I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…
US citizen charged after GrapheneOS phone wipes during airport search
891–900 of 1001 posts
Re: US citizen charged after GrapheneOS phone wipes during airport search
#892Earlier quoted context omitted.
It's a shame that the US appears on that list now.
Half of Europe does, it's just that everyone talks about the US like it's a special case because those searches happen routinely. It's legal to search a phone without reasonable suspicion at airports in the UK under the Terrorism act 2000 (pre-9/11!)
Re: US citizen charged after GrapheneOS phone wipes during airport search
#893Re: US citizen charged after GrapheneOS phone wipes during airport search
#894After reading more of this thread I'm kind of frustrated that people aren't aware of the border search exception. I strongly disagree with the border search exception and would like to see it drastically limited or abolished. It is also something that has clearly existed in caselaw for decades (arguably for centuries) and that the courts have routinely (to my regret) strongly reaffirmed. The border search doctrine sa…
There's no US law requiring key disclosure and there have been mixed court cases outcomes on whether people have to provide encryption keys.
Re: US citizen charged after GrapheneOS phone wipes during airport search
#895Instead of a PIN that wipes the device, it would be much better to setup a special PIN that logs the user into a sanitized, completely separate profile with generated content of no practical value. This would create plausible deniability, and be sufficient to allow low-level border agents to look through a phone and pass any checks without raising these kinds of alarms. The wipe PIN should still be an option, but sho…
This. Aka a Qubes style isolated image.
Once you've decrypted the disk, the contents of every permanent Qube is there for the taking, and it would be up to the user to further secure any data within specific Qubes if they desired any protection beyond what they get via FDE. Something like encrypted containers, for example, which isn't specific to Qubes (and has its own limitations).
In terms of running processes, Qubes OS benefits greatly from Xen's isolation between Qubes, but from a data forensics standpoint a recent Pixel running GrapheneOS has massively stronger (and more numerous) layers of protection against data extraction, and at all levels (I/O, memory, disk, etc.).
Re: US citizen charged after GrapheneOS phone wipes during airport search
#896Perhaps a way to avoid this would be to have the duress pin trigger not a device wipe, but a device encryption with a long, pre-set key that you would store in a safe place when setting up the duress pin. Then you haven't destroyed the evidence, but the data is irretrievable without your cooperation. Also, if you don't actually have the key saved, it would in fact be destroyed, but the prosecutor would have to prove…
They would quickly learn of this feature and stop inputting pins given by users until they can consult forensic experts. I expect this will happen with all passwords handed over on pixels since this publicity.
Re: US citizen charged after GrapheneOS phone wipes during airport search
#897So in GrapheneOS you enter your regular passcode to unlock it and a secondary passcode will wipe everything? Maybe it needs a third option where it just shows predefined apps/data, so it could just show e.g. WhatsApp, a set off chosen photo albums and some irrelevant office documents. Could also be useful for handing it to children, so they can access some games or whatever but nothing critical
They would like to but it's not possible to make a robust feature like that because of low-level architecture of SSDs. Implementing a detectable solution would give people a false sense of security.
Re: US citizen charged after GrapheneOS phone wipes during airport search
#898Why the hell doesn't the "duress PIN" just open up a sanitary profile? Bonus points for letting you set it up with plausible data before designating it as the duress profile that, when opened, wipes your real profile in the background . > "the screen went blank, flashed several times, and the phone appeared to restart," How about flash some red lights and play an airhorn sound effect, too.
Also they can plant evidence if you unlock the phone.
Re: US citizen charged after GrapheneOS phone wipes during airport search
#899I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…
So I guess what you really want is a duress PIN that loads into a fake innocent profile.
Also they can plant evidence if you unlock the phone.
Re: US citizen charged after GrapheneOS phone wipes during airport search
#900I don’t understand why phones can’t just have decoy profiles you can activate via PIN that look like regular harmless user profiles? Especially now with AI you can quickly populate with a bunch of plausible data. Or better, have PIN for taking you to your criminal/secret profile instead.
Also they can plant evidence if you unlock the phone.