The U.S. government has charged Samuel Tunick with allegedly typing in a passcode to wipe his phone before officers could search it. “I hope people understand that the charges against me are meant to intimidate people,” he said.
Just another example of the Trump admin trying to intimidate protestors using whatever the fuck they can to bring up whatever charges they can.
65 Comments
quick_snail@feddit.nl · 48 pts · 17d
I mean I think privacy advocates are looking to set a precedent. This case is perfect for us.
The officer was the one that wiped the data, so hopefully he'll loose his job. And they should be sued to pay compensation to the victim for the damages caused by lost data
Jason2357@lemmy.ca · -11 pts · 16d
There's already strong precedence that destroying data after learning of an investigation is a crime. Doesn't matter to the courts that is via a clever trigger. If he knowingly provided a pin to an official that destroys the data then he's hosed. His only hope is if they guessed on their own.
VitoRobles@lemmy.today · 16 pts · 16d
What was the investigation?
ITGuyLevi@programming.dev · 8 pts · 16d
That's the fun part... There wasn't one, he just happened to oppose a very unpopular thing happening in his city.
Malyca@lemmy.zip · 15 pts · 16d
He broke no laws, was read no rights and was repeatedly denied an attorney.
quick_snail@feddit.nl · 8 pts · 16d
Example?
GreenKnight23@lemmy.world · 3 pts · 16d
your argument would be shredded in court.
lka1988@lemmy.dbzer0.com · 2 pts · 12d
Sounds like he misremembered under duress to me
¯_(ツ)_/¯
Dryad@lemmy.world · 1 pts · 15d
There’s also precedent that “officers” may use biometric means to unlock a device, but innocent-until-proven-guilty people may not be compelled to disclose their pin.
resipsaloquitur@lemmy.cafe · 38 pts · 17d
What’s the charge?
apfelwoiSchoppen@lemmy.world · 76 pts · 17d
Destroying evidence, which is funny because that assumes there was any to begin with, which they can't prove.
tyler@programming.dev · 36 pts · 17d
That wasn’t the charge. The charge is destruction of property that the government is trying to hold on to.
Dryad@lemmy.world · 55 pts · 17d
Which would still be unreasonable search and seizure.
tyler@programming.dev · 2 pts · 17d
They were not in the United States and the constitution doesn’t apply at border searches. Their argument is going to be limited to very few things, like “I didn’t destroy anything, the cbp officer did”
justgohomealready@sh.itjust.works · 14 pts · 17d
If they were not in the United States so that the constitution doesn't apply, why would the other US laws apply? Makes no sense.
chuckleslord@lemmy.world · 9 pts · 16d
"You see these guns? That's how" - the fascist bootheels at the border
tyler@programming.dev · 1 pts · 15d
Listen, I completely agree. I’m stating what is going to be argued in court.
Dryad@lemmy.world · 4 pts · 16d
He was in fact in the US when this happened. Also he alleges he wasn’t read his Miranda rights, and there’s a good case for presumption of guilt from the “officers.” Also denied him having a lawyer present before engaging.
tyler@programming.dev · 1 pts · 15d
He hadn’t made it through border patrol. He was not in the U.S.
lambalicious@lemmy.sdf.org · 4 pts · 16d
Thus the officer has no rights to confiscate. There, done.
far_university1990@reddthat.com · 16 pts · 17d
But he did not destroy, officer did by type in code he got. His mistake to trust user.
tyler@programming.dev · 3 pts · 16d
I agree. I don’t think the charges will hold for exactly that reason, the device owner didn’t do anything to destroy the device and also didn’t prevent seizure. The CBP still has the device.
apfelwoiSchoppen@lemmy.world · 8 pts · 17d
Property is evidence.
Jyek@sh.itjust.works · 2 pts · 16d
Evidence of what? You cannot presume there was evidence unless you can prove there was evidence.
lka1988@lemmy.dbzer0.com · 1 pts · 12d
Evidence of destroying evidence. You know, like getting arrested for resisting arrest.
lambalicious@lemmy.sdf.org · 2 pts · 16d
Destroying what? The phone is still there, you just have to install an OS in there or something. A charge with "destruction of property" hinges on the assumption that 1.- there was something in there before the passcode (could have been an empty profile) 2.- that was property (corporate interests insist that our data is not ours, so I don't see how the agent can insist here that the user destroyed his own property, at least) 3.- that was destroyed (which relies on proving point 1).
tyler@programming.dev · 2 pts · 15d
Oh I completely agree. I was just stating what the charge was.
clay_pidgin@sh.itjust.works · 34 pts · 17d
Eating a meal? A succulent Chinese meal!?
