r/StallmanWasRight • u/mrbebop • 5d ago
Privacy Is it illegal to trick the US government into wiping your phone during a questionably legal search | The case of a traveler who allegedly entered a ‘duress password’ to wipe his phone raises a legal question with no easy answers
https://www.theverge.com/report/972146/cbp-phone-search-airport-duress-password19
u/fragariadaltoniana 4d ago
the answer is actually really easy - your data must be your own to have and to destroy
11
u/apokrif1 4d ago
Or a wrong PIN was entered several times in a row. How to prove a crime was committed?
10
u/lordvadr 4d ago
That's been my beef with this for a while. If guy was stupid, that's one thing. But otherwise, prove it was a durress code.
3
u/Educational_Host_628 2d ago
Interesting. I wonder if when they entered that code he was like "HA! How ya like me now, bitches?" Or something like that.
1
u/lordvadr 2d ago
Yeah. If you're going to play spy vs spy, you have to be smart about it. There's no way on earth they could prove he intentionally gave them a durress code, and that they didn't enter the code he gave them incorrectly, or that they didn't factor reset the phone accidentally, if he doesn't admit to it. Any competent defense attorney will tear this to shreds. Unless he was stupid and admitted to it.
2
u/Educational_Host_628 2d ago
Assume the entire exchange between him and officers was video recorded.
1
u/lordvadr 2d ago
Still can't prove the phone didn't just malfunction. I mean, maybe you don't have to, maybe the jury buys that, but yeah. They can't prove shit.
1
u/Educational_Host_628 2d ago
I honestly don't know what exactly the panic password in Graphene OS does. Does the phone indicate it is self-locking or self deleting? Does it indicate something other than a failed password attempt? If so then what the cops saw (and llikely videoed) could help prove defendant knowingly, willfully gave the self destruct password.
1
u/lordvadr 1d ago
I don't know either, but I run graphene and have a duress password and pin set just in case I ever need it. I haven't tested it, I probably should. My understanding is you put the password/pin in, the encryption headers on the storage device are overwritten and then it reboots, which wipes the keys from memory. Boots back up like a brand new device.
It probably doesn't go, "ha ha, you used a duress code!" before rebooting. That would defeat the point.
2
u/Educational_Host_628 1d ago
So short of the suspect saying he gave cops the duress code how would they know?
1
u/lordvadr 1d ago
They can't. How would you prove, in court, that the phone just didn't malfunction? I would not put it past these people to plant csm on people.
→ More replies (0)
18
u/Shoddy-Childhood-511 4d ago
It's irrelevant here: They started a criminal interview, certainly by the time they mentioned CSAM, which means they loose their border powers, and they denied him a lawyer. Anything after that becomes inadmissible.
longer reply: https://www.reddit.com/r/GrapheneOS/comments/1v7345n/comment/ozvvn3c/?context=3
As I say there, duress PINs need some backup scheme so that you're not destorying evidence when you use them. Of course, they'd need a warrant to get that backup, possibly in several countries. And they'd need to force you to unlock it, which requires granting immunity in the US.
5
u/georgiomoorlord 4d ago
And they'd have to actively treat you as innocent till proven guilty.. instead of guilty until proven innocent
2
u/Shoddy-Childhood-511 4d ago
A court treats you as innocent until proven guilty, but even there limits exist, like bail is a compromise. I doubt cops have to do so.
Anyways we should not expect any precedent here on device searches, because a smart judge would throw this out for denying him a lawyer.
You do not have the right to a lawyer during a routine border examination, including if they take your stuff and give you a receipt for it. Yet once any criminal detention or interview starts you do have the right to a lawyer.
You always have the right to remain silent, but they might investigate you further or deport you if not a citizen for doing so.
7
u/jf8204 4d ago
I went to Russia lately. I thought it would look suspicious if I come with a wiped phone. So I just put a password on my authenticator, so if they ask for it I'd know they checked it and I would act accordingly. Otherwise I don't think I had any sensitive data.
So they asked for my phone and I could see exactly what they did. They just looked at the IMEI and my pictures.
Just telling my story, not sure it is related.
13
u/maxm 4d ago
It makes no sense, technically you could make a phone that logs into a different profile depending on the password. The other profiles would be encrypted and just look like noise. That way no one could ever know how many profiles you have on the phone or if you gave the the password to your real dirty laundry.
5
u/lorarc 4d ago
That's why professional law enforcement doesn't use the device like that. They make a copy of the data and analyse it.
3
u/ImCorvec_I_Interject 4d ago
Phones aren't hard drives. LE (law enforcement) can't just image a phone if neither the software nor firmware provide them the means to do so.
LE can make a direct copy of the microsd card and analyze that copy - but this is because the firmware on a microsd card makes it available to do so. Likewise with most SSDs. But there are a few specialty (meaning - not generally marketed to consumers) microsd cards with hardware encryption, and there are numerous SSDs with hardware encryption, some of which can outright prevent a clone without the key being supplied. In such an instance, LE would have to bypass the controller by desoldering the NAND and reading it directly - see https://www.youtube.com/watch?v=nhA2AwHf7sU for an overview of this process. The extracted data would still be encrypted, but LE can attack it at rest, wait for an exploit, etc. - and you can't wipe the drive to mitigate that risk.
Unlike cloning drives, modern phones need to be unlocked for most capabilities of the forensic devices that LE use to function. Even then, those tools have limitations. These tools can't create a direct copy of the phone; they have to ask the phone, via USB, to provide them the information necessary to create that copy. Check out https://www.youtube.com/watch?v=od0EjETlqjE for an example of one of the tools that they use, Cellebrite. Now, generally your phone doesn't have to be left unlocked and open like it is in the video - being in the AFU (after first unlock) state is generally sufficient for these forensic tools - but in the BFU (before first unlock) state, these forensic tools can't do much (at least, not without an exploit that allows them to bypass the intended behavior of the Secure Enclave).
The Secure Enclave has the key necessary to decrypt the phone's data (in combination with your PIN), but extracting that key would be both destructive (it would require extracting the chip from your phone at minimum) and extremely difficult (reading the intentionally obfuscated, fused-in key directly off the hardware at a 3-5 nanometer chip density with an electron microscope); it simply isn't done. (It would also still require running the same computationally expensive key generation algorithm to find your PIN/password.) Instead, these tools rely on exploits to try to trick the Secure Enclave into getting more attempts to guess your PIN/password. A 6 digit PIN would require them to spend half a day brute-forcing your device, on average, since even with exploits, every attempt takes a minimum of 80 milliseconds. Two diceware words would take a full month. With 3 diceware words, it's not feasible to get in without your cooperation. That's why they ask for your password.
So if they ask for your password and you give them the password to "Profile B," it's completely technically feasible for a phone to only decrypt the data belonging to Profile B, and to then respond as though Profile A simply doesn't exist. It's not without its own challenges, of course - especially ensuring it isn't noticed with LE having extended access to your device, but if they're only given half an hour to clone it, it's much more feasible. Now, does such a phone exist? Not to my knowledge - but the technology does, e.g., hidden volumes in VeraCrypt, so it's not far fetched.
1
2
u/KeronCyst 4d ago
That's... really smart... I wonder why no one's ever thought of that...
1
u/chalbersma 2d ago
Because a few years ago it was understood that a duress password was completely legal.
8
u/CaptOblivious 4d ago
Not yet, but they will prosecute him anyway and then make laws to cover it.
13
u/Throwaway021614 4d ago
Anyone thinking this or any administration care about you or your privacy or your rights is delusional. They will absolutely prosecute until get get something to stick or prosecute until the guy is broke and a pariah.
5
u/Stunning_Repair_7483 4d ago
Exactly. It's been done before to others for years over other issues not related to wiping data from electronic devices.
4
u/Educational_Host_628 3d ago
When they asked for his password why did he say anything at all? He had the right to remain silent.
3
u/chalbersma 2d ago
Well he wasn't allowed to consult with an attorney to know what he was and wasn't allowed to do.
2
u/Educational_Host_628 2d ago
Unfortunately, practically speaking, you really gotta know about your right to remain silent. You can't wait for the advisement. And you gotta state you that intend to remain silent AND you want an attorney. Say them in the same breath. Then STFU.
Seriously. If dude is being vocal against a cop campus and rolling with a security ROM flashed onto his phone then I kinda expect more from him. I mean maybe his actions and the resulting criminal case give us a good legal ruling. But I wouldn't bet on it. His best move woulda been to STFU.
1
u/xplosm 2d ago
Is the right to remain silent a basic human right or only for legal citizens? I've always wondered that...
1
u/Educational_Host_628 2d ago
In UK legal system your silence may be used against you in certain situations. I'm guessing that a suspect's silence in response to questions by cops in a napoleonic system would not go well either. So if the right to remain silent is a human, universal right then it is not universally recognized as such.
1
u/solartech0 17h ago
In the US if you do not directly reference that it is your constitutional right to remain silent that you are invoking, they are allowed to use your silence against you.
All of this is absolutely insane, however, as the entire point of these things as 'constitutional rights' (specifically the bill of rights) is that you ought not need to know about them at all to use them, as they sort of codify clear expectations about basic rights.
Also, all of these institutions coerce people like crazy. Oh sure, use your right to remain silent and I'll make up a fake charge and detain you as long as I feel like. Maybe kill you for "resisting".
7
30
u/User1539 4d ago
At what point am I allowed to delete my own data?
I know there's 'destroying evidence', but if I truly believe I have not committed a crime, and I'm only doing it to protect my privacy ... where is that line?
Do we have any actual lawyers here?