cross-posted from: https://lemmy.world/post/49853131

Feels to me like GrapheneOS did exactly what it should, passing the US border test with flying colours!

Funny part about this lawsuit: “With a little planning ahead of time, you can always download the data you need once you get to where you’re going,”

  • jas [they/any]@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    150
    ·
    23 days ago

    this was a streisand effect for me because i didn’t have duress password set up on my grapheneos phone (security & privacy => device unlock) before but i do now! :D

      • volore@scribe.disroot.org
        link
        fedilink
        English
        arrow-up
        41
        ·
        edit-2
        23 days ago

        I imagine the best duress PIN is something you’d actually see a “normal” person set as a PIN, like their birth year or something innocuous and easy to remember (and easily believed by whoever’s demanding your PIN), while their real PIN would be longer or more abstract.

        • Pika@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          17
          ·
          edit-2
          23 days ago

          Honestly I would use a stupid basic one that someone might try and use if they were guessing. Like a duress pin of 1-1-1-1, 1-2-3-4 or 2-4-6-8. It gets the people who take the device and then try and break into it without your permission as it’s almost certain they will at least try one of those three.

          Worst case scenario they ask you and you say what it is and they give you a blank stare of “really?..” it’s not like they wouldn’t try a pin you gave them.

          • obvs@lemmy.world
            link
            fedilink
            English
            arrow-up
            23
            ·
            23 days ago

            I don’t recommend a duress password of 1-1-1-1, because that could be set off accidentally.

              • Pika@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                3
                ·
                edit-2
                21 days ago

                that’s sort of the point of it being super basic. The intent is you want it to be tried before they somehow manage to get your actual pin, or give up and try to force you to provide it.

                if they put the pin in before you tell them a pin the argument for destroying evidence is weakened heavily as it isn’t a you initiated thing.

            • Pika@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              edit-2
              21 days ago

              that’s fair, I don’t know if graphene supports press enter to submit but, I usually have that setting enabled on my devices

            • Bahnd Rollard@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              ·
              22 days ago

              Exactly that, its not easy to fat-finger, but is dumb enough that its the second thing anyone would guess.

        • ITGuyLevi@programming.dev
          link
          fedilink
          English
          arrow-up
          3
          ·
          22 days ago

          Sounds dumb to give it out, but mine is my normal 8-digit pin, just backwards. It’s easy to remember and seems like a legitimate PIN.

          • Pika@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            3
            ·
            edit-2
            21 days ago

            that would throw me for a loop longer than I would like to admit, it took me like 10-15 seconds to process what mine would be backwards and mine is only 4 digits lmao

    • obvs@lemmy.world
      link
      fedilink
      English
      arrow-up
      24
      ·
      edit-2
      22 days ago

      On GrapheneOS, you can also set a “second factor PIN” in the unlock settings under “Fingerprint Unlock”, so that to unlock your screen you need to first use the fingerprint unlock and then separately enter your PIN. This means BOTH are required every time you unlock. Your phone can’t be unlocked unless it’s your finger AND unless you enter the PIN that only you know.

      And under the Screen Lock settings you can also enable “Scramble PIN input layout”, so that the number buttons on your unlock screen will be out of order, so people watching you or recording you can’t just make note of the shape your index finger is making when touching the numbers to unlock your phone(like people looking over your shoulder or recording on store security cameras).

      • Justifier@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        22 days ago

        What I find foolish is there’s no pin only to unlock (no biometrics), but biometrics available when unlocked

        Plenty of my apps have biometric verification I’d love to take advantage of, but I don’t need or want one to unlock the phone itself

  • db2@lemmy.world
    link
    fedilink
    English
    arrow-up
    75
    ·
    23 days ago

    Good. Annoying to rebuild his phone, but better than handing it to fascists who don’t even have a lawful court order for it.

    • BrianTheeBiscuiteer@lemmy.world
      link
      fedilink
      English
      arrow-up
      36
      ·
      23 days ago

      In all likelihood they kept his phone and will retain possession until charges are dismissed. Get a burner phone and wipe it before going through security. I assume if they see your phone is “fresh” they’ll take it on suspicion anyway.

    • tabular@lemmy.world
      link
      fedilink
      English
      arrow-up
      27
      ·
      23 days ago

      Would you want the phone back after it’s been in their hands? I wouldn’t trust them to leave it alone.

      • metallic_z3r0@infosec.pub
        link
        fedilink
        English
        arrow-up
        11
        ·
        23 days ago

        I mean yeah, might be a fun reverse-engineering project to look for any backdoors or other modifications to the device.

      • eleitl@lemmy.zip
        link
        fedilink
        English
        arrow-up
        6
        ·
        22 days ago

        GOS has boot attestation. But yeah, if I would travel to the US (I will no longer do that) I would bring a sacrificial device.

          • eleitl@lemmy.zip
            link
            fedilink
            English
            arrow-up
            2
            ·
            20 days ago

            True, Pixel hardware itself might be backdoored out of the factory. But you have to titrate professional paranoia down to functional levels.

    • ITGuyLevi@programming.dev
      link
      fedilink
      English
      arrow-up
      5
      ·
      22 days ago

      Surely he was also using the built in backup feature, if he was he would have been able to grab another used Pixel, install GOS, then just recover from his backup (I haven’t tried the restore yet just because I’m lazy, fingers crossed it works).

  • badbytes@lemmy.world
    link
    fedilink
    English
    arrow-up
    29
    ·
    22 days ago

    Would be cool to have your device partitioned by separate passwords, so you could unlock a dummy system.

    • mazzilius_marsti@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      22 days ago

      yes you can. On Graphene you can set the main profile as just there with nothing except to control wifi/add esim/etc. Then you can create many profiles with their own passwords. You can store your work stuff in 1 profile, private stuff in another. You can even create a dummy profile with fake Google. .

      The downside currently is that the OS autoboot to main profile. Then you switch to your other profiles.

      • Robert_White@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        18 days ago

        Good writeup, and the downside you flagged is the interesting bit. Profiles are enumerable. A dummy profile survives a glance at the screen and stops working the second someone can see profile 2 exists and asks you to open it.

        The property you want on top of your setup is that the second thing can’t be shown to exist at all, so it looks like random noise rather than a locked door. Then the dummy isn’t a dummy, it’s just the phone.

        (I work on DeniableOS, which is built around that. Your profile setup is still the right free answer for most people and I wouldn’t talk anyone out of it.)

    • Robert_White@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      18 days ago

      That exists. The thing to watch is the difference between separate profiles and a hidden one.

      Graphene gives you multiple profiles with their own passwords, but profiles are enumerable. Anyone poking at the device sees that profile 2 is there, so “open that one too” is the obvious next sentence.

      The version you’re describing works when the second environment can’t be shown to exist at all, so it reads as encrypted random noise, which is what empty encrypted space looks like anyway. One PIN gets you a full boring phone, the other gets you your real one.

      Only holds up if the boring phone is actually convincing though. Six apps and no photos fails on the spot.

      (I work on DeniableOS, which does the hidden version, so weigh that how you like.)

  • itisileclerk@lemmy.world
    link
    fedilink
    English
    arrow-up
    25
    ·
    22 days ago

    What? US police can ask you for the phone password? No way! That is 100% police state. Stalin was amateur comparing to present day USA.

    • BigDiction@lemmy.world
      link
      fedilink
      English
      arrow-up
      14
      ·
      22 days ago

      Yes US citizens cannot be compelled to provide a password, but biometrics such as fingerprint or Face ID can. Disable these when crossing into the US.

      Non citizens can be detained and rejected for not providing access to a device via password. Best to bring a second device if you must enter. Depressing times.

      • gian @lemmy.grys.it
        link
        fedilink
        English
        arrow-up
        1
        ·
        21 days ago

        Non citizens can be detained and rejected for not providing access to a device via password. Best to bring a second device if you must enter. Depressing times.

