US citizen charged after GrapheneOS phone wipes during airport search

19 hours ago (techspot.com)

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully).

The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that.

The end result (not inherently different from what we wrote in the guide) is that you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to. I was fascinated by techniques for being unable to comply (which is straightforward to achieve if you want!) but probably didn't think enough about how much this might antagonize border agents in many cases.

I definitely don't know a comprehensive big-picture solution.

  • There are 2 cases routine inspections and targeted investigations.

    If it's a routine inspection, being uncooperative will probably lead them to escalate. You generally want to keep things routine and boring. If they want to access your device you have to weigh the costs, just log out of everything before you fly and throw away your device after they have had access to it, it's now compromised.

    If you are targeted your compliance is irrelevant and only weakens your position, the thing is at the border you don't get all of the protections you get at say a traffic stop they can search everything you have on you without warrants reasonable suspicion or anything.

    I am not a lawyer but if you are a citizen they probably can't deny you entry but can probably detain you for an uncomfortable amount of time, and seize whatever they want. Your best defense is to have a burner phone and no other devices nothing they can seize that would hurt you.

    For foreign nationals pretty much the same applies except they can deny you entry and ship you off to alligator Alcatraz, just don't fly to America for a few years.

    Remember he is not being prosecuted for not handing over his device but for destroying the data they were trying to seize, if he just let them keep the phone he would be Scott free. I.e.the best technical defense is secure encryption with a key thats long enough and not stored on the device.

    Actually for the particular case the best technical defense is to not have any data whatsoever on you.

    • > I am not a lawyer but if you are a citizen they probably can't deny you entry but can probably detain you for an uncomfortable amount of time, and seize whatever they want. Your best defense is to have a burner phone and no other devices nothing they can seize that would hurt you.

      Even having a burner phone without any personal information on it can be deemed suspicious. It would be best for your phone to have a recently-reinstalled OS, with a few critical apps like Whatsapp or iMessage set up with a few personal messages sent. You need to be able to set those up without a password manager. Anything else needs to take place on devices that you aren't carrying with you. Fortunately enough people don't update their Facebook these days that just having an account that exists but you don't use will probably work, assuming you don't look like someone that would be obsessed with their socials.

      Maybe there are USB thumb drives that operate like a YubiKey unless special setup is performed to access the storage inside? That's one way to carry data with you if you have to.

      3 replies →

    • > just log out of everything before you fly and throw away your device after they have had access to it, it's now compromised.

      I get what you are saying, but this is incredibly expensive and not really practical for most people.

      1 reply →

  • > you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to

    That's the same problem with technical solutions to crime.

    I come from a very dangerous city and I used to have a car that needed a PIN to work. You could turn then engine on and drive but after a minute if you didn't input the PIN it would turn off without warning and start blasting the alarm. The idea being that if the car was stolen the thief would be stranded not far from home unsure about what's happening. Great technical solution but it ignores that a lot of the time the car is stolen with you in it (in a kidnapping, for example). Having the car shutoff in the middle of a highway next to a panicking guy with a gun and trying to remember a PIN is not a situation you want to be in, so I just had the PIN number written down on the dashboard, which worked very well when I was eventually kidnapped and just pointed at the piece of paper with the number.

  • I think in these situations your absolute best bet is fawning compliance. Ask precisely how high they want you to jump.

    Perhaps your friendly smiling Yes-Sir-No-Sir-3-bags-Full-Sir act might just be enough to let you get on your way without anything else happening apart from a stamp in your passport.

    Even the slightest hint of defiance or surliness from you to a border guard/policeman/etc - potentially at the end of a long shift, tired, angry, pissed-off or whatever - and you're straight away hugely more likely to have a bad day.

    Finding strategies to "beat the system" will, I think, just be a shortcut to some other punishment/crime/taken-out-of-sight-and-given-a-proper-kicking-oh-they-resisted-and-went-for-my-gun/etc as this person found out the hard way by trying to be difficult.

    I genuinely don't think there is a "get out of jail free card" or magic incantation you can say to get out of these situations apart from just smiling and being polite and not being a dick - if you get into a "who can be more annoying" competition, then the border guards/police will always win since they hold all the cards and will happily ruin your day/holiday/meetings etc by detaining you (its their job to do this after all)

    There have been cases very recently in the US where the authority figures down dealing with the public are evidently in a very defensive, aggressive "us-vs-them" mindset, with an itchy trigger-finger to go with it. Don't be the person on the receiving end of a cop seeing-red because you're being a jerk.

    The house always wins.

    • This comment irritates me. On one hand, I agree with it. On the other: how is it not just a version of “if you have nothing to hide”?

      At some point, you should fight for what you consider basic human rights. Where you draw the line and how you fight is up to you.

      It sounds like your attitude is to comply with whatever the authorities want.

      It seems like a completely innocent person is the best one to push back on authoritarian overreach.

      Am I misunderstanding something here?

    • It’s weird how few people understand that just being courteous/polite eases most encounters considerably.

      Absolutely astonishing seeing people try the “I’m going to be as annoying as humanly possible” to the guy with the gun with the “my YouTube lawyer says I can” defense. You don’t want to have to defend your civil rights in court.

      This goes doubly when at immigration where you basically don’t have rights.

      This guidance also applies to: bank tellers, call takers, baristas, waiters, other people standing in line with you, the bus driver, your mom, the neighbors upstairs, the raccoon across the street, …

    • > I genuinely don't think there is a "get out of jail free card" ...

      Being rich and politically connected would probably do it.

    • It's best to do that for things they have the right to do. Trying to resist being questioned or having your stuff searched is a fool's errand. They'll make it happen one way or another.

      But I'd never unlock my phone for US immigration. That's my whole life on there, and they don't have the right to compel me to unlock it. Even there, be polite. You can say "no" politely.

      Where this guy went wrong was actively wiping his phone. That's no good. What you do is put your phone in its most secure state (generally powering it off) before you reach the immigration desk, and then if they seize it, you have to trust its security to keep them from getting into it.

  • We probably need honey pod fake OS systems that boots up if not properly handled displaying some stars & stripes as background image and having the US national anthem playing for any sound the OS is trying to play.

    • A phone with a backup account, unlocked with duress pin makes sense to me.

      How hard would it be to admin-allow some apps to work across barriers. E.g., wallet apps work, airline tickets work, but email/socials do not.

      the issue is that when a phone is unlocked, they can just plug in a USB device and scrape everything off it. The TSA agent may not be eyeballing a facebook account so much as plugging in an exfiltration software stack or malware.

      9 replies →

    • This would unironically probably work pretty well. The bullies in airports don't have that much time to investigate a phone which "looks good".

      1 reply →

    • I would prefer to backup and wipe my phone before travelling.

      Then have some planned means of restoring the backup when it's safe to do so.

      Being caught with a honeypot looks much worse than being caught with a new phone. You can always say you bought a cheap "travel" phone if asked.

      1 reply →

    • Don't forget to have the Official Social Media of the President of the United States(tm) installed, with an account following the correct list of truthtellers and rightthinkers.

  • Tell me if I'm wrong but it seems that if you cross borders a lot the solution is straightforward. Have a second set of disposable devices for out of country usage with nothing but a VPN to virtual desktop. Give them the password and your mailing address to return when they are done?

    Can they force you to log into another remote computer in another country to examine it?

  • Yeah, you really can’t outsmart those with physical power and authority over you. Americans have asked for, or tacitly accepted this treatment of their visitors. The only big-picture solution is to stop visiting.

  • can you share the link? This?

    https://www.eff.org/document/eff-border-search-pocket-guide

    ----

    Seems the better strategy (for iOS) is come in with a plan to say yes to agents without pissing them off (like handing them an empty phone).

    better to local back up, encrypt, upload to your home server etc.

    Then login to a fresh iCloud account, selectively install apps, photos, and mail accounts. So it doesn't look like you're walking in suspicious.

    • This seems like an insane thing to have to do for visiting a supposed first world country. If phones had been around during USSR times I imagine you would have had to do the same. Personally I will rather just avoid any travel to the US, and I hope others do the same.

      64 replies →

    • Xiaomi phones have/had a feature where depending on which finger you unlock the phone with, it can hide certain applications/folders on the filesystem.

    • I guess you could just bring a flip phone. But then that could be seen as suspicious these days.

      When a government is paranoid, everything is suspicious.

      Maybe just don't do anything on your phone but normal capitalist business sht.

  • I worry that at some point, the physical device won't matter. Border authorities will know your email address, and could force you to log into your account on a device they supply. Five years ago, I would have called anyone even bringing up this possibility paranoid, but a lot of things that were completely unimaginable outside of Hollywood political thrillers have already happened.

    • And then there's the problem that you can't just log in with name and password to your email address. You need your special "authy" style number generator, or a software version on the phone. They know you probably have it on the phone. but what if you bring your other phone that doesn't have it on there - you removed the software before you left so no one could even log in.

      All these fancy tricks don't work because the doofus/poor soul at the border doesn't understand the nuances and they don't know if you are lying or not. Even if you wipe your phone and restore it once in the safe usa, that's no doubt suspicion of a crime.

  • > I think they should not have this power, but the agents and courts probably don't care that I think that. ...

    > and about not angering the agents more than you plan to

    When I was a teenager (long ago at this point), I got into an argument with a police officer over surfing in a certain area. It was pouring down rain, so he was annoyed he had to sit outside and wait for my friends and me to come to shore. Once we got in, he was telling me that he could take my surfboard and my car, and all other craziness. Being the dumb smart-ass I was at the time, I laughed and told him he was full of shit, among other things. He went to take a swing at me but his partner grabbed him.

    We all go to court and the judge immediately dismisses the case against all my friends. I had a lawyer with me that I knew and he went to talk to the cop and when he came back over he goes "I don't know what you did, but that cop hates you." I get up in front the judge and he praises me for understanding the law (and I could still see the cop was visibly pissed), but then says he can't have me disrespecting and being a smart-ass to his cops and gave me community service that once completed whatever the ticket was would go away.

    • > but then says he can't have me disrespecting and being a smart-ass to his cops

      Maybe it's just me, but I am of the exact opposite opinion. Cops have enormous power, and any misuse of it should be pushed back on hard. Cops that misuse their power should not be respected. An informed citizenry is a wonderful asset in making that power imbalance less of a problem.

      24 replies →

    • And what did this judge think (not much, apparently)? Punishing you will make you respect the cops?! This idiot confuses the fear of punishment with respect. Also, does not understand that respect is not to be forced but to be earned. Forcing it will erode respect and generate lots of pretension and covert hate. This judge basically endangers all cops (and the community) for giving revenge to this one prick lacking self control! It's mind-blowing that someone less mature than a teenager can become a judge!

    • Too bad you could not bring that judge up on charges of judicial misconduct - if he indeed told you that the charge against you had no merit, but decided to punish you anyway because he did not approve of your demeanor.

      ... or otherwise, that people in your community could not apply any counter-pressure to such judicial behavior, in the media and public fora.

      2 replies →

  • There’s more to it than just not antagonizing the guards. I mean if you make them mad by doing something that is legal that’s probably not ideal for you practically speaking, but it’s not the end of the world. Destroying evidence while they are investigating you is not just going to make them mad though. It is illegal (18 USC section 1519).

    Where I think people are a little confused here is not realizing that this would be equally illegal in many other countries. At least in the UK and France, border investigators also have the power to demand your PIN. And it is also illegal to wipe your phone during an investigation in those countries.

