Live data from Hacker News

US citizen charged after GrapheneOS phone wipes during airport search

techspot.com

561–570 of 1001 posts

Re: US citizen charged after GrapheneOS phone wipes during airport search

#561
post #519

Earlier quoted context omitted.

I don't carry a smartphone, is this likely to be a red flag if I'm stopped?

Many countries now assume you have a phone. For example getting UK visa requires a smartphone. I don't think going without a phone is feasible nowadays. Another question is if going with a burner phone that has just sim card and bank card, sufficient. But then you need appleid/google account on the device, and this again links back to your phone number, and it's not easy in practice to have proper clean device.

Well, assume your phone number is public knowledge.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#562
post #431

Earlier quoted context omitted.

Note that border searches of electronic devices are extremely rare overall. There were some statistics from CBP implying a base rate lower than 1 in 10,000 (I think lower than 1 in 100,000) border crossings. I do know two people who have experienced them as a result of the government taking a personal interest in them, so it's certainly not impossible. However, it's not a common experience. I've personally experience…

But why would that be legal? The device is owned by the individual. No judge signed any warrant search for the device. I can do what I want with my device - that is a basic right of property. Imagine if border guards seize money willy-nilly.

You are allowed to refuse access to your device, and they are allowed to refuse entry to the country.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#563
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

I wonder if the smarter thing to do would be to quietly nuke it as soon as it becomes clear that you'll be detained, so they can't really know that it wasn't already blank (IE you aren't nuking it in their presence).

The smarter thing to do is to just wipe your phone of everything you don't want border patrol to see before going to an airport.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#564
post #420
post #410

Earlier quoted context omitted.

Or that just selectively wipes only stuff you have marked for deletion. That way the profile stays up to date and believable.

Problem is „are you sure you marked for deletion all the correct things” because you could have already deleted it before traveling or moved to other device you don’t travel with. Selection on border control might be arbitrary, they can hold you or send you back over a photo or something you wouldn’t think should be a problem. Ideally you would like to have all wiped just in case but then you really stand out…

That's why you do it the other way round: you mark things that you don't want deleted.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#565
post #410

Earlier quoted context omitted.

Or that just selectively wipes only stuff you have marked for deletion. That way the profile stays up to date and believable.

That's a more risky strategy. What if you added new files since the last time you updated the deletion profile? It's also technically more challenging. You have to think about what might be in RAM, caches, backups, etc. The good thing about a total wipe is that it's very easy to implement, and it's hard for it to go wrong. You just encrypt the whole drive and, when you want to wipe it, erase the key.

Obviously, you'd go the other way round and marks things that you don't want deleted.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#566
post #459

Earlier quoted context omitted.

I live in the U.S. (as, I think, does the person who is the subject of this article).

Maybe change your location then :P

The US have things like exit taxes etc which make it a pain to leave.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#567
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

> I think they should not have this power, but the agents and courts probably don't care that I think that. ... > and about not angering the agents more than you plan to When I was a teenager (long ago at this point), I got into an argument with a police officer over surfing in a certain area. It was pouring down rain, so he was annoyed he had to sit outside and wait for my friends and me to come to shore. Once we go…

I wonder if the cop learnt his lesson? (rhetorical question)

Re: US citizen charged after GrapheneOS phone wipes during airport search

#568

Earlier quoted context omitted.

This is exactly my setup with GrapheneOS. The default / main profile is patriotic, with a sterilized Telegram account, state-adjacent banks and apps, etc. The second profile (that uses a separate PIN) is not so patriotic: it has foreign bank apps, crypto apps, password manager, 2FA app, personal records, and an alternate Telegram account that I use to discuss any potentially unpatriotic topics with potentially unpatr…

It would be cool if there's a third PIN that can wipe the unpatriotic profile whilst showing the patriotic one. So you use 1st pin for normal use, 2nd for downloading your flight details on patriot mode, and 3rd for unlocking to patriot mode whilst silently nuking unpatriotic data. Or a PIN that just nukes the data for certain apps (Signal, Telegram, WhatsApp, E-mail) etc. Feds can read my Slack messages all day.

There's no PIN for deleting a particular profile, but you can quickly delete it manually, assuming that you have some private time available – for example, when you are stopped at passport control and told to wait in the waiting area.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#569
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

Just don't travel to the US.

This is an increasingly popular solution. Foreign tourism has crashed.

I love the geography of the US, and it has some truly stunning places to visit.

But they're not so stunning that I need to risk my freedom - risk my freedom - to visit them in person.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#570
post #217

Earlier quoted context omitted.

A lot of engineer types forget that the law is not code, and reductionist arguments almost never actually work in practice because it's a human interpreting the law.

For one example of this, around 10 years ago there was a company called Aereo that tried to act as a "cloud television provider". The idea was that they had thousands of tiny antennas hooked up to servers in a warehouse, and they would lease an antenna to each subscriber. This gave an experience similar to cable TV but without Aereo having to pay broadcasters cable transmission fees. The major broadcasters sued Aereo…

They were accused of "public performance" which doesn't make sense to the spirit of the law to begin with. Avoiding technicality via technicality is fine. They should have been allowed to run their thousands of independent servers.

The reason cable companies have to pay these fees in the first place is a narrow and somewhat pedantic argument that is entirely based on connecting multiple households to the same antenna. Which Aereo doesn't do, no trickery involved.

If there had been a style of "cable" company that used one wire and antenna per house from the start, they could have avoided these fees too. They only didn't exist because cables and antennas are expensive.

Any single person could have legally set up their own server and antenna. But Aereo building these en masse makes them a cable company instead of an antenna-building company because... vibes, basically.

The best evidence that this was a failure of justice is that they pivoted to "okay, we're cable, we'll pay the fees for a mandatory license" and got rejected for not being a cable company.

Post reply on HN