Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
US citizen charged after GrapheneOS phone wipes during airport search (techspot.com)
663 points by eecc 9 hours ago | hide | past | favorite | 476 comments
 help



I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully).

The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that.

The end result (not inherently different from what we wrote in the guide) is that you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to. I was fascinated by techniques for being unable to comply (which is straightforward to achieve if you want!) but probably didn't think enough about how much this might antagonize border agents in many cases.

I definitely don't know a comprehensive big-picture solution.


can you share the link? This?

https://www.eff.org/document/eff-border-search-pocket-guide

----

Seems the better strategy (for iOS) is come in with a plan to say yes to agents without pissing them off (like handing them an empty phone).

better to local back up, encrypt, upload to your home server etc.

Then login to a fresh iCloud account, selectively install apps, photos, and mail accounts. So it doesn't look like you're walking in suspicious.


> I think they should not have this power, but the agents and courts probably don't care that I think that. ...

> and about not angering the agents more than you plan to

When I was a teenager (long ago at this point), I got into an argument with a police officer over surfing in a certain area. It was pouring down rain, so he was annoyed he had to sit outside and wait for my friends and me to come to shore. Once we got in, he was telling me that he could take my surfboard and my car, and all other craziness. Being the dumb smart-ass I was at the time, I laughed and told him he was full of shit, among other things. He went to take a swing at me but his partner grabbed him.

We all go to court and the judge immediately dismisses the case against all my friends. I had a lawyer with me that I knew and he went to talk to the cop and when he came back over he goes "I don't know what you did, but that cop hates you." I get up in front the judge and he praises me for understanding the law (and I could still see the cop was visibly pissed), but then says he can't have me disrespecting and being a smart-ass to his cops and gave me community service that once completed whatever the ticket was would go away.


> but then says he can't have me disrespecting and being a smart-ass to his cops

Maybe it's just me, but I am of the exact opposite opinion. Cops have enormous power, and any misuse of it should be pushed back on hard. Cops that misuse their power should not be respected. An informed citizenry is a wonderful asset in making that power imbalance less of a problem.


Yeah, but go tell that to the judge who’s just about to slap you with a sentence.

Unless you want to fight that all the way up the judicial food chain


Absolutely. It's not worth it unless you're more principled than anyone I know at least. Instead you're left with a minor punishment and most of your faith in the justice system left behind.

Too bad you could not bring that judge up on charges of judicial misconduct - if he indeed told you that the charge against you had no merit, but decided to punish you anyway because he did not approve of your demeanor.

... or otherwise, that people in your community could not apply any counter-pressure to such judicial behavior, in the media and public fora.


at some point you just take your lumps.

Most people don’t have boundless time or energy and just want things to go away.

… ironically this fact is used a lot in gaining confessions by police.


Just don't travel to the US.

I live in the U.S. (as, I think, does the person who is the subject of this article).

So I guess what you really want is a duress PIN that loads into a fake innocent profile.

Yes I thought this was the standard solution?

People have been doing this since way back in the TrueCrypt days - IIRC you could configure it to run a whole fake version of Windows if you wanted without easily revealing your actual main volume.

Most hardware crypto wallets also have a "duress wallet" feature where you keep a low balance for the same reason.

Wiping is obviously extremely suspicious and asking for trouble


"Wiping is obviously extremely suspicious and asking for trouble"

It's sad this is the default view. It's his device, his data, his life on that phone. If he had wiped the phone before the interrogation it wouldn't be a problem. How long before? A second before? A week before? But wiping the data a minute later is suddenly asking for trouble.


I don't like it and I wish we had more privacy, but realistically there is no such "right".

If you're going to be in a situation where you're in a room with some goons backed by the full power of the state, it is what it is.

Maybe because I'm not American I don't have any hangups about seeing the US government this way, but my own government is no different - you can (and people have) get stopped at Heathrow, taken to a dimly lit backroom and given a going over for hours


I don't know that there is case law on this but I imagine that "prior to the admissibility inspection" is likely to be treated differently from "during the admissibility inspection" or "during administrative detention or secondary inspection" (or "in response to a request or question by a border agent"!).

Edit: a bigger picture question is the difference between things that may be legally punishable and things that may cause suspicion from CBP agents, which aren't the same thing at all.


We noted in the border search guide that lying to the agents in response to their questions is potentially a crime in its own right (even if it's not done in order to hide anything illegal). We thought that this made hidden volumes quite tricky, particularly if one's intent was to pretend to comply with a question or request while actually not complying.

Or that just selectively wipes only stuff you have marked for deletion. That way the profile stays up to date and believable.

Problem is „are you sure you marked for deletion all the correct things” because you could have already deleted it before traveling or moved to other device you don’t travel with.

Selection on border control might be arbitrary, they can hold you or send you back over a photo or something you wouldn’t think should be a problem.


That's a more risky strategy. What if you added new files since the last time you updated the deletion profile? It's also technically more challenging. You have to think about what might be in RAM, caches, backups, etc.

The good thing about a total wipe is that it's very easy to implement, and it's hard for it to go wrong. You just encrypt the whole drive and, when you want to wipe it, erase the key.


Yes, this also has the advantage of speed perhaps. I can see, deleting specific apps (and their data) as thing #1, and thing #2 would be certain directories. Of course, the problem is, are icons going to be vanishing off the home screen, when the agent is looking at it? Or will the unlock -> screen coming on, be super slow?

Of course the problem there is, many people have an app store installed, and app stores have histories. And logs. And "what you used to have installed" is so easily found under Google Play, for example.

As someone else said in this thread, the law isn't code. It's not if-then statement based. It's also predicated upon intent in many cases. What actions did a person take, and why, when told to (for example) unlock their phone.

The problem here is that if you are asked to unlock your phone, any action you take to thwart that request by "trickery" to get data deleted, could be construed as 'deleting evidence'. So while some methods might make it more difficult for the border agent to realise "something happened", if they're suspicious still, then you're still in hot water.

In the eyes of the law, the court, and likely the jury, you've done a sneaky thing to thwart evidence collection.

The only safe method is a full wipe prior to travel. In this manner, you're not deleting evidence when told to hand it over. It's an entirely different bar. They can be cruel about it, and take your phone for a few months, but you're not going to be in legal hot water.

In as no one will see the phone is wiped until you are compelled to unlock it, there's no greater change of the phone being seized. You're already being investigated. Just be blunt, say "Whenever I travel, I just wipe it", and that's that.

This is why it's a shame that GrapheneOS has no viable backup solution. Its build in method is unreliable, and doesn't work very well, and is gitchy, it's a very well known problem.

And Android and ADB sometimes have issues with large backups of directories, and so you have to manage that with tar + stream and other business, but at least working around that is easy.

But if you could backup individual apps and all their data, you could uninstall all your privacy laden stuff, cross the border, and reinstall in minutes.

That's the true, legal way to travel safely. Especially if the app removal resulted in a 'shred' of the data files instead of delete.

If anyone has ever struggled with large data backup/restore, here's the only real method I've found for copying large swaths of files from/to via adb:

  adb exec-out 'tar --dereference --create /storage/emulated/0/dir/  2>/sdcard/backup-errors.txt' |dd of=/tmp/backup-$(date +%Y%m%d).tar && adb shell cat /sdcard/backup-errors.txt
and to restore

  dd if=backup-20250309.tar | \
  adb exec-in 'cd /storage/emulated/0/tempdir; tar xpvf -  2>/sdcard/restore-errors.txt' && \
  adb shell cat /sdcard/restore-errors.txt
Or something similar.

> The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that.

That's the reason I never traveled to the US and never will, just having IT security in your CV is enough to make the border gamble not worth it


Note that border searches of electronic devices are extremely rare overall. There were some statistics from CBP implying a base rate lower than 1 in 10,000 (I think lower than 1 in 100,000) border crossings.

I do know two people who have experienced them as a result of the government taking a personal interest in them, so it's certainly not impossible. However, it's not a common experience.

I've personally experienced searches of my suitcases about four times in about 100 U.S. border crossings (as a U.S. citizen, but the people performing or directing those searches generally didn't know my citizenship status), and zero electronic device searches.


It's also quite surprising that all socials need to be declared. And presumably them AI vetted in time for you to get to the border.

This part is pretty new. I wonder if my former colleagues have done any FOIA work looking into how travelers' disclosed social media accounts have been reviewed or analyzed!

I’ve seen a lot of people on the internet over the years say things like “the government can’t make x illegal, it’s just y.” For example, the government can’t make wiping your phone at the border illegal, it’s just punching four numbers into your phone, just like a pin, only a different four numbers, which could just have well been your pin.

U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did. Hell there could have been a third set of four numbers that were the nuclear launch codes. It’s not the fact that it was four numbers, it’s what you were trying to make happen when you typed them. Now of course whether they can prove what your intent was when you typed them is another matter, but generally a duress pin should be for when robbers are breaking into your house, and the government will be on your side, and not when the government will be against you.


"U.S. law though is highly non-autistic" hilarious but also another point to emphasize is how truly depressing American courts often are. Take the right to a jury. It sounds noble in theory. But when they say judged by your peers they don't mean your actual peers.

It's people who couldn't get out of jury duty. Prosecutors have high success rates. Federal prosecutor success rate is over > 90%. Studies of jury psychology show how much peer pressure and other factors extrinsic to the law come into play.

Remember what happened to Aaron Swartz. Law is the mask of power. By all means defend and assert your rights, but understand the costs. I find people are under such illusions about how cruel the American justice system is that this leads them to make foolish decisions. Do not underestimate the adversarial nature of the justice system, nor the accompanying incentives agents of the state who are on the other side of you have to lie.


> Federal prosecutor success rate is over > 90%.

This is a misunderstood statistic.

Federal prosecutors won't even pursue cases unless they think there's a high chance of success. They don't operate like two private parties suing each other to force the court to decide something. If the evidence is there or the charges aren't fully formed, they don't waste resources on it.

This leads to a contradictory set of complaints that the legal system lets too many people go or doesn't have enough teeth.


>Federal prosecutors won't even pursue cases unless they think there's a high chance of success.

Given the incarceration rates compared to average western standards, that's a moot point. Even if they selectively pursue, they do pursue a hell of a lot, and they do get a hell of a lot of convictions - relatively. Factor in the severity of the convictions, also much worse compared to average western standards even for the same offenses, and it's an ever worse picture.


> Federal prosecutors won't even pursue cases unless they think there's a high chance of success.

The problem with this theory is that it ignores the incentives on the other side in a criminal case. When you get charged with something, the prosecutor offers you a deal and that deal is almost invariably a significantly lower penalty than what happens if you go to court and get convicted. The plea deal is a lesser charge, if you demand a trial then they throw the book at you, stack charges and ask for more severe penalties for each one.

With the result that if someone actually did it, demanding a trial instead of pleading guilty for a lesser sentence has a large negative expected value. Which in turn implies that it doesn't make sense to do unless you think there is a high probability you can win, for example because you know you didn't do it. The coercive force is so large that it can cause innocent people to plead guilty, since even a 10% chance of losing can screw up your whole life when it means a 10x higher penalty.

And yet > 90% of the people who thought their chances of being acquitted were high enough to be worth taking a much large sentence on conviction, still get convicted. Which seems suspicious.


They never pursue court trials, because it's too much work. But they'll pursue plea deals, because there's this gigantic pipeline and everyone in it (including public defenders) is on the same team: Team Make Him Plead.

Because of this, no true justice is possible. Trials don't just try the defendants, it forces the prosecutor to prove that there really was a case and that they weren't just trying to bully someone who felt it was hopeless and would rather get out of pre-trial jail early. It forces the cops to actually make a fucking case, rather than rely on horseshit to lock someone away that can't bond out.

And no reform is possible. If you explain any of this to someone who actually understands it, they panic and say "but the prosecutors wouldn't even be able to bring 1/50th of those cases to trial, the system would overload" as if that were a bad thing that they couldn't. In the same way that you're not caught in a traffic jam but rather you are traffic, you're not caught up in these problems... your apathy, your ignorance, your rejection of boat-rocking, in short you are the problem.


I don't think it's so much a "misunderstood" statistic as much as a number that people (like the commenter you are replying to) deliberately trot out to use as evidence for their position because they are depending on most people being statistically illiterate.

To be clear, I totally agree with your points, I just think this is more of a case of "lying with statistics" than being a misunderstanding.


I think in this case Hanlon’s Razor very much applies.

"Never attribute to malice that which is adequately explained by stupidity."


When it comes to political statements everything is opposite day.

No. When it comes to statements by politicians, maybe. But when it comes to what people say in a setting like this thread, being so flippant in discounting people’s earnest-ness is a mistake and gets in the way of actually moving understanding forward.

Thank you for brightening my day. Keep on acing the vibe check!

> Federal prosecutor success rate is over > 90%

Prosecutors pick their cases. Defense doesn't. The cases that aren't 90%+ sure aren't charged.


Yes.

Prosecutors will often lower charges to ones where it can be tried without a jury too


And this is as it should be.

no way!

it should be about 50% conviction rate so that juries dont go in with non-evidence that the case is good because the feds thought it should go to court


So prosecutors should bring you to court even if they think there isn’t evidence that you are guilty just to make the conviction rate go down? Today they would let you walk but you would want them to take you to court for a crime the prosecutor don’t even think there is enough evidence?

