frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

https://www.pcmag.com/news/grapheneos-defends-data-wiping-function-that-blocked-us-border-search
72•pseudolus•1h ago

Comments

br0ceph•48m ago
yasss this is a feel good story they entered the pass themselves, so by their own treasonous logic, they should charge themselves. hope the crim charges get dismissed, and a civil suit is filed get paid, donate a chunk Go Team Graphene!!!!
BLKNSLVR•47m ago
Keep fighting the good fight GrapheneOS!
butvacuum•45m ago
is it just me or is it about once a decade somebody gets publicised for this and the government *really* throws the book at them.
1970-01-01•41m ago
"defends" is doing quite a bit of flashy work for this headline. "Feature works as advertised, nobody upset" would be a much more practical headline.
RobotToaster•20m ago
The government appears to be quite upset. You wouldn't want to upset ingsoc would you?
ChrisArchitect•38m ago
Related:

US Government targets Cop City protester over phone operating system

https://news.ycombinator.com/item?id=49024436

mmastrac•36m ago
The founding fathers would be aghast at what America became. Hard to imagine modern America passing some of those constitutional amendments that older America passed wayyy back.
whizzter•35m ago
Someone who is a lawyer knows any details about the US justice systems precedents with regards to the fifth amendmend (regards to self incrimination) vs obstruction of justice (by destroying evidence) as would be applicable to a duress wipe? Also would the distinction of being (or not) read their miranda rights and placed under arrest in this case make a difference as to the status of any possible obstruction?
CountHackulus•32m ago
According to Homeland Security, within 100 miles of the border is a "constitution free zone". So there's a whole lot to unpack before we even get to miranda rights.
iamnothere•31m ago
Not a lawyer, but my understanding is that refusal to give the PIN (“remaining silent”) would be a valid application of the 5th, but not giving a false PIN. 5th does not imply the right to mislead or lie to someone investigating a crime.

Not clear on anything else regarding the duress PIN but I don’t think a 5th defense would apply.

Note that you apparently have to explicitly invoke your right to remain silent or your silence could be implied as an admission of guilt (thanks to Salinas v. Texas). I imagine you’d have to repeat your assertion multiple times, and the person demanding the PIN will tell you that you can’t use the 5th, will threaten you with arrest and additional charges, etc. Consult a lawyer and get training if you’re doing critical work where you may need this defense.

tracker1•18m ago
I'm mixed... if they really thought there was evidence on the phone, they should have seized the phone and acquired a warrant IMO to compel the valid, non-destructive PIN be given over.

As I mentioned earlier, this is part of why my own plans for international travel are to only go with a notebook/sheet with contact numbers and buy throwaway devices on the other side. I don't think I'd travel internationally with a phone or laptop at this point, and that's kind of been my thoughts for a while. Especially given the direction that many countries, not just the US have taken. For that matter, I don't think I'd ever even risk travelling to the UK or China at this point. Not that I like the surveillance state here in the US, at least I still have some rights preserved.

mingus88•32m ago
This should be an interesting case in today’s legal climate

Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password.

How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password does a wipe based on location? Either way, the user complied, and did not take action to wipe their device.

victorbjorklund•27m ago
Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.
Groxx•22m ago
while attempting to avoid armchair-law-interpreting because I really do not intend that, and I agree that this is going to be an interesting/deeply-worrying legal case:

wiping the device before carrying it across the border seems essentially identical to me. like, saying "you can't wipe it when searched" would also imply "you can't have an empty device when crossing because it may have been wiped before the search to avoid having your data searched" since people can (and often do) do that for exactly that reason.

that may very well be what they want / what they are trying to legally allow during searches, but it also seems like it'd raise a hell of a lot more outrage. it's essentially claiming all citizens are under full legal hold all the time, if they ever intend to leave the country for any length of time.

iamnothere•15m ago
To my knowledge, no citizen has ever been prevented from reentry due to a blank or absent device. In fact they cannot block a citizen’s legal reentry for any reason, they can only detain you while they investigate.

