I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully).<p>The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that.<p>The end result (not inherently different from what we wrote in the guide) is that you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to. I was fascinated by techniques for being unable to comply (which is straightforward to achieve if you want!) but probably didn't think enough about how much this might antagonize border agents in many cases.<p>I definitely don't know a comprehensive big-picture solution.
> you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to<p>That's the same problem with technical solutions to crime.<p>I come from a very dangerous city and I used to have a car that needed a PIN to work. You could turn then engine on and drive but after a minute if you didn't input the PIN it would turn off without warning and start blasting the alarm. The idea being that if the car was stolen the thief would be stranded not far from home unsure about what's happening. Great technical solution but it ignores that a lot of the time the car is stolen with you in it (in a kidnapping, for example). Having the car shutoff in the middle of a highway next to a panicking guy with a gun and trying to remember a PIN is not a situation you want to be in, so I just had the PIN number written down on the dashboard, which worked very well when I was eventually kidnapped and just pointed at the piece of paper with the number.
And there's the problem that if the PIN or worse a biometric version of this becomes remotely well known you've now created an incentive for a car thief to kidnap people even if they only want the car.
In phone terms, that's the $5 wrench problem. The elaborate tech is not relevant if you can be simply coerced somehow to bypass it.<p>Again in phone terms, maybe bring a blank phone through that border.
As one does. Why, six of the eleven times I've had my car stolen, it was a carjacking with myself or my family member in it.
Why are you staying in this place?<p>(Is this in South Africa?)
We probably need honey pod fake OS systems that boots up if not properly handled displaying some stars & stripes as background image and having the US national anthem playing for any sound the OS is trying to play.
Don't forget to have the Official Social Media of the President of the United States(tm) installed, with an account following the correct list of truthtellers and rightthinkers.
This would unironically probably work pretty well. The bullies in airports don't have that much time to investigate a phone which "looks good".
I would prefer to backup and wipe my phone before travelling.<p>Then have some planned means of restoring the backup when it's safe to do so.<p>Being caught with a honeypot looks much worse than being caught with a new phone. You can always say you bought a cheap "travel" phone if asked.
Yeah, you really can’t outsmart those with physical power and authority over you. Americans have asked for, or tacitly accepted this treatment of their visitors. The only big-picture solution is to stop visiting.
can you share the link? This?<p><a href="https://www.eff.org/document/eff-border-search-pocket-guide" rel="nofollow">https://www.eff.org/document/eff-border-search-pocket-guide</a><p>----<p>Seems the better strategy (for iOS) is come in with a plan to say yes to agents without pissing them off (like handing them an empty phone).<p>better to local back up, encrypt, upload to your home server etc.<p>Then login to a fresh iCloud account, selectively install apps, photos, and mail accounts. So it doesn't look like you're walking in suspicious.
This seems like an insane thing to have to do for visiting a supposed first world country. If phones had been around during USSR times I imagine you would have had to do the same. Personally I will rather just avoid any travel to the US, and I hope others do the same.
Security concerns you need to think about when visiting the US are absolutely no less than those when visiting China these days. Treat it like a totalitarian dictatorship with more technological means.
Honestly, I personally would be less nervous visiting China.
Maybe marginally, but I'm still not visiting any county where I would be in trouble if the government/police knew my opinions of them. That's not just the obvious ones like US, Russia and China, but also countries like Thailand, Egypt, UAE, Israel to name a few. I like seeing the world, but not that much.
At this point I'd be less nervous about vising North Korea.
This has become a running joke with a couple of the people in my office who have recently visited China (from the UK).<p>The next 2 years will be interesting for democracy as a whole.
I haven't been to the US since Trump first got elected, but even before that, immigration agents often seemed oddly adversarial, whereas immigration agents in China just don't really seem to give a shit.
Nobody in China cares about your phone/laptop.*<p>*Unless you are (well) known dissident/journalisy/politician.<p>US is much more totalitarian than China. Lived in China for years, had multiple times various visa/residence permit issues with police and guess what, nobody cared about my electronics or was sending me to any detention, all I've got were quie helpful officers trying to find workarounds for me to deal with the situation.<p>Same thing on my last trin in summer 2025, we didn't stay in hotel, didn't go to register to police as you are supposed to and when crossing province border checkpoint guess what happened - they let us go to our tourist sight and told us to just register after weekend and as usual officers in police station couldn't care less, they just registered us without any issues.<p>You can complain about plenty things in China, there sure is a lot of bureaucracy but when you actually have to deal with them, they are pretty laidback and trying to be helpful usually.<p>By these standards and my experiences with registration in police stations in other two EU countries I can tell you China was the friendliest most laidback and convenient experience.<p>People who claim China is totalitarian dictatorship clearly never been to China and should get off their high horse, China nowadays make less trouble for their own citizens than EU hating them trying to make lives of EU citizens as inconvenient and expensive as possible.
I wouldn't say you are overreacting at all. I know someone who was detained for months on US soil after a phone search where the only "evidence" against him they found is illegal content sent by someone else to him on a group chat he doesn't even check. Had to get a lawyer and spend time in prison just waiting to be deported back.
The US is first world on a technicality: the first world is defined as countries that were allied with the US during the cold war. If not for that, it'd be classified as developing.<p>It's common to mix up developing/developed and third/first world because they were largely aligned during the cold war. But there is one first-world developing country.
The biggest economy in the world and the richest country to have ever existed is not a developing country, although it is quite unequal. What you've stated is political rhetoric that you want others to accept as fact.
This is not true. However, because of the massive inequality, I often found it easy to use a sentence I saw somewhere: <i>"the US is a South American country that happened to become successful"</i>.
Why do yo think the US should be classified as a developing nation?<p>There’s a definition independent from 1st/2nd/3rd world [0] and the US’ income seems to clearly make it developed.<p>[0] <a href="https://en.wikipedia.org/wiki/Developing_country" rel="nofollow">https://en.wikipedia.org/wiki/Developing_country</a>
Yes, I will probably never go back to the US. But I find it sad that my kids for example, will have to think twice before visiting, if they do.
I used to love visiting the US. I have many friends there, and I really enjoy staying in places like Seattle and SF. But I haven't gone there since Trump 1.<p>That said, I think protecting your privacy is a good idea in general.
> for visiting a supposed first world country.<p>... which by now is a banana republic of the worst kind. Can you interact sanely with an insane counterpart? Avoiding to visit would be my recommendation too.
Just out of curiosity, like what country would you not have to worry about this in?<p>The US is quite transparent about these rules, and certainly other countries are not necessarily searching peoples phones as publicly<p>But anytime I transit a country USA or any thing I fully expect to have zero rights
European citizens can travel in the EU without even noticing that they are crossing borders most of the time. I once got lost on my bike and accidentally ended up in France for example.
I drove a friend to an airport in Switzerland, got lost on my way home, and accidentally visited both France <i>and</i> Germany.
And if you're unpopular enough, they can also abuse arrest warrants for political persecution from another country. Case in point, captain Tommy Olsen from Norway, who Greek authorities accused of "human trafficking" for helping boat refugees.<p>They've deliberately made it very easy to request arrests across borders, so it isn't all rosy. One of the reasons it really sucks for everyone when an EU country starts slipping towards fascism.
>But anytime I transit a country USA or any thing I fully expect to have zero rights<p>That is so sad, man. How is this normal for you?
Schengen, Nordics, Japan, Canada, in that order.<p>Trump’s America: when confronted with negative traits of your country, always assume your country is the lesser of all evils.
Australia has stricter screening for fruit than for people.<p>don't bring anything organic to Australia unless it's been commercially processed, and even then show it to the border officers so they can make the call. You don't get penalized for showing them something not allowed, you just can't bring it into the country, and they throw it in the bin for incineration. Penalties start when you try to sneak something in anyway.
Australia has very one sided arrangements with some other places. It is far easier for Aussies to get into the UK than vice versa, for example. They get in visa free, but UK citizens need a visa.<p>I have an Australian acquaintance who got into trouble recently since he was born in Scotland but moved to Australia as a child. He is about as Aussie sounding as they come and went to school there, but after working in the UK for a year or two, Australian immigration gave him grief when he decided to return.<p>Australians actually comprise one of the biggest groups of illegal migrants in the UK, but they are more rarely commented on as they are much less visible than certain other groups. Australians with a parent or grandparent from the UK qualify, whereas those who don't, don't. But the ones who don't are rarely deported, and can't be easily distinguished in many cases.
> <i>I have an Australian acquaintance who got into trouble recently since he was born in Scotland but moved to Australia as a child.</i><p>He's not a member of ACDC is he? ;)<p>I think many in the UK don't really regard Aussies or Kiwis as "immigrants" at all. I have various red faced in-laws with political views that are, shall we say, to the right of centre and they see Aussies as just Brits with funny accents.
Xiaomi phones have/had a feature where depending on which finger you unlock the phone with, it can hide certain applications/folders on the filesystem.
who believes an empty phone?
You're right for non-citizens.<p>For citizens, no one needs to believe it. You give them your empty phone and they can't download your phone contents and contacts.
The point is not what they believe, but how to avoid both breaking the law and not giving up your data, isn't it?<p>As long as that's legal, what they believe doesn't matter.<p>You are not legally obliged to keep your data on your devices all the time.
What do you mean?
> I think they should not have this power, but the agents and courts probably don't care that I think that.
...<p>> and about not angering the agents more than you plan to<p>When I was a teenager (long ago at this point), I got into an argument with a police officer over surfing in a certain area. It was pouring down rain, so he was annoyed he had to sit outside and wait for my friends and me to come to shore. Once we got in, he was telling me that he could take my surfboard and my car, and all other craziness. Being the dumb smart-ass I was at the time, I laughed and told him he was full of shit, among other things. He went to take a swing at me but his partner grabbed him.<p>We all go to court and the judge immediately dismisses the case against all my friends. I had a lawyer with me that I knew and he went to talk to the cop and when he came back over he goes "I don't know what you did, but that cop hates you." I get up in front the judge and he praises me for understanding the law (and I could still see the cop was visibly pissed), but then says he can't have me disrespecting and being a smart-ass to his cops and gave me community service that once completed whatever the ticket was would go away.
> but then says he can't have me disrespecting and being a smart-ass to his cops<p>Maybe it's just me, but I am of the exact opposite opinion. Cops have enormous power, and any misuse of it should be pushed back on hard. Cops that misuse their power should not be respected. An informed citizenry is a wonderful asset in making that power imbalance less of a problem.
There's a difference between polite pushback and being straight up disrespectful. It shouldn't matter as the cops shouldn't abuse their power and shouldn't attack people, but we live in the real world. The judge probably didn't want to have to deal with the potential future mess if op didn't learn their lesson and got beat up by a cop.
"Straight up disrespectful" can be made up to mean anything, but in general should refer to things that shouldn't bother police officers doing their job. They can get pissed off about it in their own time.
There is a general understanding that police officers deserve implicit respect while on duty, more so than random citizens, as they are representatives of the law. Swearing at a random passerby is rude but legal, swearing at a police officer is against this need for respect and is a misdemeanor in many places around the world.
And then people are surprised and saddened when LEO start acting like robots and default to treating you as threat to be mitigated as much as legally allowed in context.<p>The parent described a story from a different reality - one where people are people, where communities have basic expectations of conduct, and authority is respected on all sides. The cop was angered and snapped (bad), but was stopped by their partner (good, and it's one of the reasons cops have partners!). The parent was a kid who behaved like an asshole in a moment, by their own admission. Plenty of teenagers act like that, it's an age-old more. The judge did <i>not</i> act as a proxy for the angry cop to retaliate, but instead reacted correctly by both praising the civic attitude (to the chagrin and I imagine further embarrassment of that cop), and addressing the behavior that is not welcome in a civilized community.<p>You can't have it both ways. You can either have civilization of people, or violent hellhole of laywers and robots. Pick one.<p>(And if you pick wrong, then don't complain, and by $deity, don't export these attitudes overseas, please.)
People are frequently "straight up disrespectful" to me in my work. I have to maintain professionalism and composure at all times, and if I were to suggest otherwise I'd get laughed at best. I don't see why it's hard to ask for cops to do the same. A real threat that I need to call security for is very easy to distinguish from a person just being an asshole.
> The parent described a story from a different reality - one where people are people, where communities have basic expectations of conduct, and authority is respected on all sides. The cop was angered and snapped (bad), but was stopped by their partner (good, and it's one of the reasons cops have partners!). The parent was a kid who behaved like an asshole in a moment, by their own admission. Plenty of teenagers act like that, it's an age-old more. The judge did not act as a proxy for the angry cop to retaliate, but instead reacted correctly by both praising the civic attitude (to the chagrin and I imagine further embarrassment of that cop), and addressing the behavior that is not welcome in a civilized community.<p>So why did he not give the cop community service then?
> And then people are surprised and saddened when LEO start acting like robots and default to treating you as threat to be mitigated as much as legally allowed in context.<p>yeah that would be pretty petty, given that most people in their lives are able to perfectly deal with such behaviour, whether it's their job or in personal life, without a judge to slap annoying people on the wrist<p>what is this prima donna behaviour?<p>it is <i>them</i> that need to work to deserve their uniform, they need to understand it is an honour they have to keep up, be the better person. if you can't do that, you have no job wearing that uniform.<p>but I guess their narcissism must feel strengthened by people like you arguing this is perfectly reasonable behaviour for officers of the law<p>you can have it both ways, you just need to want it
> The judge probably didn't want to have to deal with the potential future mess if op didn't learn their lesson and got beat up by a cop.<p>A judge solving their own problems in this way is clearly abuse of power as well
Sure, I agree that we should be polite and respectful to random people, cops included, but that judge decided that it was <i>illegal</i> to be disrespectful to a cop, which is pretty fucked up.
It's not respect unless it goes both ways.
Yeah, but go tell that to the judge who’s just about to slap you with a sentence.<p>Unless you want to fight that all the way up the judicial food chain
There's a huge difference between misusing their power and not having perfect understanding of what they're allowed and not allowed to do.<p>I'm sure there are scenarios where the cop can confiscate the surfboard and the car. The distinction is probably somewhat vague even for highly educated lawyers, and cops cannot expected to be that.<p>He should have stood up for his rights, sure, but laughing in the cop's face and telling them they're full of shit is disrespectful, and at least where I live is a misdemeanor even if the original case is wrong.
As a citizen, when I have an incomplete understanding of what I'm allowed and not allowed to do I have every incentive to stay on the side of things I'm sure I am allowed to do. Just threatening to do things that you are not allowed to do has the annoying tendency of being a crime<p>I'm not sure how this suddenly flips for cops
And what did this judge think (not much, apparently)? Punishing you will make you respect the cops?! This idiot confuses the fear of punishment with respect. Also, does not understand that respect is not to be forced but to be earned. Forcing it will erode respect and generate lots of pretension and covert hate. This judge basically endangers all cops (and the community) for giving revenge to this one prick lacking self control! It's mind-blowing that someone less mature than a teenager can become a judge!
I wonder if the cop learnt his lesson? (rhetorical question)
Too bad you could not bring that judge up on charges of judicial misconduct - if he indeed told you that the charge against you had no merit, but decided to punish you anyway because he did not approve of your demeanor.<p>... or otherwise, that people in your community could not apply any counter-pressure to such judicial behavior, in the media and public fora.
To be fair to the judge we all had broken an ordinance about surfing in a certain area. It was enacted to protect swimmers in the summer. With that said, there was a storm with wind, rain, and currents that had pushed us into the area. Obviously there were also no swimmers out.<p>The ordinance was removed a few years later. This cop was also known to hate surfers. All the small beach town BS you hear about.
at some point you just take your lumps.<p>Most people don’t have boundless time or energy and just want things to go away.<p>… ironically this fact is used a lot in gaining confessions by police.
I wonder if the smarter thing to do would be to quietly nuke it as soon as it becomes clear that you'll be detained, so they can't really know that it wasn't already blank (IE you aren't nuking it in their presence).
What about simply not using a smartphone and accessing your data via internet when you're in the country? You could use Mega (secure file storage) to access your files, for example.<p>I wonder if border agents could coerce you into giving access to your internet file storage, though.
