US accuses American of allegedly wiping his phone using a 'duress' password during border search | TechCrunch (techcrunch.com)
from QuadernoFigurati@lemmy.ml to privacy@lemmy.ml on 24 Jul 20:52
https://lemmy.ml/post/50499191

#privacy

threaded - newest

StumblingWasabi@lemmy.today on 24 Jul 21:09 next collapse

Pick a lane. Either it counts as US soil so you need a warrant or it doesn’t so theres no reason for US law to apply until the person is approved.

EveryMuffinIsNowEncrypted@lemmy.blahaj.zone on 24 Jul 22:50 collapse

<whisper>No one tell them about international airports…</whisper>

atrielienz@lemmy.world on 25 Jul 04:42 collapse

They have a point though. Technically from what I’ve read just living near an airport would give ICE the authority to search your phone and anything else you might be carrying if it’s within a certain mile radius. Even if you aren’t using the port of entry (airport for instance). Regardless of whether or not they have any other form of probable cause.

I don’t understand how others don’t understand that. Because it’s a hell of a conclusion to come to.

EveryMuffinIsNowEncrypted@lemmy.blahaj.zone on 25 Jul 05:33 next collapse

Oh 100%. I was just being a lighthearted goober about it. Lol.

Duamerthrax@lemmy.world on 26 Jul 01:03 collapse

It’s 100 miles. They claim 100 miles from the boarder and now “the board” is including international airports.

www.aclu.org/know-your-rights/border-zone

Eternal192@anarchist.nexus on 24 Jul 21:17 next collapse

So? My data, my choice and right to delete it, so fuck off!

quick_snail@feddit.nl on 25 Jul 14:20 collapse

He didn’t delete it. The officer did.

I wonder if he’ll sue them for damages

blackbrook@mander.xyz on 25 Jul 15:44 next collapse

“They asked for my password. They didn’t specify which password.”

quick_snail@feddit.nl on 25 Jul 15:48 collapse

More like “sorry I couldn’t remember the password. I guessed, but I have a bad memory”

This is exactly the reason the government can’t force you to give your password in the US. They can’t prove that you remember the password.

NauticalNoodle@lemmy.ml on 26 Jul 00:19 next collapse

-That, and the 5th amendment.

Cethin@lemmy.zip on 26 Jul 00:26 collapse

If you’re in this situation, don’t say this. You are under no obligation to explain anything, and anything you say will be used against you (and will not be used to defend you). Just shut the fuck up.

quick_snail@feddit.nl on 26 Jul 03:04 collapse

Yeah, you’re right

eager_eagle@lemmy.world on 25 Jul 23:25 next collapse

lol that’d be a neat uno reverse card right there

you… you deleted my data?? shocked pikachu face

Dultas@lemmy.world on 26 Jul 00:46 collapse

Just put a note in your wallet that says cell password with the distress pin. You didn’t give them the pin their illegal search uncovered it.

davel@lemmy.ml on 24 Jul 21:47 next collapse

en.wikipedia.org/wiki/Tampering_with_evidence

Tunick’s attorneys accused the government of demanding access to his phone under the pretext of searching for child exploitation imagery, but without providing evidence to justify its suspicion.

Even if I had more information, I still wouldn’t have the law chops to predict where this may lead.

FineCoatMummy@sh.itjust.works on 24 Jul 22:19 next collapse

I don’t have those chops either. Also NAL. The wiki page says Tampering charges require there to be an ongoing investigation, which wasn’t the case here, so I’m thinking it wouldn’t apply. But! I wonder about spoliation. Spoliation before a case is brought, while not illegal per se, can result in negative inference,

spoliation inference is a negative evidentiary inference that a trier of fact can draw from a party’s destruction of evidence that is relevant to an ongoing or reasonably foreseeable civil or criminal proceeding

Negative inference, to my NAL understanding, means the tampered evidence may be taken in the worst light for the defense. Here, it’s all resting on flimsy and politically motivated pretext with no evidence. Still.

