Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
52% Positive
Analyzed from 13707 words in the discussion.
Trending Topics
#phone#data#border#don#pin#more#law#evidence#https#search
Discussion Sentiment
Analyzed from 13707 words in the discussion.
Trending Topics
Discussion (418 Comments)Read Original on HackerNews
I think it would be easier to understand the playing field and choose your actions accordingly, if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech.
The social dynamics are the same - the abuses, the selective enforcement, the lack of recourse, the same characters in the roles of various levels of "law enforcement" and "politics". I'm so very sorry, but the best you can do from here is speedrun the collapse.
I'm pretty optimistic that after the next general America will be ready to give up on the extremity of late turn over a new leaf. I fully expect a new president to be ushered in, whether R or D, and for some level of normalcy to start creeping back.
The Soviets lost eventually, I don't think America can lose. Canadians like myself have watched America win for our country's entire existence; I am unconvinced that a decade of silliness is enough to compare America to East Germany.
In 2016 I remember Americans saying this was the end of the line and the country was doomed. 10y later they're richer than ever and its companies have global dominance of the most world-changing technology of the last 20y. I just don't think "the collapse" is coming anytime soon.
If anyone's interested in a friendly wager, my email is open. I'll happily go 1:1 odds that America will have a new president come 2029 and the country will still remain the world's richest and most powerful.
Canada is moving further from US, not closer. Canadians who support Americans are in the minority at the moment.
I'm not sure how a new US president would be able to turn it around.. further more, what's to say that the president thereafter will follow suit? How about the next 5?
It's becoming more obvious every day. And yeah, people in 1910 watched Europe dominate the world for about 1500 years. Yet it came to an end.
If you want to Speedrun the collapse, vote for trump. He sure is making a good job right now with diplomacy, lack of long term planning and just getting all your allies to hate you.
[1] I'm not defending the behavior of border control here, but I also don't think we need to overreact to this one example which is exactly what is happening.
Yeah, that's awful. As far as federal overreach of power goes, that's pretty inexcusable. I'd probably posit that COINTELPRO in the 60s was more insidious, but that doesn't discount this story individually being terrible.
I still maintain that America is not in the midst of its own demise and a comparison to East Germany is inaccurate.
You are undoubtedly correct that at some point there will be new leadership in the US.
Politics makes leadership change a possibility. Biology makes it an inevitability.
But I don't think the evidence is very strong that switching from one man to a different man, even if the new man wears a blue hat instead of a red hat, will make that much difference against capital and its surveillance state.
This isn't a false equivalence "both sides" argument. I'd greatly prefer the blue hat over the red hat.
But the blue hat only makes the underlying forces of late capitalism a little slower and a little less vicious, while simultaneously legitimizing that system.
The guy doesn't have the stomach for real totalitarianism. Just populism, corruption, and weakening the country.
> I think it would be easier to understand the playing field and choose your actions accordingly, if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech.
it's as long as you're not doing anything wrong you don't have to worry about it Then once changed the definition of what wrong means.
If you're not a criminal you don't have to worry about it That's for your safety Then they changed the definition of what a crime is
The fight for privacy is not a regional issue. Every country faces this stuff.
If it walks like a duck, and quacks like a duck.. might just be a duck.
I don’t believe those living “normal lives” in East Germany or the Soviet era considered the police to be evil and invasive the way we do today.
"normal life" under the Stasi was constant political terror and suppression.
The death counts are low because they thought death too little of a penalty for opposing them - they used psychological warfare (https://en.wikipedia.org/wiki/Zersetzung) and torture instead.
Soviet famine of 1930–1933
"It is estimated that 5.7 to 8.7 million people died from starvation across the Soviet Union. In addition, 50 to 70 million Soviet citizens starved during the famine but ultimately survived."
https://en.wikipedia.org/wiki/Soviet_famine_of_1932%E2%80%93...
Great Purge
"Scholars estimate the death toll of the Great Purge at 700,000 to 1.2 million."
https://en.wikipedia.org/wiki/Great_Purge
It’s a lazy, complacent take.
the stasi were spying on people and putting them in jail. what exactly is your claim about the difference? is it a difference in distinction or a difference in degree?
What we hear about is far from comprehensive, and many of the atrocities won’t be unveiled or investigated until the next decade.
The Epstein cover up shows they’re used to keeping secrets.
I’m not sure why we’re pretending there’s not a convicted felon in charge of the entire system.
Some dark, dark things happened in the USA, and almost every progression had a corresponding backslide - but the tick-tock has always ticked further towards a freer, more equal, and more equitable society.
Progress doesn’t always (ever?) require complete collapse.
I’m willing to hope this era is another ‘tock’. But that does require people to not just give up (or even work to accelerate the backslide?!) as you seem to be suggesting is the best course of action.
This is a popular sentiment, not a statement of historical fact. Arguments both for and against this are credible.
There are just so many ways in which this seems crazy to me. I feel like you think you’re luring me into some sort of rhetorical trap - but to pick the two elephants on the room, a large proportion of the population was literally owned by other people, and only white male landowners could vote.
Or even 50 years ago? Even in the 1970s, there were places in the United States that women couldn't get a checking account without a man co-signing on the loan.
We can certainly take issue with how rich countries oppress and exploit poor countries today, but you can't honestly say it is worse today than it was during colonialism.
