• Hacker News
  • new|
  • comments|
  • show|
  • ask|
  • jobs|
  • Cider9986 5 hours

    Huh, so this is essentially very similar be what this guy said to my suggestion of a factory reset timer in GrapheneOS being flawed. Apple's implementation of the reboot timer is flawed.

    This goes to show for all the people that want GrapheneOS to implement a feature like hidden profiles–flawed features give people a false sense of security and should not be implemented (that's not to mention deniability may not even be a good feature if it was technically possible to implement it well).

    Me:

    >What about a duress timer working as the reboot timer but it wipes if you don't unlock within the time period. Would that have any advantages for destruction of evidence or deniability?

    HybridStatAnim8:

    >That would not be viable because the hardware does not support it. It cannot be implemented in the OS because the OS can be turned off or exploited endlessly. For GOS to consider it, it would likely need to be backed by the secure element.

    >Duress PIN is deemed acceptable to implement in the OS because it is expected that the user is the one to enter it, so it has not fallen into the hands of attackers who may bypass it. Once attackers have it, you are effectively gambling. Account for that in your threat model and do not let it get to that point.

    https://news.ycombinator.com/item?id=49040342

  • t1234s 2 hours

    Graphine needs a triple tap power button for a hard power off.

  • iancarroll 3 hours

    > “Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost. This is the true magic behind the GrayKey Preserve and the Evidence Preservation Mode function.”

    Based on this, it seems more likely that this involves exploiting the device to retrieve the underlying keybags present in AFU mode and store them, rather than manipulating the actual feature of automatic reboots. Then the device can be exploited again in BFU mode but with the prior keybag to decrypt everything.

    It sounds like this feature is being used to exploit and extract keys from devices without a warrant (or in advance of getting one), which seems dubious to me.

  • childintime 4 hours

    Why don't my credit card and my phone implement a second pincode or password that allows me to signal that I'm in a hostage situation, and want everything (discretely) wiped? So that would do a saldo = sqrt(saldo) for a bank card, for example, and cancel all my limits.

  • amluto 6 hours

    Ooh, I wonder whether Apple made the classic mistake of using a wall clock timer when they should have used a monotonic (local) clock timer.

    edit: having personally gone through this kind of mess, the correct solution is to use strict typing to make sure you keep track of the difference between times and durations and the difference between different clock types. Don’t use plain integers and also don’t try to fudge it the way that Go’s standard library solution does. The modern C++ library is actually pretty good, although you need to use very recent versions of the standard for full functionality.

  • monneyboi 5 hours

    So we pay Apple for friction. And the state pays for Graykey to remove it. Whoever wins that arm race this quarter determines what our rights are worth in practice.

    bluefirebrand 5 hours

    Well, that's assuming you are ever able to claim your phone back. From what I understand police might just keep it indefinitely until they are able to access it, unless you get some kind of court order that it he returned to you

    Even then, who enforces the court order? :/

  • lrvick 4 hours

    Remember that Apple has full remote code execution rights on every device and hands that power over to the CCP in China, and they could do it here too.

    It is not possible to actually own an Apple device.

    It will do whatever Apple wants it to do, or whatever anyone that pays them enough wants it to do.

  • tamimio 5 hours

    Well first on the things you can do right now till apple figures it out, you should have control center disabled while the phone is locked, you can find it under “Allow Access When Locked” in face id and passcode settings, while -per the article- this won’t stop them, it sure will make it harder as by the time they try to gain access the 72h might have passed and a reboot happens. Second, they definitely fake the internal clock through the port, and because connected phone will keep correcting it through the NTP, hence it’s crucial to them to isolate the phone, so your job is to make that harder on them or delay it enough till it reboots itself. I think some of the quick counter measures apple can do now is allowing custom reboot periods, remote reboots through icloud, and disabling the possibility of manipulating the time through the lightning/usbc port.

  • ChrisMarshallNY 6 hours

    > AFU

    Good name.

  • ethagnawl 5 hours

    > The idea behind this so-called “inactivity reboot” is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology.

    This is weird framing. The feature makes it harder for anyone to break into the device.

    tamimio 5 hours

    Not weird, not anyone can buy those equipment to break into a fully updated phone, in fact, it’s pretty much only law enforcement can or will have access to them, so that statement is true, it will make it harder for police to do so.

    ethagnawl 4 hours

    That's not how exploits work, though. This is also the reason why backdoors in encryption and the like are never a good idea. Sure, "police" are the ones _most likely_ to use this tool (developed by a private company...) to use this exploit to break into iPhones. However, anyone who is motivated enough and/or has the resources _could_ also do it.

    nikanj 3 hours

    You can buy the mandatory TSA key for your suitcase lock from eBay for a few bucks. Tools have a way of falling off the truck at the loading dock

  • mmooss 5 hours

    I wonder why Apple, with its resources, doesn't take the lawfare approach to someone attacking its phones, for profit, and damaging its reputation.

    bigyabai 4 hours

    Apple tried suing NSO Group, which is one of the most wanton and dangerous iPhone hacking firms anywhere in the world. Hilariously, halfway through the case Apple turned a 180 claiming some trade secret danger, and begged the court to drop the case: https://appleinsider.com/articles/24/09/13/apple-files-to-st...

    This entire lawsuit was bizarre, and weirdly mishandled by Apple. It suggests to me that Apple was threatened, either by US spying agencies, NSO Group or NSO's local jurisdiction.

  • TazeTSchnitzel 6 hours

    Is it maybe providing a bogus NTP server or something? Maybe the automatic reboot feature can be moved to the Secure Enclave or something, and made to only rely on the hardware RTC in a way that can't be tampered with.

    chrismarlow9 5 hours

    Here's a deeper dive on that question:

    https://naehrdine.blogspot.com/2024/11/reverse-engineering-i...

