GrapheneOS says its data-wiping "duress" password is perfectly legal, after user faces federal charges

Would be interesting to see which part of the constitution they believe protects it.
4th amendment. Protection from unreasonable search and seizure. No warrant, no probable cause (returning from the Dominican Republic does not constitute probable cause for child molestation). Searching somebody because they participated in a protest (CopCity) based on possible 'CSAM' is the very definition of civil rights abuse.
 
My point is that the case lacks consistency. Either he didn't have 4th amendment rights because he wasn't in the US meaning the US can't charge him for a crime or he was on US soil requiring a warrant to search his phone. Either way, the strength of what he is charged with is in question
The Constitution defines a set of fundamental, inalienable, human rights. They are applicable universally, and are not subject to a specific jurisdiction. Another country may not respect them, but any American authority must. As an American citizen you are also bound by certain fundamental laws Internationally, regardless of local law. These include taking and receiving bribes, child molestation, etc....... The court of pertinent jurisdiction is a seprate and distinct matter.
 
The Constitution defines a set of fundamental, inalienable, human rights. They are applicable universally, and are not subject to a specific jurisdiction. Another country may not respect them, but any American authority must. As an American citizen you are also bound by certain fundamental laws Internationally, regardless of local law. These include taking and receiving bribes, child molestation, etc....... The court of pertinent jurisdiction is a seprate and distinct matter.
Yes that makes sense, but how does that apply to the case? What I'm suggesting is it seems more like they charged him with a crime to cover their *** rather than him actually commiting a crime
 
The basic fact of the matter is that if you are within 100 air miles of an international border with the US or at an international port of call (Atlanta airport qualifies), authorities claim very broad rights of seaarch and seizure. They generally have the right to non-invasive searches (your bag, not your orifices) and further secondary screenings if they have probable cause.

They CANNOT demand that you unlock your phone, and you do not have an obligation to comply with them, BUT in the event of non-compliance they can escalate screenings, delay you substantially, seize your possessions (including your phone) for forensic analysis, etc.... HOWEVER, ultimately they have to prove that you did something illegal in the pertinent jurisdiction where the illegality was committed.

Essentially, this is a blatant attempt by the specific authorities to create a precedent that makes withholding access, asserting your right to privacy, or erasing your data a criminal offense. This is not the case, but they are trying to push their self serving and very specific interpretation into policy at the very least.

To WIT, you have every right to delete your data, it's yours. They have to prove that you deleted evidence for a charge of illegality, which also requires a specific crime,specific charges, paperwork, probable cause, etc.....Their assertion is that the very acts of protecting your privacy and asserting your rights are illegal. Which is, of course, completely ridiculous. Fascists, fascists, everywhere.....
 
...A "Private Diary" Standard: The Supreme Court has recognized the vast amount of personal information on a smartphone, effectively treating it as a "private diary" that is off-limits to warrantless police searches.
Once again: none of this applies at the US border, where even a "private diary" is open to warrantless search by border agents. It takes literally five seconds to confirm that SCOTUS rulings like Riley v. California and Chatrie v. United States don't apply at the border.

I think people over 100y ago wrote the border search law to search pockets and bags. They could not imagine a world where a small block of glass carry our intimate lives from child birth to death.
On the contrary, those people lived in a world where immigrants regularly entered the country carrying the sum totality of their intimate lives: all letters and correspondence, documents, and other personal effects, along with everything else they owned in life.

Still, if you believe the world has changed sufficiently, then advocate for it to be changed by Congress -- don't pretend it doesn't exist.

Essentially, this is a blatant attempt by the specific authorities to create a precedent that makes withholding access, asserting your right to privacy, or erasing your data a criminal offense
What nonsense is this? Precedent exists already for all of this, including and specifically that erasing data requested by law enforcement is destruction of evidence. Why deny reality?