Needs an immigration lawyer to give an answer to this, but I’m thinking it may be legally safer to have strong encryption and refuse to unlock, rather than to wipe. Not unlocking isn’t tampering, so no spoliation, but wiping might be. Well, safest of all is to use a burner. But next best, strong encryption + don’t unlock. CBP can confescate the device, but they cannot compel you to produce a pw or unlock code.

pemptago@lemmy.ml on 24 Jul 22:46 collapse

From what I’ve gathered, I think you’re right to assume it’s legally safer to refuse to unlock rather than wipe. Also, worth noting that you can be compelled to unlock with biometrics, but not a password. On grapheneOS this means simply shutting off/restarting your device as it requires a pw after a fresh boot, even if biometrics is enable.

FineCoatMummy@sh.itjust.works on 24 Jul 23:27 next collapse

you can be compelled to unlock with biometrics, but not a password

Yah, I’ve been trying to get my friends to use a pw rather than biometric unlock, for that exact reason.

I’m batting like 0 for 5, lol. Biometrics are just too convenient I guess. Plus they don’t think it will impact them personally. Which is prob true. I still think it’s best to use the way that preserves more civil rights. I just can’t convince them.

MasterBlaster@lemmy.world on 25 Jul 03:18 next collapse

Sheep will always be sheep.

pemptago@lemmy.ml on 25 Jul 17:38 collapse

Yeah, people have their own threat model and trade-offs they’re willing to make for security/convenience and it’s probably a lot lower for most people than if they knew more about the landscape and gave it careful thought. It sounds like other mobile devices might reencrypt after reboot. IDK about the pw v. bio, though, but if it’s like Grap.OS just convincing them to reboot their device before going through TSA checkpoints or other areas where their device might get confiscated may improve their security with minimal effort.

Carl@anarchist.nexus on 25 Jul 02:23 collapse

Even on iOS, you can disable biometrics by entering the power/SOS menu. Just hold the lock button and volume down for like two seconds, and biometrics are now disabled until the passcode is entered.

Worth noting that this doesn’t actually re-encrypt the device. The device boots in an encrypted state, and entering the passcode allows the phone to unencrypt itself to function. But disabling the biometrics doesn’t re-encrypt the device. You would need to reboot to accomplish that. But if you’re able to access the power menu, you’re probably able to hit the “Power Off” option too.

I only make the distinction because cops have started imaging devices after confiscating them. If they manage to image your device while it’s unencrypted, they can take their time with whatever new exploit/bypass is discovered in the future. But if the device is encrypted when they image it, they’d only get an encrypted data blob and would need to actually break the encryption instead of being able to use a passcode bypass method.

iOS actually has a hidden “reboot if inactive after a little while” feature, specifically to re-encrypt an idle device. Most users only encounter it when they wake up in the morning and have to enter their passcode. But the point is that cops usually process devices in batches, so it usually takes them at least a few hours to get to your device. So if the device has been idle for a while, it will quietly reboot to encrypt itself. This also helps protect against future passcode bypasses that may be discovered, because an attacker would only get the encrypted data blob if they bypass the code on an encrypted device.

quick_snail@feddit.nl on 25 Jul 14:19 collapse

The accused is a Stop Cop City activist in Atlanta.

wesker@lemmy.sdf.org on 24 Jul 21:47 next collapse

That’s precisely what a duress password is for. Feature working as intended, get a warrant.

Vex_Detrause@lemmy.ca on 25 Jul 15:59 next collapse

Edit:Other connent said GrapheneOS Can we get a source for this app/technique?

AnnaFrankfurter@lemmy.ml on 25 Jul 18:48 collapse

grapheneos.org/features#duress

Graphene OS Team has developed quite a lot of other useful features and some of them have even been merged into upstream AOSP allowing others also the benefits. Recent example is contact scope for apps starting Android 17 but it was initially developed by GrapheneOS team long ago.

eldavi@lemmy.ml on 29 Jul 15:10 collapse

it needs to be reworked so that it’s difficult to discern to strangers if the phone has been wiped.

it’ll probably have to include fake phone logs, fake text messages, fake pics, etc. to make the wiped phone look like it wasn’t wiped.

eager_eagle@lemmy.world on 24 Jul 21:58 next collapse

for research purposes, how would one go about setting this up?

