GrapheneOS sagt, sein Passwort zum Datenlöschen sei völlig legal, nachdem gegen den Benutzer Anklage auf Bundesebene erhoben wurde

    https://www.techspot.com/news/113273-grapheneos-data-wiping-duress-password-perfectly-legal-after.html

    Share.

    30 Kommentare

    1. While I personally agree, my opinion and the opinion of GrapheneOS are both irrelevant.

    2. Single-Virus4935 on

      I set my duress pin to my wifes birthday. One of the first they probably try. 

      Also I say my pin is the same as my eID which I am not allowed to share by German law

    3. Such_Difference_2248 on

      This case will show if there is still some land of the free left or if Trump has successfully turned it into an authoritarian police state.

    4. I’d just refuse to tell them 5th amendment, let their brute force attempt trigger the auto delete.

    5. The 5th amendments is clear. He has done the right thing not to cooperate incriminating himself. Law is clear on this one.

    6. NachmiasKelm-8436 on

      Getting federal charges for a feature is the best free ad GrapheneOS could ask for

    7. Tar_alcaran on

      When you’re forced to travel into an authoritarian state, don’t carry data across the border. Wipe your device before flying, or better yet, get a clean one.

    8. For it to count as him destroying evidence related to a crime surely they would at minimum need to have *some* other sort of evidence indicating that any such crime had even occured and that the phone would have likely contained evidence of it.

    9. The question isn’t if the duress pin is legal but when asked for your unlock pin if giving the duress pin is legal.

      I would likely argue it isn’t as the phone is in government custody however if this is the case you can’t ever be charged by not handing over the pin.

      A key aspect to remember the cops might do something illegal that doesn’t mean you can also do something illegal.

      The thing is logically if what you have on your phone is bad enough you are just going to hand the duress code and take the punishment rather than having the that info out.

    10. Graphene should implement a double bottom protection on top. Basically it’ll automatically enter in an artificial account with apps installed while deleting in the background the OG account. This way it’ll be hard to prove that another account did exist at all

    11. About 20 years ago I swore that I wouldn’t enter the US.

      At the same time, they were doing device-investigations where they were giving ZERO guarantees about what would happen to the data on any device they seized. Basically giving them free-reign to do anything from corporate espionage to just poking into your company’s data servers to reading everything you’ve ever done. Other countries limit that to specific law-enforcement purposes where such things are logged. In the US? Nope. Fuck you.

      So I at first said „Well, I’d never take a device (personal or corporate) into the US“ but with other stuff that started happening (e.g. enforced collection of social media handles, etc.) it became „I will just never go back to the US“.

      In later years, we had the same conversation at companies I worked for and we all agreed – nothing of the company’s electronic devices can enter the US. Every time, it was the same answer.

      Refusal at the border would likely result in your being sent back on a place, sure, I get that.

      Now you can be charged at the border for providing a duress PIN? Nah.

      I made the right decision. The US is now one of the worst dictatorships in the world, one of the most suppresive (can’t even clap at a meeting now!), one of the worst at consumer rights, human rights, employment rights. It has overbearing surveillance, outright corruption, ignorance of all measures designed to protect those laws that are being broken, etc. etc.

      Enjoy your hellhole of your own creation. It’s taken you 20 years to get there but you’re now officially „The Best“… banana republic.

    12. I can already hear the angle the govt will use is that the feature itself is not illegal but using it „to impede govt officials from investigating“ is illegal.

    13. CircumspectCapybara on

      So CBP is alleging he gave them a decoy or „panic“ / „duress“ code that’s designed to wipe the device when you enter it.

      If that’s *actually* the case, that does *potentially* cross into the territory of evidence destruction (once the device is in their possession, it and its data is considered evidence, you don’t have to tell them what’s in there and you can challenge their legal authority to hold onto it or to have taken it in the first place, but that takes place by the courts, and you can no longer just wipe it or *cause it to get wiped* without getting into legal trouble) than simply refusing to speak at all (which is always a good idea, it’s your 5th ammendment right) and not telling them any code.

      Asserting your 5th and refusing to unlock your phone is different than affirmatively giving them a code that wipes it. It’s the whole „You have the right to remain silent, but anything you do say (including special codes you give out) can and will be used against you in a court of law“ spiel.

      Proving that at trial will be the crux (they have to prove it was a duress code and he gave it knowing what it would do, rather than him misremembering and giving them the wrong code, or the officer making a mistake and entering the wrong code too many times), but if a jury believes he did intentionally give a code designed to cause a device wipe, that basically establishes intent.

      Also some common legal misconceptions I read about this:

      1. People like to say the officer entered the code so he technically caused the wipe, but In the legal system, it’s not necessarily about the direct or immediate cause of some effect (evidence going bye-bye), but about intent and the logical chain of events that led to it (its „proximate cause“), which is why juries are able to see through that, past the immediate cause to its proximate causation.
      2. As for how they can seize a phone or ask you to unlock it without a warrant, it’s at the border, where they have increased powers to do that without a warrant. SCOTUS has upheld that and somehow squared it with the constitution, though I don’t necessarily agree.
      3. „It’s not a device wipe it just evicts the decryption key from volatile memory or restarts the device (which was the same effect) / or in some designs deletes the key from disk, so the data is still there, it’s just (forever) unreadable“. Yeah, you gotta remember *the spirit of the law*. Erasing 32 bytes of data from a region of disk could be legally taken to be wiping the whole device if it was the decryption key (encrypted while on disk by the user’s passcode) and renders the logical data inaccessible. In fact in modern designs the „wipe my device“ button just erases the key from storage, because after that, the entire disk becomes effectively random data.

    14. Headline is misleading;

      >The GrapheneOS Foundation has since tried to downplay the importance of duress passwords for the platform’s security. The feature, the organization said, is just a minor option within a much broader security model. It can also carry physical or legal consequences, which is why users should carefully weigh whether it’s the right approach for outsmarting attackers or coercive enforcement attempts by federal agents.

    15. This whole prosecution shoud be tossed by any competent judge in the US simply on 5th amendment grounds-we have the right to not incriminate ourselves. Sadly, civil rights are shrinking with every passing day.

    16. hand_me_a_shovel on

      So maybe what we need is a „curated duress PIN“ that instead of just wiping the phone, replaces existing data with a curated set of false data that reveals nothing and does not indicate you actually wiped it.

    17. We should not have to explain or argue that our data is our own.

      Of course it’s legal.

    18. Scared_Specific9404 on

      smart move is to have a feature where a 2nd password deletes only some pre selected data so the pigs never even notice anything.

    19. Would they be so lazy stupid if it was a password to disable a bomb?

      This is just the TSA or admin being cavalier thinking their powers somehow magically enables them to attain whatever they want. It’s their modus operandi.

    Leave A Reply