Android has USB data and a large number of USB drivers available including while locked.
-
@AndyGravesGrimeSoul @GrapheneOS yes, wireless charging works independently from USB regardless of settings. On GrapheneOS, there's an "Off" option for the USBC port that even blocks charging, so wireless would really be the only way to charge your phone while it's booted into the os.
@UninterestedNerd @AndyGravesGrimeSoul Setting it to Off disables USB including charging in the regular OS boot mode.
It will still charge in the special OS boot modes: charging, recovery, fastbootd and rescue. Charging mode is what boots when you plug the device into a charger while it's turned off and shows the battery percentage on the screen.
It can also still charge while powered off and in the firmware boot modes: fastboot mode and boot ROM recovery mode.
It can't brick the device.
-
Also I don't have an X account (anymore) and can't see your reply (nor can I enlarge the picture either).
Wonder if it switches the data from cellular or wifi over to lan automatically though.
@agowa338 You can see many of the replies at https://nitter.net/linuxuser1996/status/2086757738055389637. We wrote several responses and copy-pasted those to dozens of the replies. Most of the people who replied said they have the feature on their standard Android device when they don't. They believe the standard Android USB menu is the same thing when it isn't at all. Android Advanced Protection Mode added in Android 16 is similar to the software part of our feature but not as good and it's missing the hardware-level blocking.
-
@GrapheneOS I have a question that might not have an answer, in terms of offense and defense in this context, do you think one will eventually gain a mostly permanent lead? Or will it always be a game of cat and mouse?
@AndyGravesGrimeSoul @GrapheneOS I think making use of tech like pam duress whereby one can enter a 'trash everything' pin instead of the normal pin, on the lockscreen has mileage. not sure if anyone's tried that with graphene.
-
GrapheneOS blocks new USB connections while locked by default at both a software and hardware level. It can be enabled while unlocked too. It can even be set to fully disable USB while booted including USB-PD and other charging functionality. More info:
https://grapheneos.org/features#usb-c-port-and-pogo-pins-control
USB vulnerabilities are widely exploited. It's used against journalists, activists, dissidents and others at border crossings, protests and elsewhere. Android 16+ has opt-in protection but it's far weaker than our default and blocks installing apps from outside the Play Store.
-
@AndyGravesGrimeSoul @GrapheneOS I think making use of tech like pam duress whereby one can enter a 'trash everything' pin instead of the normal pin, on the lockscreen has mileage. not sure if anyone's tried that with graphene.
@snosrapkungfu @AndyGravesGrimeSoul GrapheneOS has a duress PIN/password feature:
https://grapheneos.org/features#duress
It can be entered anywhere the PIN/password is requested by the OS across every profile on the device. It can also be entered as a 2nd factor fingerprint PIN which is another feature added by GrapheneOS.
It near instantly wipes key material needed to derive key encryption keys. It can't be bypassed by imaging and restoring SSD data due to secure element and hardware keystore integration.
-
@snosrapkungfu @AndyGravesGrimeSoul GrapheneOS has a duress PIN/password feature:
https://grapheneos.org/features#duress
It can be entered anywhere the PIN/password is requested by the OS across every profile on the device. It can also be entered as a 2nd factor fingerprint PIN which is another feature added by GrapheneOS.
It near instantly wipes key material needed to derive key encryption keys. It can't be bypassed by imaging and restoring SSD data due to secure element and hardware keystore integration.
@GrapheneOS @snosrapkungfu just curious, could GrapheneOS ever get Argon2id for the KDF? I know it's be no small task but it'd be amazing somewhere down the road.
-
@UninterestedNerd @AndyGravesGrimeSoul Setting it to Off disables USB including charging in the regular OS boot mode.
It will still charge in the special OS boot modes: charging, recovery, fastbootd and rescue. Charging mode is what boots when you plug the device into a charger while it's turned off and shows the battery percentage on the screen.
It can also still charge while powered off and in the firmware boot modes: fastboot mode and boot ROM recovery mode.
It can't brick the device.
@GrapheneOS @AndyGravesGrimeSoul thanks for the clarification, I didn't know about all those different modes it could charge in. The off setting has a string that mentions charging the device while powered off, I forgot to mention that.
-
@GrapheneOS I have a question that might not have an answer, in terms of offense and defense in this context, do you think one will eventually gain a mostly permanent lead? Or will it always be a game of cat and mouse?
