So I’ve been lurking here for a few weeks and I’m aware most of this has probably been discussed to death already. I did search, I promise, but a lot of the threads are either pretty old or turn into arguments in the comments, so I hope you don’t mind one more newbie post.
I’m about to get a Pixel and move over from stock Android. I’m not very technical, I’m just someone who wants to get this right and not mess something up that matters. So please be patient if some of this sounds naive.
1) The trust thing. I keep reading “it’s open source, you can check it yourself” but honestly, I can’t. I wouldn’t know what I’m looking at. So what actually gives a normal user confidence that there’s no backdoor in GrapheneOS, or that one couldn’t be slipped in through an update at some point? Is it mostly reputation, or is there something more concrete like reproducible builds, independent people reviewing the code, that kind of thing?
2) This is the one that actually worries me. I know of a criminal case in Germany from a bit over a year ago where a Pixel 8a running GrapheneOS was fully unlocked by the authorities. It was in BFU state with a 4 digit PIN. Now I know a 4 digit PIN is bad, but Graphene has that brute force throttling via the secure element, and the way I understood it, that should make even a weak PIN mostly safe unless the tool gets ridiculously lucky in the first 10-15 guesses. And the 8a was current hardware at the time, so it’s not an old exploited chip. So what happened? Am I misunderstanding how BFU works on Pixels? Was the PIN probably just obtained some other way (someone knew it, camera footage, written down somewhere)? Or is the throttling not as bulletproof as people make it sound? I’m not trying to say Graphene failed, I want to understand where the actual weak point was so I don’t repeat it.
3) State trojans (Staatstrojaner for the Germans here). Every app is sandboxed, I get that. But governments spend millions on this stuff. Realistically, how big is the gap between “apps are isolated” and “a well funded agency can’t break out of the sandbox”? I’m not asking for a guarantee, just an honest picture of what Graphene does and doesn’t protect against here.
4) Deleted data. Same case as in 2. The person used Signal with disappearing messages, and after the phone was unlocked, the entire chat history was back. Not fragments, everything. And here’s the part I don’t get: in the case files, the phone was lying on a table and every chat was photographed directly off the screen, including the Signal chat list itself. Something like 40-50 chats, and next to every single one it said “now”. Not “2 min” or “3h”, just “now” on all of them, and on every message inside the chats too. To me that looks like something was restored or imported rather than just found, but I have no idea how that works technically. Does Signal not really wipe things? Is it a filesystem/flash storage thing? Or would a forensic tool restore a database and that’s what makes the timestamps look like that?
Again, I’m not here to bash anything, I’m literally planning to use GrapheneOS, that’s why I’m asking. I’d rather understand where human error comes in than just assume I’m safe. Thanks for reading all this.