The naivete of some of the comments here is astounding. It doesn't matter whether you're right, it doesn't matter whether it's the law, it's irrelevant that you have rights, etc. Those things are of the past now, for the US.
I think it would be easier to understand the playing field and choose your actions accordingly, if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech.
The social dynamics are the same - the abuses, the selective enforcement, the lack of recourse, the same characters in the roles of various levels of "law enforcement" and "politics". I'm so very sorry, but the best you can do from here is speedrun the collapse.
> if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech.
I'm pretty optimistic that after the next general America will be ready to give up on the extremity of late turn over a new leaf. I fully expect a new president to be ushered in, whether R or D, and for some level of normalcy to start creeping back.
The Soviets lost eventually, I don't think America can lose. Canadians like myself have watched America win for our country's entire existence; I am unconvinced that a decade of silliness is enough to compare America to East Germany.
In 2016 I remember Americans saying this was the end of the line and the country was doomed. 10y later they're richer than ever and its companies have global dominance of the most world-changing technology of the last 20y. I just don't think "the collapse" is coming anytime soon.
If anyone's interested in a friendly wager, my email is open. I'll happily go 1:1 odds that America will have a new president come 2029 and the country will still remain the world's richest and most powerful.
America dominance on the world is ending, it's a fact. East Asia is at least on par, India is china from 25 years ago.
It's becoming more obvious every day. And yeah, people in 1910 watched Europe dominate the world for about 1500 years. Yet it came to an end.
If you want to Speedrun the collapse, vote for trump. He sure is making a good job right now with diplomacy, lack of long term planning and just getting all your allies to hate you.
Just pick up and leave. Literally. And do not feel bad about it. Also ignore other people opinions. There is like a dozen of places to go to. The easiest? UAE freelancer visa. Yes I know, I know: "... but but the drones! The collapse!" It's all BS. When / if something happens there â go to Panama. Then Costa Rica. You are not alone on this route - but only if you really committed to your freedom. If not - just sit there and vote democrats. LOL.
Moving on from being a unipolar power does not necessitate societal collapse. The UK is still around and their empire fell a long time ago.
> If you want to Speedrun the collapse, vote for trump.
This nonsense needs to stop. You canât vote for him again unless he deigns to run for a lower office (unlikely). Term limits are real. America needs to start planning for the post-Trump era and hopefully mitigate further damage with a blue wave in the midterms. Or with non-MAGA republicans who might even return to actual fiscal conservatism.
Interesting you say that, because as another Canadian, I would say that the sentiment in our country is the opposite of you describe. The actions of our government reflect it.
Canada is moving further from US, not closer. Canadians who support Americans are in the minority at the moment.
I'm not sure how a new US president would be able to turn it around.. further more, what's to say that the president thereafter will follow suit? How about the next 5?
The simple answer is we need constitutional reform. Term limits on SCOTUS, codification of norms (eg releasing presidential candidate tax returns, not blocking appointee confirmations indefinitely to steal the position for the next admin), anti corruption laws with teeth. Also things like reigning in the absurd executive power bloat thatâs gone on since Lincoln. POTUS was never meant to be a king. There should never be a case where the executive can start a war (conventional, trade or otherwise) without even CONSULTING Congress.
Your day to day is still pretty much normal. If you turned off the news and never read about Felony charges for citizen deleting phone data [1] you'd just in your head remember there are tens of millions of folks flying, going through customs and border security and all that with 0 issues. What you wrote I think regarding the decade of silliness precisely supports the point, in my opinion.
[1] I'm not defending the behavior of border control here, but I also don't think we need to overreact to this one example which is exactly what is happening.
Yeah, that's awful. As far as federal overreach of power goes, that's pretty inexcusable. I'd probably posit that COINTELPRO in the 60s was more insidious, but that doesn't discount this story individually being terrible.
I still maintain that America is not in the midst of its own demise and a comparison to East Germany is inaccurate.
> As far as federal overreach of power goes, that's pretty inexcusable.
Selectively detaining this guy, likely overreach.
Trying to get his phone's unlock code to go on a fishing expedition for whatever they can find, absolutely overreach.
But this guy catching felony charges for giving federal border police a duress PIN to wipe his phone when they asked for an unlock PIN? Not actually overreach.
You have the right to remain silent, not to lie to the police when detained (18 USC § 1001, and many state-level laws to the same effect also exist). Our justice system could not function if people had a right to lie to the police. Once you are detained, whether or not that detention is eventually determined to be lawful, destroying or disposing of your possessions to prevent police from accessing them is also generally a crime.
You fight abuses later, in court. Or, if you're going to use a duress PIN in the moment, you accept the legal consequences.
And yes, giving a duress PIN to wipe a phone when asked for an unlock PIN is a lie which may result in destruction of evidence. And no, the law does not care about "I'm not touching you"-level rationalizations of whether something is a lie or whether it was technically the police who entered the code to wipe the phone. Proximate cause is a longstanding legal concept.
> But this guy catching felony charges for giving federal border police a duress PIN to wipe his phone when they asked for an unlock PIN? Not actually overreach.
I think it's an interesting case that will get litigated in the courts. It seems they'll have to prove that the phone contained "evidence"; it could have just had embarrassing personal photos that he didn't want shared. When a house is raided and someone flushes a toilet, can courts assume they flushed drugs, or does that have to be proven?
I hope he's found not guilty, but either way this definitely is not the "sky is falling", "we're almost a police state" case that folks here are making it out to be. It's a very narrow and novel line.
Despite the normalization of masked federal gunmen kidnapping people based on the color of their skin and the language they speak.... Not even breaking a law in the process, the supreme court legalized racial profiling.
One can just argue about the normalization of people breaking the law by overstaying visas or hopping the border or whatever being the Supreme Court (or whoever you feel like blaming) legalized some other concept that most Americans also find disagreeable.
We don't have to have brown shirts pulling people off the street, and we also don't need to have this stupid fight over simply enforcing our borders like every other country on the planet. Extremists on both sides are as always, simply incorrect. Reject MAGA, reject DSA.
In context to my OP, none of this stuff or policy really affects most people's day to day lives. If you turned the news off you'd probably have no clue people were jumping the border en masse and you'd likely have no clue that those very same people were being arrested and deported.
You are undoubtedly correct that at some point there will be new leadership in the US.
Politics makes leadership change a possibility. Biology makes it an inevitability.
But I don't think the evidence is very strong that switching from one man to a different man, even if the new man wears a blue hat instead of a red hat, will make that much difference against capital and its surveillance state.
This isn't a false equivalence "both sides" argument. I'd greatly prefer the blue hat over the red hat.
But the blue hat only makes the underlying forces of late capitalism a little slower and a little less vicious, while simultaneously legitimizing that system.
Yeah, mostly agree but playing devils advocate, PRISM was authorized under bush, implemented under Obama, and is being abused by Trump. Obama promised safeguards, but itâs pretty clear those were just a ruse. Itâs only going to get worse. The well deserved controversy around Flock is the perfect example.
I agree. It's actually quite insulting to other countries whose actual atrocities were measured in lives lost. I voted for Kamala but Trump Derangement Syndrome is real. He's just a loser, he's not even remotely brave enough to be Hitler Jr.
The guy doesn't have the stomach for real totalitarianism. Just populism, corruption, and weakening the country.
With all due respect, this is a wild take. Things aren't great in the U.S. right now, but they're not even in the same universe as what the Stasi was doing.
> I think it would be easier to understand the playing field and choose your actions accordingly, if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech.
its only with the benefit of hindsight (and being on the winning side- thus the propaganda was never dispelled) that we consider the stasi and so on the way we do.
If it walks like a duck, and quacks like a duck.. might just be a duck.
I donât believe those living ânormal livesâ in East Germany or the Soviet era considered the police to be evil and invasive the way we do today.
> I donât believe those living ânormal livesâ in East Germany or the Soviet era considered the police to be evil and invasive the way we do today.
"normal life" under the Stasi was constant political terror and suppression.
The death counts are low because they thought death too little of a penalty for opposing them - they used psychological warfare (https://en.wikipedia.org/wiki/Zersetzung) and torture instead.
"It is estimated that 5.7 to 8.7 million people died from starvation across the Soviet Union. In addition, 50 to 70 million Soviet citizens starved during the famine but ultimately survived."
the stasi were spying on people and putting them in jail. what exactly is your claim about the difference? is it a difference in distinction or a difference in degree?
The USA started from and has come back from way worse in the past.
Some dark, dark things happened in the USA, and almost every progression had a corresponding backslide - but the tick-tock has always ticked further towards a freer, more equal, and more equitable society.
Iâm willing to hope this era is another âtockâ. But that does require people to not just give up (or even work to accelerate the backslide?!) as you seem to be suggesting is the best course of action.
You can make a credible argument that the American society is less free, less equal, and less equitable than it was at its founding?
There are just so many ways in which this seems crazy to me. I feel like you think youâre luring me into some sort of rhetorical trap - but to pick the two elephants in the room, a large proportion of the population was literally owned by other people, and only white male landowners could vote.
Do you honestly think that our society was more (or as) equal 200 years ago than it is today?
Or even 50 years ago? Even in the 1970s, there were places in the United States that women couldn't get a checking account without a man co-signing on the loan.
We can certainly take issue with how rich countries oppress and exploit poor countries today, but you can't honestly say it is worse today than it was during colonialism.
In law school we skipped border search cases because the border crosser cases can basically be summed up with âyou have no right to privacy at the border.â This has been the common law for 5000 years. It has nothing to do with Trump, or cell phones, or anything other than the notion that a sovereign has an absolute right to know what is crossing its borders.
This has been legal since long before Trump, if you don't like it there's laws in motion to ban it you can support, but entering across a border you've been allowed to be searched without a warrant for decades at least. And if you're being searched and then you destroy what they're trying to search... Here you are.
> US has entered its East Germany / late 20th century Soviet era
> The social dynamics are the same - the abuses, the selective enforcement, the lack of recourse, the same characters in the roles of various levels of "law enforcement" and "politics"
What you're describing is politics in general. The question is not whether abuses occur (they do, everywhere), but whether the system is built to be resilient and course-correct over time.
The thing about freedom is not just that it's less miserable than the alternative; more importantly, freedom enables a feedback loop where people's individual choices carry corrective information: what they buy, what they sell, how much, at what price, who they vote for, what they write/publish, what they read, what they say etc. The system at large can correct itself over time if (a) these choices are allowed to have power to influence the system, and (b) the courts enforce justice without interference by the ruling party.
Not a single communist country in the 20th century stayed communist for more than a few years when only 2 freedoms were allowed: (1) freedom of the press, and (2) freedom of the courts from control by the ruling party.
The Soviets and East Germans suppressed every form of freedom that carried information or potential corrective power, because they maxxed on staying in power above all - they effectively had to. No one wants to be under real communism/socialism[0], so for it to be stable it has to be maximally suppressive.
The US has it's mid-term elections this november, and it's possible, and even likely, that the Democratic candidates will win overwhealmingly. The Democrats are not a monolith, either, the Democratic Socialists of America political group is the very progressive part of the Democratic party, they are the ones that are not accepting dark money campaign donations. I do not agree with a lot of the unrealistic things that some DSA candidates have said, but those or the candidates that aren't winning the primaries. There is a giant blue tidal wave coming in November. Trump will become nothing more than a lame duck "president", and he'll likely be impeached in the House and convicted in the Senate and the Justice System will probably be the final arbiter of his fate. That's the way I see it. And I never believed I would be saying what I just said, but the fact is that since trump was elected, the democrats have flipped 31 (at last count) formorly Republican held seats, and the republicans have flipped exactly zero seats from democrat to republican. The American People are not their goverment, especially right now, even though that's not how it was meant to be, but I know one thing, they are fed up and enough is enough.
You don't need to go to other countries to play your fears, lest we forget our constitution is a pro-slavery document and one of the first acts of congress was the fugitive slave laws.
I think it's more effective to stick to our own history because this country has always been a struggle for workers outside of a small very respite after WW2 that has been actively fought against and weakened since.
> I'm so very sorry, but the best you can do from here is speedrun the collapse.
This is a pretty silly take. If you actually follow the news, all of these issues are getting pushback. It's not at all clear that even a competent fascist-leaning government would be able to push through what the current one is trying to do, and sadly for them, competence in their ranks is in short supply.
The bigger issue has nothing to do with the faddish concerns of the current government. The era we should be looking to is not East Germany/late Soviet - it's more like the Gilded Age. Robber barons need to be dealt with from time to time.
It's a temporary situation, it isn't necessarily a permanent situation.
Tell me how you think East Germany is doing these days.
And no, it doesn't have to take 40 years to right the ship, so long as people get their heads out of their asses and vote. Things are likely to change by the end of this year, and in another 2 years we could have a very different government that could undo a lot of the bullshit going on right now.
Tens of millions have voted for this 3 times in the past 10 years, it succeeded twice. This is not going away, half the voting population of the US wants to live under authoritarian rule and will do anything to take the whole country with them.
Voters change their mind all the time. Sure, there are still plenty in the US who want all this, but Trump's approval ratings are at or near all-time lows, and at least some people who voted for him finally see his lies for what they are, and have regrets.
It's still worrying! His supporters still number lots of people who a) are still somehow too gullible to realize Trump and the MAGA crowd are not going to make their lives better, and b) actively want what's going on. But there are easily more eligible voters in the US who wouldn't vote for a Republican with a gun to their head, or who are finally starting to understand that "sticking it to the libs" is hurting themselves.
It's not going away, but it's likely that it's declining, and possible it will continue to do so. Whether or not it declines quickly enough, before these jackasses consolidate power and break what's left of our institutions... well, that remains to be seen.
You can rage against Trump and republicans as much as you want but in the end the democrats must learn to formulate why anybody should vote FOR them. Even in the current chaos they arenât able to bring up a coherent message and follow through when they are in power. I see the same in Germany. AfD is getting stronger while the established parties get nothing done.
It reminds me somewhat of the state of the Weimar Republic. The democratic parties failed which gave an opening to the nazis.
Voter preferences can change with time, as voters observe the effects of their previous selections. Most voters don't want and didn't vote for authoritarian rule. They are humans with many diverse challenges & concerns in their lives. Their votes are an attempt to balance/compromise among those.
>half the voting population of the US wants to live under authoritarian rule
That's half the people who showed up to vote, not "half the voting population". 1/3 of the eligible voters simply didn't vote, and from the people I've encountered that don't vote, they are mostly left-leaning.
No, stupidity and self-harm aren't going away, those are human traits. The current admin is actively hurting everyone, with tariffs and stupid wars he campaigned that he wouldn't start, ICE in every city everywhere causing chaos even to right-wing supporter-owned businesses (they wanted immigration reform but not like that!). This admin has shit the bed, and even his supporters are feeling that. They are now in the "finding out" phase, and the next phase doesn't look so good for republicans in the next election because of it.
Does anyone on the other side have a credible plan to undo the damage?
Where's the Project 2028 book?
Is there anyone credible putting together the Executive Orders to undo the stack of shit, is anyone putting together a short list of District Attorneys to interview on January 21, etc?
That's the thing that worries me. The Democratic party just doesn't have their shit together in that way. They absolutely should be developing this sort of plan. I expect there is some plan, but I doubt it's as comprehensive or in-depth as Project 2025. And it needs to be.
On a long enough timeline, nothing is permanent. The question is how long it lasts and how bad it gets before it gets better.
In terms of the ending, East Germany was nearly an ideal case. The state just sort of gently fell over. The country got absorbed into a friendly neighbor. There wasn't much loss of life, no widespread destruction.
Then there's East Germany's predecessor state, which ended because it decided to wage war on half the world, and its people bore the consequences. Millions dead, cities wrecked, occupation by foreign armies, the country carved up. "This too shall pass" isn't always a good thing.
Or look at the state that created and sustained East Germany. Borne out of violent revolution, decades of repression, collapse, turmoil, economic hardship, brief flirtation with democracy, de facto dictatorship, no end in sight.
My biggest worry with the US right now isn't the government itself. It's that so many people want this government. Voting doesn't help when the voters want the bad stuff. We could have a very different government in another two years if the people want it. I'm not convinced they do. If they do I'm not convinced that sentiment will last. We already went through this once, and the "actually, let's not give the shitheads power" sentiment fell apart by the next election.
> Tell me how you think East Germany is doing these days.
> And no, it doesn't have to take 40 years to right the ship, so long as people get their heads out of their asses and vote.
so then you admit the outcome here is contingent/conditional. do you understand that means we are already in dire circumstances if the outcome isn't certain?
For exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs. Imagine booting the phone from a flash drive, making an encrypted image of the phone on said drive, and writing a fresh OS before reaching the border.
There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).
Some time ago, Android with a custom recovery could come close to that, but it was fussy and as far as I know, no longer viable. Increased use of TPMs for storing credentials seems to be at least one of the reasons.
It may be fun to fantasize about these things some times, but there is no technical solution to tyranny. Laws are not like code, intent matters. Ultimately if the intent is that the government wants to see your private data, hiding it in any way will be charged - it doesn't matter if you jump through hoops to avoid this specific instance.
This is a half-truth. In a full banana republic, technical compliance with the law will not prevent consequences for failing to do what the authorities want. In a jurisdiction with perfect rule of law, it always will. The USA is somewhere in between.
One of the laws that's enforced pretty well in the USA is the protection against unreasonable search. Most of the time, a search requires showing a judge evidence that the search is more likely than not to reveal evidence of a crime. Exceptions are narrow and specific; the government's options to punish someone who refuses to decrypt data at the border are limited to brief detention and seizure of the medium.
Not yet tested is the idea that erasing data on the spot satisfies the purpose of the border search exception, which is to prevent importation of things that are illegal to import. This case might address that question.
Unreasonable search is always under attack though. There are many instances today of cops forcibly entering a home claiming nothing more than a welfare check, or "we received a call."
Edit to add that its also more difficult than it should be to protect and exercise the right against unreasonable search. If a cop knocks on your door its a consent-based interaction. You can simply not respond, but if you do happen to crack the door they can and will look in for any signs to claim as probable cause. Further there are cases where a person stepped out to talk and when they turned around and walked inside the cop slid right in behind them and later claimed in court the open door was implied consent. (I don't have a link to the court docs unfortunately.)
>There are many instances today of cops forcibly entering a home claiming nothing more than a welfare check, or "we received a call."
Sure, but there are also many instances today of evidence getting thrown out in court due to cops not getting a warranty and poisoning the tree and all its fruit. Rights don't just enforce themselves, there are and have to be a number of layers to the onion to help reduce the violation numbers at each stage.
>There are many instances today of cops forcibly entering a home claiming nothing more than a welfare check, or "we received a call."
And there are also many instances of the city being sued, those cops being sued, losing qualified immunity, losing their jobs, etc, because we do still have recourse when cops do the wrong thing.
If your rights were violated, you stand to get a big payout, and get the cops fired that violated your rights. We aren't powerless, yet.
> And there are also many instances of [...] those cops being sued, losing qualified immunity, losing their jobs
Not really, the data points the other way. Cops basically never have to actually pay for their wrongdoings. Over 99.98% of money successfully recovered from cases against police is paid out by the cities, not cops personally [1]. A considerable number of cops that are fired are also eventually rehired by the same department [2] or a different one [3]. So I don't think it's that clear that you "have recourse when cops do the wrong thing".
Can you link to some of these cases of cops losing qualified immunity? It's an area in interested in but I understand that to be a vanishingly rare outcome - like only in very egregious cases, not just for run of the mill rights violations.
we're far closer to one side of that spectrum than the other. consider the retroactively legalized mass wiretapping, room 641A, NIST compromises, PRISM, 14 Eyes, the other Snowden revelations, etc
then consider this paired with the implementation of mass data sharing between the alphabet agencies, surveillance data sharing from private companies like Amazon Ring, Flock, Clearview, etc. and NSPM-7 ordering agencies to create JTTFs to target organizations like BLM
then consider the unmitigated use of force by federal law enforcement agencies like ICE
I think if this were 1995 your point might be fair but those days are unfortunately long gone
Border search exception lowers the requirements for judicial oversight.
"In United States criminal law, the border search exception is a doctrine that allows searches and seizures at international borders and their functional equivalent without a warrant or probable cause. Generally speaking, searches within 100 miles (160 km) of the border are more permissible without a warrant than those conducted elsewhere in the United States."
Agree with the thrust of your comment, but I had to comment on this:
> In a full banana republic, technical compliance with the law will not prevent consequences for failing to do what the authorities want. In a jurisdiction with perfect rule of law, it always will.
I think you may be misunderstanding that many laws, even in fair, just societies, are intentionally designed to be flexible. The real world is so variable and messy that in many cases it isn't feasible for a law to be written such it can be unambiguously determined whether or not a specific action violated the law. Laws often rely on humans using context to judge whether something violates the spirit of a law, and in a just society, this is a good thing.
My point is that I don't believe the idea of "perfect rule of law" is sensible. Law is always necessarily a bit fuzzy and nebulous.
Normally I agree, but making the implementation initially ineffective is a good way to complicate more far reaching measures.
Americans aren't standing up against this, but they might have considerably more interest if the government was instead trying to ban encrypting data in cloud storage for everyone.
There's also just the fact it's ridiculous I can't have a spare phone ready to go in a few minutes and get it back exactly as I left it.
Yes, trying to solve a regulation or legal issue by some technical workaround will never work, you have to fight it at the same level, legally, or system-wise, otherwise, you will be like the person who tries to wash the stairs from the bottom all the way up, it rarely works, you gotta go up to down, collectively go against the matter rather than individually duct taping it for your own specific needs. In that example, it wonât be far fetched the same ones who made it illegal to wipe your phone to make illegal to install xyz OS or using abc protocol, in fact, thatâs exactly what they are trying to do under the disguise of âprotect the kidsâ and going after encryption or similar privacy related issues.
They would not be so vehemently against it if it did not work. There is a reason E2EE, duress passwords and similar technologies are under such intense assault these days.
GrapheneOS has built-in encrypted backup and restore. It backs up the same data transferred by Google's device transfer feature for moving to a new phone which is nearly all app data, the data in the home directory, contacts and a bit more. Certain apps such as Signal encrypt their own data with another layer of encryption using a hardware keystore key. Signal's own backup system needs to be used for that, although it can just be used as a way to get data into the system backup.
It's worth noting wiping a device shortly before an anticipated search could also be considered destruction of evidence in the same way. It doesn't have to be done after a request for the data to be considered that.
> There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).
This was likely the best move for him to take. They could have held him for a while and wasted his time but eventually would have had to give him access to a lawyer and let him go. Unless they had a recording of him entering a PIN/password, they were nearly certainly not going to get his data from it. He very likely didn't gain anything from wiping it.
He did help every GrapheneOS user by spreading awareness of the duress PIN/password. It was designed around an adversary aware of it and therefore not wanting to attempt using a PIN/password obtained via coercion. In the future, we want to integrate the feature into the secure element rate limiting for key derivation so it can't be avoided by exploiting the OS.
I've restored iPhones before, and it does seem pretty simple. Easier than PCs for sure. It's not instant, but the basic configuration is restored pretty quickly while the bulk data restoration happens in the background while you're able to use the phone.
Depends on the app and security setup. If it's using old school Symantec VIP Access, it will not survive a restore. If it is using TOTP from 1Password, it will. Not sure about other options, those are the two I am most familiar with. Thankfully I only have a single app these days relying on VIP Access.
Think for a moment. What is the difference between giving them a password which wipes the phone and giving them a password which opens a blank phone?
It's the same thing. They punched in a code, they are presented with a wiped phone. Can they prove the guy gave them a distress password and wasn't simply carrying a wiped phone to begin with? No, but they just need to imply that is the reason to charge him with the felony.
Best you can get away with is lack of suspicion. Have a secondary phone with some standard apps on that you use now and then so theyhave a history and just look like you are just not a technical person and read novels on dead trees instead. A lot of work but likely works.
The best technical solution is one code opens to a phone that has things but isn't your actual phone, and then another code that opens to your real phone.
>What is the difference between giving them a password which wipes the phone and giving them a password which opens a blank phone?
They don't get any indication that there was data there to be deleted, and you don't just factory reset but flash w an image of a clean phone that's been used. It has apps, it has accounts, it looks to the untrained eye (because that's who's looking at it) like a phone that was used normally by someone who has done nothing wrong.
Apple makes this very easy. I broke an iPhone and bought a replacement. If you have iCloud, you login to the new phone and you can see which backups you can recover from. If you are transferring a phone, say you upgraded, itâs even easier. You can also image the phone with a connected laptop and store it on a backup drive, which is nice to not use up iCloud limits.
The transfer and backup system are pretty much the same mechanisms.
Restoring is probably order of ~1 hour to go through all the setup. Then some hours to sync any data and updates that need to be redownloaded, apps reinstalled, etc.
I mean, you could ship your real phone to w/e destination ahead of you and bring a $50 burner to the border. If you're a person of interest this won't work because they can monitor you and the destination but if you're a regular schmuck then a burner that never touches your private data or accounts and has a bunch of dummy stuff on it will get you past the border goons.
I used to play around on projects adjacent to Tor and TailsOS, and had an idea for a setup I was researching. It's a little intense and probably has annoying failure modes, but sharing in case anyone else finds it helpful:
- Tasker is an automation app for setting up rules for triggers and actions. It allows extension apps to be created to add new triggers and actions.
- someone at one point made an extension to add an action for wiping or factory resetting when triggered
- there was an existing extension (or core feature) to trigger when certain signals are lost or found (e.g., wifi signals, Bluetooth LE beacons, etc)
So the idea is to carry a BLE beacon (any "item tracking" one works) on your keychain, and an unassuming faraday cage pocket alongside it. If you want to wipe your phone, slip the fob into the pocket, the signal disappears, and your phone wipes. And if you don't have the keychain on you, just refuse to open it right away, as when they put the phone itself in a faraday cage (to prevent it from being remote wiped), they cause the signal to be lost, and it gets reset.
Not sure if all the pieces still exist (I dont think the tasker extension for wiping existed outside a forum post...)
I like the idea of a phone that automatically wipes itself if I donât act to stop it. I wonder about the legality of that if the duress code is considered âdestroying evidence.â
Or keep it in a faraday bag and have the phone wipe if it sees it. If you're ever searched (or otherwise indisposed), they'll open the bag and wipe your phone for you.
Oh hey, I like this variant! So... both the BLE beacon and the phone have a faraday cage, and if they ever appear together outside their cages, the phone wipes?
Perhaps less likely to go wrong than my original proposal when living normal life, as it might wipe if the BLE signal randomly gets lost.
It would be nicer if you could leave phone in cage during security, and remove beacon while loading airport trays ("remove all electronics from their cases..."). the only chance for a failure mode is only when you're going through security, and have the fob outside its case..
But you'd need to be able to leave your phone in the faraday cage pouch while going thru security, which is only ok if they don't notice... (maybe they commonly don't notice small faraday pouches aren't empty... Maybe they wouldn't if you had a secondary mobile device...)
I was imagining only the BLE beacon living in one of those little faraday pouches people put their key fobs in. They should be pretty much transparent passing through the x-ray and a pouch with an airtag in it wouldn't raise any suspicion at all at the airport.
Only once you're getting invasively searched would they (ideally) dump the pouch out into the tray with your phone.
When I've gotten secondary screening the first thing they do is take all my belongings and rifle through them on a table. That seems to be standard practice and I'm sure it was step 1 in Tunick's ordeal.
Both approaches have situations they wouldn't work in. If you're extra paranoid you could do both.
> If you're ever searched (or otherwise indisposed), they'll open the bag and wipe your phone for you.
Isn't that the exact same situation here that resulted in felony charges? Border agent was given a duress PIN and wiped the phone for the owner. Now owner is charged.
I don't see how. Regardless of how you feel about the lawfulness of the overall situation, Tunick gave an agent false information which resulted in the phone being wiped. That's intent.
This requires no action whatsoever from the phone's owner, you could even be unconscious/dead and it would still work.
Ah I recall I used to see the creator around :) thanks for your work!
Regarding the motivation for usbkill mentioned in the article: I too was motivated to think on this stuff in relation to my sense of injustice around Ross Ulbrecht, and wanting to think of some way that someone in his position could avoid getting caught. One creative variant in my thinking involved embedding the BLE beacon inside a rubber ball that could be launched and lost track of. Or maybe embedded in heel of a shoe and ditched in transit haha
They're also now well aware of the GrapheneOS duress PIN/password feature. It was designed to work against an attacker aware of it by acting as a deterrence. If they're aware of the feature, it discourages them from trying to coerce a PIN/password and attempt to unlock with it. We aren't fond of features depending on an attacker being unaware of them and this isn't one of those.
Pixels have a high quality secure element enforcing a maximum of 20 unique attempts to derive the encryption keys for each separately encrypted profile. There's also very aggressive rate limiting between the attempts. It filters out duplicate attempts by temporarily remembering the previous 5 unique attempts to make the rate limiting more usable. A misremembered PIN/password repeatedly entered over and over will only use up 1 attempt.
Android does have standard support for enabling wiping after N attempts and an open source app can be used to set a configurable limit rather than specifically after 10.
U.S. citizens are going to need obtain a burner phone before returning, and load it with the absolute minimum to load boarding passes, etc., perhaps some reading material or a movie to watch on the plane, and be prepared to share full credentials for thing at the border.
(I used to do some travel patterns where taking a certain client laptop wasnât an option. It was an absolute gigantic pain for the type of work I did, but it was just too risky to have a laptop seized and be expected to input credentials.)
I think it's enough to shut down you phone. Then it needs a pin, and you're entitled to not give that over, I believe. So you should be safe, apart from some kind of rubber-hose cryptanalysis.
> So you should be safe, apart from some kind of rubber-hose cryptanalysis.
There are vendors that sell the technology to adversarially access phone data, the "Before First Unlock" is the safest state a phone can be, but it's not infallible. The safest option is to have a burner or factory-reset phone with nothing on it, even if the hack succeeds.
I've worked with Cellebrite, the industry standard in IT forensics for unlocking and imaging phones. It just runs a series of known exploits. PIN lock, data encryption and regular updates will beat it most of the time.
Before First Unlock with recent hardware and an up to date OS is probably sufficiently infallible for an average person. I wouldn't want to rely on it if I was engaged in espionage, but for someone who won't get the NSA pulled into the case, I'd be pretty confident. This leaked Cellebrite support matrix shows that BFU was secure against them for iPhones that were nearly four years old at the time, and I doubt it's become significantly worse since then: https://ia800405.us.archive.org/32/items/inseyets-offline-uf...
A compromise to this is that many phones have a "lockdown" mode, where it isn't fully off but refuses to accept biometrics until a code/pattern is used to bring it to a more day-to-day mode.
It's less-secure than being fully off, but it also means if you do need to access your phone you can do so more-quickly.
If you don't give a pin, they can seize your devices (Andrew Tate on his 1st visit to Florida said that he refused to give pin and they seized phone and laptop)
They can absolutely keep them. Or they can just "lose" them "accidentally". Who exactly would force them to give them back? Or put another way, who exactly will punish them if they break the law?
They canât keep them permanently, but unfortunately they have in the past kept them from some people for years, until the hardware was past its useful life. Itâs a good idea to only travel with electronics you donât mind losing (and not just because of this).
You have a worldview thatâs incompatible with the reality of the current US legal system where things work the way you believe they should, rather than the way they actually do.
Morality and direct commonsense interpretations of law do not apply when there are literally unlimited resources stacked against you. But, assuming you can wait the potential ~10y to receive your device back that it will take to get your device returned to you, good on you. If you think that the current SCOTUS will rule in your favor, good on you.
The reality is, we live in a time where the most horrendous interpretation of the law is the one that will happen. And it wonât be in your favor.
Honestly, I think this is still fine for most people. The probability of a border agent asking me to unlock my phone is very, very low. The inconvenience of using a burner phone is high.
If they do take my phone (completely shut down, unlikely they'll be able to break in) and it's gone forever, that sucks, but then I get a new phone, restore from a backup, and move on with my life. Given that the probability of getting to this point is very low, I'm comfortable with the risk.
But sure, if I was at high risk of being detained at the border due to my profession, country of origin, ethnicity, etc., I'd probably look at this differently.
If youâre a U.S. citizen: CBP cannot deny you entry to the United States merely because you refuse to unlock the phone. If youâre a non-citizen seeking admission: refusal is much riskier.
The important wrinkle is that CBPâs published policy expressly guarantees that a person being admitted as a U.S. citizen wonât be denied entry solely because CBP couldnât inspect the device. It doesnât give lawful permanent resident (green card holders) that same explicit statement. Instead, it says refusal by a âforeign nationalâ can be considered in an admissibility determination.
In theory, yes, but in practice they can do whatever they want, and suing them after the fact is going to be expensive, and have a high probability of not working out for you.
When interacting with border officials (or any LEOs, for that matter), be polite, don't get hostile or aggressive, but also be firm and don't volunteer any information that you're not required to give.
this only applies if they don't refuse to acknowledge your papers as valid and/or they haven't previously put you on some hidden list of people of interest, in which case the instance where you get to prove you're who you say you are will be mediated, like the rest of the (as per the current system) nonpeople, by as many layers of humilliation and risk to your life and health as they can place.
Giving up knowledge (password) is something that is typically scrutinized at the border as well. Had he just handed over the phone and the phone had abilities to self destruct if tampered with (e.g too many incorrect pin entries) -- well the gov's case wouldn't been much harder. If they seized property and accidently destroyed the data, then that's on them.
You are correct, you have to give up the phone but can't be compelled to give up the password, and you'd get it back some indeterminate amount of time later.
It's actually been on the books for a while (decades at least) that customs can search you at the border without a warrant even if you are a citizen.
This case seems to have become a big 'Trump bad' poster child (people are calling the US East Germany in these comments...), but if this exact scenario happened at least in the last two decades (I found an example upholding the searches from 2004) then it would at least be possible to charge them with deleting evidence. Even this probably would have been nothing if he refused to give up his password, not being required to provide a password has been upheld for years. They can seize your phone for some time but I'm unsure on the times they ask and then just let you move on when they find out your a citizen.
leave electronics at home. never take electronics to any airport unless you don't care if everything is read. your only option now.
or have a good enough decoy or encryption system in place. Such as pressing a button to lock or replace key documents but keep the rest intact. So what looks like a sensitive document omits key information but still appears to be legit to observer.
According to the article, he was actually using GrapheneOS and gave the border official the Duress PIN. So I guess technically it was the official that erased the data :-)
Not how the law works. If I put a bomb in a box. It will explode if a certain pin is put in. And you ask âcan I open the box? What is the pin?â And I say âhere is the pin to open itâ and the bomb explodes. Do you think I can claim they blew up themselves ?
I never told you it is a box with a bomb. You just asked if you can have the pin. You can do another example where you give false information with the intent of making another person take an action that they donât wanna take and would not take unless you had provided false information. You are causing the action to happen. Just like if you yell fire in a theater. You didnât stamped anyone to death. But your words caused it.
I wonder whether it'd be better for a duress PIN to delete existing data and also create a semi plausible artificial profile to hide the deletion event.
I think for the case we're talking about here, though, it would be doable. This doesn't need to thwart deep forensic analysis. It just needs to survive a border agent thumbing through the contents of your phone for a bit. If the fake profile data looks plausible, and doesn't raise any flags, the agent gives the phone back and you're on your way.
Hell, I think a setup that doesn't wipe anything, but just drops you into a sanitized, isolated profile for the border agent to look at, would be fine for many users. Certainly you wouldn't want to use this in truly high-stakes situations where it's likely that your device will be confiscated no matter what, and analyzed to death, but for the simple "border agent wants to snoop on my data for a few seconds" case, it's likely sufficient.
(As always, risk analysis can be hard, humans are often bad at it, and not everyone's threat model is the same.)
Deleting arbitrary directories, messages and app data would be highly unreliable. There's a high likelihood of the data being recovered. It's not how computer filesystems and storage are designed to work. Reliable deletion of data requires setting it up to be reliably deleted later on by having it encrypted on storage with keys which can be reliably prevented from ever being obtained again.
Wiping the overall data on the device via a factory reset, OS recovery mode or duress PIN/password prevents recovering any of the data because it reliably wipes material needed to derive key encryption keys and also reliably wipes the encrypted disk encryption keys. Wiping the encrypted disk encryption keys alone would not be good enough because they're stored on the SSD so imaging the SSD and restoring it could preserve the ability to recover the data. The way the key material needed to derive the key encryption keys is wiped prevents recovery via imaging the SSD mainly due to the secure element.
There's already support for reliably wiping data at the granularity of Private Spaces and secondary users. Those have their own encryption keys and can be reliably deleted due to having their own Weaver slots in the secure element and other hardware-based security integration.
Apps can also assorted generate encryption keys in the secure element and use those to encrypt data where it can be reliably deleted via wiping the hardware keystore keys. That requires apps built to have granular storage and encryption of their data.
Despite it being possible to wipe a secondary user or Private Space reliably, the past existence of it and when it was wiped will be easily discoverable via the main Owner user and system data. Preventing discovery of those profiles having existed requires an overall wipe of the data. It isn't feasible to hide it without doing that and hiding it would involve a whole bunch of unreliable removal of data without a way to prevent recovery along with redoing a bunch of statistics and other metadata to hide that there was another profile until recently. For example, things like the battery and data usage stats directly refer to the profiles. Even hiding it from naive analysis not looking at the leftover data on storage would still require changing a bunch of things to hide it.
Making data deletion of the data reliable for a whole profile or the whole data partition also requires a reboot or shutdown. Consider how much data gets loaded into the page cache and many other forms of data in the Linux kernel and other processes. Consider how much linger around in various kinds of registers, etc. including outside of the OS itself. Reboot or shutdown has code to get rid of this and the device sitting there turned off or booting again also gets rid of it.
They were clearly going to hook his phone up to forensics software on a laptop and had done what they needed to do in order to justify it for their own policies. It would not make sense to set up everything they did simply to have someone non-technical manually sift through his apps. They have widespread access to forensic software and also more advanced software with exploits. They definitely have easy access to it at a major Atlanta airport. The adversary in this case is not a non-technical human but rather advanced software from Cellebrite who are fully aware of alternative operating systems and document information on it. Their documentation directly refers to GrapheneOS and has tables listing their (currently very limited) capabilities against it.
This story got widespread news coverage and is widely known about. That should help make it clear how important it is for features to work against adversaries aware of these kinds of features. Our duress PIN/password works against adversaries aware of it. If they don't coerce a PIN/password from someone or don't enter a coerced PIN/password because they know it could be in use then the feature has worked. We want to improve the feature with secure element rate limiting integration in the future so that an OS exploit cannot be used to bypass it. The secure element already prevents an OS exploit from bypassing the limit of 20 total attempts for deriving encryption keys with massively increasing delays between those attempts. It used to solely be based on delays with throttling quickly reaching 1 attempt per day after 140 failed attempts but now there are only 20 total unique attempts. The past 5 failed unique attempts are temporarily remembered and discarded when entered again rather than trying to use them again for usability.
> Reliable deletion of data requires setting it up to be reliably deleted later on
I mean - yes? If you design a subtle duress pin that only hides certain things, users would have to choose what.
I myself want the bank apps, password manager and email to disappear without a trace, but I donât care about the social media, photos or web browser history. Other people, though, will have different priorities.
To reliably delete a specific file or directory, it needs to be encrypted with a dedicated key which can be reliably deleted. It can have dedicated key material in the secure element used to derive sub-keys from the main encryption keys or it could simply be encrypted with another layer of encryption.
For the OS disk encryption, it uses separate randomly generated disk encryption keys for the main user, secondary users and Private Spaces which are different forms of profiles. Those keys are stored encrypted with key encryption keys derived from the per-profile lock method combined with various forms of key derivation material from elsewhere.
The most important of the key derivation material for profiles is the per-profile Weaver token on the secure element which it uses to enforce rate limiting for decryption attempts (max 20 attempts per profile with rapidly increasing delays) and to provide extremely reliable deletion of the data. Wiping the weaver slot for a profile prevents deriving the key encryption keys which prevents ever decrypting the randomly generated disk encryption keys again. The randomly generated disk encryption keys are only stored once and get wiped via a special SSD secure erase command but that isn't nearly as good as the secure element integration. If the SSD is imaged before a wipe and then restored, the data still isn't recoverable because the secure element wiped what's needed to decrypt the disk encryption keys.
Reliably deleting data is a much different thing from fully hiding that anything was deleted which is drastically more difficult and not compatible with how things are typically done. It's pretty much impossible to stealthily delete a secondary profile since there's too much system and Owner user data referencing them including the package manager's state, battery stats, data usage stats and far more. It's possible to attempt to go through all of that and hide it including forging the other stats to mask what was removed but data cannot be reliably deleted in a fine-grained way, especially on top of a modern copy-on-write or log structured filesystem combined with an SSD controller doing wear leveling.
An SSD controller will redirect writes to less written NAND than what is now being written to level out usage. That relies on it being aware of free storage to choose from that instead which is the purpose of TRIM. A modern SSD will also very proactively move around data rather than only redirecting writes to free space with less wear. It will identify the data that's rarely or never written and move it to the most written areas of the SSD to free up the space it was on for the most written data. Having 2TB of used space that's rarely ever touched, 1TB of a heavily written database and 1TB free will not only use the 2TB of active space for wear leveling with a modern SSD controller design. It will use the whole 4TB for it.
A modern copy-on-write or log structured filesystem doesn't write to the location where the data was originally but rather elsewhere. Android uses f2fs which is log structured which heavily helps with wear leveling at a higher level and also provides the ability to turn off data persistence temporarily and then roll back to the point it was turned back in an incredibly efficient way. Android uses that incredibly efficient rollback feature as part of A/B updates to preserve the ability to fully roll back an OS update which doesn't end up working properly until after it reaches the lockscreen successfully.
An app regularly appending data to a file, overwriting data in it or replacing the whole file is leaving data around all over the place. A decision can't simply be retroactively made to reliably delete the data for that file or the overall app. It would have had to be set up in a way that it can be reliably deleted. Without that, the whole secondary profile it's in is going to need to be deleted to reliably delete the data. If it's not in a secondary profile, the whole device needs to be wiped for it.
> I mean - yes? If you design a subtle duress pin that only hides certain things, users would have to choose what.
That's not what we were talking about. This is the full sentence we wrote:
"Reliable deletion of data requires setting it up to be reliably deleted later on by having it encrypted on storage with keys which can be reliably prevented from ever being obtained again."
What we're saying is that in order to have fine-grained deletion of data, it has to be encrypted with fine-grained keys with hardware support for deleting those keys reliably. Reliable deletion of data should also not be confused with stealthy deletion of data which is not generally possible for the kinds of data being discussed.
> I myself want the bank apps, password manager and email to disappear without a trace
You can put all of this into a Private Space or secondary user where it can be reliably deleted as a whole. There will be no way to recover any of the data if the profile is deleted. We have a planned feature for either a toggle to make the duress PIN/password only delete specific secondary profiles or more likely a 2nd duress PIN/password with that different purpose.
Deleting secondary profiles will reliably prevent recovering any of their data, at least after a reboot or shutdown. The best way to do it would be deleting them and then rebooting where the main user and secondary profiles not included in the deletion would still be there after the reboot. Without the reboot, it's unrealistic to reach the point where it's truly highly reliable. The OS does purge the keys for a secondary profile but a lot lingers around in system processes, page cache and elsewhere. If you delete a secondary profile with the goal of preventing data recovery then it's a good idea to reboot afterwards.
Dividing things up into secondary users is the way people can set up having fine-grained reliable deletion of the data. We can expand our duress PIN/password feature to support working with that.
It should be noted nothing about wiping secondary profiles is stealthy. It's very obvious there were profiles and that they were wiped. It can be determined when it happened and approximately how much data was deleted too. The data and filenames are unrecoverable but a fair bit of metadata on the sizes of files, etc. can be recoverable because that metadata is globally encrypted rather than per-profile encrypted. If you want to delete absolutely all traces of it in a reliable way, an overall wipe of the device does it extremely well. If you delete a profile then nothing encrypted by it can be recovered but what about all the evidence of it existing in the system and Owner user data? It's in the battery statistics, data usage statistics, package manager metadata and many other places. It can be purged from those but absence of data can be detected, and there's the usual problem of simply not being able to reliably delete data from computers in a fine-grained way. It's too late to reliably delete data from a file after the file has been regularly rewritten and modified.
Deletion needs to happen through deleting the keys used to encrypt all data which was ever stored in the file, so it would have had to be set up with that in advance. To reliably redact data in a file, the file would need a dedicated hardware-backed key with a new one being generated and the old one wiped as part of redacting data. Reliable wiping of a profile or the overall device works because it's all encrypted with filesystem-based full disk encryption using keys which can be reliably deleted. Profiles have fine-grained encryption for filenames and file data.
You cannot retroactively decide you want to reliably delete the data of a specific app and then do it. It's already spread all over the place. You'd need to wipe the whole profile or the whole device if it's not in a secondary profile. The OS would have had to set up a dedicated encryption key for that app's data with hardware support for deleting only that key by itself. Apps can do this and Signal is an example of app doing it which prevents backing it up via the OS backup system without also using their own backup system too.
Maybe it could cause the phone to "randomly" bootloop or something? "Oh no, my phone is broken again, last time this happened I needed to do a factory reset"
> I wonder whether it'd be better for a duress PIN to delete existing data
Reliably deleting data at the scale of the whole data partition, a secondary user or a Private Space is fully supported but requires a reboot or shutdown to truly complete it.
After wiping key derivation material needed to obtain the key encryption keys in multiple ways and wiping the encrypted disk encryption keys, the OS can still access the data. It still has data in the page cache, in registers and elsewhere. There are still a bunch of system processes with data tied to what was removed. The OS is still fully functional after the nearly instant wipe of everything needed to recover the data again. It can still access all data other than what's encrypted with hardware keystore keys and not currently decrypted.
The wiping process for the duress PIN/password is completed with a shutdown which tears down everything, zeroes memory and provides at least a small time window where the hardware is powered off too. A reboot would also work and the boot process has explicit zeroing of memory, registers, etc.
