I’ve seen a lot of people on the internet over the years say things like “the government can’t make x illegal, it’s just y.” For example, the government can’t make wiping your phone at the border illegal, it’s just punching four numbers into your phone, just like a pin, only a different four numbers, which could just have well been your pin.
U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did. Hell there could have been a third set of four numbers that were the nuclear launch codes. It’s not the fact that it was four numbers, it’s what you were trying to make happen when you typed them. Now of course whether they can prove what your intent was when you typed them is another matter, but generally a duress pin should be for when robbers are breaking into your house, and the government will be on your side, and not when the government will be against you.
"U.S. law though is highly non-autistic" hilarious but also another point to emphasize is how truly depressing American courts often are. Take the right to a jury. It sounds noble in theory. But when they say judged by your peers they don't mean your actual peers.
It's people who couldn't get out of jury duty. Prosecutors have high success rates. Federal prosecutor success rate is over > 90%. Studies of jury psychology show how much peer pressure and other factors extrinsic to the law come into play.
Remember what happened to Aaron Swartz. Law is the mask of power. By all means defend and assert your rights, but understand the costs. I find people are under such illusions about how cruel the American justice system is that this leads them to make foolish decisions. Do not underestimate the adversarial nature of the justice system, nor the accompanying incentives agents of the state who are on the other side of you have to lie.
Federal prosecutors won't even pursue cases unless they think there's a high chance of success. They don't operate like two private parties suing each other to force the court to decide something. If the evidence is there or the charges aren't fully formed, they don't waste resources on it.
This leads to a contradictory set of complaints that the legal system lets too many people go or doesn't have enough teeth.
I don't think it's so much a "misunderstood" statistic as much as a number that people (like the commenter you are replying to) deliberately trot out to use as evidence for their position because they are depending on most people being statistically illiterate.
To be clear, I totally agree with your points, I just think this is more of a case of "lying with statistics" than being a misunderstanding.
OP is strongly implying that the 90% success rate for prosecutors is due to the courts being stacked against the defense. IMO that is where the logical fallacy is. Since prosecutors have wide latitude in deciding which cases to charge in the first place, it is very possible that the high success rate is due to prosecutors only charging cases where the accused actually committed the crimes being charged. Indeed, for the ~10% of cases where the accused is not found guilty, about 8% are due to the government dropping the case - only 1% are the jury acquitting the defendant outright. Thus, it would appear from that data that when the prosecution sees they are not likely to win a case, they drop it.
I'm making no argument that the courts or law are "fair", I'm just making the argument that quoting the 90% number is in no way evidence that courts are inherently biased towards the prosecution.
Exactly. People complain police dont prevent crime, but dont realize that is not their purpose. The police exist to protect the government, not the people.
It’s not even just who couldn’t get out of it. It’s filtered for people who answer honestly. I was disqualified for a grand jury because the judge asked me if I would believe the testimony of police officers as truthful and I said it would depend on the police officer.
The system already had their hands forced on accepting that some cops lie with Brady disclosures but the fact that I didn’t just naively accept police testimony meant I was an unscramble juror.
Even if you’re a true believer in the system you won’t be allowed to participate because you didn’t lie.
Programmers have trouble seeing color (two identical numbers are the same bits, how can typing '1234' to unlock one phone be legal, and '1234' to unlock another phone be illegal?)
Courts care about color (intent, provenance, permission), even though that color cannot be digitally represented.
A lot of engineer types forget that the law is not code, and reductionist arguments almost never actually work in practice because it's a human interpreting the law.
It reminds me of tax law in many countries. You can follow the letter of the law, but if the vibes are off, you can still be found to be in breach of a vague catch-all provision (e.g. economic substance doctorine in the US, GAAR in Canada/UK, Part IVA in Australia, etc).
A duress pin is useful if the cost of the government getting mad at you because you wiped your data is less than the cost of letting the government have your data. Whether that holds depends on your situation - for example, whether your phone's data could implicate other people that you want to protect
It's kind of funny and also kind of insulting. I'd laugh if a friend said it but said seriously by some rando on the Internet, nah, find a better way to put it.
In this case, the government was against him due to his activism against a police training campus.
Him deleting his phone was very likely a matter of safety for his fellow activists. Sad that our government does this but it’s not like this guy was a drug dealing or something.
I'm waiting to see whether he is convicted before I form a strong opinion around this. I'm leaning toward thinking this case will be dropped or at least severely reduced charges.
When I had jury duty it was quite revealing as far as “this is all evidence including people’s testimony, you can believe all or some or none of a given piece of evidence based on your own judgment” goes.
When we met it was interesting how our jurors decided “I don’t believe anything that guy says” and so on when it came to their motives and so on.
The trial itself was very carefully choreographed, almost pre determined and static.
But the decisions and jury activity was very dynamic. There was absolutely no magic legal mechanisms at that point.
I think people are aware that the government can physically do a lot of stuff, e.g. shoot you in the face for no reason. And vice-versa for that matter.
However there are arguments morally, and constitutionally, and logically, about what can be done.
Yes, this is something more people really need to take to heart. As Americans are seeing, a lot of rules are unenforceable and really came down to norms and pressure. I have been thinking about this a lot over the last few years and it is roughly encapsulated in this tweet I saw a while back.
When I was a kid I wanted to be a police officer because I wouldn't have to follow any laws or rules. Then I got a little bit older and realized that wasn't how being a police officer actually worked in practice. Then, I got a little bit older than that, and realized that it actually does work like that.
This has always been true and there has never really been perfect justice. Ultimately, power and violence have always superseded the law. High trust societies with less corruption and a strong justice system try to limit these circumstances.
> This has always been true and there has never really been perfect justice.
You raise the standard for justice to perfection. There also has never been perfect corruption and anarchy.
> Ultimately, power and violence have always superseded the law.
That's like saying night has always superceded day. Everyone recognizes that recent years have been very unusual or unique in US history. That means for the great bulk of US history, it was different. Why doesn't 99% of US history outweigh the 1% (picking numbers very loosely) in determining what is somehow inevitable to you.
In fact, law is universal among human cultures. We are naturally social and live in groups with rules. Those that violate rules are generally outcasts.
But the most fundamental and significant error is attributing the current situation to some unavoidable system instead of the actions of people, especially those that stand aside and allow these things to happen. Many of them stand aside because they are told - probably messaging ultimately from the lawbreakers - that they are powerless and should despair.
When the judge and officers of the court agree with me, the law is reasonable and just, but when they do not agree with me, the law is arbitrary and capricious. ¯\_(ツ)_/¯
Having the law be whatever it's thought to be by police, prosectors, judges, and others can lead to obvious injustices, but there's been no serious attempt to remove ambiguity in any country's legal code as far as I know.