To WIT, you have every right to delete your data, it's yours. They have to prove that you deleted evidence for a charge of illegality.
This isn't even remotely correct. Resources that prove you wrong are literally one click away on the Internet...why not at least attempt to use them?
 
I think the US DOJ is being ridiculous. They do not have the right to force anyone to share what data is on their phone. Ever. The people have a right to privacy. It's a protected right.

I'm glad that GrapheneOS stands behind this privacy feature. This isn't China. This is the land of the damn free.
 
Once again, there needs to be a duress password that presents a stock/near stock image of the OS to the user (including showing empty storage etc).

If such a feature had existed, this gentleman wouldn't be in the pickle he is in.

Always an arms race between those who crave security and those that crave privacy.
 
Once again, there needs to be a duress password that presents a stock/near stock image of the OS to the user (including showing empty storage etc).
There is - and he tricked the agents detaining him into using it.
If such a feature had existed, this gentleman wouldn't be in the pickle he is in.
No - that’s actually the pickle he IS in.
Always an arms race between those who crave security and those that crave privacy.
Perhaps - but that has nothing to do with this case.
 
There is - and he tricked the agents detaining him into using it.

No - that’s actually the pickle he IS in.

Perhaps - but that has nothing to do with this case.

- My understanding is he used a duress password that wiped his phone, and the *wiped his phone* is the legal pickle that he is in. That is not what I am suggesting.

I am suggesting that there is a password that present a clean OS (for example an early image of the OS where it is still slightly customized but without access to all the data on the phone) without wiping anything.

Presumably the fact that the phone was in a complete factory reset status after entering the password tipped off CBP that they'd been had. The idea is for the phone to come up in a presentable "dummy" state that wouldn't immediately suggest to the end user that a duress password had been used.
 
Ou are legally and officially on U.S. soil when you step off the plane onto U.S. territory, but you are not legally admitted into the United States until you pass through U.S. Customs and Border Protection (CBP).Physical Arrival vs. Legal EntryPhysical Touchdown: The moment the wheels touch the ground or the aircraft door opens at a U.S. airport, you are physically on U.S. territory.Immigration Control: You must follow signs to passport control and immigration.Customs Clearance: After passing the CBP officer and collecting your bags, you officially enter the country.The Preclearance ExceptionForeign Soil: If you fly out of a foreign airport with a CBP Preclearance program (such as in Canada, Ireland, or the UAE), you actually clear U.S. immigration and customs before you board the plane.Domestic Arrival: In this case, you are already legally admitted before takeoff, and your flight lands at a domestic gate in the U.S. as if it were a local flight.If you have a specific flight path in mind, tell me your departure airport and arrival airport so I can let you know exactly when and where your check point will happen.

google search : in a us international airport when are you on us soil
 
Now this gets interesting ::

At international airports entering the United States, U.S. Customs and Border Protection (CBP) has broad legal authority to search a traveler's phone without a warrant, including basic manual reviews, advanced data copying, and temporary device confiscation.Search Types and RulesBasic Search: Officers can manually look through the files, photos, texts, and logs stored locally on your phone without any individual suspicion or a warrant.Advanced Search: Officers can connect your device to external equipment to review or copy data, but this requires reasonable suspicion of a violation or a national security concern.Cloud Limits: Officers are restricted to searching information physically present on the device at the time of inspection and are generally not allowed to intentionally browse remote cloud data.

++++++++++++++++++++++++++++++++++
Rights and Refusal Passwords: You are not legally required to give officers your password or unlock your phone. Consequences of Refusal: If you refuse to unlock your device, CBP can seize and confiscate your phone for days or weeks to inspect it.
++++++++++++++++++++++++++++++++
Citizenship Status: U.S. citizens cannot be denied entry into the country for refusing to unlock a phone
+++++++++++++++++++++++++++++++
though entry can be significantly delayed. Non-citizen visa holders, tourists, and permanent residents may face denied entry or visa revocation if they refuse a cooperative search.If you would like, I can share tips on how to back up and protect your data or what to do if your device is seized at the airport.


google search : what are customs rights to search a phone in a international airport


result.

