Notes on Internet Privacy

Posts and research from the URnetwork team and community.

RSS

The Passcode Is the Warrant Now.

On March 23, 2026, Hong Kong published rules making it a crime punishable by a year in prison to refuse to hand over your device password — and the US Consulate warned the rule reaches anyone merely transiting Hong Kong International Airport. On April 9, 2026, an FBI forensic agent testified that "deleted" Signal messages were pulled from an iPhone's notification database even after the app was uninstalled. Nine days earlier, Cellebrite announced it can now extract iPhone 17s running iOS 26. Last fiscal year, CBP searched 55,318 devices at US ports of entry, up 17.6 percent. France will jail you for three years. The UK for two. Germany's highest court ruled police can forcibly press your finger onto a sensor. The question the next decade is about to decide is whether the passcode in your head is protected speech — or just the next warrant target.

The airport, the amendment, and the thing the consulate had to say

At 4 p.m. Hong Kong time on March 23, 2026, the city's Security Bureau gazetted a three-page amendment to the Implementation Rules for Article 43 of the National Security Law. The text is understated. It empowers police investigating a "specified offence endangering national security" to serve a notice on "any person reasonably suspected to be capable of" unlocking an electronic device, and to compel that person to provide the device password, the decryption method, or "other necessary assistance." Refusal is punishable by up to one year in prison and a HK$100,000 fine. Providing a false or misleading password carries three years and HK$500,000. Journalists, doctors, and lawyers who know a device password because of their profession are not exempt.

Three days later, on March 26, the US Consulate General in Hong Kong and Macau issued a Security Alert under the STEP program warning that the law applies to "everyone in Hong Kong, including arrivals and people merely transiting Hong Kong International Airport." A three-hour layover is jurisdictionally indistinguishable from residence. Beijing summoned Consul General Julie Eadeh on March 29 to denounce the alert as "interference in China's internal affairs." Hong Kong's Secretary for Security, Chris Tang, said the magistrate's warrant requirement prevents police from demanding passwords "on the street." The American Chamber of Commerce in Hong Kong told members, in effect, to plan accordingly.

The amendment made Hong Kong the first major jurisdiction in the world whose compelled-decryption statute is, by its own government's acknowledgment, enforceable against anyone physically inside the airport perimeter. And the gazette paragraph is consistent with a quieter trend visible elsewhere — a trend that says the password you keep in your head has become the single most valuable piece of evidence in every investigation.


The $475 million industry that reads your phone for a living

On March 31, 2026, an Israeli-American firm called Cellebrite held its annual C2C User Summit in Washington, D.C. and announced its Spring 2026 release. The update closes the one remaining hole in Cellebrite's capability matrix: iOS 26 and the iPhone 17 series can now be extracted by the same Universal Forensic Extraction Device used by the 7,000 law-enforcement, intelligence, and defense customers Cellebrite counts in more than 100 countries. Cellebrite's own Q4 2025 earnings, reported February 11, showed revenue of $128.8 million for the quarter and $475.7 million for the year — up 19 percent. Annual recurring revenue crossed $480.8 million. The company closed its $200 million acquisition of Corellium, the Florida iPhone-virtualization firm, on December 1, 2025 — part of a strategy pivoting away from on-device exploitation toward virtual clones of seized phones.

We know how good Cellebrite is because, in February 2025, a representative accidentally shared the version 7.73.1 support matrix during a Microsoft Teams sales demo with a prospective customer. The customer saved it. Privacy Guides mirrored it. The GrapheneOS forum cached it. The document is the closest thing to an adversary's capability disclosure the digital-forensics market has ever produced. Almost every non-Pixel, non-Samsung Android device is listed as unlockable. Stock Pixel 9 in the Before-First-Unlock state (BFU — any phone that hasn't been unlocked since boot): "no access." iOS 17.4 and later: "no access" — the hole Cellebrite has now closed with the Spring 2026 release. And one row appears in the "no access" column for every state and every age: GrapheneOS Pixels from late 2022 onward.

