The foundation behind the ultra-secure Android-based OS is speaking out after an activist was indicted for using a ‘duress password’ to prevent federal agents from searching his phone.

  • schnurrito@discuss.tchncs.de
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    1
    ·
    1 hour ago

    Tunick’s lawyers claim the agents “never read him his Miranda rights,”

    irrelevant unless his statements are going to be used against him

    I don’t really see why this is an enormous civil liberties story. Destruction of evidence can, I think, legitimately be a crime even in a free and democratic society. It’s not like they’re trying to make the feature itself illegal… the main civil liberties complaint to have here is that searches of phones on borders are a thing at all.

    Compared to https://www.thenation.com/article/archive/you-can-be-prosecuted-clearing-your-browser-history/ (from 2015 - 11 years ago, under the Obama administration!) where the person apparently didn’t even know the government might be considering the deleted stuff “evidence”, I find this story harmless.

  • Juice@midwest.social
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    13
    Aquileo | arrow-down
    1
    ·
    19 hours ago

    Boy this story sure is getting a lot of publicity. Makes you wonder why. I forgot about this feature on Graphene phones, I’m gonna turn it on right now

  • Venia Silente@lemmy.dbzer0.com
    Aquileo | link
    Aquileo | fedilink
    English
    Aquileo | arrow-up
    13
    Aquileo | arrow-down
    4
    ·
    17 hours ago

    Ya know, all this can be avoided by simply not flying in with a phone in the first place. Or just not even going to the US.

    Any plane ticket to the US is money given to an airline company that deals in abetting fascism by providing victims.

  • Robert_White
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    13
    Aquileo | arrow-down
    1
    ·
    19 hours ago

    The reboot isn’t cosmetic, it’s structural. The duress PIN nukes the key derivation material, and a device with no keys has nothing left to boot into. There’s no quiet version of that.

    But your instinct is right and worth pushing one step further. An empty phone has the same problem as a rebooting one. Nobody owns a phone with four apps and two weeks of messages, so it just takes them a bit longer to notice.

    What you actually want is to quietly unlock into a phone that’s full. Real apps, real photos, real history, and the sensitive half behind a second PIN stored so it reads as random noise, same as any unused encrypted space. Nothing gets destroyed, so there’s nothing to reboot from and nothing to argue about afterwards.

    Catch is the decoy has to be believable, and keeping one believable is a chore most people drop after a month.

    (I work on DeniableOS, which does this, so grain of salt. Graphene’s own statement this week made roughly your point, that wiping can carry physical or legal consequences.)

    • Dionysus@leminal.space
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      6
      Aquileo | arrow-down
      2
      ·
      17 hours ago

      That’s actually a good use of onboard LLMs imo

      Give it a short innocent history, have it generate stuff.

      Do what their president does, fill the air with so much shit that you can’t tell what’s real anymore.

    • Mossheart@lemmy.ca
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      5
      Aquileo | arrow-down
      3
      ·
      19 hours ago

      Your first two paragraphs read like they were LLM output in tone and language. I need to know if that’s true or are you just was your writing style the source training material?

  • eleitl@lemmy.zip
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    37
    ·
    1 day ago

    Why do you have to defend against what is advertized as a feature and is working as advertized? The fascists can stuff it right up their arse.

    • Regrettable_incident
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      18
      ·
      20 hours ago

      IKR - if there were genuine concerns that this guy might have something nefarious on his phone, surely they should confiscate it and pass it on to their tech guys to try to backdoor or whatever. Instead, this shit finger just types in whatever he’s told and oops, he deleted any potential evidence.

    • \\\mr\rnd;@lemmy.zip
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      10
      Aquileo | arrow-down
      4
      ·
      1 day ago

      yup, already tried to find phones with GrapheneOS installed.

      • I don’t want a from Google, so no pixel
      • Motorola made plans
      • only a compatibility list :(
      • VitoRobles@lemmy.today
        Aquileo | link
        Aquileo | fedilink
        English
        Aquileo | arrow-up
        13
        ·
        20 hours ago

        Pixel phones are actually really good. You can buy them used/not directly from Google. Then reformat it to GrapheneOS.

