4 ms·
According to the article, he was actually using GrapheneOS and gave the border official the Duress PIN. So I guess technically it was the official that erased t
by floathub 1mo ago
According to the article, he was actually using GrapheneOS and gave the border official the Duress PIN. So I guess technically it was the official that erased the data :-)
- gruez 1mo ago[flagged]
- deleted 1mo ago[deleted]
- hamper653 1mo agoThere is a difference between exploding a bomb and deleting your data. One is a crime.
- LoganDark 1mo agoDeleting your data is absolutely a crime when you know the authorities could've wanted whatever it was you deleted -- even if they haven't told you yet. It stands to reason that providing a duress PIN that deletes your data when entered would be a crime as well, if said data is of interest. Not to say that I personally agree with either of those cases. But what is considered crime can get pretty unfair when it comes to the authorities thinking you did something wrong.
- bdangubic 1mo agoCan you provide a statute number for this crime please? Any federal or even state statute will do
- gruez 1mo agohttps://en.wikipedia.org/wiki/Tampering_with_evidence https://en.wikipedia.org/wiki/Tampering_with_evidence
- bdangubic 1mo agoFirst, that is not an actual statute and second exactly what "evidence" is my phone, evidence of what exactly?
- LoganDark 1mo agoEvidence of anything. You're tampering with evidence if you act to prevent them from seeing something, even if they had no reason for suspicion. Like how you get arrested for fleeing even if you didn't do anything wrong.
- someothherguyy 1mo agohttps://www.law.cornell.edu/uscode/text/18/2232 https://www.law.cornell.edu/uscode/text/18/2232 is what he was charged with (a) see also: https://en.wikipedia.org/wiki/Border_search_exception https://en.wikipedia.org/wiki/Border_search_exception
- LoganDark 1mo ago> seems like a stretch though I think the issue will fall on whether the encrypted data on the device (or its decrypted counterpart) counts as property. The rest looks pretty clear-cut to me.
- LoganDark 1mo agoThere is a federal criminal provision, 18 U.S.C. § 1519 (destruction, alteration, or falsification of records in federal investigations) > Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed under title 11, or in relation to or contemplation of any such matter or case, shall be fined under this title, imprisoned not more than 20 years, or both. That covers the first part of my comment. As for the second part, there is 18 U.S.C. § 2232(a) (destruction or removal of property to prevent seizure) > Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government's lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both. IANAL, but the encrypted data on the device could be considered property, and the act of providing the duress PIN in place of the real one could be considered a knowing action for the purpose of preventing the government either from continuing to hold that data under its control, or from seizing the data into its control in the first place (since the data was never decrypted).
- yodon 1mo ago> Can you provide a statute number for this crime please? Any federal or even state statute will do The google search required to find the answer ("federal statute for destruction of evidence") is shorter than your question here. "Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry..."[0] [0]https://www.law.cornell.edu/uscode/text/18/1519 https://www.law.cornell.edu/uscode/text/18/1519
- hamper653 1mo ago> knowingly Did he know he was suspected of something? Was he suspected of something?
- LoganDark 1mo agoIt's more about knowing the PIN would wipe the device, and providing it with that intent. Edit: 18 U.S.C. § 1519 doesn't seem to cover this (unless it covers the act of setting up the duress PIN in the first place as "altering"). § 2232(a) covers actually knowingly providing the duress PIN.
- croon 1mo agoLet's say I want to retire my laptop to my kid, so I reformat it. Are you saying in the eventuality that federal police then wants my laptop that I have committed a crime? If so, on that assumption, should no one ever be able to erase data on their hardware? Is it schrodingers guilt, that you're simply not guilty until someone looks, and then you are? And if not, you haven't answered GP's question.
- yodon 1mo ago>Are you saying in the eventuality that... Legal cases are adjudicated by human judges who have been dealing with scenarios like this for thousands of years, since long before the invention of software and laptops, and who are not the least bit challenged when presented with strawman scenarios like the one you called out.
