The border agents didn't act in good faith, regardless of what they're empowered to do. They wanted the data for one reason and fabricated another to prompt the device search. The data they were interested in pertained to protest activity protected under the constitution but the lie they told was about something criminal. That anything within 100 miles of the border is constitution free tosses that out, I guess, but is extremely problematic on its own.
The founding fathers would be aghast at what America became. Hard to imagine modern America passing some of those constitutional amendments that older America passed wayyy back.
This should be an interesting case in today’s legal climate
Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password.
How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password does a wipe based on location? Either way, the user complied, and did not take action to wipe their device.
Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.
The level of duress also matters. US citizens have been shipped to foreign prisons and there's an active case of high-level officials at DOJ violating court orders about that.
while attempting to avoid armchair-law-interpreting because I really do not intend that, and I agree that this is going to be an interesting/deeply-worrying legal case:
wiping the device before carrying it across the border seems essentially identical to me. like, saying "you can't wipe it when searched" would also imply "you can't have an empty device when crossing because it may have been wiped before the search to avoid having your data searched" since people can (and often do) do that for exactly that reason.
that may very well be what they want / what they are trying to legally allow during searches, but it also seems like it'd raise a hell of a lot more outrage. it's essentially claiming all citizens are under full legal hold all the time, if they ever intend to leave the country for any length of time.
To my knowledge, no citizen has ever been prevented from reentry due to a blank or absent device. In fact they cannot block a citizen’s legal reentry for any reason, they can only detain you while they investigate.
Beyond this, “I dropped my phone in the ocean” is always a perfectly valid reason.
If you’re a foreigner and they already suspect you of something, they can deny you entry for any reason. It may be better to be denied than arrested!
isnt it amazing how we are able to know when something is a trick and clearly caused by your action/intention vs when it isnt? i mean sure we can contrive (or maybe even find example of) some scenario where it might be a hard grey area, but ive always found it so cool how we often operate on "top down" methods like this that logically have no basis for working out but 'common sense' happens to be common enough still
If you have a safe in your home and you knowingly wire up a bomb that goes off when a certain lever is pulled then you lie to the police and tell them the way to open the safe is to pull that lever you'd pretty clearly be responsible for the damage done when the bomb goes off.
> Either way, the user complied, and did not take action to wipe their device.
The user claimed to offer a password to access the contents of the device, and instead offered a password that deleted the device. That is false testimony / lying to an investigation, and is almost certainly punishable in itself.
It would depend on precisely what the ask was. Did the officer ask, "Give me the pin to unlock the phone."? In that case the command was complied with.
The "agent entered password themselves, therefore they're to blame" seems as good of a logic as "I'm going to start swinging my arms and start walking forward, so if you don't move, it's YOU hitting YOURSELF".
Should we take the same approach for physical searches? If the cops are executing a search warrant on a house, and there's a safe, should they send in a safe cracker on the off chance the safe is wired with a "duress pin" (eg. thermite that burns the contents)?
That's egregiously disingenuous. Having a password that protects the infiltration/extraction of your intellectual artifacts is in no way akin to assault on someone else.
A duress password isn't a booby trap. Nothing was damaged except for the fragile egos of the man-children who weren't able to bully someone into giving up their wrong-think.
The point isn't that giving a duress pin is the same as physical assault, or that the duress pin feature is a "booby trap". It's that for the purposes of ascertaining guilt, you don't get a pass just because you're not the person that physically initiated the action.
On one hand, I love GrapheneOS and see it as a cornerstone of digital privacy software. I have supported the project financially for years.
On the other hand, I'm worried that the publicity will only make explicit targets out of GrapheneOS users, and that you would only be using it "if you have something to hide".
And this is why part of my plans for any international travel are to simply have a physical notebook with phone numbers to trusted friends/family and to buy throwaway devices on the other side (phone and chromebook or similar).
TBF, similar mindset if I ever attend defcon, etc. as well.
Someone who is a lawyer knows any details about the US justice systems precedents with regards to the fifth amendmend (regards to self incrimination) vs obstruction of justice (by destroying evidence) as would be applicable to a duress wipe? Also would the distinction of being (or not) read their miranda rights and placed under arrest in this case make a difference as to the status of any possible obstruction?
Not a lawyer, but my understanding is that refusal to give the PIN (“remaining silent”) would be a valid application of the 5th, but not giving a false PIN. 5th does not imply the right to mislead or lie to someone investigating a crime.
Not clear on anything else regarding the duress PIN but I don’t think a 5th defense would apply.
Note that you apparently have to explicitly invoke your right to remain silent or your silence could be implied as an admission of guilt (thanks to Salinas v. Texas). I imagine you’d have to repeat your assertion multiple times, and the person demanding the PIN will tell you that you can’t use the 5th, will threaten you with arrest and additional charges, etc. Consult a lawyer and get training if you’re doing critical work where you may need this defense.
