Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Android has USB data and a large number of USB drivers available including while locked.

Android has USB data and a large number of USB drivers available including while locked.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
29 Indlæg 12 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • snosrapkungfu@mastodon.socialS snosrapkungfu@mastodon.social

    @AndyGravesGrimeSoul @GrapheneOS I think making use of tech like pam duress whereby one can enter a 'trash everything' pin instead of the normal pin, on the lockscreen has mileage. not sure if anyone's tried that with graphene.

    grapheneos@grapheneos.socialG This user is from outside of this forum
    grapheneos@grapheneos.socialG This user is from outside of this forum
    grapheneos@grapheneos.social
    wrote sidst redigeret af
    #19

    @snosrapkungfu @AndyGravesGrimeSoul GrapheneOS has a duress PIN/password feature:

    https://grapheneos.org/features#duress

    It can be entered anywhere the PIN/password is requested by the OS across every profile on the device. It can also be entered as a 2nd factor fingerprint PIN which is another feature added by GrapheneOS.

    It near instantly wipes key material needed to derive key encryption keys. It can't be bypassed by imaging and restoring SSD data due to secure element and hardware keystore integration.

    andygravesgrimesoul@mastodon.socialA 1 Reply Last reply
    0
    • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

      @snosrapkungfu @AndyGravesGrimeSoul GrapheneOS has a duress PIN/password feature:

      https://grapheneos.org/features#duress

      It can be entered anywhere the PIN/password is requested by the OS across every profile on the device. It can also be entered as a 2nd factor fingerprint PIN which is another feature added by GrapheneOS.

      It near instantly wipes key material needed to derive key encryption keys. It can't be bypassed by imaging and restoring SSD data due to secure element and hardware keystore integration.

      andygravesgrimesoul@mastodon.socialA This user is from outside of this forum
      andygravesgrimesoul@mastodon.socialA This user is from outside of this forum
      andygravesgrimesoul@mastodon.social
      wrote sidst redigeret af
      #20

      @GrapheneOS @snosrapkungfu just curious, could GrapheneOS ever get Argon2id for the KDF? I know it's be no small task but it'd be amazing somewhere down the road.

      1 Reply Last reply
      0
      • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

        @UninterestedNerd @AndyGravesGrimeSoul Setting it to Off disables USB including charging in the regular OS boot mode.

        It will still charge in the special OS boot modes: charging, recovery, fastbootd and rescue. Charging mode is what boots when you plug the device into a charger while it's turned off and shows the battery percentage on the screen.

        It can also still charge while powered off and in the firmware boot modes: fastboot mode and boot ROM recovery mode.

        It can't brick the device.

        uninterestednerd@mastodon.socialU This user is from outside of this forum
        uninterestednerd@mastodon.socialU This user is from outside of this forum
        uninterestednerd@mastodon.social
        wrote sidst redigeret af
        #21

        @GrapheneOS @AndyGravesGrimeSoul thanks for the clarification, I didn't know about all those different modes it could charge in. The off setting has a string that mentions charging the device while powered off, I forgot to mention that.

        1 Reply Last reply
        0
        • andygravesgrimesoul@mastodon.socialA andygravesgrimesoul@mastodon.social

          @GrapheneOS I have a question that might not have an answer, in terms of offense and defense in this context, do you think one will eventually gain a mostly permanent lead? Or will it always be a game of cat and mouse?

          A This user is from outside of this forum
          A This user is from outside of this forum
          a53bdb@mastodon.social
          wrote sidst redigeret af
          #22

          @AndyGravesGrimeSoul @GrapheneOS

          When the Cellebrite Premium support matrix is leaked in 2024, they can only exploit a specific version of GrapheneOS that is released in 2022. When it’s leaked again in 2025, they had no progress. And GrapheneOS has internal access to support matrix, it is said that it still has no progress.

          https://discuss.grapheneos.org/d/27698-new-cellebrite-capability-obtained-in-teams-meeting/

          https://discuss.grapheneos.org/d/20968-grapheneos-still-not-vulnerable-to-cellebrite-device-exploitation-as-of-feb-2025/

          https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation/

          grapheneos@grapheneos.socialG 1 Reply Last reply
          0
          • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

            @AndyGravesGrimeSoul Yes, wireless charging still works with the USB-C port mode set to Off. Setting it to charging-only provides most of the security value but we decided to offer the ability to fully disable it in case there are ever USB-PD vulnerabilities in the USB controller. USB-PD is a secondary form of limited data which could be used to exploit the USB controller itself, turn on USB data and then reach the remaining attack surface for USB in the kernel despite drivers being off.

            mancube@pnw.zoneM This user is from outside of this forum
            mancube@pnw.zoneM This user is from outside of this forum
            mancube@pnw.zone
            wrote sidst redigeret af
            #23

            @GrapheneOS
            could this become a tile like WiFi, location, hotspot etc? it'd be nice to be able to toggle USB settings more easily than digging for it in menus

            the couple times a month that I drive and want to use android auto I have to go digging 😥
            @AndyGravesGrimeSoul

            xav@fosstodon.orgX 1 Reply Last reply
            0
            • A a53bdb@mastodon.social

              @AndyGravesGrimeSoul @GrapheneOS

              When the Cellebrite Premium support matrix is leaked in 2024, they can only exploit a specific version of GrapheneOS that is released in 2022. When it’s leaked again in 2025, they had no progress. And GrapheneOS has internal access to support matrix, it is said that it still has no progress.

