Live data from Hacker News

GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

pcmag.com

101–110 of 206 posts

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#101

Earlier quoted context omitted.

The same is true at any border crossing - you have to submit to searches by CBP agents, who don't need any probable cause. I believe device searches are still a somewhat greyer area, at least if password protected (as providing a password would be compelled speech, unlike a luggage search which can be conducted without any action from your part).

> as providing a password would be compelled speech which is a good reminder for anyone with reason to be concerned about this sort of thing to turn off biometric/face id/etc. access to their devices.

that's why GrapheneOS has biometric+pin

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#102
post #38
post #28

Earlier quoted context omitted.

What about the abolitionists among the signers of the Declaration?

I don't want to get into a whole thing about the founding fathers and American mythology. Yes, they had some pretty good ideas that have withstood the test of time. They also had some pretty f'ing bad ideas that we had to change. So some comment about the founding fathers rolling over in their graves about what America has become is complete nonsense.

Executive war making, overgrown militaries, debt, party politics, concentrated power, corporate power, and foreign entanglement.

The framers did not invision America in its current state, to state otherwise would be nonsense because we can just read the words they wrote.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#103
post #9

This should be an interesting case in today’s legal climate Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password. How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password do…

Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.

>Your speech is the thing that triggers a series of events that you know will lead to a wipe.

The owner of the phone doesn't know that. They have no control over or insight into the officer's brain to know what they'll do. The officer might suspect the phone-wiping functionality exists and decide not to enter the password. If we start talking about ultimate causes then judicial matters become infinitely complex. What immediately caused the phone being wiped is the wrong password being entered by the officer.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#104

Earlier quoted context omitted.

Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.

See also, 5th amendment. They can't just declare on the spot that your data is now their data.

[deleted]

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#105

Earlier quoted context omitted.

Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.

See also, 5th amendment. They can't just declare on the spot that your data is now their data.

The 4th ammendemnt is the one that protects your data and other possessions in general, not the 5th. The 5th protects you from being compelled to give testimony that might incriminate you, which then protects you from being compelled to offer a password to access data that could be used to incriminate you.

Since 4th ammendemnt protections are significantly curtailed at border crossings, they can actually declare on the spot that your data is now their data. The only thing they can't do is force you to tell them how to access it - but, if they can hack your password, they actually have the right to search your phone just as much as they have the right to search you luggage.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#106

Earlier quoted context omitted.

Not a lawyer, but my understanding is that refusal to give the PIN (“remaining silent”) would be a valid application of the 5th, but not giving a false PIN. 5th does not imply the right to mislead or lie to someone investigating a crime. Not clear on anything else regarding the duress PIN but I don’t think a 5th defense would apply. Note that you apparently have to explicitly invoke your right to remain silent or you…

I'm mixed... if they really thought there was evidence on the phone, they should have seized the phone and acquired a warrant IMO to compel the valid, non-destructive PIN be given over. As I mentioned earlier, this is part of why my own plans for international travel are to only go with a notebook/sheet with contact numbers and buy throwaway devices on the other side. I don't think I'd travel internationally with a p…

> acquired a warrant IMO to compel the valid, non-destructive PIN be given over.

Compelling a PIN, even with a warrant, is legally questionable. Courts have held that it is a form of 'testimony' because it's compelling you to disclose something you know, while some state courts have ruled the opposite way.

In all likelihood the government wouldn't push it in this instance, to avoid creating any sort of precedent.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#107
post #88
post #49

This probably doesn't hold up legally, but it does hold up logically: if the reason a border search exemption exists is to prevent importation of material that is unlawful to import, wiping a storage device also fulfills that purpose.

It would seem that the officer was searching for evidence of a crime, not to prevent importation. However, did that evidence really exist? And if it did, was it for something else? Perhaps, the guy just worried about something far more mundane being discovered? We shall never know. Think Schrodinger's password.

The border search exemption is not intended to allow searching for evidence of crimes that aren't related to importing something illegally. Of course CPB isn't expected to ignore evidence of other crimes they happen to see incidentally while checking for things that are illegal to import.

Courts have been fairly tolerant of law enforcement using pretexts like that to expand their powers.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#108
post #66

Earlier quoted context omitted.

Because booby traps are illegal and wiping your phone doesn’t kill or maim the officer

I fully agree but that is a different argument than the one mingus88 presented. They suggested that the owner did not wipe the device because they did not actively enter the pin, which seems to be a flawed idea because legally intent matters.

They're still fundamentally different questions. Rigging up a bomb to a safe is already illegal, even if the bomb never goes off. Setting up a phone to destroy its own data under certain conditions is not.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#109
post #29

This is possibly the best advertising. GrapheneOS was kind of niche before. But if the US Government hates you then you're on the right track.

On one hand, I love GrapheneOS and see it as a cornerstone of digital privacy software. I have supported the project financially for years. On the other hand, I'm worried that the publicity will only make explicit targets out of GrapheneOS users, and that you would only be using it "if you have something to hide".

The best solution to this is if orders of magnitude more people start using GrapheneOS. Once it becomes fairly normal it's no longer a viable reason to target someone.

With this publicity and the coming Motorola phones, there's reason to be at least a little optimistic.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#110
post #17

Earlier quoted context omitted.

while attempting to avoid armchair-law-interpreting because I really do not intend that, and I agree that this is going to be an interesting/deeply-worrying legal case: wiping the device before carrying it across the border seems essentially identical to me. like, saying "you can't wipe it when searched" would also imply "you can't have an empty device when crossing because it may have been wiped before the search to…

similar to structuring laws, right? trying to not provide evidence is occasionally similar to destroying it.

yes, this is what I'm leaning towards. if intent (without accusation!) is the issue, then not providing access seems the same as removing or denying access. they're trying to do this kind of thing for foreigners (no social media account -> no entry: https://www.cnbc.com/2025/12/10/us-to-inspect-tourists-socia...), this feels like a grab at applying it to citizens too.

if someone is accused of something (possibly retroactively), any of those may be illegal (under specific details etc). if not, then... am I going to be required to never delete anything just in case?

Post reply on HN