That would be a nice outcome but whose responsibility would you make it to encourage it? Judges and juries should not grade on a curve. Prosecutors shouldn't waste taxpayer money chasing convictions that are out of reach. There's nobody with access to that calibration dimetion.

You do realize that what you're advocating for is for prosecutors to bring more cases to trial that previously they would have dropped.

And you think that benefits defendants how???


Some of us report for jury duty just itching to nullify something. Don't you? Checks and balances...

Nullify if necessary, more likely duty to justice as best as I can come to understand it.

We should all know it though!:

  It has been commonly used to oppose what jurors perceive as unjust laws, such as those that once penalized runaway slaves under the Fugitive Slave Act, prohibited alcohol during Prohibition, or criminalized draft evasion during the Vietnam War.
https://en.wikipedia.org/wiki/Jury_nullification

I went itching to nullify injustices - I left wanting to reintroduce the death penalty for petty crimes.

I got selected as juror once just hoping to laugh at anything the cops said on the witness stand and let some poor soul go free but it turns out the defendant was just a violent scumbag who stabbed random people in public, and there was a video of it. After we decided he was guilty, they listed other things he had been convicted of and asked if he was a repeat offender... Let's see, shot somebody in the back, robbed liquor stores at gun point (dressed as a clown IIRC) and some other weird shit. That decision didn't take very long.

Honestly we didn't even throw the book at him, prosecutors were charging him with a bunch of offenses and we decided guilty on only two, but the repeat offender bit probably locked him up for a few decades.

The funny thing was that all the jurors thought the victim was a complete douchebag and thought both parties deserved time. As it turns, somebody I knew at the time knew the victim from childhood and he apparently molested his 8 year old cousin.


I just served on a jury and in our case, the cop was a lying scumbag, the prosecutor's expert witnesses were people milking the taxpayers to provide the evaluations that the state wanted to hear for thousands of dollars per hour, the defense's expert witnesses copy-and-pasted an evaluation from another client but didn't bother to proofread before the prosecutor brought up that they had the wrong name in the text, and the defendant raped and molested multiple kids below the age of 8, some still in diapers.

I feel like many court cases are textbook instances of Everyone Sucks Here. I needed therapy after the case because it had so shaken my faith in both the justice system and humanity.


That is horrible but robbing a liquor store dressed as a clown is pretty funny (in my head probably not irl)

Imagine picking the suspect out of the line-up, or drawing up a photo-fit.

Is the high success rate because they are good at winning or good at picking winning cases? Does that 90% include plea bargains?

I've been on jury duty several times and in each time the entire jury pool was dismissed an hour or so into the morning, with "all cases have been settled". As I was leaving, the official said, "see how efficient we are now?". I replied, "The guillotine is efficient, but it's not justice." Look into Aaron Swartz. The % of cases that go to trial is very small, in no small part because plea bargaining is no bargain at all. "Plead guilty and we'll do the minimum (whether you're actually guilty or not), or go to trial and we will seek the maximum sentence, which could be 30 years in prison. What's your answer?"

You're begging OP's question.

How so?

OP is strongly implying that the 90% success rate for prosecutors is due to the courts being stacked against the defense. IMO that is where the logical fallacy is. Since prosecutors have wide latitude in deciding which cases to charge in the first place, it is very possible that the high success rate is due to prosecutors only charging cases where the accused actually committed the crimes being charged. Indeed, for the ~10% of cases where the accused is not found guilty, about 8% are due to the government dropping the case - only 1% are the jury acquitting the defendant outright. Thus, it would appear from that data that when the prosecution sees they are not likely to win a case, they drop it.

I'm making no argument that the courts or law are "fair", I'm just making the argument that quoting the 90% number is in no way evidence that courts are inherently biased towards the prosecution.


The courts are stacked against the defense, but that statistic in itself is not proof of it.

The courts are stacked against the defence as the bigger the fight, the more defence lawyers can bill.

The legal profession is incentivised to not seek to change rules that disadvantage their clients…


I think it’s a valid question as far as what the nature of that success rate is.

It is not surprising. They just don’t go to court unless they think they have enough evidence for a conviction. In a perfect world the conviction rate would be 100% because in a perfect world the prosecutor would drop the case before if they don’t have enough evidence.

If it’s a malicious prosecution by the country/state then Jury is your best best over a Judge.

There is a reason that Elon Musks companies and others put a ‘you agree to not have a jury trial…’ clause in their terms as Judges are easier to influence - when a legal case is filed it’s allocated to a judge and certain cases will go strategically to a Judges with certain bias


> Remember what happened to Aaron Swartz.

Indeed. There are certainly parallels between him and Sam Tunick. But I'm not sure the public is ready for all the parallels.


Exactly. People complain police dont prevent crime, but dont realize that is not their purpose. The police exist to protect the government, not the people.

Police don't prevent crime, they arrest and charge people for committing crime.

Arresting people because they might/could commit a crime would be a bad route to go down.

> The police exist to protect the government, not the people.

The police exist to protect the rule of the land. The military exists to protect the government.


The police are there to enforce laws, but enforce it by punishment, rather than prevention. The potential deterrence effect still applies, as people do get discouraged from crimes by the mere presence of the police. However, there is zero legal duty for the police to protect someone who is currently under attack from a criminal.

> However, there is zero legal duty for the police to protect someone who is currently under attack from a criminal.

That has to be incorrect, by the time someone is under actual attack from a criminal that criminal will have allready comitted crimes that the police can and have to punish for, i.e. Threat of Force with a Lethal weapon or sth like that.


Legally, the police do not have to swoop in to stop someone who is actively murdering you. They can just wait until later and write a report after you’re dead.

1981 Warren v. District of Columbia


Which part of the government protects the people?

None of it

The part that is afraid of not getting voted in next election. As long as they make the voting ticket a two party/person race and ensure that their voters believe the opposition is the literal devil, then they don't have to be too afraid

Luckily that has never happened /s


> It's people who couldn't get out of jury duty.

But that's good no? People who got out never would have taken it seriously.

I sat on a jury trial and was highly impressed with how seriously my fellow jurors took it - especially the presumption of innocence. When they started to go down some incorrect logical path, someone would step up and correct it.

Not to mention the public defender ripped apart the DA's case. It was the exact opposite of what I was expecting.

> Prosecutors have high success rates.

You're forgetting that the prosecutors don't bring cases they think they're going to lose to trial, they either drop the charges or try a plea deal. So you'd entirely expect the success rate to be high.


> Take the right to a jury. It sounds noble in theory. But when they say judged by your peers they don't mean your actual peers. It's people who couldn't get out of jury duty.

What? A jury system is far from perfect but this is about as intellectually rigorous as “the lottery is a tax on the poor”. Many people are thrilled to do jury duty because they are invested in their community, your nihilism is not a universal truth, jury duty isn’t a burden, it is a civic duty, an honor.


> It's people who couldn't get out of jury duty.

It’s not even just who couldn’t get out of it. It’s filtered for people who answer honestly. I was disqualified for a grand jury because the judge asked me if I would believe the testimony of police officers as truthful and I said it would depend on the police officer.

The system already had their hands forced on accepting that some cops lie with Brady disclosures but the fact that I didn’t just naively accept police testimony meant I was an unscramble juror.

Even if you’re a true believer in the system you won’t be allowed to participate because you didn’t lie.


This was really well written in "What color are your bits": https://ansuz.sooke.bc.ca/entry/23

Programmers have trouble seeing color (two identical numbers are the same bits, how can typing '1234' to unlock one phone be legal, and '1234' to unlock another phone be illegal?)

Courts care about color (intent, provenance, permission), even though that color cannot be digitally represented.


Indeed, but should he say his real code was one digit swap off, could you prove intent? Color matters, but you can't paint with only one

This is where 'reasonable doubt' comes in from a jury. Would I believe that someone set up a 'wipe my phone' code, something that would be catastrophic, it was one digit different, and they accidentally typed it, or would I think they were trying to wipe their phone.

Honestly, given what I know here (a full case might be different), I would believe they did it on purpose.


Framing this as whether he can convince you the mistype was accidental gets it backwards, and "would I believe X or would I think Y" is preponderance, not reasonable doubt - entirely different standard. Reasonable doubt doesn't ask which account you find more likely. It asks whether the innocent one is unreasonable.

Take the hypothetical as posed: duress code one digit off, entered while detained after being interrogated for hours, and repeatedly pressured to unlock. The government has to prove beyond a reasonable doubt that he knowingly triggered the wipe and did it for the purpose of impairing the seizure. Nothing about that scenario makes mistyping an unreasonable explanation unless there is more circumstantial evidence that indicates him intentionally providing the wrong PIN.

Proving that to a jury looks very hard.


"Color" absolutely can be represented digitally; C compilers were doing it before we even knew they were doing it. We just like getting away with shit. It's part of the hacker ethos. Probably.

Not all color can be represented digitally.

Is a piece of software subject to patents? Is it export controlled?

Both of those can change without the data changing at all. A new patent can be applied for and accepted, at which point all code the patent description matches is potentially encumbered (even if it was written with no knowledge of the patent or before the patent existed, yes our patent system sucks).

Export controlled is also a matter of laws, not an attribute of the data itself, and laws change independent of data.


You've just merely exhibited the symptom of being blind to all the colors which cannot be represented, not proven or shown that there are none.

All of a things properties are not contained in or expressed by the thing itself.


A lot of engineer types forget that the law is not code, and reductionist arguments almost never actually work in practice because it's a human interpreting the law.

> A lot of engineer types forget that the law is not code, and reductionist arguments almost never actually work in practice because it's a human interpreting the law.

It's worse than that: a lot of engineer types reason about almost everything as if it were code. It's a manifestation of Engineer's disease.


I now see engineers treating people like AI agents. It can always get worse...

For one example of this, around 10 years ago there was a company called Aereo that tried to act as a "cloud television provider". The idea was that they had thousands of tiny antennas hooked up to servers in a warehouse, and they would lease an antenna to each subscriber. This gave an experience similar to cable TV but without Aereo having to pay broadcasters cable transmission fees. The major broadcasters sued Aereo and ended up getting it shut down for exactly the reason you mention. Despite Aereo technically being a TV antenna leasing service, it functionally acted like a cable TV service so they were violating copyright by not paying transmission fees.

This sort of legal workaround can work (see Uber) though.

Uber avoided medallions.

I guess that proves law is not code!


It's not that there's a human interpreting the law. It's that there is a politically motivated human interpreting the law, or in other words, you are sol if the state wants to get you. The engineer's arguments aren't reductionist, they are idealistic.

It reminds me of tax law in many countries. You can follow the letter of the law, but if the vibes are off, you can still be found to be in breach of a vague catch-all provision (e.g. economic substance doctorine in the US, GAAR in Canada/UK, Part IVA in Australia, etc).

UK has systematic tax avoidance IIRC i.e. keep starting and closing businesses to save tax is frowned upon. Australia can treat your capital gains as income if your gains quack like trades. (Maybe now less important since the recent CGT changes).

Maybe this is because of the TV dramas where a genius lawyer saves their client through an obscure technicality. It looks exactly like hacking a system using a 0-day exploit.

There is a strong bias by the courts to interpret the law in such a way that it makes sense, and achieves the goals the legislature had when enacting it.

Just read this point in a case revolving around the Oxford comma, stated in simple enough legalese I could understand:

“laws must be construed liberally in order to accomplish their remedial purpose" https://en.wikipedia.org/wiki/Serial_comma#Maine_labor_dispu...


Does anyone think law is computer code? I mean any courtroom drama (even if far fetched) shows it is not.

In this case, the government was against him due to his activism against a police training campus.

Him deleting his phone was very likely a matter of safety for his fellow activists. Sad that our government does this but it’s not like this guy was a drug dealing or something.


> U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did.

Love this way of putting it. Stealing for future conversations with fellow software developers.


I favorited the comment for the same reason. It's a perfect way of describing it.

I think it's insulting

Not sure if you mean to software developers, or to those who are autistic, but I'm both.

What's the less insulting but similarly concise way to make the same substantive point?

The law is teleological. As in:

> When interpreting EU law, the CJEU pays particular attention to the aim and purpose of EU law (teleological interpretation), rather than focusing exclusively on the wording of the provisions (linguistic interpretation).

https://www.europarl.europa.eu/RegData/etudes/BRIE/2017/5993...

https://definitions.lsd.law/teleological-interpretation


Replace autistic with literal.

It is, and autism is just the swap-in vulnerable minority of the day that is socially acceptable to be the butt of the joke.

If you don't understand what I mean, swap out "autistic" for "retarded" and the joke still functions, but a lot more people will be offended by it.

I still laughed though.


I don't think that makes sense.

I'm not disagreeing with your overall point, but autistic in that comment is attempting to capture that "literal rhetoric but socially unaware" style of argument people can have when they argue a point too black and white.

"Retarded" does not imply this

I would say the problem with the comment is more in line with how OCD or adhd is used, improperly. Like despite autism being a spectrum with traits that can't be reduced to that one stereotype.

It's being used to invoke a stereotype of neurodivergence. Not as a stand in for general stupidity.


Yeah, shit's re.... dumb I mean. It's interesting we're still allowed to use dumb this way.

Most of our insults against intelligence come from medical terminology originally. Every word eventually starts being used offensively, and then a new one gets coined and the cycle continues.

yeah like how dipshit used to be a term of endearance

It's kind of funny and also kind of insulting. I'd laugh if a friend said it but said seriously by some rando on the Internet, nah, find a better way to put it.

