▲ 397 ▼ Why the NSA Is Right About Periodically Restarting Your Smartphone (gizmodo.com) submitted 2 years ago by VITecNet@programming.dev to c/technology@lemmy.world 102 comments fedilink hide all child comments
[–] impure9435@kbin.run 43 points 2 years ago (3 children) GrapheneOS has a convenient auto-reboot feature permalink fedilink source hideshow 6 child comments replies: [–] CaptKoala@lemmy.ml 7 points 2 years ago (1 child) TIL, I use GOS and never thought to look, I just see a banner saying there's been updates and I've got "update and restart now", "schedule restart" and "I'll restart myself when ready" (or some such). permalink fedilink source parent hideshow 2 child comments replies: [–] impure9435@kbin.run 23 points 2 years ago (1 child) The main purpose of this is actually security. Because when the device is in BFU (before first unlock) state, it's much harder to gain access to the data (without the correct unlock credentials). During the reboot, the encryption keys are wiped from RAM, making it essentially impossible to access the device, since brute-force unlock attempts are prohibited by Weaver API, which is enforced by the Titan M2 hardware security module. You can read more about this at https://grapheneos.org/faq#encryption permalink fedilink source parent hideshow 2 child comments replies: [–] CaptKoala@lemmy.ml 2 points 2 years ago (1 child) I will give that a read. I have been unintentionally using this feature, anytime I expect I won't use the GOS pixel for a bit I restart it, I've also found it disables biometrics as a security measure. Cool stuff. permalink fedilink source parent hideshow 2 child comments replies: [–] impure9435@kbin.run 9 points 2 years ago (1 child) It doesn't intentionally disable biometrics. Disabling biometrics is just a logical consequence of wiping the encryption keys from RAM. Your data is encrypted with your password as the key (not exactly, it first goes through a key derivation function, but the PIN/password is the entry point for the KDF). Your biometric information can't decrypt your data, as your data is not encrypted with your biometric information as the key. When using biometrics, the encryption key is kept in RAM, and the biometric data is only validated by the OS. No actual decryption occurs here. The data on your phone is only being decrypted during the first unlock after a reboot. That's why security states are grouped into BFU (before first unlock) and AFU (after first unlock). permalink fedilink source parent hideshow 2 child comments replies: [–] CaptKoala@lemmy.ml 4 points 2 years ago Thank you for your in depth explanation, hope your comments help many others on top of myself. permalink fedilink source parent [–] lemmyingly@lemm.ee 4 points 2 years ago Samsung has had the auto reboot feature for a long time too. Samsung - auto-restart permalink fedilink source parent [–] ComradePedro@lemmy.ml 3 points 2 years ago This! Actually a great feature on GrapheneOS, been using it for over a year now. permalink fedilink source parent
[–] CaptKoala@lemmy.ml 7 points 2 years ago (1 child) TIL, I use GOS and never thought to look, I just see a banner saying there's been updates and I've got "update and restart now", "schedule restart" and "I'll restart myself when ready" (or some such). permalink fedilink source parent hideshow 2 child comments replies: [–] impure9435@kbin.run 23 points 2 years ago (1 child) The main purpose of this is actually security. Because when the device is in BFU (before first unlock) state, it's much harder to gain access to the data (without the correct unlock credentials). During the reboot, the encryption keys are wiped from RAM, making it essentially impossible to access the device, since brute-force unlock attempts are prohibited by Weaver API, which is enforced by the Titan M2 hardware security module. You can read more about this at https://grapheneos.org/faq#encryption permalink fedilink source parent hideshow 2 child comments replies: [–] CaptKoala@lemmy.ml 2 points 2 years ago (1 child) I will give that a read. I have been unintentionally using this feature, anytime I expect I won't use the GOS pixel for a bit I restart it, I've also found it disables biometrics as a security measure. Cool stuff. permalink fedilink source parent hideshow 2 child comments replies: [–] impure9435@kbin.run 9 points 2 years ago (1 child) It doesn't intentionally disable biometrics. Disabling biometrics is just a logical consequence of wiping the encryption keys from RAM. Your data is encrypted with your password as the key (not exactly, it first goes through a key derivation function, but the PIN/password is the entry point for the KDF). Your biometric information can't decrypt your data, as your data is not encrypted with your biometric information as the key. When using biometrics, the encryption key is kept in RAM, and the biometric data is only validated by the OS. No actual decryption occurs here. The data on your phone is only being decrypted during the first unlock after a reboot. That's why security states are grouped into BFU (before first unlock) and AFU (after first unlock). permalink fedilink source parent hideshow 2 child comments replies: [–] CaptKoala@lemmy.ml 4 points 2 years ago Thank you for your in depth explanation, hope your comments help many others on top of myself. permalink fedilink source parent
