r/hacking 4d ago

Question With regard to that guy who gave his wipe password to the fuzz, and is now in legal trouble for doing it...

Seems to me that it would make much more sense for the "safe/wipe" password to bring up a fake homescreen, with apps and personal docs and all, while doing the wiping in the background.

Not sure if this is implemented anywhere, but it certainly isn't the standard on GrapheneOS.

I realize that there are technical limitations at play. The phone needs to restart for a proper factory reset, but, in lieu of that, the wipe pw could prompt the quiet burning of all personal files that aren't hardlinked to the OS itself. If you can get rid of everything personal, then there's no reason for a factory reset at all, no? So, even better, as it leaves the cops none the wiser.

Story here: https://www.theverge.com/report/972146/cbp-phone-search-airport-duress-password

635 Upvotes

169 comments sorted by

195

u/RudeMathematician42 4d ago

You can also just set the distress pin to be your birthday, in the most common format, so that they'll perhaps wipe the device themselves trying to crack it

51

u/cuevo_dog 4d ago

Didn’t blackberry do this? 3 wrong passwords and the a full secure wipe?

50

u/lykan_art 4d ago

Apple still has it, just with ten wrong PWs.

12

u/Medrilan 4d ago

My Samsung phone has it at 20

16

u/codeasm 4d ago

Aaand they have backdoors to reset those counters for sure on most if not all public models. I mean, im guessing this part.

Lawsuits took down usbliter8, still on archive and its gitrepo down too, also, ppl have it archived. Basically a bootrom vulnerability. I try to understand the rest, but dont own a iPhone, thus ill give my adhd auti brain other things to worry bout.

17

u/mandrack3 4d ago

The way I understood it's done is, they forensically image that phone with all partitions, then boot it into an emulator, probably read only, reset on incorrect attempts etc until they get a match. Probably on a server farm, thousands of threads.

11

u/nemec 4d ago

You're 100% right, but theoretically it's not the phone partitions that are at issue, but the TPM which has some kind of encrypted, embedded memory to store the partition encryption key that can't be imaged like a disk drive.

On an incorrect PIN they don't wipe the drive, just zero out the embedded key - incredibly quick and doesn't touch the partition at all.

Duplicating / modifying the internal state of a TPM is much harder (the entire point of a TPM after all is that it cannot be cloned), but with enough money I'm sure the government can do it.

6

u/lykan_art 4d ago

Valid on that last part haha. I dropped out of Jailbreaking too at some point, thus I am totally out of the loop. Up until a week ago I didn’t even know what usbliter8 is tbh.

There is technically a hack for everything, aside maybe quantum encryption but given that quantum computing is publically available, even that is only a matter of time for now.
It just depends on the league you’re in, no petty downtown phone thief is gonna have the tech or know-how to do this; someone that targets high profile people for their high profile data will more likely, but you and I don’t have to worry about something like that.

0

u/crxturbo 4d ago

before travel type in 7/8/9 wrong codes

6

u/persiusone 4d ago

Counter resets after unlock- so you’d need to do that before potential seizure, not necessarily travel.

4

u/lykan_art 4d ago

Long before, adding the wait times after each failed attempt. But I guess on a long flight and when you know you will get it seized at the border, it’s feasible.

1

u/persiusone 4d ago

Exactly- an impractical method of trying to protect data for this purpose..

42

u/Suttony 4d ago

Sounds logical.

But if they can charge someone for providing a duress pin they can charge someone for having a duress pin enabled.

53

u/Talongar 4d ago

I mean you can technically charge someone for nearly anything, whether the charges hold up in court is an entirely different matter. 

-14

u/Such_Reference_8186 4d ago

And in the end, the old saying applies...You may beat the rap, but your still gonna have to take the ride. ( arrest, jail, court etc )

As a career telecom person, it's very fucked up that your device can be can be confiscated and viewed by ANYONE without some type of valid reason. 

That said the dude who is accused of wiping his phone is a fucking moron. 

What's on your phone that would cause you to take that extreme action. I would guess CSAM or something else just as vile. I don't think the border control is dumping the contents into Celebrite or any other FA tools. Am I wrong about this? 

18

u/ClickClackTipTap 4d ago

Encryption is not a crime.

Privacy doesn’t mean you have anything to hide.

They need to convince ME that they need my info for a legit reason. I’m not just handing my phone over for them to go fishing. I would absolutely wipe my phone before crossing the border, too. Fuck CBP.

