logoalt Hacker News

Felony charges for citizen deleting phone data at US Border

572 pointsby floathubyesterday at 12:10 PM752 commentsview on HN

https://archive.ph/SflVC

https://www.youtube.com/watch?v=_2rokxux5cU


Comments

gblarggyesterday at 11:30 PM

The decoy passcode feature should boot into a separate partition that looks like a normal phone setup, and during that time quietly erase the user's actual data. They would never have known if it worked like this.

show 7 replies
TowerTalltoday at 1:59 AM

"[...] Since 1953, the US Department of Justice has defined the border to be anywhere within 100 miles of the actual national limits.[...] According to the American Civil Liberties Union, about two-thirds of the people in the US live within 100 miles of a border. So in theory these 200 million border zone dwellers could have their phones seized and searched at any time by CBP agents without a warrant.[...]"

From the register (2023)

https://www.theregister.com/security/2023/06/01/us-court-fin...

Zakyesterday at 7:30 PM

For exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs. Imagine booting the phone from a flash drive, making an encrypted image of the phone on said drive, and writing a fresh OS before reaching the border.

There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).

Some time ago, Android with a custom recovery could come close to that, but it was fussy and as far as I know, no longer viable. Increased use of TPMs for storing credentials seems to be at least one of the reasons.

show 13 replies
patconyesterday at 7:48 PM

I used to play around on projects adjacent to Tor and TailsOS, and had an idea for a setup I was researching. It's a little intense and probably has annoying failure modes, but sharing in case anyone else finds it helpful:

- Tasker is an automation app for setting up rules for triggers and actions. It allows extension apps to be created to add new triggers and actions.

- someone at one point made an extension to add an action for wiping or factory resetting when triggered

- there was an existing extension (or core feature) to trigger when certain signals are lost or found (e.g., wifi signals, Bluetooth LE beacons, etc)

So the idea is to carry a BLE beacon (any "item tracking" one works) on your keychain, and an unassuming faraday cage pocket alongside it. If you want to wipe your phone, slip the fob into the pocket, the signal disappears, and your phone wipes. And if you don't have the keychain on you, just refuse to open it right away, as when they put the phone itself in a faraday cage (to prevent it from being remote wiped), they cause the signal to be lost, and it gets reset.

Not sure if all the pieces still exist (I dont think the tasker extension for wiping existed outside a forum post...)

show 5 replies
simonebrunozziyesterday at 6:49 PM

All Archive pages, when accessed from Italy, now are blocked by the Government:

"PAGINA INTERDETTA DAL CENTRO NAZIONALE PER IL CONTRASTO DELLA PEDOPORNOGRAFIA ONLINE (C.N.C.P.O.)"

“PAGE BLOCKED BY THE NATIONAL CENTER FOR COMBATING ONLINE CHILD PORNOGRAPHY (C.N.C.P.O.)”

Oh, we live in an interesting age.

show 3 replies
trollbridgeyesterday at 7:20 PM

U.S. citizens are going to need obtain a burner phone before returning, and load it with the absolute minimum to load boarding passes, etc., perhaps some reading material or a movie to watch on the plane, and be prepared to share full credentials for thing at the border.

(I used to do some travel patterns where taking a certain client laptop wasn’t an option. It was an absolute gigantic pain for the type of work I did, but it was just too risky to have a laptop seized and be expected to input credentials.)

show 6 replies
floathubyesterday at 12:19 PM

According to the article, he was actually using GrapheneOS and gave the border official the Duress PIN. So I guess technically it was the official that erased the data :-)

show 7 replies
zmmmmmyesterday at 10:32 PM

If you initiate a wipe before approaching immigration, which swaps the whole phone contents to an encrypted backup that you physically can't decrypt without a key that (say) a friend knows. Then you would be offering immigration the device in an unaltered state between when they request it and when they receive it. Any request for an alternative pass code or whether the pass code given will alter the state of the device can be honestly answered.

I am curious if this is still obstruction - you still defeated their intent. If the law is just about intent, you can never defeat it.

show 3 replies
neomyesterday at 12:49 PM

Legal Eagle just covered this, it's quite interesting analysis: https://www.youtube.com/watch?v=_2rokxux5cU

show 3 replies
tavavexyesterday at 4:30 PM

I'm not a legal expert, but all this seems to check out with US law. Americans need to remember that some of their constitutional rights don't really apply at ports of entry by design. This inconvenient truth for the land of the free has existed for a long time, this situation is just drawing attention to it. Their powers are far-reaching.

show 2 replies
c2h5ohyesterday at 11:04 PM

I always enter US with all of my devices wiped and restore them from backup once I'm past immigration, simply because I don't trust government to maintain the security level my job requires.

Now I'm worried that this will be held against me..

joshkayesterday at 4:41 PM

So the part of this that feels like it triggers the government issue here is that in effect you have a locally stored encryption key which gates access to the device, which was removed from the device due to duress password.

What if we flipped this to instead be something that's explicitly not on the device?