The extraction business is not theoretical. Between January and June 2025, Citizen Lab forensically confirmed Cellebrite use on three iPhones and one Android belonging to Jordanian civil-society members arrested during Gaza-solidarity protests; the January 22, 2026 report "From Protest to Peril" says the lab is aware of "dozens more" cases and that Jordan has been a Cellebrite customer since at least 2020. In February 2026, Citizen Lab published "Not Safe for Politics", a forensic confirmation that Cellebrite was used on the Samsung phone of Kenyan opposition politician Boniface Mwangi during his July 2025 detention. In the Serbia case documented by Amnesty's Security Lab in February 2025, Cellebrite operators used a three-CVE zero-day USB chain — CVE-2024-53104, CVE-2024-53197, and CVE-2024-50302 — to attack the Linux kernel drivers for USB Video Class, USB audio, and HID devices. The exploit chain was deployed against a Samsung Galaxy A32 belonging to a student activist on December 25, 2024. Amnesty's follow-up showed it was used after Cellebrite had been told about the Serbian abuses. Cellebrite suspended its product in Serbia on February 25, 2025. It has not suspended any other country.

The three zero-days were patched in the February 2025 Android Security Bulletin. As of March 2025, more than 40 percent of Android devices remained unpatched because of fragmented vendor update cycles. That gap — between when a fix ships and when it reaches actual phones — is the operating margin of the extraction industry.


A global split that runs through the Fifth Amendment

Hong Kong is the newest coercive jurisdiction in a global landscape that has been reorganizing around compelled decryption for almost a decade. The United Kingdom has had Part III Section 49 of the Regulation of Investigatory Powers Act on the books since 2007. Refusal to produce an encryption key when served a notice carries up to two years in prison — five years in a national-security or child-protection case. The UK has actually used it — Stephen Nicholson got fourteen months in 2018 for refusing his Facebook password during the Lucy McHugh murder investigation; a teenager named Oliver Drage was sentenced to sixteen weeks in 2010 for refusing a 50-character password. In France, Article 434-15-2 of the Penal Code, as strengthened by the June 3, 2016 law, punishes refusal to disclose a "decryption convention" with three years' imprisonment and €270,000 — rising to five years and €450,000 if cooperation would have prevented an offense. France's Cour de cassation ruled on November 7, 2022 that a phone lock-screen passcode does count as a "decryption key," ending years of lower-court conflict. A challenge, Minteh v. France, is pending at the European Court of Human Rights.

Australia's Telecommunications and Other Legislation Amendment (Assistance and Access) Act of 2018 ("TOLA") aims the compulsion at carriers and device vendors rather than individual suspects, but it threatens A$10 million penalties for non-compliance and the annexed usage numbers in ASIO's annual reports are redacted. Thailand's Computer Crime Act Article 18(7) permits court-ordered decryption orders against providers and is paired with the Article 112 lèse-majesté statute; a January 2024 sentencing in Chiang Rai was fifty years. Belgium allows compulsion against third parties but not against suspects or their families, preserving a nemo tenetur carve-out. The Netherlands cancelled a proposed 2015 compulsion bill because it was found incompatible with the same principle.

On the protective side, the ECtHR anchored the European baseline in Podchasov v. Russia on February 13, 2024. The Fifth Section held unanimously that a statutory requirement to decrypt end-to-end encrypted communications — at issue, Russia's July 2017 demand against Telegram users — is disproportionate under Article 8 of the Convention and "cannot be regarded as necessary in a democratic society." The judgment is binding on 46 Council of Europe states, including the UK post-Brexit. Privacy International and Liberty are using it in their pending Investigatory Powers Tribunal challenge to the UK's secret Technical Capability Notice to Apple — the order that forced Apple to withdraw Advanced Data Protection from UK users on February 21, 2025. The UK reportedly dropped the worldwide backdoor demand in August 2025, then served a narrower order in October 2025, and never restored ADP for new UK users.

Germany's Strafprozessordnung protects the suspect from being compelled to produce an encryption key. But on April 8, 2024, the Bundesgerichtshof ruled that police may forcibly press a suspect's finger against a smartphone sensor, reasoning that using a finger as a "natural key" is "mere tolerance" of an investigative measure, not active self-incrimination. India's Delhi High Court went the other way in Sanket Bhadresh Modi v. CBI — Justice Saurabh Banerjee held that investigators cannot compel an accused to disclose a device password because doing so would violate Article 20(3) of the Constitution and Section 161(2) of the Code of Criminal Procedure. The court famously observed that prosecutors cannot expect an accused to "sing in a tune which is music to their ears." The Karnataka High Court went the opposite way in 2021. India's Supreme Court has not resolved the split.

