this post was submitted on 28 Jul 2026
310 points (99.1% liked)

Privacy

4946 readers
178 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS
 

The U.S. government has charged Samuel Tunick with allegedly typing in a passcode to wipe his phone before officers could search it. “I hope people understand that the charges against me are meant to intimidate people,” he said.

Just another example of the Trump admin trying to intimidate protestors using whatever the fuck they can to bring up whatever charges they can.

top 50 comments
sorted by: hot top controversial new old
[–] quick_snail@feddit.nl 48 points 3 days ago (7 children)

I mean I think privacy advocates are looking to set a precedent. This case is perfect for us.

The officer was the one that wiped the data, so hopefully he'll loose his job. And they should be sued to pay compensation to the victim for the damages caused by lost data

load more comments (7 replies)
[–] Juice@midwest.social 15 points 3 days ago

Turning this feature on right now, thanks for the reminder

[–] resipsaloquitur@lemmy.cafe 38 points 4 days ago (3 children)
[–] apfelwoiSchoppen@lemmy.world 76 points 4 days ago (1 children)

Destroying evidence, which is funny because that assumes there was any to begin with, which they can't prove.

[–] tyler@programming.dev 36 points 4 days ago (5 children)

That wasn’t the charge. The charge is destruction of property that the government is trying to hold on to.

[–] Dryad@lemmy.world 55 points 4 days ago (7 children)

Which would still be unreasonable search and seizure.

load more comments (7 replies)
[–] far_university1990@reddthat.com 16 points 3 days ago (1 children)

But he did not destroy, officer did by type in code he got. His mistake to trust user.

[–] tyler@programming.dev 3 points 3 days ago

I agree. I don’t think the charges will hold for exactly that reason, the device owner didn’t do anything to destroy the device and also didn’t prevent seizure. The CBP still has the device.

[–] apfelwoiSchoppen@lemmy.world 8 points 4 days ago (1 children)
load more comments (1 replies)
load more comments (2 replies)
[–] clay_pidgin@sh.itjust.works 34 points 4 days ago (1 children)

Eating a meal? A succulent Chinese meal!?

[–] No_Eponym@lemmy.ca 4 points 2 days ago

Get your hand off my penis!

[–] orbituary@lemmy.dbzer0.com 31 points 4 days ago* (last edited 4 days ago)

Having a phone? Having a secretive phone?

[–] abbiistabbii@piefed.blahaj.zone 11 points 3 days ago (4 children)

What happened to the fourth amendment

It got amended out

load more comments (3 replies)
[–] OwOarchist@pawb.social 20 points 4 days ago (3 children)

Okay, new plan: instead of a duress password that deletes data, a duress password that randomly scrambles your decryption keys. (And of course all important data is already encrypted.)

No 'evidence' was destroyed. The encrypted data is still there, perfectly intact. It's just that easy access to it has been cut off, since now not even you have a way to decrypt it.

[–] northendtrooper@lemmy.ca 40 points 4 days ago

nah, the duress should load a 'fake' account with dummy information and media. While deleting the real account in the background. What gave it away was the 'blinking' screen. Something that GrapheneOS team should be avoiding.

[–] ornery_chemist@mander.xyz 29 points 4 days ago (1 children)

That's actually what the duress password does and did here. Deleting the data would be too slow, so it gets rid of the keys instead.

[–] Darkassassin07@lemmy.ca 10 points 3 days ago (2 children)

I wonder; can those keys be backed up to a seprate device, and reinstated later?

So: could you use the duress passcode to wipe the keys, making the device unreadable; then later use a backup to restore those keys and regain access?

[–] ornery_chemist@mander.xyz 12 points 3 days ago (4 children)

My recollection is that the keys are stored on the TPM and can't be exported. Backups kick the can down the road; now the adversary demands access to your backups. If the keys can't leave the TPM and the TPM is wiped, then there is no more leverage that can be applied that will unlock the phone. The adversary might still try to get at other kinds of backups anyway to search for whatever data they were after to begin with, but that's a separate issue.

[–] panda_abyss@lemmy.ca 11 points 3 days ago (1 children)

I'm sure there's a difference between "I deleted evidence" and "I deleted evidence off this device you're inspecting without a warrant, you can have it with a warrant".

