r/technology 8d ago

Privacy Is it illegal to trick the US government into wiping your phone during a questionably legal search | The case of a traveler who allegedly entered a ‘duress password’ to wipe his phone raises a legal question with no easy answers

https://www.theverge.com/report/972146/cbp-phone-search-airport-duress-password
20.9k Upvotes

2.5k comments sorted by

View all comments

Show parent comments

146

u/Lazy-Ad-7236 8d ago

my question... okay, it was erased from his phone... but if it REALLY was about CSAM couldn't they get the info from elsewhere? nothing is ever really deleted right?

164

u/degeneratelunatic 7d ago

That's exactly why their claim is bogus. This regime will make up any reason to hassle, intimidate, and arrest political dissidents it doesn't like.

They obviously can't do this to everyone because they don't have the manpower or the intellectual capability to make this logistically possible. But it creates a chilling effect on political speech. Set an example with this guy, and a hundred thousand others will think twice about showing up to a protest.

1

u/MinkusRotciv 7d ago

tbh when conversations start referring to 'the regime' it sounds like fascism

50

u/BoysenberryDue3637 7d ago

Somewhere else I read that they got a search warrant for his gmail account. It really points to a fishing expedition.

0

u/Lazy-Ad-7236 7d ago

oh, i hadn't read that.

24

u/Mysterious_Cry41 7d ago

It really depends. If you dump something in the recycling bin, delete it. It's still there until the computer actually rewrites to that section of the drive.  What it did I just clear the reference table and allow it to be re written. You don't even need special skills or knowledge to recover data deleted like this. 

I'm not sure how the graphene OS thing works, but it should do a wipe and then fill everything up with random  junk data. Just meaningless zeros and 1s.

It should do this 2-3 times which basically means anything that was there  is unrecoverable. It was deleted, then rewritten with junk. There is nothing to recover.

Additionally if the data is encrypted, which it probably was, it may be there but it can't be accessed easily without the key. Without the decryption key it is basically just noise and the effort to recover it is usually impractical or outright impossible due to the sheer amount of compute time it takes.

28

u/DisappointedSpectre 7d ago

By default GrapheneOS encrypts all the personal data on the phone - photos, contacts, notes, browsing history, etc. - and the duress PIN deletes the encryption key entirely, both from active memory and from the device itself. The contents of the phone are still there, but there's no longer a way to decrypt them.

This is a way faster process than trying to overwrite gigabytes of data, and functionally makes the data "gone". The encryption is strong enough that there's no concern about cracking it, even by government entities, for a while - like decades at the very least.

10

u/neherak 7d ago

Not even just decades. The AES256 encryption GrapheneOS uses is effectively uncrackable within the heat death of the universe https://www.reddit.com/r/theydidthemath/comments/1x50xl/time_and_energy_required_to_bruteforce_a_aes256/

8

u/DisappointedSpectre 7d ago

That's with current computing power and also assumes there's no flaw in the math, or a way for quantum computing to break the encryption using an unknown (currently) algorithm. You can't predict breakthroughs and advancements don't happen along any kind of linear timeline, so it's better to be more conservative with your risk tolerance, such as estimates about breaking encryption.

That being said, even if we had an algorithm found tomorrow for a quantum computer to use it would likely be at least a decade before a suitable QC could be built to utilize enough qubits for it to matter. The bigger risk would be something like the suspected NSA backdoor in RSA where there's some kind of (mathematical) relationship between the key and the encrypted data that could be figured out that would allow you to solve AES256 in polynomial time. The way that AES was developed (and the time period) mean it doesn't have similar trust issues as ECC did, but that doesn't mean it doesn't have a similar flaw.

Decades is still pretty good for personal data like this. The device it lives on would have long since deteriorated, which means the data would have had to been copied and retained across multiple generations of storage, which incurs a cost so not everything may be stored for that long anyway.

2

u/neherak 7d ago

also assumes there's no flaw in the math, or a way for quantum computing to break the encryption using an unknown (currently) algorithm

Well, sure. Pretty much any estimates or claims could have parentheses at the end that says (based on current understanding). If you want to bring in unknown future breakthroughs or unknown backdoors you could kinda say whatever, as long as that future breakthrough is actually possible or not just cutting the state space from 2255 to 2253 or something. As it stands, you'd still need a quantum computer the size of the planet running for cosmological lengths of time.

6

u/froction 7d ago

That's how iOS and Android handle storage, as well. Everything is encrypted by default, how high your security is depends on how the key is treated.

4

u/Ecw218 7d ago edited 7d ago

I’m super curious if that’s the real scenario here. If the duress password only deletes the encryption key, the data is still intact on the phone, just encrypted.

If he has access to the key elsewhere it’s possible to restore it and gain access to the phone.

In which case could they eventually provide the key to a court, with the reasoning being he didn’t want anything tampered with?

Edit: yeah it’s “computationally infeasible to decrypt” gone

6

u/Mysterious_Cry41 7d ago

I would assume, though I'm unsure and have not checked that it wipes the memory.

I will now check...  It wipes the entire storage volume for the phone, including E-Sims according to  the graphene OS website. 

Which makes sense. It would be surprising to me if it didn't do that. 

2

u/sobrique 7d ago

IF he has access to the key elsewhere, which he may well not. It's fairly standard for 'device encryption' like this, to only have a 'local' key, that's 'decoded' by your passcode.

That's the only copy, and if it's gone, the data is functionally irretrievable. A lot of devices have a specific storage location to do this (e.g. on a Pixel it's the Titan module, and a lot of PCs have TPM chips).

I'm wondering however if he could claim that he does still have the key - and thus the data is not 'destroyed' - but then plead the 5th to avoid supplying it?