That's just too ridiculous and absurd for most people to accept, thankfully. I accept reality, not social media narratives.
> The social dynamics are the same - the abuses, the selective enforcement, the lack of recourse, the same characters in the roles of various levels of "law enforcement" and "politics"
What you're describing is politics in general. The question is not whether abuses occur (they do, everywhere), but whether the system is built to be resilient and course-correct over time.
The thing about freedom is not just that it's less miserable than the alternative; more importantly, freedom enables a feedback loop where people's individual choices carry corrective information: what they buy, what they sell, how much, at what price, who they vote for, what they write/publish, what they read, what they say etc. The system at large can correct itself over time if (a) these choices are allowed to have power to influence the system, and (b) the courts enforce justice without interference by the ruling party.
Not a single communist country in the 20th century stayed communist for more than a few years when only 2 freedoms were allowed: (1) freedom of the press, and (2) freedom of the courts from control by the ruling party.
The Soviets and East Germans suppressed every form of freedom that carried information or potential corrective power, because they maxxed on staying in power above all - they effectively had to. No one wants to be under real communism/socialism[0], so for it to be stable it has to be maximally suppressive.
[0] see various records of escape attempts, such as https://www.ebsco.com/research-starters/politics-and-governm...
I think it's more effective to stick to our own history because this country has always been a struggle for workers outside of a small very respite after WW2 that has been actively fought against and weakened since.
This is HN. https://xkcd.com/538/
This is a pretty silly take. If you actually follow the news, all of these issues are getting pushback. It's not at all clear that even a competent fascist-leaning government would be able to push through what the current one is trying to do, and sadly for them, competence in their ranks is in short supply.
The bigger issue has nothing to do with the faddish concerns of the current government. The era we should be looking to is not East Germany/late Soviet - it's more like the Gilded Age. Robber barons need to be dealt with from time to time.
It's a temporary situation, it isn't necessarily a permanent situation.
Tell me how you think East Germany is doing these days.
And no, it doesn't have to take 40 years to right the ship, so long as people get their heads out of their asses and vote. Things are likely to change by the end of this year, and in another 2 years we could have a very different government that could undo a lot of the bullshit going on right now.
It's still worrying! His supporters still number lots of people who a) are still somehow too gullible to realize Trump and the MAGA crowd are not going to make their lives better, and b) actively want what's going on. But there are easily more eligible voters in the US who wouldn't vote for a Republican with a gun to their head, or who are finally starting to understand that "sticking it to the libs" is hurting themselves.
It's not going away, but it's likely that it's declining, and possible it will continue to do so. Whether or not it declines quickly enough, before these jackasses consolidate power and break what's left of our institutions... well, that remains to be seen.
It reminds me somewhat of the state of the Weimar Republic. The democratic parties failed which gave an opening to the nazis.
That's half the people who showed up to vote, not "half the voting population". 1/3 of the eligible voters simply didn't vote, and from the people I've encountered that don't vote, they are mostly left-leaning.
No, stupidity and self-harm aren't going away, those are human traits. The current admin is actively hurting everyone, with tariffs and stupid wars he campaigned that he wouldn't start, ICE in every city everywhere causing chaos even to right-wing supporter-owned businesses (they wanted immigration reform but not like that!). This admin has shit the bed, and even his supporters are feeling that. They are now in the "finding out" phase, and the next phase doesn't look so good for republicans in the next election because of it.
Where's the Project 2028 book?
Is there anyone credible putting together the Executive Orders to undo the stack of shit, is anyone putting together a short list of District Attorneys to interview on January 21, etc?
In terms of the ending, East Germany was nearly an ideal case. The state just sort of gently fell over. The country got absorbed into a friendly neighbor. There wasn't much loss of life, no widespread destruction.
Then there's East Germany's predecessor state, which ended because it decided to wage war on half the world, and its people bore the consequences. Millions dead, cities wrecked, occupation by foreign armies, the country carved up. "This too shall pass" isn't always a good thing.
Or look at the state that created and sustained East Germany. Borne out of violent revolution, decades of repression, collapse, turmoil, economic hardship, brief flirtation with democracy, de facto dictatorship, no end in sight.
My biggest worry with the US right now isn't the government itself. It's that so many people want this government. Voting doesn't help when the voters want the bad stuff. We could have a very different government in another two years if the people want it. I'm not convinced they do. If they do I'm not convinced that sentiment will last. We already went through this once, and the "actually, let's not give the shitheads power" sentiment fell apart by the next election.
> And no, it doesn't have to take 40 years to right the ship, so long as people get their heads out of their asses and vote.
so then you admit the outcome here is contingent/conditional. do you understand that means we are already in dire circumstances if the outcome isn't certain?
There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).
Some time ago, Android with a custom recovery could come close to that, but it was fussy and as far as I know, no longer viable. Increased use of TPMs for storing credentials seems to be at least one of the reasons.
One of the laws that's enforced pretty well in the USA is the protection against unreasonable search. Most of the time, a search requires showing a judge evidence that the search is more likely than not to reveal evidence of a crime. Exceptions are narrow and specific; the government's options to punish someone who refuses to decrypt data at the border are limited to brief detention and seizure of the medium.
