For exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs. Imagine booting the phone from a flash drive, making an encrypted image of the phone on said drive, and writing a fresh OS before reaching the border.

There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).

Some time ago, Android with a custom recovery could come close to that, but it was fussy and as far as I know, no longer viable. Increased use of TPMs for storing credentials seems to be at least one of the reasons.

It may be fun to fantasize about these things some times, but there is no technical solution to tyranny. Laws are not like code, intent matters. Ultimately if the intent is that the government wants to see your private data, hiding it in any way will be charged - it doesn't matter if you jump through hoops to avoid this specific instance.

This is a half-truth. In a full banana republic, technical compliance with the law will not prevent consequences for failing to do what the authorities want. In a jurisdiction with perfect rule of law, it always will. The USA is somewhere in between.

One of the laws that's enforced pretty well in the USA is the protection against unreasonable search. Most of the time, a search requires showing a judge evidence that the search is more likely than not to reveal evidence of a crime. Exceptions are narrow and specific; the government's options to punish someone who refuses to decrypt data at the border are limited to brief detention and seizure of the medium.

Not yet tested is the idea that erasing data on the spot satisfies the purpose of the border search exception, which is to prevent importation of things that are illegal to import. This case might address that question.

Unreasonable search is always under attack though. There are many instances today of cops forcibly entering a home claiming nothing more than a welfare check, or "we received a call."

Edit to add that its also more difficult than it should be to protect and exercise the right against unreasonable search. If a cop knocks on your door its a consent-based interaction. You can simply not respond, but if you do happen to crack the door they can and will look in for any signs to claim as probable cause. Further there are cases where a person stepped out to talk and when they turned around and walked inside the cop slid right in behind them and later claimed in court the open door was implied consent. (I don't have a link to the court docs unfortunately.)

>There are many instances today of cops forcibly entering a home claiming nothing more than a welfare check, or "we received a call."

Sure, but there are also many instances today of evidence getting thrown out in court due to cops not getting a warranty and poisoning the tree and all its fruit. Rights don't just enforce themselves, there are and have to be a number of layers to the onion to help reduce the violation numbers at each stage.

There's also plenty of examples of even if the evidence is thrown out, there's damage to life or property that is never made whole.

I'm personally less concerned with those cases and more concerned with evidence that ultimately is thrown out allowed them to build a case that otherwise would have gone nowhere.

Say they search a vehicle without consent or probable cause and find weed. Then they further investigate the person and find additional evidence they otherwise never would have found. That weed find may get thrown out but it doesn't always nullify the rest of the case, and if the DA is clever they simply wouldn't submit the weed as evidence at all.

Maybe a better example as a half decent defense attorney, or the judge, could get subsequent evidence thrown out there.

A cop pulls you over for a brake light. They decide to go fishing, asking where you're coming from or where you're going, looking for any inconsistency to pull on. Maybe they decide they smell something on your breath.

A well informed person would refuse to ask questions and help ensure the traffic stop can move forward with the ticket, the cop isn't allowed to hold you for longer than required for the initial offense.

Most people when asked questions, though, will answer. Most people asked to take a field sobriety test will oblige. None of that is required and all requires consent - the cop knows that and knows that few people will stand up for that.

Such fishing expeditions should be illegal and anything found should be considered inadmissible due to unreasonable search. When the professional trained in law knows that they can game the average person it should be unreasonable practice.

That's not really relevant this was about going to jail after police break the constitution. If we're talking about bad things cops do there's civil asset forfeiture.

Rights needing to occasionally be upheld by the courts wasn't my complaint though. Its cases where rights we're clearly infringed, at least I'd expect most citizens would agree, and courts uphold it because a person didn't say a particular phrase, for example, or because a "reasonable" cop would have seen a cracked door as implied consent.

>There are many instances today of cops forcibly entering a home claiming nothing more than a welfare check, or "we received a call."

And there are also many instances of the city being sued, those cops being sued, losing qualified immunity, losing their jobs, etc, because we do still have recourse when cops do the wrong thing.

If your rights were violated, you stand to get a big payout, and get the cops fired that violated your rights. We aren't powerless, yet.