Ultimately, when you choose to enter a duress PIN that will wipe your device, you have to recognize that choice may have legal consequences. I don't like the amount of power our government has at the national border when it comes to detaining and pressuring citizens, but our Constitution explicitly grants it at least some of the power it now exercises in that context.
If your threat model includes US state actors at the national border, then your security practices need to account for the confiscation of your device at that border without requiring you to willfully wipe the phone and (in the eyes of police and prosecutors) destroy evidence.
That means:
1. Don't travel with anything you can't afford to lose on device. This means setting up travel-specific password managers and hardware keys for a subset of your accounts that you absolutely need to access while abroad, and being prepared to reset those passwords and disable those hardware keys very quickly once home.
2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. Your secure setup must function without needing you to engage in those behaviors, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable.
3. Consult with a lawyer and review your security procedures from a legal standpoint. All of the above is technical and practical advice, not legal counsel and no substitute for it.
We Americans are fortunate to carry powerful passports and enjoy relatively easy international travel but, for better or worse, that velvet glove covers an iron fist we would be foolish to forget or ignore.
Have the duress PIN on sticker on your phone. Maybe put it backwards and don’t say anything to border patrol. Have them try it out and erase the phone and then you can legitimately say you didn’t do anything and they did it themselves.
But if the prosecutors can make a convincing argument that your intent was exactly that all along, then you may end up convicted anyway.
Intent matters. It might be hard to prove, but it matters.
It may not even be that hard; what other possible explanation is there for someone putting a PIN visible on their phone that wipes it while crossing a border?
Why would agents think that a number written on your phone is the PIN? That would only make sense if it was a communally-used device, not a personal one. Also, no one would put sensitive info on a devices that has the PIN affixed to it.
I suppose it's possible someone might enter it without thinking, but the odds seem low. Also seems risky to put a self-destruct PIN on your device, lest a friend (or enemy) enter it by accident or as a prank.
the funny part is he didn't enter the pin he gave it to them and they entered it..., not sure if it makes any difference but there is a certain irony to it that it was the non warrant based search actions (which might be legal at the border) which lead to the erasure of data
> It exists for when compromising the device could get people the owner cares about killed or disappeared and the owner considers their own liability, disappearance, or death a preferable outcome.
Or it's preferable to get caught lying to a federal officer than it is for them to have the evidence on your phone.
but not necessary evidence, as evidence would imply a crime. But when it comes to police harassing activists, or outright mislabeling them as terrorists, there are many fully legal things you still might prefer the police not to have. Lets not forget that boarder police has in the past tried absurd things like trying to seize Attorney-client privilege protected information from a US attorney.
Through most likely many people setting up and using a duress pins never truly think this thought from a legal POV.
They asked for the pin, maybe they should have said "not the duress pin"
>Destroying evidence
How did they know there was any evidence on there?
>it exists for when compromising the device could get people the owner cares about killed or disappeared and the owner considers their own liability, disappearance, or death a preferable outcome.
No, the duress pin is there for when I'm under duress and being forced to unlock my device against my will
> They asked for the pin, maybe they should have said "not the duress pin"
This is a Mickey Mouse distinction no court will take seriously.
> Wiping a device I own is extreme?
When the consequences are potential years in prison for lying to the US government or, in another country, torture or death in prison for obstructing an authoritarian government, then yes... Extreme.
All I'm saying is to decide to use a duress PIN at any national border or in any foreign country soberly, with knowledge of the potential or likely consequences.
That's a different discussion. Are you interested in staying out of trouble at the border? Or are you interested in taking down the system (or at least fixing it)?
If you think the system needs fixed or destroyed, you do you, but don't be surprised when that approach gets you in trouble at the border.
It's sad that your perfectly valid previous comment is dead (and that HN even works that way) ... adding is ≠ ought probably doesn't even help for the people who don't grasp that in the first place.
People who think that tricking the cops into wiping your device legally absolves you need to grow up. Also those who argue that LE can't prove any evidence was destroyed since it's been destroyed.
you had answers here. I'm trying to understand why our leaders can get away with lying so much and it being obviously in the public record, with videos on YouTube etc, and there being no recourse or accountability?
Is it true that the law is only selectively applied to some people?
> President Trump has issued a pardon to his first national security adviser, Michael Flynn. Flynn had pleaded guilty to lying to the FBI and then recanted.
"Rules for thee but not for me" - isn't that beyond obvious now? The folks running things simply do not play by the rules you or I do (assuming you do).
Generally yes, unfortunately, with very narrow exceptions. Not all countries follow this rule, but the US does, and it’s certainly not alone in this respect.
I’ve been arguing against some LLMs about this point for a good hour and there’s a whole lot of linking intent to action where you can be liable if a court can prove it. Not that an LLM is legal gold but it’s the best thing I have to pass ideas around with.
The entire situation is sort of nonsensical and boils down to lots of minutia in law that no normal person would know about.
For example having normal widely known security features like wiping the device after N failed PIN attempts is fine. Even having long standing security practices that can’t be related are fine, like having a timed touch point where if you don’t enter the PIN every… 15 days or whatever the device wipes, perfectly fine if it can’t be connected towards the crime and you’re not compelled to tell officers you have such a security mechanism.
Even if you were to set a trap where you use the same PIN for your bank, your laptop, and some other security devices in repetition then decide to set your duress PIN to that by assuming it would be discovered as a probable option they’d use, you’d be ok but it could be questionable if that was by design…
It’s so obscure really as to how and how you’re not allowed to protect your data, even if you’re not the one performing the action to clear destroy the potential evidence yourself. The entire thing seems pretty absurd a frankly arbitrary to me, and I don’t know how people could know which cases are and aren’t legal. I know not to destroy evidence myself but I wouldn’t know to tell someone to not use the duress pin or that even giving them my duress pin could somehow be my liability. It’s madness if you ask me.
Well I don’t have any legal need to hire a lawyer or anything I would need a lawyer for. It’s a rather fast way to surface legal information and precedent. I don’t see how it’s any more depressing than Google diving on a topic you’re interested in for an hour..
Who said it was evidence? Did a judge authorize or issue a warrant to collect said evidence? Absent that, it's just your property, and you can do with it as you please.
"Investigation" is a pretty generous way to label "some thugs working for an authoritarian state want to look for incriminating stuff - including criticism or mockery of them or their leader - on your communications device".
Whatever the American legal system may say, a couple of thugs with no warrant conducting searches and seizures of data is a blatant violation of the Constitution's intent. This is the sort of behavior Americans used to rightfully condemn.
"Evidence" has never been limited to the subject of a warrant. Destruction of evidence statutes typically include material that is subject to a police investigation.
To me it’s all quite analogous to walking up to, but not crossing, a border with, say, a fruit that’s legal to possess on the side you’re on, but not on the other side, and either eating or throwing away that fruit before crossing.
