• zane@infosec.pub
    link
    fedilink
    English
    arrow-up
    16
    ·
    6 hours ago

    There’s an easy legal loophole.

    When you seize their phone, tell them your passcode is explicitly not the destruction code, and do not answer any more questions besides insisting this.

    When they inevitability try to put in the only thing you mentioned, its entirely their fault for the erase.

    Your milage may vary depending on financial class.

    • SpaceCowboy@lemmy.ca
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 hours ago

      When you seize their phone, tell them your passcode is explicitly not the destruction code, and do not answer any more questions besides insisting this.

      I feel like there might be a couple of things you have the the wrong way around in this sentence.

  • schipelblorp@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    47
    ·
    edit-2
    10 hours ago

    You know, since we are entering into a lot of legal weirdness here, how about this:

    You give the cops TWO passwords. You tell them one is the duress password, and the other is the password that will unlock the phone.

    Desperate and without a warrant, they try one. Wrong try! Phone is wiped.

    In reality, both are duress passwords but they would have to prove that. (GoS only currently supports one duress password)

    Yes, it’s ridiculous, but everything about this is ridiculous.

    • Talcosis@lemmy.zip
      link
      fedilink
      English
      arrow-up
      49
      ·
      10 hours ago

      Nah, write the duress password on a piece of paper and keep it in your phone case. Then keep your mouth shut. Let the cops find it and try it themselves.

        • halcyoncmdr@piefed.social
          link
          fedilink
          English
          arrow-up
          4
          ·
          3 hours ago

          I have two different PINs I use for different debit cards. One of those is also my phone PIN, the other is my Duress PIN.

          It would be really easy for to forget which is which when in a stressful situation.

    • droppedtacos@lemmy.world
      link
      fedilink
      English
      arrow-up
      21
      ·
      10 hours ago

      And what about maybe also adding in a friend or relative that’s with you so that you can inform the cop that one of you tells only truths and one of you tells only lies. I think we’re onto something here. ‘Dispatch, I’m gonna need the Riddlemaster to come down here. We got another one.’

  • schipelblorp@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    54
    arrow-down
    7
    ·
    16 hours ago

    Advice: if you know you don´t want your phone searched going through customs, don’t bring it! Or wipe it before you go through. I’m 100% on this guy’s side, but we’re not exactly living in a free and open society.

    • thejml@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      1
      ·
      16 hours ago

      Seriously. Wipe it, claim it’s new to you or whatever, put your stuff back on later if you need to. I’m sure you can find somewhere or someone you trust to get you that data back whenever you actually need it.

      • schipelblorp@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        17
        arrow-down
        1
        ·
        15 hours ago

        It brings up an interesting question: if wiping your phone after being requested access to it is illegal (?), would wiping your phone in anticipation of access being requested also illegal? Are we effectively required to give the federal government access to every private account in order to travel?

        • Flames5123@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          6
          ·
          15 hours ago

          My understanding is that if you knew a search was going to happen, it’s illegal. But good luck proving that you knew it would happen.

            • Sunflier@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              ·
              11 hours ago

              Your linked source only applies to civil matters (think lawsuits for a slip and fall). It even says:

              Under Federal Rules of Civil Procedure Rule 37

              That basically arises out of the Fifth Amendment, which reads:

              No person shall . . . be deprived of life, liberty, or property, without due process of law

              In the criminal conrext, the Fourth Amendment rules, which reads:

              The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.

              All that “probable cause”, “stop and frisk”, and “reasonable suspicion of wrongdoing” stuff arises from the “unreasonable searches and seizures” bit.

        • GalacticRobot@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          8
          ·
          14 hours ago

          As long as you aren’t doing it during an active investigation, no it wouldn’t be illegal. That’s the problem. Guy thought he was sneaky, and got busted. If you come in to investigate and suddenly you are deleting all the records, you are going to have a serious problem.

          • schipelblorp@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            10
            arrow-down
            1
            ·
            14 hours ago

            In the regular world, you can delete something to keep the cops from knowing about it as long as it’s not covering up a crime. You won’t find a charge of “destruction of evidence” without an investigation of an explicit crime with probable cause.

            If they had probable cause to search his phone, they would have used it when he was in Georgia, not waited for him at the airport where he had fewer rights.

  • rumba@lemmy.zip
    link
    fedilink
    English
    arrow-up
    63
    arrow-down
    8
    ·
    17 hours ago

    That privacy was already long gone by the time of this case.

    https://www.law.cornell.edu/uscode/text/18/2232

    (a)Destruction or Removal of Property To Prevent Seizure.—
    Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both.
    