  • I don't own a cell phone, haven't for years. I fear this alone would be enough to arouse suspicion and I'll be denied access. Not an immediate problem for my family: as a Canadian I have no plans to visit the states for a long time. However, I could see this being suspicious in other countries as well..

  • What about simply not using a smartphone and accessing your data via internet when you're in the country? You could use Mega (secure file storage) to access your files, for example.

    I wonder if border agents could coerce you into giving access to your internet file storage, though.

    • I believe they can. I believe they can even request your social media credentials, despite that being against the ToS for those sites. It's not against the law to refuse, but they can and will reject entry on that basis.

      4 replies →

  • I wonder if the smarter thing to do would be to quietly nuke it as soon as it becomes clear that you'll be detained, so they can't really know that it wasn't already blank (IE you aren't nuking it in their presence).

  • So I guess what you really want is a duress PIN that loads into a fake innocent profile.

    • Yes I thought this was the standard solution?

      People have been doing this since way back in the TrueCrypt days - IIRC you could configure it to run a whole fake version of Windows if you wanted without easily revealing your actual main volume.

      Most hardware crypto wallets also have a "duress wallet" feature where you keep a low balance for the same reason.

      Wiping is obviously extremely suspicious and asking for trouble

      15 replies →

    • Not enough, e.g. when crossing the Russian border (even as a citizen) your phone can be connected via USB to a device that uses exploits and whatnot to download all of the data. Surely US border guard can do something similar.

      And using encryption will only make you more suspicious, and may be a reason to get jail time until the situation is "cleared up" one way or another (e.g. by getting even more jail time).

      Only a second phone works, if you can make it seem like a device you're actually using (though also not a silver bullet as e.g. a lot of messenger metadata is available to governments and border control can physically coerce you to log in to your real accounts)

  • My friends from the German CCC are mostly like (1) do not travel to the US and (2) if you absolutely must, travel with an empty device with decoy data and download all data you need once you're there.

  • I don't carry a smartphone, is this likely to be a red flag if I'm stopped?

    • Many countries now assume you have a phone. For example getting UK visa requires a smartphone. I don't think going without a phone is feasible nowadays.

      Another question is if going with a burner phone that has just sim card and bank card, sufficient. But then you need appleid/google account on the device, and this again links back to your phone number, and it's not easy in practice to have proper clean device.

      7 replies →

  • > The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that.

    That's the reason I never traveled to the US and never will, just having IT security in your CV is enough to make the border gamble not worth it

    • Note that border searches of electronic devices are extremely rare overall. There were some statistics from CBP implying a base rate lower than 1 in 10,000 (I think lower than 1 in 100,000) border crossings.

      I do know two people who have experienced them as a result of the government taking a personal interest in them, so it's certainly not impossible. However, it's not a common experience.

      I've personally experienced searches of my suitcases about four times in about 100 U.S. border crossings (as a U.S. citizen, but the people performing or directing those searches generally didn't know my citizenship status), and zero electronic device searches.

      8 replies →

  • I'm sharing this experience just to share, not suggesting or making any claims about what people should do with it:

    One of the best ways to get through airport CBP quickly without being overly hassled is to be overtly, clearly sick in a gross way. If you're about to vomit or have horrible diarrhea, they do not want you in that line any longer than you have to be. If they're the type to want to take people down a peg, they won't bother with you because they're already miserable, and if they like picking on the weak, they're probably going to go for a solo young female traveler who isn't ill.

    Nobody wants to risk getting vomit on their clothes or in their work area, having to close a line and shuffle people around while their coworkers glare daggers, or subject themselves or their coworkers to the very fun smells of human bodily fluids.

    At the same time, it isn't purposeful so it's not read as malicious.

  • Maybe the actual solution is traveling with burner devices when you are concerned with border checks?

    Like, get a cheap phone, install the bare minimum stuff you need for travel.

    For extra safety, before returning home wipe it and just put back the exact apps you need for moving around (e.g.: ride hailing app).

    Same thing with laptops, tablets, etc.

  • This is one of the reasons I also won't ever go to the US again.

    While most of my Italian/Polish friends had 0 issues, on a handful of occasions people were stopped and questioned for hours with agents pretending full access to every single device and just overall treating you as criminals.

    In one occasion a friend of mine stated that he was quite sure they just enjoyed that kind of sweeping power and it had nothing to do with border security, it was just fun to them.

    In another one, the suspicion was on the fact that this person did not have socials, he just disliked them and had nothing except a Google account for Youtube. This fact made them super suspicious and the person was stuck at La Guardia for 3 hours, even his body was inspected. Disgusting.

  • Just don't travel to the US.

    • This is an increasingly popular solution. Foreign tourism has crashed.

      I love the geography of the US, and it has some truly stunning places to visit.

      But they're not so stunning that I need to risk my freedom - risk my freedom - to visit them in person.

    • This. If any country won't treat you like a guest, avoid travelling to it.

      If it's your own, that's harder to do – time to fight and change the system before it gets worse and will swallow you whole.

  • > ... you may have to think both about protecting your data by technical means, ...

    I thought about that. And I came to the conclusion that a phone is a pathetically bad device to both store your data and to access your data. Mediocre screen. Mediocre input methods. Moreover most phones happen to also be spying device.

    So if you think about "protecting your data", a reasonable idea is that a lot of data is way better kept on your homelab, with say encrypted backups in a safe at the bank, at a relative's place, on a server you rent, etc., rather than on your phone. And there's really little need to access your data from your phone.

    Oh and I'm no luddite: I've got a homelab, I rent servers, I pay three AI subscriptions, etc.

    But my phone is boring. There's no app on it besides the stock ones (say Google Maps) and then I added the Google Authenticator app (for stuff still using that kind of 2FA).

    If people were to wake up and stop being glued to that mediocre thing, the problem would already be 99% solved.

I’ve seen a lot of people on the internet over the years say things like “the government can’t make x illegal, it’s just y.” For example, the government can’t make wiping your phone at the border illegal, it’s just punching four numbers into your phone, just like a pin, only a different four numbers, which could just have well been your pin.

U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did. Hell there could have been a third set of four numbers that were the nuclear launch codes. It’s not the fact that it was four numbers, it’s what you were trying to make happen when you typed them. Now of course whether they can prove what your intent was when you typed them is another matter, but generally a duress pin should be for when robbers are breaking into your house, and the government will be on your side, and not when the government will be against you.

  • "U.S. law though is highly non-autistic" hilarious but also another point to emphasize is how truly depressing American courts often are. Take the right to a jury. It sounds noble in theory. But when they say judged by your peers they don't mean your actual peers.

    It's people who couldn't get out of jury duty. Prosecutors have high success rates. Federal prosecutor success rate is over > 90%. Studies of jury psychology show how much peer pressure and other factors extrinsic to the law come into play.

    Remember what happened to Aaron Swartz. Law is the mask of power. By all means defend and assert your rights, but understand the costs. I find people are under such illusions about how cruel the American justice system is that this leads them to make foolish decisions. Do not underestimate the adversarial nature of the justice system, nor the accompanying incentives agents of the state who are on the other side of you have to lie.

    • As a convicted felon for the last 25 years without a single incident since I was released. I tell everyone I know to never trust a single thing anyone says if there is any chance you are being looked at for criminal charges. It's "I want a lawyer" and nothing else. Just SHUT THE FUCK UP, don't call me, your parents, someone to bail you out. Call a mother fucking lawyer. Because once you get your sleeve caught up in the gears of the system and you dont rip free fast enough, it's over. Once the system turns on you, your entire life will never be same. It will effect more aspects of your life than you can imagine. The system will chew you up. It never forgets. It's incapable of forgiveness.

      2 replies →

    • > Federal prosecutor success rate is over > 90%.

      This is a misunderstood statistic.

      Federal prosecutors won't even pursue cases unless they think there's a high chance of success. They don't operate like two private parties suing each other to force the court to decide something. If the evidence is there or the charges aren't fully formed, they don't waste resources on it.

      This leads to a contradictory set of complaints that the legal system lets too many people go or doesn't have enough teeth.

      16 replies →

    • Exactly. People complain police dont prevent crime, but dont realize that is not their purpose. The police exist to protect the government, not the people.

      7 replies →

    • It is not surprising. They just don’t go to court unless they think they have enough evidence for a conviction. In a perfect world the conviction rate would be 100% because in a perfect world the prosecutor would drop the case before if they don’t have enough evidence.

    • > Remember what happened to Aaron Swartz.

      Indeed. There are certainly parallels between him and Sam Tunick. But I'm not sure the public is ready for all the parallels.

    • >Remember what happened to Aaron Swartz

      He killed himself before the trial even began. I think he would have won the case if he actually went through it.

      1 reply →

    • If it’s a malicious prosecution by the country/state then Jury is your best best over a Judge.

      There is a reason that Elon Musks companies and others put a ‘you agree to not have a jury trial…’ clause in their terms as Judges are easier to influence - when a legal case is filed it’s allocated to a judge and certain cases will go strategically to a Judges with certain bias

    • > Take the right to a jury. It sounds noble in theory. But when they say judged by your peers they don't mean your actual peers. It's people who couldn't get out of jury duty.

      What? A jury system is far from perfect but this is about as intellectually rigorous as “the lottery is a tax on the poor”. Many people are thrilled to do jury duty because they are invested in their community, your nihilism is not a universal truth, jury duty isn’t a burden, it is a civic duty, an honor.

    • > It's people who couldn't get out of jury duty.

      But that's good no? People who got out never would have taken it seriously.

      I sat on a jury trial and was highly impressed with how seriously my fellow jurors took it - especially the presumption of innocence. When they started to go down some incorrect logical path, someone would step up and correct it.

      Not to mention the public defender ripped apart the DA's case. It was the exact opposite of what I was expecting.

      > Prosecutors have high success rates.

      You're forgetting that the prosecutors don't bring cases they think they're going to lose to trial, they either drop the charges or try a plea deal. So you'd entirely expect the success rate to be high.

    • There is no law. There is only power, and the will to use it. Remember and internalize this at all times.

    • > It's people who couldn't get out of jury duty.

      It’s not even just who couldn’t get out of it. It’s filtered for people who answer honestly. I was disqualified for a grand jury because the judge asked me if I would believe the testimony of police officers as truthful and I said it would depend on the police officer.

      The system already had their hands forced on accepting that some cops lie with Brady disclosures but the fact that I didn’t just naively accept police testimony meant I was an unscramble juror.

      Even if you’re a true believer in the system you won’t be allowed to participate because you didn’t lie.

    • Yeah, but without a jury O.J. Simpson never would've walked out of court a free man.

      For example in Europe when someone dies somebody always has to go to jail, even if they were defending themselves or responding to a potential threat. A jury could show compassion or empathy. Judges are extremely stoic in that regard.

      6 replies →

  • This was really well written in "What color are your bits": https://ansuz.sooke.bc.ca/entry/23

    Programmers have trouble seeing color (two identical numbers are the same bits, how can typing '1234' to unlock one phone be legal, and '1234' to unlock another phone be illegal?)

    Courts care about color (intent, provenance, permission), even though that color cannot be digitally represented.

    • An interesting parallel to this is parallel construction, where a side knows X but they know it through illegal/illegitimate means, so how do they create a trail of evidence for X through ordinary and legal means. This applies to legal cases and things like reverse engineering etc.

      Like we know X but the colour of the fact is red, and we need some way to figure X out with a colour of green or blue.