    Tl,dr: it's likely baked into the sep, no ntp

    I'm wondering if you put the phone into a mode where it thinks it's dialing emergency services or contacting them via crash detection etc that it won't reboot. I could picture a scenario where the code is written to never disrupt an emergency services call.

    Full disclosure I don't own an iPhone so this may not even be a thing. Just guessing based on liability risk from Apple of "what's more important than protecting the phone"

    6 hours

  • _justinfunk 3 hours

    I kept being thrown off by the headline and article saying "cops".

    monster_truck 3 hours

    Why? The only people that care about that are obnoxious judges and asshole state troopers

  • 15155 2 hours

    It's amazing that this hasn't been tried as tortious interference. If MMOGlider can be found liable, why can't Cellebrite or GrayKey? Every TOS has anti-reverse-engineering clauses.

    wat10000 1 hours

    In the implicit hierarchy of our society, large corporations and law enforcement are both near the top, whereas ordinary people are waaaaaay at the bottom. Something that helps ordinary people at the expense of large corporations gets squashed, but if it helps law enforcement that's a different matter altogether.

  • Melatonic 6 hours

    I wouldnt be surprised if they had a backdoor into the Qualcomm chip that Apple decided to oddly still include in most of their US iPhones vs the international versions that come with their own internal modem

    clueless 3 hours

    that Qualcomm chip that apple uses is a modem, so not sure it's that relevant to the phone's security in this case...

    canada_dry 2 hours

    This extremely well hidden backdoor was an interesting find:

    https://news.ycombinator.com/item?id=38783112

    bigyabai 4 hours

    I wouldn't be surprised if they had a backdoor into the Secure Enclave. Apple is definitely a part of the US' NOBUS scheming, whether or not cops get to use it.

    monster_truck 3 hours

    The past few weeks of people ripping into it have demonstrated that SE is mostly reality distortion and does not offer any unique or meaningful protection. I have no doubt the old modems had deficiencies, the new ones assuredly do too. Just a changing of the guard for however long it lasts.

    I wouldn't call it scheming though. The approach of choice to (scare quotes) ensuring continued access has traditionally been one where there is no overt coordination or communication. The ideal case is one where every engineer, pm, qa, leadership earnestly believe that they have done a good job/the correct thing... and then there is some deficiency that handily bypasses all of that, exposed publicly, without any authentication and a convenient lack of logging, or some oversight in the specification/standard everything operates against. Real world examples of this include backends to vehicle telemetry/connectivity apps that hand over complete driving histories with the right ip, json and a vin, or flock somehow deploying ~nationwide with a static password and no append only logging in each device. They're flagrant violations of best practices, without conseqeuences or liability.

    That's one of the more incredible things about LLMs, the rate at which they are finding these needles in haystacks is only going to accelerate. It's the end of an era. These things were never used for what they should have been, I struggle to imagine a legitimate argument in favor for them that isn't carrying water for the wrong team.

    eli 3 hours

    So the FBI publicly fueding with Apple over encryption is all just misdirection? I dunno about that

    monster_truck 3 hours

    More a matter of who has what when. The FBI is ass and anyone there I would have vouched for retired a bit before 2016.

    That aside, it doesn't change their extensive history of ensnaring and enabling mentally deficient young men to incriminate themselves.

    You could attempt to argue that anyone they can do that to is inherently a risk or threat because any other group could have done the same, but at the same time this approach broke containment and is being directed at a markedly more pale demographic, ie https://en.wikipedia.org/wiki/The_Base_(neo-Nazi_group), with seemingly no counterplay

    bigyabai 3 hours

    The "feud" happened only a year after the Snowden leaks revealed Apple's cooperation with the FBI.

    Both of them needed a PR win, and San Bernardino gave both sides exactly what they wanted. If it wasn't collusion, it was certainly convenient for Apple and the FBI both.

  • Cider9986 5 hours

    Offtopic:

    >Even if that device doesn't have the ability to turn on Airplane Mode or to turn off the transmitters through the Control Center of iOS.

    IIRC, the default on iOS is that anyone with your locked device can enable airplane mode which is concerning simply for thieves. But I suppose they have to use faraday bags anyway because of the Find My network.

    jonahhorowitz 3 hours

    You can (and should) disable access to the Control Center when the phone is locked. You could, alternately, remove the “airplane mode” button from the control center.

    Syper 2 hours

    Thank you for those tips you both. I have never thought about the control center. Thankfully I have yet to have my devices stolen.

  • thraway3837 6 hours

    iOS has a remote erase feature. Its also a leaked video and doesn't show which version or model. So it could be something that is already patched, or soon will be. Remember to always keep your OSes update.

    klinquist 4 hours

    The first thing the authorities know to do is put your phone in an RFID bag/enclosure so it can't talk to the outside world.

    artisinal 5 hours

    It's a bit difficult to remote erase your phone while you are in custody.

    Unless you are Norwegian royalty and are notified of your upcoming arrest, then you can wipe all you need.

    4 hours

  • int0x29 1 hours

    These three quotes make me wonder if the police are effectively searching the phone before getting a warrant

    > given that oftentimes they can’t immediately try to break into iPhones that have been seized. That could be because police are still waiting for a court authorization to do so

    > GrayKey Preserve and Evidence Preservation Mode are also designed to combat another iPhone feature that automatically deletes certain data — such as cached locations, and recently deleted photos and iMessages — after a certain number of days. “We're gonna be able to preserve that data for an infinite amount of time.”

    > “That AFU state is captured,” by GrayKey Preserve and Evidence Preservation Mode, the employee says. “Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost. This is the true magic behind the GrayKey Preserve and the Evidence Preservation Mode function.”