You DO NOT HAVE TO unlock your phone. but you wont get it back for a while

If they were detained and NOT arrested .. they can now sue for about 10 million dollars for violations of liberties.

lucky bastard... hes rich now with the right lawyer
 
Would be interesting to see which part of the constitution they believe protects it.
Well the 4th ammendment. The Fourth Amendment of the U.S. Constitution protects people from unreasonable searches and seizures by the government, requiring warrants to be based on probable cause and specific details. 1 they didnt have a warrant. 2 they never read him his Miranda rights. 3 They kept talking to him and questioning even after he asked for a lawyer multiple times. So overall they violated his constitutional rights. He had every right after that to defend himself from tyranny by wiping his phone.
 
- My understanding is he used a duress password that wiped his phone, and the *wiped his phone* is the legal pickle that he is in. That is not what I am suggesting.

I am suggesting that there is a password that present a clean OS (for example an early image of the OS where it is still slightly customized but without access to all the data on the phone) without wiping anything.
How dumb do you think the authorities are... even if it gets restored to a "clean OS", as long as the data is there, they will get it.

The duress password sets the phone back to stock - and permanently erases all data.
Presumably the fact that the phone was in a complete factory reset status after entering the password tipped off CBP that they'd been had. The idea is for the phone to come up in a presentable "dummy" state that wouldn't immediately suggest to the end user that a duress password had been used.
Lol - they knew they were had as soon as the password didn't unlock the phone! But at that point, there was nothing they could do as the wipe is instant and irreversible.
 
If they were detained and NOT arrested .. they can now sue for about 10 million dollars for violations of liberties.

lucky bastard... hes rich now with the right lawyer
Your Googling was correct up to this last point. Customs is freely able to stop you for a reasonable period -- courts have repeatedly ruled 4-6 hours -- without being required to charge or arrest you.
 
Would be interesting to see which part of the constitution they believe protects it.

Since you probably are not part of the tech world or the security world, I will break this down for you best I can. In the 1990's, the government tried to sue a group of hackers who published software for the sole purpose of hacking, then companies started to do it as well. The defendant in the first case (I cannot remember his name, I am exhausted right now) appealed all the way to the supreme court. His argument was that source code was a form of protected speech the same way art and literature are, because when you write source code, it reflects the authors creativity and is a reflection of themselves. Which is true, every coder has a unique style, and they approach problems if different ways and the software they write is a reflection of what the coder desires.

Supreme Court ruled, and has since upheld in every case that source code is protected speech
And the makers of the OS release it as source code with automated build for ease of use, however it is highly advisable to build Graphene yourself, and that is what the documentation says.

What the courts did rule however is the user is liable for anything they may do with that software. Take for instance the company I work for, Setec Security Research Labs. We have software that is designed to take down entire infrastructure such as satellite disruption tools, distributed denial of service attacks (DDOS) to knock people of the web, etc. While we build these tools for testing, which is perfectly legit, but if you went and download the open source tools we have and say your boss was being a huge cornhole and decided to use the tools against him, you are liable for your own actions, not me. Just becuase I gave you the gun, doesnt mean its my fualt if you killed someone with it.

Its why groups like cellbrite and NSO group can get away with creating spyware that gets whistleblowers, dissidents, journalist, etc killed. While I am against any company that sells those kinds of tools (and we actively release free tools to prevent those kinds of malware and intrusion devices, our main open source tools), they are completely legal(ish). Our own government uses tools from Cellbrite all the time, like the Iphone cracker used against the San Bernardino shooter (they have legit uses). But governments like Russia use them to kill anyone who speaks out against the government. Its same with the criminal groups (who now spends millions upon millions of dollars, creating software and infrastructure to run scams, exploits, spyware and such).

So GrapheneOS is 100% right.

