FYI if you are using GrapheneOS and duress password, you can natively backup your phone. Its in settings.
For people that don’t want to be dragging into a civil rights case, can you set up a dummy interface that looks used, but doesn’t have any too important available? Like you only owned the phone for a week?
You can setup different users on GrapheneOS and switch between them.
There is also a “private area” in the bottom of the app list where you can move sensitive apps and password protect them.
Either way, allowing a malicious actor into that profile exposes more attack surface for them to exploit.
Idk. Security is a journey, not a destination.
So? My data, my choice and right to delete it, so fuck off!
He didn’t delete it. The officer did.
I wonder if he’ll sue them for damages
Just put a note in your wallet that says cell password with the distress pin. You didn’t give them the pin their illegal search uncovered it.
“They asked for my password. They didn’t specify which password.”
More like “sorry I couldn’t remember the password. I guessed, but I have a bad memory”
This is exactly the reason the government can’t force you to give your password in the US. They can’t prove that you remember the password.
-That, and the 5th amendment.
If you’re in this situation, don’t say this. You are under no obligation to explain anything, and anything you say will be used against you (and will not be used to defend you). Just shut the fuck up.
Yeah, you’re right
lol that’d be a neat uno reverse card right there
you… you deleted my data?? shocked pikachu face
Pick a lane. Either it counts as US soil so you need a warrant or it doesn’t so theres no reason for US law to apply until the person is approved.
<whisper>No one tell them about international airports…</whisper>
They have a point though. Technically from what I’ve read just living near an airport would give ICE the authority to search your phone and anything else you might be carrying if it’s within a certain mile radius. Even if you aren’t using the port of entry (airport for instance). Regardless of whether or not they have any other form of probable cause.
I don’t understand how others don’t understand that. Because it’s a hell of a conclusion to come to.
Oh 100%. I was just being a lighthearted goober about it. Lol.
It’s 100 miles. They claim 100 miles from the boarder and now “the board” is including international airports.
https://en.wikipedia.org/wiki/Tampering_with_evidence
Tunick’s attorneys accused the government of demanding access to his phone under the pretext of searching for child exploitation imagery, but without providing evidence to justify its suspicion.
Even if I had more information, I still wouldn’t have the law chops to predict where this may lead.
The accused is a Stop Cop City activist in Atlanta.
I don’t have those chops either. Also NAL. The wiki page says Tampering charges require there to be an ongoing investigation, which wasn’t the case here, so I’m thinking it wouldn’t apply. But! I wonder about spoliation. Spoliation before a case is brought, while not illegal per se, can result in negative inference,
spoliation inference is a negative evidentiary inference that a trier of fact can draw from a party’s destruction of evidence that is relevant to an ongoing or reasonably foreseeable civil or criminal proceeding
Negative inference, to my NAL understanding, means the tampered evidence may be taken in the worst light for the defense. Here, it’s all resting on flimsy and politically motivated pretext with no evidence. Still.
Needs an immigration lawyer to give an answer to this, but I’m thinking it may be legally safer to have strong encryption and refuse to unlock, rather than to wipe. Not unlocking isn’t tampering, so no spoliation, but wiping might be. Well, safest of all is to use a burner. But next best, strong encryption + don’t unlock. CBP can confescate the device, but they cannot compel you to produce a pw or unlock code.
From what I’ve gathered, I think you’re right to assume it’s legally safer to refuse to unlock rather than wipe. Also, worth noting that you can be compelled to unlock with biometrics, but not a password. On grapheneOS this means simply shutting off/restarting your device as it requires a pw after a fresh boot, even if biometrics is enable.
Even on iOS, you can disable biometrics by entering the power/SOS menu. Just hold the lock button and volume down for like two seconds, and biometrics are now disabled until the passcode is entered.
Worth noting that this doesn’t actually re-encrypt the device. The device boots in an encrypted state, and entering the passcode allows the phone to unencrypt itself to function. But disabling the biometrics doesn’t re-encrypt the device. You would need to reboot to accomplish that. But if you’re able to access the power menu, you’re probably able to hit the “Power Off” option too.
I only make the distinction because cops have started imaging devices after confiscating them. If they manage to image your device while it’s unencrypted, they can take their time with whatever new exploit/bypass is discovered in the future. But if the device is encrypted when they image it, they’d only get an encrypted data blob and would need to actually break the encryption instead of being able to use a passcode bypass method.
iOS actually has a hidden “reboot if inactive after a little while” feature, specifically to re-encrypt an idle device. Most users only encounter it when they wake up in the morning and have to enter their passcode. But the point is that cops usually process devices in batches, so it usually takes them at least a few hours to get to your device. So if the device has been idle for a while, it will quietly reboot to encrypt itself. This also helps protect against future passcode bypasses that may be discovered, because an attacker would only get the encrypted data blob if they bypass the code on an encrypted device.
you can be compelled to unlock with biometrics, but not a password
Yah, I’ve been trying to get my friends to use a pw rather than biometric unlock, for that exact reason.
I’m batting like 0 for 5, lol. Biometrics are just too convenient I guess. Plus they don’t think it will impact them personally. Which is prob true. I still think it’s best to use the way that preserves more civil rights. I just can’t convince them.
Sheep will always be sheep.
That’s precisely what a duress password is for. Feature working as intended, get a warrant.
Edit:Other connent said GrapheneOS Can we get a source for this app/technique?
https://grapheneos.org/features#duress
Graphene OS Team has developed quite a lot of other useful features and some of them have even been merged into upstream AOSP allowing others also the benefits. Recent example is contact scope for apps starting Android 17 but it was initially developed by GrapheneOS team long ago.
it needs to be reworked so that it’s difficult to discern to strangers if the phone has been wiped.
it’ll probably have to include fake phone logs, fake text messages, fake pics, etc. to make the wiped phone look like it wasn’t wiped to everyone except its owner.
for research purposes, how would one go about setting this up?
I can’t seem to find it in my set up. There is no option for duress pin under device unlock selection
Are you using grapheneOS?
Yep e/OS 3.7.1
E/os isn’t graphene and doesn’t have a duress pin feature.
Lmao, the edited comment
Eos is not GrapheneOS
GrapheneOS also has options to turn off USB port so that authorities plugging in devices to try to bypass phone lock can’t be exploited. And user needs to supply password to change the USB options.
I think he was using graphene os
US is a dystopia
Sounds like the police officer tried to gain unauthorized access to a device. And, while they were trying to crack it, they wiped all of its data.
I wonder if the police officer that did this will face criminal charges of unauthorized access and destruction of evidence.
And also there’s a civil suit in there. The officer may have deleted valuable data on the victim’s device, causing them harm. I wonder what the monetary value will be.
The duress password on graphene os wipes all the data, they probably threatened or force him so he gave them that password
They charged people with terrorism for using Signal chat.
Sounds like the cops entered the passcode… Therefore the cops erased the evidence.
who knows what would’ve happened if they bothered to get a warrant first.
To step it up even further, if using a duress pin, stick it on a note inside your phone case. Don’t say a goddamn word aside from asking for a lawyer, and when they inevitably find the written code and try it out, that’s entirely on them.
that doesn’t work if they clone it
Would be great if there was a feature that detects a clone and start zeroing itself. Or start flipping bits every few seconds/random intervals in a way that just seems like nand in early stages of failing (maybe even give false drive health data). Though I have zero understanding of the cloning processes, and imagine that it would quickly be something they would have their own detectors and mitigations.
But can’t just stop trying to make it harder/frustrating for anyone trying to access all our digital lives. They already get around our rights with how they just go ask the companies like Microsoft to get people’s Bitlocker keys (which even most people seem to not even be aware of having until Windows breaks).
Just say “it’s not my birthday, so don’t try my birthday”
That’s a good idea
“Sorry my fat American fingers accidentally entered the wrong code, you understand.”
The authorities conducting the illegal search entered the code, so the phone owner could assert that he gave them the right password and they were the ones that screwed it up. It’s a bit late for that argument, but someone could use that in the future and there’d be no way to prove it wrong.
From what I read, upon demand he gave the code to the Investigator, whomst had to watch the phone start to load and then erase it self. What a joy it must have been to watch them gifauh at that
this is literally what they accuse china of
Regardless of how it happened, entering a fascist state means that you must be prepared to wipe all your devices before crossing the border. They’ll naturally fabricate justifications to employ totalitarian measures as it’s their directive to do so. If they seize your items and violate your privacy, which they will do, at least there’s nothing but a blank slate. These days I feel it’s more important than ever to have two devices, with one being a basic phone for communication only and the other a smartphone that’s backed up and ready to be wiped at a moments notice, then stuffed into your luggage.
“Entering a fascist state”, means you should turn around and go back the way you came. Why do people assume it’s safe here?
Ideally, sure. I don’t think most people assume it’s safe here, at least not anymore. I’d wager that most people, if they had the option, wouldn’t come here lol it’s not like only tourists are coming through the border.
I’d say the consequences of not coming are easier to endure than being beaten and left to rot in a concentration camp with no due process.
That choice is a privilege in itself. Tell that to those who have loved ones dying in dystopian US hospitals.
When Tunick provided his passcode and the authorities entered it, “the screen went blank, flashed several times and the phone appeared to restart.” The authorities seized his phone anyway, before telling him that he was free to go and could enter the United States.
Very glad to hear that he’s a free man while the courts try to figure out what to do.
Also it’s hilarious that he didn’t wipe it. The officers did it. I think it’s going to be very hard to get a conviction of this activist when it was the officer that wiped the data.
no he didn’t. They asked for a password that the phone would accept. They weren’t even supposed to ask, but he gave them one. They’re the ones who entered it on the phone. And by extension they’re the ones who erased the phone.
Plus he provided a passcode that unlocked the device I don’t see the issue.
Hmm this sounds like government overreach 🤔




















