matheusmoreira
3 days ago
> Until recently, only spies and criminals had to worry this obsessively about their private statements being picked up by electronic equipment.
> But soon, the average person might need to deploy surveillance countermeasures.
Already there. If you want privacy and anonymity online, you're looking at literal terrorist cell tier tradecraft. That means pulling up documents written by people from the "counterterrorism community" and "intelligence community" and learning how all of these "clandestines" operate.
Unlinking one's identity from one's actions and speech requires some serious OPSEC now. It requires constant, never ending effort. It requires perfect execution and discipline.
inigyou
3 days ago
Using GrapheneOS makes you a terrorist now. I'm a terrorist.
Alive-in-2025
3 days ago
Since the courts decided you have to use your fingerprint to unlock your phone (because they decided that's not giving up your password and they can't compel you to give up your password), what if you use your fingerprint to wipe your phone? But you don't tell anyone ahead of time when they force you to use it. I'm sure you'd be arrested at the least.
I can't be the only person who has thought of this.
Tangurena2
2 days ago
A password is considered (by courts) to be testimony. Face, gesture or fingerprints are considered things like keys which you can be forced/compelled to turn over when commanded by law enforcement. Therefore, only passwords, which will require a court order to unlock, are secure enough for now.
petesergeant
2 days ago
> A password is considered (by courts) to be testimony
For now. It doesn't seem like an especially natural fit. Regardless of the merits of being able to compelled to turn over your password, relying on labored interpretation of laws is not a good idea: 14th amendment was always a very shaky basis for abortion rights, as the 2nd is a very shaky one for personal gun rights.
inigyou
2 days ago
Fingerprint and PIN unlock, but only PIN unlocks it and fingerprint is always duress? That's a good idea.
stronglikedan
2 days ago
At that point, just don't have biometrics configured at all. It would be waaay to easy to accidentally wipe your phone. Just have an unlock PIN and a duress PIN. You're going to be charged with destroying evidence either way if you use the duress method, so you may as well use the method that won't accidentally wipe your phone with a single misplaced finger.
inigyou
2 days ago
The point is that you don't wipe your finger. The police wipes your finger against your will.
stronglikedan
2 days ago
> you have to use your fingerprint to unlock your phone
Nitpick, but that's only if you have biometric authentication configured in the first place, which you aren't compelled to do.
Alive-in-2025
20 hours ago
Yes. But I apparently didn't make the point I wanted to. If you set your phone to delete everything when you scan your fingerprint, is that a crime? No password need be provided. You cannot avoid giving them your fingerprint to unlock a phone, already established in the US as a legal rule.
I'm sure they will claim its a crime if you set it up that way, but is it?
They can already legally compel you to provide your fingerprint. You can't avoid that, you'll get put in jail. Do you have to tell them "don't do that with my phone, it will reset everything if you do that".
BoppreH
2 days ago
IANAL, but I would bet that's still destruction of evidence. Judges are human, for better or worse, and can see the intention behind cute tricks like this.
It might work if your fingerprint was used while you were unconscious, but any solution that starts with "setup a trigger that wipes a device" is already on shaky grounds.
mdp2021
2 days ago
> "setup a trigger that wipes a device" is already on shaky grounds
It isn't on shaky grounds: you protect your private device from everyone, not just from some "law enforcement". If you want to protect your private device from any party (e.g. thieves, trivially), it will also be protected against law enforcement agents as a side effect.
BoppreH
2 days ago
What trigger would you setup to protect against thieves? I can't think of any that has the right sensitivity (not triggering if I start running to catch the bus), and won't escalate the violence (like my fingerprint wiping the phone in front of an armed robber).
And remember that the context here is you explaining your digital booby trap to a judge who thinks you might have deliberately destroyed evidence.
mdp2021
2 days ago
> What trigger would you setup to protect against thieves?
"Wipe the data after a number of failed logon attempts".