(sorry if its sloppy, like I said im tired af. I was up all night writing code)
 
Last edited:
My opinion is that Graphene OS should be able to offer that "duress password" as an option; free speech protects the code needed to write those functions. If it is your phone, you should be able to wipe it whenever you choose too, or set the wipe command to be whatever you want it to be. However, if someone uses that option to wipe the phone before a legitimate government investigation then that person should subject to the same penalty they would get if they destroyed potential evidence by other methods, like slamming the phone into the ground.

Thats what it is. Supreme court has ruled on the source code debate since the 90's the same way. Its protected speach. And grapheneOS is released as open-source.
 
How dumb do you think the authorities are... even if it gets restored to a "clean OS", as long as the data is there, they will get it.
- Yes, but this was a fishing expedition. The authorities didn't know what they were looking for, they were just looking to try and find something.

The duress password sets the phone back to stock - and permanently erases all data
Lol - they knew they were had as soon as the password didn't unlock the phone! But at that point, there was nothing they could do as the wipe is instant and irreversible.

-Yes? Again I feel like we're talking past each other.

My fault, poverty of language, I probably am not being clear about what I mean when I say "Opens to a clean OS". I mean from the end user perspective it looks like you've unlocked the phone successfully using a non-duress PIN and now have access to rummage around looking for something.

Only you won't find anything because the OS is presenting a "clean (maybe I should use the word minimal instead) instance". This minimal instance would behave like a normal phone, but would tell whoever is using it that there are no photos/videos/etc or maybe a preselected set of inoffensive images/videos/whatever the user chooses to display in that instance when setting it up.

The issue in this case, presumably, is the user gave the duress PIN, and the phone then indicated somehow that it was erasing all the data on the phone (although I've read that it shouldn't do this).

I'm curious to know how CPB knew a duress PIN was used. I'm guessing they figured guy we have flagged as "problematic" has a factory reset phone after having traveled, something smells fishy here, and I'm saying there needs to be a way to avoid that trap.
 
- Yes, but this was a fishing expedition. The authorities didn't know what they were looking for, they were just looking to try and find something.
They suspected him of terrorism - and they were looking for anything incriminating…
-Yes? Again I feel like we're talking past each other.

My fault, poverty of language, I probably am not being clear about what I mean when I say "Opens to a clean OS". I mean from the end user perspective it looks like you've unlocked the phone successfully using a non-duress PIN and now have access to rummage around looking for something.

Only you won't find anything because the OS is presenting a "clean (maybe I should use the word minimal instead) instance". This minimal instance would behave like a normal phone, but would tell whoever is using it that there are no photos/videos/etc or maybe a preselected set of inoffensive images/videos/whatever the user chooses to display in that instance when setting it up.

The issue in this case, presumably, is the user gave the duress PIN, and the phone then indicated somehow that it was erasing all the data on the phone (although I've read that it shouldn't do this).

I'm curious to know how CPB knew a duress PIN was used. I'm guessing they figured guy we have flagged as "problematic" has a factory reset phone after having traveled, something smells fishy here, and I'm saying there needs to be a way to avoid that trap.
Ok, let me try to simplify… the authorities aren’t complete fools. If a phone had the option to “restore to something that looks like an inoffensive phone”, they would know about it - and be able to look beyond. Unless the data is irretrievably lost, they WILL find it.
 
Since you probably are not part of the tech world or the security world, I will break this down for you best I can. In the 1990's, the government tried to sue a group of hackers who published software for the sole purpose of hacking, then companies started to do it as well. The defendant in the first case (I cannot remember his name, I am exhausted right now) appealed all the way to the supreme court. His argument was that source code was a form of protected speech the same way art and literature are, because when you write source code, it reflects the authors creativity and is a reflection of themselves. Which is true, every coder has a unique style, and they approach problems if different ways and the software they write is a reflection of what the coder desires.