        Kinda like buying a Windows laptop to install Linux on it.

        • ximtor@lemmy.zip
          Aquileo | link
          Aquileo | fedilink
          Aquileo | arrow-up
          13
          Aquileo | arrow-down
          10
          ·
          1 day ago
          • I want to avoid Google!
          • Graphene: here you go
          • Nice, now what phone?
          • Obviously a Google phone!

          Come on, there gotta be many people who want to avoid buying a fucking pixel, even if second hand.

          • ximtor@lemmy.zip
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            1
            ·
            2 hours ago

            I get it, there are reasons, but the point stands that I(and apparently others) preferably would have nothing to do with a Google product, how is that an unreasonable opinon?

            I’m currently stuck on a phone that I can’t even root (afaik), but I am also not eager to buy a new one while this one works perfectly (and isn’t ginormous like most newer phones). I might be more willing to swich to a new non-G phone but how it is now I try to sandbox as much shit as i can (or know of) or use alternatives where possible.

            It also feels like an incredibly complicated topic on what you could and should do. And I consider myself at least somewhat tech literate. It feels frustrating and some of the elitism around it doesnt help.

          • Auli@lemmy.ca
            Aquileo | link
            Aquileo | fedilink
            English
            Aquileo | arrow-up
            16
            Aquileo | arrow-down
            1
            ·
            21 hours ago

            And if you don’t know why Pixel is the only phone supported that is on you. They are the only phone that allows you to relock the boot loader with a custom ROM. And since grapheme OS is all about security why would you want to run a phone with a unlocked boot loader. That is a point of weakness.

            • InternetCitizen2
              Aquileo | link
              Aquileo | fedilink
              Aquileo | arrow-up
              3
              Aquileo | arrow-down
              4
              ·
              21 hours ago

              Lemmy is a place of idealism. Which don’t get me wrong is great, but it does mean no practically and often detriment to the changes they want to see in society.

          • illi@sh.itjust.works
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            13
            ·
            23 hours ago

            Afaik Pixels come with the least bloat to work around amd also have some security features the GOS people like. Buying used or refurbished Pixel is currently the best you can do, so Google doesn’t get any more money.

            • Auli@lemmy.ca
              Aquileo | link
              Aquileo | fedilink
              English
              Aquileo | arrow-up
              9
              Aquileo | arrow-down
              1
              ·
              21 hours ago

              Nothing to do with bloat as pixels have ton of bloat but has to do with security. You can relock boot loaders.

          • eleitl@lemmy.zip
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            2
            Aquileo | arrow-down
            2
            ·
            19 hours ago

            If these people’s priorities are to wait for for years until an expensive phone from Motorola is supported I think they need their heads examined, but that’s just me.

            • Venia Silente@lemmy.dbzer0.com
              Aquileo | link
              Aquileo | fedilink
              English
              Aquileo | arrow-up
              2
              Aquileo | arrow-down
              1
              ·
              17 hours ago

              Some people simply can’t afford to buy an extra phone, not even a used one. And some people don’t even have a Pixel option in their market.

              But if you think money and phones simply grow out of trees in all of the places of the world that the US has fucked, maybe it’s you who needs your head examined.

              • eleitl@lemmy.zip
                Aquileo | link
                Aquileo | fedilink
                Aquileo | arrow-up
                1
                ·
                36 minutes ago

                If you don’t have the money for a used Pixel nor can DIY a secure libreboot used Thinkpad you need to go lowtech.

                If you can’t or won’t you’re simply screwed. Try finding a lamp with a helpful genie, because the universe sure as hell won’t accomodate your wishes.

              • ArcaneSlime@lemmy.dbzer0.com
                Aquileo | link
                Aquileo | fedilink
                Aquileo | arrow-up
                3
                ·
                14 hours ago

                Unfortunately Graphene has a reason for this, Pixels are (for now) the only phones with the HW security requirements list Graphene has, they’re just the most secure (HW wise) phones on the market.

