Posted by floathub 9 hours ago
I think it would be easier to understand the playing field and choose your actions accordingly, if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech.
The social dynamics are the same - the abuses, the selective enforcement, the lack of recourse, the same characters in the roles of various levels of "law enforcement" and "politics". I'm so very sorry, but the best you can do from here is speedrun the collapse.
I'm pretty optimistic that after the next general America will be ready to give up on the extremity of late turn over a new leaf. I fully expect a new president to be ushered in, whether R or D, and for some level of normalcy to start creeping back.
The Soviets lost eventually, I don't think America can lose. Canadians like myself have watched America win for our country's entire existence; I am unconvinced that a decade of silliness is enough to compare America to East Germany.
In 2016 I remember Americans saying this was the end of the line and the country was doomed. 10y later they're richer than ever and its companies have global dominance of the most world-changing technology of the last 20y. I just don't think "the collapse" is coming anytime soon.
If anyone's interested in a friendly wager, my email is open. I'll happily go 1:1 odds that America will have a new president come 2029 and the country will still remain the world's richest and most powerful.
[1] I'm not defending the behavior of border control here, but I also don't think we need to overreact to this one example which is exactly what is happening.
Yeah, that's awful. As far as federal overreach of power goes, that's pretty inexcusable. I'd probably posit that COINTELPRO in the 60s was more insidious, but that doesn't discount this story individually being terrible.
I still maintain that America is not in the midst of its own demise and a comparison to East Germany is inaccurate.
You are undoubtedly correct that at some point there will be new leadership in the US.
Politics makes the leadership change a possibility. Biology makes it an inevitability.
But I don't think the evidence is very strong that switching from one man to a different man, even if the new man wears a blue hat instead of a red hat, will make that much difference against capital and its surveillance state.
This isn't a false equivalence "both sides" argument. I'd greatly prefer the blue hat over the red hat.
But the blue hat only makes the underlying forces of late capitalism a little slower and a little less vicious, while simultaneously legitimizing that system.
The guy doesn't have the stomach for real totalitarianism. Just populism, corruption, and weakening the country.
> I think it would be easier to understand the playing field and choose your actions accordingly, if you accept the US has entered its East Germany / late 20th century Soviet era -- except of course with 1000x more invasive and effective surveillance tech.
it's as long as you're not doing anything wrong you don't have to worry about it Then once changed the definition of what wrong means.
If you're not a criminal you don't have to worry about it That's for your safety Then they changed the definition of what a crime is
If it walks like a duck, and quacks like a duck.. might just be a duck.
I don’t believe those living “normal lives” in East Germany or the Soviet era considered the police to be evil and invasive the way we do today.
"normal life" under the Stasi was constant political terror and suppression.
The death counts are low because they thought death too little of a penalty for opposing them - they used psychological warfare and torture instead: https://en.wikipedia.org/wiki/Zersetzung
Soviet famine of 1930–1933
"It is estimated that 5.7 to 8.7 million people died from starvation across the Soviet Union. In addition, 50 to 70 million Soviet citizens starved during the famine but ultimately survived."
https://en.wikipedia.org/wiki/Soviet_famine_of_1932%E2%80%93...
Great Purge
"Scholars estimate the death toll of the Great Purge at 700,000 to 1.2 million."
It’s a lazy, complacent take.
the stasi were spying on people and putting them in jail. what exactly is your claim about the difference? is it a difference in distinction or a difference in degree?
What we hear about is far from comprehensive, and many of the atrocities won’t be unveiled or investigated until the next decade.
The Epstein cover up shows they’re used to keeping secrets.
I’m not sure why we’re pretending there’s not a convicted felon in charge of the entire system.
Some dark, dark things happened in the USA, and almost every progression had a corresponding backslide - but the tick-tock has always ticked further towards a freer, more equal, and more equitable society.
Progress doesn’t always (ever?) require complete collapse.
I’m willing to hope this era is another ‘tock’. But that does require people to not just give up (or even work to accelerate the backslide?!) as you seem to be suggesting is the best course of action.
Hope always grows from those who take an initiative to change the world.. and not those that advocate for acceptance of suffering and hardship like yourself.
Fortunately history was filled with people who didn't just lie down and take it.
> The social dynamics are the same - the abuses, the selective enforcement, the lack of recourse, the same characters in the roles of various levels of "law enforcement" and "politics"
What you're describing is politics in general. The question is not whether abuses occur (they do, everywhere), but whether the system is built to be resilient and course-correct over time.
The thing about freedom is not just that it's less miserable than the alternative; more importantly, freedom enables a feedback loop where people's individual choices carry corrective information: what they buy, what they sell, how much, at what price, who they vote for, what they write/publish, what they read, what they say etc. The system at large can correct itself over time if (a) these choices are allowed to have power to influence the system, and (b) the courts enforce justice without interference by the ruling party.
Not a single communist country in the 20th century stayed communist for more than a few years when only 2 freedoms were allowed: (1) freedom of the press, and (2) freedom of the courts from control by the ruling party.
