US citizen charged after GrapheneOS phone wipes during airport search
techspot.com
techspot.com
U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did. Hell there could have been a third set of four numbers that were the nuclear launch codes. It’s not the fact that it was four numbers, it’s what you were trying to make happen when you typed them. Now of course whether they can prove what your intent was when you typed them is another matter, but generally a duress pin should be for when robbers are breaking into your house, and the government will be on your side, and not when the government will be against you.
It's people who couldn't get out of jury duty. Prosecutors have high success rates. Federal prosecutor success rate is over > 90%. Studies of jury psychology show how much peer pressure and other factors extrinsic to the law come into play.
Remember what happened to Aaron Swartz. Law is the mask of power. By all means defend and assert your rights, but understand the costs. I find people are under such illusions about how cruel the American justice system is that this leads them to make foolish decisions. Do not underestimate the adversarial nature of the justice system, nor the accompanying incentives agents of the state who are on the other side of you have to lie.
Programmers have trouble seeing color (two identical numbers are the same bits, how can typing '1234' to unlock one phone be legal, and '1234' to unlock another phone be illegal?)
Courts care about color (intent, provenance, permission), even though that color cannot be digitally represented.
Him deleting his phone was very likely a matter of safety for his fellow activists. Sad that our government does this but it’s not like this guy was a drug dealing or something.
Love this way of putting it. Stealing for future conversations with fellow software developers.
When we met it was interesting how our jurors decided “I don’t believe anything that guy says” and so on when it came to their motives and so on.
The trial itself was very carefully choreographed, almost pre determined and static.
But the decisions and jury activity was very dynamic. There was absolutely no magic legal mechanisms at that point.
Want to see a really confused border agent? Travel without a phone. Fedex your phone to your hotel/home. Read a book on the plane. The concept that someone doesn't have a phone/computer drives cops insane.
One of the wikileaks crew pulled this one in NY. Several agencies were a set to grab his devices and detain him until he unlocked them ... But all he had in his carry-on was a magazine. His devices had been wiped and sent by mail. He re-imaged them only once he was home and safe. No devices to unlock, no reason to detain him.
From the article, it looks like warrantless search & seizure and lawyerless detainment over the suspicion of participating in plain old 1st amendment activities.
On another note, maybe GrapheneOS should add some kind of feature where the phone involuntarily destructs if a correct PIN isn't entered for 48 hours (or whatever the user sets at installation time, and changing the value should not be permitted). That way the trigger for the wipe is the confiscation, not the act of entry of a duress PIN. You could disclose the mechanism to the officials who intend to confiscate, and also say (truthfully) that you have no control over the feature.
However there are arguments morally, and constitutionally, and logically, about what can be done.
LOL, that made me chuckle.
People somehow think they're the first one to think of a workaround to a law, when in fact it's been happening since the first law was written down. The law adjusted and if people think they can do one thing, then claim they intended another they have a big surprise coming.
This is the thing that people should be reminded over and over here - and to be fair it tends to be more autistic than elsewhere
(Regardless if you are on the defendant or the prosecution side - or might potentially be)
The whole case is going to come down to the nuanced and often contradictory interpretations of border law exceptions. I also don't agree that these sort of protections are for e.g. robbers, because of the criminal underground's $5 in-person data hacking tool. [1]
[1] - https://xkcd.com/538/
When the judge and officers of the court agree with me, the law is reasonable and just, but when they do not agree with me, the law is arbitrary and capricious. ¯\_(ツ)_/¯
Having the law be whatever it's thought to be by police, prosectors, judges, and others can lead to obvious injustices, but there's been no serious attempt to remove ambiguity in any country's legal code as far as I know.
The rest (believing they can't do this or that, because it's in some constitutional document, or violates a basic right) is sovereign citizen kind of self-delusion.
"Ahah! I've won! The data has gone!! MUWAHAHAH! Take THAT border guards".... congrats you're still going to the same prison though.
If you've got something to hide (legitimately or not), don't take it across the border in the US or anywhere. Even then I am sure they'll either compel you to hand over your cloud passwords or again you end up going to the same prison for some other reason.
The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that.
The end result (not inherently different from what we wrote in the guide) is that you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to. I was fascinated by techniques for being unable to comply (which is straightforward to achieve if you want!) but probably didn't think enough about how much this might antagonize border agents in many cases.
I definitely don't know a comprehensive big-picture solution.
That's the same problem with technical solutions to crime.
I come from a very dangerous city and I used to have a car that needed a PIN to work. You could turn then engine on and drive but after a minute if you didn't input the PIN it would turn off without warning and start blasting the alarm. The idea being that if the car was stolen the thief would be stranded not far from home unsure about what's happening. Great technical solution but it ignores that a lot of the time the car is stolen with you in it (in a kidnapping, for example). Having the car shutoff in the middle of a highway next to a panicking guy with a gun and trying to remember a PIN is not a situation you want to be in, so I just had the PIN number written down on the dashboard, which worked very well when I was eventually kidnapped and just pointed at the piece of paper with the number.
