11 ms·
I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't
by schoen 2mo ago
I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully).
The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that.
The end result (not inherently different from what we wrote in the guide) is that you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to. I was fascinated by techniques for being unable to comply (which is straightforward to achieve if you want!) but probably didn't think enough about how much this might antagonize border agents in many cases.
I definitely don't know a comprehensive big-picture solution.
- itake 2mo agocan you share the link? This? https://www.eff.org/document/eff-border-search-pocket-guide https://www.eff.org/document/eff-border-search-pocket-guide ---- Seems the better strategy (for iOS) is come in with a plan to say yes to agents without pissing them off (like handing them an empty phone). better to local back up, encrypt, upload to your home server etc. Then login to a fresh iCloud account, selectively install apps, photos, and mail accounts. So it doesn't look like you're walking in suspicious.
- invalidusernam3 2mo agoThis seems like an insane thing to have to do for visiting a supposed first world country. If phones had been around during USSR times I imagine you would have had to do the same. Personally I will rather just avoid any travel to the US, and I hope others do the same.
- mcv 2mo agoSecurity concerns you need to think about when visiting the US are absolutely no less than those when visiting China these days. Treat it like a totalitarian dictatorship with more technological means.
- frgturpwd 2mo agoHonestly, I personally would be less nervous visiting China.
- VBprogrammer 2mo agoThis has become a running joke with a couple of the people in my office who have recently visited China (from the UK). The next 2 years will be interesting for democracy as a whole.
- expedition32 2mo agoChina actually wants people to visit them and spend money. And although I don't agree with the CCP ideology the Shanghai subway is ridiculously impressive.
- inigyou 2mo agoRemember most of the Chinese train infrastructure was built in the time since the Hyperloop.
- Ferret7446 2mo agoChinese train infrastructure also had a lot more casualties than any modern Western nation, even with a conservative estimate of the covered up ones. Building fast is a lot easier if you can break some eggs.
- don_esteban 2mo agoYou mean casualties among workers building it? Or casualties among the passengers traveling on it?
- frgturpwd 2mo agoI wouldn't say you are overreacting at all. I know someone who was detained for months on US soil after a phone search where the only "evidence" against him they found is illegal content sent by someone else to him on a group chat he doesn't even check. Had to get a lawyer and spend time in prison just waiting to be deported back.
- oceanhaiyang 2mo agoWhat is illegal content in this context?
- rolisz 2mo agoJokes about Supreme Leader Trump? (I'm not the person you replied to, I have no idea)
- philipallstar 2mo agoJokes about Trump are rife in America, as are leader jokes in many Western countries. These are the last places you will need to worry about that.
- syockit 2mo agoIsn't Germany an exception to that?
- philipallstar 2mo agoI don't know. Can you not make jokes about the chancellor in Germany?
- defrost 2mo agoSure .. just not jokes about how tall they are with a punchline that involves raising an arm to demonstrate.
- zombot 2mo ago> for visiting a supposed first world country. ... which by now is a banana republic of the worst kind. Can you interact sanely with an insane counterpart? Avoiding to visit would be my recommendation too.
- itake 2mo agoJust out of curiosity, like what country would you not have to worry about this in? The US is quite transparent about these rules, and certainly other countries are not necessarily searching peoples phones as publicly But anytime I transit a country USA or any thing I fully expect to have zero rights
- adrianN 2mo agoEuropean citizens can travel in the EU without even noticing that they are crossing borders most of the time. I once got lost on my bike and accidentally ended up in France for example.
- InsideOutSanta 2mo agoI drove a friend to an airport in Switzerland, got lost on my way home, and accidentally visited both France and Germany.
- vintermann 2mo agoAnd if you're unpopular enough, they can also abuse arrest warrants for political persecution from another country. Case in point, captain Tommy Olsen from Norway, who Greek authorities accused of "human trafficking" for helping boat refugees. They've deliberately made it very easy to request arrests across borders, so it isn't all rosy. One of the reasons it really sucks for everyone when an EU country starts slipping towards fascism.
- spiderfarmer 2mo agoSchengen, Nordics, Japan, Canada, in that order. Trump’s America: when confronted with negative traits of your country, always assume your country is the lesser of all evils.
- inigyou 2mo agoAustralia has stricter screening for fruit than for people. don't bring anything organic to Australia unless it's been commercially processed, and even then show it to the border officers so they can make the call. You don't get penalized for showing them something not allowed, you just can't bring it into the country, and they throw it in the bin for incineration. Penalties start when you try to sneak something in anyway.
