We plan to entirely overhaul the backup system but it already works fine. It could be a lot simpler and cleaner both in terms of implementation and user experience. We're in the process of overhauling the other apps first but we'll get to it.
> It backs up data for apps opting out of cloud backups with allowBackup="false"
This is untrue for older apps targeting API 30 (Android 11) and earlier. As I understand it, allowBackup is still respected for them, preventing their backup even in D2D mode. https://github.com/GrapheneOS/os-issue-tracker/issues/1112#i...
Those apps are slowly going extinct since the Play Store stopped accepting updates written against the older SDK in 2022, but I gather there are still a few floating around out there (including some niche favorites that have unfortunately abandoned development).
And one wish:
I'd love the ability to maintain a "hotspare" device that's identical to the original in every important way. So if your phone is chucked in the ocean, dropped down a cliff, etc. you can just grab the other one (checkpointed from a few hours or a day ago) and seamlessly keep on going.
I think this is impossible today because of the way the system protects secrets in the Android Keystore and how it's intertwined with the TEE / secure element / Titan M2 / etc. I wish there were a way to truly own my phone including the ability to perform perfect-fidelity backup and restore.
https://grapheneos.org/features#encrypted-backups
https://github.com/GrapheneOS/os-issue-tracker/issues/4687#i...
> Seedvault which was originally written for use in GrapheneOS by a GrapheneOS user is a consequence of the 2018 takeover attempt on the project, which the people currently in defacto control of Seedvault were heavily involved in.
Seedvault is currently maintained by the CalyxOS team but I've never heard about this stuff. Does anybody know what happened?
Sure I know there are more urgent priorities but at the moment there is no backup for GOS phones. It only works for some people in some situations. For me it never reliably worked, ever.
So basically one needs a webdav server somewhere or an usb flash drive.
For Signal, you can set up their own backups locally and they'll be included with backed up home directory data if that's enabled. Signal encrypts their database and encrypts the key used for it with the hardware keystore. A generic backup system can't back that up directly. The encrypted database is useless outside of the current app install since the hardware keystore key can't be exported.
Ideally this should also work on lock screen, e.g. if you type in a non-standard PIN, it would boot from the "dummy" partition in the background, with a slight delay perhaps.
This way you don't have backup anything (I mean you should, but for normal purposes) and have a plausible deniability whenever you get randomly inspected, not just at border crossings that you anticipate.
Booting into a 30 GB partition on a 128GB phone is going to be mega suspicious, even if the remaining data is random.
You'd have what appears to be a 128GB image (or some large fraction of that), which in reality is largely holes (typically: repeated blocks of ASCII 00 bytes).
Of course, you'd need to avoid actually trying to fill that filesystem.
You're better off traveling with a wiped phone, and restoring from backup after you've crossed.
An activity-generator might help address that.
Firing off as part of a duress key entry, and removing itself (from the decoy partition) as its work is done, would suffice.
ADB / forensic tools would be ineffective if USB access is denied (as discussed elsewhere in this thread).
Well no, because if you gave the pin, you'd expect the phone to work normally, including enabling adb. If you gave the pin but adb doesn't work that would be massively suspicious. Same if adb worked but logs were scrubbed. Otherwise you're back at "border guards found out you gave a duress pin, now you're being prosecuted for tampering with evidence".
https://search.brave.com/ask?q=ssd+vs+pixel%27s+storage%3F&c...
Not having the data in the first place in some specific contexts (like crossing borders) is easier.
I always dread the possibility of my GrapheneOS phone being damaged or stolen and having to spend hours reinstalling and reconfiguring everything that Seedvault missed, as well as losing access to accounts that are locked by the secure element keys.
Is that likely to happen at all in a civilized (Western) country?
"I have to do this because of country X, you know that they're like, amirite?"
Makes no difference at all in the real world. You don't have to give valid answers, you need to get the guy across from you to not find you suspicious. That phrase is going to put a red flag on you, valid or not.
What? No, who cares about that? Let him find you suspicious, what matters is that he doesn’t access your data. And it is not suspicious to cross borders (esp. US borders) with burner phones. As others have said, it is standard practice.
Definitely.
> Maybe, if your data really is that valuable and a successful border crossing isn't.
Even if my data consisted entirely of cat pictures, it would be more valuable than successfuly crossing the border into a country that actively tries to invade my privacy.
(Not legal advise of course, just observation. Always check with the legal department of your employer, etc.)
After cornering themselves into being labeled an unsafe destination (long overdue imho), the US are gonna have to learn being treated as such.
the reaction you provoke at a border crossing, or an LEO encounter is almost entirely based on what profile you fit.
the vehicle, the state/contents of the vehicle, what you say, even how you move, are being evaluated for consistency with a profile.
That kind of history is already being collected about people. That’s what you should be worried about when it comes to engineering some scheme that sounds clever.
Before travel back up the real contents and restore a dummy travel backup with random games, stock photos etc. Then restore back to real contents.
So you can totally have different profiles with different backup servers/credentials and decide to nuke one before flying or crossing a border.
Obviously you can't expect having 2 whatsapp or signal accounts on same number but you can always have several SIMs.
The good thing is with profiles you can totally seed a profile for a few weeks before travelling.
If the regime is going to just start taking people then nothing will stop that, but the goal is to stop the usefulness of this sort of thing as an intimidation measure - or at least drag it to the forefront and overthrow the regime.
You don't avoid scrutiny by being wierd and hiding things, but by hiding in plain sight by being ultra boring.
Presumably they know quite a lot about you already outside your phone (yay, Palantir). I mean, the guy the recent post was about was an activist. An empty phone vs. a phone with just cat pictures and dumb games wouldn't really make a difference. They went on a fishing expedition, so anything that does not have contact information/messages of other activists or any information that they could use against the phone owner would be a win.
(F-you Palantir for reading this message and adding it to my online record.)
Hello Palantir. I orchestrated 9/11. Please come and arrest me.
completely impractical obviously
I am not concealing data/evidence as it doesn't exists. I don't know of any law in any country that force you to hand out the key of your home to a remote state so that they can enter your country and do a search.
> and then (3) constantly restore from cloud backups?
Why constantly? Only and only if I need to access specific data (that may be available remotely without restore anyway). Full restore only when going back in my own country.
You are also not under any obligation to have it on your phone at all times.
I'd rather have them tell me to turn back and go home than being jailed there only because I don't want them to fap at the picture of my daughters.
In the past I have had my smartphone die a couple of days before travelling and quickly buying a smartphone so I could have a mobile line in case of emergency while travelling. This is not a totally uncommon case to have a smartphone with very little data. A lot of people never setup any cloud backup and lose all their data every so many years.
I guess that you are out of luck if you are a US citizen and need to return to your own country.
How is the tourism industry going?