While I personally agree, my opinion and the opinion of GrapheneOS are both irrelevant.
Needle_Bearings on
Holy 4th Amendment Batman, let’s see where this goes.
Single-Virus4935 on
I set my duress pin to my wifes birthday. One of the first they probably try.
Also I say my pin is the same as my eID which I am not allowed to share by German law
mangosawce9k on
Cops are just greedy.
Such_Difference_2248 on
This case will show if there is still some land of the free left or if Trump has successfully turned it into an authoritarian police state.
Autoxquattro on
Thou shall not stop the surveillance state.
spaceursid on
I’d just refuse to tell them 5th amendment, let their brute force attempt trigger the auto delete.
The_SubGenius on
This administration is a joke and works harder every day to prove it.
Fuzzy_Paul on
The 5th amendments is clear. He has done the right thing not to cooperate incriminating himself. Law is clear on this one.
NachmiasKelm-8436 on
Getting federal charges for a feature is the best free ad GrapheneOS could ask for
Tar_alcaran on
When you’re forced to travel into an authoritarian state, don’t carry data across the border. Wipe your device before flying, or better yet, get a clean one.
zutnoq on
For it to count as him destroying evidence related to a crime surely they would at minimum need to have *some* other sort of evidence indicating that any such crime had even occured and that the phone would have likely contained evidence of it.
toolkitxx on
Good there is a 5th amendment.
HarithBK on
The question isn’t if the duress pin is legal but when asked for your unlock pin if giving the duress pin is legal.
I would likely argue it isn’t as the phone is in government custody however if this is the case you can’t ever be charged by not handing over the pin.
A key aspect to remember the cops might do something illegal that doesn’t mean you can also do something illegal.
The thing is logically if what you have on your phone is bad enough you are just going to hand the duress code and take the punishment rather than having the that info out.
Moldoteck on
Graphene should implement a double bottom protection on top. Basically it’ll automatically enter in an artificial account with apps installed while deleting in the background the OG account. This way it’ll be hard to prove that another account did exist at all
ledow on
About 20 years ago I swore that I wouldn’t enter the US.
At the same time, they were doing device-investigations where they were giving ZERO guarantees about what would happen to the data on any device they seized. Basically giving them free-reign to do anything from corporate espionage to just poking into your company’s data servers to reading everything you’ve ever done. Other countries limit that to specific law-enforcement purposes where such things are logged. In the US? Nope. Fuck you.
So I at first said „Well, I’d never take a device (personal or corporate) into the US“ but with other stuff that started happening (e.g. enforced collection of social media handles, etc.) it became „I will just never go back to the US“.
In later years, we had the same conversation at companies I worked for and we all agreed – nothing of the company’s electronic devices can enter the US. Every time, it was the same answer.
Refusal at the border would likely result in your being sent back on a place, sure, I get that.
Now you can be charged at the border for providing a duress PIN? Nah.
I made the right decision. The US is now one of the worst dictatorships in the world, one of the most suppresive (can’t even clap at a meeting now!), one of the worst at consumer rights, human rights, employment rights. It has overbearing surveillance, outright corruption, ignorance of all measures designed to protect those laws that are being broken, etc. etc.
Enjoy your hellhole of your own creation. It’s taken you 20 years to get there but you’re now officially „The Best“… banana republic.
trevx on
Apparently not in “the land of the free”.
Pirwzy on
I can already hear the angle the govt will use is that the feature itself is not illegal but using it „to impede govt officials from investigating“ is illegal.
CircumspectCapybara on
So CBP is alleging he gave them a decoy or „panic“ / „duress“ code that’s designed to wipe the device when you enter it.
If that’s *actually* the case, that does *potentially* cross into the territory of evidence destruction (once the device is in their possession, it and its data is considered evidence, you don’t have to tell them what’s in there and you can challenge their legal authority to hold onto it or to have taken it in the first place, but that takes place by the courts, and you can no longer just wipe it or *cause it to get wiped* without getting into legal trouble) than simply refusing to speak at all (which is always a good idea, it’s your 5th ammendment right) and not telling them any code.
Asserting your 5th and refusing to unlock your phone is different than affirmatively giving them a code that wipes it. It’s the whole „You have the right to remain silent, but anything you do say (including special codes you give out) can and will be used against you in a court of law“ spiel.
Proving that at trial will be the crux (they have to prove it was a duress code and he gave it knowing what it would do, rather than him misremembering and giving them the wrong code, or the officer making a mistake and entering the wrong code too many times), but if a jury believes he did intentionally give a code designed to cause a device wipe, that basically establishes intent.
Also some common legal misconceptions I read about this:
1. People like to say the officer entered the code so he technically caused the wipe, but In the legal system, it’s not necessarily about the direct or immediate cause of some effect (evidence going bye-bye), but about intent and the logical chain of events that led to it (its „proximate cause“), which is why juries are able to see through that, past the immediate cause to its proximate causation.