I understand that this does not fit completely with the "in front of law enforcement" idea, but it opposes your «any solution that starts with "setup a trigger that wipes a device" [would be] already on shaky grounds»: we can very legitimately setup triggers that wipe devices in the possibility that the device falls into random hands.
inigyou
2 days ago
AFAIK it's legal to set up a trigger that wipes a device. It isn't legal to choose to wipe your device after you know the government wants the data. Tricking the government into wiping it is still allowed, especially if you tell them not to do that.
BoppreH
2 days ago
That matches my understanding too. Unfortunately it sounds like the poster was suggesting to wipe the device after the government requests access, and was probably not planning on telling the officers about the trigger.
Alive-in-2025
20 hours ago
The theoretical scenario was the government seized your device, they don't give it back to you. You decline to give them they password. You don't say anything else, you have the right to remain silent. You aren't not telling the government to do anything. You don't suggest they scan your fingerprint. They are in charge, you are cooperating with lawful orders ("provide your fingerprint").
There are videos on youtube where the lawyers tell you what your rights are at traffic stops, also there are ones that talk about the different rules when coming through immigration. These can be painful to see when they show the ones where cops ignore limits.
So at the border, they tell you that you are legally required to provide your finger print, you do that, and don't say a word. I'm sure it will be a bad day for you, regardless of how it works out after years of litigation on whether it is your duty to tell them how NOT to unlock your device.
inigyou
2 days ago
With fingerprint unlock it's not your choice. That's what makes it clever. The cop can grab your finger and hold it to the scanner while you tell him not to do that.
Nextgrid
2 days ago
Presumably you must disclose that "doing that" would wipe the device... and you better hope this is caught on some neutral party's camera so there is a record of you saying that.
sejje
2 days ago
It's not unfortunate. It's the whole point.
kelvinjps10
2 days ago
isn't this what that guy did and he got in trouble for it? I'm talking about the one when asked for the pin gave the pin that would wipe the data from his graphene os phone
inigyou
2 days ago
No he gave the duress PIN while implying it was the correct PIN. That was the crime. Also they only caught him because he bragged that it was the duress PIN after the wipe.
Alive-in-2025
20 hours ago
Yes, the difference is you do exactly what they say, you follow legal orders to give your fingerprint, or also it could be "take a picture of you to unlock". I'm sure eventually the govt will make a new rule and a judge will say "you have to tell us in detail if we give you legal orders and it won't do what we think" or something like that.
lukan
2 days ago
Well, guess what happens:
https://www.nytimes.com/2026/07/28/us/duress-password-phone-...
inigyou
2 days ago
That happened because he chose to give the duress PIN. Cops are allowed to just grab your finger and scan it against your protest. You can say "don't do that, it'll wipe my phone" and they'll do it anyway and it'll wipe your phone, and now it certainly isn't your fault.
nisegami
2 days ago
What does it matter? The state certainly isn't going to throw up its hands and say "you got us". They're still going to try to make it out to be your fault and even if you do successfully argue it wasn't of your volition, they've still robbed you of years of your life and hundreds of thousands of dollars in lawyer fees.
inigyou
2 days ago
Well that applies to anything you do that the state doesn't like, so may as well just give up and kill yourself? Or what's your plan?
nisegami
a day ago
My plan is to live a reasonable life and treat the state like I treat violent weather. If I happen to have the misfortune of drawing the attention of the state, then yes, your suggestion may be relevant.
close04
2 days ago
> they've still robbed you of years of your life and hundreds of thousands of dollars in lawyer fees.
Intentionally giving a duress PIN which you know will wipe evidence - information you were just asked for by some law enforcement - just robs you of more of years and money. The law is lopsided and gives some more power than others. There's no point debating why it's like that, try to change the law before you break it or find ways to not need to break it at all.
brookst
2 days ago
“One simple trick” stuff rarely survives contact with the court system. Tech people like to imagine law is code, but it’s not. Nor should it be.
DennisP
2 days ago
One simple trick that's proven to work is to just leave biometrics disabled and refrain from giving your password.
