Live data from Hacker News

US citizen charged after GrapheneOS phone wipes during airport search

techspot.com

961–970 of 1001 posts

Re: US citizen charged after GrapheneOS phone wipes during airport search

#961
post #201

could graphene support multiple duress PINs? feds: "unlock your phone or else" victim: "um, you're stressing me man. It's either 1234 or 4321, I forget. One of them wipes the phone, the other will unlock it." Whichever PIN they try, it wipes the phone, but the feds can't claim it was deceitful, just unlucky.

They operate under the basis that the adversary has encyclopedic knowledge so likely not helpful.

More:

https://nitter.net/GrapheneOS/status/2082153517234676150#m

Re: US citizen charged after GrapheneOS phone wipes during airport search

#962

This grapheneOS may be another scheme from the 'deep FBI'/'services' to get intel on the very, VERY, nasty (terrorists, human traffickers, drug cartels, child stuff, etc). If I recall properly, they did that in the past (it seemed to have worked amazingly). If so, "normal" police would not have the "keys". This would be "the compromise".

Extraordinary claims require extraordinary evidence. You haven't provided any evidence.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#963

Earlier quoted context omitted.

Yeah, that's my position. If you're paranoid enough to be using GrapheneOS, why would you take it to an airport in the US of all places? I bought a second hand iPhone for overseas trips, which my daughter promptly stole because she wanted an iPhone, but then i got her old android phone, which was LineageOS-compatible, so that became my travel phone.

GrapheneOS is excellent but seems like it just brings unwanted attention at this stage. Another plus is if you do lose the device the damage is minimal, its a bit of a hassle but nothing beats peace of mind

No, he was harrased for protesting cop city

Re: US citizen charged after GrapheneOS phone wipes during airport search

#964
post #733

Earlier quoted context omitted.

A phone with a backup account, unlocked with duress pin makes sense to me. How hard would it be to admin-allow some apps to work across barriers. E.g., wallet apps work, airline tickets work, but email/socials do not. the issue is that when a phone is unlocked, they can just plug in a USB device and scrape everything off it. The TSA agent may not be eyeballing a facebook account so much as plugging in an exfiltration…

Why does the USB port need to even work anyways? It could just be designed to look like a USB port but fry whatever expensive and proprietary phone hacking device they bought from some scuzzy Israeli ‘security’ company when it’s plugged in.

For using the phone.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#965

Earlier quoted context omitted.

We probably need honey pod fake OS systems that boots up if not properly handled displaying some stars & stripes as background image and having the US national anthem playing for any sound the OS is trying to play.

A phone with a backup account, unlocked with duress pin makes sense to me. How hard would it be to admin-allow some apps to work across barriers. E.g., wallet apps work, airline tickets work, but email/socials do not. the issue is that when a phone is unlocked, they can just plug in a USB device and scrape everything off it. The TSA agent may not be eyeballing a facebook account so much as plugging in an exfiltration…

Not possible unfortunately due to low level SSD architecture[1] and other reasons:

https://nitter.net/GrapheneOS/status/2082153517234676150#m

[1] https://veracrypt.io/en/Trim%20Operation.html

https://veracrypt.io/en/Wear-Leveling.html

Re: US citizen charged after GrapheneOS phone wipes during airport search

#966

Earlier quoted context omitted.

This would unironically probably work pretty well. The bullies in airports don't have that much time to investigate a phone which "looks good".

Right, these goons are hand searching through phones specifically to find something, anything, they can use to make your life suck and detain you further. A pin that boots into a dummy account, full of benign messages, photos, innocent web browsing, etc. is going to get you a pass. They'll flip through everything and get bored after a minute of not finding anything. Far less likely to aggravate them than wiping your…

They would learn about it and it would be standard practice when they see pixels.

It's not possible unfortunately due to low level SSD architecture[1] and other reasons:

https://nitter.net/GrapheneOS/status/2082153517234676150#m

[1] https://veracrypt.io/en/Trim%20Operation.html

https://veracrypt.io/en/Wear-Leveling.html

Re: US citizen charged after GrapheneOS phone wipes during airport search

#967
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

We probably need honey pod fake OS systems that boots up if not properly handled displaying some stars & stripes as background image and having the US national anthem playing for any sound the OS is trying to play.

Not possible to be robust unfortunately due to low level SSD architecture[1] and other reasons:

https://nitter.net/GrapheneOS/status/2082153517234676150#m

[1] https://veracrypt.io/en/Trim%20Operation.html

https://veracrypt.io/en/Wear-Leveling.html

Re: US citizen charged after GrapheneOS phone wipes during airport search

#968
post #643
post #389

Earlier quoted context omitted.

can you share the link? This? https://www.eff.org/document/eff-border-search-pocket-guide ---- Seems the better strategy (for iOS) is come in with a plan to say yes to agents without pissing them off (like handing them an empty phone). better to local back up, encrypt, upload to your home server etc. Then login to a fresh iCloud account, selectively install apps, photos, and mail accounts. So it doesn't look like you…

Xiaomi phones have/had a feature where depending on which finger you unlock the phone with, it can hide certain applications/folders on the filesystem.

Not possible to be robust unfortunately due to low level SSD architecture[1] and other reasons:

https://nitter.net/GrapheneOS/status/2082153517234676150#m

[1] https://veracrypt.io/en/Trim%20Operation.html

https://veracrypt.io/en/Wear-Leveling.html

Re: US citizen charged after GrapheneOS phone wipes during airport search

#969
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

What about simply not using a smartphone and accessing your data via internet when you're in the country? You could use Mega (secure file storage) to access your files, for example. I wonder if border agents could coerce you into giving access to your internet file storage, though.

Yeah this is ideal.

Re: US citizen charged after GrapheneOS phone wipes during airport search

#970
post #852
post #383

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully). The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially se…

Me solving technical problems without motivating requirements: Can you just like have the graphene OS device wipe itself if it knows that it's going through a border and you haven't logged into the device in 24 hours? Or maybe, Enter into a precipitous one false move mode, where it's just about to wipe itself if the 24 hours elapses, And it does wipe itself if someone doesn't put in a code the next time the device re…

Wouldn't be effective because would have to be implemented at hardware level which it's not. Unreliable at software OS level.

How would it reliably reach the internet.

No real advantage over cloud backup and way more risk.

There's already the reboot timer which works fine for securing data but not under duress.

Us citizens should use that.

Post reply on HN