Not yet tested is the idea that erasing data on the spot satisfies the purpose of the border search exception, which is to prevent importation of things that are illegal to import. This case might address that question.
Edit to add that its also more difficult than it should be to protect and exercise the right against unreasonable search. If a cop knocks on your door its a consent-based interaction. You can simply not respond, but if you do happen to crack the door they can and will look in for any signs to claim as probable cause. Further there are cases where a person stepped out to talk and when they turned around and walked inside the cop slid right in behind them and later claimed in court the open door was implied consent. (I don't have a link to the court docs unfortunately.)
then consider this paired with the implementation of mass data sharing between the alphabet agencies, surveillance data sharing from private companies like Amazon Ring, Flock, Clearview, etc. and NSPM-7 ordering agencies to create JTTFs to target organizations like BLM
then consider the unmitigated use of force by federal law enforcement agencies like ICE
I think if this were 1995 your point might be fair but those days are unfortunately long gone
"In United States criminal law, the border search exception is a doctrine that allows searches and seizures at international borders and their functional equivalent without a warrant or probable cause. Generally speaking, searches within 100 miles (160 km) of the border are more permissible without a warrant than those conducted elsewhere in the United States."
https://en.wikipedia.org/wiki/Border_search_exception
213 milion people live in this zone.
https://www.aclu.org/know-your-rights/border-zone
> In a full banana republic, technical compliance with the law will not prevent consequences for failing to do what the authorities want. In a jurisdiction with perfect rule of law, it always will.
I think you may be misunderstanding that many laws, even in fair, just societies, are intentionally designed to be flexible. The real world is so variable and messy that in many cases it isn't feasible for a law to be written such it can be unambiguously determined whether or not a specific action violated the law. Laws often rely on humans using context to judge whether something violates the spirit of a law, and in a just society, this is a good thing.
My point is that I don't believe the idea of "perfect rule of law" is sensible. Law is always necessarily a bit fuzzy and nebulous.
Americans aren't standing up against this, but they might have considerably more interest if the government was instead trying to ban encrypting data in cloud storage for everyone.
There's also just the fact it's ridiculous I can't have a spare phone ready to go in a few minutes and get it back exactly as I left it.
It's worth noting wiping a device shortly before an anticipated search could also be considered destruction of evidence in the same way. It doesn't have to be done after a request for the data to be considered that.
> There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).
This was likely the best move for him to take. They could have held him for a while and wasted his time but eventually would have had to give him access to a lawyer and let him go. Unless they had a recording of him entering a PIN/password, they were nearly certainly not going to get his data from it. He very likely didn't gain anything from wiping it.
He did help every GrapheneOS user by spreading awareness of the duress PIN/password. It was designed around an adversary aware of it and therefore not wanting to attempt using a PIN/password obtained via coercion. In the future, we want to integrate the feature into the secure element rate limiting for key derivation so it can't be avoided by exploiting the OS.
You're always been able to backup and restore your iPhone to your local Windows PC or a Mac using free first party software from Apple.
[0] https://en.wikipedia.org/wiki/ESIM
How is this any different than refusing to unlock the phone? It just seems you've added unnecessary extra steps.
It's the same thing. They punched in a code, they are presented with a wiped phone. Can they prove the guy gave them a distress password and wasn't simply carrying a wiped phone to begin with? No, but they just need to imply that is the reason to charge him with the felony.
It doesn't even care about plausible deniability.
Best you can get away with is lack of suspicion. Have a secondary phone with some standard apps on that you use now and then so theyhave a history and just look like you are just not a technical person and read novels on dead trees instead. A lot of work but likely works.
They don't get any indication that there was data there to be deleted, and you don't just factory reset but flash w an image of a clean phone that's been used. It has apps, it has accounts, it looks to the untrained eye (because that's who's looking at it) like a phone that was used normally by someone who has done nothing wrong.
The transfer and backup system are pretty much the same mechanisms.
Restoring is probably order of ~1 hour to go through all the setup. Then some hours to sync any data and updates that need to be redownloaded, apps reinstalled, etc.
- Tasker is an automation app for setting up rules for triggers and actions. It allows extension apps to be created to add new triggers and actions.
- someone at one point made an extension to add an action for wiping or factory resetting when triggered
- there was an existing extension (or core feature) to trigger when certain signals are lost or found (e.g., wifi signals, Bluetooth LE beacons, etc)
So the idea is to carry a BLE beacon (any "item tracking" one works) on your keychain, and an unassuming faraday cage pocket alongside it. If you want to wipe your phone, slip the fob into the pocket, the signal disappears, and your phone wipes. And if you don't have the keychain on you, just refuse to open it right away, as when they put the phone itself in a faraday cage (to prevent it from being remote wiped), they cause the signal to be lost, and it gets reset.
Not sure if all the pieces still exist (I dont think the tasker extension for wiping existed outside a forum post...)
Perhaps less likely to go wrong than my original proposal when living normal life, as it might wipe if the BLE signal randomly gets lost.
It would be nicer if you could leave phone in cage during security, and remove beacon while loading airport trays ("remove all electronics from their cases..."). the only chance for a failure mode is only when you're going through security, and have the fob outside its case..
But you'd need to be able to leave your phone in the faraday cage pouch while going thru security, which is only ok if they don't notice... (maybe they commonly don't notice small faraday pouches aren't empty... Maybe they wouldn't if you had a secondary mobile device...)