Again in phone terms, maybe bring a blank phone through that border.
(Is this in South Africa?)
If it's a routine inspection, being uncooperative will probably lead them to escalate. You generally want to keep things routine and boring. If they want to access your device you have to weigh the costs, just log out of everything before you fly and throw away your device after they have had access to it, it's now compromised.
If you are targeted your compliance is irrelevant and only weakens your position, the thing is at the border you don't get all of the protections you get at say a traffic stop they can search everything you have on you without warrants reasonable suspicion or anything.
I am not a lawyer but if you are a citizen they probably can't deny you entry but can probably detain you for an uncomfortable amount of time, and seize whatever they want. Your best defense is to have a burner phone and no other devices nothing they can seize that would hurt you.
For foreign nationals pretty much the same applies except they can deny you entry and ship you off to alligator Alcatraz, just don't fly to America for a few years.
Remember he is not being prosecuted for not handing over his device but for destroying the data they were trying to seize, if he just let them keep the phone he would be Scott free. I.e.the best technical defense is secure encryption with a key thats long enough and not stored on the device.
Actually for the particular case the best technical defense is to not have any data whatsoever on you.
Even having a burner phone without any personal information on it can be deemed suspicious. It would be best for your phone to have a recently-reinstalled OS, with a few critical apps like Whatsapp or iMessage set up with a few personal messages sent. You need to be able to set those up without a password manager. Anything else needs to take place on devices that you aren't carrying with you. Fortunately enough people don't update their Facebook these days that just having an account that exists but you don't use will probably work, assuming you don't look like someone that would be obsessed with their socials.
Maybe there are USB thumb drives that operate like a YubiKey unless special setup is performed to access the storage inside? That's one way to carry data with you if you have to.
I get what you are saying, but this is incredibly expensive and not really practical for most people.
Perhaps your friendly smiling Yes-Sir-No-Sir-3-bags-Full-Sir act might just be enough to let you get on your way without anything else happening apart from a stamp in your passport.
Even the slightest hint of defiance or surliness from you to a border guard/policeman/etc - potentially at the end of a long shift, tired, angry, pissed-off or whatever - and you're straight away hugely more likely to have a bad day.
Finding strategies to "beat the system" will, I think, just be a shortcut to some other punishment/crime/taken-out-of-sight-and-given-a-proper-kicking-oh-they-resisted-and-went-for-my-gun/etc as this person found out the hard way by trying to be difficult.
I genuinely don't think there is a "get out of jail free card" or magic incantation you can say to get out of these situations apart from just smiling and being polite and not being a dick - if you get into a "who can be more annoying" competition, then the border guards/police will always win since they hold all the cards and will happily ruin your day/holiday/meetings etc by detaining you (its their job to do this after all)
There have been cases very recently in the US where the authority figures down dealing with the public are evidently in a very defensive, aggressive "us-vs-them" mindset, with an itchy trigger-finger to go with it. Don't be the person on the receiving end of a cop seeing-red because you're being a jerk.
The house always wins.
At some point, you should fight for what you consider basic human rights. Where you draw the line and how you fight is up to you.
It sounds like your attitude is to comply with whatever the authorities want.
It seems like a completely innocent person is the best one to push back on authoritarian overreach.
Am I misunderstanding something here?
Absolutely astonishing seeing people try the “I’m going to be as annoying as humanly possible” to the guy with the gun with the “my YouTube lawyer says I can” defense. You don’t want to have to defend your civil rights in court.
This goes doubly when at immigration where you basically don’t have rights.
This guidance also applies to: bank tellers, call takers, baristas, waiters, other people standing in line with you, the bus driver, your mom, the neighbors upstairs, the raccoon across the street, …
But I'd never unlock my phone for US immigration. That's my whole life on there, and they don't have the right to compel me to unlock it. Even there, be polite. You can say "no" politely.
Where this guy went wrong was actively wiping his phone. That's no good. What you do is put your phone in its most secure state (generally powering it off) before you reach the immigration desk, and then if they seize it, you have to trust its security to keep them from getting into it.
Being rich and politically connected would probably do it.
How hard would it be to admin-allow some apps to work across barriers. E.g., wallet apps work, airline tickets work, but email/socials do not.
the issue is that when a phone is unlocked, they can just plug in a USB device and scrape everything off it. The TSA agent may not be eyeballing a facebook account so much as plugging in an exfiltration software stack or malware.
https://www.eff.org/document/eff-border-search-pocket-guide
----
Seems the better strategy (for iOS) is come in with a plan to say yes to agents without pissing them off (like handing them an empty phone).
better to local back up, encrypt, upload to your home server etc.
