37 comments

[ 2.2 ms ] story [ 15.7 ms ] thread
yasss this is a feel good story they entered the pass themselves, so by their own treasonous logic, they should charge themselves. hope the crim charges get dismissed, and a civil suit is filed get paid, donate a chunk Go Team Graphene!!!!
Keep fighting the good fight GrapheneOS!
is it just me or is it about once a decade somebody gets publicised for this and the government *really* throws the book at them.
"defends" is doing quite a bit of flashy work for this headline. "Feature works as advertised, nobody upset" would be a much more practical headline.
The founding fathers would be aghast at what America became. Hard to imagine modern America passing some of those constitutional amendments that older America passed wayyy back.
Someone who is a lawyer knows any details about the US justice systems precedents with regards to the fifth amendmend (regards to self incrimination) vs obstruction of justice (by destroying evidence) as would be applicable to a duress wipe? Also would the distinction of being (or not) read their miranda rights and placed under arrest in this case make a difference as to the status of any possible obstruction?
This should be an interesting case in today’s legal climate

Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password.

How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password does a wipe based on location? Either way, the user complied, and did not take action to wipe their device.

The "agent entered password themselves, therefore they're to blame" seems as good of a logic as "I'm going to start swinging my arms and start walking forward, so if you don't move, it's YOU hitting YOURSELF".
And this is why part of my plans for any international travel are to simply have a physical notebook with phone numbers to trusted friends/family and to buy throwaway devices on the other side (phone and chromebook or similar).

TBF, similar mindset if I ever attend defcon, etc. as well.

The simpler option is to fly through a place with USA pre-clearance. At least in Canada you can revoke you application to enter the USA at any time when in pre-clearance, and there are very limited instances when you can be legally detained by CBP (mostly around being an immediate threat or the CBP officer has evidence that you broke a law such as attempted smuggling).

I currently fly to the USA through Canada and if CBP ever insists on seeing my phone I will revoke my application to enter and accept that Im most likely banned from entry for a while.

As a GrapheneOS user and a U.S. citizen that cares about the constitution, I fully support the actions taken by the individual
This is possibly the best advertising. GrapheneOS was kind of niche before. But if the US Government hates you then you're on the right track.
The border agents didn't act in good faith, regardless of what they're empowered to do. They wanted the data for one reason and fabricated another to prompt the device search. The data they were interested in pertained to protest activity protected under the constitution but the lie they told was about something criminal. That anything within 100 miles of the border is constitution free tosses that out, I guess, but is extremely problematic on its own.
Next version should wipe the phone while presenting a dummy account so they can't easily tell anything is missing.
(comment deleted)
Couldn’t GrapheneOS provide a special pin which boots into an “empty”session? Where the user can install some default stuff to not look suspicious?
(comment deleted)
This probably doesn't hold up legally, but it does hold up logically: if the reason a border search exemption exists is to prevent importation of material that is unlawful to import, wiping a storage device also fulfills that purpose.
No warrent? No data. Easy as.
The Fourth Amendment of the U.S. Constitution is supposed to protect people from random and arbitrary stops and searches. It's a fundamental American right. But in the 100 mile border zone, the federal government has tried to impinge on those basic rights. https://www.aclu.org/know-your-rights/border-zone
It's great publicity for GrapheneOS, has probably led to a huge spike in traffic to their website and downloads.

And ongoing publicity as the trial happens.

It is illegal to lie to a police officer in the US. It's better to remain silent than to tell a lie. Giving a false PIN is a lie. And that by itself is a crime.

I'm not taking sides here, I just wanted to make that clear.

And you should understand that they can lie to you. That's OK and legal, but you cannot lie to them.

There are limits to the lies they can tell, IIRC. They are limited to lies which would not harm an innocent person. So if an officer says "We have your fingerprints on the murder weapon", that is fine, because an innocent person will know that there is no way that can be true. Whereas a guilty person would presumably find that lie plausible.

But if an officer gets a confession by saying, "They just passed an amendment, and you don't have the right to a lawyer anymore, so you have to answer my question or I'll send you to a torture dungeon", that is a lie that can harm anyone, regardless of guilt.

any reason with graphine os to wipe vs power off? Unless you have an easy bfu password doesn't it protect you from multiple password attempts?
It uses hardware with a secure element only permitting 20 attempts. The past 5 unique attempts are rejected early out for usability.

We published a technical overview of how GrapheneOS protects against data extraction covering the major protections it adds:

https://discuss.grapheneos.org/d/40700-grapheneos-protection...

graphine os needs a feature to triple press the power button for an immediate power off.
If only these phones could have a feature where you can enter a mode to encrypt segments of data with different encryption keys, all able to be unlocked still by one single master encryption key that you could also enter at any time.

Then when in travel, and about to pass a border, you enter that selective mode. You can enter a different password as the proxy to unlock the phone in this bare minimal data mode. The agents can access it, etc but wont have all the data. That data shouldn't even be visible in the OS, and if they try to copy the hard drive they will get encrypted data in the other blocks.

You still legally comply with orders and unlock the phone but the other partitions don't unlock/decrypt unless you specifically unlock them.

This feature exists today – it's called "leave your gadgets at home". S3 bucket and / or laptop with Tails on USB stick is all you need.
if u read the grapheneos tweet about this, any form of minimal account puts all ur other accounts at risk. agents should never get any form of code execution on ur device, even from a sandbox account. the linux kernel is not secure, and they can just hold the device till the next public disclosure or use one of their existing cellebrite attacks.

duress password to shutdown instead of wipe could be an option.

duress password to restore to snapshot, effectively wiping all data after snapshot, is another option, as it would be hard to know what happened. all the now "free space" gets overwritten with prng.

when entering the duress password, maybe grapheneos needs to put some UI theatre, like saying battery low, shutting down... so the agents think the phone is just shutting down due to low battery.

another theatre could be a fake shutdown, that appears to not startup again... just wipe and kexec a fake kernel that just mimics a dead phone, till the batter actually dies. any attempts by the agents to charge the phone , is met with a fake boot and a charging error. This is just a phone with a bad battery, nothing to see here.

Please note that "search" does not mean agent just scrolling through your photos.

In Belarus, such "search" means plugging a USB cable and downloading everything from your phone AND connected clouds (Google Photos, iCloud etc). Then their software (bought for millions of dollars from a foreign security company) compares every single face in your photos/videos with every single face gov has in their database. And you don't have control of the downloaded data.