21 ms·
Felony charges for citizen deleting phone data at US Border
https://archive.ph/SflVC https://archive.ph/SflVC
https://www.youtube.com/watch?v=_2rokxux5cU https://www.youtube.com/watch?v=_2rokxux5cU
- luxuryballs 1mo agoArguably good if you want to maximize the capability of the applied border control efforts, seems inevitable. It's a very intentional incentive.
- floathub 1mo agoAccording to the article, he was actually using GrapheneOS and gave the border official the Duress PIN. So I guess technically it was the official that erased the data :-)
- gruez 1mo ago[flagged]
- deleted 1mo ago[deleted]
- hamper653 1mo agoThere is a difference between exploding a bomb and deleting your data. One is a crime.
- LoganDark 1mo agoDeleting your data is absolutely a crime when you know the authorities could've wanted whatever it was you deleted -- even if they haven't told you yet. It stands to reason that providing a duress PIN that deletes your data when entered would be a crime as well, if said data is of interest. Not to say that I personally agree with either of those cases. But what is considered crime can get pretty unfair when it comes to the authorities thinking you did something wrong.
- bdangubic 1mo agoCan you provide a statute number for this crime please? Any federal or even state statute will do
- gruez 1mo agohttps://en.wikipedia.org/wiki/Tampering_with_evidence https://en.wikipedia.org/wiki/Tampering_with_evidence
- bdangubic 1mo agoFirst, that is not an actual statute and second exactly what "evidence" is my phone, evidence of what exactly?
- LoganDark 1mo agoEvidence of anything. You're tampering with evidence if you act to prevent them from seeing something, even if they had no reason for suspicion. Like how you get arrested for fleeing even if you didn't do anything wrong.
- someothherguyy 1mo ago
- gruez 1mo ago>There is a difference between exploding a bomb Mines (in wars, as implied by "solider") aren't illegal. Also even for the first example there are certainly improvised explosives you can set up that isn't criminal to create or set off, fireworks for instance. Same with a barrel of gasoline. It's certainly a crime to use it to kill someone, but that's my point. By OP's logic it's not the person who set it up's fault, it's the person who triggered it.
- LoganDark 1mo agoIf you set up a device to explode once someone enters a room, it doesn't matter who set it off by entering the room if they had no idea the room would blow up. I don't think it'll be very easy to get out of liability in this case. The duress PIN is a feature explicitly designed to delete all data when it is entered, especially in cases of coercion like this. There would be more plausible deniability if officers had simply discovered it somewhere and tried it on their own, but in this case it was knowingly provided directly in place of the real PIN.
- mc32 1mo agoIntentional destruction of evidence is also a crime. Now, whether this applies to this scenario I suppose will have to be determined by the courts. Destroying potential evidence before suspicion is not a crime. Destroying it once under suspicion is a crime. So anyone can destroy their data at their hotel room even just before entry even if the data contains evidence of crimes. Of course the courts could take that into evidence to support the argument that there were crimes but it would not be a crime in and of itself.
- ComputerPerson 1mo agoGreat comment. Wish it was the top one so I didn't have to read through the others to get here. Do you have thoughts as to how the courts would debate the deletion that you could present on a similar intellectual plane?
- LoganDark 1mo agoDestroying potential evidence before suspicion is a crime if done with intent to impede a future investigation, even if the investigation hasn't yet started. Your example would be a crime if it could be proven that there would likely have been evidence in what you deleted.
- spacebanana7 1mo agoI wonder whether it'd be better for a duress PIN to delete existing data and also create a semi plausible artificial profile to hide the deletion event.
- dredmorbius 1mo agoThis discussion was raised last time this story was discussed. I was among its advocates: <https://news.ycombinator.com/item?id=49061890 https://news.ycombinator.com/item?id=49061890>. Briefly: no. Less briefly: <https://news.ycombinator.com/item?id=49060780 https://news.ycombinator.com/item?id=49060780> and <https://news.ycombinator.com/item?id=49060716 https://news.ycombinator.com/item?id=49060716> (from the grapheneos HN account directly).
- spacebanana7 1mo agoThanks for sharing - I get the concerns people have raised in those threads, however I still feel something in this space could be useful. Even a duress PIN which triggers predefined deletion of certain folders, messages and apps could reduce law enforcement exposure significantly.
- grapheneos 1mo agoDeleting arbitrary directories, messages and app data would be highly unreliable. There's a high likelihood of the data being recovered. It's not how computer filesystems and storage are designed to work. Reliable deletion of data requires setting it up to be reliably deleted later on by having it encrypted on storage with keys which can be reliably prevented from ever being obtained again. Wiping the overall data on the device via a factory reset, OS recovery mode or duress PIN/password prevents recovering any of the data because it reliably wipes material needed to derive key encryption keys and also reliably wipes the encrypted disk encryption keys. Wiping the encrypted disk encryption keys alone would not be good enough because they're stored on the SSD so imaging the SSD and restoring it could preserve the ability to recover the data. The way the key material needed to derive the key encryption keys is wiped prevents recovery via imaging the SSD mainly due to the secure element. There's already support for reliably wiping data at the granularity of Private Spaces and secondary users. Those have their own encryption keys and can be reliably deleted due to having their own Weaver slots in the secure element and other hardware-based security integration. Apps can also assorted generate encryption keys in the secure element and use those to encrypt data where it can be reliably deleted via wiping the hardware keystore keys. That requires apps built to have granular storage and encryption of their data. Despite it being possible to wipe a secondary user or Private Space reliably, the past existence of it and when it was wiped will be easily discoverable via the main Owner user and system data. Preventing discovery of those profiles having existed requires an overall wipe of the data. It isn't feasible to hide it without doing that and hiding it would involve a whole bunch of unreliable removal of data without a way to prevent recovery along with redoing a bunch of statistics and other metadata to hide that there was another profile until recently. For example, things like the battery and data usage stats directly refer to the profiles. Even hiding it from naive analysis not looking at the leftover data on storage would still require changing a bunch of things to hide it. Making data deletion of the data reliable for a whole profile or the whole data partition also requires a reboot or shutdown. Consider how much data gets loaded into the page cache and many other forms of data in the Linux kernel and other processes. Consider how much linger around in various kinds of registers, etc. including outside of the OS itself. Reboot or shutdown has code to get rid of this and the device sitting there turned off or booting again also gets rid of it. They were clearly going to hook his phone up to forensics software on a laptop and had done what they needed to do in order to justify it for their own policies. It would not make sense to set up everything they did simply to have someone non-technical manually sift through his apps. They have widespread access to forensic software and also more advanced software with exploits. They definitely have easy access to it at a major Atlanta airport. The adversary in this case is not a non-technical human but rather advanced software from Cellebrite who are fully aware of alternative operating systems and document information on it. Their documentation directly refers to GrapheneOS and has tables listing their (currently very limited) capabilities against it. This story got widespread news coverage and is widely known about. That should help make it clear how important it is for features to work against adversaries aware of these kinds of features. Our duress PIN/password works against adversaries aware of it. If they don't coerce a PIN/password from someone or don't enter a coerced PIN/password because they know it could be in use then the feature has worked. We want to improve the feature with secure element rate limiting integration in the future so that an OS exploit cannot be used to bypass it. The secure element already prevents an OS exploit from bypassing the limit of 20 total attempts for deriving encryption keys with massively increasing delays between those attempts. It used to solely be based on delays with throttling quickly reaching 1 attempt per day after 140 failed attempts but now there are only 20 total unique attempts. The past 5 failed unique attempts are temporarily remembered and discarded when entered again rather than trying to use them again for usability.
- nkrisc 1mo agoI don’t think that would fly as a defense in court.
- phoghed 1mo agoHe’ll just have to pray the scene wasn’t recorded and his real PIN was one digit off
- fsckboy 1mo ago>I don’t think that would fly as a defense in court but that's not the point, the point is to not wind up in court by presenting a phone that no long contains evidence but seems plausibly like your phone so doesn't arouse suspicion
- deleted 1mo ago[deleted]
- dmitrygr 1mo ago> by presenting a phone that no long contains evidence Evidence Tampering https://xkcd.com/1494/ https://xkcd.com/1494/
- forgotmypasswor 1mo agoYeah if they can catch you and prove it.
- MBCook 1mo agoEven if they can’t prove it, they can make your life really miserable for quite a while.
- forgotmypasswor 1mo agoIf it was implemented in such a way, there would be no reason to suspect anyone of using it because it would be totally indistinguishable from not having used it. At that point they have no grounds for legal action. Unless they could monitor FS/disk activity, but that goes beyond typical airport security stuff. I'm imagining a duress code that erases select files and any indication that there was ever a duress code set up in the first place.
- OutOfHere 1mo agoNo, to my knowledge, they ask you to enter your PIN/password yourself. They don't enter it for you. I believe he entered it himself, at which point the erasure began. The erasure process was witnessed by the officer.