@AndyGravesGrimeSoul @GrapheneOS
When the Cellebrite Premium support matrix is leaked in 2024, they can only exploit a specific version of GrapheneOS that is released in 2022. When it’s leaked again in 2025, they had no progress. And GrapheneOS has internal access to support matrix, it is said that it still has no progress.
https://discuss.grapheneos.org/d/27698-new-cellebrite-capability-obtained-in-teams-meeting/
https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation/
-
@AndyGravesGrimeSoul Yes, wireless charging still works with the USB-C port mode set to Off. Setting it to charging-only provides most of the security value but we decided to offer the ability to fully disable it in case there are ever USB-PD vulnerabilities in the USB controller. USB-PD is a secondary form of limited data which could be used to exploit the USB controller itself, turn on USB data and then reach the remaining attack surface for USB in the kernel despite drivers being off.
@GrapheneOS
could this become a tile like WiFi, location, hotspot etc? it'd be nice to be able to toggle USB settings more easily than digging for it in menusthe couple times a month that I drive and want to use android auto I have to go digging

@AndyGravesGrimeSoul -
@AndyGravesGrimeSoul @GrapheneOS
When the Cellebrite Premium support matrix is leaked in 2024, they can only exploit a specific version of GrapheneOS that is released in 2022. When it’s leaked again in 2025, they had no progress. And GrapheneOS has internal access to support matrix, it is said that it still has no progress.
https://discuss.grapheneos.org/d/27698-new-cellebrite-capability-obtained-in-teams-meeting/
https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation/
@a53bdb @AndyGravesGrimeSoul Note they lost their ability to extract data from GrapheneOS devices when provided with the PIN/password in late 2024. It took months for the documentation to be updated to clarify the capability had been lost for newer versions. We don't expect that to remain the case since the attack surface for an unlocked device where they can use developer options including Android Debug Bridge is massive.
-
Android has USB data and a large number of USB drivers available including while locked. Plug in a mouse, keyboard, external drive or other USB accessory and you'll see that's the case. When Android says charging-only, it means not allowing file transfer.
@GrapheneOS
️ charging only
️ charging mostly -
@GrapheneOS
could this become a tile like WiFi, location, hotspot etc? it'd be nice to be able to toggle USB settings more easily than digging for it in menusthe couple times a month that I drive and want to use android auto I have to go digging

@AndyGravesGrimeSoul@mancube @GrapheneOS @AndyGravesGrimeSoul yes an USB mode tile is a nice idea
-
@c_th1 Yes, this disables all data transfer capabilities in the USB controller. Unless you're worried about forensics companies somehow exploiting the firmware of the USB controller itself, which is unlikely, but not impossible, considering that some companies seem to specifically hire people with knowledge and understanding of the USB protocol/hardware, as well as GrapheneOS.
https://grapheneos.social/@GrapheneOS/117005499941456851
If you're really worried about these kinds of things, you can disable USB completely and use wireless charging to charge your device. Or you can at least disable USB completely when you're at an airport, or crossing a border.
-
Exploiting Linux kernel USB vulnerabilities is how exploit tools from Cellebrite and other companies extract data from Android devices in practice. They also exploit firmware bugs in other boot modes but we convinced Google to eliminate most of that attack surface for Pixels.
@GrapheneOS
"but we convinced Google to eliminate most of that attack surface for Pixels."Do you mean to say, someone on the GrapheneOS team reached out to someone at Google, and asked them to fix a known backdoor actively exploited by law enforcement, and google just complied?
This seems like a completely out of character move for Google.
Why would they help the GOS foundation in any way?
-
@c_th1 Yes, this disables all data transfer capabilities in the USB controller. Unless you're worried about forensics companies somehow exploiting the firmware of the USB controller itself, which is unlikely, but not impossible, considering that some companies seem to specifically hire people with knowledge and understanding of the USB protocol/hardware, as well as GrapheneOS.
https://grapheneos.social/@GrapheneOS/117005499941456851
If you're really worried about these kinds of things, you can disable USB completely and use wireless charging to charge your device. Or you can at least disable USB completely when you're at an airport, or crossing a border.
isn't shutting down or restarting the phone safer option?
-
P pelle@veganism.social shared this topic