I believe they can. I believe they can even request your social media credentials, despite that being against the ToS for those sites. It's not against the law to refuse, but they can and will reject entry on that basis.
AFAIK in the US their policies do not allow them to access your cloud stored data.
I don't carry a smartphone, is this likely to be a red flag if I'm stopped?
Many countries now assume you have a phone. For example getting UK visa requires a smartphone. I don't think going without a phone is feasible nowadays.<p>Another question is if going with a burner phone that has just sim card and bank card, sufficient. But then you need appleid/google account on the device, and this again links back to your phone number, and it's not easy in practice to have proper clean device.
So I guess what you <i>really</i> want is a duress PIN that loads into a fake innocent profile.
Not enough, e.g. when crossing the Russian border (even as a citizen) your phone can be connected via USB to a device that uses exploits and whatnot to download all of the data. Surely US border guard can do something similar.<p>And using encryption will only make you more suspicious, and may be a reason to get jail time until the situation is "cleared up" one way or another (e.g. by getting even more jail time).<p>Only a second phone works, if you can make it seem like a device you're actually using (though also not a silver bullet as e.g. a lot of messenger metadata is available to governments and border control can physically coerce you to log in to your real accounts)
Yes I thought this was the standard solution?<p>People have been doing this since way back in the TrueCrypt days - IIRC you could configure it to run a whole fake version of Windows if you wanted without easily revealing your actual main volume.<p>Most hardware crypto wallets also have a "duress wallet" feature where you keep a low balance for the same reason.<p>Wiping is obviously extremely suspicious and asking for trouble
"Wiping is obviously extremely suspicious and asking for trouble"<p>It's sad this is the default view. It's his device, his data, his life on that phone. If he had wiped the phone before the interrogation it wouldn't be a problem. How long before? A second before? A week before? But wiping the data a minute later is suddenly asking for trouble.
I don't like it and I wish we had more privacy, but realistically there is no such "right".<p>If you're going to be in a situation where you're in a room with some goons backed by the full power of the state, it is what it is.<p>Maybe because I'm not American I don't have any hangups about seeing the US government this way, but my own government is no different - you can (and people have) get stopped at Heathrow, taken to a dimly lit backroom and given a going over for hours
I don't know that there is case law on this but I imagine that "prior to the admissibility inspection" is likely to be treated differently from "during the admissibility inspection" or "during administrative detention or secondary inspection" (or "in response to a request or question by a border agent"!).<p>Edit: a bigger picture question is the difference between things that may be legally punishable and things that may cause suspicion from CBP agents, which aren't the same thing at all.
it seems to me that if you give them a password to unlock the phone and when it unlocks it has been wiped that will cause problems whether it is the password that causes the wiping or not?
We noted in the border search guide that lying to the agents in response to their questions is potentially a crime in its own right (even if it's not done in order to hide anything illegal). We thought that this made hidden volumes quite tricky, particularly if one's intent was to pretend to comply with a question or request while actually not complying.
Or that just selectively wipes only stuff you have marked for deletion. That way the profile stays up to date and believable.
Problem is „are you sure you marked for deletion all the correct things” because you could have already deleted it before traveling or moved to other device you don’t travel with.<p>Selection on border control might be arbitrary, they can hold you or send you back over a photo or something you wouldn’t think should be a problem.<p>Ideally you would like to have all wiped just in case but then you really stand out…
Deleted stuff can easily be recovered. I think the full clean will remove the encryption keys hence making it unrecoverable.
That's a more risky strategy. What if you added new files since the last time you updated the deletion profile? It's also technically more challenging. You have to think about what might be in RAM, caches, backups, etc.<p>The good thing about a total wipe is that it's very easy to implement, and it's hard for it to go wrong. You just encrypt the whole drive and, when you want to wipe it, erase the key.
Yes, this also has the advantage of speed perhaps. I can see, deleting specific apps (and their data) as thing #1, and thing #2 would be certain directories. Of course, the problem is, are icons going to be vanishing off the home screen, when the agent is looking at it? Or will the unlock -> screen coming on, be super slow?<p>Of course the problem there is, many people have an app store installed, and app stores have histories. And logs. And "what you used to have installed" is so easily found under Google Play, for example.<p>As someone else said in this thread, the law isn't code. It's not if-then statement based. It's also predicated upon intent in many cases. What actions did a person take, and why, when told to (for example) unlock their phone.<p>The problem here is that if you are asked to unlock your phone, any action you take to thwart that request by "trickery" to get data deleted, could be construed as 'deleting evidence'. So while some methods might make it more difficult for the border agent to realise "something happened", if they're suspicious still, then you're still in hot water.<p>In the eyes of the law, the court, and likely the jury, you've done a sneaky thing to thwart evidence collection.<p>The only safe method is a full wipe prior to travel. In this manner, you're not deleting evidence <i>when told to hand it over</i>. It's an entirely different bar. They can be cruel about it, and take your phone for a few months, but you're not going to be in legal hot water.<p>In as no one will see the phone is wiped until you are compelled to unlock it, there's no greater change of the phone being seized. You're already being investigated. Just be blunt, say "Whenever I travel, I just wipe it", and that's that.<p>This is why it's a shame that GrapheneOS has no viable backup solution. Its build in method is unreliable, and doesn't work very well, and is gitchy, it's a very well known problem.<p>And Android and ADB sometimes have issues with large backups of directories, and so you have to manage that with tar + stream and other business, but at least working around that is easy.<p>But if you could backup individual apps and all their data, you could uninstall all your privacy laden stuff, cross the border, and reinstall in minutes.<p>That's the true, legal way to travel safely. <i>Especially</i> if the app removal resulted in a 'shred' of the data files instead of delete.<p>If anyone has ever struggled with large data backup/restore, here's the only real method I've found for copying large swaths of files from/to via adb:<p><pre><code> adb exec-out 'tar --dereference --create /storage/emulated/0/dir/ 2>/sdcard/backup-errors.txt' |dd of=/tmp/backup-$(date +%Y%m%d).tar && adb shell cat /sdcard/backup-errors.txt
</code></pre>
and to restore<p><pre><code> dd if=backup-20250309.tar | \
adb exec-in 'cd /storage/emulated/0/tempdir; tar xpvf - 2>/sdcard/restore-errors.txt' && \
adb shell cat /sdcard/restore-errors.txt
</code></pre>
Or something similar.
Note that in the USA and a few other jurisdictions, I believe there is now a recognized possibility for the border agents to ask for access to your social media, so even wiping the phone, or even traveling without a phone, is not entirely safe.
As far as facts go I was thinking of this one case:<p>... where I seemed to recall it was a social media post, but it is unclear whether it's private messaging, public social media, or private messaging under a public social media account.<p>[EDIT] according to [1] it was on WhatsApp with a U.S national.<p>My understanding is that refusal to provide social media accounts, or passwords to devices, or passwords to social media accounts, can be considered suspicious in its own right and ground to be held in custody for further exam, and/or denied entry; foreigners do <i>not</i> get to have the same "give password" == "right to not incriminate yourself" that U.S of A. citizen have. In doubt I would assume I don't.<p>[0]: <a href="https://www.lemonde.fr/en/international/article/2025/03/20/french-researcher-denied-entry-to-us-for-expressing-personal-opinion-on-trump-policies_6739346_4.html" rel="nofollow">https://www.lemonde.fr/en/international/article/2025/03/20/f...</a><p>[1]: <a href="https://www.lemonde.fr/international/article/2025/03/22/le-refoulement-d-un-chercheur-francais-aux-etats-unis-tourne-a-l-imbroglio-diplomatique_6584561_3210.html" rel="nofollow">https://www.lemonde.fr/international/article/2025/03/22/le-r...</a>
Yes, as a foreigner there is no such thing as a right to enter the USA - the CBP agents can refuse you entry for any reason whatsoever and you have no recourse (they could be breaking various laws of their own and face personal liability for their own actions, of course, such as if they were seeking a bribe from you - but that doesn't give you any right to sue over their refusal to admit you). The only exception is asylum seeking, where there is a legal right for your asylum case to be heard.
Or travel with a diary containing a post-it note labelled "p4sswd"
[dead]
My friends from the German CCC are mostly like (1) do not travel to the US and (2) if you absolutely must, travel with an empty device with decoy data and download all data you need once you're there.
I'm sharing this experience just to share, not suggesting or making any claims about what people should do with it:<p>One of the best ways to get through airport CBP quickly without being overly hassled is to be overtly, clearly sick in a gross way. If you're about to vomit or have horrible diarrhea, they do <i>not</i> want you in that line any longer than you have to be. If they're the type to want to take people down a peg, they won't bother with you because they're already miserable, and if they like picking on the weak, they're probably going to go for a solo young female traveler who isn't ill.<p>Nobody wants to risk getting vomit on their clothes or in their work area, having to close a line and shuffle people around while their coworkers glare daggers, or subject themselves or their coworkers to the very fun smells of human bodily fluids.<p>At the same time, it isn't purposeful so it's not read as malicious.
So burner phone for US visits I guess
Just don't travel to the US.
This is an increasingly popular solution. Foreign tourism has crashed.<p>I <i>love</i> the geography of the US, and it has some truly stunning places to visit.<p>But they're not so stunning that I need to risk my freedom - <i>risk my freedom</i> - to visit them in person.
This person is a US citizen. What happens if he just said nothing (beyond identifying and answering basic questions) and refused to cooperate? How long could they hold him? As a citizen they have to allow him to enter eventually.<p>According to the ACLU I think this person would have been better off saying little and not wiping their phone.<p><a href="https://www.aclu.org/know-your-rights/what-do-when-encountering-law-enforcement-airports-and-other-ports-entry-us" rel="nofollow">https://www.aclu.org/know-your-rights/what-do-when-encounter...</a>
This. If any country won't treat you like a guest, avoid travelling to it.<p>If it's your own, that's harder to do – time to fight and change the system before it gets worse and will swallow you whole.
I live in the U.S. (as, I think, does the person who is the subject of this article).
> The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that.<p>That's the reason I never traveled to the US and never will, just having IT security in your CV is enough to make the border gamble not worth it
Note that border searches of electronic devices are extremely rare overall. There were some statistics from CBP implying a base rate lower than 1 in 10,000 (I think lower than 1 in 100,000) border crossings.<p>I do know two people who have experienced them as a result of the government taking a personal interest in them, so it's certainly not impossible. However, it's not a common experience.<p>I've personally experienced searches of my suitcases about four times in about 100 U.S. border crossings (as a U.S. citizen, but the people performing or directing those searches generally didn't know my citizenship status), and zero electronic device searches.
I'm European and I know plenty, albeit the minority of those I know that went to the US, so I wonder how reliable are CBP stats.<p>Maybe my anecdotal experience is influenced by me being in IT, but still.
But why would that be legal? The device is owned by the individual. No judge signed any warrant search for the device. I can do what I want with my device - that is a basic right of property. Imagine if border guards seize money willy-nilly.
> Imagine if border guards seize money willy-nilly.<p>This jogged my memory, though I couldn't find the example I was thinking of. But here's an item that is pretty similar:<p><a href="https://en.wikipedia.org/wiki/Tenaha,_Texas_asset_forfeiture_controversy" rel="nofollow">https://en.wikipedia.org/wiki/Tenaha,_Texas_asset_forfeiture...</a><p>Edit: Not on the border, btw. Just people travelling inside US. I guess it was their mistake to carry cash instead of getting a bank check or something.
You are allowed to refuse access to your device, and they are allowed to refuse entry to the country.
Most constitutional rights are suspended within 100 miles of a border or international airport.
> Imagine if border guards seize money willy-nilly.<p>no need to imagine<p><a href="https://en.wikipedia.org/wiki/Civil_forfeiture_in_the_United_States" rel="nofollow">https://en.wikipedia.org/wiki/Civil_forfeiture_in_the_United...</a>
It's also quite surprising that all socials need to be declared. And presumably them AI vetted in time for you to get to the border.
This part is pretty new. I wonder if my former colleagues have done any FOIA work looking into how travelers' disclosed social media accounts have been reviewed or analyzed!
You also have to provide every single email account you have used in the last ten years, all of them, forgetting to declare one is an offense.<p>There's no chances I can remember them all, especially as I've been contracting and get a new email every 3-4 months or so.
Maybe the actual solution is traveling with burner devices when you are concerned with border checks?<p>Like, get a cheap phone, install the bare minimum stuff you need for travel.<p>For extra safety, before returning home wipe it and just put back the exact apps you need for moving around (e.g.: ride hailing app).<p>Same thing with laptops, tablets, etc.
> ... you may have to think both about protecting your data by technical means, ...<p>I thought about that. And I came to the conclusion that a phone is a pathetically bad device to both store your data and to access your data. Mediocre screen. Mediocre input methods. Moreover most phones happen to also be spying device.<p>So if you think about "protecting your data", a reasonable idea is that a lot of data is way better kept on your homelab, with say encrypted backups in a safe at the bank, at a relative's place, on a server you rent, etc., rather than on your phone. And there's really little need to access your data from your phone.<p>Oh and I'm no luddite: I've got a homelab, I rent servers, I pay three AI subscriptions, etc.<p>But my phone is boring. There's no app on it besides the stock ones (say Google Maps) and then I added the Google Authenticator app (for stuff still using that kind of 2FA).<p>If people were to wake up and stop being glued to that mediocre thing, the problem would already be 99% solved.
This is one of the reasons I also won't ever go to the US again.<p>While most of my Italian/Polish friends had 0 issues, on a handful of occasions people were stopped and questioned for hours with agents pretending full access to every single device and just overall treating you as criminals.<p>In one occasion a friend of mine stated that he was quite sure they just enjoyed that kind of sweeping power and it had nothing to do with border security, it was just fun to them.<p>In another one, the suspicion was on the fact that this person did not have socials, he just disliked them and had nothing except a Google account for Youtube. This fact made them super suspicious and the person was stuck at La Guardia for 3 hours, even his body was inspected. Disgusting.
I’ve seen a lot of people on the internet over the years say things like “the government can’t make x illegal, it’s just y.” For example, the government can’t make wiping your phone at the border illegal, it’s just punching four numbers into your phone, just like a pin, only a different four numbers, which could just have well been your pin.<p>U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did. Hell there could have been a third set of four numbers that were the nuclear launch codes. It’s not the fact that it was four numbers, it’s what you were trying to make happen when you typed them. Now of course whether they can prove what your intent was when you typed them is another matter, but generally a duress pin should be for when robbers are breaking into your house, and the government will be on your side, and not when the government will be against you.
"U.S. law though is highly non-autistic" hilarious but also another point to emphasize is how truly depressing American courts often are. Take the right to a jury. It sounds noble in theory. But when they say judged by your peers they don't mean your actual peers.<p>It's people who couldn't get out of jury duty. Prosecutors have high success rates. Federal prosecutor success rate is over > 90%. Studies of jury psychology show how much peer pressure and other factors extrinsic to the law come into play.<p>Remember what happened to Aaron Swartz. Law is the mask of power. By all means defend and assert your rights, but understand the costs. I find people are under such illusions about how cruel the American justice system is that this leads them to make foolish decisions. Do not underestimate the adversarial nature of the justice system, nor the accompanying incentives agents of the state who are on the other side of you have to lie.
> Federal prosecutor success rate is over > 90%.<p>This is a misunderstood statistic.<p>Federal prosecutors won't even pursue cases unless they think there's a high chance of success. They don't operate like two private parties suing each other to force the court to decide something. If the evidence is there or the charges aren't fully formed, they don't waste resources on it.<p>This leads to a contradictory set of complaints that the legal system lets too many people go or doesn't have enough teeth.
><i>Federal prosecutors won't even pursue cases unless they think there's a high chance of success.</i><p>Given the incarceration rates compared to average western standards, that's a moot point. Even if they selectively pursue, they do pursue a hell of a lot, and they do get a hell of a lot of convictions - relatively. Factor in the severity of the convictions, also much worse compared to average western standards even for the same offenses, and it's an ever worse picture.
> Given the incarceration rates...<p>I don't think you make anything moot by compounding more regional stats. <i>Some countries have more crime</i>, they underinvest in rehabilitation, addiction treatment, and social diversion programmes. Shock horror: jobless, homeless addicts commit crimes. The US also has a land border with long land borders.<p>That is all to say, comparing apples and margaritas doesn't do what you think it does.