- InsideOutSanta 2mo agoI used to love visiting the US. I have many friends there, and I really enjoy staying in places like Seattle and SF. But I haven't gone there since Trump 1. That said, I think protecting your privacy is a good idea in general.
- inigyou 2mo agoThe US is first world on a technicality: the first world is defined as countries that were allied with the US during the cold war. If not for that, it'd be classified as developing. It's common to mix up developing/developed and third/first world because they were largely aligned during the cold war. But there is one first-world developing country.
- bigDinosaur 2mo agoThe biggest economy in the world and the richest country to have ever existed is not a developing country, although it is quite unequal. What you've stated is political rhetoric that you want others to accept as fact.
- inigyou 2mo agoMany developing countries have extreme inequality. What would it look like if the whole world's reserve currency accidentally ended up being the South African Rand?
- prepend 2mo agoWhy do yo think the US should be classified as a developing nation? There’s a definition independent from 1st/2nd/3rd world [0] and the US’ income seems to clearly make it developed. [0] https://en.wikipedia.org/wiki/Developing_country https://en.wikipedia.org/wiki/Developing_country
- inigyou 2mo agoWho made them the law? I don't trust the OSI to define open-source, either.
- toyg 2mo agoThis is not true. However, because of the massive inequality, I often found it easy to use a sentence I saw somewhere: "the US is a South American country that happened to become successful".
- buellerbueller 2mo ago
- bambax 2mo agoYes, I will probably never go back to the US. But I find it sad that my kids for example, will have to think twice before visiting, if they do.
- ChoGGi 2mo agoMy dad's eighty+ years old, he was born in the States, though he did give up his citizenship. He brings a "fake" phone when visiting family, he's been doing so for years. Me; I just change all my tabs and recent history to slightly kinky porn and truth social. They do look hard, but they don't look hard.
- realo 2mo agoThe older guys cannot look too hard but the young guys can certainly look quite hard while browsing through your kinky porn. (Laughs expected here)
- bryanrasmussen 2mo agowho believes an empty phone?
- hamper653 2mo agoWhat do you mean?
- dmantis 2mo agoThe point is not what they believe, but how to avoid both breaking the law and not giving up your data, isn't it? As long as that's legal, what they believe doesn't matter. You are not legally obliged to keep your data on your devices all the time.
- abirch 2mo agoYou're right for non-citizens. For citizens, no one needs to believe it. You give them your empty phone and they can't download your phone contents and contacts.
- buellerbueller 2mo agoGenerally, within 100 miles of a border (which includes international airports) there is not a warrant required for a search.
- tmp10423288442 2mo agoYou need it to look set up enough to do critical communication / tourist activities. It should look like you had to reinstall your OS right before your trip, and only had time to get the basics on there. Most people will prioritize communications, maps, and payments over anything else, with video/music/books/podcasts following that, and signing into the vast universe of social apps later if ever.
- sofixa 2mo agoXiaomi phones have/had a feature where depending on which finger you unlock the phone with, it can hide certain applications/folders on the filesystem.
- Cider9986 2mo agoNot possible to be robust unfortunately due to low level SSD architecture[1] and other reasons: https://nitter.net/GrapheneOS/status/2082153517234676150#m https://nitter.net/GrapheneOS/status/2082153517234676150#m [1] https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Wear-Leveling.html https://veracrypt.io/en/Wear-Leveling.html
- Noaidi 2mo agoI guess you could just bring a flip phone. But then that could be seen as suspicious these days. When a government is paranoid, everything is suspicious. Maybe just don't do anything on your phone but normal capitalist business sht.
- mattm 2mo agoHere's the full version https://www.eff.org/wp/digital-privacy-us-border-2017 https://www.eff.org/wp/digital-privacy-us-border-2017 One of the names in the byline matches his HN username so it's likely this.
- IshKebab 2mo agoSo I guess what you really want is a duress PIN that loads into a fake innocent profile.
- Sammi 2mo agoOr that just selectively wipes only stuff you have marked for deletion. That way the profile stays up to date and believable.
- ozim 2mo agoProblem is „are you sure you marked for deletion all the correct things” because you could have already deleted it before traveling or moved to other device you don’t travel with. Selection on border control might be arbitrary, they can hold you or send you back over a photo or something you wouldn’t think should be a problem. Ideally you would like to have all wiped just in case but then you really stand out…
- eru 2mo agoThat's why you do it the other way round: you mark things that you don't want deleted.
- ozim 2mo agoThat is not really making any difference if you can prepare beforehand and you can’t be sure which things can get you in trouble.
