The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that.
The end result (not inherently different from what we wrote in the guide) is that you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to. I was fascinated by techniques for being unable to comply (which is straightforward to achieve if you want!) but probably didn't think enough about how much this might antagonize border agents in many cases.
I definitely don't know a comprehensive big-picture solution.
U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did. Hell there could have been a third set of four numbers that were the nuclear launch codes. It’s not the fact that it was four numbers, it’s what you were trying to make happen when you typed them. Now of course whether they can prove what your intent was when you typed them is another matter, but generally a duress pin should be for when robbers are breaking into your house, and the government will be on your side, and not when the government will be against you.
If your threat model includes US state actors at the national border, then your security practices need to account for the confiscation of your device at that border without requiring you to willfully wipe the phone and (in the eyes of police and prosecutors) destroy evidence.
That means:
1. Don't travel with anything you can't afford to lose on device. This means setting up travel-specific password managers and hardware keys for a subset of your accounts that you absolutely need to access while abroad, and being prepared to reset those passwords and disable those hardware keys very quickly once home.
2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. Your secure setup must function without needing you to engage in those behaviors, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable.
3. Consult with a lawyer and review your security procedures from a legal standpoint. All of the above is technical and practical advice, not legal counsel and no substitute for it.
We Americans are fortunate to carry powerful passports and enjoy relatively easy international travel but, for better or worse, that velvet glove covers an iron fist we would be foolish to forget or ignore.
Something like this may need to become the standars over duress pins which should be treated as a fallback or more extreme alternative. Right now, A single choice to reasonably and rightfully protect your privacy reuslts in jail time over something which likely wouldnt have resulted in any issues if superficial compliance was observed.
These goons, even if a branch of a facist regime, are ultimately burocrats with violent options to settle. They aren't doing forensics on your device etc. They have neither means nor knowledge to do so. They just need to tick their boxes. Did the phone unlock? tick. Did our spyware complain? no? tick. Overall appearance of compliance from person? yes? tick. free to go, next!
You just have to find ways to stay safe without agitating their workflow and all is well.
- [1] https://veracrypt.io/en/VeraCrypt%20Hidden%20Operating%20Sys...
Here is the statute Tunick is indicted under: https://www.law.cornell.edu/uscode/text/18/2232
There is an immediate problem: the device was being searched, and this statute criminalizes destruction of property to prevent seizure, not searches. I don't think this statute applies this situation. Regardless of whether the border agents could lawfully search his phone at the border, they didn't have grounds to seize it. I suspect this prosecution will quietly be dismissed within a few months.
You’re just carrying a blank phone that you intend to set up and use later, and they can’t force you to install your backup onto a phone.
Now, this is sus as hell, and you’ll probably draw all kinds of extra attention, but if border security wants access to your phone in the first place, you’re already in a weird place.
Of course it’s about that huh. It’s quite scary how far the US will go against anyone who engages in this sort of activism.
So there’s a feature called Duress PIN which as explained through some comments means you put a different pin which intentionally wipes the phone. It’s not auto wipe or wipe after several failed attempts but intentional wipe of device. (Worth explanation as the current title nor the article doesn't easily explain this was made by the US citizen providing the alternative passcode)
For more technical details:
> GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).
Whether authoring such a feature is itself a criminal act is an outrageous question, to which the answer should be an obvious, and emphatic "no".
> It's concerning – and sends the message that [GrapheneOS] is criminal by default
What's with this sensationalism? The GrapheneOS phone didn't just wipe itself - the defendant actively took steps to wipe it. The defendant isn't being prosecuted "by default" for having a GrapheneOS phone. He is being prosecuted for what he actively chose to do with that phone.
If your argument is that the search and seizure was unconstitutional, and you're within your rights to wipe your data, then argue that. I'm very sympathetic to such arguments. But stop with this "they prosecuted me for having a GrapheneOS phone" misdirect
Most previous court cases involving encrypted devices have required substantial proof that the encrypted device contained incriminating evidence. To be clear "you sent this illegal thing from your house" levels of evidence.
It mostly seems inept, if you are going to push to expand your powers you do it on strong cases where you know what happened. Doing it on weak cases like this gives a judge an opportunity to shut down that without giving you a chance of a meaningful conviction and without that you won't get any benefits...