Only once you're getting invasively searched would they (ideally) dump the pouch out into the tray with your phone.
Both approaches have situations they wouldn't work in. If you're extra paranoid you could do both.
Isn't that the exact same situation here that resulted in felony charges? Border agent was given a duress PIN and wiped the phone for the owner. Now owner is charged.
This requires no action whatsoever from the phone's owner, you could even be unconscious/dead and it would still work.
Regarding the motivation for usbkill mentioned in the article: I too was motivated to think on this stuff in relation to my sense of injustice around Ross Ulbrecht, and wanting to think of some way that someone in his position could avoid getting caught. One creative variant in my thinking involved embedding the BLE beacon inside a rubber ball that could be launched and lost track of. Or maybe embedded in heel of a shoe and ditched in transit haha
They're also now well aware of the GrapheneOS duress PIN/password feature. It was designed to work against an attacker aware of it by acting as a deterrence. If they're aware of the feature, it discourages them from trying to coerce a PIN/password and attempt to unlock with it. We aren't fond of features depending on an attacker being unaware of them and this isn't one of those.
Pixels have a high quality secure element enforcing a maximum of 20 unique attempts to derive the encryption keys for each separately encrypted profile. There's also very aggressive rate limiting between the attempts. It filters out duplicate attempts by temporarily remembering the previous 5 unique attempts to make the rate limiting more usable. A misremembered PIN/password repeatedly entered over and over will only use up 1 attempt.
Android does have standard support for enabling wiping after N attempts and an open source app can be used to set a configurable limit rather than specifically after 10.
"PAGINA INTERDETTA DAL CENTRO NAZIONALE PER IL CONTRASTO DELLA PEDOPORNOGRAFIA ONLINE (C.N.C.P.O.)"
“PAGE BLOCKED BY THE NATIONAL CENTER FOR COMBATING ONLINE CHILD PORNOGRAPHY (C.N.C.P.O.)”
Oh, we live in an interesting age.
(That's one of the reasons why it's trivially easy for foreign visitors to China to bypass the Great Firewall.)
If you were on wifi, that's notably interesting.
(I used to do some travel patterns where taking a certain client laptop wasn’t an option. It was an absolute gigantic pain for the type of work I did, but it was just too risky to have a laptop seized and be expected to input credentials.)
There are vendors that sell the technology to adversarially access phone data, the "Before First Unlock" is the safest state a phone can be, but it's not infallible. The safest option is to have a burner or factory-reset phone with nothing on it, even if the hack succeeds.
A compromise to this is that many phones have a "lockdown" mode, where it isn't fully off but refuses to accept biometrics until a code/pattern is used to bring it to a more day-to-day mode.
It's less-secure than being fully off, but it also means if you do need to access your phone you can do so more-quickly.
Sad that we have to accept this as a risk of international travel, but here we are.
The important wrinkle is that CBP’s published policy expressly guarantees that a person being admitted as a U.S. citizen won’t be denied entry solely because CBP couldn’t inspect the device. It doesn’t give lawful permanent resident (green card holders) that same explicit statement. Instead, it says refusal by a “foreign national” can be considered in an admissibility determination.
It's actually been on the books for a while (decades at least) that customs can search you at the border without a warrant even if you are a citizen.
This case seems to have become a big 'Trump bad' poster child (people are calling the US East Germany in these comments...), but if this exact scenario happened at least in the last two decades (I found an example upholding the searches from 2004) then it would at least be possible to charge them with deleting evidence. Even this probably would have been nothing if he refused to give up his password, not being required to provide a password has been upheld for years. They can seize your phone for some time but I'm unsure on the times they ask and then just let you move on when they find out your a citizen.
Then log in with another temp account and use that for border pass etc, and then after border checks log back into your normal account?
or have a good enough decoy or encryption system in place. Such as pressing a button to lock or replace key documents but keep the rest intact. So what looks like a sensitive document omits key information but still appears to be legit to observer.
Why would the bomb squad trust the box owner to help them defuse it? To understand the issue, you have to construct a proper analog.
But if it did, you'd still be on the hook for the bomb, even though technically the LEO set it off through incompetence.
Briefly: no.
Less briefly: <https://news.ycombinator.com/item?id=49060780> and <https://news.ycombinator.com/item?id=49060716> (from the grapheneos HN account directly).
Hell, I think a setup that doesn't wipe anything, but just drops you into a sanitized, isolated profile for the border agent to look at, would be fine for many users. Certainly you wouldn't want to use this in truly high-stakes situations where it's likely that your device will be confiscated no matter what, and analyzed to death, but for the simple "border agent wants to snoop on my data for a few seconds" case, it's likely sufficient.
(As always, risk analysis can be hard, humans are often bad at it, and not everyone's threat model is the same.)
Even a duress PIN which triggers predefined deletion of certain folders, messages and apps could reduce law enforcement exposure significantly.
Reliably deleting data at the scale of the whole data partition, a secondary user or a Private Space is fully supported but requires a reboot or shutdown to truly complete it.
After wiping key derivation material needed to obtain the key encryption keys in multiple ways and wiping the encrypted disk encryption keys, the OS can still access the data. It still has data in the page cache, in registers and elsewhere. There are still a bunch of system processes with data tied to what was removed. The OS is still fully functional after the nearly instant wipe of everything needed to recover the data again. It can still access all data other than what's encrypted with hardware keystore keys and not currently decrypted.
The wiping process for the duress PIN/password is completed with a shutdown which tears down everything, zeroes memory and provides at least a small time window where the hardware is powered off too. A reboot would also work and the boot process has explicit zeroing of memory, registers, etc.
We decided to use shutdown for the duress PIN/pasword but a reboot is a valid approach too. Our locked device auto-reboot timer feature we first shipped in 2021 relies on the zeroing done by GrapheneOS for both the process of the OS tearing down and then again during booting to return the device to Before First Unlock state.
> also create a semi plausible artificial profile to hide the deletion event.
It isn't feasible to fool forensic software so it largely wouldn't work against state actors. It nearly certainly wouldn't have helped in this situation in the news. They aren't reliant on a non-technical person sifting through a phone. They'll just hook it up to a laptop and follow the data extraction procedure which involves enabling ADB. The software is aware of GrapheneOS can guide people through dealing with anything different about it. They've had a lot of trouble with extraction via ADB for GrapheneOS since the vulnerabilities they exploit via ADB keep getting patched or blocked it exploit protections but it isn't realistic to block extraction with them having the PIN/password. They could just enable the encrypted backup service in the OS instead and then use CLI tools to extract the data from there with the seed phrase. They don't do that because they want everything rather than only nearly all app data. They also have special code to deal with apps such as Signal with their own layer of data encryption since the data taken from their app data directory is nearly all useless by itself.
There's also quite a difference between wiping and rebooting into a not very plausible environment with decoy data set up by the user in advance compared to not properly wiping and giving access to a decoy profile. Bear in mind the OS can still access nearly all data after the wipe until a reboot. It could make a best effort attempt at purging as much as possible from memory, but the OS is not designed to continue functioning with all of the data disappearing. It can't just wipe all loaded encryption keys without crashing and rebooting anyway. It also has a ton of data still around in caches and elsewhere. We don't want to just do a best effort job cleaning up as much as we can but rather reliably prevent recovering any of the deleted data.
We could definitely add a duress PIN/password which wipes only specific secondary profiles, reboots and has the device still functional with whatever data was in the main user still there. That's a feature we can add, but it's important to note that it will not hide that there was deletion of data. It's easy to detect, and it's not feasible to hide that it happened. Many steps can be taken to make it less obvious, but it will still be easy for software aware of it to detect. Even a massive overhaul designed to perfect it would not address the SSD itself giving away what happened for more advanced analysis.
We aren't going to add a decoy profile compromising the security of the device and providing a way to recover data in a state where it isn't at all unrecoverable yet. We did already plan to consider a 2nd duress PIN/password which only wipes specific secondary profiles, but we need to make it clear that it cannot stealthily wipe them to users.
A duress code might let me wipe my phone when someone holds a gun to my head and demands I unlock it. Problem is, there’s still someone holding a gun to my head.
The actual solution is cloud backup + re-image after the border.
but that's not the point, the point is to not wind up in court by presenting a phone that no long contains evidence but seems plausibly like your phone so doesn't arouse suspicion
Evidence Tampering
https://xkcd.com/1494/
> Tunick provided this code to an agent, who entered it on the phone, after which “the screen went blank, flashed several times and the phone appeared to restart.”
e.g. in Hungary the authorities treat it as a felony to possess an equipment that can record video or sound and it's not obvious when looking at it. 2-8 years in prison for mere posession, i.e. even if it's turned off in your backpack. random nonsense that if it can also make phone calls then it doesn't qualify (the above is the law paraphrased).
You know, the same way we would be rightfully outraged if Apple was allowing applications to turn on the web cam without signaling to the user that the camera is engaged.
That’s all aside from the fact that Hungary was run by authoritarian minded people. But just as I think it should be illegal for cameras installed in glasses to work without an indicating light, I don’t see how this recording light situation you are describing is really such a highlight of Orban’s excesses.
UK is same.
*https://www.nbclosangeles.com/news/local/la-family-120-days-...
*https://www.militarytimes.com/news/your-military/2026/08/20/...
Republicans might as well rename their party the Democratic Fascists of America at this point.
I'm reading Stefan Zweig right now, he was a prolific Jewish author from 1890s until his suicide in 1942, living as an exiled Jew from Austria in South America. He has written many words, over a century ago, that would support your claim.
1. Was there a lawful entitlement to the papers? 2. Were the papers protected private property? 3. Were the papers released to the wind intentionally? 4. If intentionally released was it expected that they would disappear or simply fall to the ground?
A couple easy technological analogies: 3. "Sorry, I gave you the wrong code by mistake." 4. "I thought it would go to a private guest mode, not delete everything!"
What if we flipped this to instead be something that's explicitly not on the device?
The border search stuff only applies to information on the device. It cannot compel you to provide access to e.g. emails stored in a cloud provider.
If instead of making the process of stopping searches like this be a destructive one, we instead pre-purge the key but store it offsite with the ability to get it from an online location, then this feels like it's probably reasonable here. In the sense that the 4th amendment explicitly allows "The right of the people to be secure in their persons, houses, papers, and effects, ..."
There's probably some sort of technical problem I'm missing here (or maybe this functionality is available already).
