frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Hong Kong Police Can Now Demand Phone Passwords Under New Security Rules

https://www.gadgetreview.com/hong-kong-police-can-now-demand-phone-passwords-under-new-security-rules
81•vidyesh•1h ago

Comments

xvector•1h ago
This shit is why I don't visit China.
EGreg•1h ago
This shit is why I build platforms like Safecloud: https://community.safebots.ai/t/safecloud-governance-due-pro...
netsharc•1h ago
How about the US? What I'm going to write smells of "whataboutism", but it's tragic how more and more of the world is becoming police states. Going to the USA, they want your social media accounts. Regardless of that, the border thugs can probably demand you unlock your devices or they'll detain you for weeks on end, without any repercussions, because that sort of lawlessness is government policy now.
dmitrygr•1h ago
In the US, not disclosing a password is explicitly protected (5th amndmnt), SCOTUS has been clear. not so for biometrics, but so for PIN/passwd
comboy•1h ago
Haha, here's some random AI generated content:

    At least 225 judges have ruled in more than 700 cases that the administration's mandatory immigration detention policy likely violates the right to due process[1] The Fifth Amendment's Due Process Clause generally requires those having federal funds cut off to receive notice and an opportunity for a hearing, which was not provided in many of DOGE's spending freezes[2]
(there's more but what's the point)

1. https://www.justsecurity.org/107087/tracker-litigation-legal...

2. https://www.cbpp.org/research/federal-budget/many-trump-admi...

netsharc•1h ago
Ah yes, the US government still respects the 5th amendment... like they respect the other amendments as well as the constitution.

The constitution doesn't say shooting citizens is illegal, right?

plagiarist•33m ago
Federal agents couldn't possibly have been aware that executing people on the streets is a violation of those people's rights, so they are covered by QI.
garciansmith•1h ago
They have? What was the relevant case? It was my understanding that some lower courts have ruled one way, others the opposite. There are also many nuances in particular cases (e.g., the police wanting a broad search of a device for something that may or may not be there versus them knowing for a fact a device has certain information they want).
eqvinox•27m ago
> In the US, not disclosing a password is explicitly protected (5th amndmnt),

That's great but of exactly zero help if you're trying to travel to the US and CBP (or ICE) are staring you down. Even if they don't gulag you, they can always just reject entry for any non-citizen (and these days even some citizens it seems.)

danlitt•19m ago
The 5th amendment only protects citizens, and we are only talking about visiting (as far as I can tell).
dmitrygr•1h ago
Wait till you hear about most of europe...
kubb•1h ago
Roleplaying a parallel reallity where "Europe" is an oppressive totalitarian regime will never not be funny.
dmitrygr•53m ago
> Roleplaying a parallel reallity where "Europe" is an oppressive totalitarian regime will never not be funny.

Roleplaying inability to read will never not be funny

UK: https://www.pinsentmasons.com/out-law/news/law-requiring-dis...

France: https://www.fairtrials.org/articles/news/french-court-rules-...

Ireland: https://www.bbc.co.uk/news/world-europe-57468750

kubb•38m ago
UK: Police can search phones to counteract human traffickers.

China: Police can search phones of dissidents, and jail them for life for criticising the Party.

You: Europe is worse than China (or will be really soon I promise).

Disingenuous.

danlitt•20m ago
Nobody claimed Europe was worse than China, only that if you wouldn't visit China for this reason then you shouldn't visit Europe (or the US) for the same reason.

Speaking of being disingenuous, when you say "Police can search phones to counteract human traffickers", did you think critically about that at all before writing it? Given one of the stated justifications is "preventing terrorism", and the UK has been illegally arresting Palestine Action supporters as terrorists for over a year, this seems a little naive at least.

kubb•5m ago
> Nobody claimed Europe was worse than China, only that if you wouldn't visit China for this reason then you shouldn't visit Europe (or the US) for the same reason.

That would be nonsensical. If you have anti-Xi propaganda on your phone (which could be the reasons you mention), you have nothing to fear in Europe or in the US and a lot to fear in China.