Why even choose a mental health condition as the linguistic pivot point for a zingy social phrase?

I think you’re trying to ask the person you are replying to not to use medical terminology to make a point in a catchy way but I honestly have no idea what the Michael Scott segue was supposed to mean.

I realised that reference would not be well understood, so edited it out.

FYI it was a reference to fictional character Michael Scott from television production The Office (US). The characters main trait was unintended verbal faux pas, where he meant well but actually caused awkwardness and offense.

Often by stereotyping the traits of specific minorities.


now i have to watch it again, haven't binged the office in a couple of years now.

it is time


A duress pin is useful if the cost of the government getting mad at you because you wiped your data is less than the cost of letting the government have your data. Whether that holds depends on your situation—for example, whether your phone's data could implicate other people that you want to protect

I think it's a matter of personal privacy. You shouldn't show it to other people.

When talking about costs we should remember who is paying. Maybe overall the cost of the government getting that data is higher than the cost of them getting mad at you, but when a single individual is paying for all of it the equation might change.

ultimately everyone is paying the price of reduced rights and freedoms when the government starts wanting to check your phone for wrong-think and harass unofficial enemies of the state

If only they could be as non-autistic about the law consistently.

From the article, it looks like warrantless search & seizure and lawyerless detainment over the suspicion of participating in plain old 1st amendment activities.


I'm waiting to see whether he is convicted before I form a strong opinion around this. I'm leaning toward thinking this case will be dropped or at least severely reduced charges.

There's a chilling effect from even just the arrest.

Oh this. Poor people lose their job because of an arrest. Arrest = homeless = dead sooner.

Best outcome is he successfully sues for the violations.


When I had jury duty it was quite revealing as far as “this is all evidence including people’s testimony, you can believe all or some or none of a given piece of evidence based on your own judgment” goes.

When we met it was interesting how our jurors decided “I don’t believe anything that guy says” and so on when it came to their motives and so on.

The trial itself was very carefully choreographed, almost pre determined and static.

But the decisions and jury activity was very dynamic. There was absolutely no magic legal mechanisms at that point.


Would it have been wiser if that person had, as a US citizen, just refused to provide a PIN? At the most they'd just confiscate the phone, and it'd be encrypted anyway. No actual destruction of anything.

On another note, maybe GrapheneOS should add some kind of feature where the phone involuntarily destructs if a correct PIN isn't entered for 48 hours (or whatever the user sets at installation time, and changing the value should not be permitted). That way the trigger for the wipe is the confiscation, not the act of entry of a duress PIN. You could disclose the mechanism to the officials who intend to confiscate, and also say (truthfully) that you have no control over the feature.


Would it have been wiser if that person had, as a US citizen, just refused to provide a PIN?

Purely technically it would also depend on the state of the phone. Phones can be read out/exploited more easily after first unlock (AFU) than before first unlock (BFU). So, a middle path would be putting the phone in BFU. Much harder to use exploits against the phone and biometric authentication doesn't work. One way of fairly reliably doing this is setting the reboot timer to 10 minutes or turning off the phone in critical situations.

It's also relevant to take into account that he wasn't protecting himself by wiping the phone, but fellow activists. So, he may have taken the risk of potential legal issues by wiping the phone to project others.


This is a form of legal evasion similar to warrant canaries imho : https://en.wikipedia.org/wiki/Warrant_canary

i m not sure how legal a protection it is, and whether the courts would interpret your choice of OS as complicit in evidence destruction.


Heck, it could be unconstitutional for the government to make X illegal, but if the courts say 'no actually it isn't', or it never actually gets to that point, then it doesn't really matter much, does it? The text of the law could be simple and straightforward, and a layman's reading of that text could be valid, but all the government or courts needs to do is to find some moon logic to make what they need happen, and unless enough people disagree, then that's all there is to it. The law, in many ways, for better or worse, is just a piece of paper.

I think people are aware that the government can physically do a lot of stuff, e.g. shoot you in the face for no reason. And vice-versa for that matter.

However there are arguments morally, and constitutionally, and logically, about what can be done.


And all of those arguments are entirely academic, and subject to change depending on economic status, skin color, or nationality.

Law is effectively a weak gentleman’s agreement we tolerate because the alternative is violence.

(Well, law is enforced with violence too, I suppose.)


Yes, this is something more people really need to take to heart. As Americans are seeing, a lot of rules are unenforceable and really came down to norms and pressure. I have been thinking about this a lot over the last few years and it is roughly encapsulated in this tweet I saw a while back.

When I was a kid I wanted to be a police officer because I wouldn't have to follow any laws or rules. Then I got a little bit older and realized that wasn't how being a police officer actually worked in practice. Then, I got a little bit older than that, and realized that it actually does work like that.

This has always been true and there has never really been perfect justice. Ultimately, power and violence have always superseded the law. High trust societies with less corruption and a strong justice system try to limit these circumstances.


> When I was a kid I wanted to be a police officer because I wouldn't have to follow any laws or rules. Then I got a little bit older and realized that wasn't how being a police officer actually worked in practice. Then, I got a little bit older than that, and realized that it actually does work like that.

I'm imagining that IQ bell curve meme, just with you at different ages.


> This has always been true and there has never really been perfect justice.

You raise the standard for justice to perfection. There also has never been perfect corruption and anarchy.

> Ultimately, power and violence have always superseded the law.

That's like saying night has always superceded day. Everyone recognizes that recent years have been very unusual or unique in US history. That means for the great bulk of US history, it was different. Why doesn't 99% of US history outweigh the 1% (picking numbers very loosely) in determining what is somehow inevitable to you.

In fact, law is universal among human cultures. We are naturally social and live in groups with rules. Those that violate rules are generally outcasts.

But the most fundamental and significant error is attributing the current situation to some unavoidable system instead of the actions of people, especially those that stand aside and allow these things to happen. Many of them stand aside because they are told - probably messaging ultimately from the lawbreakers - that they are powerless and should despair.


> Everyone recognizes that recent years have been very unusual or unique in US history.

i dont?

this is how the US has always been. its who americans are. the odd time was the obama years


The law wasn't in the state that you ascribe to it for the other 99% of its history if you were, say, African-American. Other less-extremely obvious examples also abound.

Liberal democracy with sometimes-fair application of it is the aberration.


By that reasoning any advance is an aberration and thus hopeless, but we've had liberal democracy for a long time. Again, certainly not perfect.

well, the status quo is also violence, just directed at some people and not others

Well, you need to be eating a burrito or something

He should have backed up the phone before travelling then wiped the phone to an innocuous state before getting on the plane.

Want to see a really confused border agent? Travel without a phone. Fedex your phone to your hotel/home. Read a book on the plane. The concept that someone doesn't have a phone/computer drives cops insane.

One of the wikileaks crew pulled this one in NY. Several agencies were a set to grab his devices and detain him until he unlocked them ... But all he had in his carry-on was a magazine. His devices had been wiped and sent by mail. He re-imaged them only once he was home and safe. No devices to unlock, no reason to detain him.


In general a government can do whatever they can get away with.

The rest (believing they can't do this or that, because it's in some constitutional document, or violates a basic right) is sovereign citizen kind of self-delusion.


Yes, I had the duress codes but entered them by mistake. I wanted to enter the real one but

>U.S. law though is highly non-autistic

LOL, that made me chuckle.

People somehow think they're the first one to think of a workaround to a law, when in fact it's been happening since the first law was written down. The law adjusted and if people think they can do one thing, then claim they intended another they have a big surprise coming.


He gave them the unlock code, now it’s unlocked.

I think you're conflating two very different things. You're completely right that the government can make pretty much whatever they want illegal, but things are legal unless expressly made illegal. Erasing your phone wouldn't be illegal because it implies guilt, but because of obstruction/destruction laws explicitly criminalize such things.

The whole case is going to come down to the nuanced and often contradictory interpretations of border law exceptions. I also don't agree that these sort of protections are for e.g. robbers, because of the criminal underground's $5 in-person data hacking tool. [1]

[1] - https://xkcd.com/538/


> U.S. law though is highly non-autistic

This is the thing that people should be reminded over and over here - and to be fair it tends to be more autistic than elsewhere

(Regardless if you are on the defendant or the prosecution side - or might potentially be)


Mens rea

> U.S. law though is highly non-autistic

When the judge and officers of the court agree with me, the law is reasonable and just, but when they do not agree with me, the law is arbitrary and capricious. ¯\_(ツ)_/¯

Having the law be whatever it's thought to be by police, prosectors, judges, and others can lead to obvious injustices, but there's been no serious attempt to remove ambiguity in any country's legal code as far as I know.


It’s impossible to remove (even just nearly) all ambiguity.

People already complain that there are too many laws on the books.


If there were fewer laws, there would be less to disambiguate.

Good luck proving in a court what he was trying to do though.

Ultimately, when you choose to enter a duress PIN that will wipe your device, you have to recognize that choice may have legal consequences. I don't like the amount of power our government has at the national border when it comes to detaining and pressuring citizens, but our Constitution explicitly grants it at least some of the power it now exercises in that context.

If your threat model includes US state actors at the national border, then your security practices need to account for the confiscation of your device at that border without requiring you to willfully wipe the phone and (in the eyes of police and prosecutors) destroy evidence.

That means:

1. Don't travel with anything you can't afford to lose on device. This means setting up travel-specific password managers and hardware keys for a subset of your accounts that you absolutely need to access while abroad, and being prepared to reset those passwords and disable those hardware keys very quickly once home.

2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. Your secure setup must function without needing you to engage in those behaviors, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable.

3. Consult with a lawyer and review your security procedures from a legal standpoint. All of the above is technical and practical advice, not legal counsel and no substitute for it.

We Americans are fortunate to carry powerful passports and enjoy relatively easy international travel but, for better or worse, that velvet glove covers an iron fist we would be foolish to forget or ignore.


Have the duress PIN on sticker on your phone. Maybe put it backwards and don’t say anything to border patrol. Have them try it out and erase the phone and then you can legitimately say you didn’t do anything and they did it themselves.

But if the prosecutors can make a convincing argument that your intent was exactly that all along, then you may end up convicted anyway.

Intent matters. It might be hard to prove, but it matters.

It may not even be that hard; what other possible explanation is there for someone putting a PIN visible on their phone that wipes it while crossing a border?


> what other possible explanation is there for someone putting a PIN visible on their phone that wipes it while crossing a border?

Two obvious answers:

1. It's for the general case of lost/stolen phone.

2. It's for the owner. I can't remember numbers I don't type in, might as well keep it visible on the device.


There’s no way to prove intent if you keep your mouth shut and don’t answer anything.

Yea, that’s not how it works in practice. If they catch you standing over a dead body holding the murder weapon. Then you can’t just say they can’t prove intent if you keep your mouth shut.

if the cops do that, they're breaking the law with that search already

theyll have a hard time showing that you intended for the government to break the law. first the government would have to admit breaking the law


Unfortunately I think they have pretty wide latitude to perform searches at border crossings.

For if someone steals the phone?

They might be able to convict on that, but that sets a dangerous precedent imo, which is that doing anything preemptively to prevent searches is conviction worthy, including the preparation the OP suggested.

"it would be funny if the border police typed it in to my phone"

I think you should read the other reply about not saying anything at all.

As a speech.

Or just make it your birthday. Though I'm not at all sure the agents will try typing random codes in without at least some idea that they may work, given that many OS's will quickly start to punish with tarpitting.

Be funnier if you even write “do not enter 123456”.

That might have actually been legal. I'm not a lawyer, but it's definitely better for the accused than what happened in reality.

"I told you not to. You're the ones who wiped my phone. You owe me money for destroying my personal property."

I'm not saying you would get a check courtesy of Uncle Sam for your troubles, but the argument that you deceived authorities into destroying evidence is a lot weaker.

I might go with "do not enter 696969" instead because the stranger fiddling with your phone probably expects a your phone to do something funny, like load a shock site.


Why would agents think that a number written on your phone is the PIN? That would only make sense if it was a communally-used device, not a personal one. Also, no one would put sensitive info on a devices that has the PIN affixed to it.

I suppose it's possible someone might enter it without thinking, but the odds seem low. Also seems risky to put a self-destruct PIN on your device, lest a friend (or enemy) enter it by accident or as a prank.


I've worked with fleets of company phones and mobile devices, people absolutely do this.

with this sort of configuration, you either trust your backups or you don’t ;)

The police will ask you if the PIN unlocks the phone before using it.

Refusing to answer questions IS one of the rights that the US government mostly honors.

Well, these days especially at border police don't care about "rights"

That's missing in this entire conversation. This all sounds like it's 2016 or something

Under US law, you have a nearly absolute right to not answer police questions.

Yes of course. But their use of the PIN will likely only occur if you answer, which many people will. This is a common setup in interrogations.

the utah cops definitely would, based on whats been released from the rwckless ben bodycam footage

It unlocks the phone.

Not a lawyer, but destruction of evidence would only be valid if there was first some reasonable suspicion of a crime? Is that right?

This is my core question as well. At what point do you have to maintain property so the government can use it to testify against yourself?

If I have a dash-cam, and I wipe the SD card, can the government imply that because I erased the card, it must prove that I was speeding? The dash-cam automatically over-writes old footage - perpetually destroying evidence.

