As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
Having thugs on speed dial opens a lot of doors.
Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.
https://nccriminallaw.sog.unc.edu/2026/08/03/giving-police-a...
We'll have to see how that case goes but ultimately the reason he's getting in trouble is only tangentially related to his phone being encrypted. It's more correct to think of it like he smashed the phone to pieces (and imagine this definitively destroys the data for the sake of the metaphor) instead of it being about the encryption itself.
Though I would expect courts to consider that he knew LE planned to enter the provided PIN, and that the duress PIN would then result in the phone being wiped, and therefore accuse him of doing the wiping anyway.
But I don't think it's this guy's fault at all. LE is the one who asked him under duress, he easily could've feared for his life, and he did no direct harm. It was self-defense at worst.
Setting a booby trap to destroy evidence that then gets destroyed when that trap is triggered is the same as destroying evidence. This is common sense, but also see https://en.wikipedia.org/wiki/Principal_(criminal_law)
It's been a weakness in destructive duress codes since their inception.
You can still be held in custody for obstruction of justice:
https://www.findlaw.com/legalblogs/third-circuit/man-held-in...
It took four years before he could secure his release:
https://www.sophos.com/en-us/blog/suspect-who-refused-to-dec...
But that's all beyond the point, anyways. If they did hand you your phone and said, "enter your passphrase," you can just say, "I don't remember it." They can throw a fit and put more heat on you in various ways, but until they resort to torturing you or they develop mind-reading technology, there's not much they can do at that point until the case reaches a judge.
That's not to say "I don't remember" is a sound, blanket defense. But it's sufficient for demonstrating that these dynamics all depend on willing participants which is partially why these laws are designed the way they are.
> But it's sufficient for demonstrating that these dynamics all depend on willing participants which is partially why these laws are designed the way they are.
What happens if during serving a search warrant the door is impossible to open or they find a super reinforced safe. Owner can even say "I don't remember the combination"?
keep in mind that the "obstruction" charge can be and is abused as a catchall charge.
He didn't provide an incorrect code, or no code at all, he provided a duress code intended to destroy the device. There's a huge legal difference.
There's a difference.
SCOTUS: Hold my beer…
:)
Note that the recent high-profile case of a man being jailed involved him refusing to decrypt, rather than claiming he didn't know. He was deliberately trying to test the law regarding the permissible scope of inspection of digital data, to force the matter into the courts so the issues could be litigated in a controlled context untainted by other potential crimes; being arrested and charged was part of his plan.
>As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
Yes, it seems that way in the US: https://news.ycombinator.com/item?id=49922513
If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.
If you really want to keep this stuff on a phone at least stretch to a second phone and keep it somewhere safe.
Why...?
If I had anything I didn't want the authorities to get, I'd remove it from my phone before travel (e.g. put in cloud, etc).
Yes it's bad that the government overreaches, but it is also bad for your mental health to worry about it.
The majority of people walking in the worse neighborhoods of LA or Chicago never have a single crime happen to them. But that doesn't mean that it's safe to go in a bad neighborhood - and it really doesn't mean it's safe to go there wearing designer clothing, gold watches, diamond rings and wearing your Apple VR device.
The same is true for travel. It's perfectly safe for the vast majority - but it's very important to be aware what may make you a target and what can happen to you if you are. Tens of millions of people visit the UK or China every year with no incident. But if you're a public active supporter of Palestine Action, or an active demonstrator against the CCCP respectively, be aware that you personally face a real risk from this travel, and your devices are actually very likely to be searched at those borders. Vice versa though (anti-CCCP activist traveling to UK, PA activist traveling to China) is perfectly safe, though.
(CCCP = Union of Soviet Socialist Republics...)
>CBP only searched the electronic devices of 55,318 international travelers,” the agency wrote, or 0.0013%.
would suck to be one of those 55 thousand people. I've never been bitten by a shark but I sure care about people that have?
It seems more like they're trying to determine that it is in fact a laptop and not something resembling one.
Edit: now I am gleefully thinking about how I would craft my decoy desktop persona. What gives me the most effective non interesting profile.
https://www.aclu.org/news/privacy-technology/can-border-agen...
> could cost me my home and life savings
but it's entirely fair to point out that Cryptomator itself is not a crypto wallet. I just know too many people irl that have lost thousands of dollars because they lost crypto private keys.
> Cryptomator
Much security is poorly implemented; you can't count on it being effective. Even Apple, which takes security very seriously and has world-class talent and enormous resources, fails to implement security effectively sometimes (as in the OP). Can Cryptomator do better? Find the most respected - by professionals - security solution you can.
And on a device with many other functions - all the things you use your phone for - you risk all sorts of security holes in every function of app you use. And what happens to the data when your phone is backed up? Store the data on a single-purpose device.
Also, on an Internet-connected device, you make the data potentially accessible to the entire Internet. Use offline storage.
Bringing the storage device with you everywhere is asking for a mistake on your part - losing it, etc. Hide it someplace.
> or legal access
Ask a lawyer.