cross-posted from: https://lemmy.world/post/49853131

Feels to me like GrapheneOS did exactly what it should, passing the US border test with flying colours!

Funny part about this lawsuit: “With a little planning ahead of time, you can always download the data you need once you get to where you’re going,”

  • Robert_White@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 天前

    You guys already spotted the hole in the burner plan. A clean phone and a wiped phone look identical from the other side of the desk, and both look like someone who planned ahead.

    A burner only works if it’s lived-in instead of clean. Real accounts, months of boring messages, photos of nothing in particular. That’s a lot more effort than grabbing a spare handset the week before you fly, which is why hardly anyone does it properly.

    Same idea with less upkeep: keep one genuinely lived-in phone and put the sensitive half behind a second PIN, stored so you can’t show it’s there. Then the thing you hand over isn’t a prop, it’s just your phone.

    (I work on DeniableOS, which is that. Changes nothing about what CBP is allowed to do to you, and I’m not a lawyer.)

      • slumdogego@slrpnk.net
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        6 天前

        Imagine being on a de-federated instance like lemmy and crying about how a COP in AMERICA could not harass a person successfully.Go back to meta choom.

      • zalgotext@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        12
        ·
        6 天前

        So are you saying you’d be ok with your personal property being searched without a warrant on the suspicion that you might own child porn?

      • Virtvirt588@lemmy.world
        link
        fedilink
        English
        arrow-up
        13
        arrow-down
        1
        ·
        edit-2
        6 天前

        What if you owned: weed/drugs, illegal firearms, items which could be used for potential murder, negative opinions about the fascist government?

        This argument is shallow to the point where fascism is what you’re advocating here for. So what, if you did own something thats not law abiding - without any credible proof there is nothing there, and non of anybody’s interest.

      • tinfoilhat@lemmy.ml
        link
        fedilink
        English
        arrow-up
        7
        ·
        6 天前

        What if I am a law abiding citizen? Should I relinquish my rights against unwarranted search and seizure because of ‘woulda coulda shoulda’?

        If your rights can so easily be ignored due to some hypothetical scenario, then you never really had rights to begin with.

      • slumdogego@slrpnk.net
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        1
        ·
        6 天前

        ??? classic statistic apologist rhetoric I’m not against holding pedos accountable, I’m against searching a man/woman/non binary’s phone without proving suspicion of OWNing child pornography… please educate yourself

      • yuki_gassen@lemmy.ml
        link
        fedilink
        English
        arrow-up
        7
        ·
        6 天前

        Privacy isn’t keeping everything about your life secret from everybody. Its about having control over who in your life gets to know what. Its the pretext for honest communication. Extreme surveillance will lead to people self-censoring themselves to please the fascist state.

  • Archr@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    ·
    6 天前

    This whole situation is making me strongly consider bringing a burner phone on my next vacation. That way I can wipe it before going through customs.

    • Hubi@feddit.org
      link
      fedilink
      English
      arrow-up
      10
      ·
      6 天前

      I did something similar when I last visited the US ~15 years ago. I uploaded an encrypted backup of my phone to a server in my home country and reset the device. I then downloaded and restored the backup when I arrived at the hotel.

  • badbytes@lemmy.world
    link
    fedilink
    English
    arrow-up
    31
    ·
    7 天前

    Would be cool to have your device partitioned by separate passwords, so you could unlock a dummy system.

    • Robert_White@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 天前

      That exists. The thing to watch is the difference between separate profiles and a hidden one.

      Graphene gives you multiple profiles with their own passwords, but profiles are enumerable. Anyone poking at the device sees that profile 2 is there, so “open that one too” is the obvious next sentence.

      The version you’re describing works when the second environment can’t be shown to exist at all, so it reads as encrypted random noise, which is what empty encrypted space looks like anyway. One PIN gets you a full boring phone, the other gets you your real one.

      Only holds up if the boring phone is actually convincing though. Six apps and no photos fails on the spot.

      (I work on DeniableOS, which does the hidden version, so weigh that how you like.)

    • mazzilius_marsti@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      ·
      7 天前

      yes you can. On Graphene you can set the main profile as just there with nothing except to control wifi/add esim/etc. Then you can create many profiles with their own passwords. You can store your work stuff in 1 profile, private stuff in another. You can even create a dummy profile with fake Google. .

      The downside currently is that the OS autoboot to main profile. Then you switch to your other profiles.

      • Robert_White@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 天前

        Good writeup, and the downside you flagged is the interesting bit. Profiles are enumerable. A dummy profile survives a glance at the screen and stops working the second someone can see profile 2 exists and asks you to open it.

        The property you want on top of your setup is that the second thing can’t be shown to exist at all, so it looks like random noise rather than a locked door. Then the dummy isn’t a dummy, it’s just the phone.

        (I work on DeniableOS, which is built around that. Your profile setup is still the right free answer for most people and I wouldn’t talk anyone out of it.)

  • mazzilius_marsti@lemmy.world
    link
    fedilink
    English
    arrow-up
    24
    arrow-down
    1
    ·
    7 天前

    GrapheneOS - the only OS that i just installed and forget about it. Sure i spend time to tweak things like profiles but thats it.

    And I am a distro and rom hopper.

    The security model is that good: duress pin, scrambled pin, separate profiles with their own passwords, usb c restriction (you can set it charge only, charge while phone is off (most secure state).