Malyca@lemmy.zip on 24 Jul 22:04 next collapse

I think he was using graphene os

ExcessShiv@lemmy.dbzer0.com on 24 Jul 22:06 next collapse

grapheneos.org/features#duress

humble_boatsman@sh.itjust.works on 24 Jul 22:41 collapse

I can’t seem to find it in my set up. There is no option for duress pin under device unlock selection

ExcessShiv@lemmy.dbzer0.com on 24 Jul 22:46 collapse

Are you using grapheneOS?

humble_boatsman@sh.itjust.works on 24 Jul 23:47 collapse

Yep e/OS 3.7.1

E: well I’m a fucking idiot

RodgeGrabTheCat@sh.itjust.works on 25 Jul 00:24 next collapse

Eos is not GrapheneOS

whatiswrongwithyou@lemmy.ml on 25 Jul 02:15 next collapse

E/os isn’t graphene and doesn’t have a duress pin feature.

pineapplelover@lemmy.dbzer0.com on 25 Jul 05:21 collapse

Lmao, the edited comment

BCsven@lemmy.ca on 25 Jul 00:56 collapse

GrapheneOS also has options to turn off USB port so that authorities plugging in devices to try to bypass phone lock can’t be exploited. And user needs to supply password to change the USB options.

pierre_delecto@hexbear.net on 24 Jul 22:09 next collapse

Sounds like the cops entered the passcode… Therefore the cops erased the evidence.

who knows what would’ve happened if they bothered to get a warrant first.

nfreak@lemmy.ml on 25 Jul 00:35 collapse

To step it up even further, if using a duress pin, stick it on a note inside your phone case. Don’t say a goddamn word aside from asking for a lawyer, and when they inevitably find the written code and try it out, that’s entirely on them.

robot_dog_with_gun@hexbear.net on 25 Jul 02:08 next collapse

that doesn’t work if they clone it

dRLY@lemmy.ml on 26 Jul 03:22 collapse

Would be great if there was a feature that detects a clone and start zeroing itself. Or start flipping bits every few seconds/random intervals in a way that just seems like nand in early stages of failing (maybe even give false drive health data). Though I have zero understanding of the cloning processes, and imagine that it would quickly be something they would have their own detectors and mitigations.

But can’t just stop trying to make it harder/frustrating for anyone trying to access all our digital lives. They already get around our rights with how they just go ask the companies like Microsoft to get people’s Bitlocker keys (which even most people seem to not even be aware of having until Windows breaks).

pineapplelover@lemmy.dbzer0.com on 25 Jul 05:19 next collapse

Just say “it’s not my birthday, so don’t try my birthday”

pierre_delecto@hexbear.net on 25 Jul 12:01 collapse

That’s a good idea

HiddenLayer555@lemmy.ml on 24 Jul 22:18 next collapse

“Sorry, my fat American fingers accidentally entered the wrong code, you understand.”

N0t_5ure@lemmy.world on 24 Jul 22:30 next collapse

The authorities conducting the illegal search entered the code, so the phone owner could assert that he gave them the right password and they were the ones that screwed it up. It’s a bit late for that argument, but someone could use that in the future and there’d be no way to prove it wrong.

humble_boatsman@sh.itjust.works on 24 Jul 22:34 collapse

From what I read, upon demand he gave the code to the Investigator, whomst had to watch the phone start to load and then erase it self. What a joy it must have been to watch them gifauh at that

quick_snail@feddit.nl on 25 Jul 14:17 collapse

Pretty sure all cops have fat fingers. Too many doughnuts

lennee@lemmy.world on 24 Jul 22:20 next collapse

sorry accidentally did a duress oopsie uwu bite me

gary_host_laptop@lemmy.ml on 24 Jul 22:26 next collapse

this is literally what they accuse china of

ToiletFlushShowerScream@piefed.world on 24 Jul 22:50 next collapse

A reason to try grapheneos if you are technically inclined.

yestalgia@lemmy.world on 24 Jul 23:19 next collapse

It’s easy enough for anyone willing try. Grab any Pixel from the last few years, plug it in to a computer, and click buttons in your web browser on the GOS website and watch GOS get installed on your phone. The instructions hold your hand the whole way through.

sun_is_ra@sh.itjust.works on 24 Jul 23:25 collapse

do you know how much does any pixel from last year cost?

