I’m running Graphene on a Pixel 6. I lost it and someone opened it somehow and called two of my contacts to give it back.

I’m a bit confused how this even happened. When I got the phone back, they were going through my contacts. I checked app usage stats and they went through a banking app (not missing money), maps, signal, etc.

Is there a way to figure out how they even unlocked my phone?

57 points

Gonna need to know more. What method do you use to lock your phone? Is it rooted?

Also: did they return the phone to you, or to your friend? Could it be your friend who went through these apps?

permalink
report
reply
20 points

Fingerprint and pin code. They left the phone at a store nearby and I went to pick it up

permalink
report
parent
reply
38 points
*

Odd suggestion, but do you still have their contact info? Could you ask them? 😄

You could also send them a small thank you gift and ask them with that, so not to make it seem like you’re accusing them of anything

It’s a reasonable request, you could say that you need to keep your phone secure for work, and while it was great that the stranger was able to get it to you, you’re following up on if there is some bug you need to look into


Unrelated, it might be good to set up a “If lost, call ____” type message. If you don’t have another number, email also works.

permalink
report
parent
reply
13 points

Yeah. Definitely setting that up now haha. They used my phone to call my contacts, so I don’t have their number

permalink
report
parent
reply
16 points
*

Is your pin simple? If you hold your phone up to the light can you see the smudge marks where your pin usually goes?

Do you have people set up as emergency contacts via the lock screen?

permalink
report
parent
reply
7 points

GrapheneOS also has this cool feature called Scramble PIN Layout to try and protect against guessing the pin from fingerprints on the screen.

permalink
report
parent
reply
14 points

It might have been the fingerprint sensor. They can be fooled. Mine occasionally thinks the inside of my trouser pocket looks just like my finger.

permalink
report
parent
reply
1 point
*
permalink
report
parent
reply
34 points

Was it perhaps unlocked when you lost it?

I know I’ve set my phone down unlocked a few times; particularly at work (in a warehouse).

permalink
report
reply
-8 points

Unless you have it set to never lock its not possible. All phones lock automatically after 30-60 seconds by default.

permalink
report
parent
reply
18 points

Unless a program is keeping the screen unlocked, like a YouTube video…

permalink
report
parent
reply
-9 points

Do you frequently just leave YouTube running?

permalink
report
parent
reply
34 points

This person is clearly well-intentioned, so I don’t think an exploit was the cause of your phone being unlocked. If they knew an exploit it’s likely that by now everything about you would’ve been compromised already, like you would’ve lost access to your accounts and all your money would be gone. This person probably unlocked your phone by using your pin code, so either it was a very common pin code, or something suggested here, like smudges on your screen revealing the pin code, or highly unlikely, they guessed your pin code. Anyway, it’s better safe than sorry so check if your OS’ been tampered with using the GrapheneOS auditor app. Even if it hasn’t, you should back up everything and factory reset it just to err on the side of caution. And in the future, use an 8-10 digit pin code with pin scrambling enabled.

permalink
report
reply
16 points

100%, depending on your threat model, your device has been compromised and out of your control. You have evidence that the device was unlocked. You can no longer trust the device

Probably should change your PIN too

permalink
report
parent
reply
29 points

Is your pin something like 1234? Do you have emergency contacts set up? Do you have a setting to not lock the phone until very long? Or a smart unlock based on location or any other automation setting? An easy password hint pops up or something? Perhaps your parents forgot to mention you had a twin, who face unlocked it.

Regarding app usage, my guess is they tried to see whom to contact to give your phone back, or map history, the banking app could be a touch by mistake too.

permalink
report
reply
15 points

Hey, how did you guess my secret pin!? That is a very difficult pin that I’ve had for every account for years! /s

permalink
report
parent
reply
13 points

I have that same combination on my luggage!

permalink
report
parent
reply
24 points

Do those contacts happen to be your ICE? Some phones will allow those from the emergency dialer without unlocking. Don’t know about grapheme.

permalink
report
reply
6 points

Graphene has and emergency dialer, but you can’t call my contacts from it.

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 3.9K

    Monthly active users

  • 3K

    Posts

  • 78K

    Comments