    The power loss tolerance in particular looks iffy. The photo and iMessage bits are a bit more problematic in that light. I get that they claim the police aren't seeing the data but if they are extracting before a warrant that is effectivly the same as pre searching everyone and promising not to read it.

    Dylan16807 1 hours

    > pre searching everyone and promising not to read it

    Oh, like how bulk internet monitoring works. Ugh.

    strathmeyer 59 minutes

    [dead]

    ktm5j 1 hours

    I'm not seeing what you're seeing. The inactivity reboot wouldn't be a problem if they aren't waiting for a warrant. The fact that this article even exists supports the fact that they are waiting for warrants.

    Also, as someone who was the victim of a pretty awful violent crime I'm here to tell you that police are not the enemy. There are some really bad people out there, trust me.. if you ever met one you would probably be okay with cops violating their privacy.

    LorenPechtel 41 minutes

    Police are not supposed to be the enemy. All too often these days they become the enemy, though.

    1 hours

    writtenone 1 hours

    There's no world in which cops can or will only violate the privacy of obvious criminals.

    It becomes "well we need to scan websites to make sure there's no X, Y, or Z, and prosecute the site operators who don't cooperate" real fast.

    AngryData 34 minutes

    The most likely person to assault me are the cops so I still think cops are the enemy.

    sixothree 1 hours

    Dahmer's victim would like to have a word with you.

    whatsdowndog 1 hours

    >> police are not the enemy

    You are on the wrong website buddy. The group think here doesn't like statements like these.

    toomuchtodo 56 minutes

    Help yourself to the long list of "people with a monopoly on force and who cannot be trusted."

    https://www.prisonpolicy.org/blog/2026/01/26/police_miscondu...

    https://www.prisonpolicy.org/blog/2020/06/05/policekillings/

    https://www.policedatainitiative.org/datasets/

    https://policecrime.bgsu.edu/Home/Crimes

    https://ij.org/the-ij-database-of-alpr-abuse/

    https://ndi.iadlest.org/home

    "And some, I assume, are good people."

    jmward01 1 hours

    Most police aren't the enemy. Unfortunately it only takes a few that are or one that is having a bad day. Black and white distinctions 'they are all good' or 'they are all bad', are a core problem. Recognizing that we need to hold police accountable and limit their authority and actions isn't saying police are bad, it is proper and necessary oversight and is what is best for citizens and police.

    AdamJacobMuller 6 minutes

    I have long said, and I will stand behind, that by and large the % of police which are assholes is about the same as the % of the overall population who are assholes.

    The only difference is that a random asshole on the street can't really do anything to me, I can just walk away.

    A random asshole cop has a crazy amount of discretionary power over me, even without him stepping outside departmental procedures or the law.

    NetMageSCW 45 minutes

    I would only agree with this if supposedly good cops were willing to throw their fellow bad officers under the bus, but that practically never happends, so they are essentially all bad.

  • axus 6 hours

    Does this mean iPhones are worth more to steal?

    daveoc64 6 hours

    This article seems completely unrelated to theft of devices.

    quux 6 hours

    Perhaps for a short time. As soon as Apple understands the exploit I expect them to patch it. They may even back port the fix to older iOS versions as well.

    franczesko 3 hours

    https://www.washingtonpost.com/technology/2024/09/13/apple-l...

    klinquist 6 hours

    No. This requires an expensive license for a government agency to purchase in order to take advantage of this functionality.

    loloquwowndueo 6 hours

    Sounds like “this tsa approved lock needs a special key you can totally not just buy on Amazon”

    polskibus 6 hours

    Can you provide a reference to that?

    kube-system 5 hours

    Government contract data is public

    Here's a renewal of one, presumably basic, license:

    https://bidbanana.thebidlab.com/contract/4jKIvKMvZdoWo3d6K6q...

    The product is not publicly available, and is sold only B2G: https://www.magnetforensics.com/products/magnet-graykey/#par...

    petergs 5 hours

    The article references Magnet Forensic’s Graykey being used for this. Wikipedia shows its like 15-30k per year[1]. Doubt the relevant exploit is available to the average phone thief.

    [1] https://en.wikipedia.org/wiki/Grayshift

    toast0 5 hours

    But still available to the above average phone thief that has a buddy in digital forensics that helps him prep the goods for sale.

    klinquist 6 hours

    Unfortunately not a one I can prove to you online. I have a family member who is a district attorney, so that's my source. He said that that companies like the ones mentioned in the article sell licenses to unlock a single phone to a city or county. The city or county pays if they consider it worth it. The cost can be 5 figures.

    klinquist 6 hours

    (so the people that discover these exploits will sell them to the companies for 6 or 7 figures, far more than they would get from an Apple/Android bug bounty)

  • delichon 6 hours

    I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.

    As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

    BeetleB 1 hours

    > I keep all of my most sensitive personal documents on my phone

    Why...?

    If I had anything I didn't want the authorities to get, I'd remove it from my phone before travel (e.g. put in cloud, etc).

    mmooss 5 hours

    It seems to me you are taking a big risk. Some considerations:

    > Cryptomator

    Much security is poorly implemented; you can't count on it being effective. Even Apple, which takes security very seriously and has world-class talent and enormous resources, fails to implement security effectively sometimes (as in the OP). Can Cryptomator do better? Find the most respected - by professionals - security solution you can.

    And on a device with many other functions - all the things you use your phone for - you risk all sorts of security holes in every function of app you use. And what happens to the data when your phone is backed up? Store the data on a single-purpose device.

    Also, on an Internet-connected device, you make the data potentially accessible to the entire Internet. Use offline storage.

    Bringing the storage device with you everywhere is asking for a mistake on your part - losing it, etc. Hide it someplace.

    > or legal access

    Ask a lawyer.

    jstanley 6 hours

    It seems foolhardy to carry your life savings around everywhere, encrypted or not.

    If you really want to keep this stuff on a phone at least stretch to a second phone and keep it somewhere safe.

    devin 5 hours

    or a separate hard drive in a fireproof safe or something.

    ryandrake 4 hours

    Exactly. Don't keep your life on your phone. We shouldn't have to take these precautions but unfortunately we do.

    Razengan 3 hours

    What if everyone at the airport or border stood together and refused to comply?

    fragmede 2 hours

    Oh my god, get out of crypto. Put your money into a bank instead of trying to one-man-army yourself into being Fort Knox.

    tenacious_tuna 2 hours

    Cryptomator appears to be a file encryption tool, not a cryptocoin anything. What're you reacting to?

    fragmede 2 hours

    I made the leap based on

    > could cost me my home and life savings

    but it's entirely fair to point out that Cryptomator itself is not a crypto wallet. I just know too many people irl that have lost thousands of dollars because they lost crypto private keys.

    Cider9986 6 hours

    It would seem wise to at least keep a backup in an E2EE cloud [1]. This could possibly allow you to not give access even if legally compelled.

    >As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

    Yes, it seems that way in the US: https://news.ycombinator.com/item?id=49922513

    If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.

    [1] https://www.privacyguides.org/en/cloud/

    0x262d 4 hours

    Yeah, getting all your sensitive stuff off your phone onto a secure cloud service seems like the obvious approach here right? They can still escalate what they try to coerce you to do, but they don't have physical access to your data just by taking your phone, and you can also leave the phone with them and only lose the device if needed. In my likely scenario - innocent traveler, they aren't looking for anything specific, but I still don't want them to look through my files and photos just because I happen to travel internationally - that seems like it puts it out of reach (and out of obvious view) for now.

    WithinReason 6 hours

    If you don't give access to law enforcement when they ask: straight to jail. Encryption is irrelevant in that situation. If they see the encrypted volume you need to provide them access.

    spl757 2 hours

    Precisely, unless there is plausible deniability that a blob of data is indeed an encrypted file they can just hold you in jail until you comply. There are encryption schemes that provide plausible deniability, but implementing would probably not be trivial.

    ChrisMarshallNY 6 hours

    Classic $5 wrench.

    Having thugs on speed dial opens a lot of doors.

    gonzalohm 6 hours

    So if an app installs an encrypted volume for which you don't have the password to, you go to jail? That doesn't make sense. How can they know if I have the password or not

    wahern 5 hours

    They can't know, they infer. AFAIU, normally they just detain you at the airport and harass you to try to break you. To jail you they're technically supposed to be confident enough about you knowing the password to be able to charge you with a crime (presumably something like obstruction, possibly specific to immigration law, otherwise right against self-incrimination might prevent a conviction on failure to disclose alone), or have other evidence of some other crime. Then you end up in the legal system, where courts handle due process and a judge, preliminarily, and then a judge or jury decides if you knew the password.

    Note that the recent high-profile case of a man being jailed involved him refusing to decrypt, rather than claiming he didn't know. He was deliberately trying to test the law regarding the permissible scope of inspection of digital data, to force the matter into the courts so the issues could be litigated in a controlled context untainted by other potential crimes; being arrested and charged was part of his plan.

    rdevsrex 6 hours

    Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.

    Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.

    glitchc 5 hours

    > The Fifth Amendment protects against self-incrimination.

    You can still be held in custody for obstruction of justice:

    https://www.findlaw.com/legalblogs/third-circuit/man-held-in...

    It took four years before he could secure his release:

    https://www.sophos.com/en-us/blog/suspect-who-refused-to-dec...

    nikanj 3 hours

    The fifth amendment doesn't do jack shit if they haul you away. After a few years of trials and appeals you might regain your freedom.

    BeetleB 1 hours

    He said "jail", not "prison".

    There's a difference.

    wslh 3 hours

    I think that the issue is that the law enforcement personnel could make you pass a bad time even if it's covered by the Fifth Amendment. The enforcement could be later than the arbitrary decision.

    throw0101c 1 hours

    > Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.

    SCOTUS: Hold my beer…

    :)

    midas89 4 hours

    you have the guy sitting in jail waiting for the courts to decide if his grapheneOS wiping his computer after wrong unlock codes is him obstructing.

    keep in mind that the "obstruction" charge can be and is abused as a catchall charge.

    MC995 4 hours

    > courts to decide if his grapheneOS wiping his computer after wrong unlock codes is him obstructing

    He didn't provide an incorrect code, or no code at all, he provided a duress code intended to destroy the device. There's a huge legal difference.

    izacus 5 hours

    Self-incrimination yes, but not for cases when the person compelled has evidence to incriminate another process in a case.

    roncesvalles 2 hours

    That being said, overlap protects you still. So if answering a question about another person might incriminate you, you don't have to answer.

    rdtsc 4 hours

    Can't they just hand it to you say "you enter your passphrase, but don't divulge it to us and then hand us the phone". In other words hinging the passphrase divulging to the 5th can backfire in that respect. It like saying we have a search warrant, you open the safe for us, it's fine if you keep the combination to yourself, we just need to get inside.

    kadoban 2 hours

    The act of unlocking it can incriminate you. It's ~proof that you have control of the device beyond what they already knew.

    nater5000 4 hours

    No, that's pretty absurd. It's not specifically about the act of speaking. It's the act of incriminating yourself.

    But that's all beyond the point, anyways. If they did hand you your phone and said, "enter your passphrase," you can just say, "I don't remember it." They can throw a fit and put more heat on you in various ways, but until they resort to torturing you or they develop mind-reading technology, there's not much they can do at that point until the case reaches a judge.

    That's not to say "I don't remember" is a sound, blanket defense. But it's sufficient for demonstrating that these dynamics all depend on willing participants which is partially why these laws are designed the way they are.

    rdtsc 2 hours

    If the search warrant and seizure wasn't a thing I'd agree with you. But I can easily see opening a phone interpreted not that differently than opening a safe or your reinforced front door.

    > But it's sufficient for demonstrating that these dynamics all depend on willing participants which is partially why these laws are designed the way they are.

    What happens if during serving a search warrant the door is impossible to open or they find a super reinforced safe. Owner can even say "I don't remember the combination"?

    DaveSchmindel 6 hours

    That's been my understanding until now as well... the latest on the case against Samuel Tunick has me worried and second guessing that blanket statement though...

    https://nccriminallaw.sog.unc.edu/2026/08/03/giving-police-a...

    3 hours

    simiones 5 hours

    That's completely different. Pleading the 5th and not testifying is completely different from giving false testimony - which is never protected. Even in a trial, if you are asked under oath if you handled the body, you are allowed to say that you invoke your 5th amendment rights not to respond; but you are not allowed to say "no, I didn't" if in fact you did (you can later be accused of perjury in addition to your conviction).

    delichon 5 hours

    Yeah, if you use it as a way to destroy data that gives them a whole new and powerful attack vector. 18 U.S.C. § 2232 is very broad.

    Razengan 3 hours

    What's more infuriating than laws like that is that there's a class of people completely immune to those laws.

    rtkwe 4 hours

    That case has the specific, very important, wrinkle that he provided a _destructive_ duress code, he could have continued to refuse to provide the unlock code just fine legally. It's the use of the duress code that is likely going to be getting him in trouble and that falls outside of the existing defined protections about being compelled to unlock safes/computers etc containing possible evidence against yourself.

    We'll have to see how that case goes but ultimately the reason he's getting in trouble is only tangentially related to his phone being encrypted. It's more correct to think of it like he smashed the phone to pieces (and imagine this definitively destroys the data for the sake of the metaphor) instead of it being about the encryption itself.

    LoganDark 1 hours

    He didn't smash the phone to pieces, he gave LE a hammer and they smashed the phone to pieces. It's entirely LE's own fault this happened -- they shouldn't have been trying to get into that phone, and it's their own fault it went wrong.

    Though I would expect courts to consider that he knew LE planned to enter the provided PIN, and that the duress PIN would then result in the phone being wiped, and therefore accuse him of doing the wiping anyway.

    But I don't think it's this guy's fault at all. LE is the one who asked him under duress, he easily could've feared for his life, and he did no direct harm. It was self-defense at worst.

    someothherguyy 1 hours

    > He didn't smash the phone to pieces, he gave LE a hammer and they smashed the phone to pieces. It's entirely LE's own fault this happened -- they shouldn't have been trying to get into that phone, and it's their own fault it went wrong.

    Setting a booby trap to destroy evidence that then gets destroyed when that trap is triggered is the same as destroying evidence. This is common sense, but also see https://en.wikipedia.org/wiki/Principal_(criminal_law)

    pieter_mj 6 hours

    If you travel abroad you must unlock. No 4th amendment for you.

    eli 3 hours

    That’s not the full story and not really correct.

    https://www.aclu.org/news/privacy-technology/can-border-agen...

    skinfaxi 6 hours

    You can decline but then they can seize is that right?

    alistairSH 5 hours

    In the US, that is generally true. They cannot prevent entry (by citizens), but can keep the phone for a period.

    mmooss 5 hours

    It would depend on the country.

    jstanley 6 hours

    This is mostly FUD. I've never been asked to unlock my phone when travelling abroad.

    FireBeyond 3 hours

    TSA thought it odd that I had two MBPs (work and personal) and an iPad in my carry on, and asked me to power up all three.

    6 hours

    6 hours

    bryceacc 6 hours

    https://arstechnica.com/tech-policy/2026/09/immigration-advo...

    >CBP only searched the electronic devices of 55,318 international travelers,” the agency wrote, or 0.0013%.

    would suck to be one of those 55 thousand people. I've never been bitten by a shark but I sure care about people that have?

    serf 6 hours

    I get asked to unlock my dev laptop every single time I go from the US to Montreal. The TSA person sits there and waits for my WM to boot before waving me past.

    It seems more like they're trying to determine that it is in fact a laptop and not something resembling one.

    folmar 2 hours

    In EU normally BIOS startup screen is the point at which they wave it as ok.

    sellmesoap 41 minutes

    Might also be documenting serial number and identifying radios associated with your device. As a dragnet etc. Palantir and co love them some massive data hoards!

    dylan604 5 hours

    That's been my experience as well. I've visited Sydney twice, and both times I've been asked to light up my devices. Granted, I was on work trips requiring three separate laptops which does probably look suspect, but once they were booted they did not request to browse anything and were satisfied to see them working.

    0cf8612b2e1e 4 hours

    All the more reason to dual boot into a decoy OS. Does not stop a targeted investigation, but lets you pass a cursory examination where some thug might want to rifle through your data.

    Edit: now I am gleefully thinking about how I would craft my decoy desktop persona. What gives me the most effective non interesting profile.

    matheusmoreira 3 hours

    Now I'm wondering what exactly they're looking for... What else could those devices have been?

    0cf8612b2e1e 2 hours

    Maybe the agent gets lucky and you have a folder full of nudes on the desktop.

    wildzzz 2 hours

    They are looking to see if you've gutted a laptop and filled it with explosives or drugs. Although tbh, a computer that can launch a desktop doesn't need much physical space and the battery just has to last long enough for a cursory glance.

    Havoc 4 hours

    Dismissing something as false just because you haven’t personally experienced it is quite something

    jstanley 4 hours

    "If you travel abroad you must unlock" is hardly the central experience. It is FUD.