“Hey! I saw you holding that Mexican pepper in Mexico, and then you threw it in that Mexican trash can before crossing into Texas!”
But that's not what happened here. Here, you were trying to bring the pepper over, got inspected and somehow got rid of it because you were able to be found out.
> Who said it was evidence? Did a judge authorize or issue a warrant to collect said evidence? Absent that, it's just your property, and you can do with it as you please.
Why do people go sovereign citizen when reality doesn't work their way? Stop imagining that the way you want things to be is the way things really are.
Cops do not need a judge to authorize the seizing of evidence. Cops do not need judges to decide what evidence is. Tell me, why did you just pretend like these are real requirements? I can understand why you'd want it to be that, but you wanting it to be that doesn't change reality.
It's as if you've just learned about the Fourth Amendment but know nothing about the nuance behind it.
Your system wouldn't even work at all. Let's imagine the cops get a tip that a bald man with a blue tshirt shot a man. They patrol the streets and find a match. By your logic they should not have the ability to search the man and seize his gun as evidence until a judge issues a warrant.
Yes this is different than when law enforcement serve a warrant and the defendant wipes his computer before the agents can get a hold of it. In that case the warrant covers what you destroyed as evidence.
Though during traffic stops, if a defendant disposes of his drugs while on the run, that can also carry a charge of destroying evidence even though no warrant was issued.
Hm but the drugs are only evidence because they're illegal? So the phone owner only destroyed evidence if the phone contained something illegal, but innocent until proben guilty?
Why the hell doesn't the "duress PIN" just open up a sanitary profile? Bonus points for letting you set it up with plausible data before designating it as the duress profile that, when opened, wipes your real profile in the background.
> "the screen went blank, flashed several times, and the phone appeared to restart,"
How about flash some red lights and play an airhorn sound effect, too.
VeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give proper password, real OS and FS decrypt and load.
Something like this may need to become the standars over duress pins which should be treated as a fallback or more extreme alternative. Right now, A single choice to reasonably and rightfully protect your privacy reuslts in jail time over something which likely wouldnt have resulted in any issues if superficial compliance was observed.
These goons, even if a branch of a facist regime, are ultimately burocrats with violent options to settle. They aren't doing forensics on your device etc. They have neither means nor knowledge to do so. They just need to tick their boxes. Did the phone unlock? tick. Did our spyware complain? no? tick. Overall appearance of compliance from person? yes? tick. free to go, next!
You just have to find ways to stay safe without agitating their workflow and all is well.
this will likely fail as block devices aren't dumb anymore, the firmware state will out the hidden volume. counting on the laziness/unsophistication of an adversary isn't a great move.
this problem may be solvable by a purpose-built abstraction where every write no matter what address will look identical to the firmware (naively, a randomized key-value map).
Modern SSDs are log-structured under the hood. The presentation to the host system as a random access block device is an abstraction on top of that, emulating the semantics of spinning rust. Inspecting the underlying log will reveal the location of the hidden area, even if it looks random when read linearly.
I’m not so sure that log structure would reveal to you VeraCrypt style hidden volumes. It would only tell you about which blocks are allocated but the whole point is that VeraCrypt would allocate the whole space and within it have hidden space. You wouldn’t be able to infer (at least ethically, but you could lie) whether or not a hidden partition exists because you don’t know if the allocated block is present in the filesystem or was just allocated and never trimmed.
It would also give you information about the order in which blocks were written, and the historical state of the disk. Because of wear leveling, block allocation isn't just a one-time initial thing; the mappings between logical and physical address space are changing with each write.
SSD/NVMe keep track of what regions are wiped and which contain data that has to be preserved. To hide something in the seemingly-unused space, you have to turn off trim, eat the performance cost, and pretend you had a reason to have turned off trim.
I don't believe having trim disabled even helps here. smart firmware sees the same address being written to and may therefore reassign it to a different cell for wear leveling. it's a de facto trim.
trim lets the firmware know which mappings it can discard without the explicit reuse of the same address.
however I don't believe you can observe this effect from trim command results, it will report the usual size trimmed as if the firmware never realized that you reused the same address range multiple times.
Even in places where you can’t be compelled to hand over a password, attempting to deceive the cops will get you thrown in prison just as reliably as destroying evidence.
Sometimes it's used to uncover crimes, but very often it's used to invent crimes that never actually happened, or used to deceive a courtroom when they don't actually have evidence.
It’s also a fairly traumatic thing to people through and I can imagine it does a lot of damage to people’s faith in law enforcement. Personal anecdote: when I was a teenager some cops gave me a list of fabricated evidence that I’d committed a crime, not intending to ever show a court; just trying to get me to confess. They said they’d go easy on me if I confessed but if I held out then they would petition the court to have me tried as an adult and sent to “big boy” prison. They also told me my parents were cooperating in the investigation and didn’t tell me. The whole ordeal basically made sure no one in my previously quite pro-cop family would ever trust an LEO again.
true, but in that scenario you're going to prison either way. If you legitimately use the dummy for daily driving and hidden for sensitive work, then it's better than nothing.
Obviously a good alternative is a dummy device but it carries similar risks, and the best option is to simply not go to authoritarian shitholes like the USA. Thankfully I've been able to avoid/push for US folks visiting us instead, but honestly the alternatives are as bad.
Its a shit situation where most reasonable actions carry real risks, its up to individuals to choose what is acceptable risk to them, but a dummy os you use as a daily driver for inconsequential work is, to me, an ideal midground.
>VeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give proper password, real OS and FS decrypt and load.
Implementing it in a convincing way is harder than you think. Moreover if you're under the type of regime that will throw you in jail for not giving up a password, they're probably not going to let you off the hook because they can't definitively prove you have a hidden volume.
I could be wrong, but my understanding is that the dummy OS views the remaining space as legitimate and accessible free space. Using dummy directly is of course dangerous, as you might overwrite sectors with legitimate data, but also, you can access dummy os from secret. so you'd drive dummy from secret to prevent that but can load dummy as main if under duress and it looks fine. Browser, logged into various inconsequential things, random files for inoffensive memes and other human stuff in downloads folder etc. maybe an email account you've signed up to a few newsletters and e-stores that send spam logging in via an email client that auto-launches etc.
Done well, I see no reason it should raise redflags in routine stops, so unless you're being targeted (at which point you've got way bigger problems) it should just seem like you're a run of the mill person who does not use their device to its full capacity, which is the majority of users.
at some point, having any mitigations even present is a problem. At some point being met with a boot password at all is a problem that puts you on a list. I have no solution there other than to not go to those countries or keep dummy hot.
