And this is why you never, ever, EVER enable biometrics. EVER. Make a damn password or at least a very long PIN and enter that shit every time.
For people who don’t want to do that: turn off your phone if there’s the likelihood that your phone will be confiscated soon (crossing a state border or getting a perquisition). This will
- Disable biometrics
- Encrypt everything
On Android, entering lockdown mode does the same thing. You can do it by pressing volume-up and power at the same time, then tapping Lockdown.
Not all phones work that way. Just tried it on mine btw
deleted by creator
And this only makes it more expensive and time consuming to unlock. So if you’re small fry, they won’t waste the resources. But if you are a “person of interest” don’t be dumb, bring a burner phone.
Completely agree. There are a surprising number of folks who should know better who will swear up and down how safe they are. If they like the convenience and the “cool factor” of using them…that’s fine, whatever, none of my business. Just don’t try to gaslight me that they are safe.
Or power it off when they ask for it to disable biometric unlock.
Not always an option. Sometimes reaching for your phone to turn it off will get you killed. Just don’t use biometrics.
PSA FOR IPHONE:
if you press volume up, then volume down, then hold the power button until the power slider comes on, then it will disable biometrics until next unlock
For GrapheneOS (custom android), there is Lockdown button next to power off and restart which does the same thing. I think it may be on other Android phones as well but not sure.
Graphene even has an option to enter a fake pin and wipe the phone iirc.
Yes, known as Duress password.
Yes, and it may be a good idea to have it just in case. But the courts in the US so far mostly ruled that police forcing you to give biometrics to unlock is fine, as it is the same as fingerprinting you when you are arrested. But forcing you to give pin/password is the same as testifying against yourself, which is against the 5th amendment. So they usually can’t make you to give them a pin/password. At least in theory. Still better to have it in practice.
Yeah, it’s a feature on stock android. Should be in most android flavors
You won’t have the time or ability to do this when the police are involved. DON’T USE IT. It’s not secure.
Legit.
Do you have to slide the power slider and turn off your phone for it to work? Or does it disable biometric as the slider show up?
as soon as it shows up, i have also learned in this thread that clicking the power button 5 times does the same
Lol that’s emergency 911 on my phone
Just learned something new. Thanks!
I just tested it… it’s the same combination for a fast shutdown. Up > Down > Hold Power (1 second hold), then you’re introduced to the option of sliding to power off. If you exit from that prompt or just leave the screen idle for about 10-15 seconds (I didn’t count it) you’ll be forced to enter passcode.
Why tf to use biometrics then?
99% of the time im not in a situation where i am being confronted by cops, but crossing a border or a traffic stop it is nice to know
Doesn’t it boil down to like what you know is safe, what you are can be used?
Like they can’t make you give passwords, but biometrics are vulnerable.
Restart your phone beforehand so that it won’t accept biometrics
Both iOS and Android have Lockdown options, so that isn’t even completely necessary, granted it will also work.
Before the police pull you over?
On iOS hold vol up (or down) and power at the same time. It starts SOS but you can cancel. At this point Face ID is disabled and you must enter your pin to reenable it.
So yeah. As soon as you see lights, hit that cop button.
Just make sure you have all your docs on paper so you don’t have to open your phone.
This is Graphene OS had a distress code you can enter that will wipe the phone.
I wonder though, if you had that set up and the cops ask you for the code to unlock and you told them the code to wipe and they end up wiping the phone. Would they be able to charge you with evidence tampering?
“Sorry, my distress pin is 1 digit off of my unlock pin, you probably fat fingered it by mistake. I guess we’ll never know. You really need to be more careful.”
How would they know
Because instead of unlocking, everything would get deleted when they entered the code.
They wouldn’t know it was you.
I’d expect so. You have the right to remain silent. You do not have the right to destroy evidence. How is wiping your phone any different from running around your house flushing things?
Because they would be the ones actually entering it, you would just say some numbers out loud.
But probably the smarter thing to do would be to leave the wipe code on a sticky note inside the phone case and hope they try it.