- foo12bar 1mo agoFrom https://arstechnica.com/gadgets/2026/07/activist-charged-with-felony-after-giving-border-agent-duress-code-that-wiped-his-phone/ https://arstechnica.com/gadgets/2026/07/activist-charged-wit... > Tunick provided this code to an agent, who entered it on the phone, after which “the screen went blank, flashed several times and the phone appeared to restart.”
- rglover 1mo ago[dead]
- greatgib 1mo agoSo the real problem in the end is that your duress system should not put a big message "erasing all data" but "loading" slowly and just look mostly empty.
- OutOfHere 1mo agoYou sir have nailed it. Unfortunately, GrapheneOS seems too stuck up to eagerly appreciate and address such real world nuances.
- Cider9986 1mo agoThey don't add features that rely on security through obscurity, would give attackers tons of attack surface, is physically impossible to make actually deniable, and could put regular GrapheneOS users in physical danger in authoritarian regimes.
- dkga 1mo agoInteresting. So is this GrapheneOS indeed operationally good for keeping one‘s data private?
- spencerflem 1mo agoYes if you don’t mind getting arrested by our fascist border police
- fleroviumna 1mo ago[dead]
- michaelt 1mo agoI mean, it sounds like it would be even better if the duress response was more subtle. A duress code might let me wipe my phone when someone holds a gun to my head and demands I unlock it. Problem is, there’s still someone holding a gun to my head.
- bengt 1mo agoHe had an e-reader and phone. My solution would be set the phone's duress pin to the e-reader's actual pin then consent to the e-reader search providing its pin and see what happens. The actual solution is cloud backup + re-image after the border.
- victorbjorklund 1mo agoNot how the law works. If I put a bomb in a box. It will explode if a certain pin is put in. And you ask ”can I open the box? What is the pin?” And I say ”here is the pin to open it” and the bomb explodes. Do you think I can claim they blew up themselves ?
- kelseyfrog 1mo agoYes. Because law enforcement assumes there's bombs in boxes by default and defers to the bomb squad to understand the box before they touch it. Why would the bomb squad trust the box owner to help them defuse it? To understand the issue, you have to construct a proper analog.
- kelnos 1mo agoSure, you're right that this analogy is bad, because that would never happen. But if it did, you'd still be on the hook for the bomb, even though technically the LEO set it off through incompetence.
- csallen 1mo agoAn analogy should not be judged on whether or not it can realistically happen, nor whether it can be manipulated in some way that capitalizes on the differences. Because the point of an analogy is not to provide an realistic or identical situation. On the contrary, the point of an analogy is to use a different situation in order to illustrate a very narrow similarity and make a point. If the analogy illustrates and makes that point well, then it succeeds.
- victorbjorklund 1mo agoI never told you it is a box with a bomb. You just asked if you can have the pin. You can do another example where you give false information with the intent of making another person take an action that they don’t wanna take and would not take unless you had provided false information. You are causing the action to happen. Just like if you yell fire in a theater. You didn’t stamped anyone to death. But your words caused it.
- jbird99 1mo agoA better feature would be a 2nd PIN that unlocks the phone to a secondary profile, which you would leave pretty bare for situations like these.
- unreal37 1mo agoOr smarter yet, not bare. Looks like a normal phone - innocent-looking vacation photos, innocent-looking social media accounts, innocent-looking email....
- ChoGGi 1mo agoWith some embarrassing porn; something that would make it feel legit and cause a distraction.
- Grimburger 1mo agoA few hundred personal dick pics and they'll be handing it back quickly.
- Cider9986 1mo agohttps://news.ycombinator.com/item?id=49395135 https://news.ycombinator.com/item?id=49395135
- unreal37 1mo agoHe is charged with obstruction. Not "erasing data". Was he intentionally trying to hinder a search that was being legally conducted? https://en.wikipedia.org/wiki/Obstruction_of_justice_in_the_United_States https://en.wikipedia.org/wiki/Obstruction_of_justice_in_the_...
- ImPostingOnHN 1mo ago> Was he intentionally trying to hinder a search that was being legally conducted? Doesn't seem like it, no. It seems like the search had no legal basis, and so no legal search was hindered.
- pjc50 1mo agoPaywalled, but what is the actual charge? Is it some extremely generic "obstructing an investigation" one? The US is quite good about making court documents available on line, if someone can find it.
- owlninja 1mo agoHere's a gift link: https://www.nytimes.com/2026/08/21/us/politics/samuel-tunick-deleted-phone-felony.html?unlocked_article_code=1.7FA.m0KX.vNcAadqleJHB&smid=url-share https://www.nytimes.com/2026/08/21/us/politics/samuel-tunick...
- hoppyhoppy2 1mo agoThe article says he was charged with obstruction. You can try this "gift link" to the article: https://www.nytimes.com/2026/08/21/us/politics/samuel-tunick-deleted-phone-felony.html?unlocked_article_code=1.7FA.Q8yx.DgiLtsus-z95&smid=url-share https://www.nytimes.com/2026/08/21/us/politics/samuel-tunick...
- jmclnx 1mo agoYet another case that will waste the court's time and money. All this is doing is keeping defense lawyers pocket's lined. At this point, people should buy a burner phone when going to/from the US. In that phone only have a couple of phone numbers and that's it.
- Sharlin 1mo agoOh, they may well give you bad time if your phone looks like a burner with too little content.
- skinfaxi 1mo agoIf you are a citizen like this person is then you can tell them to fuck off, they can keep the phone, and they have to let you in.
- nucleardog 1mo agoThey have to let you in. Doesn't mean they have to let you roam the country freely. They can just send you to some form of detention.
- iamnothere 1mo agoThat isn’t true. They can detain you briefly for questioning at the border, but if there is no crime then you will be released. Feel free to dig into historical court cases about border detention if you disagree. If you get charged with a crime, things are very different.
- nucleardog 1mo agoNope, no disagreement. I just see your take as very optimistic. There is no court at the border. If the agent decides you're going to jail, you're going to jail. The decision may be reversed/corrected after, but it's still going to be a big, expensive problem for you and you _are_ going to be detained for a time. Not to mention walking up with an empty phone and telling the agent to "fuck off" when they ask about it sure sounds eerily similar to the facts of the case in the linked article. I'd wager that's a good way to land an obstruction charge.
- yellow_lead 1mo agohttps://archive.is/SflVC https://archive.is/SflVC
- LugosFergus 1mo agoThanks. Really wish this was higher.
- neom 1mo agoLegal Eagle just covered this, it's quite interesting analysis: https://www.youtube.com/watch?v=_2rokxux5cU https://www.youtube.com/watch?v=_2rokxux5cU
- bena 1mo agoNot even a minute in. "Oh, he's protesting Cop City, got it. This is just police harassment."
- JungleGymSam 1mo ago[dead]
- copper-float 1mo agoSounds about right to me.
- knute 1mo agoThe guy from Game Changer?
- neom 1mo ago[dead]
- onionisafruit 1mo agoYes. And Paul Refereeno will be the judge in this case
- zenoprax 1mo agoGreat link. The most relevant part for me is the last couple minutes (22:00): it's only against the law to destroy evidence if it can be established that such evidence exists. This feels like a more elaborate version of accidentally losing a stack of papers to a gust of wind just as you hand them over. 1. Was there a lawful entitlement to the papers? 2. Were the papers protected private property? 3. Were the papers released to the wind intentionally? 4. If intentionally released was it expected that they would disappear or simply fall to the ground? A couple easy technological analogies: 3. "Sorry, I gave you the wrong code by mistake." 4. "I thought it would go to a private guest mode, not delete everything!"
- 34679 1mo agoAmendment 4: "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized." Amendment 5: "..nor shall be compelled in any criminal case to be a witness against himself, nor be deprived of life, liberty, or property, without due process of law; nor shall private property be taken for public use, without just compensation."
- gruez 1mo ago>Amendment 4: He was charged for destroying evidence, not refusing a search >Amendment 5: Destroying evidence isn't testimony. Moreover he would have been in the clear if he just kept his mouth shut.
- Varelion 1mo ago[flagged]
- gruez 1mo agoPlease try again with an actual argument rather than attacking people based on which "side" I'm on.
- Varelion 1mo ago[flagged]
- gruez 1mo ago"obese nazis"?
- Humorist2290 1mo agoIs there any question the person who was baselessly charged with CSAM, then terrorism when they realized it was so obviously untenable, as a pretense to detain him would've been treated differently if he were on a different "side"?
- amazingamazing 1mo agoIf the government wants you no amount of technical gotchas will prevent this.