"also much worse …"<p>Why is convicting and sentencing criminals a bad thing?
> Federal prosecutors won't even pursue cases unless they think there's a high chance of success.<p>The problem with this theory is that it ignores the incentives on the other side in a criminal case. When you get charged with something, the prosecutor offers you a deal and that deal is almost invariably a significantly lower penalty than what happens if you go to court and get convicted. The plea deal is a lesser charge, if you demand a trial then they throw the book at you, stack charges and ask for more severe penalties for each one.<p>With the result that if someone actually did it, demanding a trial instead of pleading guilty for a lesser sentence has a large negative expected value. Which in turn implies that it doesn't make sense to do unless you think there is a high probability you can win, for example because you know you didn't do it. The coercive force is so large that it can cause <i>innocent</i> people to plead guilty, since even a 10% chance of losing can screw up your whole life when it means a 10x higher penalty.<p>And yet > 90% of the people who thought their chances of being acquitted were high enough to be worth taking a much large sentence on conviction, still get convicted. Which seems suspicious.
I think you forgot something even more basic. Federal prosecutors handle federal crimes and the vast majority of those require extensive investigations to gather evidence before you can even initiate a court case.<p>The most classic case of federal offense is tax fraud. You can't record tax fraud on a camera or believe the witnesses, you actually need to look at the balance sheet and contracts of the company and make sure there is actually a crime to prosecute.
I don't think it's so much a "misunderstood" statistic as much as a number that people (like the commenter you are replying to) deliberately trot out to use as evidence for their position because they are depending on most people being statistically illiterate.<p>To be clear, I totally agree with your points, I just think this is more of a case of "lying with statistics" than being a misunderstanding.
They never pursue court trials, because it's too much work. But they'll pursue plea deals, because there's this gigantic pipeline and everyone in it (including public defenders) is on the same team: <i>Team Make Him Plead</i>.<p>Because of this, no true justice is possible. Trials don't just try the defendants, it forces the prosecutor to prove that there really was a case and that they weren't just trying to bully someone who felt it was hopeless and would rather get out of pre-trial jail early. It forces the cops to actually make a fucking case, rather than rely on horseshit to lock someone away that can't bond out.<p>And no reform is possible. If you explain any of this to someone who actually understands it, they panic and say "but the prosecutors wouldn't even be able to bring 1/50th of those cases to trial, the system would overload" as if that were a bad thing that they couldn't. In the same way that you're not caught in a traffic jam but rather you are traffic, you're not caught up in these problems... your apathy, your ignorance, your rejection of boat-rocking, in short <i>you</i> are the problem.
> Federal prosecutor success rate is over > 90%<p>Prosecutors pick their cases. Defense doesn't. The cases that aren't 90%+ sure aren't charged.
Some of us report for jury duty just itching to nullify something. Don't you? Checks and balances...
Nullify if necessary, more likely duty to justice as best as I can come to understand it.<p>We should all know it though!:<p><pre><code> It has been commonly used to oppose what jurors perceive as unjust laws, such as those that once penalized runaway slaves under the Fugitive Slave Act, prohibited alcohol during Prohibition, or criminalized draft evasion during the Vietnam War.
</code></pre>
<a href="https://en.wikipedia.org/wiki/Jury_nullification" rel="nofollow">https://en.wikipedia.org/wiki/Jury_nullification</a>
I got selected as juror once just hoping to laugh at anything the cops said on the witness stand and let some poor soul go free but it turns out the defendant was just a violent scumbag who stabbed random people in public, <i>and</i> there was a video of it. After we decided he was guilty, they listed other things he had been convicted of and asked if he was a repeat offender... Let's see, shot somebody in the back, robbed liquor stores at gun point (dressed as a clown IIRC) and some other weird shit. That decision didn't take very long.<p>Honestly we didn't even throw the book at him, prosecutors were charging him with a bunch of offenses and we decided guilty on only two, but the repeat offender bit probably locked him up for a few decades.<p>The funny thing was that all the jurors thought the victim was a complete douchebag and thought both parties deserved time. As it turns, somebody I knew at the time knew the victim from childhood and he apparently molested his 8 year old cousin.
I just served on a jury and in our case, the cop was a lying scumbag, the prosecutor's expert witnesses were people milking the taxpayers to provide the evaluations that the state wanted to hear for thousands of dollars per hour, the defense's expert witnesses copy-and-pasted an evaluation from another client but didn't bother to proofread before the prosecutor brought up that they had the wrong name in the text, and the defendant raped and molested multiple kids below the age of 8, some still in diapers.<p>I feel like many court cases are textbook instances of Everyone Sucks Here. I needed therapy after the case because it had so shaken my faith in both the justice system and humanity.
"I feel like many court cases are textbook instances of Everyone Sucks Here. I needed therapy after the case because it had so shaken my faith in both the justice system and humanity."<p>I really don't think most of the people posting here understand what the professionals working in criminal justice/law see on the average day. They see the worst of the worst on one side, and then the public who they are trying to get a paycheck to defend on the other attacking them.<p>This in no way excuses bad behavior, but we're all human and these people aren't robots.
<a href="https://en.wikipedia.org/wiki/James_Grigson" rel="nofollow">https://en.wikipedia.org/wiki/James_Grigson</a><p>Forensic sciences and experts hired by prosecutors is a big problem.
Some people suck. Some of the people who suck are poor and physically violent, some are rich and politically and economically violent.<p>There's a kind of fog of incomprehension over indirect crimes which makes them much easier to get away with.<p>People still die though.
That is horrible but robbing a liquor store dressed as a clown is pretty funny (in my head probably not irl)
I don't understand the jury system. If your server is down you don't grab randos from the street to fix it.<p>Hell Americans know this too which is why you have a professional judge and lawyers. And you guys don't have a night watch with pitch forks and muskets to police the village anymore.<p>A jury system is an anachronistic relic.
If your server is down you might ask for advice in an IRC channel, receiving help from whoever is there.<p>The random selection of juries was supposed to ensure they aren't any special class of people. For instance judges are usually from upper middle class backgrounds and it used to be that your innocence or guilt was decided entirely by the aristocratic nobility. By using random selection, that sort of thing is avoided.
I went itching to nullify injustices - I left wanting to reintroduce the death penalty for petty crimes.
Is the high success rate because they are good at winning or good at picking winning cases? Does that 90% include plea bargains?
I've been on jury duty several times and in each time the entire jury pool was dismissed an hour or so into the morning, with "all cases have been settled". As I was leaving, the official said, "see how efficient we are now?". I replied, "The guillotine is efficient, but it's not justice." Look into Aaron Swartz. The % of cases that go to trial is very small, in no small part because plea bargaining is no bargain at all. "Plead guilty and we'll do the minimum (whether you're actually guilty or not), or go to trial and we will seek the maximum sentence, which could be 30 years in prison. What's your answer?"
You're begging OP's question.
How so?<p>OP is strongly implying that the 90% success rate for prosecutors is due to the courts being stacked against the defense. IMO <i>that</i> is where the logical fallacy is. Since prosecutors have wide latitude in deciding which cases to charge in the first place, it is very possible that the high success rate is due to prosecutors only charging cases where the accused actually committed the crimes being charged. Indeed, for the ~10% of cases where the accused is not found guilty, about 8% are due to the government dropping the case - only 1% are the jury acquitting the defendant outright. Thus, it would appear from that data that when the prosecution sees they are not likely to win a case, they drop it.<p>I'm making no argument that the courts or law are "fair", I'm just making the argument that quoting the 90% number is in no way evidence that courts are inherently biased towards the prosecution.
I think it’s a valid question as far as what the nature of that success rate is.
It is not surprising. They just don’t go to court unless they think they have enough evidence for a conviction. In a perfect world the conviction rate would be 100% because in a perfect world the prosecutor would drop the case before if they don’t have enough evidence.
> Remember what happened to Aaron Swartz.<p>Indeed. There are certainly parallels between him and Sam Tunick. But I'm not sure the public is ready for all the parallels.
Exactly. People complain police dont prevent crime, but dont realize that is not their purpose. The police exist to protect the government, not the people.
The police are there to enforce laws, but enforce it by punishment, rather than prevention. The potential deterrence effect still applies, as people do get discouraged from crimes by the mere presence of the police. However, there is zero legal duty for the police to protect someone who is currently under attack from a criminal.
> However, there is zero legal duty for the police to protect someone who is currently under attack from a criminal.<p>That has to be incorrect, by the time someone is under actual attack from a criminal that criminal will have allready comitted crimes that the police can and have to punish for, i.e. Threat of Force with a Lethal weapon or sth like that.
Police don't prevent crime, they arrest and charge people for committing crime.<p>Arresting people because they might/could commit a crime would be a bad route to go down.<p>> The police exist to protect the government, not the people.<p>The police exist to protect the rule of the land. The military exists to protect the government.
Which part of the government protects the people?
> It's people who couldn't get out of jury duty.<p>But that's good no? People who got out never would have taken it seriously.<p>I sat on a jury trial and was highly impressed with how seriously my fellow jurors took it - especially the presumption of innocence. When they started to go down some incorrect logical path, someone would step up and correct it.<p>Not to mention the public defender ripped apart the DA's case. It was the exact opposite of what I was expecting.<p>> Prosecutors have high success rates.<p>You're forgetting that the prosecutors don't bring cases they think they're going to lose to trial, they either drop the charges or try a plea deal. So you'd entirely expect the success rate to be high.
If it’s a malicious prosecution by the country/state then Jury is your best best over a Judge.<p>There is a reason that Elon Musks companies and others put a ‘you agree to not have a jury trial…’ clause in their terms as Judges are easier to influence - when a legal case is filed it’s allocated to a judge and certain cases will go strategically to a Judges with certain bias
> Take the right to a jury. It sounds noble in theory. But when they say judged by your peers they don't mean your actual peers. It's people who couldn't get out of jury duty.<p>What? A jury system is far from perfect but this is about as intellectually rigorous as “the lottery is a tax on the poor”. Many people are thrilled to do jury duty because they are invested in their community, your nihilism is not a universal truth, jury duty isn’t a burden, it is a civic duty, an honor.
> It's people who couldn't get out of jury duty.<p>It’s not even just who couldn’t get out of it. It’s filtered for people who answer honestly. I was disqualified for a grand jury because the judge asked me if I would believe the testimony of police officers as truthful and I said it would depend on the police officer.<p>The system already had their hands forced on accepting that some cops lie with Brady disclosures but the fact that I didn’t just naively accept police testimony meant I was an unscramble juror.<p>Even if you’re a true believer in the system you won’t be allowed to participate because you didn’t lie.
Yeah, but without a jury O.J. Simpson never would've walked out of court a free man.<p>For example in Europe when someone dies somebody always has to go to jail, even if they were defending themselves or responding to a potential threat. A jury could show compassion or empathy. Judges are extremely stoic in that regard.
The well-known country of Europe with its single set of laws? That Europe?<p>Self-defence can be a valid justification for manslaughter, at least in the UK.
> in Europe when someone dies somebody always has to go to jail<p>Please cite the european law that states this.
This was really well written in "What color are your bits": <a href="https://ansuz.sooke.bc.ca/entry/23" rel="nofollow">https://ansuz.sooke.bc.ca/entry/23</a><p>Programmers have trouble seeing color (two identical numbers are the same bits, how can typing '1234' to unlock one phone be legal, and '1234' to unlock another phone be illegal?)<p>Courts care about color (intent, provenance, permission), even though that color cannot be digitally represented.
Indeed, but should he say his real code was one digit swap off, could you prove intent? Color matters, but you can't paint with only one
This is where 'reasonable doubt' comes in from a jury. Would I believe that someone set up a 'wipe my phone' code, something that would be catastrophic, it was one digit different, and they <i>accidentally</i> typed it, or would I think they were trying to wipe their phone.<p>Honestly, given what I know here (a full case might be different), I would believe they did it on purpose.
Framing this as whether he can convince you the mistype was accidental gets it backwards, and "would I believe X or would I think Y" is preponderance, not reasonable doubt - entirely different standard. Reasonable doubt doesn't ask which account you find more likely. It asks whether the innocent one is unreasonable.<p>Take the hypothetical as posed: duress code one digit off, entered while detained after being interrogated for hours, and repeatedly pressured to unlock. The government has to prove beyond a reasonable doubt that he knowingly triggered the wipe and did it for the purpose of impairing the seizure. Nothing about that scenario makes mistyping an unreasonable explanation unless there is more circumstantial evidence that indicates him intentionally providing the wrong PIN.<p>Proving that to a jury looks very hard.
"Color" absolutely can be represented digitally; C compilers were doing it before we even <i>knew</i> they were doing it. We just like getting away with shit. It's part of the hacker ethos. Probably.
Not all color can be represented digitally.<p>Is a piece of software subject to patents? Is it export controlled?<p>Both of those can change without the data changing at all. A new patent can be applied for and accepted, at which point all code the patent description matches is potentially encumbered (even if it was written with no knowledge of the patent or before the patent existed, yes our patent system sucks).<p>Export controlled is also a matter of laws, not an attribute of the data itself, and laws change independent of data.
You've just merely exhibited the symptom of being blind to all the colors which cannot be represented, not proven or shown that there are none.<p>All of a things properties are not contained in or expressed by the thing itself.
A lot of engineer types forget that the law is not code, and reductionist arguments almost never actually work in practice because it's a human interpreting the law.
For one example of this, around 10 years ago there was a company called Aereo that tried to act as a "cloud television provider". The idea was that they had thousands of tiny antennas hooked up to servers in a warehouse, and they would lease an antenna to each subscriber. This gave an experience similar to cable TV but without Aereo having to pay broadcasters cable transmission fees. The major broadcasters sued Aereo and ended up getting it shut down for exactly the reason you mention. Despite Aereo technically being a TV antenna leasing service, it functionally acted like a cable TV service so they were violating copyright by not paying transmission fees.
They were accused of "public performance" which doesn't make sense to the spirit of the law to begin with. Avoiding technicality via technicality is fine. They should have been allowed to run their thousands of independent servers.<p>The reason cable companies have to pay these fees in the first place is a narrow and somewhat pedantic argument that is <i>entirely</i> based on connecting multiple households to the same antenna. Which Aereo doesn't do, no trickery involved.<p>If there had been a style of "cable" company that used one wire and antenna per house from the start, they could have avoided these fees too. They only didn't exist because cables and antennas are expensive.<p>Any single person could have legally set up their own server and antenna. But Aereo building these en masse makes them a cable company instead of an antenna-building company because... vibes, basically.<p>The best evidence that this was a failure of justice is that they pivoted to "okay, we're cable, we'll pay the fees for a mandatory license" and got <i>rejected</i> for <i>not</i> being a cable company.
This sort of legal workaround can work (see Uber) though.<p>Uber avoided medallions.<p>I guess that proves law is not code!
> A lot of engineer types forget that the law is not code, and reductionist arguments almost never actually work in practice because it's a human interpreting the law.<p>It's worse than that: a lot of engineer types reason about <i>almost everything</i> as if it were code. It's a manifestation of Engineer's disease.
It reminds me of tax law in many countries. You can follow the letter of the law, but if the vibes are off, you can still be found to be in breach of a vague catch-all provision (e.g. economic substance doctorine in the US, GAAR in Canada/UK, Part IVA in Australia, etc).
There is a strong bias by the courts to interpret the law in such a way that it makes sense, and achieves the goals the legislature had when enacting it.
Just read this point in a case revolving around the Oxford comma, stated in simple enough legalese I could understand:<p>“laws must be construed liberally in order to accomplish their remedial purpose" <a href="https://en.wikipedia.org/wiki/Serial_comma#Maine_labor_dispute" rel="nofollow">https://en.wikipedia.org/wiki/Serial_comma#Maine_labor_dispu...</a>
Maybe this is because of the TV dramas where a genius lawyer saves their client through an obscure technicality. It looks exactly like hacking a system using a 0-day exploit.
It's not that there's a human interpreting the law. It's that there is a politically motivated human interpreting the law, or in other words, you are sol if the state wants to get you. The engineer's arguments aren't reductionist, they are idealistic.
Does anyone think law is computer code? I mean any courtroom drama (even if far fetched) shows it is not.
