Legal question: if you had whole-disk encryption, and the duress password just zeroized the decryption key, would that be "destroying evidence?" Especially if there was a recovery possible but not instantly available, such as a Yubikey in a safe deposit box in a bank. That would take a subpoena to get, and there is an opportunity to challenge the subpoena in court first. Not instantly at the border. Something like th…
The law means nothing. The law is "interpreted" by judges. If the government wants you to be guilty, they will find a way to make that happen. They don't care about the rule of law. The US has a 99% conviction rate, highest ever in recorded history.
Felony charges for citizen deleting phone data at US Border
731–740 of 1001 posts
Re: Felony charges for citizen deleting phone data at US Border
#732Earlier quoted context omitted.
If you want actual legal advice pay for an actual lawyer. You aren’t going to get it asking a bunch of randoms on a tech forum. Since we’re techies we tend to think about technological nuances and have a certain literal frame of mind (eg “They can’t make it illegal for me to just type the wrong pin” is the type of thinking I’m talking about here) whereas in law weird precedents and your intent really matter so you re…
The interesting thing is that the "don't carry the data" scenario of wiping your phone and restoring it after you're across the border is not functionally different from the "just don't carry the keys across the border" scenario. I would be comfortable with a dd archive of my encrypted phone contents in an short-lived S3 bucket that I could restore with a simple passphrase-derived key, for example. It's hard for the…
Re: Felony charges for citizen deleting phone data at US Border
#733Re: Felony charges for citizen deleting phone data at US Border
#734The decoy passcode feature should boot into a separate partition that looks like a normal phone setup, and during that time quietly erase the user's actual data. They would never have known if it worked like this.
You only need to delete the necessary key. The 'actual' data should just look like random bits.
Re: Felony charges for citizen deleting phone data at US Border
#735Earlier quoted context omitted.
The interesting thing is that the "don't carry the data" scenario of wiping your phone and restoring it after you're across the border is not functionally different from the "just don't carry the keys across the border" scenario. I would be comfortable with a dd archive of my encrypted phone contents in an short-lived S3 bucket that I could restore with a simple passphrase-derived key, for example. It's hard for the…
For your virgin phone scenario: in practice they'll probably reverse burden of proof and call it a day.
Re: Felony charges for citizen deleting phone data at US Border
#736Legal question: if you had whole-disk encryption, and the duress password just zeroized the decryption key, would that be "destroying evidence?" Especially if there was a recovery possible but not instantly available, such as a Yubikey in a safe deposit box in a bank. That would take a subpoena to get, and there is an opportunity to challenge the subpoena in court first. Not instantly at the border. Something like th…
The law means nothing. The law is "interpreted" by judges. If the government wants you to be guilty, they will find a way to make that happen. They don't care about the rule of law. The US has a 99% conviction rate, highest ever in recorded history.
There are ~4x as many cases dismissed by judges before getting to trial. And the vast majority (90%) of defendants enter into plea bargains.
Prosecutors only bring charges when they feel they have a strong case. There are many many cases which are never pursued because of this, and people also get upset about that.
Many countries do not have a plea bargain system the way the US does. And if you look at conviction rates at trial, they are smack in line with much of e.g. Western Europe.
Re: Felony charges for citizen deleting phone data at US Border
#737The decoy passcode feature should boot into a separate partition that looks like a normal phone setup, and during that time quietly erase the user's actual data. They would never have known if it worked like this.
That seems overcomplicated and opening yourself up to risk IMO the correct solution is to erase your phone before crossing the border, and then restore it after you’ve crossed
Re: Felony charges for citizen deleting phone data at US Border
#738Earlier quoted context omitted.
The law means nothing. The law is "interpreted" by judges. If the government wants you to be guilty, they will find a way to make that happen. They don't care about the rule of law. The US has a 99% conviction rate, highest ever in recorded history.
Conviction rate only measures cases brought to trial. The overwhelming fraction of cases do not go to trial.
Convictions at trial are much lower.
Re: Felony charges for citizen deleting phone data at US Border
#739Re: Felony charges for citizen deleting phone data at US Border
#740Earlier quoted context omitted.
If you want actual legal advice pay for an actual lawyer. You aren’t going to get it asking a bunch of randoms on a tech forum. Since we’re techies we tend to think about technological nuances and have a certain literal frame of mind (eg “They can’t make it illegal for me to just type the wrong pin” is the type of thinking I’m talking about here) whereas in law weird precedents and your intent really matter so you re…
The interesting thing is that the "don't carry the data" scenario of wiping your phone and restoring it after you're across the border is not functionally different from the "just don't carry the keys across the border" scenario. I would be comfortable with a dd archive of my encrypted phone contents in an short-lived S3 bucket that I could restore with a simple passphrase-derived key, for example. It's hard for the…
Well, once you have been told to unlock the device, you're already in a legally binding process. The phone is at this point evidence. It was not evidence before. It was not evidence a month ago. It really is just that simple.
Now, they could view prior wipe as suspicious, but as a US citizen they cannot prevent entry. And they may be able to seize your phone(suspicious!). Which is why simply stating the truth politely "I believe in privacy, and loath government poking into the private affairs of citizens" might help down the road if you want to sue. Might.
Border guards protect the realm, after all, and have wide latitude.
From my side, my truthful argument for wipe has always been that all of my buisness clients, emails, data might be on my phone. I have a duty to protect their privacy.
Making reasonable statements takes the edge off of 'suspicious', and the more people who wipe? The less suspicious it becomes.
The biggest thibg anyone could do, is make 100% restorable backups for non-rooted Android a thing. It's doable, but a PITA right now. Make it one-click, perfect, reliable, and more will do it.
And then it isn't unusual, it's normal, and the suspicious elements vanishes.
Of course, as Google is mired in asshattery lately, I'd expect any attempts to protect us all, such as ASOP patches or bug reports, would be fought against and ignored. Helping the world, protecting travellers, political dissidents, not on their radar.
They even fight such things.
Because in this day and age, Google does not have your back. Instead, they shove knives there.