We decided to use shutdown for the duress PIN/pasword but a reboot is a valid approach too. Our locked device auto-reboot timer feature we first shipped in 2021 relies on the zeroing done by GrapheneOS for both the process of the OS tearing down and then again during booting to return the device to Before First Unlock state.
> also create a semi plausible artificial profile to hide the deletion event.
It isn't feasible to fool forensic software so it largely wouldn't work against state actors. It nearly certainly wouldn't have helped in this situation in the news. They aren't reliant on a non-technical person sifting through a phone. They'll just hook it up to a laptop and follow the data extraction procedure which involves enabling ADB. The software is aware of GrapheneOS can guide people through dealing with anything different about it. They've had a lot of trouble with extraction via ADB for GrapheneOS since the vulnerabilities they exploit via ADB keep getting patched or blocked it exploit protections but it isn't realistic to block extraction with them having the PIN/password. They could just enable the encrypted backup service in the OS instead and then use CLI tools to extract the data from there with the seed phrase. They don't do that because they want everything rather than only nearly all app data. They also have special code to deal with apps such as Signal with their own layer of data encryption since the data taken from their app data directory is nearly all useless by itself.
There's also quite a difference between wiping and rebooting into a not very plausible environment with decoy data set up by the user in advance compared to not properly wiping and giving access to a decoy profile. Bear in mind the OS can still access nearly all data after the wipe until a reboot. It could make a best effort attempt at purging as much as possible from memory, but the OS is not designed to continue functioning with all of the data disappearing. It can't just wipe all loaded encryption keys without crashing and rebooting anyway. It also has a ton of data still around in caches and elsewhere. We don't want to just do a best effort job cleaning up as much as we can but rather reliably prevent recovering any of the deleted data.
We could definitely add a duress PIN/password which wipes only specific secondary profiles, reboots and has the device still functional with whatever data was in the main user still there. That's a feature we can add, but it's important to note that it will not hide that there was deletion of data. It's easy to detect, and it's not feasible to hide that it happened. Many steps can be taken to make it less obvious, but it will still be easy for software aware of it to detect. Even a massive overhaul designed to perfect it would not address the SSD itself giving away what happened for more advanced analysis.
We aren't going to add a decoy profile compromising the security of the device and providing a way to recover data in a state where it isn't at all unrecoverable yet. We did already plan to consider a 2nd duress PIN/password which only wipes specific secondary profiles, but we need to make it clear that it cannot stealthily wipe them to users.
I mean, it sounds like it would be even better if the duress response was more subtle.
A duress code might let me wipe my phone when someone holds a gun to my head and demands I unlock it. Problem is, thereâs still someone holding a gun to my head.
He had an e-reader and phone. My solution would be set the phone's duress pin to the e-reader's actual pin then consent to the e-reader search providing its pin and see what happens.
The actual solution is cloud backup + re-image after the border.
>I donât think that would fly as a defense in court
but that's not the point, the point is to not wind up in court by presenting a phone that no long contains evidence but seems plausibly like your phone so doesn't arouse suspicion
If it was implemented in such a way, there would be no reason to suspect anyone of using it because it would be totally indistinguishable from not having used it. At that point they have no grounds for legal action. Unless they could monitor FS/disk activity, but that goes beyond typical airport security stuff.
I'm imagining a duress code that erases select files and any indication that there was ever a duress code set up in the first place.
As things stand right now, software is 1-A protected speech. I'm not sure how long that will be the case with growing authoritarianism, specifically wrt to tech, on both sides of the aisle. I am concerned it may be considered probable cause though -- like how you can legally have an ax in the bed of your pickup but it's a free pass for a cop to search your vehicle if they're so inclined -- but really, they can manufacture probable cause for anyone if they want so it's kind of moot. You may be attracting unnecessary attention though if
you've got "GrapheneOS" on your lock screen. But this goes back to my original point, they still have to catch you in the first place.
(1) Keep manufacturer's Android plus some plausible apps and data in a reserved part of the drive. (2) GrapheneOS runs from the other part of the drive. (3) Make sure PIN screen designed to not give away the OS. (4) When duress PIN is entered, erase GrapheneOS and restore manufacturer's Android. (5) Now you won't be charged for having GrapheneOS because they won't know you had it.
No, to my knowledge, they ask you to enter your PIN/password yourself. They don't enter it for you. I believe he entered it himself, at which point the erasure began. The erasure process was witnessed by the officer.
> Tunick provided this code to an agent, who entered it on the phone, after which âthe screen went blank, flashed several times and the phone appeared to restart.â
i think it's just that the American population is the last bunch who gives a damn about it, and the pockets of resistance still makes the news... the same happens mostly everywhere else, just without much complaints.
e.g. in Hungary the authorities treat it as a felony to possess an equipment that can record video or sound and it's not obvious when looking at it. 2-8 years in prison for mere posession, i.e. even if it's turned off in your backpack. random nonsense that if it can also make phone calls then it doesn't qualify (the above is the law paraphrased).
Since there are zero devices that are released that donât indicate recording, it doesnât seem unreasonable to outlaw modification of recording equipment to hide recording.
You know, the same way we would be rightfully outraged if Apple was allowing applications to turn on the web cam without signaling to the user that the camera is engaged.
Thatâs all aside from the fact that Hungary was run by authoritarian minded people. But just as I think it should be illegal for cameras installed in glasses to work without an indicating light, I donât see how this recording light situation you are describing is really such a highlight of Orbanâs excesses.
I know surveillance is on par in the UK, but is the UK also building and populating massive detention centers where people are kept without due process*? Are they flooding the streets of liberal cities with soldiers*? Killing citizens on the streets of liberal states (Minnesota) out in the open? Has nationalism completely overtaken the government and citizenship? Has the opposition party been completely neutered? Does your leader openly break any laws of their choosing while plundering national coffers?
This is a bit worse than that. They're specifically targeting this guy because they don't like his politics, an act that is unconstitutional, but Trump and his administration has had contempt for the constitution since day one.
Republicans might as well rename their party the Democratic Fascists of America at this point.
> Republicans might as well rename their party the Democratic Fascists of America at this point.
I'm reading Stefan Zweig right now, he was a prolific Jewish author from 1890s until his suicide in 1942, living as an exiled Jew from Austria in South America. He has written many words, over a century ago, that would support your claim.
Great link. The most relevant part for me is the last couple minutes (22:00): it's only against the law to destroy evidence if it can be established that such evidence exists. This feels like a more elaborate version of accidentally losing a stack of papers to a gust of wind just as you hand them over.
1. Was there a lawful entitlement to the papers?
2. Were the papers protected private property?
3. Were the papers released to the wind intentionally?
4. If intentionally released was it expected that they would disappear or simply fall to the ground?
A couple easy technological analogies:
3. "Sorry, I gave you the wrong code by mistake."
4. "I thought it would go to a private guest mode, not delete everything!"
I'm not a legal expert, but all this seems to check out with US law. Americans need to remember that some of their constitutional rights don't really apply at ports of entry by design. This inconvenient truth for the land of the free has existed for a long time, this situation is just drawing attention to it. Their powers are far-reaching.
Fun fact, there is a long standing exemption to the unreasonable search and seizure protection laws if you're out on a boat (it may only be on the open ocean and Great Lakes, though IANAL). One of the earliest Supreme Court rulings essentially said that without it, it would be impossible for the US to enforce tariffs, which were the main source of revenue at the time. Anybody who boats often enough has been boarded by the coast guard for various safety checks that allows them to poke around and there's little you can do about it.
So the part of this that feels like it triggers the government issue here is that in effect you have a locally stored encryption key which gates access to the device, which was removed from the device due to duress password.
What if we flipped this to instead be something that's explicitly not on the device?
The border search stuff only applies to information on the device. It cannot compel you to provide access to e.g. emails stored in a cloud provider.
If instead of making the process of stopping searches like this be a destructive one, we instead pre-purge the key but store it offsite with the ability to get it from an online location, then this feels like it's probably reasonable here. In the sense that the 4th amendment explicitly allows "The right of the people to be secure in their persons, houses, papers, and effects, ..."
There's probably some sort of technical problem I'm missing here (or maybe this functionality is available already).
> The border search will include an examination of only the
information that is resident upon the device and accessible through the device's operating system
or through other software, tools, or applications. Officers may not intentionally use the device to
access information that is solely stored remotely. To avoid retrieving or accessing information
stored remotely and not otherwise present on the device, officers will either request that the
traveler disable connectivity to any network ( e.g., by placing the device in airplane mode and
disabling Bluetooth and Wi-Fi connections) or where warranted by national security, law
enforcement, officer safety, or other operational considerations, officers will themselves disable
network connectivity. Officers should also take care to ensure, throughout the course of a border
search, that they do not take actions that would make any changes to the contents of the device.
and
> Passcodes or other means of access obtained during a border inspection will only be
utilized to facilitate the inspection of devices and information subject to border search. Passcodes
or other means of access may not be utilized to access information that is only stored remotely.
Passcodes or other means of access should only be recorded by the officer in a temporary format
and should not be uploaded into CBP systems. Passcodes or other means of access recorded by
the officer will be deleted or destroyed when no longer needed to facilitate the search of a given
device.
The existence of a key only being somewhere other than your current location during a border search enables you to legally say "I cannot unlock this device" and move on with your day.
Well even today this guy could have just said 'I will not unlock this device' and they can seize it for some time, but they can't deny you entry. Which is pretty much the same scenario you created except the guy literally can't unlock it (but that doesn't actually matter here, he never _had_ to unlock it).
> or maybe this functionality is available already
Basically already exists depending on specific trade offs and risk profile.
You already can encrypt your data and store the encryption key offsite. But then you couldnât use your phone during travel, if you toss the key locally.
You can encrypt the data at rest and leave the decryption key in RAM and just turn off your phone. But they can still take the phone and copy the encrypted data, if they think theyâll get the key later.
My understanding is that this individual would t want the government to access the encrypted data either.
I'm talking specifically about the graphene OS ability for that approach, not the ability to add an external key to some generalized encryption. The threat model here is that the traveler was required to provide a passcode unlocking a key they had with them on their phone. If that threat is not there, then this bypasses problem.
The search is supposed to be lawful without a warrant because you're not really in the US yet per-se, hence if you're not there, how deleting the data can be a felony?
I think you legally are in the US while at an American border crossing - at least if the crossing is on US land, which it was in this case. It might be more complicated for preclearance spots. It's just that normal rights are suspended there despite being in the US, even for citizens. Make of that what you will.
The alleged crime is knowingly interfering with a lawful search (by providing a duress password that deleted the phone). Location has nothing to do with it.
It's a fairly shallow point that ignores how laws work.
The premise that the law doesn't apply because you're not in the country is false. The constitution applies generally everywhere to all Americans, it's just that what's regarded as reasonable differs during a border search. IANAL, so just my lay opinion on this. Just to validate this, it's only because the constitution exists that the border authorities have any legal basis in doing inspections.
But in general, the thing to note here is that the 4th amendment is always applicable and in force. It's how it's interpreted that changes depending on the circumstance.
It doesnât matter where he was when he deleted the data. He could be in China, itâs still a crime in the us to destroy evidence wanted by American authorities.
- if you're deemed to be on US soil, constitutional protections (4A) apply; can't be destroying "evidence" unless you're accused of a crime or found to have committed a crime
- if you're deemed _not_ yet on US soil, then how can you be charged with a crime under _US_ law?
The US views that US law applies worldwide. There is no requirement that you be anywhere near the US to be under US jurisdiction for an alleged offense against the US, according to the US.
Also, that constitutional protections are suspended within 100 miles of a land, sea, or air border.
4A still doesn't permit you to destroy the evidence. Resist on 4A grounds, destroy the evidence, 4A reasons get overturned - you've got yourself a conviction. US v. Akram Musleh.
in practice you're right, but it's hard to see how that squares with the 4A.
an officer can't stop me on the street and demand to see the contents of my phone -- unless they can show "probable cause" that I was about to commit a crime (based on other evidence), or I'm already named as a suspect or POI in an investigation. So if they ask to see the contents of my phone and I delete it instead (it's a very small bag in this example, Lol) am I obstructing an investigation?
It's like those notices "by clicking accept below you agree to giving up your data", by purchasing a ticket to visit US all your data are belong to the US.
How did it end up, because itâs not a new thing to happen. First time I read about this guyâs border crossing case was few months ago and was of course very much highlighted for the level of surveillance govs can do.. but I also read some
Time later that by the letter of law he was not proven wrongdoing.
Are we still discussing a border crossing case that is long historic or there is still an active drama for this guy going on?
Seems like it would be better to have a truecrypt type of situation, where if you put in a certain pin, then it just logs you into a separate OS with nothing you want to hide.
Obviously have the duress pin if whatâs in your phone is worse than the obstruction charges too.
In the truecrypt scenario youâd be using the hidden and encrypted volume only for what you explicitly want to keep hidden and use the other one for your daily life.
So in the article situation, the guy is a protestor and presumably suspects heâs going to be targeted by the police for it. Heâd keep that stuff isolated from his usual activity. Thereâd be no need to generate convincing fake activity.
Certainly more of a hassle than having a PIN that can destroy everything.
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."
Amendment 5:
"..nor shall be compelled in any criminal case to be a witness against himself, nor be deprived of life, liberty, or property, without due process of law; nor shall private property be taken for public use, without just compensation."
But the bar for hauling someone to court and defacto punishing them financially and smearing them in the eyes of the public is so low. And the path to getting compensation for wrongful prosecution so fraught. What an easy tool the justice system is to punish uppity citizens thinking they don't have a king.
You think they'll see a courtroom? Ha! If they're lucky they'll get there in 5yr and $15k.
When the administrative enforcement bureaucracies want to harass you they'll hit you with some ruinously expensive civil fine BS. No court will give a crap about you until you've exhausted a bunch of appeals, which you of course appeal to the same agency that's trying to screw you. Only after years of that (and invariably legal fees, because you can't go it alone), do you sue them and get to see a real courtroom. But even then, this is a civil matter, not a criminal one, so all your rights have been nerf'd and there's a hundred years of precedent and case law that tilt things in their favor. If you get lucky, they'll settle and you'll only be out a few tens of thousands for the ordeal.
If you are a US citizen, they are not entitled to your unlocked phone. They need a judicial warrant if they want you to unlock your phone with a PIN/password. It is settled case law that that falls under your protections under the 14th Amendment.
They can take it for a "reasonable amount of time" (inconvenience you for a few hours and make you miss your connecting flight) while they copy an encrypted image. They then must return it to you.
It seems like the best course of action would be to argue he did not destroy evidence, just made it unavailable at the location to force the requirement for a search warrant. It would probably be a hard sell, but I can't think of a better argument (not a lawyer).
Problem is, he didn't destroy shit. "He" (by which I mean, technically the agents) deleted a header that's used to encrypt data but can restored from a backup.
This is why we have judges, I wonder if this has been ruled on already. If you filled out a notebook in a special cipher with the cipher stored separately beside it, then when a cop asked for the notebook you handed the cipher over and then burned the cipher right in front of them, is that destruction of evidence? Idk at the end of the day it does have the same result as destroying the data.
>"He" (by which I mean, technically the agents)
Under the same logic you could mail a bomb to anyone and say you didn't kill anyone, they did. It was just rigged to blow when they opened the box.
Sure, but the issue is he didn't delete his data, he deleted a header with a key in it, that's it, just a few MB. He didn't delete hundreds of GB of chats or browsing history, he deleted a key to access it and that key isn't necessarily the only one that can access it. All the stuff they want can still be accessed just fine if another copy of the key exists.
To put it in protective, just opening a web browser or some other app can delete/alter more data than was deleted in this case.
Evidence of what? Destroying evidence assumes he is guilty of a crime which there be evidence of. Our system is predicated on an assumption of innocence. The normal threshold to accuse is a "reasonable, articulable suspicion." This does not meet that criteria.
Well that's the thing with destroying evidence. If you destroyed it, it becomes harder (or impossible) to prove you did the crime. That's why it's not uncommon for people to be only charged with stuff like "obstruction of justice" rather than the actual crime they allegedly did.
In this case, the authorities are claiming they were looking for CSAM. So wiping the phone hindered a valid investigation.
They can say anything they want. They hold all the power. This will never change until enough people take matters into their own hands, as the system has been compromised.
And what if he was erasing a steamy affair with a border patrol agent? That's not illegal, but releasing knowledge of it could be damaging to all parties for no reason.
if the only evidence of a crime is on your phone, what kind of crime is it?
we should always be asking: is this the only way you can prove the accusation? just because it would make LEO life easier - that's not justification for violating the constitution.
an consider what this case teaches us: clean up your devices before you cross a border. how does that even help the goal of law enforcement?
They were pretty obviously hoping to find a specific crime to accuse him of (because he is a protester against the Atlanta "Cop City" thing).
But no respectable judge would ever have issued a search warrant on the basis of "we want to rifle through his messages/contacts so we can hopefully accuse him of something".
Protesters against this exact same thing were mis-prosecuted under "domestic terrorism" and "racketeering" charges before (got dismissed in 2025).
The original text is basically useless. They're more like a mission statement rather than directives. They set up broad aspirations, but the implementation has to be aggregated over literally millions of pages of judicial decisions.
Even lawyers with extremely different ideologies will give you convergent answers in a lot of cases, even when those answers conflict with an apparently obvious reading of the original text. Explaining that would require drilling down into details of thousands of court cases -- like reading a complex proof of a seemingly simple theorem.
I don't like that any more than you do. It's not mathematics, and even when given all the details, I usually find their inferences laughably bad -- even when I agree with the conclusion. It's not "logic" as I apply it as a logician, philosopher, or software developer. Lawyers (people on my side ideologically) will insist on the soundness of reasoning for decisions that they don't like but accept as valid.
So I don't find quoting the Constitution to be of any utility. None of those words what you think they mean. And fixing that requires basically throwing out the entire system of American jurisprudence. Which would be fine with me, to be honest.
And that alone is already a pretty scandalous problem. If the law is not stated in a way that ordinary people can understand, how the hell are they supposed to obey it? Those who cannot afford the highly paid law explainers are basically locked out of society.
I don't think you're entirely wrong, but the Constitution binds the government, not citizens. The government can damn well afford to know what the 4th and 5th Amendments mean.
The words are actually extremely clear and its exceptionally prudent to quote them, because nobody with a brain can read them and fail see that the government is simply being unconstitutional - all over the place. Even when the people are powerless, we dont have to give up our powers of seeing the truth. Your post and this whole idea that "the words dont mean what they say they mean" is frankly doublespeak of the lowest form.
> we dont have to give up our powers of seeing the truth
The truth is that the constitution is interpreted by humans in a common law context, and enforced by the apparatus of state, which has the means to impose its will. Calling this doublespeak is weird.
When its "interpreted" in a way that directly contradicts the words themselves then its not an interpretation, its a smokescreen to try and cover up the fact people in power dont want to follow the constitution and are not planning on doing so.
> None of those words what you think they mean. And fixing that requires basically throwing out the entire system of American jurisprudence. Which would be fine with me, to be honest.
The Constitution is written in plain English. And for the most part, Supreme Court decisions are written in plain English that any reasonably literate US citizen can understand. Yes, the law has technicalities and terms of art just like any other profession.
But one of the most damaging mentalities in modern times is the idea that the common man is incapable of understanding the law at even a basic level. This is flat-out not the case. Which leads to the follow-on problem: people who think lawyers have the ability to cast magic mumbo-jumbo spells that "get their clients off on a technicality" somehow. The best quote I ever heard about that from an attorney was "any time someone says a person 'got off on a technicality,' you can pretty much just safely replace that in your head with 'had their constitutional rights egregiously violated.'"
Yes, there are problems. Qualified immunity is a problem. Prosecutorial misconduct can be a problem. Abuse of discretion at the border is a problem. But that's different from doomerism about the entire justice system to the degree Very Online people express it.
I'm just guessing here, but the most problematic word on the 4th amendment to attack from the government's perspective is "unreasonable". It's easy to see how a phone border search could be construed as reasonable, and (without digging into this deeply) I suspect that's where most of the push back on this will be.
I suspect the 5th amendment is probably more valuable to the defense here as the password is effectively testimonial and the give us your password or we'll ... is compelled speech.
Either way, it's gonna be many 10s of thousands of dollars in lawyers fees to fight this. Which sucks.
> It's easy to see how a phone border search could be construed as reasonable
I'm curious, is there any case law from the pre digital age regarding people forced to open their briefcase and let the border guard read all their documents at a port of entry?
There is no such exception allowed in the Constitution. And if a case is made that they're not legally in the US yet, then by the same logic, they should not be subject to all the same laws of the US yet.
The Supreme Court has long recognized a border-search exception to the Fourth Amendmentâs warrant requirement. In United States v. Flores-Montano, the Court looked to the nationâs sovereign âinterest in protecting . . . its territorial integrityâ to justify such searches.3 In United States v. Montoya de Hernandez, the Court stated, somewhat more narrowly, that Congress is the source of the executiveâs power. It explained that â[s]ince the founding of our Republic . . . [Congress has] granted the Executive plenary authority to conduct routine searches and seizures at the border, without probable cause or a warrant.â The Commerce Clause permits Congress to authorize the seizure of goods at the border.
> While the Supreme Court has long recognized a border-search exception to the Fourth Amendmentâs warrant requirement, it applies to only two interests: promoting the duty regime and preventing contraband from entering the country; and ensuring that individuals are legally admitted.
The only reasons allowed for border searches are ensuring that individuals are legally admitted (inapplicable here because citizens are always legally entitled to enter) and preventing contraband from entering.
A wiped phone can't contain contraband, so wiping the phone serves the same purpose as a search. It's not destroying evidence anymore than throwing away a water bottle before going through TSA is destroying evidence.
I see a vast gulf between searching a truck of produce driven by a non-citizen vs intercepting a citizen at the boarder with known affiliations with the opposing political party.
And it's impossible to ignore that context. This is plainly wrong. And people trying to justify this plainly fascist search is sickening.
Even Wikipedia spells out that invasive searches require "reasonable suspicion." So we return to the core question... suspicion of what? Suspicion is not a crime. https://en.wikipedia.org/wiki/Border_search_exception
"The government is allowed to use scanning devices and to search personal electronics. Invasive bodily searches, however, require reasonable suspicion." is what the article says
What about none citizens? Customs kicks you out or throws you into a camp first.
E: but seriously, what happens to non citizens. What happens if you bring a burner/wiped phone? I assume digit forensics can confirm it was pre wiped but what's topping them from alleged you wiped on US soil.
I don't know about you, but don't people use encryption to retain privacy? And are people still free to manage their personal information? Doesn't a duress PIN present that information in its intended form? I'm confused.
What I don't understand is if he just didn't give any password, he would have been fine. It's only because he gave him a duress pin that he's in trouble.
So, in both cases the government wouldn't have access to the contents of the phone
18 months is, by precedent, the limit on contempt for refusal to decrypt[0], but this administration is happy to disregard any precedent that does not agree with them.
Actually no, they are required to allow you to enter the country, but they will make it a hassle, to the point of dehydrating you and/or refusing bathroom access, and confiscate the device in the end and access is through other technical means.
> Courts have generally found that compelling individuals to provide their numeric or alphanumeric passcode is potentially testimonial under the Fifth Amendment, as it forces the defendant to reveal âthe contents of his own mind.â In Re Grand Jury Subpoena Duces Tecum 670 F.3d at 1345; see also U.S. v. Apple MacPro Computer, 851 F.3d 238 (3d Cir. 2017). It is analogous to compelling production of the combination to a wall safe, which is testimonial, as opposed to surrendering the key to a strongbox, which is not. See Doe v. U.S., 487 U.S. 201, 220 (1988). However, even if a court finds that providing the passcode is âtestimonial,â it may still fall under the âforegone conclusionâ exception
In short, you can't be compelled to give up the code in a dragnet attempt to find evidence against you (e.g. a boarder guard can't riffle through your text messages to see if you might have done something illegal), but if it's already certain that particular evidence exists on the device as a result of other evidence, they may be able to compel you to give up your passcode.
Note though that the cases where this has come up are very few and far between, and there isn't a super clear overriding precedent to follow.
In general though, the best choice here is to say nothing at all and work with a lawyer to figure out how to proceed.
What about everyone does this at the border. Then what is normalized is deleting your encryption key while entering, they wonât prosecute everyone on their baseless prosecutions. Join in I say, there is no law being broken only scare tactics being applied to prevent this kind of thing. Normalize the act not the consequences.
Anyone that is surprised by this or somehow thinks this is new clearly hasn't crossed the border a whole lot. I grew up in a city along the US/Canada border. You don't fuck around with US Customs (or Canadian) agents. My cousin (not always so friendly) pissed off a US Customs agent (in the 90s mind you) and they promptly took his car and disassembled much of it looking for non-existent drugs. When they put it back together it was never the same. Their job is to be suspicious, 99.999% of the time people are completely innocent. But let 1 bad person through and it's Customs' fault for whatever bad thing they do. Not an easy job. Not an excuse for how they can misbehave either.
Is it right? It makes no difference, Customs can make your life miserable, that's just the reality of it, always has been and it can't have gotten better in recent times.
So we're presumed guilty until proven otherwise (the presumption is, any data we delete must be illegal; couldn't possibly be nude selfies that the government has no right to see)
Would it be permissible to wipe your phone before going through customs to get back into the US? If they ask to search your already wiped phone, you arenât destroying any evidence.
We were talking about an attacker taking an image of the SSD prior to it being wiped not helping them because information needed to derive the key encryption keys is gone from the secure element. It similarly doesn't help them to do a brute force on a server farm since they're rate limited by the secure element. It only allows 20 attempts and has rapidly increasing delays between those. There's also hardware bound key derivation but that only helps improve the strength of a decent password. The secure element rate limiting makes even a random 6 digit PIN highly insecure unless an attacker can exploit the secure element.
I wouldn't assume that to be the case. It's illegal under federal law to destroy evidence of a crime. Just what the government needs to do to show that you've destroyed evidence of a crime and not just the sexting you did with your girlfriend is a pretty murky area of law, from what I can tell.
I would not present a phone to customs that had clearly just been wiped.
You're speaking nonsense since there was no charge or warrant against him. There was no crime that was committed. People are free to use their phone for f sake. People who reason as poorly as you will lead to all remaining rights being lost.
The way he wiped it is legal for the same reason. It was an illegal search and he was under no obligation to preserve the data on his phone.
It's legal to refuse to provide a PIN/password in the US. He's a US citizen so they couldn't refuse him entry. If he wasn't then the result would be getting deported.
It likely would have been a much better decision to refuse to provide the PIN/password and rely on the encryption and device security instead. He could have done a reboot or shutdown in advance but even without that it would have done it automatically via the locked device auto-reboot timer. The secure element only allows 20 attempts for key derivation with rapidly growing delays between those. If he had a strong passphrase then even a secure element exploit wouldn't obtain the data protected by it.
Paywalled, but what is the actual charge? Is it some extremely generic "obstructing an investigation" one? The US is quite good about making court documents available on line, if someone can find it.
Knowingly providing a PIN that would erase evidence is going to get tough in court.
But the man was also hated by the cops because of his activism. They were going to catch him for something, some day. This incident just provided the necessary excuse to lock him up.
There is no duty to keep a copy of messages and private data on your phone for the FBI to peruse at its leisure. Quite the opposite, actually (according to the constitution).
It is pretty clear to me that law enforcement conspired to abuse a border crossing to effect basically an unconstitutional search ("fishing expedition"), which it would never have gotten a warrant for.
This is them being spiteful after that whole thing failed. Note how law enforcement basically admits this on the record. The whole thing is a disgrace; every decisionmaker involved in this should be sacked immediately.
Whatever they claimed they needed access for his phone to. Probably nothing serious that would be worth more than a fine, if anything. But now they've got him for deleting evidence, which is pretty bad.
There is no "evidence"; by any reasonable interpretation of that word there would have to be an actual accusation of crime for there to be evidence of one. This was a search predicated on literally no actual basis apart from "we have the right to search your device because we have ultimate power at border passings", essentially just a fishing expedition.
This also doesn't even get to the more important point: If you don't have the contents of the phone you have literally no evidence of a crime being committed, other than the one they invented post-facto: "Deleting data that could hypothetically be incriminating, not in any specific way but just generally, maybe".
That shouldn't be too hard. Get someone from Google or someone with any tech knowledge to explain to the judge how phones normally work, what encryption keys are, the implications of wiping an encryption key, and then get someone to show the difference between entering a normal PIN wrong several times and entering the duress PIN. You just need to convince the jury (or judge, if there is no jury for whatever reason).
People have gone to jail or have been executed for less than a glitch. Theoretically a highly charged particle from space could've messed with exactly the right transistors exactly when entering the correct PIN and trigger the wipe process. There is no way to prove that didn't happen. But you don't need that kind of proof.
Sure buddy. And the uncertainty principle means you can't prove I was at the scene of the crime.
The fact phones don't usually wipe themselves will be plenty good for a judge.
Btw: Regardless of the above I support this guy's right to protect his private data from baseless and unreasonable searches. He should not be charged with a crime.
No, it means there is no general solution to the problem of proving software correct. You can prove if a specific program will halt or not given certain parameters. You cannot write an algorithm that will work to prove if any arbitrary program will halt.
> They were going to catch him for something, some day. This incident just provided the necessary excuse to lock him up
funny reading this (don't disagree) and then also reading on HN how China is "bad" this is some gestapo shit but not surprising that it is getting normalised ...
China is strictly worse than the USA when it comes to border controls. That doesn't mean the USA is good or acceptable in any way; these laws are part of the reason why I don't plan on visiting the country. The USA also has much worse laws on the books, like having to give the authorities your social media passwords to check if you're secretly a terrorist (though that doesn't apply to citizens).
Excessive border patrol power has been around in the USA for ages now, it's all part of the post-9/11 package. I don't think many Americans even know they live in a zone where the border police can do shit like this, even if they haven't left the country, as international airports are usually near big cities, and they have a wide border zone around them. This stuff only really makes it into the news when it happens to one of the "good guys".
China is indeed "bad" for the gestapo shit. The difference is that China's gestapo shit comes with benefits for the common man too, whereas in the US the gestapo shit only serves the inner circle at the top of the regime with zero benefits to 99% of the populace.
I don't agree with all this and this increasingly fascist regime but... this was the most predictable outcome. Consider these two scenarios.
1. You factory reset your phone before entering the US and give it to CBP blank. There's nothing to find;
2. You have a self-destruct PIN like this guy did and give it CBP so it destroys the phone's contents.
Tech people will say that these two things are functionally the same. This is a fundamental misunderstanding of how the law works. If you factory reset your phone first with the intention of restoring it after entry, that's completely fine (legally). You could've factory reset that for any reason. But as soon as an officer wants to search your phone, now you're engaging in evidence destruction (spoliation). The destruction to the phone's contents was done in response to an unfortunately lawful search.
Even if you don't want to factory reset your phone, you can probably just delete (or even log out) of key apps. They can still get messages but if you're so concerned about that, use WhatsApp or whatever.
None of this should be necessary but we are where we are. But whatever you do, don't use a self-destruct PIN if you don't want to be charged with a felon and likely to be found guilty.
A court has not yet determined whether the use of the duress PIN/password was legal. There's definitely no consensus among legal experts of it being illegal as you're portraying it. The US has strong legal protections against self-incrimination and unreasonable searches despite erosion of how much people's rights are respected.
A factory reset done in anticipation of a search is not as different from using a duress feature as you believe it is. Forensics software would have clearly identified the device was recently factory reset. It would provide another defense argument by arguing it was wiped for another reason, but whether that would be believed by a court is unknown. It would make a difference if there was a good argument about why it was done, but it isn't necessary for this to have been done instead for wiping the device to have been legal.
Once he was in the situation already, the best move was very likely refusing to provide the PIN/password indefinitely and only talking to them to demand access to lawyer. There are strong protections against data extraction and it's highly unlikely they would have been able to get the data from it. Refusing to provide a PIN/password is protected under the 5th amendment in the US and these rights do exist at the border. They can turn away a non-citizen but they can't refuse entry to an American citizen because they won't provide a PIN/password. They could waste a lot of his time but he'd get access to a lawyer and would get released. They could make a court case over demanding the PIN/password and they'd nearly certainly lose. He'd likely spend months or even years without getting back his phone of course.
If they had a video recording of him entering the PIN/password from somewhere, they could have used that to get the data. By using the duress PIN/password, he prevented it. It was probably not necessary to keep the data safe, but that's unknown.
With only a tiny bit of preparation time, rebooting or powering off the device would have gotten it into Before First Unlock state without the locked device auto-reboot timer needing to complete. In Before First Unlock state, a decent random 6 digit PIN is enough for the data stored protected with it to be highly secure without an extremely sophisticated secure element exploit. If the device had a strong passphrase, then no level of sophisticated exploits would recover that data.
> Oh, they may well give you bad time if your phone looks like a burner with too little content.
Issuing 'burner phones' and laptops to staff visiting countries such as China or the USA is now SOP for many companies handling sensitive data, including mine.
This is not... advice. But if anyone's actually going to do this, the method that's worked for me...
A couple weeks before your trip, factory reset whatever burner phone you're planning on using and swap your SIM card over. Install a few basic apps you wouldn't mind them looking through. Enable hotspot/tethering, and connect your other phone via Wi-Fi.
For a couple of weeks, use the burner as much as you can with what is available on it. When you're driving, us the maps app for GPS. Make and receive some calls, ignore some spam calls. Read the news. Get a few inane text messages conversations going, etc.
When you travel, leave your regular phone at home and take the burner. When it's searched at the border, it has enough activity to pass most initial smell tests. If asked, you dropped your other phone and didn't have time to get it fixed before your trip, this is one a friend lent you.
This has worked for me. Never _actually_ into anything illegal, but just apparently had a suspicious vibe about me or something because every time I crossed the border into or out of the country I was spending 4-5 hours getting searched. Didn't need someone going through my entire life going back decades every time--once was enough.
So what, donât do anything to protect yourself because thereâs no hope? Give up?
Believe it or not, due process still generally exists and most people still benefit from taking precautions to protect themselves. Thatâs not to imply that things are great or that we arenât in a time of declining civil liberties.
Seriously, there is something wrong with privacy doomers.
And yet this distant possibility doesnât seem to happen very often to citizens, as long as we still have courts. Not that actual abuses should be trivialized.
This comes across as fearmongering to keep people from protecting themselves.
That isnât true. They can detain you briefly for questioning at the border, but if there is no crime then you will be released. Feel free to dig into historical court cases about border detention if you disagree.
If you get charged with a crime, things are very different.
Nope, no disagreement. I just see your take as very optimistic.
There is no court at the border. If the agent decides you're going to jail, you're going to jail. The decision may be reversed/corrected after, but it's still going to be a big, expensive problem for you and you _are_ going to be detained for a time.
Not to mention walking up with an empty phone and telling the agent to "fuck off" when they ask about it sure sounds eerily similar to the facts of the case in the linked article. I'd wager that's a good way to land an obstruction charge.
If the abuse is egregious, you have a decent chance of pro bono representation or a lawsuit payout. In any case, activism comes with personal risk, and part of activism is accepting that risk while attempting to protect others. (This person was an activist, and itâs likely that they wanted to confine the damage to themselves.)
For the second part, having an empty phone is not a crime, and being arrested for this would be a major scandal. The tech press and political outlets would be all over it. Itâs generally a good idea to avoid directly antagonizing border guards, though.
They won't unless you are already on "their list" My phone basically looks like a burner phone, I do not use social media, do not install apps, my iphone fits (with room to spare) all "apps" on a "single page." I just call and text from my phone and have a browser and maps and that is basically it.
I'm a bit mystified why anyone would bring an electronic device over an international border with anything that could be construed, fairly or not, as evidence of criminal behavior.
Years ago I chatted with a border guard from another country about their job (while they were not working). Not having a phone nowadays would be considered "strange" enough to flag you. If you're not a citizen of said country, it could even dramatically increase the odds of disallowing you entry. Often this would prevent you returning for a set number of years.
At the end of the day, it's always best to just not have anything "bad" on your devices. People have been caught up for all numbers of "innocent" reasons (pictures of their kids in the bathtub, ancient photos in their albums of themselves doing illegal things such as drugs or underage drinking, text messages or browser history disparaging politicians the border guard may support, porn in your history) that can give a border guard in a bad mood good reason to ruin your day.
I personally don't want my phone data hoovered in and analyzed or marked, even though I don't really have anything to hide. I don't care enough to do anything about it, but if I did I would probably have a second travel phone with a curated amount of data, apps, accounts, etc.
They didn't get the data from his phone and will likely lose the case against him. They probably wanted data to go after other people and those people were protected against it.
It was likely unnecessary to use the duress PIN/password. He likely would have been better off simply refusing to provide the PIN/password. He could have rebooted or powered off the device before going through but even without that it would have automatically rebooted itself after 18 hours by default, or a lower time if he had configured one.
With a lot more preparation he could have done an encrypted backup, wiped the device and restored it later but that's very inconvenient.
Y'know, makes me wonder why Democrates didn't disband ICE and CBP when they had control over the Congress and the government. I mean, they knew those agencies would be used in precisely this way, yet did nothing anyhow.
Democrats built the blueprint for ICE's deportation program and architected the law that enabled it.
Clinton's IIRAIRA bill literally introduced expedited removal procedures and created the concept of 'administrative warrants', routinely used by CBP/ICE today.
Without the IIRAIRA, removal would be substantially harder.
IIRIRA was not a 'Clinton' bill. It was initially drafted by Lamar Smith (r) of Texas (HR 2202) and subsequently attached to an appropriations bill (HR 2610), and passed with a bipartisan veto-proof majority.
The naivete of some of the comments here is astounding. It doesn't matter whether you're right, it doesn't matter whether it's the law, it's irrelevant that you have rights, etc. Those things are of the past now, for the US.
I think it would be easier to understand the playing field and choose your actions accordingly, if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech.
The social dynamics are the same - the abuses, the selective enforcement, the lack of recourse, the same characters in the roles of various levels of "law enforcement" and "politics". I'm so very sorry, but the best you can do from here is speedrun the collapse.
> if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech.
I'm pretty optimistic that after the next general America will be ready to give up on the extremity of late turn over a new leaf. I fully expect a new president to be ushered in, whether R or D, and for some level of normalcy to start creeping back.
The Soviets lost eventually, I don't think America can lose. Canadians like myself have watched America win for our country's entire existence; I am unconvinced that a decade of silliness is enough to compare America to East Germany.
In 2016 I remember Americans saying this was the end of the line and the country was doomed. 10y later they're richer than ever and its companies have global dominance of the most world-changing technology of the last 20y. I just don't think "the collapse" is coming anytime soon.
If anyone's interested in a friendly wager, my email is open. I'll happily go 1:1 odds that America will have a new president come 2029 and the country will still remain the world's richest and most powerful.
America dominance on the world is ending, it's a fact. East Asia is at least on par, India is china from 25 years ago.
It's becoming more obvious every day. And yeah, people in 1910 watched Europe dominate the world for about 1500 years. Yet it came to an end.
If you want to Speedrun the collapse, vote for trump. He sure is making a good job right now with diplomacy, lack of long term planning and just getting all your allies to hate you.
I'm just not sure what to do. What the US is turning into is incredibly sad and I wish I could leave.
Just pick up and leave. Literally. And do not feel bad about it. Also ignore other people opinions. There is like a dozen of places to go to. The easiest? UAE freelancer visa. Yes I know, I know: "... but but the drones! The collapse!" It's all BS. When / if something happens there â go to Panama. Then Costa Rica. You are not alone on this route - but only if you really committed to your freedom. If not - just sit there and vote democrats. LOL.
Moving on from being a unipolar power does not necessitate societal collapse. The UK is still around and their empire fell a long time ago.
> If you want to Speedrun the collapse, vote for trump.
This nonsense needs to stop. You canât vote for him again unless he deigns to run for a lower office (unlikely). Term limits are real. America needs to start planning for the post-Trump era and hopefully mitigate further damage with a blue wave in the midterms. Or with non-MAGA republicans who might even return to actual fiscal conservatism.
Interesting you say that, because as another Canadian, I would say that the sentiment in our country is the opposite of you describe. The actions of our government reflect it.
Canada is moving further from US, not closer. Canadians who support Americans are in the minority at the moment.
I'm not sure how a new US president would be able to turn it around.. further more, what's to say that the president thereafter will follow suit? How about the next 5?
The simple answer is we need constitutional reform. Term limits on SCOTUS, codification of norms (eg releasing presidential candidate tax returns, not blocking appointee confirmations indefinitely to steal the position for the next admin), anti corruption laws with teeth. Also things like reigning in the absurd executive power bloat thatâs gone on since Lincoln. POTUS was never meant to be a king. There should never be a case where the executive can start a war (conventional, trade or otherwise) without even CONSULTING Congress.
Your day to day is still pretty much normal. If you turned off the news and never read about Felony charges for citizen deleting phone data [1] you'd just in your head remember there are tens of millions of folks flying, going through customs and border security and all that with 0 issues. What you wrote I think regarding the decade of silliness precisely supports the point, in my opinion.
[1] I'm not defending the behavior of border control here, but I also don't think we need to overreact to this one example which is exactly what is happening.
> Felony charges for citizen deleting phone data
Yeah, that's awful. As far as federal overreach of power goes, that's pretty inexcusable. I'd probably posit that COINTELPRO in the 60s was more insidious, but that doesn't discount this story individually being terrible.
I still maintain that America is not in the midst of its own demise and a comparison to East Germany is inaccurate.
> As far as federal overreach of power goes, that's pretty inexcusable.
Selectively detaining this guy, likely overreach.
Trying to get his phone's unlock code to go on a fishing expedition for whatever they can find, absolutely overreach.
But this guy catching felony charges for giving federal border police a duress PIN to wipe his phone when they asked for an unlock PIN? Not actually overreach.
You have the right to remain silent, not to lie to the police when detained (18 USC § 1001, and many state-level laws to the same effect also exist). Our justice system could not function if people had a right to lie to the police. Once you are detained, whether or not that detention is eventually determined to be lawful, destroying or disposing of your possessions to prevent police from accessing them is also generally a crime.
You fight abuses later, in court. Or, if you're going to use a duress PIN in the moment, you accept the legal consequences.
And yes, giving a duress PIN to wipe a phone when asked for an unlock PIN is a lie which may result in destruction of evidence. And no, the law does not care about "I'm not touching you"-level rationalizations of whether something is a lie or whether it was technically the police who entered the code to wipe the phone. Proximate cause is a longstanding legal concept.
> But this guy catching felony charges for giving federal border police a duress PIN to wipe his phone when they asked for an unlock PIN? Not actually overreach.
I think it's an interesting case that will get litigated in the courts. It seems they'll have to prove that the phone contained "evidence"; it could have just had embarrassing personal photos that he didn't want shared. When a house is raided and someone flushes a toilet, can courts assume they flushed drugs, or does that have to be proven?
I hope he's found not guilty, but either way this definitely is not the "sky is falling", "we're almost a police state" case that folks here are making it out to be. It's a very narrow and novel line.
Despite the normalization of masked federal gunmen kidnapping people based on the color of their skin and the language they speak.... Not even breaking a law in the process, the supreme court legalized racial profiling.
One can just argue about the normalization of people breaking the law by overstaying visas or hopping the border or whatever being the Supreme Court (or whoever you feel like blaming) legalized some other concept that most Americans also find disagreeable.
We don't have to have brown shirts pulling people off the street, and we also don't need to have this stupid fight over simply enforcing our borders like every other country on the planet. Extremists on both sides are as always, simply incorrect. Reject MAGA, reject DSA.
In context to my OP, none of this stuff or policy really affects most people's day to day lives. If you turned the news off you'd probably have no clue people were jumping the border en masse and you'd likely have no clue that those very same people were being arrested and deported.
Most major industrialized nations have gone through something like this and it usually takes much longer than 10 years to escape and correct.
> some level of normalcy
You are undoubtedly correct that at some point there will be new leadership in the US.
Politics makes leadership change a possibility. Biology makes it an inevitability.
But I don't think the evidence is very strong that switching from one man to a different man, even if the new man wears a blue hat instead of a red hat, will make that much difference against capital and its surveillance state.
This isn't a false equivalence "both sides" argument. I'd greatly prefer the blue hat over the red hat.
But the blue hat only makes the underlying forces of late capitalism a little slower and a little less vicious, while simultaneously legitimizing that system.
Yeah, mostly agree but playing devils advocate, PRISM was authorized under bush, implemented under Obama, and is being abused by Trump. Obama promised safeguards, but itâs pretty clear those were just a ruse. Itâs only going to get worse. The well deserved controversy around Flock is the perfect example.
I agree. It's actually quite insulting to other countries whose actual atrocities were measured in lives lost. I voted for Kamala but Trump Derangement Syndrome is real. He's just a loser, he's not even remotely brave enough to be Hitler Jr.
The guy doesn't have the stomach for real totalitarianism. Just populism, corruption, and weakening the country.
Yes but many who support him and bankroll him do. They use him as a public thermostat to keep upping the heat to see if any of the frogs jump.
With all due respect, this is a wild take. Things aren't great in the U.S. right now, but they're not even in the same universe as what the Stasi was doing.
> I think it would be easier to understand the playing field and choose your actions accordingly, if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech.
It's a very insidious, first you look all over your neighborhood flock cameras Hundreds of them came out of nowhere Nobody fought back .
it's as long as you're not doing anything wrong you don't have to worry about it Then once changed the definition of what wrong means.
If you're not a criminal you don't have to worry about it That's for your safety Then they changed the definition of what a crime is
its only with the benefit of hindsight (and being on the winning side- thus the propaganda was never dispelled) that we consider the stasi and so on the way we do.
If it walks like a duck, and quacks like a duck.. might just be a duck.
I donât believe those living ânormal livesâ in East Germany or the Soviet era considered the police to be evil and invasive the way we do today.
> I donât believe those living ânormal livesâ in East Germany or the Soviet era considered the police to be evil and invasive the way we do today.
"normal life" under the Stasi was constant political terror and suppression.
