10 ms·
Hong Kong police can now demand phone passwords under new security rules
- vrganj 6mo agoThe horrible bastion of despotism that is China-run Hong Kong has now caught up to the rule of law utopias of enlightened thought in the US and UK.
- gruez 6mo ago>in the US and UK ??? Of all the issues with the US justice system, being compelled to disclose passwords isn't one of them. It is an issue for UK, though.
- 0x3f 6mo agoDepends, you can get NSL'd to disclose passwords. Good luck running that one up to the supreme court. And biometrics aren't as well-protected. Though, yes, in the UK it's a much more routine affair.
- gruez 6mo ago>Depends, you can get NSL'd to disclose passwords Source? Given 5th amendment protections I'm guessing this only covers snitching on others, but that's standard subpoena law. If you're issued a subpoena to produce documents on someone else (eg. a customer of yours), you can't refuse. It's called protection against "self-incrimination" for a reason.
- FpUser 6mo agoThe above probably meant a point that current democracies are increasingly sliding into the same hole as authoritarian governments. Amount on encroachment of governments and big corporations on personal freedoms and democracy in "democratic" countries is quickly becoming intolerable under a guise of safety and "save the children" mantras
- traceroute66 6mo ago> Of all the issues with the US justice system, being compelled to disclose passwords isn't one of them Under the present administration I wouldn't be surprised if for example ICE tried the $5 wrench method.
- quentindanjou 6mo ago> Of all the issues with the US justice system, being compelled to disclose passwords isn't one of them. This is not totally true. It is also a US issue: CBP has been asking for passwords (or to unlock the device) for phones and computers for more than a year now. Last year, multiple people got turned around because they disagreed with US policies and political views that differ from those of the US's current president.
- throwaway290 6mo ago> Last year, multiple people got turned around because they disagreed with US policies and political views so they were not in US technically?
- quentindanjou 6mo agoExactly, everything is in "technically" because, for example, to the best of my knowledge, JFK airport is located in the US. There are plenty of articles that actually explain that the practice is illegal, but the gov doesn't really care about its legality + there is no organization able to fight it, and even if there were, the Supreme Court would likely be in favor of the US gov. What is private life if it can be broken for no reason? What is freedom of speech if it doesn't apply to the people who don't agree with you?
- throwaway290 6mo agonot sure if you travel much but you're not legally in the country until you passed immigration > What is private life if it can be broken for no reason? What is freedom of speech if it doesn't apply to the people who don't agree with you? totally but that's a different thing a little
- NoImmatureAdHom 6mo agoYou don't have the protections of U.S. law at the border. CBP is also asking, not compelling. You don't have to give them your password. If you don't, and you're a foreigner, you may be turned away. If you're a citizen, and I remember correctly, they can seize your device for up to two days if they want. But they're not going to put you in prison for refusing like the U.K. and Hong Kong will.
- ulfw 6mo agoYou have never crossed the border into the Great US of A then
- ericd 6mo agoIt's possible to cross the border many times and not have this happen.
- john_strinlai 6mo agookay, but it is also possible to have it happen.
- vrganj 6mo agoI take it you haven't crossed the border recently?
- some_random 6mo agoFunny how it's a horrible misrepresentation slurring the honor of the United Kingdom to exaggerate the penalty of not unlocking your phone for His Majesty's Law Enforcement, but US border cops being allowed to ask foreigners for the same thing upon pain of not being allowed to enter the country (something that no one seems to care about other nations doing?) is totally the same thing.
