cross-posted from: https://lemmy.world/post/49853131
Feels to me like GrapheneOS did exactly what it should, passing the US border test with flying colours!
Funny part about this lawsuit: “With a little planning ahead of time, you can always download the data you need once you get to where you’re going,”
This whole situation is making me strongly consider bringing a burner phone on my next vacation. That way I can wipe it before going through customs.
I did something similar when I last visited the US ~15 years ago. I uploaded an encrypted backup of my phone to a server in my home country and reset the device. I then downloaded and restored the backup when I arrived at the hotel.
„unlawful to knowingly destroy or damage property to prevent authorities from seizing it” - but did it fucking explode, catch on fire, or blew some fuse on the phone or in any other way prevented it from working? No, they (not him) just wiped the data. I didn’t know deleting files off YOUR OWN DEVICE is a crime. I need to think twice before I empty trash on my computer next time.
„I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.” Wow that’s an advice fitting entering Russia, Iran, etc. Nice club you’ve joined here
I just heard about this yesterday and it’s very interesting and fascinating to me, how the duress PIN worked if a situation like this arose. I cannot think that GrapheneOS team for implementing such a feature. Lowkey want the team’s input on this. 🥰
Sounds like the border guard wiped his phone, not him.
why are they so concerned about what you OWN
Can’t control people without controlling things. And vice versa.
Imagine being on a de-federated instance like lemmy and crying about how a COP in AMERICA could not harass a person successfully.Go back to meta choom.
…Who tf was complaining? You’re fighting ghosts.
What if you OWNed some child pornography.
What if I am a law abiding citizen? Should I relinquish my rights against unwarranted search and seizure because of ‘woulda coulda shoulda’?
If your rights can so easily be ignored due to some hypothetical scenario, then you never really had rights to begin with.
So are you saying you’d be ok with your personal property being searched without a warrant on the suspicion that you might own child porn?
What if you owned: weed/drugs, illegal firearms, items which could be used for potential murder, negative opinions about the fascist government?
This argument is shallow to the point where fascism is what you’re advocating here for. So what, if you did own something thats not law abiding - without any credible proof there is nothing there, and non of anybody’s interest.
Surveillance is fascism… it is clear to me that neither do you understand the word nor do you know about the most basic features of it.
Lets go by your logic then, What IF a cop plants contraband or CASM pictures onto your device?
not bro resorting to whataboutism.
Begone Fed
??? classic statistic apologist rhetoric I’m not against holding pedos accountable, I’m against searching a man/woman/non binary’s phone without proving suspicion of OWNing child pornography… please educate yourself
Privacy isn’t keeping everything about your life secret from everybody. Its about having control over who in your life gets to know what. Its the pretext for honest communication. Extreme surveillance will lead to people self-censoring themselves to please the fascist state.
Yeah I wonder what the penalty is for doing something legal with something you own.
GrapheneOS - the only OS that i just installed and forget about it. Sure i spend time to tweak things like profiles but thats it.
And I am a distro and rom hopper.
The security model is that good: duress pin, scrambled pin, separate profiles with their own passwords, usb c restriction (you can set it charge only, charge while phone is off (most secure state).
and yet people even here don’t understand why it would be useful even without the hardware security thinhs of the pixel
You can only install Graphene on a Google phone and there’s two big issues with that:
- you are rewarding Google by buying their hardware.
- it doesn’t matter how secure the os claims to be if the hardware is compromised and there is nothing you can do to convince me that a pixel doesn’t have a backdoor into your data at a hardware level. If I was a conspiracy minded type I might say that Graphene is a Trojan Horse.
Would be cool to have your device partitioned by separate passwords, so you could unlock a dummy system.
I believe some password manager (was it 1Password?) has this
This is an excellent idea honestly.
There are ways to do this on some devices. Here’s an article about it, Google translate’d to English:
yes you can. On Graphene you can set the main profile as just there with nothing except to control wifi/add esim/etc. Then you can create many profiles with their own passwords. You can store your work stuff in 1 profile, private stuff in another. You can even create a dummy profile with fake Google. .
The downside currently is that the OS autoboot to main profile. Then you switch to your other profiles.
He would have had a lot better legal leg to stand on I think if he had just refused to give them any passcode. Now instead of a potential case of being forced to compel speech, he is facing what will be argued is an attempt to destroy evidence. His defense is probably a lot stronger with the former than the latter.
Does it count as destroying evidence if they don’t have a warrant for it? I can destroy whatever device or document I want. It’s my property
Not once law enforcement tell you it is relevant to an ongoing investigation.
To charge someone with destroying evidence wouldn’t they first have to somehow prove the evidence existed?
No they would have to prove that what was on his phone was evidence in the first place. Which is why arrest and search warrants list all kinds of potential evidence and if it isn’t listed in the warrant they can’t collect or use it against you.
I’m not exactly sure how this works during a border patrol search. It’s technically his phone and if it’s locked they would need his permission or a warrant to search it.
What? US police can ask you for the phone password? No way! That is 100% police state. Stalin was amateur comparing to present day USA.
The important thing is this: can you still deliver lectures to the rest of the world on the Importance of Freedom Of Speech, and the fact that only Yanks have it because Elon can worship Hitler on the Internet?
And the answer is, yes. Yes you can, and always will. So the actual reality isn’t really important. Because all you actually learned from 1984 is that of the government tells you that you have freedom of speech, and also tells you that Eastasia and Eurasia don’t, That’s Good Enough For You and you’re The Free-est People In The World.
Yes US citizens cannot be compelled to provide a password, but biometrics such as fingerprint or Face ID can. Disable these when crossing into the US.
Non citizens can be detained and rejected for not providing access to a device via password. Best to bring a second device if you must enter. Depressing times.
