GrapheneOS / os-issue-tracker

Issue tracker for GrapheneOS Android Open Source Project hardening work. Standalone projects like Auditor, AttestationServer and hardened_malloc have their own dedicated trackers.
https://grapheneos.org/
335 stars 18 forks source link

Device locking Power Button only on Pixel 6 does not work (5 attempts fingerprint to slow, Lockdown Button dangerous) #1308

Open Retroman445 opened 1 year ago

Retroman445 commented 1 year ago

In the past I used the on/off button only to covertly get into lockdown mode (phone off) with other phones while in my pocket. When using GrapheneOS I cannot get into lockdown mode when holding the power button, I have to select the (Lockdown) on screen button.

This is a visible action and when the phone gets confiscated and I hand it over while pressing buttons, it might be explained as purposely destroying evidence with the intent to frustrate investigations. Longpressing the powerbutton (3/5 seconds) when reaching for the phone, cannot be proven as easily, if at all. (Vibration to confirm lockdown would be awesome!)

Can engaging the lockdown mode with only the power button be enabled? Pressing the fingerprint sensor 5 times with the wrong finger is VERY slow on the Pixel 6 and locating it in my pocket is near to impossible.

"The U.S. government takes tampering with evidence very seriously. A person who is convicted of the crime under federal law may face a prison sentence of not more than 20 years, a fine, or both. (18 U.S.C. § 1519.)"

flawedworld commented 1 year ago

We could look at having a power button gesture to trigger lockdown mode, similar to how it works on iPhone.

Please note that Android's lockdown mode kind of sucks, data is not getting put to rest and it's just disabling biometrics. Ideally the phone would be powered off, be it directly by the user, or indirectly via auto reboot.

Retroman445 commented 1 year ago

We could look at having a power button gesture to trigger lockdown mode, similar to how it works on iPhone. Ideally the phone would be powered off.

That would be fantastic and if a shutdown provides better security, then by all means, go ahead.

enduring78 commented 1 year ago

Please note that Android's lockdown mode kind of sucks, data is not getting put to rest and it's just disabling biometrics. Ideally the phone would be powered off, be it directly by the user, or indirectly via auto reboot.

Why not just reboot the phone when holding the power button?

Retroman445 commented 1 year ago

Please note that Android's lockdown mode kind of sucks, data is not getting put to rest and it's just disabling biometrics. Ideally the phone would be powered off, be it directly by the user, or indirectly via auto reboot.

Why not just reboot the phone when holding the power button?

That does not work anymore. In the past phones would shutdown as I mentioned in the original post, but this is exactly what is missing. I cannot reboot or power down the phone by holding the power button.

Quote from original post: "In the past I used the on/off button only to covertly get into lockdown mode (phone off) with other phones while in my pocket."

Retroman445 commented 1 year ago

After updating to Android 13 I found out the delay for the shutdown while holding the powerbutton is 30 seconds. So it IS possible to shut the phone down. 30 seconds is a bit long though, if this would be configurable it would be perfect.

SevenFactors commented 1 year ago

After updating to Android 13 I found out the delay for the shutdown while holding the powerbutton is 30 seconds. So it IS possible to shut the phone down. 30 seconds is a bit long though, if this would be configurable it would be perfect.

Yes. This feature should become part of GOS. It would be a great improvement to privacy and security GOS already provides.

In such scenarios, 30 seconds is way too long to force-shutdown the phone. Having this configurable or reduced would be great.