6 ms·
Hi Peter, thanks for the AMA! I work for an American company and I am based in Europe. I visit the US for work every now and then. I heard a lot of horror stor
by miotintherain 10mo ago
Hi Peter, thanks for the AMA!
I work for an American company and I am based in Europe. I visit the US for work every now and then. I heard a lot of horror stories regarding border entries. If I am ever in a situation where the border police asks for access to my personal phone and pin code, what are my options? Can I refuse and what happens then?
- stevenwoo 10mo agoBorder Patrol can wait longer than you want to wait at the airport, you should not bring your personal phone if you don't want them going through all the contents, they can hold your device for an inconvenient amount of time if you are an American citizen. If you say no and are not an American citizen you can be denied entry at the airport and sent home.
- cmrdporcupine 10mo agoBeing quickly denied and sent home is the best possibility in that scenario. If you're on American soil they can just detain you. Or worse. If you ever want nightmares, read the story of Maher Arar.
- fsckboy 10mo ago>you should not bring your personal phone if you don't want them going through all the contents isn't the right move here: wipe your phone, travel to destination, then restore from cloud backup? in the middle, you can let them inspect your wiped phone.
- nerdsniper 10mo agoFor non-citizens, there's not really any law against them installing malware on your phone which could persist through a factory reset. Though I've not heard of such malware for flagship phones.
- lrvick 10mo agoI have heard of malware like this, and engineers that found it at Google were instructed by higher ups to ignore it and never talk about it without explanation. Good luck getting anyone close to this to go on the record about it though given such things normally come with corporate or government gag orders. There are hundreds of privileged vendor binary blobs on most flagship devices not even Google gets source code to though so supply chain attacks should be assumed.
- monerozcash 10mo agoI think this is broadly not true. Sure, the NSA can probably pull this off. Thing is, the NSA probably does not need to do this at immigration. I seriously doubt that this is a realistic problem if your threat model is anything less than "The NSA is very interested in me". In that case I don't see how you could trust any phone, regardless of it having been in the hands of border officials or not.
- lrvick 10mo ago> I don't see how you could trust any phone Correct, and I do not own one.
- mschild 10mo agoProbably more convinient to get a cheap, 2nd hand phone with the travel essentials and use that instead.
- lrvick 10mo agoOr just do not use a phone at all. I travel internationally without one a few times a year. Europe, mexico, canada, japan, no problems. Dirty looks, but no problems.
- lrvick 10mo agoIf you are of interest to the US government or any ally, assume your phone comes back from inspection with a compromised bootloader that will continuously re-infect your phone after you wipe/reinstall. Wipe it, let them inspect it, sell it, and buy a new one.
- eduction 10mo agoIs your name peter?
- monerozcash 10mo agoI think this EFF document probably provides a more comprehensive answer than what can be provided in a HN comment https://www.eff.org/files/2017/03/10/digital-privacy-border-2017-guide3.10.17.pdf https://www.eff.org/files/2017/03/10/digital-privacy-border-... Peter might have good insights on whether the relevant case law has changed since 2017 though.
- lcc 10mo agoThe only relevant part from that document is this line from page 33: "Foreign visitors have the fewest rights... if a foreign visitor refuses a border agent’s demand to unlock their digital device, provide the device password, or provide social media information, and the agent responds by denying entry, the foreign visitor may have little legal recourse."
- proberts 10mo agoYou are within your rights to say no but if you say no, almost certainly CBP will assume that you are hiding something and deny you admission.
- ToucanLoucan 10mo ago[flagged]
- flanked-evergl 10mo ago[flagged]
- wrs 10mo agoWho said anything about a “right to enter”? This is just about not massively invading visitors’ privacy for no good reason. Of course, if you just don’t want anyone with intelligence or dignity to visit the country, this is great policy.
- zahlman 10mo agoAs explained upthread, > You are within your rights to say no Given that you don't have a right to enter, if you say no (which you are within your rights to do), and you are denied entry, then nothing wrong has happened. If you believe that they shouldn't make entry conditional on something, then you are asserting a right to enter. That's what "right" means.
- tempfile 10mo agoThis argument is absurd. If someone comes up to me and asks for food, I am not obliged to give it to them. If I say to them, "I will give you food, on the condition that I can punch you in the face", and they decline to be punched in the face, do you really believe "nothing wrong has happened"? That I, applying an unethical condition, did nothing wrong? If someone else says "You must not make punching someone in the face a precondition of giving them food", does that create a "right to food"? Of course not.
- ripplebob 10mo agoWhy not just carry a burner phone or buy a blank one and restore it after customs from backup?
- trollbridge 10mo agoOne of the latest tricks is that if you have social media accounts yet no social media apps or accounts are loaded on your phone, or your phone appears to be a burner phone, they'll ask you why you didn't bring your main, primary phone. So your "burner phone" needs to be your primary phone, which is something that is hard to go back in time to fix.
- hn_acc1 10mo agoI have a few social accounts, but no apps installed on my primary, 2.5+ year old S21. I prefer to visit via browser (firefox, mostly).
- raddan 10mo agoThis sounds like a rumor to me. Plenty of people (including me) have no social media presence (unless you count HN as social media). How do you know that the person on whatevergram with the same name is me?
- trollbridge 10mo agoBecause the ad networks associated with social media are really good at ascertaining identity. People with no social media presence at all have been denied entry.
- raddan 10mo agoCitation?
- smcin 10mo agoIt's in general possible to only access social media via browser, not apps.
- christkv 10mo agoI always traveled with a feature phone and a travel laptop with just work stuff on it when going to the us. Nothing personal like email or other stuff on me.
- monerozcash 10mo agoThe typical solutions deployed by some European bigcos are: 1) only bring burner devices 2) have your devices travel separately using some courier service Yeah, they can still request your social media profiles and whatnot. You are not particularly likely to be denied entry because you don't have your normal devices with you, this is not very uncommon these days. Of course it's better to be able to say that your employer requires you to do this, so it's probably good to ask your boss to write up such a policy. Otherwise "why?" could be a pretty uncomfortable question.