You can also set it to wipe if you don’t enter a PIN after a set amount of time.
What an outrageously evil and dystopian ruling.
Bending over backwards to find logic that lets cops ignore the Constitution.
If it’s a search violation without biometrics then it’s a search violation with biometrics. Next up they’re going to rule that no matter how much you get recorded telling them you don’t consent to a search, a search is legal as long as they can smash their way into your car.
I forgot my passcode.
What then?
They can only force you to use biometrics to open it, not a password.
Noted!
Jokes on them, my biometrics don’t work most of the time and I have to enter my pin anyway.
AlternativeeEmergency PIN for deleting the Phone
This isn’t new. This can also be compelled by the courts. If you want your phone secure, don’t have one. If you want it to be expensive to open, use a long passcode, do NOT use fingerprint or face unlock.
What a terrible decision. That’s like saying if you have a house key they can search your house.
There’s a reason they keep you focused on the first two amendments. Don’t want you realizing how comfortable they are with unregulated search and seizure.
Honestly idk how the civil forfeiture can possibly be considered constitutional
Sneaky fuckers thought I forgot about the third amendment.
Soldiers keep trying to sleep with your spouse?
They can’t be, at least not without a trial.
That won’t stop the Court.
they did in fact use the data seized from his phone to find his house, then took his key and searched it
There are finger print locks for doors available commercially too
His attorney probably should have raised that objection in the first place. He should have objected based on the phone not being material to the search of the car. But if he didn’t raise the objection correctly during the initial trial, then he can’t raise the objection on the appeal either.
That’s why passwords are safer in this situation. Cops can’t compel you to reveal it.
Oblig:
I miss when crypto nerd meant cryptography nerd
It still does. People who like cryptocurrency are crypto bros (regardless of gender).
?
They mean literal cryptography.
https://en.m.wikipedia.org/wiki/Cryptography
Now, a lot of old crypto bros were the origins of crypto currency, but that’s a different breed of nerd than the modern crypto bro. The difference is how much you like math and how many posters of Alan Turing you have.
I don’t really know how you misunderstood his post in order to correct you, but I’ll try.
He’s saying crypto nerds like cryptography and crypto bros are cryptocurrency shills.
Ah, I see. The confusion happened because crypto nerd absolutely does not mean that to the casual public anymore, as bemoaned in the parent comment, and I didn’t realize he was insisting there is still a distinction.
I really don’t have a leg to stand on with that topic because I always put “libertarian” in scare quotes.
The thing is, however, that a lot of the crypto nerds are also crypto bros. Or at least, they’re who the crypto bros were trying to be, the guys who were mining Bitcoin when it was worth $0.13, but those two people sound exactly alike on the Internet on their shared interest because they’re both trying to sell you the coins.
cryptocurrency is applied cryptography, no reason you can’t like both.
Yeah, unfortunately, this isn’t a new thing, just upholding the old standard. I explicitly avoid fingerprint and face recognition features because of this. Your fingerprint and your face are legally considered what you are, so things like 5th amendment right to avoid self incrimination don’t apply, but passwords and PINs are legally considered what you know, so you can’t be forced to divulge.
The wrinkle in this case is that the thumb print giver was in parole. The conditions of parole stated that failure to divulge phone pass codes on phones could result in arrest and phone seizure “pending further investigation”. The parole conditions didn’t say anything about forcible thumb print taking.
So the logic here seems to be:
- If he had agreed to unlock the phone then the result would be the same.
- If he refused to unlock the phone, that is a legitimate grounds for arrest. Fingerprinting is a routine part of being arrested, so there’s really no harm if it’s done on a phone in a patrol car. Either way, the result would end up about the same.
Yeah that’s even less than what the standard is. That’s just saying “you have to do what’s in the conditions of your parole, and we won’t accept sneaky technicalities.”
But I suppose “appeals court rules that you have to obey the terms of your parole” is far less ragebaity.
The real story here is how terms of parole are often ridiculous and contribute heavily to our high recidivism rate. Not to mention stripping away rights.
