This matters a lot because people are constantly asking me if they should set up a duress passcode in order to fool law enforcement.
@evacide a lunatic with the codes to "our" nukes seems to be keeping our former allies at bay. They're as concerned/worried as we are.
We're getting our renewed passports. I've made the statement if we plan on getting out of this country, we bring burner phones and no computer. I wish the guy the best and a gofundme if needed.
@evacide It's import to make informed decisions and everyone has their own level of risk tolerance.
Personally, one of the reasons I run GrapheneOS is for the Duress PIN feature. But I'm more risk tolerant than many can be.
@allpoints Indeed. We all have very different threat models and there are plenty of threat models that don't involve trying to keep data about from customs agents at US borders.
@evacide @allpoints Before the world cup it was reported that us border control wold check , social media posts and I think 5 years o emails ( no i think it was longer ) to check what was posted or emailed . some people who may or may not have disrespected 😡 Had there travail plans (esta) cancelled with no time to appeal . They lost a lot o money . some had to go to a different country to a US embassy to plead and beg , to no avail .
@evacide Mine is PIN protected and I would never give my PIN. What I wonder is I put the duress PIN on a piece of paper and put it inside of the protective shield. If they found it and entered it am I liable because I knew they might do that. But truthfully I've forgotten my duress PIN and would need to do this to remember it.
I feel like maybe the lawyer writing the indictment was using their own distress code
"The government’s indictment, which contains a typo (“Untied States Code”)..."
@evacide I don't understand their argument that they do not need a warrant and I have no rights because I have not yet crossed the boarder. Doesn't that actually mean they have no law enforcement jurisdiction either? How can I be tried for breaking a federal statute if I'm not technically in the US when the action happens? What if I wipe the phone before I get on the plane? Can I be tried for breaking a US statue if I'm in another country where that activity is legal when I do it.
@evacide Has the US gone completely mad?
The actual way to get your data to be safe is to use something like Veracrypt's hidden volumes - the same partition can be decrypted with two different passwords, where you use one as a normal desktop you don't mind sharing the contents of, and the other to save the files you don't want to share. To the normal volume, the hidden one is merely pre-encrypted empty space, and vice versa. The only thing you need is being careful enough not to accidentally overwrite data from the hidden volume with the standard one, as the contents of each volume must be hidden from each other for the ruse to work.
@evacide @jripley a thing that's been kicking around in my mind is whose action it is to *use* a duress PIN. The interaction between an officer and the person under duress is one I expect to usually be framed as "give me access to this device", and as I understand it, GrapheneOS's duress PIN does provide *access* to the freshly-wiped system. I can see the construction of an argument that the officer's actions are what actually destroyed the data, even if I cannot see a court taking that argument very seriously (because the destruction being possible is a premeditated action blah blah)
But if the courts decide that someone else's action constitutes destruction of evidence on the part of the accused as a general pattern, the implications seem… not good!
@evacide I’ve been following this story for awhile and it brings a lot of questions in regards to what rights a citizen has when it comes to illegal seizures. Unfortunately things like this a more and more common even without an activist background.
“I have not seen this before, though I’ve discussed the potential scenario with activists and journalists over the years,” said Sandvik. “I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.”
Agree with Sandvik on this. Say you’re a journalist or activist, I would imagine having an encrypted remote backup on a home server, with the ability to load that backup via a vpn, and a utilizing mostly blank phone when moving through processing locations like a border would be a smart move.
@hotelzululima @psh There are many different approaches you can take for border crossings, which we discuss in the Border Crossing Guide: https://www.eff.org/wp/digital-privacy-us-border-2017#main-content but generally, I advise people not to have data on their devices at the US border that they would not want falling into the hands of the US govt.
clean freshly erased&formatted devices with just the name/number of your attorney is really best thats how I have traveled since the advent of phones that have internet accesses built in..b4 that ramp checks were uncomfortable, I used to get them on the way to financial crypto as my names on several watchlists for both PGP & working for [redacted] & [redacted] but have even had rampchecks by US embassy in KL
funny to as I alway travel sanitized just like they taught us lol
@evacide They have no proof that any evidence existed to be destroyed, so I can't see how this would go anywhere in a normal court.
@evacide is there an option that the duress code would just unlock to a different android account? I will be switching to grapheneOS in August.
@evacide Would it matter? A guilty system recognizes no innocents.
@evacide I've always wondered if this would be considered destruction of evidence... I guess now we get to find out.
@evacide
If you're a criminal, it's better to have a duress PIN. You are able to destroy evidence that is more incriminating than the erase action itself.
If you're not a criminal, it's better to have a duress PIN, because the law enforcement is not allowed to search your phone without a warrant and you protect your valuable private data.
Since being criminal (or not) is an invariant here, you should use a duress PIN.
@nakal I see that you are not a lawyer, are not familiar with spoliation of evidence, and have not read the part of the article that specifically talks about warrantless border searches.
@evacide I am not a lawyer. Glad that it's obvious. I cannot read the article because "disable your adblocker" which is not possible.
In an ideal world a permanent warrant for searches at the border wouldn't be allowed to exist.
But this is a tricky situation in which you need to decide quickly, if you prefer months of work to restore device integrity or being detained for some time.
@nakal I strongly recommend refraining from giving privacy and security advice predicated on an article that you have not read.
@evacide Also rephrased as "Should I engage in an action that could easily be perceived as destruction of evidence?" to the shrieks of lawyers everywhere
@tehfishman As I have said elsewhere, our lawyers have been cautioning us about spoliation of evidence for as long as we have been writing guides. This is absolutely one of those things that seems clever to engineers and horrifying to US lawyers.
@evacide @tehfishman the guy was under duress in a situation where he was not entitled to legal representation so the opinion of lawyers is somewhat less significant