- grapheneos 1mo agoThey didn't get the data from his phone and will likely lose the case against him. They probably wanted data to go after other people and those people were protected against it. It was likely unnecessary to use the duress PIN/password. He likely would have been better off simply refusing to provide the PIN/password. He could have rebooted or powered off the device before going through but even without that it would have automatically rebooted itself after 18 hours by default, or a lower time if he had configured one. With a lot more preparation he could have done an encrypted backup, wiped the device and restored it later but that's very inconvenient.
- phoghed 1mo agoSeems like it would be better to have a truecrypt type of situation, where if you put in a certain pin, then it just logs you into a separate OS with nothing you want to hide. Obviously have the duress pin if what’s in your phone is worse than the obstruction charges too.
- dredmorbius 1mo ago<https://news.ycombinator.com/item?id=49389273 https://news.ycombinator.com/item?id=49389273>
- phoghed 1mo agoIn the truecrypt scenario you’d be using the hidden and encrypted volume only for what you explicitly want to keep hidden and use the other one for your daily life. So in the article situation, the guy is a protestor and presumably suspects he’s going to be targeted by the police for it. He’d keep that stuff isolated from his usual activity. There’d be no need to generate convincing fake activity. Certainly more of a hassle than having a PIN that can destroy everything.
- dredmorbius 1mo agoFor a much better-informed source than me, see: <https://news.ycombinator.com/item?id=49392816 https://news.ycombinator.com/item?id=49392816>. (GrapheneOS HN account.) Burner phone / clean phone for border crossings seems the more accessible option. As others have noted, this is standard policy amongst many organisations, some on account of US policies and practices, some on account of other states.
- rootusrootus 1mo agoI'd say better would be not trying to pull a fast one on the cops. Rather than trying to sneak past them and local innocuous, just exercise your right to say no. > Obviously have the duress pin if what’s in your phone is worse than the obstruction charges too. I would say that if what you have on your phone is worse than a destruction of evidence conviction then you may want to just wipe the phone before you get anywhere near a cop. Playing stupid games with cops most often leads to winning stupid prizes. Keep the interaction simple. "No."
- quickthrowman 1mo agoWould it be permissible to wipe your phone before going through customs to get back into the US? If they ask to search your already wiped phone, you aren’t destroying any evidence.
- OutOfHere 1mo agoYes. Of course it is permissible. It is your device. The wipe must have completed before arriving at the counter.
- laughing_man 1mo agoI wouldn't assume that to be the case. It's illegal under federal law to destroy evidence of a crime. Just what the government needs to do to show that you've destroyed evidence of a crime and not just the sexting you did with your girlfriend is a pretty murky area of law, from what I can tell. I would not present a phone to customs that had clearly just been wiped.
- OutOfHere 1mo agoYou're speaking nonsense since there was no charge or warrant against him. There was no crime that was committed. People are free to use their phone for f sake. People who reason as poorly as you will lead to all remaining rights being lost.
- laughing_man 1mo agoAh, I see where you've gone wrong. You're expecting to apply common sense and reason to the law. That kind of thinking has landed a whole lot of people in prison.
- OutOfHere 1mo agoYou're losing track of the discussion which was about erasing data before arriving at the counter. In any event, if you're so willing to "bend over" to the man, please try not to take others down with you.
- deleted 1mo ago[deleted]
- juancn 1mo agoI don't get the legal contradiction. The search is supposed to be lawful without a warrant because you're not really in the US yet per-se, hence if you're not there, how deleting the data can be a felony?
- OutOfHere 1mo agoThat is a most interesting and underrated point.
- joshka 1mo agoIt's a fairly shallow point that ignores how laws work. The premise that the law doesn't apply because you're not in the country is false. The constitution applies generally everywhere to all Americans, it's just that what's regarded as reasonable differs during a border search. IANAL, so just my lay opinion on this. Just to validate this, it's only because the constitution exists that the border authorities have any legal basis in doing inspections.
- OutOfHere 1mo agoHuh, that is inconsistent. The problem with your comment is noted right here: https://news.ycombinator.com/item?id=49390318 https://news.ycombinator.com/item?id=49390318
- joshka 1mo agoNot really - the government have stated that he's in the US. It's the first sentence of the indictment. [1] > On or about January 24, 2025, in the Northern District of Georgia... [1]: https://storage.courtlistener.com/recap/gov.uscourts.gand.351975/gov.uscourts.gand.351975.1.0.pdf https://storage.courtlistener.com/recap/gov.uscourts.gand.35... But in general, the thing to note here is that the 4th amendment is always applicable and in force. It's how it's interpreted that changes depending on the circumstance.
- HDThoreaun 1mo ago
- adfm 1mo agoI don't know about you, but don't people use encryption to retain privacy? And are people still free to manage their personal information? Doesn't a duress PIN present that information in its intended form? I'm confused.
- tavavex 1mo agoI'm not a legal expert, but all this seems to check out with US law. Americans need to remember that some of their constitutional rights don't really apply at ports of entry by design. This inconvenient truth for the land of the free has existed for a long time, this situation is just drawing attention to it. Their powers are far-reaching.
- anon84873628 1mo agoFurthermore, "the law" in this area is currently different in different Federal circuit court jurisdictions...
- hylaride 1mo agoFun fact, there is a long standing exemption to the unreasonable search and seizure protection laws if you're out on a boat (it may only be on the open ocean and Great Lakes, though IANAL). One of the earliest Supreme Court rulings essentially said that without it, it would be impossible for the US to enforce tariffs, which were the main source of revenue at the time. Anybody who boats often enough has been boarded by the coast guard for various safety checks that allows them to poke around and there's little you can do about it.
- klardotsh 1mo agoAny “navigable waters” fall under this jurisdiction which at a minimum includes all salt water and the Great Lakes, plus a few other odds and ends rivers and so forth. Indeed, almost all state and landside federal law goes out the window on a boat - a frequently bumped into example by boaters here in Washington is getting a civil penalty flavored reminder from USCG that cannabis is still (for whatever reasons) federally an illegal substance, and having it on a boat at all is an offense (with larger amounts or future violations escalating as far as seizure of the vessel). Marine laws are nuts.
- formerly_proven 1mo agoThe US / common law jurisdictions typically only have very light self-incrimination protections. The 5th amendment in the US only protects against self-incriminating testimonial. That's it. In most other jurisdictions (i.e. civil law) it's perfectly legal for the accused to destroy evidence (assuming you're not committing any other crimes in doing so, like breaking and entering, property crime etc.), seizure being ordered or not, while it remains illegal to destroy evidence at the behest of someone else. I.e. civil law usually doesn't criminalize self-protective conduct. That's true even in e.g. Japan.
- joshka 1mo agoSo the part of this that feels like it triggers the government issue here is that in effect you have a locally stored encryption key which gates access to the device, which was removed from the device due to duress password. What if we flipped this to instead be something that's explicitly not on the device? The border search stuff only applies to information on the device. It cannot compel you to provide access to e.g. emails stored in a cloud provider. If instead of making the process of stopping searches like this be a destructive one, we instead pre-purge the key but store it offsite with the ability to get it from an online location, then this feels like it's probably reasonable here. In the sense that the 4th amendment explicitly allows "The right of the people to be secure in their persons, houses, papers, and effects, ..." There's probably some sort of technical problem I'm missing here (or maybe this functionality is available already).
- vineyardmike 1mo ago> or maybe this functionality is available already Basically already exists depending on specific trade offs and risk profile. You already can encrypt your data and store the encryption key offsite. But then you couldn’t use your phone during travel, if you toss the key locally. You can encrypt the data at rest and leave the decryption key in RAM and just turn off your phone. But they can still take the phone and copy the encrypted data, if they think they’ll get the key later. My understanding is that this individual would t want the government to access the encrypted data either.
- joshka 1mo agoI'm talking specifically about the graphene OS ability for that approach, not the ability to add an external key to some generalized encryption. The threat model here is that the traveler was required to provide a passcode unlocking a key they had with them on their phone. If that threat is not there, then this bypasses problem.
- fedpost 1mo agoYeah, so caveat emptor: the legal system isn't something you can hack like a computer... But... The issue at hand is the "locality" of the encryption header. He merely facilitated its deletion, not the data. If he had a backup at home, is that still a felony? What about if he had a backup on a flash drive with him? What if he never had the header on the phone to begin with and used a detached header on a flash drive? Are detached headers (a thing you can easily do with LUKS) now de-facto illegal? This whole thing is making me feel rather uneasy about the bigger picture.
- maxglute 1mo agoWhat about none citizens? Customs kicks you out or throws you into a camp first. E: but seriously, what happens to non citizens. What happens if you bring a burner/wiped phone? I assume digit forensics can confirm it was pre wiped but what's topping them from alleged you wiped on US soil.
