cross-posted from: https://lemmy.world/post/49853131
Feels to me like GrapheneOS did exactly what it should, passing the US border test with flying colours!
Funny part about this lawsuit: “With a little planning ahead of time, you can always download the data you need once you get to where you’re going,”
You guys already spotted the hole in the burner plan. A clean phone and a wiped phone look identical from the other side of the desk, and both look like someone who planned ahead.
A burner only works if it’s lived-in instead of clean. Real accounts, months of boring messages, photos of nothing in particular. That’s a lot more effort than grabbing a spare handset the week before you fly, which is why hardly anyone does it properly.
Same idea with less upkeep: keep one genuinely lived-in phone and put the sensitive half behind a second PIN, stored so you can’t show it’s there. Then the thing you hand over isn’t a prop, it’s just your phone.
(I work on DeniableOS, which is that. Changes nothing about what CBP is allowed to do to you, and I’m not a lawyer.)
deleted by creator
Sounds like the border guard wiped his phone, not him.
This whole situation is making me strongly consider bringing a burner phone on my next vacation. That way I can wipe it before going through customs.
I did something similar when I last visited the US ~15 years ago. I uploaded an encrypted backup of my phone to a server in my home country and reset the device. I then downloaded and restored the backup when I arrived at the hotel.
„I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.” Wow that’s an advice fitting entering Russia, Iran, etc. Nice club you’ve joined here
Yeah I wonder what the penalty is for doing something legal with something you own.
Would be cool to have your device partitioned by separate passwords, so you could unlock a dummy system.
That exists. The thing to watch is the difference between separate profiles and a hidden one.
Graphene gives you multiple profiles with their own passwords, but profiles are enumerable. Anyone poking at the device sees that profile 2 is there, so “open that one too” is the obvious next sentence.
The version you’re describing works when the second environment can’t be shown to exist at all, so it reads as encrypted random noise, which is what empty encrypted space looks like anyway. One PIN gets you a full boring phone, the other gets you your real one.
Only holds up if the boring phone is actually convincing though. Six apps and no photos fails on the spot.
(I work on DeniableOS, which does the hidden version, so weigh that how you like.)
yes you can. On Graphene you can set the main profile as just there with nothing except to control wifi/add esim/etc. Then you can create many profiles with their own passwords. You can store your work stuff in 1 profile, private stuff in another. You can even create a dummy profile with fake Google. .
The downside currently is that the OS autoboot to main profile. Then you switch to your other profiles.
Good writeup, and the downside you flagged is the interesting bit. Profiles are enumerable. A dummy profile survives a glance at the screen and stops working the second someone can see profile 2 exists and asks you to open it.
The property you want on top of your setup is that the second thing can’t be shown to exist at all, so it looks like random noise rather than a locked door. Then the dummy isn’t a dummy, it’s just the phone.
(I work on DeniableOS, which is built around that. Your profile setup is still the right free answer for most people and I wouldn’t talk anyone out of it.)
This is an excellent idea honestly.
I believe some password manager (was it 1Password?) has this
„unlawful to knowingly destroy or damage property to prevent authorities from seizing it” - but did it fucking explode, catch on fire, or blew some fuse on the phone or in any other way prevented it from working? No, they (not him) just wiped the data. I didn’t know deleting files off YOUR OWN DEVICE is a crime. I need to think twice before I empty trash on my computer next time.
100/100 remark!!!
Perfectly legal. Unless they were legally charged and ordered by a court to preserve data considered to be used in a crime, they can’t be charged with shit. Cops don’t dictate this, courts do, AND that scope only applies to an active prosecution anyway.
Legality seems to be a fairytale concept in the USA, except for oligarchs. They get full legal coverage.
Perfectly legal. Unless they were legally charged and ordered by a court to preserve data considered to be used in a crime, they can’t be charged with shit. Cops don’t dictate this, courts do, AND that scope only applies to an active prosecution anyway.
I’m not a lawyer, so I’m not arguing that you’re wrong here, but the article describes the federal law the journalist was charged with. It seems very broad, and it’s a bullshit law, but from what’s here, it seems more grey area than perfectly legal. All of 2232 seems to require knowledge (which it seems like he had, but might be arguable) and action. You could argue that the journalist didn’t take any affirmative action to wipe the phone. The action that wiped it was the feds entering a code.
Yeah, you’re wrong in a number of different ways. No, you’re not a lawyer.
What you linked to is precedent par notice. Every single subordinate literally mentions notice.
A law enforcement officer of ANY type is not able able to issue that notice.
It depends. If the police suspect the owner has evidence of some sort on the phone, destroying it can lead to a tampering with evidence charge from the police.
A tampering charge doesn’t have to be from a court order. If someone eats or dumps out drugs where the police can’t collect the physical drug, it will stick.
