Posted by floathub 11 hours ago
So, in both cases the government wouldn't have access to the contents of the phone
[0] https://arstechnica.com/tech-policy/2020/02/man-who-refused-...
> Courts have generally found that compelling individuals to provide their numeric or alphanumeric passcode is potentially testimonial under the Fifth Amendment, as it forces the defendant to reveal “the contents of his own mind.” In Re Grand Jury Subpoena Duces Tecum 670 F.3d at 1345; see also U.S. v. Apple MacPro Computer, 851 F.3d 238 (3d Cir. 2017). It is analogous to compelling production of the combination to a wall safe, which is testimonial, as opposed to surrendering the key to a strongbox, which is not. See Doe v. U.S., 487 U.S. 201, 220 (1988). However, even if a court finds that providing the passcode is “testimonial,” it may still fall under the “foregone conclusion” exception
https://www.nacdl.org/Content/Compelled-Decryption-Primer
In short, you can't be compelled to give up the code in a dragnet attempt to find evidence against you (e.g. a boarder guard can't riffle through your text messages to see if you might have done something illegal), but if it's already certain that particular evidence exists on the device as a result of other evidence, they may be able to compel you to give up your passcode.
Note though that the cases where this has come up are very few and far between, and there isn't a super clear overriding precedent to follow.
In general though, the best choice here is to say nothing at all and work with a lawyer to figure out how to proceed.
Either way the USA needs to stop abusing its citizens. The people need to take back control over the court system. Way too much abuse is happening here. Land of the free no more.
<https://news.ycombinator.com/item?id=49060780>
(From the HN GrapheneOS account about a month ago.)
We were talking about an attacker taking an image of the SSD prior to it being wiped not helping them because information needed to derive the key encryption keys is gone from the secure element. It similarly doesn't help them to do a brute force on a server farm since they're rate limited by the secure element. It only allows 20 attempts and has rapidly increasing delays between those. There's also hardware bound key derivation but that only helps improve the strength of a decent password. The secure element rate limiting makes even a random 6 digit PIN highly insecure unless an attacker can exploit the secure element.
(Very much appreciate your active participation here.)
OP is talking about just backing up what you need off-phone and then wiping it.
I would not present a phone to customs that had clearly just been wiped.
It's legal to refuse to provide a PIN/password in the US. He's a US citizen so they couldn't refuse him entry. If he wasn't then the result would be getting deported.
It likely would have been a much better decision to refuse to provide the PIN/password and rely on the encryption and device security instead. He could have done a reboot or shutdown in advance but even without that it would have done it automatically via the locked device auto-reboot timer. The secure element only allows 20 attempts for key derivation with rapidly growing delays between those. If he had a strong passphrase then even a secure element exploit wouldn't obtain the data protected by it.
That kind of thinking has landed a whole lot of people in prison.
Is it right? It makes no difference, Customs can make your life miserable, that's just the reality of it, always has been and it can't have gotten better in recent times.
You can try this "gift link" to the article: https://www.nytimes.com/2026/08/21/us/politics/samuel-tunick...
But the man was also hated by the cops because of his activism. They were going to catch him for something, some day. This incident just provided the necessary excuse to lock him up.
It is pretty clear to me that law enforcement conspired to abuse a border crossing to effect basically an unconstitutional search ("fishing expedition"), which it would never have gotten a warrant for.
This is them being spiteful after that whole thing failed. Note how law enforcement basically admits this on the record. The whole thing is a disgrace; every decisionmaker involved in this should be sacked immediately.
This also doesn't even get to the more important point: If you don't have the contents of the phone you have literally no evidence of a crime being committed, other than the one they invented post-facto: "Deleting data that could hypothetically be incriminating, not in any specific way but just generally, maybe".
That’s the crux of the matter, isn’t it? If there was no suspicion whatsoever, hence no investigation, then he couldn’t possibly obstruct it.
People have gone to jail or have been executed for less than a glitch. Theoretically a highly charged particle from space could've messed with exactly the right transistors exactly when entering the correct PIN and trigger the wipe process. There is no way to prove that didn't happen. But you don't need that kind of proof.
The fact phones don't usually wipe themselves will be plenty good for a judge.
Btw: Regardless of the above I support this guy's right to protect his private data from baseless and unreasonable searches. He should not be charged with a crime.
funny reading this (don't disagree) and then also reading on HN how China is "bad" this is some gestapo shit but not surprising that it is getting normalised ...
Excessive border patrol power has been around in the USA for ages now, it's all part of the post-9/11 package. I don't think many Americans even know they live in a zone where the border police can do shit like this, even if they haven't left the country, as international airports are usually near big cities, and they have a wide border zone around them. This stuff only really makes it into the news when it happens to one of the "good guys".