If you read the linked thread, you'd see the reasons are:
1. SSDs (including phones) have TRIM/discard, so you need to disable it, otherwise the hidden volume would get wiped. You going out of your way to disable it is going to be suspicious.
2. Even if the above wasn't an issue, you can't really use the outer os to any meaningful extent, because you run the risk of overwriting the inner volume. That makes your decoy os suspicious. It's not definitive proof you have a hidden volume, but I doubt the authorities would care too much about that.
I last used this feature probably more than a decade ago, but: you provide 2 passwords when decrypting. If the first password is the main volume, the second is attempted as a hidden volume. If both match, the main volume registers the hidden volume as free space but prevents writing to it. If the hidden volume doesn't match, the main volume will clobber the hidden volume.
So the main/hidden volumes really works like a duress: you might destroy your hidden volume while using the main one under duress, but that does not apply when using the main volume while able to additionally unlock the hidden volume.
If you are in a situation to need to worry about any of this, you're probably going to jail for one reason or another, anyways.
This seems like the kind of thing that would put US citizens in way more legal jeopardy than just using a secure phone with a long password, refusing to unlock it, and buying a new one if the officers involved confiscate it out of spite.
This is always been the dumbest thing about "hidden volumes": It relies upon your adversary not knowing about veracrypt's hidden volume. Which BTW, is plainly ADVERTISED on the web site. The second he knows you have veracode, he will ask for the other encrypted volume.
If your threat model means you can’t afford for border security to view your device, wipe the damn thing yourself before crossing the border and restore it from an encrypted online backup on the other side.
You’re just carrying a blank phone that you intend to set up and use later, and they can’t force you to install your backup onto a phone.
Now, this is sus as hell, and you’ll probably draw all kinds of extra attention, but if border security wants access to your phone in the first place, you’re already in a weird place.
Pff one time when travelling to the US I brought two laptops, macbook and a thinkpad. I just reinstalled the thinkpad and somehow the border patrol was very interested in it. Asked me to ‘show my gallery’… it was a guiless setup and only had a terminal, problem was… somehow my keyboard layout or something was messed up and i could not even login… i spend around 2 hours being questioned by 6 people…they didnt even take a look at the macbook
this isn't even that weird, when I worked in a BigTech it was pretty explicit that there were certain countries where you should not bring your actual work device through the border, and you'll get set up with a different one while in that country.
> federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City
Of course it’s about that huh. It’s quite scary how far the US will go against anyone who engages in this sort of activism.
How are they going to prove there was evidence of a crime? While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device".
Most previous court cases involving encrypted devices have required substantial proof that the encrypted device contained incriminating evidence. To be clear "you sent this illegal thing from your house" levels of evidence.
It mostly seems inept, if you are going to push to expand your powers you do it on strong cases where you know what happened. Doing it on weak cases like this gives a judge an opportunity to shut down that without giving you a chance of a meaningful conviction and without that you won't get any benefits...
>How are they going to prove there was evidence of a crime?
They don't have to, only that you destroyed evidence. That's why many people get prosecuted with "obstruction of justice" rather than the actual crime.
>While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device".
So if someone was doing insider trading, and the SEC came knocking, then immediately afterwards they start burning every document they have and microwaving their computers, do you think they should get off the hook? Surely you must think, even if the authorities or society can't a priori know you were guilty, the subsequent activity should be illegal? Note this isn't the same as banning burning documents or microwaving computers, only doing so after you're aware there's an ongoing investigation.
They need to prove you destroyed evidence, you have the mens rea component with the deceptive pin code but the defense can simply plainly say they didn't want the police to read their private device.
Your example is fabricated since the justice department didn't even bring forward a specific crime they believe was committed here.
If they charged him with a crime and had evidence his device had evidence of that crime (even if in reality it didn't) that would be a more interesting question.
>with the deceptive pin code but the defense can simply plainly say they didn't want the police to read their private device.
That's as convincing as saying you burned all the documents because you don't want people who break in to read all your financial records. It just happened to start after the SEC came knocking
Except this isn't the SEC actually pursuing a voicable crime. This person was under no suspicion at all. They were simply coming home after being abroad: last I checked that is not a crime. Outside of a crime, "evidence" is just called property. If the TSA can't show "we have provable evidence gathered elsewhere to show that there was possible incriminating data on that phone" all they did was wipe this guys phone. All they had was pre-crime "he was involved in the movement against Cop City so we're gonna search his phone". No "he was meeting with terrorists in the DR". No "we have good reason to believe that when he was in the DR he communicated with terrorists". Just "uhhh we were looking for anything prohibited[1] and we targeted this guy because he was involved in some anti-cop protest group 3 years ago".
If you can't see how insanely thin their argument is, and how easily this will be abused, I don't know what to tell you. We could just as easily say having any passcode on your phone at all is obstruction of justice, since the feds could want to look on your phone for whatever made up reason, and if they can't because its encrypted, well why did you do that? What are you trying to hide? Evidence of a crime!?!?!
1. I had to call out, "looking for anything prohibited" is a direct fucking quote from CBP. They admitted it was a fishing expedition.
>We could just as easily say having any passcode on your phone at all is obstruction of justice, since the feds could want to look on your phone for whatever made up reason, and if they can't because its encrypted, well why did you do that? What are you trying to hide? Evidence of a crime!?!?!
I specifically said this wouldn't be covered, because you set up the pin before you knew any investigation occurred. However, I think it's reasonable if you were pulled aside by CBP while deplaning, and while you're waiting to interview you decided to hastily turn on encryption on your laptop, or eat a bunch of papers you had on you, I'd say that's similar to evidence tampering, not unlike flushing drugs down the toilet when you see a cop pulling up on your driveway.
Hmmmm sounds like the government can launch endless bs investigations, wait for their target to throw something (anything, a piece of paper, whatever) in the trash then charge them with destruction of evidence. A infinite guilty-change glitch if you will.
That's what judges are for, so cute hacks like "putting everyone in the US under "investigation" won't work. That said, if I was under investigation, you bet your ass I'd be extra diligent in ensuring I'm not accidentally shredding any documents.
You have to prove it is an evidence of a crime to start with, speculation is not a fact. My property, my business, i can smash the phone and no one has anything to do or say unless there’s an undeniable fact that there’s an evidence there and it got destroyed, else, it’s no one’s business.
> So if someone was doing insider trading, and the SEC came knocking, then immediately afterwards they start burning every document they have and microwaving their computers, do you think they should get off the hook?
Apples and oranges. They presumably already have some sort of evidence in order to get a warrant and are under criminal investigation.
According to the article the agents said it was just a normal part of screening.
I'm not a lawyer, but my work domain revolves around data analysis of certain types of crime. Often times the suspects are flagged and under surveillance, so if and when they cross borders or go through check-points where you have a great deal of authority, they'll get searched.
