Live data from Hacker News

GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

pcmag.com

11–20 of 206 posts

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#11
post #8

Someone who is a lawyer knows any details about the US justice systems precedents with regards to the fifth amendmend (regards to self incrimination) vs obstruction of justice (by destroying evidence) as would be applicable to a duress wipe? Also would the distinction of being (or not) read their miranda rights and placed under arrest in this case make a difference as to the status of any possible obstruction?

Not a lawyer, but my understanding is that refusal to give the PIN (“remaining silent”) would be a valid application of the 5th, but not giving a false PIN. 5th does not imply the right to mislead or lie to someone investigating a crime.

Not clear on anything else regarding the duress PIN but I don’t think a 5th defense would apply.

Note that you apparently have to explicitly invoke your right to remain silent or your silence could be implied as an admission of guilt (thanks to Salinas v. Texas). I imagine you’d have to repeat your assertion multiple times, and the person demanding the PIN will tell you that you can’t use the 5th, will threaten you with arrest and additional charges, etc. Consult a lawyer and get training if you’re doing critical work where you may need this defense.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#13

The "agent entered password themselves, therefore they're to blame" seems as good of a logic as "I'm going to start swinging my arms and start walking forward, so if you don't move, it's YOU hitting YOURSELF".

Maybe digital forensics shouldn't be handled by barely highschool graduates at a busy border crossing

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#14
post #9

This should be an interesting case in today’s legal climate Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password. How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password do…

Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#15
And this is why part of my plans for any international travel are to simply have a physical notebook with phone numbers to trusted friends/family and to buy throwaway devices on the other side (phone and chromebook or similar).

TBF, similar mindset if I ever attend defcon, etc. as well.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#17
post #9

This should be an interesting case in today’s legal climate Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password. How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password do…

Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.

while attempting to avoid armchair-law-interpreting because I really do not intend that, and I agree that this is going to be an interesting/deeply-worrying legal case:

wiping the device before carrying it across the border seems essentially identical to me. like, saying "you can't wipe it when searched" would also imply "you can't have an empty device when crossing because it may have been wiped before the search to avoid having your data searched" since people can (and often do) do that for exactly that reason.

that may very well be what they want / what they are trying to legally allow during searches, but it also seems like it'd raise a hell of a lot more outrage. it's essentially claiming all citizens are under full legal hold all the time, if they ever intend to leave the country for any length of time.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#18
post #9

This should be an interesting case in today’s legal climate Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password. How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password do…

> Either way, the user complied, and did not take action to wipe their device.

The user claimed to offer a password to access the contents of the device, and instead offered a password that deleted the device. That is false testimony / lying to an investigation, and is almost certainly punishable in itself.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#19
post #9

This should be an interesting case in today’s legal climate Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password. How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password do…

Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.

isnt it amazing how we are able to know when something is a trick and clearly caused by your action/intention vs when it isnt? i mean sure we can contrive (or maybe even find example of) some scenario where it might be a hard grey area, but ive always found it so cool how we often operate on "top down" methods like this that logically have no basis for working out but 'common sense' happens to be common enough still

i pray that sense doesnt erode

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#20
post #9

This should be an interesting case in today’s legal climate Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password. How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password do…

If you have a safe in your home and you knowingly wire up a bomb that goes off when a certain lever is pulled then you lie to the police and tell them the way to open the safe is to pull that lever you'd pretty clearly be responsible for the damage done when the bomb goes off.

I don't see why this would be any different.

Post reply on HN