The border search stuff only applies to information on the device. It cannot compel you to provide access to e.g. emails stored in a cloud provider.

If instead of making the process of stopping searches like this be a destructive one, we instead pre-purge the key but store it offsite with the ability to get it from an online location, then this feels like it's probably reasonable here. In the sense that the 4th amendment explicitly allows "The right of the people to be secure in their persons, houses, papers, and effects, ..."

There's probably some sort of technical problem I'm missing here (or maybe this functionality is available already).

show 2 replies
braiamptoday at 1:28 AM

I am baffled that the number of comments trying to work around a problem that shouldn't exists is above zero. No, this crap shouldn't happen. It's an appalling situation that it is happening at all.

lrvickyesterday at 11:57 PM

I hope some day border agents ask for my phone, because I have not used one or even had a cell phone plan in over 5 years. Checkmate, assholes.

show 2 replies
juancnyesterday at 1:34 PM

I don't get the legal contradiction.

The search is supposed to be lawful without a warrant because you're not really in the US yet per-se, hence if you're not there, how deleting the data can be a felony?

show 4 replies
blobbersyesterday at 10:59 PM

Does anyone know if this border security inspection is a goon scrolling through your photos, or do they just copy the whole memory of your phone to a real “threat detector”.

When I used to work in cell phones and I was debugging them, when they crash I would analyze the OS core dump for things like repeated phone numbers or emails etc. Basically any thing that signifies a memory leak. But that core dump would be the entire phone’s RAM and storage.

Border guards have always been of questionable value: they inspect your TN-1 and made somewhat arbitrary decisions on your documentation. You’d go one week and they’d send you to secondary but another they’d glance at the docs and just wave you through.

show 1 reply
gchamonliveyesterday at 6:49 PM

It's like those notices "by clicking accept below you agree to giving up your data", by purchasing a ticket to visit US all your data are belong to the US.

phoghedyesterday at 1:02 PM

Seems like it would be better to have a truecrypt type of situation, where if you put in a certain pin, then it just logs you into a separate OS with nothing you want to hide.

Obviously have the duress pin if what’s in your phone is worse than the obstruction charges too.

show 1 reply
34679yesterday at 12:50 PM

Amendment 4:

"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."

Amendment 5:

"..nor shall be compelled in any criminal case to be a witness against himself, nor be deprived of life, liberty, or property, without due process of law; nor shall private property be taken for public use, without just compensation."

show 5 replies
xhrpostyesterday at 8:58 PM

Would he have been better off just refusing to give a code?

show 1 reply
hollowoneplyesterday at 9:01 PM

How did it end up, because it’s not a new thing to happen. First time I read about this guy’s border crossing case was few months ago and was of course very much highlighted for the level of surveillance govs can do.. but I also read some Time later that by the letter of law he was not proven wrongdoing.

Are we still discussing a border crossing case that is long historic or there is still an active drama for this guy going on?

btbuildemyesterday at 7:53 PM

The naivete of some of the comments here is astounding. It doesn't matter whether you're right, it doesn't matter whether it's the law, it's irrelevant that you have rights, etc. Those things are of the past now, for the US.

I think it would be easier to understand the playing field and choose your actions accordingly, if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech.

The social dynamics are the same - the abuses, the selective enforcement, the lack of recourse, the same characters in the roles of various levels of "law enforcement" and "politics". I'm so very sorry, but the best you can do from here is speedrun the collapse.

show 20 replies
jdofazyesterday at 10:58 PM

I wonder if what might save him is he asked for a lawyer before giving the duress PIN, a lawyer might have told him it was a bad idea to do it.

show 2 replies
creamedcornyesterday at 11:41 PM

How does it work for China and Russia?

show 1 reply
marcosdumayyesterday at 7:03 PM

Goes to show that he should have made an LLM do it instead.

zuzululuyesterday at 11:49 PM

But what did Mr. Tunick had to hide tho im serious what did he have (illegal?) that he chose to delete it??

i dont think it was ideological....

i bring a new device just for traveling and wireguard rdp (iphone mirror) into my home desktop

show 1 reply
adfmyesterday at 1:38 PM

I don't know about you, but don't people use encryption to retain privacy? And are people still free to manage their personal information? Doesn't a duress PIN present that information in its intended form? I'm confused.

steviehicks78yesterday at 8:27 PM

Obstruction to what? Also thought this would be covered by the fourth and fifth amendment.

hirvi74yesterday at 11:37 PM

To anyone worried, it doesn't matter how many felonies you get -- you can still be president one day.

nphardonyesterday at 8:39 PM

He's lucky they didn't ship him right off to the Dilley Detention Center

phendrenad2today at 12:36 AM

Next they'll be demanding the passwords to your dropbox and onedrive, because you "might have uploaded something from your phone before re-entering the country". Bet on it.

thomasjeff1yesterday at 6:52 PM

Why American authorities are always attacking their citizens freedom?

show 5 replies
freediddyyesterday at 11:09 PM

The difference is that this guy gave a code that wiped the device while it was under investigation. That's obstruction.