The death counts are low because they thought death too little of a penalty for opposing them - they used psychological warfare (https://en.wikipedia.org/wiki/Zersetzung) and torture instead.
Soviet era under Stalin was brutal.
Soviet famine of 1930â1933
"It is estimated that 5.7 to 8.7 million people died from starvation across the Soviet Union. In addition, 50 to 70 million Soviet citizens starved during the famine but ultimately survived."
https://en.wikipedia.org/wiki/Soviet_famine_of_1932%E2%80%93...
Great Purge
"Scholars estimate the death toll of the Great Purge at 700,000 to 1.2 million."
https://en.wikipedia.org/wiki/Great_Purge
> this is a wild take
Itâs a lazy, complacent take.
I mean its so much easier to do stuff the Stasi could only dream of with technology today.
What makes you qualified and informed of whatâs taking place to determine that?
What we hear about is far from comprehensive, and many of the atrocities wonât be unveiled or investigated until the next decade.
The Epstein cover up shows theyâre used to keeping secrets.
Iâm not sure why weâre pretending thereâs not a convicted felon in charge of the entire system.
> what the Stasi was doing
the stasi were spying on people and putting them in jail. what exactly is your claim about the difference? is it a difference in distinction or a difference in degree?
The USA started from and has come back from way worse in the past.
Some dark, dark things happened in the USA, and almost every progression had a corresponding backslide - but the tick-tock has always ticked further towards a freer, more equal, and more equitable society.
Progress doesnât always (ever?) require complete collapse.
Iâm willing to hope this era is another âtockâ. But that does require people to not just give up (or even work to accelerate the backslide?!) as you seem to be suggesting is the best course of action.
>but the tick-tock has always ticked further towards a freer, more equal, and more equitable society.
This is a popular sentiment, not a statement of historical fact. Arguments both for and against this are credible.
You can make a credible argument that the American society is less free, less equal, and less equitable than it was at its founding?
There are just so many ways in which this seems crazy to me. I feel like you think youâre luring me into some sort of rhetorical trap - but to pick the two elephants in the room, a large proportion of the population was literally owned by other people, and only white male landowners could vote.
Do you honestly think that our society was more (or as) equal 200 years ago than it is today?
Or even 50 years ago? Even in the 1970s, there were places in the United States that women couldn't get a checking account without a man co-signing on the loan.
We can certainly take issue with how rich countries oppress and exploit poor countries today, but you can't honestly say it is worse today than it was during colonialism.
This defeatism is unhelpful. I'll not simply surrender the country that I love, thanks.
> if you accept the US has entered its East Germany / late 20th century Soviet era
That's just too ridiculous and absurd for most people to accept, thankfully. I accept reality, not social media narratives.
In law school we skipped border search cases because the border crosser cases can basically be summed up with âyou have no right to privacy at the border.â This has been the common law for 5000 years. It has nothing to do with Trump, or cell phones, or anything other than the notion that a sovereign has an absolute right to know what is crossing its borders.
This has been legal since long before Trump, if you don't like it there's laws in motion to ban it you can support, but entering across a border you've been allowed to be searched without a warrant for decades at least. And if you're being searched and then you destroy what they're trying to search... Here you are.
> US has entered its East Germany / late 20th century Soviet era
> The social dynamics are the same - the abuses, the selective enforcement, the lack of recourse, the same characters in the roles of various levels of "law enforcement" and "politics"
What you're describing is politics in general. The question is not whether abuses occur (they do, everywhere), but whether the system is built to be resilient and course-correct over time.
The thing about freedom is not just that it's less miserable than the alternative; more importantly, freedom enables a feedback loop where people's individual choices carry corrective information: what they buy, what they sell, how much, at what price, who they vote for, what they write/publish, what they read, what they say etc. The system at large can correct itself over time if (a) these choices are allowed to have power to influence the system, and (b) the courts enforce justice without interference by the ruling party.
Not a single communist country in the 20th century stayed communist for more than a few years when only 2 freedoms were allowed: (1) freedom of the press, and (2) freedom of the courts from control by the ruling party.
The Soviets and East Germans suppressed every form of freedom that carried information or potential corrective power, because they maxxed on staying in power above all - they effectively had to. No one wants to be under real communism/socialism[0], so for it to be stable it has to be maximally suppressive.
[0] see various records of escape attempts, such as https://www.ebsco.com/research-starters/politics-and-governm...
The US has it's mid-term elections this november, and it's possible, and even likely, that the Democratic candidates will win overwhealmingly. The Democrats are not a monolith, either, the Democratic Socialists of America political group is the very progressive part of the Democratic party, they are the ones that are not accepting dark money campaign donations. I do not agree with a lot of the unrealistic things that some DSA candidates have said, but those or the candidates that aren't winning the primaries. There is a giant blue tidal wave coming in November. Trump will become nothing more than a lame duck "president", and he'll likely be impeached in the House and convicted in the Senate and the Justice System will probably be the final arbiter of his fate. That's the way I see it. And I never believed I would be saying what I just said, but the fact is that since trump was elected, the democrats have flipped 31 (at last count) formorly Republican held seats, and the republicans have flipped exactly zero seats from democrat to republican. The American People are not their goverment, especially right now, even though that's not how it was meant to be, but I know one thing, they are fed up and enough is enough.
> The naivete of some of the comments here is astounding
This is HN. https://xkcd.com/538/
Hallelujah!
You don't need to go to other countries to play your fears, lest we forget our constitution is a pro-slavery document and one of the first acts of congress was the fugitive slave laws.
I think it's more effective to stick to our own history because this country has always been a struggle for workers outside of a small very respite after WW2 that has been actively fought against and weakened since.
> I'm so very sorry, but the best you can do from here is speedrun the collapse.
This is a pretty silly take. If you actually follow the news, all of these issues are getting pushback. It's not at all clear that even a competent fascist-leaning government would be able to push through what the current one is trying to do, and sadly for them, competence in their ranks is in short supply.
The bigger issue has nothing to do with the faddish concerns of the current government. The era we should be looking to is not East Germany/late Soviet - it's more like the Gilded Age. Robber barons need to be dealt with from time to time.
>Those things are of the past now, for the US.
It's a temporary situation, it isn't necessarily a permanent situation.
Tell me how you think East Germany is doing these days.
And no, it doesn't have to take 40 years to right the ship, so long as people get their heads out of their asses and vote. Things are likely to change by the end of this year, and in another 2 years we could have a very different government that could undo a lot of the bullshit going on right now.
Tens of millions have voted for this 3 times in the past 10 years, it succeeded twice. This is not going away, half the voting population of the US wants to live under authoritarian rule and will do anything to take the whole country with them.
I think if I lived in a truly authoritarian country I'd be a bit taken aback to have my situation equated to that of Americans'.
Voters change their mind all the time. Sure, there are still plenty in the US who want all this, but Trump's approval ratings are at or near all-time lows, and at least some people who voted for him finally see his lies for what they are, and have regrets.
It's still worrying! His supporters still number lots of people who a) are still somehow too gullible to realize Trump and the MAGA crowd are not going to make their lives better, and b) actively want what's going on. But there are easily more eligible voters in the US who wouldn't vote for a Republican with a gun to their head, or who are finally starting to understand that "sticking it to the libs" is hurting themselves.
It's not going away, but it's likely that it's declining, and possible it will continue to do so. Whether or not it declines quickly enough, before these jackasses consolidate power and break what's left of our institutions... well, that remains to be seen.
You can rage against Trump and republicans as much as you want but in the end the democrats must learn to formulate why anybody should vote FOR them. Even in the current chaos they arenât able to bring up a coherent message and follow through when they are in power. I see the same in Germany. AfD is getting stronger while the established parties get nothing done.
It reminds me somewhat of the state of the Weimar Republic. The democratic parties failed which gave an opening to the nazis.
Voter preferences can change with time, as voters observe the effects of their previous selections. Most voters don't want and didn't vote for authoritarian rule. They are humans with many diverse challenges & concerns in their lives. Their votes are an attempt to balance/compromise among those.
>half the voting population of the US wants to live under authoritarian rule
That's half the people who showed up to vote, not "half the voting population". 1/3 of the eligible voters simply didn't vote, and from the people I've encountered that don't vote, they are mostly left-leaning.
No, stupidity and self-harm aren't going away, those are human traits. The current admin is actively hurting everyone, with tariffs and stupid wars he campaigned that he wouldn't start, ICE in every city everywhere causing chaos even to right-wing supporter-owned businesses (they wanted immigration reform but not like that!). This admin has shit the bed, and even his supporters are feeling that. They are now in the "finding out" phase, and the next phase doesn't look so good for republicans in the next election because of it.
Does anyone on the other side have a credible plan to undo the damage?
Where's the Project 2028 book?
Is there anyone credible putting together the Executive Orders to undo the stack of shit, is anyone putting together a short list of District Attorneys to interview on January 21, etc?
https://www.liberalcurrents.com/the-reconstruction-papers/ is explicitly aiming to be a Project 2028 book for the left.
That's the thing that worries me. The Democratic party just doesn't have their shit together in that way. They absolutely should be developing this sort of plan. I expect there is some plan, but I doubt it's as comprehensive or in-depth as Project 2025. And it needs to be.
On a long enough timeline, nothing is permanent. The question is how long it lasts and how bad it gets before it gets better.
In terms of the ending, East Germany was nearly an ideal case. The state just sort of gently fell over. The country got absorbed into a friendly neighbor. There wasn't much loss of life, no widespread destruction.
Then there's East Germany's predecessor state, which ended because it decided to wage war on half the world, and its people bore the consequences. Millions dead, cities wrecked, occupation by foreign armies, the country carved up. "This too shall pass" isn't always a good thing.
Or look at the state that created and sustained East Germany. Borne out of violent revolution, decades of repression, collapse, turmoil, economic hardship, brief flirtation with democracy, de facto dictatorship, no end in sight.
My biggest worry with the US right now isn't the government itself. It's that so many people want this government. Voting doesn't help when the voters want the bad stuff. We could have a very different government in another two years if the people want it. I'm not convinced they do. If they do I'm not convinced that sentiment will last. We already went through this once, and the "actually, let's not give the shitheads power" sentiment fell apart by the next election.
> Tell me how you think East Germany is doing these days.
> And no, it doesn't have to take 40 years to right the ship, so long as people get their heads out of their asses and vote.
so then you admit the outcome here is contingent/conditional. do you understand that means we are already in dire circumstances if the outcome isn't certain?
For exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs. Imagine booting the phone from a flash drive, making an encrypted image of the phone on said drive, and writing a fresh OS before reaching the border.
There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).
Some time ago, Android with a custom recovery could come close to that, but it was fussy and as far as I know, no longer viable. Increased use of TPMs for storing credentials seems to be at least one of the reasons.
It may be fun to fantasize about these things some times, but there is no technical solution to tyranny. Laws are not like code, intent matters. Ultimately if the intent is that the government wants to see your private data, hiding it in any way will be charged - it doesn't matter if you jump through hoops to avoid this specific instance.
This is a half-truth. In a full banana republic, technical compliance with the law will not prevent consequences for failing to do what the authorities want. In a jurisdiction with perfect rule of law, it always will. The USA is somewhere in between.
One of the laws that's enforced pretty well in the USA is the protection against unreasonable search. Most of the time, a search requires showing a judge evidence that the search is more likely than not to reveal evidence of a crime. Exceptions are narrow and specific; the government's options to punish someone who refuses to decrypt data at the border are limited to brief detention and seizure of the medium.
Not yet tested is the idea that erasing data on the spot satisfies the purpose of the border search exception, which is to prevent importation of things that are illegal to import. This case might address that question.
Unreasonable search is always under attack though. There are many instances today of cops forcibly entering a home claiming nothing more than a welfare check, or "we received a call."
Edit to add that its also more difficult than it should be to protect and exercise the right against unreasonable search. If a cop knocks on your door its a consent-based interaction. You can simply not respond, but if you do happen to crack the door they can and will look in for any signs to claim as probable cause. Further there are cases where a person stepped out to talk and when they turned around and walked inside the cop slid right in behind them and later claimed in court the open door was implied consent. (I don't have a link to the court docs unfortunately.)
>There are many instances today of cops forcibly entering a home claiming nothing more than a welfare check, or "we received a call."
Sure, but there are also many instances today of evidence getting thrown out in court due to cops not getting a warranty and poisoning the tree and all its fruit. Rights don't just enforce themselves, there are and have to be a number of layers to the onion to help reduce the violation numbers at each stage.
>There are many instances today of cops forcibly entering a home claiming nothing more than a welfare check, or "we received a call."
And there are also many instances of the city being sued, those cops being sued, losing qualified immunity, losing their jobs, etc, because we do still have recourse when cops do the wrong thing.
If your rights were violated, you stand to get a big payout, and get the cops fired that violated your rights. We aren't powerless, yet.
> And there are also many instances of [...] those cops being sued, losing qualified immunity, losing their jobs
Not really, the data points the other way. Cops basically never have to actually pay for their wrongdoings. Over 99.98% of money successfully recovered from cases against police is paid out by the cities, not cops personally [1]. A considerable number of cops that are fired are also eventually rehired by the same department [2] or a different one [3]. So I don't think it's that clear that you "have recourse when cops do the wrong thing".
[1] https://nyulawreview.org/wp-content/uploads/2018/08/NYULawRe...
[2] https://scholarship.law.vanderbilt.edu/vlr/vol74/iss4/4/
[3] https://yalelawjournal.org/pdf/GrunwaldRappaportArticle_s6br...
Can you link to some of these cases of cops losing qualified immunity? It's an area in interested in but I understand that to be a vanishingly rare outcome - like only in very egregious cases, not just for run of the mill rights violations.
Or your family gets the payout because the cops killed you.
we're far closer to one side of that spectrum than the other. consider the retroactively legalized mass wiretapping, room 641A, NIST compromises, PRISM, 14 Eyes, the other Snowden revelations, etc
then consider this paired with the implementation of mass data sharing between the alphabet agencies, surveillance data sharing from private companies like Amazon Ring, Flock, Clearview, etc. and NSPM-7 ordering agencies to create JTTFs to target organizations like BLM
then consider the unmitigated use of force by federal law enforcement agencies like ICE
I think if this were 1995 your point might be fair but those days are unfortunately long gone
Border search exception lowers the requirements for judicial oversight.
"In United States criminal law, the border search exception is a doctrine that allows searches and seizures at international borders and their functional equivalent without a warrant or probable cause. Generally speaking, searches within 100 miles (160 km) of the border are more permissible without a warrant than those conducted elsewhere in the United States."
https://en.wikipedia.org/wiki/Border_search_exception
213 milion people live in this zone.
https://www.aclu.org/know-your-rights/border-zone
Agree with the thrust of your comment, but I had to comment on this:
> In a full banana republic, technical compliance with the law will not prevent consequences for failing to do what the authorities want. In a jurisdiction with perfect rule of law, it always will.
I think you may be misunderstanding that many laws, even in fair, just societies, are intentionally designed to be flexible. The real world is so variable and messy that in many cases it isn't feasible for a law to be written such it can be unambiguously determined whether or not a specific action violated the law. Laws often rely on humans using context to judge whether something violates the spirit of a law, and in a just society, this is a good thing.
My point is that I don't believe the idea of "perfect rule of law" is sensible. Law is always necessarily a bit fuzzy and nebulous.
Normally I agree, but making the implementation initially ineffective is a good way to complicate more far reaching measures.
Americans aren't standing up against this, but they might have considerably more interest if the government was instead trying to ban encrypting data in cloud storage for everyone.
There's also just the fact it's ridiculous I can't have a spare phone ready to go in a few minutes and get it back exactly as I left it.
Yes, trying to solve a regulation or legal issue by some technical workaround will never work, you have to fight it at the same level, legally, or system-wise, otherwise, you will be like the person who tries to wash the stairs from the bottom all the way up, it rarely works, you gotta go up to down, collectively go against the matter rather than individually duct taping it for your own specific needs. In that example, it wonât be far fetched the same ones who made it illegal to wipe your phone to make illegal to install xyz OS or using abc protocol, in fact, thatâs exactly what they are trying to do under the disguise of âprotect the kidsâ and going after encryption or similar privacy related issues.
They would not be so vehemently against it if it did not work. There is a reason E2EE, duress passwords and similar technologies are under such intense assault these days.
GrapheneOS has built-in encrypted backup and restore. It backs up the same data transferred by Google's device transfer feature for moving to a new phone which is nearly all app data, the data in the home directory, contacts and a bit more. Certain apps such as Signal encrypt their own data with another layer of encryption using a hardware keystore key. Signal's own backup system needs to be used for that, although it can just be used as a way to get data into the system backup.
It's worth noting wiping a device shortly before an anticipated search could also be considered destruction of evidence in the same way. It doesn't have to be done after a request for the data to be considered that.
> There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).
This was likely the best move for him to take. They could have held him for a while and wasted his time but eventually would have had to give him access to a lawyer and let him go. Unless they had a recording of him entering a PIN/password, they were nearly certainly not going to get his data from it. He very likely didn't gain anything from wiping it.
He did help every GrapheneOS user by spreading awareness of the duress PIN/password. It was designed around an adversary aware of it and therefore not wanting to attempt using a PIN/password obtained via coercion. In the future, we want to integrate the feature into the secure element rate limiting for key derivation so it can't be avoided by exploiting the OS.
> refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA)
⌠yeah I doubt that nowadays honestly
I've restored iPhones before, and it does seem pretty simple. Easier than PCs for sure. It's not instant, but the basic configuration is restored pretty quickly while the bulk data restoration happens in the background while you're able to use the phone.
What about banking apps and stuff? Does the device binding still work or do you need to set it up again?
Depends on the app and security setup. If it's using old school Symantec VIP Access, it will not survive a restore. If it is using TOTP from 1Password, it will. Not sure about other options, those are the two I am most familiar with. Thankfully I only have a single app these days relying on VIP Access.
> For exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs.
You're always been able to backup and restore your iPhone to your local Windows PC or a Mac using free first party software from Apple.
Also, it is just a nice idea if you are prone to losing phones. Backups are good for all kinds of reasons.
There's a way simpler solution and it's just to leave your phone at home and put your SIM in a different handset without all your data on it
An increasing portion of phones are eSIM [0] only these days, and the difficulty of swapping can be weirdly-bad depending on provider.
[0] https://en.wikipedia.org/wiki/ESIM
But non esims exist still, and if you're that worried about security, you can get one.
> ...making an encrypted image of the phone on said drive... refuse to unlock the drive
How is this any different than refusing to unlock the phone? It just seems you've added unnecessary extra steps.
Think for a moment. What is the difference between giving them a password which wipes the phone and giving them a password which opens a blank phone?
It's the same thing. They punched in a code, they are presented with a wiped phone. Can they prove the guy gave them a distress password and wasn't simply carrying a wiped phone to begin with? No, but they just need to imply that is the reason to charge him with the felony.
Tyranny does not care about "proof".
It doesn't even care about plausible deniability.
Best you can get away with is lack of suspicion. Have a secondary phone with some standard apps on that you use now and then so theyhave a history and just look like you are just not a technical person and read novels on dead trees instead. A lot of work but likely works.
are we seriously approaching a point where its quasi-illegal to not participate in the socials?
More like they've looked you up and the apps being missing would be a giveaway about the dummy phone
The best technical solution is one code opens to a phone that has things but isn't your actual phone, and then another code that opens to your real phone.
Have you considered "no password set"?
>What is the difference between giving them a password which wipes the phone and giving them a password which opens a blank phone?
They don't get any indication that there was data there to be deleted, and you don't just factory reset but flash w an image of a clean phone that's been used. It has apps, it has accounts, it looks to the untrained eye (because that's who's looking at it) like a phone that was used normally by someone who has done nothing wrong.
Really? Does it take a long time to recover the phone? Havenât really ever needed to recover a backup
Apple makes this very easy. I broke an iPhone and bought a replacement. If you have iCloud, you login to the new phone and you can see which backups you can recover from. If you are transferring a phone, say you upgraded, itâs even easier. You can also image the phone with a connected laptop and store it on a backup drive, which is nice to not use up iCloud limits.
The transfer and backup system are pretty much the same mechanisms.
Restoring is probably order of ~1 hour to go through all the setup. Then some hours to sync any data and updates that need to be redownloaded, apps reinstalled, etc.
Aha that is actually pretty long
I mean, you could ship your real phone to w/e destination ahead of you and bring a $50 burner to the border. If you're a person of interest this won't work because they can monitor you and the destination but if you're a regular schmuck then a burner that never touches your private data or accounts and has a bunch of dummy stuff on it will get you past the border goons.
I used to play around on projects adjacent to Tor and TailsOS, and had an idea for a setup I was researching. It's a little intense and probably has annoying failure modes, but sharing in case anyone else finds it helpful:
- Tasker is an automation app for setting up rules for triggers and actions. It allows extension apps to be created to add new triggers and actions.
- someone at one point made an extension to add an action for wiping or factory resetting when triggered
- there was an existing extension (or core feature) to trigger when certain signals are lost or found (e.g., wifi signals, Bluetooth LE beacons, etc)
So the idea is to carry a BLE beacon (any "item tracking" one works) on your keychain, and an unassuming faraday cage pocket alongside it. If you want to wipe your phone, slip the fob into the pocket, the signal disappears, and your phone wipes. And if you don't have the keychain on you, just refuse to open it right away, as when they put the phone itself in a faraday cage (to prevent it from being remote wiped), they cause the signal to be lost, and it gets reset.
Not sure if all the pieces still exist (I dont think the tasker extension for wiping existed outside a forum post...)
I like the idea of a phone that automatically wipes itself if I donât act to stop it. I wonder about the legality of that if the duress code is considered âdestroying evidence.â
Or keep it in a faraday bag and have the phone wipe if it sees it. If you're ever searched (or otherwise indisposed), they'll open the bag and wipe your phone for you.
Oh hey, I like this variant! So... both the BLE beacon and the phone have a faraday cage, and if they ever appear together outside their cages, the phone wipes?
Perhaps less likely to go wrong than my original proposal when living normal life, as it might wipe if the BLE signal randomly gets lost.
It would be nicer if you could leave phone in cage during security, and remove beacon while loading airport trays ("remove all electronics from their cases..."). the only chance for a failure mode is only when you're going through security, and have the fob outside its case..
But you'd need to be able to leave your phone in the faraday cage pouch while going thru security, which is only ok if they don't notice... (maybe they commonly don't notice small faraday pouches aren't empty... Maybe they wouldn't if you had a secondary mobile device...)
I was imagining only the BLE beacon living in one of those little faraday pouches people put their key fobs in. They should be pretty much transparent passing through the x-ray and a pouch with an airtag in it wouldn't raise any suspicion at all at the airport.
Only once you're getting invasively searched would they (ideally) dump the pouch out into the tray with your phone.
This depends on the beacon being visible. If they just take the phone and walk away, because that's where they think the evidence is, it won't wipe.
When I've gotten secondary screening the first thing they do is take all my belongings and rifle through them on a table. That seems to be standard practice and I'm sure it was step 1 in Tunick's ordeal.
Both approaches have situations they wouldn't work in. If you're extra paranoid you could do both.