Not arguing in favor of them, with how awful the police and oftentimes court systems are, I’m not surprised to hear parole ones are bad too. But what about them contribute to reoffending?
(I’m too lazy to check myself right now, and maybe the answer will help others too? Plus it might vary in jurisdictions)
I wasn’t referring to the parole officers per se, just the parole stipulations. For example, a common one is that you must be employed. But then you also must make your regularly scheduled meetings with your parole officer, which are scheduled during working hours. The parole board will determine your address (usually as a stipulation of release, usually with family) but the parole office will be on the other side of the city. Public transit is unreliable, if you miss your bus you go to prison.
I had a friend of a friend who was getting released to a halfway house. Never saw the light of day. When they released his clothes to him, that he got arrested in seven years previously, they found Marijuana seeds in the pockets. Not bud, seeds. That’s a parole violation, instant back to prison for 3 more years, minimum. The parole officer who was there told me about it (was also the officer of my friend, who I was giving a ride to).
Any time a cop has the legal authority to access the contents of your phone, you can be compelled to provide your fingerprint or face to unlock it if that will work. If your phone doesn’t have those features enabled and relies on a PIN, they can’t force you to tell them that outside of some unusual circumstances like parole obligations because you agree to those. They can still access your phone, but only to the extent that they can without the PIN. In this case, cops had the required authority because of his parole obligations, but they’d be equally able to force you to unlock by fingerprint or face if they got your phone as part of a search warrant and I think if you’re arrested but only if your phone is relevant evidence. Maybe even if it’s not, but I’m less sure about that.
I just have lockdown mode enabled from the power menu so that it forces pass code login instead of allow fingerprint login.
Never been pulled over or talked to a cop (other than family members) in my life.
You can use the lockdown mode on Android, but you have to remember to turn it on.
Android: Search settings for “Lockdown” and enable “Show lockdown option”
When needed hold the power button and the lockdown option will appear alongside the standard power menu options.
IOS: Hold the Lock button and either volume button to show the power off screen. Cancel out and FaceID will be disabled until you use your pin to unlock the phone.
You can also spam the power button on IOS. It should pop up the same menu as holding the power button. You can cancel, but it requires a password to get back into the phone.
Not sure about Android but IOS you can actually use FaceID for all the things you want like password managers, log into PayPal, and other biometric features but have it disabled to unlock the phone. It’s what I do, you don’t need to spam anything. Just use a pin to unlock.
I didn’t know that!
Cool!
I’ve never understood people who are happy to give their biometrics to fucking PayPal and every other random company. Just use a password for everything.
You don’t “give” your *biometrics to any of them. Your biometric data is used to encrypt and store each services password hash or auth token on your device.
*At least when it comes to login authentication. Nothing stopping them from acquiring your biometric data from a hundred data brokers.
Nothing stopping them
Stop using biometrics for everything, that’ll help
That’s a fair point, I don’t want my info given to every private company out there. However the idea of the biometrics (if you take it at face value [no pun intended]) is that the biometrics are stored on the chip in your device. Then the password or authorization is then granted based on approval from that.
It’s not like you can grab another phone and try to log into said service with your biometrics.
I 100000% guarantee there is a backdoor that allows someone (at least the nsa, probably various companies) to get that data.
I did not know about this feature. Thank you!
Thank you!
Truecrypt had a false volume for this very purpose.
You have one password to unlock your drive, and one password to fake unlock your drive and instead unlock a volume that looks like your drive, where you store stuff that looks important but isn’t your real secret.
By physical here, they mean using your biometrics by force. They’re still not allowed to beat you with a rubber hose.
A court, however, can force you to give up a password or hold you in contempt (which is essentially the rubber hose option). Having false unlocks defeats that
A court, however, can force you to give up a password or hold you in contempt (which is essentially the rubber hose option)
That remains to be seen; I don’t think that there’s ever been a definitive ruling on this in the US. One real problem is that they would have to be able to prove that you knew the password, and that can be a real problem. I have an old Tails drive; it’s been years since I used it, and I have no idea what the password is anymore. Shit, I sometimes have a brain fart and can’t remember the passphrase for my password manager, and I use that a lot.
