Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's immensely different. Leaps and bounds different. Why?

Well, once you have been told to unlock the device, you're already in a legally binding process. The phone is at this point evidence. It was not evidence before. It was not evidence a month ago. It really is just that simple.

Now, they could view prior wipe as suspicious, but as a US citizen they cannot prevent entry. And they may be able to seize your phone(suspicious!). Which is why simply stating the truth politely "I believe in privacy, and loath government poking into the private affairs of citizens" might help down the road if you want to sue. Might.

Border guards protect the realm, after all, and have wide latitude.

From my side, my truthful argument for wipe has always been that all of my buisness clients, emails, data might be on my phone. I have a duty to protect their privacy.

Making reasonable statements takes the edge off of 'suspicious', and the more people who wipe? The less suspicious it becomes.

The biggest thibg anyone could do, is make 100% restorable backups for non-rooted Android a thing. It's doable, but a PITA right now. Make it one-click, perfect, reliable, and more will do it.

And then it isn't unusual, it's normal, and the suspicious elements vanishes.

Of course, as Google is mired in asshattery lately, I'd expect any attempts to protect us all, such as ASOP patches or bug reports, would be fought against and ignored. Helping the world, protecting travellers, political dissidents, not on their radar.

They even fight such things.

Because in this day and age, Google does not have your back. Instead, they shove knives there.



> Well, once you have been told to unlock the device, you're already in a legally binding process

In none of my scenarios am I describing actions to be taken after you have been told to unlock the phone. I’m talking about before you ever approach the border. There is no functional difference between wiping a key which encrypts the entire device (but leaving the encrypted data in place) vs wiping the entire device, from a security point of view, except one requires twiddling fewer bits to restore the data.

My point is that the law is unable to see that equivalence, but it is also unable to compel a different result. If choice A and B are identical for security purposes but the government can technically prosecute A but not B, all they have accomplished is forcing people to choose B.


The Aftermath: Because the encryption keys are already instantly nuked at the hardware level, the phone boots directly into the Google Pixel recovery or factory-fresh setup screen.

It's exceptionally apparent you've caused destructive behaviour, after the phone is in evidence.

None of the other scenarios, show your duress pin factory resetting the device, then dropping into a setup screen, after the border agent confiscated it. So much of tbe law is intent, coupled with knowledge of your situation.

There's nothing new here really. Throw a diary into the fireplace at home? Fine! Travel with a blank diary? Fine!

Grqb it from a border guard and and rip it up? Trouble.

It's not about the state of the device at the border. It's intent to change the state after confiscation.


That's not the scenario I'm talking about at all. I'm considering entering the duress code before you approach the border and before the border guard gets anywhere near it, on the assumption that you have a byte perfect backup which is trivial to restore somewhere in the cloud.


Percisely. To know the implications of your theoretical act, you must know +why+ the act caused issue in this story's case.

In all your scenarios, you would not be charged with this crime. They may seize the device, but not charge you.


Well I certainly hope. I have my suspicions that if you pre-wiped your key but left the data “intact” but unusable, you open yourself to the law declaring that as somehow withholding evidence. Actually wiping the entire phone and restoring is certainly the safest in terms of how others may interpret it.


> It's immensely different. Leaps and bounds different. Why? [O]nce you have been told to unlock the device, you're already in a legally binding process.

From a factual point of view, rather than the narrow legal one offered, it is not materially different to delete a phone in anticipation of a future search. In most cases, outside the customs context, it's just harder for the government to prove obstruction of justice.

What's different here is that the government only had a right to search the phone in relation to the border, and the government used that right not just to search for contraband like the law anticipates. If someone dumped their contraband and made it disappear before actually crossing a border, would that be an evidence-related crime? What if they thought about a contraband conspiracy, and then intentionally forgot? What if the customs office presented a form to all travelers, well in advance of formal screening, that they must preserve their contraband henceforth? And then they decided not to smuggle it? Interesting questions legally, but factually, considering criminal charges in those scenarios over the evidentiary situation would be pretty silly.

So then, when you delete purportedly contraband data at the border, have you really just done a public service of removing one more potentially contraband item from border inspection? Or is it that once any of us create data in the vicinity of a border or in a context where we might approach a border in the future with the access device or storage medium, do we all have a duty to preserve it for inspection until the customs authorities get around to inspecting us? Or is it just that this series of hypotheticals illustrate that we have here an epic mash-up of misinterpretation here?


One can’t help but wonder if a motivated DOJ could twist a “destruction of the evidence” charge out of someone dumping a kilo of cocaine just before traveling to the US.


Maybe just don't enter a duress pin, causing the phone to blatantly wipe, and rrboot, and enter a setup screen, right after a customs officer confiscates your potential "contraband", and demands the pin?

I mean really, this act is exceptionally blunt, clear, and overt. All this hand waving won't change things.


Google could not care less; this feature does not make money and adds support burden.


well, i guess the writing was on the wall, so to say, pretty much from the beginning: "don't be evil".


They deprecated that one.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: