US Government targets Cop City protester over phone operating system
theguardian.com
theguardian.com
Talk about burying the lede
Btw, here's a list of the zines for which people got charged as terrorists and sentenced for decades in prison for https://pnppl.cc/prairieland/
Sam was physically in the US, but because he was on an international flight, he was arrested in a manner that would be unconstitutional anywhere else in the US. He was denied a lawyer, questioned for I presume hours, had his phone stolen without a warrant, and then was released because there was no crime CBP could figure out how to charge him with then and there.
Months later, he gets charged by a federal statute even though where he committed the crime was a place that federal law does? doesn't? extend. Apparently it's a very convenient place where the constitution is void but federal laws still matter.
Cops can't arrest or detain you without some articulable suspicion of a crime being committed. They can't steal your stuff to try and find a crime you committed. They can't search your phone without a warrant in which they provide a judge with enough evidence to reasonably suspect a crime has been committed.
Yet Sam apparently had no rights because he was put on a watchlist for exercising first amendment rights.
Very despicable behavior by the government and the federal prosecutors pursuing this case.
It is not always obvious how necessary it is to get involved in politics, even if it is inconvenient, as Mr. Tunick demonstrates. I’m not American and don’t live in the US, so, what I can objectively do is very close to nothing- my advice is pretty obvious and far from unique.
It seems many countries have a general low opinion of politics, as something dirty you shouldn’t engage with. We need to overcome that.
https://www.aclu.org/documents/constitution-100-mile-border-...
Instead of wiping and rebooting, it should wipe while showing a lame spreadsheet application, or possibly a grocery list.
id expect that youd be ordered to retain the data though, if an investigation is being done
But this stance amounts to giving up. Within the wiggle room a system gives us there are still ways to widen cracks or attach a lever, however small they may be.
Leaked documents from mobile forensics companies, such as Cellebrite or XRY confirm this. It's impossible to crack a Pixel with GrapheneOS in BFU state. See https://grapheneos.social/@GrapheneOS/112462758257739953 and https://grapheneos.social/@GrapheneOS/112826067364945164
Do, I guess the cops will continue to beat me until I produce a valid passcode.
Doesn't really matter if the reboot timer is triggered if the thugs have beaten your code out of you.
It shouldn't be this way, but oh well.
The duress wipe feature shuts the device down to let RAM discharge, this is an important step to remove any components of decryption before they can be lifted.
For GOS to consider it, it would likely need to be backed by the secure element.
Duress PIN is deemed acceptable to implement in the OS because it is expected that the user is the one to enter it, so it has not fallen into the hands of attackers who may bypass it. Once attackers have it, you are effectively gambling. Account for that in your threat model and do not let it get to that point.
Government overreach cannot be solved with technical solutions.
Dark forest
Most of the EU is lovely.
So, I ask again: please, my American friends, fix the country. It’s a very nice one, I like it, and I miss visiting you. Your fellow contrypeople deserve better, even if this is what they vote for. I would love to be able to help, but I really can’t.
It is better to live on one's feet, than to die on one's knees.
You said that there are no partitions. That's wrong. There are no hidden partitions, because they would be ineffective. You can have up to 32 user profiles with different unlock methods, and within them you can have private spaces which are basically the same as user profiles.
User profiles and private spaces are great because they can allow more of your OS to remain BFU, which is more secure than AFU. They are great for security, but they provide no plausible deniability.
>The technical problem here seems to be that GrapheneOS apparently doesn't support logging in to a partitioned empty OS for scanning purposes
Initially you suggest deniable partitions. I explain that it's not possible to achieve robust deniability that way, because it would leave forensic traces.
>since even simple encrypted containers on mass-market Android devices work to shield the user.
User profiles and private spaces are encrypted, isolated containers, and they exist on Android and are enhanced by GrapheneOS.
The forensic trace doesn't grant access to the container.
That is about security, which is already fine. We aren't talking about security; we are talking about deniability. Your suggestion to add fake partitions would not be effective for deniability because it would leave forensic traces. Deniability with hidden partitions is not currently possible on the flash storage used in Pixels and all modern phones, due to wear leveling and many other critical problems inherent to flash memory [1].
> Initially you suggest deniable partitions.
That's nonsense because I never suggested a goal of complete deniability. You keep insisting I did, and attempting to bury the discussion on such grounds, but I never did.
No I did not mean that. There's means to fully encrypt applications and files, like on any modern smartphone. There's also user profiles and private spaces which allow you to separate your data and encrypt them differently. Notice "private spaces" and user profiles. There's no "deniable spaces"
There's no means to allow decryption while hiding data. The only deniability feature I'm aware of is the duress password.
>"Initially you suggest deniable partitions."
>That's nonsense because I never suggested a goal of complete deniability.
>"The technical problem here seems to be that GrapheneOS apparently doesn't support logging in to a partitioned empty OS for scanning purposes"
This is what a form of plausible deniability would look like. GrapheneOS isn't going to implement a non-robust plausible deniability feature.
>You keep insisting I [suggested a goal of complete deniability], and attempting to bury the discussion on such grounds
I never insisted that you suggested a goal of effective deniability. I only explained that GrapheneOS isn't going to implement a non-robust implementation of that feature, which is the only implementation that is technically possible right now.