There are all sorts of situations where people go free despite the wistful desires of prosecutors, due to the details of what happened and what the law actually says.
dns_snek
2 days ago
Can you come up with a plausible argument for how that applies in this scenario? What they said doesn't hinge on some sort of "clever" technicality.
inigyou
2 days ago
This may be true for hackers but courts have to prove guilty beyond a reasonable doubt to the letter of the law.
The law here is destruction of evidence. The guy destroyed evidence by giving the wrong password to the police. If the police had destroyed it of their own accord, he'd be free. If the duress PIN was 1234 and the police just tried it, he'd be free.
user
2 days ago
red-iron-pine
2 days ago
see also: sovereign citizen approaches
amelius
2 days ago
Best approach is to shadow-ban the user when they do a secret gesture before logging in. No wiping necessary. Easiest implementation is to just log them into a shadow account.
inigyou
2 days ago
GrapheneOS rejected the shadow account idea because it would be very obvious to everyone that it was a shadow account.
reedf1
2 days ago
This would still be destruction of evidence - virtually your only defense against that would be if it was not triggered by you.
bloak
2 days ago
Since you seem to know about this, what are the actual rules about "destruction of evidence" in your jurisdiction? What does the accused need to have known for a crime to have been committed?
(Common sense tells me that the accusation might make sense both in cases in which the accused knows about a crime and in cases in which the accused knows about a police investigation, even in the absence of a crime, but deleting nude photographs to stop a customs officer from seeing them, for a random example, would that be a crime?)
reedf1
2 days ago
Generally any material you intentionally delete after you are told to hand over evidence is considered to be the most incriminating version of that material in a court of law.
bloak
a day ago
That rule wouldn't work very well if the person who destroyed the evidence isn't the person suspected of the crime and it is unclear whether the person who destroyed the evidence is a friend or an enemy of the suspect. So I think a sane legal system would want to punish the person who destroyed the evidence rather than jeopardise the fair trial of the suspect.
dormento
2 days ago
Imagine dozing off in the interrogation room, and the not-so-sharp officer seizes the moment and decides to use your thumb to unlock the phone, with the camera recording.
"You dumbass! You use my thumb to trigger duress mode! Don't you know thumb is always wipe, and PIN is always unlock? Moron!"
shevy-java
2 days ago
How can they reason that evidence was destroyed when they can not prove it ever existed in the first place?
joebates
2 days ago
They don't need to reason that evidence was destroyed. They just need to reason they there was an attempt to destroy potential evidence, whether or not there was actually any evidence. Any kind of interference with an investigation in any way is likely subject to prosecution.
inigyou
2 days ago
How can they in the GrapheneOS duress pin case?
graceful6800
2 days ago
Using a duress PIN or other duress feature is now considered destroying evidence so YMMV
ern_ave
2 days ago
Write your duress PIN on the back of the phone. I guarantee you the first cop that sees it will go, "LOLOL!!!! HIS PASSWORD IS RIGHT THERE!!! LOLOL" and immediately enter it.
inigyou
2 days ago
I heard for this reason police are now trained not to try any code that you can't go to jail for if it turns out to be a duress code. That means anything you didn't tell them was the unlock code.
dwedge
2 days ago
I used GrapheneOS without a sim card for 4 months and the battery life was great. I put a sim card in, and since then (2 months) the battery dies twice as fast no matter which profile it's in, and dies faster even on airplane mode. I left it at 80% the other day and went out, came back 6 hours later and it was dead and red hot.
Maybe it's just a dodgy phone, maybe it's not doing something on the less-trackable sim connection, but I realised I can never really know.
NewJazz
2 days ago
What model do you have?
The pixel 6a does terribly when it is in 5g mode, something abput the hardware is broken or bugged. My friend who has a 6a has to keep it in 4g only mode or sacrifice battrry life.
dwedge
2 days ago
Pixel 9 but it could be another obscure bug that only shows up with that Sim
user
2 days ago
red-iron-pine
2 days ago
lasts for days with a pixel 9. literally don't need to plug it in for a couple days at a stretch
might just be an older phone and older battery
dwedge
2 days ago
It's a 9 and I had exactly the same experience until I put the Sim in. Maybe I should try first taking the Sim back out and second reinstalling it
matheusmoreira
3 days ago
We're all terrorists here.
Own a general purpose computer you can run arbitrary software on, not just corporation and government approved software? You're clearly a money laundering drug trafficking child molesting terrorist.
xnzakg
2 days ago
Don't worry, the arbitrary software is probably running under Intel's ME or AMD's PSP.
Noaidi
2 days ago
This is why we should all be stopping, or at least minimizing, the use of our phones. The point is it’ll make the corporations more mad and that will get the government to change. money changes everything
Gud
3 days ago
Let’s be real, it’s an important topic.
mdp2021
2 days ago
> Using GrapheneOS makes you a
According to?
inigyou
2 days ago
mdp2021
2 days ago
Thank you, I will devour it, but it seems to misrepresent a naïve point: simple Bayes. Id est,
> Law enforcement officials in Catalonia say they associate Pixels with crime because drug traffickers are increasingly turning to these phones
And that is correct behaviour under frequentistic reasoning (and still abysmal behaviour in the non-expressed potential case that it be done indiscriminately): if in a population a tool is related to many criminals and the very few sane people, that tool is a justified element for suspicion. But for suspicion only, in the coldest terms: the Sane use it, and using it is a sign of sanity: for that reason, of course you do not /assume/ that those who use that tools are criminals.
To have a knife raises suspect in the land of the stabbers and raises little suspect in the land of the scouts.
Only the bad tail of the curve mixes "suspect" and "assumption"; and only the worse tail of the curve thinks that since stabbers use knives we should do without them. Especially in this dire case in which obviously for reasons of Dignity, we will not, all capitals, ___will not___, keep spying devices on us. It is difficult to find examples and similes stronger than the actual case.
The article in fact fumbles into a very bad sentence:
> You might be wondering: if I don’t have anything to hide, why should I bother using GrapheneOS? That[!!!] a fair question
No, that is a very stupid question: Dignity imposes privacy, and we have ___everything___ to hide to the zombie apocalypse of cretins.
brazzy
2 days ago
Hoodedcrow
2 days ago
Statements like this are a stretch. This was not the fact of using the OS, but specifically the fact of wiping it. The situation is atrocious enough as is, no need to make up additions.
kQq9oHeAz6wLLS
3 days ago
Friend of a friend retired several years ago from Intel. He'll go into detail about all the ways you're being spied on. He won't let you into his house with a smartphone; you have to turn it off and leave it in your car.
I used to think he was just paranoid...
exodust
3 days ago
> He won't let you into his house with a smartphone
His mistrust might be about the phone's owner and the recording apps they might use, more than the smartphone itself.
Socially it's much safer to direct suspicion at "the smartphone" rather than the people invited to your house.
close04
2 days ago
A visitor who wants to record will just have a second recording device. Asking nicely to leave the phone behind could only protect from spying the phone owner never intended.
Hoodedcrow
2 days ago
To be fair, most phones have invasive Google/Apple/Chinese OEM services that work with high privileges and are invasive on their own, without apps. The share of people using degoogled OSes is small enough to assume it isn't the case. And, to be fair, if someone has a degoogled phone, you'd probably know that by now (I say as also a degoogled user XD)
Der_Einzige
2 days ago
The fun part about this comment is that we don't know if "Intel" is the company, or the term for the IC. I'm pretty sure it's equally likely to be either meaning, and no surprise based on whichever is correct.
red-iron-pine
2 days ago
there is quite a lot of industrial espionage happening with Intel and AMD, so I wouldn't be surprised if they are, in fact, extra paranoid
vasco
2 days ago
The likelihood is 100% that it is the company.
lukan
2 days ago
Not likely.
kQq9oHeAz6wLLS
2 days ago
In this case, it's Intel the processor company
everybodyknows
2 days ago
How about a Faraday box, by the door? Take to the next level with acoustic insulation, just in case there's a record-now, upload-later mode.
nbernard
2 days ago
> How about a Faraday box, by the door?
