Live data from Hacker News

US citizen charged after GrapheneOS phone wipes during airport search

techspot.com

551–560 of 1001 posts

Re: US citizen charged after GrapheneOS phone wipes during airport search

#551
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

> you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to

That's the same problem with technical solutions to crime.

I come from a very dangerous city and I used to have a car that needed a PIN to work. You could turn then engine on and drive but after a minute if you didn't input the PIN it would turn off without warning and start blasting the alarm. The idea being that if the car was stolen the thief would be stranded not far from home unsure about what's happening. Great technical solution but it ignores that a lot of the time the car is stolen with you in it (in a kidnapping, for example). Having the car shutoff in the middle of a highway next to a panicking guy with a gun and trying to remember a PIN is not a situation you want to be in, so I just had the PIN number written down on the dashboard, which worked very well when I was eventually kidnapped and just pointed at the piece of paper with the number.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#552

Earlier quoted context omitted.

PIN to wipe seems suspicious. How about a PIN where it login to a patriotic profile and phone looks like normal android.

This is exactly my setup with GrapheneOS. The default / main profile is patriotic, with a sterilized Telegram account, state-adjacent banks and apps, etc. The second profile (that uses a separate PIN) is not so patriotic: it has foreign bank apps, crypto apps, password manager, 2FA app, personal records, and an alternate Telegram account that I use to discuss any potentially unpatriotic topics with potentially unpatr…

It would be cool if there's a third PIN that can wipe the unpatriotic profile whilst showing the patriotic one.

So you use 1st pin for normal use, 2nd for downloading your flight details on patriot mode, and 3rd for unlocking to patriot mode whilst silently nuking unpatriotic data in case of seizure.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#553

Ultimately, when you choose to enter a duress PIN that will wipe your device, you have to recognize that choice may have legal consequences. I don't like the amount of power our government has at the national border when it comes to detaining and pressuring citizens, but our Constitution explicitly grants it at least some of the power it now exercises in that context. If your threat model includes US state actors at…

Well I prefer simply to stay out of countries that haven't got their ducks in a row when it comes to freedom. Saves a lot of hassle.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#554
post #546

Earlier quoted context omitted.

This seems like an insane thing to have to do for visiting a supposed first world country. If phones had been around during USSR times I imagine you would have had to do the same. Personally I will rather just avoid any travel to the US, and I hope others do the same.

Just out of curiosity, like what country would you not have to worry about this in? The US is quite transparent about these rules, and certainly other countries are not necessarily searching peoples phones as publicly But anytime I transit a country USA or any thing I fully expect to have zero rights

Schengen, Nordics, Japan, Canada, in that order.

Trump’s America: when confronted with negative traits of your country, always assume your country is the lesser of all evils.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#556

Earlier quoted context omitted.

PIN to wipe seems suspicious. How about a PIN where it login to a patriotic profile and phone looks like normal android.

This is exactly my setup with GrapheneOS. The default / main profile is patriotic, with a sterilized Telegram account, state-adjacent banks and apps, etc. The second profile (that uses a separate PIN) is not so patriotic: it has foreign bank apps, crypto apps, password manager, 2FA app, personal records, and an alternate Telegram account that I use to discuss any potentially unpatriotic topics with potentially unpatr…

It would be cool if there's a third PIN that can wipe the unpatriotic profile whilst showing the patriotic one.

So you use 1st pin for normal use, 2nd for downloading your flight details on patriot mode, and 3rd for unlocking to patriot mode whilst silently nuking unpatriotic data.

Or a PIN that just nukes the data for certain apps (Signal, Telegram, WhatsApp, E-mail) etc. Feds can read my Slack messages all day.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#557
post #546

Earlier quoted context omitted.

This seems like an insane thing to have to do for visiting a supposed first world country. If phones had been around during USSR times I imagine you would have had to do the same. Personally I will rather just avoid any travel to the US, and I hope others do the same.

Just out of curiosity, like what country would you not have to worry about this in? The US is quite transparent about these rules, and certainly other countries are not necessarily searching peoples phones as publicly But anytime I transit a country USA or any thing I fully expect to have zero rights

>But anytime I transit a country USA or any thing I fully expect to have zero rights

That is so sad, man. How is this normal for you?

Re: US citizen charged after GrapheneOS phone wipes during airport search

#558
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

I wonder if the smarter thing to do would be to quietly nuke it as soon as it becomes clear that you'll be detained, so they can't really know that it wasn't already blank (IE you aren't nuking it in their presence).

Re: US citizen charged after GrapheneOS phone wipes during airport search

#559
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

> you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to That's the same problem with technical solutions to crime. I come from a very dangerous city and I used to have a car that needed a PIN to work. You could turn then engine on and drive but after a minute if you didn't input the PIN it would turn off without warning and start blasting the…

Why are you staying in this place?

(Is this in South Africa?)

Re: US citizen charged after GrapheneOS phone wipes during airport search

#560

Earlier quoted context omitted.

What about simply not using a smartphone and accessing your data via internet when you're in the country? You could use Mega (secure file storage) to access your files, for example. I wonder if border agents could coerce you into giving access to your internet file storage, though.

I believe they can. I believe they can even request your social media credentials, despite that being against the ToS for those sites. It's not against the law to refuse, but they can and will reject entry on that basis.

That's interesting. I don't even know most of my passwords (thanks to password managers).
Post reply on HN