Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you want actual legal advice pay for an actual lawyer. You aren’t going to get it asking a bunch of randoms on a tech forum.

Since we’re techies we tend to think about technological nuances and have a certain literal frame of mind (eg “They can’t make it illegal for me to just type the wrong pin” is the type of thinking I’m talking about here) whereas in law weird precedents and your intent really matter so you really need expert advice and either way, you are throwing yourself at the mercy of a stochastic process that depends on a bunch of fallible humans along the way many of whom have the power to make your life extremely miserable.

Technicalities of destroying the data vs destroying the key to the data, destroying the data when you have a backup etc may matter a lot to us but may not mean anything in an actual judicial process depending on how it goes.

It seems to me if you have data you don’t want subject to seizure at a border it is best not to travel over the border carrying that data. If you have a backup (in your scenario), why not restore your phone from that backup after you have travelled, and not cross the border with anything that is likely to be a problem if seized? Then you’re not putting yourself at risk from this process.



I am a lawyer (this is not legal advice) and agree with the main thrust of this comment.

The law is not “hackable.” Ultimately people are making decisions about guilt and punishment. And judges really, really don’t take kindly to defendants who think they’re trying to outsmart the court.


> The law is not “hackable.”

The point the sibling comments miss is that for the hoi polloi, this one-weird-trick does not work because such laws has been written to broaden the scope as much as possible by heavily relying on intent instead of the micro mechanics (which keep changing) AND the enforcers focus on the intent. For the rich and wealthy, the law may be the same but the enforcement is wildly different because they absolutely have the enforcers on their side. I bet such people don't get strip searched like the unwashed masses as they roll off their private jets.


i used to work for a rich one like that ~20 years ago. we were walking through the border without a word, boarding his private jet, and crossing the Schengen border.


> The law is not “hackable.”

It absolutely is. The rich and powerful do it all the time.


it's not a hack, it's a feature


Paying for something is not really a hack, because at least in this case, it’s the system working as intended.


Not sure what you mean by "in this case." I'm pretty sure that the founders intended the Bill of Rights to apply everywhere including the border.


Why do you think the Supreme Court disagrees with you?

See https://en.wikipedia.org/wiki/Border_search_exception


The Supreme Court has a long history of ignoring both the letter and the spirit of the law for the sake of politics and practical expediency. I can legally buy an AK-47 but not a Patriot missile despite the fact that the second amendment makes no distinction between different kinds of armaments. Allowing Patriots to be banned but not AK-47s is a distinction that the Court invented out of whole cloth. Likewise the weakening of the fourth amendment at the border is an exception that the Court invented out of whole cloth. Both of these exceptions were invented for defensible reasons. I don't want people to be able to buy Patriot missiles or nuclear bombs (or AK-47s). But that doesn't change the fact that there is a line that was invented by the Court out of whole cloth.

The problem is that the Constitution is broken, and has been since it was drafted. The right to bear arms probably should be conditioned on something more clear than the necessity of a well regulated militia (whatever the hell that means) to the security of a free state. The requirements for warrants probably ought to be weakened somewhat at border crossings. But the plain text of the Constitution does not allow this. The plain text contains no exceptions, and does not empower Congress to make exceptions. But changing the Constitution is hard, so rather than go through this slow, arduous process, everyone just punts the problem to the Court and says, "You deal with it." And so they do. The Court just does end-runs around the Constitution for defensible and practical reasons. But this doesn't change the fact that it is doing end-runs around the Constitution.


> Paying for something is not really a hack

Although bribery is a felony in itself

> it’s the system working as intended.

Maybe it is


It’s not bribery if the system is designed to support it.


Probably not in the same sense of "one weird trick" though.


Second lawyer here, well - ex-lawyer, I'm saying the first Law Talking Guy is 100% right.


It is somewhat hackable, but not to the extent that a computer is. Sometimes laws have some unintended loopholes that can be exploited for benefit if it isn't something obviously malicious.

But there are often vaguer higher level principles that can stop the fun, involving concept like "reasonable person" and "good faith" which are interpreted by humans. But this also doesn't happen always. Sometimes people do get away on technicalities, though many may suspect corruption in those cases, but sometimes the law is indeed powerless against certain novel tricks. There is no general answer.


