Thieves are stealing iPhone pins | GrapheneOS settings and protections

  Рет қаралды 6,363

Side Of Burritos

Side Of Burritos

Күн бұрын

Пікірлер: 60
@Liberty4Ever
@Liberty4Ever Жыл бұрын
I prefer not to use biometric authentication, mostly because I don't want my biometrics used to grant access without my permission. I like the PIN scrambling feature that makes it much more difficult to decode a PIN. I no longer have muscle memory unlocking my phone, and that's a good thing. The best phone security is similar to the best personal security. Don't be drunk in public. Pay attention to your surroundings and be mindful of your security.
@sideofburritos
@sideofburritos Жыл бұрын
There are some downsides to biometric authentication. I do think for certain situations (like a public setting) it's a better option than a PIN. Paying attention to your surroundings leaves too much up to chance, IMO. With biometric authentication, you can avoid the shoulder surfing issue. There's also security cameras that could be above you watching and depending on how crowded a place is, you likely won't be able to notice everyone. At the end of the day, it comes down to your threat model. If there's a greater chance of you being mugged and forced to use your fingerprint, then a PIN would be the ideal choice.
@Liberty4Ever
@Liberty4Ever Жыл бұрын
@@sideofburritos - All great points. I suspect my threat model differs from the norm. I never go to bars, I don't live in a big city, I'm seldom out in public at places like concerts, restaurants or sporting events. I avoid crowds in general. I'm less concerned about being mugged and forced to use my fingerprint, but I've seen too many videos of corrupt cops seizing a phone and using someone's face to unlock their phone to delete video evidence, etc. I do like PIN scrambling in GrapheneOS to prevent the eye in the sky camera or a shoulder surfer from obtaining the PIN. I've been using GrapheneOS for a couple of weeks and I'm loving it. I urge others to make a donation to support the development effort.
@user-rk2sy8df4s
@user-rk2sy8df4s Жыл бұрын
Using separate profiles for banking is a good idea. Just saw a news report where an armed robber demanded a passcode.
@davidprock904
@davidprock904 Жыл бұрын
2:03 , I noticed when you put in your pin code the screen was black like it should be , but you had the taps showing which gave it away, I know its not a personal pin 12345 , but what gets me is it showed your pin pad a split second before going away, SO what IF pin Scrambling was on, it WOULD HAVE completely gave away your pin! Put the play back speed on 0.25 if you have trouble seeing it, I could just take screen shots and overlay them and there is your 'demo' pin 12345
@sideofburritos
@sideofburritos Жыл бұрын
That is a valid point. In defense of that occurring, I did manually turn on "show taps" in developer options. So this is not standard behavior if you were to do a screen recording without altering developer settings. The built-in screen recorder used to have an option to "show taps" I don't recall whether that showed taps when entering a pin or not, I don't have a device with an older OS version. It is good to note though in case anyone does a screen recording on their main device with a personal pin showing taps.
@davidprock904
@davidprock904 Жыл бұрын
@@sideofburritos play back your own video, but after the black screen went away for a half second it showed the pin pad you typed into
@sideofburritos
@sideofburritos Жыл бұрын
I understand what you're explaining, I was commenting that this would not happen in a standard setup screen recording. You would have briefly seen the keypad, but you wouldn't have seen the finger taps on the screen. Show taps was a developer option I enabled to help people see where I'm pressing on the screen.
@fabio.brunori
@fabio.brunori Жыл бұрын
Great advice. Watching this video I realized another option to protect our devices; in a supported phone is possible to use a different finger for unlock a different profile, seems a viable way instead of putting a code every time. Ps: I laugh at "Bank" app... :-)
@sideofburritos
@sideofburritos Жыл бұрын
Thanks! Ah, that's a great point as well, to use a different fingerprint for a separate user profile. Haha, thanks!
@jethroknightify
@jethroknightify Жыл бұрын
I would love to use a fingerprint, but I have a privacy screen protector installed. That has neutered the in screen reader for the Pixel 7 unfortunately. That pin scrambling feature is something I did not know about, thank you for that tip!
@sideofburritos
@sideofburritos Жыл бұрын
Try enabling settings -> Display -> 'Increase touch sensitivity', then re-add your fingerprint. It still doesn't work perfect for me, but it definitely helps with a screen protector.