> And there are also many instances of [...] those cops being sued, losing qualified immunity, losing their jobs

Not really, the data points the other way. Cops basically never have to actually pay for their wrongdoings. Over 99.98% of money successfully recovered from cases against police is paid out by the cities, not cops personally [1]. A considerable number of cops that are fired are also eventually rehired by the same department [2] or a different one [3]. So I don't think it's that clear that you "have recourse when cops do the wrong thing".

[1] https://nyulawreview.org/wp-content/uploads/2018/08/NYULawRe...

[2] https://scholarship.law.vanderbilt.edu/vlr/vol74/iss4/4/

[3] https://yalelawjournal.org/pdf/GrunwaldRappaportArticle_s6br...

[deleted]

It isn't foolproof though, and police and DAs have incentive to both work together and to look the other way.

Note I also didn't say the problem is rampant. I take issue that its possible at all, and that it isn't a 100% success rate of holding police to account, especially when most are required to wear body cameras today.

Can you link to some of these cases of cops losing qualified immunity? It's an area in interested in but I understand that to be a vanishingly rare outcome - like only in very egregious cases, not just for run of the mill rights violations.

In case this isn't a bot and simply someone unfamiliar with the internet search, here is a snippet from the Google AI results when searching for the phrase, "list of US court cases where police lost qualified immunity."

--------

A federal court denies qualified immunity when an officer’s conduct violates a clearly established constitutional right or when material facts remain heavily disputed for a jury. While appellate and district courts routinely evaluate these claims, absolute lists contain thousands of entries because denials typically happen at the lower or circuit court levels rather than as sweeping national precedent.[0]

Notable Federal and Supreme Court Cases Denying Immunity

Taylor v. Riojas (2020): The U.S. Supreme Court summarily reversed a lower court and denied qualified immunity to correctional officers who housed an inmate in shockingly filthy, human-waste-packed cells for days, ruling that the extreme conditions-violating the Eighth Amendment-needed no prior identical precedent.[1]

King v. Brownback (Sixth Circuit): The 6th U.S. Circuit Court of Appeals denied qualified immunity to members of a joint law enforcement task force after they aggressively tackled and beat an innocent man (James King) outside a convenience store when they mistook him for a suspect.[2]

Schroeder v. City of Des Moines (2022): The Eighth Circuit Court of Appeals ruled that three police officers were not entitled to qualified immunity after conducting an unlawful, suspicionless car stop and subsequent arrest based on an unverified temporary license plate.[3]

Glover v. City of Jackson (2024): A federal district court famously rejected a detective’s qualified immunity defense in a major civil rights action involving fabricated evidence and malicious prosecution, highlighting systemic flaws in the doctrine itself.[4]

[0] - https://ij.org/press-release/massive-new-study-reveals-that-...

[1] - https://leb.fbi.gov/articles/featured-articles/qualified-imm...

[2] - https://ij.org/case/king-v-brownback/

[3] - https://iowaappeals.com/uncategorized/three-des-moines-polic...

[4] - https://eji.org/news/federal-court-denies-qualified-immunity...

Or your family gets the payout because the cops killed you.

[deleted]

Border search exception lowers the requirements for judicial oversight.

"In United States criminal law, the border search exception is a doctrine that allows searches and seizures at international borders and their functional equivalent without a warrant or probable cause. Generally speaking, searches within 100 miles (160 km) of the border are more permissible without a warrant than those conducted elsewhere in the United States."

https://en.wikipedia.org/wiki/Border_search_exception

213 milion people live in this zone.

https://www.aclu.org/know-your-rights/border-zone

It's really crazy. If 2/3 of us don't have privacy rights then what are we even doing.

we're far closer to one side of that spectrum than the other. consider the retroactively legalized mass wiretapping, room 641A, NIST compromises, PRISM, 14 Eyes, the other Snowden revelations, etc

then consider this paired with the implementation of mass data sharing between the alphabet agencies, surveillance data sharing from private companies like Amazon Ring, Flock, Clearview, etc. and NSPM-7 ordering agencies to create JTTFs to target organizations like BLM

then consider the unmitigated use of force by federal law enforcement agencies like ICE

I think if this were 1995 your point might be fair but those days are unfortunately long gone

shudder. but, where else could we go? switzerland? my point being we need to try to get 1995 back. id gladly trade my iphone for a car phone.

Agree with the thrust of your comment, but I had to comment on this:

> In a full banana republic, technical compliance with the law will not prevent consequences for failing to do what the authorities want. In a jurisdiction with perfect rule of law, it always will.

I think you may be misunderstanding that many laws, even in fair, just societies, are intentionally designed to be flexible. The real world is so variable and messy that in many cases it isn't feasible for a law to be written such it can be unambiguously determined whether or not a specific action violated the law. Laws often rely on humans using context to judge whether something violates the spirit of a law, and in a just society, this is a good thing.

My point is that I don't believe the idea of "perfect rule of law" is sensible. Law is always necessarily a bit fuzzy and nebulous.

Theres a reason why the motto of banana republic leaders is: "For my friends, everything. For my enemies, the law"

I think I mostly disagree with this. "Technical compliance" is not and should not be the thing that a legal system is designed to incentivize, and should not be the criterion for "perfect rule of law."

I would disagree with you, because "technical compliance" is compliance with the letter of the law. You have complied with every explicit requirement of the law. If the law is insufficient then legislature is free to add a clause that bans whatever aspect you technically comply with that they don't like.

The alternative is complying with the spirit of the law, which is an eternal guessing game. Who knows whether it's legal or not, we have to wait for the Supreme Court to decide what Congress _actually_ meant. It implies that the law means something beyond what anybody bothered to actually write down, and nobody has any idea what that is until the Judiciary interprets it into "actual law".

What should be the thing that it is designed to incentivize, then? Compliance with the spirit of the law?

Having good technical tools won't fix a failing society, but they're still nice to have and they make state surveillance of its citizens just a little bit harder. I mean, where would we be without strong cryptography?

these are abuses of existing powers, rather than acting with reckless abandon

the government would have no ability to access the data if he didnt bring it on his person here.

hell, he could have just continued to not given his password and left his phone with them, too.

This is false. If you can image and wipe your phone on the plane before landing, and write those random bytes to a usb stick, the usb stick will appear blank, because encrypted data is noise. You land with a factory blank phone. You clear customs and get where you are going and restore your phone.

Substitute cloud storage for a USB stick if you do it at your departure hotel.

There are absolutely technical solutions to the implementations of tyranny. Otherwise we wouldn’t bother with encryption. Violence can’t solve math problems.

How do you solve it when they beat you for having a phone that doesn't look like they want?

Like whatever arbitrary thing they decide it should look like that day.

You can’t solve that in any case, but that has nothing to do with tech.

Normally I agree, but making the implementation initially ineffective is a good way to complicate more far reaching measures.

Americans aren't standing up against this, but they might have considerably more interest if the government was instead trying to ban encrypting data in cloud storage for everyone.

There's also just the fact it's ridiculous I can't have a spare phone ready to go in a few minutes and get it back exactly as I left it.

Yes, trying to solve a regulation or legal issue by some technical workaround will never work, you have to fight it at the same level, legally, or system-wise, otherwise, you will be like the person who tries to wash the stairs from the bottom all the way up, it rarely works, you gotta go up to down, collectively go against the matter rather than individually duct taping it for your own specific needs. In that example, it won’t be far fetched the same ones who made it illegal to wipe your phone to make illegal to install xyz OS or using abc protocol, in fact, that’s exactly what they are trying to do under the disguise of “protect the kids” and going after encryption or similar privacy related issues.

They would not be so vehemently against it if it did not work. There is a reason E2EE, duress passwords and similar technologies are under such intense assault these days.

Destruction of evidence as a crime goes back a long, long way. There's no precedent for making it illegal to install some OS or protocol the feds don't like. I don't particularly like what's being done to this guy, but what he did was pretty stupid. You can't be obligated to incriminate yourself but you aren't allowed to destroy evidence.

[deleted]

GrapheneOS has built-in encrypted backup and restore. It backs up the same data transferred by Google's device transfer feature for moving to a new phone which is nearly all app data, the data in the home directory, contacts and a bit more. Certain apps such as Signal encrypt their own data with another layer of encryption using a hardware keystore key. Signal's own backup system needs to be used for that, although it can just be used as a way to get data into the system backup.

It's worth noting wiping a device shortly before an anticipated search could also be considered destruction of evidence in the same way. It doesn't have to be done after a request for the data to be considered that.

> There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).

This was likely the best move for him to take. They could have held him for a while and wasted his time but eventually would have had to give him access to a lawyer and let him go. Unless they had a recording of him entering a PIN/password, they were nearly certainly not going to get his data from it. He very likely didn't gain anything from wiping it.

He did help every GrapheneOS user by spreading awareness of the duress PIN/password. It was designed around an adversary aware of it and therefore not wanting to attempt using a PIN/password obtained via coercion. In the future, we want to integrate the feature into the secure element rate limiting for key derivation so it can't be avoided by exploiting the OS.

> GrapheneOS has built-in encrypted backup and restore.

The backup tool on GrapheneOS doesn't work for a large percentage of app data. And it often silently fails to backup some data, so you don't even know where the gaps are.

There have been promises of a better solution for years, but I haven't seen any movement yet.

This has gotten much better fairly recently ime. My backups to WebDAV work most of the time and when it fails I get notifications. But it was quite bad for a long time so I sympathize with your point

> He did help every GrapheneOS user by spreading awareness of the duress PIN/password. It was designed around an adversary aware of it and therefore not wanting to attempt using a PIN/password obtained via coercion.

You added it by copying Blackberry[1]? But seriously how did you think of that feature?

Genius feature when you put it like that.

[1] https://discuss.grapheneos.org/d/40700-grapheneos-protection...

[deleted]

Those "nandroid" backups weren't "close" to that, they were literally that initially. Then, when Android phones started coming with the /sdcard partition mapped to the internal flash memory (a subdirectory of /data) instead of an actual SD card, the /data partition backup mechanism was changed to copy individual files into some sort of archive, but the end result remained the same.

You can still do it on modern Android devices, as long as the bootloader is unlocked. Yes, the file system is encrypted, but a modern custom recovery is able decrypt and mount it.

How many mainstream phones come with unlocked bootloaders? Just pixel right?

Fairphone

You have to ask yourself why this isn't possible anymore. Similar to how recording calls used to be possible but no longer. I don't know why it is but it is awfully strange that they keep tightening the belt on what we can do with our own devices.

I really really want this for GrapheneOS. The current backup situation is terrible and nowhere near being able to easily image and restore the entire phone (or at least user data).

Also, it is just a nice idea if you are prone to losing phones. Backups are good for all kinds of reasons.

There's a way simpler solution and it's just to leave your phone at home and put your SIM in a different handset without all your data on it

An increasing portion of phones are eSIM [0] only these days, and the difficulty of swapping can be weirdly-bad depending on provider.

[0] https://en.wikipedia.org/wiki/ESIM

But non esims exist still, and if you're that worried about security, you can get one.

Not forever though, and if you're an iPhone user, already current iPhones sold in the US are eSIM only. So in some number of years (depenfing on your device oldness tolerance), they will become obsolete eventually.

US iPhones don’t have sim slots at all anymore.

Can't one just buy some craphone for like $50? with whatever sim.

The whole problem as I see it is that people for some reason submit all their life to a device they can not control. And when it bites them they go all suprised.

PinePhone will boot off a microSD before the internal flash, so you could have a clean OS on the card and your real one on the flash. The SD card is under the back cover with the battery and SIM, so chances are they won't think to try to remove it.

It'd be less of a hassle to buy a burner phone to travel with. It's not a felony to not bring your main phone when leaving the country.

I agree. Here's my method.

I have my passwords on proton pass with 2fa. I back my pics to private cloud storage. I keep 2fa backup codes in my wallet.

Wiping the phone on a whim is a minor inconvenience. Full image restoration would be neat.

I've restored iPhones before, and it does seem pretty simple. Easier than PCs for sure. It's not instant, but the basic configuration is restored pretty quickly while the bulk data restoration happens in the background while you're able to use the phone.

What about banking apps and stuff? Does the device binding still work or do you need to set it up again?

Depends on the app and security setup. If it's using old school Symantec VIP Access, it will not survive a restore. If it is using TOTP from 1Password, it will. Not sure about other options, those are the two I am most familiar with. Thankfully I only have a single app these days relying on VIP Access.

It is not remotely simple. So much is lost on device change.

Isn’t this basically what you do with an iPhone. You reset/format it then it gets back to its original state with iCloud?

> ...making an encrypted image of the phone on said drive... refuse to unlock the drive

How is this any different than refusing to unlock the phone? It just seems you've added unnecessary extra steps.

As I understand it, the drive can thus be seized, and a potential loss of a cheap flash drive is a lower inconvenience than loss of the phone.

Think for a moment. What is the difference between giving them a password which wipes the phone and giving them a password which opens a blank phone?

It's the same thing. They punched in a code, they are presented with a wiped phone. Can they prove the guy gave them a distress password and wasn't simply carrying a wiped phone to begin with? No, but they just need to imply that is the reason to charge him with the felony.

> What is the difference between giving them a password which wipes the phone and giving them a password which opens a blank phone?

> It's the same thing. They punched in a code, they are presented with a wiped phone.

No, the behavior between the two is in fact visibly and obviously different.

The regular passcode unlocks the phone. The duress passcode reboots the phone and resets it. I know this because this is literally what previous articles said happened when they entered the passcode in regards to this case.

See for yourself:

https://www.youtube.com/watch?v=jcgnBjHOK2g

Tyranny does not care about "proof".

It doesn't even care about plausible deniability.

Best you can get away with is lack of suspicion. Have a secondary phone with some standard apps on that you use now and then so theyhave a history and just look like you are just not a technical person and read novels on dead trees instead. A lot of work but likely works.

are we seriously approaching a point where its quasi-illegal to not participate in the socials?

More like they've looked you up and the apps being missing would be a giveaway about the dummy phone

So it’s becoming illegal to not have the Facebook app installed on your phone if you have a Facebook account?

The best technical solution is one code opens to a phone that has things but isn't your actual phone, and then another code that opens to your real phone.

One is destroying evidence and the other is not.

Have you considered "no password set"?

>What is the difference between giving them a password which wipes the phone and giving them a password which opens a blank phone?

They don't get any indication that there was data there to be deleted, and you don't just factory reset but flash w an image of a clean phone that's been used. It has apps, it has accounts, it looks to the untrained eye (because that's who's looking at it) like a phone that was used normally by someone who has done nothing wrong.

[deleted]

Really? Does it take a long time to recover the phone? Haven’t really ever needed to recover a backup

Apple makes this very easy. I broke an iPhone and bought a replacement. If you have iCloud, you login to the new phone and you can see which backups you can recover from. If you are transferring a phone, say you upgraded, it’s even easier. You can also image the phone with a connected laptop and store it on a backup drive, which is nice to not use up iCloud limits.

The transfer and backup system are pretty much the same mechanisms.

Restoring is probably order of ~1 hour to go through all the setup. Then some hours to sync any data and updates that need to be redownloaded, apps reinstalled, etc.

Aha that is actually pretty long

That's mostly time for data sync in the background. It takes 5-10 minutes tops to have the phone working again, but longer to get all of the media and other data restored. Depends on how good your connection is.

> refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA)

… yeah I doubt that nowadays honestly

I mean, you could ship your real phone to w/e destination ahead of you and bring a $50 burner to the border. If you're a person of interest this won't work because they can monitor you and the destination but if you're a regular schmuck then a burner that never touches your private data or accounts and has a bunch of dummy stuff on it will get you past the border goons.

How about every civilian banding together and refusing to comply?

in before those fucking "I hAvE nOtHiNg tO hIdE" twats

I already refuse to comply with questioning at the border. Been being harassed and my non-citizen travel companions being SA’d by CBP for decades. Get with the program.

> For exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs.

You're always been able to backup and restore your iPhone to your local Windows PC or a Mac using free first party software from Apple.

Only app data, not the apps themselves. On restore you need an internet connection to redownload the applications.

> I wish smartphones could be imaged and restored as easily as PCs. Imagine booting the phone from a flash drive, making an encrypted image of the phone on said drive, and writing a fresh OS before reaching the border.

Backing up and restoring an iPhone is extremely easy. You don't need to imagine all of this flash drive or encrypted imaging stuff. You plug it into your computer and do a backup. You can then wipe the phone through the menus. Restoring from the same computer is easy.

Except apps themselves don't get backed up, only their data. So if you had any apps that are no longer in the app store or that came from outside of it (e.g. TestFlight or development builds), those won't be restored.