2. As for how they can seize a phone or ask you to unlock it without a warrant, it’s at the border, where they have increased powers to do that without a warrant. SCOTUS has upheld that and somehow squared it with the constitution, though I don’t necessarily agree.
3. „It’s not a device wipe it just evicts the decryption key from volatile memory or restarts the device (which was the same effect) / or in some designs deletes the key from disk, so the data is still there, it’s just (forever) unreadable“. Yeah, you gotta remember *the spirit of the law*. Erasing 32 bytes of data from a region of disk could be legally taken to be wiping the whole device if it was the decryption key (encrypted while on disk by the user’s passcode) and renders the logical data inaccessible. In fact in modern designs the „wipe my device“ button just erases the key from storage, because after that, the entire disk becomes effectively random data.
lolschrauber on
Deleting your own data on your own device is terrorism!
CanadianGenealogy on
Remember when SCOTUS ruled it’s ok for cops to lie?
stirling_s on
Headline is misleading;
>The GrapheneOS Foundation has since tried to downplay the importance of duress passwords for the platform’s security. The feature, the organization said, is just a minor option within a much broader security model. It can also carry physical or legal consequences, which is why users should carefully weigh whether it’s the right approach for outsmarting attackers or coercive enforcement attempts by federal agents.
FanDry5374 on
This whole prosecution shoud be tossed by any competent judge in the US simply on 5th amendment grounds-we have the right to not incriminate ourselves. Sadly, civil rights are shrinking with every passing day.
hand_me_a_shovel on
So maybe what we need is a „curated duress PIN“ that instead of just wiping the phone, replaces existing data with a curated set of false data that reveals nothing and does not indicate you actually wiped it.
shadowdra126 on
I wish I could have this on my iPhone.
SCphotog on
We should not have to explain or argue that our data is our own.
Of course it’s legal.
Scared_Specific9404 on
smart move is to have a feature where a 2nd password deletes only some pre selected data so the pigs never even notice anything.
360_face_palm on
My kitchen knives are also totally legal.
vurto on
Would they be so lazy stupid if it was a password to disable a bomb?
This is just the TSA or admin being cavalier thinking their powers somehow magically enables them to attain whatever they want. It’s their modus operandi.
DesiOtaku on
This is not new. Back in 2019, [an Apple employee was detained by border police for refusing to give agents his company phone](https://www.businessinsider.com/andreas-gal-aclu-cbp-phone-laptop-2019-4?op=1) which had a lot of information covered under an NDA. He was eventually released but has to go through secondary security each time he travels.
Leave A Reply
Du musst angemeldet sein, um einen Kommentar abzugeben.
30 Kommentare
While I personally agree, my opinion and the opinion of GrapheneOS are both irrelevant.
Holy 4th Amendment Batman, let’s see where this goes.
I set my duress pin to my wifes birthday. One of the first they probably try.
Also I say my pin is the same as my eID which I am not allowed to share by German law
Cops are just greedy.
This case will show if there is still some land of the free left or if Trump has successfully turned it into an authoritarian police state.
Thou shall not stop the surveillance state.
I’d just refuse to tell them 5th amendment, let their brute force attempt trigger the auto delete.
This administration is a joke and works harder every day to prove it.
The 5th amendments is clear. He has done the right thing not to cooperate incriminating himself. Law is clear on this one.
Getting federal charges for a feature is the best free ad GrapheneOS could ask for
When you’re forced to travel into an authoritarian state, don’t carry data across the border. Wipe your device before flying, or better yet, get a clean one.
For it to count as him destroying evidence related to a crime surely they would at minimum need to have *some* other sort of evidence indicating that any such crime had even occured and that the phone would have likely contained evidence of it.
Good there is a 5th amendment.
The question isn’t if the duress pin is legal but when asked for your unlock pin if giving the duress pin is legal.
I would likely argue it isn’t as the phone is in government custody however if this is the case you can’t ever be charged by not handing over the pin.
A key aspect to remember the cops might do something illegal that doesn’t mean you can also do something illegal.
The thing is logically if what you have on your phone is bad enough you are just going to hand the duress code and take the punishment rather than having the that info out.
Graphene should implement a double bottom protection on top. Basically it’ll automatically enter in an artificial account with apps installed while deleting in the background the OG account. This way it’ll be hard to prove that another account did exist at all
About 20 years ago I swore that I wouldn’t enter the US.
At the same time, they were doing device-investigations where they were giving ZERO guarantees about what would happen to the data on any device they seized. Basically giving them free-reign to do anything from corporate espionage to just poking into your company’s data servers to reading everything you’ve ever done. Other countries limit that to specific law-enforcement purposes where such things are logged. In the US? Nope. Fuck you.
