L
L8437

  • Joined Nov 3, 2022
  • It's not a substitute for having a strong password. The feature does a good job of disabling USB at a software and hardware level but nothing is bulletproof. USB is also not the only usable vector.

    What you can do is have a diceware passphrase as your primary unlock method, and a fingerprint + PIN combo as your secondary method. That way, you only have to enter your long passphrase after a reboot or every couple of days when it asks for it, and use fingerprint + PIN which takes no effort for daily use.

    To avoid being prompted for your passphrase when you're out and about, make a habit of unlocking your phone with it daily to reset the timer.

    Soon, we'll be providing a way to generate random PINs and diceware passphrases to make choosing a secure unlock method easier to do.

  • [deleted] the initial question was answered.

    Nobody can give an 100% correct answer on what can be done against pixel in AFU mode. Because it can change right now.

    The only 100% correct answer is make sure to always have control of the state the device is in. Use it only in AFU mode when you can make sure you are the one that can change it into BFU.

    BFU with 128 bit of random entropy pass isn't possible to decrypt without the password.