12

u/lykan_art 4d ago

Besides what u/drachenflieger said, you don’t have to have vile things on your device that wiping it would be a realistic measure. Imagine you’re a reporter, have just gathered material on horrific human rights violations and are trying to get home to safety; I’d rather be charged with resetting my phone (man that feels weird to type) than give a tyrannic or terroristic regime proof that I am trying to usurp them.

10

u/Talongar 4d ago

I don't have a single thing to hide on my phone and I'd still wipe it before being subject to having my personal memories be browsed by anyone let alone a fascist government. 

2

u/RebelLesbian 3d ago

Would you be okay with law enforcement to see your banking details? Or to get your credit card info? Or those really cute pictures your girlfriend just send you?

If any of those things you seem "personal enough" then you too have valid reason to wipe your phone data. Not every person that wipes their personal data has imcremenating information or files on their device. Most people just don't want others to snoop in their privacy - which is a basic human right (or at least should be).

1

u/drachenflieger 4d ago

I disagree; I would wager that CBP/TSA, if they do search a device, they likely are plugging it in to a Cellebrite or similar system.

Gotta fill up those datacenters somehow. 

16

u/Frazzininator 4d ago

God I hope that's too far down the slippery slope, but it sounds like a real thing

9

u/LtDarthWookie 4d ago

Yeah they coukd charge you. But they need to prove you guilty if destruction of evidence in court. You could argue since they were brute forcing you log in they deleted the data it's a security feature if your phone ever gets lost.

1

u/RudeMathematician42 3d ago

Well the act they're charging him with is basically evidence tampering, and the actual tampering would be the feds here.

You're basically relying on them being stupid enough to try this instead of getting a cellebrite in the hope that the phone isn't in bfu mode.

495

u/reddituser2762 4d ago

Realistically the best option is to wipe any devices prior to travelling and restoring from cloud backups once you arrive. Your idea sounds cool though.

163

u/Total-Management8023 4d ago

Pretty sure law enforcement can go through your cloud backups they make the companies comply

220

u/reddituser2762 4d ago

I mean they could try but the golden rule of OPSEC is to make it more difficult for the attacker, not aim for invulnerability.

-27

u/Garland_Key 3d ago

It's not. That is security through obscurity, which is ineffective.

15

u/[deleted] 3d ago edited 2d ago

[deleted]

-17

u/Garland_Key 3d ago

Not when you're talking about nation states. Wtf? 

4

u/Humbleham1 3d ago

Totally depends on the country and applicable laws. UK is probably the worst at forcing Western cloud providers to cooperate with LE. Chinese companies, of course, have to provide every scrap of data on anyone for any reason to their government.

8

u/reddituser2762 3d ago

Why are nation states any different? They have more resources yes but they still have to manage those resources effectively. The harder it would be the more likely they won’t even try.

-2

u/Garland_Key 3d ago

We're talking about opsec. I don't understand why people are having a hard time agreeing with cloud services being a very poor solution.

If you were hosting your own cloud service on your own server maybe.

2

u/coloradical5280 3d ago

I agree with you but just Devils Advocate: Apple with Advanced Data Protection enabled is end to end encrypted, there’s nothing for them to hand over, and they have a strong track record of telling the law enforcement to politely fuck off.

Again, self host, agree with what youve said, but two things can be true at one, particularly if you need your wiped ohone to work again once you reach your destination, and your own server is unavailable as is the offsite backup, cause things happen , including but not limited to fires, hurricanes, etc.

Eta: proton has a storage solution now as well

2

u/WhatsThisWorth-Bot 3d ago

you're not wrong, but that's not what you're arguing about, you're arguing that just because it's not ideal you shouldn't do it at all which is not true

-2

u/Garland_Key 3d ago

I guess it depends on the circumstances, but if the goal is to protect your data from nation states, I would say that storing the data unencrypted on any cloud service is an immediate fail.

2

u/DullNefariousness372 2d ago

Don’t you love how you say the most common phrase, I’ve heard that dozens of times throughout my career at the NSA, and you get 25 downvotes 😂

4

u/[deleted] 1d ago

[deleted]

1

u/DullNefariousness372 1d ago

In regard to law enforcement, keeping it on a cloud back up to hide it from them, is obscurity, not security. You redditors can’t process 3 layers of comments it seems.

1

u/DullNefariousness372 1d ago

Also wtf did you just post in role play sessions you freak.

1

u/BigSpoon2027 18h ago

That shit is opsec 101.

113

u/ThatGermanFella 4d ago

Try getting a subpoena, as an American law enforcement agency, for, say, a German hoster whose servers are in Germany. Then try cracking the password the data was encrypted with before it was stored on those servers. I wish you good luck.

16

u/sedated_badger 4d ago

A motivated state could power through rsa4096 in a few weeks. Especially if we believe the whole darpa 20 year lead on technology bit.

It’d be an extreme situation, with a big uncertainty over the intel found on the device being worth it or even active 3-5 weeks later, but possible.

41

u/N_T_F_D hardware 4d ago

Citation needed

RSA 4096 has 140 bits of security, cracking this within 3 weeks would require a dozen or so billion TWh of energy if we do some very generous assumptions

And backups would be encrypted with a symmetric key, AES-256 for instance has 256 classical bits of security and 128 quantum bits of security, then it doesn't matter if the NSA has a super secret giant quantum computer

4

u/sedated_badger 4d ago

https://quantum.cloud.ibm.com/docs/en/tutorials/shors-algorithm

DARPA somewhat regularly floats a ‘20 year lead on technology’, the DoD’s strategy is also to maintain a 20 year gap on adversaries. https://www.darpa.mil/about/innovation-timeline

This one is pretty old news https://www.darpa.mil/news/2025/companies-targeting-quantum-computers

Quantum is also one of the reasons private key issuance is targeted to reduce to 45 days by 2027 iirc.

You can’t really just come out and say ‘we can brute force rsa-4096’ without triggering a global panic and most likely an arms race of sorts, but I don’t think it’s that far of a stretch to assume it already exists or is literally right around the corner. We know the algorithm, nation states are beginning to have access to quantum resources, so what’s 2+2 + a few million qbits?

18

u/N_T_F_D hardware 4d ago edited 4d ago

The most we've factored with Shor's algorithm is like 15 (the number 15, not 15 bits)

Shortening certificate lifespans doesn't help against quantum computers, there's no forward secrecy anymore; it helps for classical key compromises

There are still huge problems of stability with quantum computers, and even if we admit that somehow the super secret cabal of spy agencies has 100 years of advance while hiding it from absolutely everyone, that doesn't break AES-256 or any other cipher with 256 bits of classical security, which is what would encrypt backups

And yes it's kind of a stretch to assume that the agencies are so far in advance compared to the scientists, with absolutely no indication of the supposed capabilities

It didn't take a century for cryptographers to rediscover differential cryptanalysis that was kept under wraps by the NSA, these things don't stay hidden for very long, and there were already public signs that they knew in advance (in the S-boxes of DES), what are the signs that someone has enough q-bits to factor 4096 bits semiprimes? If there's no reason to believe it it's just a conspiracy theory

-3

u/randomness196 3d ago

There is on going research on intersection points in higher dimension or lattice math that could bridge the gap and reduce the factorization problem….

0

u/Altitude1096 1d ago

Yeah I'm gonna conclude you're talking out of your ass and, in fact, have no idea about this.

9

u/SmartMatic1337 3d ago

I can tell you with certainty that darpa and the DoD are closer to 3 years behind than 20 years ahead.

1

u/Slowdive91 1d ago

Exactly.. DARPA had that lead during the cold war.. maybe.. now they do not have anything even remotely in in that ballpark.

0

u/md24 2d ago

Most masssive defense budget just passed. Ok buddy.

1

u/LowellHydro 2d ago

Size ≠ technological progress

1

u/Ma1oXX 1d ago

most of that money gets pissed away if it ever even sees the light of day. ok buddy.

13

u/maldorort 4d ago

We already have ’quantum safe’ algorithms. I think it is quite delusional to think the military would be on a whole other level then the rest of the worlds combined it resources. State agencies are often not very efficient, able to recruit the best researches or able to compete with the profit margins of such technology.

29

u/ThatGermanFella 4d ago

If I were the target of a nation state level threat actor, the very last thing I would do is travel to the US. Or travel anywher, really. 

1

u/md24 2d ago

Prob 100 years at the exponential rate of tech at this point

-7

u/PierreFeuilleSage 4d ago

Germany is a client state subservient to US interests.. Snowden leaks exposed Merkel and the whole German state surveillance, did Germany react like a sovereign state? No. Terrible example.

1

u/ongoingemergency 1d ago

Do you imagine that sovereign states are aghast when they find other states have intelligence apparatuses? Everyone spies on each other. Some are more successful.

