logoalt Hacker News

US citizen charged after GrapheneOS phone wipes during airport search

385 pointsby eeccyesterday at 10:21 PM250 commentsview on HN

Comments

cameldrvtoday at 1:39 AM

I’ve seen a lot of people on the internet over the years say things like “the government can’t make x illegal, it’s just y.” For example, the government can’t make wiping your phone at the border illegal, it’s just punching four numbers into your phone, just like a pin, only a different four numbers, which could just have well been your pin.

U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did. Hell there could have been a third set of four numbers that were the nuclear launch codes. It’s not the fact that it was four numbers, it’s what you were trying to make happen when you typed them. Now of course whether they can prove what your intent was when you typed them is another matter, but generally a duress pin should be for when robbers are breaking into your house, and the government will be on your side, and not when the government will be against you.

show 17 replies
rock_artisttoday at 4:13 AM

For non-graphene users (eg. Boring iPhone people like me).

So there’s a feature called Duress PIN which as explained through some comments means you put a different pin which intentionally wipes the phone. It’s not auto wipe or wipe after several failed attempts but intentional wipe of device. (Worth explanation as the current title nor the article doesn't easily explain this was made by the US citizen providing the alternative passcode)

For more technical details:

> GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).

https://grapheneos.org/features#duress

show 2 replies
sfRattantoday at 12:56 AM

Ultimately, when you choose to enter a duress PIN that will wipe your device, you have to recognize that choice may have legal consequences. I don't like the amount of power our government has at the national border when it comes to detaining and pressuring citizens, but our Constitution explicitly grants it at least some of the power it now exercises in that context.

If your threat model includes US state actors at the national border, then your security practices need to account for the confiscation of your device at that border without requiring you to willfully wipe the phone and (in the eyes of police and prosecutors) destroy evidence.

That means:

1. Don't travel with anything you can't afford to lose on device. This means setting up travel-specific password managers and hardware keys for a subset of your accounts that you absolutely need to access while abroad, and being prepared to reset those passwords and disable those hardware keys very quickly once home.

2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. Your secure setup must function without needing you to engage in those behaviors, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable.

3. Consult with a lawyer and review your security procedures from a legal standpoint. All of the above is technical and practical advice, not legal counsel and no substitute for it.

We Americans are fortunate to carry powerful passports and enjoy relatively easy international travel but, for better or worse, that velvet glove covers an iron fist we would be foolish to forget or ignore.

show 4 replies
Grimblewaldyesterday at 11:37 PM

VeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give proper password, real OS and FS decrypt and load.

Something like this may need to become the standars over duress pins which should be treated as a fallback or more extreme alternative. Right now, A single choice to reasonably and rightfully protect your privacy reuslts in jail time over something which likely wouldnt have resulted in any issues if superficial compliance was observed.

These goons, even if a branch of a facist regime, are ultimately burocrats with violent options to settle. They aren't doing forensics on your device etc. They have neither means nor knowledge to do so. They just need to tick their boxes. Did the phone unlock? tick. Did our spyware complain? no? tick. Overall appearance of compliance from person? yes? tick. free to go, next!

You just have to find ways to stay safe without agitating their workflow and all is well.

- [1] https://veracrypt.io/en/VeraCrypt%20Hidden%20Operating%20Sys...

show 5 replies
DanHultontoday at 1:34 AM

If your threat model means you can’t afford for border security to view your device, wipe the damn thing yourself before crossing the border and restore it from an encrypted online backup on the other side.

You’re just carrying a blank phone that you intend to set up and use later, and they can’t force you to install your backup onto a phone.

Now, this is sus as hell, and you’ll probably draw all kinds of extra attention, but if border security wants access to your phone in the first place, you’re already in a weird place.

show 4 replies
daishi55today at 1:58 AM

> federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City

Of course it’s about that huh. It’s quite scary how far the US will go against anyone who engages in this sort of activism.

Guvantetoday at 12:19 AM

How are they going to prove there was evidence of a crime? While destruction of potential evidence does introduce a certain amount of leeway that doesn't allow going from absolutely nothing to "evidence was on the wiped device".

Most previous court cases involving encrypted devices have required substantial proof that the encrypted device contained incriminating evidence. To be clear "you sent this illegal thing from your house" levels of evidence.