- hamper653 1mo ago> when it comes to the authorities thinking you did something wrong Did they though? Was there an actual investigation going on?
- LoganDark 1mo agoHere "wrong" includes phony bullshit like going after political activists. Even if you did nothing actually wrong, and you know it, and you can prove it, successfully messing with the authorities tends to be pretty difficult.
- gruez 1mo ago>There is a difference between exploding a bomb Mines (in wars, as implied by "solider") aren't illegal. Also even for the first example there are certainly improvised explosives you can set up that isn't criminal to create or set off, fireworks for instance. Same with a barrel of gasoline. It's certainly a crime to use it to kill someone, but that's my point. By OP's logic it's not the person who set it up's fault, it's the person who triggered it.
- LoganDark 1mo agoIf you set up a device to explode once someone enters a room, it doesn't matter who set it off by entering the room if they had no idea the room would blow up. I don't think it'll be very easy to get out of liability in this case. The duress PIN is a feature explicitly designed to delete all data when it is entered, especially in cases of coercion like this. There would be more plausible deniability if officers had simply discovered it somewhere and tried it on their own, but in this case it was knowingly provided directly in place of the real PIN.
- mc32 1mo agoIntentional destruction of evidence is also a crime. Now, whether this applies to this scenario I suppose will have to be determined by the courts. Destroying potential evidence before suspicion is not a crime. Destroying it once under suspicion is a crime. So anyone can destroy their data at their hotel room even just before entry even if the data contains evidence of crimes. Of course the courts could take that into evidence to support the argument that there were crimes but it would not be a crime in and of itself.
- ComputerPerson 1mo agoGreat comment. Wish it was the top one so I didn't have to read through the others to get here. Do you have thoughts as to how the courts would debate the deletion that you could present on a similar intellectual plane?
- LoganDark 1mo agoDestroying potential evidence before suspicion is a crime if done with intent to impede a future investigation, even if the investigation hasn't yet started. Your example would be a crime if it could be proven that there would likely have been evidence in what you deleted.
- spacebanana7 1mo agoI wonder whether it'd be better for a duress PIN to delete existing data and also create a semi plausible artificial profile to hide the deletion event.
- dredmorbius 1mo agoThis discussion was raised last time this story was discussed. I was among its advocates: <https://news.ycombinator.com/item?id=49061890 https://news.ycombinator.com/item?id=49061890>. Briefly: no. Less briefly: <https://news.ycombinator.com/item?id=49060780 https://news.ycombinator.com/item?id=49060780> and <https://news.ycombinator.com/item?id=49060716 https://news.ycombinator.com/item?id=49060716> (from the grapheneos HN account directly).
- spacebanana7 1mo agoThanks for sharing - I get the concerns people have raised in those threads, however I still feel something in this space could be useful. Even a duress PIN which triggers predefined deletion of certain folders, messages and apps could reduce law enforcement exposure significantly.
- grapheneos 1mo agoDeleting arbitrary directories, messages and app data would be highly unreliable. There's a high likelihood of the data being recovered. It's not how computer filesystems and storage are designed to work. Reliable deletion of data requires setting it up to be reliably deleted later on by having it encrypted on storage with keys which can be reliably prevented from ever being obtained again. Wiping the overall data on the device via a factory reset, OS recovery mode or duress PIN/password prevents recovering any of the data because it reliably wipes material needed to derive key encryption keys and also reliably wipes the encrypted disk encryption keys. Wiping the encrypted disk encryption keys alone would not be good enough because they're stored on the SSD so imaging the SSD and restoring it could preserve the ability to recover the data. The way the key material needed to derive the key encryption keys is wiped prevents recovery via imaging the SSD mainly due to the secure element. There's already support for reliably wiping data at the granularity of Private Spaces and secondary users. Those have their own encryption keys and can be reliably deleted due to having their own Weaver slots in the secure element and other hardware-based security integration. Apps can also assorted generate encryption keys in the secure element and use those to encrypt data where it can be reliably deleted via wiping the hardware keystore keys. That requires apps built to have granular storage and encryption of their data. Despite it being possible to wipe a secondary user or Private Space reliably, the past existence of it and when it was wiped will be easily discoverable via the main Owner user and system data. Preventing discovery of those profiles having existed requires an overall wipe of the data. It isn't feasible to hide it without doing that and hiding it would involve a whole bunch of unreliable removal of data without a way to prevent recovery along with redoing a bunch of statistics and other metadata to hide that there was another profile until recently. For example, things like the battery and data usage stats directly refer to the profiles. Even hiding it from naive analysis not looking at the leftover data on storage would still require changing a bunch of things to hide it. Making data deletion of the data reliable for a whole profile or the whole data partition also requires a reboot or shutdown. Consider how much data gets loaded into the page cache and many other forms of data in the Linux kernel and other processes. Consider how much linger around in various kinds of registers, etc. including outside of the OS itself. Reboot or shutdown has code to get rid of this and the device sitting there turned off or booting again also gets rid of it. They were clearly going to hook his phone up to forensics software on a laptop and had done what they needed to do in order to justify it for their own policies. It would not make sense to set up everything they did simply to have someone non-technical manually sift through his apps. They have widespread access to forensic software and also more advanced software with exploits. They definitely have easy access to it at a major Atlanta airport. The adversary in this case is not a non-technical human but rather advanced software from Cellebrite who are fully aware of alternative operating systems and document information on it. Their documentation directly refers to GrapheneOS and has tables listing their (currently very limited) capabilities against it. This story got widespread news coverage and is widely known about. That should help make it clear how important it is for features to work against adversaries aware of these kinds of features. Our duress PIN/password works against adversaries aware of it. If they don't coerce a PIN/password from someone or don't enter a coerced PIN/password because they know it could be in use then the feature has worked. We want to improve the feature with secure element rate limiting integration in the future so that an OS exploit cannot be used to bypass it. The secure element already prevents an OS exploit from bypassing the limit of 20 total attempts for deriving encryption keys with massively increasing delays between those attempts. It used to solely be based on delays with throttling quickly reaching 1 attempt per day after 140 failed attempts but now there are only 20 total unique attempts. The past 5 failed unique attempts are temporarily remembered and discarded when entered again rather than trying to use them again for usability.
- nkrisc 1mo agoI don’t think that would fly as a defense in court.
- phoghed 1mo agoHe’ll just have to pray the scene wasn’t recorded and his real PIN was one digit off
- fsckboy 1mo ago>I don’t think that would fly as a defense in court but that's not the point, the point is to not wind up in court by presenting a phone that no long contains evidence but seems plausibly like your phone so doesn't arouse suspicion
- deleted 1mo ago[deleted]
- dmitrygr 1mo ago> by presenting a phone that no long contains evidence Evidence Tampering https://xkcd.com/1494/ https://xkcd.com/1494/
- forgotmypasswor 1mo agoYeah if they can catch you and prove it.
- MBCook 1mo agoEven if they can’t prove it, they can make your life really miserable for quite a while.
- forgotmypasswor 1mo agoIf it was implemented in such a way, there would be no reason to suspect anyone of using it because it would be totally indistinguishable from not having used it. At that point they have no grounds for legal action. Unless they could monitor FS/disk activity, but that goes beyond typical airport security stuff. I'm imagining a duress code that erases select files and any indication that there was ever a duress code set up in the first place.
- OutOfHere 1mo agoNo, to my knowledge, they ask you to enter your PIN/password yourself. They don't enter it for you. I believe he entered it himself, at which point the erasure began. The erasure process was witnessed by the officer.
- foo12bar 1mo agoFrom https://arstechnica.com/gadgets/2026/07/activist-charged-with-felony-after-giving-border-agent-duress-code-that-wiped-his-phone/ https://arstechnica.com/gadgets/2026/07/activist-charged-wit... > Tunick provided this code to an agent, who entered it on the phone, after which “the screen went blank, flashed several times and the phone appeared to restart.”
- rglover 1mo ago[dead]
- greatgib 1mo agoSo the real problem in the end is that your duress system should not put a big message "erasing all data" but "loading" slowly and just look mostly empty.
- OutOfHere 1mo agoYou sir have nailed it. Unfortunately, GrapheneOS seems too stuck up to eagerly appreciate and address such real world nuances.
- Cider9986 1mo agoThey don't add features that rely on security through obscurity, would give attackers tons of attack surface, is physically impossible to make actually deniable, and could put regular GrapheneOS users in physical danger in authoritarian regimes.
- dkga 1mo agoInteresting. So is this GrapheneOS indeed operationally good for keeping one‘s data private?
- spencerflem 1mo agoYes if you don’t mind getting arrested by our fascist border police
- fleroviumna 1mo ago[dead]
- michaelt 1mo agoI mean, it sounds like it would be even better if the duress response was more subtle. A duress code might let me wipe my phone when someone holds a gun to my head and demands I unlock it. Problem is, there’s still someone holding a gun to my head.
- bengt 1mo agoHe had an e-reader and phone. My solution would be set the phone's duress pin to the e-reader's actual pin then consent to the e-reader search providing its pin and see what happens. The actual solution is cloud backup + re-image after the border.
- victorbjorklund 1mo agoNot how the law works. If I put a bomb in a box. It will explode if a certain pin is put in. And you ask ”can I open the box? What is the pin?” And I say ”here is the pin to open it” and the bomb explodes. Do you think I can claim they blew up themselves ?
- kelseyfrog 1mo agoYes. Because law enforcement assumes there's bombs in boxes by default and defers to the bomb squad to understand the box before they touch it. Why would the bomb squad trust the box owner to help them defuse it? To understand the issue, you have to construct a proper analog.
- kelnos 1mo agoSure, you're right that this analogy is bad, because that would never happen. But if it did, you'd still be on the hook for the bomb, even though technically the LEO set it off through incompetence.
- csallen 1mo agoAn analogy should not be judged on whether or not it can realistically happen, nor whether it can be manipulated in some way that capitalizes on the differences. Because the point of an analogy is not to provide an realistic or identical situation. On the contrary, the point of an analogy is to use a different situation in order to illustrate a very narrow similarity and make a point. If the analogy illustrates and makes that point well, then it succeeds.
- victorbjorklund 1mo agoI never told you it is a box with a bomb. You just asked if you can have the pin. You can do another example where you give false information with the intent of making another person take an action that they don’t wanna take and would not take unless you had provided false information. You are causing the action to happen. Just like if you yell fire in a theater. You didn’t stamped anyone to death. But your words caused it.
- jbird99 1mo agoA better feature would be a 2nd PIN that unlocks the phone to a secondary profile, which you would leave pretty bare for situations like these.
- unreal37 1mo agoOr smarter yet, not bare. Looks like a normal phone - innocent-looking vacation photos, innocent-looking social media accounts, innocent-looking email....
- ChoGGi 1mo agoWith some embarrassing porn; something that would make it feel legit and cause a distraction.
- Grimburger 1mo agoA few hundred personal dick pics and they'll be handing it back quickly.
- Cider9986 1mo agohttps://news.ycombinator.com/item?id=49395135 https://news.ycombinator.com/item?id=49395135
- unreal37 1mo agoHe is charged with obstruction. Not "erasing data". Was he intentionally trying to hinder a search that was being legally conducted? https://en.wikipedia.org/wiki/Obstruction_of_justice_in_the_United_States https://en.wikipedia.org/wiki/Obstruction_of_justice_in_the_...
- ImPostingOnHN 1mo ago> Was he intentionally trying to hinder a search that was being legally conducted? Doesn't seem like it, no. It seems like the search had no legal basis, and so no legal search was hindered.