But...
The issue at hand is the "locality" of the encryption header. He merely facilitated its deletion, not the data.
If he had a backup at home, is that still a felony?
What about if he had a backup on a flash drive with him?
What if he never had the header on the phone to begin with and used a detached header on a flash drive?
Are detached headers (a thing you can easily do with LUKS) now de-facto illegal?
This whole thing is making me feel rather uneasy about the bigger picture.
> The border search will include an examination of only the information that is resident upon the device and accessible through the device's operating system or through other software, tools, or applications. Officers may not intentionally use the device to access information that is solely stored remotely. To avoid retrieving or accessing information stored remotely and not otherwise present on the device, officers will either request that the traveler disable connectivity to any network ( e.g., by placing the device in airplane mode and disabling Bluetooth and Wi-Fi connections) or where warranted by national security, law enforcement, officer safety, or other operational considerations, officers will themselves disable network connectivity. Officers should also take care to ensure, throughout the course of a border search, that they do not take actions that would make any changes to the contents of the device.
and
> Passcodes or other means of access obtained during a border inspection will only be utilized to facilitate the inspection of devices and information subject to border search. Passcodes or other means of access may not be utilized to access information that is only stored remotely. Passcodes or other means of access should only be recorded by the officer in a temporary format and should not be uploaded into CBP systems. Passcodes or other means of access recorded by the officer will be deleted or destroyed when no longer needed to facilitate the search of a given device.
Basically already exists depending on specific trade offs and risk profile.
You already can encrypt your data and store the encryption key offsite. But then you couldn’t use your phone during travel, if you toss the key locally.
You can encrypt the data at rest and leave the decryption key in RAM and just turn off your phone. But they can still take the phone and copy the encrypted data, if they think they’ll get the key later.
My understanding is that this individual would t want the government to access the encrypted data either.
The search is supposed to be lawful without a warrant because you're not really in the US yet per-se, hence if you're not there, how deleting the data can be a felony?
The premise that the law doesn't apply because you're not in the country is false. The constitution applies generally everywhere to all Americans, it's just that what's regarded as reasonable differs during a border search. IANAL, so just my lay opinion on this. Just to validate this, it's only because the constitution exists that the border authorities have any legal basis in doing inspections.
- if you're deemed to be on US soil, constitutional protections (4A) apply; can't be destroying "evidence" unless you're accused of a crime or found to have committed a crime
- if you're deemed _not_ yet on US soil, then how can you be charged with a crime under _US_ law?
Also, that constitutional protections are suspended within 100 miles of a land, sea, or air border.
https://www.congress.gov/crs-product/RS22497
Although obviously not all US laws apply and enforcement is a whole other kettle of fish.
an officer can't stop me on the street and demand to see the contents of my phone -- unless they can show "probable cause" that I was about to commit a crime (based on other evidence), or I'm already named as a suspect or POI in an investigation. So if they ask to see the contents of my phone and I delete it instead (it's a very small bag in this example, Lol) am I obstructing an investigation?
Are we still discussing a border crossing case that is long historic or there is still an active drama for this guy going on?
Obviously have the duress pin if what’s in your phone is worse than the obstruction charges too.
So in the article situation, the guy is a protestor and presumably suspects he’s going to be targeted by the police for it. He’d keep that stuff isolated from his usual activity. There’d be no need to generate convincing fake activity.
Certainly more of a hassle than having a PIN that can destroy everything.
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."
Amendment 5:
"..nor shall be compelled in any criminal case to be a witness against himself, nor be deprived of life, liberty, or property, without due process of law; nor shall private property be taken for public use, without just compensation."
When the administrative enforcement bureaucracies want to harass you they'll hit you with some ruinously expensive civil fine BS. No court will give a crap about you until you've exhausted a bunch of appeals, which you of course appeal to the same agency that's trying to screw you. Only after years of that (and invariably legal fees, because you can't go it alone), do you sue them and get to see a real courtroom. But even then, this is a civil matter, not a criminal one, so all your rights have been nerf'd and there's a hundred years of precedent and case law that tilt things in their favor. If you get lucky, they'll settle and you'll only be out a few tens of thousands for the ordeal.
He was charged for destroying evidence, not refusing a search
>Amendment 5:
Destroying evidence isn't testimony. Moreover he would have been in the clear if he just kept his mouth shut.
Evidence with regard to which investigation?
>"He" (by which I mean, technically the agents)
Under the same logic you could mail a bomb to anyone and say you didn't kill anyone, they did. It was just rigged to blow when they opened the box.
Although then you get a possible delay of undefined duration, additional questioning and seizure of your device.
In theory. In practice, this is a hopelessly outdated supposition.
But no respectable judge would ever have issued a search warrant on the basis of "we want to rifle through his messages/contacts so we can hopefully accuse him of something".
Protesters against this exact same thing were mis-prosecuted under "domestic terrorism" and "racketeering" charges before (got dismissed in 2025).
Even lawyers with extremely different ideologies will give you convergent answers in a lot of cases, even when those answers conflict with an apparently obvious reading of the original text. Explaining that would require drilling down into details of thousands of court cases -- like reading a complex proof of a seemingly simple theorem.
I don't like that any more than you do. It's not mathematics, and even when given all the details, I usually find their inferences laughably bad -- even when I agree with the conclusion. It's not "logic" as I apply it as a logician, philosopher, or software developer. Lawyers (people on my side ideologically) will insist on the soundness of reasoning for decisions that they don't like but accept as valid.
So I don't find quoting the Constitution to be of any utility. None of those words what you think they mean. And fixing that requires basically throwing out the entire system of American jurisprudence. Which would be fine with me, to be honest.
And that alone is already a pretty scandalous problem. If the law is not stated in a way that ordinary people can understand, how the hell are they supposed to obey it? Those who cannot afford the highly paid law explainers are basically locked out of society.
The truth is that the constitution is interpreted by humans in a common law context, and enforced by the apparatus of state, which has the means to impose its will. Calling this doublespeak is weird.
The Constitution is written in plain English. And for the most part, Supreme Court decisions are written in plain English that any reasonably literate US citizen can understand. Yes, the law has technicalities and terms of art just like any other profession.
But one of the most damaging mentalities in modern times is the idea that the common man is incapable of understanding the law at even a basic level. This is flat-out not the case. Which leads to the follow-on problem: people who think lawyers have the ability to cast magic mumbo-jumbo spells that "get their clients off on a technicality" somehow. The best quote I ever heard about that from an attorney was "any time someone says a person 'got off on a technicality,' you can pretty much just safely replace that in your head with 'had their constitutional rights egregiously violated.'"
Yes, there are problems. Qualified immunity is a problem. Prosecutorial misconduct can be a problem. Abuse of discretion at the border is a problem. But that's different from doomerism about the entire justice system to the degree Very Online people express it.
I suspect the 5th amendment is probably more valuable to the defense here as the password is effectively testimonial and the give us your password or we'll ... is compelled speech.
Either way, it's gonna be many 10s of thousands of dollars in lawyers fees to fight this. Which sucks.
I'm curious, is there any case law from the pre digital age regarding people forced to open their briefcase and let the border guard read all their documents at a port of entry?
https://yalelawjournal.org/forum/customs-immigration-and-rig...
E: but seriously, what happens to non citizens. What happens if you bring a burner/wiped phone? I assume digit forensics can confirm it was pre wiped but what's topping them from alleged you wiped on US soil.
So, in both cases the government wouldn't have access to the contents of the phone
[0] https://arstechnica.com/tech-policy/2020/02/man-who-refused-...
> Courts have generally found that compelling individuals to provide their numeric or alphanumeric passcode is potentially testimonial under the Fifth Amendment, as it forces the defendant to reveal “the contents of his own mind.” In Re Grand Jury Subpoena Duces Tecum 670 F.3d at 1345; see also U.S. v. Apple MacPro Computer, 851 F.3d 238 (3d Cir. 2017). It is analogous to compelling production of the combination to a wall safe, which is testimonial, as opposed to surrendering the key to a strongbox, which is not. See Doe v. U.S., 487 U.S. 201, 220 (1988). However, even if a court finds that providing the passcode is “testimonial,” it may still fall under the “foregone conclusion” exception
https://www.nacdl.org/Content/Compelled-Decryption-Primer
In short, you can't be compelled to give up the code in a dragnet attempt to find evidence against you (e.g. a boarder guard can't riffle through your text messages to see if you might have done something illegal), but if it's already certain that particular evidence exists on the device as a result of other evidence, they may be able to compel you to give up your passcode.
Note though that the cases where this has come up are very few and far between, and there isn't a super clear overriding precedent to follow.
In general though, the best choice here is to say nothing at all and work with a lawyer to figure out how to proceed.
You can refuse to hand over access. You can't go torch evidence. Caught Ollie North as well.
Is it right? It makes no difference, Customs can make your life miserable, that's just the reality of it, always has been and it can't have gotten better in recent times.
<https://news.ycombinator.com/item?id=49060780>
(From the HN GrapheneOS account about a month ago.)
We were talking about an attacker taking an image of the SSD prior to it being wiped not helping them because information needed to derive the key encryption keys is gone from the secure element. It similarly doesn't help them to do a brute force on a server farm since they're rate limited by the secure element. It only allows 20 attempts and has rapidly increasing delays between those. There's also hardware bound key derivation but that only helps improve the strength of a decent password. The secure element rate limiting makes even a random 6 digit PIN highly insecure unless an attacker can exploit the secure element.
OP is talking about just backing up what you need off-phone and then wiping it.
I would not present a phone to customs that had clearly just been wiped.
You can try this "gift link" to the article: https://www.nytimes.com/2026/08/21/us/politics/samuel-tunick...
But the man was also hated by the cops because of his activism. They were going to catch him for something, some day. This incident just provided the necessary excuse to lock him up.
It is pretty clear to me that law enforcement conspired to abuse a border crossing to effect basically an unconstitutional search ("fishing expedition"), which it would never have gotten a warrant for.
This is them being spiteful after that whole thing failed. Note how law enforcement basically admits this on the record. The whole thing is a disgrace; every decisionmaker involved in this should be sacked immediately.
People have gone to jail or have been executed for less than a glitch. Theoretically a highly charged particle from space could've messed with exactly the right transistors exactly when entering the correct PIN and trigger the wipe process. There is no way to prove that didn't happen. But you don't need that kind of proof.
funny reading this (don't disagree) and then also reading on HN how China is "bad" this is some gestapo shit but not surprising that it is getting normalised ...
Excessive border patrol power has been around in the USA for ages now, it's all part of the post-9/11 package. I don't think many Americans even know they live in a zone where the border police can do shit like this, even if they haven't left the country, as international airports are usually near big cities, and they have a wide border zone around them. This stuff only really makes it into the news when it happens to one of the "good guys".
1. You factory reset your phone before entering the US and give it to CBP blank. There's nothing to find;
2. You have a self-destruct PIN like this guy did and give it CBP so it destroys the phone's contents.
Tech people will say that these two things are functionally the same. This is a fundamental misunderstanding of how the law works. If you factory reset your phone first with the intention of restoring it after entry, that's completely fine (legally). You could've factory reset that for any reason. But as soon as an officer wants to search your phone, now you're engaging in evidence destruction (spoliation). The destruction to the phone's contents was done in response to an unfortunately lawful search.
Even if you don't want to factory reset your phone, you can probably just delete (or even log out) of key apps. They can still get messages but if you're so concerned about that, use WhatsApp or whatever.
None of this should be necessary but we are where we are. But whatever you do, don't use a self-destruct PIN if you don't want to be charged with a felon and likely to be found guilty.
A factory reset done in anticipation of a search is not as different from using a duress feature as you believe it is. Forensics software would have clearly identified the device was recently factory reset. It would provide another defense argument by arguing it was wiped for another reason, but whether that would be believed by a court is unknown. It would make a difference if there was a good argument about why it was done, but it isn't necessary for this to have been done instead for wiping the device to have been legal.
Once he was in the situation already, the best move was very likely refusing to provide the PIN/password indefinitely and only talking to them to demand access to lawyer. There are strong protections against data extraction and it's highly unlikely they would have been able to get the data from it. Refusing to provide a PIN/password is protected under the 5th amendment in the US and these rights do exist at the border. They can turn away a non-citizen but they can't refuse entry to an American citizen because they won't provide a PIN/password. They could waste a lot of his time but he'd get access to a lawyer and would get released. They could make a court case over demanding the PIN/password and they'd nearly certainly lose. He'd likely spend months or even years without getting back his phone of course.
If they had a video recording of him entering the PIN/password from somewhere, they could have used that to get the data. By using the duress PIN/password, he prevented it. It was probably not necessary to keep the data safe, but that's unknown.
With only a tiny bit of preparation time, rebooting or powering off the device would have gotten it into Before First Unlock state without the locked device auto-reboot timer needing to complete. In Before First Unlock state, a decent random 6 digit PIN is enough for the data stored protected with it to be highly secure without an extremely sophisticated secure element exploit. If the device had a strong passphrase, then no level of sophisticated exploits would recover that data.
At this point, people should buy a burner phone when going to/from the US. In that phone only have a couple of phone numbers and that's it.
Issuing 'burner phones' and laptops to staff visiting countries such as China or the USA is now SOP for many companies handling sensitive data, including mine.
Don't think this isn't unusual.
A couple weeks before your trip, factory reset whatever burner phone you're planning on using and swap your SIM card over. Install a few basic apps you wouldn't mind them looking through. Enable hotspot/tethering, and connect your other phone via Wi-Fi.
For a couple of weeks, use the burner as much as you can with what is available on it. When you're driving, us the maps app for GPS. Make and receive some calls, ignore some spam calls. Read the news. Get a few inane text messages conversations going, etc.
When you travel, leave your regular phone at home and take the burner. When it's searched at the border, it has enough activity to pass most initial smell tests. If asked, you dropped your other phone and didn't have time to get it fixed before your trip, this is one a friend lent you.
This has worked for me. Never _actually_ into anything illegal, but just apparently had a suspicious vibe about me or something because every time I crossed the border into or out of the country I was spending 4-5 hours getting searched. Didn't need someone going through my entire life going back decades every time--once was enough.
At the end of the day, it's always best to just not have anything "bad" on your devices. People have been caught up for all numbers of "innocent" reasons (pictures of their kids in the bathtub, ancient photos in their albums of themselves doing illegal things such as drugs or underage drinking, text messages or browser history disparaging politicians the border guard may support, porn in your history) that can give a border guard in a bad mood good reason to ruin your day.
I personally don't want my phone data hoovered in and analyzed or marked, even though I don't really have anything to hide. I don't care enough to do anything about it, but if I did I would probably have a second travel phone with a curated amount of data, apps, accounts, etc.
At this point? This has been standard practice for a while now.
It was likely unnecessary to use the duress PIN/password. He likely would have been better off simply refusing to provide the PIN/password. He could have rebooted or powered off the device before going through but even without that it would have automatically rebooted itself after 18 hours by default, or a lower time if he had configured one.
With a lot more preparation he could have done an encrypted backup, wiped the device and restored it later but that's very inconvenient.
Clinton's IIRAIRA bill literally introduced expedited removal procedures and created the concept of 'administrative warrants', routinely used by CBP/ICE today.
Without the IIRAIRA, removal would be substantially harder.
https://www.congress.gov/bill/104th-congress/house-bill/2202
https://www.congress.gov/bill/104th-congress/house-bill/3610
It's easier than ever to check legal assertions before you post instead of posting incorrect information.