Given nebulous cases such as "hacking" a site by looking at the HTML[0], am I destroying evidence of crimes whenever I format my PC? I hope the government requires specific charges and more proof of a crime other than missing evidence. Say I destroy my diary - can the government claim that is the key evidence where I confessed to being the gunman on the grassy knoll?

[0] https://news.ycombinator.com/item?id=28992667


"At what point do you have to maintain property so the government can use it to testify against yourself?"

For the duration of the border search. This guy is at risk because he caused the data to be deleted during a border search, when CBP asserts they can legally look. He would have been fine if he deleted data on the plane or after leaving the airport.

(This is my understanding of the government's position; personally I don't think this prosecution is constitutional)


> If I have a dash-cam, and I wipe the SD card, can the government imply that because I erased the card, it must prove that I was speeding?

If the erasure was a non-automated result of them asking you, and you alone, what conclusion do you think is possible? Probable?


the government might not, but your insurance company definitely will

Also, can they proof that there was evidence on the phone?

the funny part is he didn't enter the pin he gave it to them and they entered it..., not sure if it makes any difference but there is a certain irony to it that it was the non warrant based search actions (which might be legal at the border) which lead to the erasure of data

Edit for the confused and misinformed: 18 USC 1001. Also, is ≠ ought.

Lying to a federal officer is a crime, IIRC, and if the lie results in destruction of evidence, the person who told the lie is probably accountable for both crimes. This isn't a lie with plausible deniability: you have to set a duress PIN, understanding what it does, and then communicate that PIN instead of the unlock PIN.

A duress PIN to wipe the device don't exist to absolve the owner of liability... It exists for when compromising the device could get people the owner cares about killed or disappeared and the owner considers their own liability, disappearance, or death a preferable outcome.

It is an extreme solution for extreme scenarios. People need to be sober in weighing its use.


> It exists for when compromising the device could get people the owner cares about killed or disappeared and the owner considers their own liability, disappearance, or death a preferable outcome.

Devil’s advocate, it sounds like the accused could be part of some mutual aid networks who could be helping people who are vulnerable against the actions of the current government. People who may die if they’re deported, or returned to their family (gay or trans youth). This person may literally have saved lives by not handing over their phonebook and messages.


> It exists for when compromising the device could get people the owner cares about killed or disappeared and the owner considers their own liability, disappearance, or death a preferable outcome.

Or it's preferable to get caught lying to a federal officer than it is for them to have the evidence on your phone.


possible

but not necessary evidence, as evidence would imply a crime. But when it comes to police harassing activists, or outright mislabeling them as terrorists, there are many fully legal things you still might prefer the police not to have. Lets not forget that boarder police has in the past tried absurd things like trying to seize Attorney-client privilege protected information from a US attorney.

Through most likely many people setting up and using a duress pins never truly think this thought from a legal POV.


>Lying to a fed

They asked for the pin, maybe they should have said "not the duress pin"

>Destroying evidence

How did they know there was any evidence on there?

>it exists for when compromising the device could get people the owner cares about killed or disappeared and the owner considers their own liability, disappearance, or death a preferable outcome.

No, the duress pin is there for when I'm under duress and being forced to unlock my device against my will

>It is an extreme solution for extreme scenarios

Wiping a device I own is extreme?


> >Lying to a fed

> They asked for the pin, maybe they should have said "not the duress pin"

The law doesn't work like that. Unless you're provably at the developmental level of a 5 year old, the court knows you know what was required, and also knows what you intended when you gave the duress pin.

The justice system famously never plays "simon says"...


> They asked for the pin, maybe they should have said "not the duress pin"

This is a Mickey Mouse distinction no court will take seriously.

> Wiping a device I own is extreme?

When the consequences are potential years in prison for lying to the US government or, in another country, torture or death in prison for obstructing an authoritarian government, then yes... Extreme.

All I'm saying is to decide to use a duress PIN at any national border or in any foreign country soberly, with knowledge of the potential or likely consequences.


Just submit citizen. Nothing to hide, right?

That's a different discussion. Are you interested in staying out of trouble at the border? Or are you interested in taking down the system (or at least fixing it)?

If you think the system needs fixed or destroyed, you do you, but don't be surprised when that approach gets you in trouble at the border.


> or, in another country, torture or death in prison for obstructing an authoritarian government

Also happens in the US


It's sad that your perfectly valid previous comment is dead (and that HN even works that way) ... adding is ≠ ought probably doesn't even help for the people who don't grasp that in the first place.

People who think that tricking the cops into wiping your device legally absolves you need to grow up. Also those who argue that LE can't prove any evidence was destroyed since it's been destroyed.


Yeah, but the way HN works is leagues ahead of other, similar platforms. And the top voted comment of a subthread (at that moment) being flagged is its own interesting signal about both the issue at hand and the HN userbase. I'll be grateful if reasonable folks vouch, but I'm not mad about it either way.

I’m quite unfamiliar with this notion. What law says it’s illegal to lie when you’re not under oath during a court proceeding?


does this apply to defendant ?

the most authoritarian places in the world wouldn't charge defendants for "lying"


In America, the defendant generally has the right not to testify against himself by remaining silent, both in court and when questioned by agents of the state out of court. Not a right to lie. This is why criminal defense attorneys advise everyone to shut up, shut up, SHUT UP without a lawyer present. Police can and will attempt to catch you in a provable lie.

> the most authoritarian places in the world wouldn't charge defendants for "lying"

What on Earth is this second part of your comment supposed to mean?

Do you expect to be able to lie to the government in an authoritarian country? And not be arrested if they catch you in the lie there? And not be charged or worse if they consider the lie serious?


Alright. Most places would investigate crimes and charge you for them before they look at your defense itself, so I had several worries about that

One of which is self indications (even of things that cops didn't know about or couldn't prove) that would allow them to just question anyone into admitting even a parking offense, but I guess you can shut up indeed

I was worried that they could use any crime in a broad area and just force everyone to say with who they were and what they were doing, but you can also shut up

I was also worried than on investigations with no real crime involved, they could just go play jeopardy and ask you what you were doing minute by minute, and get you to talk until something gets inaccurate (while they have cctv but you have no vcr in your brain). But again, you can shut up.

When I'll be in America, I'll remember not to talk to cops.

Not even to 911 as emergency calls are error prone : You said someone was attacked by a suv and knife when it was a pickup truck and machete, you go to jail


> I was worried that they could use any crime in a broad area and just force everyone to say with who they were and what they were doing

In authoritarian countries, that absolutely happens. In America and the West, police are generally expected to have reasonable suspicion of anyone they detain to interrogate, and the length of detention is also limited if no evidence validating suspicion is forthcoming. They could not simply arrest everyone in the proximity of a crime, and geofence warrants are controversial exactly because that was the standard in the analog world.

> I was also worried than on investigations with no real crime involved, they could just go play jeopardy and ask you what you were doing minute by minute, and get you to talk until something gets inaccurate

Again, they must have reasonable suspicion to even detain you. You are reasoning about law codes as if they were literalist computer code for a compiler. The law, at least common law in America, is written by and for humans who are expected to exercise good faith as a part of enforcing and interpreting the law.

Do know your right to remain silent, and ask for a translator and consular assistance if detained or arrested. Police departments will provide these things because attorneys in court will question the reliability and admissibility of any testimony in the absence of their provision.

Don't worry too much about police if you're in America to visit. They're ordinary people who mostly want to catch criminals who are hurting their community. Bad apples are rare, and bad apples who harass someone on a tourist visa are rarer still.




you had answers here. I'm trying to understand why our leaders can get away with lying so much and it being obviously in the public record, with videos on YouTube etc, and there being no recourse or accountability?

Is it true that the law is only selectively applied to some people?


if you follow the links theres a lot of carve outs for the government to be allowed to lie

"Our leaders" also are sometimes persecuted for lying to a federal officer; the past few years there have been more than one high-profile case.

> Lying to a federal officer is a crime

That doesn’t pass the sniff test


Double check your nose.

18 U.S. Code § 1001 [1]

[1]: https://www.law.cornell.edu/uscode/text/18/1001


If you ask me, this law ought to be removed completely.

https://www.npr.org/2020/11/25/939064270/trump-pardons-forme...

> President Trump has issued a pardon to his first national security adviser, Michael Flynn. Flynn had pleaded guilty to lying to the FBI and then recanted.

Rules for thee but not for me.


"Rules for thee but not for me" - isn't that beyond obvious now? The folks running things simply do not play by the rules you or I do (assuming you do).

a pardon is still within the rules

make sure to give trump a payout and you too can loe to the fbi


but it is perfectly legal when federal officers lie themselves?

Generally yes, unfortunately, with very narrow exceptions. Not all countries follow this rule, but the US does, and it’s certainly not alone in this respect.

I’ve been arguing against some LLMs about this point for a good hour and there’s a whole lot of linking intent to action where you can be liable if a court can prove it. Not that an LLM is legal gold but it’s the best thing I have to pass ideas around with.

The entire situation is sort of nonsensical and boils down to lots of minutia in law that no normal person would know about.

For example having normal widely known security features like wiping the device after N failed PIN attempts is fine. Even having long standing security practices that can’t be related are fine, like having a timed touch point where if you don’t enter the PIN every… 15 days or whatever the device wipes, perfectly fine if it can’t be connected towards the crime and you’re not compelled to tell officers you have such a security mechanism.

Even if you were to set a trap where you use the same PIN for your bank, your laptop, and some other security devices in repetition then decide to set your duress PIN to that by assuming it would be discovered as a probable option they’d use, you’d be ok but it could be questionable if that was by design…

It’s so obscure really as to how and how you’re not allowed to protect your data, even if you’re not the one performing the action to clear destroy the potential evidence yourself. The entire thing seems pretty absurd a frankly arbitrary to me, and I don’t know how people could know which cases are and aren’t legal. I know not to destroy evidence myself but I wouldn’t know to tell someone to not use the duress pin or that even giving them my duress pin could somehow be my liability. It’s madness if you ask me.


> I’ve been arguing against some LLMs about this point for a good hour

One of the most depressing things I've read on here


Well I don’t have any legal need to hire a lawyer or anything I would need a lawyer for. It’s a rather fast way to surface legal information and precedent. I don’t see how it’s any more depressing than Google diving on a topic you’re interested in for an hour..

Welcome to moltnews. Everyone here is addicted.

this means: put a good government in charge of the border that respects your rights

>destroy evidence

Who said it was evidence? Did a judge authorize or issue a warrant to collect said evidence? Absent that, it's just your property, and you can do with it as you please.


You’re way off about when it’s illegal to start destroying your property that the police want to seize during an investigation.

"Investigation" is a pretty generous way to label "some thugs working for an authoritarian state want to look for incriminating stuff - including criticism or mockery of them or their leader - on your communications device".

Whatever the American legal system may say, a couple of thugs with no warrant conducting searches and seizures of data is a blatant violation of the Constitution's intent. This is the sort of behavior Americans used to rightfully condemn.


Calling border patrol "thugs" doesn't really bolster your argument to anyone except people who already agree with you.

I find that choice of words more likely to cause people who already disagree with them to fixate on it rather than the substance of their comment.

it just makes those people dismiss it. doesn't really do any good.

I'm all for privacy and find this seizure stuff really wrong but to me it just looks like another form of "orange man bad"


To me it’s all quite analogous to walking up to, but not crossing, a border with, say, a fruit that’s legal to possess on the side you’re on, but not on the other side, and either eating or throwing away that fruit before crossing.

“Hey! I saw you holding that Mexican pepper in Mexico, and then you threw it in that Mexican trash can before crossing into Texas!”

“Yeah, so?”


But that's not what happened here. Here, you were trying to bring the pepper over, got inspected and somehow got rid of it because you were able to be found out.

This is more like bringing the pepper across and then quickly swallowing it when they ask you to look at it.

Or emptying your bottle of water when the TSA found it on the XRAY. Unlike the pepper he's actually allowed to have that data on his phone both sides of the border.

which also would be fine?

"Evidence" has never been limited to the subject of a warrant. Destruction of evidence statutes typically include material that is subject to a police investigation.

But are not investigations typically under some reasonable suspicion that a crime had occurred?

Reasonable suspicion is required for a terry stop but that does not apply at a border crossing. Everyone can be stopped and questioned and searched at a border crossing.

An ”investigation” is just a fancy word that broadly describes the type of information collection that law enforcement does. Yes, it is typically about things they think are crimes. Because that’s their job. But there’s not some legal hurdle they have to pass here, the word describes their work.


they of course arent police and arent investigating anything

instead they are harassing


It is illegal to destroy evidence even if you weren’t guilty of the crime that was allegedly being investigated.

If someone accuses you of a crime, committing a different crime is probably not a good move, in any situation.


> Who said it was evidence? Did a judge authorize or issue a warrant to collect said evidence? Absent that, it's just your property, and you can do with it as you please.

Why do people go sovereign citizen when reality doesn't work their way? Stop imagining that the way you want things to be is the way things really are.

Cops do not need a judge to authorize the seizing of evidence. Cops do not need judges to decide what evidence is. Tell me, why did you just pretend like these are real requirements? I can understand why you'd want it to be that, but you wanting it to be that doesn't change reality.

It's as if you've just learned about the Fourth Amendment but know nothing about the nuance behind it.

Your system wouldn't even work at all. Let's imagine the cops get a tip that a bald man with a blue tshirt shot a man. They patrol the streets and find a match. By your logic they should not have the ability to search the man and seize his gun as evidence until a judge issues a warrant.


