- cross-posted to:
- technology@beehaw.org
- cross-posted to:
- technology@beehaw.org
It pretty much makes privacy illegal.
You know, since we are entering into a lot of legal weirdness here, how about this:
You give the cops TWO passwords. You tell them one is the duress password, and the other is the password that will unlock the phone.
Desperate and without a warrant, they try one. Wrong try! Phone is wiped.
In reality, both are duress passwords (I know GoS only supports one currently) but they would have to prove that.
Yes, it’s ridiculous, but everything about this is ridiculous.
I think what he did was brave and I think there’s a good chance he loses this, and I think the guilty verdict will be really unpopular
Someone has to fall on their sword to get important issues brought before the supreme court but I wouldn’t get my hopes up with this court.
Jury nullification is a thing for reason.
Advice: if you know you don´t want your phone searched going through customs, don’t bring it! Or wipe it before you go through. I’m 100% on this guy’s side, but we’re not exactly living in a free and open society.
This isn’t new. Journalists coming into the US in the aughts would be harassed by CBT and DHS, forced to open and unlock their laptops (and then delete whatever the officers found unsavory.
So they’d come in with their computers fully encrypted and wouldn’t have the pass key, themselves, so it was impossible to unlock them. If they were detained unreasonably, that became a new story the next morning.
Once through customs, correspondents would call their office and get the key.
But it sucks if you don’t have a whole news agency to back your rights.
Interesting. Could they hold the device, though, until it’s unlocked? I think this might be the Bad Press exception, not a legal right that would work for anyone else. Because if I gave the encryption key to a friend, they would just tell me to call the friend and get it… and if they refused to give it to me, it would because I instructed them not to…
This isn’t new. Journalists coming into the US in the aughts would be harassed by CBT and DHS, forced to open and unlock their laptops (and then delete whatever the officers found unsavory.
So they’d come in with their computers fully encrypted and wouldn’t have the pass key, themselves, so it was impossible to unlock them. If they were detained unreasonably, that became a new story the next morning.
Once through customs, correspondents would call their office and get the key.
But it sucks if you don’t have a whole news agency to back your rights.
I’m replying to what I’m designating as the duplicate comment.
Seriously. Wipe it, claim it’s new to you or whatever, put your stuff back on later if you need to. I’m sure you can find somewhere or someone you trust to get you that data back whenever you actually need it.
It brings up an interesting question: if wiping your phone after being requested access to it is illegal (?), would wiping your phone in anticipation of access being requested also illegal? Are we effectively required to give the federal government access to every private account in order to travel?
My understanding is that if you knew a search was going to happen, it’s illegal. But good luck proving that you knew it would happen.
I think you might be thinking of spoilation–https://civilprocedure.uslegal.com/discovery/spoliation-of-evidence/ --which is destroying evidence you think might be subpoened. I don’t think it would apply in this scenario.
As long as you aren’t doing it during an active investigation, no it wouldn’t be illegal. That’s the problem. Guy thought he was sneaky, and got busted. If you come in to investigate and suddenly you are deleting all the records, you are going to have a serious problem.
In the regular world, you can delete something to keep the cops from knowing about it as long as it’s not covering up a crime. You won’t find a charge of “destruction of evidence” without an investigation of an explicit crime with probable cause.
If they had probable cause to search his phone, they would have used it when he was in Georgia, not waited for him at the airport where he had fewer rights.
What if you don’t wipe it, but a different password sends the user to a virtual instance with unremarkable accounts.
That privacy was already long gone by the time of this case.
https://www.law.cornell.edu/uscode/text/18/2232
(a)Destruction or Removal of Property To Prevent Seizure.— Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both.If he hadn’t used duress and had just refused, he’d have been fine. Graphine is secure and would have had his back
If he hadn’t given them the code and instead left it in his wallet, and they did it themselves, he’d have been fine.
All he had to do was plead the 5th.
He’s going to get hit with a felony for destroying data to prevent a search. There are tons of precedents in the 11th Circuit for searching without a warrant.
A duress password is only useful if what you’d be facing is worse than 18 U.S. Code § 2232a, and then only if they don’t have enough to convict you already.
https://www.youtube.com/watch?v=_2rokxux5cU`___`
Dude is just protesting the construction of a large cop training facility near him. I don’t know what the fuck he did to get on the FBI radar, but I wish him good luck; he’s gonna need it.