    • Indeed, but should he say his real code was one digit swap off, could you prove intent? Color matters, but you can't paint with only one

      3 replies →

    • "Color" absolutely can be represented digitally; C compilers were doing it before we even knew they were doing it. We just like getting away with shit. It's part of the hacker ethos. Probably.

      2 replies →

  • A lot of engineer types forget that the law is not code, and reductionist arguments almost never actually work in practice because it's a human interpreting the law.

    • For one example of this, around 10 years ago there was a company called Aereo that tried to act as a "cloud television provider". The idea was that they had thousands of tiny antennas hooked up to servers in a warehouse, and they would lease an antenna to each subscriber. This gave an experience similar to cable TV but without Aereo having to pay broadcasters cable transmission fees. The major broadcasters sued Aereo and ended up getting it shut down for exactly the reason you mention. Despite Aereo technically being a TV antenna leasing service, it functionally acted like a cable TV service so they were violating copyright by not paying transmission fees.

      3 replies →

    • > A lot of engineer types forget that the law is not code, and reductionist arguments almost never actually work in practice because it's a human interpreting the law.

      It's worse than that: a lot of engineer types reason about almost everything as if it were code. It's a manifestation of Engineer's disease.

      1 reply →

    • It reminds me of tax law in many countries. You can follow the letter of the law, but if the vibes are off, you can still be found to be in breach of a vague catch-all provision (e.g. economic substance doctorine in the US, GAAR in Canada/UK, Part IVA in Australia, etc).

      2 replies →

    • There is a strong bias by the courts to interpret the law in such a way that it makes sense, and achieves the goals the legislature had when enacting it.

      1 reply →

    • Maybe this is because of the TV dramas where a genius lawyer saves their client through an obscure technicality. It looks exactly like hacking a system using a 0-day exploit.

    • It's not that there's a human interpreting the law. It's that there is a politically motivated human interpreting the law, or in other words, you are sol if the state wants to get you. The engineer's arguments aren't reductionist, they are idealistic.

    • Does anyone think law is computer code? I mean any courtroom drama (even if far fetched) shows it is not.

  • In this case, the government was against him due to his activism against a police training campus.

    Him deleting his phone was very likely a matter of safety for his fellow activists. Sad that our government does this but it’s not like this guy was a drug dealing or something.

  • > U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did.

    Love this way of putting it. Stealing for future conversations with fellow software developers.

  • A duress pin is useful if the cost of the government getting mad at you because you wiped your data is less than the cost of letting the government have your data. Whether that holds depends on your situation—for example, whether your phone's data could implicate other people that you want to protect

    • When talking about costs we should remember who is paying. Maybe overall the cost of the government getting that data is higher than the cost of them getting mad at you, but when a single individual is paying for all of it the equation might change.

      1 reply →

    • I think it's a matter of personal privacy. You shouldn't show it to other people.

  • When I had jury duty it was quite revealing as far as “this is all evidence including people’s testimony, you can believe all or some or none of a given piece of evidence based on your own judgment” goes.

    When we met it was interesting how our jurors decided “I don’t believe anything that guy says” and so on when it came to their motives and so on.

    The trial itself was very carefully choreographed, almost pre determined and static.

    But the decisions and jury activity was very dynamic. There was absolutely no magic legal mechanisms at that point.

  • I'm waiting to see whether he is convicted before I form a strong opinion around this. I'm leaning toward thinking this case will be dropped or at least severely reduced charges.

    • It doesn't matter.

      Mamy will read this and think that crossing a border with a GrapheneOS device is a bad idea, or just drop using what is a nice security feature entirely.

      Just being charged is already a massive pain in the ass (both in terms of stress and costs) to an individual.

      1 reply →

  • If only they could be as non-autistic about the law consistently.

    From the article, it looks like warrantless search & seizure and lawyerless detainment over the suspicion of participating in plain old 1st amendment activities.

  • He didn't type the numbers. The destruction was performed by the border guards recklessly typing in commands to a phone without knowing what it would do.

  • Would it have been wiser if that person had, as a US citizen, just refused to provide a PIN? At the most they'd just confiscate the phone, and it'd be encrypted anyway. No actual destruction of anything.

    On another note, maybe GrapheneOS should add some kind of feature where the phone involuntarily destructs if a correct PIN isn't entered for 48 hours (or whatever the user sets at installation time, and changing the value should not be permitted). That way the trigger for the wipe is the confiscation, not the act of entry of a duress PIN. You could disclose the mechanism to the officials who intend to confiscate, and also say (truthfully) that you have no control over the feature.

    • Would it have been wiser if that person had, as a US citizen, just refused to provide a PIN?

      Purely technically it would also depend on the state of the phone. Phones can be read out/exploited more easily after first unlock (AFU) than before first unlock (BFU). So, a middle path would be putting the phone in BFU. Much harder to use exploits against the phone and biometric authentication doesn't work. One way of fairly reliably doing this is setting the reboot timer to 10 minutes or turning off the phone in critical situations.

      It's also relevant to take into account that he wasn't protecting himself by wiping the phone, but fellow activists. So, he may have taken the risk of potential legal issues by wiping the phone to project others.

  • Heck, it could be unconstitutional for the government to make X illegal, but if the courts say 'no actually it isn't', or it never actually gets to that point, then it doesn't really matter much, does it? The text of the law could be simple and straightforward, and a layman's reading of that text could be valid, but all the government or courts needs to do is to find some moon logic to make what they need happen, and unless enough people disagree, then that's all there is to it. The law, in many ways, for better or worse, is just a piece of paper.

  • I think people are aware that the government can physically do a lot of stuff, e.g. shoot you in the face for no reason. And vice-versa for that matter.

    However there are arguments morally, and constitutionally, and logically, about what can be done.

    • And all of those arguments are entirely academic, and subject to change depending on economic status, skin color, or nationality.

      Law is effectively a weak gentleman’s agreement we tolerate because the alternative is violence.

      (Well, law is enforced with violence too, I suppose.)

      10 replies →

  • He should have backed up the phone before travelling then wiped the phone to an innocuous state before getting on the plane.

    Want to see a really confused border agent? Travel without a phone. Fedex your phone to your hotel/home. Read a book on the plane. The concept that someone doesn't have a phone/computer drives cops insane.

    One of the wikileaks crew pulled this one in NY. Several agencies were a set to grab his devices and detain him until he unlocked them ... But all he had in his carry-on was a magazine. His devices had been wiped and sent by mail. He re-imaged them only once he was home and safe. No devices to unlock, no reason to detain him.

  • Maybe I should get a thicker skin, but the prevalence of “autistic” as shorthand for “moronically literal-minded” on a place as prudish as hn is a bit surprising.

  • >U.S. law though is highly non-autistic

    LOL, that made me chuckle.

    People somehow think they're the first one to think of a workaround to a law, when in fact it's been happening since the first law was written down. The law adjusted and if people think they can do one thing, then claim they intended another they have a big surprise coming.

  • I think you're conflating two very different things. You're completely right that the government can make pretty much whatever they want illegal, but things are legal unless expressly made illegal. Erasing your phone wouldn't be illegal because it implies guilt, but because of obstruction/destruction laws explicitly criminalize such things.

    The whole case is going to come down to the nuanced and often contradictory interpretations of border law exceptions. I also don't agree that these sort of protections are for e.g. robbers, because of the criminal underground's $5 in-person data hacking tool. [1]

    [1] - https://xkcd.com/538/

  • Yes this is the whole $5-dollar-wrench XKCD thing.

    "Ahah! I've won! The data has gone!! MUWAHAHAH! Take THAT border guards".... congrats you're still going to the same prison though.

    If you've got something to hide (legitimately or not), don't take it across the border in the US or anywhere. Even then I am sure they'll either compel you to hand over your cloud passwords or again you end up going to the same prison for some other reason.

  • > U.S. law though is highly non-autistic

    When the judge and officers of the court agree with me, the law is reasonable and just, but when they do not agree with me, the law is arbitrary and capricious. ¯\_(ツ)_/¯

    Having the law be whatever it's thought to be by police, prosectors, judges, and others can lead to obvious injustices, but there's been no serious attempt to remove ambiguity in any country's legal code as far as I know.

  • In general a government can do whatever they can get away with.

    The rest (believing they can't do this or that, because it's in some constitutional document, or violates a basic right) is sovereign citizen kind of self-delusion.

    • If a government operates outside its remit, competing forces (opposition parties, civil society, counter-elites, foreign influences) use that as an opportunity to gain power by calling attention to the violation. “The law” may be a fuzzy illusion, but it’s delineating a real social boundary. Legal processes are a way of processing that conflict symbolically rather than jumping straight to open warfare. But you better believe that open warfare will result if those boundaries are ignored for long enough or if they are violated egregiously.

  • > U.S. law though is highly non-autistic

    This is the thing that people should be reminded over and over here - and to be fair it tends to be more autistic than elsewhere

    (Regardless if you are on the defendant or the prosecution side - or might potentially be)

Ultimately, when you choose to enter a duress PIN that will wipe your device, you have to recognize that choice may have legal consequences. I don't like the amount of power our government has at the national border when it comes to detaining and pressuring citizens, but our Constitution explicitly grants it at least some of the power it now exercises in that context.

If your threat model includes US state actors at the national border, then your security practices need to account for the confiscation of your device at that border without requiring you to willfully wipe the phone and (in the eyes of police and prosecutors) destroy evidence.

That means:

1. Don't travel with anything you can't afford to lose on device. This means setting up travel-specific password managers and hardware keys for a subset of your accounts that you absolutely need to access while abroad, and being prepared to reset those passwords and disable those hardware keys very quickly once home.

2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. Your secure setup must function without needing you to engage in those behaviors, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable.

3. Consult with a lawyer and review your security procedures from a legal standpoint. All of the above is technical and practical advice, not legal counsel and no substitute for it.

We Americans are fortunate to carry powerful passports and enjoy relatively easy international travel but, for better or worse, that velvet glove covers an iron fist we would be foolish to forget or ignore.

  • > 1. Don't travel with anything you can't afford to lose on device. This means setting up travel-specific password managers and hardware keys for a subset of your accounts that you absolutely need to access while abroad, and being prepared to reset those passwords and disable those hardware keys very quickly once home.

    > 2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. Your secure setup must function without needing you to engage in those behaviors, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable.

    > 3. Consult with a lawyer and review your security procedures from a legal standpoint. All of the above is technical and practical advice, not legal counsel and no substitute for it.

    Just don't go to the usa and if it's for professional reason, don't bring your personal phone.

    • You've left out the important qualifier I put at the outset of those three points:

      > If your threat model includes US state actors

      It was not advice for everyone, nor even most people. I have plenty of friends abroad, and a few of them have even traveled to my country for the World Cup and had a grand time.

      I roll my eyes at this kind of overreaction, the same way I imagine Europeans rolling their eyes to hear Americans worried about migrant crime news stories not wanting to travel to Europe. Or maybe they used to roll their eyes at that... I'm less sure now.

  • Have the duress PIN on sticker on your phone. Maybe put it backwards and don’t say anything to border patrol. Have them try it out and erase the phone and then you can legitimately say you didn’t do anything and they did it themselves.

    • But if the prosecutors can make a convincing argument that your intent was exactly that all along, then you may end up convicted anyway.

      Intent matters. It might be hard to prove, but it matters.

      It may not even be that hard; what other possible explanation is there for someone putting a PIN visible on their phone that wipes it while crossing a border?