- nerdsniper 6mo agoUpon entering the US, CBP can ask you to unlock your phone, then connect it to a little box that hacks into the phone and downloads everything. Search for "Cellebrite Universal Forensic Extraction Device (UFED)" or "Grayshift GrayKey". The border agent doesn't have to know anything about phones/computers, it's just "plug in, press button". With modern phones, they really only work if you unlock your phone before handing it to them, and they'll make you do that. If you don't unlock the phone and let them walk off with it for awhile, they'll refuse you entry into the USA and send you back. US citizens are, of course, allowed in even if they refuse, but they will confiscate a citizen's phone in exchange for a custody receipt (Form 6051-D) and they are supposed to return it to the US citizen after they break into the phone / crack the encryption. If they can't crack it, they can choose to never return the phone to the US citizen. And it can be a very stressful situation in which citizens may not know what their rights are in the moment (or can't afford to replace their phone or lose access to it because how would you even get an Uber from the airport or coordinate a pickup if you don't have a phone). You can choose to bring burner phones or make sure your phone is freshly factory reset, but if you're a non-citizen that can also be a reason to be refused entry, and if you are a citizen that can "get you on a list", leading to getting "SSSS" stamped on every boarding pass for every flight you take, in every country in the world, for the next many years. If your boarding pass gets "SSSS" written on it, you will get pulled aside by security and all your bags get individually hand-searched prior to every single flight (even transfers/connections/layovers). This will be a global thing, not limited to USA flights. Non-citizens are also sometimes asked for a list of your social media accounts and the passwords to their social media accounts. Refusing to provide your passwords can be used as a reason to refuse entry to the USA. If the USA believes you have a social media account that you failed to tell them about, that can also be a reason to refuse entry.
- gib444 6mo agoNo but .. but the constitution.. but...
- throwaway290 6mo agoin china was never a problem for police to detain you for any reason (or no reason) but HK has a different legal system
- xvector 6mo agoThis shit is why I don't visit China.
- EGreg 6mo agoThis shit is why I build platforms like Safecloud: https://community.safebots.ai/t/safecloud-governance-due-process-in-a-distributed-network/35 https://community.safebots.ai/t/safecloud-governance-due-pro...
- netsharc 6mo agoHow about the US? What I'm going to write smells of "whataboutism", but it's tragic how more and more of the world is becoming police states. Going to the USA, they want your social media accounts. Regardless of that, the border thugs can probably demand you unlock your devices or they'll detain you for weeks on end, without any repercussions, because that sort of lawlessness is government policy now.
- dmitrygr 6mo agoIn the US, not disclosing a password is explicitly protected (5th amndmnt), SCOTUS has been clear. not so for biometrics, but so for PIN/passwd
- comboy 6mo agoHaha, here's some random AI generated content: At least 225 judges have ruled in more than 700 cases that the administration's mandatory immigration detention policy likely violates the right to due process[1] The Fifth Amendment's Due Process Clause generally requires those having federal funds cut off to receive notice and an opportunity for a hearing, which was not provided in many of DOGE's spending freezes[2] (there's more but what's the point) 1. https://www.justsecurity.org/107087/tracker-litigation-legal-challenges-trump-administration/ https://www.justsecurity.org/107087/tracker-litigation-legal... 2. https://www.cbpp.org/research/federal-budget/many-trump-administration-fiscal-and-regulatory-actions-are-unlawful https://www.cbpp.org/research/federal-budget/many-trump-admi...
- 6mo ago
- tyho 6mo agoWow, what a free society! In the UK if you refuse to unlock your device you can be imprisoned indefinitely! In HK it's just one year!
- netsharc 6mo ago[flagged]
- embedding-shape 6mo agoYou're in a place called "Hacker" news, many of us hackers feel like we shouldn't be forced to unlock our private devices, not sure this is surprising.
- netsharc 6mo ago[flagged]
- embedding-shape 6mo agoHow is "against democracies" even on topic here? Parent commentator said HK is now like the UK, why it matter how much of a democracy either of the places are? And no, it isn't a "nazi bar" just because someone disagrees with you, that's not how that label should be applied. Save it for actual nazis, otherwise you're doing the rest of us a huge disservice, as when there are actual nazis, people think we're talking opinions rather than facts. As a human who despise nazis and fascists, please don't contribute to making the world worse.
