For exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs. Imagine booting the phone from a flash drive, making an encrypted image of the phone on said drive, and writing a fresh OS before reaching the border.
There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).
Some time ago, Android with a custom recovery could come close to that, but it was fussy and as far as I know, no longer viable. Increased use of TPMs for storing credentials seems to be at least one of the reasons.
I used to play around on projects adjacent to Tor and TailsOS, and had an idea for a setup I was researching. It's a little intense and probably has annoying failure modes, but sharing in case anyone else finds it helpful:
- Tasker is an automation app for setting up rules for triggers and actions. It allows extension apps to be created to add new triggers and actions.
- someone at one point made an extension to add an action for wiping or factory resetting when triggered
- there was an existing extension (or core feature) to trigger when certain signals are lost or found (e.g., wifi signals, Bluetooth LE beacons, etc)
So the idea is to carry a BLE beacon (any "item tracking" one works) on your keychain, and an unassuming faraday cage pocket alongside it. If you want to wipe your phone, slip the fob into the pocket, the signal disappears, and your phone wipes. And if you don't have the keychain on you, just refuse to open it right away, as when they put the phone itself in a faraday cage (to prevent it from being remote wiped), they cause the signal to be lost, and it gets reset.
Not sure if all the pieces still exist (I dont think the tasker extension for wiping existed outside a forum post...)
All Archive pages, when accessed from Italy, now are blocked by the Government:
"PAGINA INTERDETTA DAL CENTRO NAZIONALE PER IL CONTRASTO DELLA PEDOPORNOGRAFIA ONLINE (C.N.C.P.O.)"
“PAGE BLOCKED BY THE NATIONAL CENTER FOR COMBATING ONLINE CHILD PORNOGRAPHY (C.N.C.P.O.)”
Oh, we live in an interesting age.
U.S. citizens are going to need obtain a burner phone before returning, and load it with the absolute minimum to load boarding passes, etc., perhaps some reading material or a movie to watch on the plane, and be prepared to share full credentials for thing at the border.
(I used to do some travel patterns where taking a certain client laptop wasn’t an option. It was an absolute gigantic pain for the type of work I did, but it was just too risky to have a laptop seized and be expected to input credentials.)
According to the article, he was actually using GrapheneOS and gave the border official the Duress PIN. So I guess technically it was the official that erased the data :-)
Why American authorities are always attacking their citizens freedom?
Legal Eagle just covered this, it's quite interesting analysis: https://www.youtube.com/watch?v=_2rokxux5cU
I'm not a legal expert, but all this seems to check out with US law. Americans need to remember that some of their constitutional rights don't really apply at ports of entry by design. This inconvenient truth for the land of the free has existed for a long time, this situation is just drawing attention to it. Their powers are far-reaching.
So the part of this that feels like it triggers the government issue here is that in effect you have a locally stored encryption key which gates access to the device, which was removed from the device due to duress password.
What if we flipped this to instead be something that's explicitly not on the device?
The border search stuff only applies to information on the device. It cannot compel you to provide access to e.g. emails stored in a cloud provider.
If instead of making the process of stopping searches like this be a destructive one, we instead pre-purge the key but store it offsite with the ability to get it from an online location, then this feels like it's probably reasonable here. In the sense that the 4th amendment explicitly allows "The right of the people to be secure in their persons, houses, papers, and effects, ..."
There's probably some sort of technical problem I'm missing here (or maybe this functionality is available already).
I don't get the legal contradiction.
The search is supposed to be lawful without a warrant because you're not really in the US yet per-se, hence if you're not there, how deleting the data can be a felony?
How did it end up, because it’s not a new thing to happen. First time I read about this guy’s border crossing case was few months ago and was of course very much highlighted for the level of surveillance govs can do.. but I also read some Time later that by the letter of law he was not proven wrongdoing.
Are we still discussing a border crossing case that is long historic or there is still an active drama for this guy going on?
It's like those notices "by clicking accept below you agree to giving up your data", by purchasing a ticket to visit US all your data are belong to the US.
Seems like it would be better to have a truecrypt type of situation, where if you put in a certain pin, then it just logs you into a separate OS with nothing you want to hide.
Obviously have the duress pin if what’s in your phone is worse than the obstruction charges too.
Amendment 4:
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."
Amendment 5:
"..nor shall be compelled in any criminal case to be a witness against himself, nor be deprived of life, liberty, or property, without due process of law; nor shall private property be taken for public use, without just compensation."