In many countries certain agencies / agents can do searches which normal law enforcement officers can't. Like not needing a search warrant or even probable cause. Not to mention that wiping a device could in itself be a crime, if it is suspected that evidence is being destroyed.
The key point here is that, as I wrote, some agencies have a lot of authority, and have the power to do pretty drastic stuff.
If your legal system depends on the benevolence of prosecutors, you've already lost before it began.
Attorneys are supposed to be adversarial. The system's soundness shouldn't depend on anything more than them trying to win and not doing anything illegal.
Before "prosecutor" became an elected/appointed office, prosecutors were independent contractors, hired for a single case only and serving at the pleasure of the Grand Jury. The Grand Jury's job was to decide how to spend the public prosecution budget. "Indictment" meant exactly that "prosecuting this person is a good use of tax dollars" and nothing more. We should go back to that.
Any system ultimately depends on the benevolence (or at least the decency) of the people in it. The idea that a society can design a perfect system and it will run itself is very dangerous.
One of the GrapheneOS people (I think) suggested keeping a bit of paper in your wallet with the duress pin, perhaps thinly disguised. Then the cops could try it on their own initiative. I suppose they'd become aware of that trick eventually, but then they wouldn't be able to use all those other genuine pins they find.
Perhaps a way to avoid this would be to have the duress pin trigger not a device wipe, but a device encryption with a long, pre-set key that you would store in a safe place when setting up the duress pin. Then you haven't destroyed the evidence, but the data is irretrievable without your cooperation. Also, if you don't actually have the key saved, it would in fact be destroyed, but the prosecutor would have to prove that you don't have the key saved somewhere.
This is one of those things the other comment calling the law "non-autistic" is referring to. In the eyes of 99% of people, it's functionally the same thing. "Well teeeecccchhhhnicallyyyyyyyy I still have the data..." isn't going to make the security workers at the airport slap their heads and say "damn, he really got us! Go on through!"
No. They'll arrest you just the same for obstructing their search. Then they'll keep you in detention for a long time while you say "I can unlock it for you! You just have to let me out!"
You can pretend you have leverage and say they need to cooperate with you. But once you're detained, police and prosecutors don't really care about cooperation anymore. Their idea of cooperation is you giving them what they want immediately without question. You're made into an example if you don't abide.
The article seems to be muddying the water bringing up grapheneOS itself. Or maybe it's the EFF.
>Experts said the legal approach is unusual and may be the first time the law has been aimed at an operating system. "It's concerning – and sends the message that [GrapheneOS] is criminal by default," said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.
Is the actual case about banning the OS? Because it seems pretty clear the case is about the result (the phone being wiped with a special passcode).
The better defense imo would be one of those 'wipe the phone if you get the password wrong x times' and try and claim you forgot under pressure. At least if you wanted to wipe the phone without being accused of destroying evidence during a search.
Its best for all of us to figure out how to use phone-as-a-linux-vm with the physical phone just hardware. It will solve many problems: commoditize the phone ecosystem, eventually making them repairable, run our own apps instead of apple/google. Access phone-vm from laptop/desktop ...
Seems like they’re going to have a struggle proving intent. “I was stressed out and afraid and I got the passwords mixed up” would be the magic words I’d hear as a juror and I wouldn’t be able to vote to convict.
If you get a jury who doesn't think that "strange self-destructing phone" isn't a criminal's tool to begin with. Which I'd guess is probably not likely.
> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart.
I'm confused to understand if Tunick did anything illegal here. If the authorities want the phone, they should have the warrant and seize it without Tunick's permission.
It appears authorities did not have the warrant which give Tunick all the right to do whatever he desires with his property.
Among other things that CBP does not need a warrant to search or seize anything and everything at a border. Everything is subject to search at the border. To make a seizure all that is needed is reasonable cause that customs law/regs were violated. And there are specific federal laws relating to thwarting such seizures.
If you don’t want something searched do not bring it across the US border. There is very clear constitutional and statutory authority for these searches.
> US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search
I really don't like this title. Officers asked him to open the phone, which he pretended to do, but instead wiped the device
> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart. The defense motion states that "the screen went blank, flashed several times, and the phone appeared to restart," resulting in the loss of data.
The title implies the agents maybe entered too many pins by mistake and the device auto-wiped, or that it reset itself with no human intervention, which isn't what happened. This is more like shredding paper when the FBI arrives at your office, which most people would attribute to destroying evidence. I hope he wins the case in principle (I think there's a risk of a slippery slope here) but it wouldn't be a moral tragedy if he lost.
Having just gone through having to give pin to cbp you just need the apps on your phones to have separate pins so when police unlocks it, they cannot unlock WhatsApp afterwards. Faceid or unique pin. Problem is your phone pin overwrites Face ID
They claimed they were looking for CSAM. There's a border search exception to the fourth amendment that says CBP can search your phone at the border. You aren't required to give them a password (but possibly a fingerprint or facial scan) but they can temporarily sieze it (and do god knows what to it).
Seems like a good court argument too—no destruction of data was even attempted because I know I have my iCloud or Google backup. Personally, my phone has access credentials to information, but not the information itself. So you need a serious warrant before you can get those access, but the data is there.
I agree that it seems a simple argument for any competent lawyer to make that the phone isn't the "gold copy". The phone is just an ephemeral copy of the real data which is safely stored away in the cloud, and the authorities can request access to with the proper warrants.
Of course this argument will only work if the phone is indeed and a ephemeral copy of your real data.
While I like the idea behind GrapheneOS, I'd rather not place myself in jeopardy of some ridiculous charge like this one. I prefer to travel with a travel device, some inexpensive phone and/or laptop that contains nothing interesting. If they then wish to take it from me because I won't unlock it, then have at it!
That said, the situation with respect to our Bill of Rights at the border has gotten ridiculous.
The "duress PIN that nigh guarantees destruction of evidence charges" functionality is extremely stupid, but otherwise GrapheneOS on a flagship phone is your best bet for an Android phone that can't be cracked by low-effort attempts, government or otherwise.
Instead of a PIN that wipes the device, it would be much better to setup a special PIN that logs the user into a sanitized, completely separate profile with generated content of no practical value. This would create plausible deniability, and be sufficient to allow low-level border agents to look through a phone and pass any checks without raising these kinds of alarms. The wipe PIN should still be an option, but should be separate, and only be for cases where you suspect a forensic imaging or search of the device is to take place and the legal consequences outweigh the risks.
I don’t understand why phones can’t just have decoy profiles you can activate via PIN that look like regular harmless user profiles? Especially now with AI you can quickly populate with a bunch of plausible data.
Or better, have PIN for taking you to your criminal/secret profile instead.
If you're paranoid enough to be using GrapheneOS, why would you take it to an airport in the US of all places?