*Veracrypt, Truecrypt is no longer maintained
iPhone users:
-
DO NOT USE FINGERPRINT unless you absolutely have to for, say, disability reasons.
-
if you use facial recognition, don’t. Same as above.
-
If you find yourselves in a situation with the police, tap the lock button 5 times. This forces a passcode to open the phone and they cannot (yet) force you to enter a passcode.
Anytime I am filming a protest or anywhere near police, I just tap the lock button a bunch of times in my pocket and I can rest easy.
Samsung users (not sure if it also applies to other android flavors):
Go to settings>lock screen>secure lock>show lockdown option and turn it on.
Now if you hold the power button for over a second, a menu pops up with an option to turn on lockdown mode. This disables all biometric unlock methods until the next time you unlock it.
You can also turn the phone off.
Edit: and I also have this on my Pixel so this may apply to all versions of android
Is it a rumor or is there a legal requirement that you must have some battery juuce left (in your laptop iirc) in order to cross US or UK borders? I remember this as an answer to “sorry, can’t fire up my device I’m out of battery”.
I’ve seen it happen when flying back to the US through Germany. There was random additional searches at the gate for select passengers. The guy next to me could not get his laptop to turn on as it was out of juice. He was told either he finds / buys a charger or the laptop is not flying with him on the plane.
I don’t see how they can ever enforce that. Also, if they really want they can plug the device in and make you log in I guess?
You can also just hold power + volume up while it’s locked, once you feel the buzz it won’t accept biometrics until you put in the password.
On Motorola it’s press power + volume up button and then the lockdown button.
on android you can get Private Lock which locks your phone and disables biometric unlock, when the phone is shaken hard enough
Anytime I am filming a protest or anywhere near police, I just tap the lock button a bunch of times in my pocket and I can rest easy.
How does that help if the police are the ones that alert you to their presence? I highly recommend against quickly shoving your hand in your pocket to tap a button 5 times.
I do it in anticipation. It’s not like they sneak up on you like a ninja. They are very clearly around.
Plus it takes like 2 seconds. Unless they got you at gunpoint you’re probably going to have an opportunity to accomplish this. Most people interact with police in the US being pulled over - you’re telling me you can’t lock your phone before they come to your window?
Holy crap this is a great tip I did not know! I haven’t had a run in with the police in like a decade, but better safe than sorry. Hopefully I never need to use it, but I just tried it on my iphone and works like a charm, so thanks mate!
Another dude pointed out you can hold lock + volume up as well
I learned something from my (quite activists) daughters recently: they delete the Signal app each time they cross a border.
It’s the main coordination and information tool in their circles, and the recommended behavior is just to not have the app when at risk.
Good luck finding incriminating evidence stifling through zillions of Pouting Selfies and Gossip-Sharing Screenshots of Idiot Boyfriend’ text messages.
-
OP can you put the country in the title? Like [US] for example
Done!
Luckily GrapheneOS has a duress passowrd feature. Very useful for these situatuons!
I didn’t know that. Is that in settings somewhere?
Edit: yep, see it now. Damn this must be new or I never looked into it.
It’s new as of about 1-2 months ago.
It was released with the 2024053100 build, so not even a month ago.
How does it work? Can someone use a specified finger to trigger the password requirement?
Nore information at: https://grapheneos.org/features#duress
Passcode. Not fingerprint.
Ah. Then I guess I don’t see how this is related to the post.
It’s not, technically, but if I have sensitive documents on my phone and a law officer is trying to get me to unlock my phone, I will be entering and/or putting the duress code into my phone. GrapheneOS has ‘lockdown’ button by ‘restart’ and ‘shutdown’ all of which will require a passphrase to unlock, even if you normally have fingerprint enabled for X hours each time of use.
So it’s semi-related in that GrapheneOS protects against this type of attack.