(a)Destruction or Removal ofPropertyTo Prevent Seizure.—
Whoever, before, during, or after any search foror seizure ofpropertyby any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government’s lawful authority totake such propertyinto its custody or control ortocontinue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both.
If he hadn’t used duress and had just refused, he’d have been fine. Graphine is secure and would have had his back
If he hadn’t given them the code and instead left it in his wallet, and they did it themselves, he’d have been fine.
All he had to do was plead the 5th.
He’s going to get hit with a felony for destroying data to prevent a search. There are tons of precedents in the 11th Circuit for searching without a warrant.
A duress password is only useful if what you’d be facing is worse than 18 U.S. Code § 2232a, and then only if they don’t have enough to convict you already.
Dude is just protesting the construction of a large cop training facility near him. I don’t know what the fuck he did to get on the FBI radar, but I wish him good luck; he’s gonna need it.
What if you set a durress password to something simple like 12345, plead the 5th, and the cops try to brute force your device? Would it still be your fault or is it the cops fault since they are the ones who entered the password while trying to bypass your phone’s security measures?
Also, what if you explicitly tell them there is a durress password, but refuse to tell them what it is? Surely if they were informed of the risk and proceeded regardless the blame would fall squarely on them for risking a process that might “destroy evidence”
They’re there because you’re being watched already. You’re coming in from an international flight to the 11th district so they have unreasonable search and seizure rules.
Graphine is clean enough that they can’t sidestep it. Just plead the 5th and leave it at that. They’ll probably confiscate it in hopes they’ll eventually be able to break it on a zero day.
Telling them the duress password is the unlock code will def get you fucked.
Pleading the 5th and then them entering a password found in your wallet that wipes it will get you dragged into court, but probably in a defensible position; those lawyer fees are going to be immense.
Pleading the 5th and having your duress as 1234, which they try, would also put you in a defensible position with 10s of thousands in lawyers’ fees.
The duress password isn’t illegal. The knowing destruction of data is. If you set it up so they’re likely to destroy the data in attempting, you’re going to get served.
Don’t go through a border with a phone full of questionable personal data. Legal or not.
The issue I’m seeing with the whole case is they siezed his phone, they kept his phone, the seizure of his property happened successfully. A person later entered something they believed would open it but instead it wiped it. The end user didn’t wipe it, and didn’t lie to the agents of the state because a duress PIN is still a PIN, I’m willing to wager they didn’t specify that they wanted his ‘unlock PIN’ and instead just asked him for a PIN (personal identification number), which he gave.
Is data property? Sure, ideas, concepts, photos, etc can be trademarked/copy-write protected and have some degree of ownership, but I’m talking at a much lower level here… Is the particular configuration of memory on your phone a piece of property? If no, then no property was destroyed by wiping the phone. All of the storage and memory is still intact and functional. If yes, then we must look further…is the position (not the switch itself) of a binary switch (like a light switch) a physical thing that you can own? Would you consider it destroyed if it was switched away from it’s original position?
I don’t think you could charge him with destroying property… Destruction of evidence maybe, but the property is undamaged and functioning normally.
Other arguments. The cop actually destroyed the data. Or, defendant claims he did not know the cops would use the pin to wipe the phone, and that they just wanted to know what the PIN was.
I wouldn’t say there is enough evidence here to prove beyond a reasonable doubt that this guy destroyed any property in response to a search. He didn’t destroy anything, what was destroyed is arguably not property, and he may not be aware that his duress pin was going to be used on the device in the first place.
So far, every time I’ve been outraged about Buckees, they’ve sued a small business that’s trying to file their own trademark. And while I don’t like it one bit, trademark law is more or less designed for that exact purpose. Logos don’t have to be close, they could just vaguely remind you of another established trademark. The barrier to winning is extremely low, and the fault lies with the shitty, overly vague trademark law that attempts to make trademark owners fight any possible contender.
I don’t know if these guys were or were not trying to file a trademark, but I do know the three I looked at so far were begridgingly acceptable by trademark standards.
The video I provided covers this. There are plenty of statutes and precedents. There’s a tiny little bit of unsettled case law to be decided here that will, at best, lower his sentence a bit.
I strongly suspect an imminent plea bargain, unless they want to use him as an example.
It’s unfortunately a border entry. They can do whatever they want regarding searches in that jurisdiction. He won’t get away with it being an illegal search.
There are still outs, but they are not super likely :/
If he hadn’t used duress and had just refused, he’d have been fine. Graphene is secure
Graphene devs fucked over this guy. They should apologize
When Graphene is serious, the duress passcode will QUIETLY wipe your phone and leave it looking normal, preferably with normal-looking innocuous photos, media, etc.
This is what happens when devs aren’t really thinking about the real world use case.
Can’t Graphene be used like this already? Dude may not have known, or may not have bothered to set up multiple profiles. But I’m pretty sure it can be done.
No. If you make and distribute security-related software, you should consider the safety of your user.
Your threat model absolutely should include this exact scenario. And you should know enough to understand and implement principles like plausible deniability and repudiation.
That privacy was already long gone by the time of this case.
https://www.law.cornell.edu/uscode/text/18/2232
(a)Destruction or Removal of Property To Prevent Seizure.— Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both.If he hadn’t used duress and had just refused, he’d have been fine. Graphine is secure and would have had his back
If he hadn’t given them the code and instead left it in his wallet, and they did it themselves, he’d have been fine.