I bought a second hand iPhone for overseas trips, which my daughter promptly stole because she wanted an iPhone, but then i got her old android phone, which was LineageOS-compatible, so that became my travel phone.
U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did. Hell there could have been a third set of four numbers that were the nuclear launch codes. It’s not the fact that it was four numbers, it’s what you were trying to make happen when you typed them. Now of course whether they can prove what your intent was when you typed them is another matter, but generally a duress pin should be for when robbers are breaking into your house, and the government will be on your side, and not when the government will be against you.
It's people who couldn't get out of jury duty. Prosecutors have high success rates. Federal prosecutor success rate is over > 90%. Studies of jury psychology show how much peer pressure and other factors extrinsic to the law come into play.
Remember what happened to Aaron Swartz. Law is the mask of power. By all means defend and assert your rights, but understand the costs. I find people are under such illusions about how cruel the American justice system is that this leads them to make foolish decisions. Do not underestimate the adversarial nature of the justice system, nor the accompanying incentives agents of the state who are on the other side of you have to lie.
This is a misunderstood statistic.
Federal prosecutors won't even pursue cases unless they think there's a high chance of success. They don't operate like two private parties suing each other to force the court to decide something. If the evidence is there or the charges aren't fully formed, they don't waste resources on it.
This leads to a contradictory set of complaints that the legal system lets too many people go or doesn't have enough teeth.
To be clear, I totally agree with your points, I just think this is more of a case of "lying with statistics" than being a misunderstanding.
"Never attribute to malice that which is adequately explained by stupidity."
Prosecutors pick their cases. Defense doesn't. The cases that aren't 90%+ sure aren't charged.
OP is strongly implying that the 90% success rate for prosecutors is due to the courts being stacked against the defense. IMO that is where the logical fallacy is. Since prosecutors have wide latitude in deciding which cases to charge in the first place, it is very possible that the high success rate is due to prosecutors only charging cases where the accused actually committed the crimes being charged. Indeed, for the ~10% of cases where the accused is not found guilty, about 8% are due to the government dropping the case - only 1% are the jury acquitting the defendant outright. Thus, it would appear from that data that when the prosecution sees they are not likely to win a case, they drop it.
I'm making no argument that the courts or law are "fair", I'm just making the argument that quoting the 90% number is in no way evidence that courts are inherently biased towards the prosecution.
It’s not even just who couldn’t get out of it. It’s filtered for people who answer honestly. I was disqualified for a grand jury because the judge asked me if I would believe the testimony of police officers as truthful and I said it would depend on the police officer.
The system already had their hands forced on accepting that some cops lie with Brady disclosures but the fact that I didn’t just naively accept police testimony meant I was an unscramble juror.
Even if you’re a true believer in the system you won’t be allowed to participate because you didn’t lie.
Programmers have trouble seeing color (two identical numbers are the same bits, how can typing '1234' to unlock one phone be legal, and '1234' to unlock another phone be illegal?)
Courts care about color (intent, provenance, permission), even though that color cannot be digitally represented.
Love this way of putting it. Stealing for future conversations with fellow software developers.
If you don't understand what I mean, swap out "autistic" for "retarded" and the joke still functions, but a lot more people will be offended by it.
I still laughed though.
Him deleting his phone was very likely a matter of safety for his fellow activists. Sad that our government does this but it’s not like this guy was a drug dealing or something.
When we met it was interesting how our jurors decided “I don’t believe anything that guy says” and so on when it came to their motives and so on.
The trial itself was very carefully choreographed, almost pre determined and static.
But the decisions and jury activity was very dynamic. There was absolutely no magic legal mechanisms at that point.
However there are arguments morally, and constitutionally, and logically, about what can be done.
Law is effectively a weak gentleman’s agreement we tolerate because the alternative is violence.
(Well, law is enforced with violence too, I suppose.)
When I was a kid I wanted to be a police officer because I wouldn't have to follow any laws or rules. Then I got a little bit older and realized that wasn't how being a police officer actually worked in practice. Then, I got a little bit older than that, and realized that it actually does work like that.
This has always been true and there has never really been perfect justice. Ultimately, power and violence have always superseded the law. High trust societies with less corruption and a strong justice system try to limit these circumstances.
You raise the standard for justice to perfection. There also has never been perfect corruption and anarchy.
> Ultimately, power and violence have always superseded the law.
That's like saying night has always superceded day. Everyone recognizes that recent years have been very unusual or unique in US history. That means for the great bulk of US history, it was different. Why doesn't 99% of US history outweigh the 1% (picking numbers very loosely) in determining what is somehow inevitable to you.
In fact, law is universal among human cultures. We are naturally social and live in groups with rules. Those that violate rules are generally outcasts.
But the most fundamental and significant error is attributing the current situation to some unavoidable system instead of the actions of people, especially those that stand aside and allow these things to happen. Many of them stand aside because they are told - probably messaging ultimately from the lawbreakers - that they are powerless and should despair.
When the judge and officers of the court agree with me, the law is reasonable and just, but when they do not agree with me, the law is arbitrary and capricious. ¯\_(ツ)_/¯
Having the law be whatever it's thought to be by police, prosectors, judges, and others can lead to obvious injustices, but there's been no serious attempt to remove ambiguity in any country's legal code as far as I know.
People already complain that there are too many laws on the books.
If your threat model includes US state actors at the national border, then your security practices need to account for the confiscation of your device at that border without requiring you to willfully wipe the phone and (in the eyes of police and prosecutors) destroy evidence.
That means:
1. Don't travel with anything you can't afford to lose on device. This means setting up travel-specific password managers and hardware keys for a subset of your accounts that you absolutely need to access while abroad, and being prepared to reset those passwords and disable those hardware keys very quickly once home.
2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. Your secure setup must function without needing you to engage in those behaviors, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable.
3. Consult with a lawyer and review your security procedures from a legal standpoint. All of the above is technical and practical advice, not legal counsel and no substitute for it.
We Americans are fortunate to carry powerful passports and enjoy relatively easy international travel but, for better or worse, that velvet glove covers an iron fist we would be foolish to forget or ignore.
Intent matters. It might be hard to prove, but it matters.
It may not even be that hard; what other possible explanation is there for someone putting a PIN visible on their phone that wipes it while crossing a border?
I suppose it's possible someone might enter it without thinking, but the odds seem low. Also seems risky to put a self-destruct PIN on your device, lest a friend (or enemy) enter it by accident or as a prank.
Or it's preferable to get caught lying to a federal officer than it is for them to have the evidence on your phone.
but not necessary evidence, as evidence would imply a crime. But when it comes to police harassing activists, or outright mislabeling them as terrorists, there are many fully legal things you still might prefer the police not to have. Lets not forget that boarder police has in the past tried absurd things like trying to seize Attorney-client privilege protected information from a US attorney.