Supreme Court ruled, and has since upheld in every case that source code is protected speech
And the makers of the OS release it as source code with automated build for ease of use, however it is highly advisable to build Graphene yourself, and that is what the documentation says.

What the courts did rule however is the user is liable for anything they may do with that software. Take for instance the company I work for, Setec Security Research Labs. We have software that is designed to take down entire infrastructure such as satellite disruption tools, distributed denial of service attacks (DDOS) to knock people of the web, etc. While we build these tools for testing, which is perfectly legit, but if you went and download the open source tools we have and say your boss was being a huge cornhole and decided to use the tools against him, you are liable for your own actions, not me. Just becuase I gave you the gun, doesnt mean its my fualt if you killed someone with it.

Its why groups like cellbrite and NSO group can get away with creating spyware that gets whistleblowers, dissidents, journalist, etc killed. While I am against any company that sells those kinds of tools (and we actively release free tools to prevent those kinds of malware and intrusion devices, our main open source tools), they are completely legal(ish). Our own government uses tools from Cellbrite all the time, like the Iphone cracker used against the San Bernardino shooter (they have legit uses). But governments like Russia use them to kill anyone who speaks out against the government. Its same with the criminal groups (who now spends millions upon millions of dollars, creating software and infrastructure to run scams, exploits, spyware and such).

So GrapheneOS is 100% right.

(sorry if its sloppy, like I said im tired af. I was up all night writing code)
Freedom of speech doesn’t matter in cases of other crimes though. For example you can try freedom of speech as much as you want but if you’re threatening someone you can certainly be charged with several crimes.
 
They suspected him of terrorism - and they were looking for anything incriminating…

Ok, let me try to simplify… the authorities aren’t complete fools. If a phone had the option to “restore to something that looks like an inoffensive phone”, they would know about it - and be able to look beyond. Unless the data is irretrievably lost, they WILL find it.
Yeah you have to write over data to fully get rid of it
 
4th amendment. Protection from unreasonable search and seizure. No warrant, no probable cause (returning from the Dominican Republic does not constitute probable cause for child molestation). Searching somebody because they participated in a protest (CopCity) based on possible 'CSAM' is the very definition of civil rights abuse.

It's a border search. Same rules they use to search people transporting goods into the country.

Sometimes goods include information.

I'm sorry you guys seem to have so much trouble understanding this.

You both clamour "Omg my rights!!" Written by people 100+ years ago, and "law written 100+ years ago can't possibly apply in this instance it never existed as a rule!"

No. this is open and shut case. At borders you get 4th amendment protection. But remember, 4th is protection against UNREASONABLE search. Crossing a border you might have drugs or guns stuffed up your ***, or whatever, if they truly think you have them they can search you for them. If they think you have CSAM they can ask for your phone pin. It's a reasonable search AT A BORDER.

Outside of a person crossing a border? They can get completely ****ed and can't ask for the pin, can't search his person without a warrant. But this guy was at a border.

They can search his suitcase, they can ask him to strip down naked and cavity search them whatever they want.

And, if you are being searched, setting fire to the objects they are searching, directly or indirectly is destruction of evidence. EVEN IF IT IS EVIDENCE OF INNOCENCE. (Ie destroying "no CSAM" on the device is still destruction of evidence).

If he'd typed the duress code before getting to the front desk? He's fine. He hadn't been subjected to the search yet, the phone has not yet become evidence.
 
I'm going to completely jump off the bandwagon of the current debate, because I would only make it trail on for another 30 something pages to prove my point...

Instead, I'm going to propose those who agree with me bands together and start a very publicly focused and visible petition to Google, Samsung, and every other Android based manufacturer of phones, that all of them collectively also include a duress PIN feature, card embedded within the operating system and irrefutably unbipassable or abortable, and to make their stand and position clear at minimum towards the privacy rights and control that an individual should have over their own device and data regardless of their standpoint of rooting or complete hardware control or even right to repair, but in line with the same positions that all of those beliefs hold in common as it pertains to the spirit and written law of the Constitution and our Country.