In the United States, the answer depends on where you live. The Pennsylvania Supreme Court held in Commonwealth v. Davis (2019) that compelling disclosure of a computer password violates the Fifth Amendment because it requires revealing the contents of the mind, and rejected the government's "foregone conclusion" workaround. The Utah Supreme Court ruled the same way unanimously in State v. Valdez in 2023 and Utah filed a cert petition at the Supreme Court in 2024 that has not been taken. New Jersey went the other way in State v. Andrews (2020), accepting the "foregone conclusion" exception because prosecutors had shown the passcode existed and the defendant operated the phone. The circuit split is unresolved and the Supreme Court has declined every opportunity to hear it.

Justice John Paul Stevens's dissent in Doe v. United States (1988) — the "safe combination versus key" distinction — remains the central frame for every modern passcode case. A key lives in the physical world; a combination lives in the mind. The 2026 question is whether the distinction will survive another year of biometric unlock, face-scanning, and forensic tools that pretend they don't care either way.


Fifty-five thousand searches and no warrant

Inside the United States, the Customs and Border Protection number for fiscal year 2025 is 55,318 searches of travelers' electronic devices, up 17.6 percent from the year before. Ninety-two percent were "basic" searches — an officer in a secondary room scrolling through the phone by hand. Eight percent were "advanced" — the phone plugged into a Cellebrite or Graykey extraction terminal and imaged in full. Advanced searches doubled. CBP retains whatever it extracts for fifteen years under standing agency policy. None of these searches required a warrant; none required reasonable suspicion unless the traveler was a US citizen and even then only in the Ninth and Fourth Circuits.

The human texture of that 55,318 is the point. Rasha Alawieh, a kidney transplant specialist at Brown with an H-1B visa, was turned away at Boston Logan in March 2025 — CBP deleted photos from her phone before sending her back to Beirut. Alistair Kitchen, an Australian memoirist traveling on an ESTA in August 2025, was flagged at LAX, handed a note asking for his phone password, and held for hours while officers searched his device for his reporting on the Columbia University protest encampment. "I had been, as far as I can tell, one of the first people to have their ESTA cancelled without prior notice" for things written on the internet, Kitchen would later tell the Guardian. A year earlier, the Canadian Ontario Court of Appeal had held in R. v. Pike that Section 99(1)(a) of Canada's Customs Act is unconstitutional as applied to warrantless device searches and imposed a "reasonable grounds to suspect" floor. The US has no equivalent ruling. A Chicago petitioner asked the Supreme Court in December 2024 to resolve the question. No grant.

On April 10, 2026, the European Union's Entry/Exit System went operational — a biometric database that will, beginning this fall, fingerprint six-year-old asylum seekers on first contact with the Schengen area. That fingerprint becomes the key to everything subsequent. It is difficult to imagine a compelled-decryption regime more frictionless than the one where the decryption key is a body part you cannot leave at home.


The notification database trick

On April 9, 2026, Federal Bureau of Investigation Special Agent Clark Wiethorn testified in the federal prosecution of Lynette Sharp and others for the July 4, 2025 Prairieland ICE Detention Facility attack in Alvarado, Texas. On the stand, Wiethorn described the forensic analysis his team had performed on an iPhone seized from one of the defendants. According to reporting from 9to5Mac, Wiethorn testified that his team was able to recover fragments of Signal messages from the device even after Signal had been uninstalled.

The mechanism is an iOS system component called the notification database. Every push notification iOS displays — including the lock-screen preview of a Signal message — gets logged into a persistent system database. The database is not part of the Signal sandbox. Uninstalling Signal does not touch it. Only incoming messages are recoverable; only the ones with lock-screen previews enabled; only the portion that actually appeared in the notification text. But the analytic power of the database for forensic purposes is considerable: it survives the deletion the user thinks cleaned the device, and it is readable by any Cellebrite-class tool with AFU access.

The notification-database testimony is a neat illustration of the deeper problem. You can encrypt the wire. You can encrypt the cloud backup. You can install a secure messenger whose server literally has no message content to produce. And then a system service on your own phone keeps a plaintext copy of the preview text for reasons that have nothing to do with security and everything to do with product design. The only defense is to turn off lock-screen previews for every sensitive app — a setting most users will never find.


