What does it actually take to stop police extracting your phone?
A stock iPhone or Android device, in the hands of a capable extraction tool, gives up nearly everything — messages, photos, location history, deleted files. The fix is not a Nokia. The fix is a Google Pixel running GrapheneOS, a free and open-source operating system hardened well beyond what shipped from the factory. It installs in an afternoon.
A friend sent me a video doing the rounds. The caption claimed NSW Police can extract every bit of information from your phone using Israeli spyware, with a quip about going back to a Nokia. It cut to Sue Higginson, the NSW Greens MLC who has spent her time in parliament pressing the state on police powers and the thin scrutiny they receive. The video was built for outrage. It worked on me, but not in the direction it intended.
What struck me was how few people know that the spyware threat is largely solvable at the device. The same class of tool that infected journalists and activists across the Pegasus Project investigations — Pegasus, built by the Israeli surveillance company NSO Group and delivered via “zero-click” exploits, meaning the phone is compromised without the owner clicking a link, opening a file, or making any mistake at all — runs into a wall against a properly configured GrapheneOS handset. Verified boot means the phone checks its own software against a known-good copy every time it starts, so tampered code simply refuses to run. The hardened memory allocator is a rewritten piece of the operating system's plumbing that closes off the exact memory-corruption tricks these exploits need to gain control in the first place. The USB-C port itself is switched off while the screen is locked, so a device plugged in by someone else — police, a thief, anyone — can't talk to the phone at all. You do not need to be a cypherpunk to run it. You need an afternoon and a strong password.
Is GrapheneOS actually military-grade?
GrapheneOS is a free, open-source Android build for Google Pixel phones, hardened for a threat model that includes state actors — built to resist not just phone thieves and dodgy apps, but governments with forensic tools and warrants. It inherits Android's verified boot and app sandboxing (the wall that stops one app reaching into another app's data) and adds a genuinely serious set of hardening features: a hardened memory allocator (closing off a whole class of bugs attackers rely on, at the source), control-flow integrity (stopping malicious code from hijacking a program while it's mid-run), PIN scrambling (the number pad shuffles every time you open the phone, so someone watching your fingers over your shoulder learns nothing), an auto-reboot that re-encrypts your data after the phone sits idle, and scoped-access permissions that let you hand an app your photos folder without handing it your entire camera and microphone too.
I use it every day. In my experience the “military-grade” label gets thrown around loosely in privacy marketing, but GrapheneOS earns it in the only way that matters — independent security researchers use it, audit it, and recommend it for threat models that include governments. The Auditor app is the clearest proof: it performs hardware-backed attestation, meaning it asks the phone's own security chip to prove, cryptographically, that the software hasn't been swapped or tampered with — even by someone who had the device in their hands for a few minutes while you weren't looking.
The trade-off is small and worth naming. You lose Google Play Services by default — the background Google software that stock Android quietly runs with deep system access, handling push notifications and location for most apps. Some apps that depend on it behave differently as a result. GrapheneOS offers a sandboxed Google Play compatibility layer for people who need those apps: the same Google services, but running as an ordinary app with no special privileges, instead of built into the operating system itself. You keep the hardening. You lose nothing that matters.
Can you harden a Windows PC the same way?
A Windows PC can be hardened to the point that a locked screen cannot be bypassed, even with physical access. BitLocker disk encryption with a pre-boot PIN, a locked-down BIOS (the software that runs before Windows even loads), and the right CPU features close the cold-boot and direct-memory-access attack paths — both are ways of pulling your encryption keys straight out of the computer's memory chips, either by forcing a fast reboot before the data fades or by plugging in a device that reads the memory directly, bypassing Windows entirely. None of it is on by default. Most of it is buried.
The baseline is local disk encryption with a pre-boot authentication layer — not the TPM-only release that ships enabled on modern Windows installs. The TPM is a small security chip built into most modern PCs that stores your encryption key; on its own, it protects against casual theft but folds under a determined attacker with physical access. The stronger configuration pairs the TPM with a PIN or password you must type before the operating system even loads, so the key never releases without something only you know. Microsoft documents the exact commands. I will walk through the full setup, with copy-paste scripts and the password-manager pattern for storing your recovery key, in the second guide in this series. I have run this exact configuration on my own machines for years — it is not theoretical.
Why be wary of Apple in Australia?
Apple's American brand is built on privacy. Apple's international brand is built on compliance. In 2017, to satisfy China's Cybersecurity Law, Apple moved Chinese users' iCloud data and the cryptographic keys to it onto servers operated by Guizhou-Cloud Big Data, a Chinese state-owned enterprise. The legal reality is straightforward: data sitting on a Chinese-owned entity's infrastructure inside China is reachable by the Chinese government under Chinese law.
