• schipelblorp@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    21 days ago

    You know, since we are entering into a lot of legal weirdness here, how about this:

    You give the cops TWO passwords. You tell them one is the duress password, and the other is the password that will unlock the phone.

    Desperate and without a warrant, they try one. Wrong try! Phone is wiped.

    In reality, both are duress passwords but they would have to prove that. (GoS only currently supports one duress password)

    Yes, it’s ridiculous, but everything about this is ridiculous.

    • droppedtacos@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      21 days ago

      And what about maybe also adding in a friend or relative that’s with you so that you can inform the cop that one of you tells only truths and one of you tells only lies. I think we’re onto something here. ‘Dispatch, I’m gonna need the Riddlemaster to come down here. We got another one.’

    • Talcosis@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      21 days ago

      Nah, write the duress password on a piece of paper and keep it in your phone case. Then keep your mouth shut. Let the cops find it and try it themselves.

        • WhyJiffie@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          17 days ago

          aand it would make the stolen phone ready to use by the thief, because I guess graphene os does not implement factory reset protection, because that traditionally relies on login to a google account

          • SpaceCowboy@lemmy.ca
            link
            fedilink
            English
            arrow-up
            0
            ·
            16 days ago

            The guy in the story we’re discussing found a way to make a duress password work using graphene.

            • WhyJiffie@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              0
              ·
              16 days ago

              “found a way” it is a feature, you can set it up in the settings. there is not much figuring out in that. but if you turn that on, and your phone legitimately gets stolen, now the thief can sell it for good money, because it is still usable. there is no easy toggle for that in the settings.

              • SpaceCowboy@lemmy.ca
                link
                fedilink
                English
                arrow-up
                0
                ·
                15 days ago

                Well yeah the thief can sell the hardware, but the data is wiped. Not expecting it to be a self destruct feature.

  • schipelblorp@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    0
    ·
    22 days ago

    Advice: if you know you don´t want your phone searched going through customs, don’t bring it! Or wipe it before you go through. I’m 100% on this guy’s side, but we’re not exactly living in a free and open society.

    • Uriel238 [all pronouns]@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      22 days ago

      This isn’t new. Journalists coming into the US in the aughts would be harassed by CBT and DHS, forced to open and unlock their laptops (and then delete whatever the officers found unsavory.

      So they’d come in with their computers fully encrypted and wouldn’t have the pass key, themselves, so it was impossible to unlock them. If they were detained unreasonably, that became a new story the next morning.

      Once through customs, correspondents would call their office and get the key.

      But it sucks if you don’t have a whole news agency to back your rights.

      • schipelblorp@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        0
        ·
        22 days ago

        Interesting. Could they hold the device, though, until it’s unlocked? I think this might be the Bad Press exception, not a legal right that would work for anyone else. Because if I gave the encryption key to a friend, they would just tell me to call the friend and get it… and if they refused to give it to me, it would because I instructed them not to…

    • thejml@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      22 days ago

      Seriously. Wipe it, claim it’s new to you or whatever, put your stuff back on later if you need to. I’m sure you can find somewhere or someone you trust to get you that data back whenever you actually need it.

      • schipelblorp@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        0
        ·
        22 days ago

        It brings up an interesting question: if wiping your phone after being requested access to it is illegal (?), would wiping your phone in anticipation of access being requested also illegal? Are we effectively required to give the federal government access to every private account in order to travel?

        • GalacticRobot@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          22 days ago

          As long as you aren’t doing it during an active investigation, no it wouldn’t be illegal. That’s the problem. Guy thought he was sneaky, and got busted. If you come in to investigate and suddenly you are deleting all the records, you are going to have a serious problem.

          • schipelblorp@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            0
            ·
            22 days ago

            In the regular world, you can delete something to keep the cops from knowing about it as long as it’s not covering up a crime. You won’t find a charge of “destruction of evidence” without an investigation of an explicit crime with probable cause.

            If they had probable cause to search his phone, they would have used it when he was in Georgia, not waited for him at the airport where he had fewer rights.

  • rumba@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    22 days ago

    That privacy was already long gone by the time of this case.

    https://www.law.cornell.edu/uscode/text/18/2232

    (a)Destruction or Removal of Property To Prevent Seizure.—
    Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both.
    

    If he hadn’t used duress and had just refused, he’d have been fine. Graphine is secure and would have had his back

    If he hadn’t given them the code and instead left it in his wallet, and they did it themselves, he’d have been fine.

    All he had to do was plead the 5th.

    He’s going to get hit with a felony for destroying data to prevent a search. There are tons of precedents in the 11th Circuit for searching without a warrant.

    A duress password is only useful if what you’d be facing is worse than 18 U.S. Code § 2232a, and then only if they don’t have enough to convict you already.

    https://www.youtube.com/watch?v=_2rokxux5cU`___`

    Dude is just protesting the construction of a large cop training facility near him. I don’t know what the fuck he did to get on the FBI radar, but I wish him good luck; he’s gonna need it.

    • Bytemeister@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      21 days ago

      Here is my problem with this interpretation…

      Is data property? Sure, ideas, concepts, photos, etc can be trademarked/copy-write protected and have some degree of ownership, but I’m talking at a much lower level here… Is the particular configuration of memory on your phone a piece of property? If no, then no property was destroyed by wiping the phone. All of the storage and memory is still intact and functional. If yes, then we must look further…is the position (not the switch itself) of a binary switch (like a light switch) a physical thing that you can own? Would you consider it destroyed if it was switched away from it’s original position?

      I don’t think you could charge him with destroying property… Destruction of evidence maybe, but the property is undamaged and functioning normally.

      Other arguments. The cop actually destroyed the data. Or, defendant claims he did not know the cops would use the pin to wipe the phone, and that they just wanted to know what the PIN was.

      I wouldn’t say there is enough evidence here to prove beyond a reasonable doubt that this guy destroyed any property in response to a search. He didn’t destroy anything, what was destroyed is arguably not property, and he may not be aware that his duress pin was going to be used on the device in the first place.

      • WhyJiffie@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        0
        ·
        17 days ago

        If yes, then we must look further…is the position (not the switch itself) of a binary switch (like a light switch) a physical thing that you can own? Would you consider it destroyed if it was switched away from it’s original position?

        the light switch is not something intended to store data, but the memory in your phone is. wiping the data destroys all the photos, media, logins, configuration on your phone, making them permanently and irreversibly inaccessible. and all of that is my property.

        • Bytemeister@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          17 days ago

          Light switches can store data. You can have open equal 1, and closed equal 0. Tada! You’re storing data on a light switch. All you need to do, is allow an electrical signal to control the position of the switch, and you essentially have 1bit of data storage right there.

          • WhyJiffie@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            0
            ·
            17 days ago

            anything can store data in some abstract sense, I don’t think that is a valid argument here

            All you need to do, is allow an electrical signal to control the position of the switch, and you essentially have 1bit of data storage right there.

            besides, most light switches cannot do that

            • Bytemeister@lemmy.world
              link
              fedilink
              English
              arrow-up
              0
              ·
              17 days ago

              anything can store data in some abstract sense, I don’t think that is a valid argument here

              You know that hard drives don’t literally store the number 1 or 0 right? We arbitrarily assign a value to a specific configuration of a material or circuit.

              besides, most light switches cannot do that

              Most hunks of silicon can’t do that either.

              • WhyJiffie@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                0
                ·
                17 days ago

                You know that hard drives don’t literally store the number 1 or 0 right? We arbitrarily assign a value to a specific configuration of a material or circuit.

                that’s besides the point. hard drives are very commonly used for large scale data storage. that is its intended use, and people are storing legible data on it, in practice. light switches? who the hack stores data on light switches, bit by bit?

                this discussion is not productive. you have already decided that destroying user data is a nothingburger.