The Soviets and East Germans suppressed every form of freedom that carried information or potential corrective power, because they maxxed on staying in power above all - they effectively had to. No one wants to be under real communism/socialism[0], so for it to be stable it has to be maximally suppressive.
[0] see various records of escape attempts, such as https://www.ebsco.com/research-starters/politics-and-governm...
I think it's more effective to stick to our own history because this country has always been a struggle for workers outside of a small very respite after WW2 that has been actively fought against and weakened since.
It's a temporary situation, it isn't necessarily a permanent situation.
Tell me how you think East Germany is doing these days.
And no, it doesn't have to take 40 years to right the ship, so long as people get their heads out of their asses and vote. Things are likely to change by the end of this year, and in another 2 years we could have a very different government that could undo a lot of the bullshit going on right now.
It's still worrying! His supporters still number lots of people who a) are still somehow too gullible to realize Trump and the MAGA crowd are not going to make their lives better, and b) actively want what's going on. But there are easily more eligible voters in the US who wouldn't vote for a Republican with a gun to their head, or who are finally starting to understand that "sticking it to the libs" is hurting themselves.
It's not going away, but it's likely that it's declining, and possible it will continue to do so. Whether or not it declines quickly enough, before these jackasses consolidate power and break what's left of our institutions... well, that remains to be seen.
It reminds me somewhat of the state of the Weimar Republic. The democratic parties failed which gave an opening to the nazis.
That's half the people who showed up to vote, not "half the voting population". 1/3 of the eligible voters simply didn't vote, and from the people I've encountered that don't vote, they are mostly left-leaning.
No, stupidity and self-harm aren't going away, those are human traits. The current admin is actively hurting everyone, with tariffs and stupid wars he campaigned that he wouldn't start, ICE in every city everywhere causing chaos even to right-wing supporter-owned businesses (they wanted immigration reform but not like that!). This admin has shit the bed, and even his supporters are feeling that. They are now in the "finding out" phase, and the next phase doesn't look so good for republicans in the next election because of it.
Where's the Project 2028 book?
Is there anyone credible putting together the Executive Orders to undo the stack of shit, is anyone putting together a short list of District Attorneys to interview on January 21, etc?
In terms of the ending, East Germany was nearly an ideal case. The state just sort of gently fell over. The country got absorbed into a friendly neighbor. There wasn't much loss of life, no widespread destruction.
Then there's East Germany's predecessor state, which ended because it decided to wage war on half the world, and its people bore the consequences. Millions dead, cities wrecked, occupation by foreign armies, the country carved up. "This too shall pass" isn't always a good thing.
Or look at the state that created and sustained East Germany. Borne out of violent revolution, decades of repression, collapse, turmoil, economic hardship, brief flirtation with democracy, de facto dictatorship, no end in sight.
My biggest worry with the US right now isn't the government itself. It's that so many people want this government. Voting doesn't help when the voters want the bad stuff. We could have a very different government in another two years if the people want it. I'm not convinced they do. If they do I'm not convinced that sentiment will last. We already went through this once, and the "actually, let's not give the shitheads power" sentiment fell apart by the next election.
> And no, it doesn't have to take 40 years to right the ship, so long as people get their heads out of their asses and vote.
so then you admit the outcome here is contingent/conditional. do you understand that means we are already in dire circumstances if the outcome isn't certain?
This is a pretty silly take. If you actually follow the news, all of these issues are getting pushback. It's not at all clear that even a competent fascist-leaning government would be able to push through what the current one is trying to do, and sadly for them, competence in their ranks is in short supply.
The bigger issue has nothing to do with the faddish concerns of the current government. The era we should be looking to is not East Germany/late Soviet - it's more like the Gilded Age. Robber barons need to be dealt with from time to time.
There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).
Some time ago, Android with a custom recovery could come close to that, but it was fussy and as far as I know, no longer viable. Increased use of TPMs for storing credentials seems to be at least one of the reasons.
One of the laws that's enforced pretty well in the USA is the protection against unreasonable search. Most of the time, a search requires showing a judge evidence that the search is more likely than not to reveal evidence of a crime. Exceptions are narrow and specific; the government's options to punish someone who refuses to decrypt data at the border are limited to brief detention and seizure of the medium.
Not yet tested is the idea that erasing data on the spot satisfies the purpose of the border search exception, which is to prevent importation of things that are illegal to import. This case might address that question.
Edit to add that its also more difficult than it should be to protect and exercise the right against unreasonable search. If a cop knocks on your door its a consent-based interaction. You can simply not respond, but if you do happen to crack the door they can and will look in for any signs to claim as probable cause. Further there are cases where a person stepped out to talk and when they turned around and walked inside the cop slid right in behind them and later claimed in court the open door was implied consent. (I don't have a link to the court docs unfortunately.)
Sure, but there are also many instances today of evidence getting thrown out in court due to cops not getting a warranty and poisoning the tree and all its fruit. Rights don't just enforce themselves, there are and have to be a number of layers to the onion to help reduce the violation numbers at each stage.
