US accuses American of allegedly wiping his phone using a 'duress' password during border search | TechCrunch
https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search
267 points · 72 comments · view on lemmy.world
72 Comments
wesker@lemmy.sdf.org · 129 pts · 28d
That's precisely what a duress password is for. Feature working as intended, get a warrant.
Vex_Detrause@lemmy.ca · 3 pts · 27d
Edit:Other connent said GrapheneOS Can we get a source for this app/technique?
AnnaFrankfurter@lemmy.ml · 10 pts · 27d
https://grapheneos.org/features#duress
Graphene OS Team has developed quite a lot of other useful features and some of them have even been merged into upstream AOSP allowing others also the benefits. Recent example is contact scope for apps starting Android 17 but it was initially developed by GrapheneOS team long ago.
eldavi@lemmy.ml · 2 pts · 23d
it needs to be reworked so that it's difficult to discern to strangers if the phone has been wiped.
it'll probably have to include fake phone logs, fake text messages, fake pics, etc. to make the wiped phone look like it wasn't wiped to everyone except its owner.
StumblingWasabi@lemmy.today · 106 pts · 28d
Pick a lane. Either it counts as US soil so you need a warrant or it doesn't so theres no reason for US law to apply until the person is approved.
EveryMuffinIsNowEncrypted@lemmy.blahaj.zone · 30 pts · 28d
No one tell them about international airports...
atrielienz@lemmy.world · 14 pts · 28d
They have a point though. Technically from what I've read just living near an airport would give ICE the authority to search your phone and anything else you might be carrying if it's within a certain mile radius. Even if you aren't using the port of entry (airport for instance). Regardless of whether or not they have any other form of probable cause.
I don't understand how others don't understand that. Because it's a hell of a conclusion to come to.
EveryMuffinIsNowEncrypted@lemmy.blahaj.zone · 7 pts · 28d
Oh 100%. I was just being a lighthearted goober about it. Lol.
Duamerthrax@lemmy.world · 4 pts · 27d
It's 100 miles. They claim 100 miles from the boarder and now "the board" is including international airports.
https://www.aclu.org/know-your-rights/border-zone
Eternal192@anarchist.nexus · 72 pts · 28d
So? My data, my choice and right to delete it, so fuck off!
quick_snail@feddit.nl · 13 pts · 27d
He didn't delete it. The officer did.
I wonder if he'll sue them for damages
Dultas@lemmy.world · 7 pts · 27d
Just put a note in your wallet that says cell password with the distress pin. You didn't give them the pin their illegal search uncovered it.
blackbrook@mander.xyz · 7 pts · 27d
"They asked for my password. They didn't specify which password."
quick_snail@feddit.nl · 10 pts · 27d
More like "sorry I couldn't remember the password. I guessed, but I have a bad memory"
This is exactly the reason the government can't force you to give your password in the US. They can't prove that you remember the password.
Cethin@lemmy.zip · 12 pts · 27d
If you're in this situation, don't say this. You are under no obligation to explain anything, and anything you say will be used against you (and will not be used to defend you). Just shut the fuck up.
quick_snail@feddit.nl · 6 pts · 27d
Yeah, you're right
NauticalNoodle@lemmy.ml · 3 pts · 27d
-That, and the 5th amendment.
eager_eagle@lemmy.world · 4 pts · 27d
lol that'd be a neat uno reverse card right there
MasterBlaster@lemmy.world · 64 pts · 28d
Citizen enforces his own right to the Fourth Amendment and is prosecuted by the government for not letting them try to find incriminating evidence on him. For something. Maybe. Because he looks suspicious.
I hope that lawyer gets it thrown out. I'm not holding my breath. We've gone so far into fascism I'm not sure it'll take anything less than violence to end it.
AHemlocksLie@lemmy.zip · 19 pts · 28d
Unfortunately, the 4th is pretty well destroyed at the border. And within 100 miles of the border.
Quill7513@slrpnk.net · 22 pts · 27d
they've expanded the 100 miles to 250, and include cities with international airports now. we're at a point now where USBP jurisdiction is wherever a USBP agent happens to be
ToiletFlushShowerScream@piefed.world · 51 pts · 28d
A reason to try grapheneos if you are technically inclined.
yestalgia@lemmy.world · 29 pts · 28d
It's easy enough for anyone willing try. Grab any Pixel from the last few years, plug it in to a computer, and click buttons in your web browser on the GOS website and watch GOS get installed on your phone. The instructions hold your hand the whole way through.
sun_is_ra@sh.itjust.works · 7 pts · 28d
do you know how much does any pixel from last year cost?
yestalgia@lemmy.world · 20 pts · 28d
I paid $300 for a mint condition 9a about a month ago on Swappa. Obviously the price is lower for other conditions.
https://grapheneos.org/faq#recommended-devices
RodgeGrabTheCat@sh.itjust.works · 10 pts · 28d
I know what the 10a costs, bought one a few weeks ago. Worth every penny.
surewhynotlem@lemmy.world · 8 pts · 28d
I sold a 6a for like $50 recently. Here on lemmy, oddly enough. Those are still good.
sun_is_ra@sh.itjust.works · 5 pts · 28d
wow! What community do you sell at?
