That's a misconception. Border/immigration agents can operate inside this zone, including making stops with reasonable suspicion or running checkpoints where everyone is stopped with no suspicion. The checkpoints are limited in scope, and do not provide authority for searching electronic devices. Some people, including a couple dissenting supreme court justices do feel the checkpoint part violates the constitution.
That's distinct from the border search exemption, which allows inspection of everyone and everything crossing the border. It only exists when someone is actually crossing the border and does not allow CBP to stop or search people who are not crossing the border.
Seems like so far it didn't create any problems, so public is ok with that.
From Chief Justice Roberts in Riley v. California: "One of the most notable distinguishing features of modern cell phones is their immense storage capacity. Before cell phones, a search of a person was limited by physical realities and tended as a general matter to constitute only a narrow intrusion on privacy."
Because they had direct experience with tyranny and exploitation, and documented their response to that in the US founding documents. We care because if you don't learn from history, you're doomed to repeat it. Which is pretty much what's happening right now.
Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password.
How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password does a wipe based on location? Either way, the user complied, and did not take action to wipe their device.
On the other hand, I'm worried that the publicity will only make explicit targets out of GrapheneOS users, and that you would only be using it "if you have something to hide".
With this publicity and the coming Motorola phones, there's reason to be at least a little optimistic.
"Give us the PIN for your phone"
"I don't want you to search my phone, and I want to talk to my lawyer"
"If you don't comply, you're going to be in a lot of trouble"
"Can I please just go, I don't want to answer questions or be searched"
"If you don't comply we will seize your phone and detain you indefinitely until we can unlock your phone!"
"I want my lawyer."
"Just tell us the PIN and you'll be on your way. Otherwise it's gonna be bad."
"Look if I have no choice my PIN is 1234, but I don't want you searching my phone without my lawyer present."
...
"Hey! We tried to search your phone and the phone wiped itself! You're going to prison for destruction of evidence!"
A duress password isn't a booby trap. Nothing was damaged except for the fragile egos of the man-children who weren't able to bully someone into giving up their wrong-think.
However, did that evidence really exist? And if it did, was it for something else? Perhaps, the guy just worried about something far more mundane being discovered? We shall never know.
Think Schrodinger's password.
Courts have been fairly tolerant of law enforcement using pretexts like that to expand their powers.
I'm not taking sides here, I just wanted to make that clear.
And you should understand that they can lie to you. That's OK and legal, but you cannot lie to them.
forensics will reveal the other partition(s), and then you're in the exact same position having to answer "what's the other partition, provide the password"
And ongoing publicity as the trial happens.
https://en.wikipedia.org/wiki/Phantom_Secure#Law_enforcement...
TBF, similar mindset if I ever attend defcon, etc. as well.
US Government targets Cop City protester over phone operating system
wiping the device before carrying it across the border seems essentially identical to me. like, saying "you can't wipe it when searched" would also imply "you can't have an empty device when crossing because it may have been wiped before the search to avoid having your data searched" since people can (and often do) do that for exactly that reason.
that may very well be what they want / what they are trying to legally allow during searches, but it also seems like it'd raise a hell of a lot more outrage. it's essentially claiming all citizens are under full legal hold all the time, if they ever intend to leave the country for any length of time.
The owner of the phone doesn't know that. They have no control over or insight into the officer's brain to know what they'll do. The officer might suspect the phone-wiping functionality exists and decide not to enter the password. If we start talking about ultimate causes then judicial matters become infinitely complex. What immediately caused the phone being wiped is the wrong password being entered by the officer.
i pray that sense doesnt erode
Fed: "give us your PIN or else"
me: "528491"
Fed: <types 528491, presses OK>
me: "no! 528419, I meant 528419!!"
Fed: <watches phone wipe...>
Could you be charged with destruction of evidence?
I don't see why this would be any different.
The user claimed to offer a password to access the contents of the device, and instead offered a password that deleted the device. That is false testimony / lying to an investigation, and is almost certainly punishable in itself.
Not clear on anything else regarding the duress PIN but I don’t think a 5th defense would apply.
Note that you apparently have to explicitly invoke your right to remain silent or your silence could be implied as an admission of guilt (thanks to Salinas v. Texas). I imagine you’d have to repeat your assertion multiple times, and the person demanding the PIN will tell you that you can’t use the 5th, will threaten you with arrest and additional charges, etc. Consult a lawyer and get training if you’re doing critical work where you may need this defense.
As I mentioned earlier, this is part of why my own plans for international travel are to only go with a notebook/sheet with contact numbers and buy throwaway devices on the other side. I don't think I'd travel internationally with a phone or laptop at this point, and that's kind of been my thoughts for a while. Especially given the direction that many countries, not just the US have taken. For that matter, I don't think I'd ever even risk travelling to the UK or China at this point. Not that I like the surveillance state here in the US, at least I still have some rights preserved.
As such in a case like the Salinas one, being silent or "pleading the fifth" would be moot as both would just indicate "deafening silence" to the judges since the defendant had been cooperative up until that point.
(the Swedish judicial system has no juries, instead there's a professionally learned judge and 2 "laymen judges" appointed from political parties acting as the peoples representatives, if that triumvirate fucks up, higher courts can and often will kick rulings back down for retrials).
>"ok are you sure that's your pin?"
>they exit the room and come back 5 min later
>"that pin didn't work, can you write it again?"
You're going to have a hard time convincing the judge that you "accidentally" gave the wrong pin in this case.
Compelling a PIN, even with a warrant, is legally questionable. Courts have held that it is a form of 'testimony' because it's compelling you to disclose something you know, while some state courts have ruled the opposite way.
In all likelihood the government wouldn't push it in this instance, to avoid creating any sort of precedent.
>During the fall of Enron, Arthur Andersen, Enron's accounting firm, instructed its employees to destroy documents relating to Enron after Andersen officials learned they would soon be investigated by the Securities and Exchange Commission.
https://en.wikipedia.org/wiki/Arthur_Andersen_LLP_v._United_...
The conviction was overturned, but only on procedural grounds
which is a good reminder for anyone with reason to be concerned about this sort of thing to turn off biometric/face id/etc. access to their devices.
unless the phone itself is a suspicious good, there should never be any justification for a border officer to demand visibility of the contents of the phone, or the data that its permitted to access on other systems.
I presume the counter to this is that they must be able to examine the socials in order to see if you should 'death to america' on message boards. is that really an important vector? is the balance of that security concern versus speech rights (which are supposed to be 'universal') something we want individual field officers to decide?
Personally, I believe that there should be explicit laws protecting your personal devices, given the amount of sensitive private information they carry. I think an explicit law, or even amendment to the constitution, would be much better than relying on ever more arcane legal interpretations being invented by judges based on vague wording and vague principles.
Since 4th ammendemnt protections are significantly curtailed at border crossings, they can actually declare on the spot that your data is now their data. The only thing they can't do is force you to tell them how to access it - but, if they can hack your password, they actually have the right to search your phone just as much as they have the right to search you luggage.
1. They do field tests before sending to a lab
2. They're sending it to a lab to ensure the results are accurate, not to guard against an off chance something is boobytrapped.
Theoretically yes, but in this case there's approximately zero chance a judge would accept "I destroyed evidence because there's a vague chance ICE might send me to a deportation camp".
That's not what you originally said though, which was "The level of duress also matters. US citizens have been shipped to foreign prisons ...".
> US citizens have been shipped to foreign prisons
From US soil?Your original post:
>Maybe digital forensics shouldn't be handled by barely highschool graduates at a busy border crossing
Sounds like you're moving the goalposts from "haha CBP agents are dumb" to "they should get warrants".
Beyond this, “I dropped my phone in the ocean” is always a perfectly valid reason.
If you’re a foreigner and they already suspect you of something, they can deny you entry for any reason. It may be better to be denied than arrested!
> wiping the device before carrying it across the border seems essentially identical to me.
This seems more in line with many companies' email retention policies to delete all mail after some time period. This is to protect the company from anything compromising that might have been said, should an investigation ever occur. Better to just not have any record of anything.And this policy is already accepted in practice.
On the contrary, there is a huge gulf between these. Providing a fake password that wipes a device while under active questioning is a clear case of providing false testimony. Lying to the police while under investigation is simply illegal, regardless of the thing you're lying about.
By contrast, entering the country with a clear device is not a crime under any possible interpretation that I can see. Now, if you are wiping evidence while you know there is an active investigation against you, that may be a crime as well, but it's a completely separate crime and can't be easily judged by an officer that simply finds you with a clean phone.
False testimony of what? Can you be compelled to provide testimony that allows a police officer access to your private data? Can a police officer demand I log into my online medical chart so they can complete their investigation?
> Lying to the police while under investigation is simply illegal, regardless of the thing you're lying about.
Perhaps for certain definitions of police, investigation, illegal, and lie. But as a blanket statement, not even remotely. Otherwise every person found guilty of any crime they said they didn't commit would also be found guilty of lying to the police officers who interrogated them.
False testimony of what your password is.
> Can you be compelled to provide testimony that allows a police officer access to your private data?
When under police investigation, you are only allowed to do one of two things: explicitly invoke your 5th amendment right not to provide testimony, or provide truthful testimony of anything the police ask you. Anything else is technically illegal.
> Can a police officer demand I log into my online medical chart so they can complete their investigation?
Yes, though you can refuse their demand by explicitly invoking your 5th ammendemnt right to stay silent. They can legally lie to you about your obligations, though.
> Otherwise every person found guilty of any crime they said they didn't commit would also be found guilty of lying to the police officers who interrogated them.
Indeed, people who proclaim their innocence to police can face additional charges if later found guilty. It's quite rare for this to be pursued in criminal cases, as the additional punishment would not be worth the effort of proving you knowingly lied about this. But it is actually sometimes pursued in misdemeanor cases, as lying to the police is a crime and can actually carry a steeper sentence than the misdemeanor itself, so it can be a powerful incentive to convince you to admit guilt for the lesser charge.
Note: I'm using legal terms rather loosely, and I am probably wrong on some of the details. Perhaps a statement such as "I'm innocent, officer" is too vague to constitute a material falsehood and be prosecutable, even in principle. But something like "I couldn't have killed that man, I was not there that night, I was at this other location" would almost certainly qualify you for additional liability if it can be clearly established that you were in fact at the location the victim was.
if someone is accused of something (possibly retroactively), any of those may be illegal (under specific details etc). if not, then... am I going to be required to never delete anything just in case?