If he wiped his phone before crossing the border, he would have been fine.

If he refused to give his password to the phone, he would have been held up for a bit and then he would have to leave his phone, but he would be fine. American citizens cannot be denied entry into the US.

The difference is that the phone was wiped while it was under investigation because of an instruction he gave the CBP. That was ill-advised because that is clearly obstruction. He didn't understand the law and now he's probably going to pay for it.

And I say this as someone who had a very bad experience at the border. A CBP accused me of not being the same person on my Green Card and I had to wait 15 mins for that to clear up even though there was nothing to dispute here, it was me. The CBP are fascists and it doesn't matter who is president, this was during Obama's presidency.

maxgluteyesterday at 5:56 PM

What about none citizens? Customs kicks you out or throws you into a camp first.

E: but seriously, what happens to non citizens. What happens if you bring a burner/wiped phone? I assume digit forensics can confirm it was pre wiped but what's topping them from alleged you wiped on US soil.

show 2 replies
groby_byesterday at 8:22 PM

While I think it's an abuse of power from a moral point of view - yes, that would be the expected legal outcome. Under any administration.

You can refuse to hand over access. You can't go torch evidence. Caught Ollie North as well.

livinglistyesterday at 11:13 PM

I always bring two phones when I travel, sometimes more than two, mostly because I’m a mobile engineer so I need devices to test apps on, but also just in case of situation like this.

Brian_K_Whiteyesterday at 11:10 PM

We can only hope that it eventually gets decided that there can be no such thing as destroying evidence before a judge has initiated the discovery phase of a proceeding, outside of any standing operational requirements like business records.

IncreasePostsyesterday at 7:09 PM

What I don't understand is if he just didn't give any password, he would have been fine. It's only because he gave him a duress pin that he's in trouble.

So, in both cases the government wouldn't have access to the contents of the phone

show 3 replies
zug_zugyesterday at 8:43 PM

Well hopefully there’s a jury so this nonsense can get nullified

righthandyesterday at 8:37 PM

What about everyone does this at the border. Then what is normalized is deleting your encryption key while entering, they won’t prosecute everyone on their baseless prosecutions. Join in I say, there is no law being broken only scare tactics being applied to prevent this kind of thing. Normalize the act not the consequences.

quickthrowmanyesterday at 1:03 PM

Would it be permissible to wipe your phone before going through customs to get back into the US? If they ask to search your already wiped phone, you aren’t destroying any evidence.

show 2 replies
0xbadcafebeeyesterday at 7:24 PM

So we're presumed guilty until proven otherwise (the presumption is, any data we delete must be illegal; couldn't possibly be nude selfies that the government has no right to see)

yapyapyesterday at 10:07 PM

yikes

pjc50yesterday at 12:37 PM

Paywalled, but what is the actual charge? Is it some extremely generic "obstructing an investigation" one? The US is quite good about making court documents available on line, if someone can find it.

show 4 replies
TZubiritoday at 12:22 AM

I left this comment 2 weeks ago on a youtube short on the subject:

"I have an opinion on the legal matter. But I think it's worth noting that destroying the data was a categoric strategic blunder by the defendant. If you don't destroy the data, but just don't provide the password, they might never be able to recover the data, perhaps with the exception of a multi million dollar cryptographic attack.

Destroying the data is a strategic mistake even if there's a mildly strong case that deleting the data is a crime, as it provides no benefit at the cost of increasing the risk of being sentenced for evidence tampering. I personally am not appealed by the grapheneOS thing, but I can't see any case were that feature would be beneficial, it sounds like a shitty technology."

To me this is evidence tampering, and again to me, it's a great law to have that evidence cannot be destroyed. But even if you argue that it's a bad law, and even if you argue that this was not evidence tampering, you have to concede that it IS the law and that it IS highly likely that courts will find it to be evidence tampering, finally that there is little value to destroying encrypted evidence. It's a categoric legally strategic mistake.

And GrapheneOS is a dumb product by consequence for this matter, unless you are like some high level spy whose security model is being tortured or dissapeared instead of being put to jail.

jijjiyesterday at 7:20 PM

amatuer... when you leave the us you bring a wiped phone, never bring your primary phone/laptop/camera/etc

GiorgioGyesterday at 9:49 PM

Anyone that is surprised by this or somehow thinks this is new clearly hasn't crossed the border a whole lot. I grew up in a city along the US/Canada border. You don't fuck around with US Customs (or Canadian) agents. My cousin (not always so friendly) pissed off a US Customs agent (in the 90s mind you) and they promptly took his car and disassembled much of it looking for non-existent drugs. When they put it back together it was never the same. Their job is to be suspicious, 99.999% of the time people are completely innocent. But let 1 bad person through and it's Customs' fault for whatever bad thing they do. Not an easy job. Not an excuse for how they can misbehave either.

Is it right? It makes no difference, Customs can make your life miserable, that's just the reality of it, always has been and it can't have gotten better in recent times.

🔗 View 17 more comments