Beyond this, “I dropped my phone in the ocean” is always a perfectly valid reason.

If you’re a foreigner and they already suspect you of something, they can deny you entry for any reason. It may be better to be denied than arrested!

pavel_lishin•30m ago
The "agent entered password themselves, therefore they're to blame" seems as good of a logic as "I'm going to start swinging my arms and start walking forward, so if you don't move, it's YOU hitting YOURSELF".
skullone•28m ago
Maybe digital forensics shouldn't be handled by barely highschool graduates at a busy border crossing
gruez•16m ago
Should we take the same approach for physical searches? If the cops are executing a search warrant on a house, and there's a safe, should they send in a safe cracker on the off chance the safe is wired with a "duress pin" (eg. thermite that burns the contents)?
rc5150•17m ago
That's egregiously disingenuous. Having a password that protects the infiltration/extraction of your intellectual artifacts is in no way akin to assault on someone else.

A duress password isn't a booby trap. Nothing was damaged except for the fragile egos of the man-children who weren't able to bully someone into giving up their wrong-think.

gruez•14m ago
The point isn't that giving a duress pin is the same as physical assault, or that the duress pin feature is a "booby trap". It's that for the purposes of ascertaining guilt, you don't get a pass just because you're not the person that physically initiated the action.
tracker1•25m ago
And this is why part of my plans for any international travel are to simply have a physical notebook with phone numbers to trusted friends/family and to buy throwaway devices on the other side (phone and chromebook or similar).

TBF, similar mindset if I ever attend defcon, etc. as well.

flr03•17m ago
The crazy part is that you might be denied entering the country you don't travel with a device...
drnick1•14m ago
I have never heard of something like that.
tracker1•8m ago
So be it, they can send me back.
Magicrafter13•20m ago
As a GrapheneOS user and a U.S. citizen that cares about the constitution, I fully support the actions taken by the individual
yardie•15m ago
This is possibly the best advertising. GrapheneOS was kind of niche before. But if the US Government hates you then you're on the right track.
illithid0•12m ago
On one hand, I love GrapheneOS and see it as a cornerstone of digital privacy software. I have supported the project financially for years.

On the other hand, I'm worried that the publicity will only make explicit targets out of GrapheneOS users, and that you would only be using it "if you have something to hide".

gadders•12m ago
UBS had a similar capability on their laptops so they facilitate tax evasion for US clients: https://www.cnbc.com/2015/04/30/why-did-the-us-pay-this-form...
cdrnsf•11m ago
The border agents didn't act in good faith, regardless of what they're empowered to do. They wanted the data for one reason and fabricated another to prompt the device search. The data they were interested in pertained to protest activity protected under the constitution but the lie they told was about something criminal. That anything within 100 miles of the border is constitution free tosses that out, I guess, but is extremely problematic on its own.
luxuryballs•11m ago
Next version should wipe the phone while presenting a dummy account so they can't easily tell anything is missing.
shreddit•7m ago
Couldn’t GrapheneOS provide a special pin which boots into an “empty”session? Where the user can install some default stuff to not look suspicious?
Zak•5m ago
This probably doesn't hold up legally, but it does hold up logically: if the reason a border search exemption exists is to prevent importation of material that is unlawful to import, wiping a storage device also fulfills that purpose.
whizzter•13m ago
Hmm, interestingly here in Sweden we have "free evidence" (way of gathering is not considered even if "illegal", however someone doing something illegal to obtain it could instead be charged separately).

As such in a case like the Salinas one, being silent or "pleading the fifth" would be moot as both would just indicate "deafening silence" to the judges since the defendant had been cooperative up until that point.