Not as easy as one may think. If you put a phone in a generic waterproof metal box (metal junction or biscuit box for instance) and call it with another one, most of the time it will still ring...
pluc
2 days ago
A Faraday box that doesn't block signals is just a box.
inigyou
2 days ago
The point is how do you know it's a Faraday box?
wackro
2 days ago
Presumably if you're driven by paranoia to buy or make a Faraday box you will be paranoid enough to try putting your phone in it and calling it
nbernard
2 days ago
The problem is a Faraday box only attenuates signals. And it usually does not attenuate all frequencies identically.
So your test may seem successful, but the box not be enough closer to a tower, or if your neighbor added a new AP, or if cell phone frequencies changed since you bought and tested it. Moreover, if you have to open and close it often, you have to be careful that the attenuation doesn't degrade.
All that to say that the "Faraday box solution" would mean testing it regularly with professional instruments and all that. It is far simpler and cheaper to ask guests to leave their phones in their cars.
ChoGGi
2 days ago
I bought a Faraday box for my car keys. I made sure it was big enough for my phone, then used a network monitoring app.
aidenn0
2 days ago
Car keys usually use a wavelength of 1 meter; networking on your phone is going to be typically shorter than 15cm (though varies widely based on geographic region and carrier). A faraday box for your phone might not work for your car keys.
matheusmoreira
3 days ago
> He'll go into detail about all the ways you're being spied on.
Don't doubt it for even a second.
calvinmorrison
2 days ago
or just get on the alternet. If you and your peers care about communicating and you dont feel like doing state witch craft, the easiest thing is to just setup your own opt in systems and not use facebook, etc. run your own IRC server, file share, whatever. self host. it's easier than ever. Don't use discord, run your own communities, etc.
jahnu
3 days ago
“Chief, we got a citizen here with a suspiciously small online footprint. Investigate further?”
Borg3
2 days ago
And this is what I worry about. Seriously. My online footprint is minimal. I just hope gov will be still incompetent and lazy...
user
2 days ago
inigyou
2 days ago
IIRC ICE has detained people trying to enter America without social media apps.
jbxntuehineoh
2 days ago
wise move, they could be radical anarcho-boomerists
red-iron-pine
2 days ago
it's kinda like how the old FBI email monitoring thing, CARNIVORE, automatically flagged anyone talking about BSD for a 2nd scan
mdp2021
2 days ago
I met the parent comment downvoted: I don't know why, given e.g. the rule from the current administration in the USA that, for visitors, the absence of social network profiles is to be taken as cause for suspicion.
slipperybeluga
2 days ago
I've applied to jobs recently that require listing LinkedIn profile. Don't see how that is legal. I always put something like idonthavesocialmedia.com but I imagine it's a strike against me according to see brainless HR drone who sees it as problematic
adolph
2 days ago
> Unlinking one's identity from one's actions and speech
This is an odd formulation. What is one's identity other than one's actions (physical body) and speech (mental state serialized into language)?
user
2 days ago
purplemoonx
2 days ago
This is paranoid. It is not that hard. HN famously can’t keep people out of here. They make new accounts. It’s not enough to IP ban. It’s impossible to retarget people even without vpn, all I need is a different cell tower.
I interact at various levels of anon all the time, it’s easy just cover your:
-Network (geo/IP)
-Device (useragent, cookies)
-Fingerprints (browser vendor, screen size)
And you’re off to trolling
datadrivenangel
2 days ago
Good luck keeping law enforcement from finding your location if they really don't like you.
purplemoonx
2 days ago
[flagged]
vaylian
2 days ago
Palantir and Flock have entered the chat
purplemoonx
2 days ago
Mainstream News has entered your mind. It likes it here, and is going to stay a while.
txrx0000
2 days ago
While this is true, it's not an all-or-nothing game. A little bit of countersurveillance is better than none, even if you're not that savvy. We can win by gradually raising the per capita cost of surveillance until it's infeasible to surveil everybody. Individual digital sovereignty will be achieved eventually, but we won't get there in a single step. Start small and iterate. Even simple things like periodically wiping browser cache or changing the apps you use can meaningfully raise the cost.