So I at first said „Well, I’d never take a device (personal or corporate) into the US“ but with other stuff that started happening (e.g. enforced collection of social media handles, etc.) it became „I will just never go back to the US“.
In later years, we had the same conversation at companies I worked for and we all agreed – nothing of the company’s electronic devices can enter the US. Every time, it was the same answer.
Refusal at the border would likely result in your being sent back on a place, sure, I get that.
Now you can be charged at the border for providing a duress PIN? Nah.
I made the right decision. The US is now one of the worst dictatorships in the world, one of the most suppresive (can’t even clap at a meeting now!), one of the worst at consumer rights, human rights, employment rights. It has overbearing surveillance, outright corruption, ignorance of all measures designed to protect those laws that are being broken, etc. etc.
Enjoy your hellhole of your own creation. It’s taken you 20 years to get there but you’re now officially „The Best“… banana republic.
Apparently not in “the land of the free”.
I can already hear the angle the govt will use is that the feature itself is not illegal but using it „to impede govt officials from investigating“ is illegal.
So CBP is alleging he gave them a decoy or „panic“ / „duress“ code that’s designed to wipe the device when you enter it.
If that’s *actually* the case, that does *potentially* cross into the territory of evidence destruction (once the device is in their possession, it and its data is considered evidence, you don’t have to tell them what’s in there and you can challenge their legal authority to hold onto it or to have taken it in the first place, but that takes place by the courts, and you can no longer just wipe it or *cause it to get wiped* without getting into legal trouble) than simply refusing to speak at all (which is always a good idea, it’s your 5th ammendment right) and not telling them any code.
Asserting your 5th and refusing to unlock your phone is different than affirmatively giving them a code that wipes it. It’s the whole „You have the right to remain silent, but anything you do say (including special codes you give out) can and will be used against you in a court of law“ spiel.
Proving that at trial will be the crux (they have to prove it was a duress code and he gave it knowing what it would do, rather than him misremembering and giving them the wrong code, or the officer making a mistake and entering the wrong code too many times), but if a jury believes he did intentionally give a code designed to cause a device wipe, that basically establishes intent.
Also some common legal misconceptions I read about this:
1. People like to say the officer entered the code so he technically caused the wipe, but In the legal system, it’s not necessarily about the direct or immediate cause of some effect (evidence going bye-bye), but about intent and the logical chain of events that led to it (its „proximate cause“), which is why juries are able to see through that, past the immediate cause to its proximate causation.
2. As for how they can seize a phone or ask you to unlock it without a warrant, it’s at the border, where they have increased powers to do that without a warrant. SCOTUS has upheld that and somehow squared it with the constitution, though I don’t necessarily agree.
3. „It’s not a device wipe it just evicts the decryption key from volatile memory or restarts the device (which was the same effect) / or in some designs deletes the key from disk, so the data is still there, it’s just (forever) unreadable“. Yeah, you gotta remember *the spirit of the law*. Erasing 32 bytes of data from a region of disk could be legally taken to be wiping the whole device if it was the decryption key (encrypted while on disk by the user’s passcode) and renders the logical data inaccessible. In fact in modern designs the „wipe my device“ button just erases the key from storage, because after that, the entire disk becomes effectively random data.
Deleting your own data on your own device is terrorism!
Remember when SCOTUS ruled it’s ok for cops to lie?
Headline is misleading;
>The GrapheneOS Foundation has since tried to downplay the importance of duress passwords for the platform’s security. The feature, the organization said, is just a minor option within a much broader security model. It can also carry physical or legal consequences, which is why users should carefully weigh whether it’s the right approach for outsmarting attackers or coercive enforcement attempts by federal agents.
This whole prosecution shoud be tossed by any competent judge in the US simply on 5th amendment grounds-we have the right to not incriminate ourselves. Sadly, civil rights are shrinking with every passing day.
So maybe what we need is a „curated duress PIN“ that instead of just wiping the phone, replaces existing data with a curated set of false data that reveals nothing and does not indicate you actually wiped it.
I wish I could have this on my iPhone.
We should not have to explain or argue that our data is our own.
Of course it’s legal.
smart move is to have a feature where a 2nd password deletes only some pre selected data so the pigs never even notice anything.
My kitchen knives are also totally legal.
Would they be so lazy stupid if it was a password to disable a bomb?
This is just the TSA or admin being cavalier thinking their powers somehow magically enables them to attain whatever they want. It’s their modus operandi.
This is not new. Back in 2019, [an Apple employee was detained by border police for refusing to give agents his company phone](https://www.businessinsider.com/andreas-gal-aclu-cbp-phone-laptop-2019-4?op=1) which had a lot of information covered under an NDA. He was eventually released but has to go through secondary security each time he travels.