25 ms·
US citizen charged after GrapheneOS phone wipes during airport search
- dotcoma 2mo agoIn Russia? In China? In Iran? Nope, in the US.
- jcarrano 2mo agoThe problem with this feature is that the agents could realize the phone was being wiped. For the duress pin to be 100% effective, it would have to log in normally to a default install.
- I_am_tiberius 2mo agoDystopian reality. Sounds like Russia.
- nalekberov 2mo agoIt has always fascinated me, the degree to which airport staff feel so important, as if the world would stop revolving without them.
- Grimblewald 2mo agoVeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give proper password, real OS and FS decrypt and load. Something like this may need to become the standars over duress pins which should be treated as a fallback or more extreme alternative. Right now, A single choice to reasonably and rightfully protect your privacy reuslts in jail time over something which likely wouldnt have resulted in any issues if superficial compliance was observed. These goons, even if a branch of a facist regime, are ultimately burocrats with violent options to settle. They aren't doing forensics on your device etc. They have neither means nor knowledge to do so. They just need to tick their boxes. Did the phone unlock? tick. Did our spyware complain? no? tick. Overall appearance of compliance from person? yes? tick. free to go, next! You just have to find ways to stay safe without agitating their workflow and all is well. - [1] https://veracrypt.io/en/VeraCrypt%20Hidden%20Operating%20System.html https://veracrypt.io/en/VeraCrypt%20Hidden%20Operating%20Sys...
- bigfatkitten 2mo agoEven in places where you can’t be compelled to hand over a password, attempting to deceive the cops will get you thrown in prison just as reliably as destroying evidence.
- Grimblewald 2mo agotrue, but in that scenario you're going to prison either way. If you legitimately use the dummy for daily driving and hidden for sensitive work, then it's better than nothing. Obviously a good alternative is a dummy device but it carries similar risks, and the best option is to simply not go to authoritarian shitholes like the USA. Thankfully I've been able to avoid/push for US folks visiting us instead, but honestly the alternatives are as bad. Its a shit situation where most reasonable actions carry real risks, its up to individuals to choose what is acceptable risk to them, but a dummy os you use as a daily driver for inconsequential work is, to me, an ideal midground.
- AngryData 2mo agoMeanwhile cops can and do regularly deceive and lie to citizen and not only don't face any consequences but actively benefit from it.
- tripleee 2mo agoI don't really see a problem with this assuming the deception is used to uncover crimes.
- nkrisc 2mo agoWill the problem is that we’ve seen it’s not only used to uncover crimes. There’s plenty of empirical evidence of cops lying to lock up innocent people. One truly absurd case was lying to convince a man he killed his father, and extracted a murder confession for a victim who they knew wasn’t dead. https://people.com/thomas-perez-jr-murder-interrogation-11862514 https://people.com/thomas-perez-jr-murder-interrogation-1186...
- amanaplanacanal 2mo agoIf they were searching for evidence of a crime, what crime was it?
- iAMkenough 2mo agoThe crime of disagreeing with the President.
- Freedom2 2mo ago[flagged]
- iAMkenough 2mo agoDoesn't mean they won't still dump your phone and detain you as long as they can if they see a meme they don't like. They can detain you for days if you're not white. (Kavanaugh Stop)
- _carbyau_ 2mo ago> That isn't a crime in the US thanks to the first amendment. Technically correct is not the same as practically correct.
- LtWorf 2mo agoThe downvotes you get on this website for being completely correct never cease to astonish me. I'd like some filter where if a comment is downvoted by IP addresses located in USA, they are considered as upvotes.
- wildzzz 2mo agoThey claimed they were looking for CSAM. There's a border search exception to the fourth amendment that says CBP can search your phone at the border. You aren't required to give them a password (but possibly a fingerprint or facial scan) but they can temporarily sieze it (and do god knows what to it).
- Guvante 2mo agoHow are they going to prove there was evidence of a crime? While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device". Most previous court cases involving encrypted devices have required substantial proof that the encrypted device contained incriminating evidence. To be clear "you sent this illegal thing from your house" levels of evidence. It mostly seems inept, if you are going to push to expand your powers you do it on strong cases where you know what happened. Doing it on weak cases like this gives a judge an opportunity to shut down that without giving you a chance of a meaningful conviction and without that you won't get any benefits...
- gruez 2mo ago>How are they going to prove there was evidence of a crime? They don't have to, only that you destroyed evidence. That's why many people get prosecuted with "obstruction of justice" rather than the actual crime. >While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device". So if someone was doing insider trading, and the SEC came knocking, then immediately afterwards they start burning every document they have and microwaving their computers, do you think they should get off the hook? Surely you must think, even if the authorities or society can't a priori know you were guilty, the subsequent activity should be illegal? Note this isn't the same as banning burning documents or microwaving computers, only doing so after you're aware there's an ongoing investigation.
- fluidcruft 2mo agoDestroyed evidence of what?
- gruez 2mo agoDestroyed materials that might be relevant to an investigation that you know exists.
- 2mo ago
- comrade1234 2mo agoSo let them just sieze your device. Don't unlock. You'll get it back in a few months.
- teravor 2mo agomaybe write down the duress pin somewhere in your wallet. let them make their own assumptions and erase the alleged evidence on their own.
- flerchin 2mo ago[flagged]
- blitzar 2mo agoMy airport phone is full to the brim with them - I want to watch the officer to check every single one.
- ekjhgkejhgk 2mo agoWouldn't be surprised if they charge you with exposing yourself.
- sfRattan 2mo agoUltimately, when you choose to enter a duress PIN that will wipe your device, you have to recognize that choice may have legal consequences. I don't like the amount of power our government has at the national border when it comes to detaining and pressuring citizens, but our Constitution explicitly grants it at least some of the power it now exercises in that context. If your threat model includes US state actors at the national border, then your security practices need to account for the confiscation of your device at that border without requiring you to willfully wipe the phone and (in the eyes of police and prosecutors) destroy evidence. That means: 1. Don't travel with anything you can't afford to lose on device. This means setting up travel-specific password managers and hardware keys for a subset of your accounts that you absolutely need to access while abroad, and being prepared to reset those passwords and disable those hardware keys very quickly once home. 2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. Your secure setup must function without needing you to engage in those behaviors, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable. 3. Consult with a lawyer and review your security procedures from a legal standpoint. All of the above is technical and practical advice, not legal counsel and no substitute for it. We Americans are fortunate to carry powerful passports and enjoy relatively easy international travel but, for better or worse, that velvet glove covers an iron fist we would be foolish to forget or ignore.
- SubiculumCode 2mo agoNot a lawyer, but destruction of evidence would only be valid if there was first some reasonable suspicion of a crime? Is that right?
- 3eb7988a1663 2mo agoThis is my core question as well. At what point do you have to maintain property so the government can use it to testify against yourself? If I have a dash-cam, and I wipe the SD card, can the government imply that because I erased the card, it must prove that I was speeding? The dash-cam automatically over-writes old footage - perpetually destroying evidence. Given nebulous cases such as "hacking" a site by looking at the HTML[0], am I destroying evidence of crimes whenever I format my PC? I hope the government requires specific charges and more proof of a crime other than missing evidence. Say I destroy my diary - can the government claim that is the key evidence where I confessed to being the gunman on the grassy knoll? [0] https://news.ycombinator.com/item?id=28992667 https://news.ycombinator.com/item?id=28992667
- ChrisArchitect 2mo ago[dupe] Discussion: https://news.ycombinator.com/item?id=49024436 https://news.ycombinator.com/item?id=49024436
- drweevil 2mo agoWhile I like the idea behind GrapheneOS, I'd rather not place myself in jeopardy of some ridiculous charge like this one. I prefer to travel with a travel device, some inexpensive phone and/or laptop that contains nothing interesting. If they then wish to take it from me because I won't unlock it, then have at it! That said, the situation with respect to our Bill of Rights at the border has gotten ridiculous.
- crooked-v 2mo agoThe "duress PIN that nigh guarantees destruction of evidence charges" functionality is extremely stupid, but otherwise GrapheneOS on a flagship phone is your best bet for an Android phone that can't be cracked by low-effort attempts, government or otherwise.
- Cider9986 2mo agoDuress pin is an optional feature not recommended for use unless you're being coerced and have advice from legal professionals. It's a small part of the protection of the OS. Perfectly secure without it. More: https://discuss.grapheneos.org/d/40700-grapheneos-protections-against-data-extraction-from-locked-devices/ https://discuss.grapheneos.org/d/40700-grapheneos-protection...