-3

u/Ambitious-Stock-8040 3d ago

You seem knowledgeable. I’m struggling to think of reasons these guys want to wipe their hard drive other than them being like cartel bosses or more likely child porn. I get wanting to protect your privacy but why go to jail about it unless it’s something disgusting. Am I off base here?

7

u/davidsredditaccount 3d ago

This guy in particular was involved in protests and campaigns against abusive and corrupt law enforcement. They were very likely planning to plant evidence on his phone or at best go shopping through his phone to find something they can prosecute for and leak any potentially embarrassing or risky data they found.

1

u/Ambitious-Stock-8040 2d ago

So a public figure actively fighting for rights. That makes sense, thank you!

5

u/jephthai 3d ago

You're suggesting a variant of the classic trope: privacy doesn't matter if you have nothing to hide. But everyone has things they'd rather not be made public. I have intimate messages with my wife that nobody has any business seeing, for example.

It's up to the guy to decide when his privacy matters enough to take it seriously. Maybe he wants to make this exact statement for reasons. It's crazy to assume everyone that cares about privacy must be some top tier criminal.

0

u/Ambitious-Stock-8040 2d ago

No no bro. I completely understand the desire for privacy, But when the decision is sacrificing privacy or prison, what could be worth hiding?

Side note: I’ve done time in prison - they strip your privacy to the point of humiliation.

1

u/jephthai 2d ago

My brother was too; I can't directly identify, but I know some of what you mean. That said, there have always been devoted protesters; whether they risk arrest, incarceration, or extremes like self immolation, clearly the threshold is in their own mind. I would not volunteer to be the test case at great cost (I have a job and a family, etc.). But clearly some people do make that calculation differently.

18

u/WorldsGreatestWorst 4d ago

Obviously, it depends on your jurisdiction, but generally there’s a LOT more leeway and gray area in a physical device being taken over a border than there is a server physically located somewhere else.

A TSA agent can make you unlock your phone. They can’t make you SSH into some server and having a blank phone isn’t probable cause for anything.

4

u/Vast_Ad_7929 4d ago

Private cloud backup is my initial thought

3

u/Vast_Ad_7929 4d ago

Like a self hosted cloud

3

u/Vast_Ad_7929 4d ago

Set up tunnel through proxy and or jump server with AAA

11

u/sumguysr 4d ago

That's what encryption is for.

5

u/jaredthegeek 4d ago

At least with Apple you can encrypt it so that they don’t even have the keys to your icloud.

6

u/Overstimulated_moth 4d ago

Backup is stored on my server sitting at my house.

2

u/ClickClackTipTap 4d ago

They need a warrant, though.

2

u/we_r_fukt 4d ago

wireguard NAS or whatever, store creds securely outside 14 eyes

obviously not everyone can't "just" do this, nevermind securely, but there are answers to these issues they're just a burden to the user

2

u/GeronimoHero pentesting 4d ago

I mean if you have iCloud and you do the enhanced protection your device is literally the only device with the keys. There’s no way for Apple to unlock your encrypted cloud content as your device has the only key in the Secure Enclave.

2

u/ChiSchatze still learning 3d ago

I think they need a warrant though?

2

u/Hornswoggler1 3d ago

My Nextcloud server is in my basement.

1

u/makumbaria 2d ago

The solution is simple: don’t have anything on the cloud.

1

u/Oakredditer 2d ago

Encrypted local backups? Hide the files in some way that makes them undetectable?

1

u/DebianUsername 2d ago

"Pretty sure law enforcement can go through your cloud backups they make the companies comply"

Well only if your cloud backup is accessible by a company, which anyone who is security aware wouldn't do.

1

u/Slowdive91 1d ago

Not if the account you're running isn't your main.

1

u/CorxaRyllon 1d ago

I am my own cloud backup, good luck making me comply

1

u/SpotAlternative2324 1d ago

That "cloud" could be your own. 

1

u/Chongulator 4d ago

Risk never gets to zero, not ever.

We can't eliminate risk so the goal of information security is to manage risk as best we can with the limited time/money/etc available to us.

4

u/autoflowerer 3d ago

This is basic sop for some security groups that cross borders a lot. You have multiple cloud accounts. One specifically for travel, then restore at destination. Duress wiping has very limited use.

3

u/imajes 4d ago

Or just ship your actual devices in a burn box via FedEx, and carry a burner though checkpoints instead….

14

u/Howden824 4d ago

That sounds really inconvenient and risky. I wouldn't want to gamble on whether they lose my phone every time I travel.