And there are also many instances of the city being sued, those cops being sued, losing qualified immunity, losing their jobs, etc, because we do still have recourse when cops do the wrong thing.
If your rights were violated, you stand to get a big payout, and get the cops fired that violated your rights. We aren't powerless, yet.
Not really, the data points the other way. Cops basically never have to actually pay for their wrongdoings. Over 99.98% of money successfully recovered from cases against police is paid out by the cities, not cops personally [1]. A considerable number of cops that are fired are also eventually rehired by the same department [2] or a different one [3]. So I don't think it's that clear that you "have recourse when cops do the wrong thing".
[1] https://nyulawreview.org/wp-content/uploads/2018/08/NYULawRe...
[2] https://scholarship.law.vanderbilt.edu/vlr/vol74/iss4/4/
[3] https://yalelawjournal.org/pdf/GrunwaldRappaportArticle_s6br...
"In United States criminal law, the border search exception is a doctrine that allows searches and seizures at international borders and their functional equivalent without a warrant or probable cause. Generally speaking, searches within 100 miles (160 km) of the border are more permissible without a warrant than those conducted elsewhere in the United States."
https://en.wikipedia.org/wiki/Border_search_exception
213 milion people live in this zone.
then consider this paired with the implementation of mass data sharing between the alphabet agencies, surveillance data sharing from private companies like Amazon Ring, Flock, Clearview, etc. and NSPM-7 ordering agencies to create JTTFs to target organizations like BLM
then consider the unmitigated use of force by federal law enforcement agencies like ICE
I think if this were 1995 your point might be fair but those days are unfortunately long gone
> In a full banana republic, technical compliance with the law will not prevent consequences for failing to do what the authorities want. In a jurisdiction with perfect rule of law, it always will.
I think you may be misunderstanding that many laws, even in fair, just societies, are intentionally designed to be flexible. The real world is so variable and messy that in many cases it isn't feasible for a law to be written such it can be unambiguously determined whether or not a specific action violated the law. Laws often rely on humans using context to judge whether something violates the spirit of a law, and in a just society, this is a good thing.
My point is that I don't believe the idea of "perfect rule of law" is sensible. Law is always necessarily a bit fuzzy and nebulous.
Americans aren't standing up against this, but they might have considerably more interest if the government was instead trying to ban encrypting data in cloud storage for everyone.
There's also just the fact it's ridiculous I can't have a spare phone ready to go in a few minutes and get it back exactly as I left it.
It's worth noting wiping a device shortly before an anticipated search could also be considered destruction of evidence.
> There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).
This was likely the best move for him to take. They could have held him for a while and wasted his time but eventually would have had to give him access to a lawyer and let him go. Unless they had a recording of him entering a PIN/password, they were nearly certainly not going to get his data from it. He very likely didn't gain anything from wiping it.
He did help every GrapheneOS user by spreading awareness of the duress PIN/password. It was designed around an adversary aware of it and therefore not wanting to attempt using a PIN/password obtained via coercion. In the future, we want to integrate the feature into the secure element rate limiting for key derivation so it can't be avoided by exploiting the OS.
You're always been able to backup and restore your iPhone to your local Windows PC or a Mac using free first party software from Apple.
How is this any different than refusing to unlock the phone? It just seems you've added unnecessary extra steps.
It's the same thing. They punched in a code, they are presented with a wiped phone. Can they prove the guy gave them a distress password and wasn't simply carrying a wiped phone to begin with? No, but they just need to imply that is the reason to charge him with the felony.
It doesn't even care about plausible deniability.
Best you can get away with is lack of suspicion. Have a secondary phone with some standard apps on that you use now and then so theyhave a history and just look like you are just not a technical person and read novels on dead trees instead. A lot of work but likely works.
They don't get any indication that there was data there to be deleted, and you don't just factory reset but flash w an image of a clean phone that's been used. It has apps, it has accounts, it looks to the untrained eye (because that's who's looking at it) like a phone that was used normally by someone who has done nothing wrong.
The transfer and backup system are pretty much the same mechanisms.
Restoring is probably order of ~1 hour to go through all the setup. Then some hours to sync any data and updates that need to be redownloaded, apps reinstalled, etc.
- Tasker is an automation app for setting up rules for triggers and actions. It allows extension apps to be created to add new triggers and actions.
- someone at one point made an extension to add an action for wiping or factory resetting when triggered
- there was an existing extension (or core feature) to trigger when certain signals are lost or found (e.g., wifi signals, Bluetooth LE beacons, etc)
So the idea is to carry a BLE beacon (any "item tracking" one works) on your keychain, and an unassuming faraday cage pocket alongside it. If you want to wipe your phone, slip the fob into the pocket, the signal disappears, and your phone wipes. And if you don't have the keychain on you, just refuse to open it right away, as when they put the phone itself in a faraday cage (to prevent it from being remote wiped), they cause the signal to be lost, and it gets reset.
Not sure if all the pieces still exist (I dont think the tasker extension for wiping existed outside a forum post...)
