TLDR: Drug dealers in Catalonia have started to adopt GrapheneOS en masse leading to Catalan police suspecting anyone with a Google Pixel is a drug dealer

  • @besselj@lemmy.ca
    link
    fedilink
    English
    114 days ago

    They’re mad they can’t use cellbrite to snoop on properly configured GOS phones and that they actually have to do real police work to catch drug dealers

    • @boonhet@sopuli.xyz
      link
      fedilink
      English
      114 days ago

      Yes. They (cellebrite) don’t mention GrapheneOS support very loudly because it’s poor. They can’t decrypt one that’s BFU (Before First Unlock), not even by brute force if it’s a 6 digit passcode apparently. Don’t know if they can get data from an AFU GOS pixel. A year ago when their internal docs leaked, they also had no support for latest iOS at the time, but had brute force support for older versions as long as phone itself wasn’t too new and had AFU access without brute force for even older versions.

      Moral of the story: if there’s a chance police might take your phone to investigate for a crime you hopefully didn’t even commit, shut down your phone completely - the 5x power button trick on iOS disables biometric unlock, but the device itself stays decrypted and thus more vulnerable. Also keep your OS up to date.

      If you’ve got a phone that’s neither iOS nor GrapheneOS, it’s probably pretty much Swiss cheese anyway. IOS isn’t as good as GrapheneOS either, but it offers some protection against Cellebrite if up to date and BFU. But if they keep your phone for long enough (months, years), they’ll get it unlocked because you can’t install updates that would patch any newly discovered vulnerabilities and one day they’ll find a BFU unlock for it, probably.

        • AmbiguousProps
          link
          fedilink
          English
          114 days ago

          Yep, disabling it entirely allows for charging when the device is off, but otherwise, it is functionally useless and is disabled at the hardware level.

      • @Zetta@mander.xyz
        link
        fedilink
        English
        1
        edit-2
        14 days ago

        Graphene OS in particular comes with a default feature enabled called Auto Reboot to protect against this. I think it’s set to 18 hours by default because that’s what mine is, but you can go as low as 4 hours.

        If you have it set to four hours, I’d wager your phone would reset way before the pigs had enough time to try and get their way in.

        • @sugar_in_your_tea@sh.itjust.works
          link
          fedilink
          English
          113 days ago

          Yeah, I have mine at 4 hours and it’s pretty good. It triggers while I’m at work sometimes, but other than that, it’s mostly just when I sleep.