Live data from Hacker News

US citizen charged after GrapheneOS phone wipes during airport search

techspot.com

581–590 of 1001 posts

Re: US citizen charged after GrapheneOS phone wipes during airport search

#581
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

Maybe the actual solution is traveling with burner devices when you are concerned with border checks?

Like, get a cheap phone, install the bare minimum stuff you need for travel.

For extra safety, before returning home wipe it and just put back the exact apps you need for moving around (e.g.: ride hailing app).

Same thing with laptops, tablets, etc.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#582
post #546

Earlier quoted context omitted.

Just out of curiosity, like what country would you not have to worry about this in? The US is quite transparent about these rules, and certainly other countries are not necessarily searching peoples phones as publicly But anytime I transit a country USA or any thing I fully expect to have zero rights

European citizens can travel in the EU without even noticing that they are crossing borders most of the time. I once got lost on my bike and accidentally ended up in France for example.

I drove a friend to an airport in Switzerland, got lost on my way home, and accidentally visited both France and Germany.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#583
post #559

Earlier quoted context omitted.

> you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to That's the same problem with technical solutions to crime. I come from a very dangerous city and I used to have a car that needed a PIN to work. You could turn then engine on and drive but after a minute if you didn't input the PIN it would turn off without warning and start blasting the…

Why are you staying in this place? (Is this in South Africa?)

Brazil maybe?

Re: US citizen charged after GrapheneOS phone wipes during airport search

#584

Earlier quoted context omitted.

> but then says he can't have me disrespecting and being a smart-ass to his cops Maybe it's just me, but I am of the exact opposite opinion. Cops have enormous power, and any misuse of it should be pushed back on hard. Cops that misuse their power should not be respected. An informed citizenry is a wonderful asset in making that power imbalance less of a problem.

There's a difference between polite pushback and being straight up disrespectful. It shouldn't matter as the cops shouldn't abuse their power and shouldn't attack people, but we live in the real world. The judge probably didn't want to have to deal with the potential future mess if op didn't learn their lesson and got beat up by a cop.

> The judge probably didn't want to have to deal with the potential future mess if op didn't learn their lesson and got beat up by a cop.

A judge solving their own problems in this way is clearly abuse of power as well

Re: US citizen charged after GrapheneOS phone wipes during airport search

#585
Ok, so I'm just angry so take this comment in that light please:

1. What happens if the masses just do this? Today it's just a few folks who know how to do this. Tomorrow it could be 10, a year later 100. What's to stop 1000s from doing this and then what is the government going to do? Ban the OS and block it on Github?

2. What exactly happens after you're charged? This doesn't mean the person is convicted. Just that they now have to show up to court wherever the trial is held and have to retain their own lawyer (or public defender?). And what is the likelihood that the case is thrown out or the person is convicted and receives a stiff penalty?

I ask these questions because as far as I can tell, the person was not suspected or convicted of anything, and it's infuriating me that we are just going to stop random citizens and ask for their private data.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#586

I’ve seen a lot of people on the internet over the years say things like “the government can’t make x illegal, it’s just y.” For example, the government can’t make wiping your phone at the border illegal, it’s just punching four numbers into your phone, just like a pin, only a different four numbers, which could just have well been your pin. U.S. law though is highly non-autistic and what you were trying to do is jus…

I'm waiting to see whether he is convicted before I form a strong opinion around this. I'm leaning toward thinking this case will be dropped or at least severely reduced charges.

It doesn't matter.

Mamy will read this and think that crossing a border with a GrapheneOS device is a bad idea, or just drop using what is a nice security feature entirely.

Just being charged is already a massive pain in the ass (both in terms of stress and costs) to an individual.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#587

Earlier quoted context omitted.

I wonder if the smarter thing to do would be to quietly nuke it as soon as it becomes clear that you'll be detained, so they can't really know that it wasn't already blank (IE you aren't nuking it in their presence).

The smarter thing to do is to just wipe your phone of everything you don't want border patrol to see before going to an airport.

[deleted]

Re: US citizen charged after GrapheneOS phone wipes during airport search

#589
post #16

VeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give proper password, real OS and FS decrypt and load. Something like this may need to become the standars over duress pins which sho…

this will likely fail as block devices aren't dumb anymore, the firmware state will out the hidden volume. counting on the laziness/unsophistication of an adversary isn't a great move. this problem may be solvable by a purpose-built abstraction where every write no matter what address will look identical to the firmware (naively, a randomized key-value map).

I largly agree, hence why the prudent move is not visiting shitholes like the (current) USA with anything important on your person.

However, if you must do it, there are better options than duress pins that wipe a device.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#590
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

We probably need honey pod fake OS systems that boots up if not properly handled displaying some stars & stripes as background image and having the US national anthem playing for any sound the OS is trying to play.
Post reply on HN