cross-posted from: https://lemmy.world/post/49853131
Feels to me like GrapheneOS did exactly what it should, passing the US border test with flying colours!
Funny part about this lawsuit: “With a little planning ahead of time, you can always download the data you need once you get to where you’re going,”
this was a streisand effect for me because i didn’t have duress password set up on my grapheneos phone (security & privacy => device unlock) before but i do now! :D
best promotion ever haha What is it? FU-123?
I imagine the best duress PIN is something you’d actually see a “normal” person set as a PIN, like their birth year or something innocuous and easy to remember (and easily believed by whoever’s demanding your PIN), while their real PIN would be longer or more abstract.
Honestly I would use a stupid basic one that someone might try and use if they were guessing. Like a duress pin of 1-1-1-1, 1-2-3-4 or 2-4-6-8. It gets the people who take the device and then try and break into it without your permission as it’s almost certain they will at least try one of those three.
Worst case scenario they ask you and you say what it is and they give you a blank stare of “really?..” it’s not like they wouldn’t try a pin you gave them.
I don’t recommend a duress password of 1-1-1-1, because that could be set off accidentally.
Or those common dumb ones could be attempted by someone just trying to snoop on your phone.
that’s sort of the point of it being super basic. The intent is you want it to be tried before they somehow manage to get your actual pin, or give up and try to force you to provide it.
if they put the pin in before you tell them a pin the argument for destroying evidence is weakened heavily as it isn’t a you initiated thing.
that’s fair, I don’t know if graphene supports press enter to submit but, I usually have that setting enabled on my devices
The sort of code an idiot puts on his luggage.
Exactly that, its not easy to fat-finger, but is dumb enough that its the second thing anyone would guess.
Or Jenny’s phone number.
8 6 7 5 3 0 9
Is it with a Zero or letter O? They sing the letter “O”. Or, what about handing “niiine”… 3 nines?
Sounds dumb to give it out, but mine is my normal 8-digit pin, just backwards. It’s easy to remember and seems like a legitimate PIN.
that would throw me for a loop longer than I would like to admit, it took me like 10-15 seconds to process what mine would be backwards and mine is only 4 digits lmao
It may be an IT person thing but I like numbers lol.
On GrapheneOS, you can also set a “second factor PIN” in the unlock settings under “Fingerprint Unlock”, so that to unlock your screen you need to first use the fingerprint unlock and then separately enter your PIN. This means BOTH are required every time you unlock. Your phone can’t be unlocked unless it’s your finger AND unless you enter the PIN that only you know.
And under the Screen Lock settings you can also enable “Scramble PIN input layout”, so that the number buttons on your unlock screen will be out of order, so people watching you or recording you can’t just make note of the shape your index finger is making when touching the numbers to unlock your phone(like people looking over your shoulder or recording on store security cameras).
What I find foolish is there’s no pin only to unlock (no biometrics), but biometrics available when unlocked
Plenty of my apps have biometric verification I’d love to take advantage of, but I don’t need or want one to unlock the phone itself
This is why I’m never going to the US until all this shit is fixed. Which will probably be never
Tourists going to the US and US residents leaving should take a burner phone.
Citizens too, at this point.
Definitely
I lost interest of ever visiting again when they started collecting fingerprints from everyone visiting.
You can sand your fingerprints painlessly with fine sandpaper, my dad did it so he didn’t have to clock in at work
Say more
That’s it, you just sand them off, it works best if done slowly over a long period of time, they will grow back.
Lol. CBP taking man to court after agency says “we just know he did this on purpose!”
Same is true for the entire Shengen zone. I was fingerprinted flying into Germany
And pictures for facial recognition
Pretty sure most countries do this now, sadly.
Good. Annoying to rebuild his phone, but better than handing it to fascists who don’t even have a lawful court order for it.
In all likelihood they kept his phone and will retain possession until charges are dismissed. Get a burner phone and wipe it before going through security. I assume if they see your phone is “fresh” they’ll take it on suspicion anyway.
If you change phones regularly you can use an old phone. No need to buy a new one.
Would you want the phone back after it’s been in their hands? I wouldn’t trust them to leave it alone.
I mean yeah, might be a fun reverse-engineering project to look for any backdoors or other modifications to the device.
GOS has boot attestation. But yeah, if I would travel to the US (I will no longer do that) I would bring a sacrificial device.