@reichardkonige6905
@reichardkonige6905 Жыл бұрын
I use biometrics for my main profile (non financial secure apps). I use for samsung secure folder (finance and secure items) a long pincode, separate network settings...., My password safe keypass is also two separate files (main vs private) synced between devices with syncthing. looking to switch to grapheneOS but I worry about app compatabilty like ledger live and other crypto apps.
@dertrissel9694
@dertrissel9694 Жыл бұрын
Thanks for sharing this! I've got a question related to multiple profiles: Is there a good way to transfer files from one profile to another? Something like a shared directory? Currently I'm using one additional profile with Play Services installed, and that's also where I have the proprietary messengers like WhatsApp. Problem is that it's quite cumbersome to transfer let's say a picture to the other profile. My solutions for now is using a synchronized Syncthing folder on both profiles, which works fine but maybe you know of a better solution. PS: love your content. It's because of you that I made the switch to GrapheneOS so thank you for making privacy respecting options accessible :)
@sideofburritos
@sideofburritos Жыл бұрын
"My solutions for now is using a synchronized Syncthing folder on both profiles, which works fine but maybe you know of a better solution." That was going to be my suggestion, I'm not aware of an easier/better option. You're most welcome! That's been my goal from the beginning. I've been trying to lower the "barrier to entry” to demonstrate that anyone who wants to do it, can. I'm glad to hear that it's worked out well for you!
@Jordan-hz1wr
@Jordan-hz1wr 11 ай бұрын
Don’t forget they turn on Advanced Data Protection too. Thus permanently locking both you AND Apple put and preventing the account from ever being recovered.
@michael49789
@michael49789 Жыл бұрын
Danke!
@sideofburritos
@sideofburritos Жыл бұрын
Herzlichen Dank für Ihre Unterstützung!
@iTheGeo
@iTheGeo Жыл бұрын
As usual, good tips man... Cheers!
@sideofburritos
@sideofburritos Жыл бұрын
Glad you like them, cheers!
@_modiX
@_modiX Жыл бұрын
I'm against the advice to use biometric data to authenticate, because you can never change your biometric data. Once someone can fake your fingerprint you can never change that fact. Even if I consider GOS secure in that regard, the potential harm on a biometric leak is much greater.
@sideofburritos
@sideofburritos Жыл бұрын
I think it depends on your threat model. If you decide to just use it in a public setting and disable it after, I think that's a decent compromise. I believe there's a greater chance of someone shoulder surfing your pin code in public vs. gathering your fingerprint and faking it at a later time in that setting. But I can understand where you're coming from. For someone with a high enough threat model a password would be the best option.
@Flashbrickanimations
@Flashbrickanimations Жыл бұрын
Great video as always
@sideofburritos
@sideofburritos Жыл бұрын
Thank you!
@anonanon3066
@anonanon3066 Жыл бұрын
I completely forgot about lockdown. Super handy!
@sideofburritos
@sideofburritos Жыл бұрын
It is!
@anonanon3066
@anonanon3066 Жыл бұрын
@@sideofburritos Especially in Germany, where uniformed threat vectors are now allowed to use your on-record finger prints stored with your state id card to unlock devices.
@noomondai
@noomondai Жыл бұрын
Thanks Josh!
@UnknownUnrecognized
@UnknownUnrecognized 10 күн бұрын
So I can install google services in main profile, don't grant any privilages, then just install it in second profile and grand privilages? this way main profile is safeR?
@floydffrogfloydffrog7453
@floydffrogfloydffrog7453 Жыл бұрын
If you turn on Phone and SMS in the 2nd user profile does it access the same contacts/call history/texts that were done on the main profile? Or are they a clean slate for the 2nd profile?
@anonanon3066
@anonanon3066 Жыл бұрын
the calls list seems to be identical. contacts, i cannot say, as i sync them via a cloud provider.
@mrcvry
@mrcvry Жыл бұрын
They are separate.
@sideofburritos
@sideofburritos Жыл бұрын
What @mrcvry said. Contacts are part of the profile data which is separate per user profile - grapheneos.org/features#improved-user-profiles Turning on Phone and SMS for the second user profile will share the SMS history and call history with the secondary user.