      15 replies →

    • Or just make it your birthday. Though I'm not at all sure the agents will try typing random codes in without at least some idea that they may work, given that many OS's will quickly start to punish with tarpitting.

    • I wouldn't write it down, I would just make it 1234. They're bound to try that. Then they have absolutely no case against you.

    • Why would agents think that a number written on your phone is the PIN? That would only make sense if it was a communally-used device, not a personal one. Also, no one would put sensitive info on a devices that has the PIN affixed to it.

      I suppose it's possible someone might enter it without thinking, but the odds seem low. Also seems risky to put a self-destruct PIN on your device, lest a friend (or enemy) enter it by accident or as a prank.

      3 replies →

  • the funny part is he didn't enter the pin he gave it to them and they entered it..., not sure if it makes any difference but there is a certain irony to it that it was the non warrant based search actions (which might be legal at the border) which lead to the erasure of data

    • Edit for the confused and misinformed: 18 USC 1001. Also, is ≠ ought.

      Lying to a federal officer is a crime, IIRC, and if the lie results in destruction of evidence, the person who told the lie is probably accountable for both crimes. This isn't a lie with plausible deniability: you have to set a duress PIN, understanding what it does, and then communicate that PIN instead of the unlock PIN.

      A duress PIN to wipe the device don't exist to absolve the owner of liability... It exists for when compromising the device could get people the owner cares about killed or disappeared and the owner considers their own liability, disappearance, or death a preferable outcome.

      It is an extreme solution for extreme scenarios. People need to be sober in weighing its use.

      34 replies →

    • I’ve been arguing against some LLMs about this point for a good hour and there’s a whole lot of linking intent to action where you can be liable if a court can prove it. Not that an LLM is legal gold but it’s the best thing I have to pass ideas around with.

      The entire situation is sort of nonsensical and boils down to lots of minutia in law that no normal person would know about.

      For example having normal widely known security features like wiping the device after N failed PIN attempts is fine. Even having long standing security practices that can’t be related are fine, like having a timed touch point where if you don’t enter the PIN every… 15 days or whatever the device wipes, perfectly fine if it can’t be connected towards the crime and you’re not compelled to tell officers you have such a security mechanism.

      Even if you were to set a trap where you use the same PIN for your bank, your laptop, and some other security devices in repetition then decide to set your duress PIN to that by assuming it would be discovered as a probable option they’d use, you’d be ok but it could be questionable if that was by design…

      It’s so obscure really as to how and how you’re not allowed to protect your data, even if you’re not the one performing the action to clear destroy the potential evidence yourself. The entire thing seems pretty absurd a frankly arbitrary to me, and I don’t know how people could know which cases are and aren’t legal. I know not to destroy evidence myself but I wouldn’t know to tell someone to not use the duress pin or that even giving them my duress pin could somehow be my liability. It’s madness if you ask me.

      4 replies →

  • Not a lawyer, but destruction of evidence would only be valid if there was first some reasonable suspicion of a crime? Is that right?

    • This is my core question as well. At what point do you have to maintain property so the government can use it to testify against yourself?

      If I have a dash-cam, and I wipe the SD card, can the government imply that because I erased the card, it must prove that I was speeding? The dash-cam automatically over-writes old footage - perpetually destroying evidence.

      Given nebulous cases such as "hacking" a site by looking at the HTML[0], am I destroying evidence of crimes whenever I format my PC? I hope the government requires specific charges and more proof of a crime other than missing evidence. Say I destroy my diary - can the government claim that is the key evidence where I confessed to being the gunman on the grassy knoll?

      [0] https://news.ycombinator.com/item?id=28992667

      3 replies →

  • Well I prefer simply to stay out of countries that haven't got their ducks in a row when it comes to freedom. Saves a lot of hassle.

  • this means: put a good government in charge of the border that respects your rights

  • >destroy evidence

    Who said it was evidence? Did a judge authorize or issue a warrant to collect said evidence? Absent that, it's just your property, and you can do with it as you please.

    • To me it’s all quite analogous to walking up to, but not crossing, a border with, say, a fruit that’s legal to possess on the side you’re on, but not on the other side, and either eating or throwing away that fruit before crossing.

      “Hey! I saw you holding that Mexican pepper in Mexico, and then you threw it in that Mexican trash can before crossing into Texas!”

      “Yeah, so?”

      5 replies →

    • "Evidence" has never been limited to the subject of a warrant. Destruction of evidence statutes typically include material that is subject to a police investigation.

      4 replies →

    • > Who said it was evidence? Did a judge authorize or issue a warrant to collect said evidence? Absent that, it's just your property, and you can do with it as you please.

      Why do people go sovereign citizen when reality doesn't work their way? Stop imagining that the way you want things to be is the way things really are.

      Cops do not need a judge to authorize the seizing of evidence. Cops do not need judges to decide what evidence is. Tell me, why did you just pretend like these are real requirements? I can understand why you'd want it to be that, but you wanting it to be that doesn't change reality.

      It's as if you've just learned about the Fourth Amendment but know nothing about the nuance behind it.

      Your system wouldn't even work at all. Let's imagine the cops get a tip that a bald man with a blue tshirt shot a man. They patrol the streets and find a match. By your logic they should not have the ability to search the man and seize his gun as evidence until a judge issues a warrant.

      7 replies →

    • Yes this is different than when law enforcement serve a warrant and the defendant wipes his computer before the agents can get a hold of it. In that case the warrant covers what you destroyed as evidence.

      Though during traffic stops, if a defendant disposes of his drugs while on the run, that can also carry a charge of destroying evidence even though no warrant was issued.

      IANAL

      15 replies →

  • It is so sad and worrying when the already oppressed population argue for paranoid practices constraining their own practices considerably and with great efforts, eroding the other thing that constitution was so famous about, freedom, so some officers supposed to serve the population can do things easily to anyone. If they please and want it easy for themselves.

Reading the comments here makes me think that even US citizens might be better off not trying to enter the US.

VeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give proper password, real OS and FS decrypt and load.

Something like this may need to become the standars over duress pins which should be treated as a fallback or more extreme alternative. Right now, A single choice to reasonably and rightfully protect your privacy reuslts in jail time over something which likely wouldnt have resulted in any issues if superficial compliance was observed.

These goons, even if a branch of a facist regime, are ultimately burocrats with violent options to settle. They aren't doing forensics on your device etc. They have neither means nor knowledge to do so. They just need to tick their boxes. Did the phone unlock? tick. Did our spyware complain? no? tick. Overall appearance of compliance from person? yes? tick. free to go, next!

You just have to find ways to stay safe without agitating their workflow and all is well.

- [1] https://veracrypt.io/en/VeraCrypt%20Hidden%20Operating%20Sys...

  • I worry about approaches like this because maybe the forensics tool fills all available space and then clears it, noticing that this particular phone is an anomaly re:

        manufacturer published space = allegedly available space + size of known files
    

    If you're hiding something in "empty space" it won't behave like empty space when you try to fill it.

    I think we need to be stenographically smarter. Like if there's some mechanism of deduplicating blocks across volumes, then perhaps when given the special key you could temporarily render a volume whose parts are hidden in the data already occupied by the other volume and then just run it in memory so that a reboot clears it.

  • this will likely fail as block devices aren't dumb anymore, the firmware state will out the hidden volume. counting on the laziness/unsophistication of an adversary isn't a great move.

    this problem may be solvable by a purpose-built abstraction where every write no matter what address will look identical to the firmware (naively, a randomized key-value map).

    • I largly agree, hence why the prudent move is not visiting shitholes like the (current) USA with anything important on your person.

      However, if you must do it, there are better options than duress pins that wipe a device.

    • Not that shufflecake solves the issue you highlighted, but I found the shufflecake FAQ to be a good intro to the topic for anyone curious. It does a good job explaining the threat vectors and the relevant trade offs, in particular the TRIM and ORAM sections. It’s also just a cool project: https://shufflecake.net/

    • I agree that trying to outcompete seems really hard, but also:

      Given what the experience of using a non-rooted phone is like, how very very tight the sandboxing is and how useless it is a General Purpose Computer that will tell you anything: I find it very hard to believe the unlocked phone is going to let you start probing firmware & snooping on hidden volumes.

      This post sent my BS detector on high alert. I'm struggling to take it seriously.

      1 reply →

  • Even in places where you can’t be compelled to hand over a password, attempting to deceive the cops will get you thrown in prison just as reliably as destroying evidence.

    • The best thing to do in such a case is issue the following statement -

      "I am in full physical compliance and will not interfere with investigation in any way, but I plead the 5th on answering any questions, and plead the 4th on any personal property", and just sit there silently. Let them break into the phone if they want.

    • true, but in that scenario you're going to prison either way. If you legitimately use the dummy for daily driving and hidden for sensitive work, then it's better than nothing.

      Obviously a good alternative is a dummy device but it carries similar risks, and the best option is to simply not go to authoritarian shitholes like the USA. Thankfully I've been able to avoid/push for US folks visiting us instead, but honestly the alternatives are as bad.

      Its a shit situation where most reasonable actions carry real risks, its up to individuals to choose what is acceptable risk to them, but a dummy os you use as a daily driver for inconsequential work is, to me, an ideal midground.

    • No, you're being very dramatic. Lying to cops is very often your best strategy.

      I doubt this person will be found guilty. They will be able to prove he wiped his phone, but it will be hard to prove he destroyed evidence.

  • >VeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give proper password, real OS and FS decrypt and load.

    See: https://news.ycombinator.com/item?id=49057812

    Implementing it in a convincing way is harder than you think. Moreover if you're under the type of regime that will throw you in jail for not giving up a password, they're probably not going to let you off the hook because they can't definitively prove you have a hidden volume.

    • I could be wrong, but my understanding is that the dummy OS views the remaining space as legitimate and accessible free space. Using dummy directly is of course dangerous, as you might overwrite sectors with legitimate data, but also, you can access dummy os from secret. so you'd drive dummy from secret to prevent that but can load dummy as main if under duress and it looks fine. Browser, logged into various inconsequential things, random files for inoffensive memes and other human stuff in downloads folder etc. maybe an email account you've signed up to a few newsletters and e-stores that send spam logging in via an email client that auto-launches etc.

      Done well, I see no reason it should raise redflags in routine stops, so unless you're being targeted (at which point you've got way bigger problems) it should just seem like you're a run of the mill person who does not use their device to its full capacity, which is the majority of users.

      at some point, having any mitigations even present is a problem. At some point being met with a boot password at all is a problem that puts you on a list. I have no solution there other than to not go to those countries or keep dummy hot.

      4 replies →

  • This seems like the kind of thing that would put US citizens in way more legal jeopardy than just using a secure phone with a long password, refusing to unlock it, and buying a new one if the officers involved confiscate it out of spite.

  • This is always been the dumbest thing about "hidden volumes": It relies upon your adversary not knowing about veracrypt's hidden volume. Which BTW, is plainly ADVERTISED on the web site. The second he knows you have veracode, he will ask for the other encrypted volume.

    See also relevant XKCD:

    https://xkcd.com/538/

    • But Veracrypt can be used for encryption of a volume, without creating a hidden volume. I assume it would often be used this way.

      The $5 wrench decryption technique would be even more unpleasant if you hadn’t created a hidden volume, as there would be no way to prove you hadn’t.

      Should people be sure to never use Veracrypt volume encryption unless they create a hidden volume? I have trouble even thinking this way!

