Cops can force suspect to unlock phone with thumbprint, US court rules
arstechnica.com
arstechnica.com
Payne was required as a part of his parole to reveal the passcode/password to his electronic devices. He had already told, when asked, the officer the color and location of his phone, then when asked for the passcode he denied the phone was his. That's when the officer physically forced him to unlock it with his thumb (this is the contentious part in the case).
The fourth amendment challenge against the search starts on page 10, and the fifth amendment challenge on page 21. The fact that he was a parolee substantially factors into the decision regarding the fourth amendment challenge.
https://www.forbes.com/sites/thomasbrewster/2021/11/29/fbi-n...
Press and hold side button + volume up (or down) button until you see a slide to power off screen.
You don't have to do anything - at that point biometrics have been disabled and only a pin will unlock the phone.
Parolees have restrictions placed on them as part of their release, including the right of police to inspect things on their person and property. If parolees find those conditions burdensome, they are more than welcome to reject parole and finish their sentence as it was originally imposed.
The word "parolee" is mentioned 99 times in the judgement. This is very much about someone who is on parole, who agreed to let law enforcement access their devices, and not about an average person that isn't under parole.
https://www.androidcentral.com/apps-software/how-to-disable-...
This is perhaps off topic, but does this mean you put your phone in your pocket with the screen facing outward? I do the opposite, am I weird?
EDIT: I suppose maybe you meant when the phone was on a table or something
it's kinda a fun trick when I'm showing people something on my phone and need to unlock it :)
1. Check your “Emergency SOS” settings. It is possible to set it so that holding down those buttons like that initiates a countdown to an emergency call. Depending on the exact settings this may also be accompanies after a few seconds with a loud alarm.
If you are trying to surreptitiously disable biometrics this might be irksome.
2. I think these procedures were different on earlier phones or iOS versions, so test it out.
3. It also works to click the power button rapidly 5 times. That too can be set in the “Emergency SOS” setting to trigger an emergency call so check that before using it.
For example, if your voiceprint were required to unlock your phone, but not a particular passphrase. Could you be compelled to speak (or just recorded speaking) general statements in order to unlock?
I'd bet that law enforcement will be routinely using backdoors to gain access to our devices long before the laws that protect us from giving up a password are changed.
This is practically impossible. IMO it has been impossible for as long as phones have fused the decryption key and the screen unlock key into the same thing. (Some older Android ROMs let you have separate unlock and deception keys; does anyone know of any that still do?)
Either you choose a strong encryption key, in which case you have to spend a ton of time typing it in every time you want to unlock your phone, or you choose something easy to type in which case the key becomes easy to crack.
And in either case you have to do it over and over again in front of other people or security cameras constantly recording you.
> And in either case you have to do it over and over again in front of other people or security cameras constantly recording you.
That's partly prevented by having keys randomize their position on the screen so that your movements don't give away your code, and also by occasionally changing your password. Obviously if a camera is looking directly at the screen while you enter your password you're probably screwed.
I don't believe I ever claimed that.
> I'd expect that a longer password would only increase your security but that even the shortest password wouldn't leave the data encryption trivial to crack.
How short are you talking? Most people do like 4-6 digits. That's not going to protect you against anyone brute-forcing keys on the raw encrypted data. Your only real hope is the TPM holding the real key and being physically secure, which you have no way to ensure. And that still fails due to cameras etc. as mentioned.
> That's partly prevented by having keys randomize their position on the screen
That's almost security theater. It really only protects you from laymen, not state actors. It forces you to use numeric digits if you want that, which itself makes your key much weaker.
> Obviously if a camera is looking directly at the screen while you enter your password you're probably screwed.
Which is guaranteed to happen at some point when you're in public.
Also, I believe things are different in civil trials too. I heard you might be compelled to give up a password and could even get in trouble if you claim you forgot it. It was a plot point in the Cryptonomicon novel.
Even if it doesn't include the government biometrics still leave you much more vulnerable. You leave your biometric information everywhere you go. Your face is easily found in photographs. Fingerprints are left on everything you touch. Your voice is easily recorded and deepfaked. Attacks on biometric authentication are well documented and while some seem pretty impressive (https://www.bleepingcomputer.com/news/security/scientists-ex...) others are embarrassingly unsophisticated (https://www.marketwatch.com/story/heres-how-easily-hackers-c...). Unlike passwords your fingerprints can't be changed following a compromise either.
I can also set a unique password for every device/service I use. Even if you managed to guess my hackernews password, that password would be useless to you for anything else. The face/voice/fingerprint that unlocks one device will forever be identical to the one that unlocks everything else someone has or will secure with it.
biometrics sacrifice huge amounts of security for the sake of convenience and an appearance of being "high tech" and "fancy".
I was just thinking that the average person's risk is going to be either casual snooping by people they know, or common theft for resale. In both of those cases, the weaknesses that biometrics present don't strike me as being a huge problem. They do exist, though.
Before biometrics, I would eventually know everyone in my home's pin unless I made a conscious effort to always look away each time they unlocked their phone.
I'd be cautious to use anything but biometrics on a crowded train.
I'm much more security-focused than most, and I don't use these features. I don't think that using them presents a real security problem for most users or anything, though.
The reason I don't use them is that I don't think they increase security enough to be worth the additional hassle and battery drain.
Edit: spelling
If my phone was handed to or taken by an officer, I would either quickly do the 5-tap on the lock button which will require a password (not faceid or touchid) next time, or, simply by them handling it, faceid would be locked out.
Is that not a thing with Android? I've seen articles where a suspect is requested or compelled to unlock a phone with biometrics which was held in evidence for months!
Does Android (and I know this is a much broader question than with iPhone) just allow touch/face ID in perpetuity with no locks on it?
1 - (I'm not sure what this is technically called)
When faceless Zombie thugs of a military junta beat you with a rubberhose you can give up successive passwords to deeper and deeper "secrets" until finally(???) your embarrasing stash of midget donkey necro porn is revealed!! .. and no one can ever establish whether there is yet another password that hides your local contacts in the resistance.
The success of this may vary in practice and black site .. but mathematically the theory is sound.
Today we have the less evocative name Deniable encryption.
Fun Trivia:
Rubberhose (also known by its development codename Marutukku) is a deniable encryption program which encrypts data on a storage device and hides the encrypted data. The existence of the encrypted data can only be verified using the appropriate cryptographic key. It was created by Julian Assange, Suelette Dreyfus, and Ralf Weinmann as a tool for human rights workers who needed to protect sensitive data in the field and was initially released in 1997.
https://en.wikipedia.org/wiki/Deniable_encryptionhttps://theconversation.com/profiles/suelette-dreyfus-1102/a...
I've spent 25 years fighting against intrusions in our rights. Admittedly, quietly and sadly, mostly unsuccessfully as every year things are eroded further and further.
I don't think the US will ever devolve into a scenario where the police will beat you for refusing to provide your password, I don't even think we will end up in a situation where police can legally compel you to give up your password. I think we will end up where cloud providers will be legally compelled to provide data on request (banning E2E) and consumers will be incentivized (both in unnatural and natural ways) to more deeply rely on cloud services.
> "When Officer Coddington used Payne's thumb to unlock his phone—which he could have accomplished even if Payne had been unconscious—he did not intrude on the contents of Payne's mind," the court also said.
I think that is a pretty reasonable interpretation.
The point is that the police can't prove you do or do not remember a code. Consequently, they can't compel you to use that code.
However, since your thumbprint definitely exists, they can compel you to use it.
As I understood it, the police can not compel you to tell them something you know because this would be analogous to testifying against yourself, however, they can require you to give them something you have (or something they would find with a warrant) because it is a physical thing, not testimony.
It's the difference between being required to give up a safe combination which the police can not compel you to tell them, vs, a key to a safe which the police could search you for and take from you and use to open the safe within the bounds of a warrant (or some other theoretical circumstances).
Also, they can't coerce you to reveal the code even if they can prove you know it. Confessions extracted under torture by inquisitors was a recent memory when the Bill of Rights was drafted.
If you keep incriminating documents in a safe, the police have every right (with a warrant) to cut it open and get the documents. If the safe has a code, you don't have to share the code, but only because SHARING the code requires you to be "a witness against yourself" in violation of the 5th amendment, not because you have a right to privacy in the safe.
It's hard to justify giving a fingerprint as being a "witness against yourself". So with a warrant or other relevant due process it's hard to object.
That said, I think bigger problems with this standard are coming down the line eventually.
Was very common for drug dealers to break their phones on being caught
The "good" cops might be reluctant to push back on this pattern because they see value in having such tactics in their back pocket for extraordinary circumstances (cf. the various "is torture justified in a ticking-time-bomb scenario" debates and thought experiments, or just most seasons of 24).
What does help is the power balances - how strongly the people will protest, it coming from one party and the other fighting it, and so on.
And to answer the flagged guy:
"so that means, as a regular citizen, I can interpret the laws how I want? since they are also words on paper."
No, it obviously means those that have the political power can interpret the laws how they want. So unless you have that kind of power, you'll need to stand by the interpretation others make of it.
How so? What witnesseth a fingerprint?