The pattern repeats. Apple is a US company that complies with the laws of every jurisdiction it operates in, and it operates everywhere. The privacy marketing you see in San Francisco is real, but it is not a promise that travels. Australians buying iPhones on the strength of Apple's privacy stance are importing a brand claim that was built for a different legal system. Apple will comply with an Australian Assistance and Access Act notice the same way it complied with Beijing — quietly, under gag, because the law compels it.
Does Australia really have no Bill of Rights?
Australia is the only western democracy without a national constitutional or statutory bill of rights. We rely on common law, a handful of constitutional protections, and anti-discrimination statutes. Three states and territories — Victoria, the ACT, and Queensland — have their own human rights charters. The federal level does not. The Australian Law Reform Commission has documented this gap at length across multiple inquiries.
The practical consequence is narrow but real. When a government passes a law expanding surveillance powers or restricting movement, Australians have no domestic constitutional mechanism to test whether the measure is proportionate. Countries with a bill of rights — or the UK with its Human Rights Act incorporating the European Convention — have courts that apply a proportionality test to such laws: a legal check asking whether a restriction on people's rights actually matches the size of the problem it claims to solve, rather than just taking the government's word for it. Australia applies political scrutiny alone, which is to say hardly at all.
This matters during crises. Through COVID, Australian states issued public health orders backed by fines and, in some cases, imprisonment for breach. The UK locked down too — I am not arguing Australia was uniquely authoritarian. The difference is that British courts and the European Court of Human Rights provided a review mechanism Australians simply do not have. The argument is not that Australia was wrong to lock down. The argument is that Australians had no instrument to test whether the specific measures were proportionate, and still do not.
What does the Assistance and Access Act actually let the government do?
The Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 — TOLA, or the Assistance and Access Act — lets the Attorney-General issue notices compelling communications providers and anyone with knowledge of a computer system to assist police and security agencies in accessing data. The government frames it as a response to encryption eroding investigative capability.
The mechanism is the part that should concentrate minds. A provider served with a notice is compelled to assist, and the notice carries confidentiality restrictions — the recipient cannot disclose that they received it, what it required, or whether they complied. The Citizen Lab's body of work on NSO Group shows what happens when surveillance capabilities are deployed quietly. TOLA builds the legal architecture for that kind of quiet into Australian law, applied not to an Israeli vendor but to every technology company operating here.
The United States has its own secrecy regime — national security letters, FISA orders, the works. The difference, again, is constitutional. An American company served with a secrecy order has First Amendment grounds to challenge it in court, and has done so. An Australian company served with a TOLA notice has no equivalent recourse. We have no right to constitutional dispute. The law is the law.
What happens if you refuse to hand over your password?
Refusing to comply with an order under section 3LA of the Crimes Act 1914 carries a maximum penalty of five years imprisonment, or 300 penalty units (a fixed fine amount courts use instead of a dollar figure, adjusted periodically), or both. Where the underlying warrant relates to a serious offence or a serious terrorism offence, the maximum rises to ten years. The order is magistrate-issued, not a demand a police officer can make on the street.
The technology in this series is not about helping you refuse a lawful order. It is about giving you the sovereign choice of what you are compelled to hand over in the first place. A GrapheneOS handset, locked, with a strong password you have not written down, gives up very little even to a capable extraction tool. A BitLocked Windows machine with the keys wiped from memory is a brick. The law can compel your cooperation. The mathematics does not care about the law.
Where do you start?
Everything in this series can be set up by a layman with minimal experience, inside a day. In the age of AI, the barrier is lower still — point a camera at the screen, share the guide, and ask what comes next.
Three guides follow this post:
- How to install GrapheneOS on a Google Pixel — the full step-by-step, the only real requirement being one strong password, fingerprint for daily access, the long password reserved for the rare reboot. The passive benefits of running it, explained plainly.
- How to harden Windows against physical and state access — BitLocker with a pre-boot PIN, the password-manager pattern for your recovery key, BIOS lockdown against USB keystroke-injection attacks, and the extreme end of hardware-based encryption for those who need it.
- Choosing a password manager for sovereign key storage — Bitwarden and Proton Pass, both end-to-end encrypted and zero-knowledge, and how to use one as the single source of truth for every recovery key, seed phrase, and backup code you depend on.
The privacy technology archive collects the guides as they publish. The broader cypherpunk philosophy archive holds the argument behind them — why cryptography, not policy, is the durable answer to overreach. Start with the phone. The phone is the thing in your pocket that follows you everywhere, and it is the easiest win.





