Data Privacy in the U.S. Border Zone theguardian.com

Timothy Pratt, the Guardian:

The US Department of Justice is attempting to prosecute an Atlanta resident in connection with the movement against the police training center known as Cop City because he had GrapheneOS on his phone, an open-source operating system that enables users to enter a passcode and wipe a phone clean.

[…]

Meanwhile, [surveillance expert Christophe] Boutry, who lives in France, said Tunick’s case was of a piece with tendencies in France and Spain, where authorities have been frustrated in attempts to gain access to the phones of journalists, lawyers and political opponents due to GrapheneOS.

The details of this case sound, as is so often the case for U.S. Customs and Border Patrol, troubling. It is a pretty good ad for the hardened capabilities of GrapheneOS, though.

Ben Werdmuller:

While a duress password is a deliberate act of destruction, the better path when crossing the border is to not have data to seize to begin with. Anyone who deals with sensitive information should consider that their phone might be taken at the border. Customs and Border Protection policy even allows agents to clone it, giving them permanent access to your data even after they hand your device back to you. They’re only supposed to do this when there’s a national security concern or reasonable suspicion of a crime — but if activists are being targeted as terrorists, that policy threshold doesn’t feel like a solid protection.

The classic advice of turning off your devices when passing through a border or, on an iPhone, entering the “Power Off” mode to suspend biometric features seems insufficient. Border agents claimed that “refusing to talk [gives them] the authority to go through your phone” and demand a passcode without needing a warrant.