There are exploits that may work on a different level than bootloader
True, Pixel hardware itself might be backdoored out of the factory. But you have to titrate professional paranoia down to functional levels.
Surely he was also using the built in backup feature, if he was he would have been able to grab another used Pixel, install GOS, then just recover from his backup (I haven’t tried the restore yet just because I’m lazy, fingers crossed it works).

Sounds like the border guard wiped his phone, not him.
Would be cool to have your device partitioned by separate passwords, so you could unlock a dummy system.
This is an excellent idea honestly.
There are ways to do this on some devices. Here’s an article about it, Google translate’d to English:
yes you can. On Graphene you can set the main profile as just there with nothing except to control wifi/add esim/etc. Then you can create many profiles with their own passwords. You can store your work stuff in 1 profile, private stuff in another. You can even create a dummy profile with fake Google. .
The downside currently is that the OS autoboot to main profile. Then you switch to your other profiles.
Good writeup, and the downside you flagged is the interesting bit. Profiles are enumerable. A dummy profile survives a glance at the screen and stops working the second someone can see profile 2 exists and asks you to open it.
The property you want on top of your setup is that the second thing can’t be shown to exist at all, so it looks like random noise rather than a locked door. Then the dummy isn’t a dummy, it’s just the phone.
(I work on DeniableOS, which is built around that. Your profile setup is still the right free answer for most people and I wouldn’t talk anyone out of it.)
I believe some password manager (was it 1Password?) has this
That exists. The thing to watch is the difference between separate profiles and a hidden one.
Graphene gives you multiple profiles with their own passwords, but profiles are enumerable. Anyone poking at the device sees that profile 2 is there, so “open that one too” is the obvious next sentence.
The version you’re describing works when the second environment can’t be shown to exist at all, so it reads as encrypted random noise, which is what empty encrypted space looks like anyway. One PIN gets you a full boring phone, the other gets you your real one.
Only holds up if the boring phone is actually convincing though. Six apps and no photos fails on the spot.
(I work on DeniableOS, which does the hidden version, so weigh that how you like.)
What? US police can ask you for the phone password? No way! That is 100% police state. Stalin was amateur comparing to present day USA.
Yes US citizens cannot be compelled to provide a password, but biometrics such as fingerprint or Face ID can. Disable these when crossing into the US.
Non citizens can be detained and rejected for not providing access to a device via password. Best to bring a second device if you must enter. Depressing times.
Non citizens can be detained and rejected for not providing access to a device via password. Best to bring a second device if you must enter. Depressing times.
Or simply do not go to the US and let them to rot in their own madness
I don’t believe you can be compelled to provide a password. That does after all (at the very least) constitute speech. And freedom of speech is also freedom of non-speech, they can’t make you say something.
They will however try to make you do that… In many situations authorities are allowed to lie to you. So that’s sucks. They can tell you that you’re required to unlock your phone, you just have to know that your not actually.
Also they can’t make you say anything, but they can make you do things, like for instance “put your finger here” or “look into this camera”, which is why biometric unlock is unsafe around cops.
There’s that one guy who is being held in contempt of the court (to be clear this is not the police asking for his password, but a judge in a court of law) because he won’t give a password to decrypt a hard drive.
They believe it is highly likely that the drive contains sexually explicit material of children, which is why he’s being held in prison until he gives up the password.
I would want to catch pedophiles too, but I seriously don’t believe a damn thing any branch of this government says about anyone.
For all I know he has a video of trumps night out at Epstein island and that’s why they want the password to destroy it.
Obviously probably not but still, I’m supposed to just take the scouts honor of our unhonorable government that this guy totally has this on his hard drive even if they can’t prove it?
They could say this about any of us at any time for any devices password we won’t give them.
I don’t agree with this precedent.
Oh yeah I think it’s terrible this guy is imprisoned for not giving up a password, for something they can’t prove. Like they shouldn’t be able to detain someone indefinitely for an unproven crime. At some point they have to release them or it’s guilty until proven innocent.
he’s being held in prison until he gives up the password
So basically he is in prison without proven guilty? That is exactly how “Communist” countries did: “you are probably guilty and just in case you will spend next 10-20 years in prison untill you admit your guilt”. Now is “OK” for pedophiles, next will be OK too for political oposition.
The important thing is this: can you still deliver lectures to the rest of the world on the Importance of Freedom Of Speech, and the fact that only Yanks have it because Elon can worship Hitler on the Internet?