        Or simply do not go to the US and let them to rot in their own madness

    • Cocodapuf@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      edit-2
      22 days ago

      I don’t believe you can be compelled to provide a password. That does after all (at the very least) constitute speech. And freedom of speech is also freedom of non-speech, they can’t make you say something.

      They will however try to make you do that… In many situations authorities are allowed to lie to you. So that’s sucks. They can tell you that you’re required to unlock your phone, you just have to know that your not actually.

      Also they can’t make you say anything, but they can make you do things, like for instance “put your finger here” or “look into this camera”, which is why biometric unlock is unsafe around cops.

      • BlackAura@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        22 days ago

        There’s that one guy who is being held in contempt of the court (to be clear this is not the police asking for his password, but a judge in a court of law) because he won’t give a password to decrypt a hard drive.

        They believe it is highly likely that the drive contains sexually explicit material of children, which is why he’s being held in prison until he gives up the password.

        • DanceMomsSavedMe@lemmy.zip
          link
          fedilink
          English
          arrow-up
          8
          ·
          edit-2
          22 days ago

          I would want to catch pedophiles too, but I seriously don’t believe a damn thing any branch of this government says about anyone.

          For all I know he has a video of trumps night out at Epstein island and that’s why they want the password to destroy it.

          Obviously probably not but still, I’m supposed to just take the scouts honor of our unhonorable government that this guy totally has this on his hard drive even if they can’t prove it?

          They could say this about any of us at any time for any devices password we won’t give them.

          I don’t agree with this precedent.

          • BlackAura@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            21 days ago

            Oh yeah I think it’s terrible this guy is imprisoned for not giving up a password, for something they can’t prove. Like they shouldn’t be able to detain someone indefinitely for an unproven crime. At some point they have to release them or it’s guilty until proven innocent.

        • itisileclerk@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          21 days ago

          he’s being held in prison until he gives up the password

          So basically he is in prison without proven guilty? That is exactly how “Communist” countries did: “you are probably guilty and just in case you will spend next 10-20 years in prison untill you admit your guilt”. Now is “OK” for pedophiles, next will be OK too for political oposition.

    • timochka@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      22 days ago

      The important thing is this: can you still deliver lectures to the rest of the world on the Importance of Freedom Of Speech, and the fact that only Yanks have it because Elon can worship Hitler on the Internet?

      And the answer is, yes. Yes you can, and always will. So the actual reality isn’t really important. Because all you actually learned from 1984 is that of the government tells you that you have freedom of speech, and also tells you that Eastasia and Eurasia don’t, That’s Good Enough For You and you’re The Free-est People In The World.

  • mazzilius_marsti@lemmy.world
    link
    fedilink
    English
    arrow-up
    21
    ·
    22 days ago

    GrapheneOS - the only OS that i just installed and forget about it. Sure i spend time to tweak things like profiles but thats it.

    And I am a distro and rom hopper.

    The security model is that good: duress pin, scrambled pin, separate profiles with their own passwords, usb c restriction (you can set it charge only, charge while phone is off (most secure state).

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      8
      ·
      22 days ago

      and yet people even here don’t understand why it would be useful even without the hardware security thinhs of the pixel

      • BigTwerp@feddit.uk
        link
        fedilink
        English
        arrow-up
        13
        ·
        edit-2
        22 days ago

        You can only install Graphene on a Google phone and there’s two big issues with that:

        1. you are rewarding Google by buying their hardware.
        2. it doesn’t matter how secure the os claims to be if the hardware is compromised and there is nothing you can do to convince me that a pixel doesn’t have a backdoor into your data at a hardware level. If I was a conspiracy minded type I might say that Graphene is a Trojan Horse.
      • zalgotext@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        12
        ·
        21 days ago

        So are you saying you’d be ok with your personal property being searched without a warrant on the suspicion that you might own child porn?