The reason I'm emphasising an effective plausible deniability solution is because that's the only solution that would actually help anybody. It's also the only solution that would ever be implemented. A non-robust solution would give people a false sense of security and would therefore help attackers.
Honeypot operating systems like Anøm are the ones that hide the OS within a calculator. GrapheneOS is not gonna do something stupid like that.
I'm just informing you of the real landscape of the feature you want. I thought it was a nice thing to do.
However, it makes an erroneous equivocation that, I believe, has profound technical and legal implications. In the article's first paragraph, it claims that GrapheneOS "enables users to enter a passcode and wipe a phone clean". What the author of the article is referring to is GrapheneOS's duress password/PIN feature[1], which does not (contrary to what it may seem on first glance) delete or modify the data on the persistent flash storage phone in any way. What it does is zero the key slots in the phone's Secure Element, which stores the disk encryption keys necessary to decrypt the data on persistent storage (technically, these disk encryption keys are not themselves stored in the secure element, but are first encrypted with a key encryption key/KEK derived from a user-entered passcode/PIN and then stored in the secure element[2]. If an adversary were able to break the secure element and extract the contents of the key slots, they would still need to brute-force the KEK in order to obtain the actual disk encryption keys).
To my knowledge, US law does not explicitly say whether deleting the key necessary to decrypt a given ciphertext is equivalent to deleting the ciphertext itself. Technically speaking, they are not equivalent, even if it would take an exorbitant amount of time to recover a deleted key using a brute-force search or some forensic method. If the federal government wants to claim, using this case to set a legal precedent, that it is equivalent, then I would argue that this in effect makes encryption as a concept illegal (as encryption is nothing without the ability of the person using encryption to control access to the encryption key(s)). Reading about the recent Prairieland trial, in which (among other blatant injustices) an activist was convicted by a kangaroo court of "destroying evidence" because they merely removed someone from a Signal group[3], it's clear to me that Prairieland along with Sam's case is part of a coordinated strategy under the NSPM-7 "Antifa Memorandum"[4]: the federal government is using lawfare to establish that it has a right to arbitrarily access the data of its citizens in order to crush political dissent.
[1] https://grapheneos.org/features#duress
[2] https://grapheneos.org/faq#encryption
[3] https://www.theguardian.com/us-news/ng-interactive/2026/jun/...
I’m sure this case will be dropped because it will open bigger can of worms and may jeopardize the current practice of warrantless invasive searches at the entry points. Secretly I hope this goes to Supreme Court and once and for all they clarify on “constitution doesn’t apply at the border” piece of thinking
"Corrupting and concealing documents, interfering with their ability to be used in grand jury and criminal proceedings; Conspiracy to conceal documents that would implicate Maricela Rueda"
By removing people from the Signal group?
https://news.ycombinator.com/item?id=48994716
2 days ago 87 comments
If he was under arrest, sure. The cops claiming this was a routine airport inspection would seem to muddy the waters, at least.
Now, could that get tossed about because they denied him access to a lawyer? Maybe, I don't know about that part.
Isn’t the relevant bit whether you think you’re doing crimes and/or being investigated?
If I’m shredding while the cops knock on my door because they’re looking for a missing cat, that’s obviously not criminal. (I guess the more-pertinent comparison would be they knock on my door and then I put stuff in the shredder while I check around my home.)
Deletion to protect privacy does not prove deletion to prevent apprehension.
I could believe that everything is wholly innocent, but wish to protect privacy regardless.
They can prosecute him (and probably will) but he's got a pretty strong civil rights claim against the federal government for a false arrest and illegal search and seizure.
You can't arrest someone without a warrant or a reasonable suspicion of a crime. These thugs had neither when they arrested him, just that he's "a terrorist". That's why they were trying to get him to confess or commit a crime. That's why they didn't want a lawyer to get involved.
> A person commits the offense of tampering with evidence when, with the intent to prevent the apprehension or cause the wrongful apprehension of any person or to obstruct the prosecution or defense of any person, he knowingly destroys, alters, conceals, or disguises physical evidence or makes, devises, prepares, or plants false evidence
Is this legally true? At least in civil matters, destroying evidence typically causes the worst to be assumed about whatever was destroyed.
> Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed under title 11, or in relation to or contemplation of any such matter or case, shall be fined under this title, imprisoned not more than 20 years, or both.
I'm not a lawyer, but I think the federal law might be more damning since the law clearly doesn't state that there has to actually be anything of value on the device as long as there was "intent to impede, obstruct, or influence the investigation". Wiping a phone that they want to look at will impede the investigation.
GraphenOS has a couple of settings, a distress pin that wipes the device, and a number of failed attempts that will wipe the device. If the person handed over their "pin", they didn't need to
We wrote an overview of the features we provide:
https://discuss.grapheneos.org/d/40700-grapheneos-protection...
> (a) Every person concerned in the commission of a crime is a party thereto and may be charged with and convicted of commission of the crime
>(b) A person is concerned in the commission of a crime only if he: (1) Directly commits the crime; (2) Intentionally causes some other person to commit the crime under such circumstances that the other person is not guilty of any crime either in fact or because of legal incapacity; (3) Intentionally aids or abets in the commission of the crime; or (4) Intentionally advises, encourages, hires, counsels, or procures another to commit the crime
Seems like this is a clear case to me.