It mostly seems inept, if you are going to push to expand your powers you do it on strong cases where you know what happened. Doing it on weak cases like this gives a judge an opportunity to shut down that without giving you a chance of a meaningful conviction and without that you won't get any benefits...

show 3 replies
anonymousiamtoday at 4:23 AM

There was no warrant, nor any court order compelling him to provide the unlock code. They had no probable cause, other than that they had labeled him a "terrorist" because of his political activities. The CSAM pretext was provably just a pretext. If he gets good representation, he should be able to (eventually) beat this rap.

If he had simply refused to provide the unlock PIN, he would have walked away. They may have kept his phone, but they would never have got anything from it anyway.

incompatibletoday at 1:07 AM

One of the GrapheneOS people (I think) suggested keeping a bit of paper in your wallet with the duress pin, perhaps thinly disguised. Then the cops could try it on their own initiative. I suppose they'd become aware of that trick eventually, but then they wouldn't be able to use all those other genuine pins they find.

show 2 replies
sire-vctoday at 4:07 AM

To everyone who thinks this is somehow a violation of rights: if you were being questioned by border officers, and were asked 'Sir could you please open your suitcase', and you pressed a button that caused it to burst into flames, there isn't a country in the entire world that wouldn't arrest you on the spot. Why would 'wipe a phone when officer requests it opened' be treated any differently? Suspicious behaviour is treated as suspicious by normal people.

show 3 replies
LPisGoodtoday at 3:27 AM

> federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City.

This is practically the only thing I care about here and there are almost no details. What was his alleged involvement? How many others were targeted?

hyperion2010today at 3:57 AM

I suspect that this will ultimately be thrown out for a very simple reason which is that the government will have to prove that a duress PIN was actually entered. That is going to be quite difficult unless the person charged openly admitted it.

The reason is because anyone running an os with a duress PIN that has done nothing wrong can be accused of using a duress PIN because the whole point of the duress PIN is that it looks like you just have a normal phone.

Running a normal apple operating system with just stock apps? Boom, you're a criminal because you obviously used a duress PIN and have something to hide! There is no way to prove you didn't use a duress PIN because the phone was "wiped."

Now unfortunately grapheneos probably leaks information so that a duress "unlock" can be differentiated from a standard unlock by some means. If not then kudos. It looks like it is done instantly by keeping everything encrypted and just zapping the keys, but it also needs to actually unlock to something instead of rebooting to prevent leaking the information that a duress pin was used. Not sure how fiesable that would be though.

show 1 reply
andrewflnrtoday at 3:24 AM

Why the hell doesn't the "duress PIN" just open up a sanitary profile? Bonus points for letting you set it up with plausible data before designating it as the duress profile that, when opened, wipes your real profile in the background.

> "the screen went blank, flashed several times, and the phone appeared to restart,"

How about flash some red lights and play an airhorn sound effect, too.

show 1 reply
mullingitovertoday at 2:09 AM

Seems like they’re going to have a struggle proving intent. “I was stressed out and afraid and I got the passwords mixed up” would be the magic words I’d hear as a juror and I wouldn’t be able to vote to convict.

show 2 replies
istjohntoday at 2:57 AM

Perhaps a way to avoid this would be to have the duress pin trigger not a device wipe, but a device encryption with a long, pre-set key that you would store in a safe place when setting up the duress pin. Then you haven't destroyed the evidence, but the data is irretrievable without your cooperation. Also, if you don't actually have the key saved, it would in fact be destroyed, but the prosecutor would have to prove that you don't have the key saved somewhere.

show 2 replies
ApolloFortyNinetoday at 1:36 AM

The article seems to be muddying the water bringing up grapheneOS itself. Or maybe it's the EFF.

>Experts said the legal approach is unusual and may be the first time the law has been aimed at an operating system. "It's concerning – and sends the message that [GrapheneOS] is criminal by default," said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.

Is the actual case about banning the OS? Because it seems pretty clear the case is about the result (the phone being wiped with a special passcode).

The better defense imo would be one of those 'wipe the phone if you get the password wrong x times' and try and claim you forgot under pressure. At least if you wanted to wipe the phone without being accused of destroying evidence during a search.

jamesontoday at 2:07 AM

> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart.

I'm confused to understand if Tunick did anything illegal here. If the authorities want the phone, they should have the warrant and seize it without Tunick's permission.

It appears authorities did not have the warrant which give Tunick all the right to do whatever he desires with his property.

What am I missing here?

show 4 replies
asdfxkcdtoday at 3:43 AM

Maybe also shows that the duress PIN feature could be implemented better. Booting into a completely fresh phone is suspicious. There also shouldn't be any visual or other indicators of that happening.

In the old TrueCrypt containers you could set an optional second password that would decrypt a different volume. The size of the container file was always the same, a decrypted volume always showed the full container size, the portion not occupied by the data in the main volume was filled with noise, and the data on the non-loaded volume was not protected (so you could erase it without warning by storing too much on the loaded volume), making it practically impossible to prove the existence of a second volume either way in a search situation. I guess there was a reason why the project was stopped.

anduril22today at 1:13 AM

As a citizen the safest way is to just refuse. They can’t refuse entry. Not the same for LPRs.

dotcomatoday at 4:37 AM

In Russia? In China? In Iran?

Nope, in the US.

thelastgallontoday at 2:43 AM

Its best for all of us to figure out how to use phone-as-a-linux-vm with the physical phone just hardware. It will solve many problems: commoditize the phone ecosystem, eventually making them repairable, run our own apps instead of apple/google. Access phone-vm from laptop/desktop ...

teravortoday at 12:41 AM

maybe write down the duress pin somewhere in your wallet. let them make their own assumptions and erase the alleged evidence on their own.

comrade1234today at 12:37 AM

So let them just sieze your device. Don't unlock. You'll get it back in a few months.

NDlurkertoday at 3:41 AM

They violated his rights and he pulled a prank on them. They need to chill out.

ww520today at 2:25 AM

Charged is not convicted. Anyone can be charged with anything if the prosecution is vindictive.

drweeviltoday at 1:04 AM

While I like the idea behind GrapheneOS, I'd rather not place myself in jeopardy of some ridiculous charge like this one. I prefer to travel with a travel device, some inexpensive phone and/or laptop that contains nothing interesting. If they then wish to take it from me because I won't unlock it, then have at it! That said, the situation with respect to our Bill of Rights at the border has gotten ridiculous.

show 1 reply
amanaplanacanaltoday at 12:13 AM

If they were searching for evidence of a crime, what crime was it?

show 2 replies
siilatstoday at 1:27 AM

Having just gone through having to give pin to cbp you just need the apps on your phones to have separate pins so when police unlocks it, they cannot unlock WhatsApp afterwards. Faceid or unique pin. Problem is your phone pin overwrites Face ID

guywithahattoday at 2:39 AM

> US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search

I really don't like this title. Officers asked him to open the phone, which he pretended to do, but instead wiped the device

> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart. The defense motion states that "the screen went blank, flashed several times, and the phone appeared to restart," resulting in the loss of data.

The title implies the agents maybe entered too many pins by mistake and the device auto-wiped, or that it reset itself with no human intervention, which isn't what happened. This is more like shredding paper when the FBI arrives at your office, which most people would attribute to destroying evidence. I hope he wins the case in principle (I think there's a risk of a slippery slope here) but it wouldn't be a moral tragedy if he lost.

MikeNotThePopetoday at 1:11 AM

There needs to be a simple feature to wipe your phone and then restore to a point and time. That’d be really convenient.

show 1 reply
iamlepperttoday at 1:55 AM

Instead of a PIN that wipes the device, it would be much better to setup a special PIN that logs the user into a sanitized, completely separate profile with generated content of no practical value. This would create plausible deniability, and be sufficient to allow low-level border agents to look through a phone and pass any checks without raising these kinds of alarms. The wipe PIN should still be an option, but should be separate, and only be for cases where you suspect a forensic imaging or search of the device is to take place and the legal consequences outweigh the risks.

calvinmorrisontoday at 2:03 AM

Related, There was a local guy who was held 'in contempt' for 4 years for refusing to turn over his password/encryption key

https://arstechnica.com/tech-policy/2020/02/man-who-refused-...

nicoistoday at 3:32 AM

could graphene support multiple duress PINs?

feds: "unlock your phone or else" victim: "um, you're stressing me man. It's either 1234 or 4321, I forget. One of them wipes the phone, the other will unlock it."

Whichever PIN they try, it wipes the phone, but the feds can't claim it was deceitful, just unlucky.

ulfwtoday at 3:03 AM

Every day I thank the lord that I left the US for good and never went back

deadbabetoday at 1:54 AM

I don’t understand why phones can’t just have decoy profiles you can activate via PIN that look like regular harmless user profiles? Especially now with AI you can quickly populate with a bunch of plausible data.

Or better, have PIN for taking you to your criminal/secret profile instead.

show 1 reply
zuzululutoday at 1:52 AM

why not just have a separate device for traveling ?

show 2 replies
crypttalestoday at 1:12 AM

[dead]

flerchintoday at 12:53 AM

I just wouldn't want my dick pics to get out.