- deleted 2mo ago[deleted]
- incompatible 2mo agoOne of the GrapheneOS people (I think) suggested keeping a bit of paper in your wallet with the duress pin, perhaps thinly disguised. Then the cops could try it on their own initiative. I suppose they'd become aware of that trick eventually, but then they wouldn't be able to use all those other genuine pins they find.
- Verdex 2mo agoThis is an interesting idea, but was that GrapheneOS person a lawyer giving legal advice?
- morkalork 2mo agoNo, he wasn't, what is your point?
- zarzavat 2mo agoIt's possible that could be destruction of evidence as well. Why should it matter whose meat sticks type in the decoy pin?
- MetaWhirledPeas 2mo agoBecause one is a clear intent to mislead while the other has plausible deniability. "It was there in case of robbery."
- mattstir 2mo agoThe prosecution would argue that you ought to have warned officers about the duress pin since this wasn't a robbery scenario.
- make3 2mo agoIt's harder for them to argue you were actively destroying evidence; you could say that you had written the wipe pin there for a legitimate use case like both your wallet and your phone get stolen
- MikeNotThePope 2mo agoThere needs to be a simple feature to wipe your phone and then restore to a point and time. That’d be really convenient.
- manwe150 2mo agoSeems like a good court argument too—no destruction of data was even attempted because I know I have my iCloud or Google backup. Personally, my phone has access credentials to information, but not the information itself. So you need a serious warrant before you can get those access, but the data is there.
- intrasight 2mo agoI agree that it seems a simple argument for any competent lawyer to make that the phone isn't the "gold copy". The phone is just an ephemeral copy of the real data which is safely stored away in the cloud, and the authorities can request access to with the proper warrants. Of course this argument will only work if the phone is indeed and a ephemeral copy of your real data.
- AnimalMuppet 2mo agoHonest question: Does a wipe just wipe what's on the phone, or does it also tell the cloud to delete stuff?
- crypttales 2mo ago"When he finally provided a passcode, the phone appeared to restart. The defense motion states that "the screen went blank, flashed several times, and the phone appeared to restart," resulting in the loss of data." I dont use grapheneOS, but it seems he activated a self-destruct code after being arrested. That's always been illegal, and computers don't change that: Arthur Andersen LLP v. United States (2005) On the surface this case sides with evidence destruction, except "Chief Justice Rehnquist noted that routine document management is not inherently corrupt; to be a felony, the government must prove the defendant had a "consciousness of wrongdoing" and a specific intent to obstruct a known or imminent proceeding" [1] He fellow obviously had a consciousness of wrongdoing since he purposely set the delete triggers off during a police interrogation! [1] https://www.oyez.org/cases/2004/04-368 https://www.oyez.org/cases/2004/04-368
- anduril22 2mo agoAs a citizen the safest way is to just refuse. They can’t refuse entry. Not the same for LPRs.
- idontwantthis 2mo agoAlso not a good idea if you are a citizen with non-citizen family. I assume at this point that anything on my record will come back to haunt them.
- siilats 2mo agoHaving just gone through having to give pin to cbp you just need the apps on your phones to have separate pins so when police unlocks it, they cannot unlock WhatsApp afterwards. Faceid or unique pin. Problem is your phone pin overwrites Face ID
- DanHulton 2mo agoIf your threat model means you can’t afford for border security to view your device, wipe the damn thing yourself before crossing the border and restore it from an encrypted online backup on the other side. You’re just carrying a blank phone that you intend to set up and use later, and they can’t force you to install your backup onto a phone. Now, this is sus as hell, and you’ll probably draw all kinds of extra attention, but if border security wants access to your phone in the first place, you’re already in a weird place.
- intrasight 2mo agoThose who thought that a duress pin was a good idea for border crossing are probably going to choose this alternative. It doesn't have to be blank - just clean.
- krunck 2mo agoUnless you are an activist who is being targeted by a government. A "clean" OS can still have incriminating "evidence" planted on it.
- deleted 2mo ago[deleted]
- bobthepanda 2mo agothis isn't even that weird, when I worked in a BigTech it was pretty explicit that there were certain countries where you should not bring your actual work device through the border, and you'll get set up with a different one while in that country.
- tonyedgecombe 2mo agoIt's a shame that the US appears on that list now.
- badatnames 2mo agoHalf of Europe does, it's just that everyone talks about the US like it's a special case because those searches happen routinely. It's legal to search a phone without reasonable suspicion at airports in the UK under the Terrorism act 2000 (pre-9/11!)
- ApolloFortyNine 2mo agoThe article seems to be muddying the water bringing up grapheneOS itself. Or maybe it's the EFF. >Experts said the legal approach is unusual and may be the first time the law has been aimed at an operating system. "It's concerning – and sends the message that [GrapheneOS] is criminal by default," said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case. Is the actual case about banning the OS? Because it seems pretty clear the case is about the result (the phone being wiped with a special passcode). The better defense imo would be one of those 'wipe the phone if you get the password wrong x times' and try and claim you forgot under pressure. At least if you wanted to wipe the phone without being accused of destroying evidence during a search.
- cameldrv 2mo agoI’ve seen a lot of people on the internet over the years say things like “the government can’t make x illegal, it’s just y.” For example, the government can’t make wiping your phone at the border illegal, it’s just punching four numbers into your phone, just like a pin, only a different four numbers, which could just have well been your pin. U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did. Hell there could have been a third set of four numbers that were the nuclear launch codes. It’s not the fact that it was four numbers, it’s what you were trying to make happen when you typed them. Now of course whether they can prove what your intent was when you typed them is another matter, but generally a duress pin should be for when robbers are breaking into your house, and the government will be on your side, and not when the government will be against you.
- halestock 2mo agoA lot of engineer types forget that the law is not code, and reductionist arguments almost never actually work in practice because it's a human interpreting the law.
- hahahaa 2mo agoDoes anyone think law is computer code? I mean any courtroom drama (even if far fetched) shows it is not.
- steve_taylor 2mo agoIt reminds me of tax law in many countries. You can follow the letter of the law, but if the vibes are off, you can still be found to be in breach of a vague catch-all provision (e.g. economic substance doctorine in the US, GAAR in Canada/UK, Part IVA in Australia, etc).
- hahahaa 2mo agoUK has systematic tax avoidance IIRC i.e. keep starting and closing businesses to save tax is frowned upon. Australia can treat your capital gains as income if your gains quack like trades. (Maybe now less important since the recent CGT changes).
- zuzululu 2mo agowhy not just have a separate device for traveling ?
- BLKNSLVR 2mo agoYeah, that's my position. If you're paranoid enough to be using GrapheneOS, why would you take it to an airport in the US of all places? I bought a second hand iPhone for overseas trips, which my daughter promptly stole because she wanted an iPhone, but then i got her old android phone, which was LineageOS-compatible, so that became my travel phone.
- Freedom2 2mo ago[flagged]
- thunderfork 2mo agoApparently not
- BLKNSLVR 2mo agoWelcome to 2026, you have a lot to catch up on. Maybe sit down for this.
- itake 2mo agoHow do you manage data between your primary and travel-phone? I _think_ you would need a fresh iCloud account (thus losing access to purchased apps and subscriptions). You also need to manually create fresh social media accounts, copy over contacts, etc.? Any advice on how to automate this process or is this just a 2-4 hours exercise you do before your trip?
- BLKNSLVR 2mo agoA couple of hour exercise setting up the minimal amount necessary for the travel beforehand. Then once you're at destination, you can set up everything else if you want. I don't have a lot of "everything else" anyway, so my device would probably look suspiciously 'clean' even if it was my in-this-moment daily driver. (HN is my news and social media). I don't use banking apps, but the irony is that I would need to whilst overseas. One of the funny things is, I should be able to re-setup any device with an old gmail account at any time in any place, but with all the extra security these days, you need an old device to authorise the setup of a new device. I'm going away early next year, so I'll need to have a dry-run of the setup...
- deadbabe 2mo agoI don’t understand why phones can’t just have decoy profiles you can activate via PIN that look like regular harmless user profiles? Especially now with AI you can quickly populate with a bunch of plausible data. Or better, have PIN for taking you to your criminal/secret profile instead.