This is practically the only thing I care about here and there are almost no details. What was his alleged involvement? How many others were targeted?
If you don't trust a government, ensure you aren't carrying any information you don't want to give up before entering their borders where you will be under their power.
> "the screen went blank, flashed several times, and the phone appeared to restart,"
How about flash some red lights and play an airhorn sound effect, too.
WTF.
Instead, I would set a timer before going through customs and if I don't unlock my phone and disable it within a set time, it initiates a wipe. I think that would be a safer way of doing this than a duress PIN.
Small inconvenience for me, but better than dealing with bullies.
This is like saying it's my car's fault if I decided to drive onto the sidewalk or something.
>It's possible to make a semi-hidden feature but hiding it well enough to avoid detection by software forensic tools requires not basing it around profiles. It would really need to be a nested GrapheneOS in a virtual machine. It could also still be detected at an SSD level
https://nitter.net/GrapheneOS/status/2081471477174456340#m
Here's some info from veracrypt on the SSD level.
The money comes out, but the cops show up.
>Experts said the legal approach is unusual and may be the first time the law has been aimed at an operating system. "It's concerning – and sends the message that [GrapheneOS] is criminal by default," said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.
Is the actual case about banning the OS? Because it seems pretty clear the case is about the result (the phone being wiped with a special passcode).
The better defense imo would be one of those 'wipe the phone if you get the password wrong x times' and try and claim you forgot under pressure. At least if you wanted to wipe the phone without being accused of destroying evidence during a search.
I strongly disagree with the border search exception and would like to see it drastically limited or abolished.
It is also something that has clearly existed in caselaw for decades (arguably for centuries) and that the courts have routinely (to my regret) strongly reaffirmed.
The border search doctrine says that border agents do not need a reason to examine you or your possessions when you are entering the country. They do not need to believe that you are doing something wrong or committing a crime. If they suspect you, they don't need proof or a good reason to investigate you.
I find this doctrine very disturbing and I hope it will be changed or narrowed. I also would like people commenting in this thread to understand that border agents are not just imagining things when they claim to have legal authority to inspect people (or, alas, electronic devices or data) at the border, and that this didn't just start under the Trump administration or something.
The legal consequences of providing a duress PIN may not have been tested and this defendant could well prevail in this case. I just wish people commenting here would understand that there is a tremendous amount of history related to border search authority. You can disagree with it (I hope you will!), but you should understand that it's not just something that someone just made up last week or last month or last year.
On the duress pin, they say (read the whole thing though):
> People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device.
The powers of investigators special rights and abilities rely on them being used very rarely. Last thing the terrorism investigators want is media coverage exposing their tactics.
This is the kind of thing that loses cases, even if they were legitimate at first. Seems like the prosecutor is desperate charging for the phone wipe cause they didn't have any evidence of terrorism, child-pornography, etc. The problem they have now is given he was in custody and agents pressured him to provide the passcode that they then incompetently put into the phone, the fact that they denied him a lawyer multiple times means there is a very strong argument that his rights were violated. Typically, courts suppress any evidence when there is a violation like this with someone in custody. So the compelled passcode, the phone's reaction when that passcode was entered, and the agents' testimony describing the supposed wipe would be thrown out by most judges. What's left for the prosecution after this is jack and shit, but jack left town.
Not sure why the police and news are saying that he destroyed evidence, since the evidence (as it always has existed before the search began) remains on the disk.
> According to court testimony, federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City.
I didn't know about Cop City, but I found this on Wiki: https://en.wikipedia.org/wiki/Cop_CityThis part is interesting to me:
> RICO conspiracy indictment
> In September 2023, sixty-one people who had been arrested in the forest or at stop cop city protests were charged with racketeering under Georgia’s RICO law. This indictment is likely the largest criminal conspiracy case ever filed against protestors in the US.
> As of April 2025, the racketeering case was stalled. Defendants in the case maintained their innocence and reported difficulty getting work and other hardships while they awaited trial for more than 20 months. In September, all RICO charges were dropped. Judge Kevin Farmer found that the Georgia Attorney General did not have the authority to bring RICO charges in the case.