    If he hadn’t used duress and had just refused, he’d have been fine. Graphine is secure and would have had his back

    If he hadn’t given them the code and instead left it in his wallet, and they did it themselves, he’d have been fine.

    All he had to do was plead the 5th.

    He’s going to get hit with a felony for destroying data to prevent a search. There are tons of precedents in the 11th Circuit for searching without a warrant.

    A duress password is only useful if what you’d be facing is worse than 18 U.S. Code § 2232a, and then only if they don’t have enough to convict you already.

    https://www.youtube.com/watch?v=_2rokxux5cU`___`

    Dude is just protesting the construction of a large cop training facility near him. I don’t know what the fuck he did to get on the FBI radar, but I wish him good luck; he’s gonna need it.

    • this@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      3 hours ago

      What if you set a durress password to something simple like 12345, plead the 5th, and the cops try to brute force your device? Would it still be your fault or is it the cops fault since they are the ones who entered the password while trying to bypass your phone’s security measures?

      Also, what if you explicitly tell them there is a durress password, but refuse to tell them what it is? Surely if they were informed of the risk and proceeded regardless the blame would fall squarely on them for risking a process that might “destroy evidence”

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        3 hours ago

        They’re there because you’re being watched already. You’re coming in from an international flight to the 11th district so they have unreasonable search and seizure rules.

        Graphine is clean enough that they can’t sidestep it. Just plead the 5th and leave it at that. They’ll probably confiscate it in hopes they’ll eventually be able to break it on a zero day.

        Telling them the duress password is the unlock code will def get you fucked.

        Pleading the 5th and then them entering a password found in your wallet that wipes it will get you dragged into court, but probably in a defensible position; those lawyer fees are going to be immense.

        Pleading the 5th and having your duress as 1234, which they try, would also put you in a defensible position with 10s of thousands in lawyers’ fees.

        The duress password isn’t illegal. The knowing destruction of data is. If you set it up so they’re likely to destroy the data in attempting, you’re going to get served.

        Don’t go through a border with a phone full of questionable personal data. Legal or not.

    • Bytemeister@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      9 hours ago

      Here is my problem with this interpretation…

      Is data property? Sure, ideas, concepts, photos, etc can be trademarked/copy-write protected and have some degree of ownership, but I’m talking at a much lower level here… Is the particular configuration of memory on your phone a piece of property? If no, then no property was destroyed by wiping the phone. All of the storage and memory is still intact and functional. If yes, then we must look further…is the position (not the switch itself) of a binary switch (like a light switch) a physical thing that you can own? Would you consider it destroyed if it was switched away from it’s original position?

      I don’t think you could charge him with destroying property… Destruction of evidence maybe, but the property is undamaged and functioning normally.

      Other arguments. The cop actually destroyed the data. Or, defendant claims he did not know the cops would use the pin to wipe the phone, and that they just wanted to know what the PIN was.

      I wouldn’t say there is enough evidence here to prove beyond a reasonable doubt that this guy destroyed any property in response to a search. He didn’t destroy anything, what was destroyed is arguably not property, and he may not be aware that his duress pin was going to be used on the device in the first place.

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        3 hours ago

        The video I provided covers this. There are plenty of statutes and precedents. There’s a tiny little bit of unsettled case law to be decided here that will, at best, lower his sentence a bit.

        I strongly suspect an imminent plea bargain, unless they want to use him as an example.

        • Bytemeister@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          1
          ·
          5 hours ago

          Bucees just successfully argued in court that a beaver and an alligator are visually indistinguishable to the common man…

          • rumba@lemmy.zip
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            2 hours ago

            So far, every time I’ve been outraged about Buckees, they’ve sued a small business that’s trying to file their own trademark. And while I don’t like it one bit, trademark law is more or less designed for that exact purpose. Logos don’t have to be close, they could just vaguely remind you of another established trademark. The barrier to winning is extremely low, and the fault lies with the shitty, overly vague trademark law that attempts to make trademark owners fight any possible contender.

            I don’t know if these guys were or were not trying to file a trademark, but I do know the three I looked at so far were begridgingly acceptable by trademark standards.