In this case, the government was against him due to his activism against a police training campus.<p>Him deleting his phone was very likely a matter of safety for his fellow activists. Sad that our government does this but it’s not like this guy was a drug dealing or something.
> U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did.<p>Love this way of putting it. Stealing for future conversations with fellow software developers.
A duress pin is useful if the cost of the government getting mad at you because you wiped your data is less than the cost of letting the government have your data. Whether that holds depends on your situation—for example, whether your phone's data could implicate other people that you want to protect
When talking about costs we should remember who is paying. Maybe overall the cost of the government getting that data is higher than the cost of them getting mad at you, but when a single individual is paying for all of it the equation might change.
I think it's a matter of personal privacy. You shouldn't show it to other people.
When I had jury duty it was quite revealing as far as “this is all evidence including people’s testimony, you can believe all or some or none of a given piece of evidence based on your own judgment” goes.<p>When we met it was interesting how our jurors decided “I don’t believe anything that guy says” and so on when it came to their motives and so on.<p>The trial itself was very carefully choreographed, almost pre determined and static.<p>But the decisions and jury activity was very dynamic. There was absolutely no magic legal mechanisms at that point.
I'm waiting to see whether he is convicted before I form a strong opinion around this. I'm leaning toward thinking this case will be dropped or at least severely reduced charges.
There's a chilling effect from even just the arrest.
If you're against an academia for further police militarization you're a terrorist apparently.<p>And people are still convinced that's the land of the free, when it's a distorted non-representative democracy on top of a police state.<p>US is closer to South American banana republics than Iceland or Japan.
Oh this. Poor people lose their job because of an arrest. Arrest = homeless = dead sooner.<p>Best outcome is he successfully sues for the violations.
It doesn't matter.<p>Mamy will read this and think that crossing a border with a GrapheneOS device is a bad idea, or just drop using what is a nice security feature entirely.<p>Just being charged is already a massive pain in the ass (both in terms of stress and costs) to an individual.
If only they could be as non-autistic about the law consistently.<p>From the article, it looks like warrantless search & seizure and lawyerless detainment over the suspicion of participating in plain old 1st amendment activities.
Would it have been wiser if that person had, as a US citizen, just refused to provide a PIN? At the most they'd just confiscate the phone, and it'd be encrypted anyway. No actual destruction of anything.<p>On another note, maybe GrapheneOS should add some kind of feature where the phone <i>involuntarily</i> destructs if a correct PIN isn't entered for 48 hours (or whatever the user sets at installation time, and changing the value should not be permitted). That way the trigger for the wipe is the confiscation, not the act of entry of a duress PIN. You could disclose the mechanism to the officials who intend to confiscate, and also say (truthfully) that you have no control over the feature.
<i>Would it have been wiser if that person had, as a US citizen, just refused to provide a PIN?</i><p>Purely technically it would also depend on the state of the phone. Phones can be read out/exploited more easily after first unlock (AFU) than before first unlock (BFU). So, a middle path would be putting the phone in BFU. Much harder to use exploits against the phone and biometric authentication doesn't work. One way of fairly reliably doing this is setting the reboot timer to 10 minutes or turning off the phone in critical situations.<p>It's also relevant to take into account that he wasn't protecting himself by wiping the phone, but fellow activists. So, he may have taken the risk of potential legal issues by wiping the phone to project others.
This is a form of legal evasion similar to warrant canaries imho : <a href="https://en.wikipedia.org/wiki/Warrant_canary" rel="nofollow">https://en.wikipedia.org/wiki/Warrant_canary</a><p>i m not sure how legal a protection it is, and whether the courts would interpret your choice of OS as complicit in evidence destruction.
Heck, it could be unconstitutional for the government to make X illegal, but if the courts say 'no actually it isn't', or it never actually gets to that point, then it doesn't really matter much, does it? The text of the law could be simple and straightforward, and a layman's reading of that text could be valid, but all the government or courts needs to do is to find some moon logic to make what they need happen, and unless enough people disagree, then that's all there is to it. The law, in many ways, for better or worse, is just a piece of paper.
I think people are aware that the government can physically do a lot of stuff, e.g. shoot you in the face for no reason. And vice-versa for that matter.<p>However there are arguments morally, and constitutionally, and logically, about what can be done.
And all of those arguments are entirely academic, and subject to change depending on economic status, skin color, or nationality.<p>Law is effectively a weak gentleman’s agreement we tolerate because the alternative is violence.<p>(Well, law is enforced with violence too, I suppose.)
Yes, this is something more people really need to take to heart. As Americans are seeing, a lot of rules are unenforceable and really came down to norms and pressure. I have been thinking about this a lot over the last few years and it is roughly encapsulated in this tweet I saw a while back.<p>When I was a kid I wanted to be a police officer because I wouldn't have to follow any laws or rules. Then I got a little bit older and realized that wasn't how being a police officer actually worked in practice. Then, I got a little bit older than that, and realized that it actually does work like that.<p>This has always been true and there has never really been perfect justice. Ultimately, power and violence have always superseded the law. High trust societies with less corruption and a strong justice system try to limit these circumstances.
> When I was a kid I wanted to be a police officer because I wouldn't have to follow any laws or rules. Then I got a little bit older and realized that wasn't how being a police officer actually worked in practice. Then, I got a little bit older than that, and realized that it actually does work like that.<p>I'm imagining that IQ bell curve meme, just with you at different ages.
> This has always been true and there has never really been perfect justice.<p>You raise the standard for justice to perfection. There also has never been perfect corruption and anarchy.<p>> Ultimately, power and violence have always superseded the law.<p>That's like saying night has always superceded day. Everyone recognizes that recent years have been very unusual or unique in US history. That means for the great bulk of US history, it was different. Why doesn't 99% of US history outweigh the 1% (picking numbers very loosely) in determining what is somehow inevitable to you.<p>In fact, law is universal among human cultures. We are naturally social and live in groups with rules. Those that violate rules are generally outcasts.<p>But the most fundamental and significant error is attributing the current situation to some unavoidable system instead of the actions of people, especially those that stand aside and allow these things to happen. Many of them stand aside because they are told - probably messaging ultimately from the lawbreakers - that they are powerless and should despair.
> Everyone recognizes that recent years have been very unusual or unique in US history.<p>i dont?<p>this is how the US has <i>always</i> been. its who americans are. the odd time was the obama years
The law wasn't in the state that you ascribe to it for the other 99% of its history if you were, say, African-American. Other less-extremely obvious examples also abound.<p>Liberal democracy with sometimes-fair application of it is the aberration.
> Law is effectively a weak gentleman’s agreement we tolerate<p>Not all of us do. To be honest, the older I am, the less sense many laws make to me, and the more I'm willing to help people break them.
well, the status quo is also violence, just directed at some people and not others
Well, you need to be eating a burrito or something
Maybe I should get a thicker skin, but the prevalence of “autistic” as shorthand for “moronically literal-minded” on a place as prudish as hn is a bit surprising.
He should have backed up the phone before travelling then wiped the phone to an innocuous state before getting on the plane.<p>Want to see a really confused border agent? Travel without a phone. Fedex your phone to your hotel/home. Read a book on the plane. The concept that someone doesn't have a phone/computer drives cops insane.<p>One of the wikileaks crew pulled this one in NY. Several agencies were a set to grab his devices and detain him until he unlocked them ... But all he had in his carry-on was a magazine. His devices had been wiped and sent by mail. He re-imaged them only once he was home and safe. No devices to unlock, no reason to detain him.
Yes, I had the duress codes but entered them by mistake. I wanted to enter the real one but
>U.S. law though is highly non-autistic<p>LOL, that made me chuckle.<p>People somehow think they're the first one to think of a workaround to a law, when in fact it's been happening since the first law was written down. The law adjusted and if people think they can do one thing, then claim they intended another they have a big surprise coming.
Please elaborate on how US law isn't "autistic".
I think you're conflating two very different things. You're completely right that the government can make pretty much whatever they want illegal, but things are legal unless expressly made illegal. Erasing your phone wouldn't be illegal because it implies guilt, but because of obstruction/destruction laws explicitly criminalize such things.<p>The whole case is going to come down to the nuanced and often contradictory interpretations of border law exceptions. I also don't agree that these sort of protections are for e.g. robbers, because of the criminal underground's $5 in-person data hacking tool. [1]<p>[1] - <a href="https://xkcd.com/538/" rel="nofollow">https://xkcd.com/538/</a>
In general a government can do whatever they can get away with.<p>The rest (believing they can't do this or that, because it's in some constitutional document, or violates a basic right) is sovereign citizen kind of self-delusion.
Mens rea
> <i>U.S. law though is highly non-autistic</i><p>When the judge and officers of the court agree with me, the law is reasonable and just, but when they do not agree with me, the law is arbitrary and capricious. ¯\_(ツ)_/¯<p>Having the law be whatever it's thought to be by police, prosectors, judges, and others can lead to obvious injustices, but there's been no serious attempt to remove ambiguity in any country's legal code as far as I know.
> U.S. law though is highly non-autistic<p>This is the thing that people should be reminded over and over here - and to be fair it tends to be more autistic than elsewhere<p>(Regardless if you are on the defendant or the prosecution side - or might potentially be)
Good luck proving in a court what he was trying to do though.
He gave them the unlock code, now it’s unlocked.
Ultimately, when you choose to enter a duress PIN that will wipe your device, you have to recognize that choice may have legal consequences. I don't like the amount of power our government has at the national border when it comes to detaining and pressuring citizens, but our Constitution explicitly grants it at least some of the power it now exercises in that context.<p>If your threat model includes US state actors at the national border, then your security practices need to account for the confiscation of your device at that border without requiring you to willfully wipe the phone and (in the eyes of police and prosecutors) destroy evidence.<p>That means:<p>1. <i>Don't travel with anything you can't afford to lose on device</i>. This means setting up travel-specific password managers and hardware keys for a subset of your accounts that you absolutely need to access while abroad, and being prepared to reset those passwords and disable those hardware keys very quickly once home.<p>2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. <i>Your secure setup must function without needing you to engage in those behaviors</i>, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable.<p>3. <i>Consult with a lawyer and review your security procedures from a legal standpoint</i>. All of the above is technical and practical advice, not legal counsel and no substitute for it.<p>We Americans are fortunate to carry powerful passports and enjoy relatively easy international travel but, for better or worse, that velvet glove covers an iron fist we would be foolish to forget or ignore.
> 1. Don't travel with anything you can't afford to lose on device. This means setting up travel-specific password managers and hardware keys for a subset of your accounts that you absolutely need to access while abroad, and being prepared to reset those passwords and disable those hardware keys very quickly once home.<p>> 2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. Your secure setup must function without needing you to engage in those behaviors, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable.<p>> 3. Consult with a lawyer and review your security procedures from a legal standpoint. All of the above is technical and practical advice, not legal counsel and no substitute for it.<p>Just don't go to the usa and if it's for professional reason, don't bring your personal phone.
Have the duress PIN on sticker on your phone. Maybe put it backwards and don’t say anything to border patrol. Have them try it out and erase the phone and then you can legitimately say you didn’t do anything and they did it themselves.
But if the prosecutors can make a convincing argument that your intent was exactly that all along, then you may end up convicted anyway.<p>Intent matters. It might be hard to prove, but it matters.<p>It may not even be that hard; what other possible explanation is there for someone putting a PIN visible on their phone that wipes it while crossing a border?
> what other possible explanation is there for someone putting a PIN visible on their phone that wipes it while crossing a border?<p>Two obvious answers:<p>1. It's for the general case of lost/stolen phone.<p>2. It's for the owner. I can't remember numbers I don't type in, might as well keep it visible on the device.
There’s no way to prove intent if you keep your mouth shut and don’t answer anything.
Yea, that’s not how it works in practice. If they catch you standing over a dead body holding the murder weapon. Then you can’t just say they can’t prove intent if you keep your mouth shut.
That’s good advice to not talk, but it won’t necessarily save you.
claim your password to be some derivative of the duress PIN, for example: 1234 is password reminder for 2444 (one 2 three 4), the device is erased anyway.
For if someone steals the phone?
if the cops do that, they're breaking the law with that search already<p>theyll have a hard time showing that you intended for the government to break the law. first the government would have to admit breaking the law
They might be able to convict on that, but that sets a dangerous precedent imo, which is that doing anything preemptively to prevent searches is conviction worthy, including the preparation the OP suggested.
"it would be funny if the border police typed it in to my phone"
As a speech.
Or just make it your birthday. Though I'm not at all sure the agents will try typing random codes in without at least some idea that they may work, given that many OS's will quickly start to punish with tarpitting.
Be funnier if you even write “do not enter 123456”.
That might have actually been legal. I'm not a lawyer, but it's definitely better for the accused than what happened in reality.<p>"I told you not to. You're the ones who wiped my phone. You owe me money for destroying my personal property."<p>I'm not saying you would get a check courtesy of Uncle Sam for your troubles, but the argument that you deceived authorities into destroying evidence is a lot weaker.<p>I might go with "do not enter 696969" instead because the stranger fiddling with your phone probably expects a your phone to do something funny, like load a shock site.
I wouldn't write it down, I would just make it 1234. They're bound to try that. Then they have absolutely no case against you.
The police will ask you if the PIN unlocks the phone before using it.
Refusing to answer questions IS one of the rights that the US government mostly honors.
Under US law, you have a nearly absolute right to not answer police questions.
It unlocks the phone.
Why would agents think that a number written on your phone is the PIN? That would only make sense if it was a communally-used device, not a personal one. Also, no one would put sensitive info on a devices that has the PIN affixed to it.<p>I suppose it's possible someone might enter it without thinking, but the odds seem low. Also seems risky to put a self-destruct PIN on your device, lest a friend (or enemy) enter it by accident or as a prank.
I've worked with fleets of company phones and mobile devices, people absolutely do this.
with this sort of configuration, you either trust your backups or you don’t ;)
Not a lawyer, but destruction of evidence would only be valid if there was first some reasonable suspicion of a crime? Is that right?
This is my core question as well. At what point do you have to maintain property so the government can use it to testify against yourself?<p>If I have a dash-cam, and I wipe the SD card, can the government imply that because I erased the card, it must prove that I was speeding? The dash-cam automatically over-writes old footage - perpetually destroying evidence.<p>Given nebulous cases such as "hacking" a site by looking at the HTML[0], am I destroying evidence of crimes whenever I format my PC? I hope the government requires specific charges and more proof of a crime other than missing evidence. Say I destroy my diary - can the government claim that is the key evidence where I confessed to being the gunman on the grassy knoll?<p>[0] <a href="https://news.ycombinator.com/item?id=28992667">https://news.ycombinator.com/item?id=28992667</a>
"At what point do you have to maintain property so the government can use it to testify against yourself?"<p>For the duration of the border search. This guy is at risk because he caused the data to be deleted during a border search, when CBP asserts they can legally look. He would have been fine if he deleted data on the plane or after leaving the airport.<p>(This is my understanding of the government's position; personally I don't think this prosecution is constitutional)
> If I have a dash-cam, and I wipe the SD card, can the government imply that because I erased the card, it must prove that I was speeding?<p>If the erasure was a non-automated <i>result</i> of them asking you, and you alone, what conclusion do <i>you</i> think is possible? Probable?
the government might not, but your insurance company definitely will
Also, can they proof that there was evidence on the phone?
the funny part is he didn't enter the pin he gave it to them and they entered it..., not sure if it makes any difference but there is a certain irony to it that it was the non warrant based search actions (which might be legal at the border) which lead to the erasure of data
<i>Edit for the confused and misinformed: 18 USC 1001. Also, is ≠ ought.</i><p>Lying to a federal officer is a crime, IIRC, and if the lie results in destruction of evidence, the person who told the lie is probably accountable for both crimes. This isn't a lie with plausible deniability: you have to set a duress PIN, understanding what it does, and then communicate that PIN instead of the unlock PIN.<p>A duress PIN to wipe the device don't exist to absolve the owner of liability... It exists for when compromising the device could get people the owner cares about killed or disappeared and the owner considers their own liability, disappearance, or death a preferable outcome.<p>It is an extreme solution for extreme scenarios. People need to be sober in weighing its use.