    Havoc 3 hours

    No, it's just incredibly bad reasoning. I've not been in a car crash yet, but I don't conclude that therefore talk of road safety is FUD.

    dana-s 6 hours

    I believe the parent comment is talking about leaving US, coming back to the US and then having US's border patrol do so. If that is also what you understood, are you an activist or anyone whom would be of interest to the feds to be asked so? Otherwise saying "I've never been asked" sounds like a common thing for most people.

    jimt1234 6 hours

    What's the BFD? I have nothing to hide! (I hear that shit all the time. So annoying.)

    jstanley 6 hours

    Reading this kind of stuff online made me afraid of international travel for many years. When I finally did it literally nothing happened to me.

    Yes it's bad that the government overreaches, but it is also bad for your mental health to worry about it.

    bryceacc 3 hours

    this sounds exactly like the chilling effect and fear the US government wants to instill on people these days. They want us to know big brother is watching, they have the power to stop and search you, and you can't do anything about it

    UpsideDownRide 5 hours

    It's even worse for your mental to never think about It.

    simiones 5 hours

    It's important to separate what can happen from what will happen.

    The majority of people walking in the worse neighborhoods of LA or Chicago never have a single crime happen to them. But that doesn't mean that it's safe to go in a bad neighborhood - and it really doesn't mean it's safe to go there wearing designer clothing, gold watches, diamond rings and wearing your Apple VR device.

    The same is true for travel. It's perfectly safe for the vast majority - but it's very important to be aware what may make you a target and what can happen to you if you are. Tens of millions of people visit the UK or China every year with no incident. But if you're a public active supporter of Palestine Action, or an active demonstrator against the CCCP respectively, be aware that you personally face a real risk from this travel, and your devices are actually very likely to be searched at those borders. Vice versa though (anti-CCCP activist traveling to UK, PA activist traveling to China) is perfectly safe, though.

    Liftyee 5 hours

    Last time I checked, the Soviet Union was dissolved.

    (CCCP = Union of Soviet Socialist Republics...)

  • Cider9986 6 hours

    For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.

    GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.

    On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.

    If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.

    [1] https://strongphrase.net give memorable ones which is cool.

    NetMageSCW 43 minutes

    Note that the iPhone also can be set to use a complicated password instead of a PIN and it will require it on first unlock.

    burningChrome 2 hours

    >> then a fingerprint with a second factor pin as the secondary unlock

    Unless you have a 4 or 4XL which are pretty popular with graphene os users. The weird thing is the 4 and 4XL are the only models without fingerprint because Google was pushing its #D Face Unlock System at the time.

    The funny part is Graphene by default now disables face unlock on newer Pixel models.

    fluidcruft 4 hours

    Why not automatically power down if any unknown USB device is attached?

    ssl-3 43 minutes

    Or shut down when any USB device is attached while the phone is locked/inactive?

    It'd work like this: Unlock phone, plug in USB widget; it works.

    Or: Plug in USB widget without first unlocking phone; phone shuts down.

    eli 3 hours

    So like you connect it to your computer for the first time and it shuts off?

    sellmesoap 2 hours

    Could request unlock and reboot if no valid pass is accepted within n minutes.

    olyjohn 3 hours

    Yeah... that could be an option you configure.

    dzhiurgis 9 minutes

    TBF pretty much no one connects their devices anymore to anything other than charging. For those who do some timeout could work.

    isoprophlex 3 hours

    Better wire it up to a thermite charge just to be sure. Untrusted USB device? Hope you enjoy 1400 degree molten iron

    nkrisc 2 hours

    Or it’s not enabled by default.

    83 3 hours

    that doesn't seem unreasonable. You only have one first time. Maybe two if you upgrade your computer more often than your phone.

    39 minutes

    usern20260720 1 hours

    1. disable shutting down. 2. connect device and fingerprint it. 3. enable shutting down

    NetMageSCW 40 minutes

    How do you disable shutting down?

    iamnothere 5 hours

    Never use a website to generate a password for something important like this. You can print out diceware passwords and roll dice.

    throw0101c 1 hours

    > You can print out diceware passwords and roll dice.

    Or on the CLI:

    * https://packages.debian.org/search?keywords=diceware

    * https://packages.debian.org/search?keywords=pwgen

    fluidcruft 4 hours

    You can just take a picture of a pile of dice, a pile of rice, or a tree, patch of grass, etc, and compute a secure hash/whatever and base six it to get the rolls.

    theendisney 2 hours

    If you have a computer do something you cant know if it really did what you wanted.

    Brybry 3 hours

    Are you saying to take a hash of a picture and convert that to base 6 for your dice rolls to plug into a word list for creating a passphrase?

    Is that actually better (in practice, not in terms of entropy) than /dev/urandom? I have a lot less trust in my ability to successfully scrub a picture from my phone that deterministically created my passphrase.

    lisper 2 hours

    > Is that actually better (in practice, not in terms of entropy) than /dev/urandom?

    It offers protection in the event that your /dev/urandom is compromised. Otherwise no.

    (Of course, if your /dev/urandom is compromised then whatever process you use to compute a hash of a photo is likely compromised as well.)

    Matumio 2 hours

    If you're concerned about that, you can concat your JPEG with a few bytes from /dev/random and you'll get the security of whichever is stronger. In practice none of this will be your weakest link.

    NetMageSCW 41 minutes

    It is possible that using a JPEG with its known bytes could make the final effort weaker than if you just used /dev/random.

    cj 3 hours

    I actually have a lava lamp next to my desk for this reason. Snap a photo, compute a hash!

    theendisney 2 hours

    Count the bubbels with your fingers while you count from 0 to 9. Every x fingers you write down the number.

    Extra points if you hold you face really close and count in a dead language. You can also make ordered hand gestures in stead of counting on your fingers. Be a wizard about it!

    cheschire 1 hours

    Yer a cryptographer, Harry!

    dylan604 5 hours

    > On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase

    Why do you call out just one OS? It's a good idea for any OS.

    subscribed 1 hours

    Because apart of the IOS, according to GrayKey and Cellebrite, GrapheneOS on Pixels is the only phone where it even makes sense (realistically).

    Cider9986 5 hours

    Yes, in fact on GrapheneOS it's less necessary and it's only necessary if you don't want to rely on the secure element rate limiting.

    GrapheneOS allows using a passphrase with more convenience because of the fingerprint plus second factor pin (I don't think you can just have a pin as a secondary unlock). You don't need to enter the passphrase every time you unlock with this setup, only when first starting up.

    The official opinion: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

    rtkwe 5 hours

    This seems specific to GrapheneOS (unique as far as I know though I'd be happy to learn otherwise) where you could set a very long first unlock passphrase and have a shorter less cumbersome fingerprint plus pin option for subsequent unlocks. I wouldn't want to have to enter a long passphrase every time I unlock but once a day isn't so bad.

    dylan604 5 hours

    I don't run GrapheneOS, but I have an >15 character passphrase that must be used before biometrics can be used after reboot. I haven't used a 4-digit pin since the option to not use it was available.

    rtkwe 4 hours

    The specific extra that grapheneOS adds is that you can have a required Fingerprint + PIN with a shorter easier to enter pin while also having a long first unlock passcode. Only a first unlock passcode then biometrics is not secure in the US if your device is in the AFU/biometric-only (after first unlock) state because you can be easily and legally compelled to provide a biometric unlock.

    https://threecats.au/two-factor-pin-fingerprint-unlock-graph...

    dataflow 5 hours

    The option was there in Cyanogenmod back during the OnePlus One days. It was such a step backwards when it was removed. You almost had to wonder if it was deliberately done at the request of some TLA to prevent users from using too strong of a password for decryption.

    rtkwe 4 hours

    I doubt it, mostly because phones were a lot easier to crack back in those days already so I doubt a TLA needed to push for it to be removed.

    23ahGa17 5 hours

    People believed the reboot feature last time GrapheneOS was mentioned. It is of course nonsense.

    Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.

    3128128 1 hours

    GrapheneOS is critical infrastructure. Questioning it is not like criticizing Neovim. People can get detained, killed and more.

    Perhaps the reflexive genius downvoters can explain what happened to Richard Medhurst? After his phone was snatched and the authorities pretended not to be able to decrypt it, he went on a GrapheneOS promotion spree on X and wanted to write a book about computer security.

    Now he has disappeared for nearly 6 weeks. How many more people do you want to get in trouble with your false promises?

    Cider9986 5 hours

    > Shut down the phone in areas with a high snatch risk.

    Yes this is of course safer. What evidence do you have that it doesn't work on GrapheneOS, though?

    https://www.computerweekly.com/feature/Journalist-Richard-Me...

    1298436 5 hours

    Medhurst has no evidence that it worked either. He hasn't tweeted since August 24th, I hope he is well and at liberty.

    markus_zhang 5 hours

    To add an extra layer of safety. Bring a secondary phone when travelling by airplanes, especially to other countries. You should also use it frequently, maybe with some side apps to make it look like it's your daily phone.

    ryandrake 5 hours

    Or, just don't bring a phone if you're particularly vulnerable. What are they going to do? Deny you entry because you don't carry a phone? If we're really at that point, where merely not having some item is suspicious, we're in deep shit.

    altruios 4 hours

    I wouldn't want to be the one to test this. That's an indication of how deep we dug ourselves in.

    midas89 4 hours

    if you don't know yet, we are in deep

    stefan_ 5 hours

    The internet exists and can transfer your data with no customs and borders, so if you are at risk of being snatched, the correct choice is to not carry a phone (or laptop, or..) at all.

    Someone 5 hours

    https://en.wikipedia.org/wiki/Great_Firewall:

    “The Great Firewall operates by checking transmission control protocol (TCP) packets for keywords or sensitive words. If the keywords or sensitive words appear in the TCP packets, access will be closed. If one link is closed, more links from the same machine will be blocked by the Great Firewall. The effect includes: limiting access to foreign information sources, blocking popular foreign websites and mobile apps, and requiring foreign companies to adapt to domestic regulations. Due to the Great Firewall, China has one of the lowest cross-border internet traffic rates in the world. Usage of foreign apps in China is minuscule; Asia Society estimated in 2026 that foreign apps blocked by the Great Firewall have extremely low traffic, particularly compared to domestic apps; the top five domestic apps saw traffic that was 1,000 times more than the top five foreign apps.”

    oasisaimlessly 4 hours

    The Great Firewall doesn't restrict SSH, so you can functionally ignore it (assuming using e.g. `ssh -D` is second-nature to you).

    wat10000 1 hours

    Last time I tried it (which was quite a while ago, but I'd be surprised if they became less restrictive) ssh was fine for interactive use, but they did some sort of traffic analysis to kill connections that got used for tunneling other traffic like that.

    When I was there last year, it took some doing to get a VPN working. Mullvad was pretty good but it would take a few tries to find an endpoint I could connect to. The simplest escape hatch is to have a cellular connection from another country, but that's either expensive or slow.

    alkh-qrt 4 hours

    If you live in the UK and travel to the US and are afraid of state actors, leaving your hardware at home seems like a bad idea, too.

    gambiting 4 hours

    Despite all the nonsense that's posted about UK on the internet, British agencies do require a warrant to enter your home. TSA on the other hand does not require a court order to confiscate and mirror your device before giving it back to you.

    Edit: Just to be perfectly clear - Border Force in the UK can do the exact same thing to you once you return, British citizen or not. Leaving your device at home is still the safest choice.

    Cider9986 4 hours

    I believe it's CBP that does this, not TSA. Therefore Americans don't have to worry about it during domestic flights.

    > Despite all the nonsense that's posted about UK on the internet

    How is it nonsense? I'm not debating the warrant thing, but it's very reasonable to assume the UK has terrible protections for these sorts of things.

    https://en.wikipedia.org/wiki/Key_disclosure_law#:~:text=Uni...

    https://eylenburg.github.io/countries.htm

    gambiting 4 hours

    I mean in a broad sense if you read any news about the UK it might looks like a dystopian surveillance state where you get arrested for criticising the king(I kid you not - I've had multiple American coworkers ask me if this is true).

    And yes, UK has some awful laws around this. Yes it has put people in jail just for planning a protest before. Yes you can go to jail for not disclosing your passwords. But what you read on the internet is almost laughably out of proportion - no, you won't get arrested for posting a meme about the king.

    nostrademons 3 hours

    FWIW the same applies to flying in the U.S. as long as you're not a person that the government cares about. I haven't had any issues with either TSA or CBP since 2011 (when, apparently, being multiracial with facial hair made me look Middle-Eastern and looking Middle-Eastern is a cardinal sin at U.S. ports of entry). Neither has anyone I've observed at the airport, and that's thousands of people per flight, and I fly about 3-4 times per year. There's plenty of stories on the Internet, and I don't doubt the stories are true, but the Internet can easily make a 1-in-a-million occurrence happen every day (indeed, given the sheer numbers, a 1 in a million occurrence does happen every day, it's just that it's unlikely to happen to you).

    subscribed 1 hours

    Yeah, it's true, you should go back to your coworkers and straighten it up.

    6 people got arrested for trying to say "Not my king!" BEFORE his coronation: https://londondaily.com/not-my-king-anti-monarchy-protesters...

    Before they had a chance of protest. After months of discussing the planned protest in details and getting a green light from the Met Police: https://www.bbc.co.uk/news/uk-65542558

    It's not like Republicans in the UK are a violent group, unlike far right coddled by the same Met police.

    52 people were arrested DURING the coronation, for example for holding a placard "not my king": https://londondaily.com/over-52-anti-monarchy-protestors-arr...

    Police arrested despite KNOWING it's baseless and frankly illegal: https://novaramedia.com/2025/03/11/police-officer-who-arrest...

    Tell me some more how it isn't arresting for criticising the king. Oh, well, technically he wasn't a king yet.... but that's even worse to be fair.

    dmitrygr 3 hours

    > news about the UK it might looks like a dystopian surveillance state where you get arrested for criticising

    Might it "seem" that way because it is that way?

    https://www.forbes.com/sites/steveforbes/2025/09/09/people-a...

    https://www.telegraph.co.uk/news/2026/08/22/britain-has-beco...

    https://freespeechunion.org/news/more-than-62-000-people-hav...

    Oh, and your government itself openly states it on record, too: https://hansard.parliament.uk/lords/2025-07-17/debates/F807C...

    gambiting 3 hours

    How many of those people got arrested for criticising the king?

    Not that this is some kind of great bar to clear, but if you're going to argue with what I said, argue with what I actually wrote.

    dmitrygr 3 hours

    Ok then. Soviet Union had free speech too. Nobody got arrested for criticizing Reagan or Churchill.

    Clearly the point is clear. Why nitpick pointlessly?

    gambiting 2 hours

    You've missed my point entirely, by a country mile.

    Someone above asked me how it was nonsense. I responded that people parotting the point about getting arrested for criticising the king is nonsense - like for instance, my American coworkers asking if that's true, because they read it somewhere on the internet. That is nonsense.

    If you want to argue with this point please do, but also please observe the rest of my comment and especially the parts that I haven't actually said.

    2ahg7 1 hours

    Yes, and no one mentioned parroting the king in this thread. Journalists under known observation from the state, which the UK does arrest from time to time, were mentioned however.

    You can use other European countries like The Netherlands, which is a lawless police state with a liberal cover, as well.

    subscribed 1 hours

    Let me repeat reports about these arrests here as well, for your convenience.

    6 people got arrested for trying to say "Not my king!" BEFORE his coronation: https://londondaily.com/not-my-king-anti-monarchy-protesters...

    Before they had a chance of protest. After months of discussing the planned protest in details and getting a green light from the Met Police: https://www.bbc.co.uk/news/uk-65542558

    52 people were arrested DURING the coronation, for example for holding a placard "not my king": https://londondaily.com/over-52-anti-monarchy-protestors-arr...

    Police arrested despite KNOWING it's the member of public doesn't commit any offence: https://novaramedia.com/2025/03/11/police-officer-who-arrest...

    I'm afraid you unwittingly misled your coworkers.

    gambiting 1 hours

    I'm aware you are still going to twist what I said to prove your point, but I really don't fancy repeating the exact same point for the third time just so you can say something unrelated.

    Dylan16807 1 hours

    They already said you can get in trouble for [planning] protesting. They said you won't get in trouble for online criticism. Your links about protests aren't proving anything.

    subscribed 1 hours

    It's not in the comment I'm responding to,

    >> Someone above asked me how it was nonsense. I responded that people parotting the point about getting arrested for criticising the king is nonsense

    Protesting against the king is criticising the king IMO. I didn't see his quantifier, since I would agree that online critique of the king in particular is not yet penalised.

    Not surprising you're implying bad faith though, if we're splitting the hair this thin.

    (and this specific planning of the protest was so heavy handed, because it belong to one of the two naughty protests, environmental. The second naughty one is protesting against the genocide. The rest is okay)