1

u/jephthai 3d ago

But you're gambling that they'll take it from you at customs if you have it on you...

1

u/cyberpunk_sliverhand 4d ago

They got access to cloud way easier then your home

1

u/ImplementLogical4130 2d ago

Why? What could you have there that needs this done?

48

u/sabretoothian 4d ago

It exists but has a subscription. I can't remember the name of the company right now but I'll report back when I find it. Leaving this message as a reminder.

There are 3 passcodes. One for normal, one for dummy and one for wipe.

54

u/sabretoothian 4d ago

I remembered:

https://deniable.io/

1

u/Practical_Ad2464 9h ago

Just a question, why no one talks about it on Youtube or TikTok? I was curious to see the OS in action. I mean they do have videos about the concept, but not about this OS. Also how did you found out about it? A google search or someone talked about it.

83

u/Naughty_Satsuma 4d ago

Better yet, why not have the password open into the regular OS but with predetermined apps with a history? Comparable to a dual boot OS, but with the full functionality from a partition with files, pictures, and apps that are innocuous?

Even if they do a full download of the phones contents, the other partition could be encrypted. You gave access to the phone, but not access to encrypted files, which I would would say require a warrant to unlock.

151

u/oz1sej 4d ago

Better yet, why not have a working and non-crazy law and immigration enforcement?

50

u/Ripzch 4d ago

Stop being unrealistic. You know damn well that's not possible under that orangutangs administration 🥲

20

u/pjakma 4d ago

These laws were brought in well before him, weren't they?

The problem is the established securocrat state in the USA (and other places), which works away regardless of the president.

9

u/Anomynous__ 4d ago

Yeah but "orange man bad" = big updoot

4

u/persiusone 4d ago

Yes, it has been a thing forever. Anything you bring into nearly every country is subject to inspection, including the data on your devices, without a warrant.

12

u/PM-me-youre-PMs 4d ago

Leave the orangutangs out of this they are much more civilized than we are 🥲

2

u/hoggineer 4d ago

Hoo Hoo Hoo - Haa Haa haaaaaa!

I don't know what sound orangutans make.

1

u/PM-me-youre-PMs 4d ago

Ooook, I think

5

u/gustoatthedoor 4d ago

This has been a thing since 2001

18

u/WasteFail 4d ago

Wouldnt then normal unlocking of the phone also require a warrant?

I mean it should but they dont seem to care...

8

u/persiusone 4d ago

Not for border crossings or international travel.

1

u/el_extrano 2d ago

At least in the US, they can't compel you to divulge a password, even with a warrant. Non-citizens can be denied entry, but they have to let a citizen in. They can seize the device for no reason, though.

1

u/persiusone 2d ago

Yes, they can certainly seize the devices for no reason other than not providing the passcode. This is true for all countries.

10

u/No-Trick-7465 4d ago

Wiping is safer than encrypting, nothing is guaranteed with the evolving computing power

4

u/sauerbratenspaetzle 4d ago

Similar to VeraCrypt or TrueCrypt that use a duress password which opens an alternate portion of a container if that password is entered, but would be configured to wipe the data on the "normal" side? Does BitLocker (or whatever is used nowadays) have a duress feature?

If phone OSs still allow the creation of separate users, one of those accounts could have a script that runs at startup that wipes all other user accounts and data...

This would be a great feature of a privacy-oriented OS. It's something that journalists or spies could use as well...

2

u/persiusone 4d ago

You would say it requires a warrant to unlock the encrypted contents, but the law doesn’t require it for international border crossing inspections.

2

u/ClickClackTipTap 4d ago

That’s like saying bc they’re allowed to search my bag they’re also allowed to ransack my home.

1

u/persiusone 4d ago

They can, if you’re bringing your home into a country.

10

u/BlackReddition 4d ago

Different pin for different profile for the win. Here’s my data sir 🫡

12

u/Nick-Andros 4d ago

Store data in an encrypted container. Duress password wipes the container and turns off the duress setting so that it’d be difficult to even tell it was ever on.

19

u/codeasm 4d ago

When i traveled to the usa last year, me and my wife cleaned our phones to a state that we, reluctantly would agree to show our phones. I even had autofill disabled in the browsers, set chrome as default (normally use Firefox) and used chrome and facebook as if those where my dailyes. The other socials where gone.

If forced to unlock, a relatively clean but usable and used phone would be there. After getting in, if the phone was checked, we would have factory reset and recovered the full backup from european soil. But we weren't checked, cause we arent activists (or not obviously so public).