> It exists for when compromising the device could get people the owner cares about killed or disappeared and the owner considers their own liability, disappearance, or death a preferable outcome.<p>Devil’s advocate, it sounds like the accused could be part of some mutual aid networks who could be helping people who are vulnerable against the actions of the current government. People who may die if they’re deported, or returned to their family (gay or trans youth). This person may literally have saved lives by not handing over their phonebook and messages.
> It exists for when compromising the device could get people the owner cares about killed or disappeared and the owner considers their own liability, disappearance, or death a preferable outcome.<p>Or it's preferable to get caught lying to a federal officer than it is for them to have the evidence on your phone.
possible<p>but not necessary evidence, as evidence would imply a crime. But when it comes to police harassing activists, or outright mislabeling them as terrorists, there are many fully legal things you still might prefer the police not to have. Lets not forget that boarder police has in the past tried absurd things like trying to seize Attorney-client privilege protected information from a US attorney.<p>Through most likely many people setting up and using a duress pins never truly think this thought from a legal POV.
I’m quite unfamiliar with this notion. What law says it’s illegal to lie when you’re not under oath during a court proceeding?
18 U.S. Code § 1001 [1]<p>[1]: <a href="https://www.law.cornell.edu/uscode/text/18/1001" rel="nofollow">https://www.law.cornell.edu/uscode/text/18/1001</a>
Famously, 18 USC 1001<p><a href="https://www.law.cornell.edu/uscode/text/18/1001" rel="nofollow">https://www.law.cornell.edu/uscode/text/18/1001</a>
Here's one: <a href="https://codes.findlaw.com/tx/penal-code/penal-sect-37-08/" rel="nofollow">https://codes.findlaw.com/tx/penal-code/penal-sect-37-08/</a>
you had answers here. I'm trying to understand why our leaders can get away with lying so much and it being obviously in the public record, with videos on YouTube etc, and there being no recourse or accountability?<p>Is it true that the law is only selectively applied to some people?
if you follow the links theres a lot of carve outs for the government to be allowed to lie
"Our leaders" also are sometimes persecuted for lying to a federal officer; the past few years there have been more than one high-profile case.
>Lying to a fed<p>They asked for the pin, maybe they should have said "not the duress pin"<p>>Destroying evidence<p>How did they know there was any evidence on there?<p>>it exists for when compromising the device could get people the owner cares about killed or disappeared and the owner considers their own liability, disappearance, or death a preferable outcome.<p>No, the duress pin is there for when I'm under duress and being forced to unlock my device against my will<p>>It is an extreme solution for extreme scenarios<p>Wiping a device I own is extreme?
> >Lying to a fed<p>> They asked for the pin, maybe they should have said "not the duress pin"<p>The law doesn't work like that. Unless you're provably at the developmental level of a 5 year old, the court knows you know what was required, and also knows what you intended when you gave the duress pin.<p>The justice system famously never plays "simon says"...
> They asked for the pin, maybe they should have said "not the duress pin"<p>This is a Mickey Mouse distinction no court will take seriously.<p>> Wiping a device I own is extreme?<p>When the consequences are potential years in prison for lying to the US government or, in another country, torture or death in prison for obstructing an authoritarian government, then yes... Extreme.<p>All I'm saying is to decide to use a duress PIN at any national border or in any foreign country soberly, with knowledge of the potential or likely consequences.
Just submit citizen. Nothing to hide, right?
That's a different discussion. Are you interested in staying out of trouble at the border? Or are you interested in taking down the system (or at least fixing it)?<p>If you think the system needs fixed or destroyed, you do you, but don't be surprised when that approach gets you in trouble at the border.
> or, in another country, torture or death in prison for obstructing an authoritarian government<p>Also happens in the US
It's sad that your perfectly valid previous comment is dead (and that HN even works that way) ... adding <i>is ≠ ought</i> probably doesn't even help for the people who don't grasp that in the first place.<p>People who think that tricking the cops into wiping your device legally absolves you need to grow up. Also those who argue that LE can't prove any evidence was destroyed since it's been destroyed.
Yeah, but the way HN works is leagues ahead of other, similar platforms. And the top voted comment of a subthread (at that moment) being flagged is its own interesting signal about both the issue at hand and the HN userbase. I'll be grateful if reasonable folks vouch, but I'm not mad about it either way.
> Lying to a federal officer is a crime<p>That doesn’t pass the sniff test
I’ve been arguing against some LLMs about this point for a good hour and there’s a whole lot of linking intent to action where you can be liable if a court can prove it. Not that an LLM is legal gold but it’s the best thing I have to pass ideas around with.<p>The entire situation is sort of nonsensical and boils down to lots of minutia in law that no normal person would know about.<p>For example having normal widely known security features like wiping the device after N failed PIN attempts is fine. Even having long standing security practices that can’t be related are fine, like having a timed touch point where if you don’t enter the PIN every… 15 days or whatever the device wipes, perfectly fine if it can’t be connected towards the crime and you’re not compelled to tell officers you have such a security mechanism.<p>Even if you were to set a trap where you use the same PIN for your bank, your laptop, and some other security devices in repetition then decide to set your duress PIN to that by assuming it would be discovered as a probable option they’d use, you’d be ok but it could be questionable if that was by design…<p>It’s so obscure really as to how and how you’re not allowed to protect your data, even if you’re not the one performing the action to clear destroy the potential evidence yourself. The entire thing seems pretty absurd a frankly arbitrary to me, and I don’t know how people could know which cases are and aren’t legal. I know not to destroy evidence myself but I wouldn’t know to tell someone to not use the duress pin or that even giving them my duress pin could somehow be my liability. It’s madness if you ask me.
Well I prefer simply to stay out of countries that haven't got their ducks in a row when it comes to freedom. Saves a lot of hassle.
this means: put a good government in charge of the border that respects your rights
It is so sad and worrying when the already oppressed population argue for paranoid practices constraining their own practices considerably and with great efforts, eroding the other thing that constitution was so famous about, freedom, so some officers supposed to serve the population can do things easily to anyone. If they please and want it easy for themselves.
>destroy evidence<p>Who said it was evidence? Did a judge authorize or issue a warrant to collect said evidence? Absent that, it's just your property, and you can do with it as you please.
You’re way off about when it’s illegal to start destroying your property that the police want to seize during an investigation.
"Investigation" is a pretty generous way to label "some thugs working for an authoritarian state want to look for incriminating stuff - including criticism or mockery of them or their leader - on your communications device".<p>Whatever the American legal system may say, a couple of thugs with no warrant conducting searches and seizures of <i>data</i> is a blatant violation of the Constitution's intent. This is the sort of behavior Americans used to rightfully condemn.
Calling border patrol "thugs" doesn't really bolster your argument to anyone except people who already agree with you.
I would also like the fourth amendment to apply at the border.<p>Have you read United States v. Flores-Montano? The border search exception (which I disagree with) is pretty old. Can you find an era in which Americans in general found it objectionable or were united in rejecting its application to data?
To me it’s all quite analogous to walking up to, but not crossing, a border with, say, a fruit that’s legal to possess on the side you’re on, but not on the other side, and either eating or throwing away that fruit before crossing.<p>“Hey! I saw you holding that Mexican pepper in Mexico, and then you threw it in that Mexican trash can before crossing into Texas!”<p>“Yeah, so?”
But that's not what happened here. Here, you were trying to bring the pepper over, got inspected and somehow got rid of it because you were able to be found out.
This is more like bringing the pepper across and then quickly swallowing it when they ask you to look at it.
"Evidence" has never been limited to the subject of a warrant. Destruction of evidence statutes typically include material that is subject to a police investigation.
> Who said it was evidence? Did a judge authorize or issue a warrant to collect said evidence? Absent that, it's just your property, and you can do with it as you please.<p>Why do people go sovereign citizen when reality doesn't work their way? Stop imagining that the way you want things to be is the way things really are.<p>Cops do not need a judge to authorize the seizing of evidence. Cops do not need judges to decide what evidence is. Tell me, why did you just pretend like these are real requirements? I can understand why you'd want it to be that, but you wanting it to be that doesn't change reality.<p>It's as if you've just learned about the Fourth Amendment but know nothing about the nuance behind it.<p>Your system wouldn't even work at all. Let's imagine the cops get a tip that a bald man with a blue tshirt shot a man. They patrol the streets and find a match. By your logic they should not have the ability to search the man and seize his gun as evidence until a judge issues a warrant.
How about, is there reasonable suspicion that a crime has occurred?
uhh, are you a lawyer with knowledge about how evidence works?<p>its not just a word, its a specific legal term<p>cops definitely do need judges to say what evidence is admissible, and they really dont have thr ability to just declare anything they want as evidence and just steal it
Yes this is different than when law enforcement serve a warrant and the defendant wipes his computer before the agents can get a hold of it. In that case the warrant covers what you destroyed as evidence.<p>Though during traffic stops, if a defendant disposes of his drugs while on the run, that can also carry a charge of destroying evidence even though no warrant was issued.<p>IANAL
Hm but the drugs are only evidence because they're illegal? So the phone owner only destroyed evidence if the phone contained something illegal, but innocent until proben guilty?
Destroying evidence is a crime, regardless of any warrant.<p><a href="https://www.law.cornell.edu/uscode/text/18/1519" rel="nofollow">https://www.law.cornell.edu/uscode/text/18/1519</a>
VeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give proper password, real OS and FS decrypt and load.<p>Something like this may need to become the standars over duress pins which should be treated as a fallback or more extreme alternative. Right now, A single choice to reasonably and rightfully protect your privacy reuslts in jail time over something which likely wouldnt have resulted in any issues if superficial compliance was observed.<p>These goons, even if a branch of a facist regime, are ultimately burocrats with violent options to settle. They aren't doing forensics on your device etc. They have neither means nor knowledge to do so. They just need to tick their boxes. Did the phone unlock? tick. Did our spyware complain? no? tick. Overall appearance of compliance from person? yes? tick. free to go, next!<p>You just have to find ways to stay safe without agitating their workflow and all is well.<p>- [1] <a href="https://veracrypt.io/en/VeraCrypt%20Hidden%20Operating%20System.html" rel="nofollow">https://veracrypt.io/en/VeraCrypt%20Hidden%20Operating%20Sys...</a>
this will likely fail as block devices aren't dumb anymore, the firmware state will out the hidden volume. counting on the laziness/unsophistication of an adversary isn't a great move.<p>this problem may be solvable by a purpose-built abstraction where every write no matter what address will look identical to the firmware (naively, a randomized key-value map).
I largly agree, hence why the prudent move is not visiting shitholes like the (current) USA with anything important on your person.<p>However, if you must do it, there are better options than duress pins that wipe a device.
Not that shufflecake solves the issue you highlighted, but I found the shufflecake FAQ to be a good intro to the topic for anyone curious. It does a good job explaining the threat vectors and the relevant trade offs, in particular the TRIM and ORAM sections. It’s also just a cool project: <a href="https://shufflecake.net/" rel="nofollow">https://shufflecake.net/</a>
What does “block devices aren’t dumb anymore” mean?
Modern SSDs are log-structured under the hood. The presentation to the host system as a random access block device is an abstraction on top of that, emulating the semantics of spinning rust. Inspecting the underlying log will reveal the location of the hidden area, even if it looks random when read linearly.
I’m not so sure that log structure would reveal to you VeraCrypt style hidden volumes. It would only tell you about which blocks are allocated but the whole point is that VeraCrypt would allocate the whole space and within it have hidden space. You wouldn’t be able to infer (at least ethically, but you could lie) whether or not a hidden partition exists because you don’t know if the allocated block is present in the filesystem or was just allocated and never trimmed.
> allocate the whole space<p>what do you imagine allocation is in this context? it's just a set of written blocks that mark address ranges and other metadata for the OS filesystem driver (all encrypted).<p>firmware metadata will leak the fact that there is churn in the address range where a potential hidden volume lies. the churn will be inconsistent with filesystem activity that would be present in its absence.<p>it's not just SSDs you need to worry about either, HDD firmware also keeps metadata, some of it could be be proxy to churn by region.
It would also give you information about the order in which blocks were written, and the historical state of the disk. Because of wear leveling, block allocation isn't just a one-time initial thing; the mappings between logical and physical address space are changing with each write.
SSD/NVMe keep track of what regions are wiped and which contain data that has to be preserved. To hide something in the seemingly-unused space, you have to turn off trim, eat the performance cost, and pretend you had a reason to have turned off trim.
I don't believe having trim disabled even helps here. smart firmware sees the same address being written to and may therefore reassign it to a different cell for wear leveling. it's a de facto trim.<p>trim lets the firmware know which mappings it can discard without the explicit reuse of the same address.<p>however I don't believe you can observe this effect from trim command results, it will report the usual size trimmed as if the firmware never realized that you reused the same address range multiple times.
I agree that trying to outcompete seems really hard, but also:<p>Given what the experience of using a non-rooted phone is like, how very very tight the sandboxing is and how useless it is a General Purpose Computer that will tell you anything: I find it very hard to believe the unlocked phone is going to let you start probing firmware & snooping on hidden volumes.<p>This post sent my BS detector on high alert. I'm struggling to take it seriously.
Even in places where you can’t be compelled to hand over a password, attempting to deceive the cops will get you thrown in prison just as reliably as destroying evidence.
Meanwhile cops can and do regularly deceive and lie to citizen and not only don't face any consequences but actively benefit from it.
No, you're being very dramatic. Lying to cops is very often your best strategy.<p>I doubt this person will be found guilty. They will be able to prove he wiped his phone, but it will be hard to prove he destroyed evidence.
true, but in that scenario you're going to prison either way. If you legitimately use the dummy for daily driving and hidden for sensitive work, then it's better than nothing.<p>Obviously a good alternative is a dummy device but it carries similar risks, and the best option is to simply not go to authoritarian shitholes like the USA. Thankfully I've been able to avoid/push for US folks visiting us instead, but honestly the alternatives are as bad.<p>Its a shit situation where most reasonable actions carry real risks, its up to individuals to choose what is acceptable risk to them, but a dummy os you use as a daily driver for inconsequential work is, to me, an ideal midground.
>VeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give proper password, real OS and FS decrypt and load.<p>See: <a href="https://news.ycombinator.com/item?id=49057812">https://news.ycombinator.com/item?id=49057812</a><p>Implementing it in a convincing way is harder than you think. Moreover if you're under the type of regime that will throw you in jail for not giving up a password, they're probably not going to let you off the hook because they can't definitively prove you have a hidden volume.
I could be wrong, but my understanding is that the dummy OS views the remaining space as legitimate and accessible free space. Using dummy directly is of course dangerous, as you might overwrite sectors with legitimate data, but also, you can access dummy os from secret. so you'd drive dummy from secret to prevent that but can load dummy as main if under duress and it looks fine. Browser, logged into various inconsequential things, random files for inoffensive memes and other human stuff in downloads folder etc. maybe an email account you've signed up to a few newsletters and e-stores that send spam logging in via an email client that auto-launches etc.<p>Done well, I see no reason it should raise redflags in routine stops, so unless you're being targeted (at which point you've got way bigger problems) it should just seem like you're a run of the mill person who does not use their device to its full capacity, which is the majority of users.<p>at some point, having any mitigations even present is a problem. At some point being met with a boot password at all is a problem that puts you on a list. I have no solution there other than to not go to those countries or keep dummy hot.
If you read the linked thread, you'd see the reasons are:<p>1. SSDs (including phones) have TRIM/discard, so you need to disable it, otherwise the hidden volume would get wiped. You going out of your way to disable it is going to be suspicious.<p>2. Even if the above wasn't an issue, you can't really use the outer os to any meaningful extent, because you run the risk of overwriting the inner volume. That makes your decoy os suspicious. It's not definitive proof you have a hidden volume, but I doubt the authorities would care too much about that.
I last used this feature probably more than a decade ago, but: you provide 2 passwords when decrypting. If the first password is the main volume, the second is attempted as a hidden volume. If both match, the main volume registers the hidden volume as free space but prevents writing to it. If the hidden volume doesn't match, the main volume will clobber the hidden volume.<p>So the main/hidden volumes really works like a duress: you <i>might</i> destroy your hidden volume while using the main one under duress, but that does not apply when using the main volume while able to additionally unlock the hidden volume.<p>If you are in a situation to need to worry about any of this, you're probably going to jail for one reason or another, anyways.