MidnightMarauder@lemmy.dbzer0.com · 7 pts · 28d
Bought a new 8a for 300,- a year or so ago. Way Cheaper than a flagship Samsung or iPhone, runs really smooth on Graphene.
It_is_gaslighting@discuss.tchncs.de · 6 pts · 28d
200€ used market if not even less. Look on grapheneOS website for compatible devices.
ColeSloth@discuss.tchncs.de · 4 pts · 28d
I soooo want that feature, but less and less phones will even let you unlock your bootloader. Graphene OS doesn't get to support many phones.
mnemonicmonkeys@sh.itjust.works · 8 pts · 27d
The bigger issue with GOS compatibility is the ability to relock your bootloader and a few other security features.
Also, Motorola is releasing a GOS compatible phone next year. They consuled with the devs on what features were needed
FineCoatMummy@sh.itjust.works · 1 pts · 27d
I really wanna give that time to be stress tested against Celebrite tho. Celebrite was able to get into locked devices. For all but the latest gens of iPhones and Andoids, which have better h/w security features. Older models they can access.
If we see that Celebrite isn't able to break the new GOS Motorolas, that'll be good to learn.
MML@sh.itjust.works · 1 pts · 27d
Just one? I really want a Graphene Razr but if that doesn't happen I'm just going to get a FLX or similar
OS2Warp@lemmy.zip · 4 pts · 27d
Or, on iOS, wipe the device after 10 failed attempts.
apftwb@lemmy.world · 36 pts · 28d
FYI if you are using GrapheneOS with the duress password, you can natively backup your phone. Its in settings.
Duamerthrax@lemmy.world · 3 pts · 27d
For people that don't want to be dragging into a civil rights case, can you set up a dummy interface that looks used, but doesn't have any too important available? Like you only owned the phone for a week?
apftwb@lemmy.world · 5 pts · 27d
You can setup different users on GrapheneOS and switch between them.
There is also a "private area" in the bottom of the app list where you can move sensitive apps and password protect them.
Either way, allowing a malicious actor into that profile exposes more attack surface for them to exploit.
Idk. Security is a journey, not a destination.
quick_snail@feddit.nl · 36 pts · 27d
Sounds like the police officer tried to gain unauthorized access to a device. And, while they were trying to crack it, they wiped all of its data.
I wonder if the police officer that did this will face criminal charges of unauthorized access and destruction of evidence.
And also there's a civil suit in there. The officer may have deleted valuable data on the victim's device, causing them harm. I wonder what the monetary value will be.
queermunist@lemmy.ml · 10 pts · 27d
They charged people with terrorism for using Signal chat.
Hiro8811@lemmy.world · 8 pts · 27d
The duress password on graphene os wipes all the data, they probably threatened or force him so he gave them that password
vrighter@discuss.tchncs.de · 33 pts · 27d
no he didn't. They asked for a password that the phone would accept. They weren't even supposed to ask, but he gave them one. They're the ones who entered it on the phone. And by extension they're the ones who erased the phone.
MML@sh.itjust.works · 21 pts · 27d
Plus he provided a passcode that unlocked the device I don't see the issue.
davel@lemmy.ml · 29 pts · 28d
https://en.wikipedia.org/wiki/Tampering_with_evidence
Even if I had more information, I still wouldn’t have the law chops to predict where this may lead.
FineCoatMummy@sh.itjust.works · 13 pts · 28d
I don't have those chops either. Also NAL. The wiki page says Tampering charges require there to be an ongoing investigation, which wasn't the case here, so I'm thinking it wouldn't apply. But! I wonder about spoliation. Spoliation before a case is brought, while not illegal per se, can result in negative inference,
Negative inference, to my NAL understanding, means the tampered evidence may be taken in the worst light for the defense. Here, it's all resting on flimsy and politically motivated pretext with no evidence. Still.
Needs an immigration lawyer to give an answer to this, but I'm thinking it may be legally safer to have strong encryption and refuse to unlock, rather than to wipe. Not unlocking isn't tampering, so no spoliation, but wiping might be. Well, safest of all is to use a burner. But next best, strong encryption + don't unlock. CBP can confescate the device, but they cannot compel you to produce a pw or unlock code.
pemptago@lemmy.ml · 12 pts · 28d
From what I've gathered, I think you're right to assume it's legally safer to refuse to unlock rather than wipe. Also, worth noting that you can be compelled to unlock with biometrics, but not a password. On grapheneOS this means simply shutting off/restarting your device as it requires a pw after a fresh boot, even if biometrics is enable.
FineCoatMummy@sh.itjust.works · 4 pts · 28d
Yah, I've been trying to get my friends to use a pw rather than biometric unlock, for that exact reason.