    • ITGuyLevi@programming.dev
      link
      fedilink
      English
      arrow-up
      7
      ·
      13 hours ago

      The issue I’m seeing with the whole case is they siezed his phone, they kept his phone, the seizure of his property happened successfully. A person later entered something they believed would open it but instead it wiped it. The end user didn’t wipe it, and didn’t lie to the agents of the state because a duress PIN is still a PIN, I’m willing to wager they didn’t specify that they wanted his ‘unlock PIN’ and instead just asked him for a PIN (personal identification number), which he gave.

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        8
        ·
        13 hours ago

        That’s court fodder, and unfortunately, I don’t believe it’ll pass.

        • ITGuyLevi@programming.dev
          link
          fedilink
          English
          arrow-up
          3
          ·
          8 hours ago

          Yeah, sadly I don’t think it will either, I’m just hoping the jury decides the precedent they truly want to set.

    • schipelblorp@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      6
      ·
      16 hours ago

      I think the application of that law depends on whether a seizure is valid (aka legal), which is kind of up in the air, as your video points out.

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        13 hours ago

        It’s unfortunately a border entry. They can do whatever they want regarding searches in that jurisdiction. He won’t get away with it being an illegal search.

        There are still outs, but they are not super likely :/

    • nymnympseudonym@piefed.social
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      11
      ·
      15 hours ago

      If he hadn’t used duress and had just refused, he’d have been fine. Graphene is secure

      Graphene devs fucked over this guy. They should apologize

      When Graphene is serious, the duress passcode will QUIETLY wipe your phone and leave it looking normal, preferably with normal-looking innocuous photos, media, etc.

      This is what happens when devs aren’t really thinking about the real world use case.

      • kestrel7_7@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        14 hours ago

        Can’t Graphene be used like this already? Dude may not have known, or may not have bothered to set up multiple profiles. But I’m pretty sure it can be done.

        • nymnympseudonym@piefed.social
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          4
          ·
          12 hours ago

          Point is that when graphene gets the distress code, it makes it really clear that it’s wiping the phone.

          That’s the Stupid Part

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        3
        ·
        13 hours ago

        Something designed like SAmsung Knox would be much better. the rest of the phone/apps are still fine.

      • GalacticRobot@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        arrow-down
        7
        ·
        14 hours ago

        They shouldn’t apologize, the dude should of known that destroying evidence during an investigation is going to land you in jail.

        • nymnympseudonym@piefed.social
          link
          fedilink
          English
          arrow-up
          12
          arrow-down
          6
          ·
          14 hours ago

          No. If you make and distribute security-related software, you should consider the safety of your user.

          Your threat model absolutely should include this exact scenario. And you should know enough to understand and implement principles like plausible deniability and repudiation.

    • technobyte@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      7 hours ago

      GrapheneOS team had already said they won’t add this as it’s significantly less secure than keeping the phone locked or wiping the data

    • northendtrooper@lemmy.ca
      link
      fedilink
      English
      arrow-up
      4
      ·
      12 hours ago

      I believe there is a child profile to allow them to play with your phone and not download or delete important stuff. I do wish there was a travel profile where you can put mock data and photos on it. Then have parameters whereas if the code is inputed (not bio) multiple times at an airport then it wipes the normal profile in the background and keeps the ‘travel’ profile.

      • Bytemeister@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        10 hours ago

        Geofence the phone. Within 5 miles of the airport, it only shows the sanitized profile.

        Outside that zone, it unlocks the encrypted data and shows you the full phone.

  • hemmes@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    17 hours ago

    What if we just say I always forget the code and use the built-in too many tries wipes the data setting?

    If you forgot the code can you offer to let them have it? Then you could wipe it remotely?

    Trying to understand what would happen if you really forgot the passcode.

    • schipelblorp@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      16 hours ago

      Unless you suffered some traumatic brain injury, nobody is going to believe you can’t unlock your phone after being in detention for 24 hours.

      It would probably be treated as an intentional wipe.

      • Nollij@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        1
        ·
        8 hours ago

        There’s already precedent that you cannot be forced to give up your passwords. It’s a 5th amendment violation. But I’m not sure if it applies to this case or not.

        • schipelblorp@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          8 hours ago

          Yeah, there’s reading the bill of rights, understanding what it means and how it was intended, and it’s another thing to understand how it’s been thoroughly chipped away at, year by year, state by state, decision by decision. You would legitimately be shocked and horrified at how many exceptions there are, and this MAY fall within one of them the–the border exception.

      • mystik@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        16 hours ago

        Perhaps the trauma of being in detention made you unable to remember it? It’s really up to the prosecution/accusers to prove it, isn’t it?