Then login to a fresh iCloud account, selectively install apps, photos, and mail accounts. So it doesn't look like you're walking in suspicious.
> and about not angering the agents more than you plan to
When I was a teenager (long ago at this point), I got into an argument with a police officer over surfing in a certain area. It was pouring down rain, so he was annoyed he had to sit outside and wait for my friends and me to come to shore. Once we got in, he was telling me that he could take my surfboard and my car, and all other craziness. Being the dumb smart-ass I was at the time, I laughed and told him he was full of shit, among other things. He went to take a swing at me but his partner grabbed him.
We all go to court and the judge immediately dismisses the case against all my friends. I had a lawyer with me that I knew and he went to talk to the cop and when he came back over he goes "I don't know what you did, but that cop hates you." I get up in front the judge and he praises me for understanding the law (and I could still see the cop was visibly pissed), but then says he can't have me disrespecting and being a smart-ass to his cops and gave me community service that once completed whatever the ticket was would go away.
That's the reason I never traveled to the US and never will, just having IT security in your CV is enough to make the border gamble not worth it
Where I think people are a little confused here is not realizing that this would be equally illegal in many other countries. At least in the UK and France, border investigators also have the power to demand your PIN. And it is also illegal to wipe your phone during an investigation in those countries.
I wonder if border agents could coerce you into giving access to your internet file storage, though.
One of the best ways to get through airport CBP quickly without being overly hassled is to be overtly, clearly sick in a gross way. If you're about to vomit or have horrible diarrhea, they do not want you in that line any longer than you have to be. If they're the type to want to take people down a peg, they won't bother with you because they're already miserable, and if they like picking on the weak, they're probably going to go for a solo young female traveler who isn't ill.
Nobody wants to risk getting vomit on their clothes or in their work area, having to close a line and shuffle people around while their coworkers glare daggers, or subject themselves or their coworkers to the very fun smells of human bodily fluids.
At the same time, it isn't purposeful so it's not read as malicious.
Can they force you to log into another remote computer in another country to examine it? I'm not discussing politics, simply the solution that you can actually do now side of things.
I don't have any hope of this situation improving globally and my gut says it will get much worse over time. I wonder if in the future you will have to not only give them your computer but have some sort of follow up investigation of your "real" computer if you do this two device method.
While most of my Italian/Polish friends had 0 issues, on a handful of occasions people were stopped and questioned for hours with agents pretending full access to every single device and just overall treating you as criminals.
In one occasion a friend of mine stated that he was quite sure they just enjoyed that kind of sweeping power and it had nothing to do with border security, it was just fun to them.
In another one, the suspicion was on the fact that this person did not have socials, he just disliked them and had nothing except a Google account for Youtube. This fact made them super suspicious and the person was stuck at La Guardia for 3 hours, even his body was inspected. Disgusting.
Can you just like have the graphene OS device wipe itself if it knows that it's going through a border and you haven't logged into the device in 24 hours?
Or maybe, Enter into a precipitous one false move mode, where it's just about to wipe itself if the 24 hours elapses, And it does wipe itself if someone doesn't put in a code the next time the device recognizes that is being handled, within like 90 seconds of being picked up?
I thought about that. And I came to the conclusion that a phone is a pathetically bad device to both store your data and to access your data. Mediocre screen. Mediocre input methods. Moreover most phones happen to also be spying device.
So if you think about "protecting your data", a reasonable idea is that a lot of data is way better kept on your homelab, with say encrypted backups in a safe at the bank, at a relative's place, on a server you rent, etc., rather than on your phone. And there's really little need to access your data from your phone.
Oh and I'm no luddite: I've got a homelab, I rent servers, I pay three AI subscriptions, etc.
But my phone is boring. There's no app on it besides the stock ones (say Google Maps) and then I added the Google Authenticator app (for stuff still using that kind of 2FA).
If people were to wake up and stop being glued to that mediocre thing, the problem would already be 99% solved.
Like, get a cheap phone, install the bare minimum stuff you need for travel.
For extra safety, before returning home wipe it and just put back the exact apps you need for moving around (e.g.: ride hailing app).
Same thing with laptops, tablets, etc.
If your threat model includes US state actors at the national border, then your security practices need to account for the confiscation of your device at that border without requiring you to willfully wipe the phone and (in the eyes of police and prosecutors) destroy evidence.
That means:
1. Don't travel with anything you can't afford to lose on device. This means setting up travel-specific password managers and hardware keys for a subset of your accounts that you absolutely need to access while abroad, and being prepared to reset those passwords and disable those hardware keys very quickly once home.
2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. Your secure setup must function without needing you to engage in those behaviors, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable.
3. Consult with a lawyer and review your security procedures from a legal standpoint. All of the above is technical and practical advice, not legal counsel and no substitute for it.