It_is_gaslighting@discuss.tchncs.de on 24 Jul 23:41 next collapse

200€ used market if not even less. Look on grapheneOS website for compatible devices.

yestalgia@lemmy.world on 24 Jul 23:56 next collapse

I paid $300 for a mint condition 9a about a month ago on Swappa. Obviously the price is lower for other conditions.

grapheneos.org/faq#recommended-devices

RodgeGrabTheCat@sh.itjust.works on 25 Jul 00:28 next collapse

I know what the 10a costs, bought one a few weeks ago. Worth every penny.

surewhynotlem@lemmy.world on 25 Jul 00:47 next collapse

I sold a 6a for like $50 recently. Here on lemmy, oddly enough. Those are still good.

sun_is_ra@sh.itjust.works on 25 Jul 00:56 collapse

wow! What community do you sell at?

MidnightMarauder@lemmy.dbzer0.com on 25 Jul 06:29 collapse

Bought a new 8a for 300,- a year or so ago. Way Cheaper than a flagship Samsung or iPhone, runs really smooth on Graphene.

ColeSloth@discuss.tchncs.de on 25 Jul 02:06 next collapse

I soooo want that feature, but less and less phones will even let you unlock your bootloader. Graphene OS doesn’t get to support many phones.

mnemonicmonkeys@sh.itjust.works on 25 Jul 14:08 next collapse

The bigger issue with GOS compatibility is the ability to relock your bootloader and a few other security features.

Also, Motorola is releasing a GOS compatible phone next year. They consuled with the devs on what features were needed

MML@sh.itjust.works on 25 Jul 15:12 next collapse

Just one? I really want a Graphene Razr but if that doesn’t happen I’m just going to get a FLX or similar

FineCoatMummy@sh.itjust.works on 25 Jul 16:44 collapse

I really wanna give that time to be stress tested against Celebrite tho. Celebrite was able to get into locked devices. For all but the latest gens of iPhones and Andoids, which have better h/w security features. Older models they can access.

If we see that Celebrite isn’t able to break the new GOS Motorolas, that’ll be good to learn.

oats@beehaw.org on 26 Jul 01:11 collapse

Yeah, I bought my pixel specifically to run Graphene. Hope the Motorola devices come sooner that later, so one has a bit of a choice

OS2Warp@lemmy.zip on 25 Jul 15:32 collapse

Or, on iOS, wipe the device after 10 failed attempts.

segfault11@hexbear.net on 24 Jul 23:41 next collapse

they’re gonna use this case as pretext to ban graphene os

quick_snail@feddit.nl on 25 Jul 14:19 collapse

Lol I think they’ll loose. It’ll be good to have legal protection for this tech.

apftwb@lemmy.world on 25 Jul 00:27 next collapse

FYI if you are using GrapheneOS with the duress password, you can natively backup your phone. Its in settings.

Duamerthrax@lemmy.world on 26 Jul 01:05 collapse

For people that don’t want to be dragging into a civil rights case, can you set up a dummy interface that looks used, but doesn’t have any too important available? Like you only owned the phone for a week?

apftwb@lemmy.world on 26 Jul 02:05 collapse

You can setup different users on GrapheneOS and switch between them.

There is also a “private area” in the bottom of the app list where you can move sensitive apps and password protect them.

Either way, allowing a malicious actor into that profile exposes more attack surface for them to exploit.

Idk. Security is a journey, not a destination.

MasterBlaster@lemmy.world on 25 Jul 03:12 next collapse

Citizen enforces his own right to the Fourth Amendment and is prosecuted by the government for not letting them try to find incriminating evidence on him. For something. Maybe. Because he looks suspicious.

I hope that lawyer gets it thrown out. I’m not holding my breath. We’ve gone so far into fascism I’m not sure it’ll take anything less than violence to end it.

