14 ms·
Travelers just won back a bit of their privacy at the border
- epmaybe 9y agoHm. Lots of information is cached, like facebook messages. And Whatsapp is located on the phone itself. Honestly, it's still pretty bad no matter how you look at it.
- mozumder 9y agoSync to the cloud, then reset the device at the border, then restore from cloud after that.
- porlune 9y agoExcept now you've transferred your data over an international border and into a third parties infrastructure. If you're paranoid, that isn't more reassuring either. I suppose if you encrypt the files yourself before uploading, then your data are a bit safer.
- andrei_says_ 9y ago100+gb of data?
- bigbugbag 9y agoThe cloud ? Do you mean a third party owned server, probably one that is hosted on US soil and subject to patriot act, one over which you have no rights ? That's not how you protect sensitive data. Try crossing the border with a reset device and see by yourself if this makes you suspicious enough to get yourself in trouble (hint: it is)
- ironic_ali 9y agoCan they still feel the crotch of me, my wife and 3 year old though?
- throwanem 9y agoAre those cached locally, or only stored on a remote host?
- reallydattrue 9y agoLast I checked, a video of his wife in college "experimenting" was still up on PornHub.
- loeg 9y agoAnd how capable of distinguishing remote from local data do you suspect CBP are, given a phone's UI?
- epmaybe 9y agoWell they would in theory turn airplane mode on.
- draz 9y agoNot to sound facetious, but data on a "remote server" could be accessed through a (legal or non-legal) backdoor. So this amendment is little relief.
- SuperInEveryWay 9y agoNefarious types can leave their phone at home or ditch it before crossing a border. And just buy a new phone after crossing a border to connect to their existing phone plan account. It's easy for these persons to bypass security checkpoints and still connect with their regular contacts abroad. Ultimately it's just another useless "security" measure.
- xyzxyz998 9y agoAnd I can't even delete my profile/old comments on "Hacker news".
- jliptzin 9y ago1. Backup phone 2. Encrypt backup 3. Upload encrypted backup to cloud server 4. Delete backup 5. Wipe phone back to factory settings 6. Cross border 7. Download backup from cloud 8. Decrypt backup 9. Restore phone This is the only sane thing to do besides not crossing the border with an electronic device at all.
- loceng 9y agoAny software that does this all for you?
- ohthehugemanate 9y agoAndroid/Google does this extremely well. I've recently had to do a few factory resets trying to fix a hardware issue on my phone. Just turn on Google's backup service for apps and settings, let it finish syncing, and then factory reset. When you login to the fresh phone, it offers you that backup in the startup wizard. If you're on a good connection, restoring the backup is surprisingly fast.
- khedoros1 9y agoAlthough, I think that you can potentially lose a bunch of stuff, depending on how you use your phone. Like any app sideloaded or installed through another app store, the extra data chunks that lots of games download, data created by apps (subject to developer settings), loose files being stored on the phone, etc. I know that when I switched phones last year, there were a lot of manual steps moving between devices (the HTC transfer mechanism worked for most of that, but I still ended up moving some files manually).
- tedajax 9y agoDoes this effect 2FA auth at all? Will I need to remove all existing authenticators to accounts and then reenable after the factory reset?
- askvictor 9y ago
- aluhut 9y agoIt's not that long ago when downloading SMS etc. was worth an outrage. I hope it's not only time between us and the server access.
- jjbiotech 9y agoPhone applications and their data are so abstracted these days, it would be difficult for even an IT expert to differentiate between cloud and local data if search takes place using the device itself (which I assume is what happens). If they connect the phone via USB and browse the contents with a workstation, that might be a different story. So in practice, nothing has changed.
- lb1lf 9y agoJust put the phone in flight mode. Wireless interfaces are deactivated, and any attempt at accessing online material is greeted with a message stating that you're offline.
- fuzzybeard 9y agoSome apps won't let you access any of your content without authenticating with their servers. So even if it's local content, not having an internet connection would deny access. I can envision CBP saying they need to crack your phone to get to the local stuff.
- pavel_lishin 9y agoAnd watch the border patrol agent to make sure he doesn't turn it back off?
- riffic 9y agoRequire all searches to be performed in a faraday cage? A better solution would be to disallow all searches of electronic devices since this seems unnecessarily intrusive.
- droithomme 9y agoThe "freedom won" described in the article is not significant. It clarifies that border searches won't routinely include using your local credentials to log into your facebook or other social media accounts whose data is not stored on the phone other than log in credentials. Yet one is still expected to provide log in credentials to the phone during border crossings. This still means that the only reasonable and sane process is to factory reset a phone or not carry one at all.
- deleted 9y ago[deleted]
- sbov 9y agoI don't see anything travelers won back. The letter is saying CBP policy doesn't allow these things, when obviously agents have been doing them. It may be against policy, but unless you reprimand or fire people over it your policy is useless. The letter is just ass covering and the title is terribly misleading.
- 4bpp 9y agoThis seems to be a general issue with any sort of attempt to impose restrictions on police-like agencies these days - between the boundlessly sympathetic legal system, the political power of police unions and an institutional culture that distributes responsibility between superiors and "boots on the ground" in a maximally deniable way, in practice the only way to get them to abide by a rule is to get them to believe themselves that to do so is for the better.
- riffic 9y agoThis is exactly why I donate to the EFF. I urge anyone else to do so as well: https://www.eff.org/helpout https://www.eff.org/helpout
- ganoushoreilly 9y agoIt also doesn't address that many of those apps have local caches of data that would fall under the rules.
- codezero 9y agoAre they required at all to produce a list of what they are looking for, like the police must do when serving a search warrant? If not, what guarantees do people have that they won't hold/prosecute you for anything unlawful they find?
- kleiba 9y agoI couldn't care less about cell phones as long as I still have to provide my finger prints.
- eridius 9y agoSounds like 1Password's new Travel Mode (https://support.1password.com/travel-mode/ https://support.1password.com/travel-mode/) is actually going to be effective.
- pavel_lishin 9y agoUnless they install Faraday cages at airports, I don't see how this practically changes things for travelers. Do I turn on "airplane mode", and make the border patrol agent super-duper pinky swear that he won't toggle it back off?