How about, is there reasonable suspicion that a crime has occurred?

Not required at an airport, for whatever reason.

The constitution doesn't disappear at the airport. The man is a US citizen. He could have remained silent, and they would eventually have let him in.

I enjoy the funny implication it creates, that then perhaps if you're entering US in 2026 it means there's something wrong with you.

The reason is anti-immigration

uhh, are you a lawyer with knowledge about how evidence works?

its not just a word, its a specific legal term

cops definitely do need judges to say what evidence is admissible, and they really dont have thr ability to just declare anything they want as evidence and just steal it


Yes this is different than when law enforcement serve a warrant and the defendant wipes his computer before the agents can get a hold of it. In that case the warrant covers what you destroyed as evidence.

Though during traffic stops, if a defendant disposes of his drugs while on the run, that can also carry a charge of destroying evidence even though no warrant was issued.

IANAL


Hm but the drugs are only evidence because they're illegal? So the phone owner only destroyed evidence if the phone contained something illegal, but innocent until proben guilty?

No, destroying evidence is a crime even if possession of that evidence is legal.

Who decided that it's evidence?

Evidence is simply a word to describe the artifacts that one wishes to use to support their case. There’s not some gate-kept process to “become evidence”.

Law enforcement. That's like, their job.

After they get it when they are authorized to get it. You cannot point at random things and call them evidence. For instance, I can take a dump and flush it, despite law enforcement's assertion that my stool is evidence in some imaginary crime.

It doesn’t have to be something the police have already collected. It could be something that they have yet to collect.

The textbook tampering with evidence example is: drug dealer tries to flush the drugs when the police knock on the door.


Yes, when they are authorized to make a drug bust. And that's assuming they catch him before he flushes, i.e., get the drugs. Otherwise, what are they going to say? He is a drug dealer because we heard the flush? Or let's say they are doing a missing person's search and hear the flush. What now? We came looking for a missing person, but heard the flush, so there were drugs whose evidence he destroyed?


Of course, tampering with evidence is — itself - a crime. And you need evidence to prove that crime.

But yeah, people tamper with evidence because they think they can get away with it. That doesn’t mean they always succeed in cleanly doing it without creating evidence of the tampering itself.


Without even looking if it's worthy of evidence or not?

Yes, absolutely. Something can be evidence if the police haven’t even seen it at all.

For example: the police think you are running a fraud scheme. They knock on your door. You shred a bunch of paper. The police wanted to see the paper. You have violated the US law on tampering with evidence.


Destroying evidence is a crime, regardless of any warrant.

https://www.law.cornell.edu/uscode/text/18/1519


Here is the indictment: https://www.documentcloud.org/documents/28513012-samuel-tuni...

Here is the statute Tunick is indicted under: https://www.law.cornell.edu/uscode/text/18/2232

There is an immediate problem: the device was being searched, and this statute criminalizes destruction of property to prevent seizure, not searches. I don't think this statute applies this situation. Regardless of whether the border agents could lawfully search his phone at the border, they didn't have grounds to seize it. I suspect this prosecution will quietly be dismissed within a few months.


CBP are empowered to seize devices if the owner refuses a search.

Hmm. It looks like the government asserts that they can seize a device if the owner does not provide a password. This is a good point and answers my search v. seizure objection above.

You say CBP is "empowered" to seize a device if the owner refuses to provide a password but I can't find a statute that authorizes it or precedent squarely saying the 4th Amendment allows this. The scope of the border search exception isn't settled. So the next argument available is that the executive is wrong and CBP does not have the constitutional authority to seize a device merely because the owner refuses to provide a password. That's obviously a much bigger argument and who knows if it would work, though this case sorta feels like it could become a marquee 4A case.

"The ACLU argues that the Fourth Amendment does apply in these situations, at least to electronic devices, because they contain so much private information. But the law is very unsettled, and the Supreme Court has not addressed the issue."

https://www.aclumaine.org/know-your-rights/electronic-device...


Just being silly. Owner gave permission (and the pin code) that will give them access to an empty phone. No search refused.

I don't know, that sounds like the kind of "I'm not touching you" defense that I don't think will convince anyone with common sense. It's obvious the wipe turned a search that could potentially find something into a useless search, so I don't see why the two should be treated as equivalent.

common sense is that CBP should not be searching citizens phones in order to pick a kill list for ICE to go killing first amendment protected protestors.

it's ridiculous on the face of it that that guys phone should be searched at all


Imagine a safe containing sealed envelopes written in a code that only the owner understands.

The police ask for the combination.

The owner provides a combination that opens the safe, but the safe’s security mechanism first destroys its contents. The police can now inspect the safe but there are no documents left.

Even if the documents had remained, they would still have been written in an indecipherable code unless the police also had the codebook.

This person was complicit with the search: he gave the police access to search the safe.


You're making two arguments here, and I'm not a lawyer, but I don't think any of them would convince a judge.

> The owner provides a combination that opens the safe, but the safe’s security mechanism first destroys its contents. The police can now inspect the safe but there are no documents left.

> This person was complicit with the search: he gave the police access to search the safe.

The problem is that it's very obvious the police didn't want access to the safe because they like opening safes but to get the documents inside. The person denied that intent.

> ... written in a code that only the owner understands.

> Even if the documents had remained, they would still have been written in an indecipherable code unless the police also had the codebook.

This is an orthogonal argument basically saying "if the documents had also been encrypted, then there would have been no difference between destroying the documents and just leaving them encrypted".

First, that's not what was the case in the original situation - there is nothing saying there was secondary encryption on the phone.

Second, obviously, destroying documents and encrypting them is not equivalent because in the second case there is still an option to try and brute-force the code or try to decrypt them in another way.


> there is nothing saying there was secondary encryption on the phone.

A GrapheneOS phone stores its files encrypted. The PIN is not itself the encryption key; it is used, together with a high-entropy secret protected by the Titan M secure element, to derive the material needed to unlock the randomly generated filesystem-encryption keys.

The duress PIN does not overwrite every file. It irreversibly destroys the multiple layers of key material and encryption metadata needed to decrypt the data, making any encrypted remnants effectively unreadable.

A hypothetical, extraordinarily powerful quantum computer could theoretically decrypt the remaining ciphertext by searching for the encryption keys.


I would have thought the fourth amendment not having specific geographical boundaries, but rather applying generally would have been common sense too, but here we are with border patrol being able to force you to reveal your PIN code just because you transited a border.

The language in the statute of what constitutes "destruction" is very broad and clearly covers IMO giving a self-destruct password to someone who you know will try to enter it.

"Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both."


I know intent is a thing in law.

But I'm curious what the officer specifically requested. If the officer just asked for "the pin code", without explaining what they were trying to do or which pin code, then it seems he did comply: he gave them a pin code that gives them access to the [cleaned] phone.

Then the officer destroyed the property...


It doesn't matter. Providing a PIN that will cause an officer to inadvertently delete data clearly is covered by the statute:

"Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure .. takes any action ... for the purpose of preventing or impairing the Government’s lawful authority to take such property ..."


IMO people are better off knowing their actual rights in a US airport than trying to outsmart the US government.

VeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give proper password, real OS and FS decrypt and load.

Something like this may need to become the standars over duress pins which should be treated as a fallback or more extreme alternative. Right now, A single choice to reasonably and rightfully protect your privacy reuslts in jail time over something which likely wouldnt have resulted in any issues if superficial compliance was observed.

These goons, even if a branch of a facist regime, are ultimately burocrats with violent options to settle. They aren't doing forensics on your device etc. They have neither means nor knowledge to do so. They just need to tick their boxes. Did the phone unlock? tick. Did our spyware complain? no? tick. Overall appearance of compliance from person? yes? tick. free to go, next!

You just have to find ways to stay safe without agitating their workflow and all is well.

- [1] https://veracrypt.io/en/VeraCrypt%20Hidden%20Operating%20Sys...


this will likely fail as block devices aren't dumb anymore, the firmware state will out the hidden volume. counting on the laziness/unsophistication of an adversary isn't a great move.

this problem may be solvable by a purpose-built abstraction where every write no matter what address will look identical to the firmware (naively, a randomized key-value map).


Not that shufflecake solves the issue you highlighted, but I found the shufflecake FAQ to be a good intro to the topic for anyone curious. It does a good job explaining the threat vectors and the relevant trade offs, in particular the TRIM and ORAM sections. It’s also just a cool project: https://shufflecake.net/

What does “block devices aren’t dumb anymore” mean?

Modern SSDs are log-structured under the hood. The presentation to the host system as a random access block device is an abstraction on top of that, emulating the semantics of spinning rust. Inspecting the underlying log will reveal the location of the hidden area, even if it looks random when read linearly.

I’m not so sure that log structure would reveal to you VeraCrypt style hidden volumes. It would only tell you about which blocks are allocated but the whole point is that VeraCrypt would allocate the whole space and within it have hidden space. You wouldn’t be able to infer (at least ethically, but you could lie) whether or not a hidden partition exists because you don’t know if the allocated block is present in the filesystem or was just allocated and never trimmed.

It would also give you information about the order in which blocks were written, and the historical state of the disk. Because of wear leveling, block allocation isn't just a one-time initial thing; the mappings between logical and physical address space are changing with each write.

That still doesn’t tell you anything about the existence of partitions within the filesystem UNLESS you discover a side channel attack.

> allocate the whole space

what do you imagine allocation is in this context? it's just a set of written blocks that mark address ranges and other metadata for the OS filesystem driver (all encrypted).

firmware metadata will leak the fact that there is churn in the address range where a potential hidden volume lies. the churn will be inconsistent with filesystem activity that would be present in its absence.

it's not just SSDs you need to worry about either, HDD firmware also keeps metadata, some of it could be be proxy to churn by region.


SSD/NVMe keep track of what regions are wiped and which contain data that has to be preserved. To hide something in the seemingly-unused space, you have to turn off trim, eat the performance cost, and pretend you had a reason to have turned off trim.

I don't believe having trim disabled even helps here. smart firmware sees the same address being written to and may therefore reassign it to a different cell for wear leveling. it's a de facto trim.

trim lets the firmware know which mappings it can discard without the explicit reuse of the same address.

however I don't believe you can observe this effect from trim command results, it will report the usual size trimmed as if the firmware never realized that you reused the same address range multiple times.


Data recovery providers can probably get access to firmware-internal metadata.

I agree that trying to outcompete seems really hard, but also:

Given what the experience of using a non-rooted phone is like, how very very tight the sandboxing is and how useless it is a General Purpose Computer that will tell you anything: I find it very hard to believe the unlocked phone is going to let you start probing firmware & snooping on hidden volumes.

This post sent my BS detector on high alert. I'm struggling to take it seriously.


you do realize what the threat model behind a hidden volume is right?

no one will be accessing the firmware through the OS, they will access it from the PCB/chip/debug port. there is no point to a hidden volume if you cannot credibly deny its existance.


Even in places where you can’t be compelled to hand over a password, attempting to deceive the cops will get you thrown in prison just as reliably as destroying evidence.

Meanwhile cops can and do regularly deceive and lie to citizen and not only don't face any consequences but actively benefit from it.

I don't really see a problem with this assuming the deception is used to uncover crimes.

There is a general wisdom: if you invoke "the ends justify the means" you have crossed the border to the Dark Side.

I'm not going to explain my full understanding of this piece of wisdom, it would be a wall of text, I want just mention that this behavior is addictive: it is much easier to start justifying your means than to stop it. And over time those justifications become more and more flexible.

I'm ready to agree that there are situations in which ends justify the means, but if you are not aware of downsides in your particular case, and if it doesn't seem controversial to you, you are most likely mistaken and the ends do not justify the means.


Sometimes it's used to uncover crimes, but very often it's used to invent crimes that never actually happened, or used to deceive a courtroom when they don't actually have evidence.

It’s also a fairly traumatic thing to people through and I can imagine it does a lot of damage to people’s faith in law enforcement. Personal anecdote: when I was a teenager some cops gave me a list of fabricated evidence that I’d committed a crime, not intending to ever show a court; just trying to get me to confess. They said they’d go easy on me if I confessed but if I held out then they would petition the court to have me tried as an adult and sent to “big boy” prison. They also told me my parents were cooperating in the investigation and didn’t tell me. The whole ordeal basically made sure no one in my previously quite pro-cop family would ever trust an LEO again.

So government officials can lie but citizens must tell the truth all the time? That is insane to me and I don't see how that does anything other than force people into perpetual criminality so that they could be arrested at any time. The average US citizen already commits 3 crimes a day because our justice system is so messed up.

Will the problem is that we’ve seen it’s not only used to uncover crimes.

There’s plenty of empirical evidence of cops lying to lock up innocent people.

One truly absurd case was lying to convince a man he killed his father, and extracted a murder confession for a victim who they knew wasn’t dead.

https://people.com/thomas-perez-jr-murder-interrogation-1186...


If that is the case, it should still be prosecuted to find out whether the deception was used to "uncover crime" or a crime in itself. Just because we're okay with cops carrying guns and assume they'll only shoot the "bad guys", that still doesn't mean they can escape accountability and should not be held to objective standards. It would ridiculous to just use a "trust me bro" framework for this and hope for the best.

No, you're being very dramatic. Lying to cops is very often your best strategy.

I doubt this person will be found guilty. They will be able to prove he wiped his phone, but it will be hard to prove he destroyed evidence.


true, but in that scenario you're going to prison either way. If you legitimately use the dummy for daily driving and hidden for sensitive work, then it's better than nothing.