We Americans are fortunate to carry powerful passports and enjoy relatively easy international travel but, for better or worse, that velvet glove covers an iron fist we would be foolish to forget or ignore.
> 2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. Your secure setup must function without needing you to engage in those behaviors, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable.
> 3. Consult with a lawyer and review your security procedures from a legal standpoint. All of the above is technical and practical advice, not legal counsel and no substitute for it.
Just don't go to the usa and if it's for professional reason, don't bring your personal phone.
There actually not that special, requiring a visa in 35 countries compared to 25/26 for most European passports: https://www.passportindex.org/byRank.php
Unrestricted access to the US is probably the bigger advantage you get.
Who said it was evidence? Did a judge authorize or issue a warrant to collect said evidence? Absent that, it's just your property, and you can do with it as you please.
Something like this may need to become the standars over duress pins which should be treated as a fallback or more extreme alternative. Right now, A single choice to reasonably and rightfully protect your privacy reuslts in jail time over something which likely wouldnt have resulted in any issues if superficial compliance was observed.
These goons, even if a branch of a facist regime, are ultimately burocrats with violent options to settle. They aren't doing forensics on your device etc. They have neither means nor knowledge to do so. They just need to tick their boxes. Did the phone unlock? tick. Did our spyware complain? no? tick. Overall appearance of compliance from person? yes? tick. free to go, next!
You just have to find ways to stay safe without agitating their workflow and all is well.
- [1] https://veracrypt.io/en/VeraCrypt%20Hidden%20Operating%20Sys...
this problem may be solvable by a purpose-built abstraction where every write no matter what address will look identical to the firmware (naively, a randomized key-value map).
See: https://news.ycombinator.com/item?id=49057812
Implementing it in a convincing way is harder than you think. Moreover if you're under the type of regime that will throw you in jail for not giving up a password, they're probably not going to let you off the hook because they can't definitively prove you have a hidden volume.
manufacturer published space = allegedly available space + size of known files
If you're hiding something in "empty space" it won't behave like empty space when you try to fill it.I think we need to be stenographically smarter. Like if there's some mechanism of deduplicating blocks across volumes, then perhaps when given the special key you could temporarily render a volume whose parts are hidden in the data already occupied by the other volume and then just run it in memory so that a reboot clears it.
See also relevant XKCD:
You’re just carrying a blank phone that you intend to set up and use later, and they can’t force you to install your backup onto a phone.
Now, this is sus as hell, and you’ll probably draw all kinds of extra attention, but if border security wants access to your phone in the first place, you’re already in a weird place.
It doesn't have to be blank - just clean.
They can just make this illegal too, and ask for the keys to your backup, or detain you until you do. Point is, you can't gain freedom through technology. It was always a political thing.
Now having a corporate device with little data is no longer outstanding. Everything is in the cloud these days.
As for personal devices, you can explain you're taking a dumb cheap laptop for your holiday as you're working on a desktop PC at home. You're not taking your entire house when you're on a trip, just a laptop to check tourism information and post blog posts
I myself bought a crap laptop on ebay to shove it in bags and backpacks and go to conferences and not be sad the day it's broken.
but above all, he's a citizen so shouldn't care about looking "suspect". He has a right, not a privilege, to cross that border. They can explain a judge how he looked sus if they really want to search his home.
Here is the statute Tunick is indicted under: https://www.law.cornell.edu/uscode/text/18/2232
There is an immediate problem: the device was being searched, and this statute criminalizes destruction of property to prevent seizure, not searches. I don't think this statute applies this situation. Regardless of whether the border agents could lawfully search his phone at the border, they didn't have grounds to seize it. I suspect this prosecution will quietly be dismissed within a few months.
As usual, government should have obtained a warrant if they wanted to search a US citizen.
Of course it’s about that huh. It’s quite scary how far the US will go against anyone who engages in this sort of activism.
Wonder if it’s just a fishing expedition
So there’s a feature called Duress PIN which as explained through some comments means you put a different pin which intentionally wipes the phone. It’s not auto wipe or wipe after several failed attempts but intentional wipe of device. (Worth explanation as the current title nor the article doesn't easily explain this was made by the US citizen providing the alternative passcode)
For more technical details:
> GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).
I believe the old TrueCrypt had two passwords, each revealing a different set of files. You'd put e.g. your tax forms in one, so if forced to decrypt your drive, you could cooperate and do so.
It's not illegal to delete your own vacation photos. So to prove this guy guilty of destruction of evidence, does the government need to prove there was actual evidence in the phone?
Most previous court cases involving encrypted devices have required substantial proof that the encrypted device contained incriminating evidence. To be clear "you sent this illegal thing from your house" levels of evidence.