But in the story’s case, it falls within the 100 miles of the US boarder (called a boarder search exception) a warrant, probable cause, or RAS aren’t needed here. It’s considered a reasonable search so the 4th amendment is limited here.
There is a lot to it and really don’t think this is the best format for it here.
It does not depend. 4th amendment is superceded by any state law, and it’s SUPER clear that unless a crime has been committed and prosecutorial procedures are in place, no search or seizure is legal.
That’s the whole point.
It’s a federal law. It’s been legal since the constitution was written. There have been numerous court hearings stating it’s legal.
You might want to reread the 4th again. The supreme court has ruled international boarder crossing as a reaonable search, thus no warrant, RAS, or PC needed.
Again…you can SEARCH all you want. Whether you find anything is not mandated.
I’m not sure what’s so hard to understand about this.
And if you destroy evidence during an official investigation, it’s tampering.
I’m not sure why you’re so confidently wrong. It’s fucking embarrassing.
Did you read the article and the laws pertaining to data seizure at the border? Crossing the border doesn’t constitue an investigation of ANY kind, and also doesn’t suddenly conjure up some sort of suspicion that a crime is in progress or has been committed, meaning no pretense for charges because PERSONAL DATA was not seized. Good lawd.
GrapheneOS - the only OS that i just installed and forget about it. Sure i spend time to tweak things like profiles but thats it.
And I am a distro and rom hopper.
The security model is that good: duress pin, scrambled pin, separate profiles with their own passwords, usb c restriction (you can set it charge only, charge while phone is off (most secure state).
and yet people even here don’t understand why it would be useful even without the hardware security thinhs of the pixel
I just heard about this yesterday and it’s very interesting and fascinating to me, how the duress PIN worked if a situation like this arose. I cannot think that GrapheneOS team for implementing such a feature. Lowkey want the team’s input on this. 🥰
What? US police can ask you for the phone password? No way! That is 100% police state. Stalin was amateur comparing to present day USA.
Yes US citizens cannot be compelled to provide a password, but biometrics such as fingerprint or Face ID can. Disable these when crossing into the US.
Non citizens can be detained and rejected for not providing access to a device via password. Best to bring a second device if you must enter. Depressing times.
I don’t believe you can be compelled to provide a password. That does after all (at the very least) constitute speech. And freedom of speech is also freedom of non-speech, they can’t make you say something.
They will however try to make you do that… In many situations authorities are allowed to lie to you. So that’s sucks. They can tell you that you’re required to unlock your phone, you just have to know that your not actually.
Also they can’t make you say anything, but they can make you do things, like for instance “put your finger here” or “look into this camera”, which is why biometric unlock is unsafe around cops.
There’s that one guy who is being held in contempt of the court (to be clear this is not the police asking for his password, but a judge in a court of law) because he won’t give a password to decrypt a hard drive.
They believe it is highly likely that the drive contains sexually explicit material of children, which is why he’s being held in prison until he gives up the password.
he’s being held in prison until he gives up the password
So basically he is in prison without proven guilty? That is exactly how “Communist” countries did: “you are probably guilty and just in case you will spend next 10-20 years in prison untill you admit your guilt”. Now is “OK” for pedophiles, next will be OK too for political oposition.
Good. Annoying to rebuild his phone, but better than handing it to fascists who don’t even have a lawful court order for it.
In all likelihood they kept his phone and will retain possession until charges are dismissed. Get a burner phone and wipe it before going through security. I assume if they see your phone is “fresh” they’ll take it on suspicion anyway.
Would you want the phone back after it’s been in their hands? I wouldn’t trust them to leave it alone.
Surely he was also using the built in backup feature, if he was he would have been able to grab another used Pixel, install GOS, then just recover from his backup (I haven’t tried the restore yet just because I’m lazy, fingers crossed it works).
Hmm. Maybe DHS can fuck all the way off?
He would have had a lot better legal leg to stand on I think if he had just refused to give them any passcode. Now instead of a potential case of being forced to compel speech, he is facing what will be argued is an attempt to destroy evidence. His defense is probably a lot stronger with the former than the latter.
To charge someone with destroying evidence wouldn’t they first have to somehow prove the evidence existed?
No they would have to prove that what was on his phone was evidence in the first place. Which is why arrest and search warrants list all kinds of potential evidence and if it isn’t listed in the warrant they can’t collect or use it against you.
I’m not exactly sure how this works during a border patrol search. It’s technically his phone and if it’s locked they would need his permission or a warrant to search it.
Does it count as destroying evidence if they don’t have a warrant for it? I can destroy whatever device or document I want. It’s my property
Not once law enforcement tell you it is relevant to an ongoing investigation.