Through most likely many people setting up and using a duress pins never truly think this thought from a legal POV.
They asked for the pin, maybe they should have said "not the duress pin"
>Destroying evidence
How did they know there was any evidence on there?
>it exists for when compromising the device could get people the owner cares about killed or disappeared and the owner considers their own liability, disappearance, or death a preferable outcome.
No, the duress pin is there for when I'm under duress and being forced to unlock my device against my will
>It is an extreme solution for extreme scenarios
Wiping a device I own is extreme?
This is a Mickey Mouse distinction no court will take seriously.
> Wiping a device I own is extreme?
When the consequences are potential years in prison for lying to the US government or, in another country, torture or death in prison for obstructing an authoritarian government, then yes... Extreme.
All I'm saying is to decide to use a duress PIN at any national border or in any foreign country soberly, with knowledge of the potential or likely consequences.
If you think the system needs fixed or destroyed, you do you, but don't be surprised when that approach gets you in trouble at the border.
People who think that tricking the cops into wiping your device legally absolves you need to grow up. Also those who argue that LE can't prove any evidence was destroyed since it's been destroyed.
[1]: https://www.law.cornell.edu/uscode/text/18/1001
https://www.law.cornell.edu/uscode/text/18/1001
Is it true that the law is only selectively applied to some people?
That doesn’t pass the sniff test
18 U.S. Code § 1001 [1]
[1]: https://www.law.cornell.edu/uscode/text/18/1001
https://www.npr.org/2020/11/25/939064270/trump-pardons-forme...
> President Trump has issued a pardon to his first national security adviser, Michael Flynn. Flynn had pleaded guilty to lying to the FBI and then recanted.
Rules for thee but not for me.
The entire situation is sort of nonsensical and boils down to lots of minutia in law that no normal person would know about.
For example having normal widely known security features like wiping the device after N failed PIN attempts is fine. Even having long standing security practices that can’t be related are fine, like having a timed touch point where if you don’t enter the PIN every… 15 days or whatever the device wipes, perfectly fine if it can’t be connected towards the crime and you’re not compelled to tell officers you have such a security mechanism.
Even if you were to set a trap where you use the same PIN for your bank, your laptop, and some other security devices in repetition then decide to set your duress PIN to that by assuming it would be discovered as a probable option they’d use, you’d be ok but it could be questionable if that was by design…
It’s so obscure really as to how and how you’re not allowed to protect your data, even if you’re not the one performing the action to clear destroy the potential evidence yourself. The entire thing seems pretty absurd a frankly arbitrary to me, and I don’t know how people could know which cases are and aren’t legal. I know not to destroy evidence myself but I wouldn’t know to tell someone to not use the duress pin or that even giving them my duress pin could somehow be my liability. It’s madness if you ask me.
One of the most depressing things I've read on here
Who said it was evidence? Did a judge authorize or issue a warrant to collect said evidence? Absent that, it's just your property, and you can do with it as you please.
Whatever the American legal system may say, a couple of thugs with no warrant conducting searches and seizures of data is a blatant violation of the Constitution's intent. This is the sort of behavior Americans used to rightfully condemn.
“Hey! I saw you holding that Mexican pepper in Mexico, and then you threw it in that Mexican trash can before crossing into Texas!”
“Yeah, so?”
Why do people go sovereign citizen when reality doesn't work their way? Stop imagining that the way you want things to be is the way things really are.
Cops do not need a judge to authorize the seizing of evidence. Cops do not need judges to decide what evidence is. Tell me, why did you just pretend like these are real requirements? I can understand why you'd want it to be that, but you wanting it to be that doesn't change reality.
It's as if you've just learned about the Fourth Amendment but know nothing about the nuance behind it.
Your system wouldn't even work at all. Let's imagine the cops get a tip that a bald man with a blue tshirt shot a man. They patrol the streets and find a match. By your logic they should not have the ability to search the man and seize his gun as evidence until a judge issues a warrant.
Though during traffic stops, if a defendant disposes of his drugs while on the run, that can also carry a charge of destroying evidence even though no warrant was issued.
IANAL
https://www.law.cornell.edu/uscode/text/18/1519
> "the screen went blank, flashed several times, and the phone appeared to restart,"
How about flash some red lights and play an airhorn sound effect, too.
Something like this may need to become the standars over duress pins which should be treated as a fallback or more extreme alternative. Right now, A single choice to reasonably and rightfully protect your privacy reuslts in jail time over something which likely wouldnt have resulted in any issues if superficial compliance was observed.
These goons, even if a branch of a facist regime, are ultimately burocrats with violent options to settle. They aren't doing forensics on your device etc. They have neither means nor knowledge to do so. They just need to tick their boxes. Did the phone unlock? tick. Did our spyware complain? no? tick. Overall appearance of compliance from person? yes? tick. free to go, next!
You just have to find ways to stay safe without agitating their workflow and all is well.
- [1] https://veracrypt.io/en/VeraCrypt%20Hidden%20Operating%20Sys...
this problem may be solvable by a purpose-built abstraction where every write no matter what address will look identical to the firmware (naively, a randomized key-value map).
trim lets the firmware know which mappings it can discard without the explicit reuse of the same address.
however I don't believe you can observe this effect from trim command results, it will report the usual size trimmed as if the firmware never realized that you reused the same address range multiple times.
There’s plenty of empirical evidence of cops lying to lock up innocent people.
One truly absurd case was lying to convince a man he killed his father, and extracted a murder confession for a victim who they knew wasn’t dead.
https://people.com/thomas-perez-jr-murder-interrogation-1186...
I doubt this person will be found guilty. They will be able to prove he wiped his phone, but it will be hard to prove he destroyed evidence.
Obviously a good alternative is a dummy device but it carries similar risks, and the best option is to simply not go to authoritarian shitholes like the USA. Thankfully I've been able to avoid/push for US folks visiting us instead, but honestly the alternatives are as bad.
Its a shit situation where most reasonable actions carry real risks, its up to individuals to choose what is acceptable risk to them, but a dummy os you use as a daily driver for inconsequential work is, to me, an ideal midground.
See: https://news.ycombinator.com/item?id=49057812
Implementing it in a convincing way is harder than you think. Moreover if you're under the type of regime that will throw you in jail for not giving up a password, they're probably not going to let you off the hook because they can't definitively prove you have a hidden volume.
Done well, I see no reason it should raise redflags in routine stops, so unless you're being targeted (at which point you've got way bigger problems) it should just seem like you're a run of the mill person who does not use their device to its full capacity, which is the majority of users.
at some point, having any mitigations even present is a problem. At some point being met with a boot password at all is a problem that puts you on a list. I have no solution there other than to not go to those countries or keep dummy hot.