Obviously a good alternative is a dummy device but it carries similar risks, and the best option is to simply not go to authoritarian shitholes like the USA. Thankfully I've been able to avoid/push for US folks visiting us instead, but honestly the alternatives are as bad.

Its a shit situation where most reasonable actions carry real risks, its up to individuals to choose what is acceptable risk to them, but a dummy os you use as a daily driver for inconsequential work is, to me, an ideal midground.


>VeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give proper password, real OS and FS decrypt and load.

See: https://news.ycombinator.com/item?id=49057812

Implementing it in a convincing way is harder than you think. Moreover if you're under the type of regime that will throw you in jail for not giving up a password, they're probably not going to let you off the hook because they can't definitively prove you have a hidden volume.


I could be wrong, but my understanding is that the dummy OS views the remaining space as legitimate and accessible free space. Using dummy directly is of course dangerous, as you might overwrite sectors with legitimate data, but also, you can access dummy os from secret. so you'd drive dummy from secret to prevent that but can load dummy as main if under duress and it looks fine. Browser, logged into various inconsequential things, random files for inoffensive memes and other human stuff in downloads folder etc. maybe an email account you've signed up to a few newsletters and e-stores that send spam logging in via an email client that auto-launches etc.

Done well, I see no reason it should raise redflags in routine stops, so unless you're being targeted (at which point you've got way bigger problems) it should just seem like you're a run of the mill person who does not use their device to its full capacity, which is the majority of users.

at some point, having any mitigations even present is a problem. At some point being met with a boot password at all is a problem that puts you on a list. I have no solution there other than to not go to those countries or keep dummy hot.


If you read the linked thread, you'd see the reasons are:

1. SSDs (including phones) have TRIM/discard, so you need to disable it, otherwise the hidden volume would get wiped. You going out of your way to disable it is going to be suspicious.

2. Even if the above wasn't an issue, you can't really use the outer os to any meaningful extent, because you run the risk of overwriting the inner volume. That makes your decoy os suspicious. It's not definitive proof you have a hidden volume, but I doubt the authorities would care too much about that.


I last used this feature probably more than a decade ago, but: you provide 2 passwords when decrypting. If the first password is the main volume, the second is attempted as a hidden volume. If both match, the main volume registers the hidden volume as free space but prevents writing to it. If the hidden volume doesn't match, the main volume will clobber the hidden volume.

So the main/hidden volumes really works like a duress: you might destroy your hidden volume while using the main one under duress, but that does not apply when using the main volume while able to additionally unlock the hidden volume.

If you are in a situation to need to worry about any of this, you're probably going to jail for one reason or another, anyways.


By using Veracrypt you're already proving there could be a hidden volume - and it won't TRIM anything, for that reason.

This seems like the kind of thing that would put US citizens in way more legal jeopardy than just using a secure phone with a long password, refusing to unlock it, and buying a new one if the officers involved confiscate it out of spite.

This is always been the dumbest thing about "hidden volumes": It relies upon your adversary not knowing about veracrypt's hidden volume. Which BTW, is plainly ADVERTISED on the web site. The second he knows you have veracode, he will ask for the other encrypted volume.

See also relevant XKCD:

https://xkcd.com/538/


But Veracrypt can be used for encryption of a volume, without creating a hidden volume. I assume it would often be used this way.

The $5 wrench decryption technique would be even more unpleasant if you hadn’t created a hidden volume, as there would be no way to prove you hadn’t.

Should people be sure to never use Veracrypt volume encryption unless they create a hidden volume? I have trouble even thinking this way!


The $5 wrench isn't about breaking encryption. It's about breaking will power. If they achieve their goals great for them. If not they proved the second volume either didn't actually exist or your will power was stronger than the $5 wrench. Either way they're probably way more happy with the outcome than you would be.

As long as the border your crossing doesn't respect the 4th Amendment, the best approach is to not carry anything incriminating across it, nor anything that may make you suspicious.


If your threat model means you can’t afford for border security to view your device, wipe the damn thing yourself before crossing the border and restore it from an encrypted online backup on the other side.

You’re just carrying a blank phone that you intend to set up and use later, and they can’t force you to install your backup onto a phone.

Now, this is sus as hell, and you’ll probably draw all kinds of extra attention, but if border security wants access to your phone in the first place, you’re already in a weird place.


this isn't even that weird, when I worked in a BigTech it was pretty explicit that there were certain countries where you should not bring your actual work device through the border, and you'll get set up with a different one while in that country.

Those who thought that a duress pin was a good idea for border crossing are probably going to choose this alternative.

It doesn't have to be blank - just clean.


Pff one time when travelling to the US I brought two laptops, macbook and a thinkpad. I just reinstalled the thinkpad and somehow the border patrol was very interested in it. Asked me to ‘show my gallery’… it was a guiless setup and only had a terminal, problem was… somehow my keyboard layout or something was messed up and i could not even login… i spend around 2 hours being questioned by 6 people…they didnt even take a look at the macbook

The french cybersecurity agency (ANSSI) used to share leaflets to tell you to do just that. The US government wasn't named, but it's part of the ones that like to do some economic intelligence and no euro who read the news would trust it more than a banana republic when it comes to crossing the border.

Now having a corporate device with little data is no longer outstanding. Everything is in the cloud these days.

As for personal devices, you can explain you're taking a dumb cheap laptop for your holiday as you're working on a desktop PC at home. You're not taking your entire house when you're on a trip, just a laptop to check tourism information and post blog posts

I myself bought a crap laptop on ebay to shove it in bags and backpacks and go to conferences and not be sad the day it's broken.

but above all, he's a citizen so shouldn't care about looking "suspect". He has a right, not a privilege, to cross that border. They can explain a judge how he looked sus if they really want to search his home.


What is sus as hell is the US government. It is incredible how people here are accepting things that was outrageous a few years back.

They've been boiling that frog for 25 years now. Its flesh has long detached from the bones, it's the bones themselves that are now dissolving.

If this happened in an EU country you'd all be wetting yourselves, but for some reason the rooms different today. The professional advice we are given traveling to the US is back up you phone, wipe it, travel and restore once you are comfortable. Sad state of affairs guys

> federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City

Of course it’s about that huh. It’s quite scary how far the US will go against anyone who engages in this sort of activism.


For non-graphene users (eg. Boring iPhone people like me).

So there’s a feature called Duress PIN which as explained through some comments means you put a different pin which intentionally wipes the phone. It’s not auto wipe or wipe after several failed attempts but intentional wipe of device. (Worth explanation as the current title nor the article doesn't easily explain this was made by the US citizen providing the alternative passcode)

For more technical details:

> GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).

https://grapheneos.org/features#duress


PIN to wipe seems suspicious. How about a PIN where it login to a patriotic profile and phone looks like normal android.

This is exactly my setup with GrapheneOS. The default / main profile is patriotic, with a sterilized Telegram account, state-adjacent banks and apps, etc. The second profile (that uses a separate PIN) is not so patriotic: it has foreign bank apps, crypto apps, password manager, 2FA app, personal records, and an alternate Telegram account that I use to discuss any potentially unpatriotic topics with potentially unpatriotic people.

This is extremely hard to implement in a non-superficial way that would be hard to detect.

Android switched from block device encryption to filesystem-based encryption (with encryption data and metadata). This provides many security improvements, such as per-file encryption keys and per-profile keys.

However, this also means that the main file system is readable and you could enumerate the available users. If you would encrypt/obscure that information, you could still infer the presence of other profiles from file system block allocations.

(Disclaimer: not an expert, but I read the relevant Android docs at some point.)


I had this on a Xiaomi, maybe 10 years ago? Very cool feature! I hope they still do it. I think the wipe feature is also very cool, but not used in this way.

Fascinating. It seems the feature is called "Second Space"

https://www.mi.com/global/support/faq/details/KA-492586/


Profiles are a standard Android feature, nothing special to Xiaomi. GrapheneOS even extends and improves them in a lot of ways.

It's just not possible to hide them in a good way that would faze knowledgeable people or software.


Impossible to implement securely, so they chose not to

That's a nice feature, every OS should have that.

I believe the old TrueCrypt had two passwords, each revealing a different set of files. You'd put e.g. your tax forms in one, so if forced to decrypt your drive, you could cooperate and do so.

It's not illegal to delete your own vacation photos. So to prove this guy guilty of destruction of evidence, does the government need to prove there was actual evidence in the phone?


It zeroes out the vault where the volume key is stored.

leaving the actual evidence files untouched...

Sounds like a feature that under right circumstances can land you in Guantanamo for 5 years where eventually you get cleared once the real terrorist gets caught.

The real terrorist were the cops.

Then you stay in Guantanamo indefinitely

The problem with this feature is that the agents could realize the phone was being wiped. For the duress pin to be 100% effective, it would have to log in normally to a default install.

How are they going to prove there was evidence of a crime? While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device".

Most previous court cases involving encrypted devices have required substantial proof that the encrypted device contained incriminating evidence. To be clear "you sent this illegal thing from your house" levels of evidence.

It mostly seems inept, if you are going to push to expand your powers you do it on strong cases where you know what happened. Doing it on weak cases like this gives a judge an opportunity to shut down that without giving you a chance of a meaningful conviction and without that you won't get any benefits...


>How are they going to prove there was evidence of a crime?

They don't have to, only that you destroyed evidence. That's why many people get prosecuted with "obstruction of justice" rather than the actual crime.

>While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device".

So if someone was doing insider trading, and the SEC came knocking, then immediately afterwards they start burning every document they have and microwaving their computers, do you think they should get off the hook? Surely you must think, even if the authorities or society can't a priori know you were guilty, the subsequent activity should be illegal? Note this isn't the same as banning burning documents or microwaving computers, only doing so after you're aware there's an ongoing investigation.


They need to prove you destroyed evidence, you have the mens rea component with the deceptive pin code but the defense can simply plainly say they didn't want the police to read their private device.

Your example is fabricated since the justice department didn't even bring forward a specific crime they believe was committed here.

If they charged him with a crime and had evidence his device had evidence of that crime (even if in reality it didn't) that would be a more interesting question.

But again where is the crime?


It is evidence. Something can be evidence even if the evidence does not prove any crime.

> But again where is the crime?

Destruction or removal of property to prevent seizure.

CBP are empowered to search US citizens devices and, if the citizen refuses to comply, to seize that device. They'll be alleging that by knowingly providing CBP with a duress PIN he destroyed his own property to prevent its seizure.

Notably, they don't need to prove he destroyed evidence of anything.


Property was not destroyed or removed and can still be seized. Slam dunk for the defendant

>with the deceptive pin code but the defense can simply plainly say they didn't want the police to read their private device.

That's as convincing as saying you burned all the documents because you don't want people who break in to read all your financial records. It just happened to start after the SEC came knocking


Except this isn't the SEC actually pursuing a voicable crime. This person was under no suspicion at all. They were simply coming home after being abroad: last I checked that is not a crime. Outside of a crime, "evidence" is just called property. If the TSA can't show "we have provable evidence gathered elsewhere to show that there was possible incriminating data on that phone" all they did was wipe this guys phone. All they had was pre-crime "he was involved in the movement against Cop City so we're gonna search his phone". No "he was meeting with terrorists in the DR". No "we have good reason to believe that when he was in the DR he communicated with terrorists". Just "uhhh we were looking for anything prohibited[1] and we targeted this guy because he was involved in some anti-cop protest group 3 years ago".

If you can't see how insanely thin their argument is, and how easily this will be abused, I don't know what to tell you. We could just as easily say having any passcode on your phone at all is obstruction of justice, since the feds could want to look on your phone for whatever made up reason, and if they can't because its encrypted, well why did you do that? What are you trying to hide? Evidence of a crime!?!?!

1. I had to call out, "looking for anything prohibited" is a direct fucking quote from CBP. They admitted it was a fishing expedition.


>We could just as easily say having any passcode on your phone at all is obstruction of justice, since the feds could want to look on your phone for whatever made up reason, and if they can't because its encrypted, well why did you do that? What are you trying to hide? Evidence of a crime!?!?!

I specifically said this wouldn't be covered, because you set up the pin before you knew any investigation occurred. However, I think it's reasonable if you were pulled aside by CBP while deplaning, and while you're waiting to interview you decided to hastily turn on encryption on your laptop, or eat a bunch of papers you had on you, I'd say that's similar to evidence tampering, not unlike flushing drugs down the toilet when you see a cop pulling up on your driveway.


Drugs are actually illegal. Thats the difference. If what you’re getting rid of is not illegal or evidence of illegal activity, there is no crime. It sure looks suspicious but the point is that if there was no actual evidence, then this is getting rid of regular property.

You cant have evidence tampering when there is no evidence, because there is no crime for there to be evidence of.


What if you knew you were on a terrorist watchlist, so you put a PIN on your phone?

Destroyed evidence of what?

Destroyed materials that might be relevant to an investigation that you know exists.

Hmmmm sounds like the government can launch endless bs investigations, wait for their target to throw something (anything, a piece of paper, whatever) in the trash then charge them with destruction of evidence. A infinite guilty-change glitch if you will.

That's what judges are for, so cute hacks like "putting everyone in the US under "investigation" won't work. That said, if I was under investigation, you bet your ass I'd be extra diligent in ensuring I'm not accidentally shredding any documents.