From my outside view, it looks like these investigations are nothing more than an attempt to suppress free speech and protests.For anyone unaware, RICO is both a Federal law and a Georgia state law that stands for: "Racketeer Influenced and Corrupt Organizations". It is used to take down mafia, gangs, organized crime, etc. It is a bit sad to see state prosecutors trying to use this against protesters.
If Customs already knew whether the suspect had incriminating files on his/her phone things might be different.
Anyone know if this is a viable strategy on iOS, and what the required pin-length is these days?
Before entering the airport you set your device to auto-wipe after x hours.
Once you are sitting in the airplane and flying, you cancel the scheduled automatic wipe.
If he had simply refused to provide the unlock PIN, he would have walked away. They may have kept his phone, but they would never have got anything from it anyway.
I'm confused to understand if Tunick did anything illegal here. If the authorities want the phone, they should have the warrant and seize it without Tunick's permission.
It appears authorities did not have the warrant which give Tunick all the right to do whatever he desires with his property.
What am I missing here?
The reason is because anyone running an os with a duress PIN that has done nothing wrong can be accused of using a duress PIN because the whole point of the duress PIN is that it looks like you just have a normal phone.
Running a normal apple operating system with just stock apps? Boom, you're a criminal because you obviously used a duress PIN and have something to hide! There is no way to prove you didn't use a duress PIN because the phone was "wiped."
Now unfortunately grapheneos probably leaks information so that a duress "unlock" can be differentiated from a standard unlock by some means. If not then kudos. It looks like it is done instantly by keeping everything encrypted and just zapping the keys, but it also needs to actually unlock to something instead of rebooting to prevent leaking the information that a duress pin was used. Not sure how fiesable that would be though.
In the old TrueCrypt containers you could set an optional second password that would decrypt a different volume. The size of the container file was always the same, a decrypted volume always showed the full container size, the portion not occupied by the data in the main volume was filled with noise, and the data on the non-loaded volume was not protected (so you could erase it without warning by storing too much on the loaded volume), making it practically impossible to prove the existence of a second volume either way in a search situation. I guess there was a reason why the project was stopped.
Instead of wiping it clean, wipe to innocuous mode. Then the burden on their part is not only to show that I gave a bad pun, but that the innocuous mode is materially different than the previous state.
Of course TSA agents become angry when they enter the PIN and see a message "wiping device".
So yes, we've created an authoritarian hellhole, but the alternative is even MORE unthinkable: struggling to pay for parking in some areas, needing to visit a website for a menu or (GASP) visiting a different restaurant, or just having a friend order for you.
No, these are too much to ask of anyone. No one can overcome these challenges. The only answer is to weep for the liberty that we have lost.
If it were a box of drugs and he triggers an incendiary device - he's in trouble . If agents trip a protective boobie trap and destroy the box- he is fine.
Don't know why but this feels correct to me.
1. What happens if the masses just do this? Today it's just a few folks who know how to do this. Tomorrow it could be 10, a year later 100. What's to stop 1000s from doing this and then what is the government going to do? Ban the OS and block it on Github?
2. What exactly happens after you're charged? This doesn't mean the person is convicted. Just that they now have to show up to court wherever the trial is held and have to retain their own lawyer (or public defender?). And what is the likelihood that the case is thrown out or the person is convicted and receives a stiff penalty?
I ask these questions because as far as I can tell, the person was not suspected or convicted of anything, and it's infuriating me that we are just going to stop random citizens and ask for their private data.
#1. The download and restore backup method would work- except it doesn't capture what people would need. Exmaple: I have some thermal cameras that rely on old 32 bit apps that do not run on anything android 12 onwards- If i wipe those old phones, and restore- the apps often wanted to reach out to a server for initial activation- they would fail upon reinstall and i'd be out of the apps that are required to control my cameras and related equipment,which is worth thousands and thousands and thousands. And it'd be all dead weight and rendered useless.
(and competitors today do not compete- for example try finding a 640*480 30 hz or better form factor thermal camera that attaches to phones - they dont exist anymore)
\The solution is imaging- but there isnt a way to fully image phones and restore backups today. There used to be it seems- but not really with the latest.
Veracrypt- The weakness of truecrypt and veracrypt, the hidden OS option only worked if you converted your computer to MBR, which means you can't have a hard drive too large. Making a UEFI hidden OS has not been done yet.