All he had to do was plead the 5th.
He’s going to get hit with a felony for destroying data to prevent a search. There are tons of precedents in the 11th Circuit for searching without a warrant.
A duress password is only useful if what you’d be facing is worse than 18 U.S. Code § 2232a, and then only if they don’t have enough to convict you already.
https://www.youtube.com/watch?v=_2rokxux5cU`___`
Dude is just protesting the construction of a large cop training facility near him. I don’t know what the fuck he did to get on the FBI radar, but I wish him good luck; he’s gonna need it.
What if you set a durress password to something simple like 12345, plead the 5th, and the cops try to brute force your device? Would it still be your fault or is it the cops fault since they are the ones who entered the password while trying to bypass your phone’s security measures?
Also, what if you explicitly tell them there is a durress password, but refuse to tell them what it is? Surely if they were informed of the risk and proceeded regardless the blame would fall squarely on them for risking a process that might “destroy evidence”
They’re there because you’re being watched already. You’re coming in from an international flight to the 11th district so they have unreasonable search and seizure rules.
Graphine is clean enough that they can’t sidestep it. Just plead the 5th and leave it at that. They’ll probably confiscate it in hopes they’ll eventually be able to break it on a zero day.
Telling them the duress password is the unlock code will def get you fucked.
Pleading the 5th and then them entering a password found in your wallet that wipes it will get you dragged into court, but probably in a defensible position; those lawyer fees are going to be immense.
Pleading the 5th and having your duress as 1234, which they try, would also put you in a defensible position with 10s of thousands in lawyers’ fees.
The duress password isn’t illegal. The knowing destruction of data is. If you set it up so they’re likely to destroy the data in attempting, you’re going to get served.
Don’t go through a border with a phone full of questionable personal data. Legal or not.
The issue I’m seeing with the whole case is they siezed his phone, they kept his phone, the seizure of his property happened successfully. A person later entered something they believed would open it but instead it wiped it. The end user didn’t wipe it, and didn’t lie to the agents of the state because a duress PIN is still a PIN, I’m willing to wager they didn’t specify that they wanted his ‘unlock PIN’ and instead just asked him for a PIN (personal identification number), which he gave.
That’s court fodder, and unfortunately, I don’t believe it’ll pass.
Yeah, sadly I don’t think it will either, I’m just hoping the jury decides the precedent they truly want to set.
Here is my problem with this interpretation…
Is data property? Sure, ideas, concepts, photos, etc can be trademarked/copy-write protected and have some degree of ownership, but I’m talking at a much lower level here… Is the particular configuration of memory on your phone a piece of property? If no, then no property was destroyed by wiping the phone. All of the storage and memory is still intact and functional. If yes, then we must look further…is the position (not the switch itself) of a binary switch (like a light switch) a physical thing that you can own? Would you consider it destroyed if it was switched away from it’s original position?
I don’t think you could charge him with destroying property… Destruction of evidence maybe, but the property is undamaged and functioning normally.
Other arguments. The cop actually destroyed the data. Or, defendant claims he did not know the cops would use the pin to wipe the phone, and that they just wanted to know what the PIN was.
I wouldn’t say there is enough evidence here to prove beyond a reasonable doubt that this guy destroyed any property in response to a search. He didn’t destroy anything, what was destroyed is arguably not property, and he may not be aware that his duress pin was going to be used on the device in the first place.
None of that would hold up in court.
Bucees just successfully argued in court that a beaver and an alligator are visually indistinguishable to the common man…
So far, every time I’ve been outraged about Buckees, they’ve sued a small business that’s trying to file their own trademark. And while I don’t like it one bit, trademark law is more or less designed for that exact purpose. Logos don’t have to be close, they could just vaguely remind you of another established trademark. The barrier to winning is extremely low, and the fault lies with the shitty, overly vague trademark law that attempts to make trademark owners fight any possible contender.
I don’t know if these guys were or were not trying to file a trademark, but I do know the three I looked at so far were begridgingly acceptable by trademark standards.
The video I provided covers this. There are plenty of statutes and precedents. There’s a tiny little bit of unsettled case law to be decided here that will, at best, lower his sentence a bit.
I strongly suspect an imminent plea bargain, unless they want to use him as an example.
I think the application of that law depends on whether a seizure is valid (aka legal), which is kind of up in the air, as your video points out.
It’s unfortunately a border entry. They can do whatever they want regarding searches in that jurisdiction. He won’t get away with it being an illegal search.
There are still outs, but they are not super likely :/
Graphene devs fucked over this guy. They should apologize
When Graphene is serious, the duress passcode will QUIETLY wipe your phone and leave it looking normal, preferably with normal-looking innocuous photos, media, etc.
This is what happens when devs aren’t really thinking about the real world use case.
Can’t Graphene be used like this already? Dude may not have known, or may not have bothered to set up multiple profiles. But I’m pretty sure it can be done.
Point is that when graphene gets the distress code, it makes it really clear that it’s wiping the phone.
That’s the Stupid Part
Something designed like SAmsung Knox would be much better. the rest of the phone/apps are still fine.
They shouldn’t apologize, the dude should of known that destroying evidence during an investigation is going to land you in jail.
There was no investigation, no evidence, and no jurisdiction
No. If you make and distribute security-related software, you should consider the safety of your user.
Your threat model absolutely should include this exact scenario. And you should know enough to understand and implement principles like plausible deniability and repudiation.