It mostly seems inept, if you are going to push to expand your powers you do it on strong cases where you know what happened. Doing it on weak cases like this gives a judge an opportunity to shut down that without giving you a chance of a meaningful conviction and without that you won't get any benefits...
They don't have to, only that you destroyed evidence. That's why many people get prosecuted with "obstruction of justice" rather than the actual crime.
>While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device".
So if someone was doing insider trading, and the SEC came knocking, then immediately afterwards they start burning every document they have and microwaving their computers, do you think they should get off the hook? Surely you must think, even if the authorities or society can't a priori know you were guilty, the subsequent activity should be illegal? Note this isn't the same as banning burning documents or microwaving computers, only doing so after you're aware there's an ongoing investigation.
In many countries certain agencies / agents can do searches which normal law enforcement officers can't. Like not needing a search warrant or even probable cause. Not to mention that wiping a device could in itself be a crime, if it is suspected that evidence is being destroyed.
The key point here is that, as I wrote, some agencies have a lot of authority, and have the power to do pretty drastic stuff.
The terrifying line of this for me is: "before and during the search", namely the "before" part. Even if you wiped your device days before, they could always make the argument that you destroyed evidence back then because you were trying to prevent them from searching your device.
INAL so not sure if this would hold up in court.
In many countries other then the US like Ireland, they have key disclosure laws which require you to testify against yourself.
In the UK, police can even require key disclosure without a judge.
> It's concerning – and sends the message that [GrapheneOS] is criminal by default
What's with this sensationalism? The GrapheneOS phone didn't just wipe itself - the defendant actively took steps to wipe it. The defendant isn't being prosecuted "by default" for having a GrapheneOS phone. He is being prosecuted for what he actively chose to do with that phone.
If your argument is that the search and seizure was unconstitutional, and you're within your rights to wipe your data, then argue that. I'm very sympathetic to such arguments. But stop with this "they prosecuted me for having a GrapheneOS phone" misdirect
The officer will say something like "That's your choice, but I will need to seize the device to conduct an analysis. It will be returned once the analysis is complete".
Then you shrug, and they will let you enter the US. The cops will try to get into the phone, fail, and return it to you.
Just bring a phone you don't mind losing for a few months.
This is practically the only thing I care about here and there are almost no details. What was his alleged involvement? How many others were targeted?
> "the screen went blank, flashed several times, and the phone appeared to restart,"
How about flash some red lights and play an airhorn sound effect, too.
Also they can plant evidence if you unlock the phone.
My understanding is phone’s security model aren’t designed for multiple user accounts
Do you think things are going to improve in our lifetime?
Also they can plant evidence if you unlock the phone.
WTF.
If you don't trust a government, ensure you aren't carrying any information you don't want to give up before entering their borders where you will be under their power.
No. They'll arrest you just the same for obstructing their search. Then they'll keep you in detention for a long time while you say "I can unlock it for you! You just have to let me out!"
You can pretend you have leverage and say they need to cooperate with you. But once you're detained, police and prosecutors don't really care about cooperation anymore. Their idea of cooperation is you giving them what they want immediately without question. You're made into an example if you don't abide.
They would quickly learn of this feature and stop inputting pins given by users until they can consult forensic experts. I expect this will happen with all passwords handed over on pixels since this publicity.
This is like saying it's my car's fault if I decided to drive onto the sidewalk or something.
But "GrapheneOS! Spain! Profiling Pixel users! Spain equates GrapheneOS to criminals!" sounds far more spectacular and will give more clicks/links. Sadly, it feeds the narrative that GrapheneOS is just for activists/criminals/whatever. An iPhone in BFU state would have been nearly as safe, but nobody makes these implications about iPhones because everybody has iPhones.
While he technically did use a special GrapheneOS feature to wipe his phone, the criminal charges would have been the same if he had used the default "reset phone" feature on Android or iOS right before handing the phone over.
The real focus of this case should be on the reason for his detainment and the confiscatation of his phone and multiple refusals to contact his lawyer.
They would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security.
>Experts said the legal approach is unusual and may be the first time the law has been aimed at an operating system. "It's concerning – and sends the message that [GrapheneOS] is criminal by default," said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.
Is the actual case about banning the OS? Because it seems pretty clear the case is about the result (the phone being wiped with a special passcode).
The better defense imo would be one of those 'wipe the phone if you get the password wrong x times' and try and claim you forgot under pressure. At least if you wanted to wipe the phone without being accused of destroying evidence during a search.
I strongly disagree with the border search exception and would like to see it drastically limited or abolished.
It is also something that has clearly existed in caselaw for decades (arguably for centuries) and that the courts have routinely (to my regret) strongly reaffirmed.
The border search doctrine says that border agents do not need a reason to examine you or your possessions when you are entering the country. They do not need to believe that you are doing something wrong or committing a crime. If they suspect you, they don't need proof or a good reason to investigate you.