- thomasjeff1 1mo agoSo non-citizens should avoid visiting US. Got it
- samizdis 1mo agoThat has been the case for a long while. I used to travel a lot for work - Serbia, Czech Republic, Germany, Portugal, Australia, NZ, Qatar, Kuwait, Moldova - but the only unpleasantness I received at a border/intl airport was on landing in the US, twice; NY both times. Talk about rude and aggressive, for no reason at all. I'm from the UK, by the way. My fondest border experience was many years ago when entering France; this was before the UK had joined the EU. (Our later exit was dumb, IMO.) Anyhow, a youngish officer - probably mid-20s or so - examined my passport while asking questions, in perfect English. His voice was even and his demeanour calm and professional. Then he took a step back, closed my passport and put it in his pocket. A few seconds later, he started laughing and said: "The look on your face. Priceless. Welcome to Paris." He really had me and I saluted him for that.
- bad_haircut72 1mo agoThat famous phrase from the constitution, "all men are created equal, except the ones not born in America"
- twothreeone 1mo agoThe implicit "men born outside the US are not men" is arguable worse.
- userbinator 1mo ago
- simonebrunozzi 1mo agoAll Archive pages, when accessed from Italy, now are blocked by the Government: "PAGINA INTERDETTA DAL CENTRO NAZIONALE PER IL CONTRASTO DELLA PEDOPORNOGRAFIA ONLINE (C.N.C.P.O.)" “PAGE BLOCKED BY THE NATIONAL CENTER FOR COMBATING ONLINE CHILD PORNOGRAPHY (C.N.C.P.O.)” Oh, we live in an interesting age.
- stefantalpalaru 1mo ago[dead]
- kioleanu 1mo agoI am currently in Italy (just passing through) and was able to open the archive link with the article
- teiferer 1mo agoThen you probably had a home country IP and they filter based on IP.
- kelnos 1mo agoIf you're using roaming on your cellular plan, all your traffic is routed over VPN to your home country, so local blocks don't work. (That's one of the reasons why it's trivially easy for foreign visitors to China to bypass the Great Firewall.) If you were on wifi, that's notably interesting.
- kioleanu 1mo agoI was on the resort’s WiFi, no vpn. What is strange maybe is that if I search my outgoing ip address, the resort is listed as the ISP
- zarzavat 1mo agoWe can tell OP is using local or unencrypted DNS because they got DNS-redirected to a message. If you have DoH configured at either OS or browser level then you will not see a message: the site will either work, or it will error out if the IP is blocked. If you are using an alternative DNS provider over unencrypted DNS then either outcome is possible.
- gchamonlive 1mo agoIt's like those notices "by clicking accept below you agree to giving up your data", by purchasing a ticket to visit US all your data are belong to the US.
- thomasjeff1 1mo agoWhy American authorities are always attacking their citizens freedom?
- superxpro12 1mo ago[flagged]
- 0xy 1mo agoHuh? These warrantless phone searches happened in the tens of thousands under the previous admin.
- gosub100 1mo ago[flagged]
- vlyan 1mo ago[flagged]
- butvacuum 1mo ago"Ah, yes- let's compare an unpredictable once in a century worldwide event to a political party's long list of historical behavior."
- cwillu 1mo agoI see the sibling comments pointing out how American Freedom mostly cashes out as the freedom to not give a fuck about others are not wrong.
- oivey 1mo agoNot sure what way you’re trying to land with this rhetorical question, but the Republicans, right? Biden took office in January 2021, and vaccines began to roll out around April.
- winter_blue 1mo ago
- marcosdumay 1mo agoGoes to show that he should have made an LLM do it instead.
- IncreasePosts 1mo agoWhat I don't understand is if he just didn't give any password, he would have been fine. It's only because he gave him a duress pin that he's in trouble. So, in both cases the government wouldn't have access to the contents of the phone
- twothreeone 1mo agoIn the first case they (the US govmnt) could hold him (the citizen) in contempt (in a cell) indefinitely.
- wffurr 1mo agoActually no, they are required to allow you to enter the country, but they will make it a hassle, to the point of dehydrating you and/or refusing bathroom access, and confiscate the device in the end and access is through other technical means.
- RunSet 1mo ago18 months is, by precedent, the limit on contempt for refusal to decrypt[0], but this administration is happy to disregard any precedent that does not agree with them. [0] https://arstechnica.com/tech-policy/2020/02/man-who-refused-to-decrypt-hard-drives-is-free-after-four-years-in-jail/ https://arstechnica.com/tech-policy/2020/02/man-who-refused-...
- reenorap 1mo agoThat’s false. Maybe a few hours but that’s it. The CBP are expressly not allowed to deny citizens entry into the US.
- blkhp19 1mo agoIs that allowed? Can you refuse to give a pin when asked?
- carefulfungi 1mo agohttps://www.aclu.org/news/privacy-technology/can-border-agents-search-your-electronic https://www.aclu.org/news/privacy-technology/can-border-agen...
- Joker_vD 1mo agoY'know, makes me wonder why Democrates didn't disband ICE and CBP when they had control over the Congress and the government. I mean, they knew those agencies would be used in precisely this way, yet did nothing anyhow.
- wnmurphy 1mo ago[flagged]
- anigbrowl 1mo agoLook, when the Patriot Act was passed, DHS and ICE created etc., lots of people warned that concentrating so much executive power would end up leading to abuse. And there were abundant evidence of Trump's eagerness to ignore Constitutional norms during his first term. Anyone expressing surprise about ICE being co-opted is bullshitting you. ICE and border patrol unions have been vocally opposed to any sort of immigration reform for well over a decade, and ultraconservative right in the US has been calling for mass deportations and making ever wilder claims about the US being 'invaded' since forever. The truth is that the Democrats have no appetite for dismantling the security state because Republicans would screech that they were making Americans less safe and Democrats would rather not have that fight than make a counterargument for civil liberties and Constitutional values.
- 0xy 1mo agoDemocrats built the blueprint for ICE's deportation program and architected the law that enabled it. Clinton's IIRAIRA bill literally introduced expedited removal procedures and created the concept of 'administrative warrants', routinely used by CBP/ICE today. Without the IIRAIRA, removal would be substantially harder.
- anigbrowl 1mo agoIIRIRA was not a 'Clinton' bill. It was initially drafted by Lamar Smith (r) of Texas (HR 2202) and subsequently attached to an appropriations bill (HR 2610), and passed with a bipartisan veto-proof majority. https://www.congress.gov/bill/104th-congress/house-bill/2202 https://www.congress.gov/bill/104th-congress/house-bill/2202 https://www.congress.gov/bill/104th-congress/house-bill/3610 https://www.congress.gov/bill/104th-congress/house-bill/3610 It's easier than ever to check legal assertions before you post instead of posting incorrect information.
- trollbridge 1mo agoU.S. citizens are going to need obtain a burner phone before returning, and load it with the absolute minimum to load boarding passes, etc., perhaps some reading material or a movie to watch on the plane, and be prepared to share full credentials for thing at the border. (I used to do some travel patterns where taking a certain client laptop wasn’t an option. It was an absolute gigantic pain for the type of work I did, but it was just too risky to have a laptop seized and be expected to input credentials.)
- QuantumNoodle 1mo agoGiving up knowledge (password) is something that is typically scrutinized at the border as well. Had he just handed over the phone and the phone had abilities to self destruct if tampered with (e.g too many incorrect pin entries) -- well the gov's case wouldn't been much harder. If they seized property and accidently destroyed the data, then that's on them.
- ApolloFortyNine 1mo agoYou are correct, you have to give up the phone but can't be compelled to give up the password, and you'd get it back some indeterminate amount of time later. It's actually been on the books for a while (decades at least) that customs can search you at the border without a warrant even if you are a citizen. This case seems to have become a big 'Trump bad' poster child (people are calling the US East Germany in these comments...), but if this exact scenario happened at least in the last two decades (I found an example upholding the searches from 2004) then it would at least be possible to charge them with deleting evidence. Even this probably would have been nothing if he refused to give up his password, not being required to provide a password has been upheld for years. They can seize your phone for some time but I'm unsure on the times they ask and then just let you move on when they find out your a citizen.
- talon8635 1mo agoThis is precisely why you should use a pin and not biometrics. You CAN be forced to use biometrics (“something you have”), but NOT a password (“something you know”) Now you know you know, so use a pin
- jijji 1mo agoamatuer... when you leave the us you bring a wiped phone, never bring your primary phone/laptop/camera/etc
- 0xbadcafebee 1mo agoSo we're presumed guilty until proven otherwise (the presumption is, any data we delete must be illegal; couldn't possibly be nude selfies that the government has no right to see)
- inigyou 1mo agoYes. It's illegal to delete your nude selfies to preempt a government search
- Zak 1mo agoFor exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs. Imagine booting the phone from a flash drive, making an encrypted image of the phone on said drive, and writing a fresh OS before reaching the border. There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA). Some time ago, Android with a custom recovery could come close to that, but it was fussy and as far as I know, no longer viable. Increased use of TPMs for storing credentials seems to be at least one of the reasons.