- drewfax 2mo agoHow would it work? Isn't it easy for the authorities to check the list of users on the device?
- deadbabe 2mo agoThe PIN you enter determines what profile opens up, and they are not connected to each other at all, they are isolated.
- Cider9986 2mo agoThey would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security. Also they can plant evidence if you unlock the phone. https://nitter.net/GrapheneOS/status/2081471477174456340#m https://nitter.net/GrapheneOS/status/2081471477174456340#m
- deleted 2mo ago[deleted]
- iamleppert 2mo agoInstead of a PIN that wipes the device, it would be much better to setup a special PIN that logs the user into a sanitized, completely separate profile with generated content of no practical value. This would create plausible deniability, and be sufficient to allow low-level border agents to look through a phone and pass any checks without raising these kinds of alarms. The wipe PIN should still be an option, but should be separate, and only be for cases where you suspect a forensic imaging or search of the device is to take place and the legal consequences outweigh the risks.
- ktallett 2mo agoThis. Aka a Qubes style isolated image.
- handedness 2mo agoAnti-forensics just isn't a focus of the Qubes OS project. Beyond a typical LUKS/dm-crypt FDE implementation, there isn't much else in the way of protections. There have been some community efforts around it to make some relatively minor enhancements. Once you've decrypted the disk, the contents of every permanent Qube is there for the taking, and it would be up to the user to further secure any data within specific Qubes if they desired any protection beyond what they get via FDE. Something like encrypted containers, for example, which isn't specific to Qubes (and has its own limitations). In terms of running processes, Qubes OS benefits greatly from Xen's isolation between Qubes, but from a data forensics standpoint a recent Pixel running GrapheneOS has massively stronger (and more numerous) layers of protection against data extraction, and at all levels (I/O, memory, disk, etc.).
- ktallett 2mo agoYou can use a disposable Qube every time.
- handedness 2mo agoDisposable Qubes are not intended to be robustly anti-forensic in nature. Implementing robust anti-forensic measures in stateful hardware requires far more from the hardware layer than is on offer. There have been and are some community efforts towards mitigations, but nothing remotely approaching what three (soon to be four) specific phone architectures provide. Qubes OS is many wonderful things, but it is not particularly anti-forensic. If anti-forensics on PC hardware is the primary intention behind disposable VMs, there are better options.
- daishi55 2mo ago> federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City Of course it’s about that huh. It’s quite scary how far the US will go against anyone who engages in this sort of activism.
- calvinmorrison 2mo agoRelated, There was a local guy who was held 'in contempt' for 4 years for refusing to turn over his password/encryption key https://arstechnica.com/tech-policy/2020/02/man-who-refused-to-decrypt-hard-drives-is-free-after-four-years-in-jail/ https://arstechnica.com/tech-policy/2020/02/man-who-refused-...
- Cider9986 2mo agoHe had a warrant from a judge which is much less bad. Still probably 5th Amendment problem
- jameson 2mo ago> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart. I'm confused to understand if Tunick did anything illegal here. If the authorities want the phone, they should have the warrant and seize it without Tunick's permission. It appears authorities did not have the warrant which give Tunick all the right to do whatever he desires with his property. What am I missing here?
- fwipsy 2mo agoIt appears to be illegal to destroy property to prevent seizure. I don't know the details; if you search that phrase you can find more info yourself.
- trollbridge 2mo agoDid he actually destroy any property, though?
- free652 2mo agoThey don't need a warrant to seize the phone at the border. They were after the pin code, he should have just refused to give the pin. That's the 5th. What they got him on, is that supposedly he destroyed evidence.
- wildfireday2 2mo agoAmong other things that CBP does not need a warrant to search or seize anything and everything at a border. Everything is subject to search at the border. To make a seizure all that is needed is reasonable cause that customs law/regs were violated. And there are specific federal laws relating to thwarting such seizures. If you don’t want something searched do not bring it across the US border. There is very clear constitutional and statutory authority for these searches.
- mullingitover 2mo agoSeems like they’re going to have a struggle proving intent. “I was stressed out and afraid and I got the passwords mixed up” would be the magic words I’d hear as a juror and I wouldn’t be able to vote to convict.
- gib444 2mo agoSurely they'll just dig into as to why he set up the feature originally?
- deleted 2mo ago[deleted]
- kombookcha 2mo ago'I don't want some sketchy phone mugger to end up with sexy photos of my girlfriend/myself' would seem like a plausible reason to me, if I was a juror.
- microtonal 2mo agoIANAL, but I think that argument would be stronger if there was a way of a mugger to use the pincode (like putting it on a note inside the case) and law enforcement just used that code.
- kombookcha 2mo agoThat sounds sensible to me. But I am likewise NAL. If you've refused to answer questions and giving them the password, and they don't have a warrant, taking your case off and inputting the mysterious number they found in there seems a lot more like them destroying your (data) property by oafishly trying to force access to a phone they have no business messing with, rather than you ostensibly destroying evidence of a theoretical undiscovered crime. I'm sure they would still try to mess with you in a dozen ways for annoying them, but at least you'd be on decently solid ground in court as far as that goes.
- 2mo ago
- ww520 2mo agoCharged is not convicted. Anyone can be charged with anything if the prosecution is vindictive.
- guywithahat 2mo ago> US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search I really don't like this title. Officers asked him to open the phone, which he pretended to do, but instead wiped the device > During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart. The defense motion states that "the screen went blank, flashed several times, and the phone appeared to restart," resulting in the loss of data. The title implies the agents maybe entered too many pins by mistake and the device auto-wiped, or that it reset itself with no human intervention, which isn't what happened. This is more like shredding paper when the FBI arrives at your office, which most people would attribute to destroying evidence. I hope he wins the case in principle (I think there's a risk of a slippery slope here) but it wouldn't be a moral tragedy if he lost.
- thelastgallon 2mo agoIts best for all of us to figure out how to use phone-as-a-linux-vm with the physical phone just hardware. It will solve many problems: commoditize the phone ecosystem, eventually making them repairable, run our own apps instead of apple/google. Access phone-vm from laptop/desktop ...
- istjohn 2mo agoPerhaps a way to avoid this would be to have the duress pin trigger not a device wipe, but a device encryption with a long, pre-set key that you would store in a safe place when setting up the duress pin. Then you haven't destroyed the evidence, but the data is irretrievable without your cooperation. Also, if you don't actually have the key saved, it would in fact be destroyed, but the prosecutor would have to prove that you don't have the key saved somewhere.
- kdheiwns 2mo agoThis is one of those things the other comment calling the law "non-autistic" is referring to. In the eyes of 99% of people, it's functionally the same thing. "Well teeeecccchhhhnicallyyyyyyyy I still have the data..." isn't going to make the security workers at the airport slap their heads and say "damn, he really got us! Go on through!" No. They'll arrest you just the same for obstructing their search. Then they'll keep you in detention for a long time while you say "I can unlock it for you! You just have to let me out!" You can pretend you have leverage and say they need to cooperate with you. But once you're detained, police and prosecutors don't really care about cooperation anymore. Their idea of cooperation is you giving them what they want immediately without question. You're made into an example if you don't abide.
- thecrash 2mo agoYou are incorrect, US border patrol can not arrest you for refusing to decrypt your phone (if you are a citizen). It is not considered obstructing a search to refuse to provide a password. This is not "autistic" speculation about legal technicalities, there are many many examples which support this. The worst they can do is seize the device.
- kdheiwns 2mo agoYou're free to test them. See what they do when you say "it's not deleted. It's just inaccessible until I cooperate." Because it's identical in their eyes. People who confidently say "the government can't do that" rarely have a good day. They end up sharing a cell with the person in the article this discussion is about. And we're living in an era where immigration enforcement can shoot Americans without penalty. It just makes the claims that the government can't arrest someone come across as naive.
- ulfw 2mo agoEvery day I thank the lord that I left the US for good and never went back
- morgan814 2mo agoI would be very interested in how you did this / where you ended up. Feels like an impossible task every time I consider it.
- rsynnott 2mo agoThere’s been a large uptick in immigration from the US to Ireland; almost ten thousand last year. In general, people would do this via employment; software engineers and similar would generally qualify for a critical skills permit. For critical skills, after two years on a stamp 1 visa (tied to a specific employment) you can move to a stamp 4 (not tied to specific employment). After five years working in the country you can apply for citizenship.