      1 reply →

Here is the indictment: https://www.documentcloud.org/documents/28513012-samuel-tuni...

Here is the statute Tunick is indicted under: https://www.law.cornell.edu/uscode/text/18/2232

There is an immediate problem: the device was being searched, and this statute criminalizes destruction of property to prevent seizure, not searches. I don't think this statute applies this situation. Regardless of whether the border agents could lawfully search his phone at the border, they didn't have grounds to seize it. I suspect this prosecution will quietly be dismissed within a few months.

  • OR the US administration could drag out the case hope it gets to the Supreme Court for another roll of the dice on weakening the Bill of Rights.

    As usual, government should have obtained a warrant if they wanted to search a US citizen.

  • CBP are empowered to seize devices if the owner refuses a search.

    • Hmm. It looks like the government asserts that they can seize a device if the owner does not provide a password. This is a good point and answers my search v. seizure objection above.

      You say CBP is "empowered" to seize a device if the owner refuses to provide a password but I can't find a statute that authorizes it or precedent squarely saying the 4th Amendment allows this. The scope of the border search exception isn't settled. So the next argument available is that the executive is wrong and CBP does not have the constitutional authority to seize a device merely because the owner refuses to provide a password. That's obviously a much bigger argument and who knows if it would work, though this case sorta feels like it could become a marquee 4A case.

      "The ACLU argues that the Fourth Amendment does apply in these situations, at least to electronic devices, because they contain so much private information. But the law is very unsettled, and the Supreme Court has not addressed the issue."

      https://www.aclumaine.org/know-your-rights/electronic-device...

If your threat model means you can’t afford for border security to view your device, wipe the damn thing yourself before crossing the border and restore it from an encrypted online backup on the other side.

You’re just carrying a blank phone that you intend to set up and use later, and they can’t force you to install your backup onto a phone.

Now, this is sus as hell, and you’ll probably draw all kinds of extra attention, but if border security wants access to your phone in the first place, you’re already in a weird place.

  • this isn't even that weird, when I worked in a BigTech it was pretty explicit that there were certain countries where you should not bring your actual work device through the border, and you'll get set up with a different one while in that country.

  • Those who thought that a duress pin was a good idea for border crossing are probably going to choose this alternative.

    It doesn't have to be blank - just clean.

    • Unless you are an activist who is being targeted by a government. A "clean" OS can still have incriminating "evidence" planted on it.

  • Pff one time when travelling to the US I brought two laptops, macbook and a thinkpad. I just reinstalled the thinkpad and somehow the border patrol was very interested in it. Asked me to ‘show my gallery’… it was a guiless setup and only had a terminal, problem was… somehow my keyboard layout or something was messed up and i could not even login… i spend around 2 hours being questioned by 6 people…they didnt even take a look at the macbook

  • The french cybersecurity agency (ANSSI) used to share leaflets to tell you to do just that. The US government wasn't named, but it's part of the ones that like to do some economic intelligence and no euro who read the news would trust it more than a banana republic when it comes to crossing the border.

    Now having a corporate device with little data is no longer outstanding. Everything is in the cloud these days.

    As for personal devices, you can explain you're taking a dumb cheap laptop for your holiday as you're working on a desktop PC at home. You're not taking your entire house when you're on a trip, just a laptop to check tourism information and post blog posts

    I myself bought a crap laptop on ebay to shove it in bags and backpacks and go to conferences and not be sad the day it's broken.

    but above all, he's a citizen so shouldn't care about looking "suspect". He has a right, not a privilege, to cross that border. They can explain a judge how he looked sus if they really want to search his home.

  • What is sus as hell is the US government. It is incredible how people here are accepting things that was outrageous a few years back.

    • They've been boiling that frog for 25 years now. Its flesh has long detached from the bones, it's the bones themselves that are now dissolving.

  • > You’re just carrying a blank phone that you intend to set up and use later, and they can’t force you to install your backup onto a phone.

    They can just make this illegal too, and ask for the keys to your backup, or detain you until you do. Point is, you can't gain freedom through technology. It was always a political thing.

    • You can hide a backup very well. Make a Proton account for drive over Tor and memorize the credentials.

      You can gain freedom though technology but if someone wants to torture you or a regime wants to put you in prison they can always do that.

      You could also gain freedom by being anonymous preventing getting caught, though technology.

> federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City

Of course it’s about that huh. It’s quite scary how far the US will go against anyone who engages in this sort of activism.

  • This is the most troubling part of the whole episode. Targeted by the government. Its been a long rough slope to get here but they are at the goal line.

  • An earlier story alluded to csam

    Wonder if it’s just a fishing expedition

Grapheneos comment on hidden profiles/veracrypt style plausible deniability:

>It's possible to make a semi-hidden feature but hiding it well enough to avoid detection by software forensic tools requires not basing it around profiles. It would really need to be a nested GrapheneOS in a virtual machine. It could also still be detected at an SSD level

https://nitter.net/GrapheneOS/status/2081471477174456340#m

Here's some info from veracrypt on the SSD level.

https://veracrypt.io/en/Wear-Leveling.html

https://veracrypt.io/en/Trim%20Operation.html

For non-graphene users (eg. Boring iPhone people like me).

So there’s a feature called Duress PIN which as explained through some comments means you put a different pin which intentionally wipes the phone. It’s not auto wipe or wipe after several failed attempts but intentional wipe of device. (Worth explanation as the current title nor the article doesn't easily explain this was made by the US citizen providing the alternative passcode)

For more technical details:

> GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).

https://grapheneos.org/features#duress

  • PIN to wipe seems suspicious. How about a PIN where it login to a patriotic profile and phone looks like normal android.

    • This is exactly my setup with GrapheneOS. The default / main profile is patriotic, with a sterilized Telegram account, state-adjacent banks and apps, etc. The second profile (that uses a separate PIN) is not so patriotic: it has foreign bank apps, crypto apps, password manager, 2FA app, personal records, and an alternate Telegram account that I use to discuss any potentially unpatriotic topics with potentially unpatriotic people.

      6 replies →

    • This is extremely hard to implement in a non-superficial way that would be hard to detect.

      Android switched from block device encryption to filesystem-based encryption (with encryption data and metadata). This provides many security improvements, such as per-file encryption keys and per-profile keys.

      However, this also means that the main file system is readable and you could enumerate the available users. If you would encrypt/obscure that information, you could still infer the presence of other profiles from file system block allocations.

      (Disclaimer: not an expert, but I read the relevant Android docs at some point.)

    • I had this on a Xiaomi, maybe 10 years ago? Very cool feature! I hope they still do it. I think the wipe feature is also very cool, but not used in this way.

      4 replies →

    • And wipes the main partition in the background at the same time

      Also too patriotic is sus. Better to keep some minor offenses (that give you a fine or a week of jail at most) on that partition so they will think that this is the thing that made you so nervous during the search

  • That's a nice feature, every OS should have that.

    I believe the old TrueCrypt had two passwords, each revealing a different set of files. You'd put e.g. your tax forms in one, so if forced to decrypt your drive, you could cooperate and do so.

    It's not illegal to delete your own vacation photos. So to prove this guy guilty of destruction of evidence, does the government need to prove there was actual evidence in the phone?

What I would like is a setting kind of like the already-existing safety feature on pixel phones. You set a timer and if you fail to end the timer or respond when it goes off, it calls 911.

Instead, I would set a timer before going through customs and if I don't unlock my phone and disable it within a set time, it initiates a wipe. I think that would be a safer way of doing this than a duress PIN.

> US citizen charged after GrapheneOS phone wipes during airport search

> It's concerning – and sends the message that [GrapheneOS] is criminal by default

What's with this sensationalism? The GrapheneOS phone didn't just wipe itself - the defendant actively took steps to wipe it. The defendant isn't being prosecuted "by default" for having a GrapheneOS phone. He is being prosecuted for what he actively chose to do with that phone.

If your argument is that the search and seizure was unconstitutional, and you're within your rights to wipe your data, then argue that. I'm very sympathetic to such arguments. But stop with this "they prosecuted me for having a GrapheneOS phone" misdirect

  • Doesn't matter, increasingly law enforcement is treating nicher secure OSs as a sign of illegal activity.

If this happened in an EU country you'd all be wetting yourselves, but for some reason the rooms different today. The professional advice we are given traveling to the US is back up you phone, wipe it, travel and restore once you are comfortable. Sad state of affairs guys

  • In the US, he could have refused to give the pin and that's protected under the 5th Amendment. They would have nothing because they couldn't get into the encrypted phone.

    In many countries other then the US like Ireland, they have key disclosure laws which require you to testify against yourself.

    In the UK, police can even require key disclosure without a judge.

How are they going to prove there was evidence of a crime? While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device".

Most previous court cases involving encrypted devices have required substantial proof that the encrypted device contained incriminating evidence. To be clear "you sent this illegal thing from your house" levels of evidence.

It mostly seems inept, if you are going to push to expand your powers you do it on strong cases where you know what happened. Doing it on weak cases like this gives a judge an opportunity to shut down that without giving you a chance of a meaningful conviction and without that you won't get any benefits...

  • >How are they going to prove there was evidence of a crime?

    They don't have to, only that you destroyed evidence. That's why many people get prosecuted with "obstruction of justice" rather than the actual crime.

    >While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device".

    So if someone was doing insider trading, and the SEC came knocking, then immediately afterwards they start burning every document they have and microwaving their computers, do you think they should get off the hook? Surely you must think, even if the authorities or society can't a priori know you were guilty, the subsequent activity should be illegal? Note this isn't the same as banning burning documents or microwaving computers, only doing so after you're aware there's an ongoing investigation.

    • They need to prove you destroyed evidence, you have the mens rea component with the deceptive pin code but the defense can simply plainly say they didn't want the police to read their private device.

      Your example is fabricated since the justice department didn't even bring forward a specific crime they believe was committed here.

      If they charged him with a crime and had evidence his device had evidence of that crime (even if in reality it didn't) that would be a more interesting question.

      But again where is the crime?

      12 replies →

    • You have to prove it is an evidence of a crime to start with, speculation is not a fact. My property, my business, i can smash the phone and no one has anything to do or say unless there’s an undeniable fact that there’s an evidence there and it got destroyed, else, it’s no one’s business.

      1 reply →

    • > So if someone was doing insider trading, and the SEC came knocking, then immediately afterwards they start burning every document they have and microwaving their computers, do you think they should get off the hook?

      Apples and oranges. They presumably already have some sort of evidence in order to get a warrant and are under criminal investigation.

      According to the article the agents said it was just a normal part of screening.

      3 replies →

    • Well, good luck to them. If I'm on the jury and he argues "I got my passcodes confused" that's reasonable doubt for me.

  • I'm not a lawyer, but my work domain revolves around data analysis of certain types of crime. Often times the suspects are flagged and under surveillance, so if and when they cross borders or go through check-points where you have a great deal of authority, they'll get searched.

    In many countries certain agencies / agents can do searches which normal law enforcement officers can't. Like not needing a search warrant or even probable cause. Not to mention that wiping a device could in itself be a crime, if it is suspected that evidence is being destroyed.

    The key point here is that, as I wrote, some agencies have a lot of authority, and have the power to do pretty drastic stuff.

  • The career prosecutors at the DoJ are not the same as a couple years ago. I hope this case ends the same way as the sub sandwich assault.

    • If your legal system depends on the benevolence of prosecutors, you've already lost before it began.