And the answer is, yes. Yes you can, and always will. So the actual reality isn’t really important. Because all you actually learned from 1984 is that of the government tells you that you have freedom of speech, and also tells you that Eastasia and Eurasia don’t, That’s Good Enough For You and you’re The Free-est People In The World.
GrapheneOS - the only OS that i just installed and forget about it. Sure i spend time to tweak things like profiles but thats it.
And I am a distro and rom hopper.
The security model is that good: duress pin, scrambled pin, separate profiles with their own passwords, usb c restriction (you can set it charge only, charge while phone is off (most secure state).
and yet people even here don’t understand why it would be useful even without the hardware security thinhs of the pixel
You can only install Graphene on a Google phone and there’s two big issues with that:
- you are rewarding Google by buying their hardware.
- it doesn’t matter how secure the os claims to be if the hardware is compromised and there is nothing you can do to convince me that a pixel doesn’t have a backdoor into your data at a hardware level. If I was a conspiracy minded type I might say that Graphene is a Trojan Horse.
why are they so concerned about what you OWN
What if you OWNed some child pornography.
So are you saying you’d be ok with your personal property being searched without a warrant on the suspicion that you might own child porn?
What if you owned: weed/drugs, illegal firearms, items which could be used for potential murder, negative opinions about the fascist government?
This argument is shallow to the point where fascism is what you’re advocating here for. So what, if you did own something thats not law abiding - without any credible proof there is nothing there, and non of anybody’s interest.
not bro resorting to whataboutism.
Begone Fed
Lets go by your logic then, What IF a cop plants contraband or CASM pictures onto your device?
Surveillance is fascism… it is clear to me that neither do you understand the word nor do you know about the most basic features of it.
??? classic statistic apologist rhetoric I’m not against holding pedos accountable, I’m against searching a man/woman/non binary’s phone without proving suspicion of OWNing child pornography… please educate yourself
Privacy isn’t keeping everything about your life secret from everybody. Its about having control over who in your life gets to know what. Its the pretext for honest communication. Extreme surveillance will lead to people self-censoring themselves to please the fascist state.
What if I am a law abiding citizen? Should I relinquish my rights against unwarranted search and seizure because of ‘woulda coulda shoulda’?
If your rights can so easily be ignored due to some hypothetical scenario, then you never really had rights to begin with.
He would have had a lot better legal leg to stand on I think if he had just refused to give them any passcode. Now instead of a potential case of being forced to compel speech, he is facing what will be argued is an attempt to destroy evidence. His defense is probably a lot stronger with the former than the latter.
Does it count as destroying evidence if they don’t have a warrant for it? I can destroy whatever device or document I want. It’s my property
Not once law enforcement tell you it is relevant to an ongoing investigation.
I may be about to move to a town near the border, and I fully plan on visiting Mexico as frequently as I can. It’s one of the things I’m most excited about about moving there.
I will 100% be getting a second cheap phone, and only taking that when I cross the border.
This whole situation is making me strongly consider bringing a burner phone on my next vacation. That way I can wipe it before going through customs.
I did something similar when I last visited the US ~15 years ago. I uploaded an encrypted backup of my phone to a server in my home country and reset the device. I then downloaded and restored the backup when I arrived at the hotel.
„I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.” Wow that’s an advice fitting entering Russia, Iran, etc. Nice club you’ve joined here
That’s it. I’m getting a burner phone if I leave the country.
Edit: Serious question… what if you just wiped your phone and then restored it when you got wherever you were going?
Honestly I’m not considering leaving at all while this administration is in power. We’ve already heard too many stories of arbitrary detentions even for lawful citizens or visitors that I simply don’t want to roll the dice on whether my vacation ends with a nightmare or just another flight in as normal
Ditto.
If I have to leave the US, its a one way trip
Given that the state of this guy’s phone would look the same as a burner phone, I’m not sure how that will work out.
„unlawful to knowingly destroy or damage property to prevent authorities from seizing it” - but did it fucking explode, catch on fire, or blew some fuse on the phone or in any other way prevented it from working? No, they (not him) just wiped the data. I didn’t know deleting files off YOUR OWN DEVICE is a crime. I need to think twice before I empty trash on my computer next time.
100/100 remark!!!


