I rarely participate in public debate or join in on otherwise weak, or unlikely to succeed regardless of the numbers, petitions or movements, solely because I don't want to waste my time or my breath on something that clearly so many people understand but none of us have a chance in making a point and more importantly a change in the way things work, but because this has gotten so much attention for whatever reason, and I'm not going to question it, I think this is the exact opportunity for us to band together and make a very loud very principled point about the intention and purpose of our country as it was founded and what all we had to fight to obtain as far as freedom is concerned, and the rights we are supposed to have as any recognized or natural born citizen of this country.


I didn't care so much before, but now I have a family to look out for, and to make sure that they have a good life to grow up into, and what I'm seeing right now and have seen for many years in the past, gives me very grim hopes for all of our futures...

Let's do something because it's it before it's too late, because in this instance it's not about the exact letter of the law, which we all know has been bent and corrupted for many years and I could post like I said or at least alluded to before, entire papers and tens or hundreds of thousands of words to prove that point, it's about the spirit of the law and the intention of our law and our country as it was founded and as those who live within it and defend it can unanimously agree that it should be and that we expect it to be, and the moment that that no longer is true, is the exact same moment that in history a civil uprising or civil war begins to form. I don't want that and no one else does, and I think we need to work together to make a clear point in a very broad spectrum,all together; otherwise it doesn't matter and doesn't work and doesn't hold any weight; to peacefully and verbally and within the rights that we still hold even after most of our amendments having been shaved down or exempted so much that they hold fractions of their initial weight and intention, so that we can, as many people believe to be needed and, finally agree upon enough, that we hold a constitutional convention, a multi-month-long if not multi-year long debate and input, and volunteer ourselves, even if it means going through tons of resistance, to truly reform in the way that we can at least all agree on primarily and table the things that are still sufficient debate for the next round of amendments on a clean slate, but at least build a foundation that our country truly believes in, amongst its people, for the people, by the people, one nation under God...

Just wish more people believed that the reform was necessary and possible and truly wanted the outcome of it...
 
It's a border search. Same rules they use to search people transporting goods into the country.

Sometimes goods include information.

I'm sorry you guys seem to have so much trouble understanding this.

You both clamour "Omg my rights!!" Written by people 100+ years ago, and "law written 100+ years ago can't possibly apply in this instance it never existed as a rule!"

No. this is open and shut case. At borders you get 4th amendment protection. But remember, 4th is protection against UNREASONABLE search. Crossing a border you might have drugs or guns stuffed up your ***, or whatever, if they truly think you have them they can search you for them. If they think you have CSAM they can ask for your phone pin. It's a reasonable search AT A BORDER.

Outside of a person crossing a border? They can get completely ****ed and can't ask for the pin, can't search his person without a warrant. But this guy was at a border.

They can search his suitcase, they can ask him to strip down naked and cavity search them whatever they want.

And, if you are being searched, setting fire to the objects they are searching, directly or indirectly is destruction of evidence. EVEN IF IT IS EVIDENCE OF INNOCENCE. (Ie destroying "no CSAM" on the device is still destruction of evidence).

If he'd typed the duress code before getting to the front desk? He's fine. He hadn't been subjected to the search yet, the phone has not yet become evidence.
It is unreasonable if you're just at the border and absolutely no evidence of a trace of CSAM is to be provided, they just made that **** up, be real, there's also procedures, they didn't follow any procedure and just went "f it" and asked the password directly, almost every single time even when it's clear as day that the accused is guilty, if the evidence is gotten through illegitimate means, such as without following the procedure on the field, that evidence would be unusable and sometimes even get the case thrown out, it is not that hard to understand.
Or do you want a cop to come up to you, say "We think you possess CSAM" without any evidence, and take and hack your device? I don't think so
 
Back