In all cases just don't cross security checks with evidence you wouldn't want to be seized, its not that hard
US citizen charged after GrapheneOS phone wipes during airport search
401–410 of 1001 posts
Re: US citizen charged after GrapheneOS phone wipes during airport search
#402I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…
Re: US citizen charged after GrapheneOS phone wipes during airport search
#403Re: US citizen charged after GrapheneOS phone wipes during airport search
#404Seems like they’re going to have a struggle proving intent. “I was stressed out and afraid and I got the passwords mixed up” would be the magic words I’d hear as a juror and I wouldn’t be able to vote to convict.
Surely they'll just dig into as to why he set up the feature originally?
Re: US citizen charged after GrapheneOS phone wipes during airport search
#405Re: US citizen charged after GrapheneOS phone wipes during airport search
#406I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…
That's the reason I never traveled to the US and never will, just having IT security in your CV is enough to make the border gamble not worth it
Re: US citizen charged after GrapheneOS phone wipes during airport search
#407If they were searching for evidence of a crime, what crime was it?
The crime of disagreeing with the President.
I'd like some filter where if a comment is downvoted by IP addresses located in USA, they are considered as upvotes.
Re: US citizen charged after GrapheneOS phone wipes during airport search
#408Earlier quoted context omitted.
Exactly. People complain police dont prevent crime, but dont realize that is not their purpose. The police exist to protect the government, not the people.
Which part of the government protects the people?
Luckily that has never happened /s
Re: US citizen charged after GrapheneOS phone wipes during airport search
#409For non-graphene users (eg. Boring iPhone people like me). So there’s a feature called Duress PIN which as explained through some comments means you put a different pin which intentionally wipes the phone. It’s not auto wipe or wipe after several failed attempts but intentional wipe of device. (Worth explanation as the current title nor the article doesn't easily explain this was made by the US citizen providing the…
PIN to wipe seems suspicious. How about a PIN where it login to a patriotic profile and phone looks like normal android.
Android switched from block device encryption to filesystem-based encryption (with encryption data and metadata). This provides many security improvements, such as per-file encryption keys and per-profile keys.
However, this also means that the main file system is readable and you could enumerate the available users. If you would encrypt/obscure that information, you could still infer the presence of other profiles from file system block allocations.
(Disclaimer: not an expert, but I read the relevant Android docs at some point.)
Re: US citizen charged after GrapheneOS phone wipes during airport search
#410I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…
So I guess what you really want is a duress PIN that loads into a fake innocent profile.