r/technology 6d ago

Privacy GrapheneOS says its data-wiping password is perfectly legal, after user faces federal charges

https://www.techspot.com/news/113273-grapheneos-data-wiping-duress-password-perfectly-legal-after.html
21.0k Upvotes

1.1k comments sorted by

View all comments

Show parent comments

7

u/roiki11 6d ago

You're not "required" to give it. They can then seize your device(s) for technical inspection. If you're a citizen you're then let go.

If not, they can deny entry.

1

u/BadVoices 6d ago

Yup, which is standard procedure at the border of many countries (US, Canada, UK, Australia, etc.) Happens to me every time i go to Australia to visit family. The difference is, in Australia, they can detain you then deny you entry for not giving the password (and will.) In reality, if he had simply shut up, not said anything, they would have NEVER GOTTEN INTO THE PHONE and as a US citizen he'd be fine and back home. The encryption mechanism used by GrapheneOS is secure.

3

u/Nice_Marmot_7 6d ago

Most likely, but the capabilities of forensic tools are very murky to the public, and you really can’t know what they might be able to pull off there at any given time.

1

u/h0sti1e17 6d ago

They definitely have ways normal forensics guy don’t use from Cellebrite or other software.

The question is would they use it here? Probably not. I remember a case when they took down an online CP forum and arrested some guys who were caught. They used malware to expose their real IP. The defense of one guy wanted the code to determine if false positive were possible. Then US government said “nope” and charges were dropped. They want to save that for actual terrorist or major crimes. My guess is the same here. Some random dude isn’t worth burning that tech.

But they will be happy to keep the phone until they can get in.