Live data from Hacker News

GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

pcmag.com

41–50 of 206 posts

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#43
post #9

This should be an interesting case in today’s legal climate Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password. How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password do…

Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.

[deleted]

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#44
post #9

This should be an interesting case in today’s legal climate Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password. How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password do…

Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.

The level of duress also matters. US citizens have been shipped to foreign prisons and there's an active case of high-level officials at DOJ violating court orders about that.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#45
post #25

And this is why part of my plans for any international travel are to simply have a physical notebook with phone numbers to trusted friends/family and to buy throwaway devices on the other side (phone and chromebook or similar). TBF, similar mindset if I ever attend defcon, etc. as well.

The crazy part is that you might be denied entering the country you don't travel with a device...

So be it, they can send me back.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#46
post #37

Earlier quoted context omitted.

> Either way, the user complied, and did not take action to wipe their device. The user claimed to offer a password to access the contents of the device, and instead offered a password that deleted the device. That is false testimony / lying to an investigation, and is almost certainly punishable in itself.

It would depend on precisely what the ask was. Did the officer ask, "Give me the pin to unlock the phone."? In that case the command was complied with.

Even if the prompt was vague like "what's the pin for the phone", you'd be hard pressed to convince a judge that a duress pin (to wipe the phone) is a reasonable person[1] interpretation.

[1] https://en.wikipedia.org/wiki/Reasonable_person

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#48
post #44

Earlier quoted context omitted.

Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.

The level of duress also matters. US citizens have been shipped to foreign prisons and there's an active case of high-level officials at DOJ violating court orders about that.

[flagged]

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#50
post #17

Earlier quoted context omitted.

Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.

while attempting to avoid armchair-law-interpreting because I really do not intend that, and I agree that this is going to be an interesting/deeply-worrying legal case: wiping the device before carrying it across the border seems essentially identical to me. like, saying "you can't wipe it when searched" would also imply "you can't have an empty device when crossing because it may have been wiped before the search to…

> wiping the device before carrying it across the border seems essentially identical to me.

On the contrary, there is a huge gulf between these. Providing a fake password that wipes a device while under active questioning is a clear case of providing false testimony. Lying to the police while under investigation is simply illegal, regardless of the thing you're lying about.

By contrast, entering the country with a clear device is not a crime under any possible interpretation that I can see. Now, if you are wiping evidence while you know there is an active investigation against you, that may be a crime as well, but it's a completely separate crime and can't be easily judged by an officer that simply finds you with a clean phone.

Post reply on HN