I find this doctrine very disturbing and I hope it will be changed or narrowed. I also would like people commenting in this thread to understand that border agents are not just imagining things when they claim to have legal authority to inspect people (or, alas, electronic devices or data) at the border, and that this didn't just start under the Trump administration or something.
The legal consequences of providing a duress PIN may not have been tested and this defendant could well prevail in this case. I just wish people commenting here would understand that there is a tremendous amount of history related to border search authority. You can disagree with it (I hope you will!), but you should understand that it's not just something that someone just made up last week or last month or last year.
There's no US law requiring key disclosure and there have been mixed court cases outcomes on whether people have to provide encryption keys.
Small inconvenience for me, but better than dealing with bullies.
On the duress pin, they say (read the whole thing though):
> People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device.
Instead, I would set a timer before going through customs and if I don't unlock my phone and disable it within a set time, it initiates a wipe. I think that would be a safer way of doing this than a duress PIN.
https://arstechnica.com/tech-policy/2020/02/man-who-refused-...
It's his device, so he can do everything he wants to. The USA is currently re-purposing constitutional protections. A judge has not signed these warrantless seizures, so why would the individual be under any obligation to cooperate? Besides, why would anyone want to incriminate oneself? The onus would be on the state to prove a guilty state.
I really don't like this title. Officers asked him to open the phone, which he pretended to do, but instead wiped the device
> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart. The defense motion states that "the screen went blank, flashed several times, and the phone appeared to restart," resulting in the loss of data.
The title implies the agents maybe entered too many pins by mistake and the device auto-wiped, or that it reset itself with no human intervention, which isn't what happened. This is more like shredding paper when the FBI arrives at your office, which most people would attribute to destroying evidence. I hope he wins the case in principle (I think there's a risk of a slippery slope here) but it wouldn't be a moral tragedy if he lost.
The powers of investigators special rights and abilities rely on them being used very rarely. Last thing the terrorism investigators want is media coverage exposing their tactics.
I dont use grapheneOS, but it seems he activated a self-destruct code after being arrested.
That's always been illegal, and computers don't change that:
Arthur Andersen LLP v. United States (2005)
On the surface this case sides with evidence destruction, except
"Chief Justice Rehnquist noted that routine document management is not inherently corrupt; to be a felony, the government must prove the defendant had a "consciousness of wrongdoing" and a specific intent to obstruct a known or imminent proceeding" [1]
He fellow obviously had a consciousness of wrongdoing since he purposely set the delete triggers off during a police interrogation!
>It's possible to make a semi-hidden feature but hiding it well enough to avoid detection by software forensic tools requires not basing it around profiles. It would really need to be a nested GrapheneOS in a virtual machine. It could also still be detected at an SSD level
https://nitter.net/GrapheneOS/status/2081471477174456340#m
Here's some info from veracrypt on the SSD level.
The money comes out, but the cops show up.
In the old TrueCrypt containers you could set an optional second password that would decrypt a different volume. The size of the container file was always the same, a decrypted volume always showed the full container size, the portion not occupied by the data in the main volume was filled with noise, and the data on the non-loaded volume was not protected (so you could erase it without warning by storing too much on the loaded volume), making it practically impossible to prove the existence of a second volume either way in a search situation. I guess there was a reason why the project was stopped.
https://nitter.net/GrapheneOS/status/2082153517234676150#m
This is the kind of thing that loses cases, even if they were legitimate at first. Seems like the prosecutor is desperate charging for the phone wipe cause they didn't have any evidence of terrorism, child-pornography, etc. The problem they have now is given he was in custody and agents pressured him to provide the passcode that they then incompetently put into the phone, the fact that they denied him a lawyer multiple times means there is a very strong argument that his rights were violated. Typically, courts suppress any evidence when there is a violation like this with someone in custody. So the compelled passcode, the phone's reaction when that passcode was entered, and the agents' testimony describing the supposed wipe would be thrown out by most judges. What's left for the prosecution after this is jack and shit, but jack left town.
Not sure why the police and news are saying that he destroyed evidence, since the evidence (as it always has existed before the search began) remains on the disk.
Or better, have PIN for taking you to your criminal/secret profile instead.
Also they can plant evidence if you unlock the phone.
> According to court testimony, federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City.
I didn't know about Cop City, but I found this on Wiki: https://en.wikipedia.org/wiki/Cop_CityThis part is interesting to me:
> RICO conspiracy indictment
> In September 2023, sixty-one people who had been arrested in the forest or at stop cop city protests were charged with racketeering under Georgia’s RICO law. This indictment is likely the largest criminal conspiracy case ever filed against protestors in the US.
> As of April 2025, the racketeering case was stalled. Defendants in the case maintained their innocence and reported difficulty getting work and other hardships while they awaited trial for more than 20 months. In September, all RICO charges were dropped. Judge Kevin Farmer found that the Georgia Attorney General did not have the authority to bring RICO charges in the case.
From my outside view, it looks like these investigations are nothing more than an attempt to suppress free speech and protests.For anyone unaware, RICO is both a Federal law and a Georgia state law that stands for: "Racketeer Influenced and Corrupt Organizations". It is used to take down mafia, gangs, organized crime, etc. It is a bit sad to see state prosecutors trying to use this against protesters.
The criminalization of activism (domestic terrorism, really?) does not bode well for freedom of Americans.
https://prismreports.org/2023/06/07/escalating-tactics-again...
I realize that in this case the person repeatedly asked for a lawyer, but if you are in a borderline authoritarian state, all bets are off.
If he had simply refused to provide the unlock PIN, he would have walked away. They may have kept his phone, but they would never have got anything from it anyway.
I'm confused to understand if Tunick did anything illegal here. If the authorities want the phone, they should have the warrant and seize it without Tunick's permission.
It appears authorities did not have the warrant which give Tunick all the right to do whatever he desires with his property.
What am I missing here?
What they got him on, is that supposedly he destroyed evidence.
If you don’t want something searched do not bring it across the US border. There is very clear constitutional and statutory authority for these searches.
However, if Tunick was smart he would have refused to provide the PIN, and let them seize it. He'll get it back eventually, but it was in his right to refuse.
Before entering the airport you set your device to auto-wipe after x hours.
Once you are sitting in the airplane and flying, you cancel the scheduled automatic wipe.
[1] This is in contrast to many other Android phones outside Pixel and Samsung flagships, because they are too cheap to add a secure element, which iPhone has had since 2013 and Google Pixel since 2018.
Also they can plant evidence if you unlock the phone.
If Customs already knew whether the suspect had incriminating files on his/her phone things might be different.
Even then, they'd have to produce such in court. ?
Anyone know if this is a viable strategy on iOS, and what the required pin-length is these days?
Make sure to get to BFU though through restarting.
In the Age of LLMs we could generate a fake digital existence as fast as we can delete a real one.
The goal is to appear like you complying without any evidence you are not. Graphene — build this feature!
The reason is because anyone running an os with a duress PIN that has done nothing wrong can be accused of using a duress PIN because the whole point of the duress PIN is that it looks like you just have a normal phone.
Running a normal apple operating system with just stock apps? Boom, you're a criminal because you obviously used a duress PIN and have something to hide! There is no way to prove you didn't use a duress PIN because the phone was "wiped."
Now unfortunately grapheneos probably leaks information so that a duress "unlock" can be differentiated from a standard unlock by some means. If not then kudos. It looks like it is done instantly by keeping everything encrypted and just zapping the keys, but it also needs to actually unlock to something instead of rebooting to prevent leaking the information that a duress pin was used. Not sure how fiesable that would be though.
Whether authoring such a feature is itself a criminal act is an outrageous question, to which the answer should be an obvious, and emphatic "no".
https://nitter.net/GrapheneOS/status/2082153517234676150#m
Instead of wiping it clean, wipe to innocuous mode. Then the burden on their part is not only to show that I gave a bad pun, but that the innocuous mode is materially different than the previous state.
https://nitter.net/GrapheneOS/status/2082153517234676150#m
Of course TSA agents become angry when they enter the PIN and see a message "wiping device".
https://nitter.net/GrapheneOS/status/2082153517234676150#m
So yes, we've created an authoritarian hellhole, but the alternative is even MORE unthinkable: struggling to pay for parking in some areas, needing to visit a website for a menu or (GASP) visiting a different restaurant, or just having a friend order for you.
No, these are too much to ask of anyone. No one can overcome these challenges. The only answer is to weep for the liberty that we have lost.
If it were a box of drugs and he triggers an incendiary device - he's in trouble . If agents trip a protective boobie trap and destroy the box- he is fine.
Don't know why but this feels correct to me.
Even if the accelerated executive capture of the judiciary is largely ruled back post Trump (big IF), I fear the government will be unwilling to pay with much of the convenience of rule-by-law that it's been given a taste for.
1. What happens if the masses just do this? Today it's just a few folks who know how to do this. Tomorrow it could be 10, a year later 100. What's to stop 1000s from doing this and then what is the government going to do? Ban the OS and block it on Github?
2. What exactly happens after you're charged? This doesn't mean the person is convicted. Just that they now have to show up to court wherever the trial is held and have to retain their own lawyer (or public defender?). And what is the likelihood that the case is thrown out or the person is convicted and receives a stiff penalty?
I ask these questions because as far as I can tell, the person was not suspected or convicted of anything, and it's infuriating me that we are just going to stop random citizens and ask for their private data.
Tsk, amateur hour. I thought it's been decades since disk encryption software had two-password functionality that provided plausible deniability by booting into an alternative, clean OS. Impossible to prove intent to deceive.
How disappointing to see such a naive phone wipe functionality, it's so obvious even non-technical people could probably tell what happened. Smh. It can't be that hard to design something at least a little better.
I think the issue is that people expect the USA to be the "land of freedom" when it's not anymore. It's turning more and more into an oligarchy and we are at the point where it's just as bad as russia or china.
If i was offered a trip to China or russia, i'd go but i would take a burner phone with absolutely nothing important; It's the same for the usa now.
China wants tourists and don't care about your stupid social media.
#1. The download and restore backup method would work- except it doesn't capture what people would need. Exmaple: I have some thermal cameras that rely on old 32 bit apps that do not run on anything android 12 onwards- If i wipe those old phones, and restore- the apps often wanted to reach out to a server for initial activation- they would fail upon reinstall and i'd be out of the apps that are required to control my cameras and related equipment,which is worth thousands and thousands and thousands. And it'd be all dead weight and rendered useless.
(and competitors today do not compete- for example try finding a 640*480 30 hz or better form factor thermal camera that attaches to phones - they dont exist anymore)
\The solution is imaging- but there isnt a way to fully image phones and restore backups today. There used to be it seems- but not really with the latest.
Veracrypt- The weakness of truecrypt and veracrypt, the hidden OS option only worked if you converted your computer to MBR, which means you can't have a hard drive too large. Making a UEFI hidden OS has not been done yet.
I am aware of Shufflecake attempting to make a solution.
And the Hidden Volume option- isn't 'as' useful, and of course, your OS might make a copy and put it somewhere, you have to be careful. Any time I open a file, using the software tool Everything to search and confirm this- you can easily see Windows makes copies and temp files and whatnot in randomly named locations- that's the sort of behavior that would screw people over
We need fully image-backup capable Phones. I mean fully. Not just backing up some apps- as this refuses to backup apps you have that are no longer on app stores, or that Play Protect doesn't like, etc.
Next- Plausible deniability is a way forward- but you need multiple profiles, that are cryptographically indistinguishable, along with the phone being hardened so GreyKey /Cellebrite won't be able to exploit a way in. This needs to be built this way from the ground up ideally, eventually.
There has been research about making devices that treat all block space the same way so you can't tell if someone has 1, or 50 profiles or partitions, etc- and even stuff that overlaps. But nothing has come out - and especially, for phones.
After all, if you travel to a hostile country, you can tell them you have just one profile, and if they ask, you could theoretically mention a 2nd, and then show it- but you might have 3 more - and they'd all be immune to forensic inspection if the system is built right.(Yes, there's often issues you have to be careful of ,like setting this up so you dont destroy data when in other profiles,)
This is how you solve this problem -make computing devices impossible to analyze
smuggling endangered species? bad. okay search a suitcase.
having unrestricted access to all my gmails because i need to catch a plane? absolutely unacceptable.
having your phone autowipe when pressed by authority? quit whatever nefarious shit you're doing, thanks
Nope, in the US.
feds: "unlock your phone or else" victim: "um, you're stressing me man. It's either 1234 or 4321, I forget. One of them wipes the phone, the other will unlock it."
Whichever PIN they try, it wipes the phone, but the feds can't claim it was deceitful, just unlucky.
More:
If you're paranoid enough to be using GrapheneOS, why would you take it to an airport in the US of all places?
I bought a second hand iPhone for overseas trips, which my daughter promptly stole because she wanted an iPhone, but then i got her old android phone, which was LineageOS-compatible, so that became my travel phone.
- presumably border patrol wants to see his photos, social accounts, and email. A separate device with a copy of the information they want isn't a defense. Creating fresh travel-only accounts is tedious, b/c fresh accounts aren't connected to your friends or network (with whom you'd want to share your trip with).
www.github.com/jegly/box
If so, "normal" police would not have the "keys". This would be "the compromise".
It's a small part of the protection of the OS. Perfectly secure without it.
More: https://discuss.grapheneos.org/d/40700-grapheneos-protection...
It's not stated, but probably we can assume the person didn't ask for his phone to be searched - probably he asked NOT for it to be searched, at least based on his multiple requests to talk to his lawyer.
Considering those factors, I'd say border patrol is more responsible for wiping the phone than the person.
(1password has a “traveling” mode that wipes it of sensitive passwords before going across borders. Is that suspicious? Should it be criminalized?)
Are we supposed to live in a world where if I'm crossing a border I must give access to all of my information? That's absurd and more equivalent to a full brain/memory scan than a suitcase search from your example. This is dystopian in every sense of the word.
In all cases just don't cross security checks with evidence you wouldn't want to be seized, its not that hard
The Bentham business is alive and kicking.