I don’t believe you can be compelled to provide a password. That does after all (at the very least) constitute speech. And freedom of speech is also freedom of non-speech, they can’t make you say something.
They will however try to make you do that… In many situations authorities are allowed to lie to you. So that’s sucks. They can tell you that you’re required to unlock your phone, you just have to know that your not actually.
Also they can’t make you say anything, but they can make you do things, like for instance “put your finger here” or “look into this camera”, which is why biometric unlock is unsafe around cops.
There’s that one guy who is being held in contempt of the court (to be clear this is not the police asking for his password, but a judge in a court of law) because he won’t give a password to decrypt a hard drive.
They believe it is highly likely that the drive contains sexually explicit material of children, which is why he’s being held in prison until he gives up the password.
I would want to catch pedophiles too, but I seriously don’t believe a damn thing any branch of this government says about anyone.
For all I know he has a video of trumps night out at Epstein island and that’s why they want the password to destroy it.
Obviously probably not but still, I’m supposed to just take the scouts honor of our unhonorable government that this guy totally has this on his hard drive even if they can’t prove it?
They could say this about any of us at any time for any devices password we won’t give them.
I don’t agree with this precedent.
Oh yeah I think it’s terrible this guy is imprisoned for not giving up a password, for something they can’t prove. Like they shouldn’t be able to detain someone indefinitely for an unproven crime. At some point they have to release them or it’s guilty until proven innocent.
That’s it. I’m getting a burner phone if I leave the country.
Edit: Serious question… what if you just wiped your phone and then restored it when you got wherever you were going?
Given that the state of this guy’s phone would look the same as a burner phone, I’m not sure how that will work out.
Honestly I’m not considering leaving at all while this administration is in power. We’ve already heard too many stories of arbitrary detentions even for lawful citizens or visitors that I simply don’t want to roll the dice on whether my vacation ends with a nightmare or just another flight in as normal
If I have to leave the US, its a one way trip
Ditto.
claimed they did not need a warrant to search Tunick’s phone because he had not yet crossed the U.S. border.
Also no right to search / seize his phone then. US law doesn’t apply on non-US soil.
But what law/rights do apply there?
If it’s not US soil, it’s not a detention, it’s a rendition, a kidnapping.
Also, I don’t know how citizenship works I this respect in the US, but in my country a citizen cannot be denied entry. It can be detained upon entering, but by then you are in sovereign soil.
Its the same in the US. They can’t deny entry to US citizens.
this was a streisand effect for me because i didn’t have duress password set up on my grapheneos phone (security & privacy => device unlock) before but i do now! :D
On GrapheneOS, you can also set a “second factor PIN” in the unlock settings under “Fingerprint Unlock”, so that to unlock your screen you need to first use the fingerprint unlock and then separately enter your PIN. This means BOTH are required every time you unlock. Your phone can’t be unlocked unless it’s your finger AND unless you enter the PIN that only you know.
And under the Screen Lock settings you can also enable “Scramble PIN input layout”, so that the number buttons on your unlock screen will be out of order, so people watching you or recording you can’t just make note of the shape your index finger is making when touching the numbers to unlock your phone(like people looking over your shoulder or recording on store security cameras).
What I find foolish is there’s no pin only to unlock (no biometrics), but biometrics available when unlocked
Plenty of my apps have biometric verification I’d love to take advantage of, but I don’t need or want one to unlock the phone itself
But there is
Settings > Security & Privacy > Device Unlock > Fingerprint and there you can toggle to use the fingerprint for device unlocking and/or verification in Apps
Huh cool
That definitely was not there when I installed GrapheneOS
best promotion ever haha What is it? FU-123?
I imagine the best duress PIN is something you’d actually see a “normal” person set as a PIN, like their birth year or something innocuous and easy to remember (and easily believed by whoever’s demanding your PIN), while their real PIN would be longer or more abstract.
Honestly I would use a stupid basic one that someone might try and use if they were guessing. Like a duress pin of 1-1-1-1, 1-2-3-4 or 2-4-6-8. It gets the people who take the device and then try and break into it without your permission as it’s almost certain they will at least try one of those three.
Worst case scenario they ask you and you say what it is and they give you a blank stare of “really?..” it’s not like they wouldn’t try a pin you gave them.
I don’t recommend a duress password of 1-1-1-1, because that could be set off accidentally.
that’s fair, I don’t know if graphene supports press enter to submit but, I usually have that setting enabled on my devices
Or those common dumb ones could be attempted by someone just trying to snoop on your phone.
that’s sort of the point of it being super basic. The intent is you want it to be tried before they somehow manage to get your actual pin, or give up and try to force you to provide it.
if they put the pin in before you tell them a pin the argument for destroying evidence is weakened heavily as it isn’t a you initiated thing.
The sort of code an idiot puts on his luggage.
Exactly that, its not easy to fat-finger, but is dumb enough that its the second thing anyone would guess.
Yeah, you actually gotta remember it too! So a 1234 pword is kind of great
Sounds dumb to give it out, but mine is my normal 8-digit pin, just backwards. It’s easy to remember and seems like a legitimate PIN.
that would throw me for a loop longer than I would like to admit, it took me like 10-15 seconds to process what mine would be backwards and mine is only 4 digits lmao
It may be an IT person thing but I like numbers lol.
Or Jenny’s phone number.
8 6 7 5 3 0 9
Is it with a Zero or letter O? They sing the letter “O”. Or, what about handing “niiine”… 3 nines?
Good.
That’s legal, fuck you. It’s my data, and I want it (gone) now!
Its good if the courts hold that sentiment up in his favor.
If they don’t and take the border patrols side in this case then this just sets a horrific precedent for the future.
I hope the feds get raked over the coals in this court case and not only loose but get the dog shit sued out of them for this stunt.
I’m not optimistic anymore though.