The US is actually worse than both China and Europe because it's 18th century amendments protect human traffickers. Although they do what they can to not have to adhere to those, especially in border control.

> What about Palestine Action...

I'll limit myself to the LARP about "oppressive Europe invigilating your phone".

tyho•1h ago
Wow, what a free society! In the UK if you refuse to unlock your device you can be imprisoned indefinitely! In HK it's just one year!
andylynch•1h ago
Why are you misrepresenting about UK law?

Yes, it can be a criminal offence. But the maximum tariff for this under RIPA 2000 is five years. If it’s not about nation security or CSAM, it’s two.

(Incidentally, the USA is a real outlier in this topic)

gib444•1h ago
Oh just 5 years, that's OK then.
roenxi•59m ago
Are we damning the UK with faint praise now?

I'm not even sure how much practical difference there is between 5 and indefinite in practice, 5 years is a long time. I imagine it is pretty life-destroying. Especially for the crime of having something on your phone that you want to keep private.

> If it’s not about nation security or CSAM, it’s two.

I am sure we all get what you mean, but there is a comic interpretation in vaguely-Soviet style here where if someone hasn't done anything wrong they only get 2 years. I'm going to spend some time this weekend making sure my encryption is plausibly deniable where possible.

idiotsecant•37m ago
You're unsure of the difference between 5 and infinity?
deejaaymac•29m ago
5 years in prison can destroy your life easily, so yeah, what's the difference?
pcdevils•51m ago
The police must obtain appropriate permission from a judge to obtain a s.49 RIPA notice.

Before a judge grants the notice, they must be satisfied that:

The key to the protected information is in the possession of the person given notice. Disclosure is necessary in the interest of national security, in preventing or detecting crime or in the interests of the economic wellbeing of the UK. Disclosure is proportionate. If the protected information cannot be obtained by reasonable means.

beambot•44m ago
So you're saying it's still at the discretion of a single magistrate?

I'm sure China could find some judges to rule in the name of national security if it would give everyone warm fuzzies.

Judicial checks and balances only function when they're independent of the executive and parliament

danlitt•30m ago
Not addressing your main point, magistrates and judges are not the same thing. It would be much worse if it were at the discretion of a magistrate.
mmsc•1h ago
Ah, finally catching up to ... The UK, Australia, Ireland, France, the Netherlands, and probably a lot more.
vrganj•1h ago
The horrible bastion of despotism that is China-run Hong Kong has now caught up to the rule of law utopias of enlightened thought in the US and UK.
gruez•1h ago
>in the US and UK

???

Of all the issues with the US justice system, being compelled to disclose passwords isn't one of them. It is an issue for UK, though.

0x3f•1h ago
Depends, you can get NSL'd to disclose passwords. Good luck running that one up to the supreme court. And biometrics aren't as well-protected. Though, yes, in the UK it's a much more routine affair.
FpUser•1h ago
The above probably meant a point that current democracies are increasingly sliding into the same hole as authoritarian governments. Amount on encroachment of governments and big corporations on personal freedoms and democracy in "democratic" countries is quickly becoming intolerable under a guise of safety and "save the children" mantras
traceroute66•1h ago
> Of all the issues with the US justice system, being compelled to disclose passwords isn't one of them

Under the present administration I wouldn't be surprised if for example ICE tried the $5 wrench method.

quentindanjou•59m ago
> Of all the issues with the US justice system, being compelled to disclose passwords isn't one of them.

This is not totally true. It is also a US issue: CBP has been asking for passwords (or to unlock the device) for phones and computers for more than a year now. Last year, multiple people got turned around because they disagreed with US policies and political views that differ from those of the US's current president.

throwaway290•50m ago
> Last year, multiple people got turned around because they disagreed with US policies and political views

so they were not in US technically?

NoImmatureAdHom•8m ago
You don't have the protections of U.S. law at the border.

CBP is also asking, not compelling. You don't have to give them your password. If you don't, and you're a foreigner, you may be turned away. If you're a citizen, and I remember correctly, they can seize your device for up to two days if they want.

But they're not going to put you in prison for refusing like the U.K. and Hong Kong will.

mothballed•5m ago
CBP has absolutely put me in jail (not prison) for refusing to answer questions (including the strip search and being put in chains and handcuffs). As well as threatening to revoke my passport (though they could not). On another occasion they threatened to deport me even though I'm a US citizen. On yet another, they faked a drug dog hit then dragged me to multiple hospitals, racking up bills in my name while claiming I was packing drugs up my ass. I am still being chased by debt collectors for the last one.
ulfw•53m ago
You have never crossed the border into the Great US of A then
ericd•47m ago
It's possible to cross the border many times and not have this happen.
john_strinlai•39m ago
okay, but it is also possible to have it happen.
vrganj•52m ago
I take it you haven't crossed the border recently?
some_random•35m ago
Funny how it's a horrible misrepresentation slurring the honor of the United Kingdom to exaggerate the penalty of not unlocking your phone for His Majesty's Law Enforcement, but US border cops being allowed to ask foreigners for the same thing upon pain of not being allowed to enter the country (something that no one seems to care about other nations doing?) is totally the same thing.
throwaway290•1h ago
in china was never a problem for police to detain you for any reason (or no reason) but HK has a different legal system
jonex•1h ago
Feature request: Make it default behavior on phones that you can have multiple passwords, connected to different profiles. With no way to determine how many profiles a phone have.

I'm sure there's some people here working on mobile operating systems, might be worth considering?

hananova•59m ago
"This profile doesn't have anything on it. Give us the password for the real profile."

Or even worse, you did give them the real password, but because your phone supports the feature and your profile is kind of barren, they don't believe you. Now you are in a very bad lose-lose situation.

keiferski•48m ago
With LLMs, it should be easier than ever to fake generate text messages, notes, emails, etc.
hydrogen7800•40m ago
xkcd 538

https://imgs.xkcd.com/comics/security.png

idiotsecant•38m ago
So put stuff on it, duh
hananova•36m ago
"This isn't what we expected to find. Give us the real password."
eqvinox•31m ago
So your approach instead is...?
limagnolia•22m ago
You do use your "fake" profile regularly, just for "sanitized" activities. Check in on official sanctioned news sources, do your "legit" banking and financial stuff, etc.
hypeatei•43m ago
Software isn't going to save you in this scenario. If you're worried about local laws violating your privacy then buy a burner and only put data on there that's necessary for your travels.
dachris•42m ago
Veracrypt e.g. has had this for a long time.

https://en.wikipedia.org/wiki/Plausible_deniability

mikhael•34m ago
> Provide fake credentials? Three years behind bars.
varenc•27m ago
relevant xkcd: https://imgs.xkcd.com/comics/security.png

It'd be pretty hard to make the fake profile appear to be the real one.

yakkomajuri•9m ago
As others have pointed out this would likely not save you in this case, but there are some phones which do support this, and I know people in Brazil that use these features in order to be able to comply when getting mugged without giving away access to your bank etc.
joekrill•9m ago
Android has a "Private Space" feature. As far as I can tell it's only a single extra profile you can create, but I think you can keep it "hidden" (at least in as much as you can't tell if it's been created without unlocking it).

https://source.android.com/docs/security/features/private-sp...

kleiba•1h ago
It would be nice if phones had a feature where you can define more than one pin, but only one is for your actual phone contents - the other ones leave you to a completely harmless but otherwise indistinguishable looking smartphone interface that contains no or only completely bogus data.
gmerc•1h ago
Almost every chinese android variant has that. On Oppo it’s called clone system
ulfw•54m ago
My Oppo Find N6 allows multiple user accounts
pavel_lishin•49m ago
It would be nice if I didn't get beaten with a hose in a vain attempt to prove that I unlocked the "real" one.
iamnothere•47m ago
If your country has this problem, you’re way past worrying about phones, and you need to be acquiring arms and training.
embedding-shape•1h ago
"Featured" on HN just a week ago, seems GrapheneOS' "Duress pin" would be very helpful in these cases: https://grapheneos.org/features#duress (https://news.ycombinator.com/item?id=47445931).

