Live data from Hacker News

US citizen charged after GrapheneOS phone wipes during airport search

techspot.com

981–990 of 1001 posts

Re: US citizen charged after GrapheneOS phone wipes during airport search

#981

Earlier quoted context omitted.

> you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to That's the same problem with technical solutions to crime. I come from a very dangerous city and I used to have a car that needed a PIN to work. You could turn then engine on and drive but after a minute if you didn't input the PIN it would turn off without warning and start blasting the…

What city was this, if you don't mind me asking?

Caracas

Re: US citizen charged after GrapheneOS phone wipes during airport search

#982

While I like the idea behind GrapheneOS, I'd rather not place myself in jeopardy of some ridiculous charge like this one. I prefer to travel with a travel device, some inexpensive phone and/or laptop that contains nothing interesting. If they then wish to take it from me because I won't unlock it, then have at it! That said, the situation with respect to our Bill of Rights at the border has gotten ridiculous.

Duress pin is an optional feature not recommended for use unless you're being coerced and have advice from legal professionals.

It's a small part of the protection of the OS. Perfectly secure without it.

More: https://discuss.grapheneos.org/d/40700-grapheneos-protection...

Re: US citizen charged after GrapheneOS phone wipes during airport search

#983
post #261

Earlier quoted context omitted.

Would it have been wiser if that person had, as a US citizen, just refused to provide a PIN? At the most they'd just confiscate the phone, and it'd be encrypted anyway. No actual destruction of anything. On another note, maybe GrapheneOS should add some kind of feature where the phone involuntarily destructs if a correct PIN isn't entered for 48 hours (or whatever the user sets at installation time, and changing the…

Would it have been wiser if that person had, as a US citizen, just refused to provide a PIN? Purely technically it would also depend on the state of the phone. Phones can be read out/exploited more easily after first unlock (AFU) than before first unlock (BFU). So, a middle path would be putting the phone in BFU. Much harder to use exploits against the phone and biometric authentication doesn't work. One way of fairl…

[deleted]

Re: US citizen charged after GrapheneOS phone wipes during airport search

#984

Earlier quoted context omitted.

What city was this, if you don't mind me asking?

Caracas

I have no idea what it was like to live there, but did visit circa-late-90s.

Remember noticing that "walls" in Caracas meant 10' high concrete or brick, topped by glass shards or razor wire.

And there were walls around everything: university professors' homes, social clubs, etc.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#985
post #261

I’ve seen a lot of people on the internet over the years say things like “the government can’t make x illegal, it’s just y.” For example, the government can’t make wiping your phone at the border illegal, it’s just punching four numbers into your phone, just like a pin, only a different four numbers, which could just have well been your pin. U.S. law though is highly non-autistic and what you were trying to do is jus…

Would it have been wiser if that person had, as a US citizen, just refused to provide a PIN? At the most they'd just confiscate the phone, and it'd be encrypted anyway. No actual destruction of anything. On another note, maybe GrapheneOS should add some kind of feature where the phone involuntarily destructs if a correct PIN isn't entered for 48 hours (or whatever the user sets at installation time, and changing the…

They wont add that feature because it wouldn't be robust unless implemented at a hardware level. Grapheneos assumes advesaries have encyclopedic knowledge of the OS so features must work in spite of that. It's already standard to put phones in faraday Containers because of remote wiping on some phones. It wouldn't take long for then to adapt and turn off the device to prevent the timer from functioning.

Although that would bring it BFU which is more secure. But there's already the reboot timer.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#986
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

We probably need honey pod fake OS systems that boots up if not properly handled displaying some stars & stripes as background image and having the US national anthem playing for any sound the OS is trying to play.

Due to low level SSD architecture[1] and other reasons it is detectable:

https://nitter.net/GrapheneOS/status/2082153517234676150#m

[1] https://veracrypt.io/en/Trim%20Operation.html

https://veracrypt.io/en/Wear-Leveling.html

Re: US citizen charged after GrapheneOS phone wipes during airport search

#987

Earlier quoted context omitted.

And there's the problem that if the PIN or worse a biometric version of this becomes remotely well known you've now created an incentive for a car thief to kidnap people even if they only want the car.

Or anything else you can't easily transfer. I can't help but point at passkeys in particular (or 2FA in general). A variant of this is the well-known scene from a previous century's movie involving extracting an eye to bypass retinal scanner.

[deleted]

Re: US citizen charged after GrapheneOS phone wipes during airport search

#988
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

> you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to That's the same problem with technical solutions to crime. I come from a very dangerous city and I used to have a car that needed a PIN to work. You could turn then engine on and drive but after a minute if you didn't input the PIN it would turn off without warning and start blasting the…

Oh god, I am glad you can still write here. That sounds terrifying

Re: US citizen charged after GrapheneOS phone wipes during airport search

#989

Earlier quoted context omitted.

No, as someone who lived in China for years (as foreigner) and visited also last year after many years I WOULD BE SURPRISED if this happened when travelling to China, since China is clearly more free than US/Israel. China wants tourists and don't care about your stupid social media.

True, they focus their oppression on their own citizens and minorities for the most part.

Have you lived in China or you just parrot some US propaganda? In years of living there I haven't noticed any of my Chinese family/friends being opressed in any way.

And if you mean by opression that Han majority population was for decades allowed to have less children than ANY OTHER minority I agree with you...

Re: US citizen charged after GrapheneOS phone wipes during airport search

#990
post #302

Perhaps we need the following feature: Before entering the airport you set your device to auto-wipe after x hours. Once you are sitting in the airplane and flying, you cancel the scheduled automatic wipe.

Not possible due to not being a reliable software feature. It would have to be in the hardware.

Could you elaborate?
Post reply on HN