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      9
      ·
      7 天前

      and yet people even here don’t understand why it would be useful even without the hardware security thinhs of the pixel

      • BigTwerp@feddit.uk
        link
        fedilink
        English
        arrow-up
        15
        arrow-down
        1
        ·
        6 天前

        You can only install Graphene on a Google phone and there’s two big issues with that:

        1. you are rewarding Google by buying their hardware.
        2. it doesn’t matter how secure the os claims to be if the hardware is compromised and there is nothing you can do to convince me that a pixel doesn’t have a backdoor into your data at a hardware level. If I was a conspiracy minded type I might say that Graphene is a Trojan Horse.
  • spitfire@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    1
    ·
    6 天前

    „I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.” Wow that’s an advice fitting entering Russia, Iran, etc. Nice club you’ve joined here

  • spitfire@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    6 天前

    „unlawful to knowingly destroy or damage property to prevent authorities from seizing it” - but did it fucking explode, catch on fire, or blew some fuse on the phone or in any other way prevented it from working? No, they (not him) just wiped the data. I didn’t know deleting files off YOUR OWN DEVICE is a crime. I need to think twice before I empty trash on my computer next time.

  • flop_leash_973@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    1
    ·
    7 天前

    He would have had a lot better legal leg to stand on I think if he had just refused to give them any passcode. Now instead of a potential case of being forced to compel speech, he is facing what will be argued is an attempt to destroy evidence. His defense is probably a lot stronger with the former than the latter.

      • mechoman444@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        7 天前

        No they would have to prove that what was on his phone was evidence in the first place. Which is why arrest and search warrants list all kinds of potential evidence and if it isn’t listed in the warrant they can’t collect or use it against you.

        I’m not exactly sure how this works during a border patrol search. It’s technically his phone and if it’s locked they would need his permission or a warrant to search it.

    • TORFdot0@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      6 天前

      Does it count as destroying evidence if they don’t have a warrant for it? I can destroy whatever device or document I want. It’s my property

  • billwashere@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    7 天前

    That’s it. I’m getting a burner phone if I leave the country.

    Edit: Serious question… what if you just wiped your phone and then restored it when you got wherever you were going?

    • Shortstack@reddthat.com
      link
      fedilink
      English
      arrow-up
      9
      ·
      7 天前

      Honestly I’m not considering leaving at all while this administration is in power. We’ve already heard too many stories of arbitrary detentions even for lawful citizens or visitors that I simply don’t want to roll the dice on whether my vacation ends with a nightmare or just another flight in as normal

    • JcbAzPx@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 天前

      Given that the state of this guy’s phone would look the same as a burner phone, I’m not sure how that will work out.

  • fearlessseraphim@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    ·
    6 天前

    I just heard about this yesterday and it’s very interesting and fascinating to me, how the duress PIN worked if a situation like this arose. I cannot think that GrapheneOS team for implementing such a feature. Lowkey want the team’s input on this. 🥰

  • jas [they/any]@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    166
    arrow-down
    1
    ·
    8 天前

    this was a streisand effect for me because i didn’t have duress password set up on my grapheneos phone (security & privacy => device unlock) before but i do now! :D

      • volore@scribe.disroot.org
        link
        fedilink
        English
        arrow-up
        47
        ·
        8 天前

        I imagine the best duress PIN is something you’d actually see a “normal” person set as a PIN, like their birth year or something innocuous and easy to remember (and easily believed by whoever’s demanding your PIN), while their real PIN would be longer or more abstract.

        • Pika@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          19
          ·
          7 天前

          Honestly I would use a stupid basic one that someone might try and use if they were guessing. Like a duress pin of 1-1-1-1, 1-2-3-4 or 2-4-6-8. It gets the people who take the device and then try and break into it without your permission as it’s almost certain they will at least try one of those three.

          Worst case scenario they ask you and you say what it is and they give you a blank stare of “really?..” it’s not like they wouldn’t try a pin you gave them.

          • obvs@lemmy.world
            link
            fedilink
            English
            arrow-up
            24
            ·
            7 天前

            I don’t recommend a duress password of 1-1-1-1, because that could be set off accidentally.

              • Pika@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                3
                ·
                6 天前

                that’s sort of the point of it being super basic. The intent is you want it to be tried before they somehow manage to get your actual pin, or give up and try to force you to provide it.

                if they put the pin in before you tell them a pin the argument for destroying evidence is weakened heavily as it isn’t a you initiated thing.

            • Pika@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              6 天前

              that’s fair, I don’t know if graphene supports press enter to submit but, I usually have that setting enabled on my devices

        • ITGuyLevi@programming.dev
          link
          fedilink
          English
          arrow-up
          3
          ·
          7 天前

          Sounds dumb to give it out, but mine is my normal 8-digit pin, just backwards. It’s easy to remember and seems like a legitimate PIN.

    • obvs@lemmy.world
      link
      fedilink
      English
      arrow-up
      27
      arrow-down
      1
      ·
      7 天前

      On GrapheneOS, you can also set a “second factor PIN” in the unlock settings under “Fingerprint Unlock”, so that to unlock your screen you need to first use the fingerprint unlock and then separately enter your PIN. This means BOTH are required every time you unlock. Your phone can’t be unlocked unless it’s your finger AND unless you enter the PIN that only you know.

      And under the Screen Lock settings you can also enable “Scramble PIN input layout”, so that the number buttons on your unlock screen will be out of order, so people watching you or recording you can’t just make note of the shape your index finger is making when touching the numbers to unlock your phone(like people looking over your shoulder or recording on store security cameras).

      • Justifier@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        7 天前

        What I find foolish is there’s no pin only to unlock (no biometrics), but biometrics available when unlocked

        Plenty of my apps have biometric verification I’d love to take advantage of, but I don’t need or want one to unlock the phone itself

        • db_null@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          11
          arrow-down
          1
          ·
          7 天前

          But there is

          Settings > Security & Privacy > Device Unlock > Fingerprint and there you can toggle to use the fingerprint for device unlocking and/or verification in Apps