Now we just have to wait N years for Android and iOS to get approval from the government to build something similar, that they can market yet somehow screw up enough to not actually help.

everdrive•55m ago
No one likes when I say this but it's really past time to stop doing anything interesting on your phone. Delete all your apps, set it as minimally as possible. Leave it home when you go for walks, and power it off when you go driving or to the store, or whatever.
pavel_lishin•50m ago
For many people, their phone is their primary, if not only, computing and communications device.
everdrive•46m ago
Right, which is why they need to start changing their behavior.
em-bee•14m ago
how? whatsapp, wechat, telegram, even signal, all require a phone to be used.

if i didn't need any of those apps then sure, but unfortunately there is no way around these apps if i want to keep in touch with certain people that are important to me.

nhecker•37m ago
I'm starting to believe this is [a] way forward. Or maybe an approach which is on a spectrum between <everything I have is on a phone behind a fingerprint and a four digit pin> and <I don't own a smartphone>.

Unfortunately, it's pretty common to only have a smartphone as your sole compute device, and increasingly onerous not to own one at all.

everdrive•29m ago
>Or maybe an approach which is on a spectrum between >increasingly onerous not to own one at all.

Yes, and I think this unfortunately demands a grey area. I'm starting to treat my smartphone more like a work device, and there are a few things I do on it:

- My work's authenticator app is there.

- Unfortunately Signal is tied to smartphone usage.

- Practically speaking, people will expect to be able to send you text messages.

- It's still useful for taking pictures.

- My banking app is on there.

Outside of rare occasions, that's really all I use my phone for. I don't carry it around the house. If I go somewhere with my wife, I don't even bring my phone most of the time. I'm "required" to have it, but in principle it's not even mine. It shouldn't be trusted or enjoyed.

kevincloudsec•45m ago
I think everyone's glossing over that this extends to anyone who knows the password. Your sysadmin, your business partner, your spouse. Hong Kong just turned your company's entire key management chain into a legal liability.
dev_l1x_be•40m ago
Ohh no, so they caught up with US border patrol?
3yr-i-frew-up•17m ago
>The US is evil

>China makes you give phone passwords, China makes Apple give user data

>The US wiretaps 1 person

"OMG THIS IS AN OUTRAGE!"

We forget because a Republikan is in charge how good we have it in the west. We forget how bad it is elsewhere.

maplant•17m ago
The cops from the John Woo HK action flicks I've seen would love this
firefax•10m ago
These kinds of laws worry me since I have forgotten several old passwords. Being disorganized shouldn't be a criminal offense.

Anatomy of the .claude/ Folder

https://blog.dailydoseofds.com/p/anatomy-of-the-claude-folder
57•freedomben•1h ago•26 comments

The 'Paperwork Flood': How I Drowned a Bureaucrat Before Dinner

https://sightlessscribbles.com/posts/the-paperwork-flood/
322•robin_reala•3h ago•218 comments

Installing a Let's Encrypt TLS Certificate on a Brother Printer with Certbot

https://owltec.ca/Other/Installing+a+Let%27s+Encrypt+TLS+certificate+on+a+Brother+printer+automat...
43•8organicbits•1h ago•3 comments

Iran-linked hackers claim breach of FBI director's personal email

https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email...
105•m-hodges•1h ago•52 comments

Special desk for people who work at home with a cat

https://soranews24.com/2026/03/27/japan-now-has-a-special-desk-for-people-who-work-at-home-with-a...
5•zdw•15m ago•0 comments

A Faster Alternative to Jq

https://micahkepe.com/blog/jsongrep/
271•pistolario•8h ago•168 comments

This picture broke my brain [3B1B video]

https://www.youtube.com/watch?v=ldxFjLJ3rVY
89•jgwil2•4d ago•34 comments

Hold on to Your Hardware

https://xn--gckvb8fzb.com/hold-on-to-your-hardware/
378•LucidLynx•5h ago•319 comments