@mikeypiontek2855
@mikeypiontek2855 Жыл бұрын
Also a good idea would be to use an alpha numeric password instead of a pin code altogether
@anonanon3066
@anonanon3066 Жыл бұрын
just like scrambled pins, they are a pain in the butt
@sideofburritos
@sideofburritos Жыл бұрын
That's true, but for my threat level and convenience it's overkill and a PITA.
@suave319
@suave319 Жыл бұрын
I wish we had something instant like a fingerprint reader but that can be rotated if it gets compromised.
@sideofburritos
@sideofburritos Жыл бұрын
That would be handy (pun intended). Some form of 2FA like a YubiKey with NFC would be useful since you could rotate it, but definitely not as seamless.
@suave319
@suave319 Жыл бұрын
​@@sideofburritos I was thinking about an NFC ring with one button which wipes the previous key and generates a new key (challenge response). If you get compromised, you just press the button -- no more ring unlock. If you pressed it accidentally, you just pair the new key to the phone. It would require modifying AOSP unlock mechanism though. I cant think of an easier, more secure solution to this.
@-someone-.
@-someone-. Жыл бұрын
Does Graphene have an option to disable cellular data, app specific? Like on Apple iOS, you can choose which apps use cellular data. I turn everything off except for signal. When I’m out and about, I don’t need anything else. I’m seriously thinking of getting the pixel, thanks to your vids on graphene! Thx👋
@sideofburritos
@sideofburritos Жыл бұрын
Not at the OS level as far as I'm aware. There is a permission toggle for "network" which would restrict all network access for an app. There are apps like NetGuard (netguard.me/) which can replicate the Apple iOS functionality you described. Nice! It can be a bit of a shock at first, especially coming from an Apple device, but I think it's worth the effort! edit: added part about getting a Pixel
@-someone-.
@-someone-. Жыл бұрын
@@sideofburritos thanks! That’s something at least, coz no calculator app, or calendar, or any number of apps should be contacting the net... I’ve been jailbreaking all my life, so my iPhone’s are pretty well locked down. You’d think it’s impossible, but there are many really powerful tweaks, like firewall ip, app firewall, Netfence etc. You get pop ups every single time an app wants to contact the net. Gets annoying at first, but if you monitor each outgoing connection, you can either block or allow... many of the attempts are like analytics, or google ads, so block those, and you never get ads on that app! Let alone waste data I never updated past iOS 13 on the majority of my devices, I don’t need any social media when I’m out and about, and Apple kept locking down their systems even more after iOS 14 👍 I’m looking forward to testing graphene out.
@rasix86
@rasix86 Жыл бұрын
one thing to think about: In some countries (e.g. Germany) the authorities can force you to give your fingerprint so they can unlock the device. The same does not apply for e.g. pin codes.
@sideofburritos
@sideofburritos Жыл бұрын
That's a fair point. That's where I like the user of “lockdown mode” so that they can't force you to use your fingerprint since the pin code is needed to re-enable it. It definitely comes down to the individual's threat model, since situations will vary greatly.
@pinoygal6232
@pinoygal6232 Жыл бұрын
Hey Burrito Guy, (sorry, don't know your name) Did you install a launcher with Graphene OS on Pixel phone?
@1albumamonth
@1albumamonth Жыл бұрын
The launcher in the video is the default AOSP launcher, which is used in GrapheneOS.
@sideofburritos
@sideofburritos Жыл бұрын
Exactly what @1albumamonth said. I stick with the default launcher that ships with GrapheneOS.
@pinoygal6232
@pinoygal6232 Жыл бұрын
@@1albumamonth I'm trying to use Articons, and I don't see AOSP listed under launcher. Does it go by another name? Maybe it isn't compatible. anyway, thanks for reply.
@hansbacker
@hansbacker Жыл бұрын
i currently only have fingerprint and a pasword. where is the option to set a pin code i cant find it...
@sideofburritos
@sideofburritos Жыл бұрын
Under security, you would have to change your "Screen lock" from password to pin to use it.
@hansbacker
@hansbacker Жыл бұрын
@@sideofburritos thanks i found it now. i wish there was an option to use both pin and password and pin could bisabled with the lockdown feature like fingerprint. so pin could be my fast/easy access which is currently fingerprint
@hansbacker
@hansbacker Жыл бұрын
that way i would extend my already long password since i would only need it very rarely. also i consider pin with the scrambling feature safer than fingerprint, but ofc a long password is the safest
@jayjoneslive
@jayjoneslive Жыл бұрын
What I just saw was "The WSJ is reporting that iPhone users are prone to hackers stealing their PIN and causing chaos. That's what you get for using an iPhone, but here's a link to do something about it. In the meantime here's what Android users should do, unless you us iOS, in which case you'll just switch to Android, learn how to ROM the device and put on GrapheneOS". The Android instructions are great to have, but iOS/iPadOS users shouldn't be left in the dark without their own clip to talk about security steps to combat this if you don't have a FaceID iPhone/iPad. I don't hate the video, I think it just may send a condescending message to people that they should be punished a little bit for having an Apple device.
@sideofburritos
@sideofburritos Жыл бұрын
Thanks for the feedback, that's a fair point. I didn't intend for it to come across that way, I just don't have an iPhone or iPad to demo with. The linked article (www.karltarvas.com/2023/02/25/protecting-your-iphone-against-shoulder-surfing-password-theft.html) is the best option at this time. My family all use iPhones, and the linked article is the same suggestion I provided to them. I also don't believe in punishing people for their device of choice, as I'm writing this from a MacBook. With a channel that is primarily Android privacy/security, my family still prefers their iPhones, and I don't fault them for that. Nor do I ever try to convince them to switch, unless they come to me asking questions first. The “preachy privacy” approach never works long term. Thanks again.
@jayjoneslive
@jayjoneslive Жыл бұрын
@@sideofburritos That makes sense. Likewise, if I had the option, I’d find a cheap Google Pixel phone and get a second Google Fi number + SIM just to have to experiment with. I just get so sick to death when people whine and complain about Apple doing something “dumb” and praising Google or Microsoft for doing it “””””””better””””””” or sooner like LTT (sometimes) or my coworkers/friends or whoever & get brutalized from hearing that. I don’t care that people absolutely love their products; my job is to be unbiased to an extent and recommend what I know works. So thank you for addressing this like I wish others would.
@jayjoneslive
@jayjoneslive Жыл бұрын
@@sideofburritos Side note to the article: I would also add investing in an iPhone screen protector that doubles as a privacy filter like from Otter Box or other companies.
@sideofburritos
@sideofburritos Жыл бұрын
I actually laughed out loud when I read this because that seems like such an obvious option. Sometimes physical problems require physical solutions, not just software setting changes. I've used privacy screens in the past and have one for my laptop, but it didn't even cross my mind for this. That would have been a great suggestion in this video. I'll have to incorporate that into a future video, thank you!
Obtainium overview | My favorite way to track Open Source apps
16:09
Side Of Burritos
Рет қаралды 28 М.
FULL reveal of what apps I use on my personal phone | GrapheneOS
10:39
Side Of Burritos
Рет қаралды 35 М.
Когда отец одевает ребёнка @JaySharon
00:16
История одного вокалиста
Рет қаралды 8 МЛН
pumpkins #shorts
00:39
Mr DegrEE
Рет қаралды 74 МЛН
Do you choose Inside Out 2 or The Amazing World of Gumball? 🤔
00:19
iPhone Mistakes That RUIN Your Privacy
10:57
All Things Secured
Рет қаралды 42 М.
003 - The Invisible Net, and Why I use GrapheneOS
25:50
The Lockdown - Practical Privacy & Security
Рет қаралды 3,1 М.
Your iPhone has a MAJOR security problem (5 tips to keep you safe)
13:18
Proper Honest Tech
Рет қаралды 720 М.
The iPhone 14
10:16
Mental Outlaw
Рет қаралды 385 М.
14 settings I changed after installing GrapheneOS
7:23
Side Of Burritos
Рет қаралды 43 М.
Considering GrapheneOS? Quick tour + useful settings
6:09
Side Of Burritos
Рет қаралды 70 М.
Your iPhone Isn't Secure - Do This Now!
9:31
Payette Forward
Рет қаралды 162 М.
GrapheneOS Profiles - Work Profiles vs User Profiles | Shelter & Insular
7:33
Когда отец одевает ребёнка @JaySharon
00:16
История одного вокалиста
Рет қаралды 8 МЛН