[–] impure9435@kbin.run 23 points 2 years ago (1 child) The main purpose of this is actually security. Because when the device is in BFU (before first unlock) state, it's much harder to gain access to the data (without the correct unlock credentials). During the reboot, the encryption keys are wiped from RAM, making it essentially impossible to access the device, since brute-force unlock attempts are prohibited by Weaver API, which is enforced by the Titan M2 hardware security module. You can read more about this at https://grapheneos.org/faq#encryption permalink fedilink source parent hideshow 2 child comments replies: [–] CaptKoala@lemmy.ml 2 points 2 years ago (1 child) I will give that a read. I have been unintentionally using this feature, anytime I expect I won't use the GOS pixel for a bit I restart it, I've also found it disables biometrics as a security measure. Cool stuff. permalink fedilink source parent hideshow 2 child comments replies: [–] impure9435@kbin.run 9 points 2 years ago (1 child) It doesn't intentionally disable biometrics. Disabling biometrics is just a logical consequence of wiping the encryption keys from RAM. Your data is encrypted with your password as the key (not exactly, it first goes through a key derivation function, but the PIN/password is the entry point for the KDF). Your biometric information can't decrypt your data, as your data is not encrypted with your biometric information as the key. When using biometrics, the encryption key is kept in RAM, and the biometric data is only validated by the OS. No actual decryption occurs here. The data on your phone is only being decrypted during the first unlock after a reboot. That's why security states are grouped into BFU (before first unlock) and AFU (after first unlock). permalink fedilink source parent hideshow 2 child comments replies: [–] CaptKoala@lemmy.ml 4 points 2 years ago Thank you for your in depth explanation, hope your comments help many others on top of myself. permalink fedilink source parent
[–] CaptKoala@lemmy.ml 2 points 2 years ago (1 child) I will give that a read. I have been unintentionally using this feature, anytime I expect I won't use the GOS pixel for a bit I restart it, I've also found it disables biometrics as a security measure. Cool stuff. permalink fedilink source parent hideshow 2 child comments replies: [–] impure9435@kbin.run 9 points 2 years ago (1 child) It doesn't intentionally disable biometrics. Disabling biometrics is just a logical consequence of wiping the encryption keys from RAM. Your data is encrypted with your password as the key (not exactly, it first goes through a key derivation function, but the PIN/password is the entry point for the KDF). Your biometric information can't decrypt your data, as your data is not encrypted with your biometric information as the key. When using biometrics, the encryption key is kept in RAM, and the biometric data is only validated by the OS. No actual decryption occurs here. The data on your phone is only being decrypted during the first unlock after a reboot. That's why security states are grouped into BFU (before first unlock) and AFU (after first unlock). permalink fedilink source parent hideshow 2 child comments replies: [–] CaptKoala@lemmy.ml 4 points 2 years ago Thank you for your in depth explanation, hope your comments help many others on top of myself. permalink fedilink source parent
[–] impure9435@kbin.run 9 points 2 years ago (1 child) It doesn't intentionally disable biometrics. Disabling biometrics is just a logical consequence of wiping the encryption keys from RAM. Your data is encrypted with your password as the key (not exactly, it first goes through a key derivation function, but the PIN/password is the entry point for the KDF). Your biometric information can't decrypt your data, as your data is not encrypted with your biometric information as the key. When using biometrics, the encryption key is kept in RAM, and the biometric data is only validated by the OS. No actual decryption occurs here. The data on your phone is only being decrypted during the first unlock after a reboot. That's why security states are grouped into BFU (before first unlock) and AFU (after first unlock). permalink fedilink source parent hideshow 2 child comments replies: [–] CaptKoala@lemmy.ml 4 points 2 years ago Thank you for your in depth explanation, hope your comments help many others on top of myself. permalink fedilink source parent
[–] CaptKoala@lemmy.ml 4 points 2 years ago Thank you for your in depth explanation, hope your comments help many others on top of myself. permalink fedilink source parent
[–] lemmyingly@lemm.ee 4 points 2 years ago Samsung has had the auto reboot feature for a long time too. Samsung - auto-restart permalink fedilink source parent
[–] ComradePedro@lemmy.ml 3 points 2 years ago This! Actually a great feature on GrapheneOS, been using it for over a year now. permalink fedilink source parent