      Attorneys are supposed to be adversarial. The system's soundness shouldn't depend on anything more than them trying to win and not doing anything illegal.

      Before "prosecutor" became an elected/appointed office, prosecutors were independent contractors, hired for a single case only and serving at the pleasure of the Grand Jury. The Grand Jury's job was to decide how to spend the public prosecution budget. "Indictment" meant exactly that "prosecuting this person is a good use of tax dollars" and nothing more. We should go back to that.

      4 replies →

One of the GrapheneOS people (I think) suggested keeping a bit of paper in your wallet with the duress pin, perhaps thinly disguised. Then the cops could try it on their own initiative. I suppose they'd become aware of that trick eventually, but then they wouldn't be able to use all those other genuine pins they find.

  • A far better approach is for the US citizen to simply say "I chose not to provide my PIN".

    The officer will say something like "That's your choice, but I will need to seize the device to conduct an analysis. It will be returned once the analysis is complete".

    Then you shrug, and they will let you enter the US. The cops will try to get into the phone, fail, and return it to you.

    Just bring a phone you don't mind losing for a few months.

    • This person was under "investigation" for protesting against cop city. The authorities were waiting for him to turn up at a place where the law would give them more power.

      They were never going to let him just walk in. Eventually, they'd have to, possibly after lawyers and news would get involved, but it's not like saying "no" was going to end the ordeal right away.

      5 replies →

I think if I were headed out of country i would make a full backup of my phone, then wipe it and set it up using my old gmail account that i only use for spam and stuff, fwd my reservations to that account. I would not install my normal accounts on it. I would not install my bitwarden either. I would keep everything minimal, use web UIs where possible. then when i return, it looks like I use my phone and didn't wipe it but I also live a boring life.

Small inconvenience for me, but better than dealing with bullies.

How is it different from smashing your phone on the floor and destroying it when asked to unlock? Just because it's a code that wipes it makes no difference. I'm not saying the agents were right to ask for it, but it seems like if you feel that your rights are violated you should refuse to unlock the phone, not destroy the content in front of them.

Seems like they’re going to have a struggle proving intent. “I was stressed out and afraid and I got the passwords mixed up” would be the magic words I’d hear as a juror and I wouldn’t be able to vote to convict.

  • If you get a jury who doesn't think that "strange self-destructing phone" isn't a criminal's tool to begin with. Which I'd guess is probably not likely.

    • The defense has a chance to educate the jury about it in a trial, and given how widely CBP/DHS is distrusted in 2026 it’s not difficult to see at least one juror having reasonable doubt.

      Bonus for the defense: whatever is left of the DOJ, it’s mainly cranks, cronies, and people who can’t find work elsewhere.

In Catalonia, Spain, police have been profiling people carrying Pixel phones, assuming they have GrapheneOS installed and are drug dealers or gang members.

WTF.

> federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City.

This is practically the only thing I care about here and there are almost no details. What was his alleged involvement? How many others were targeted?

I think a wiser approach for crossing a border might be to have another phone with regular Android installed on it, so it doesn't look suspicious, and then connect remotely to your main phone. Before crossing the border, you would just need to remove the remote-connection app, and after crossing, install it again.

Why the hell doesn't the "duress PIN" just open up a sanitary profile? Bonus points for letting you set it up with plausible data before designating it as the duress profile that, when opened, wipes your real profile in the background.

> "the screen went blank, flashed several times, and the phone appeared to restart,"

How about flash some red lights and play an airhorn sound effect, too.

  • Just a guess… but they would just go back and ask him for the real pin if they saw the profile was empty.

    My understanding is phone’s security model aren’t designed for multiple user accounts

    • Android has had multiple users for many years, though it's a feature most smart phone brands turn off for some reason.

      You can switch users just fine, you just cannot hide the primary user from the secondary user. Opening up the device also makes it a lot more vulnerable to attacks to dump the keys and storage.

      Having multiple users is quite handy but it's not going to do anything at a border checkpoint that'll save you.

I have a friend who is a peace negotiator in the balkans for 20 years. He has lots of amusing (to my horrifying) stories of cat and mouse interrogations with the FSB etc as he travels between Moscow, Kyiv and the West. He uses threema and signal for most diplomatic conversations, but when he travels he only carries burner phones.

If you don't trust a government, ensure you aren't carrying any information you don't want to give up before entering their borders where you will be under their power.

So in GrapheneOS you enter your regular passcode to unlock it and a secondary passcode will wipe everything? Maybe it needs a third option where it just shows predefined apps/data, so it could just show e.g. WhatsApp, a set off chosen photo albums and some irrelevant office documents. Could also be useful for handing it to children, so they can access some games or whatever but nothing critical

Why is the headline blaming the OS for what the user chose to do?

This is like saying it's my car's fault if I decided to drive onto the sidewalk or something.

  • Yes, the only relevant property is the use of a duress PIN. They could have simply stated that he erased his phone with a duress PIN.

    But "GrapheneOS! Spain! Profiling Pixel users! Spain equates GrapheneOS to criminals!" sounds far more spectacular and will give more clicks/links. Sadly, it feeds the narrative that GrapheneOS is just for activists/criminals/whatever. An iPhone in BFU state would have been nearly as safe, but nobody makes these implications about iPhones because everybody has iPhones.

    • I mean, yes?

      If 1% of iPhone users are criminals and 5% of GrapheneOS users are criminals, border search agents are going to be interested in your GrapheneOS mobile.

      I am pretty sure criminals are more likely to use a super safe and secure phone that is easy to obtain.

  • Yeah, the way that this case is being reported on is really irritating.

    While he technically did use a special GrapheneOS feature to wipe his phone, the criminal charges would have been the same if he had used the default "reset phone" feature on Android or iOS right before handing the phone over.

    The real focus of this case should be on the reason for his detainment and the confiscatation of his phone and multiple refusals to contact his lawyer.

Perhaps a way to avoid this would be to have the duress pin trigger not a device wipe, but a device encryption with a long, pre-set key that you would store in a safe place when setting up the duress pin. Then you haven't destroyed the evidence, but the data is irretrievable without your cooperation. Also, if you don't actually have the key saved, it would in fact be destroyed, but the prosecutor would have to prove that you don't have the key saved somewhere.

  • This is one of those things the other comment calling the law "non-autistic" is referring to. In the eyes of 99% of people, it's functionally the same thing. "Well teeeecccchhhhnicallyyyyyyyy I still have the data..." isn't going to make the security workers at the airport slap their heads and say "damn, he really got us! Go on through!"

    No. They'll arrest you just the same for obstructing their search. Then they'll keep you in detention for a long time while you say "I can unlock it for you! You just have to let me out!"

    You can pretend you have leverage and say they need to cooperate with you. But once you're detained, police and prosecutors don't really care about cooperation anymore. Their idea of cooperation is you giving them what they want immediately without question. You're made into an example if you don't abide.

    • You are incorrect, US border patrol can not arrest you for refusing to decrypt your phone (if you are a citizen). It is not considered obstructing a search to refuse to provide a password. This is not "autistic" speculation about legal technicalities, there are many many examples which support this. The worst they can do is seize the device.

      3 replies →

  • The entire point of modern encryption is that the encrypted data should be indistinguishable from noise until you have the key in its entirety. Turning your data into random noise (whether or not there’s a secret code somewhere that can reverse the process) is destruction.

After reading more of this thread I'm kind of frustrated that people aren't aware of the border search exception.

I strongly disagree with the border search exception and would like to see it drastically limited or abolished.

It is also something that has clearly existed in caselaw for decades (arguably for centuries) and that the courts have routinely (to my regret) strongly reaffirmed.

The border search doctrine says that border agents do not need a reason to examine you or your possessions when you are entering the country. They do not need to believe that you are doing something wrong or committing a crime. If they suspect you, they don't need proof or a good reason to investigate you.

I find this doctrine very disturbing and I hope it will be changed or narrowed. I also would like people commenting in this thread to understand that border agents are not just imagining things when they claim to have legal authority to inspect people (or, alas, electronic devices or data) at the border, and that this didn't just start under the Trump administration or something.

The legal consequences of providing a duress PIN may not have been tested and this defendant could well prevail in this case. I just wish people commenting here would understand that there is a tremendous amount of history related to border search authority. You can disagree with it (I hope you will!), but you should understand that it's not just something that someone just made up last week or last month or last year.

I'd love a feature where if you enter a specific passcode it unlocks the phone into a different account that has curated things in it. Pictures, some pre-approved apps, etc. So you look like you've cooperated but you haven't really.

  • And each user's home directory is stored on a separate hidden partition that is encrypted with another PIN so that even if the device is rooted they can't look at the other user's data.

As a citizen the safest way is to just refuse. They can’t refuse entry. Not the same for LPRs.

The article seems to be muddying the water bringing up grapheneOS itself. Or maybe it's the EFF.

>Experts said the legal approach is unusual and may be the first time the law has been aimed at an operating system. "It's concerning – and sends the message that [GrapheneOS] is criminal by default," said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.

Is the actual case about banning the OS? Because it seems pretty clear the case is about the result (the phone being wiped with a special passcode).

The better defense imo would be one of those 'wipe the phone if you get the password wrong x times' and try and claim you forgot under pressure. At least if you wanted to wipe the phone without being accused of destroying evidence during a search.

> The motion also states that Tunick asked four times to speak with a lawyer and was denied each time.

This is the kind of thing that loses cases, even if they were legitimate at first. Seems like the prosecutor is desperate charging for the phone wipe cause they didn't have any evidence of terrorism, child-pornography, etc. The problem they have now is given he was in custody and agents pressured him to provide the passcode that they then incompetently put into the phone, the fact that they denied him a lawyer multiple times means there is a very strong argument that his rights were violated. Typically, courts suppress any evidence when there is a violation like this with someone in custody. So the compelled passcode, the phone's reaction when that passcode was entered, and the agents' testimony describing the supposed wipe would be thrown out by most judges. What's left for the prosecution after this is jack and shit, but jack left town.

Wiping could be the last resort. Instead how about auto creating a new profile! As far as I remember Android profiles isolate apps, files, and system data and providing a fresh environment without erasing the device. To make it feel more authentic there could also be an option to automatically install a few commonly used apps by default. Thats it. (assuming the officials don't have time for an thorough inspection)

  • There are forensic tools that can probably bypass those. I don’t think the agent is just going through your phone by using the phone itself, though maybe it is that stupid, idk.

Why did he do this? Really, if this is a way to protect your privacy, then it's a bad way because it causes such a scenario. Of course it works well against the stolen phone scenario, but not again "state authorities suspect me". Especially if this is the authority of some authoritarian state, where your rights do not really matter. Maybe he did this as a protest act?

maybe write down the duress pin somewhere in your wallet. let them make their own assumptions and erase the alleged evidence on their own.

By raising the profile of airport seizures all it means is that serious criminals will wipe their devices prior to travelling and restore afterwards/buy a new device for travel.

The powers of investigators special rights and abilities rely on them being used very rarely. Last thing the terrorism investigators want is media coverage exposing their tactics.

From the article, I saw this:

    > According to court testimony, federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City.

I didn't know about Cop City, but I found this on Wiki: https://en.wikipedia.org/wiki/Cop_City

This part is interesting to me:

    > RICO conspiracy indictment

    > In September 2023, sixty-one people who had been arrested in the forest or at stop cop city protests were charged with racketeering under Georgia’s RICO law. This indictment is likely the largest criminal conspiracy case ever filed against protestors in the US.

    > As of April 2025, the racketeering case was stalled. Defendants in the case maintained their innocence and reported difficulty getting work and other hardships while they awaited trial for more than 20 months. In September, all RICO charges were dropped. Judge Kevin Farmer found that the Georgia Attorney General did not have the authority to bring RICO charges in the case.

From my outside view, it looks like these investigations are nothing more than an attempt to suppress free speech and protests.

For anyone unaware, RICO is both a Federal law and a Georgia state law that stands for: "Racketeer Influenced and Corrupt Organizations". It is used to take down mafia, gangs, organized crime, etc. It is a bit sad to see state prosecutors trying to use this against protesters.

I'm not doing anything the government should be worried about. Nevertheless my pin has for a long time been longer than standard, specifically on the very long-shot possibility someone decides they want to crack it.

Anyone know if this is a viable strategy on iOS, and what the required pin-length is these days?

The duress pin deletes the encryption key information used to decode the documents and does not damage the documents themselves.

Not sure why the police and news are saying that he destroyed evidence, since the evidence (as it always has existed before the search began) remains on the disk.

  • Someone else commented about the law being “non-autistic”, this is a perfect example of that. The technicality of the encryption keys vs the files is irrelevant, the intent was to successfully prevent a search. The border agents will not be even remotely impressed or suddenly decide to release you just because you say “well the files are technically still there”.

    • What they should really do is make the decryption key backupable.

      Then you can keep it at home, and you can genuinely say that you don't remember it because it's like 128 digits.

      And you're not "destroying evidence" in the jurisdiction in question because the phone is already locked. And you can't unlock it on demand.

    • Perhaps a defence to this is ensure that a copy of the encryption key exists in a location outside the jurisdiction of the state.

There are laws against the destruction of evidence, but I'd argue that there's no evidence in this case since they don't have clear-cut knowledge what's on the phone. It's potential evidence at best and it's therefore not clear if the law applies.

If Customs already knew whether the suspect had incriminating files on his/her phone things might be different.

Wouldn't it be better from a legal standpoint to power the phone off and refuse to give your pin in such cases? A no-pin cold boot is pretty hard to recover data from with GrapheneOS.

  • Most likely, at least you are not doing something irreversible. In all these cases, the best answer is "ask a lawyer". Before wiping a device in possession of law enforcement you definitely want to ask a lawyer.

    I realize that in this case the person repeatedly asked for a lawyer, but if you are in a borderline authoritarian state, all bets are off.

Sort of feels like he should have wiped it right away, not after they seized it (by giving them the “wipe me” passcode). No idea if that’s how the law works, just my gut reaction.

Its best for all of us to figure out how to use phone-as-a-linux-vm with the physical phone just hardware. It will solve many problems: commoditize the phone ecosystem, eventually making them repairable, run our own apps instead of apple/google. Access phone-vm from laptop/desktop ...

Perhaps we need the following feature:

Before entering the airport you set your device to auto-wipe after x hours.

Once you are sitting in the airplane and flying, you cancel the scheduled automatic wipe.

  • A GrapheneOS is most likely completely secure in BFU state [1]. So just switch the phone off or reboot it and don't enter your PIN. It is very unlikely that law enforcement is able to decrypt the phone and it does not put you in murky legal terrain, because even an auto-wipe is intentional (IANAL).

    [1] This is in contrast to many other Android phones outside Pixel and Samsung flagships, because they are too cheap to add a secure element, which iPhone has had since 2013 and Google Pixel since 2018.

    • Nothing is completely secure. Your data is less likely to be accessed if your device wipes it.

      > even an auto-wipe is intentional (IANAL)

      It's also something that's very hard to prove.

There was no warrant, nor any court order compelling him to provide the unlock code. They had no probable cause, other than that they had labeled him a "terrorist" because of his political activities. The CSAM pretext was provably just a pretext. If he gets good representation, he should be able to (eventually) beat this rap.

If he had simply refused to provide the unlock PIN, he would have walked away. They may have kept his phone, but they would never have got anything from it anyway.

His mistake was giving a passcode he knew would destroy the data on the phone. Instead leave the destruct passcode written on a scarp of paper inside your phone case.

> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart.

I'm confused to understand if Tunick did anything illegal here. If the authorities want the phone, they should have the warrant and seize it without Tunick's permission.

It appears authorities did not have the warrant which give Tunick all the right to do whatever he desires with his property.

What am I missing here?

  • They don't need a warrant to seize the phone at the border. They were after the pin code, he should have just refused to give the pin. That's the 5th.

    What they got him on, is that supposedly he destroyed evidence.

  • Among other things that CBP does not need a warrant to search or seize anything and everything at a border. Everything is subject to search at the border. To make a seizure all that is needed is reasonable cause that customs law/regs were violated. And there are specific federal laws relating to thwarting such seizures.

    If you don’t want something searched do not bring it across the US border. There is very clear constitutional and statutory authority for these searches.

    • > To make a seizure all that is needed is reasonable cause that customs law/regs were violated.

      What would be the reasonable suspicion that a USC bringing their personal phone on a trip with them would be a customs violation?

      That doesn't sound at all reasonable.

      In fact, the only "suspicion" they had was that he was someone who didn't like LE or Trump which is still not a crime, nor a customs violation.

      1 reply →

  • CBP doesn't need a warrant to search at the border, including electronic devices.

    However, if Tunick was smart he would have refused to provide the PIN, and let them seize it. He'll get it back eventually, but it was in his right to refuse.

I feel like the advice given by IT departments for years was to wipe your device ahead of travel, and restore from backup upon arriving. Or, to take a travel device.

One clean implementation of this is to wipe everything on the 2nd password failure.

They have absolutely no idea if evidence was destroyed, and the only thing he is charged with is the possibility that it was.

If they were searching for evidence of a crime, what crime was it?

  • They claimed they were looking for CSAM. There's a border search exception to the fourth amendment that says CBP can search your phone at the border. You aren't required to give them a password (but possibly a fingerprint or facial scan) but they can temporarily sieze it (and do god knows what to it).

The problem with this feature is that the agents could realize the phone was being wiped. For the duress pin to be 100% effective, it would have to log in normally to a default install.

It seems to me that this should have been a case of steganography?

Instead of wiping it clean, wipe to innocuous mode. Then the burden on their part is not only to show that I gave a bad pun, but that the innocuous mode is materially different than the previous state.

  • creating a convincing and actually safe innocuous mode is probably harder than it sounds in practice

Rather than wipe the phone to an obvious reset state, this feature should boot into a benign setup with normal contacts etc. after it erases the user's data. Let the user periodically boot into this benign setup to add basic contacts etc.

I suspect that this will ultimately be thrown out for a very simple reason which is that the government will have to prove that a duress PIN was actually entered. That is going to be quite difficult unless the person charged openly admitted it.

The reason is because anyone running an os with a duress PIN that has done nothing wrong can be accused of using a duress PIN because the whole point of the duress PIN is that it looks like you just have a normal phone.

Running a normal apple operating system with just stock apps? Boom, you're a criminal because you obviously used a duress PIN and have something to hide! There is no way to prove you didn't use a duress PIN because the phone was "wiped."

Now unfortunately grapheneos probably leaks information so that a duress "unlock" can be differentiated from a standard unlock by some means. If not then kudos. It looks like it is done instantly by keeping everything encrypted and just zapping the keys, but it also needs to actually unlock to something instead of rebooting to prevent leaking the information that a duress pin was used. Not sure how fiesable that would be though.

  • I'm a GrapheneOS user. The duress passcode feature will reboot the phone to a "corrupted data" screen, so it's pretty obvious that it's been used to render data inaccessible.

Maybe also shows that the duress PIN feature could be implemented better. Booting into a completely fresh phone is suspicious. There also shouldn't be any visual or other indicators of that happening.

In the old TrueCrypt containers you could set an optional second password that would decrypt a different volume. The size of the container file was always the same, a decrypted volume always showed the full container size, the portion not occupied by the data in the main volume was filled with noise, and the data on the non-loaded volume was not protected (so you could erase it without warning by storing too much on the loaded volume), making it practically impossible to prove the existence of a second volume either way in a search situation. I guess there was a reason why the project was stopped.

Why didn't the device shadow-ban the user instead of wiping the device upon entering the wrong PIN?

Of course TSA agents become angry when they enter the PIN and see a message "wiping device".

Obviously you should just write the duress pin on the back of the phone inside the case. If the ask what the PIN is for, stand mute. If they enter it, it is their decision.

Charged is not convicted. Anyone can be charged with anything if the prosecution is vindictive.

A few things:

#1. The download and restore backup method would work- except it doesn't capture what people would need. Exmaple: I have some thermal cameras that rely on old 32 bit apps that do not run on anything android 12 onwards- If i wipe those old phones, and restore- the apps often wanted to reach out to a server for initial activation- they would fail upon reinstall and i'd be out of the apps that are required to control my cameras and related equipment,which is worth thousands and thousands and thousands. And it'd be all dead weight and rendered useless.

(and competitors today do not compete- for example try finding a 640*480 30 hz or better form factor thermal camera that attaches to phones - they dont exist anymore)

\The solution is imaging- but there isnt a way to fully image phones and restore backups today. There used to be it seems- but not really with the latest.

Veracrypt- The weakness of truecrypt and veracrypt, the hidden OS option only worked if you converted your computer to MBR, which means you can't have a hard drive too large. Making a UEFI hidden OS has not been done yet.

I am aware of Shufflecake attempting to make a solution.

And the Hidden Volume option- isn't 'as' useful, and of course, your OS might make a copy and put it somewhere, you have to be careful. Any time I open a file, using the software tool Everything to search and confirm this- you can easily see Windows makes copies and temp files and whatnot in randomly named locations- that's the sort of behavior that would screw people over

We need fully image-backup capable Phones. I mean fully. Not just backing up some apps- as this refuses to backup apps you have that are no longer on app stores, or that Play Protect doesn't like, etc.

Next- Plausible deniability is a way forward- but you need multiple profiles, that are cryptographically indistinguishable, along with the phone being hardened so GreyKey /Cellebrite won't be able to exploit a way in. This needs to be built this way from the ground up ideally, eventually.

There has been research about making devices that treat all block space the same way so you can't tell if someone has 1, or 50 profiles or partitions, etc- and even stuff that overlaps. But nothing has come out - and especially, for phones.

After all, if you travel to a hostile country, you can tell them you have just one profile, and if they ask, you could theoretically mention a 2nd, and then show it- but you might have 3 more - and they'd all be immune to forensic inspection if the system is built right.(Yes, there's often issues you have to be careful of ,like setting this up so you dont destroy data when in other profiles,)

This is how you solve this problem -make computing devices impossible to analyze

why would you need to carry incriminating data with you when travelling? An encrypted blob stuck 'somewhere' would be fine, no?

You wouldn't be surprised if that happened when traveling to China or any other autocratic country.

I think the issue is that people expect the USA to be the "land of freedom" when it's not anymore. It's turning more and more into an oligarchy and we are at the point where it's just as bad as russia or china.

If i was offered a trip to China or russia, i'd go but i would take a burner phone with absolutely nothing important; It's the same for the usa now.

  • No, as someone who lived in China for years (as foreigner) and visited also last year after many years I WOULD BE SURPRISED if this happened when travelling to China, since China is clearly more free than US/Israel.

    China wants tourists and don't care about your stupid social media.

Privacy and security are important, but there should also be clear legal guidelines for such situations.

  • Clear legal guidelines for which country? Or, better yet, for which subdivision within said country?

  • anyone would think that wiping entire device than giving sneak peak about what is in the phone is 100% sus as hell

It feels like if he triggered a wipe - that is destruction of evidence; but if it auto-wiped he's fine.

If it were a box of drugs and he triggers an incendiary device - he's in trouble . If agents trip a protective boobie trap and destroy the box- he is fine.

Don't know why but this feels correct to me.

Ok, so I'm just angry so take this comment in that light please:

1. What happens if the masses just do this? Today it's just a few folks who know how to do this. Tomorrow it could be 10, a year later 100. What's to stop 1000s from doing this and then what is the government going to do? Ban the OS and block it on Github?

2. What exactly happens after you're charged? This doesn't mean the person is convicted. Just that they now have to show up to court wherever the trial is held and have to retain their own lawyer (or public defender?). And what is the likelihood that the case is thrown out or the person is convicted and receives a stiff penalty?

I ask these questions because as far as I can tell, the person was not suspected or convicted of anything, and it's infuriating me that we are just going to stop random citizens and ask for their private data.

Dude I said 1,2,3-FIVE! jesus did you break my phone?! What the hell did you do?! Man my wife is going to be so mad she didn't even want me to upgrade to a new handset.

In fairness to the victim, he did really need to have that phone. What if there had been a restaurant with a QR-code menu? What would he have done then?

So yes, we've created an authoritarian hellhole, but the alternative is even MORE unthinkable: struggling to pay for parking in some areas, needing to visit a website for a menu or (GASP) visiting a different restaurant, or just having a friend order for you.

No, these are too much to ask of anyone. No one can overcome these challenges. The only answer is to weep for the liberty that we have lost.

There needs to be a simple feature to wipe your phone and then restore to a point and time. That’d be really convenient.

  • Seems like a good court argument too—no destruction of data was even attempted because I know I have my iCloud or Google backup. Personally, my phone has access credentials to information, but not the information itself. So you need a serious warrant before you can get those access, but the data is there.

    • I agree that it seems a simple argument for any competent lawyer to make that the phone isn't the "gold copy". The phone is just an ephemeral copy of the real data which is safely stored away in the cloud, and the authorities can request access to with the proper warrants.

      Of course this argument will only work if the phone is indeed and a ephemeral copy of your real data.

    • Honest question: Does a wipe just wipe what's on the phone, or does it also tell the cloud to delete stuff?

and what part of "search my digital device for words and phrases" is expressly allowed by the fourth amendment that protects against warrantless search and seizure? oh yeah, none of it. that's right. the fact that agents are conducting broadsweeping searches in clear violation of The Constitution is so painful it's almost laughable. it being a "border crossing" applied to digital information and not just the contents of my suitcase is an appalling transgression of the spirit of the law. also why is your device programmed to self-erase? that's also incredibly sus.

smuggling endangered species? bad. okay search a suitcase.

having unrestricted access to all my gmails because i need to catch a plane? absolutely unacceptable.

having your phone autowipe when pressed by authority? quit whatever nefarious shit you're doing, thanks

What nobody has commented yet here is that the incident is 7 months old but we're only hearing about it now. Imagine the incidents we DON'T hear about at all.

This sends like a more-info-requiered situation. Per this article, the LEOs seemed to be fishing, so they presumably couldn't claim as a matter of fact that evidence had been destroyed. Also, claiming destruction of property seems unreasonable since the phone, the property, still exists as before. If I sell my phone, I'm going to wipe it. I think we all understand that it would be ludicrous for the buyer to claim I was destroying the phone, the property they've been sold, by doing so.

Even if the accelerated executive capture of the judiciary is largely ruled back post Trump (big IF), I fear the government will be unwilling to pay with much of the convenience of rule-by-law that it's been given a taste for.

Instead of a PIN that wipes the device, it would be much better to setup a special PIN that logs the user into a sanitized, completely separate profile with generated content of no practical value. This would create plausible deniability, and be sufficient to allow low-level border agents to look through a phone and pass any checks without raising these kinds of alarms. The wipe PIN should still be an option, but should be separate, and only be for cases where you suspect a forensic imaging or search of the device is to take place and the legal consequences outweigh the risks.

Gotta wonder how it would've gone if the citizen hadn't mentioned GrapheneOS at all and instead tried to sue them for wiping his phone without his permission.

"Prosecutors say the OS erased evidence"

It's his device, so he can do everything he wants to. The USA is currently re-purposing constitutional protections. A judge has not signed these warrantless seizures, so why would the individual be under any obligation to cooperate? Besides, why would anyone want to incriminate oneself? The onus would be on the state to prove a guilty state.

How dare he outwit a bunch of nincompoops. If the United State was a nation of laws this suit should be tossed with prejudice.

Having just gone through having to give pin to cbp you just need the apps on your phones to have separate pins so when police unlocks it, they cannot unlock WhatsApp afterwards. Faceid or unique pin. Problem is your phone pin overwrites Face ID

maybe have the default behavior for the phone to reset if it doesn't get the right pin every so many hours

it's a bug: the wipe should only apply to a see secure enclave, and the phone should restart `normally`

It has always fascinated me, the degree to which airport staff feel so important, as if the world would stop revolving without them.

Every day I thank the lord that I left the US for good and never went back

  • I would be very interested in how you did this / where you ended up. Feels like an impossible task every time I consider it.

    • There’s been a large uptick in immigration from the US to Ireland; almost ten thousand last year. In general, people would do this via employment; software engineers and similar would generally qualify for a critical skills permit. For critical skills, after two years on a stamp 1 visa (tied to a specific employment) you can move to a stamp 4 (not tied to specific employment). After five years working in the country you can apply for citizenship.

I don’t understand why phones can’t just have decoy profiles you can activate via PIN that look like regular harmless user profiles? Especially now with AI you can quickly populate with a bunch of plausible data.

Or better, have PIN for taking you to your criminal/secret profile instead.

  • How would it work? Isn't it easy for the authorities to check the list of users on the device?

    • The PIN you enter determines what profile opens up, and they are not connected to each other at all, they are isolated.

> US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search

I really don't like this title. Officers asked him to open the phone, which he pretended to do, but instead wiped the device

> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart. The defense motion states that "the screen went blank, flashed several times, and the phone appeared to restart," resulting in the loss of data.

The title implies the agents maybe entered too many pins by mistake and the device auto-wiped, or that it reset itself with no human intervention, which isn't what happened. This is more like shredding paper when the FBI arrives at your office, which most people would attribute to destroying evidence. I hope he wins the case in principle (I think there's a risk of a slippery slope here) but it wouldn't be a moral tragedy if he lost.

This grapheneOS may be another scheme from the 'deep FBI'/'services' to get intel on the very, VERY, nasty (terrorists, human traffickers, drug cartels, child stuff, etc). If I recall properly, they did that in the past (it seemed to have worked amazingly).

If so, "normal" police would not have the "keys". This would be "the compromise".

could graphene support multiple duress PINs?

feds: "unlock your phone or else" victim: "um, you're stressing me man. It's either 1234 or 4321, I forget. One of them wipes the phone, the other will unlock it."

Whichever PIN they try, it wipes the phone, but the feds can't claim it was deceitful, just unlucky.

why not just have a separate device for traveling ?

  • Yeah, that's my position.

    If you're paranoid enough to be using GrapheneOS, why would you take it to an airport in the US of all places?

    I bought a second hand iPhone for overseas trips, which my daughter promptly stole because she wanted an iPhone, but then i got her old android phone, which was LineageOS-compatible, so that became my travel phone.

    • How do you manage data between your primary and travel-phone?

      I _think_ you would need a fresh iCloud account (thus losing access to purchased apps and subscriptions). You also need to manually create fresh social media accounts, copy over contacts, etc.?

      Any advice on how to automate this process or is this just a 2-4 hours exercise you do before your trip?

      4 replies →

    • GrapheneOS is excellent but seems like it just brings unwanted attention at this stage.

      Another plus is if you do lose the device the damage is minimal, its a bit of a hassle but nothing beats peace of mind

  • - e-sims make it much more difficult to swap sim cards between devices.

    - presumably border patrol wants to see his photos, social accounts, and email. A separate device with a copy of the information they want isn't a defense. Creating fresh travel-only accounts is tedious, b/c fresh accounts aren't connected to your friends or network (with whom you'd want to share your trip with).

    • you could login to your stuff after but the point is to minimize damage when you do lose your device abroad

      laziness isn't an excuse and if you do want access to your phone or device at home you could setup that as well

While I like the idea behind GrapheneOS, I'd rather not place myself in jeopardy of some ridiculous charge like this one. I prefer to travel with a travel device, some inexpensive phone and/or laptop that contains nothing interesting. If they then wish to take it from me because I won't unlock it, then have at it! That said, the situation with respect to our Bill of Rights at the border has gotten ridiculous.

  • The "duress PIN that nigh guarantees destruction of evidence charges" functionality is extremely stupid, but otherwise GrapheneOS on a flagship phone is your best bet for an Android phone that can't be cracked by low-effort attempts, government or otherwise.

My bets for the actual story behind this are: 95% a criminal hiding evidence 4.99% an autistic attempt to "keep his privacy" for no reason at all 0.01% a genuine need to keep something away from the government

In all cases just don't cross security checks with evidence you wouldn't want to be seized, its not that hard

  • Wrote someone who's got a CCTV camera installed inside his toilet bowl, no less! Right?

    The Bentham business is alive and kicking.

To everyone who thinks this is somehow a violation of rights: if you were being questioned by border officers, and were asked 'Sir could you please open your suitcase', and you pressed a button that caused it to burst into flames, there isn't a country in the entire world that wouldn't arrest you on the spot. Why would 'wipe a phone when officer requests it opened' be treated any differently? Suspicious behaviour is treated as suspicious by normal people.

  • It doesn't sound like this person pressed any buttons. They were pressured to provide a PIN or be delayed and further harassed. They obliged, and agents decided to enter it to attempt a warrantless search of the phone.

    It's not stated, but probably we can assume the person didn't ask for his phone to be searched - probably he asked NOT for it to be searched, at least based on his multiple requests to talk to his lawyer.

    Considering those factors, I'd say border patrol is more responsible for wiping the phone than the person.

  • Right, but by that rationale, it’s also suspicious to say “no” when they ask if they can open your suitcase. Or decline to tell them where the key is. Or ask to speak to your lawyer first. Or refuse to tell them what is in the suitcase. Or lock the suitcase in the first place. And I want to live in a society where those behaviors are protected.

    (1password has a “traveling” mode that wipes it of sensitive passwords before going across borders. Is that suspicious? Should it be criminalized?)

    • If they ask to open my suitcase and I say 'no' that is suspicious. I've done a lot of travelling and have been questioned more than once: being candid and transparent has always been prudent.

  • Yes, they would be rightfully arrested for setting off an explosive device in an airport. This analogy ... isn't great.

  • material =/= information.

    Are we supposed to live in a world where if I'm crossing a border I must give access to all of my information? That's absurd and more equivalent to a full brain/memory scan than a suitcase search from your example. This is dystopian in every sense of the word.

    • The Overton window of this fucking prison planet went so far that there's little to no discussion on how absurd and dystopian it is.

      And rest assured, when it gets to actual full brain scans, the corresponding threads will be chock full of scum tasked to normalize that.