- ahhhhnoooo 6mo agoI strongly disagree with the parent poster, but they are deploying a specific term. Nazi Bar doesn't imply everyone within is a Nazi. It implies a bar that permits a Nazi to stay and drink. That Nazi will come back later with their friends who are also Nazis, and over time the bar will increasingly become funded by Nazis. It's really really strange to use here, however, because this thread is about not giving in to authoritarianism. If you want to see intolerance, this person should go look at the recent transgender athletes thread. That post might actually be a "Nazi bar".
- mmsc 6mo agoAh, finally catching up to ... The UK, Australia, Ireland, France, the Netherlands, and probably a lot more.
- october8140 6mo ago[flagged]
- jonex 6mo agoFeature request: Make it default behavior on phones that you can have multiple passwords, connected to different profiles. With no way to determine how many profiles a phone have. I'm sure there's some people here working on mobile operating systems, might be worth considering?
- dachris 6mo agoVeracrypt e.g. has had this for a long time. https://en.wikipedia.org/wiki/Plausible_deniability https://en.wikipedia.org/wiki/Plausible_deniability
- hananova 6mo ago"This profile doesn't have anything on it. Give us the password for the real profile." Or even worse, you did give them the real password, but because your phone supports the feature and your profile is kind of barren, they don't believe you. Now you are in a very bad lose-lose situation.
- keiferski 6mo agoWith LLMs, it should be easier than ever to fake generate text messages, notes, emails, etc.
- hydrogen7800 6mo agoxkcd 538 https://imgs.xkcd.com/comics/security.png https://imgs.xkcd.com/comics/security.png
- idiotsecant 6mo agoSo put stuff on it, duh
- hananova 6mo ago"This isn't what we expected to find. Give us the real password."
- kleiba 6mo agoIt would be nice if phones had a feature where you can define more than one pin, but only one is for your actual phone contents - the other ones leave you to a completely harmless but otherwise indistinguishable looking smartphone interface that contains no or only completely bogus data.
- gmerc 6mo agoAlmost every chinese android variant has that. On Oppo it’s called clone system
- ulfw 6mo agoMy Oppo Find N6 allows multiple user accounts
- pavel_lishin 6mo agoIt would be nice if I didn't get beaten with a hose in a vain attempt to prove that I unlocked the "real" one.
- iamnothere 6mo agoIf your country has this problem, you’re way past worrying about phones, and you need to be acquiring arms and training.
- whatsupdog 6mo agoIt's illegal to have any decently good arms in Canada.
- iamnothere 6mo agoIf you live in a country where the police will beat you to extract a confession, it may be time to start violating the law. (To my knowledge this is not the case in Canada.)
- 6mo ago
- embedding-shape 6mo ago"Featured" on HN just a week ago, seems GrapheneOS' "Duress pin" would be very helpful in these cases: https://grapheneos.org/features#duress https://grapheneos.org/features#duress (https://news.ycombinator.com/item?id=47445931 https://news.ycombinator.com/item?id=47445931). Now we just have to wait N years for Android and iOS to get approval from the government to build something similar, that they can market yet somehow screw up enough to not actually help.
- everdrive 6mo agoNo one likes when I say this but it's really past time to stop doing anything interesting on your phone. Delete all your apps, set it as minimally as possible. Leave it home when you go for walks, and power it off when you go driving or to the store, or whatever.
- pavel_lishin 6mo agoFor many people, their phone is their primary, if not only, computing and communications device.
- everdrive 6mo agoRight, which is why they need to start changing their behavior.
- em-bee 6mo agohow? whatsapp, wechat, telegram, even signal, all require a phone to be used. if i didn't need any of those apps then sure, but unfortunately there is no way around these apps if i want to keep in touch with certain people that are important to me.
- iamnothere 6mo agoIf you “must” use those then keep a phone off in a drawer and turn it on once a day to keep in touch. If those people won’t allow you to be offline from time to time and aren’t willing to switch communication methods as an alternative, maybe it’s not a symmetrical relationship. Or use something like Beeper (works on Linux): https://www.beeper.com/ https://www.beeper.com/
- zie 6mo agoIf you need to use these, set the history retention to like no time. That would help a lot. They could still get the contents from the person you are communicating with, but it would require more work on their part. Humans are generally fairly lazy. If you can get the people you communicate iwth to also turn off message retention, that would help. Then they could tell you talked with Tootie, but not what you talked about, at least from the device(s) themselves.