                • Bytemeister@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  16 days ago

                  that’s besides the point.

                  It’s not besides the point. It exactly is the point. Functionally, computer storage is a stable binary state circuit, just like a light switch. When we wire billions of them together and automate the switching process, and throw in a few layers of abstraction, you get functional data. Changing the state of those switches does not destroy them, therefore changing the state of those switches is not destruction of property, unless by extension, flipping a light switch counts as destruction of property. It may be destruction of evidence, as the state of that memory or the position of the switch could be considered evidence, but it is a far cry from actual destruction of property.

                  who the hack stores data on light switches, bit by bit?

                  This is exactly how early computer programs were stored/written.

                  you have already decided that destroying user data is a nothingburger.

                  Correction: I am arguing that the alteration of computer storage is not destruction of property as written in the law that prevents you from destroying property to in response to or as the result of a lawful search.

    • curbstickle@anarchist.nexus
      link
      fedilink
      English
      arrow-up
      0
      ·
      22 days ago

      I don’t know what the fuck he did to get on the FBI radar

      Dude is just protesting the construction of a large cop training facility near him.

      That is what did it.

    • sem@piefed.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      22 days ago

      If they found a duress password in his wallet, and used it, they would 100% prosecute for that.

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        22 days ago

        They would, but he’d have a significantly better chance at winning. Having a duress setup/password isn’t illegal. if you plead the 5th on what that pin code is, i don’t think they’d have a leg to stand on.

        • sem@piefed.blahaj.zone
          link
          fedilink
          English
          arrow-up
          0
          ·
          21 days ago

          I don’t know if it would win or not. But the cops could argue that you put that piece of paper as a premeditated trap designed to wipe evidence and interfere with their investigation, if they caught you. Especially if you wrote any of that down and they found it. Honestly I’m not sure what the jury would agree with in this country.

          • DarkwingDuck@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            0
            ·
            21 days ago

            So what? Yes, that’s what the paper note is for. If someone wants to get unauthorized access, they will likely try it and wipe the phone. You have zero obligation to warn them not to do that. You didn’t authorize access.

            • sem@piefed.blahaj.zone
              link
              fedilink
              English
              arrow-up
              0
              ·
              21 days ago

              I think you’re on the right track. You could say the note was for cell phone thieves or something and you didn’t expect the police to use it. Plausible deniability.

              • DarkwingDuck@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                0
                ·
                edit-2
                17 days ago

                Even if you did expect the police to use it, you aren’t obligated to front that information to them. Anything you say or do may be used in against you in the court of law. So, the safe option is to say and do nothing at all, let them dig their own grave.

                • sem@piefed.blahaj.zone
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  17 days ago

                  I’m talking about in the court of law, when they’re claiming you tampered with evidence by leaving the note. Your lawyer could tell the jury that there were many reasons someone might have a note with a pin that erases the phone, including theft. Their client (you) invoked their right to silence, and you had no obligation to prevent the police from erasing your phone.

    • nymnympseudonym@piefed.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      22 days ago

      If he hadn’t used duress and had just refused, he’d have been fine. Graphene is secure

      Graphene devs fucked over this guy. They should apologize

      When Graphene is serious, the duress passcode will QUIETLY wipe your phone and leave it looking normal, preferably with normal-looking innocuous photos, media, etc.

      This is what happens when devs aren’t really thinking about the real world use case.

      • GalacticRobot@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        22 days ago

        They shouldn’t apologize, the dude should of known that destroying evidence during an investigation is going to land you in jail.

        • nymnympseudonym@piefed.social
          link
          fedilink
          English
          arrow-up
          0
          ·
          22 days ago

          No. If you make and distribute security-related software, you should consider the safety of your user.

          Your threat model absolutely should include this exact scenario. And you should know enough to understand and implement principles like plausible deniability and repudiation.

    • schipelblorp@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      22 days ago

      I think the application of that law depends on whether a seizure is valid (aka legal), which is kind of up in the air, as your video points out.