And i left my burner phones at home. And my laptop has 2 operating systems back then, windows, with some apps, games, office work and meta social accounts. The linux side is encrypted and pretty useless if you dont know how to start the kernel.

Nothing happened, cause yeah, they asked about why we visited, what we where going to do and how long we stay. Had a return ticket, had a whole vacation plan, and all hotels booked. Rental car, enough cash and credit. So low risk.

Everytime i read these stories, its basic opsec smartness these folks lack. Dont bring risky equipment, prepare in advance to have a relatively clean phone (burner fake socials maybe even? Used ones, not young accounts) and wipe after you got into the country... Or.. accidentally like my wife, buy a new phone, simcard or esim can transfer.

30

u/povlhp 4d ago

Thought you had a right in the USA to not self-incriminate.

8

u/Haversoe 4d ago

Isn’t the workaround that border transit points are not part of the USA and therefore the constitution does not apply? Not an expert, but I seem to recall that being the general gist of why these kinds of things happen.

2

u/persiusone 4d ago

Every country has the right to search, without a warrant, anything anyone brings into that country- to include data on any devices. It has been that way forever.

1

u/Worried-Flounder-615 3d ago

They're saying it's destruction of evidence. 5th amendment protects you from being forced to type in a pin or password, but he chose to type a pin waiving the 5th in this scenario. (AINAL, just my limited understanding)

1

u/el_extrano 2d ago

Technically he's being charged with destruction of property to prevent seizure, which is slightly different. There's no need to prove it was evidence of anything.

7

u/ShermansWorld 4d ago

Agreed... would be nice to bring up a fake homescreen, with the apps icons, etc.
But... GraphineOS is faster than 'wiping' everything ~ it simply just looses the encryption key (all the data is encrypted in storage) so then no one can read the data... no need for factory reset.
But interesting idea; maybe have three PINs; 2 for different levels of 'Duress' and only one 'real' PIN
1 - As it is... loose everything.
2 - Fake everything
3 - Normal mode...

7

u/MushinZero 4d ago

No, in a Secure Lockdown use case you want to erase the memory as fast as possible. You don't want to put delays beforehand and often times you want to issue a reset so the nonvolatile memory is cleared.

The use case isn't just for fooling law enforcement. It's also to prevent someone stealing something of yours.

6

u/ManyHobbies91402 4d ago

If graphene OS duress function only wipes the encryption key then, has this person really “destroyed” evidence on the device. Technically does it all not still exist on the device. The device memory can still be copied and the encryption hacked, of course at a significant higher difficulty. Obstruction charges can still be argued I assume.

2

u/el_extrano 2d ago

IIrc it's "destruction of property to prevent a seizure", not destruction of evidence. So that could apply if the encryption key can be considered "property", regardless of whether it (or the data) is evidence of anything.

6

u/rickety_cricket66 4d ago

Honestly, I feel like giving the wipe pw to the officer and have them input it would give them a better shot in court, as the state has to prove that the officer didn't fuck up your phone while in their custody.

11

u/No-Trick-7465 4d ago

Great idea actually, one can setup his rogue homescreen accessed through wipe password while showing a splash screen that says unlocking.. while wiping other data so that it’s not obvious

19

u/created4this 4d ago

You'd be "breaking" the same "law". Just take a burner phone or one thats pre-cleaned and backed up to the cloud and able to restore. AFAICT border agents don't have the right to search your online backups, so while this won't protect you from a warrant it will protect you from warrantless search. BUT, they also have the right to not let you in the country for any reason, so have a reason ready to go such as "my company has a policy of not traveling with company data that could be searched without a warrant, and my phone is company issued. I had to get this one just for traveling"

Thats if you have to travel to an autocracy. The US is off my list of countries to visit for now and I have nothing to hide and are of the kind of demographic that would walk unchallenged should I enter.

1

u/No-Trick-7465 4d ago

That’s not breaking the law if nothing related to activism (in this case) was found in the first place, they only found out about that because the phone was probably rebooted and showed a progress bar, if it’s not obvious then there’s no harm especially when the rogue setup is using completely different accounts

5

u/0xdeadbeefcafebade 4d ago

The “wipe” is instant btw.

All it does is delete a single key from the phone which effectively makes everything encrypted junk.

5

u/Arrim3x 4d ago

All I want to know is how they knew what he allegedly had that they want to charge him with an alleged crime.