He's lucky they didn't ship him right off to the Dilley Detention Center
Obstruction to what? Also thought this would be covered by the fourth and fifth amendment.
Goes to show that he should have made an LLM do it instead.
What about none citizens? Customs kicks you out or throws you into a camp first.
E: but seriously, what happens to non citizens. What happens if you bring a burner/wiped phone? I assume digit forensics can confirm it was pre wiped but what's topping them from alleged you wiped on US soil.
I don't know about you, but don't people use encryption to retain privacy? And are people still free to manage their personal information? Doesn't a duress PIN present that information in its intended form? I'm confused.
What about everyone does this at the border. Then what is normalized is deleting your encryption key while entering, they won’t prosecute everyone on their baseless prosecutions. Join in I say, there is no law being broken only scare tactics being applied to prevent this kind of thing. Normalize the act not the consequences.
Anyone that is surprised by this or somehow thinks this is new clearly hasn't crossed the border a whole lot. I grew up in a city along the US/Canada border. You don't fuck around with US Customs (or Canadian) agents. My cousin (not always so friendly) pissed off a US Customs agent (in the 90s mind you) and they promptly took his car and disassembled much of it looking for non-existent drugs. When they put it back together it was never the same. Their job is to be suspicious, 99.999% of the time people are completely innocent. But let 1 bad person through and it's Customs' fault for whatever bad thing they do. Not an easy job. Not an excuse for how they can misbehave either.
Is it right? It makes no difference, Customs can make your life miserable, that's just the reality of it, always has been and it can't have gotten better in recent times.
What I don't understand is if he just didn't give any password, he would have been fine. It's only because he gave him a duress pin that he's in trouble.
So, in both cases the government wouldn't have access to the contents of the phone
While I think it's an abuse of power from a moral point of view - yes, that would be the expected legal outcome. Under any administration.
You can refuse to hand over access. You can't go torch evidence. Caught Ollie North as well.
Well hopefully there’s a jury so this nonsense can get nullified
So we're presumed guilty until proven otherwise (the presumption is, any data we delete must be illegal; couldn't possibly be nude selfies that the government has no right to see)
The land of the free!
Would it be permissible to wipe your phone before going through customs to get back into the US? If they ask to search your already wiped phone, you aren’t destroying any evidence.
amatuer... when you leave the us you bring a wiped phone, never bring your primary phone/laptop/camera/etc
Paywalled, but what is the actual charge? Is it some extremely generic "obstructing an investigation" one? The US is quite good about making court documents available on line, if someone can find it.
One more reason to not go to the US
I don't agree with all this and this increasingly fascist regime but... this was the most predictable outcome. Consider these two scenarios.
1. You factory reset your phone before entering the US and give it to CBP blank. There's nothing to find;
2. You have a self-destruct PIN like this guy did and give it CBP so it destroys the phone's contents.
Tech people will say that these two things are functionally the same. This is a fundamental misunderstanding of how the law works. If you factory reset your phone first with the intention of restoring it after entry, that's completely fine (legally). You could've factory reset that for any reason. But as soon as an officer wants to search your phone, now you're engaging in evidence destruction (spoliation). The destruction to the phone's contents was done in response to an unfortunately lawful search.
Even if you don't want to factory reset your phone, you can probably just delete (or even log out) of key apps. They can still get messages but if you're so concerned about that, use WhatsApp or whatever.
None of this should be necessary but we are where we are. But whatever you do, don't use a self-destruct PIN if you don't want to be charged with a felon and likely to be found guilty.
[dead]
[flagged]
[dead]
Yet another case that will waste the court's time and money. All this is doing is keeping defense lawyers pocket's lined.
At this point, people should buy a burner phone when going to/from the US. In that phone only have a couple of phone numbers and that's it.
If the government wants you no amount of technical gotchas will prevent this.
FAFO
Y'know, makes me wonder why Democrates didn't disband ICE and CBP when they had control over the Congress and the government. I mean, they knew those agencies would be used in precisely this way, yet did nothing anyhow.
The naivete of some of the comments here is astounding. It doesn't matter whether you're right, it doesn't matter whether it's the law, it's irrelevant that you have rights, etc. Those things are of the past now, for the US.
I think it would be easier to understand the playing field and choose your actions accordingly, if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech.
The social dynamics are the same - the abuses, the selective enforcement, the lack of recourse, the same characters in the roles of various levels of "law enforcement" and "politics". I'm so very sorry, but the best you can do from here is speedrun the collapse.