1. SSDs (including phones) have TRIM/discard, so you need to disable it, otherwise the hidden volume would get wiped. You going out of your way to disable it is going to be suspicious.
2. Even if the above wasn't an issue, you can't really use the outer os to any meaningful extent, because you run the risk of overwriting the inner volume. That makes your decoy os suspicious. It's not definitive proof you have a hidden volume, but I doubt the authorities would care too much about that.
So the main/hidden volumes really works like a duress: you might destroy your hidden volume while using the main one under duress, but that does not apply when using the main volume while able to additionally unlock the hidden volume.
If you are in a situation to need to worry about any of this, you're probably going to jail for one reason or another, anyways.
See also relevant XKCD:
https://xkcd.com/538/
You’re just carrying a blank phone that you intend to set up and use later, and they can’t force you to install your backup onto a phone.
Now, this is sus as hell, and you’ll probably draw all kinds of extra attention, but if border security wants access to your phone in the first place, you’re already in a weird place.
It doesn't have to be blank - just clean.
Of course it’s about that huh. It’s quite scary how far the US will go against anyone who engages in this sort of activism.
Most previous court cases involving encrypted devices have required substantial proof that the encrypted device contained incriminating evidence. To be clear "you sent this illegal thing from your house" levels of evidence.
It mostly seems inept, if you are going to push to expand your powers you do it on strong cases where you know what happened. Doing it on weak cases like this gives a judge an opportunity to shut down that without giving you a chance of a meaningful conviction and without that you won't get any benefits...
They don't have to, only that you destroyed evidence. That's why many people get prosecuted with "obstruction of justice" rather than the actual crime.
>While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device".
So if someone was doing insider trading, and the SEC came knocking, then immediately afterwards they start burning every document they have and microwaving their computers, do you think they should get off the hook? Surely you must think, even if the authorities or society can't a priori know you were guilty, the subsequent activity should be illegal? Note this isn't the same as banning burning documents or microwaving computers, only doing so after you're aware there's an ongoing investigation.
Your example is fabricated since the justice department didn't even bring forward a specific crime they believe was committed here.
If they charged him with a crime and had evidence his device had evidence of that crime (even if in reality it didn't) that would be a more interesting question.
But again where is the crime?
That's as convincing as saying you burned all the documents because you don't want people who break in to read all your financial records. It just happened to start after the SEC came knocking
If you can't see how insanely thin their argument is, and how easily this will be abused, I don't know what to tell you. We could just as easily say having any passcode on your phone at all is obstruction of justice, since the feds could want to look on your phone for whatever made up reason, and if they can't because its encrypted, well why did you do that? What are you trying to hide? Evidence of a crime!?!?!
1. I had to call out, "looking for anything prohibited" is a direct fucking quote from CBP. They admitted it was a fishing expedition.
I specifically said this wouldn't be covered, because you set up the pin before you knew any investigation occurred. However, I think it's reasonable if you were pulled aside by CBP while deplaning, and while you're waiting to interview you decided to hastily turn on encryption on your laptop, or eat a bunch of papers you had on you, I'd say that's similar to evidence tampering, not unlike flushing drugs down the toilet when you see a cop pulling up on your driveway.
Apples and oranges. They presumably already have some sort of evidence in order to get a warrant and are under criminal investigation.
According to the article the agents said it was just a normal part of screening.
What if there was no warrant, and the SEC just came to ask questions?
In many countries certain agencies / agents can do searches which normal law enforcement officers can't. Like not needing a search warrant or even probable cause. Not to mention that wiping a device could in itself be a crime, if it is suspected that evidence is being destroyed.
The key point here is that, as I wrote, some agencies have a lot of authority, and have the power to do pretty drastic stuff.
Attorneys are supposed to be adversarial. The system's soundness shouldn't depend on anything more than them trying to win and not doing anything illegal.
Before "prosecutor" became an elected/appointed office, prosecutors were independent contractors, hired for a single case only and serving at the pleasure of the Grand Jury. The Grand Jury's job was to decide how to spend the public prosecution budget. "Indictment" meant exactly that "prosecuting this person is a good use of tax dollars" and nothing more. We should go back to that.
No. They'll arrest you just the same for obstructing their search. Then they'll keep you in detention for a long time while you say "I can unlock it for you! You just have to let me out!"
You can pretend you have leverage and say they need to cooperate with you. But once you're detained, police and prosecutors don't really care about cooperation anymore. Their idea of cooperation is you giving them what they want immediately without question. You're made into an example if you don't abide.
>Experts said the legal approach is unusual and may be the first time the law has been aimed at an operating system. "It's concerning – and sends the message that [GrapheneOS] is criminal by default," said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.
Is the actual case about banning the OS? Because it seems pretty clear the case is about the result (the phone being wiped with a special passcode).
The better defense imo would be one of those 'wipe the phone if you get the password wrong x times' and try and claim you forgot under pressure. At least if you wanted to wipe the phone without being accused of destroying evidence during a search.
I'm confused to understand if Tunick did anything illegal here. If the authorities want the phone, they should have the warrant and seize it without Tunick's permission.
It appears authorities did not have the warrant which give Tunick all the right to do whatever he desires with his property.
What am I missing here?
If you don’t want something searched do not bring it across the US border. There is very clear constitutional and statutory authority for these searches.
What would be the reasonable suspicion that a USC bringing their personal phone on a trip with them would be a customs violation?
That doesn't sound at all reasonable.
In fact, the only "suspicion" they had was that he was someone who didn't like LE or Trump which is still not a crime, nor a customs violation.
What they got him on, is that supposedly he destroyed evidence.
I really don't like this title. Officers asked him to open the phone, which he pretended to do, but instead wiped the device
> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart. The defense motion states that "the screen went blank, flashed several times, and the phone appeared to restart," resulting in the loss of data.
The title implies the agents maybe entered too many pins by mistake and the device auto-wiped, or that it reset itself with no human intervention, which isn't what happened. This is more like shredding paper when the FBI arrives at your office, which most people would attribute to destroying evidence. I hope he wins the case in principle (I think there's a risk of a slippery slope here) but it wouldn't be a moral tragedy if he lost.
Technically correct is not the same as practically correct.
They can detain you for days if you're not white. (Kavanaugh Stop)
Of course this argument will only work if the phone is indeed and a ephemeral copy of your real data.
Or better, have PIN for taking you to your criminal/secret profile instead.
https://arstechnica.com/tech-policy/2020/02/man-who-refused-...
If you're paranoid enough to be using GrapheneOS, why would you take it to an airport in the US of all places?
I bought a second hand iPhone for overseas trips, which my daughter promptly stole because she wanted an iPhone, but then i got her old android phone, which was LineageOS-compatible, so that became my travel phone.