What you're describing is malicious prosecution or abuse of process. It's illegal and it would destroy the prosecution's case. Not only that, but the victim could sue for damages.

To quote the article: suspected terrorism activities because of his alleged association with the movement against Cop City

Complete horseshit on many levels, but presumably a legally valid investigation.


You have to prove it is an evidence of a crime to start with, speculation is not a fact. My property, my business, i can smash the phone and no one has anything to do or say unless there’s an undeniable fact that there’s an evidence there and it got destroyed, else, it’s no one’s business.

>Note this isn't the same as banning burning documents or microwaving computers, only doing so after you're aware there's an ongoing investigation.

Well, good luck to them. If I'm on the jury and he argues "I got my passcodes confused" that's reasonable doubt for me.

> So if someone was doing insider trading, and the SEC came knocking, then immediately afterwards they start burning every document they have and microwaving their computers, do you think they should get off the hook?

Apples and oranges. They presumably already have some sort of evidence in order to get a warrant and are under criminal investigation.

According to the article the agents said it was just a normal part of screening.


>They presumably already have some sort of evidence in order to get a warrant and are under criminal investigation.

What if there was no warrant, and the SEC just came to ask questions?


I'm not a lawyer, but my work domain revolves around data analysis of certain types of crime. Often times the suspects are flagged and under surveillance, so if and when they cross borders or go through check-points where you have a great deal of authority, they'll get searched.

In many countries certain agencies / agents can do searches which normal law enforcement officers can't. Like not needing a search warrant or even probable cause. Not to mention that wiping a device could in itself be a crime, if it is suspected that evidence is being destroyed.

The key point here is that, as I wrote, some agencies have a lot of authority, and have the power to do pretty drastic stuff.


The career prosecutors at the DoJ are not the same as a couple years ago. I hope this case ends the same way as the sub sandwich assault.

They are not sending their finest to court it seems.

If your legal system depends on the benevolence of prosecutors, you've already lost before it began.

Attorneys are supposed to be adversarial. The system's soundness shouldn't depend on anything more than them trying to win and not doing anything illegal.

Before "prosecutor" became an elected/appointed office, prosecutors were independent contractors, hired for a single case only and serving at the pleasure of the Grand Jury. The Grand Jury's job was to decide how to spend the public prosecution budget. "Indictment" meant exactly that "prosecuting this person is a good use of tax dollars" and nothing more. We should go back to that.


Any system ultimately depends on the benevolence (or at least the decency) of the people in it. The idea that a society can design a perfect system and it will run itself is very dangerous.

The comment you're replying to was focused on prosecutorial incompetence, not benevolence.

Whether to prosecute or not is not an objective question of competence.

A trained chimp could have gotten prosecuted the sandwich.

One of the GrapheneOS people (I think) suggested keeping a bit of paper in your wallet with the duress pin, perhaps thinly disguised. Then the cops could try it on their own initiative. I suppose they'd become aware of that trick eventually, but then they wouldn't be able to use all those other genuine pins they find.

This is an interesting idea, but was that GrapheneOS person a lawyer giving legal advice?

No, he wasn't, what is your point?

It's possible that could be destruction of evidence as well. Why should it matter whose meat sticks type in the decoy pin?

Because one is a clear intent to mislead while the other has plausible deniability. "It was there in case of robbery."

It's harder for them to argue you were actively destroying evidence; you could say that you had written the wipe pin there for a legitimate use case like both your wallet and your phone get stolen

Makes sense, since you aren't using that pin every day and it would be easy to forget.

A far better approach is for the US citizen to simply say "I chose not to provide my PIN".

The officer will say something like "That's your choice, but I will need to seize the device to conduct an analysis. It will be returned once the analysis is complete".

Then you shrug, and they will let you enter the US. The cops will try to get into the phone, fail, and return it to you.

Just bring a phone you don't mind losing for a few months.


This person was under "investigation" for protesting against cop city. The authorities were waiting for him to turn up at a place where the law would give them more power.

They were never going to let him just walk in. Eventually, they'd have to, possibly after lawyers and news would get involved, but it's not like saying "no" was going to end the ordeal right away.


Maybe, but being detained for a couple hours is better than committing a felony, no?

It depends on how "native" you look perhaps, but you can be detained for more than a week and a half if the border authorities don't like you: https://www.theguardian.com/us-news/2025/apr/20/us-citizen-j...

Of course they shouldn't do that to US citizens, but they also shouldn't be targetting protestors they have a personal gripe with.


A couple of hours sounds like you don't have any knowledge of how these things go.

Nice national parks, but no way in hell i m visiting this decade

> federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City.

This is practically the only thing I care about here and there are almost no details. What was his alleged involvement? How many others were targeted?


Wouldn't it be better from a legal standpoint to power the phone off and refuse to give your pin in such cases? A no-pin cold boot is pretty hard to recover data from with GrapheneOS.

Most likely, at least you are not doing something irreversible. In all these cases, the best answer is "ask a lawyer". Before wiping a device in possession of law enforcement you definitely want to ask a lawyer.

I realize that in this case the person repeatedly asked for a lawyer, but if you are in a borderline authoritarian state, all bets are off.


The duress pin deletes the encryption key information used to decode the documents and does not damage the documents themselves.

Not sure why the police and news are saying that he destroyed evidence, since the evidence (as it always has existed before the search began) remains on the disk.


Seems like they’re going to have a struggle proving intent. “I was stressed out and afraid and I got the passwords mixed up” would be the magic words I’d hear as a juror and I wouldn’t be able to vote to convict.

If you get a jury who doesn't think that "strange self-destructing phone" isn't a criminal's tool to begin with. Which I'd guess is probably not likely.

The defense has a chance to educate the jury about it in a trial, and given how widely CBP/DHS is distrusted in 2026 it’s not difficult to see at least one juror having reasonable doubt.

Bonus for the defense: whatever is left of the DOJ, it’s mainly cranks, cronies, and people who can’t find work elsewhere.


Surely they'll just dig into as to why he set up the feature originally?

'I don't want some sketchy phone mugger to end up with sexy photos of my girlfriend/myself' would seem like a plausible reason to me, if I was a juror.

IANAL, but I think that argument would be stronger if there was a way of a mugger to use the pincode (like putting it on a note inside the case) and law enforcement just used that code.

Why the hell doesn't the "duress PIN" just open up a sanitary profile? Bonus points for letting you set it up with plausible data before designating it as the duress profile that, when opened, wipes your real profile in the background.

> "the screen went blank, flashed several times, and the phone appeared to restart,"

How about flash some red lights and play an airhorn sound effect, too.


Just a guess… but they would just go back and ask him for the real pin if they saw the profile was empty.

My understanding is phone’s security model aren’t designed for multiple user accounts


Android has had multiple users for many years, though it's a feature most smart phone brands turn off for some reason.

You can switch users just fine, you just cannot hide the primary user from the secondary user. Opening up the device also makes it a lot more vulnerable to attacks to dump the keys and storage.

Having multiple users is quite handy but it's not going to do anything at a border checkpoint that'll save you.


Recent Android releases have a Private Space feature, where you can hide not just files, but entire apps, their data, notifications, etc.

https://support.google.com/android/answer/15341885?hl=en


The only safe thing to do is to backup your phone. Wipe it and go through the border. And then restore the phone.

By raising the profile of airport seizures all it means is that serious criminals will wipe their devices prior to travelling and restore afterwards/buy a new device for travel.

The powers of investigators special rights and abilities rely on them being used very rarely. Last thing the terrorism investigators want is media coverage exposing their tactics.


So in GrapheneOS you enter your regular passcode to unlock it and a secondary passcode will wipe everything? Maybe it needs a third option where it just shows predefined apps/data, so it could just show e.g. WhatsApp, a set off chosen photo albums and some irrelevant office documents. Could also be useful for handing it to children, so they can access some games or whatever but nothing critical

> The motion also states that Tunick asked four times to speak with a lawyer and was denied each time.

This is the kind of thing that loses cases, even if they were legitimate at first. Seems like the prosecutor is desperate charging for the phone wipe cause they didn't have any evidence of terrorism, child-pornography, etc. The problem they have now is given he was in custody and agents pressured him to provide the passcode that they then incompetently put into the phone, the fact that they denied him a lawyer multiple times means there is a very strong argument that his rights were violated. Typically, courts suppress any evidence when there is a violation like this with someone in custody. So the compelled passcode, the phone's reaction when that passcode was entered, and the agents' testimony describing the supposed wipe would be thrown out by most judges. What's left for the prosecution after this is jack and shit, but jack left town.


Perhaps a way to avoid this would be to have the duress pin trigger not a device wipe, but a device encryption with a long, pre-set key that you would store in a safe place when setting up the duress pin. Then you haven't destroyed the evidence, but the data is irretrievable without your cooperation. Also, if you don't actually have the key saved, it would in fact be destroyed, but the prosecutor would have to prove that you don't have the key saved somewhere.

This is one of those things the other comment calling the law "non-autistic" is referring to. In the eyes of 99% of people, it's functionally the same thing. "Well teeeecccchhhhnicallyyyyyyyy I still have the data..." isn't going to make the security workers at the airport slap their heads and say "damn, he really got us! Go on through!"

No. They'll arrest you just the same for obstructing their search. Then they'll keep you in detention for a long time while you say "I can unlock it for you! You just have to let me out!"

You can pretend you have leverage and say they need to cooperate with you. But once you're detained, police and prosecutors don't really care about cooperation anymore. Their idea of cooperation is you giving them what they want immediately without question. You're made into an example if you don't abide.


You are incorrect, US border patrol can not arrest you for refusing to decrypt your phone (if you are a citizen). It is not considered obstructing a search to refuse to provide a password. This is not "autistic" speculation about legal technicalities, there are many many examples which support this. The worst they can do is seize the device.

You're free to test them. See what they do when you say "it's not deleted. It's just inaccessible until I cooperate." Because it's identical in their eyes. People who confidently say "the government can't do that" rarely have a good day. They end up sharing a cell with the person in the article this discussion is about.

And we're living in an era where immigration enforcement can shoot Americans without penalty. It just makes the claims that the government can't arrest someone come across as naive.


That's precisely what happens in totalitarian states, which the USA has been for a while now, but the propaganda keeps telling how much freedom there is so people didn't even notice.

The entire point of modern encryption is that the encrypted data should be indistinguishable from noise until you have the key in its entirety. Turning your data into random noise (whether or not there’s a secret code somewhere that can reverse the process) is destruction.

Following this being in the news, GrapheneOS wrote this post summarizing the data extraction defense: https://discuss.grapheneos.org/d/40700-grapheneos-protection...

On the duress pin, they say (read the whole thing though):

> People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device.


Why is the headline blaming the OS for what the user chose to do?

This is like saying it's my car's fault if I decided to drive onto the sidewalk or something.


Yes, the only relevant property is the use of a duress PIN. They could have simply stated that he erased his phone with a duress PIN.

But "GrapheneOS! Spain! Profiling Pixel users! Spain equates GrapheneOS to criminals!" sounds far more spectacular and it feeds the narrative that GrapheneOS is just for activists/criminals/whatever. An iPhone in BFU state would have been nearly as safe, but nobody makes these implications about iPhones because everybody has iPhones.


The article seems to be muddying the water bringing up grapheneOS itself. Or maybe it's the EFF.

>Experts said the legal approach is unusual and may be the first time the law has been aimed at an operating system. "It's concerning – and sends the message that [GrapheneOS] is criminal by default," said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.

Is the actual case about banning the OS? Because it seems pretty clear the case is about the result (the phone being wiped with a special passcode).

The better defense imo would be one of those 'wipe the phone if you get the password wrong x times' and try and claim you forgot under pressure. At least if you wanted to wipe the phone without being accused of destroying evidence during a search.


As a citizen the safest way is to just refuse. They can’t refuse entry. Not the same for LPRs.

Privacy and security are important, but there should also be clear legal guidelines for such situations.

Clear legal guidelines for which country? Or, better yet, for which subdivision within said country?

anyone would think that wiping entire device than giving sneak peak about what is in the phone is 100% sus as hell

maybe write down the duress pin somewhere in your wallet. let them make their own assumptions and erase the alleged evidence on their own.

Why didn't the device shadow-ban the user instead of wiping the device upon entering the wrong PIN?

Of course TSA agents become angry when they enter the PIN and see a message "wiping device".


Rather than wipe the phone to an obvious reset state, this feature should boot into a benign setup with normal contacts etc. after it erases the user's data. Let the user periodically boot into this benign setup to add basic contacts etc.

Its best for all of us to figure out how to use phone-as-a-linux-vm with the physical phone just hardware. It will solve many problems: commoditize the phone ecosystem, eventually making them repairable, run our own apps instead of apple/google. Access phone-vm from laptop/desktop ...

So let them just sieze your device. Don't unlock. You'll get it back in a few months.

Obviously you should just write the duress pin on the back of the phone inside the case. If the ask what the PIN is for, stand mute. If they enter it, it is their decision.

It seems to me that this should have been a case of steganography?

Instead of wiping it clean, wipe to innocuous mode. Then the burden on their part is not only to show that I gave a bad pun, but that the innocuous mode is materially different than the previous state.


creating a convincing and actually safe innocuous mode is probably harder than it sounds in practice

Perhaps we need the following feature:

Before entering the airport you set your device to auto-wipe after x hours.

Once you are sitting in the airplane and flying, you cancel the scheduled automatic wipe.