The issue I’m seeing with the whole case is they siezed his phone, they kept his phone, the seizure of his property happened successfully. A person later entered something they believed would open it but instead it wiped it. The end user didn’t wipe it, and didn’t lie to the agents of the state because a duress PIN is still a PIN, I’m willing to wager they didn’t specify that they wanted his ‘unlock PIN’ and instead just asked him for a PIN (personal identification number), which he gave.
That’s court fodder, and unfortunately, I don’t believe it’ll pass.
I don’t know what the fuck he did to get on the FBI radar
…
Dude is just protesting the construction of a large cop training facility near him.
That is what did it.
i mean, the broad strokes are obvious, but if they went after every person who was vocal about something being build in their backyard, they’d need the whole of ICE to staff themselves. He must have been saying some shit to an insider. Come to think of it, I bet they have a pretty fucking big online presence for that purpose.
He associated with Defend the Atlanta Forest, which due to being against Cop City, has been flagged as a terrorist organization by the fascists in charge.
There is literally no other reason to be found.
His lawyers have already found (through internal CBP emails) that they flagged him for suspected terrorism because he was associated with Defend the Atlanta Forest.
They internally categorized the group as anti-government, anti-authority, and a violent extremist group.
He protested against Cop City and associated with a non-violent, peaceful org that also protested against Cop City. Thats it.
I don’t think ordinary citizens should be required to know the law in lawyer-like detail when they travel.
I think in the broad strokes, you’re probably right about his legal situation, but it suuuuuucks and it’s not what I think of when I hear the word “freedom,” for sure.
I don’t think ordinary citizens should be required to know the law in lawyer-like detail when they travel.
It becomes a slippery slope. He is unfortunately going to be a martyr that teaches us
Freedom, lol. How many prisoners per capita again?
If he hadn’t used duress and had just refused, he’d have been fine. Graphene is secure
Graphene devs fucked over this guy. They should apologize
When Graphene is serious, the duress passcode will QUIETLY wipe your phone and leave it looking normal, preferably with normal-looking innocuous photos, media, etc.
This is what happens when devs aren’t really thinking about the real world use case.
Something designed like SAmsung Knox would be much better. the rest of the phone/apps are still fine.
They shouldn’t apologize, the dude should of known that destroying evidence during an investigation is going to land you in jail.
No. If you make and distribute security-related software, you should consider the safety of your user.
Your threat model absolutely should include this exact scenario. And you should know enough to understand and implement principles like plausible deniability and repudiation.
Can’t Graphene be used like this already? Dude may not have known, or may not have bothered to set up multiple profiles. But I’m pretty sure it can be done.
Point is that when graphene gets the distress code, it makes it really clear that it’s wiping the phone.
That’s the Stupid Part
If they found a duress password in his wallet, and used it, they would 100% prosecute for that.
They would, but he’d have a significantly better chance at winning. Having a duress setup/password isn’t illegal. if you plead the 5th on what that pin code is, i don’t think they’d have a leg to stand on.
I think the application of that law depends on whether a seizure is valid (aka legal), which is kind of up in the air, as your video points out.
It’s unfortunately a border entry. They can do whatever they want regarding searches in that jurisdiction. He won’t get away with it being an illegal search.
There are still outs, but they are not super likely :/
It’s legal within most of the US for customs/border enforcement to do warrantless phone searches, because their definition of border is 100 miles from point of entry to the country. So every coastline, every international airport, etc.
Maybe so. But probably guessing targeting someone for a warrantless search would not be legal. That is to say, the cops can’t follow a guy and wait until they’re 100 miles from the border to pull them over and call over customs to search them. What may save Turnick is he was already being investigated and this search was clearly an endrun around needing a warrant.
My understanding is that it’s “only” 100 miles from the coast/border, which turns out to be most major population centers.
Yup, because airports
No, what I’m saying is that airports do not count. See: https://en.wikipedia.org/wiki/Border_search_exception
See also the ACLU site: https://www.aclu.org/documents/constitution-100-mile-border-zone
What if we just say I always forget the code and use the built-in too many tries wipes the data setting?
If you forgot the code can you offer to let them have it? Then you could wipe it remotely?
Trying to understand what would happen if you really forgot the passcode.
what would happen if you really forgot the passcode
I believe the threat here was: Tell us the access code or we confiscate your phone, which we’ll hack into at our leisure.
Just don’t provide it.
Unless you suffered some traumatic brain injury, nobody is going to believe you can’t unlock your phone after being in detention for 24 hours.
It would probably be treated as an intentional wipe.
Perhaps the trauma of being in detention made you unable to remember it? It’s really up to the prosecution/accusers to prove it, isn’t it?
In that case, you can argue you gave the duress password by accident, too.