I'm batting like 0 for 5, lol. Biometrics are just too convenient I guess. Plus they don't think it will impact them personally. Which is prob true. I still think it's best to use the way that preserves more civil rights. I just can't convince them.
MasterBlaster@lemmy.world · 3 pts · 28d
Sheep will always be sheep.
pemptago@lemmy.ml · 1 pts · 27d
Yeah, people have their own threat model and trade-offs they're willing to make for security/convenience and it's probably a lot lower for most people than if they knew more about the landscape and gave it careful thought. It sounds like other mobile devices might reencrypt after reboot. IDK about the pw v. bio, though, but if it's like Grap.OS just convincing them to reboot their device before going through TSA checkpoints or other areas where their device might get confiscated may improve their security with minimal effort.
Carl@anarchist.nexus · 3 pts · 28d
Even on iOS, you can disable biometrics by entering the power/SOS menu. Just hold the lock button and volume down for like two seconds, and biometrics are now disabled until the passcode is entered.
Worth noting that this doesn’t actually re-encrypt the device. The device boots in an encrypted state, and entering the passcode allows the phone to unencrypt itself to function. But disabling the biometrics doesn’t re-encrypt the device. You would need to reboot to accomplish that. But if you’re able to access the power menu, you’re probably able to hit the “Power Off” option too.
I only make the distinction because cops have started imaging devices after confiscating them. If they manage to image your device while it’s unencrypted, they can take their time with whatever new exploit/bypass is discovered in the future. But if the device is encrypted when they image it, they’d only get an encrypted data blob and would need to actually break the encryption instead of being able to use a passcode bypass method.
iOS actually has a hidden “reboot if inactive after a little while” feature, specifically to re-encrypt an idle device. Most users only encounter it when they wake up in the morning and have to enter their passcode. But the point is that cops usually process devices in batches, so it usually takes them at least a few hours to get to your device. So if the device has been idle for a while, it will quietly reboot to encrypt itself. This also helps protect against future passcode bypasses that may be discovered, because an attacker would only get the encrypted data blob if they bypass the code on an encrypted device.
quick_snail@feddit.nl · 5 pts · 27d
The accused is a Stop Cop City activist in Atlanta.
quick_snail@feddit.nl · 28 pts · 27d
Very glad to hear that he's a free man while the courts try to figure out what to do.
Also it's hilarious that he didn't wipe it. The officers did it. I think it's going to be very hard to get a conviction of this activist when it was the officer that wiped the data.
Fancy_Gecko@lemmy.ml · 22 pts · 27d
US is a dystopia
NauticalNoodle@lemmy.ml · 12 pts · 27d
HiddenLayer555@lemmy.ml · 15 pts · 28d
"Sorry, my fat American fingers accidentally entered the wrong code, you understand."
humble_boatsman@sh.itjust.works · 24 pts · 28d
From what I read, upon demand he gave the code to the Investigator, whomst had to watch the phone start to load and then erase it self. What a joy it must have been to watch them gifauh at that
quick_snail@feddit.nl · 1 pts · 27d
Pretty sure all cops have fat fingers. Too many doughnuts
N0t_5ure@lemmy.world · 15 pts · 28d
The authorities conducting the illegal search entered the code, so the phone owner could assert that he gave them the right password and they were the ones that screwed it up. It's a bit late for that argument, but someone could use that in the future and there'd be no way to prove it wrong.
eager_eagle@lemmy.world · 15 pts · 28d
for research purposes, how would one go about setting this up?
ExcessShiv@lemmy.dbzer0.com · 22 pts · 28d
https://grapheneos.org/features#duress
humble_boatsman@sh.itjust.works · 1 pts · 28d
I can't seem to find it in my set up. There is no option for duress pin under device unlock selection
ExcessShiv@lemmy.dbzer0.com · 9 pts · 28d
Are you using grapheneOS?
humble_boatsman@sh.itjust.works · 7 pts · 28d
Yep e/OS 3.7.1
E: well I'm a fucking idiot
RodgeGrabTheCat@sh.itjust.works · 15 pts · 28d
Eos is not GrapheneOS
whatiswrongwithyou@lemmy.ml · 10 pts · 28d
E/os isn’t graphene and doesn’t have a duress pin feature.
pineapplelover@lemmy.dbzer0.com · 7 pts · 28d
Lmao, the edited comment
BCsven@lemmy.ca · 13 pts · 28d
GrapheneOS also has options to turn off USB port so that authorities plugging in devices to try to bypass phone lock can't be exploited. And user needs to supply password to change the USB options.
Malyca@lemmy.zip · 4 pts · 28d
I think he was using graphene os
reagansrottencorpse@lemmy.ml · 15 pts · 27d
Hmm this sounds like government overreach 🤔
lennee@lemmy.world · 8 pts · 28d
sorry accidentally did a duress oopsie uwu bite me
magnue@lemmy.world · 6 pts · 27d
Would love to see how that happened. Extra points if they are the ones that entered it.
Pandantic@midwest.social · 16 pts · 27d
They were: