Man Charged for Wiping Phone Before CBP Could Search It

Good point. I doubt any officer would check for a random USB stick in a tech bag unless they’re guarding the CIA headquarters or something.

I’m more worried that these people will still have incriminating evidence on their phones even if they carry around a Tails USB. Even if it is not content data of Signal messages per say, information such as where they were going or what sites they visited could reveal that they have a Tails USB

1 Like

Which ones though? The people need a list.

1 Like

Depends on the type of risk one is at. But I see you’re being facetious.

1 Like

I use china as a prime example so it’s one of them

Still not really a valid solution, at least in my experience

What @anon57862721 said too

I mean, this is where good OPSEC comes in. Keeping minimal info. Doing things in a vacuum on Tails only and following The Fight Club rule.

Archive link requires no VPN. Unfortunate, but I can give a brief summary.

According the official indictment, an Atlanta-based activist named Samuel Tunick was arrested by the FBI after a CBP agent seized his phone and observed that is was wiped beforehand. All we know that he had a Google Pixel phone and he was searched by a CBP unit known as the “Tactical Terrorism Response Team”.

Note that he is American. Or at least, an American resident. He probably came across CBP at an airport and got shaken down there.

It depends on the information I hold on that device, but from my experience:

  1. Never mix up personal and “work” devices & accounts.
  2. Leave as less information as possible on “work” device.
  3. Good OPSEC on storing and using “work” device and while “working”.
  4. Whoever within that “working group” has public presence of any kind, that person(s) should not hold any important information and their access to any information should be remotely revocable by admin (who has no public presence i.e. extremely low profile).
  5. If travel, check destination’s for any extradition agreements and history of extradition with your adversaries.

TBH, if the information is so crucial that could lead to multiple persecutions, it makes sense just to wipe the device, even if it would leads to charges on the device owner. I think it is a basic quality of being an activist.

1 Like

@JG
How is that facetious?

Thanks for sharing.

I wonder if this story is first of its kind. I would imagine this would have happened many times. I also wonder (though I am pretty sure) that FBI has a “black list” akin to that of the 50s during McCarthyism to keep track of those who are a problem to “national security”.

The current US admin really wants to take us back. Too bad they don’t know how to bring Unions back with it at the same time.

If you read it as such..

I imagine that if I gave a legal authority a duress code to punch in, it would still be tampering. Wbut what’s the case for when they punch in the duress code when trying to bruteforce it, without me giving them any info? Would it still be intent to tamper?

Trying to brute force a phone that’s not encrypted is not considered tampering

Tampering is when you’re modifying or removing evidence of the crime happening

Or I guess “crime” if you wanna put it that way

I think technically the charge would be “obstruction of justice”. But I am no lawyer.

Not talking about me bruteforcing my own phone.. I’m saying if a legal authority like the police are brute forcing my phone by hand and they happen to punch in my GOS duress code, would that be tampering on my end, equivalent to me erasing my own data? Or maybe not tampering, but

or some other kind of legal trouble?

If they happen to touch the duress pin upon bruteforcing and you were in sight, They have reasonable suspicion to charge with Tampering evidence

Obligatory not a lawyer btw (always consult an actual lawyer for actual legal advice)

1 Like

@JG
?

That was exactly my first impression.

However, the pretext of the arrest seems unclear to me. From what I see it could possibly be obstruction of a border agent’s duties (lawful access to the phone’s contents?), not destruction of evidence.

The indictment says on January 24, Tunick “did knowingly destroy, damage, waste, dispose of, and otherwise take any action to delete the digital contents of a Google Pixel cellular phone, for the purpose of preventing and impairing the Government’s lawful authority to take said property into its custody and control.”

About destruction of evidence, a lawyer discussed plausible deniability and privacy tools. They said there’s nothing inherently illegal about using privacy tools (to their knowledge*) and encourages their use, but how they’re used can constitute a crime. The specific example given was Signal disappearing messages. On one hand, if Signal disappearing messages are used routinely then there’s nothing legally wrong. They add that they use Signal all the time and use disappearing messages to protect their communications from subpoenas. On the other hand, if something else is routinely used for communications but someone pivots to Signal disappearing messages for a specific purpose, that may be treated as suspicious. Amazon and some politicians have been accused of using Signal for destruction of evidence.

\* Financial privacy

Tornado Cash, Samourai Wallet and other financial privacy tools have been criminalized.

Even if the CBP Tactical Terror team’s arrest was unlawful (failed to establish suspicion/evidence that a crime occurred) and the arrested person is eventually acquitted, they still successfully repressed the arrested person (arrest, prosecution and other personal damages) and instill fear into society by demonstrating their aggressiveness at the border. I wouldn’t rely on legal technicalities for avoiding harassment/abuse.

In case it helps, travel and border agents have been discussed elsewhere in this forum.

One tip from there I like is this.

@GorujoCY Yah peer pressure sucks, and it isn’t a trivial/easy problem to solve if those “family” or “friends” have enough power over you. If you have good reasons not to go somewhere that those people have no knowledge of, and they won’t take no for an answer, one option may be to lie to them about why you cannot go. Create a cover story, for instance a clash with some important event or work, or fake an illness that would prevent you from traveling. Another option is to preemptively create personal or relationship boundaries that are clear and well known, for instance “I will never travel to country X, Y and Z for any reason.” If those people are toxic and you want them out of your life, consider building and executing a relationship termination plan.

Doubtful the phone owner could be charged for this because they weren’t the one who did the act. But who knows? I’d say “seek legal advice” is a good tip for those thinking using duress code systems.

3 Likes

The GOS duress pin is unnecessary in almost any normal circumstance. Shut off your phone before passing through security - so long as you use a strong password, GOS is believed to be uncrackable in BFU state. Wiping it becomes a unnecessary crime

IMO duress pin use case is extreme scenarios: wartime, torture, or autocratic regimes, where you may be literally incapable of withholding the pin

Extra credit: set a booby trap by keeping a note in your wallet with the duress pin clearly written down. A nosey adversary may mistake you for a moron & wipe the device for you, absolving you of sin

5 Likes

I can definitely understand the logic behind wiping your phone before handing it to the authorities. Even with GOS’s security features, there are still ways for law enforcement to cause issues for you.

If they get a warrant for your passwords, you are required to provide them or else you can be imprisoned until you comply with the warrant. If you haven’t wiped your phone before handing it over, that’ll be the most direct way for law enforcement to get your data, circumventing GOS’s protections.

In this case, the man wiped his phone before it was taken into custody. It does mean he’s been charged with destruction/tampering of evidence. But he’s not being held in prison for the time being at least.

But as others in this thread have stated, a much better solution to the problem is to not have traveled with sensitive data on his phone in the first place.

Depends on the jurisdiction. In the US I believe at least one federal appeals circuit court has ruled that it is unconstitutional to compel disclosure of passwords for a criminal investigation. Another court at the same level I think has ruled the opposite though, so it will be varied within the US until someone appeals a case to the supreme court. I am personally of the opinion that the legally correct decision is that it is unconstitutional as providing something you know to help a prosecution against yourself is the same thing as testifying against yourself, so it should be protected by the fifth amendment.

I’m not a lawyer, and this is not legal advice.

1 Like