Then why have circumventions of the 4th amendment not been shut down immediately in court (this specific case, ALPRs contracted by police departments)? Same question for the first amendment with the FCC using license leverage to control speech?


It’s a provision not circumvention, also not a hack. /s


There are also novel situations for which precedent is set and becomes defacto law. Personally I think this is a big issue with how the US works.


Not a lawyer, but the law is hackable in a sense. Interpretation sets precedent and strategic litigation is common.


Is the government not hacking the law with its weird interpretations and assertions?


If the law isn't hackable what do you call what these billionaires and religious fundamentalists are doing to it right now?


You've answered your own question. The law is hackable for certain kinds of people. If you're not one of the protected categories, it's prudent to consider it unhackable.


At the same time, courts regularly get outsmarted without knowing it. The key is that they don't know it. Right? So don't brag about how you outsmarted the police or the courts, especially not to the police or the courts. I am not a lawyer and you are, but I hope I'm right about this point.


The interesting thing is that the "don't carry the data" scenario of wiping your phone and restoring it after you're across the border is not functionally different from the "just don't carry the keys across the border" scenario. I would be comfortable with a dd archive of my encrypted phone contents in an short-lived S3 bucket that I could restore with a simple passphrase-derived key, for example. It's hard for the law to recognize that they haven't achieved anything useful by forcing me to do that instead of just lose the key.

One thing this case makes me wonder is if the government would have a problem with someone walking across the border with a completely virgin phone. They must have wiped it, right? Would they try to prosecute? How could they possibly know the defendant in this case actually had anything on his phone before the duress code was entered?


It's immensely different. Leaps and bounds different. Why?

Well, once you have been told to unlock the device, you're already in a legally binding process. The phone is at this point evidence. It was not evidence before. It was not evidence a month ago. It really is just that simple.

Now, they could view prior wipe as suspicious, but as a US citizen they cannot prevent entry. And they may be able to seize your phone(suspicious!). Which is why simply stating the truth politely "I believe in privacy, and loath government poking into the private affairs of citizens" might help down the road if you want to sue. Might.

Border guards protect the realm, after all, and have wide latitude.

From my side, my truthful argument for wipe has always been that all of my buisness clients, emails, data might be on my phone. I have a duty to protect their privacy.

Making reasonable statements takes the edge off of 'suspicious', and the more people who wipe? The less suspicious it becomes.

The biggest thibg anyone could do, is make 100% restorable backups for non-rooted Android a thing. It's doable, but a PITA right now. Make it one-click, perfect, reliable, and more will do it.

And then it isn't unusual, it's normal, and the suspicious elements vanishes.

Of course, as Google is mired in asshattery lately, I'd expect any attempts to protect us all, such as ASOP patches or bug reports, would be fought against and ignored. Helping the world, protecting travellers, political dissidents, not on their radar.

They even fight such things.

Because in this day and age, Google does not have your back. Instead, they shove knives there.


> Well, once you have been told to unlock the device, you're already in a legally binding process

In none of my scenarios am I describing actions to be taken after you have been told to unlock the phone. I’m talking about before you ever approach the border. There is no functional difference between wiping a key which encrypts the entire device (but leaving the encrypted data in place) vs wiping the entire device, from a security point of view, except one requires twiddling fewer bits to restore the data.

My point is that the law is unable to see that equivalence, but it is also unable to compel a different result. If choice A and B are identical for security purposes but the government can technically prosecute A but not B, all they have accomplished is forcing people to choose B.


The Aftermath: Because the encryption keys are already instantly nuked at the hardware level, the phone boots directly into the Google Pixel recovery or factory-fresh setup screen.

It's exceptionally apparent you've caused destructive behaviour, after the phone is in evidence.

None of the other scenarios, show your duress pin factory resetting the device, then dropping into a setup screen, after the border agent confiscated it. So much of tbe law is intent, coupled with knowledge of your situation.

There's nothing new here really. Throw a diary into the fireplace at home? Fine! Travel with a blank diary? Fine!

Grqb it from a border guard and and rip it up? Trouble.

It's not about the state of the device at the border. It's intent to change the state after confiscation.


That's not the scenario I'm talking about at all. I'm considering entering the duress code before you approach the border and before the border guard gets anywhere near it, on the assumption that you have a byte perfect backup which is trivial to restore somewhere in the cloud.