                They also share your sentiment, but realistically they have to work with what exists, not what is fantasy. They are taking steps with Moto to get off of that dependency however and that phone should be just as secure (where their current ones lack something on the list.)

                If you just want to get away from google, try LineageOS, if you need it to be secure then you’re just as stuck as Graphene is, I’m afraid.

    • mathemachristian [he/him]@lemmy.blahaj.zone
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      1
      ·
      13 hours ago

      It depends on the scenario. If someone thinks you gave a dummy profile while the real on is intact then you’re in for a rough time. Note that it doesn’t matter if you what you actually entered is a distress password and the data is really gone. If there’s ambiguity the only variable left is how far the other person is willing to go to get the data they think might still exist.

  • ExtremeDullard@piefed.socialOP
    Aquileo | link
    Aquileo | fedilink
    English
    Aquileo | arrow-up
    70
    ·
    2 days ago

    This is what happens when you try to maintain your rights in a fascist country: you risk five years in the slammer.

    I wonder why GrapheneOS makes a big flashy rebooty show when using the duress password instead of quietly unlocking to an empty phone though…

    • Batman
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      1
      ·
      10 hours ago

      my understamding is the phone is bricked when you do this. the key used to read the os itself is lost so you have to install a new one. the harddrive might as well be random noise.

    • LibertyLizard@slrpnk.net
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      24
      Aquileo | arrow-down
      2
      ·
      2 days ago

      Not sure there’s a realistic way they don’t notice. It takes time to wipe things and then the phone is empty. I feel like they’ll figure it out.

        • nymnympseudonym@piefed.social
          Aquileo | link
          Aquileo | fedilink
          English
          Aquileo | arrow-up
          18
          ·
          1 day ago

          I just realized there are ways you could do plausible deniability.

          What if we keep a decoy partition ready to go? Pre-populate it with some AI-generated slop Facebook account, photos, etc. Keep A small random sample of music files. etc. Something that looks as plausible and bland as possible.

          This is a feature that could get better & better over time. Don’t just wipe my old data; make my adversary unaware that there was anything worth wiping.

          • coolman
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            3
            ·
            20 hours ago

            I could absolutely see this being a thing, veracrypt has an option to create a hidden volume, and the two different passwords open up to two different encrypted volumes. Also if you start writing information to the non-hidden volume, it will start overwriting the hidden volume and corrupting files without any guardrails which is nice

          • Bytemeister
            Aquileo | link
            Aquileo | fedilink
            English
            Aquileo | arrow-up
            1
            ·
            17 hours ago

            What if you were able to pick apps/accounts that mirrors to the decoy partition? Then you have real data, but all the private stuff stays locked away.

            • BottleBoardBakon@lemmy.ml
              Aquileo | link
              Aquileo | fedilink
              Aquileo | arrow-up
              1
              ·
              13 hours ago

              You can already make hidden spaces in graphene!

              Although I think this guy should’ve just had an alt user active during the search and turned off usb data transfer.

              He shouldn’t have been searched, but he should’ve realized that he probably would be and prepared his device better.

      • usrtrv@sh.itjust.works
        Aquileo | link
        Aquileo | fedilink
        English
        Aquileo | arrow-up
        19
        Aquileo | arrow-down
        3
        ·
        2 days ago

        Android supports multiple user profiles. They could have a duress code login to a more sanitary profile while data get wiped in the background. This has been discussed on the forums I believe.

        • Lytia @lemmy.today
          Aquileo | link
          Aquileo | fedilink
          Aquileo | arrow-up
          5
          Aquileo | arrow-down
          1
          ·
          2 days ago

          The wiping in the background is very fast, and would in turn take out the profile. The only thing a decoy profile would achieve in that case would be a slight splash of color before the phone shuts down.

            • Lytia @lemmy.today
              Aquileo | link
              Aquileo | fedilink
              Aquileo | arrow-up
              1
              Aquileo | arrow-down
              1
              ·
              17 hours ago

              That would reduce the security of the duress pin significantly, and would require rewritting how the feature works in the first place.

