Live data from Hacker News

GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

pcmag.com

111–120 of 206 posts

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#111
post #86
post #7

The founding fathers would be aghast at what America became. Hard to imagine modern America passing some of those constitutional amendments that older America passed wayyy back.

On the other hand, why care what the American founding fathers thought? There have been two centuries since then of developments in democratic countries that some Americans could choose as a model they like more. And now it's the Chinese century anyway.

Because they provide a reasonable common foundation. Otherwise you will forever be arguing with Christian nationalists.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#112

Earlier quoted context omitted.

The same is true at any border crossing - you have to submit to searches by CBP agents, who don't need any probable cause. I believe device searches are still a somewhat greyer area, at least if password protected (as providing a password would be compelled speech, unlike a luggage search which can be conducted without any action from your part).

> as providing a password would be compelled speech which is a good reminder for anyone with reason to be concerned about this sort of thing to turn off biometric/face id/etc. access to their devices.

on iphone - tap power button 5 times.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#113
post #62

Earlier quoted context omitted.

I mean, if it's possible to configure and there is at all a reason for someone to configure it as such, then it makes the most sense to treat it as a very valid possibility, right?

Hindsight is 20/20 right? Sure, the duress pin feature was around for years, but so was the technology to set up a thermite boobytrap in a safe. Maybe now CBP officers should be more careful about entering random pins people gave them, but snarky remarks like "Maybe digital forensics shouldn't be handled by barely highschool graduates at a busy border crossing" are entirely unjustified.

It is not snarky, it's the truth. Suspending the constitution within 100 miles of every port of entry? Nah son, the government can conduct their petty investigations with a warrant and proper digital forensics if they want to search your property.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#114
post #86
post #7

The founding fathers would be aghast at what America became. Hard to imagine modern America passing some of those constitutional amendments that older America passed wayyy back.

On the other hand, why care what the American founding fathers thought? There have been two centuries since then of developments in democratic countries that some Americans could choose as a model they like more. And now it's the Chinese century anyway.

To be fair, there have been a few democratic developments since the founding fathers were around. 27 at the last count.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#115
post #9

This should be an interesting case in today’s legal climate Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password. How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password do…

[deleted]

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#116
post #55

Earlier quoted context omitted.

Interesting that all that rules don't apply to water. The moment you stepped on a boat, coastal guard can (and do regularly) board it and conduct a search without any reasoning. They don't need any probable causes, warrants, nothing. Seems like so far it didn't create any problems, so public is ok with that.

The same is true at any border crossing - you have to submit to searches by CBP agents, who don't need any probable cause. I believe device searches are still a somewhat greyer area, at least if password protected (as providing a password would be compelled speech, unlike a luggage search which can be conducted without any action from your part).

in autistic-land, doesn't it seem like the power to perform searches by border police should be directed related and limited to their function - that is the inspection of material goods to insure that (a) illegal smuggling isn't taking place and (b) the proper import taxes have been paid.

unless the phone itself is a suspicious good, there should never be any justification for a border officer to demand visibility of the contents of the phone, or the data that its permitted to access on other systems.

I presume the counter to this is that they must be able to examine the socials in order to see if you should 'death to america' on message boards. is that really an important vector? is the balance of that security concern versus speech rights (which are supposed to be 'universal') something we want individual field officers to decide?

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#117
post #9

This should be an interesting case in today’s legal climate Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password. How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password do…

> Either way, the user complied, and did not take action to wipe their device. The user claimed to offer a password to access the contents of the device, and instead offered a password that deleted the device. That is false testimony / lying to an investigation, and is almost certainly punishable in itself.

"If you enter this password you will have access to everything you need and deserve."

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#118
post #100

Earlier quoted context omitted.

> wiping the device before carrying it across the border seems essentially identical to me. On the contrary, there is a huge gulf between these. Providing a fake password that wipes a device while under active questioning is a clear case of providing false testimony. Lying to the police while under investigation is simply illegal, regardless of the thing you're lying about. By contrast, entering the country with a cl…

> Providing a fake password that wipes a device while under active questioning is a clear case of providing false testimony. False testimony of what? Can you be compelled to provide testimony that allows a police officer access to your private data? Can a police officer demand I log into my online medical chart so they can complete their investigation? > Lying to the police while under investigation is simply illegal…

> False testimony of what?

False testimony of what your password is.

> Can you be compelled to provide testimony that allows a police officer access to your private data?

When under police investigation, you are only allowed to do one of two things: explicitly invoke your 5th amendment right not to provide testimony, or provide truthful testimony of anything the police ask you. Anything else is technically illegal.

> Can a police officer demand I log into my online medical chart so they can complete their investigation?

Yes, though you can refuse their demand by explicitly invoking your 5th ammendemnt right to stay silent. They can legally lie to you about your obligations, though.

> Otherwise every person found guilty of any crime they said they didn't commit would also be found guilty of lying to the police officers who interrogated them.

Indeed, people who proclaim their innocence to police can face additional charges if later found guilty. It's quite rare for this to be pursued in criminal cases, as the additional punishment would not be worth the effort of proving you knowingly lied about this. But it is actually sometimes pursued in misdemeanor cases, as lying to the police is a crime and can actually carry a steeper sentence than the misdemeanor itself, so it can be a powerful incentive to convince you to admit guilt for the lesser charge.

Note: I'm using legal terms rather loosely, and I am probably wrong on some of the details. Perhaps a statement such as "I'm innocent, officer" is too vague to constitute a material falsehood and be prosecutable, even in principle. But something like "I couldn't have killed that man, I was not there that night, I was at this other location" would almost certainly qualify you for additional liability if it can be clearly established that you were in fact at the location the victim was.

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#119
post #62

Earlier quoted context omitted.

Hindsight is 20/20 right? Sure, the duress pin feature was around for years, but so was the technology to set up a thermite boobytrap in a safe. Maybe now CBP officers should be more careful about entering random pins people gave them, but snarky remarks like "Maybe digital forensics shouldn't be handled by barely highschool graduates at a busy border crossing" are entirely unjustified.

It is not snarky, it's the truth. Suspending the constitution within 100 miles of every port of entry? Nah son, the government can conduct their petty investigations with a warrant and proper digital forensics if they want to search your property.

>Nah son, the government can conduct their petty investigations with a warrant

Your original post:

>Maybe digital forensics shouldn't be handled by barely highschool graduates at a busy border crossing

Sounds like you're moving the goalposts from "haha CBP agents are dumb" to "they should get warrants".

Re: GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

#120

Earlier quoted context omitted.

The same is true at any border crossing - you have to submit to searches by CBP agents, who don't need any probable cause. I believe device searches are still a somewhat greyer area, at least if password protected (as providing a password would be compelled speech, unlike a luggage search which can be conducted without any action from your part).

in autistic-land, doesn't it seem like the power to perform searches by border police should be directed related and limited to their function - that is the inspection of material goods to insure that (a) illegal smuggling isn't taking place and (b) the proper import taxes have been paid. unless the phone itself is a suspicious good, there should never be any justification for a border officer to demand visibility of…

[deleted]
Post reply on HN