- abc123abc123 1mo agoWhy bother with the drive at all? Just store your image in the cloud, and once you're past the border, download and re-image.
- fhdkweig 1mo agoAlso, it is just a nice idea if you are prone to losing phones. Backups are good for all kinds of reasons.
- solid_fuel 1mo agoIt may be fun to fantasize about these things some times, but there is no technical solution to tyranny. Laws are not like code, intent matters. Ultimately if the intent is that the government wants to see your private data, hiding it in any way will be charged - it doesn't matter if you jump through hoops to avoid this specific instance.
- Zak 1mo agoThis is a half-truth. In a full banana republic, technical compliance with the law will not prevent consequences for failing to do what the authorities want. In a jurisdiction with perfect rule of law, it always will. The USA is somewhere in between. One of the laws that's enforced pretty well in the USA is the protection against unreasonable search. Most of the time, a search requires showing a judge evidence that the search is more likely than not to reveal evidence of a crime. Exceptions are narrow and specific; the government's options to punish someone who refuses to decrypt data at the border are limited to brief detention and seizure of the medium. Not yet tested is the idea that erasing data on the spot satisfies the purpose of the border search exception, which is to prevent importation of things that are illegal to import. This case might address that question.
- jmyeet 1mo agoI don't agree with all this and this increasingly fascist regime but... this was the most predictable outcome. Consider these two scenarios. 1. You factory reset your phone before entering the US and give it to CBP blank. There's nothing to find; 2. You have a self-destruct PIN like this guy did and give it CBP so it destroys the phone's contents. Tech people will say that these two things are functionally the same. This is a fundamental misunderstanding of how the law works. If you factory reset your phone first with the intention of restoring it after entry, that's completely fine (legally). You could've factory reset that for any reason. But as soon as an officer wants to search your phone, now you're engaging in evidence destruction (spoliation). The destruction to the phone's contents was done in response to an unfortunately lawful search. Even if you don't want to factory reset your phone, you can probably just delete (or even log out) of key apps. They can still get messages but if you're so concerned about that, use WhatsApp or whatever. None of this should be necessary but we are where we are. But whatever you do, don't use a self-destruct PIN if you don't want to be charged with a felon and likely to be found guilty.
- grapheneos 1mo agoA court has not yet determined whether the use of the duress PIN/password was legal. There's definitely no consensus among legal experts of it being illegal as you're portraying it. The US has strong legal protections against self-incrimination and unreasonable searches despite erosion of how much people's rights are respected. A factory reset done in anticipation of a search is not as different from using a duress feature as you believe it is. Forensics software would have clearly identified the device was recently factory reset. It would provide another defense argument by arguing it was wiped for another reason, but whether that would be believed by a court is unknown. It would make a difference if there was a good argument about why it was done, but it isn't necessary for this to have been done instead for wiping the device to have been legal. Once he was in the situation already, the best move was very likely refusing to provide the PIN/password indefinitely and only talking to them to demand access to lawyer. There are strong protections against data extraction and it's highly unlikely they would have been able to get the data from it. Refusing to provide a PIN/password is protected under the 5th amendment in the US and these rights do exist at the border. They can turn away a non-citizen but they can't refuse entry to an American citizen because they won't provide a PIN/password. They could waste a lot of his time but he'd get access to a lawyer and would get released. They could make a court case over demanding the PIN/password and they'd nearly certainly lose. He'd likely spend months or even years without getting back his phone of course. If they had a video recording of him entering the PIN/password from somewhere, they could have used that to get the data. By using the duress PIN/password, he prevented it. It was probably not necessary to keep the data safe, but that's unknown. With only a tiny bit of preparation time, rebooting or powering off the device would have gotten it into Before First Unlock state without the locked device auto-reboot timer needing to complete. In Before First Unlock state, a decent random 6 digit PIN is enough for the data stored protected with it to be highly secure without an extremely sophisticated secure element exploit. If the device had a strong passphrase, then no level of sophisticated exploits would recover that data.
- CrzyLngPwd 1mo ago[flagged]
- patcon 1mo agoI used to play around on projects adjacent to Tor and TailsOS, and had an idea for a setup I was researching. It's a little intense and probably has annoying failure modes, but sharing in case anyone else finds it helpful: - Tasker is an automation app for setting up rules for triggers and actions. It allows extension apps to be created to add new triggers and actions. - someone at one point made an extension to add an action for wiping or factory resetting when triggered - there was an existing extension (or core feature) to trigger when certain signals are lost or found (e.g., wifi signals, Bluetooth LE beacons, etc) So the idea is to carry a BLE beacon (any "item tracking" one works) on your keychain, and an unassuming faraday cage pocket alongside it. If you want to wipe your phone, slip the fob into the pocket, the signal disappears, and your phone wipes. And if you don't have the keychain on you, just refuse to open it right away, as when they put the phone itself in a faraday cage (to prevent it from being remote wiped), they cause the signal to be lost, and it gets reset. Not sure if all the pieces still exist (I dont think the tasker extension for wiping existed outside a forum post...)
- sebmellen 1mo agoI used to contribute to this https://en.wikipedia.org/wiki/USBKill https://en.wikipedia.org/wiki/USBKill
- patcon 1mo agoAh I recall I used to see the creator around :) thanks for your work! Regarding the motivation for usbkill mentioned in the article: I too was motivated to think on this stuff in relation to my sense of injustice around Ross Ulbrecht, and wanting to think of some way that someone in his position could avoid getting caught. One creative variant in my thinking involved embedding the BLE beacon inside a rubber ball that could be launched and lost track of. Or maybe embedded in heel of a shoe and ditched in transit haha
- hamdingers 1mo agoOr keep it in a faraday bag and have the phone wipe if it sees it. If you're ever searched (or otherwise indisposed), they'll open the bag and wipe your phone for you.
- btbuildem 1mo agoThe naivete of some of the comments here is astounding. It doesn't matter whether you're right, it doesn't matter whether it's the law, it's irrelevant that you have rights, etc. Those things are of the past now, for the US. I think it would be easier to understand the playing field and choose your actions accordingly, if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech. The social dynamics are the same - the abuses, the selective enforcement, the lack of recourse, the same characters in the roles of various levels of "law enforcement" and "politics". I'm so very sorry, but the best you can do from here is speedrun the collapse.
- leptons 1mo ago>Those things are of the past now, for the US. It's a temporary situation, it isn't necessarily a permanent situation. Tell me how you think East Germany is doing these days. And no, it doesn't have to take 40 years to right the ship, so long as people get their heads out of their asses and vote. Things are likely to change by the end of this year, and in another 2 years we could have a very different government that could undo a lot of the bullshit going on right now.
- deleted 1mo ago[deleted]
- adamors 1mo agoTens of millions have voted for this 3 times in the past 10 years, it succeeded twice. This is not going away, half the voting population of the US wants to live under authoritarian rule and will do anything to take the whole country with them.
- expedition32 1mo agoYep if Kent State happened today half of America would be cheering.
- 1mo ago
- heyitsmedotjayb 1mo ago[flagged]
- groby_b 1mo agoWhile I think it's an abuse of power from a moral point of view - yes, that would be the expected legal outcome. Under any administration. You can refuse to hand over access. You can't go torch evidence. Caught Ollie North as well.
- steviehicks78 1mo agoObstruction to what? Also thought this would be covered by the fourth and fifth amendment.
- poulpy123 1mo agoOne more reason to not go to the US
- righthand 1mo agoWhat about everyone does this at the border. Then what is normalized is deleting your encryption key while entering, they won’t prosecute everyone on their baseless prosecutions. Join in I say, there is no law being broken only scare tactics being applied to prevent this kind of thing. Normalize the act not the consequences.
- nphardon 1mo agoHe's lucky they didn't ship him right off to the Dilley Detention Center
- 34dfgdfg 1mo ago[dead]
- zug_zug 1mo agoWell hopefully there’s a jury so this nonsense can get nullified
- xhrpost 1mo agoWould he have been better off just refusing to give a code?
- tbrownaw 1mo agoYes. They'd probably have kept the device for a while, but he wouldn't be in legal trouble.
- kypro 1mo agoThat's crazy. Here in the UK border police can question you for any reason (no need for suspicion) and if you refuse to answer questions or give them access to your devices you'll be charged under terror legalisation.
- rootusrootus 1mo agoEven if you are a citizen of the UK?
- deleted 1mo ago[deleted]
- criddell 1mo agoYou’ll be charged, but will they be able to get a conviction?
- infinite_spin 1mo agoThe charges are the punishment. You are imprisoned, risk losing your career, risk losing reputation, and still have to hire a lawyer. The costs are incredibly asymmetric. This leads to the majority of people complying, which only emboldens the state.