AHemlocksLie@lemmy.zip on 25 Jul 05:21 collapse

Unfortunately, the 4th is pretty well destroyed at the border. And within 100 miles of the border.

Quill7513@slrpnk.net on 25 Jul 13:01 collapse

they’ve expanded the 100 miles to 250, and include cities with international airports now. we’re at a point now where USBP jurisdiction is wherever a USBP agent happens to be

magnue@lemmy.world on 25 Jul 12:45 next collapse

Would love to see how that happened. Extra points if they are the ones that entered it.

Pandantic@midwest.social on 25 Jul 13:48 collapse

They were:

When Tunick provided his passcode and the authorities entered it, “the screen went blank, flashed several times and the phone appeared to restart.”

reagansrottencorpse@lemmy.ml on 25 Jul 13:08 next collapse

Hmm this sounds like government overreach 🤔

vrighter@discuss.tchncs.de on 25 Jul 14:05 next collapse

no he didn’t. They asked for a password that the phone would accept. They weren’t even supposed to ask, but he gave them one. They’re the ones who entered it on the phone. And by extension they’re the ones who erased the phone.

MML@sh.itjust.works on 25 Jul 15:06 collapse

Plus he provided a passcode that unlocked the device I don’t see the issue.

quick_snail@feddit.nl on 25 Jul 14:16 next collapse

When Tunick provided his passcode and the authorities entered it, “the screen went blank, flashed several times and the phone appeared to restart.” The authorities seized his phone anyway, before telling him that he was free to go and could enter the United States.

Very glad to hear that he’s a free man while the courts try to figure out what to do.

Also it’s hilarious that he didn’t wipe it. The officers did it. I think it’s going to be very hard to get a conviction of this activist when it was the officer that wiped the data.

99zz99@hexbear.net on 25 Jul 14:23 next collapse

Regardless of how it happened, entering a fascist state means that you must be prepared to wipe all your devices before crossing the border. They’ll naturally fabricate justifications to employ totalitarian measures as it’s their directive to do so. If they seize your items and violate your privacy, which they will do, at least there’s nothing but a blank slate. These days I feel it’s more important than ever to have two devices, with one being a basic phone for communication only and the other a smartphone that’s backed up and ready to be wiped at a moments notice, then stuffed into your luggage.

ScoffingLizard@lemmy.dbzer0.com on 25 Jul 16:32 collapse

“Entering a fascist state”, means you should turn around and go back the way you came. Why do people assume it’s safe here?

99zz99@hexbear.net on 25 Jul 17:25 collapse

Ideally, sure. I don’t think most people assume it’s safe here, at least not anymore. I’d wager that most people, if they had the option, wouldn’t come here lol it’s not like only tourists are coming through the border.

ScoffingLizard@lemmy.dbzer0.com on 25 Jul 19:45 collapse

I’d say the consequences of not coming are easier to endure than being beaten and left to rot in a concentration camp with no due process.

99zz99@hexbear.net on 25 Jul 21:29 collapse

That choice is a privilege in itself. Tell that to those who have loved ones dying in dystopian US hospitals.

ScoffingLizard@lemmy.dbzer0.com on 28 Jul 01:29 collapse

The hospitals are noy bad yet, but point taken.

quick_snail@feddit.nl on 25 Jul 15:35 next collapse

Sounds like the police officer tried to gain unauthorized access to a device. And, while they were trying to crack it, they wiped all of its data.

I wonder if the police officer that did this will face criminal charges of unauthorized access and destruction of evidence.

And also there’s a civil suit in there. The officer may have deleted valuable data on the victim’s device, causing them harm. I wonder what the monetary value will be.

Hiro8811@lemmy.world on 25 Jul 17:55 next collapse

The duress password on graphene os wipes all the data, they probably threatened or force him so he gave them that password

queermunist@lemmy.ml on 25 Jul 18:01 collapse

They charged people with terrorism for using Signal chat.

Fancy_Gecko@lemmy.ml on 25 Jul 16:58 collapse

US is a dystopia

NauticalNoodle@lemmy.ml on 25 Jul 23:50 collapse