              https://discuss.grapheneos.org/d/27698-new-cellebrite-capability-obtained-in-teams-meeting/

              https://discuss.grapheneos.org/d/20968-grapheneos-still-not-vulnerable-to-cellebrite-device-exploitation-as-of-feb-2025/

              https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation/

              grapheneos@grapheneos.socialG This user is from outside of this forum
              grapheneos@grapheneos.socialG This user is from outside of this forum
              grapheneos@grapheneos.social
              wrote sidst redigeret af
              #24

              @a53bdb @AndyGravesGrimeSoul Note they lost their ability to extract data from GrapheneOS devices when provided with the PIN/password in late 2024. It took months for the documentation to be updated to clarify the capability had been lost for newer versions. We don't expect that to remain the case since the attack surface for an unlocked device where they can use developer options including Android Debug Bridge is massive.

              1 Reply Last reply
              0
              • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                Android has USB data and a large number of USB drivers available including while locked. Plug in a mouse, keyboard, external drive or other USB accessory and you'll see that's the case. When Android says charging-only, it means not allowing file transfer.

                gael_rostang@mastodon.socialG This user is from outside of this forum
                gael_rostang@mastodon.socialG This user is from outside of this forum
                gael_rostang@mastodon.social
                wrote sidst redigeret af
                #25

                @GrapheneOS
                ❌️ charging only
                ✅️ charging mostly

                1 Reply Last reply
                0
                • mancube@pnw.zoneM mancube@pnw.zone

                  @GrapheneOS
                  could this become a tile like WiFi, location, hotspot etc? it'd be nice to be able to toggle USB settings more easily than digging for it in menus

                  the couple times a month that I drive and want to use android auto I have to go digging 😥
                  @AndyGravesGrimeSoul

                  xav@fosstodon.orgX This user is from outside of this forum
                  xav@fosstodon.orgX This user is from outside of this forum
                  xav@fosstodon.org
                  wrote sidst redigeret af
                  #26

                  @mancube @GrapheneOS @AndyGravesGrimeSoul yes an USB mode tile is a nice idea

                  1 Reply Last reply
                  0
                  • andromxda@infosec.spaceA This user is from outside of this forum
                    andromxda@infosec.spaceA This user is from outside of this forum
                    andromxda@infosec.space
                    wrote sidst redigeret af
                    #27

                    @c_th1 Yes, this disables all data transfer capabilities in the USB controller. Unless you're worried about forensics companies somehow exploiting the firmware of the USB controller itself, which is unlikely, but not impossible, considering that some companies seem to specifically hire people with knowledge and understanding of the USB protocol/hardware, as well as GrapheneOS.

                    https://grapheneos.social/@GrapheneOS/117005499941456851

                    If you're really worried about these kinds of things, you can disable USB completely and use wireless charging to charge your device. Or you can at least disable USB completely when you're at an airport, or crossing a border.

                    polixgen@cyberfurz.socialP 1 Reply Last reply
                    0
                    • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                      Exploiting Linux kernel USB vulnerabilities is how exploit tools from Cellebrite and other companies extract data from Android devices in practice. They also exploit firmware bugs in other boot modes but we convinced Google to eliminate most of that attack surface for Pixels.

                      L This user is from outside of this forum
                      L This user is from outside of this forum
                      libreovergratis@mastodon.social
                      wrote sidst redigeret af
                      #28

                      @GrapheneOS
                      "but we convinced Google to eliminate most of that attack surface for Pixels."

                      Do you mean to say, someone on the GrapheneOS team reached out to someone at Google, and asked them to fix a known backdoor actively exploited by law enforcement, and google just complied?

                      This seems like a completely out of character move for Google.

                      Why would they help the GOS foundation in any way?

                      1 Reply Last reply
                      0
                      • andromxda@infosec.spaceA andromxda@infosec.space

                        @c_th1 Yes, this disables all data transfer capabilities in the USB controller. Unless you're worried about forensics companies somehow exploiting the firmware of the USB controller itself, which is unlikely, but not impossible, considering that some companies seem to specifically hire people with knowledge and understanding of the USB protocol/hardware, as well as GrapheneOS.

                        https://grapheneos.social/@GrapheneOS/117005499941456851

                        If you're really worried about these kinds of things, you can disable USB completely and use wireless charging to charge your device. Or you can at least disable USB completely when you're at an airport, or crossing a border.

                        polixgen@cyberfurz.socialP This user is from outside of this forum
                        polixgen@cyberfurz.socialP This user is from outside of this forum
                        polixgen@cyberfurz.social
                        wrote sidst redigeret af
                        #29

                        isn't shutting down or restarting the phone safer option?

                        1 Reply Last reply
                        0
                        • pelle@veganism.socialP pelle@veganism.social shared this topic
                        Svar
                        • Svar som emne
                        Login for at svare
                        • Ældste til nyeste
                        • Nyeste til ældste
                        • Most Votes


                        • Log ind

                        • Har du ikke en konto? Tilmeld

                        • Login or register to search.
                        Powered by NodeBB Contributors
                        Graciously hosted by data.coop
                        • First post
                          Last post
                        0
                        • Hjem
                        • Seneste
                        • Etiketter
                        • Populære
                        • Verden
                        • Bruger
                        • Grupper