      • Virtvirt588@lemmy.world
        link
        fedilink
        English
        arrow-up
        11
        ·
        edit-2
        21 days ago

        What if you owned: weed/drugs, illegal firearms, items which could be used for potential murder, negative opinions about the fascist government?

        This argument is shallow to the point where fascism is what you’re advocating here for. So what, if you did own something thats not law abiding - without any credible proof there is nothing there, and non of anybody’s interest.

      • slumdogego@slrpnk.net
        link
        fedilink
        English
        arrow-up
        8
        ·
        21 days ago

        ??? classic statistic apologist rhetoric I’m not against holding pedos accountable, I’m against searching a man/woman/non binary’s phone without proving suspicion of OWNing child pornography… please educate yourself

      • yuki_gassen@lemmy.ml
        link
        fedilink
        English
        arrow-up
        6
        ·
        21 days ago

        Privacy isn’t keeping everything about your life secret from everybody. Its about having control over who in your life gets to know what. Its the pretext for honest communication. Extreme surveillance will lead to people self-censoring themselves to please the fascist state.

      • tinfoilhat@lemmy.ml
        link
        fedilink
        English
        arrow-up
        6
        ·
        21 days ago

        What if I am a law abiding citizen? Should I relinquish my rights against unwarranted search and seizure because of ‘woulda coulda shoulda’?

        If your rights can so easily be ignored due to some hypothetical scenario, then you never really had rights to begin with.

  • flop_leash_973@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    ·
    edit-2
    22 days ago

    He would have had a lot better legal leg to stand on I think if he had just refused to give them any passcode. Now instead of a potential case of being forced to compel speech, he is facing what will be argued is an attempt to destroy evidence. His defense is probably a lot stronger with the former than the latter.

    • TORFdot0@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      21 days ago

      Does it count as destroying evidence if they don’t have a warrant for it? I can destroy whatever device or document I want. It’s my property

  • Dharma Curious (he/him)@slrpnk.net
    link
    fedilink
    English
    arrow-up
    13
    ·
    23 days ago

    I may be about to move to a town near the border, and I fully plan on visiting Mexico as frequently as I can. It’s one of the things I’m most excited about about moving there.

    I will 100% be getting a second cheap phone, and only taking that when I cross the border.

  • Archr@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    ·
    21 days ago

    This whole situation is making me strongly consider bringing a burner phone on my next vacation. That way I can wipe it before going through customs.

    • Hubi@feddit.org
      link
      fedilink
      English
      arrow-up
      10
      ·
      edit-2
      21 days ago

      I did something similar when I last visited the US ~15 years ago. I uploaded an encrypted backup of my phone to a server in my home country and reset the device. I then downloaded and restored the backup when I arrived at the hotel.

  • spitfire@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    21 days ago

    „I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.” Wow that’s an advice fitting entering Russia, Iran, etc. Nice club you’ve joined here

  • billwashere@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    edit-2
    22 days ago

    That’s it. I’m getting a burner phone if I leave the country.

    Edit: Serious question… what if you just wiped your phone and then restored it when you got wherever you were going?

    • Shortstack@reddthat.com
      link
      fedilink
      English
      arrow-up
      8
      ·
      22 days ago

      Honestly I’m not considering leaving at all while this administration is in power. We’ve already heard too many stories of arbitrary detentions even for lawful citizens or visitors that I simply don’t want to roll the dice on whether my vacation ends with a nightmare or just another flight in as normal

    • JcbAzPx@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      21 days ago

      Given that the state of this guy’s phone would look the same as a burner phone, I’m not sure how that will work out.

  • spitfire@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    21 days ago

    „unlawful to knowingly destroy or damage property to prevent authorities from seizing it” - but did it fucking explode, catch on fire, or blew some fuse on the phone or in any other way prevented it from working? No, they (not him) just wiped the data. I didn’t know deleting files off YOUR OWN DEVICE is a crime. I need to think twice before I empty trash on my computer next time.