According to The Guardian, the US Department of Justice is prosecuting Atlanta resident Samuel Tunick after he allegedly gave a GrapheneOS duress PIN while border agents were trying to search his Google Pixel phone.
It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm surprised they didn't back up the device first.
From what I understand he was not formally arrested at the time, just interrogated at the border. I am not familiar with US laws but from what I understand the device was not (yet?) considered evidence in an investigation. I imagine backing up might not be as easy an option without tearing down the device as the memory chip is no the device mainboard, so not something you can necessarily do on the side of the road or at a border without a formal warrant/investigation.
>I imagine backing up might not be as easy an option without tearing down the device as the memory chip is no the device mainboard, so not something you can necessarily do on the side of the road or at a border
Oh you sweet innocent child. US Customs and Boarder agents, every federal agency, and most local law enforcement agencies all have Cellebrite, Oxygen, or an equivalent tool which can perform a full device extraction on basically any phone expect for a pixel running Graphene OS with the current updates and a new model iPhone also running it's current updates. Every other phone on the market in the US can be cracked and extracted by cellebrite simply by plugging in a usb-c cable. Even a stock pixel, Samsung, iPhone, etc. Typically they would absolutely need a warrant to perform a device extraction but the supreme court has ruled that at boarder crossings, a person is not actually in the US until allowed entry by an agent and by not being in the US, US law and constitutional rights dont apply. If you are a US citizen, they can not deny you entry but that can keep your phone and attempt to extract it at a later time when exploits may be uncovered to break the encryption or bypass it completely
> I'm surprised they didn't back up the device first.
There's no use in taking an image of the SSD and restoring it after a wipe. Data needed to derive the key encryption keys was wiped from the secure element. Separately from that, there's also additional data on the SSD needed to derive the key encryption keys which the TEE hardware will no longer consider valid.
Entering the duress PIN/password does the following:
* wipes TEE hardware keystore
* wipes secure element hardware keystore
* wipes the secure element other than Factory Reset Protection data which isn't used by GrapheneOS at this time
* wipes the encryption metadata on the SSD with special wiping commands
The secure element data is inside the secure element's internal storage. TEE keystore keys are normally stored encrypted on the SSD with a hardware-based anti-rollback storage system to prevent reusing deleted keys. The secure element keystore is a lot more secure.
The most important data that's wiped is the Weaver table on the secure element. Weaver is the secure element rate limiting feature we describe in our post. It's implemented by the OS passing a dedicated hash of the initial key derived from the user's PIN/password. If it's the valid hash, the secure element provides a token needed alongside the initial derived key for the final key derivation. If it's not valid, it's a failed attempt wasting one of 20 attempts and triggering a hardware enforced delay.
It also isn't possible to simply image the SSD and then try to brute force the PIN/password due to the secure element rate limiting and the final key derivation done in the TEE.
It isn't the same as a typical disk encryption approach on a desktop, although GrapheneOS supports using a strong passphrase to avoid depending on the secure element rate limiting. GrapheneOS makes it convenient to use one via 2-factor fingerprint+PIN secondary unlock in After First Unlock state. It's the same as regular fingerprint unlock but with a PIN needed to complete it where incorrect ones count towards the limit of 5 attempts (reduced from 20 by GrapheneOS).
This is really an interesting case. Hope to see a ruling here. The edge cases are really interesting as well, like the fake pin on the back of the phone. I also wonder generally about the 'destruction' of data
Wouldn't the government need to prove that there is no backup, because just making it more difficult (like hiding) would probably not call for the paragraph. Unfortunately for the rest of us the defence is based on more proven grounds. I guess only plausible deniability is helpful: I e.g. would love to see my trusted android space being empty/recreated on false password.
> The edge cases are really interesting as well, like the fake pin on the back of the phone.
"Your honor, I have the real pin memorized because I use it all the time, but since I can never use the duress code, I had to keep it somewhere handy."
Or
"Pickpocketing and phone-snatching is a real problem overseas, I put it there so that criminal would wipe the phone trying to get in, denying them access to things like my bank account."
Heck, those aren't just plausible, they might be a good idea.
It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm surprised they didn't back up the device first.
The duress password does not wipe the phone. It wipes the encryption keys from the secure element. The phone's storage is the backup, but it is worthless, unless law enforcement has an attack against AES that does not require a brute force attack (unlikely).
This site is called Hacker News :), people might just want to learn how it works technically, so I think it is worth mentioning technical differences.
Also, it does make a small difference in practice. Erasing keys is pretty much immediate, while erasing storage can take some time (especially for phones with larger storage), so the attacker could still try to power down the device in some way to avoid all storage gets wiped.
I'm not sure it would have been that easy for them to back it up.
Depending on his settings.
You can disable the usb port entirely if you like, so that it is only possible to charge the device by switching it off. Or enable charging only when unlocked etc.
Or if his device had rebooted I don't think it would be possible to extract anything.
The alleged charges seem nonsense - destruction of property to prevent seizure? First no property was destroyed, and second they could still seize it. But US courts are a coin toss so it may still work for the government.
Yes, it would be interesting if the question was formulated like "we're gonna need a password" and this ends up being a lawyerdog situation. https://blogs.illinois.edu/view/25/574827