- ulfw 2mo agoIt's really easy if you just look for jobs elsewhere and go throw the local legal processes, which are generally all easier/better/more helpful than the 'we don't want you' USA. I have lived in Thailand, Singapore, Hong Kong since leaving California and have Permanent Residence now in Hong Kong and Australia.
- fsuts 2mo agoOther countries are worse legally than USA, including uk
- andrewflnr 2mo agoWhy the hell doesn't the "duress PIN" just open up a sanitary profile? Bonus points for letting you set it up with plausible data before designating it as the duress profile that, when opened, wipes your real profile in the background. > "the screen went blank, flashed several times, and the phone appeared to restart," How about flash some red lights and play an airhorn sound effect, too.
- itake 2mo agoJust a guess… but they would just go back and ask him for the real pin if they saw the profile was empty. My understanding is phone’s security model aren’t designed for multiple user accounts
- jeroenhd 2mo agoAndroid has had multiple users for many years, though it's a feature most smart phone brands turn off for some reason. You can switch users just fine, you just cannot hide the primary user from the secondary user. Opening up the device also makes it a lot more vulnerable to attacks to dump the keys and storage. Having multiple users is quite handy but it's not going to do anything at a border checkpoint that'll save you.
- ButlerianJihad 2mo agoRecent Android releases have a Private Space feature, where you can hide not just files, but entire apps, their data, notifications, etc. https://support.google.com/android/answer/15341885?hl=en https://support.google.com/android/answer/15341885?hl=en
- Cider9986 2mo agoThey would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security. Also they can plant evidence if you unlock the phone. https://nitter.net/GrapheneOS/status/2081471477174456340#m https://nitter.net/GrapheneOS/status/2081471477174456340#m
- LPisGood 2mo ago> federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City. This is practically the only thing I care about here and there are almost no details. What was his alleged involvement? How many others were targeted?
- nicois 2mo agocould graphene support multiple duress PINs? feds: "unlock your phone or else" victim: "um, you're stressing me man. It's either 1234 or 4321, I forget. One of them wipes the phone, the other will unlock it." Whichever PIN they try, it wipes the phone, but the feds can't claim it was deceitful, just unlucky.
- Cider9986 2mo agoThey operate under the basis that the adversary has encyclopedic knowledge so likely not helpful. More: https://nitter.net/GrapheneOS/status/2082153517234676150#m https://nitter.net/GrapheneOS/status/2082153517234676150#m
- NDlurker 2mo agoThey violated his rights and he pulled a prank on them. They need to chill out.
- asdfxkcd 2mo agoMaybe also shows that the duress PIN feature could be implemented better. Booting into a completely fresh phone is suspicious. There also shouldn't be any visual or other indicators of that happening. In the old TrueCrypt containers you could set an optional second password that would decrypt a different volume. The size of the container file was always the same, a decrypted volume always showed the full container size, the portion not occupied by the data in the main volume was filled with noise, and the data on the non-loaded volume was not protected (so you could erase it without warning by storing too much on the loaded volume), making it practically impossible to prove the existence of a second volume either way in a search situation. I guess there was a reason why the project was stopped.
- Cider9986 2mo agoNot possible to be robust unfortunately due to low level SSD architecture[1] and other reasons: https://nitter.net/GrapheneOS/status/2082153517234676150#m https://nitter.net/GrapheneOS/status/2082153517234676150#m [1] https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Wear-Leveling.html https://veracrypt.io/en/Wear-Leveling.html
- hyperion2010 2mo agoI suspect that this will ultimately be thrown out for a very simple reason which is that the government will have to prove that a duress PIN was actually entered. That is going to be quite difficult unless the person charged openly admitted it. The reason is because anyone running an os with a duress PIN that has done nothing wrong can be accused of using a duress PIN because the whole point of the duress PIN is that it looks like you just have a normal phone. Running a normal apple operating system with just stock apps? Boom, you're a criminal because you obviously used a duress PIN and have something to hide! There is no way to prove you didn't use a duress PIN because the phone was "wiped." Now unfortunately grapheneos probably leaks information so that a duress "unlock" can be differentiated from a standard unlock by some means. If not then kudos. It looks like it is done instantly by keeping everything encrypted and just zapping the keys, but it also needs to actually unlock to something instead of rebooting to prevent leaking the information that a duress pin was used. Not sure how fiesable that would be though.
- deleted 2mo ago[deleted]
- zache6 2mo agoI'm a GrapheneOS user. The duress passcode feature will reboot the phone to a "corrupted data" screen, so it's pretty obvious that it's been used to render data inaccessible.
- sire-vc 2mo agoTo everyone who thinks this is somehow a violation of rights: if you were being questioned by border officers, and were asked 'Sir could you please open your suitcase', and you pressed a button that caused it to burst into flames, there isn't a country in the entire world that wouldn't arrest you on the spot. Why would 'wipe a phone when officer requests it opened' be treated any differently? Suspicious behaviour is treated as suspicious by normal people.
- thecrash 2mo agoIt doesn't sound like this person pressed any buttons. They were pressured to provide a PIN or be delayed and further harassed. They obliged, and agents decided to enter it to attempt a warrantless search of the phone. It's not stated, but probably we can assume the person didn't ask for his phone to be searched - probably he asked NOT for it to be searched, at least based on his multiple requests to talk to his lawyer. Considering those factors, I'd say border patrol is more responsible for wiping the phone than the person.
- TheTaytay 2mo agoRight, but by that rationale, it’s also suspicious to say “no” when they ask if they can open your suitcase. Or decline to tell them where the key is. Or ask to speak to your lawyer first. Or refuse to tell them what is in the suitcase. Or lock the suitcase in the first place. And I want to live in a society where those behaviors are protected. (1password has a “traveling” mode that wipes it of sensitive passwords before going across borders. Is that suspicious? Should it be criminalized?)
- sire-vc 2mo agoIf they ask to open my suitcase and I say 'no' that is suspicious. I've done a lot of travelling and have been questioned more than once: being candid and transparent has always been prudent.
- wraptile 2mo agomaterial =/= information. Are we supposed to live in a world where if I'm crossing a border I must give access to all of my information? That's absurd and more equivalent to a full brain/memory scan than a suitcase search from your example. This is dystopian in every sense of the word.
- rock_artist 2mo agoFor non-graphene users (eg. Boring iPhone people like me). So there’s a feature called Duress PIN which as explained through some comments means you put a different pin which intentionally wipes the phone. It’s not auto wipe or wipe after several failed attempts but intentional wipe of device. (Worth explanation as the current title nor the article doesn't easily explain this was made by the US citizen providing the alternative passcode) For more technical details: > GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS). https://grapheneos.org/features#duress https://grapheneos.org/features#duress
- il-b 2mo agoIt zeroes out the vault where the volume key is stored.
- itake 2mo agoleaving the actual evidence files untouched...
- f-serif 2mo agoPIN to wipe seems suspicious. How about a PIN where it login to a patriotic profile and phone looks like normal android.
- _kidlike 2mo agoI had this on a Xiaomi, maybe 10 years ago? Very cool feature! I hope they still do it. I think the wipe feature is also very cool, but not used in this way.
- culi 2mo agoFascinating. It seems the feature is called "Second Space" https://www.mi.com/global/support/faq/details/KA-492586/ https://www.mi.com/global/support/faq/details/KA-492586/
- anonymousiam 2mo agoThere was no warrant, nor any court order compelling him to provide the unlock code. They had no probable cause, other than that they had labeled him a "terrorist" because of his political activities. The CSAM pretext was provably just a pretext. If he gets good representation, he should be able to (eventually) beat this rap. If he had simply refused to provide the unlock PIN, he would have walked away. They may have kept his phone, but they would never have got anything from it anyway.
- unwise-exe 2mo agoWhy is the headline blaming the OS for what the user chose to do? This is like saying it's my car's fault if I decided to drive onto the sidewalk or something.
- microtonal 2mo agoYes, the only relevant property is the use of a duress PIN. They could have simply stated that he erased his phone with a duress PIN. But "GrapheneOS! Spain! Profiling Pixel users! Spain equates GrapheneOS to criminals!" sounds far more spectacular and will give more clicks/links. Sadly, it feeds the narrative that GrapheneOS is just for activists/criminals/whatever. An iPhone in BFU state would have been nearly as safe, but nobody makes these implications about iPhones because everybody has iPhones.
- mrbn100ful 2mo agoI mean, yes? If 1% of iPhone users are criminals and 5% of GrapheneOS users are criminals, border search agents are going to be interested in your GrapheneOS mobile. I am pretty sure criminals are more likely to use a super safe and secure phone that is easy to obtain.
- Pikamander2 2mo agoYeah, the way that this case is being reported on is really irritating. While he technically did use a special GrapheneOS feature to wipe his phone, the criminal charges would have been the same if he had used the default "reset phone" feature on Android or iOS right before handing the phone over. The real focus of this case should be on the reason for his detainment and the confiscatation of his phone and multiple refusals to contact his lawyer.
- lotu 2mo agoHis mistake was giving a passcode he knew would destroy the data on the phone. Instead leave the destruct passcode written on a scarp of paper inside your phone case.
- crusty 2mo agoThis sends like a more-info-requiered situation. Per this article, the LEOs seemed to be fishing, so they presumably couldn't claim as a matter of fact that evidence had been destroyed. Also, claiming destruction of property seems unreasonable since the phone, the property, still exists as before. If I sell my phone, I'm going to wipe it. I think we all understand that it would be ludicrous for the buyer to claim I was destroying the phone, the property they've been sold, by doing so. Even if the accelerated executive capture of the judiciary is largely ruled back post Trump (big IF), I fear the government will be unwilling to pay with much of the convenience of rule-by-law that it's been given a taste for.
- flyingcapabara 2mo agoAnyone else running box for local ai on android ? www.github.com/jegly/box
- kirykl 2mo agomaybe have the default behavior for the phone to reset if it doesn't get the right pin every so many hours
- whats_a_quasar 2mo agoHere is the indictment: https://www.documentcloud.org/documents/28513012-samuel-tunick-indictment/ https://www.documentcloud.org/documents/28513012-samuel-tuni... Here is the statute Tunick is indicted under: https://www.law.cornell.edu/uscode/text/18/2232 https://www.law.cornell.edu/uscode/text/18/2232 There is an immediate problem: the device was being searched, and this statute criminalizes destruction of property to prevent seizure, not searches. I don't think this statute applies this situation. Regardless of whether the border agents could lawfully search his phone at the border, they didn't have grounds to seize it. I suspect this prosecution will quietly be dismissed within a few months.
- ytoawwhra92 2mo agoCBP are empowered to seize devices if the owner refuses a search.
- itake 2mo agoJust being silly. Owner gave permission (and the pin code) that will give them access to an empty phone. No search refused.
- ytoawwhra92 2mo agoIMO people are better off knowing their actual rights in a US airport than trying to outsmart the US government.
- xg15 2mo agoI don't know, that sounds like the kind of "I'm not touching you" defense that I don't think will convince anyone with common sense. It's obvious the wipe turned a search that could potentially find something into a useless search, so I don't see why the two should be treated as equivalent.
- LadyCailin 2mo agoI would have thought the fourth amendment not having specific geographical boundaries, but rather applying generally would have been common sense too, but here we are with border patrol being able to force you to reveal your PIN code just because you transited a border.
- polotics 2mo agoit's a bug: the wipe should only apply to a see secure enclave, and the phone should restart `normally`
- jojohohanon 2mo agoIt seems to me that this should have been a case of steganography? Instead of wiping it clean, wipe to innocuous mode. Then the burden on their part is not only to show that I gave a bad pun, but that the innocuous mode is materially different than the previous state.
- make3 2mo agocreating a convincing and actually safe innocuous mode is probably harder than it sounds in practice
- Cider9986 2mo agoNot possible unfortunately due to low level SSD architecture[1] and other reasons: https://nitter.net/GrapheneOS/status/2082153517234676150#m https://nitter.net/GrapheneOS/status/2082153517234676150#m [1] https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Wear-Leveling.html https://veracrypt.io/en/Wear-Leveling.html
- Tepix 2mo agoPerhaps we need the following feature: Before entering the airport you set your device to auto-wipe after x hours. Once you are sitting in the airplane and flying, you cancel the scheduled automatic wipe.
- microtonal 2mo agoA GrapheneOS is most likely completely secure in BFU state [1]. So just switch the phone off or reboot it and don't enter your PIN. It is very unlikely that law enforcement is able to decrypt the phone and it does not put you in murky legal terrain, because even an auto-wipe is intentional (IANAL). [1] This is in contrast to many other Android phones outside Pixel and Samsung flagships, because they are too cheap to add a secure element, which iPhone has had since 2013 and Google Pixel since 2018.
- Tepix 2mo agoNothing is completely secure. Your data is less likely to be accessed if your device wipes it. > even an auto-wipe is intentional (IANAL) It's also something that's very hard to prove.
- Cider9986 2mo agoNot possible due to not being a reliable software feature. It would have to be in the hardware.
- Eriks 2mo agoSo having a Casio F-91W and a Pixel 9a at an airport in US basically sends me to Guantanamo?
- blitzar 2mo agoIts the new brown skin.
- gblargg 2mo agoRather than wipe the phone to an obvious reset state, this feature should boot into a benign setup with normal contacts etc. after it erases the user's data. Let the user periodically boot into this benign setup to add basic contacts etc.
- nttylock 2mo ago[flagged]
- __MatrixMan__ 2mo agoGotta wonder how it would've gone if the citizen hadn't mentioned GrapheneOS at all and instead tried to sue them for wiping his phone without his permission.
- amelius 2mo agoWhy didn't the device shadow-ban the user instead of wiping the device upon entering the wrong PIN? Of course TSA agents become angry when they enter the PIN and see a message "wiping device".
- Cider9986 2mo agoNot possible unfortunately due to low level SSD architecture[1] and other reasons: https://nitter.net/GrapheneOS/status/2082153517234676150#m https://nitter.net/GrapheneOS/status/2082153517234676150#m [1] https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Wear-Leveling.html https://veracrypt.io/en/Wear-Leveling.html
- seydor 2mo agoNice national parks, but no way in hell i m visiting this decade
- ragazzina 2mo ago> this decade Do you think things are going to improve in our lifetime?
- Arodex 2mo agoMaybe, with the help of measles, screwworms and explosive diarrhea...
- I_am_tiberius 2mo agoMight take longer I assume. This has been building up since at least 2001 and I don't believe it will be faster they get healthy again.
- etienne89 2mo agoSo in GrapheneOS you enter your regular passcode to unlock it and a secondary passcode will wipe everything? Maybe it needs a third option where it just shows predefined apps/data, so it could just show e.g. WhatsApp, a set off chosen photo albums and some irrelevant office documents. Could also be useful for handing it to children, so they can access some games or whatever but nothing critical
- Cider9986 2mo agoYes that's correct. They would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security. https://nitter.net/GrapheneOS/status/2081471477174456340#m https://nitter.net/GrapheneOS/status/2081471477174456340#m
- angry_octet 2mo agoObviously you should just write the duress pin on the back of the phone inside the case. If the ask what the PIN is for, stand mute. If they enter it, it is their decision.
- northernsausage 2mo agoIf this happened in an EU country you'd all be wetting yourselves, but for some reason the rooms different today. The professional advice we are given traveling to the US is back up you phone, wipe it, travel and restore once you are comfortable. Sad state of affairs guys
- Cider9986 2mo agoIn the US, he could have refused to give the pin and that's protected under the 5th Amendment. They would have nothing because they couldn't get into the encrypted phone. In many countries other then the US like Ireland, they have key disclosure laws which require you to testify against yourself. In the UK, police can even require key disclosure without a judge.
- padjo 2mo agoWait 'till you hear about the special criminal court...
- _fat_santa 2mo agoAnother commenter posted the complaint: https://www.documentcloud.org/documents/28513012-samuel-tunick-indictment/ https://www.documentcloud.org/documents/28513012-samuel-tuni... The terrifying line of this for me is: "before and during the search", namely the "before" part. Even if you wiped your device days before, they could always make the argument that you destroyed evidence back then because you were trying to prevent them from searching your device. INAL so not sure if this would hold up in court.
- fsuts 2mo agoBy raising the profile of airport seizures all it means is that serious criminals will wipe their devices prior to travelling and restore afterwards/buy a new device for travel. The powers of investigators special rights and abilities rely on them being used very rarely. Last thing the terrorism investigators want is media coverage exposing their tactics.
- tencentshill 2mo agoThey are trying to make buying a burner phone illegal as well. Pushing a rule to require an ID to buy any SIM.
- Cider9986 2mo agoYou don't need a phone number to use a phone.. It's not secure messaging at all anyway.
- Aissen 2mo agoFollowing this being in the news, GrapheneOS wrote this post summarizing the data extraction defense: https://discuss.grapheneos.org/d/40700-grapheneos-protections-against-data-extraction-from-locked-devices https://discuss.grapheneos.org/d/40700-grapheneos-protection... On the duress pin, they say (read the whole thing though): > People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device.
- man_luke 2mo agoThis case will only help make more criminals aware of this possibility.
- schoen 2mo agoI co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that. The end result (not inherently different from what we wrote in the guide) is that you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to. I was fascinated by techniques for being unable to comply (which is straightforward to achieve if you want!) but probably didn't think enough about how much this might antagonize border agents in many cases. I definitely don't know a comprehensive big-picture solution.
- jpfromlondon 2mo agoI don't carry a smartphone, is this likely to be a red flag if I'm stopped?
- majke 2mo agoMany countries now assume you have a phone. For example getting UK visa requires a smartphone. I don't think going without a phone is feasible nowadays. Another question is if going with a burner phone that has just sim card and bank card, sufficient. But then you need appleid/google account on the device, and this again links back to your phone number, and it's not easy in practice to have proper clean device.
- itake 2mo agoThe duress pin deletes the encryption key information used to decode the documents and does not damage the documents themselves. Not sure why the police and news are saying that he destroyed evidence, since the evidence (as it always has existed before the search began) remains on the disk.
- neilalexander 2mo agoSomeone else commented about the law being “non-autistic”, this is a perfect example of that. The technicality of the encryption keys vs the files is irrelevant, the intent was to successfully prevent a search. The border agents will not be even remotely impressed or suddenly decide to release you just because you say “well the files are technically still there”.
- FeepingCreature 2mo agoWhat they should really do is make the decryption key backupable. Then you can keep it at home, and you can genuinely say that you don't remember it because it's like 128 digits. And you're not "destroying evidence" in the jurisdiction in question because the phone is already locked. And you can't unlock it on demand.
- itake 2mo ago> decryption key backupable that seems like a security nightmare... Passing through immigration with a fully reset phone does the same. The full encrypted backup is on a HD at home. Nothing to access on the phone.
- chaz6 2mo agoPerhaps a defence to this is ensure that a copy of the encryption key exists in a location outside the jurisdiction of the state.
- iepathos 2mo ago> The motion also states that Tunick asked four times to speak with a lawyer and was denied each time. This is the kind of thing that loses cases, even if they were legitimate at first. Seems like the prosecutor is desperate charging for the phone wipe cause they didn't have any evidence of terrorism, child-pornography, etc. The problem they have now is given he was in custody and agents pressured him to provide the passcode that they then incompetently put into the phone, the fact that they denied him a lawyer multiple times means there is a very strong argument that his rights were violated. Typically, courts suppress any evidence when there is a violation like this with someone in custody. So the compelled passcode, the phone's reaction when that passcode was entered, and the agents' testimony describing the supposed wipe would be thrown out by most judges. What's left for the prosecution after this is jack and shit, but jack left town.
- madhu_ghalame 2mo ago[dead]
- drdrek 2mo agoMy bets for the actual story behind this are: 95% a criminal hiding evidence 4.99% an autistic attempt to "keep his privacy" for no reason at all 0.01% a genuine need to keep something away from the government In all cases just don't cross security checks with evidence you wouldn't want to be seized, its not that hard
- wartywhoa23 2mo agoWrote someone who's got a CCTV camera installed inside his toilet bowl, no less! Right? The Bentham business is alive and kicking.
- MrDrMcCoy 2mo agoWouldn't it be better from a legal standpoint to power the phone off and refuse to give your pin in such cases? A no-pin cold boot is pretty hard to recover data from with GrapheneOS.
- microtonal 2mo agoMost likely, at least you are not doing something irreversible. In all these cases, the best answer is "ask a lawyer". Before wiping a device in possession of law enforcement you definitely want to ask a lawyer. I realize that in this case the person repeatedly asked for a lawyer, but if you are in a borderline authoritarian state, all bets are off.
- tonyhart7 2mo agohe doesn't need to do this if all he doing is legal
- victorbjorklund 2mo agoThe only safe thing to do is to backup your phone. Wipe it and go through the border. And then restore the phone.
- schoen 2mo agoAfter reading more of this thread I'm kind of frustrated that people aren't aware of the border search exception. I strongly disagree with the border search exception and would like to see it drastically limited or abolished. It is also something that has clearly existed in caselaw for decades (arguably for centuries) and that the courts have routinely (to my regret) strongly reaffirmed. The border search doctrine says that border agents do not need a reason to examine you or your possessions when you are entering the country. They do not need to believe that you are doing something wrong or committing a crime. If they suspect you, they don't need proof or a good reason to investigate you. I find this doctrine very disturbing and I hope it will be changed or narrowed. I also would like people commenting in this thread to understand that border agents are not just imagining things when they claim to have legal authority to inspect people (or, alas, electronic devices or data) at the border, and that this didn't just start under the Trump administration or something. The legal consequences of providing a duress PIN may not have been tested and this defendant could well prevail in this case. I just wish people commenting here would understand that there is a tremendous amount of history related to border search authority. You can disagree with it (I hope you will!), but you should understand that it's not just something that someone just made up last week or last month or last year.
- Cider9986 2mo agoThe thing you are missing is that although that doctrine weakens the 4th Amendment, there's no precedent it weakens the first and 5th amendment afaik. There's no US law requiring key disclosure and there have been mixed court cases outcomes on whether people have to provide encryption keys.
- schoen 2mo agoI agree with all of that, but what I saw throughout the thread was many people talking about probable cause and warrants and suspicion. I would love for that to be the rule at the border just as elsewhere, but it's very far away from what the courts have been saying so far, as well as what CBP has done for many years.
- jwally 2mo agoIt feels like if he triggered a wipe - that is destruction of evidence; but if it auto-wiped he's fine. If it were a box of drugs and he triggers an incendiary device - he's in trouble . If agents trip a protective boobie trap and destroy the box- he is fine. Don't know why but this feels correct to me.
- shevy-java 2mo ago"Prosecutors say the OS erased evidence" It's his device, so he can do everything he wants to. The USA is currently re-purposing constitutional protections. A judge has not signed these warrantless seizures, so why would the individual be under any obligation to cooperate? Besides, why would anyone want to incriminate oneself? The onus would be on the state to prove a guilty state.
- jagadaga 2mo agoI think a wiser approach for crossing a border might be to have another phone with regular Android installed on it, so it doesn't look suspicious, and then connect remotely to your main phone. Before crossing the border, you would just need to remove the remote-connection app, and after crossing, install it again.
- throwaway2037 2mo agoFrom the article, I saw this: > According to court testimony, federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City. I didn't know about Cop City, but I found this on Wiki: https://en.wikipedia.org/wiki/Cop_City https://en.wikipedia.org/wiki/Cop_City This part is interesting to me: > RICO conspiracy indictment > In September 2023, sixty-one people who had been arrested in the forest or at stop cop city protests were charged with racketeering under Georgia’s RICO law. This indictment is likely the largest criminal conspiracy case ever filed against protestors in the US. > As of April 2025, the racketeering case was stalled. Defendants in the case maintained their innocence and reported difficulty getting work and other hardships while they awaited trial for more than 20 months. In September, all RICO charges were dropped. Judge Kevin Farmer found that the Georgia Attorney General did not have the authority to bring RICO charges in the case. From my outside view, it looks like these investigations are nothing more than an attempt to suppress free speech and protests. For anyone unaware, RICO is both a Federal law and a Georgia state law that stands for: "Racketeer Influenced and Corrupt Organizations". It is used to take down mafia, gangs, organized crime, etc. It is a bit sad to see state prosecutors trying to use this against protesters.
- ergocoder 2mo agoIs this an ads for GrepheneOS?
- whh 2mo agoI feel like the advice given by IT departments for years was to wipe your device ahead of travel, and restore from backup upon arriving. Or, to take a travel device.
- whack 2mo ago> US citizen charged after GrapheneOS phone wipes during airport search > It's concerning – and sends the message that [GrapheneOS] is criminal by default What's with this sensationalism? The GrapheneOS phone didn't just wipe itself - the defendant actively took steps to wipe it. The defendant isn't being prosecuted "by default" for having a GrapheneOS phone. He is being prosecuted for what he actively chose to do with that phone. If your argument is that the search and seizure was unconstitutional, and you're within your rights to wipe your data, then argue that. I'm very sympathetic to such arguments. But stop with this "they prosecuted me for having a GrapheneOS phone" misdirect
- epolanski 2mo agoDoesn't matter, increasingly law enforcement is treating nicher secure OSs as a sign of illegal activity.
- Cider9986 2mo agoWe need more users. iOS is similarly hardened but calling iOS users criminals wouldn't go over well. He was not harrased for using Grapheneos, but for protesting cop city in Atlanta.
- aucisson_masque 2mo agoYou wouldn't be surprised if that happened when traveling to China or any other autocratic country. I think the issue is that people expect the USA to be the "land of freedom" when it's not anymore. It's turning more and more into an oligarchy and we are at the point where it's just as bad as russia or china. If i was offered a trip to China or russia, i'd go but i would take a burner phone with absolutely nothing important; It's the same for the usa now.
- Markoff 2mo agoNo, as someone who lived in China for years (as foreigner) and visited also last year after many years I WOULD BE SURPRISED if this happened when travelling to China, since China is clearly more free than US/Israel. China wants tourists and don't care about your stupid social media.
- Cider9986 2mo agoTrue, they focus their oppression on their own citizens and minorities for the most part.
- Markoff 2mo agoHave you lived in China or you just parrot some US propaganda? In years of living there I haven't noticed any of my Chinese family/friends being opressed in any way. And if you mean by opression that Han majority population was for decades allowed to have less children than ANY OTHER minority I agree with you...
- Cider9986 2mo agoWhether or not someone personally witnesses oppression doesn't change whether it happened. My relatives are fine in the US but it doesn't mean ICE isn't unjustly harming people and violating their rights. Evidence: Torture, brainwashing based on race: https://www.xinjiangpolicefiles.org/ https://www.xinjiangpolicefiles.org/ https://en.wikipedia.org/wiki/Xinjiang_Police_Files https://en.wikipedia.org/wiki/Xinjiang_Police_Files https://en.wikipedia.org/wiki/China_Cables https://en.wikipedia.org/wiki/China_Cables This doesn't come from the US government or any media. The Xinjiang Police Files are the Chinese government's own internal documents. Here's a more encyclopedic summary: https://en.wikipedia.org/wiki/Persecution_of_Uyghurs_in_China https://en.wikipedia.org/wiki/Persecution_of_Uyghurs_in_Chin...
- hn_submit 2mo agoThere are laws against the destruction of evidence, but I'd argue that there's no evidence in this case since they don't have clear-cut knowledge what's on the phone. It's potential evidence at best and it's therefore not clear if the law applies. If Customs already knew whether the suspect had incriminating files on his/her phone things might be different.
- Ylpertnodi 2mo ago> if customs knew... Even then, they'd have to produce such in court. ?
- alfiedotwtf 2mo agoWhat nobody has commented yet here is that the incident is 7 months old but we're only hearing about it now. Imagine the incidents we DON'T hear about at all.
- Unicironic 2mo agoThey have absolutely no idea if evidence was destroyed, and the only thing he is charged with is the possibility that it was.
- thraway3837 2mo agoOk, so I'm just angry so take this comment in that light please: 1. What happens if the masses just do this? Today it's just a few folks who know how to do this. Tomorrow it could be 10, a year later 100. What's to stop 1000s from doing this and then what is the government going to do? Ban the OS and block it on Github? 2. What exactly happens after you're charged? This doesn't mean the person is convicted. Just that they now have to show up to court wherever the trial is held and have to retain their own lawyer (or public defender?). And what is the likelihood that the case is thrown out or the person is convicted and receives a stiff penalty? I ask these questions because as far as I can tell, the person was not suspected or convicted of anything, and it's infuriating me that we are just going to stop random citizens and ask for their private data.
- neumann 2mo agoI have a friend who is a peace negotiator in the balkans for 20 years. He has lots of amusing (to my horrifying) stories of cat and mouse interrogations with the FSB etc as he travels between Moscow, Kyiv and the West. He uses threema and signal for most diplomatic conversations, but when he travels he only carries burner phones. If you don't trust a government, ensure you aren't carrying any information you don't want to give up before entering their borders where you will be under their power.
- sylware 2mo agoThis grapheneOS may be another scheme from the 'deep FBI'/'services' to get intel on the very, VERY, nasty (terrorists, human traffickers, drug cartels, child stuff, etc). If I recall properly, they did that in the past (it seemed to have worked amazingly). If so, "normal" police would not have the "keys". This would be "the compromise".
- Cider9986 2mo agoExtraordinary claims require extraordinary evidence. You haven't provided any evidence.
- sylware 2mo agoThere are videos on youtube on the previous deep FBI/services hardware tech scheme. In this context, grapheneos looks like more just 'And Another Time...'. In the end, it does not matter: we all know here that "information system security" is a fantasy, it does not exist. When somebody does pretend the opposite: this person wants to scam you or sell you something.
- firebot 2mo agoTIL about cop city... Wtf?
- gcanyon 2mo agoI'm not doing anything the government should be worried about. Nevertheless my pin has for a long time been longer than standard, specifically on the very long-shot possibility someone decides they want to crack it. Anyone know if this is a viable strategy on iOS, and what the required pin-length is these days?
- Cider9986 2mo agoIt's viable depending on iPhone modernity and OS updatedness. 11 and 12s have unpatchable exploits. Make sure to get to BFU though through restarting.
- deleted 2mo ago[deleted]
- alienbaby 2mo agowhy would you need to carry incriminating data with you when travelling? An encrypted blob stuck 'somewhere' would be fine, no?
- deleted 2mo ago[deleted]
- redsymbol 2mo agoIn Catalonia, Spain, police have been profiling people carrying Pixel phones, assuming they have GrapheneOS installed and are drug dealers or gang members. WTF.
- everdrive 2mo agoIn fairness to the victim, he did really need to have that phone. What if there had been a restaurant with a QR-code menu? What would he have done then? So yes, we've created an authoritarian hellhole, but the alternative is even MORE unthinkable: struggling to pay for parking in some areas, needing to visit a website for a menu or (GASP) visiting a different restaurant, or just having a friend order for you. No, these are too much to ask of anyone. No one can overcome these challenges. The only answer is to weep for the liberty that we have lost.
- virajk_31 2mo agoWiping could be the last resort. Instead how about auto creating a new profile! As far as I remember Android profiles isolate apps, files, and system data and providing a fresh environment without erasing the device. To make it feel more authentic there could also be an option to automatically install a few commonly used apps by default. Thats it. (assuming the officials don't have time for an thorough inspection)
- left-struck 2mo agoThere are forensic tools that can probably bypass those. I don’t think the agent is just going through your phone by using the phone itself, though maybe it is that stupid, idk.
- Cider9986 2mo agoThey would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security. Also they can plant evidence if you unlock the phone. https://nitter.net/GrapheneOS/status/2081471477174456340#m https://nitter.net/GrapheneOS/status/2081471477174456340#m
- Alien1Being 2mo agoNever piss off the minions of the Supreme Leader.
- ErneX 2mo agoAFAIK border agents can even clone your device if they deem it necessary.
- feelamee 2mo agoWhy did he do this? Really, if this is a way to protect your privacy, then it's a bad way because it causes such a scenario. Of course it works well against the stolen phone scenario, but not again "state authorities suspect me". Especially if this is the authority of some authoritarian state, where your rights do not really matter. Maybe he did this as a protest act?
- 6r17 2mo agoOne clean implementation of this is to wipe everything on the 2nd password failure.
- alistairSH 2mo agoSort of feels like he should have wiped it right away, not after they seized it (by giving them the “wipe me” passcode). No idea if that’s how the law works, just my gut reaction.
- summarybot 2mo agoand what part of "search my digital device for words and phrases" is expressly allowed by the fourth amendment that protects against warrantless search and seizure? oh yeah, none of it. that's right. the fact that agents are conducting broadsweeping searches in clear violation of The Constitution is so painful it's almost laughable. it being a "border crossing" applied to digital information and not just the contents of my suitcase is an appalling transgression of the spirit of the law. also why is your device programmed to self-erase? that's also incredibly sus. smuggling endangered species? bad. okay search a suitcase. having unrestricted access to all my gmails because i need to catch a plane? absolutely unacceptable. having your phone autowipe when pressed by authority? quit whatever nefarious shit you're doing, thanks
- mattlondon 2mo agoDude I said 1,2,3-FIVE! jesus did you break my phone?! What the hell did you do?! Man my wife is going to be so mad she didn't even want me to upgrade to a new handset.
- VortexLain 2mo agoAt this point, GrapheneOS must introduce a feature to delete only specific data (apps & files) when the decoy password is entered, and then unlock the phone.
- Cider9986 2mo agoThey would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security. https://nitter.net/GrapheneOS/status/2081471477174456340#m https://nitter.net/GrapheneOS/status/2081471477174456340#m
- sailfast 2mo agoHow dare he outwit a bunch of nincompoops. If the United State was a nation of laws this suit should be tossed with prejudice.
- dopamean 2mo agoI'd love a feature where if you enter a specific passcode it unlocks the phone into a different account that has curated things in it. Pictures, some pre-approved apps, etc. So you look like you've cooperated but you haven't really.
- krunck 2mo agoAnd each user's home directory is stored on a separate hidden partition that is encrypted with another PIN so that even if the device is rooted they can't look at the other user's data.
- deleted 2mo ago[deleted]
- Cider9986 2mo agoNot possible unfortunately due to low level SSD architecture[1] and other reasons: https://nitter.net/GrapheneOS/status/2082153517234676150#m https://nitter.net/GrapheneOS/status/2082153517234676150#m [1] https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Wear-Leveling.html https://veracrypt.io/en/Wear-Leveling.html
- regnull 2mo agoHow is it different from smashing your phone on the floor and destroying it when asked to unlock? Just because it's a code that wipes it makes no difference. I'm not saying the agents were right to ask for it, but it seems like if you feel that your rights are violated you should refuse to unlock the phone, not destroy the content in front of them.
- HumblyTossed 2mo agoI think if I were headed out of country i would make a full backup of my phone, then wipe it and set it up using my old gmail account that i only use for spam and stuff, fwd my reservations to that account. I would not install my normal accounts on it. I would not install my bitwarden either. I would keep everything minimal, use web UIs where possible. then when i return, it looks like I use my phone and didn't wipe it but I also live a boring life. Small inconvenience for me, but better than dealing with bullies.
- cindyllm 2mo ago[dead]
- LWIRVoltage 2mo agoA few things: #1. The download and restore backup method would work- except it doesn't capture what people would need. Exmaple: I have some thermal cameras that rely on old 32 bit apps that do not run on anything android 12 onwards- If i wipe those old phones, and restore- the apps often wanted to reach out to a server for initial activation- they would fail upon reinstall and i'd be out of the apps that are required to control my cameras and related equipment,which is worth thousands and thousands and thousands. And it'd be all dead weight and rendered useless. (and competitors today do not compete- for example try finding a 640*480 30 hz or better form factor thermal camera that attaches to phones - they dont exist anymore) \The solution is imaging- but there isnt a way to fully image phones and restore backups today. There used to be it seems- but not really with the latest. Veracrypt- The weakness of truecrypt and veracrypt, the hidden OS option only worked if you converted your computer to MBR, which means you can't have a hard drive too large. Making a UEFI hidden OS has not been done yet. I am aware of Shufflecake attempting to make a solution. And the Hidden Volume option- isn't 'as' useful, and of course, your OS might make a copy and put it somewhere, you have to be careful. Any time I open a file, using the software tool Everything to search and confirm this- you can easily see Windows makes copies and temp files and whatnot in randomly named locations- that's the sort of behavior that would screw people over We need fully image-backup capable Phones. I mean fully. Not just backing up some apps- as this refuses to backup apps you have that are no longer on app stores, or that Play Protect doesn't like, etc. Next- Plausible deniability is a way forward- but you need multiple profiles, that are cryptographically indistinguishable, along with the phone being hardened so GreyKey /Cellebrite won't be able to exploit a way in. This needs to be built this way from the ground up ideally, eventually. There has been research about making devices that treat all block space the same way so you can't tell if someone has 1, or 50 profiles or partitions, etc- and even stuff that overlaps. But nothing has come out - and especially, for phones. After all, if you travel to a hostile country, you can tell them you have just one profile, and if they ask, you could theoretically mention a 2nd, and then show it- but you might have 3 more - and they'd all be immune to forensic inspection if the system is built right.(Yes, there's often issues you have to be careful of ,like setting this up so you dont destroy data when in other profiles,) This is how you solve this problem -make computing devices impossible to analyze
- g8oz 2mo agoAs this is Hacker News the focus is on GrapheneOS. I think the background issue of Cop City and the hysterical over reaction of the state of Georgia and now the feds to the protestors deserves discussion as well. The criminalization of activism (domestic terrorism, really?) does not bode well for freedom of Americans. https://prismreports.org/2023/06/07/escalating-tactics-against-stop-cop-city/ https://prismreports.org/2023/06/07/escalating-tactics-again...
- throwprivsec1 2mo ago[dead]
- Varelion 2mo agoSo much for innocent until proven guilty.
- Cider9986 2mo agoGrapheneos comment on hidden profiles/veracrypt style plausible deniability: >It's possible to make a semi-hidden feature but hiding it well enough to avoid detection by software forensic tools requires not basing it around profiles. It would really need to be a nested GrapheneOS in a virtual machine. It could also still be detected at an SSD level https://nitter.net/GrapheneOS/status/2081471477174456340#m https://nitter.net/GrapheneOS/status/2081471477174456340#m Here's some info from veracrypt on the SSD level. https://veracrypt.io/en/Wear-Leveling.html https://veracrypt.io/en/Wear-Leveling.html https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Trim%20Operation.html
- fooqux 2mo agoWhat I would like is a setting kind of like the already-existing safety feature on pixel phones. You set a timer and if you fail to end the timer or respond when it goes off, it calls 911. Instead, I would set a timer before going through customs and if I don't unlock my phone and disable it within a set time, it initiates a wipe. I think that would be a safer way of doing this than a duress PIN.
- VikingCoder 2mo agoI wish ATMs had distress PINs, too. The money comes out, but the cops show up.
- ninalanyon 2mo agoReading the comments here makes me think that even US citizens might be better off not trying to enter the US.
- onethought 2mo agoDuress pin should unlock a benign version with ai generated chats to ai generated friends about the latest benign topics. In the Age of LLMs we could generate a fake digital existence as fast as we can delete a real one. The goal is to appear like you complying without any evidence you are not. Graphene — build this feature!
- MetroWind 2mo agoI have said this in multiple occasions both on and off line. The world is converging to China in terms of how and how much the governments want to be totalitarian. China already has decades of experience on this, and is both strong and subtle in doing this; almost elegant. US and Europe just got started. It's just too good to resist. (For the government, that is.)
- game_the0ry 2mo agoAmazing that someone could be held in detention without even committing a crime. We are going back to pre magna carta and pre habeas corpus medieval justice. A lot of innocent people died in those times.
- eggplantemoji69 2mo agoProbably wiser to have travel-only devices that are clean by default
- mattm 2mo agoNote: The HN headline says "US citizen charged" but the article's headline and content do not mention his status at all.
- Mawr 2mo ago> When he finally provided a passcode, the phone appeared to restart. The defense motion states that "the screen went blank, flashed several times, and the phone appeared to restart," resulting in the loss of data. Tsk, amateur hour. I thought it's been decades since disk encryption software had two-password functionality that provided plausible deniability by booting into an alternative, clean OS. Impossible to prove intent to deceive. How disappointing to see such a naive phone wipe functionality, it's so obvious even non-technical people could probably tell what happened. Smh. It can't be that hard to design something at least a little better.
- Recoordinates 2mo ago[dead]
- h14h 2mo agoWhether wiping your phone is a criminal act seems could be a legitimate question depending on the circumstances. Whether authoring such a feature is itself a criminal act is an outrageous question, to which the answer should be an obvious, and emphatic "no".
- econ 2mo agoTo perhaps state the obvious, rather than wiping everything one should present a credible setup to the intruder.
- timoxley 2mo agoThe obvious answer is rather than wipe, have a pin code that logs into a convincing and clean phone?