3 ms·
As an iPhone 3G user who spends a lot of time bouncing between countries, this makes me think I should upgrade to something more recent the next time I'm headed
by throwaway7312 10y ago
As an iPhone 3G user who spends a lot of time bouncing between countries, this makes me think I should upgrade to something more recent the next time I'm headed anywhere there's a risk customs may inspect my devices.
- praseodym 10y agoThere haven't been any security updates for the iPhone 3G since 2011, so I'd worry about other types of attacks (web malware) as well.
- nkristoffersen 10y agoyes, time for an updated model. backup and wipe your phone before you travel. there are several stories now of customs compelling you to unlock the phone before allowing you to leave. https://www.theatlantic.com/technology/archive/2017/02/a-nasa-engineer-is-required-to-unlock-his-phone-at-the-border/516489/ https://www.theatlantic.com/technology/archive/2017/02/a-nas...
- mastax 10y agoWill that help? There have been many stories (some posted on HN) of customs saying "unlock your phone or be detained indefinitely".
- daenney 10y agoUnless you have to, leave your fancy device at home and bring a dumb(er) travel phone with you that only contains the information you need for that trip. And there's nothing stopping you from loading more information on it after you've made it through customs.
- schoen 10y agoHave you heard "indefinitely" anywhere? I helped write both versions of the EFF border search guide and I don't think I've ever heard of "indefinitely", either as a threat or a reality.
- jandrese 10y agoI'm more impressed that your battery life hasn't gone to shit by this point.
- geofft 10y agoCustoms is a different threat model: they have the ability to say "Please unlock your phone and show us what's on it." You can refuse, although that might get your device confiscated or your trip delayed or cancelled. The CIA's threat model in the leaked documents involve silent software exploits. There's no involvement with the human owner of the device. It's very important to understand the silent-exploit threat model! That's the model used when someone is being investigated as a terrorist (or freedom fighter) and the government doesn't want to make them aware they're being surveilled, because they might change their plans. In particular, the 3G is going to be highly vulnerable to silent exploits because of the lack of software updates, but that's not your concern at the border. Your concern is the lack of Secure Enclave on the 3G. That means that if they take your phone from you, they can image the contents of it fairly easily, without needing a fingerprint or passcode from you. If you get a newer phone, enable encryption, and use a strong passcode instead of a fingerprint, you can reboot the phone before a border crossing, and then the data is strongly protected unless you choose to give up your passcode. For the customs threat model, you might also want to bring a different phone with limited data when traveling. It might make sense to have a powered-off phone with a Secure Element somewhere separate from you (e.g., shipped via post), and just use the 3G for contacting folks while in transit, wiping all interesting data from it. In theory, this means your secure phone could get confiscated but you can't be compelled to unlock it (since you're not physically with it). I'm curious if other folks on this forum think this is a reasonable plan. ... Also, the easy vulnerability to silent exploits is probably a huge threat for you for non-government attackers, which are a much more common attack.