Perhaps less likely to go wrong. Would be nicer if you could leave phone in cage, and remove beacon while loading airport trays ("remove all electronics from their cases..."). the failure mode is only when you're going through security, and the fob is outside it's case on their instruction.
But you'd need to be able to leave your phone in the faraday cage pouch while going thru scanner, which is only ok if they don't notice (maybe they commonly don't?)
Isn't that the exact same situation here that resulted in felony charges? Border agent was given a duress PIN and wiped the phone for the owner. Now owner is charged.
Regarding the motivation for usbkill mentioned in the article: I too was motivated to think on this stuff in relation to my sense of injustice around Ross Ulbrecht, and wanting to think of some way that someone in his position could avoid getting caught. One creative variant in my thinking involved embedding the BLE beacon inside a rubber ball that could be launched and lost track of. Or maybe embedded in heel of a shoe and ditched in transit haha
They're also now well aware of the GrapheneOS duress PIN/password feature. It was designed to work against an attacker aware of it by acting as a deterrence. If they're aware of the feature, it discourages them from trying to coerce a PIN/password and attempt to unlock with it. We aren't fond of features depending on an attacker being unaware of them and this isn't one of those.
Pixels have a high quality secure element enforcing a maximum of 20 unique attempts to derive the encryption keys for each separately encrypted profile. There's also very aggressive rate limiting between the attempts. It filters out duplicate attempts by temporarily remembering the previous 5 unique attempts to make the rate limiting more usable. A misremembered PIN/password repeatedly entered over and over will only use up 1 attempt.
Android does have standard support for enabling wiping after N attempts and an open source app can be used to set a configurable limit rather than specifically after 10.
"PAGINA INTERDETTA DAL CENTRO NAZIONALE PER IL CONTRASTO DELLA PEDOPORNOGRAFIA ONLINE (C.N.C.P.O.)"
“PAGE BLOCKED BY THE NATIONAL CENTER FOR COMBATING ONLINE CHILD PORNOGRAPHY (C.N.C.P.O.)”
Oh, we live in an interesting age.
(That's one of the reasons why it's trivially easy for foreign visitors to China to bypass the Great Firewall.)
If you were on wifi, that's notably interesting.
(I used to do some travel patterns where taking a certain client laptop wasn’t an option. It was an absolute gigantic pain for the type of work I did, but it was just too risky to have a laptop seized and be expected to input credentials.)
There are vendors that sell the technology to adversarially access phone data, the "Before First Unlock" is the safest state a phone can be, but it's not infallible. The safest option is to have a burner or factory-reset phone with nothing on it, even if the hack succeeds.
A compromise to this is that many phones have a "lockdown" mode, where it isn't fully off but refuses to accept biometrics until a code/pattern is used to bring it to a more day-to-day mode.
It's less-secure than being fully off, but it also means if you do need to access your phone you can do so more-quickly.
Sad that we have to accept this as a risk of international travel, but here we are.
If they do take my phone (completely shut down, unlikely they'll be able to break in) and it's gone forever, that sucks, but then I get a new phone, restore from a backup, and move on with my life. Given that the probability of getting to this point is very low, I'm comfortable with the risk.
But sure, if I was at high risk of being detained at the border due to my profession, country of origin, ethnicity, etc., I'd probably look at this differently.
Morality and direct commonsense interpretations of law do not apply when there are literally unlimited resources stacked against you. But, assuming you can wait the potential ~10y to receive your device back that it will take to get your device returned to you, good on you. If you think that the current SCOTUS will rule in your favor, good on you.
The reality is, we live in a time where the most horrendous interpretation of the law is the one that will happen. And it won’t be in your favor.
The important wrinkle is that CBP’s published policy expressly guarantees that a person being admitted as a U.S. citizen won’t be denied entry solely because CBP couldn’t inspect the device. It doesn’t give lawful permanent resident (green card holders) that same explicit statement. Instead, it says refusal by a “foreign national” can be considered in an admissibility determination.
When interacting with border officials (or any LEOs, for that matter), be polite, don't get hostile or aggressive, but also be firm and don't volunteer any information that you're not required to give.
It's actually been on the books for a while (decades at least) that customs can search you at the border without a warrant even if you are a citizen.
This case seems to have become a big 'Trump bad' poster child (people are calling the US East Germany in these comments...), but if this exact scenario happened at least in the last two decades (I found an example upholding the searches from 2004) then it would at least be possible to charge them with deleting evidence. Even this probably would have been nothing if he refused to give up his password, not being required to provide a password has been upheld for years. They can seize your phone for some time but I'm unsure on the times they ask and then just let you move on when they find out your a citizen.
Then log in with another temp account and use that for border pass etc, and then after border checks log back into your normal account?
or have a good enough decoy or encryption system in place. Such as pressing a button to lock or replace key documents but keep the rest intact. So what looks like a sensitive document omits key information but still appears to be legit to observer.
Why would the bomb squad trust the box owner to help them defuse it? To understand the issue, you have to construct a proper analog.
But if it did, you'd still be on the hook for the bomb, even though technically the LEO set it off through incompetence.
Briefly: no.
Less briefly: <https://news.ycombinator.com/item?id=49060780> and <https://news.ycombinator.com/item?id=49060716> (from the grapheneos HN account directly).
Hell, I think a setup that doesn't wipe anything, but just drops you into a sanitized, isolated profile for the border agent to look at, would be fine for many users. Certainly you wouldn't want to use this in truly high-stakes situations where it's likely that your device will be confiscated no matter what, and analyzed to death, but for the simple "border agent wants to snoop on my data for a few seconds" case, it's likely sufficient.
(As always, risk analysis can be hard, humans are often bad at it, and not everyone's threat model is the same.)
Even a duress PIN which triggers predefined deletion of certain folders, messages and apps could reduce law enforcement exposure significantly.
Wiping the overall data on the device via a factory reset, OS recovery mode or duress PIN/password prevents recovering any of the data because it reliably wipes material needed to derive key encryption keys and also reliably wipes the encrypted disk encryption keys. Wiping the encrypted disk encryption keys alone would not be good enough because they're stored on the SSD so imaging the SSD and restoring it could preserve the ability to recover the data. The way the key material needed to derive the key encryption keys is wiped prevents recovery via imaging the SSD mainly due to the secure element.
There's already support for reliably wiping data at the granularity of Private Spaces and secondary users. Those have their own encryption keys and can be reliably deleted due to having their own Weaver slots in the secure element and other hardware-based security integration.
Apps can also assorted generate encryption keys in the secure element and use those to encrypt data where it can be reliably deleted via wiping the hardware keystore keys. That requires apps built to have granular storage and encryption of their data.
Despite it being possible to wipe a secondary user or Private Space reliably, the past existence of it and when it was wiped will be easily discoverable via the main Owner user and system data. Preventing discovery of those profiles having existed requires an overall wipe of the data. It isn't feasible to hide it without doing that and hiding it would involve a whole bunch of unreliable removal of data without a way to prevent recovery along with redoing a bunch of statistics and other metadata to hide that there was another profile until recently. For example, things like the battery and data usage stats directly refer to the profiles. Even hiding it from naive analysis not looking at the leftover data on storage would still require changing a bunch of things to hide it.
Making data deletion of the data reliable for a whole profile or the whole data partition also requires a reboot or shutdown. Consider how much data gets loaded into the page cache and many other forms of data in the Linux kernel and other processes. Consider how much linger around in various kinds of registers, etc. including outside of the OS itself. Reboot or shutdown has code to get rid of this and the device sitting there turned off or booting again also gets rid of it.
They were clearly going to hook his phone up to forensics software on a laptop and had done what they needed to do in order to justify it for their own policies. It would not make sense to set up everything they did simply to have someone non-technical manually sift through his apps. They have widespread access to forensic software and also more advanced software with exploits. They definitely have easy access to it at a major Atlanta airport. The adversary in this case is not a non-technical human but rather advanced software from Cellebrite who are fully aware of alternative operating systems and document information on it. Their documentation directly refers to GrapheneOS and has tables listing their (currently very limited) capabilities against it.
This story got widespread news coverage and is widely known about. That should help make it clear how important it is for features to work against adversaries aware of these kinds of features. Our duress PIN/password works against adversaries aware of it. If they don't coerce a PIN/password from someone or don't enter a coerced PIN/password because they know it could be in use then the feature has worked. We want to improve the feature with secure element rate limiting integration in the future so that an OS exploit cannot be used to bypass it. The secure element already prevents an OS exploit from bypassing the limit of 20 total attempts for deriving encryption keys with massively increasing delays between those attempts. It used to solely be based on delays with throttling quickly reaching 1 attempt per day after 140 failed attempts but now there are only 20 total unique attempts. The past 5 failed unique attempts are temporarily remembered and discarded when entered again rather than trying to use them again for usability.
I mean - yes? If you design a subtle duress pin that only hides certain things, users would have to choose what.
I myself want the bank apps, password manager and email to disappear without a trace, but I don’t care about the social media, photos or web browser history. Other people, though, will have different priorities.
For the OS disk encryption, it uses separate randomly generated disk encryption keys for the main user, secondary users and Private Spaces which are different forms of profiles. Those keys are stored encrypted with key encryption keys derived from the per-profile lock method combined with various forms of key derivation material from elsewhere.
The most important of the key derivation material for profiles is the per-profile Weaver token on the secure element which it uses to enforce rate limiting for decryption attempts (max 20 attempts per profile with rapidly increasing delays) and to provide extremely reliable deletion of the data. Wiping the weaver slot for a profile prevents deriving the key encryption keys which prevents ever decrypting the randomly generated disk encryption keys again. The randomly generated disk encryption keys are only stored once and get wiped via a special SSD secure erase command but that isn't nearly as good as the secure element integration. If the SSD is imaged before a wipe and then restored, the data still isn't recoverable because the secure element wiped what's needed to decrypt the disk encryption keys.
