Hot Take How to setup a completely unbreakable phone?

General Security Discussions
15 Replies 1,732 Views

Studynxx

Level 9
Verified
Well-known
I've read about certain people rooting their phone to install some Linux distro specifically designed for smartphones and apparently they're untraceable and unbreakable, as in you can't trace them and you can't break into them through biometrics/PIN/etc

Is this possible to do? Sort of how apparently BitLocker Pre-Boot PIN still doesn't have an exploit, at least I've read and asked about it on here and the Internet and nobody has yet broken BitLocker if there's TPM+PinProtector
 
The best-known Android phone for security is either a Pixel or a Pixel with GrapheneOS, for example:


Not because it is "untraceable" or "unbreakable," but because the phones are harder to break into. Enforcement/"spyware" tools like Cellebrite sometimes advertise taking a few months behind the latest updates before being able to use 0-day exploits "unknown" to Google to break into BFU phones. In contrast, these tools advertise being able to break into other phones right away.

For PC, yes, I have the same understanding: these enforcement tools still can't break Windows + TPM + preboot/security key. The reason seems easy to understand: if you can't get the TPM to release the secret to unlock the BitLocker encryption key, the protected randomly generated 128/256-bit AES key cannot be broken.
 
apparently they're untraceable and unbreakable
Nothing is ever going to be 'untraceable' or 'unbreakable'.

There is only best practice and guides which you can use i.e. Pixel with GrapheneOS with 64 character PIN with Signal installed or Apple iPhone in lock-down mode with Signal installed.

The problem is if you lose control over your phone you have basically lost the war. There may not be a unlock exploit/vulnerability now but in 5 or 10 years there may be new research and exploits.
 
Not because it is "untraceable" or "unbreakable," but because the phones (Pixels) are harder to break into.
Indeed.
Enforcement/"spyware" tools like Cellebrite sometimes advertise taking a few months behind the latest updates before being able to use 0-day exploits "unknown" to Google to break into BFU phones. In contrast, these tools advertise being able to break into other phones right away.
Except there are plenty of tools that have no problem penetrating phone security, regardless of phone brand or model. Israeli companies are famous for their ability to hack any phone, but there are plenty of others, both private companies and governments, that can do the same.

Anyone can become a target.
 
Last edited:
I've read about certain people rooting their phone to install some Linux distro specifically designed for smartphones and apparently they're untraceable and unbreakable, as in you can't trace them and you can't break into them through biometrics/PIN/etc

Is this possible to do? Sort of how apparently BitLocker Pre-Boot PIN still doesn't have an exploit, at least I've read and asked about it on here and the Internet and nobody has yet broken BitLocker if there's TPM+PinProtector
I don't know about "untraceable" or "unbreakable." It all depends upon what the definition of those used within the context of whatever discussion(s) you saw.

Did you not grab the infos on the OS that is installed?



Any concerns about BitLocker started years ago via FOSS types spreading FUD and tinfoil hat paranoid extremists spreading even more FUD about Microsoft planting a backdoor into Windows to break BitLocker and how Microsoft will cooperate with the U.S. Government. So the answer was TrueCrypt until that project imploded, and then VeraCrypt which still exists.

Lots of spontaneous paranoid hysteria amongst the hoomans.
 
I don't know about "untraceable" or "unbreakable." It all depends upon what the definition of those used within the context of whatever discussion(s) you saw.

Did you not grab the infos on the OS that is installed?



Any concerns about BitLocker started years ago via FOSS types spreading FUD and tinfoil hat paranoid extremists spreading even more FUD about Microsoft planting a backdoor into Windows to break BitLocker and how Microsoft will cooperate with the U.S. Government. So the answer was TrueCrypt until that project imploded, and then VeraCrypt which still exists.

Lots of spontaneous paranoid hysteria amongst the hoomans.
Maybe "they" haven't gone away, maybe they just got better at hidding?
 
Rumor has it the TrueCrypt author/dev got arrested and was given a very large sentence. Hence the message on the TrueCrypt website advising people to switch to BitLocker when it shutdown.
Does not surprise me. Lots of people within FOSS are fringe rebels intent upon making global society unstable and criminals of various kinds. Not to mention creepy and bizarre.

