How GrapheneOS Blocks Data Extraction from Locked Devices
GrapheneOS protections against data extraction from locked devices

I explain the specific security measures GrapheneOS implements to prevent unauthorized data extraction from locked devices. These protections go beyond standard Android features, ensuring that even if a device is physically compromised, sensitive user data remains inaccessible without proper authentication. The focus is on hardening the system against forensic attacks and maintaining privacy through robust encryption and strict access controls.
The goal is to ensure that no amount of physical access to a locked device can bypass the encryption protecting your data.
- rzk
I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password.
On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.
[1] A US man is being prosecuted after allegedly using a GrapheneOS duress PIN to wipe his Pixel during a border search – https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...
[2] A Journalist had his mobile phone seized. Did using GrapheneOS protect his data? – https://www.computerweekly.com/feature/Journalist-Richard-Me...
- prmoustache
What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf of my plane tickets, take the plane and cross the border with a smartphone with very little but real personal data they already know and be able to provide my PIN/password to law enforcement if they ask for it, abiding with law if such a law exist (which is the case in my home country), than using a duress and risk prosecution.
Sure that doesn't protect your data from any other attack vector but it allows you to travel with less risk of getting detained by law enforcement of a country you are visiting. You get asked your password, you can give it, and they see a phone that is used like a dumbphone. If you get questioned for that a simple "my phone died yesterday, a friend just gave me his old pixel". If you need more stuff/information during your travel you would basically only need to remember the passphrase to access a password manager or a remote ssh server but you can restore only the stuff you need when travelling and and wipe again at any moment.
Having said that maybe it is better to set this up some way but not have it builtin so that law enforcement doesn […]
- muyuu
There was some comment here somewhere arguing that 16 characters for a password is too little, but that he used the pattern lock. Looks like it was deleted.
Anyway. The pattern lock in Android provides Log2(389112) =~ 18.57 bits of entropy. This is less than 3 random characters, or 4 lowercase letters, or a decimal PIN digit password of 6 characters.
Granted, you could use mnemonics for long passwords, but how convenient is to input those long passwords?
I wonder why don't they just allow for longer passwords and just use a hash digest when it's too long, rather than just disallowing people from using strong passwords that they will remember. This pushes people to reuse passwords, send them to themselves, and other bad practices.
- usern20260720
although it is wonderful to know that there exists a piece of hardware in the world that is not conspiring against its users, the outcome of entering a duress password should be indistinguishable to the user that grabs hold of the mobile phone. The duress password should wipe off the real user account information but present the kidnappers with a full-fledged operating system populated with real-looking content to entertain the police officers with polite meaningless e-mails saying things like
> > On Apr 11, 2015, at 5:45 PM, Jim Steyer Hey John, > > > > We know you're a true master of cuisine and we have appreciated that for > years ... > > > > But walnut sauce for the pasta? Mary, plz tell us the straight story, > was the sauce actually very tasty? > > > > > Jim
- CommanderData
Here's an idea: soft duress PIN that wipes a list of apps of your choice however doesn't make it obvious it's done so.
Or restores app data to a restore point of your choosing making it seem like everything is fine.
- saidnooneever
if you get searched by a law enforcement officer and then proceed to quicky destroy the pocket contents you can be assured to raise suspicion. this was a stupid thing to do by the person in question regardless of laws or device properties or privacy stuff.
if you move the example from a phone and encryption to something more mundane you can see that this is not a smart move and you will most likely face penalties or atleast a bad time with enormous amount of questions and further poking at you.
it was already pretty much impossible to get an encrypted device past US Customs more than 15 years ago.
even though that is not a good thing, people should know this by now. just use a less suspicious device or OS and likely they wont even bother to search it... Better to avoid than to try and cure.
- ddtaylor
Does anyone know if the Motorola partnership is still on with GrapheneOS or how long until a phone is made available from them?
- t1234s
I always leave my phone and laptop off when going through TSA or Passport Control. I don't think in the US you an be compelled into giving up your password. They are free to confiscate the device but with it powered down good luck trying to break the password.