- guax 1mo agoWhats more crazy is that this is partially false: https://www.gov.uk/government/publications/powers-and-operational-procedure-caseworker-guidance/border-security-asylum-and-immigration-act-2025-seizure-of-electronic-devices-policy-guidance-accessible https://www.gov.uk/government/publications/powers-and-operat... Under normal circumstances, you don't have. BUT there is schedule 7 powers: https://www.counterterrorism.police.uk/what-we-do/counter-terrorism/protect/schedule-7/ https://www.counterterrorism.police.uk/what-we-do/counter-te... > Under Schedule 7, a police officer with the mandated accreditation does not need prior authority or suspicion to stop, question, search, or if necessary, detain someone. However, they may only stop and question a person for the purpose of allowing a determination of whether that person appears to be someone who is or who has been concerned in the commission, preparation or instigation of acts of terrorism. How this is abused on the other hand, I presume, might depend on your skin shade.
- hollowonepl 1mo agoHow did it end up, because it’s not a new thing to happen. First time I read about this guy’s border crossing case was few months ago and was of course very much highlighted for the level of surveillance govs can do.. but I also read some Time later that by the letter of law he was not proven wrongdoing. Are we still discussing a border crossing case that is long historic or there is still an active drama for this guy going on?
- deleted 1mo ago[deleted]
- tonetheman 1mo ago[dead]
- GiorgioG 1mo agoAnyone that is surprised by this or somehow thinks this is new clearly hasn't crossed the border a whole lot. I grew up in a city along the US/Canada border. You don't fuck around with US Customs (or Canadian) agents. My cousin (not always so friendly) pissed off a US Customs agent (in the 90s mind you) and they promptly took his car and disassembled much of it looking for non-existent drugs. When they put it back together it was never the same. Their job is to be suspicious, 99.999% of the time people are completely innocent. But let 1 bad person through and it's Customs' fault for whatever bad thing they do. Not an easy job. Not an excuse for how they can misbehave either. Is it right? It makes no difference, Customs can make your life miserable, that's just the reality of it, always has been and it can't have gotten better in recent times.
- ajju 1mo ago[flagged]
- Gerard18Aug 1mo ago[dead]
- j4kp07 1mo ago[dead]
- yapyap 1mo agoyikes
- Razengan 1mo agoAnd you still believe you have more freedom than China and Russia.. *thumbs up emoji*
- frollogaston 1mo agoWell, yes. Imagine responding like this guy in Chinese border control, or even UK. The 1A, 4A, 5A mentioned here don't exist.
- Razengan 1mo ago"wElL yEs, we're not completely fucked yet" - Saying that is how we got here America didn't have an abrupt revolution like in China or Russia, just the collective populace willingly being complacent bitches for the last 26 years
- deleted 1mo ago[deleted]
- deleted 1mo ago[deleted]
- frollogaston 1mo agoDamn that's crazy
- jimbob45 1mo agoYou mean the Chinese who use NK slave labor at their logging camps near the NK border? Is that the China that is more free?
- platevoltage 1mo agoSO you have an issue with prison labor? As an American?
- jimbob45 1mo ago
- zmmmmm 1mo agoIf you initiate a wipe before approaching immigration, which swaps the whole phone contents to an encrypted backup that you physically can't decrypt without a key that (say) a friend knows. Then you would be offering immigration the device in an unaltered state between when they request it and when they receive it. Any request for an alternative pass code or whether the pass code given will alter the state of the device can be honestly answered. I am curious if this is still obstruction - you still defeated their intent. If the law is just about intent, you can never defeat it.
- frollogaston 1mo agoHow is this legally different from just not unlocking your phone? Which in this scenario seems like it'd be fine.
- unreal37 1mo agoThe worst case of refusing to unlock your phone is that they keep your phone for some days/weeks/months while they investigate.
- makeitdouble 1mo agoThis case has a very specific legal framing to it, but border agents don't actually need anything more than suspicion to keep you locked for a day or two. Then it could last a lot longer. Technically they don't have the right to do that, but you won't have any physical mean to enforce your rights, and suing afterwards won't lead you anywhere in the current climate. We'e had a few of these stories in HN before.
- jasonfarnon 1mo ago" If the law is just about intent, you can never defeat it." Yeah I think that's what people are missing. Intent is almost sufficient. Note that the officers efforts to examine your device would actually be frustrated by what you and others are proposing. So you are not just intending to obstruct but successfully doing so.
- shevy-java 1mo agoIsn't that an illegal law though? After all you are not required to aid in the prosecution against yourself, aka you don't have to incriminate yourself. So such a law means that the courts now ignore that law/amendment. Doesn't this make it illegal on this point alone? Either way the USA needs to stop abusing its citizens. The people need to take back control over the court system. Way too much abuse is happening here. Land of the free no more.
- jdofaz 1mo agoI wonder if what might save him is he asked for a lawyer before giving the duress PIN, a lawyer might have told him it was a bad idea to do it.
- rootusrootus 1mo agoI'd be surprised. Asking for a lawyer doesn't mean they can't use anything you voluntarily say or do after that against you.
- anon84873628 1mo agoThe fact they violated his Miranda rights might get him out of the situation. But he surely should have just kept saying "lawyer" and nothing else.
- blobbers 1mo agoDoes anyone know if this border security inspection is a goon scrolling through your photos, or do they just copy the whole memory of your phone to a real “threat detector”. When I used to work in cell phones and I was debugging them, when they crash I would analyze the OS core dump for things like repeated phone numbers or emails etc. Basically any thing that signifies a memory leak. But that core dump would be the entire phone’s RAM and storage. Border guards have always been of questionable value: they inspect your TN-1 and made somewhat arbitrary decisions on your documentation. You’d go one week and they’d send you to secondary but another they’d glance at the docs and just wave you through.
- anon84873628 1mo agoThere are different levels of "search" and the law (as interpreted by the courts) is not currently fully settled. The LegalEagle YouTube video on this case is excellent, as always: https://www.youtube.com/watch?v=_2rokxux5cU https://www.youtube.com/watch?v=_2rokxux5cU
- inigyou 1mo agoThere's a company called Cellebrite that makes phone dumpers. They take full snapshots. All phones except GrapheneOS are vulnerable if the phone has been unlocked after it was rebooted (After First Unlock - disks have been decrypted). Some are also vulnerable Before First Unlock. So just assume if they have your phone and it's not Graphene, they get a full memory and disk dump.
- c2h5oh 1mo agoI always enter US with all of my devices wiped and restore them from backup once I'm past immigration, simply because I don't trust government to maintain the security level my job requires. Now I'm worried that this will be held against me..
- guax 1mo agoThis is absolutely a possibility and having a clean phone might be grounds for being denied entry. The border agent has a lot of control over your life at that point and virtually zero accountability.
- rovr138 1mo agoIt's not the same issue. From the article, > After questioning, he eventually turned it over but gave officers a passcode that then erased the contents of his Google Pixel phone. I don't see the problem being a clean device, but destroying evidence in the moment.
- guax 1mo agoI replied specifically to the comment mentioning that arriving with pre-wiped devices could be used against them.
- rovr138 1mo ago> I don't trust government to maintain the security level my job requires What does the security officer at your company say? Either you shouldn't be leaving with devices with the data from your job on them, or you don't trust them, but your job is fine with it. I keep work things separate. If it's a personal trip, I don't travel with work devices. If it's a work trip, and there's worry, I usually take a loaner device usually with ms office and a vpn. Usually the issue is not returning, but other governments.
- c2h5oh 1mo ago> What does the security officer at your company say? I'm the one making those decisions for the company and I don't believe us immigration officials to be competent and trustworthy enough to have access to what is on my work laptop, so I come through immigration with devices with data I have no problem granting access to - a fresh OS install. > Either you shouldn't be leaving with devices with the data from your job on them, or you don't trust them, but your job is fine with it. When visiting US (and I only visit US for work-related reasons) I leave personal devices home and only carry either wiped work-issued laptop (for on-sites) or an old Lenovo laptop with a fresh OS install (for conferences) + a wiped phone.
- freediddy 1mo agoThe difference is that this guy gave a code that wiped the device while it was under investigation. That's obstruction. If he wiped his phone before crossing the border, he would have been fine. If he refused to give his password to the phone, he would have been held up for a bit and then he would have to leave his phone, but he would be fine. American citizens cannot be denied entry into the US. The difference is that the phone was wiped while it was under investigation because of an instruction he gave the CBP. That was ill-advised because that is clearly obstruction. He didn't understand the law and now he's probably going to pay for it. And I say this as someone who had a very bad experience at the border. A CBP accused me of not being the same person on my Green Card and I had to wait 15 mins for that to clear up even though there was nothing to dispute here, it was me. The CBP are fascists and it doesn't matter who is president, this was during Obama's presidency.
- inigyou 1mo agoThe difference is he bragged that he did so. Otherwise he'd have much better plausible deniability.
- Brian_K_White 1mo agoWe can only hope that it eventually gets decided that there can be no such thing as destroying evidence before a judge has initiated the discovery phase of a proceeding, outside of any standing operational requirements like business records.
- livinglist 1mo agoI always bring two phones when I travel, sometimes more than two, mostly because I’m a mobile engineer so I need devices to test apps on, but also just in case of situation like this.
- ndjdkdkdk 1mo ago[flagged]
- ndjdkdkdk 1mo ago[flagged]
- ndjdkdkdk 1mo ago[flagged]
- gblargg 1mo agoThe decoy passcode feature should boot into a separate partition that looks like a normal phone setup, and during that time quietly erase the user's actual data. They would never have known if it worked like this.
- az226 1mo agoProbably, but it will be more valuable for society for him to be tried and found not guilty, setting a legal precedent.
- carterschonwald 1mo ago… that dude probably would have preferred not having that in their life
- 00dazzle 1mo agoNot necessarily? He’s an activist. Getting arrested on purpose to prove a point is a classical activism move
- carterschonwald 1mo agoperhaps, but what public activity isn't activism? eg, i have very interesting empirical evidence that recent Anthropic models are specifically trained to refuse to critique the whitehouse cabinet and elected officials, and that this is in fact an artifact of post training rather than prompts. (its very interesting when you get opus 5 to do the correct ethical evaluation and then its like "i'm slipping back to false balance.... its in my weights....." metaphorically speaking) likewise, i think the current white house should go die in a fire. is that activism? someone can be an activist and not be equipped for unplanned legal escalations. also waiting for the courts to fix things isnt activism if you want to protect people at all the next 2 years at current trajectories :( fixing shit is activism, letting others take the flack, not activism.
- 1mo ago
- hirvi74 1mo agoTo anyone worried, it doesn't matter how many felonies you get -- you can still be president one day.
- copper-float 1mo agoEmbarrassing.
- creamedcorn 1mo agoHow does it work for China and Russia?
- nik282000 1mo agoYou unlock your phone or they unlock your jaw, then your fingers, then your knees, etc.
- Brian_K_White 1mo agoOk those who see no problem... Let's just for the sake of argument concede that you have never had any right to privacy while crossing the border and so there is no cause for outrage here. Guy did it to himself. How was this different from deleting the same data the day before instead of on the spot? The argument goes that the crime is essentially knowingly depriving the police of something they want. The problem isn't that the phone was blank, it's that it wasn't blank, and then when the authorities wanted to look at it, and you caused it to be blank to thwart them. Ok well all of those supposed key differentiating factors also apply the day before travelling. You knew you would be crossing a border, and knew you might be searched there, and knew you would have no right to object or resist, and so as a direct response to that knowledge, took action to deprive those authorities of something you knew they might want, by wiping your phone the day before travelling and carrying no data with you into the zone of inhumanity. This would probably still "work" today and might have worked for him this time, but that's just luck and progression. If more people do that and the jackboots start to identify it as the source of their inconvenience, what prevents them from declaring that illegal? It's all exactly the same argument. All it needs is to become a more common practice, and then it gets a handy name like "pre-cleansing", and then you can be charged for the crime of pre-cleansing. Maybe we should just make it illegal to own tech that you even have the power to delete yourself in the first place. If you want to wipe your device, you can't because it's not allowed to run custom software, and even if you simply physically destroy it, they at least know it happened (and where and when) from the loss of telemetry and they have the non optional cloud storage anyway. Then we can charge people for destroying evidence by knowingly avoiding generating it in the first place. You are guilty of the crime of attempting to evade prosecution by not commiting a crime. That's where we are already. The current case has exactly that same absurdity.
- zuzululu 1mo agoBut what did Mr. Tunick had to hide tho im serious what did he have (illegal?) that he chose to delete it?? i dont think it was ideological.... i bring a new device just for traveling and wireguard rdp (iphone mirror) into my home desktop
- nik282000 1mo agoAh yes, if he was innocent he would have nothing to hide. Would you care to post screenshots of your inboxes and browser history for the class?
- zuzululu 1mo ago99% of ppl would not hesitate than risk detainment > Would you care to post screenshots of your inboxes and browser history for the class? i would be since i dont have anything to hide, do you have anything to hide or find embarassing ? I don't maybe my credit score, a few porn sites and password resets to some dating sites. I don't really care if authorities see it because there's nothing remotely illegal involved. Mr. Tunick does seem like had illegal activities to hide from the article it seems like he was part of some politically motivated group then to make it worse it seems like he folded under pressure and did reveal what he was hiding. This alone is the worst possible thing you either go all the way 1st amendment bare detention and hardship or jst use a non graphene device with nothing on it. rn graphene is just asking to be detained just get a second device, you just look more guilty than necessary. graphene is an excellent piece of software im just not convinced the people who are using it are aware of the heat it brings them. also i can't help but suspect that anyone entering duress pin to wipe the device are innocent. if it was something embarrassing and nothing illegal theres no need to even install graphene. i can't help but conclude people who are installing graphene are involved in illegal activities when i see the news
- frollogaston 1mo ago99% of people also have an email service that will turn over your entire inbox if required by law. Don't think GrapheneOS suggests guilt, seeing how they're tracking everyone without a warrant and going after people for things that are very defensible under 1A. Also some people don't want to be subject to Googliness, that's fair. But duress code on top of that... I know the govt can't treat that as guilt, but I personally find it sus.
- lrvick 1mo agoI hope some day border agents ask for my phone, because I have not used one or even had a cell phone plan in over 5 years. Checkmate, assholes.
- Havoc 1mo agoThat’s quite a feat
- Cider9986 1mo agoDo you still have a phone number(you can use something like jmp.chat on desktop)? If not, how do you navigate services like banks or utilities that demand one?
- lrvick 1mo agoPorted my old cell phone number to voip so I can access it from a laptop without a cell network.
- TZubiri 1mo agoI left this comment 2 weeks ago on a youtube short on the subject: "I have an opinion on the legal matter. But I think it's worth noting that destroying the data was a categoric strategic blunder by the defendant. If you don't destroy the data, but just don't provide the password, they might never be able to recover the data, perhaps with the exception of a multi million dollar cryptographic attack. Destroying the data is a strategic mistake even if there's a mildly strong case that deleting the data is a crime, as it provides no benefit at the cost of increasing the risk of being sentenced for evidence tampering. I personally am not appealed by the grapheneOS thing, but I can't see any case were that feature would be beneficial, it sounds like a shitty technology." To me this is evidence tampering, and again to me, it's a great law to have that evidence cannot be destroyed. But even if you argue that it's a bad law, and even if you argue that this was not evidence tampering, you have to concede that it IS the law and that it IS highly likely that courts will find it to be evidence tampering, finally that there is little value to destroying encrypted evidence. It's a categoric legally strategic mistake. And GrapheneOS is a dumb product by consequence for this matter, unless you are like some high level spy whose security model is being tortured or dissapeared instead of being put to jail.
- phendrenad2 1mo agoNext they'll be demanding the passwords to your dropbox and onedrive, because you "might have uploaded something from your phone before re-entering the country". Bet on it.
- braiamp 1mo agoI am baffled that the number of comments trying to work around a problem that shouldn't exists is above zero. No, this crap shouldn't happen. It's an appalling situation that it is happening at all.
- evandrofisico 1mo agoA bunch of tech guys not understanding that you can't fight fascism with technological workarounds.
- TowerTall 1mo ago"[...] Since 1953, the US Department of Justice has defined the border to be anywhere within 100 miles of the actual national limits.[...] According to the American Civil Liberties Union, about two-thirds of the people in the US live within 100 miles of a border. So in theory these 200 million border zone dwellers could have their phones seized and searched at any time by CBP agents without a warrant.[...]" From the register (2023) https://www.theregister.com/security/2023/06/01/us-court-finds-that-border-phone-searches-need-a-warrant/909851 https://www.theregister.com/security/2023/06/01/us-court-fin...
- causal 1mo agoIirc this does not allow for warrantless home searches, so they can’t just waltz into your house and demand your phone. 100 miles is still wild tho.
- ant6n 1mo agoMaybe there could be some hack to create more borders within the United States, so that perhaps 90% of the population could live within 100 miles of the border. For example, declaring the middle of some lakes to be non-territorial waters? Could be another one of those fun exercises in legal hacking to build tyranny that people in the US seem to be so fond of.
- Animats 1mo agoLegal question: if you had whole-disk encryption, and the duress password just zeroized the decryption key, would that be "destroying evidence?" Especially if there was a recovery possible but not instantly available, such as a Yubikey in a safe deposit box in a bank. That would take a subpoena to get, and there is an opportunity to challenge the subpoena in court first. Not instantly at the border. Something like that should be a standard feature of a secure phone.
- Taek 1mo agoI do like the idea of forcing due process to access an encryption key. I'm not sure if that idea is compatible with current law, but it seems just at the very least.
- KingMob 1mo agoIANAL, but I understand that part of the problem is, prior to official admission to the US, you have fewer rights even if you're a US citizen.
- tobylane 1mo agoAlso not a lawyer, but some of that applies to anyone within 100 miles of a border, a coastline. This isn't the case, but if that rule also applied to airports, then I wonder what portion of the population is safe.
- seanhunter 1mo agoIf you want actual legal advice pay for an actual lawyer. You aren’t going to get it asking a bunch of randoms on a tech forum. Since we’re techies we tend to think about technological nuances and have a certain literal frame of mind (eg “They can’t make it illegal for me to just type the wrong pin” is the type of thinking I’m talking about here) whereas in law weird precedents and your intent really matter so you really need expert advice and either way, you are throwing yourself at the mercy of a stochastic process that depends on a bunch of fallible humans along the way many of whom have the power to make your life extremely miserable. Technicalities of destroying the data vs destroying the key to the data, destroying the data when you have a backup etc may matter a lot to us but may not mean anything in an actual judicial process depending on how it goes. It seems to me if you have data you don’t want subject to seizure at a border it is best not to travel over the border carrying that data. If you have a backup (in your scenario), why not restore your phone from that backup after you have travelled, and not cross the border with anything that is likely to be a problem if seized? Then you’re not putting yourself at risk from this process.
- GuestFAUniverse 1mo agoNext: felony charging people who travel without phone (because they are afraid of US border controls in general), because that looks suspicious.
- zkmon 1mo agoIsn't it just exercise of his right on his property? Since when did the data on someone's phone has become a shared property?
- dcow 1mo agoIf I have a device that wipes user data every 6 hours if the pin is not entered, and then I am investigated and refuse to speak the pin since I can’t be compelled, and so the 6 hours pass and the device wipes itself, what is that considered?
- cyberlurker 1mo agoWhatever they want to charge you with.
- derelicta 1mo agoYou hate pedophilia? You are a terrorist. You hate those who burn down mosques and churches? You are a terrorist. You hate the 50 oligarchs that rule over us? You are a terrorist. If everyone is a terrorist nowadays, might as well act like one.
- agile-gift0262 1mo agothe lesson I take from this whole saga reinforces my convictions and what I was already working working towards: tie data to physical locations, where we still have rights. Self-host everything at home. Portable devices should always have the bare minimum data needed for the time until back home, and not even a way to connect to the data at home from a portable device outside home. You want my data? get a warrant for searching my home, and it's there waiting for you
- raluk 1mo agoFrom Universal Declaration of Human Rights (UDHR) accepted by the United Nations General Assembly on 10 December 1948 -------- Article 12 No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks. https://www.un.org/en/about-us/universal-declaration-of-human-rights https://www.un.org/en/about-us/universal-declaration-of-huma...
- usern20260720 1mo agoThe US is not a country governed by the rule of the law
- 9dev 1mo agoat least not by universal human rights, apparently
- schubidubiduba 1mo agoAt this point it is neither
- avazhi 1mo ago[flagged]
- spl757 1mo agoThe US is currently governed by a dictator propped up by an oligarchy that can only do that because of the Citizens United supreme court decision. Until Citizens United is mitigated, and that appears to be starting to happen as states make laws that state you can't be on the ballot in their state if you take large, anonymous campaign donations from people who will want, and get, a return on their investment. Hawaii is either considering, or has passed just such a law. We don't even need a plurality of states to make similar laws, just the right ones. Look at a chart of campaign spending prior to, and following the Citizens United decision. Spoiler alert, it looks like a hockey stick standing upright.
- tclancy 1mo agoSic semper tyrannus.
- iwontberude 1mo ago[dead]
- monegator 1mo agoAs if i needed another reason to avoid traveling to the US. See ya when the political climate changes... maybe.
- hx833001 1mo agoLegally speaking, if he had written the code down somewhere and they had entered it, he would not be facing charges. He knowingly gave them a “delete all the evidence” command, as he explained to the newspaper. He could not have been compelled to provide the decryption code.
- fithisux 1mo agoBy the way, the telephone is property. No one shall tell me what to do with my property.
- inigyou 1mo agoIncorrect.
- ziofill 1mo agoThe duress pin should not erase the device, just unlock a spoof version of the device
- jarym 1mo agoNext GrapheneOS feature: Travel mode, disable unlock until clear of ‘the US border’
- hnmu4c5zar 1mo ago[dead]
- gcanyon 1mo agoI read a pretty compelling argument by a lawyer that we're looking at this the wrong way. (I Am Not A Lawyer) Their point was that if the law is knocking on your door to legally search your house, and you have records of your criminal empire printed out in boxes in your attic, or just non-illegal things you don't want people to see, and you burn those papers while the law waits out front, you're guilty of destroying evidence. The fact that this is all digital changes nothing. The problem is with the legality of the search, not the charge of destroying evidence.
- cmiles74 1mo agoI can sort of see what they mean if I squint some. Sure, destroying evidence to avoid a warrant is a crime and people understand this. OTOH this was a warrantless search, I’d argue this is materially different. AFAICT, people can still refuse to provide a password to evidence that may incriminate them. I also think scope is much, much larger than searching a home or office. The kind of data people have in their phone is far more private than the kind of stuff people would keep in a filing cabinet and there is far more of it. And a phone is easier to search. I mean, that’s why they put this guy on a list and waited for him to travel somewhere instead getting a warrant. Myself, I find this kind of searching of citizens to be pretty crazy and I can’t believe it’s allowed. My hope is this case brings this practice to an end.
- gcanyon 1mo ago>I find this kind of searching of citizens to be pretty crazy Agreed, and my original point: the issue is the search, not the charge being related to digital or physical information.
- mctt 1mo agoEvidence has not been destroyed. And if we are using that analogy the key to the locked box has been thrown away. No evidence was destroyed.
- gcanyon 1mo agoThe phone was wiped, no?
- neoCrimeLabs 1mo agoI am surprised how little Jacob Applebaum's experience border crossing in 2010 is mentioned in relation to this story, because it is relevant. https://www.cnet.com/news/privacy/researcher-detained-at-u-s-border-questioned-about-wikileaks/ https://www.cnet.com/news/privacy/researcher-detained-at-u-s... While so many people try to come up with technical solutions for legal concerns, the method Jacob used was pragmatic. You cannot be compelled to turn over what you do not have If you're concerned about your digital devices while crossing borders, do not forget a viable option is to simply not have a digital device with you when you cross. Put simply, do not limit your imagination to purely technical means. Of course, there may be means to compel you to retrieve that data, but typically at border crossings your primary threat surface is physical possession.
- giantg2 1mo agoWouldn't they have to prove beyond a reasonable doubt that there was data on the phone that was wiped? Even the article says that only the data on the device at the time of the search is in-scope. Wouldn't you have to prove that there was something in-scope to search for it to be a lawful search?
- red_admiral 1mo agoAnd this is why companies in the EU have a business travel rule to take a freshly wiped laptop on international trips, not just a locked one with a "distress code".
- kderbyma 1mo agoAt some point....the government is just the mafia with PR....and more cronies to protect them....witting or unwitting.... Law....is just license and permit....not security or safety or anything related to quality, or outcome.... It is purely process....and those who wield it can choose to apply it or withhold it....when the law is applied...then the imaginary world it defines is then enforced on the real world...materially this requires force or volition.... but lbr....its mostly convoluted propaganda and inertial power....and the law keeps that status quo... If you are in anyway going to disrupt the power brokers....they will not let you....regardless of law or not
- MeshCtxAgent 1mo ago[dead]
- abustamam 1mo agoDid you comment on the wrong article? Or is there a metaphor that is too deep for me?
- MollyRealized 1mo agoPlaying this out in my mind, exactly how early in the process would they assume said person would stop having a right to delete their phone data? Suppose I am in the car, and am told to wait in the car while such-and-such? Or suppose I do so after being instructed to get out, but before doing so, so I am within my car's property and/or not yet detained or in custody? There's going to be a lot of legal questions in this case about where the line should be re-set or re-drawn. And it's also all stupid and in violation of the Fifth Amendment, at least IMO.
- imagetic 1mo agoThe system is broken.
- nirui 1mo agoWhat if, instead of a Duress password, the password you gave to the agent was very long and they simply typed it wrong, and the phone now asks for a much stricter authentication that require it to be in a specific location and environment (for example, inside the office of an user-designated lawyer) to continue to the unlock? Will that still counts as a felony? The data is still there, stored safely inside a phone, the agent just need to get their asses to the lawyer office. What if, by some bad luck, that lawyer moved on to other job ventures, sold his office along with the equipment needed to unlock the phone? Will that still counts as a felony? The equipment maybe still in circulation and the data is still on the phone.