• Sources: GrapheneOS forum post, Android rate limiting documentation, HN 49055169
  • Summary: The project account posted a consolidated account of what stops forensic extraction from a locked device, stated in numbers rather than claims. It states that Android 16 QPR2 requires a secure element implementing ramping rate limits, 4 hours of delay after 10 failed attempts and 41 days after 15, with only 20 attempts allowed and the most recent 5 unique failures rejected early so repeated typos do not consume the budget, and that GrapheneOS supports only devices implementing that generation. The secure element also carries insider attack resistance: the Owner user must authenticate before secure element firmware can be updated, so a valid signing key and a higher version number alone cannot be used to coerce away the rate limit. GrapheneOS raises the password character limit from 16 to 128 to allow diceware passphrases that do not depend on that rate limiting, adds an optional second-factor fingerprint PIN, and cuts allowed fingerprint attempts from 20 to 5. It blocks new USB connections in software and hardware while locked and disables USB data once no connection is active. Its locked-device auto-reboot timer shipped in June 2021, is settable between 10 minutes and 72 hours, now defaults to 18 hours, and returns the device to Before First Unlock through memory zeroing. The post also states a Motorola Mobility partnership will end the Pixel-only hardware requirement in 2027.
  • Why it matters: The post names the specific secure element generation and attempt budgets that decide whether a locked phone resists extraction, which is what a threat model needs instead of a vendor assurance.
  • Follow-up: Watch for the Motorola Mobility devices named and for whether the Android 16 QPR2 secure element requirement appears outside Pixel hardware.

send feedback on this story