Volumes of conspiracy drivel came out of the project and comments about the project. It was peak social media.
 
Does not surprise me. Lots of people within FOSS are fringe rebels intent upon making global society unstable and criminals of various kinds. Not to mention creepy and bizarre.

Volumes of conspiracy drivel came out of the project and comments about the project. It was peak social media.
Do you feel like he was rightfully persecuted, arrested and prosecuted? What's wrong with TrueCrypt and VeraCrypt? I don't want anybody, not even the government, to have access to my data.
 
Do you feel like he was rightfully persecuted, arrested and prosecuted? What's wrong with TrueCrypt and VeraCrypt?
Do you know why he was prosecuted, convicted, and sentenced to prison? It was not because he created TrueCrypt.

I don't want anybody, not even the government, to have access to my data.
In most nations, it does not matter what you want. Most any government can legally access your data or compel you to provide your data against your will under specific circumstances.
 
Rumor has it the TrueCrypt author/dev got arrested and was given a very large sentence. Hence the message on the TrueCrypt website advising people to switch to BitLocker when it shutdown.

Just wanted to jump in and debunk a common myth about why TrueCrypt disappeared back in 2014. A lot of people think it vanished because one of the developers was arrested, but that story doesn't really hold up.

For one, the TrueCrypt devs were basically ghosts, we never knew who they were.

What probably happened is that people are confusing the TrueCrypt story with the much crazier story of Paul Le Roux. Le Roux created E4M, the software that TrueCrypt was forked from. This guy wasn't just a coder, he was a real-life crime lord involved in everything from drug running to contract killings. He was arrested in 2012 and eventually got 25 years in prison.

Because TrueCrypt was based on his code, the two stories got tangled over time. So yeah, a developer connected to the code's origin was arrested, but that was long before the TrueCrypt project itself abruptly ended.

Do you feel like he was rightfully persecuted, arrested and prosecuted?

As mentioned above...
 
Just wanted to jump in and debunk a common myth about why TrueCrypt disappeared back in 2014. A lot of people think it vanished because one of the developers was arrested, but that story doesn't really hold up.

For one, the TrueCrypt devs were basically ghosts, we never knew who they were.

What probably happened is that people are confusing the TrueCrypt story with the much crazier story of Paul Le Roux. Le Roux created E4M, the software that TrueCrypt was forked from. This guy wasn't just a coder, he was a real-life crime lord involved in everything from drug running to contract killings. He was arrested in 2012 and eventually got 25 years in prison.

Because TrueCrypt was based on his code, the two stories got tangled over time. So yeah, a developer connected to the code's origin was arrested, but that was long before the TrueCrypt project itself abruptly ended.
A criminal that creates a software to "Protect the people from the government."

"I am being righteous and self-righteous because I believe that I am not a criminal, that the governments are unfairly persecuting me, and all the government's laws are unfair, oppressive, and wrong. Power to the People! If any of you want a kilo of cocaina, you can contact me at 'Jimmy from Juarez's Place' or hit me on Telegram @druglord. Make sure you VPN through Tor."
 
Because TrueCrypt was based on his code, the two stories got tangled over time. So yeah, a developer connected to the code's origin was arrested, but that was long before the TrueCrypt project itself abruptly ended.
Thanks, this is reading like an interesting real-life novel. The Wikipedia article says this:
According to Matthew Green, a computer science professor at the Johns Hopkins Information Security Institute and leader of the TrueCrypt audit in 2014, TrueCrypt "was written by anonymous folks; it could have been Paul Le Roux writing under an assumed name, or it could have been someone completely different."
The article also makes it sound like the reason for the development stoppage is a legal dispute.
Hafner sent a cease-and-desist letter to an email address associated with the TrueCrypt developers. The TrueCrypt Team immediately stopped development and distribution of TrueCrypt, which they announced on Usenet.[4][14] Team member David Tesařík stated that Le Roux informed the team that there was a legal dispute between himself and SecurStar, and that he had received legal advice not to comment on the case.
The question why TrueCrypt could continue with another version, and how VeraCrypt was able to fork from it, because of the dispute, wasn't answered?
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top