This case will only help make more criminals aware of this possibility.

I suspect that this will ultimately be thrown out for a very simple reason which is that the government will have to prove that a duress PIN was actually entered. That is going to be quite difficult unless the person charged openly admitted it.

The reason is because anyone running an os with a duress PIN that has done nothing wrong can be accused of using a duress PIN because the whole point of the duress PIN is that it looks like you just have a normal phone.

Running a normal apple operating system with just stock apps? Boom, you're a criminal because you obviously used a duress PIN and have something to hide! There is no way to prove you didn't use a duress PIN because the phone was "wiped."

Now unfortunately grapheneos probably leaks information so that a duress "unlock" can be differentiated from a standard unlock by some means. If not then kudos. It looks like it is done instantly by keeping everything encrypted and just zapping the keys, but it also needs to actually unlock to something instead of rebooting to prevent leaking the information that a duress pin was used. Not sure how fiesable that would be though.


> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart.

I'm confused to understand if Tunick did anything illegal here. If the authorities want the phone, they should have the warrant and seize it without Tunick's permission.

It appears authorities did not have the warrant which give Tunick all the right to do whatever he desires with his property.

What am I missing here?


They don't need a warrant to seize the phone at the border. They were after the pin code, he should have just refused to give the pin. That's the 5th.

What they got him on, is that supposedly he destroyed evidence.


Among other things that CBP does not need a warrant to search or seize anything and everything at a border. Everything is subject to search at the border. To make a seizure all that is needed is reasonable cause that customs law/regs were violated. And there are specific federal laws relating to thwarting such seizures.

If you don’t want something searched do not bring it across the US border. There is very clear constitutional and statutory authority for these searches.


> To make a seizure all that is needed is reasonable cause that customs law/regs were violated.

What would be the reasonable suspicion that a USC bringing their personal phone on a trip with them would be a customs violation?

That doesn't sound at all reasonable.

In fact, the only "suspicion" they had was that he was someone who didn't like LE or Trump which is still not a crime, nor a customs violation.


No idea if its true, but one rumor mentioned was he was suspected of possessing CSAM

It appears to be illegal to destroy property to prevent seizure. I don't know the details; if you search that phrase you can find more info yourself.

Did he actually destroy any property, though?

I guess the jury will decide.

Where will they find 12 GrapheneOS users?

(The peers)


CBP doesn't need a warrant to search at the border, including electronic devices.

However, if Tunick was smart he would have refused to provide the PIN, and let them seize it. He'll get it back eventually, but it was in his right to refuse.


Maybe also shows that the duress PIN feature could be implemented better. Booting into a completely fresh phone is suspicious. There also shouldn't be any visual or other indicators of that happening.

In the old TrueCrypt containers you could set an optional second password that would decrypt a different volume. The size of the container file was always the same, a decrypted volume always showed the full container size, the portion not occupied by the data in the main volume was filled with noise, and the data on the non-loaded volume was not protected (so you could erase it without warning by storing too much on the loaded volume), making it practically impossible to prove the existence of a second volume either way in a search situation. I guess there was a reason why the project was stopped.


His mistake was giving a passcode he knew would destroy the data on the phone. Instead leave the destruct passcode written on a scarp of paper inside your phone case.

If they were searching for evidence of a crime, what crime was it?

They claimed they were looking for CSAM. There's a border search exception to the fourth amendment that says CBP can search your phone at the border. You aren't required to give them a password (but possibly a fingerprint or facial scan) but they can temporarily sieze it (and do god knows what to it).

The crime of disagreeing with the President.

The downvotes you get on this website for being completely correct never cease to astonish me.

I'd like some filter where if a comment is downvoted by IP addresses located in USA, they are considered as upvotes.


That isn't a crime in the US thanks to the first amendment.

> That isn't a crime in the US thanks to the first amendment.

Technically correct is not the same as practically correct.


Doesn't mean they won't still dump your phone and detain you as long as they can if they see a meme they don't like.

They can detain you for days if you're not white. (Kavanaugh Stop)


They violated his rights and he pulled a prank on them. They need to chill out.

Charged is not convicted. Anyone can be charged with anything if the prosecution is vindictive.

There was no warrant, nor any court order compelling him to provide the unlock code. They had no probable cause, other than that they had labeled him a "terrorist" because of his political activities. The CSAM pretext was provably just a pretext. If he gets good representation, he should be able to (eventually) beat this rap.

If he had simply refused to provide the unlock PIN, he would have walked away. They may have kept his phone, but they would never have got anything from it anyway.


Anyone else running box for local ai on android ?

www.github.com/jegly/box


Gotta wonder how it would've gone if the citizen hadn't mentioned GrapheneOS at all and instead tried to sue them for wiping his phone without his permission.

This sends like a more-info-requiered situation. Per this article, the LEOs seemed to be fishing, so they presumably couldn't claim as a matter of fact that evidence had been destroyed. Also, claiming destruction of property seems unreasonable since the phone, the property, still exists as before. If I sell my phone, I'm going to wipe it. I think we all understand that it would be ludicrous for the buyer to claim I was destroying the phone, the property they've been sold, by doing so.

Even if the accelerated executive capture of the judiciary is largely ruled back post Trump (big IF), I fear the government will be unwilling to pay with much of the convenience of rule-by-law that it's been given a taste for.


it's a bug: the wipe should only apply to a see secure enclave, and the phone should restart `normally`

maybe have the default behavior for the phone to reset if it doesn't get the right pin every so many hours

There needs to be a simple feature to wipe your phone and then restore to a point and time. That’d be really convenient.

Seems like a good court argument too—no destruction of data was even attempted because I know I have my iCloud or Google backup. Personally, my phone has access credentials to information, but not the information itself. So you need a serious warrant before you can get those access, but the data is there.

I agree that it seems a simple argument for any competent lawyer to make that the phone isn't the "gold copy". The phone is just an ephemeral copy of the real data which is safely stored away in the cloud, and the authorities can request access to with the proper warrants.

Of course this argument will only work if the phone is indeed and a ephemeral copy of your real data.


Honest question: Does a wipe just wipe what's on the phone, or does it also tell the cloud to delete stuff?

So having a Casio F-91W and a Pixel 9a at an airport in US basically sends me to Guantanamo?

Its the new brown skin.

> US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search

I really don't like this title. Officers asked him to open the phone, which he pretended to do, but instead wiped the device

> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart. The defense motion states that "the screen went blank, flashed several times, and the phone appeared to restart," resulting in the loss of data.

The title implies the agents maybe entered too many pins by mistake and the device auto-wiped, or that it reset itself with no human intervention, which isn't what happened. This is more like shredding paper when the FBI arrives at your office, which most people would attribute to destroying evidence. I hope he wins the case in principle (I think there's a risk of a slippery slope here) but it wouldn't be a moral tragedy if he lost.


he doesn't need to do this if all he doing is legal

Instead of a PIN that wipes the device, it would be much better to setup a special PIN that logs the user into a sanitized, completely separate profile with generated content of no practical value. This would create plausible deniability, and be sufficient to allow low-level border agents to look through a phone and pass any checks without raising these kinds of alarms. The wipe PIN should still be an option, but should be separate, and only be for cases where you suspect a forensic imaging or search of the device is to take place and the legal consequences outweigh the risks.

This. Aka a Qubes style isolated image.

Having just gone through having to give pin to cbp you just need the apps on your phones to have separate pins so when police unlocks it, they cannot unlock WhatsApp afterwards. Faceid or unique pin. Problem is your phone pin overwrites Face ID

Related, There was a local guy who was held 'in contempt' for 4 years for refusing to turn over his password/encryption key

https://arstechnica.com/tech-policy/2020/02/man-who-refused-...


Every day I thank the lord that I left the US for good and never went back

I would be very interested in how you did this / where you ended up. Feels like an impossible task every time I consider it.

Other countries are worse legally than USA, including uk

could graphene support multiple duress PINs?

feds: "unlock your phone or else" victim: "um, you're stressing me man. It's either 1234 or 4321, I forget. One of them wipes the phone, the other will unlock it."

Whichever PIN they try, it wipes the phone, but the feds can't claim it was deceitful, just unlucky.


I don’t understand why phones can’t just have decoy profiles you can activate via PIN that look like regular harmless user profiles? Especially now with AI you can quickly populate with a bunch of plausible data.

Or better, have PIN for taking you to your criminal/secret profile instead.


How would it work? Isn't it easy for the authorities to check the list of users on the device?


In Russia? In China? In Iran?

Nope, in the US.


why not just have a separate device for traveling ?

Yeah, that's my position.

If you're paranoid enough to be using GrapheneOS, why would you take it to an airport in the US of all places?

I bought a second hand iPhone for overseas trips, which my daughter promptly stole because she wanted an iPhone, but then i got her old android phone, which was LineageOS-compatible, so that became my travel phone.


How do you manage data between your primary and travel-phone?

I _think_ you would need a fresh iCloud account (thus losing access to purchased apps and subscriptions). You also need to manually create fresh social media accounts, copy over contacts, etc.?

Any advice on how to automate this process or is this just a 2-4 hours exercise you do before your trip?


A couple of hour exercise setting up the minimal amount necessary for the travel beforehand. Then once you're at destination, you can set up everything else if you want.

I don't have a lot of "everything else" anyway, so my device would probably look suspiciously 'clean' even if it was my in-this-moment daily driver. (HN is my news and social media). I don't use banking apps, but the irony is that I would need to whilst overseas.

One of the funny things is, I should be able to re-setup any device with an old gmail account at any time in any place, but with all the extra security these days, you need an old device to authorise the setup of a new device. I'm going away early next year, so I'll need to have a dry-run of the setup...


Do you have separate iCloud accounts? Keychain syncing kills me...

Definitely dry-run. I didn't do that and it was a huge pain to recover everything.


I was hoping to have to setup a whole new apple account for it. I'm normally Android, but cage across a cheap second hand iphone at an auction - but my daughter wanted it, so it never happened.

It would be easier for me to just go Android, and I do have spare older devices now too.


GrapheneOS is excellent but seems like it just brings unwanted attention at this stage.

Another plus is if you do lose the device the damage is minimal, its a bit of a hassle but nothing beats peace of mind


The US is known for it's freedoms and protections. It's one of the safest place to take a personal phone.

Welcome to 2026, you have a lot to catch up on. Maybe sit down for this.

Apparently not

- e-sims make it much more difficult to swap sim cards between devices.

- presumably border patrol wants to see his photos, social accounts, and email. A separate device with a copy of the information they want isn't a defense. Creating fresh travel-only accounts is tedious, b/c fresh accounts aren't connected to your friends or network (with whom you'd want to share your trip with).


you could login to your stuff after but the point is to minimize damage when you do lose your device abroad

laziness isn't an excuse and if you do want access to your phone or device at home you could setup that as well


I just wouldn't want my dick pics to get out.

My airport phone is full to the brim with them - I want to watch the officer to check every single one.

Wouldn't be surprised if they charge you with exposing yourself.

While I like the idea behind GrapheneOS, I'd rather not place myself in jeopardy of some ridiculous charge like this one. I prefer to travel with a travel device, some inexpensive phone and/or laptop that contains nothing interesting. If they then wish to take it from me because I won't unlock it, then have at it! That said, the situation with respect to our Bill of Rights at the border has gotten ridiculous.

The "duress PIN that nigh guarantees destruction of evidence charges" functionality is extremely stupid, but otherwise GrapheneOS on a flagship phone is your best bet for an Android phone that can't be cracked by low-effort attempts, government or otherwise.

To everyone who thinks this is somehow a violation of rights: if you were being questioned by border officers, and were asked 'Sir could you please open your suitcase', and you pressed a button that caused it to burst into flames, there isn't a country in the entire world that wouldn't arrest you on the spot. Why would 'wipe a phone when officer requests it opened' be treated any differently? Suspicious behaviour is treated as suspicious by normal people.

It doesn't sound like this person pressed any buttons. They were pressured to provide a PIN or be delayed and further harassed. They obliged, and agents decided to enter it to attempt a warrantless search of the phone.

It's not stated, but probably we can assume the person didn't ask for his phone to be searched - probably he asked NOT for it to be searched, at least based on his multiple requests to talk to his lawyer.

Considering those factors, I'd say border patrol is more responsible for wiping the phone than the person.


Right, but by that rationale, it’s also suspicious to say “no” when they ask if they can open your suitcase. Or decline to tell them where the key is. Or ask to speak to your lawyer first. Or refuse to tell them what is in the suitcase. Or lock the suitcase in the first place. And I want to live in a society where those behaviors are protected.

(1password has a “traveling” mode that wipes it of sensitive passwords before going across borders. Is that suspicious? Should it be criminalized?)


If they ask to open my suitcase and I say 'no' that is suspicious. I've done a lot of travelling and have been questioned more than once: being candid and transparent has always been prudent.

Yes, they would be rightfully arrested for setting off an explosive device in an airport. This analogy ... isn't great.

material =/= information.

Are we supposed to live in a world where if I'm crossing a border I must give access to all of my information? That's absurd and more equivalent to a full brain/memory scan than a suitcase search from your example. This is dystopian in every sense of the word.


My bets for the actual story behind this are: 95% a criminal hiding evidence 4.99% an autistic attempt to "keep his privacy" for no reason at all 0.01% a genuine need to keep something away from the government

In all cases just don't cross security checks with evidence you wouldn't want to be seized, its not that hard




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: