apps; the top five domestic apps saw traffic that was 1,000 times more than the top five foreign apps.”
Last time I tried it (which was quite a while ago, but I'd be surprised if they became less restrictive) ssh was fine for interactive use, but they did some sort of traffic analysis to kill connections that got used for tunneling other traffic like that.
When I was there last year, it took some doing to get a VPN working. Mullvad was pretty good but it would take a few tries to find an endpoint I could connect to. The simplest escape hatch is to have a cellular connection from another country, but that's either expensive or slow.
Despite all the nonsense that's posted about UK on the internet, British agencies do require a warrant to enter your home. TSA on the other hand does not require a court order to confiscate and mirror your device before giving it back to you.
Edit: Just to be perfectly clear - Border Force in the UK can do the exact same thing to you once you return, British citizen or not. Leaving your device at home is still the safest choice.
I mean in a broad sense if you read any news about the UK it might looks like a dystopian surveillance state where you get arrested for criticising the king(I kid you not - I've had multiple American coworkers ask me if this is true).
And yes, UK has some awful laws around this. Yes it has put people in jail just for planning a protest before. Yes you can go to jail for not disclosing your passwords. But what you read on the internet is almost laughably out of proportion - no, you won't get arrested for posting a meme about the king.
FWIW the same applies to flying in the U.S. as long as you're not a person that the government cares about. I haven't had any issues with either TSA or CBP since 2011 (when, apparently, being multiracial with facial hair made me look Middle-Eastern and looking Middle-Eastern is a cardinal sin at U.S. ports of entry). Neither has anyone I've observed at the airport, and that's thousands of people per flight, and I fly about 3-4 times per year. There's plenty of stories on the Internet, and I don't doubt the stories are true, but the Internet can easily make a 1-in-a-million occurrence happen every day (indeed, given the sheer numbers, a 1 in a million occurrence does happen every day, it's just that it's unlikely to happen to you).
Before they had a chance of protest. After months of discussing the planned protest in details and getting a green light from the Met Police: https://www.bbc.co.uk/news/uk-65542558
It's not like Republicans in the UK are a violent group, unlike far right coddled by the same Met police.
You've missed my point entirely, by a country mile.
Someone above asked me how it was nonsense. I responded that people parotting the point about getting arrested for criticising the king is nonsense - like for instance, my American coworkers asking if that's true, because they read it somewhere on the internet. That is nonsense.
If you want to argue with this point please do, but also please observe the rest of my comment and especially the parts that I haven't actually said.
Before they had a chance of protest. After months of discussing the planned protest in details and getting a green light from the Met Police: https://www.bbc.co.uk/news/uk-65542558
I'm aware you are still going to twist what I said to prove your point, but I really don't fancy repeating the exact same point for the third time just so you can say something unrelated.
They already said you can get in trouble for [planning] protesting. They said you won't get in trouble for online criticism. Your links about protests aren't proving anything.
>> Someone above asked me how it was nonsense. I responded that people parotting the point about getting arrested for criticising the king is nonsense
Protesting against the king is criticising the king IMO. I didn't see his quantifier, since I would agree that online critique of the king in particular is not yet penalised.
Not surprising you're implying bad faith though, if we're splitting the hair this thin.
(and this specific planning of the protest was so heavy handed, because it belong to one of the two naughty protests, environmental. The second naughty one is protesting against the genocide. The rest is okay)
It's in the original comment you responded to, and it's a critical part of the conversation chain.
"And yes, UK has some awful laws around this. Yes it has put people in jail just for planning a protest before. Yes you can go to jail for not disclosing your passwords. But what you read on the internet is almost laughably out of proportion - no, you won't get arrested for posting a meme about the king."
I'm not saying bad faith, I'm saying you misread their argument pretty badly.
Your citations support the problems they already admitted. The hair was split before you got here because they're distinguishing in-person and online actions.
Yes, and no one mentioned parroting the king in this thread. Journalists under known observation from the state, which the UK does arrest from time to time, were mentioned however.
You can use other European countries like The Netherlands, which is a lawless police state with a liberal cover, as well.
GrapheneOS is critical infrastructure. Questioning it is not like criticizing Neovim. People can get detained, killed and more.
Perhaps the reflexive genius downvoters can explain what happened to Richard Medhurst? After his phone was snatched and the authorities pretended not to be able to decrypt it, he went on a GrapheneOS promotion spree on X and wanted to write a book about computer security.
Now he has disappeared for nearly 6 weeks. How many more people do you want to get in trouble with your false promises?
This seems specific to GrapheneOS (unique as far as I know though I'd be happy to learn otherwise) where you could set a very long first unlock passphrase and have a shorter less cumbersome fingerprint plus pin option for subsequent unlocks. I wouldn't want to have to enter a long passphrase every time I unlock but once a day isn't so bad.
I don't run GrapheneOS, but I have an >15 character passphrase that must be used before biometrics can be used after reboot. I haven't used a 4-digit pin since the option to not use it was available.
The specific extra that grapheneOS adds is that you can have a required Fingerprint + PIN with a shorter easier to enter pin while also having a long first unlock passcode. Only a first unlock passcode then biometrics is not secure in the US if your device is in the AFU/biometric-only (after first unlock) state because you can be easily and legally compelled to provide a biometric unlock.
The option was there in Cyanogenmod back during the OnePlus One days. It was such a step backwards when it was removed. You almost had to wonder if it was deliberately done at the request of some TLA to prevent users from using too strong of a password for decryption.
Yes, in fact on GrapheneOS it's less necessary and it's only necessary if you don't want to rely on the secure element rate limiting.
GrapheneOS allows using a passphrase with more convenience because of the fingerprint plus second factor pin (I don't think you can just have a pin as a secondary unlock). You don't need to enter the passphrase every time you unlock with this setup, only when first starting up.
>> then a fingerprint with a second factor pin as the secondary unlock
Unless you have a 4 or 4XL which are pretty popular with graphene os users. The weird thing is the 4 and 4XL are the only models without fingerprint because Google was pushing its #D Face Unlock System at the time.
The funny part is Graphene by default now disables face unlock on newer Pixel models.
GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.
On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.
If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.
[1] https://strongphrase.net give memorable ones which is cool.