- _slih 6mo agoI think everyone's glossing over that this extends to anyone who knows the password. Your sysadmin, your business partner, your spouse. Hong Kong just turned your company's entire key management chain into a legal liability.
- dev_l1x_be 6mo agoOhh no, so they caught up with US border patrol?
- deleted 6mo ago[deleted]
- 3yr-i-frew-up 6mo ago>The US is evil >China makes you give phone passwords, China makes Apple give user data >The US wiretaps 1 person "OMG THIS IS AN OUTRAGE!" We forget because a Republikan is in charge how good we have it in the west. We forget how bad it is elsewhere.
- maplant 6mo agoThe cops from the John Woo HK action flicks I've seen would love this
- firefax 6mo agoThese kinds of laws worry me since I have forgotten several old passwords. Being disorganized shouldn't be a criminal offense.
- chirau 6mo agoWhat happens if you just say "I don't know it, only answer calls on it."
- gs17 6mo agoI'd imagine that's even more suspicious if you can't tell them who does know the password, or just gets lumped in with "refused to unlock your device".
- anonymousiam 6mo agoI wonder what would happen if HK tried to force somebody to unlock their business phone. It's typically a violation of corporate policy to allow a third party to access the encrypted, confidential information on corporate mobile devices. The poor device user would be faced with a choice of losing their job and being held criminally liable for breaching their company's systems, or going to jail in Hong Kong.
- mytailorisrich 6mo agoPolice in HK will not ask you to unlock your business phone, or personal phone. They are pro-business and want to remain an attractive international business hub so they are nice to foreign visitors. Likewise China (mainland) is nice to Western visitors and will not create trouble to you. If you visit the mainland these days (visa free if coming from Europe!) they also make efforts so that you are not impacted by the Great Firewall. The way it works on the mainland and HK is that you must have shown by your actions that you are a "troublemaker" and got onto their radar. Then you are in trouble. China is keen to attract Western visitors for tourism, business, and to stay if you're top talent (visa-free travel, new work visa for STEM talent) so they will try ot project a positive image.
- nerdsniper 6mo agoThat just boils down to “you have no real rights, but if you keep your head down and dont get unlucky, you probably won’t be targeted”. I’m a white US citizen who worked on oil rigs in GCC countries (Arabian Gulf). I was put on a global watch list for 6 years due to my work in the middle east. I still don’t know why - maybe due to colleagues in my contacts? There was a “mega church” near me that some of my coworkers attended which was the “minority religion” of Saudi Arabia, so perhaps I was a few degrees of Kevin Bacon from some people that Saudi had flagged. Or maybe just travel patterns - I often didn’t know exactly when my rotation would end and I frequently bought last minute flights to head back home / to vacation destinations. I certainly was not put on a list for any of my speech (public or private), which had been extremely measured at the time (and still is), due to understanding that my host countries had different laws and constitutions from our own. I very carefully observed all the laws and social expectations. But nonetheless, I found myself on a list anyways and for that 6-7 year duration, all of my boarding passes globally got “SSSS” written on it and all my luggage + carryons got unpacked by hand and hand-searched prior to every flight, including connecting flights. Every flight I flew those searches were a very personal 20-30 minute long reminder to carefully manicure who I’m in contact with, what I say, how/where/when I travel, and any other records/data that I might generate. I often had to give a heads up to anyone I was traveling with (colleagues or personal friends) that we had to leave a little extra early to accommodate those searches.
- davidfekke 6mo agoWow, it sounds like they are becomming a bunch of commies.
- RandomGerm4n 6mo agoThat is exactly why a Duress Pin, like the one in GrapheneOS, should be standard everywhere. Ideally, it should also include an option to visibly destroy the device by overheating it, to ensure that no one can accuse you of not having actually deleted the data and keep asking for a password.