I am aware of Shufflecake attempting to make a solution.
And the Hidden Volume option- isn't 'as' useful, and of course, your OS might make a copy and put it somewhere, you have to be careful. Any time I open a file, using the software tool Everything to search and confirm this- you can easily see Windows makes copies and temp files and whatnot in randomly named locations- that's the sort of behavior that would screw people over
We need fully image-backup capable Phones. I mean fully. Not just backing up some apps- as this refuses to backup apps you have that are no longer on app stores, or that Play Protect doesn't like, etc.
Next- Plausible deniability is a way forward- but you need multiple profiles, that are cryptographically indistinguishable, along with the phone being hardened so GreyKey /Cellebrite won't be able to exploit a way in. This needs to be built this way from the ground up ideally, eventually.
There has been research about making devices that treat all block space the same way so you can't tell if someone has 1, or 50 profiles or partitions, etc- and even stuff that overlaps. But nothing has come out - and especially, for phones.
After all, if you travel to a hostile country, you can tell them you have just one profile, and if they ask, you could theoretically mention a 2nd, and then show it- but you might have 3 more - and they'd all be immune to forensic inspection if the system is built right.(Yes, there's often issues you have to be careful of ,like setting this up so you dont destroy data when in other profiles,)
This is how you solve this problem -make computing devices impossible to analyze
Even if the accelerated executive capture of the judiciary is largely ruled back post Trump (big IF), I fear the government will be unwilling to pay with much of the convenience of rule-by-law that it's been given a taste for.
I think the issue is that people expect the USA to be the "land of freedom" when it's not anymore. It's turning more and more into an oligarchy and we are at the point where it's just as bad as russia or china.
If i was offered a trip to China or russia, i'd go but i would take a burner phone with absolutely nothing important; It's the same for the usa now.
It's his device, so he can do everything he wants to. The USA is currently re-purposing constitutional protections. A judge has not signed these warrantless seizures, so why would the individual be under any obligation to cooperate? Besides, why would anyone want to incriminate oneself? The onus would be on the state to prove a guilty state.
smuggling endangered species? bad. okay search a suitcase.
having unrestricted access to all my gmails because i need to catch a plane? absolutely unacceptable.
having your phone autowipe when pressed by authority? quit whatever nefarious shit you're doing, thanks
In the Age of LLMs we could generate a fake digital existence as fast as we can delete a real one.
The goal is to appear like you complying without any evidence you are not. Graphene — build this feature!
The criminalization of activism (domestic terrorism, really?) does not bode well for freedom of Americans.
https://prismreports.org/2023/06/07/escalating-tactics-again...
https://arstechnica.com/tech-policy/2020/02/man-who-refused-...
Or better, have PIN for taking you to your criminal/secret profile instead.
Nope, in the US.
I really don't like this title. Officers asked him to open the phone, which he pretended to do, but instead wiped the device
> During the questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused. When he finally provided a passcode, the phone appeared to restart. The defense motion states that "the screen went blank, flashed several times, and the phone appeared to restart," resulting in the loss of data.
The title implies the agents maybe entered too many pins by mistake and the device auto-wiped, or that it reset itself with no human intervention, which isn't what happened. This is more like shredding paper when the FBI arrives at your office, which most people would attribute to destroying evidence. I hope he wins the case in principle (I think there's a risk of a slippery slope here) but it wouldn't be a moral tragedy if he lost.
feds: "unlock your phone or else" victim: "um, you're stressing me man. It's either 1234 or 4321, I forget. One of them wipes the phone, the other will unlock it."
Whichever PIN they try, it wipes the phone, but the feds can't claim it was deceitful, just unlucky.
Tsk, amateur hour. I thought it's been decades since disk encryption software had two-password functionality that provided plausible deniability by booting into an alternative, clean OS. Impossible to prove intent to deceive.
How disappointing to see such a naive phone wipe functionality, it's so obvious even non-technical people could probably tell what happened. Smh. It can't be that hard to design something at least a little better.
If so, "normal" police would not have the "keys". This would be "the compromise".
www.github.com/jegly/box
In all cases just don't cross security checks with evidence you wouldn't want to be seized, its not that hard