(the Swedish judicial system has no juries, instead there's a professionally learned judge and 2 "laymen judges" appointed from political parties acting as the peoples representatives, if that triumvirate fucks up, higher courts can and often will kick rulings back down for retrials).

tsimionescu•12m ago
The moment you start talking, you're no longer using your 5th amendment rights. And anything that you tell an officer that is not truthful, such as providing the wrong password, can be considered a crime in itself. Even claiming you are innocent can be considered a separate crime if you are not proven innocent later on.
nemomarx•13m ago
similar to structuring laws, right? trying to not provide evidence is occasionally similar to destroying it.
tsimionescu•4m ago
> wiping the device before carrying it across the border seems essentially identical to me.

On the contrary, there is a huge gulf between these. Providing a fake password that wipes a device while under active questioning is a clear case of providing false testimony. Lying to the police while under investigation is simply illegal, regardless of the thing you're lying about.

By contrast, entering the country with a clear device is not a crime under any possible interpretation that I can see. Now, if you are wiping evidence while you know there is an active investigation against you, that may be a crime as well, but it's a completely separate crime and can't be easily judged by an officer that simply finds you with a clean phone.

order-matters•20m ago
isnt it amazing how we are able to know when something is a trick and clearly caused by your action/intention vs when it isnt? i mean sure we can contrive (or maybe even find example of) some scenario where it might be a hard grey area, but ive always found it so cool how we often operate on "top down" methods like this that logically have no basis for working out but 'common sense' happens to be common enough still

i pray that sense doesnt erode

Zigurd•9m ago
The level of duress also matters. US citizens have been shipped to foreign prisons and there's an active case of high-level officials at DOJ violating court orders about that.
gruez•5m ago
>The level of duress also matters

Theoretically yes, but in this case there's approximately zero chance a judge would accept "I destroyed evidence because there's a vague chance ICE might send me to a deportation camp".

tsimionescu•21m ago
> Either way, the user complied, and did not take action to wipe their device.

The user claimed to offer a password to access the contents of the device, and instead offered a password that deleted the device. That is false testimony / lying to an investigation, and is almost certainly punishable in itself.

GVIrish•12m ago
It would depend on precisely what the ask was. Did the officer ask, "Give me the pin to unlock the phone."? In that case the command was complied with.
gruez•8m ago
Even if the prompt was vague like "what's the pin for the phone", you'd be hard pressed to convince a judge that a duress pin (to wipe the phone) is a reasonable person[1] interpretation.

[1] https://en.wikipedia.org/wiki/Reasonable_person

CSMastermind•20m ago
If you have a safe in your home and you knowingly wire up a bomb that goes off when a certain lever is pulled then you lie to the police and tell them the way to open the safe is to pull that lever you'd pretty clearly be responsible for the damage done when the bomb goes off.

I don't see why this would be any different.

idbnstra•14m ago
cause you're not harming the officer. this is more like a safe that destroys whatever is inside

7.1 Earthquake in Japan

https://www.data.jma.go.jp/multi/quake/quake_detail.html?eventID=20260728163528&lang=en
652•krembo•8h ago•137 comments

New HIV vaccine shows unprecedented success in preclinical study

https://www.lji.org/news-events/news/post/new-hiv-vaccine-shows-unprecedented-success-in-preclini...
298•codebyaditya•3h ago•134 comments

How Do I Profile eBPF Code?

https://naveensrinivasan.com/posts/2026-07-22-how-do-i-profile-ebpf-code/
18•snaveen•24m ago•0 comments

Harmony Explained: Progress Towards a Scientific Theory of Music (2012)

https://arxiv.org/abs/1202.4212
25•surprisetalk•59m ago•12 comments

Zig's Incremental Compilation Internals

https://mlugg.co.uk/posts/incremental-compilation-internals/
18•garyhtou•33m ago•1 comments

Delayed Gratification – Proud to Be 'Last to Breaking News'

https://www.slow-journalism.com/
13•speerer•29m ago•0 comments

Italy Blocks Reproductive Health Websites Women on Web and Women Help Women

https://ooni.org/post/2026-italy-blocks-wow-and-whw
48•miniBill•2h ago•33 comments

Kimi Linear: An Expressive, Efficient Attention Architecture

https://arxiv.org/abs/2510.26692
165•ronfriedhaber•5h ago•61 comments

Show HN: Formally verified 3D CSG: Trust 93 lines spec, not 1000 lines AI code

https://github.com/schildep/verified-3d-mesh-intersection
75•permute•3h ago•33 comments

GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

https://www.pcmag.com/news/grapheneos-defends-data-wiping-function-that-blocked-us-border-search
73•pseudolus•1h ago•51 comments

DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It

https://ciphercue.com/blog/dmarc-enforcement-gap-rua-fragmentation-2026
90•adulion•5h ago•70 comments

You Could Have Come Up with Kimi Delta Attention

https://blog.doubleword.ai/you-could-have-come-up-with-kimi-delta-attention
6•AnhTho_FR•18m ago•0 comments

How to Survive Boiling Water

https://taxa.substack.com/p/how-to-survive-boiling-water
274•cainxinth•4d ago•46 comments

Google's Beyond Zero: Enterprise Security for the AI Era

https://spawn-queue.acm.org/doi/10.1145/3819083
100•jordigg•6h ago•54 comments

Show HN: XY – Fast, composable, GPU-accelerated charts, written in Rust

https://github.com/reflex-dev/xy
15•apetuskey•25m ago•1 comments

Solving Fermat: Andrew Wiles

https://www.pbs.org/wgbh/nova/proof/wiles.html
40•1970-01-01•19h ago•15 comments

I showed an AI an image it couldn't see – then caught it lying about what it saw

https://paulshepherd.com/conversations/session-1.html
4•LifeWithGlee•16m ago•2 comments

VMs can't boot with Network Mode set to Bridged on Apple M5 Pro machines

https://github.com/utmapp/UTM/issues/7658
21•IndySun•2h ago•10 comments

Show HN: Scala Tutorials – interactive Scala 3 lessons in the browser

https://scalatutorials.com
59•eranation•3d ago•18 comments

Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/
47•882542F3884314B•4h ago•31 comments

What AI developers could learn from Charles Bukowski?

https://galjot.si/what-ai-developers-could-learn-from-charles-bukowski
50•sedovsek•3h ago•37 comments

A $500 RL fine-tune of a 9B open model beat frontier models on catalog review

https://fermisense.com/when-machines-take-the-wheel/
281•ilreb•14h ago•94 comments

So, you want to make a game engine (2023)

https://lisyarus.github.io/blog/posts/so-you-want-to-make-a-game-engine.html#part-3
3•kugurerdem•43m ago•1 comments

Show HN: Flashpaper – Self-destructing secret sharing with no database

https://flashpaper.app/
4•minpym•43m ago•2 comments

Dolmenwood: Fantasy RPG built around the acclaimed Old-School Essentials rules

https://necroticgnome.com/collections/dolmenwood
37•doener•3d ago•12 comments

A Deep Logo Study

https://dannyspina.com/blog/my_new_logo_study
8•nate•4d ago•2 comments

Show HN: Ctrlb-decompose: Strip the noise from logs before sending to LLMs

https://github.com/ctrlb-hq/ctrlb-decompose
46•ruhani_grover•3h ago•6 comments

About the security content of macOS Tahoe 26.6

https://support.apple.com/en-us/128067
170•andor•6h ago•114 comments

Show HN: tale.fyi, we deserve a home for fiction

https://tale.fyi/@sam/announcing-tale-fyi-read-or-listen-to-an-entire-book-from-a-single-link
66•samuelcole•3h ago•45 comments

Mondragon Corporation – a federation of co-operatives

https://en.wikipedia.org/wiki/Mondragon_Corporation
139•brnt•4h ago•24 comments