US Accuses American of Allegedly Wiping His Phone Using a 'Duress' Password During Border Search
Report from TechCrunch
An anonymous reader quotes a report from TechCrunch: The U.S. Justice Department is prosecuting an American for allegedly providing U.S. border authorities with a passcode that wiped the contents of his phone, according to an indictment and media reports.
This is thought to be the first known case in the United States where federal prosecutors have charged someone for the alleged destruction of data using a so-called “duress” password built into a phone’s software.
According to The Guardian, which covered the story earlier this week following the court’s first hearing on Monday, Atlanta resident Samuel Tunick is fighting the charges. Tunick’s attorneys said that it was unlawful for U.S. Customs and Border Protection to seize his phone as he arrived back in the U.S. last year, and that any evidence - including the alleged wiping of his phone - should be thrown out.
The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick’s attorneys confirmed GrapheneOS was running on his phone. The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user’s unlock passcode.
Tunick’s case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter.
Bill Budington, a senior staff technologist at the Electronic Frontier Foundation, and Runa Sandvik, a digital security expert who works to protect at-risk people as the founder of security consultancy firm Granitt, told TechCrunch that they had not seen similar cases involving the use of duress passwords.
“I have not seen this before, though I’ve discussed the potential scenario with activists and journalists over the years,” said Sandvik. “I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.”
“With a little planning ahead of time, you can always download the data you need once you get to where you’re going,” said Sandvik.
Read more of this story at Slashdot.
US Accuses American of Allegedly Wiping His Phone Using a 'Duress' Password During Border Search (techcrunch.com) 3
An anonymous reader quotes a report from TechCrunch: The U.S. Justice Department is prosecuting an American for allegedly providing U.S. border authorities with a passcode that wiped the contents of his phone, according to an indictment and media reports. This is thought to be the first known case in the United States where federal prosecutors have charged someone for the alleged destruction of data using a so-called “duress” password built into a phone’s software. According to The Guardian, which covered the story earlier this week following the court’s first hearing on Monday, Atlanta resident Samuel Tunick is fighting the charges. Tunick’s attorneys said that it was unlawful for U.S. Customs and Border Protection to seize his phone as he arrived back in the U.S. last year, and that any evidence - including the alleged wiping of his phone - should be thrown out. The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick’s attorneys confirmed GrapheneOS was running on his phone. The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user’s unlock passcode. Tunick’s case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter. Bill Budington, a senior staff technologist at the Electronic Frontier Foundation, and Runa Sandvik, a digital security expert who works to protect at-risk people as the founder of security consultancy firm Granitt, told TechCrunch that they had not seen similar cases involving the use of duress passwords. “I have not seen this before, though I’ve discussed the potential scenario with activists and journalists over the years,” said Sandvik. “I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.” “With a little planning ahead of time, you can always download the data you need once you get to where you’re going,” said Sandvik.
Community Discussion on Slashdot
Plausible deniability is better (Score:2)
There should be an option for a password which unlocks the phone in a separate sandbox which is benign. Of course, if the government has a warrant, even this will get you into trouble.
Here we go (Score:1)
The scenario always talked about here gets the legal test. Wonder if the usual bootlickers will have anything to say?
Good for him! (Score:2)
If he actually did what he is accused of, then good for him! I hope the ACLU steps in to provide for his defense. I would wish that the court would find "Fuck you, he has the right to privacy" (wishful thinking, I know...) Even if he wins in the end, they are going to make his life hell.
Comments
No comments yet. Start the discussion.