> If you're ever searched (or otherwise indisposed), they'll open the bag and wipe your phone for you.
Isn't that the exact same situation here that resulted in felony charges? Border agent was given a duress PIN and wiped the phone for the owner. Now owner is charged.
I don't see how. Regardless of how you feel about the lawfulness of the overall situation, Tunick gave an agent false information which resulted in the phone being wiped. That's intent.
This requires no action whatsoever from the phone's owner, you could even be unconscious/dead and it would still work.
The intent in that scenario is to wipe your phone (destroy evidence) when a bag is searched by federal agents.
I used to contribute to this https://en.wikipedia.org/wiki/USBKill
Ah I recall I used to see the creator around :) thanks for your work!
Regarding the motivation for usbkill mentioned in the article: I too was motivated to think on this stuff in relation to my sense of injustice around Ross Ulbrecht, and wanting to think of some way that someone in his position could avoid getting caught. One creative variant in my thinking involved embedding the BLE beacon inside a rubber ball that could be launched and lost track of. Or maybe embedded in heel of a shoe and ditched in transit haha
With no third party apps you can set an iPhone to wipe itself after 10 failed passcode attempts.
US law enforcement is well aware of it.
They're also now well aware of the GrapheneOS duress PIN/password feature. It was designed to work against an attacker aware of it by acting as a deterrence. If they're aware of the feature, it discourages them from trying to coerce a PIN/password and attempt to unlock with it. We aren't fond of features depending on an attacker being unaware of them and this isn't one of those.
Pixels have a high quality secure element enforcing a maximum of 20 unique attempts to derive the encryption keys for each separately encrypted profile. There's also very aggressive rate limiting between the attempts. It filters out duplicate attempts by temporarily remembering the previous 5 unique attempts to make the rate limiting more usable. A misremembered PIN/password repeatedly entered over and over will only use up 1 attempt.
Android does have standard support for enabling wiping after N attempts and an open source app can be used to set a configurable limit rather than specifically after 10.
tfw face when I leave my phone on the table and go to the restaurant bathroom only to return to a brand new squeaky clean factory reset
All Archive pages, when accessed from Italy, now are blocked by the Government:
"PAGINA INTERDETTA DAL CENTRO NAZIONALE PER IL CONTRASTO DELLA PEDOPORNOGRAFIA ONLINE (C.N.C.P.O.)"
âPAGE BLOCKED BY THE NATIONAL CENTER FOR COMBATING ONLINE CHILD PORNOGRAPHY (C.N.C.P.O.)â
Oh, we live in an interesting age.
I am currently in Italy (just passing through) and was able to open the archive link with the article
If you're using roaming on your cellular plan, all your traffic is routed over VPN to your home country, so local blocks don't work.
(That's one of the reasons why it's trivially easy for foreign visitors to China to bypass the Great Firewall.)
If you were on wifi, that's notably interesting.
Then you probably had a home country IP and they filter based on IP.
U.S. citizens are going to need obtain a burner phone before returning, and load it with the absolute minimum to load boarding passes, etc., perhaps some reading material or a movie to watch on the plane, and be prepared to share full credentials for thing at the border.
(I used to do some travel patterns where taking a certain client laptop wasnât an option. It was an absolute gigantic pain for the type of work I did, but it was just too risky to have a laptop seized and be expected to input credentials.)
I think it's enough to shut down you phone. Then it needs a pin, and you're entitled to not give that over, I believe. So you should be safe, apart from some kind of rubber-hose cryptanalysis.
> So you should be safe, apart from some kind of rubber-hose cryptanalysis.
There are vendors that sell the technology to adversarially access phone data, the "Before First Unlock" is the safest state a phone can be, but it's not infallible. The safest option is to have a burner or factory-reset phone with nothing on it, even if the hack succeeds.
I've worked with Cellebrite, the industry standard in IT forensics for unlocking and imaging phones. It just runs a series of known exploits. PIN lock, data encryption and regular updates will beat it most of the time.
> I've worked with Cellebrite
Any chance you want to do a public service and publish the latest compatibility matrix?
Just joking, obviouslyâŚ
Before First Unlock with recent hardware and an up to date OS is probably sufficiently infallible for an average person. I wouldn't want to rely on it if I was engaged in espionage, but for someone who won't get the NSA pulled into the case, I'd be pretty confident. This leaked Cellebrite support matrix shows that BFU was secure against them for iPhones that were nearly four years old at the time, and I doubt it's become significantly worse since then: https://ia800405.us.archive.org/32/items/inseyets-offline-uf...
> Then it needs a pin
A compromise to this is that many phones have a "lockdown" mode, where it isn't fully off but refuses to accept biometrics until a code/pattern is used to bring it to a more day-to-day mode.
It's less-secure than being fully off, but it also means if you do need to access your phone you can do so more-quickly.
If you don't give a pin, they can seize your devices (Andrew Tate on his 1st visit to Florida said that he refused to give pin and they seized phone and laptop)
They can't keep them, you'll get the devices back. Use a temp phone in the mean time.
Sad that we have to accept this as a risk of international travel, but here we are.
They can absolutely keep them. Or they can just "lose" them "accidentally". Who exactly would force them to give them back? Or put another way, who exactly will punish them if they break the law?
They canât keep them permanently, but unfortunately they have in the past kept them from some people for years, until the hardware was past its useful life. Itâs a good idea to only travel with electronics you donât mind losing (and not just because of this).
You have a worldview thatâs incompatible with the reality of the current US legal system where things work the way you believe they should, rather than the way they actually do.
Morality and direct commonsense interpretations of law do not apply when there are literally unlimited resources stacked against you. But, assuming you can wait the potential ~10y to receive your device back that it will take to get your device returned to you, good on you. If you think that the current SCOTUS will rule in your favor, good on you.
The reality is, we live in a time where the most horrendous interpretation of the law is the one that will happen. And it wonât be in your favor.
Honestly, I think this is still fine for most people. The probability of a border agent asking me to unlock my phone is very, very low. The inconvenience of using a burner phone is high.
If they do take my phone (completely shut down, unlikely they'll be able to break in) and it's gone forever, that sucks, but then I get a new phone, restore from a backup, and move on with my life. Given that the probability of getting to this point is very low, I'm comfortable with the risk.
But sure, if I was at high risk of being detained at the border due to my profession, country of origin, ethnicity, etc., I'd probably look at this differently.
I'll take that risk. It's pretty unlikely, and if it happens, having to buy a new phone is not the worst thing in the world.
If youâre a U.S. citizen: CBP cannot deny you entry to the United States merely because you refuse to unlock the phone. If youâre a non-citizen seeking admission: refusal is much riskier.
The important wrinkle is that CBPâs published policy expressly guarantees that a person being admitted as a U.S. citizen wonât be denied entry solely because CBP couldnât inspect the device. It doesnât give lawful permanent resident (green card holders) that same explicit statement. Instead, it says refusal by a âforeign nationalâ can be considered in an admissibility determination.
Isn't the guarantee for citizens a bit stronger than CBP's policy? I don't think they can lawfully deny entry of a citizen, period.
They cannot (lawfully) deny entry. But they can admit you and then immediately detain and/or arrest you.
Sure, if they have a warrant or probable cause, just like any other law enforcement officer.
In theory, yes, but in practice they can do whatever they want, and suing them after the fact is going to be expensive, and have a high probability of not working out for you.
When interacting with border officials (or any LEOs, for that matter), be polite, don't get hostile or aggressive, but also be firm and don't volunteer any information that you're not required to give.
this only applies if they don't refuse to acknowledge your papers as valid and/or they haven't previously put you on some hidden list of people of interest, in which case the instance where you get to prove you're who you say you are will be mediated, like the rest of the (as per the current system) nonpeople, by as many layers of humilliation and risk to your life and health as they can place.
Giving up knowledge (password) is something that is typically scrutinized at the border as well. Had he just handed over the phone and the phone had abilities to self destruct if tampered with (e.g too many incorrect pin entries) -- well the gov's case wouldn't been much harder. If they seized property and accidently destroyed the data, then that's on them.
You are correct, you have to give up the phone but can't be compelled to give up the password, and you'd get it back some indeterminate amount of time later.
It's actually been on the books for a while (decades at least) that customs can search you at the border without a warrant even if you are a citizen.
This case seems to have become a big 'Trump bad' poster child (people are calling the US East Germany in these comments...), but if this exact scenario happened at least in the last two decades (I found an example upholding the searches from 2004) then it would at least be possible to charge them with deleting evidence. Even this probably would have been nothing if he refused to give up his password, not being required to provide a password has been upheld for years. They can seize your phone for some time but I'm unsure on the times they ask and then just let you move on when they find out your a citizen.
As everything on your phone should be backed up, you could just wipe your phone to new.
Then log in with another temp account and use that for border pass etc, and then after border checks log back into your normal account?
Just get a boarding pass from the counter old school style. They still print them.
Why would they need to do that?
leave electronics at home. never take electronics to any airport unless you don't care if everything is read. your only option now.
or have a good enough decoy or encryption system in place. Such as pressing a button to lock or replace key documents but keep the rest intact. So what looks like a sensitive document omits key information but still appears to be legit to observer.
That's probably a bit overkill. TSA doesn't have nearly as much power as CBP, so it's only a concern when coming back across the international border.
the best decoy is a cheap burner phone that you only use for travel purposes
According to the article, he was actually using GrapheneOS and gave the border official the Duress PIN. So I guess technically it was the official that erased the data :-)
Not how the law works. If I put a bomb in a box. It will explode if a certain pin is put in. And you ask âcan I open the box? What is the pin?â And I say âhere is the pin to open itâ and the bomb explodes. Do you think I can claim they blew up themselves ?
I'd guess the smiley indicates that op meant it as a joke.
Yes. Because law enforcement assumes there's bombs in boxes by default and defers to the bomb squad to understand the box before they touch it.
Why would the bomb squad trust the box owner to help them defuse it? To understand the issue, you have to construct a proper analog.
Sure, you're right that this analogy is bad, because that would never happen.
But if it did, you'd still be on the hook for the bomb, even though technically the LEO set it off through incompetence.
I never told you it is a box with a bomb. You just asked if you can have the pin. You can do another example where you give false information with the intent of making another person take an action that they donât wanna take and would not take unless you had provided false information. You are causing the action to happen. Just like if you yell fire in a theater. You didnât stamped anyone to death. But your words caused it.
A better feature would be a 2nd PIN that unlocks the phone to a secondary profile, which you would leave pretty bare for situations like these.
I wonder whether it'd be better for a duress PIN to delete existing data and also create a semi plausible artificial profile to hide the deletion event.
This discussion was raised last time this story was discussed. I was among its advocates: <https://news.ycombinator.com/item?id=49061890>.
Briefly: no.
Less briefly: <https://news.ycombinator.com/item?id=49060780> and <https://news.ycombinator.com/item?id=49060716> (from the grapheneos HN account directly).
I think for the case we're talking about here, though, it would be doable. This doesn't need to thwart deep forensic analysis. It just needs to survive a border agent thumbing through the contents of your phone for a bit. If the fake profile data looks plausible, and doesn't raise any flags, the agent gives the phone back and you're on your way.
Hell, I think a setup that doesn't wipe anything, but just drops you into a sanitized, isolated profile for the border agent to look at, would be fine for many users. Certainly you wouldn't want to use this in truly high-stakes situations where it's likely that your device will be confiscated no matter what, and analyzed to death, but for the simple "border agent wants to snoop on my data for a few seconds" case, it's likely sufficient.
(As always, risk analysis can be hard, humans are often bad at it, and not everyone's threat model is the same.)
Thanks for sharing - I get the concerns people have raised in those threads, however I still feel something in this space could be useful.
Even a duress PIN which triggers predefined deletion of certain folders, messages and apps could reduce law enforcement exposure significantly.
Deleting arbitrary directories, messages and app data would be highly unreliable. There's a high likelihood of the data being recovered. It's not how computer filesystems and storage are designed to work. Reliable deletion of data requires setting it up to be reliably deleted later on by having it encrypted on storage with keys which can be reliably prevented from ever being obtained again.
Wiping the overall data on the device via a factory reset, OS recovery mode or duress PIN/password prevents recovering any of the data because it reliably wipes material needed to derive key encryption keys and also reliably wipes the encrypted disk encryption keys. Wiping the encrypted disk encryption keys alone would not be good enough because they're stored on the SSD so imaging the SSD and restoring it could preserve the ability to recover the data. The way the key material needed to derive the key encryption keys is wiped prevents recovery via imaging the SSD mainly due to the secure element.
There's already support for reliably wiping data at the granularity of Private Spaces and secondary users. Those have their own encryption keys and can be reliably deleted due to having their own Weaver slots in the secure element and other hardware-based security integration.
Apps can also assorted generate encryption keys in the secure element and use those to encrypt data where it can be reliably deleted via wiping the hardware keystore keys. That requires apps built to have granular storage and encryption of their data.
Despite it being possible to wipe a secondary user or Private Space reliably, the past existence of it and when it was wiped will be easily discoverable via the main Owner user and system data. Preventing discovery of those profiles having existed requires an overall wipe of the data. It isn't feasible to hide it without doing that and hiding it would involve a whole bunch of unreliable removal of data without a way to prevent recovery along with redoing a bunch of statistics and other metadata to hide that there was another profile until recently. For example, things like the battery and data usage stats directly refer to the profiles. Even hiding it from naive analysis not looking at the leftover data on storage would still require changing a bunch of things to hide it.
Making data deletion of the data reliable for a whole profile or the whole data partition also requires a reboot or shutdown. Consider how much data gets loaded into the page cache and many other forms of data in the Linux kernel and other processes. Consider how much linger around in various kinds of registers, etc. including outside of the OS itself. Reboot or shutdown has code to get rid of this and the device sitting there turned off or booting again also gets rid of it.
They were clearly going to hook his phone up to forensics software on a laptop and had done what they needed to do in order to justify it for their own policies. It would not make sense to set up everything they did simply to have someone non-technical manually sift through his apps. They have widespread access to forensic software and also more advanced software with exploits. They definitely have easy access to it at a major Atlanta airport. The adversary in this case is not a non-technical human but rather advanced software from Cellebrite who are fully aware of alternative operating systems and document information on it. Their documentation directly refers to GrapheneOS and has tables listing their (currently very limited) capabilities against it.
This story got widespread news coverage and is widely known about. That should help make it clear how important it is for features to work against adversaries aware of these kinds of features. Our duress PIN/password works against adversaries aware of it. If they don't coerce a PIN/password from someone or don't enter a coerced PIN/password because they know it could be in use then the feature has worked. We want to improve the feature with secure element rate limiting integration in the future so that an OS exploit cannot be used to bypass it. The secure element already prevents an OS exploit from bypassing the limit of 20 total attempts for deriving encryption keys with massively increasing delays between those attempts. It used to solely be based on delays with throttling quickly reaching 1 attempt per day after 140 failed attempts but now there are only 20 total unique attempts. The past 5 failed unique attempts are temporarily remembered and discarded when entered again rather than trying to use them again for usability.
> Reliable deletion of data requires setting it up to be reliably deleted later on
I mean - yes? If you design a subtle duress pin that only hides certain things, users would have to choose what.
I myself want the bank apps, password manager and email to disappear without a trace, but I donât care about the social media, photos or web browser history. Other people, though, will have different priorities.
You misunderstood the parent post, it's extremely difficult to delete the data without leaving a trace that something was deleted.
To reliably delete a specific file or directory, it needs to be encrypted with a dedicated key which can be reliably deleted. It can have dedicated key material in the secure element used to derive sub-keys from the main encryption keys or it could simply be encrypted with another layer of encryption.
For the OS disk encryption, it uses separate randomly generated disk encryption keys for the main user, secondary users and Private Spaces which are different forms of profiles. Those keys are stored encrypted with key encryption keys derived from the per-profile lock method combined with various forms of key derivation material from elsewhere.
The most important of the key derivation material for profiles is the per-profile Weaver token on the secure element which it uses to enforce rate limiting for decryption attempts (max 20 attempts per profile with rapidly increasing delays) and to provide extremely reliable deletion of the data. Wiping the weaver slot for a profile prevents deriving the key encryption keys which prevents ever decrypting the randomly generated disk encryption keys again. The randomly generated disk encryption keys are only stored once and get wiped via a special SSD secure erase command but that isn't nearly as good as the secure element integration. If the SSD is imaged before a wipe and then restored, the data still isn't recoverable because the secure element wiped what's needed to decrypt the disk encryption keys.
Reliably deleting data is a much different thing from fully hiding that anything was deleted which is drastically more difficult and not compatible with how things are typically done. It's pretty much impossible to stealthily delete a secondary profile since there's too much system and Owner user data referencing them including the package manager's state, battery stats, data usage stats and far more. It's possible to attempt to go through all of that and hide it including forging the other stats to mask what was removed but data cannot be reliably deleted in a fine-grained way, especially on top of a modern copy-on-write or log structured filesystem combined with an SSD controller doing wear leveling.
An SSD controller will redirect writes to less written NAND than what is now being written to level out usage. That relies on it being aware of free storage to choose from that instead which is the purpose of TRIM. A modern SSD will also very proactively move around data rather than only redirecting writes to free space with less wear. It will identify the data that's rarely or never written and move it to the most written areas of the SSD to free up the space it was on for the most written data. Having 2TB of used space that's rarely ever touched, 1TB of a heavily written database and 1TB free will not only use the 2TB of active space for wear leveling with a modern SSD controller design. It will use the whole 4TB for it.
A modern copy-on-write or log structured filesystem doesn't write to the location where the data was originally but rather elsewhere. Android uses f2fs which is log structured which heavily helps with wear leveling at a higher level and also provides the ability to turn off data persistence temporarily and then roll back to the point it was turned back in an incredibly efficient way. Android uses that incredibly efficient rollback feature as part of A/B updates to preserve the ability to fully roll back an OS update which doesn't end up working properly until after it reaches the lockscreen successfully.
An app regularly appending data to a file, overwriting data in it or replacing the whole file is leaving data around all over the place. A decision can't simply be retroactively made to reliably delete the data for that file or the overall app. It would have had to be set up in a way that it can be reliably deleted. Without that, the whole secondary profile it's in is going to need to be deleted to reliably delete the data. If it's not in a secondary profile, the whole device needs to be wiped for it.
> I mean - yes? If you design a subtle duress pin that only hides certain things, users would have to choose what.
That's not what we were talking about. This is the full sentence we wrote:
"Reliable deletion of data requires setting it up to be reliably deleted later on by having it encrypted on storage with keys which can be reliably prevented from ever being obtained again."
What we're saying is that in order to have fine-grained deletion of data, it has to be encrypted with fine-grained keys with hardware support for deleting those keys reliably. Reliable deletion of data should also not be confused with stealthy deletion of data which is not generally possible for the kinds of data being discussed.
> I myself want the bank apps, password manager and email to disappear without a trace
You can put all of this into a Private Space or secondary user where it can be reliably deleted as a whole. There will be no way to recover any of the data if the profile is deleted. We have a planned feature for either a toggle to make the duress PIN/password only delete specific secondary profiles or more likely a 2nd duress PIN/password with that different purpose.
Deleting secondary profiles will reliably prevent recovering any of their data, at least after a reboot or shutdown. The best way to do it would be deleting them and then rebooting where the main user and secondary profiles not included in the deletion would still be there after the reboot. Without the reboot, it's unrealistic to reach the point where it's truly highly reliable. The OS does purge the keys for a secondary profile but a lot lingers around in system processes, page cache and elsewhere. If you delete a secondary profile with the goal of preventing data recovery then it's a good idea to reboot afterwards.
Dividing things up into secondary users is the way people can set up having fine-grained reliable deletion of the data. We can expand our duress PIN/password feature to support working with that.
It should be noted nothing about wiping secondary profiles is stealthy. It's very obvious there were profiles and that they were wiped. It can be determined when it happened and approximately how much data was deleted too. The data and filenames are unrecoverable but a fair bit of metadata on the sizes of files, etc. can be recoverable because that metadata is globally encrypted rather than per-profile encrypted. If you want to delete absolutely all traces of it in a reliable way, an overall wipe of the device does it extremely well. If you delete a profile then nothing encrypted by it can be recovered but what about all the evidence of it existing in the system and Owner user data? It's in the battery statistics, data usage statistics, package manager metadata and many other places. It can be purged from those but absence of data can be detected, and there's the usual problem of simply not being able to reliably delete data from computers in a fine-grained way. It's too late to reliably delete data from a file after the file has been regularly rewritten and modified.
Deletion needs to happen through deleting the keys used to encrypt all data which was ever stored in the file, so it would have had to be set up with that in advance. To reliably redact data in a file, the file would need a dedicated hardware-backed key with a new one being generated and the old one wiped as part of redacting data. Reliable wiping of a profile or the overall device works because it's all encrypted with filesystem-based full disk encryption using keys which can be reliably deleted. Profiles have fine-grained encryption for filenames and file data.
You cannot retroactively decide you want to reliably delete the data of a specific app and then do it. It's already spread all over the place. You'd need to wipe the whole profile or the whole device if it's not in a secondary profile. The OS would have had to set up a dedicated encryption key for that app's data with hardware support for deleting only that key by itself. Apps can do this and Signal is an example of app doing it which prevents backing it up via the OS backup system without also using their own backup system too.
Maybe it could cause the phone to "randomly" bootloop or something? "Oh no, my phone is broken again, last time this happened I needed to do a factory reset"
> I wonder whether it'd be better for a duress PIN to delete existing data
Reliably deleting data at the scale of the whole data partition, a secondary user or a Private Space is fully supported but requires a reboot or shutdown to truly complete it.
After wiping key derivation material needed to obtain the key encryption keys in multiple ways and wiping the encrypted disk encryption keys, the OS can still access the data. It still has data in the page cache, in registers and elsewhere. There are still a bunch of system processes with data tied to what was removed. The OS is still fully functional after the nearly instant wipe of everything needed to recover the data again. It can still access all data other than what's encrypted with hardware keystore keys and not currently decrypted.
The wiping process for the duress PIN/password is completed with a shutdown which tears down everything, zeroes memory and provides at least a small time window where the hardware is powered off too. A reboot would also work and the boot process has explicit zeroing of memory, registers, etc.
We decided to use shutdown for the duress PIN/pasword but a reboot is a valid approach too. Our locked device auto-reboot timer feature we first shipped in 2021 relies on the zeroing done by GrapheneOS for both the process of the OS tearing down and then again during booting to return the device to Before First Unlock state.
> also create a semi plausible artificial profile to hide the deletion event.
It isn't feasible to fool forensic software so it largely wouldn't work against state actors. It nearly certainly wouldn't have helped in this situation in the news. They aren't reliant on a non-technical person sifting through a phone. They'll just hook it up to a laptop and follow the data extraction procedure which involves enabling ADB. The software is aware of GrapheneOS can guide people through dealing with anything different about it. They've had a lot of trouble with extraction via ADB for GrapheneOS since the vulnerabilities they exploit via ADB keep getting patched or blocked it exploit protections but it isn't realistic to block extraction with them having the PIN/password. They could just enable the encrypted backup service in the OS instead and then use CLI tools to extract the data from there with the seed phrase. They don't do that because they want everything rather than only nearly all app data. They also have special code to deal with apps such as Signal with their own layer of data encryption since the data taken from their app data directory is nearly all useless by itself.
There's also quite a difference between wiping and rebooting into a not very plausible environment with decoy data set up by the user in advance compared to not properly wiping and giving access to a decoy profile. Bear in mind the OS can still access nearly all data after the wipe until a reboot. It could make a best effort attempt at purging as much as possible from memory, but the OS is not designed to continue functioning with all of the data disappearing. It can't just wipe all loaded encryption keys without crashing and rebooting anyway. It also has a ton of data still around in caches and elsewhere. We don't want to just do a best effort job cleaning up as much as we can but rather reliably prevent recovering any of the deleted data.
We could definitely add a duress PIN/password which wipes only specific secondary profiles, reboots and has the device still functional with whatever data was in the main user still there. That's a feature we can add, but it's important to note that it will not hide that there was deletion of data. It's easy to detect, and it's not feasible to hide that it happened. Many steps can be taken to make it less obvious, but it will still be easy for software aware of it to detect. Even a massive overhaul designed to perfect it would not address the SSD itself giving away what happened for more advanced analysis.
We aren't going to add a decoy profile compromising the security of the device and providing a way to recover data in a state where it isn't at all unrecoverable yet. We did already plan to consider a 2nd duress PIN/password which only wipes specific secondary profiles, but we need to make it clear that it cannot stealthily wipe them to users.
Just wanted to say I appreciate your comprehensive comments in this thread. Learned a lot.
Or put a dead man's switch on there
Interesting. So is this GrapheneOS indeed operationally good for keeping oneâs data private?
I mean, it sounds like it would be even better if the duress response was more subtle.
A duress code might let me wipe my phone when someone holds a gun to my head and demands I unlock it. Problem is, thereâs still someone holding a gun to my head.
He had an e-reader and phone. My solution would be set the phone's duress pin to the e-reader's actual pin then consent to the e-reader search providing its pin and see what happens.
The actual solution is cloud backup + re-image after the border.
Yes if you donât mind getting arrested by our fascist border police
I donât think that would fly as a defense in court.
Heâll just have to pray the scene wasnât recorded and his real PIN was one digit off
>I donât think that would fly as a defense in court
but that's not the point, the point is to not wind up in court by presenting a phone that no long contains evidence but seems plausibly like your phone so doesn't arouse suspicion
> by presenting a phone that no long contains evidence
Evidence Tampering
https://xkcd.com/1494/
Yeah if they can catch you and prove it.
Even if they canât prove it, they can make your life really miserable for quite a while.
If it was implemented in such a way, there would be no reason to suspect anyone of using it because it would be totally indistinguishable from not having used it. At that point they have no grounds for legal action. Unless they could monitor FS/disk activity, but that goes beyond typical airport security stuff.
I'm imagining a duress code that erases select files and any indication that there was ever a duress code set up in the first place.
As soon as that starts, authorities will charge people just for having GrapheneOS. There are 0 checks and balances right now, it's a free for all.
As things stand right now, software is 1-A protected speech. I'm not sure how long that will be the case with growing authoritarianism, specifically wrt to tech, on both sides of the aisle. I am concerned it may be considered probable cause though -- like how you can legally have an ax in the bed of your pickup but it's a free pass for a cop to search your vehicle if they're so inclined -- but really, they can manufacture probable cause for anyone if they want so it's kind of moot. You may be attracting unnecessary attention though if you've got "GrapheneOS" on your lock screen. But this goes back to my original point, they still have to catch you in the first place.
(1) Keep manufacturer's Android plus some plausible apps and data in a reserved part of the drive. (2) GrapheneOS runs from the other part of the drive. (3) Make sure PIN screen designed to not give away the OS. (4) When duress PIN is entered, erase GrapheneOS and restore manufacturer's Android. (5) Now you won't be charged for having GrapheneOS because they won't know you had it.
No, to my knowledge, they ask you to enter your PIN/password yourself. They don't enter it for you. I believe he entered it himself, at which point the erasure began. The erasure process was witnessed by the officer.
From https://arstechnica.com/gadgets/2026/07/activist-charged-wit...
> Tunick provided this code to an agent, who entered it on the phone, after which âthe screen went blank, flashed several times and the phone appeared to restart.â
Why American authorities are always attacking their citizens freedom?
i think it's just that the American population is the last bunch who gives a damn about it, and the pockets of resistance still makes the news... the same happens mostly everywhere else, just without much complaints.
e.g. in Hungary the authorities treat it as a felony to possess an equipment that can record video or sound and it's not obvious when looking at it. 2-8 years in prison for mere posession, i.e. even if it's turned off in your backpack. random nonsense that if it can also make phone calls then it doesn't qualify (the above is the law paraphrased).
Since there are zero devices that are released that donât indicate recording, it doesnât seem unreasonable to outlaw modification of recording equipment to hide recording.
You know, the same way we would be rightfully outraged if Apple was allowing applications to turn on the web cam without signaling to the user that the camera is engaged.
Thatâs all aside from the fact that Hungary was run by authoritarian minded people. But just as I think it should be illegal for cameras installed in glasses to work without an indicating light, I donât see how this recording light situation you are describing is really such a highlight of Orbanâs excesses.
right, it's just Hungary... in Germany you must ask for permission from the military to leave the country for more than 3 months.
It's not just America. It's many countries.
UK is same.
I know surveillance is on par in the UK, but is the UK also building and populating massive detention centers where people are kept without due process*? Are they flooding the streets of liberal cities with soldiers*? Killing citizens on the streets of liberal states (Minnesota) out in the open? Has nationalism completely overtaken the government and citizenship? Has the opposition party been completely neutered? Does your leader openly break any laws of their choosing while plundering national coffers?
*https://www.nbclosangeles.com/news/local/la-family-120-days-...
*https://www.militarytimes.com/news/your-military/2026/08/20/...
Not yet, but Elon Musk is doing his best to get similar types elected in UK.
This is a bit worse than that. They're specifically targeting this guy because they don't like his politics, an act that is unconstitutional, but Trump and his administration has had contempt for the constitution since day one.
Republicans might as well rename their party the Democratic Fascists of America at this point.
> Republicans might as well rename their party the Democratic Fascists of America at this point.
I'm reading Stefan Zweig right now, he was a prolific Jewish author from 1890s until his suicide in 1942, living as an exiled Jew from Austria in South America. He has written many words, over a century ago, that would support your claim.
Legal Eagle just covered this, it's quite interesting analysis: https://www.youtube.com/watch?v=_2rokxux5cU
Great link. The most relevant part for me is the last couple minutes (22:00): it's only against the law to destroy evidence if it can be established that such evidence exists. This feels like a more elaborate version of accidentally losing a stack of papers to a gust of wind just as you hand them over.
1. Was there a lawful entitlement to the papers? 2. Were the papers protected private property? 3. Were the papers released to the wind intentionally? 4. If intentionally released was it expected that they would disappear or simply fall to the ground?
A couple easy technological analogies: 3. "Sorry, I gave you the wrong code by mistake." 4. "I thought it would go to a private guest mode, not delete everything!"
The guy from Game Changer?
Yes. And Paul Refereeno will be the judge in this case
Not even a minute in. "Oh, he's protesting Cop City, got it. This is just police harassment."
I'm not a legal expert, but all this seems to check out with US law. Americans need to remember that some of their constitutional rights don't really apply at ports of entry by design. This inconvenient truth for the land of the free has existed for a long time, this situation is just drawing attention to it. Their powers are far-reaching.
Fun fact, there is a long standing exemption to the unreasonable search and seizure protection laws if you're out on a boat (it may only be on the open ocean and Great Lakes, though IANAL). One of the earliest Supreme Court rulings essentially said that without it, it would be impossible for the US to enforce tariffs, which were the main source of revenue at the time. Anybody who boats often enough has been boarded by the coast guard for various safety checks that allows them to poke around and there's little you can do about it.
Do NOT go to or transit via that shtihole of a country.
yikes
So the part of this that feels like it triggers the government issue here is that in effect you have a locally stored encryption key which gates access to the device, which was removed from the device due to duress password.
What if we flipped this to instead be something that's explicitly not on the device?
The border search stuff only applies to information on the device. It cannot compel you to provide access to e.g. emails stored in a cloud provider.
If instead of making the process of stopping searches like this be a destructive one, we instead pre-purge the key but store it offsite with the ability to get it from an online location, then this feels like it's probably reasonable here. In the sense that the 4th amendment explicitly allows "The right of the people to be secure in their persons, houses, papers, and effects, ..."
There's probably some sort of technical problem I'm missing here (or maybe this functionality is available already).
Yeah, so caveat emptor: the legal system isn't something you can hack like a computer...
But...
The issue at hand is the "locality" of the encryption header. He merely facilitated its deletion, not the data.
If he had a backup at home, is that still a felony?
What about if he had a backup on a flash drive with him?
What if he never had the header on the phone to begin with and used a detached header on a flash drive?
Are detached headers (a thing you can easily do with LUKS) now de-facto illegal?
This whole thing is making me feel rather uneasy about the bigger picture.
See https://www.cbp.gov/document/directives/cbp-directive-no-334...
> The border search will include an examination of only the information that is resident upon the device and accessible through the device's operating system or through other software, tools, or applications. Officers may not intentionally use the device to access information that is solely stored remotely. To avoid retrieving or accessing information stored remotely and not otherwise present on the device, officers will either request that the traveler disable connectivity to any network ( e.g., by placing the device in airplane mode and disabling Bluetooth and Wi-Fi connections) or where warranted by national security, law enforcement, officer safety, or other operational considerations, officers will themselves disable network connectivity. Officers should also take care to ensure, throughout the course of a border search, that they do not take actions that would make any changes to the contents of the device.
and
> Passcodes or other means of access obtained during a border inspection will only be utilized to facilitate the inspection of devices and information subject to border search. Passcodes or other means of access may not be utilized to access information that is only stored remotely. Passcodes or other means of access should only be recorded by the officer in a temporary format and should not be uploaded into CBP systems. Passcodes or other means of access recorded by the officer will be deleted or destroyed when no longer needed to facilitate the search of a given device.
I'm not sure what you're trying to say
The existence of a key only being somewhere other than your current location during a border search enables you to legally say "I cannot unlock this device" and move on with your day.
Well even today this guy could have just said 'I will not unlock this device' and they can seize it for some time, but they can't deny you entry. Which is pretty much the same scenario you created except the guy literally can't unlock it (but that doesn't actually matter here, he never _had_ to unlock it).
> or maybe this functionality is available already
Basically already exists depending on specific trade offs and risk profile.
You already can encrypt your data and store the encryption key offsite. But then you couldnât use your phone during travel, if you toss the key locally.
You can encrypt the data at rest and leave the decryption key in RAM and just turn off your phone. But they can still take the phone and copy the encrypted data, if they think theyâll get the key later.
My understanding is that this individual would t want the government to access the encrypted data either.
I'm talking specifically about the graphene OS ability for that approach, not the ability to add an external key to some generalized encryption. The threat model here is that the traveler was required to provide a passcode unlocking a key they had with them on their phone. If that threat is not there, then this bypasses problem.
I don't get the legal contradiction.
The search is supposed to be lawful without a warrant because you're not really in the US yet per-se, hence if you're not there, how deleting the data can be a felony?
I think you legally are in the US while at an American border crossing - at least if the crossing is on US land, which it was in this case. It might be more complicated for preclearance spots. It's just that normal rights are suspended there despite being in the US, even for citizens. Make of that what you will.
Your rights are not suspended, but border agents donât need a reason to investigate you
...and then they start violating all your rights after starting the investigation lol. its just wordplay.
The Constitution makes no exemption for a suspension of rights at the border.
The Supreme court disagrees with you.
The supreme court is made of fallible humans
The Supreme Court often disagrees with itself.
The alleged crime is knowingly interfering with a lawful search (by providing a duress password that deleted the phone). Location has nothing to do with it.
The location is the crux of the "lawful" part of the search.
That is a most interesting and underrated point.
It's a fairly shallow point that ignores how laws work.
The premise that the law doesn't apply because you're not in the country is false. The constitution applies generally everywhere to all Americans, it's just that what's regarded as reasonable differs during a border search. IANAL, so just my lay opinion on this. Just to validate this, it's only because the constitution exists that the border authorities have any legal basis in doing inspections.
Huh, that is inconsistent. The problem with your comment is noted right here: https://news.ycombinator.com/item?id=49390318
Not really - the government have stated that he's in the US. It's the first sentence of the indictment. [1]
> On or about January 24, 2025, in the Northern District of Georgia...
[1]: https://storage.courtlistener.com/recap/gov.uscourts.gand.35...
But in general, the thing to note here is that the 4th amendment is always applicable and in force. It's how it's interpreted that changes depending on the circumstance.
It doesnât matter where he was when he deleted the data. He could be in China, itâs still a crime in the us to destroy evidence wanted by American authorities.
You're speaking nonsense since there was no charge or warrant against him. People are free to use their phone for f sake.
Law enforcement doesnât need a warrant to search phones at the border. I agree this is a terrible rule but it is the rule right now.
Is that the 100 mile wide border?
You have lost track of the chain of discussion.
right, there's a contradiction here:
- if you're deemed to be on US soil, constitutional protections (4A) apply; can't be destroying "evidence" unless you're accused of a crime or found to have committed a crime
- if you're deemed _not_ yet on US soil, then how can you be charged with a crime under _US_ law?
The US views that US law applies worldwide. There is no requirement that you be anywhere near the US to be under US jurisdiction for an alleged offense against the US, according to the US.
Also, that constitutional protections are suspended within 100 miles of a land, sea, or air border.
where's that in the Constitution?
Not sure why you're getting downvoted, since your statement is true:
https://www.congress.gov/crs-product/RS22497
Although obviously not all US laws apply and enforcement is a whole other kettle of fish.
4A still doesn't permit you to destroy the evidence. Resist on 4A grounds, destroy the evidence, 4A reasons get overturned - you've got yourself a conviction. US v. Akram Musleh.
in practice you're right, but it's hard to see how that squares with the 4A.
an officer can't stop me on the street and demand to see the contents of my phone -- unless they can show "probable cause" that I was about to commit a crime (based on other evidence), or I'm already named as a suspect or POI in an investigation. So if they ask to see the contents of my phone and I delete it instead (it's a very small bag in this example, Lol) am I obstructing an investigation?
It's like those notices "by clicking accept below you agree to giving up your data", by purchasing a ticket to visit US all your data are belong to the US.
How did it end up, because itâs not a new thing to happen. First time I read about this guyâs border crossing case was few months ago and was of course very much highlighted for the level of surveillance govs can do.. but I also read some Time later that by the letter of law he was not proven wrongdoing.
Are we still discussing a border crossing case that is long historic or there is still an active drama for this guy going on?
Would he have been better off just refusing to give a code?
Yes. They'd probably have kept the device for a while, but he wouldn't be in legal trouble.
https://archive.is/SflVC
Seems like it would be better to have a truecrypt type of situation, where if you put in a certain pin, then it just logs you into a separate OS with nothing you want to hide.
Obviously have the duress pin if whatâs in your phone is worse than the obstruction charges too.
<https://news.ycombinator.com/item?id=49389273>
In the truecrypt scenario youâd be using the hidden and encrypted volume only for what you explicitly want to keep hidden and use the other one for your daily life.
So in the article situation, the guy is a protestor and presumably suspects heâs going to be targeted by the police for it. Heâd keep that stuff isolated from his usual activity. Thereâd be no need to generate convincing fake activity.
Certainly more of a hassle than having a PIN that can destroy everything.
Amendment 4:
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."
Amendment 5:
"..nor shall be compelled in any criminal case to be a witness against himself, nor be deprived of life, liberty, or property, without due process of law; nor shall private property be taken for public use, without just compensation."
But the bar for hauling someone to court and defacto punishing them financially and smearing them in the eyes of the public is so low. And the path to getting compensation for wrongful prosecution so fraught. What an easy tool the justice system is to punish uppity citizens thinking they don't have a king.
You think they'll see a courtroom? Ha! If they're lucky they'll get there in 5yr and $15k.
When the administrative enforcement bureaucracies want to harass you they'll hit you with some ruinously expensive civil fine BS. No court will give a crap about you until you've exhausted a bunch of appeals, which you of course appeal to the same agency that's trying to screw you. Only after years of that (and invariably legal fees, because you can't go it alone), do you sue them and get to see a real courtroom. But even then, this is a civil matter, not a criminal one, so all your rights have been nerf'd and there's a hundred years of precedent and case law that tilt things in their favor. If you get lucky, they'll settle and you'll only be out a few tens of thousands for the ordeal.
>Amendment 4:
He was charged for destroying evidence, not refusing a search
>Amendment 5:
Destroying evidence isn't testimony. Moreover he would have been in the clear if he just kept his mouth shut.
> He was charged for destroying evidence, not refusing a search
Evidence with regard to which investigation?
Border agents are entitled to investigate anything for any reason more or less
But did they? Was there an actual investigation going on?
If you are a US citizen, they are not entitled to your unlocked phone. They need a judicial warrant if they want you to unlock your phone with a PIN/password. It is settled case law that that falls under your protections under the 14th Amendment.
They can take it for a "reasonable amount of time" (inconvenience you for a few hours and make you miss your connecting flight) while they copy an encrypted image. They then must return it to you.
It seems like the best course of action would be to argue he did not destroy evidence, just made it unavailable at the location to force the requirement for a search warrant. It would probably be a hard sell, but I can't think of a better argument (not a lawyer).
Problem is, he didn't destroy shit. "He" (by which I mean, technically the agents) deleted a header that's used to encrypt data but can restored from a backup.
This is why we have judges, I wonder if this has been ruled on already. If you filled out a notebook in a special cipher with the cipher stored separately beside it, then when a cop asked for the notebook you handed the cipher over and then burned the cipher right in front of them, is that destruction of evidence? Idk at the end of the day it does have the same result as destroying the data.
>"He" (by which I mean, technically the agents)
Under the same logic you could mail a bomb to anyone and say you didn't kill anyone, they did. It was just rigged to blow when they opened the box.
Deleting isnât destroying?
Sure, but the issue is he didn't delete his data, he deleted a header with a key in it, that's it, just a few MB. He didn't delete hundreds of GB of chats or browsing history, he deleted a key to access it and that key isn't necessarily the only one that can access it. All the stuff they want can still be accessed just fine if another copy of the key exists.
To put it in protective, just opening a web browser or some other app can delete/alter more data than was deleted in this case.
Thatâs semantics. For all intents and purposes he destroyed it, no different than if he stomped on the phone or deleted all the files traditionally.
I donât think a judge would care about splitting that hair.
> Moreover he would have been in the clear if he just kept his mouth shut.
Although then you get a possible delay of undefined duration, additional questioning and seizure of your device.
Evidence of what? Destroying evidence assumes he is guilty of a crime which there be evidence of. Our system is predicated on an assumption of innocence. The normal threshold to accuse is a "reasonable, articulable suspicion." This does not meet that criteria.
Well that's the thing with destroying evidence. If you destroyed it, it becomes harder (or impossible) to prove you did the crime. That's why it's not uncommon for people to be only charged with stuff like "obstruction of justice" rather than the actual crime they allegedly did.
But you can't assume someone committed a crime.
In this case, the authorities are claiming they were looking for CSAM. So wiping the phone hindered a valid investigation.
They can say anything they want. They hold all the power. This will never change until enough people take matters into their own hands, as the system has been compromised.
They think a well known protester who was savvy enough to wipe their phone was crossing the border with CSAM on their phone? Do people buy this shit?
And what if he was erasing a steamy affair with a border patrol agent? That's not illegal, but releasing knowledge of it could be damaging to all parties for no reason.
if the only evidence of a crime is on your phone, what kind of crime is it?
we should always be asking: is this the only way you can prove the accusation? just because it would make LEO life easier - that's not justification for violating the constitution.
an consider what this case teaches us: clean up your devices before you cross a border. how does that even help the goal of law enforcement?
> Our system is predicated on an assumption of innocence.
In theory. In practice, this is a hopelessly outdated supposition.
"Evidence" of what, exactly? What specific crime did they expect to find evidence of on his phone?
They were pretty obviously hoping to find a specific crime to accuse him of (because he is a protester against the Atlanta "Cop City" thing).
But no respectable judge would ever have issued a search warrant on the basis of "we want to rifle through his messages/contacts so we can hopefully accuse him of something".
Protesters against this exact same thing were mis-prosecuted under "domestic terrorism" and "racketeering" charges before (got dismissed in 2025).
The original text is basically useless. They're more like a mission statement rather than directives. They set up broad aspirations, but the implementation has to be aggregated over literally millions of pages of judicial decisions.
Even lawyers with extremely different ideologies will give you convergent answers in a lot of cases, even when those answers conflict with an apparently obvious reading of the original text. Explaining that would require drilling down into details of thousands of court cases -- like reading a complex proof of a seemingly simple theorem.
I don't like that any more than you do. It's not mathematics, and even when given all the details, I usually find their inferences laughably bad -- even when I agree with the conclusion. It's not "logic" as I apply it as a logician, philosopher, or software developer. Lawyers (people on my side ideologically) will insist on the soundness of reasoning for decisions that they don't like but accept as valid.
So I don't find quoting the Constitution to be of any utility. None of those words what you think they mean. And fixing that requires basically throwing out the entire system of American jurisprudence. Which would be fine with me, to be honest.
> None of those words what you think they mean.
And that alone is already a pretty scandalous problem. If the law is not stated in a way that ordinary people can understand, how the hell are they supposed to obey it? Those who cannot afford the highly paid law explainers are basically locked out of society.
I don't think you're entirely wrong, but the Constitution binds the government, not citizens. The government can damn well afford to know what the 4th and 5th Amendments mean.
The words are actually extremely clear and its exceptionally prudent to quote them, because nobody with a brain can read them and fail see that the government is simply being unconstitutional - all over the place. Even when the people are powerless, we dont have to give up our powers of seeing the truth. Your post and this whole idea that "the words dont mean what they say they mean" is frankly doublespeak of the lowest form.
[delayed]
> we dont have to give up our powers of seeing the truth
The truth is that the constitution is interpreted by humans in a common law context, and enforced by the apparatus of state, which has the means to impose its will. Calling this doublespeak is weird.
When its "interpreted" in a way that directly contradicts the words themselves then its not an interpretation, its a smokescreen to try and cover up the fact people in power dont want to follow the constitution and are not planning on doing so.
> None of those words what you think they mean. And fixing that requires basically throwing out the entire system of American jurisprudence. Which would be fine with me, to be honest.
The Constitution is written in plain English. And for the most part, Supreme Court decisions are written in plain English that any reasonably literate US citizen can understand. Yes, the law has technicalities and terms of art just like any other profession.
But one of the most damaging mentalities in modern times is the idea that the common man is incapable of understanding the law at even a basic level. This is flat-out not the case. Which leads to the follow-on problem: people who think lawyers have the ability to cast magic mumbo-jumbo spells that "get their clients off on a technicality" somehow. The best quote I ever heard about that from an attorney was "any time someone says a person 'got off on a technicality,' you can pretty much just safely replace that in your head with 'had their constitutional rights egregiously violated.'"
Yes, there are problems. Qualified immunity is a problem. Prosecutorial misconduct can be a problem. Abuse of discretion at the border is a problem. But that's different from doomerism about the entire justice system to the degree Very Online people express it.
I'm just guessing here, but the most problematic word on the 4th amendment to attack from the government's perspective is "unreasonable". It's easy to see how a phone border search could be construed as reasonable, and (without digging into this deeply) I suspect that's where most of the push back on this will be.
I suspect the 5th amendment is probably more valuable to the defense here as the password is effectively testimonial and the give us your password or we'll ... is compelled speech.
Either way, it's gonna be many 10s of thousands of dollars in lawyers fees to fight this. Which sucks.
> It's easy to see how a phone border search could be construed as reasonable
I'm curious, is there any case law from the pre digital age regarding people forced to open their briefcase and let the border guard read all their documents at a port of entry?
you don't have those protections at the border: https://en.wikipedia.org/wiki/Border_search_exception
There is no such exception allowed in the Constitution. And if a case is made that they're not legally in the US yet, then by the same logic, they should not be subject to all the same laws of the US yet.
The Supreme Court has long recognized a border-search exception to the Fourth Amendmentâs warrant requirement. In United States v. Flores-Montano, the Court looked to the nationâs sovereign âinterest in protecting . . . its territorial integrityâ to justify such searches.3 In United States v. Montoya de Hernandez, the Court stated, somewhat more narrowly, that Congress is the source of the executiveâs power. It explained that â[s]ince the founding of our Republic . . . [Congress has] granted the Executive plenary authority to conduct routine searches and seizures at the border, without probable cause or a warrant.â The Commerce Clause permits Congress to authorize the seizure of goods at the border.
https://yalelawjournal.org/forum/customs-immigration-and-rig...
> While the Supreme Court has long recognized a border-search exception to the Fourth Amendmentâs warrant requirement, it applies to only two interests: promoting the duty regime and preventing contraband from entering the country; and ensuring that individuals are legally admitted.
The only reasons allowed for border searches are ensuring that individuals are legally admitted (inapplicable here because citizens are always legally entitled to enter) and preventing contraband from entering.
A wiped phone can't contain contraband, so wiping the phone serves the same purpose as a search. It's not destroying evidence anymore than throwing away a water bottle before going through TSA is destroying evidence.
I see a vast gulf between searching a truck of produce driven by a non-citizen vs intercepting a citizen at the boarder with known affiliations with the opposing political party.
And it's impossible to ignore that context. This is plainly wrong. And people trying to justify this plainly fascist search is sickening.
Even Wikipedia spells out that invasive searches require "reasonable suspicion." So we return to the core question... suspicion of what? Suspicion is not a crime. https://en.wikipedia.org/wiki/Border_search_exception
"The government is allowed to use scanning devices and to search personal electronics. Invasive bodily searches, however, require reasonable suspicion." is what the article says
He's lucky they didn't ship him right off to the Dilley Detention Center
Obstruction to what? Also thought this would be covered by the fourth and fifth amendment.
Goes to show that he should have made an LLM do it instead.
What about none citizens? Customs kicks you out or throws you into a camp first.
E: but seriously, what happens to non citizens. What happens if you bring a burner/wiped phone? I assume digit forensics can confirm it was pre wiped but what's topping them from alleged you wiped on US soil.
That famous phrase from the constitution, "all men are created equal, except the ones not born in America"
The original you're riffing on is from the Declaration of Independence (a purely rhetorical document), not the Constitution of a decade later.
The constitution says it is written to "secure the Blessings of Liberty to ourselves and our Posterity", actually.
The implicit "men born outside the US are not men" is arguable worse.
So non-citizens should avoid visiting US. Got it
I don't know about you, but don't people use encryption to retain privacy? And are people still free to manage their personal information? Doesn't a duress PIN present that information in its intended form? I'm confused.
What I don't understand is if he just didn't give any password, he would have been fine. It's only because he gave him a duress pin that he's in trouble.
So, in both cases the government wouldn't have access to the contents of the phone
In the first case they (the US govmnt) could hold him (the citizen) in contempt (in a cell) indefinitely.
18 months is, by precedent, the limit on contempt for refusal to decrypt[0], but this administration is happy to disregard any precedent that does not agree with them.
[0] https://arstechnica.com/tech-policy/2020/02/man-who-refused-...
Actually no, they are required to allow you to enter the country, but they will make it a hassle, to the point of dehydrating you and/or refusing bathroom access, and confiscate the device in the end and access is through other technical means.
Is that allowed? Can you refuse to give a pin when asked?
It's complicated.
> Courts have generally found that compelling individuals to provide their numeric or alphanumeric passcode is potentially testimonial under the Fifth Amendment, as it forces the defendant to reveal âthe contents of his own mind.â In Re Grand Jury Subpoena Duces Tecum 670 F.3d at 1345; see also U.S. v. Apple MacPro Computer, 851 F.3d 238 (3d Cir. 2017). It is analogous to compelling production of the combination to a wall safe, which is testimonial, as opposed to surrendering the key to a strongbox, which is not. See Doe v. U.S., 487 U.S. 201, 220 (1988). However, even if a court finds that providing the passcode is âtestimonial,â it may still fall under the âforegone conclusionâ exception
https://www.nacdl.org/Content/Compelled-Decryption-Primer
In short, you can't be compelled to give up the code in a dragnet attempt to find evidence against you (e.g. a boarder guard can't riffle through your text messages to see if you might have done something illegal), but if it's already certain that particular evidence exists on the device as a result of other evidence, they may be able to compel you to give up your passcode.
Note though that the cases where this has come up are very few and far between, and there isn't a super clear overriding precedent to follow.
In general though, the best choice here is to say nothing at all and work with a lawyer to figure out how to proceed.
https://www.aclu.org/news/privacy-technology/can-border-agen...
What about everyone does this at the border. Then what is normalized is deleting your encryption key while entering, they wonât prosecute everyone on their baseless prosecutions. Join in I say, there is no law being broken only scare tactics being applied to prevent this kind of thing. Normalize the act not the consequences.
While I think it's an abuse of power from a moral point of view - yes, that would be the expected legal outcome. Under any administration.
You can refuse to hand over access. You can't go torch evidence. Caught Ollie North as well.
Anyone that is surprised by this or somehow thinks this is new clearly hasn't crossed the border a whole lot. I grew up in a city along the US/Canada border. You don't fuck around with US Customs (or Canadian) agents. My cousin (not always so friendly) pissed off a US Customs agent (in the 90s mind you) and they promptly took his car and disassembled much of it looking for non-existent drugs. When they put it back together it was never the same. Their job is to be suspicious, 99.999% of the time people are completely innocent. But let 1 bad person through and it's Customs' fault for whatever bad thing they do. Not an easy job. Not an excuse for how they can misbehave either.
Is it right? It makes no difference, Customs can make your life miserable, that's just the reality of it, always has been and it can't have gotten better in recent times.
Well hopefully thereâs a jury so this nonsense can get nullified
So we're presumed guilty until proven otherwise (the presumption is, any data we delete must be illegal; couldn't possibly be nude selfies that the government has no right to see)
The land of the free!
Would it be permissible to wipe your phone before going through customs to get back into the US? If they ask to search your already wiped phone, you arenât destroying any evidence.
There are apparently problems with wipe/restore under GrapheneOS:
<https://news.ycombinator.com/item?id=49060780>
(From the HN GrapheneOS account about a month ago.)
It has an encrypted backup/restore system.
We were talking about an attacker taking an image of the SSD prior to it being wiped not helping them because information needed to derive the key encryption keys is gone from the secure element. It similarly doesn't help them to do a brute force on a server farm since they're rate limited by the secure element. It only allows 20 attempts and has rapidly increasing delays between those. There's also hardware bound key derivation but that only helps improve the strength of a decent password. The secure element rate limiting makes even a random 6 digit PIN highly insecure unless an attacker can exploit the secure element.
That link says you can't take a image of the disk prior to wiping.
OP is talking about just backing up what you need off-phone and then wiping it.
What problems are you referring to?
Yes. Of course it is permissible. It is your device. The wipe must have completed before arriving at the counter.
I wouldn't assume that to be the case. It's illegal under federal law to destroy evidence of a crime. Just what the government needs to do to show that you've destroyed evidence of a crime and not just the sexting you did with your girlfriend is a pretty murky area of law, from what I can tell.
I would not present a phone to customs that had clearly just been wiped.
You're speaking nonsense since there was no charge or warrant against him. There was no crime that was committed. People are free to use their phone for f sake. People who reason as poorly as you will lead to all remaining rights being lost.
The way he wiped it is legal for the same reason. It was an illegal search and he was under no obligation to preserve the data on his phone.
It's legal to refuse to provide a PIN/password in the US. He's a US citizen so they couldn't refuse him entry. If he wasn't then the result would be getting deported.
It likely would have been a much better decision to refuse to provide the PIN/password and rely on the encryption and device security instead. He could have done a reboot or shutdown in advance but even without that it would have done it automatically via the locked device auto-reboot timer. The secure element only allows 20 attempts for key derivation with rapidly growing delays between those. If he had a strong passphrase then even a secure element exploit wouldn't obtain the data protected by it.
Ah, I see where you've gone wrong. You're expecting to apply common sense and reason to the law.
That kind of thinking has landed a whole lot of people in prison.
amatuer... when you leave the us you bring a wiped phone, never bring your primary phone/laptop/camera/etc
Paywalled, but what is the actual charge? Is it some extremely generic "obstructing an investigation" one? The US is quite good about making court documents available on line, if someone can find it.
The article says he was charged with obstruction.
You can try this "gift link" to the article: https://www.nytimes.com/2026/08/21/us/politics/samuel-tunick...
He is charged with obstruction, but under domestic terrorism (as defined by a national security presidential memorandum).
But republicans assured me that they wouldn't ever start throwing around domestic terrorism at democrats!
The gift link shows only a fraction of the article text. Just stick to https://archive.is/SflVC.
Obstruction to what though?
Injustice ;)
Illegitimate abuse of border control power to restrict freedom of speech.
Knowingly providing a PIN that would erase evidence is going to get tough in court.
But the man was also hated by the cops because of his activism. They were going to catch him for something, some day. This incident just provided the necessary excuse to lock him up.
There is no duty to keep a copy of messages and private data on your phone for the FBI to peruse at its leisure. Quite the opposite, actually (according to the constitution).
It is pretty clear to me that law enforcement conspired to abuse a border crossing to effect basically an unconstitutional search ("fishing expedition"), which it would never have gotten a warrant for.
This is them being spiteful after that whole thing failed. Note how law enforcement basically admits this on the record. The whole thing is a disgrace; every decisionmaker involved in this should be sacked immediately.
Evidence of what?
Whatever they claimed they needed access for his phone to. Probably nothing serious that would be worth more than a fine, if anything. But now they've got him for deleting evidence, which is pretty bad.
There is no "evidence"; by any reasonable interpretation of that word there would have to be an actual accusation of crime for there to be evidence of one. This was a search predicated on literally no actual basis apart from "we have the right to search your device because we have ultimate power at border passings", essentially just a fishing expedition.
This also doesn't even get to the more important point: If you don't have the contents of the phone you have literally no evidence of a crime being committed, other than the one they invented post-facto: "Deleting data that could hypothetically be incriminating, not in any specific way but just generally, maybe".
> if anything
Thatâs the crux of the matter, isnât it? If there was no suspicion whatsoever, hence no investigation, then he couldnât possibly obstruct it.
How can they prove that? What if it was a glitch?
That shouldn't be too hard. Get someone from Google or someone with any tech knowledge to explain to the judge how phones normally work, what encryption keys are, the implications of wiping an encryption key, and then get someone to show the difference between entering a normal PIN wrong several times and entering the duress PIN. You just need to convince the jury (or judge, if there is no jury for whatever reason).
People have gone to jail or have been executed for less than a glitch. Theoretically a highly charged particle from space could've messed with exactly the right transistors exactly when entering the correct PIN and trigger the wipe process. There is no way to prove that didn't happen. But you don't need that kind of proof.
Right, the halting problem means one can hardly prove anything at all when it comes to software.
Sure buddy. And the uncertainty principle means you can't prove I was at the scene of the crime.
The fact phones don't usually wipe themselves will be plenty good for a judge.
Btw: Regardless of the above I support this guy's right to protect his private data from baseless and unreasonable searches. He should not be charged with a crime.
No, it means there is no general solution to the problem of proving software correct. You can prove if a specific program will halt or not given certain parameters. You cannot write an algorithm that will work to prove if any arbitrary program will halt.
> They were going to catch him for something, some day. This incident just provided the necessary excuse to lock him up
funny reading this (don't disagree) and then also reading on HN how China is "bad" this is some gestapo shit but not surprising that it is getting normalised ...
China is strictly worse than the USA when it comes to border controls. That doesn't mean the USA is good or acceptable in any way; these laws are part of the reason why I don't plan on visiting the country. The USA also has much worse laws on the books, like having to give the authorities your social media passwords to check if you're secretly a terrorist (though that doesn't apply to citizens).
Excessive border patrol power has been around in the USA for ages now, it's all part of the post-9/11 package. I don't think many Americans even know they live in a zone where the border police can do shit like this, even if they haven't left the country, as international airports are usually near big cities, and they have a wide border zone around them. This stuff only really makes it into the news when it happens to one of the "good guys".
FWIW the 100 mile airport border zone thing has been debunked, as the 100 mile zone by statute applies only to land and maritime borders. https://www.aclu.org/know-your-rights/border-zone
China is indeed "bad" for the gestapo shit. The difference is that China's gestapo shit comes with benefits for the common man too, whereas in the US the gestapo shit only serves the inner circle at the top of the regime with zero benefits to 99% of the populace.
Kindly list here the most important 3 benefits "for the common man" that accompany "China's Gestapo shit".
The right to work 996, obviously!
Here's a gift link: https://www.nytimes.com/2026/08/21/us/politics/samuel-tunick...
Paywall/archive: <https://news.ycombinator.com/item?id=49387289>
One more reason to not go to the US
I don't agree with all this and this increasingly fascist regime but... this was the most predictable outcome. Consider these two scenarios.
1. You factory reset your phone before entering the US and give it to CBP blank. There's nothing to find;
2. You have a self-destruct PIN like this guy did and give it CBP so it destroys the phone's contents.
Tech people will say that these two things are functionally the same. This is a fundamental misunderstanding of how the law works. If you factory reset your phone first with the intention of restoring it after entry, that's completely fine (legally). You could've factory reset that for any reason. But as soon as an officer wants to search your phone, now you're engaging in evidence destruction (spoliation). The destruction to the phone's contents was done in response to an unfortunately lawful search.
Even if you don't want to factory reset your phone, you can probably just delete (or even log out) of key apps. They can still get messages but if you're so concerned about that, use WhatsApp or whatever.
None of this should be necessary but we are where we are. But whatever you do, don't use a self-destruct PIN if you don't want to be charged with a felon and likely to be found guilty.
A court has not yet determined whether the use of the duress PIN/password was legal. There's definitely no consensus among legal experts of it being illegal as you're portraying it. The US has strong legal protections against self-incrimination and unreasonable searches despite erosion of how much people's rights are respected.
A factory reset done in anticipation of a search is not as different from using a duress feature as you believe it is. Forensics software would have clearly identified the device was recently factory reset. It would provide another defense argument by arguing it was wiped for another reason, but whether that would be believed by a court is unknown. It would make a difference if there was a good argument about why it was done, but it isn't necessary for this to have been done instead for wiping the device to have been legal.
Once he was in the situation already, the best move was very likely refusing to provide the PIN/password indefinitely and only talking to them to demand access to lawyer. There are strong protections against data extraction and it's highly unlikely they would have been able to get the data from it. Refusing to provide a PIN/password is protected under the 5th amendment in the US and these rights do exist at the border. They can turn away a non-citizen but they can't refuse entry to an American citizen because they won't provide a PIN/password. They could waste a lot of his time but he'd get access to a lawyer and would get released. They could make a court case over demanding the PIN/password and they'd nearly certainly lose. He'd likely spend months or even years without getting back his phone of course.
If they had a video recording of him entering the PIN/password from somewhere, they could have used that to get the data. By using the duress PIN/password, he prevented it. It was probably not necessary to keep the data safe, but that's unknown.
With only a tiny bit of preparation time, rebooting or powering off the device would have gotten it into Before First Unlock state without the locked device auto-reboot timer needing to complete. In Before First Unlock state, a decent random 6 digit PIN is enough for the data stored protected with it to be highly secure without an extremely sophisticated secure element exploit. If the device had a strong passphrase, then no level of sophisticated exploits would recover that data.
Yet another case that will waste the court's time and money. All this is doing is keeping defense lawyers pocket's lined.
At this point, people should buy a burner phone when going to/from the US. In that phone only have a couple of phone numbers and that's it.
Oh, they may well give you bad time if your phone looks like a burner with too little content.
> Oh, they may well give you bad time if your phone looks like a burner with too little content.
Issuing 'burner phones' and laptops to staff visiting countries such as China or the USA is now SOP for many companies handling sensitive data, including mine.
Don't think this isn't unusual.
Exactly, these people making shit up about border crossings are either doing so in bad faith or havenât done a lot of international business travel.
This is not... advice. But if anyone's actually going to do this, the method that's worked for me...
A couple weeks before your trip, factory reset whatever burner phone you're planning on using and swap your SIM card over. Install a few basic apps you wouldn't mind them looking through. Enable hotspot/tethering, and connect your other phone via Wi-Fi.
For a couple of weeks, use the burner as much as you can with what is available on it. When you're driving, us the maps app for GPS. Make and receive some calls, ignore some spam calls. Read the news. Get a few inane text messages conversations going, etc.
When you travel, leave your regular phone at home and take the burner. When it's searched at the border, it has enough activity to pass most initial smell tests. If asked, you dropped your other phone and didn't have time to get it fixed before your trip, this is one a friend lent you.
This has worked for me. Never _actually_ into anything illegal, but just apparently had a suspicious vibe about me or something because every time I crossed the border into or out of the country I was spending 4-5 hours getting searched. Didn't need someone going through my entire life going back decades every time--once was enough.
If you are a citizen it doesnât matter. They have to let you in.
According to this admin due process is only for citizens, and since weâve claimed you arenât a citizen you have no due process to prove otherwise.
So what, donât do anything to protect yourself because thereâs no hope? Give up?
Believe it or not, due process still generally exists and most people still benefit from taking precautions to protect themselves. Thatâs not to imply that things are great or that we arenât in a time of declining civil liberties.
Seriously, there is something wrong with privacy doomers.
Wouldnât be the first time the US government grossly abused its own citizens and violated their rights
And yet this distant possibility doesnât seem to happen very often to citizens, as long as we still have courts. Not that actual abuses should be trivialized.
This comes across as fearmongering to keep people from protecting themselves.
If you are a citizen like this person is then you can tell them to fuck off, they can keep the phone, and they have to let you in.
They have to let you in. Doesn't mean they have to let you roam the country freely. They can just send you to some form of detention.
They can hold you for a few hours while they investigate, but they can't just arbitrarily detain you without a legal basis.
That isnât true. They can detain you briefly for questioning at the border, but if there is no crime then you will be released. Feel free to dig into historical court cases about border detention if you disagree.
If you get charged with a crime, things are very different.
Nope, no disagreement. I just see your take as very optimistic.
There is no court at the border. If the agent decides you're going to jail, you're going to jail. The decision may be reversed/corrected after, but it's still going to be a big, expensive problem for you and you _are_ going to be detained for a time.
Not to mention walking up with an empty phone and telling the agent to "fuck off" when they ask about it sure sounds eerily similar to the facts of the case in the linked article. I'd wager that's a good way to land an obstruction charge.
If the abuse is egregious, you have a decent chance of pro bono representation or a lawsuit payout. In any case, activism comes with personal risk, and part of activism is accepting that risk while attempting to protect others. (This person was an activist, and itâs likely that they wanted to confine the damage to themselves.)
For the second part, having an empty phone is not a crime, and being arrested for this would be a major scandal. The tech press and political outlets would be all over it. Itâs generally a good idea to avoid directly antagonizing border guards, though.
They won't unless you are already on "their list" My phone basically looks like a burner phone, I do not use social media, do not install apps, my iphone fits (with room to spare) all "apps" on a "single page." I just call and text from my phone and have a browser and maps and that is basically it.
I'm a bit mystified why anyone would bring an electronic device over an international border with anything that could be construed, fairly or not, as evidence of criminal behavior.
Think itâs better to travel without a phone at all and buy one when arriving in the us? Problematic I guess with everything being digital
Years ago I chatted with a border guard from another country about their job (while they were not working). Not having a phone nowadays would be considered "strange" enough to flag you. If you're not a citizen of said country, it could even dramatically increase the odds of disallowing you entry. Often this would prevent you returning for a set number of years.
At the end of the day, it's always best to just not have anything "bad" on your devices. People have been caught up for all numbers of "innocent" reasons (pictures of their kids in the bathtub, ancient photos in their albums of themselves doing illegal things such as drugs or underage drinking, text messages or browser history disparaging politicians the border guard may support, porn in your history) that can give a border guard in a bad mood good reason to ruin your day.
I personally don't want my phone data hoovered in and analyzed or marked, even though I don't really have anything to hide. I don't care enough to do anything about it, but if I did I would probably have a second travel phone with a curated amount of data, apps, accounts, etc.
The last time I tried to do that on a trip to Germany, admittedly many years ago, I found I could not get phone service without a local address.
If you can, just avoid ever entering the US at all.
It has been standard practice for some time now in some European companies.
Also, you might accidentally drop your burner in the lake/ocean before you return. It happens!
> At this point, people should buy a burner phone when going to/from the US.
At this point? This has been standard practice for a while now.
If the government wants you no amount of technical gotchas will prevent this.
They didn't get the data from his phone and will likely lose the case against him. They probably wanted data to go after other people and those people were protected against it.
It was likely unnecessary to use the duress PIN/password. He likely would have been better off simply refusing to provide the PIN/password. He could have rebooted or powered off the device before going through but even without that it would have automatically rebooted itself after 18 hours by default, or a lower time if he had configured one.
With a lot more preparation he could have done an encrypted backup, wiped the device and restored it later but that's very inconvenient.
FAFO
Y'know, makes me wonder why Democrates didn't disband ICE and CBP when they had control over the Congress and the government. I mean, they knew those agencies would be used in precisely this way, yet did nothing anyhow.
Democrats built the blueprint for ICE's deportation program and architected the law that enabled it.
Clinton's IIRAIRA bill literally introduced expedited removal procedures and created the concept of 'administrative warrants', routinely used by CBP/ICE today.
Without the IIRAIRA, removal would be substantially harder.
IIRIRA was not a 'Clinton' bill. It was initially drafted by Lamar Smith (r) of Texas (HR 2202) and subsequently attached to an appropriations bill (HR 2610), and passed with a bipartisan veto-proof majority.
https://www.congress.gov/bill/104th-congress/house-bill/2202
https://www.congress.gov/bill/104th-congress/house-bill/3610
It's easier than ever to check legal assertions before you post instead of posting incorrect information.