No_Eponym@lemmy.ca · 4 pts · 16d
Get your hand off my penis!
orbituary@lemmy.dbzer0.com · 31 pts · 17d
Having a phone? Having a secretive phone?
OwOarchist@pawb.social · 20 pts · 17d
Okay, new plan: instead of a duress password that deletes data, a duress password that randomly scrambles your decryption keys. (And of course all important data is already encrypted.)
No 'evidence' was destroyed. The encrypted data is still there, perfectly intact. It's just that easy access to it has been cut off, since now not even you have a way to decrypt it.
northendtrooper@lemmy.ca · 40 pts · 17d
nah, the duress should load a 'fake' account with dummy information and media. While deleting the real account in the background. What gave it away was the 'blinking' screen. Something that GrapheneOS team should be avoiding.
ornery_chemist@mander.xyz · 28 pts · 17d
That's actually what the duress password does and did here. Deleting the data would be too slow, so it gets rid of the keys instead.
Darkassassin07@lemmy.ca · 9 pts · 17d
I wonder; can those keys be backed up to a seprate device, and reinstated later?
So: could you use the duress passcode to wipe the keys, making the device unreadable; then later use a backup to restore those keys and regain access?
ornery_chemist@mander.xyz · 11 pts · 17d
My recollection is that the keys are stored on the TPM and can't be exported. Backups kick the can down the road; now the adversary demands access to your backups. If the keys can't leave the TPM and the TPM is wiped, then there is no more leverage that can be applied that will unlock the phone. The adversary might still try to get at other kinds of backups anyway to search for whatever data they were after to begin with, but that's a separate issue.
panda_abyss@lemmy.ca · 10 pts · 17d
I'm sure there's a difference between "I deleted evidence" and "I deleted evidence off this device you're inspecting without a warrant, you can have it with a warrant".
But I also feel that unless there's suspicion of a specific crime, you can't really accuse someone of deleting evidence. And no, protesting peacefully is not a crime.
quick_snail@feddit.nl · 7 pts · 17d
In the US, they can't force you to give a password. Because they can't prove you haven't forgotten it.
In this case, it was an officer who was attempting to gain unauthorized access to a device and then accidentally entered a code that caused it to wipe its own data
So the activist has a pretty good case here to sue the officer for damages
OwOarchist@pawb.social · 4 pts · 17d
Technically, no.
They can't force you to give a password because of court precedent around the 5th amendment. Courts ruled that being forced to give a password counted as being forced to divulge information and was thus a violation of your 5th amendment right to remain silent and not incriminate yourself.
That's why they're still allowed to force you to give biometrics to unlock a device, though. Different court cases have ruled that being forced to put your finger on a fingerprint reader or show your face to a face scanner does not count as being forced to divulge information -- since it's action, not information -- so law enforcement is still allowed to force you to do those things.
(Which means, if you're about to be arrested or you're crossing a border or something and you don't want your device searched, you should disable any biometric unlocking features first. I'm not familiar with Android, but in iphones, you can do this by restarting/powering off the phone (always requires pin/password on first boot) or by pressing the lock button repeatedly while already locked.)
logging_strict@programming.dev · 1 pts · 17d
... and the govt would argue that the officer was doing his job. And the rubber stamping wigged political activist would merely rubber stamp that
Darkassassin07@lemmy.ca · 4 pts · 17d
Makes sense; if you can export them, so can an adversary.
Only if they know/think they exist. The idea here would have been to make a nondescript offline backup of the keys and keep them totally seprate from the rest of your data/belongings. Possibly in a geocache type location.
JustEnoughDucks@slrpnk.net · 1 pts · 16d
The services (cellebrite) they use to crack normal androids and iphone s would surely let them know that there was an off site backup that likely exists, given that the company doing it knows grapheneOS exists and is used by journalists and their owner's regime is the top murder of journalists in the world
logging_strict@programming.dev · 3 pts · 17d
... and that would require a search warrant. But then the highwaymen would have to go in front of a wigged political activist to seek approval of a search warrant. Baseless allegations by someone with dubious jurisdiction?
Bet that hearing would never make it into the press
cheeseburger@lemmy.ca · 1 pts · 16d
Must be related to why GrapheneOS only supports pixel hardware at the moment, because it has the hardware to keep the keys locked up and provide attestation that they are.
ch00f@lemmy.world · 14 pts · 17d
The correct solution is a duress password that just opens a generic smartphone interface with nothing on it. Nothing suspicious. They won't even know to investigate.