Hmm, interestingly here in Sweden we have "free evidence" (way of gathering is not considered even if "illegal", however someone doing something illegal to obtain it could instead be charged separately).
As such in a case like the Salinas one, being silent or "pleading the fifth" would be moot as both would just indicate "deafening silence" to the judges since the defendant had been cooperative up until that point.
(the Swedish judicial system has no juries, instead there's a professionally learned judge and 2 "laymen judges" appointed from political parties acting as the peoples representatives, if that triumvirate fucks up, higher courts can and often will kick rulings back down for retrials).
I'm mixed... if they really thought there was evidence on the phone, they should have seized the phone and acquired a warrant IMO to compel the valid, non-destructive PIN be given over.
As I mentioned earlier, this is part of why my own plans for international travel are to only go with a notebook/sheet with contact numbers and buy throwaway devices on the other side. I don't think I'd travel internationally with a phone or laptop at this point, and that's kind of been my thoughts for a while. Especially given the direction that many countries, not just the US have taken. For that matter, I don't think I'd ever even risk travelling to the UK or China at this point. Not that I like the surveillance state here in the US, at least I still have some rights preserved.
According to Homeland Security, within 100 miles of the border is a "constitution free zone". So there's a whole lot to unpack before we even get to miranda rights.
The moment you start talking, you're no longer using your 5th amendment rights. And anything that you tell an officer that is not truthful, such as providing the wrong password, can be considered a crime in itself. Even claiming you are innocent can be considered a separate crime if you are not proven innocent later on.
yasss
this is a feel good story
they entered the pass themselves, so by their own treasonous logic, they should charge themselves.
hope the crim charges get dismissed, and a civil suit is filed
get paid, donate a chunk
Go Team Graphene!!!!
The border agents didn't act in good faith, regardless of what they're empowered to do. They wanted the data for one reason and fabricated another to prompt the device search. The data they were interested in pertained to protest activity protected under the constitution but the lie they told was about something criminal. That anything within 100 miles of the border is constitution free tosses that out, I guess, but is extremely problematic on its own.
The founding fathers would be aghast at what America became. Hard to imagine modern America passing some of those constitutional amendments that older America passed wayyy back.
This should be an interesting case in today’s legal climate
Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password.
How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password does a wipe based on location? Either way, the user complied, and did not take action to wipe their device.
Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.
The level of duress also matters. US citizens have been shipped to foreign prisons and there's an active case of high-level officials at DOJ violating court orders about that.
while attempting to avoid armchair-law-interpreting because I really do not intend that, and I agree that this is going to be an interesting/deeply-worrying legal case:
wiping the device before carrying it across the border seems essentially identical to me. like, saying "you can't wipe it when searched" would also imply "you can't have an empty device when crossing because it may have been wiped before the search to avoid having your data searched" since people can (and often do) do that for exactly that reason.
that may very well be what they want / what they are trying to legally allow during searches, but it also seems like it'd raise a hell of a lot more outrage. it's essentially claiming all citizens are under full legal hold all the time, if they ever intend to leave the country for any length of time.
To my knowledge, no citizen has ever been prevented from reentry due to a blank or absent device. In fact they cannot block a citizen’s legal reentry for any reason, they can only detain you while they investigate.
Beyond this, “I dropped my phone in the ocean” is always a perfectly valid reason.
If you’re a foreigner and they already suspect you of something, they can deny you entry for any reason. It may be better to be denied than arrested!
similar to structuring laws, right? trying to not provide evidence is occasionally similar to destroying it.
isnt it amazing how we are able to know when something is a trick and clearly caused by your action/intention vs when it isnt? i mean sure we can contrive (or maybe even find example of) some scenario where it might be a hard grey area, but ive always found it so cool how we often operate on "top down" methods like this that logically have no basis for working out but 'common sense' happens to be common enough still
i pray that sense doesnt erode
If you have a safe in your home and you knowingly wire up a bomb that goes off when a certain lever is pulled then you lie to the police and tell them the way to open the safe is to pull that lever you'd pretty clearly be responsible for the damage done when the bomb goes off.
I don't see why this would be any different.
cause you're not harming the officer. this is more like a safe that destroys whatever is inside
> Either way, the user complied, and did not take action to wipe their device.
The user claimed to offer a password to access the contents of the device, and instead offered a password that deleted the device. That is false testimony / lying to an investigation, and is almost certainly punishable in itself.
It would depend on precisely what the ask was. Did the officer ask, "Give me the pin to unlock the phone."? In that case the command was complied with.
The "agent entered password themselves, therefore they're to blame" seems as good of a logic as "I'm going to start swinging my arms and start walking forward, so if you don't move, it's YOU hitting YOURSELF".
Maybe digital forensics shouldn't be handled by barely highschool graduates at a busy border crossing
Should we take the same approach for physical searches? If the cops are executing a search warrant on a house, and there's a safe, should they send in a safe cracker on the off chance the safe is wired with a "duress pin" (eg. thermite that burns the contents)?
That's egregiously disingenuous. Having a password that protects the infiltration/extraction of your intellectual artifacts is in no way akin to assault on someone else.
A duress password isn't a booby trap. Nothing was damaged except for the fragile egos of the man-children who weren't able to bully someone into giving up their wrong-think.
The point isn't that giving a duress pin is the same as physical assault, or that the duress pin feature is a "booby trap". It's that for the purposes of ascertaining guilt, you don't get a pass just because you're not the person that physically initiated the action.
"GrapheneOS Defends Data-Wiping Function"
who are they "defending" it from? i haven't seen anyone really make a fuss about it.
i guess "Reich Bunny" with 11 followers is who they're referring to...?
UBS had a similar capability on their laptops so they facilitate tax evasion for US clients: https://www.cnbc.com/2015/04/30/why-did-the-us-pay-this-form...
As a GrapheneOS user and a U.S. citizen that cares about the constitution, I fully support the actions taken by the individual
This is possibly the best advertising. GrapheneOS was kind of niche before. But if the US Government hates you then you're on the right track.
On one hand, I love GrapheneOS and see it as a cornerstone of digital privacy software. I have supported the project financially for years.
On the other hand, I'm worried that the publicity will only make explicit targets out of GrapheneOS users, and that you would only be using it "if you have something to hide".
"defends" is doing quite a bit of flashy work for this headline. "Feature works as advertised, nobody upset" would be a much more practical headline.
The government appears to be quite upset. You wouldn't want to upset ingsoc would you?
And this is why part of my plans for any international travel are to simply have a physical notebook with phone numbers to trusted friends/family and to buy throwaway devices on the other side (phone and chromebook or similar).
TBF, similar mindset if I ever attend defcon, etc. as well.
The crazy part is that you might be denied entering the country you don't travel with a device...
I have never heard of something like that.
Someone who is a lawyer knows any details about the US justice systems precedents with regards to the fifth amendmend (regards to self incrimination) vs obstruction of justice (by destroying evidence) as would be applicable to a duress wipe? Also would the distinction of being (or not) read their miranda rights and placed under arrest in this case make a difference as to the status of any possible obstruction?
Not a lawyer, but my understanding is that refusal to give the PIN (“remaining silent”) would be a valid application of the 5th, but not giving a false PIN. 5th does not imply the right to mislead or lie to someone investigating a crime.
Not clear on anything else regarding the duress PIN but I don’t think a 5th defense would apply.
Note that you apparently have to explicitly invoke your right to remain silent or your silence could be implied as an admission of guilt (thanks to Salinas v. Texas). I imagine you’d have to repeat your assertion multiple times, and the person demanding the PIN will tell you that you can’t use the 5th, will threaten you with arrest and additional charges, etc. Consult a lawyer and get training if you’re doing critical work where you may need this defense.
Hmm, interestingly here in Sweden we have "free evidence" (way of gathering is not considered even if "illegal", however someone doing something illegal to obtain it could instead be charged separately).
As such in a case like the Salinas one, being silent or "pleading the fifth" would be moot as both would just indicate "deafening silence" to the judges since the defendant had been cooperative up until that point.
(the Swedish judicial system has no juries, instead there's a professionally learned judge and 2 "laymen judges" appointed from political parties acting as the peoples representatives, if that triumvirate fucks up, higher courts can and often will kick rulings back down for retrials).
I'm mixed... if they really thought there was evidence on the phone, they should have seized the phone and acquired a warrant IMO to compel the valid, non-destructive PIN be given over.
As I mentioned earlier, this is part of why my own plans for international travel are to only go with a notebook/sheet with contact numbers and buy throwaway devices on the other side. I don't think I'd travel internationally with a phone or laptop at this point, and that's kind of been my thoughts for a while. Especially given the direction that many countries, not just the US have taken. For that matter, I don't think I'd ever even risk travelling to the UK or China at this point. Not that I like the surveillance state here in the US, at least I still have some rights preserved.
According to Homeland Security, within 100 miles of the border is a "constitution free zone". So there's a whole lot to unpack before we even get to miranda rights.
The moment you start talking, you're no longer using your 5th amendment rights. And anything that you tell an officer that is not truthful, such as providing the wrong password, can be considered a crime in itself. Even claiming you are innocent can be considered a separate crime if you are not proven innocent later on.
Keep fighting the good fight GrapheneOS!
yasss this is a feel good story they entered the pass themselves, so by their own treasonous logic, they should charge themselves. hope the crim charges get dismissed, and a civil suit is filed get paid, donate a chunk Go Team Graphene!!!!
Next version should wipe the phone while presenting a dummy account so they can't easily tell anything is missing.
Related:
US Government targets Cop City protester over phone operating system
https://news.ycombinator.com/item?id=49024436
is it just me or is it about once a decade somebody gets publicised for this and the government *really* throws the book at them.