Reliably deleting data is a much different thing from fully hiding that anything was deleted which is drastically more difficult and not compatible with how things are typically done. It's pretty much impossible to stealthily delete a secondary profile since there's too much system and Owner user data referencing them including the package manager's state, battery stats, data usage stats and far more. It's possible to attempt to go through all of that and hide it including forging the other stats to mask what was removed but data cannot be reliably deleted in a fine-grained way, especially on top of a modern copy-on-write or log structured filesystem combined with an SSD controller doing wear leveling.
An SSD controller will redirect writes to less written NAND than what is now being written to level out usage. That relies on it being aware of free storage to choose from that instead which is the purpose of TRIM. A modern SSD will also very proactively move around data rather than only redirecting writes to free space with less wear. It will identify the data that's rarely or never written and move it to the most written areas of the SSD to free up the space it was on for the most written data. Having 2TB of used space that's rarely ever touched, 1TB of a heavily written database and 1TB free will not only use the 2TB of active space for wear leveling with a modern SSD controller design. It will use the whole 4TB for it.
A modern copy-on-write or log structured filesystem doesn't write to the location where the data was originally but rather elsewhere. Android uses f2fs which is log structured which heavily helps with wear leveling at a higher level and also provides the ability to turn off data persistence temporarily and then roll back to the point it was turned back in an incredibly efficient way. Android uses that incredibly efficient rollback feature as part of A/B updates to preserve the ability to fully roll back an OS update which doesn't end up working properly until after it reaches the lockscreen successfully.
An app regularly appending data to a file, overwriting data in it or replacing the whole file is leaving data around all over the place. A decision can't simply be retroactively made to reliably delete the data for that file or the overall app. It would have had to be set up in a way that it can be reliably deleted. Without that, the whole secondary profile it's in is going to need to be deleted to reliably delete the data. If it's not in a secondary profile, the whole device needs to be wiped for it.
That's not what we were talking about. This is the full sentence we wrote:
"Reliable deletion of data requires setting it up to be reliably deleted later on by having it encrypted on storage with keys which can be reliably prevented from ever being obtained again."
What we're saying is that in order to have fine-grained deletion of data, it has to be encrypted with fine-grained keys with hardware support for deleting those keys reliably. Reliable deletion of data should also not be confused with stealthy deletion of data which is not generally possible for the kinds of data being discussed.
> I myself want the bank apps, password manager and email to disappear without a trace
You can put all of this into a Private Space or secondary user where it can be reliably deleted as a whole. There will be no way to recover any of the data if the profile is deleted. We have a planned feature for either a toggle to make the duress PIN/password only delete specific secondary profiles or more likely a 2nd duress PIN/password with that different purpose.
Deleting secondary profiles will reliably prevent recovering any of their data, at least after a reboot or shutdown. The best way to do it would be deleting them and then rebooting where the main user and secondary profiles not included in the deletion would still be there after the reboot. Without the reboot, it's unrealistic to reach the point where it's truly highly reliable. The OS does purge the keys for a secondary profile but a lot lingers around in system processes, page cache and elsewhere. If you delete a secondary profile with the goal of preventing data recovery then it's a good idea to reboot afterwards.
Dividing things up into secondary users is the way people can set up having fine-grained reliable deletion of the data. We can expand our duress PIN/password feature to support working with that.
It should be noted nothing about wiping secondary profiles is stealthy. It's very obvious there were profiles and that they were wiped. It can be determined when it happened and approximately how much data was deleted too. The data and filenames are unrecoverable but a fair bit of metadata on the sizes of files, etc. can be recoverable because that metadata is globally encrypted rather than per-profile encrypted. If you want to delete absolutely all traces of it in a reliable way, an overall wipe of the device does it extremely well. If you delete a profile then nothing encrypted by it can be recovered but what about all the evidence of it existing in the system and Owner user data? It's in the battery statistics, data usage statistics, package manager metadata and many other places. It can be purged from those but absence of data can be detected, and there's the usual problem of simply not being able to reliably delete data from computers in a fine-grained way. It's too late to reliably delete data from a file after the file has been regularly rewritten and modified.
Deletion needs to happen through deleting the keys used to encrypt all data which was ever stored in the file, so it would have had to be set up with that in advance. To reliably redact data in a file, the file would need a dedicated hardware-backed key with a new one being generated and the old one wiped as part of redacting data. Reliable wiping of a profile or the overall device works because it's all encrypted with filesystem-based full disk encryption using keys which can be reliably deleted. Profiles have fine-grained encryption for filenames and file data.
You cannot retroactively decide you want to reliably delete the data of a specific app and then do it. It's already spread all over the place. You'd need to wipe the whole profile or the whole device if it's not in a secondary profile. The OS would have had to set up a dedicated encryption key for that app's data with hardware support for deleting only that key by itself. Apps can do this and Signal is an example of app doing it which prevents backing it up via the OS backup system without also using their own backup system too.
Reliably deleting data at the scale of the whole data partition, a secondary user or a Private Space is fully supported but requires a reboot or shutdown to truly complete it.
After wiping key derivation material needed to obtain the key encryption keys in multiple ways and wiping the encrypted disk encryption keys, the OS can still access the data. It still has data in the page cache, in registers and elsewhere. There are still a bunch of system processes with data tied to what was removed. The OS is still fully functional after the nearly instant wipe of everything needed to recover the data again. It can still access all data other than what's encrypted with hardware keystore keys and not currently decrypted.
The wiping process for the duress PIN/password is completed with a shutdown which tears down everything, zeroes memory and provides at least a small time window where the hardware is powered off too. A reboot would also work and the boot process has explicit zeroing of memory, registers, etc.
We decided to use shutdown for the duress PIN/pasword but a reboot is a valid approach too. Our locked device auto-reboot timer feature we first shipped in 2021 relies on the zeroing done by GrapheneOS for both the process of the OS tearing down and then again during booting to return the device to Before First Unlock state.
> also create a semi plausible artificial profile to hide the deletion event.
It isn't feasible to fool forensic software so it largely wouldn't work against state actors. It nearly certainly wouldn't have helped in this situation in the news. They aren't reliant on a non-technical person sifting through a phone. They'll just hook it up to a laptop and follow the data extraction procedure which involves enabling ADB. The software is aware of GrapheneOS can guide people through dealing with anything different about it. They've had a lot of trouble with extraction via ADB for GrapheneOS since the vulnerabilities they exploit via ADB keep getting patched or blocked it exploit protections but it isn't realistic to block extraction with them having the PIN/password. They could just enable the encrypted backup service in the OS instead and then use CLI tools to extract the data from there with the seed phrase. They don't do that because they want everything rather than only nearly all app data. They also have special code to deal with apps such as Signal with their own layer of data encryption since the data taken from their app data directory is nearly all useless by itself.
There's also quite a difference between wiping and rebooting into a not very plausible environment with decoy data set up by the user in advance compared to not properly wiping and giving access to a decoy profile. Bear in mind the OS can still access nearly all data after the wipe until a reboot. It could make a best effort attempt at purging as much as possible from memory, but the OS is not designed to continue functioning with all of the data disappearing. It can't just wipe all loaded encryption keys without crashing and rebooting anyway. It also has a ton of data still around in caches and elsewhere. We don't want to just do a best effort job cleaning up as much as we can but rather reliably prevent recovering any of the deleted data.
We could definitely add a duress PIN/password which wipes only specific secondary profiles, reboots and has the device still functional with whatever data was in the main user still there. That's a feature we can add, but it's important to note that it will not hide that there was deletion of data. It's easy to detect, and it's not feasible to hide that it happened. Many steps can be taken to make it less obvious, but it will still be easy for software aware of it to detect. Even a massive overhaul designed to perfect it would not address the SSD itself giving away what happened for more advanced analysis.
We aren't going to add a decoy profile compromising the security of the device and providing a way to recover data in a state where it isn't at all unrecoverable yet. We did already plan to consider a 2nd duress PIN/password which only wipes specific secondary profiles, but we need to make it clear that it cannot stealthily wipe them to users.
A duress code might let me wipe my phone when someone holds a gun to my head and demands I unlock it. Problem is, there’s still someone holding a gun to my head.
The actual solution is cloud backup + re-image after the border.
but that's not the point, the point is to not wind up in court by presenting a phone that no long contains evidence but seems plausibly like your phone so doesn't arouse suspicion
Evidence Tampering
I'm imagining a duress code that erases select files and any indication that there was ever a duress code set up in the first place.
> Tunick provided this code to an agent, who entered it on the phone, after which “the screen went blank, flashed several times and the phone appeared to restart.”
Mines (in wars, as implied by "solider") aren't illegal. Also even for the first example there are certainly improvised explosives you can set up that isn't criminal to create or set off, fireworks for instance. Same with a barrel of gasoline. It's certainly a crime to use it to kill someone, but that's my point. By OP's logic it's not the person who set it up's fault, it's the person who triggered it.
I don't think it'll be very easy to get out of liability in this case. The duress PIN is a feature explicitly designed to delete all data when it is entered, especially in cases of coercion like this. There would be more plausible deniability if officers had simply discovered it somewhere and tried it on their own, but in this case it was knowingly provided directly in place of the real PIN.
Destroying potential evidence before suspicion is not a crime. Destroying it once under suspicion is a crime. So anyone can destroy their data at their hotel room even just before entry even if the data contains evidence of crimes. Of course the courts could take that into evidence to support the argument that there were crimes but it would not be a crime in and of itself.
Do you have thoughts as to how the courts would debate the deletion that you could present on a similar intellectual plane?
Not to say that I personally agree with either of those cases. But what is considered crime can get pretty unfair when it comes to the authorities thinking you did something wrong.
Did they though? Was there an actual investigation going on?
is what he was charged with (a)
see also: https://en.wikipedia.org/wiki/Border_search_exception
I think the issue will fall on whether the encrypted data on the device (or its decrypted counterpart) counts as property. The rest looks pretty clear-cut to me.
Are you sure about that?
The google search required to find the answer ("federal statute for destruction of evidence") is shorter than your question here.
"Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry..."[0]
If so, on that assumption, should no one ever be able to erase data on their hardware? Is it schrodingers guilt, that you're simply not guilty until someone looks, and then you are?
And if not, you haven't answered GP's question.
Legal cases are adjudicated by human judges who have been dealing with scenarios like this for thousands of years, since long before the invention of software and laptops, and who are not the least bit challenged when presented with strawman scenarios like the one you called out.
Did he know he was suspected of something? Was he suspected of something?
Edit: 18 U.S.C. § 1519 doesn't seem to cover this (unless it covers the act of setting up the duress PIN in the first place as "altering"). § 2232(a) covers actually knowingly providing the duress PIN.
> Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed under title 11, or in relation to or contemplation of any such matter or case, shall be fined under this title, imprisoned not more than 20 years, or both.
That covers the first part of my comment. As for the second part, there is 18 U.S.C. § 2232(a) (destruction or removal of property to prevent seizure)
> Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government's lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both.
IANAL, but the encrypted data on the device could be considered property, and the act of providing the duress PIN in place of the real one could be considered a knowing action for the purpose of preventing the government either from continuing to hold that data under its control, or from seizing the data into its control in the first place (since the data was never decrypted).
There was a federal investigation going on?
e.g. in Hungary the authorities treat it as a felony to possess an equipment that can record video or sound and it's not obvious when looking at it. 2-8 years in prison for mere posession, i.e. even if it's turned off in your backpack. random nonsense that if it can also make phone calls then it doesn't qualify (the above is the law paraphrased).
You know, the same way we would be rightfully outraged if Apple was allowing applications to turn on the web cam without signaling to the user that the camera is engaged.
That’s all aside from the fact that Hungary was run by authoritarian minded people. But just as I think it should be illegal for cameras installed in glasses to work without an indicating light, I don’t see how this recording light situation you are describing is really such a highlight of Orban’s excesses.
UK is same.
*https://www.nbclosangeles.com/news/local/la-family-120-days-...
*https://www.militarytimes.com/news/your-military/2026/08/20/...
Republicans might as well rename their party the Democratic Fascists of America at this point.
I'm reading Stefan Zweig right now, he was a prolific Jewish author from 1890s until his suicide in 1942, living as an exiled Jew from Austria in South America. He has written many words, over a century ago, that would support your claim.
The current situation is a result of a nearly unanimous Washington consensus regarding this issue. Not one party vs another.
That's nonsense and the voting record proves you wrong.
Please link to any privacy related vote that hurts the public where "both sides" voted for it.
Of course, Snowden gave us definitive proof back in 2013 that 'rights' were being systematically violated for arbitrary purposes. But, no one dares be objective about world events lest they accidentally seed territory to their enemy! "But we can use that for XYZ if we get in!" says the American with glee.
If Americans could be honest with themselves, they would realize national collapse is imminent within a decade. The only path forward is treating those around you with respect such that community is preemptively fostered before it is invariably required for survival.
The cognitive dissonance is staggering.
At the same time, there is a complete lack of cognitive dissonance in this thread that is even more staggering.
The American healthcare system is fundamentally broken on top of this. How is forcing me to pay into a system that is broken and a system I won't use, how is that freedom? Americans spend more money than any other country only to recieve worse outcomes. You can walk into an American hospital, tell them you have just returned from west Africa where there is an Ebola outbreak, and tell the nurse you have Ebola symptoms, and that nurse will send you home with a perscription for antibiotics that don't work against viral infections at all. And then you die. I'm citing a real example that actually happened.
https://abcnews.com/news/story/ebola-patient-released-texas-...
Given the state of American healthcare, I wouldn't go to an American hospital even if near death. I'd try to get myself to a hospital in some other country before going to an American one.
"One of the most significant challenges in combating the rise of sugary drink consumption in Latin America is the lack of stringent regulations on advertising and the availability of these products. While some countries have introduced taxes on sugary beverages and implemented labeling regulations, these measures are often met with strong opposition from the beverage industry. The industry’s lobbying efforts have been effective in delaying or diluting such policies, leaving many children vulnerable to the adverse health effects of excessive sugar consumption."
https://latinamericanpost.com/science-technology/latin-ameri...
But this case is pretty clearly about negative rights (preventing the government from doing something) which based on the original Bill of Rights is pretty clear.
> The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
When you think about it, non-European migration into the United States actually does strengthen their national identity, because the core identity of America is trying to horde as much as you can and interact with your community as little as possible. It's a match made in heaven!
True freedom is shape shifting your identity to match whatever argument you feel like making.
1. Was there a lawful entitlement to the papers? 2. Were the papers protected private property? 3. Were the papers released to the wind intentionally? 4. If intentionally released was it expected that they would disappear or simply fall to the ground?
A couple easy technological analogies: 3. "Sorry, I gave you the wrong code by mistake." 4. "I thought it would go to a private guest mode, not delete everything!"