Percisely. To know the implications of your theoretical act, you must know +why+ the act caused issue in this story's case.

In all your scenarios, you would not be charged with this crime. They may seize the device, but not charge you.


Well I certainly hope. I have my suspicions that if you pre-wiped your key but left the data “intact” but unusable, you open yourself to the law declaring that as somehow withholding evidence. Actually wiping the entire phone and restoring is certainly the safest in terms of how others may interpret it.


> It's immensely different. Leaps and bounds different. Why? [O]nce you have been told to unlock the device, you're already in a legally binding process.

From a factual point of view, rather than the narrow legal one offered, it is not materially different to delete a phone in anticipation of a future search. In most cases, outside the customs context, it's just harder for the government to prove obstruction of justice.

What's different here is that the government only had a right to search the phone in relation to the border, and the government used that right not just to search for contraband like the law anticipates. If someone dumped their contraband and made it disappear before actually crossing a border, would that be an evidence-related crime? What if they thought about a contraband conspiracy, and then intentionally forgot? What if the customs office presented a form to all travelers, well in advance of formal screening, that they must preserve their contraband henceforth? And then they decided not to smuggle it? Interesting questions legally, but factually, considering criminal charges in those scenarios over the evidentiary situation would be pretty silly.

So then, when you delete purportedly contraband data at the border, have you really just done a public service of removing one more potentially contraband item from border inspection? Or is it that once any of us create data in the vicinity of a border or in a context where we might approach a border in the future with the access device or storage medium, do we all have a duty to preserve it for inspection until the customs authorities get around to inspecting us? Or is it just that this series of hypotheticals illustrate that we have here an epic mash-up of misinterpretation here?


One can’t help but wonder if a motivated DOJ could twist a “destruction of the evidence” charge out of someone dumping a kilo of cocaine just before traveling to the US.


Maybe just don't enter a duress pin, causing the phone to blatantly wipe, and rrboot, and enter a setup screen, right after a customs officer confiscates your potential "contraband", and demands the pin?

I mean really, this act is exceptionally blunt, clear, and overt. All this hand waving won't change things.


Google could not care less; this feature does not make money and adds support burden.


well, i guess the writing was on the wall, so to say, pretty much from the beginning: "don't be evil".


They deprecated that one.


For your virgin phone scenario: in practice they'll probably reverse burden of proof and call it a day.


Or just subpoena AWS for a copy of their shit and dump them in a hole until it’s unlocked. Yay america.


If you actually have a virgin phone, there's no data on Amazon to subpoena.


Wasn't this about entering a duress pin? Therefore, the law hasn't decided on pre-border key wipe. Lots wipe their phone... yet no actions taken.

I believe the duress password reboots the phone. They likely know this, hence the different outcome.


> we tend to think about technological nuances and have a certain literal frame of mind

see the colored bits essay for an ur-example of this

https://ansuz.sooke.bc.ca/entry/23


100% this

People here thinks in technicalities and what if, and while technicalities apply in legal cases, they're not like a lot of people here think they work (quite the contrary!)

This is not "well if the gov had a quantum computer they could decode" this is not how the legal world decided things.


What about the opposite? remove the tech from the hypotetical.

Say you carry a valise with a lock. They ask for the key, you truthfully answer that you do not have with you. They burn the valise and lose all the contents.

So, are you in jail? or can you sue them for destroying your stuff?


What the point of this hypothetical?

In real life they would break the lock on your valise and return it to you bound together with tape.


and how if this similar to how a duress password work? say breaking the lock burn the contents somehow, to prevent documents falling into thief's hands for the sake of the comparison.


You didn’t tamper with the potential evidence; they did.


right. that's my point. why if they try to guess your password and end up wiping data, then magically you're guilty?


Intent matters in a court of law. A judge or a jury will consider:

- did you intend for the data to be destroyed in an eventual search?

- probably yes, because you went to the trouble to set up a duress password

- is it reasonably that you mixed up the two passwords? No, because only an idiot would make them similar and you're clearly no idiot, because you were able to set up a phone with a duress password.

- hence, you intentionally made the officer wipe your data, and you will be held liable.

It doesn't make any difference if the destroyed potential evidence is physical or digital.

The law as written is stupid, but that does not mean courts are stupid.

It is rather funny to look at how some programmers believe they can "trick" the law. It does not work like computer code!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: