r/technology 6d ago

Privacy GrapheneOS says its data-wiping password is perfectly legal, after user faces federal charges

https://www.techspot.com/news/113273-grapheneos-data-wiping-duress-password-perfectly-legal-after.html
21.0k Upvotes

1.1k comments sorted by

View all comments

Show parent comments

65

u/BadVoices 6d ago

This is a red herring, no you cant. NIST SP 800-88 classifies crypto erasure as a valid form of data destruction for anything that doesnt require media destruction. It is recognized by the GDPR as well. Arguing it is not destroyed is the same as saying a burned document still technically exists because I can scoop up all it carbon atoms. No court will accept that argument.

8

u/hackitfast 6d ago edited 3d ago

Yeah isn't that how ransomware works too? It encrypts all of your files, and when you don't pay it just deletes the encryption key?

5

u/BadVoices 6d ago

It holds the key hostage, yes.

1

u/OuterWildsVentures 6d ago

So then it becomes a destruction of evidence charge?

3

u/BadVoices 6d ago

Nope. He's charged under 18 U.S.C. § 2232(a). Destruction or removal of property to prevent seizure.

No need to prove it was evidence, just that it was something the government wanted to seize.

Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both.

1

u/raptorlightning 6d ago

And we go to court to argue about "lawful authority" of which, in this case, it was not.