              The duress pin shreds the decryption keys to the entire OS, which is much much faster than erasing the data itself, and arguably more secure. If you’re worried about getting caught wiping the device, just don’t wipe it. There is no known way to get into a phone running an up to date GrapheneOS install (or anything post Q3 2022) unless you have significantly reduced the security of the phone.

      • TipRing
        Aquileo | link
        Aquileo | fedilink
        English
        Aquileo | arrow-up
        5
        ·
        2 days ago

        If the phone is encrypted already you really just need to destroy the key. Of course then it needs to be reimaged to be used again which isn’t very user friendly.

    • Lytia @lemmy.today
      Aquileo | link
      Aquileo | fedilink
      English
      Aquileo | arrow-up
      12
      Aquileo | arrow-down
      2
      ·
      2 days ago

      This is a very common complaint, and the main reason is that it’s way more complicated than it sounds. The duress feature is designed to immediately erase any chance to recover the unencrypted data from the phone by destroying part of the data used to derive the decryption keys (the other part being your pin/password, which can’t be destroyed for obvious reasons). Any attempt to boot into a fake OS would be obvious to anyone familiar with the OS, thus making it effectively security theater. Not to mention the waste of space maintaining a fake OS, which would require fully featured apps and settings, all of which would have to be designed to pass verified boot, which means you can’t actually destroy the original OS the way they do.

      There’s currently no known way to extract data from a locked GrapheneOS device, especially once it’s in BFU, unless you’ve heavily reduced the default security measures, so the duress pin/password is likely unnecessary unless the danger of someone accessing the data is greater than the punishment for destruction of the data.

      Also, the “big flashy rebooty show” is less of a feature and more of an unintended happenstance caused by the device immediately losing critical data and being forced to restart. The articles make it sound flashier than it is. It looks more like the device is powering on but the screen keeps disconnecting for a second, before going black.

  • NRay7882
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    1
    ·
    18 hours ago

    I had read one source that stated they wanted to search his phone for possession of CP but I haven’t found other stories with details suggesting that. It seems they went about it all wrong but I’d like to know the reasoning for why they wanted to search his phone in the first place.

    • chortle_tortle@mander.xyz
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      12
      ·
      17 hours ago

      From his lawyers motion to suppress:

      The government was investigating Mr. Tunick because of his association with an environmental movement known as Defend the Atlanta Forest, which opposed the destruction of the South River Forest for the construction of an 85-acre, $115 million police training facility known as the Atlanta Public Safety Training Center.

      So like right there next to the bomb in Luigi’s backpack, they made up a justification to violate his rights because this is a fascist police state.

  • HazardousBanjo
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    42
    ·
    2 days ago

    Those fascist fucks didn’t have a right to confiscate his phone, nor any probable cause.

    He was well within his rights to do with his property as he saw fit.

    • Courtney (she/her/they) @lemmy.blahaj.zone
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      27
      ·
      2 days ago

      The whole thing is just for show, I don’t believe they expect to win this, it’s a message to anyone who wants to try on the future “we will try to destroy your life if you resist even slightly”

      They are claiming he destroyed evidence.

      Evidence of what? What crime did he commit that you are searching the phone for evidence? If you don’t believe a crime occurred, not only do you not have a reason to search the phone, but it doesn’t matter if he took out a hammer and smashed it to little bits, it’s his own property and he’s free to do with it what he likes. He wanted to wipe it, and he got it wiped. What you wanted in that moment didn’t matter in the slightest since you have no probable cause to search, no crime committed, no reason to baselessly charge someone for destroying something that doesn’t exist.

      It sounds exactly as ridiculous as someone being charge only with resisting arrest. If the person had provably done a crime worth arresting, that charge would be there as well.

  • Rajtinka
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    3
    Aquileo | arrow-down
    5
    ·
    2 days ago

    I fail to see how wiping data prevents the government from seizing property. They got the property. Just not the data, which isn’t property? It’s data. Seems like an easy win and just a scare tactic by the land of the free…