The one operating system the extraction industry can't touch

The February 2025 Cellebrite matrix leak is not subtle. Almost every Android in the "supported" columns is extractable. Almost every iPhone up to iOS 17.3 is extractable. Everything from the Spring 2026 release is now extractable. And in the "no access" column, alongside a few specific Pixel BFU configurations, is the entire GrapheneOS family. The reason, explained by GrapheneOS itself, is layered hardening that attacks the exact bugs extraction tools rely on. A hardened memory allocator that closes heap-based exploit chains. USB peripheral restrictions while locked, blocking the UVC/audio/HID vectors used against Serbia. An auto-reboot timer that forces a device back to the Before-First-Unlock state after a configurable idle period — in BFU the decryption keys are not in RAM, and the full-disk encryption is intact.

The project released build 2026032000 on March 20, 2026 with experimental Pixel 10a support. Its estimated user base is roughly 400,000 devices, or about one in 25 Pixel users. At MWC 2026 in late February, GrapheneOS confirmed a partnership with Motorola Mobility — the first non-Pixel hardware in the project's history, with shipment expected Q4 2026 or early 2027. CalyxOS is on hiatus. The privacy-phone market, to the extent there is one, is consolidating.

The most elegant feature GrapheneOS ships is the Duress PIN. Set a second unlock code. When typed anywhere the system accepts authentication — the lock screen, a developer-options prompt, any per-app auth challenge — it silently triggers an irreversible factory reset that wipes all encryption keys plus the eSIM partition. No reboot required. Cannot be interrupted. Cannot be undone. Civil liberties lawyers believe, though no court has ruled, that a November 19, 2025 French case — Bilel — involved exactly this feature. The suspect's phone mysteriously reset itself while being imaged. Amnesty's technical team traced the reset pattern to GrapheneOS. The Duress PIN is the cleanest technical response to compelled-decryption laws in the world. It is also, under RIPA Section 49, Hong Kong's March 23 rules, France's 434-15-2, and every TOLA-equivalent statute, potentially a criminal act of obstruction.

Tails 7.6 shipped March 26, 2026 — the Debian 13/GNOME 48 branch of the Tor Project's amnesic live operating system. The flagship feature is automatic Tor bridge retrieval via the Moat API with domain fronting, so a censored network sees an ordinary HTTPS handshake to a popular CDN rather than an explicit bridge request. Qubes OS 4.3.0 shipped December 21, 2025 with Whonix 18, preloaded disposables for faster VM spin-up, and a new Devices API. VeraCrypt 1.26.18 (January 2025) continues to offer plausible-deniability hidden volumes — though no court in any jurisdiction has tested VeraCrypt PD under compelled-decryption pressure, and the best academic attacks do demonstrate that a hidden OS can be revealed as existing. None of these are consumer products. All of them are the working toolkit of anyone who has actually thought about what "the passcode is the warrant" means.


The memorized secret

Every compelled-decryption regime in the world — coercive and protective alike — has to answer a single philosophical question: does the state have the right to force a person to retrieve knowledge from their own mind and deliver it into the hands of an investigator? The German BGH in 2024 said no to passcodes and yes to fingerprints. The Pennsylvania, Utah, and Delhi courts said no to passcodes. The Hong Kong amendment says yes, provided a magistrate has first issued a warrant. France and the UK say yes without much ceremony. The Podchasov ruling says no in Europe, absolutely. And the Fifth Amendment in the United States says no, except in New Jersey, and only when the prosecutor is willing to litigate up a circuit that the US Supreme Court has refused to unify for six years.

What is left, inside all those answers, is the distinction Justice Stevens drew nearly forty years ago. A key exists in the physical world. A combination exists only in the mind. A fingerprint is a key; you can be compelled to surrender it. A passcode is a combination; the state would have to reach into your head to take it. Every biometric unlock is a quiet ratification of the biometric-as-key theory. Every passcode is a small rehearsal of the older argument that some things you know are protected speech until the moment you choose to say them.

In 2026, the answers to those questions are not abstract. They are operating parameters for airports, for drivers entering Canada, for researchers presenting at conferences in Hong Kong, for journalists landing at LAX, for doctors passing through Boston Logan, and for anyone who keeps, on their phone, the trace evidence of what they think and who they love and whom they work for. The Cellebrite matrix is a shopping list. The Hong Kong amendment is a working example. The Prairieland notification database is a reminder that the surface area is bigger than the app you uninstalled. The Fifth Amendment and its global analogues are the fragile membrane between you and a spreadsheet of your own memory.

There is a version of the next decade in which encryption as a technical matter is almost perfectly solved — Signal Secure Backups, Advanced Data Protection, post-quantum cipher migration, the entire 2025 vintage of secure-messaging improvements — and the compelled-decryption legal regime walks around all of it by treating the passcode in your head as a document you are obligated to produce. The only passcode that cannot be compelled is the one the state cannot find. The only device that cannot be imaged is the one that is properly encrypted and in the Before-First-Unlock state and running an operating system the extraction industry has not yet bought its way through and carried only to places where the law does not treat your silence as a crime.

That list used to be long. It is getting shorter.


Further reading

URnetwork is building the whole-internet encryption layer between you and the public network. ur.io.

Further Discussion

Your Fingerprint Is a Key. Your Passcode Is Speech. Stop Using the Key.

The single biggest mistake most people make in 2026 is assuming Face ID or Touch ID is the same level of privacy as a passcode. It isn't, and every major court that has touched the question has said so. Germany's Bundesgerichtshof ruled in April 2024 that police can forcibly press a suspect's finger onto a sensor, because the finger is a "natural key" — tolerating the measure is not self-incrimination. US courts that *protect* passcodes — Pennsylvania Supreme Court in *Davis*, Utah Supreme Court in *Valdez*, the Delhi High Court in *Sanket Modi* — all draw the line at the exact place Justice Stevens drew it in *Doe v. United States* in 1988: a key exists in the physical world, a combination exists only in the mind. A passcode is the contents of your mind. A fingerprint is a body part you can be compelled to extend. Biometrics are the loophole. The 2026 threat model is simple: if your device can be unlocked by any part of your body, someone at an airport with a warrant and a hand can unlock it for you. The defense is to turn off biometric unlock before you travel, memorize a long passphrase, set up GrapheneOS's Duress PIN as a secondary, and remember that under the Fifth Amendment and its international cousins, your knowledge — until you choose to speak it — is still protected speech. The most future-proof security primitive is the one stored where the state cannot reach: in a memorized phrase you never write down and never say out loud.

The Leaked Cellebrite Matrix Is Your Shopping List. Buy What's in the 'No Access' Column.

In February 2025, a Cellebrite sales rep accidentally shared their version 7.73.1 capability matrix during a Teams demo. A prospective customer saved it. The document is the only known disclosure of exactly which phones, operating systems, and states (Before First Unlock, After First Unlock, Unlocked) the extraction industry can crack. Almost every Android is in the "supported" column. A few specific Pixel configurations in BFU are not. iOS 17.3 and below are supported. iOS 17.4 through iOS 18 had been a hole — and on March 31, 2026, Cellebrite announced the Spring Release that closes it. iOS 26 and iPhone 17 can now be extracted by the same machine. There is exactly one row in the "no access" column that doesn't change between revisions: GrapheneOS on Pixels from late 2022 onward. Not because GrapheneOS is magic, but because it closed the specific bug classes Cellebrite's exploit chains depend on — hardened memory allocator, USB peripheral restrictions while locked, auto-reboot to the BFU state after idle. The same leak was corroborated by Amnesty's investigation of the Serbia case, which documented Cellebrite operators deploying a three-CVE zero-day USB chain (CVE-2024-53104, -53197, -50302) against a Samsung Galaxy A32. Six weeks later those CVEs were in the Android Security Bulletin — and a month after that, more than 40% of Android devices still hadn't been patched because of vendor update cycles. The gap between patch ship date and patch arrival date is Cellebrite's operating margin. If you want to opt out of being on the shopping list, the short version is: run an OS whose own adversary says they can't touch it, run it on hardware that wasn't bought by any of the 7,000 Cellebrite customers, keep the device in BFU as often as you can, and remember that the adversary publishes its own capability matrix for anyone who reads it.

Comics

#1Your Fingerprint Is a Key. Your Passcode Is Speech. Stop Using the Key.
#2The Leaked Cellebrite Matrix Is Your Shopping List. Buy What's in the 'No Access' Column.