By using Veracrypt you're already proving there <i>could be</i> a hidden volume - and it won't TRIM anything, for that reason.
This seems like the kind of thing that would put US citizens in way more legal jeopardy than just using a secure phone with a long password, refusing to unlock it, and buying a new one if the officers involved confiscate it out of spite.
This is always been the dumbest thing about "hidden volumes": It relies upon your adversary not knowing about veracrypt's hidden volume. Which BTW, is plainly ADVERTISED on the web site. The second he knows you have veracode, he will ask for the other encrypted volume.<p>See also relevant XKCD:<p><a href="https://xkcd.com/538/" rel="nofollow">https://xkcd.com/538/</a>
But Veracrypt can be used for encryption of a volume, without creating a hidden volume. I assume it would often be used this way.<p>The $5 wrench decryption technique would be even more unpleasant if you hadn’t created a hidden volume, as there would be no way to prove you hadn’t.<p>Should people be sure to never use Veracrypt volume encryption unless they create a hidden volume? I have trouble even thinking this way!
The $5 wrench isn't about breaking encryption. It's about breaking will power. If they achieve their goals great for them. If not they proved the second volume either didn't actually exist or your will power was stronger than the $5 wrench. Either way they're probably way more happy with the outcome than you would be.<p>As long as the border your crossing doesn't respect the 4th Amendment, the best approach is to not carry anything incriminating across it, nor anything that may make you suspicious.
Here is the indictment:
<a href="https://www.documentcloud.org/documents/28513012-samuel-tunick-indictment/" rel="nofollow">https://www.documentcloud.org/documents/28513012-samuel-tuni...</a><p>Here is the statute Tunick is indicted under:
<a href="https://www.law.cornell.edu/uscode/text/18/2232" rel="nofollow">https://www.law.cornell.edu/uscode/text/18/2232</a><p>There is an immediate problem: the device was being searched, and this statute criminalizes destruction of property to prevent seizure, not searches. I don't think this statute applies this situation. Regardless of whether the border agents could lawfully search his phone at the border, they didn't have grounds to seize it. I suspect this prosecution will quietly be dismissed within a few months.
If your threat model means you can’t afford for border security to view your device, wipe the damn thing yourself before crossing the border and restore it from an encrypted online backup on the other side.<p>You’re just carrying a blank phone that you intend to set up and use later, and they can’t force you to install your backup onto a phone.<p>Now, this is sus as hell, and you’ll probably draw all kinds of extra attention, but if border security wants access to your phone in the first place, you’re already in a weird place.
this isn't even that weird, when I worked in a BigTech it was pretty explicit that there were certain countries where you should not bring your actual work device through the border, and you'll get set up with a different one while in that country.
Those who thought that a duress pin was a good idea for border crossing are probably going to choose this alternative.<p>It doesn't have to be blank - just clean.
Pff one time when travelling to the US I brought two laptops, macbook and a thinkpad. I just reinstalled the thinkpad and somehow the border patrol was very interested in it. Asked me to ‘show my gallery’… it was a guiless setup and only had a terminal, problem was… somehow my keyboard layout or something was messed up and i could not even login… i spend around 2 hours being questioned by 6 people…they didnt even take a look at the macbook
What is sus as hell is the US government. It is incredible how people here are accepting things that was outrageous a few years back.
The french cybersecurity agency (ANSSI) used to share leaflets to tell you to do just that.
The US government wasn't named, but it's part of the ones that like to do some economic intelligence and no euro who read the news would trust it more than a banana republic when it comes to crossing the border.<p>Now having a corporate device with little data is no longer outstanding. Everything is in the cloud these days.<p>As for personal devices, you can explain you're taking a dumb cheap laptop for your holiday as you're working on a desktop PC at home. You're not taking your entire house when you're on a trip, just a laptop to check tourism information and post blog posts<p>I myself bought a crap laptop on ebay to shove it in bags and backpacks and go to conferences and not be sad the day it's broken.<p>but above all, he's a citizen so shouldn't care about looking "suspect". He has a right, not a privilege, to cross that border. They can explain a judge how he looked sus if they really want to search his home.
> federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City<p>Of course it’s about that huh. It’s quite scary how far the US will go against anyone who engages in this sort of activism.
AFAIK border agents can even clone your device if they deem it necessary.
Why did he do this?
Really, if this is a way to protect your privacy, then it's a bad way because it causes such a scenario. Of course it works well against the stolen phone scenario, but not again "state authorities suspect me". Especially if this is the authority of some authoritarian state, where your rights do not really matter.
Maybe he did this as a protest act?
For non-graphene users (eg. Boring iPhone people like me).<p>So there’s a feature called Duress PIN which as explained through some comments means you put a different pin which intentionally wipes the phone.
It’s not auto wipe or wipe after several failed attempts but intentional wipe of device.
(Worth explanation as the current title nor the article doesn't easily explain this was made by the US citizen providing the alternative passcode)<p>For more technical details:<p>> GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).<p><a href="https://grapheneos.org/features#duress" rel="nofollow">https://grapheneos.org/features#duress</a>
PIN to wipe seems suspicious. How about a PIN where it login to a patriotic profile and phone looks like normal android.
This is exactly my setup with GrapheneOS. The default / main profile is patriotic, with a sterilized Telegram account, state-adjacent banks and apps, etc. The second profile (that uses a separate PIN) is not so patriotic: it has foreign bank apps, crypto apps, password manager, 2FA app, personal records, and an alternate Telegram account that I use to discuss any potentially unpatriotic topics with potentially unpatriotic people.
It would be cool if there's a third PIN that can wipe the unpatriotic profile whilst showing the patriotic one.<p>So you use 1st pin for normal use, 2nd for downloading your flight details on patriot mode, and 3rd for unlocking to patriot mode whilst silently nuking unpatriotic data.<p>Or a PIN that just nukes the data for certain apps (Signal, Telegram, WhatsApp, E-mail) etc. Feds can read my Slack messages all day.
Regarding Signal, Telegram, and WhatApp:<p>1. Never ever have Signal installed on the phone during border crossing. The presence of the app itself may trigger them (speaking from first-hand experience).<p>2. Having an empty Telegram account may look suspicious. My recommendation is to have two separate Telegram accounts, with the "unpatriotic" one in the separate profile only.<p>3. Never ever use WhatsApp for anything "unpatriotic". It's way of deleting messages leaves traces ("This message has been deleted") which may rise suspicions.<p>As for email, I just don't have any email clients installed on my "patriotic" profile. They all go to the "unpatriotic" one.
There's no PIN for deleting a particular profile, but you can quickly delete it manually, assuming that you have some private time available – for example, when you are stopped at passport control and told to wait in the waiting area.
It would be cool if there's a third PIN that can wipe the unpatriotic profile whilst showing the patriotic one.<p>So you use 1st pin for normal use, 2nd for downloading your flight details on patriot mode, and 3rd for unlocking to patriot mode whilst silently nuking unpatriotic data in case of seizure.
It's absurd that you have to do this and/or be so careful.
But if you live in Russia, China, or another dictatorship, then I understand.
Yep, full agreement here. The amount of hoop-jumping is ridiculous. However, I live in Russia so I have to do all that, plus some more (e.g. the work to protect my own self-hosted VPN after Roskomnadzor issued the recommendation for big Russian online services to sniff out and report user's VPN settings).<p>I spent two weeks thinking about my new setup on Graphene OS and Windows, but it was time well spent. Before that, my checklist for pre-border-crossing cleanup required about 8 hours of work. With the new setup, I can complete the cleanup in about an hour, and restoring takes even less.
This is extremely hard to implement in a non-superficial way that would be hard to detect.<p>Android switched from block device encryption to filesystem-based encryption (with encryption data and metadata). This provides many security improvements, such as per-file encryption keys and per-profile keys.<p>However, this also means that the main file system is readable and you could enumerate the available users. If you would encrypt/obscure that information, you could still infer the presence of other profiles from file system block allocations.<p>(Disclaimer: not an expert, but I read the relevant Android docs at some point.)
I had this on a Xiaomi, maybe 10 years ago? Very cool feature! I hope they still do it. I think the wipe feature is also very cool, but not used in this way.
And wipes the main partition in the background at the same time<p>Also too patriotic is sus. Better to keep some minor offenses (that give you a fine or a week of jail at most) on that partition so they will think that this is the thing that made you so nervous during the search
Impossible to implement securely, so they chose not to
That's a nice feature, every OS should have that.<p>I believe the old TrueCrypt had two passwords, each revealing a different set of files. You'd put e.g. your tax forms in one, so if forced to decrypt your drive, you could cooperate and do so.<p>It's not illegal to delete your own vacation photos. So to prove this guy guilty of destruction of evidence, does the government need to prove there was actual evidence in the phone?
It zeroes out the vault where the volume key is stored.
Sounds like a feature that under right circumstances can land you in Guantanamo for 5 years where eventually you get cleared once the real terrorist gets caught.
If this happened in an EU country you'd all be wetting yourselves, but for some reason the rooms different today. The professional advice we are given traveling to the US is back up you phone, wipe it, travel and restore once you are comfortable. Sad state of affairs guys
Sort of feels like he should have wiped it right away, not after they seized it (by giving them the “wipe me” passcode). No idea if that’s how the law works, just my gut reaction.
> <i>US citizen charged after GrapheneOS phone wipes during airport search</i><p>> <i>It's concerning – and sends the message that [GrapheneOS] is criminal by default</i><p>What's with this sensationalism? The GrapheneOS phone didn't just wipe itself - the defendant actively took steps to wipe it. The defendant isn't being prosecuted "by default" for having a GrapheneOS phone. He is being prosecuted for what he actively chose to do with that phone.<p>If your argument is that the search and seizure was unconstitutional, and you're within your rights to wipe your data, then argue that. I'm very sympathetic to such arguments. But stop with this "they prosecuted me for having a GrapheneOS phone" misdirect
Wiping could be the last resort. Instead how about auto creating a new profile! As far as I remember Android profiles isolate apps, files, and system data and providing a fresh environment without erasing the device. To make it feel more authentic there could also be an option to automatically install a few commonly used apps by default.
Thats it. (assuming the officials don't have time for an thorough inspection)
One clean implementation of this is to wipe everything on the 2nd password failure.
How are they going to prove there was evidence of a crime? While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device".<p>Most previous court cases involving encrypted devices have required substantial proof that the encrypted device contained incriminating evidence. To be clear "you sent this illegal thing from your house" levels of evidence.<p>It mostly seems inept, if you are going to push to expand your powers you do it on strong cases where you know what happened. Doing it on weak cases like this gives a judge an opportunity to shut down that without giving you a chance of a meaningful conviction and without that you won't get any benefits...
>How are they going to prove there was evidence of a crime?<p>They don't have to, only that you destroyed evidence. That's why many people get prosecuted with "obstruction of justice" rather than the actual crime.<p>>While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device".<p>So if someone was doing insider trading, and the SEC came knocking, then immediately afterwards they start burning every document they have and microwaving their computers, do you think they should get off the hook? Surely you must think, even if the authorities or society can't a priori know you were guilty, the subsequent activity should be illegal? Note this isn't the same as banning burning documents or microwaving computers, only doing so after you're aware there's an ongoing investigation.
They need to prove you destroyed evidence, you have the mens rea component with the deceptive pin code but the defense can simply plainly say they didn't want the police to read their private device.<p>Your example is fabricated since the justice department didn't even bring forward a specific crime they believe was committed here.<p>If they charged him with a crime and had evidence his device had evidence of that crime (even if in reality it didn't) that would be a more interesting question.<p>But again where is the crime?
> But again where is the crime?<p>Destruction or removal of property to prevent seizure.<p>CBP are empowered to search US citizens devices and, if the citizen refuses to comply, to seize that device. They'll be alleging that by knowingly providing CBP with a duress PIN he destroyed his own property to prevent its seizure.<p>Notably, they don't need to prove he destroyed evidence of anything.
>with the deceptive pin code but the defense can simply plainly say they didn't want the police to read their private device.<p>That's as convincing as saying you burned all the documents because you don't want people who break in to read all your financial records. It just happened to start after the SEC came knocking
Except this isn't the SEC actually pursuing a voicable crime. This person was under no suspicion at all. They were simply coming home after being abroad: last I checked that is not a crime. Outside of a crime, "evidence" is just called property. If the TSA can't show "we have provable evidence gathered elsewhere to show that there was possible incriminating data on that phone" all they did was wipe this guys phone. All they had was pre-crime "he was involved in the movement against Cop City so we're gonna search his phone". No "he was meeting with terrorists in the DR". No "we have good reason to believe that when he was in the DR he communicated with terrorists". Just "uhhh we were looking for anything prohibited[1] and we targeted this guy because he was involved in some anti-cop protest group 3 years ago".<p>If you can't see how insanely thin their argument is, and how easily this will be abused, I don't know what to tell you. We could just as easily say having any passcode on your phone at all is obstruction of justice, since the feds could want to look on your phone for whatever made up reason, and if they can't because its encrypted, well why did you do that? What are you trying to hide? Evidence of a crime!?!?!<p>1. I had to call out, "looking for anything prohibited" is a direct fucking quote from CBP. They admitted it was a fishing expedition.
>We could just as easily say having any passcode on your phone at all is obstruction of justice, since the feds could want to look on your phone for whatever made up reason, and if they can't because its encrypted, well why did you do that? What are you trying to hide? Evidence of a crime!?!?!<p>I specifically said this wouldn't be covered, because you set up the pin before you knew any investigation occurred. However, I think it's reasonable if you were pulled aside by CBP while deplaning, and while you're waiting to interview you decided to hastily turn on encryption on your laptop, or eat a bunch of papers you had on you, I'd say that's similar to evidence tampering, not unlike flushing drugs down the toilet when you see a cop pulling up on your driveway.
> I specifically said this wouldn't be covered, because you set up the pin before you knew any investigation occurred.<p>But that’s just the thing: no investigation did occur. Being pulled aside by CBP doesn’t amount to an investigation. There can’t be an investigation without suspicion of a crime.
Drugs are actually illegal. Thats the difference. If what you’re getting rid of is not illegal or evidence of illegal activity, there is no crime. It sure looks suspicious but the point is that if there was no actual evidence, then this is getting rid of regular property.<p>You cant have evidence tampering when there is no evidence, because there is no crime for there to be evidence of.
What if you knew you were on a terrorist watchlist, so you put a PIN on your phone?
It is evidence. Something can be evidence even if the evidence does not prove any crime.
Destroyed evidence of what?
Destroyed materials that might be relevant to an investigation that you know exists.
Hmmmm sounds like the government can launch endless bs investigations, wait for their target to throw something (anything, a piece of paper, whatever) in the trash then charge them with destruction of evidence. A infinite guilty-change glitch if you will.
That's what judges are for, so cute hacks like "putting everyone in the US under "investigation" won't work. That said, if I was under investigation, you bet your ass I'd be extra diligent in ensuring I'm not accidentally shredding any documents.
What you're describing is malicious prosecution or abuse of process. It's illegal and it would destroy the prosecution's case. Not only that, but the victim could sue for damages.
To quote the article: suspected terrorism activities because of his alleged association with the movement against Cop City<p>Complete horseshit on many levels, but presumably a legally valid investigation.
You have to prove it is an evidence of a crime to start with, speculation is not a fact. My property, my business, i can smash the phone and no one has anything to do or say unless there’s an undeniable fact that there’s an evidence there and it got destroyed, else, it’s no one’s business.
> So if someone was doing insider trading, and the SEC came knocking, then immediately afterwards they start burning every document they have and microwaving their computers, do you think they should get off the hook?<p>Apples and oranges. They presumably already have some sort of evidence in order to get a warrant and are under criminal investigation.<p>According to the article the agents said it was just a normal part of screening.
Well, good luck to them. If I'm on the jury and he argues "I got my passcodes confused" that's reasonable doubt for me.