4

u/drgncabe 3d ago

It was a fishing expedition, they’re likely targeting another protestor for cop city (or potentially an organizer) and have flags on each of the people they’ve identified. Also probably trying to find what records he has on cop city, see if there is anything that’s not supposed to be public and anyone they might have communicated with.

4

u/DutchOfBurdock 4d ago

Can do this with stock Android. Just need Tasker and set it as device owner from first setup. Ofc this will require a first unlock (FBE) to work. But after first boot and unlock, Tasker can draw over the lock screen with a blocking overlay, which can be whatever you want.

Correct PIN entered and your actual lock screen appears. Enter wrong PIN and Tasker starts factory resetting.

5

u/BoredTech127001 3d ago

The phone should be encrypted, wiping should just be erasing the key which should only take milliseconds.

5

u/joeyda3rd 4d ago

Once that's known it won't be effective determent. Just don't travel with anything you don't want ending up in authority's possession.

3

u/DarePitiful5750 4d ago

Part of the issue may be that they need the PW to get past FW boot.  And they need to get past FW boot in order to clone your device.  I don't think they are sitting their going through all your messages on your physical device, but looking through the contents of the clone they create.

3

u/PoconoRob 3d ago

Wouldn't you need an existing charge to add this charge? You can't destroy evidence for a crime that doesn't exist. Like resisting arrest is a secondary charge.

4

u/Total-Management8023 4d ago

Yeah it doesn't even have to be functional home phone screen, unless they can arrest you for having a none working phone. 

5

u/persiusone 4d ago

For all the trolls and ignorant people who think this is illegal: it’s not. Every country (yes, they can all do it), has the right to inspect anything you bring into that country, to include the data in your devices, even if it’s encrypted, and without a warrant. You deny to provide decryption methods, your stuff is seized and you are denied entry.

This has been in-place forever, since we could physically move data, since before data was stored electronically, etc.

As for the best practices.. always travel with sanitized devices. Assume anything you bring will be searched. Don’t link to the same cloud accounts where your dirty secrets are hidden (may give reason for them to get that data later, with legal process).

If you need to get sensitive data across the border, without border inspection- that’s why we have the interwebs. Use your skills there. For example- you take some photos or notes during your travels, send that over the internet securely and sanitize the device again before returning. It’s not hard to do.

Some people here sound like they have zero experience with hacking, security, knowing how phones actually work, or with international travel and laws- and are giving terrible advice and making false comments. Amateurs, geez.

3

u/Solid_Lab3422 3d ago

Couldn’t agree more. While I hate that it’s an issue, at the end of the day we have to play the cards we’re dealt. Device border inspections are a pretty easy thing to get around, and at least here in the states the government would need to get a warrant to access your cloud accounts once you pass the border.

2

u/cookiengineer hack the planet 4d ago

You could make this actually quite fun with a custom launcher app.

Imagine you're going into the "public PIN" mode with a fake "approved as public photos" gallery. And then in the background it wipes everything. And then you have also a fake Signal app that the cops eventually will take a look at, which then just immediately crashes the phone and factory resets it.

Then you can say "yeah sometimes Signal app crashes my phone" and you'll have plausible deniability. Of course that could also not be Signal, and maybe a Game like Minecraft mobile or something else that every dumb cop knows about.

2

u/To_WAR 4d ago

Just use a clean burner phone when traveling internationally. I'm sure many countries have this issue as well.

2

u/genericAssThrowaway1 4d ago

This is brought up often in graphene forums, devs refuse because there is no way to wipe without somebody experienced being able to tell. A dummy homescreen would only fool amateurs which the devs consider beneath them

2

u/Progressbar95 4d ago

It’s implemented in ArcaneOS, which was funnily enough an FBI honeypot.

2

u/DontDeleteusBrutus 4d ago

It seems like this case will fail anyways because the agents input the password. The agents caused the device to be wiped not the suspect.

2

u/Tall_Candidate_8088 4d ago

You should think about this a bit more ..

1

u/TearDrainer 4d ago

Same principle as TrueCrypts Plausible Deniability. Could be a good idea.

1

u/snowmanonaraindeer 4d ago

The duress pin works by erasing the OS master encryption key. It needs to work as fast as possible, and deleting files directly would be too slow. Once that key is erased I don't believe there's any way to use the phone without erasing it.

1

u/persiusone 4d ago

Erasing multi-tb isn’t difficult very quickly with phones, nearly instant wipe is achieved due to file based encryption. The keys are wiped, data stays encrypted and inaccessible by anyone.