But I also feel that unless there's suspicion of a specific crime, you can't really accuse someone of deleting evidence. And no, protesting peacefully is not a crime.

[–] quick_snail@feddit.nl 7 points 3 days ago (2 children)

In the US, they can't force you to give a password. Because they can't prove you haven't forgotten it.

In this case, it was an officer who was attempting to gain unauthorized access to a device and then accidentally entered a code that caused it to wipe its own data

So the activist has a pretty good case here to sue the officer for damages

[–] OwOarchist@pawb.social 5 points 3 days ago (1 children)

Because they can’t prove you haven’t forgotten it.

Technically, no.

They can't force you to give a password because of court precedent around the 5th amendment. Courts ruled that being forced to give a password counted as being forced to divulge information and was thus a violation of your 5th amendment right to remain silent and not incriminate yourself.

That's why they're still allowed to force you to give biometrics to unlock a device, though. Different court cases have ruled that being forced to put your finger on a fingerprint reader or show your face to a face scanner does not count as being forced to divulge information -- since it's action, not information -- so law enforcement is still allowed to force you to do those things.

(Which means, if you're about to be arrested or you're crossing a border or something and you don't want your device searched, you should disable any biometric unlocking features first. I'm not familiar with Android, but in iphones, you can do this by restarting/powering off the phone (always requires pin/password on first boot) or by pressing the lock button repeatedly while already locked.)

[–] ByteSorcerer@beehaw.org 4 points 3 days ago

Android also requires you to enter a password on first boot. So rebooting also works there.

load more comments (1 replies)
load more comments (3 replies)
load more comments (1 replies)
[–] ch00f@lemmy.world 14 points 4 days ago (2 children)

The correct solution is a duress password that just opens a generic smartphone interface with nothing on it. Nothing suspicious. They won't even know to investigate.

[–] Darkassassin07@lemmy.ca 11 points 3 days ago* (last edited 3 days ago) (1 children)

Both. Wipe the real keys so they can't read it if they do a more invasive look into the device; but present a clean profile to the dumb cop that entered your duress pass, to curb suspicion.

load more comments (1 replies)
load more comments (1 replies)
[–] msokiovt@lemmy.today 19 points 4 days ago* (last edited 4 days ago) (2 children)

The charge is destruction of evidence because he used a duress password (he was legitimately under duress) to wipe the encryption keys off his phone, making it impossible for officers to do anything with.

This was a violation of his 4th Amendment and 5th Amendment rights (4A is unreasonable search and siezure, while 5A is prevention of forced self-incrimination). Oh wait, the PATRIOT Act and Red Flag laws made 4A and 5A (respectively) defunct.

[–] iocase@lemmy.zip 5 points 3 days ago (3 children)

There are 4th amendment free zones in the US surrounding certain areas... Meaning the government can just violate your 4th amendment because it decided you have no rights due to living within a no rights zone.

Freedom!

load more comments (3 replies)
load more comments (1 replies)
[–] Marija_@programming.dev 1 points 2 days ago

Different CDMWorlds, different assumptions about privacy.

[–] fizzle@quokk.au 9 points 4 days ago (4 children)

I don't really know anything about privacy and security in this context, but I remember playing around with encrypted disks and reading that encryption isn't really useful if your adversary knows that something exists albeit encrypted.

I think this is similar: having a freshly wiped phone is going to attract attention. I'm not saying it's the wrong move in all cases, but it's probably the wrong move in the kinds of situations most people are going to encounter.

I think the latest advice for attending protests and similar is to take a cheap burner.

[–] otacon239@lemmy.world 16 points 3 days ago (1 children)
[–] quick_snail@feddit.nl 10 points 3 days ago

The duress password is literally the solution to this.

After the keys are wiped, they can't get the data - even if you give them the password before or after they repeatedly hit you with a wrench

[–] Badabinski@kbin.earth 7 points 3 days ago (1 children)

What we really need is deniable encryption, where you can decrypt just a specific layer of your device which is entirely innocent, while also possibly destroying the deeper layer which has anything incriminating. It's been a concept since the 90s, but it's not widely used or known of.

load more comments (1 replies)
[–] triple_entendre@infosec.pub 6 points 3 days ago (2 children)

The trouble here is that this happened to him in an airport, not during a protest.

load more comments (2 replies)
load more comments (1 replies)
load more comments
view more: next ›