I'm not a lawyer, but my work domain revolves around data analysis of certain types of crime. Often times the suspects are flagged and under surveillance, so if and when they cross borders or go through check-points where you have a great deal of authority, they'll get searched.<p>In many countries certain agencies / agents can do searches which normal law enforcement officers can't. Like not needing a search warrant or even probable cause. Not to mention that wiping a device could in itself be a crime, if it is suspected that evidence is being destroyed.<p>The key point here is that, as I wrote, some agencies have <i>a lot</i> of authority, and have the power to do pretty drastic stuff.
The career prosecutors at the DoJ are not the same as a couple years ago. I hope this case ends the same way as the sub sandwich assault.
They are not sending their finest to court it seems.
If your legal system depends on the benevolence of prosecutors, you've already lost before it began.<p>Attorneys are supposed to be <i>adversarial</i>. The system's soundness shouldn't depend on anything more than them trying to win and not doing anything illegal.<p>Before "prosecutor" became an elected/appointed office, prosecutors were independent contractors, hired for a single case only and serving at the pleasure of the Grand Jury. The Grand Jury's job was to decide how to spend the public prosecution budget. "Indictment" meant exactly that "prosecuting this person is a good use of tax dollars" and nothing more. We should go back to that.
Any system ultimately depends on the benevolence (or at least the decency) of the people in it. The idea that a society can design a perfect system and it will run itself is very dangerous.
The comment you're replying to was focused on prosecutorial incompetence, not benevolence.
One of the GrapheneOS people (I think) suggested keeping a bit of paper in your wallet with the duress pin, perhaps thinly disguised. Then the cops could try it on their own initiative. I suppose they'd become aware of that trick eventually, but then they wouldn't be able to use all those other genuine pins they find.
This is an interesting idea, but was that GrapheneOS person a lawyer giving legal advice?
A far better approach is for the US citizen to simply say "I chose not to provide my PIN".<p>The officer will say something like "That's your choice, but I will need to seize the device to conduct an analysis. It will be returned once the analysis is complete".<p>Then you shrug, and they will let you enter the US. The cops will try to get into the phone, fail, and return it to you.<p>Just bring a phone you don't mind losing for a few months.
This person was under "investigation" for protesting against cop city. The authorities were waiting for him to turn up at a place where the law would give them more power.<p>They were never going to let him just walk in. Eventually, they'd have to, possibly after lawyers and news would get involved, but it's not like saying "no" was going to end the ordeal right away.
I have a friend who is a peace negotiator in the balkans for 20 years. He has lots of amusing (to my horrifying) stories of cat and mouse interrogations with the FSB etc as he travels between Moscow, Kyiv and the West. He uses threema and signal for most diplomatic conversations, but when he travels he only carries burner phones.<p>If you don't trust a government, ensure you aren't carrying any information you don't want to give up before entering their borders where you will be under their power.
<i>In Catalonia, Spain, police have been profiling people carrying Pixel phones, assuming they have GrapheneOS installed and are drug dealers or gang members.</i><p>WTF.
I'm not doing anything the government should be worried about. Nevertheless my pin has for a long time been longer than standard, specifically on the very long-shot possibility someone decides they want to crack it.<p>Anyone know if this is a viable strategy on iOS, and what the required pin-length is these days?
I think a wiser approach for crossing a border might be to have another phone with regular Android installed on it, so it doesn't look suspicious, and then connect remotely to your main phone. Before crossing the border, you would just need to remove the remote-connection app, and after crossing, install it again.
Never piss off the minions of the Supreme Leader.
Nice national parks, but no way in hell i m visiting this decade
Might take longer I assume. This has been building up since at least 2001 and I don't believe it will be faster they get healthy again.
> this decade<p>Do you think things are going to improve in our lifetime?
> federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City.<p>This is practically the only thing I care about here and there are almost no details. What was his alleged involvement? How many others were targeted?
Seems like they’re going to have a struggle proving intent. “I was stressed out and afraid and I got the passwords mixed up” would be the magic words I’d hear as a juror and I wouldn’t be able to vote to convict.
If you get a jury who doesn't think that "strange self-destructing phone" isn't a criminal's tool to begin with. Which I'd guess is probably not likely.
The defense has a chance to educate the jury about it in a trial, and given how widely CBP/DHS is distrusted in 2026 it’s not difficult to see at least one juror having reasonable doubt.<p>Bonus for the defense: whatever is left of the DOJ, it’s mainly cranks, cronies, and people who can’t find work elsewhere.
Surely they'll just dig into as to why he set up the feature originally?
Why the hell doesn't the "duress PIN" just open up a sanitary profile? Bonus points for letting you set it up with plausible data before designating it as the duress profile that, when opened, wipes your real profile <i>in the background</i>.<p>> "the screen went blank, flashed several times, and the phone appeared to restart,"<p>How about flash some red lights and play an airhorn sound effect, too.
So in GrapheneOS you enter your regular passcode to unlock it and a secondary passcode will wipe everything? Maybe it needs a third option where it just shows predefined apps/data, so it could just show e.g. WhatsApp, a set off chosen photo albums and some irrelevant office documents. Could also be useful for handing it to children, so they can access some games or whatever but nothing critical
Perhaps a way to avoid this would be to have the duress pin trigger not a device wipe, but a device encryption with a long, pre-set key that you would store in a safe place when setting up the duress pin. Then you haven't destroyed the evidence, but the data is irretrievable without your cooperation. Also, if you don't actually have the key saved, it would in fact be destroyed, but the prosecutor would have to prove that you don't have the key saved somewhere.
This is one of those things the other comment calling the law "non-autistic" is referring to. In the eyes of 99% of people, it's functionally the same thing. "Well teeeecccchhhhnicallyyyyyyyy I still have the data..." isn't going to make the security workers at the airport slap their heads and say "damn, he really got us! Go on through!"<p>No. They'll arrest you just the same for obstructing their search. Then they'll keep you in detention for a long time while you say "I can unlock it for you! You just have to let me out!"<p>You can pretend you have leverage and say they need to cooperate with you. But once you're detained, police and prosecutors don't really care about cooperation anymore. Their idea of cooperation is you giving them what they want immediately without question. You're made into an example if you don't abide.
You are incorrect, US border patrol can not arrest you for refusing to decrypt your phone (if you are a citizen). It is not considered obstructing a search to refuse to provide a password. This is not "autistic" speculation about legal technicalities, there are many many examples which support this. The worst they can do is seize the device.
The entire point of modern encryption is that the encrypted data should be indistinguishable from noise until you have the key in its entirety. Turning your data into random noise (whether or not there’s a secret code somewhere that can reverse the process) is destruction.
After reading more of this thread I'm kind of frustrated that people aren't aware of the border search exception.<p>I strongly disagree with the border search exception and would like to see it drastically limited or abolished.<p>It is also something that has clearly existed in caselaw for decades (arguably for centuries) and that the courts have routinely (to my regret) strongly reaffirmed.<p>The border search doctrine says that border agents do not need a reason to examine you or your possessions when you are entering the country. They do not need to believe that you are doing something wrong or committing a crime. If they suspect you, they don't need proof or a good reason to investigate you.<p>I find this doctrine very disturbing and I hope it will be changed or narrowed. I also would like people commenting in this thread to understand that border agents are not just imagining things when they claim to have legal authority to inspect people (or, alas, electronic devices or data) at the border, and that this didn't just start under the Trump administration or something.<p>The legal consequences of providing a duress PIN may not have been tested and this defendant could well prevail in this case. I just wish people commenting here would understand that there is a tremendous amount of history related to border search authority. You can disagree with it (I hope you will!), but you should understand that it's not just something that someone just made up last week or last month or last year.
Why is the headline blaming the OS for what the user chose to do?<p>This is like saying it's my car's fault if I decided to drive onto the sidewalk or something.
Yes, the only relevant property is the use of a duress PIN. They could have simply stated that he erased his phone with a duress PIN.<p>But "GrapheneOS! Spain! Profiling Pixel users! Spain equates GrapheneOS to criminals!" sounds far more spectacular and will give more clicks/links. Sadly, it feeds the narrative that GrapheneOS is just for activists/criminals/whatever. An iPhone in BFU state would have been nearly as safe, but nobody makes these implications about iPhones because everybody has iPhones.
I mean, yes?<p>If 1% of iPhone users are criminals and 5% of GrapheneOS users are criminals, border search agents are going to be interested in your GrapheneOS mobile.<p>I am pretty sure criminals are more likely to use a super safe and secure phone that is easy to obtain.
Yeah, the way that this case is being reported on is really irritating.<p>While he technically did use a special GrapheneOS feature to wipe his phone, the criminal charges would have been the same if he had used the default "reset phone" feature on Android or iOS right before handing the phone over.<p>The real focus of this case should be on the reason for his detainment and the confiscatation of his phone and multiple refusals to contact his lawyer.
There are laws against the destruction of evidence, but I'd argue that there's no evidence in this case since they don't have clear-cut knowledge what's on the phone. It's <i>potential</i> evidence at best and it's therefore not clear if the law applies.<p>If Customs already <i>knew</i> whether the suspect had incriminating files on his/her phone things might be different.
In fairness to the victim, he did really need to have that phone. What if there had been a restaurant with a QR-code menu? What would he have done then?<p>So yes, we've created an authoritarian hellhole, but the alternative is even MORE unthinkable: struggling to pay for parking in some areas, needing to visit a website for a menu or (GASP) visiting a different restaurant, or just having a friend order for you.<p>No, these are too much to ask of anyone. No one can overcome these challenges. The only answer is to weep for the liberty that we have lost.
why would you need to carry incriminating data with you when travelling? An encrypted blob stuck 'somewhere' would be fine, no?
As a citizen the safest way is to just refuse. They can’t refuse entry. Not the same for LPRs.
The article seems to be muddying the water bringing up grapheneOS itself. Or maybe it's the EFF.<p>>Experts said the legal approach is unusual and may be the first time the law has been aimed at an operating system. "It's concerning – and sends the message that [GrapheneOS] is criminal by default," said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.<p>Is the actual case about banning the OS? Because it seems pretty clear the case is about the result (the phone being wiped with a special passcode).<p>The better defense imo would be one of those 'wipe the phone if you get the password wrong x times' and try and claim you forgot under pressure. At least if you wanted to wipe the phone without being accused of destroying evidence during a search.
By raising the profile of airport seizures all it means is that serious criminals will wipe their devices prior to travelling and restore afterwards/buy a new device for travel.<p>The powers of investigators special rights and abilities rely on them being used very rarely. Last thing the terrorism investigators want is media coverage exposing their tactics.
> The motion also states that Tunick asked four times to speak with a lawyer and was denied each time.<p>This is the kind of thing that loses cases, even if they were legitimate at first. Seems like the prosecutor is desperate charging for the phone wipe cause they didn't have any evidence of terrorism, child-pornography, etc. The problem they have now is given he was in custody and agents pressured him to provide the passcode that they then incompetently put into the phone, the fact that they denied him a lawyer multiple times means there is a very strong argument that his rights were violated. Typically, courts suppress any evidence when there is a violation like this with someone in custody. So the compelled passcode, the phone's reaction when that passcode was entered, and the agents' testimony describing the supposed wipe would be thrown out by most judges. What's left for the prosecution after this is jack and shit, but jack left town.
The duress pin deletes the encryption key information used to decode the documents and does not damage the documents themselves.<p>Not sure why the police and news are saying that he destroyed evidence, since the evidence (as it always has existed before the search began) remains on the disk.
Someone else commented about the law being “non-autistic”, this is a perfect example of that. The technicality of the encryption keys vs the files is irrelevant, the <i>intent</i> was to successfully prevent a search. The border agents will not be even remotely impressed or suddenly decide to release you just because you say “well the files are <i>technically</i> still there”.
What they should really do is make the decryption key backupable.<p>Then you can keep it at home, and you can genuinely say that you don't remember it because it's like 128 digits.<p>And you're not "destroying evidence" in the jurisdiction in question because the phone is already locked. And you <i>can't</i> unlock it on demand.
Perhaps a defence to this is ensure that a copy of the encryption key exists in a location outside the jurisdiction of the state.
So let them just sieze your device. Don't unlock. You'll get it back in a few months.
maybe write down the duress pin somewhere in your wallet. let them make their own assumptions and erase the alleged evidence on their own.
They have absolutely no idea if evidence was destroyed, and the only thing he is charged with is the possibility that it was.
Wouldn't it be better from a legal standpoint to power the phone off and refuse to give your pin in such cases? A no-pin cold boot is pretty hard to recover data from with GrapheneOS.
Most likely, at least you are not doing something irreversible. In all these cases, the best answer is "ask a lawyer". Before wiping a device in possession of law enforcement you definitely want to ask a lawyer.<p>I realize that in this case the person repeatedly asked for a lawyer, but if you are in a borderline authoritarian state, all bets are off.
Following this being in the news, GrapheneOS wrote this post summarizing the data extraction defense: <a href="https://discuss.grapheneos.org/d/40700-grapheneos-protections-against-data-extraction-from-locked-devices" rel="nofollow">https://discuss.grapheneos.org/d/40700-grapheneos-protection...</a><p>On the duress pin, they say (read the whole thing though):<p>> People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device.
I feel like the advice given by IT departments for years was to wipe your device ahead of travel, and restore from backup upon arriving. Or, to take a travel device.
From the article, I saw this:<p><pre><code> > According to court testimony, federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City.
</code></pre>
I didn't know about Cop City, but I found this on Wiki: <a href="https://en.wikipedia.org/wiki/Cop_City" rel="nofollow">https://en.wikipedia.org/wiki/Cop_City</a><p>This part is interesting to me:<p><pre><code> > RICO conspiracy indictment
> In September 2023, sixty-one people who had been arrested in the forest or at stop cop city protests were charged with racketeering under Georgia’s RICO law. This indictment is likely the largest criminal conspiracy case ever filed against protestors in the US.
> As of April 2025, the racketeering case was stalled. Defendants in the case maintained their innocence and reported difficulty getting work and other hardships while they awaited trial for more than 20 months. In September, all RICO charges were dropped. Judge Kevin Farmer found that the Georgia Attorney General did not have the authority to bring RICO charges in the case.
</code></pre>
From my outside view, it looks like these investigations are nothing more than an attempt to suppress free speech and protests.<p>For anyone unaware, RICO is both a Federal law and a Georgia state law that stands for: "Racketeer Influenced and Corrupt Organizations". It is used to take down mafia, gangs, organized crime, etc. It is a bit sad to see state prosecutors trying to use this against protesters.
Its best for all of us to figure out how to use phone-as-a-linux-vm with the physical phone just hardware. It will solve many problems: commoditize the phone ecosystem, eventually making them repairable, run our own apps instead of apple/google. Access phone-vm from laptop/desktop ...
His mistake was giving a passcode he knew would destroy the data on the phone. Instead leave the destruct passcode written on a scarp of paper inside your phone case.
The problem with this feature is that the agents could realize the phone was being wiped. For the duress pin to be 100% effective, it would have to log in normally to a default install.
Ok, so I'm just angry so take this comment in that light please:<p>1. What happens if the masses just do this? Today it's just a few folks who know how to do this. Tomorrow it could be 10, a year later 100. What's to stop 1000s from doing this and then what is the government going to do? Ban the OS and block it on Github?<p>2. What exactly happens after you're charged? This doesn't mean the person is convicted. Just that they now have to show up to court wherever the trial is held and have to retain their own lawyer (or public defender?). And what is the likelihood that the case is thrown out or the person is convicted and receives a stiff penalty?<p>I ask these questions because as far as I can tell, the person was not suspected or convicted of anything, and it's infuriating me that we are just going to stop random citizens and ask for their private data.
You wouldn't be surprised if that happened when traveling to China or any other autocratic country.<p>I think the issue is that people expect the USA to be the "land of freedom" when it's not anymore. It's turning more and more into an oligarchy and we are at the point where it's just as bad as russia or china.<p>If i was offered a trip to China or russia, i'd go but i would take a burner phone with absolutely nothing important; It's the same for the usa now.
No, as someone who lived in China for years (as foreigner) and visited also last year after many years I WOULD BE SURPRISED if this happened when travelling to China, since China is clearly more free than US/Israel.<p>China wants tourists and don't care about your stupid social media.
It has always fascinated me, the degree to which airport staff feel so important, as if the world would stop revolving without them.
> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart.<p>I'm confused to understand if Tunick did anything illegal here. If the authorities want the phone, they should have the warrant and seize it without Tunick's permission.<p>It appears authorities did not have the warrant which give Tunick all the right to do whatever he desires with his property.<p>What am I missing here?
They don't need a warrant to seize the phone at the <i>border</i>. They were after the pin code, he should have just refused to give the pin. That's the 5th.<p>What they got him on, is that supposedly he destroyed evidence.
Among other things that CBP does not need a warrant to search or seize anything and everything at a border. Everything is subject to search at the border. To make a seizure all that is needed is reasonable cause that customs law/regs were violated. And there are specific federal laws relating to thwarting such seizures.<p>If you don’t want something searched do not bring it across the US border. There is very clear constitutional and statutory authority for these searches.
> To make a seizure all that is needed is reasonable cause that customs law/regs were violated.<p>What would be the reasonable suspicion that a USC bringing their personal phone on a trip with them would be a customs violation?<p>That doesn't sound at all reasonable.<p>In fact, the only "suspicion" they had was that he was someone who didn't like LE or Trump which is still not a crime, nor a customs violation.
It appears to be illegal to destroy property to prevent seizure. I don't know the details; if you search that phrase you can find more info yourself.
CBP doesn't need a warrant to search at the border, including electronic devices.<p>However, if Tunick was smart he would have refused to provide the PIN, and let them seize it. He'll get it back eventually, but it was in his right to refuse.
Rather than wipe the phone to an obvious reset state, this feature should boot into a benign setup with normal contacts etc. after it erases the user's data. Let the user periodically boot into this benign setup to add basic contacts etc.
It seems to me that this should have been a case of steganography?<p>Instead of wiping it clean, wipe to innocuous mode. Then the burden on their part is not only to show that I gave a bad pun, but that the innocuous mode is materially different than the previous state.
I suspect that this will ultimately be thrown out for a very simple reason which is that the government will have to prove that a duress PIN was actually entered. That is going to be quite difficult unless the person charged openly admitted it.<p>The reason is because anyone running an os with a duress PIN that has done nothing wrong can be accused of using a duress PIN because the whole point of the duress PIN is that it looks like you just have a normal phone.<p>Running a normal apple operating system with just stock apps? Boom, you're a criminal because you obviously used a duress PIN and have something to hide! There is no way to prove you didn't use a duress PIN because the phone was "wiped."<p>Now unfortunately grapheneos probably leaks information so that a duress "unlock" can be differentiated from a standard unlock by some means. If not then kudos. It looks like it is done instantly by keeping everything encrypted and just zapping the keys, but it also needs to actually unlock to something instead of rebooting to prevent leaking the information that a duress pin was used. Not sure how fiesable that would be though.
Why didn't the device shadow-ban the user instead of wiping the device upon entering the wrong PIN?<p>Of course TSA agents become angry when they enter the PIN and see a message "wiping device".
If they were searching for evidence of a crime, what crime was it?
They claimed they were looking for CSAM. There's a border search exception to the fourth amendment that says CBP can search your phone at the border. You aren't required to give them a password (but possibly a fingerprint or facial scan) but they can temporarily sieze it (and do god knows what to it).
The crime of disagreeing with the President.
The downvotes you get on this website for being completely correct never cease to astonish me.<p>I'd like some filter where if a comment is downvoted by IP addresses located in USA, they are considered as upvotes.
That isn't a crime in the US thanks to the first amendment.
> That isn't a crime in the US thanks to the first amendment.<p>Technically correct is not the same as practically correct.
Doesn't mean they won't still dump your phone and detain you as long as they can if they see a meme they don't like.<p>They can detain you for days if you're not white. (Kavanaugh Stop)
Maybe also shows that the duress PIN feature could be implemented better. Booting into a completely fresh phone is suspicious. There also shouldn't be any visual or other indicators of that happening.<p>In the old TrueCrypt containers you could set an optional second password that would decrypt a different volume. The size of the container file was always the same, a decrypted volume always showed the full container size, the portion not occupied by the data in the main volume was filled with noise, and the data on the non-loaded volume was not protected (so you could erase it without warning by storing too much on the loaded volume), making it practically impossible to prove the existence of a second volume either way in a search situation. I guess there was a reason why the project was stopped.
Obviously you should just write the duress pin on the back of the phone inside the case. If the ask what the PIN is for, stand mute. If they enter it, it is their decision.
The only safe thing to do is to backup your phone. Wipe it and go through the border. And then restore the phone.
It feels like if he triggered a wipe - that is destruction of evidence; but if it auto-wiped he's fine.<p>If it were a box of drugs and he triggers an incendiary device - he's in trouble . If agents trip a protective boobie trap and destroy the box- he is fine.<p>Don't know why but this feels correct to me.
Perhaps we need the following feature:<p>Before entering the airport you set your device to auto-wipe after x hours.<p>Once you are sitting in the airplane and flying, you cancel the scheduled automatic wipe.
A GrapheneOS is most likely completely secure in BFU state [1]. So just switch the phone off or reboot it and don't enter your PIN. It is very unlikely that law enforcement is able to decrypt the phone and it does not put you in murky legal terrain, because even an auto-wipe is intentional (IANAL).<p>[1] This is in contrast to many other Android phones outside Pixel and Samsung flagships, because they are too cheap to add a secure element, which iPhone has had since 2013 and Google Pixel since 2018.
Privacy and security are important, but there should also be clear legal guidelines for such situations.
Clear legal guidelines for which country? Or, better yet, for which subdivision within said country?
anyone would think that wiping entire device than giving sneak peak about what is in the phone is 100% sus as hell
They violated his rights and he pulled a prank on them. They need to chill out.
Charged is not convicted. Anyone can be charged with anything if the prosecution is vindictive.
There was no warrant, nor any court order compelling him to provide the unlock code. They had no probable cause, other than that they had labeled him a "terrorist" because of his political activities. The CSAM pretext was provably just a pretext. If he gets good representation, he should be able to (eventually) beat this rap.<p>If he had simply refused to provide the unlock PIN, he would have walked away. They may have kept his phone, but they would never have got anything from it anyway.
Is this an ads for GrepheneOS?
So having a Casio F-91W and a Pixel 9a at an airport in US basically sends me to Guantanamo?
This grapheneOS may be another scheme from the 'deep FBI'/'services' to get intel on the very, VERY, nasty (terrorists, human traffickers, drug cartels, child stuff, etc). If I recall properly, they did that in the past (it seemed to have worked amazingly).<p>If so, "normal" police would not have the "keys". This would be "the compromise".
This case will only help make more criminals aware of this possibility.
There needs to be a simple feature to wipe your phone and then restore to a point and time. That’d be really convenient.
Seems like a good court argument too—no destruction of data was even attempted because I know I have my iCloud or Google backup. Personally, my phone has access credentials to information, but not the information itself. So you need a serious warrant before you can get those access, but the data is there.
I agree that it seems a simple argument for any competent lawyer to make that the phone isn't the "gold copy". The phone is just an ephemeral copy of the real data which is safely stored away in the cloud, and the authorities can request access to with the proper warrants.<p>Of course this argument will only work if the phone is indeed and a ephemeral copy of your real data.
Honest question: Does a wipe just wipe what's on the phone, or does it also tell the cloud to delete stuff?
This sends like a more-info-requiered situation. Per this article, the LEOs seemed to be fishing, so they presumably couldn't claim as a matter of fact that evidence had been destroyed. Also, claiming destruction of property seems unreasonable since the phone, the property, still exists as before. If I sell my phone, I'm going to wipe it. I think we all understand that it would be ludicrous for the buyer to claim I was destroying the phone, the property they've been sold, by doing so.<p>Even if the accelerated executive capture of the judiciary is largely ruled back post Trump (big IF), I fear the government will be unwilling to pay with much of the convenience of rule-by-law that it's been given a taste for.
Gotta wonder how it would've gone if the citizen hadn't mentioned GrapheneOS at all and instead tried to sue them for wiping his phone without his permission.
> US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search<p>I really don't like this title. Officers asked him to open the phone, which he pretended to do, but instead wiped the device<p>> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart. The defense motion states that "the screen went blank, flashed several times, and the phone appeared to restart," resulting in the loss of data.<p>The title implies the agents maybe entered too many pins by mistake and the device auto-wiped, or that it reset itself with no human intervention, which isn't what happened. This is more like shredding paper when the FBI arrives at your office, which most people would attribute to destroying evidence. I hope he wins the case in principle (I think there's a risk of a slippery slope here) but it wouldn't be a moral tragedy if he lost.
What nobody has commented yet here is that the incident is 7 months old but we're only hearing about it now. Imagine the incidents we DON'T hear about at all.
maybe have the default behavior for the phone to reset if it doesn't get the right pin every so many hours
it's a bug: the wipe should only apply to a see secure enclave, and the phone should restart `normally`
Instead of a PIN that wipes the device, it would be much better to setup a special PIN that logs the user into a sanitized, completely separate profile with generated content of no practical value. This would create plausible deniability, and be sufficient to allow low-level border agents to look through a phone and pass any checks without raising these kinds of alarms. The wipe PIN should still be an option, but should be separate, and only be for cases where you suspect a forensic imaging or search of the device is to take place and the legal consequences outweigh the risks.
Having just gone through having to give pin to cbp you just need the apps on your phones to have separate pins so when police unlocks it, they cannot unlock WhatsApp afterwards. Faceid or unique pin. Problem is your phone pin overwrites Face ID
Dystopian reality. Sounds like Russia.
"Prosecutors say the OS erased evidence"<p>It's his device, so he can do everything he wants to. The USA
is currently re-purposing constitutional protections. A judge
has not signed these warrantless seizures, so why would the
individual be under any obligation to cooperate? Besides, why
would anyone want to incriminate oneself? The onus would be on
the state to prove a guilty state.
Every day I thank the lord that I left the US for good and never went back
I would be very interested in how you did this / where you ended up. Feels like an impossible task every time I consider it.
There’s been a large uptick in immigration from the US to Ireland; almost ten thousand last year. In general, people would do this via employment; software engineers and similar would generally qualify for a critical skills permit. For critical skills, after two years on a stamp 1 visa (tied to a specific employment) you can move to a stamp 4 (not tied to specific employment). After five years working in the country you can apply for citizenship.
Other countries are worse legally than USA, including uk
Anyone else running box for local ai on android ?<p>www.github.com/jegly/box
Related, There was a local guy who was held 'in contempt' for 4 years for refusing to turn over his password/encryption key<p><a href="https://arstechnica.com/tech-policy/2020/02/man-who-refused-to-decrypt-hard-drives-is-free-after-four-years-in-jail/" rel="nofollow">https://arstechnica.com/tech-policy/2020/02/man-who-refused-...</a>
I don’t understand why phones can’t just have decoy profiles you can activate via PIN that look like regular harmless user profiles? Especially now with AI you can quickly populate with a bunch of plausible data.<p>Or better, have PIN for taking you to your criminal/secret profile instead.
TIL about cop city... Wtf?
could graphene support multiple duress PINs?<p>feds: "unlock your phone or else"
victim: "um, you're stressing me man. It's either 1234 or 4321, I forget. One of them wipes the phone, the other will unlock it."<p>Whichever PIN they try, it wipes the phone, but the feds can't claim it was deceitful, just unlucky.
[dupe] Discussion: <a href="https://news.ycombinator.com/item?id=49024436">https://news.ycombinator.com/item?id=49024436</a>
In Russia? In China? In Iran?<p>Nope, in the US.
why not just have a separate device for traveling ?
Yeah, that's my position.<p>If you're paranoid enough to be using GrapheneOS, why would you take it to an airport in the US of all places?<p>I bought a second hand iPhone for overseas trips, which my daughter promptly stole because she wanted an iPhone, but then i got her old android phone, which was LineageOS-compatible, so that became my travel phone.
How do you manage data between your primary and travel-phone?<p>I _think_ you would need a fresh iCloud account (thus losing access to purchased apps and subscriptions). You also need to manually create fresh social media accounts, copy over contacts, etc.?<p>Any advice on how to automate this process or is this just a 2-4 hours exercise you do before your trip?
A couple of hour exercise setting up the minimal amount necessary for the travel beforehand. Then once you're at destination, you can set up everything else if you want.<p>I don't have a lot of "everything else" anyway, so my device would probably look suspiciously 'clean' even if it was my in-this-moment daily driver. (HN is my news and social media). I don't use banking apps, but the irony is that I would need to whilst overseas.<p>One of the funny things is, I should be able to re-setup any device with an old gmail account at any time in any place, but with all the extra security these days, you need an old device to authorise the setup of a new device. I'm going away early next year, so I'll need to have a dry-run of the setup...
You mostly don't sync any such data. Prepare some file (or a few files, including an .ics for itinerary or what-not) with information about your trip, a few days in advance, and copy the file(s) to the phone. That's it.<p>And if you use iCloud or any of that stuff - you've already lost; Apple, and the US government already have access to your files and communications before you ever came to the airport. Sure, maybe it's not the specific border guards who have the access, but still.
GrapheneOS is excellent but seems like it just brings unwanted attention at this stage.<p>Another plus is if you do lose the device the damage is minimal, its a bit of a hassle but nothing beats peace of mind
The US is known for it's freedoms and protections. It's one of the safest place to take a personal phone.
- e-sims make it much more difficult to swap sim cards between devices.<p>- presumably border patrol wants to see his photos, social accounts, and email. A separate device with a copy of the information they want isn't a defense. Creating fresh travel-only accounts is tedious, b/c fresh accounts aren't connected to your friends or network (with whom you'd want to share your trip with).
he doesn't need to do this if all he doing is legal
[dead]
[flagged]
I just wouldn't want my dick pics to get out.
While I like the idea behind GrapheneOS, I'd rather not place myself in jeopardy of some ridiculous charge like this one. I prefer to travel with a travel device, some inexpensive phone and/or laptop that contains nothing interesting. If they then wish to take it from me because I won't unlock it, then have at it!
That said, the situation with respect to our Bill of Rights at the border has gotten ridiculous.
The "duress PIN that nigh guarantees destruction of evidence charges" functionality is extremely stupid, but otherwise GrapheneOS on a flagship phone is your best bet for an Android phone that can't be cracked by low-effort attempts, government or otherwise.
My bets for the actual story behind this are:
95% a criminal hiding evidence
4.99% an autistic attempt to "keep his privacy" for no reason at all
0.01% a genuine need to keep something away from the government<p>In all cases just don't cross security checks with evidence you wouldn't want to be seized, its not that hard
To everyone who thinks this is somehow a violation of rights: if you were being questioned by border officers, and were asked 'Sir could you please open your suitcase', and you pressed a button that caused it to burst into flames, there isn't a country in the entire world that wouldn't arrest you on the spot. Why would 'wipe a phone when officer requests it opened' be treated any differently? Suspicious behaviour is treated as suspicious by normal people.
It doesn't sound like this person pressed any buttons. They were pressured to provide a PIN or be delayed and further harassed. They obliged, and agents decided to enter it to attempt a warrantless search of the phone.<p>It's not stated, but probably we can assume the person didn't ask for his phone to be searched - probably he asked NOT for it to be searched, at least based on his multiple requests to talk to his lawyer.<p>Considering those factors, I'd say border patrol is more responsible for wiping the phone than the person.
Right, but by that rationale, it’s also suspicious to say “no” when they ask if they can open your suitcase. Or decline to tell them where the key is. Or ask to speak to your lawyer first. Or refuse to tell them what is in the suitcase. Or lock the suitcase in the first place. And I want to live in a society where those behaviors are protected.<p>(1password has a “traveling” mode that wipes it of sensitive passwords before going across borders. Is that suspicious? Should it be criminalized?)
Yes, they would be rightfully arrested for setting off an explosive device in an airport. This analogy ... isn't great.
material =/= information.<p>Are we supposed to live in a world where if I'm crossing a border I must give access to all of my information? That's absurd and more equivalent to a full brain/memory scan than a suitcase search from your example. This is dystopian in every sense of the word.
The Overton window of this fucking prison planet went so far that there's little to no discussion on how absurd and dystopian it is.<p>And rest assured, when it gets to actual full brain scans, the corresponding threads will be chock full of scum tasked to normalize that.