Hmm. It looks like the government asserts that they can seize a device if the owner does not provide a password. This is a good point and answers my search v. seizure objection above.
You say CBP is "empowered" to seize a device if the owner refuses to provide a password but I can't find a statute that authorizes it or precedent squarely saying the 4th Amendment allows this. The scope of the border search exception isn't settled. So the next argument available is that the executive is wrong and CBP does not have the constitutional authority to seize a device merely because the owner refuses to provide a password. That's obviously a much bigger argument and who knows if it would work, though this case sorta feels like it could become a marquee 4A case.
"The ACLU argues that the Fourth Amendment does apply in these situations, at least to electronic devices, because they contain so much private information. But the law is very unsettled, and the Supreme Court has not addressed the issue."
The cost of asserting your 4th amendment right in this situation is that you have to sue the US government after you leave the airport, or invoke the 4th amendment as your defence if they charge you with one or more crimes.
I think most people lack the resources and the wherewithal to do either of those things.
And in the process of asserting your rights you may inadvertently commit a crime for which the 4th amendment isn't a defence.
Like most self-defence, the best option is to avoid the situation entirely.
I don't know, that sounds like the kind of "I'm not touching you" defense that I don't think will convince anyone with common sense. It's obvious the wipe turned a search that could potentially find something into a useless search, so I don't see why the two should be treated as equivalent.
common sense is that CBP should not be searching citizens phones in order to pick a kill list for ICE to go killing first amendment protected protestors.
it's ridiculous on the face of it that that guys phone should be searched at all
I would have thought the fourth amendment not having specific geographical boundaries, but rather applying generally would have been common sense too, but here we are with border patrol being able to force you to reveal your PIN code just because you transited a border.
Imagine a safe containing sealed envelopes written in a code that only the owner understands.
The police ask for the combination.
The owner provides a combination that opens the safe, but the safe’s security mechanism first destroys its contents. The police can now inspect the safe but there are no documents left.
Even if the documents had remained, they would still have been written in an indecipherable code unless the police also had the codebook.
This person was complicit with the search: he gave the police access to search the safe.
You're making two arguments here, and I'm not a lawyer, but I don't think any of them would convince a judge.
> The owner provides a combination that opens the safe, but the safe’s security mechanism first destroys its contents. The police can now inspect the safe but there are no documents left.
> This person was complicit with the search: he gave the police access to search the safe.
The problem is that it's very obvious the police didn't want access to the safe because they like opening safes but to get the documents inside. The person denied that intent.
> ... written in a code that only the owner understands.
> Even if the documents had remained, they would still have been written in an indecipherable code unless the police also had the codebook.
This is an orthogonal argument basically saying "if the documents had also been encrypted, then there would have been no difference between destroying the documents and just leaving them encrypted".
First, that's not what was the case in the original situation - there is nothing saying there was secondary encryption on the phone.
Second, obviously, destroying documents and encrypting them is not equivalent because in the second case there is still an option to try and brute-force the code or try to decrypt them in another way.
> there is nothing saying there was secondary encryption on the phone.
A GrapheneOS phone stores its files encrypted. The PIN is not itself the encryption key; it is used, together with a high-entropy secret protected by the Titan M secure element, to derive the material needed to unlock the randomly generated filesystem-encryption keys.
The duress PIN does not overwrite every file. It irreversibly destroys the multiple layers of key material and encryption metadata needed to decrypt the data, making any encrypted remnants effectively unreadable.
A hypothetical, extraordinarily powerful quantum computer could theoretically decrypt the remaining ciphertext by searching for the encryption keys.
The language in the statute of what constitutes "destruction" is very broad and clearly covers IMO giving a self-destruct password to someone who you know will try to enter it.
"Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both."
But I'm curious what the officer specifically requested. If the officer just asked for "the pin code", without explaining what they were trying to do or which pin code, then it seems he did comply: he gave them a pin code that gives them access to the [cleaned] phone.
It doesn't matter. Providing a PIN that will cause an officer to inadvertently delete data clearly is covered by the statute:
"Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure .. takes any action ... for the purpose of preventing or impairing the Government’s lawful authority to take such property ..."
This is a (terrible) semantic argument that will never work in any Common Law legal system.
CBP is trying to gain access to the files contained in the system.
The files in question were functionally accessible to an authorized party (the owner, GrayKey or Cellebrite acting with judicial authority, etc)
The actions undertaken by Defendant during this investigation (which Defendant was obviously aware of and participating in) permanently impaired the ability for any party to access these files. Any reasonable person, or more importantly, a sworn technical expert, would agree with this.
Specifics here are irrelevant: feasibility of access doesn't change the intent or effect of the act in question. Files existed in every reasonable characterization, now they don't.
This is functionally the same as artfully convicing the officers to light a bunch of seized documents on fire, or to open a booby trapped container that is known (and intended) to effectuate the destruction of its contents.
Hmm. It looks like the government asserts that they can seize a device if the owner does not provide a password. This is a good point and answers my search v. seizure objection above.
You say CBP is "empowered" to seize a device if the owner refuses to provide a password but I can't find a statute that authorizes it or precedent squarely saying the 4th Amendment allows this. The scope of the border search exception isn't settled. So the next argument available is that the executive is wrong and CBP does not have the constitutional authority to seize a device merely because the owner refuses to provide a password. That's obviously a much bigger argument and who knows if it would work, though this case sorta feels like it could become a marquee 4A case.
"The ACLU argues that the Fourth Amendment does apply in these situations, at least to electronic devices, because they contain so much private information. But the law is very unsettled, and the Supreme Court has not addressed the issue."
https://www.aclumaine.org/know-your-rights/electronic-device...
The cost of asserting your 4th amendment right in this situation is that you have to sue the US government after you leave the airport, or invoke the 4th amendment as your defence if they charge you with one or more crimes.
I think most people lack the resources and the wherewithal to do either of those things.
And in the process of asserting your rights you may inadvertently commit a crime for which the 4th amendment isn't a defence.
Like most self-defence, the best option is to avoid the situation entirely.
Just being silly. Owner gave permission (and the pin code) that will give them access to an empty phone. No search refused.
I don't know, that sounds like the kind of "I'm not touching you" defense that I don't think will convince anyone with common sense. It's obvious the wipe turned a search that could potentially find something into a useless search, so I don't see why the two should be treated as equivalent.
common sense is that CBP should not be searching citizens phones in order to pick a kill list for ICE to go killing first amendment protected protestors.
it's ridiculous on the face of it that that guys phone should be searched at all
This is an absurd statement. A “kill list”? Please.
I would have thought the fourth amendment not having specific geographical boundaries, but rather applying generally would have been common sense too, but here we are with border patrol being able to force you to reveal your PIN code just because you transited a border.
Imagine a safe containing sealed envelopes written in a code that only the owner understands.
The police ask for the combination.
The owner provides a combination that opens the safe, but the safe’s security mechanism first destroys its contents. The police can now inspect the safe but there are no documents left.
Even if the documents had remained, they would still have been written in an indecipherable code unless the police also had the codebook.
This person was complicit with the search: he gave the police access to search the safe.
You're making two arguments here, and I'm not a lawyer, but I don't think any of them would convince a judge.
> The owner provides a combination that opens the safe, but the safe’s security mechanism first destroys its contents. The police can now inspect the safe but there are no documents left.
> This person was complicit with the search: he gave the police access to search the safe.
The problem is that it's very obvious the police didn't want access to the safe because they like opening safes but to get the documents inside. The person denied that intent.
> ... written in a code that only the owner understands.
> Even if the documents had remained, they would still have been written in an indecipherable code unless the police also had the codebook.
This is an orthogonal argument basically saying "if the documents had also been encrypted, then there would have been no difference between destroying the documents and just leaving them encrypted".
First, that's not what was the case in the original situation - there is nothing saying there was secondary encryption on the phone.
Second, obviously, destroying documents and encrypting them is not equivalent because in the second case there is still an option to try and brute-force the code or try to decrypt them in another way.
> there is nothing saying there was secondary encryption on the phone.
A GrapheneOS phone stores its files encrypted. The PIN is not itself the encryption key; it is used, together with a high-entropy secret protected by the Titan M secure element, to derive the material needed to unlock the randomly generated filesystem-encryption keys.
The duress PIN does not overwrite every file. It irreversibly destroys the multiple layers of key material and encryption metadata needed to decrypt the data, making any encrypted remnants effectively unreadable.
A hypothetical, extraordinarily powerful quantum computer could theoretically decrypt the remaining ciphertext by searching for the encryption keys.
The language in the statute of what constitutes "destruction" is very broad and clearly covers IMO giving a self-destruct password to someone who you know will try to enter it.
"Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both."
I know intent is a thing in law.
But I'm curious what the officer specifically requested. If the officer just asked for "the pin code", without explaining what they were trying to do or which pin code, then it seems he did comply: he gave them a pin code that gives them access to the [cleaned] phone.
Then the officer destroyed the property...
It doesn't matter. Providing a PIN that will cause an officer to inadvertently delete data clearly is covered by the statute:
"Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure .. takes any action ... for the purpose of preventing or impairing the Government’s lawful authority to take such property ..."
My understanding is the duress pin deletes encryption keys, but leaves the property untouched.
This is a (terrible) semantic argument that will never work in any Common Law legal system.
CBP is trying to gain access to the files contained in the system.
The files in question were functionally accessible to an authorized party (the owner, GrayKey or Cellebrite acting with judicial authority, etc)
The actions undertaken by Defendant during this investigation (which Defendant was obviously aware of and participating in) permanently impaired the ability for any party to access these files. Any reasonable person, or more importantly, a sworn technical expert, would agree with this.
Specifics here are irrelevant: feasibility of access doesn't change the intent or effect of the act in question. Files existed in every reasonable characterization, now they don't.
This is functionally the same as artfully convicing the officers to light a bunch of seized documents on fire, or to open a booby trapped container that is known (and intended) to effectuate the destruction of its contents.
IMO people are better off knowing their actual rights in a US airport than trying to outsmart the US government.