Darkassassin07@lemmy.ca · 11 pts · 17d
Both. Wipe the real keys so they can't read it if they do a more invasive look into the device; but present a clean profile to the dumb cop that entered your duress pass, to curb suspicion.
Cheebus@lemmy.world · 3 pts · 17d
Maybe a snapshot of a “clean” version (os) than can be unique to the owner
VitoRobles@lemmy.today · 1 pts · 16d
Duress password that causes the phone to burst into flames. It also shouts "You killed me you murderer! I had a family! You sicko!" As it melts.
The smoke causes everyone to weep. It's not tear gas. Its emotional gas, as everyone in the room is crying at the death of the phone and the life it could have lived.
lka1988@lemmy.dbzer0.com · 1 pts · 12d
I'm pretty sure Graphene can do this.
Juice@midwest.social · 17 pts · 16d
Turning this feature on right now, thanks for the reminder
abbiistabbii@piefed.blahaj.zone · 12 pts · 16d
What happened to the fourth amendment
01189998819991197253@infosec.pub · 6 pts · 16d
It got amended out
InternetCitizen2@lemmy.world · 3 pts · 16d
It exists as part of your argument in court. The gos helps you enforce your right and catch them in the cookie jar if they try to be slick. At least that is how I think of it.... Or used to in more normal times.
abbiistabbii@piefed.blahaj.zone · 2 pts · 16d
Kinda wish people would go as hard on their Fourth Amendment rights as their second.
InternetCitizen2@lemmy.world · 2 pts · 15d
And that the ammosexualls were not the biggest boot lickers
fizzle@quokk.au · 10 pts · 17d
I don't really know anything about privacy and security in this context, but I remember playing around with encrypted disks and reading that encryption isn't really useful if your adversary knows that something exists albeit encrypted.
I think this is similar: having a freshly wiped phone is going to attract attention. I'm not saying it's the wrong move in all cases, but it's probably the wrong move in the kinds of situations most people are going to encounter.
I think the latest advice for attending protests and similar is to take a cheap burner.
otacon239@lemmy.world · 17 pts · 17d
quick_snail@feddit.nl · 11 pts · 17d
The duress password is literally the solution to this.
After the keys are wiped, they can't get the data - even if you give them the password before or after they repeatedly hit you with a wrench
Badabinski@kbin.earth · 8 pts · 17d
What we really need is deniable encryption, where you can decrypt just a specific layer of your device which is entirely innocent, while also possibly destroying the deeper layer which has anything incriminating. It's been a concept since the 90s, but it's not widely used or known of.
iocase@lemmy.zip · 3 pts · 16d
Veracrypt can do this with hidden volumes. The danger is the hidden layer can look stable and fake so you need enough data that changes recently enough, and if you add too much to either volume it starts corrupting everything because one partition overwrites the other.
triple_entendre@infosec.pub · 7 pts · 17d
The trouble here is that this happened to him in an airport, not during a protest.
fizzle@quokk.au · 6 pts · 17d
Emphasis added.
I remember reading warnings about having laptops and devices checked at airports a decade ago. As a matter of fact I think that's why I was looking into having hidden, encrypted partitions: because getting caught with some pirate TV series on my laptop might have meant having to pay a bribe or whatever.
Regardless, it doesn't really change my point - if there's a chance you're going to interact with a government official and they might want to look at your device, wiping it is going to attract attention.
logging_strict@programming.dev · 1 pts · 17d
Which according to mafia he has about the same rights as Fauci's beagles. Which is what makes this case interesting. The bewigged political activists will be doing legal cartwheels to keep the "before admitted to US" scam alive.
drcobaltjedi@programming.dev · 3 pts · 17d
I mean, most people don't know their encryption keys. A correct password retrieves the keys from the TPM, the duress pin wipes the TMP so now even a correct password is unable to get any of the data.
Hell, even if you use the same password in multiple locations (you shouldn't) a good service will salt (add a random but consistent jumble of characters for your account specifically) and then hash (weird complicated math that makes it really hard to reverse your password) your salted password then check if that salted hash matches what's on file.
quick_snail@feddit.nl · 2 pts · 17d
Article doesn't load
Marija_@programming.dev · 1 pts · 15d
Different CDMWorlds, different assumptions about privacy.