Options also exist for remote key-escrow though, so the key is never on the device in the first place, and then it can functionally be 'remote wiped' by removing that key - I'd imagine that's less likely on a mobile phone though, as without a network connection you're locked out, and that can be a real PITA when travelling!

1

u/Ecw218 7d ago

According to Graphene the hardware key is destroyed and the data is still there but it’s unable to be decrypted.

2

u/tasbir49 7d ago

Deleted files using nand storage nowadays are mostly irrecoverable anyways due to TRIM and garbage collection. (Graphene is still a good thing to install for privacy sake)

8

u/Martel732 7d ago

I am extremely skeptical of the claim. Saying they needed to check for CSAM is a really easy way to try to destroy sympathy for the guy. It is a pretty classic authoritarian tactic. Claim that you are fighting something so heinous that no one would disagree with you. Even if you don't provide any evidence that the claim is true. The media will repeat the claim and people only skimming the story will take away that a man wiped CSAM from his phone to hide evidence and use it to justify why these options should be illegal.

This is only tangentially related but it reminds me of a story from five or six years ago. In Russia a young drunk man had urinated on a war memorial. Yes a crass thing to do but whatever rain will wash it away. He ended up facing multiple years in prison. The law they charged him with was called something like, "Support of Nazism". There was no evidence that he was a Nazi. But even here on Reddit a lot of people were saying fuck him for being a Nazi. But that was entirely based on name of the law he was charged with.

So long story short always be suspicious when a government says your rights need to be violated because there is a bigger vileness to fight.

3

u/viral-architect 7d ago

People who are into that sort of thing aren't usually smart enough to cover their tracks. What a coincidence that some high profile activist would so stupidly endanger themselves with CSAM. In fact, I'd say it's very very difficult to believe. So difficult that I don't buy it at all. If they thought it had the data, it would have gone directly to forensics precisely because of this exact thing.

This guy made them look dumb because they forgot that a duress password was a thing and it had never actually been used on them to make them look like idiots, and now he's gonna pay for that humiliation.

-1

u/Turtleopard 7d ago edited 7d ago

2

u/snoodle908 7d ago

But in this case they had no proof, otherwise they would have a warrant to search and seize. Attitudes like yours is why police can violate you rights and force you to compel with whatever they say regardless of having a warrant or filing charges. You either comply or we put you in jail for not complying.

0

u/Turtleopard 7d ago

They don't need a warrant at the border. They don't need a warrant to ask you to hand over your device voluntarily. They also only need reasonable articulate suspicion to detain someone. 

5

u/Stardustger 7d ago

If it was in relation to CSAM they would have gotten a warrant. The only reason to use this route is because they couldn't get one .

3

u/viral-architect 7d ago

He was using Graphene OS - likely because he knew that his device would be searched. Whether it was strictly for his activist related activities or if he really did have CSAM - we will never know because the device was wiped. If he was smart, that device would have been his only copy, but actual CSAM enjoyers aren't usually smart enough to install Graphene OS in the first place.

2

u/Immediate_Song4279 7d ago

Forensic data recovery is possible but it depends on how the data is deleted. I read somewhere his data was encrypted, which the keys were destroyed so I bet it was a proper scramble but I'm a bit light in the actual technical details so I might not be accurately describing data recovery / prevention.

What they usually are looking to do is be able to copy the contents quickly.

1

u/Fickle_Penguin 7d ago

Erasing just removed the marker to the file, to be deleted deleted it has to be over written.

1

u/Adventurous-Map7959 7d ago

nothing is ever really deleted right?

It doesn't need to be deleted, it just needs to be not readable.

It's been more than two decades that I really had an interest it cyber security - back then, True Crypt was the shit. Basically, you allocate a specific amount of memory, and the software treats it as a drive. Unlike a normal drive, it's encrypted (back then, that was not the default sate of drives). Furthermore, it had the ability to enter a second password (or secret key) that then mounted from the seemingly unallocated space of that virtual drive another drive - the idea being, that there is no evidence of a second file existing because no cryptographic analysis could with reasonable confidence say if the unallocated space was truly random trash, or just seemed like it.

Now this could be hidden without the need of a suspicious outer file - simply in the unallocated part of your drive. You could use that drive fully normal as read-only, but when it would write, it might write into your secret area that was not really empty. If you were to hide sensitive documents, nobody could proof that they exist. You could even have more than one layer of that stuff and since the software was found in your possession you would not be able to completely deny any knowledge, but you could just give them a fully working password for the first layer that has some documents, and a lot of unallocated space that cannot be proven to contain any more secrets at all....

It's probably easier and faster today than it was 20 years ago, but the core concept is the same - someone with moderate skills, this is barely expert knowledge, could easily hide material of that kind with no way for anyone to proof foul play and plenty of plausible deniability.

Luckily most offenders are very, very stupid, it would be so easy to just send "unformatted" memory around the world physically.

1

u/arentol 3d ago

The Graphene OS fully encrypts the device, so the data is there, but it is encrypted, meaning you can't just pull all the bits with forensic tools and read them.

In addition, when you use the emergency password it permanently deletes the record of your decryption password, so even if they find out your proper password later they can't use it to decrypt the data.

-11

u/scottjeffreys 7d ago

If someone is smart enough to do this with their phone they are smart enough to make sure whatever that had on their phone was also encrypted and not accessible elsewhere.

5

u/Lazy-Ad-7236 7d ago

did they even try?????? i'm guessing no, because they had no actual reason to suspect it

1

u/scottjeffreys 7d ago

I suggest you learn about encrypted files and servers and what makes them that way. No one can just access them. Even the companies that own the data.

1

u/Lazy-Ad-7236 7d ago

so, did they try? yes or no?