This matters a lot because people are constantly asking me if they should set up a duress passcode in order to fool law enforcement.
What has not been mentioned is the 100 mile border zone . Nearly two thirds of Americans live within this area where CBP had much greater powers.
@evacide if the citizen had no legal rights b/c he hadn't yet crossed the border & thus wasn't on USAmerican soil as they claim, wouldn't USAmerican authorities be outside their jurisdiction & couldn't have seized & interrogated anyone? Besides, even if their claim was true, which seems highly unlikely, why is a citizen held contained for maybe porn, when a rapist & child abuser reigns the country?
@evacide I want to state up front that I can not an American citizen. As such, I would never advise anyone going to the US to use a duress password. That’s just asking for trouble.
That said, this is certainly a troubling development and just reinforces that I never want to visit your country. I would have zero rights and they could do pretty much anything they wanted to me. A lot of modern privacy tech has the “encryption == criminal” in the eyes of law enforcement these days.
Law enforcement has used our private data to harm us not keep us safe
@evacide the winning move is not to play.
I.e. don't have any devices/data with you when you cross a US border.
Even better, if at all possible, don't cross a US border. It's a Kafkaesque twilight zone where you're currently at the mercy of an openly fascist executive branch
@evacide great #grapheneos advertisement. Good.
@evacide I set my phone up to shut down and stop doing Face ID if I press it on the side. That effectively locks it out because they’re not getting my password.
The fascist US thought police in action. Fuck this…
@evacide Just wondering if just denying that the password was a duress password and that some coincidental bug caused the device to be reset would be an effective tactic. Wouldn’t the government have to prove that the guy in fact had set a duress password? The defendant would have to perjure themselves if they testified, but in the absence of some kind of device trace that this was the reason for a device reset the prosecution evidence would solely be circumstantial.
@evacide I think you should set it up in any case... but providing it instead of the real one is an absolutely bad idea. Either don't provide or provide the correct one.
You can gamble on them trying certain common codes and if your duress pin is among these – lucky you. You can also use fingerprint+2F-PIN (e.g., 1234) as your primary method with a different PIN (e.g. 5678) as an alternative set up, and the duress PIN happen to be the same as the 2F-PIN (1234) and hope for the LEOs to "observe" you entering it – which may be blurry enough to convince a judge that you didn't trick them but they tricked themselves.
But the best way is to have no evidence in the first place, and as long as you can get away with wiping the device at a time were you can plausibly deny police being after you, you're in a good situation – but still, the judge may think otherwise.
However this is *obviously* trickery and not how duress PINs should be used, ever. *smh*
@evacide FWIW, I keep a flash drive with my house keys. It contains an ext4 file system. On it are 3 files: a directory named 'root' used as a mount point, a large file containing a LUKS file system, and a GPG-encrypted LUKS password (randomly generated and one I've never seen as plain text). At a border, I can truthfully tell them that I cannot decrypt the password without my GPG keyring, which I can't access remotely - I have to be home to get it.
@evacide I’m no law expert, but the defendant didn’t delete the information, the border security did. They did it unknowingly, but it was still them who deleted the information, and I think that matters.
He could probably still be charged with lying to police, but I’d think that’s a lesser crime.
@evacide In this scenario, a blank phone and a phone with "sus" technology both appear to be risks for an unhinged regime.
A potential approach to this is to:
1. prep a non-Graphene phone with fascist-passing use history and software installs. No sensitive data on device, even if its encrypted.
2. only access and store sensitive data remotely
3. have a verifiable alternative story for anything that is related to 2.
@evacide so many of the comments here are variations of ‘but what if X, would it still be illegal to intentionally destroy evidence then?’
(yes)
@Mudlark There's also a lot of "I am not a lawyer, but here is my opinion of how the law works, completely uninformed by the contents of this news article or even the other posts on this thread that repeatedly point out how wrong I am."
@evacide Ah the border. A place where you are subject to laws, but not protected by them. Neat trick.
@evacide A perfect example of „unlawful law“. This is a question I’m asking myself very often: What should we do when the law becomes obviously unlawful but it’s still lawfully because it’s the law?
And then they allowed him into the US, so they could legally arrest him here.
They've got it both ways. They can snatch you while in border limbo, and certainly after they pass you through. Just setting foot on a US airport surface seems enough to justify suspicion to revoke every right.
@evacide I do wonder if this would still be considered a crime under an administration that isn't actively trying to turn America into Russia/Nazi Germany.
@evacide My general opinion on this sort of thing is, it's a tool for when you'd rather take the charge for destruction of evidence instead of the charge for whatever they'd find otherwise is.
@evacide (sorry I can't read the article without disabling ad blocker) I wonder if it would be the same to reboot/clear RAM instead of wipe the device. Same question for graphene's periodic reboot. If my device reboots every hour, have I destroyed evidence?
@evacide what about a dummy session PIN ? How will it be considered form lawyer as no evidence found on device ? (Like encrypt data still behind real user pin ?)
@evacide A very tricky situation. Depending on the exact circumstances, they can charge you with a crime. Even if it's not, you'll be spending a lot of money proving that in court.
Yet in other situations, it can be perfectly innocent and cause no issues whatsoever.
As any lawyer will tell you, "it depends." ;)
The Supremes ruled, many years ago, that even US citizens have no constitutional right within (IIRC) 500 miles of any border. So there's that to consider.
@evacide a lunatic with the codes to "our" nukes seems to be keeping our former allies at bay. They're as concerned/worried as we are.
We're getting our renewed passports. I've made the statement if we plan on getting out of this country, we bring burner phones and no computer. I wish the guy the best and a gofundme if needed.
@evacide It's import to make informed decisions and everyone has their own level of risk tolerance.
Personally, one of the reasons I run GrapheneOS is for the Duress PIN feature. But I'm more risk tolerant than many can be.
@allpoints Indeed. We all have very different threat models and there are plenty of threat models that don't involve trying to keep data about from customs agents at US borders.
its real simple travel with uninitialized or minimally installed devices do any wipe& reinitialization necessary long b4 you are at customs control point..
reinstall your data from a remote secure server(prep that b4 you wipe your phone and reinit) once you are exUS(not just exCONUS) and NOT in danger of seizure then restore your data and go about your life(if your threat model is solely US)
@evacide @allpoints Before the world cup it was reported that us border control wold check , social media posts and I think 5 years o emails ( no i think it was longer ) to check what was posted or emailed . some people who may or may not have disrespected 😡 Had there travail plans (esta) cancelled with no time to appeal . They lost a lot o money . some had to go to a different country to a US embassy to plead and beg , to no avail .
@evacide Mine is PIN protected and I would never give my PIN. What I wonder is I put the duress PIN on a piece of paper and put it inside of the protective shield. If they found it and entered it am I liable because I knew they might do that. But truthfully I've forgotten my duress PIN and would need to do this to remember it.
I feel like maybe the lawyer writing the indictment was using their own distress code
"The government’s indictment, which contains a typo (“Untied States Code”)..."
@evacide I don't understand their argument that they do not need a warrant and I have no rights because I have not yet crossed the boarder. Doesn't that actually mean they have no law enforcement jurisdiction either? How can I be tried for breaking a federal statute if I'm not technically in the US when the action happens? What if I wipe the phone before I get on the plane? Can I be tried for breaking a US statue if I'm in another country where that activity is legal when I do it.
@evacide Has the US gone completely mad?
The actual way to get your data to be safe is to use something like Veracrypt's hidden volumes - the same partition can be decrypted with two different passwords, where you use one as a normal desktop you don't mind sharing the contents of, and the other to save the files you don't want to share. To the normal volume, the hidden one is merely pre-encrypted empty space, and vice versa. The only thing you need is being careful enough not to accidentally overwrite data from the hidden volume with the standard one, as the contents of each volume must be hidden from each other for the ruse to work.
forget ruses.. thats too complicated and can be reversed.. wipe then reinit the device and don't transfer your account data back in travel sterile.. same goes for usbkeys sims etc dont temp fate.. travel with unopened devices populate at destination and wipe&destroy and do NOT come over a border control point with even a destroyed device crush on site and mix with the garden.. dont look suspicious, you wont win this battle.. they hold all the power
as far as laptops go?? dont travel with a populated device.. create a tails boot key once at destination boot from it and then fetch your wireguard key from the remote VPS you setup b4 you left now access your VPN safely you can use RDP through a wireguard tunnel leaving the tails install sterile except for the wireguard key)you will be crushing yet some more media at your hotel room b4 traveling again..
get a copy of "extreme privacy" and use it
https://www.amazon.com/Extreme-Privacy-What-Takes-Disappear/dp/B0DCJN61GF
How do you ensure you can access the remote VPN from your destination, without access to the SSH keys? Do you just memorize a long password and hope you haven't accidentally forgotten it during the trip?
@evacide @jripley a thing that's been kicking around in my mind is whose action it is to *use* a duress PIN. The interaction between an officer and the person under duress is one I expect to usually be framed as "give me access to this device", and as I understand it, GrapheneOS's duress PIN does provide *access* to the freshly-wiped system. I can see the construction of an argument that the officer's actions are what actually destroyed the data, even if I cannot see a court taking that argument very seriously (because the destruction being possible is a premeditated action blah blah)
But if the courts decide that someone else's action constitutes destruction of evidence on the part of the accused as a general pattern, the implications seem… not good!
@evacide I’ve been following this story for awhile and it brings a lot of questions in regards to what rights a citizen has when it comes to illegal seizures. Unfortunately things like this a more and more common even without an activist background.
“I have not seen this before, though I’ve discussed the potential scenario with activists and journalists over the years,” said Sandvik. “I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.”
Agree with Sandvik on this. Say you’re a journalist or activist, I would imagine having an encrypted remote backup on a home server, with the ability to load that backup via a vpn, and a utilizing mostly blank phone when moving through processing locations like a border would be a smart move.
@hotelzululima @psh There are many different approaches you can take for border crossings, which we discuss in the Border Crossing Guide: https://www.eff.org/wp/digital-privacy-us-border-2017#main-content but generally, I advise people not to have data on their devices at the US border that they would not want falling into the hands of the US govt.
@evacide @hotelzululima @psh
"that they would not want falling into the hands of the US govt."
Which is, of course, everything. The US government has been shown that it cannot be trusted with literally anything I know, including my dog's name.
clean freshly erased&formatted devices with just the name/number of your attorney is really best thats how I have traveled since the advent of phones that have internet accesses built in..b4 that ramp checks were uncomfortable, I used to get them on the way to financial crypto as my names on several watchlists for both PGP & working for [redacted] & [redacted] but have even had rampchecks by US embassy in KL
funny to as I alway travel sanitized just like they taught us lol
@evacide They have no proof that any evidence existed to be destroyed, so I can't see how this would go anywhere in a normal court.
@evacide is there an option that the duress code would just unlock to a different android account? I will be switching to grapheneOS in August.
@evacide Would it matter? A guilty system recognizes no innocents.