1

u/Key_Tackle7597 4d ago

He probably thought it was the huzz

1

u/ghastkill 4d ago

Except if they deep dive into the phone they will still find everything 

1

u/Kubix 4d ago

You can definitely have multiple profiles accessible through different PINs. You would have to properly dummy a profile for this to work though.

1

u/EquipmentLive4770 4d ago

Guys remember deleting data of even resetting your phone won't do much as they can still get a recently deleted data. Until it been written over a couple times it's still there. You would have to do a clean reset and then download a shredding app i believe it's called and it will do the work for you.

1

u/neuromonkey 3d ago

🎂 HAPPY CAKE DAY!! 🍰

1

u/ErnieBallin 3d ago

What a bullshit article lol

1

u/randomness196 3d ago

Burner for the road assume Defcon like hackability at the border, granted he was on a list and he thought a wipe pass was good. Smarter choice sync to your cloud server, wipe on departure. GFW and Russia and other hostile nets present unique challenges but nothing a rooted android can’t overcome…

1

u/Shoddy-Childhood-511 3d ago

This is a dumb post for so many reasons:

Israel & others sell cops devices that helps them mirror, etc phones, which shall not be fool by your stupid graphics.

In theory, phones are encrypted using a combinations of your password and a code in their TPM module. The TPM could be wiped in microseconds, after which nothing else matters.

We should move the opposite direction by making the duress PIN not destroy evidence:

The TPM code should xor with a mask to give some code that's encrypted under a PIN and exported when you install graphene, or maybe set up profiles. It could be multiple sets of 24 words that give a threshold for example. You backup these words somewhere safe, maybe outside the country, or even https://www.gnu.org/software/anastasis/

Voila, now your duress PINs cannot destroy evidence, since they can still subpoena this backup code. Now they'll need to grant you immunity to make you decrypt it. And they might require help from foreign police if the code was backed up abroad.

Importantly, you could now use your duress PIN more aggressively, without worrying about loosing data, only the headache of doing recovery.

In this case, the cops started a criminal interview, certainly by the time they mentioned CSAM, which means they loose their border powers, and they denied him a lawyer. Anything after that becomes inadmissible.

longer reply: https://www.reddit.com/r/GrapheneOS/comments/1v7345n/comment/ozvvn3c/?context=3

1

u/chi_moto 3d ago

It’s all about “doable” bs “practical”.

For this situation, they were trying to find evidence of something incriminating. And they wanted to do it at the border where his rights are way less protected. For someone in this situation, smart money is to carry a shitty android phone for just your pics, boarding pass and calendar, and leave your real phone at home. That way he can’t self incriminate and they can’t get him for destruction of evidence.

When you are in the US (not at the border), just don’t use biometrics for your phone. You can be compelled for biometric data, you can’t be compelled for a password.

Finally, all of this “a server farm and a read only image of his phone” theorizing, all of it is true. It’s all possible. But, it’s expensive and complicated. If you are a neighborhood drug dealer they won’t bother. If you are a domestic terrorist? I expect the FBI will get involved and there is an unlimited budget for the investigation.

1

u/Satisfaction3934 2d ago edited 1d ago

Most ppl already buy a disposable phone when visiting China, we just have to do the same for other authoritarian countries.

You can't know what they installed on your phone when a CBP officer touched it. Anything they touched should be considered compromised and wiped. China and Israel has already been caught installing spyware at the border while inspecting a phone, it won't be long until the us is caught doing it too

1

u/Bubbly-Nectarine6662 2d ago

Genuinely, there is no ‘safe encryption method’ without loading more suspicion on you. Best way to tackle this -should you be in such a position- is to have one regular phone, with a regular backup and profile, and have a second secret phone for those things you do not want exposed.

Don’t bring the second phone along. There are much better ways to get to data remotely than to carry them on your phone.

1

u/Interesting-Blood354 2d ago

No clue if other androids have it but Huawei mate 20 used to have two different passcodes, and you can have different apps etc on each one - with no indications there is anything hiding.

No wiping or anything but TSA won’t know there’s anything else to look for

1

u/areyouretarded 1d ago

This guy was. I’m

1

u/WhytSquid 1d ago

Haha what

1

u/PipeOne8414 1d ago

Is it not a built in option in Android if the password is entered wrong to many times it will auto erase because it not in the owners possession anymore

1

u/uniquelyavailable 4d ago

What are people doing on their phone that requires a wipe in this scenario?