The U.S. government has charged Samuel Tunick with allegedly typing in a passcode to wipe his phone before officers could search it. “I hope people understand that the charges against me are meant to intimidate people,” he said.

Just another example of the Trump admin trying to intimidate protestors using whatever the fuck they can to bring up whatever charges they can.

  • ornery_chemist@mander.xyz
    link
    fedilink
    arrow-up
    29
    ·
    2 days ago

    That’s actually what the duress password does and did here. Deleting the data would be too slow, so it gets rid of the keys instead.

    • Darkassassin07@lemmy.ca
      link
      fedilink
      English
      arrow-up
      10
      ·
      2 days ago

      I wonder; can those keys be backed up to a seprate device, and reinstated later?

      So: could you use the duress passcode to wipe the keys, making the device unreadable; then later use a backup to restore those keys and regain access?

      • ornery_chemist@mander.xyz
        link
        fedilink
        arrow-up
        12
        ·
        2 days ago

        My recollection is that the keys are stored on the TPM and can’t be exported. Backups kick the can down the road; now the adversary demands access to your backups. If the keys can’t leave the TPM and the TPM is wiped, then there is no more leverage that can be applied that will unlock the phone. The adversary might still try to get at other kinds of backups anyway to search for whatever data they were after to begin with, but that’s a separate issue.

        • [object Object]@lemmy.ca
          link
          fedilink
          arrow-up
          11
          ·
          2 days ago

          I’m sure there’s a difference between “I deleted evidence” and “I deleted evidence off this device you’re inspecting without a warrant, you can have it with a warrant”.

          But I also feel that unless there’s suspicion of a specific crime, you can’t really accuse someone of deleting evidence. And no, protesting peacefully is not a crime.

          • quick_snail@feddit.nl
            link
            fedilink
            arrow-up
            6
            ·
            2 days ago

            In the US, they can’t force you to give a password. Because they can’t prove you haven’t forgotten it.

            In this case, it was an officer who was attempting to gain unauthorized access to a device and then accidentally entered a code that caused it to wipe its own data

            So the activist has a pretty good case here to sue the officer for damages

            • OwOarchist@pawb.social
              link
              fedilink
              English
              arrow-up
              5
              ·
              2 days ago

              Because they can’t prove you haven’t forgotten it.

              Technically, no.

              They can’t force you to give a password because of court precedent around the 5th amendment. Courts ruled that being forced to give a password counted as being forced to divulge information and was thus a violation of your 5th amendment right to remain silent and not incriminate yourself.

              That’s why they’re still allowed to force you to give biometrics to unlock a device, though. Different court cases have ruled that being forced to put your finger on a fingerprint reader or show your face to a face scanner does not count as being forced to divulge information – since it’s action, not information – so law enforcement is still allowed to force you to do those things.

              (Which means, if you’re about to be arrested or you’re crossing a border or something and you don’t want your device searched, you should disable any biometric unlocking features first. I’m not familiar with Android, but in iphones, you can do this by restarting/powering off the phone (always requires pin/password on first boot) or by pressing the lock button repeatedly while already locked.)

            • logging_strict@programming.dev
              link
              fedilink
              arrow-up
              1
              ·
              2 days ago

              … and the govt would argue that the officer was doing his job. And the rubber stamping wigged political activist would merely rubber stamp that

        • Darkassassin07@lemmy.ca
          link
          fedilink
          English
          arrow-up
          4
          ·
          2 days ago

          the keys are stored on the TPM and can’t be exported

          Makes sense; if you can export them, so can an adversary.

          now the adversary demands access to your backups

          Only if they know/think they exist. The idea here would have been to make a nondescript offline backup of the keys and keep them totally seprate from the rest of your data/belongings. Possibly in a geocache type location.

          • JustEnoughDucks@slrpnk.net
            link
            fedilink
            arrow-up
            1
            ·
            17 hours ago

            The services (cellebrite) they use to crack normal androids and iphone s would surely let them know that there was an off site backup that likely exists, given that the company doing it knows grapheneOS exists and is used by journalists and their owner’s regime is the top murder of journalists in the world

        • logging_strict@programming.dev
          link
          fedilink
          arrow-up
          3
          ·
          2 days ago

          … and that would require a search warrant. But then the highwaymen would have to go in front of a wigged political activist to seek approval of a search warrant. Baseless allegations by someone with dubious jurisdiction?

          Bet that hearing would never make it into the press

      • cheeseburger@lemmy.ca
        link
        fedilink
        arrow-up
        1
        ·
        1 day ago

        Must be related to why GrapheneOS only supports pixel hardware at the moment, because it has the hardware to keep the keys locked up and provide attestation that they are.