Schedule tasks on the web

https://code.claude.com/docs/en/web-scheduled-tasks
233•iBelieve•10h ago•193 comments

Apple discontinues the Mac Pro

https://9to5mac.com/2026/03/26/apple-discontinues-the-mac-pro/
543•bentocorp•18h ago•487 comments

Why so many control rooms were seafoam green (2025)

https://bethmathews.substack.com/p/why-so-many-control-rooms-were-seafoam
935•Amorymeltzer•2d ago•191 comments

The European AllSky7 fireball network

https://www.allsky7.net/#archive
97•marklit•8h ago•7 comments

Anthropic's Claude loses its >99% uptime in Q1 2026

https://bsky.app/profile/teropa.bsky.social/post/3mi2dbt27m226
35•timpera•1h ago•32 comments

EMachines never obsolete PCs: More than a meme

https://dfarq.homeip.net/emachines-never-obsolete-pcs-more-than-a-meme/
7•zdw•3d ago•2 comments

Local Bernstein theory, and lower bounds for Lebesgue constants

https://terrytao.wordpress.com/2026/03/23/local-bernstein-theory-and-lower-bounds-for-lebesgue-co...
34•jjgreen•3d ago•7 comments

Gzip decompression in 250 lines of Rust

https://iev.ee/blog/gzip-decompression-in-250-lines-of-rust/
32•vismit2000•3d ago•14 comments

Rising Air-Conditioning Use Intensifies Global Warming

https://www.nature.com/articles/s41467-026-69393-1
15•PaulHoule•53m ago•12 comments

People inside Microsoft are fighting to drop mandatory Microsoft Account

https://www.windowscentral.com/microsoft/windows-11/people-inside-microsoft-are-fighting-to-drop-...
36•breve•1h ago•12 comments

Rank the 50 best Apple products

https://www.theverge.com/cs/tech/900477/apple-50-anniversary-rank-products
20•dqieu•1h ago•8 comments

Show HN: I put an AI agent on a $7/month VPS with IRC as its transport layer

https://georgelarson.me/writing/2026-03-23-nullclaw-doorman/
297•j0rg3•17h ago•84 comments

$500 GPU outperforms Claude Sonnet on coding benchmarks

https://github.com/itigges22/ATLAS
411•yogthos•22h ago•226 comments

Hong Kong Police Can Now Demand Phone Passwords Under New Security Rules

https://www.gadgetreview.com/hong-kong-police-can-now-demand-phone-passwords-under-new-security-r...
81•vidyesh•1h ago•79 comments

QRV Operating System: QNX on RISC-V

https://r-tty.blogspot.com/2026/03/qrv-operating-system-first-publication.html
40•chrsw•4d ago•7 comments

We rewrote JSONata with AI in a day, saved $500k/year

https://www.reco.ai/blog/we-rewrote-jsonata-with-ai
232•cjlm•17h ago•210 comments

DOOM Over DNS

https://github.com/resumex/doom-over-dns
330•Venn1•4d ago•87 comments

Everything old is new again: memory optimization

https://nibblestew.blogspot.com/2026/03/everything-old-is-new-again-memory.html
120•ibobev•3d ago•85 comments

Running Tesla Model 3's computer on my desk using parts from crashed cars

https://bugs.xdavidhu.me/tesla/2026/03/23/running-tesla-model-3s-computer-on-my-desk-using-parts-...
921•driesdep•1d ago•320 comments

My minute-by-minute response to the LiteLLM malware attack

https://futuresearch.ai/blog/litellm-attack-transcript/
409•Fibonar•23h ago•152 comments

Whistler: Live eBPF Programming from the Common Lisp REPL

https://atgreen.github.io/repl-yell/posts/whistler/
119•varjag•3d ago•14 comments

HyperAgents: Self-referential self-improving agents

https://github.com/facebookresearch/hyperagents
219•andyg_blog•2d ago•77 comments