- eru 2mo agoIt does make a difference: you only mark enough to be kept to make your phone looks like it's in use, as opposed to obviously wiped. By default, new material will be deleted. So you don't have to prepare again and again. > you can’t be sure which things can get you in trouble. When in doubt, don't mark it as keep.
- 2mo ago
- realusername 2mo ago> The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that. That's the reason I never traveled to the US and never will, just having IT security in your CV is enough to make the border gamble not worth it
- rustyhancock 2mo agoIt's also quite surprising that all socials need to be declared. And presumably them AI vetted in time for you to get to the border.
- schoen 2mo agoThis part is pretty new. I wonder if my former colleagues have done any FOIA work looking into how travelers' disclosed social media accounts have been reviewed or analyzed!
- epolanski 2mo agoYou also have to provide every single email account you have used in the last ten years, all of them, forgetting to declare one is an offense. There's no chances I can remember them all, especially as I've been contracting and get a new email every 3-4 months or so.
- salad-tycoon 2mo agoOr like me, I use disposable emails via simplelogin (?) and iCloud hide my email. I have hundreds. “Roflz” but I’m a citizen so guess I’m okay?
- everfrustrated 2mo agoIt's reasonable for a country to want to know if you're likely to abuse your visa. Eg your socials might show you are a professional paid speaker at conferences. If you applied for a tourist visa that would be reasonable to flag you and ask you if you have paid gigs on the wrong visa. Europe will also ask the same questions for foreigners. If you're a young woman travelling on your own you can expect questions to challenge if you might be earning money as a nanny on a visitor visa. Checking their phone messages to see if they've been making arrangements to this effect is a very straightforward way to determine intent. Not everything is an evil conspiracy.
- matwood 2mo ago> I think they should not have this power, but the agents and courts probably don't care that I think that. ... > and about not angering the agents more than you plan to When I was a teenager (long ago at this point), I got into an argument with a police officer over surfing in a certain area. It was pouring down rain, so he was annoyed he had to sit outside and wait for my friends and me to come to shore. Once we got in, he was telling me that he could take my surfboard and my car, and all other craziness. Being the dumb smart-ass I was at the time, I laughed and told him he was full of shit, among other things. He went to take a swing at me but his partner grabbed him. We all go to court and the judge immediately dismisses the case against all my friends. I had a lawyer with me that I knew and he went to talk to the cop and when he came back over he goes "I don't know what you did, but that cop hates you." I get up in front the judge and he praises me for understanding the law (and I could still see the cop was visibly pissed), but then says he can't have me disrespecting and being a smart-ass to his cops and gave me community service that once completed whatever the ticket was would go away.
- einpoklum 2mo agoToo bad you could not bring that judge up on charges of judicial misconduct - if he indeed told you that the charge against you had no merit, but decided to punish you anyway because he did not approve of your demeanor. ... or otherwise, that people in your community could not apply any counter-pressure to such judicial behavior, in the media and public fora.
- dijit 2mo agoat some point you just take your lumps. Most people don’t have boundless time or energy and just want things to go away. … ironically this fact is used a lot in gaining confessions by police.
- matwood 2mo agoTo be fair to the judge we all had broken an ordinance about surfing in a certain area. It was enacted to protect swimmers in the summer. With that said, there was a storm with wind, rain, and currents that had pushed us into the area. Obviously there were also no swimmers out. The ordinance was removed a few years later. This cop was also known to hate surfers. All the small beach town BS you hear about.
- jonathanstrange 2mo agoJust don't travel to the US.
- schoen 2mo agoI live in the U.S. (as, I think, does the person who is the subject of this article).
- brettermeier 2mo agoMaybe change your location then :P
- eru 2mo agoThe US have things like exit taxes etc which make it a pain to leave.
- _moof 2mo agoTurns out immigration in other countries isn't a cakewalk either.
- brettermeier 2mo agoYeah that is true, sadly... I was a little too provocative without acknowledging the complexity behind it.
- deleted 2mo ago[deleted]
- wvh 2mo agoThis. If any country won't treat you like a guest, avoid travelling to it. If it's your own, that's harder to do – time to fight and change the system before it gets worse and will swallow you whole.
- TheOtherHobbes 2mo agoThis is an increasingly popular solution. Foreign tourism has crashed. I love the geography of the US, and it has some truly stunning places to visit. But they're not so stunning that I need to risk my freedom - risk my freedom - to visit them in person.
- atoav 2mo agoMy friends from the German CCC are mostly like (1) do not travel to the US and (2) if you absolutely must, travel with an empty device with decoy data and download all data you need once you're there.
- hn_submit 2mo agoWhat about simply not using a smartphone and accessing your data via internet when you're in the country? You could use Mega (secure file storage) to access your files, for example. I wonder if border agents could coerce you into giving access to your internet file storage, though.
- Gareth321 2mo agoI believe they can. I believe they can even request your social media credentials, despite that being against the ToS for those sites. It's not against the law to refuse, but they can and will reject entry on that basis.
- eru 2mo agoThat's interesting. I don't even know most of my passwords (thanks to password managers).
- Gareth321 2mo agoDon't worry, they can ask for that password too :D
- eru 2mo agoYes, but that one has 2FA, and I might not travel with that second factor on me. Of course, they won't be amused.
- TeMPOraL 2mo agoIn other words, 2FA might actively put you in danger. Something to consider before travel and perhaps temporarily lowering your digital security to preserve your physical one.
- elephanlemon 2mo agoAFAIK in the US their policies do not allow them to access your cloud stored data.
- jpfromlondon 2mo agoI don't carry a smartphone, is this likely to be a red flag if I'm stopped?
- majke 2mo agoMany countries now assume you have a phone. For example getting UK visa requires a smartphone. I don't think going without a phone is feasible nowadays. Another question is if going with a burner phone that has just sim card and bank card, sufficient. But then you need appleid/google account on the device, and this again links back to your phone number, and it's not easy in practice to have proper clean device.
- epolanski 2mo agoThis is one of the reasons I also won't ever go to the US again. While most of my Italian/Polish friends had 0 issues, on a handful of occasions people were stopped and questioned for hours with agents pretending full access to every single device and just overall treating you as criminals. In one occasion a friend of mine stated that he was quite sure they just enjoyed that kind of sweeping power and it had nothing to do with border security, it was just fun to them. In another one, the suspicion was on the fact that this person did not have socials, he just disliked them and had nothing except a Google account for Youtube. This fact made them super suspicious and the person was stuck at La Guardia for 3 hours, even his body was inspected. Disgusting.
- lentil_soup 2mo ago> you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to That's the same problem with technical solutions to crime. I come from a very dangerous city and I used to have a car that needed a PIN to work. You could turn then engine on and drive but after a minute if you didn't input the PIN it would turn off without warning and start blasting the alarm. The idea being that if the car was stolen the thief would be stranded not far from home unsure about what's happening. Great technical solution but it ignores that a lot of the time the car is stolen with you in it (in a kidnapping, for example). Having the car shutoff in the middle of a highway next to a panicking guy with a gun and trying to remember a PIN is not a situation you want to be in, so I just had the PIN number written down on the dashboard, which worked very well when I was eventually kidnapped and just pointed at the piece of paper with the number.
- eru 2mo agoWhy are you staying in this place? (Is this in South Africa?)
- Hendrikto 2mo agoBrazil maybe?
- hammock 2mo agoIceland I think
- ChoGGi 2mo agoWashington most likely
- ryan_j_naughton 2mo agoI live in Washington DC, and even though carjacking is a problem here, not to a degree that people plan on it happening to them. I would be surprised if OP's situation took place in DC.
- antihero 2mo agoI wonder if the smarter thing to do would be to quietly nuke it as soon as it becomes clear that you'll be detained, so they can't really know that it wasn't already blank (IE you aren't nuking it in their presence).
- saalweachter 2mo agoThe smarter thing to do is to just wipe your phone of everything you don't want border patrol to see before going to an airport.
- InsideOutSanta 2mo agoWith self-hosting, it's possible to easily bootstrap a clean phone with all your data and passwords from scratch, without relying on any third-party cloud services. The only thing you need to bring across the border is your brain (which contains the most basic information on how to set up your password manager) and maybe some kind of 2FA generator. Your password manager then contains all the other information you need to get everything running. I don't think it ever makes sense to transport actual data across borders if you care about governments gaining access to it.
- Zak 2mo agoPossible, yes. Easy, not so much. Phone operating systems don't really place nice with local backup and restore, which I consider a serious flaw.
- InsideOutSanta 2mo agoI'm not sure what you're referring to, but what I basically do is self-host everything that stores relevant data: Vaultwarden, Immich, Notesnook, etc. I only know how to set up Bitwarden and my 2FA generator from scratch, so when I get a new phone, I install Bitwarden and the 2FA app and set them up. Then everything else is documented inside Bitwarden. It's just a matter of installing the apps and logging in using the credentials stored in Bitwarden and a 2FA token generator. There's no need for relying on any phone OS features.
- surgical_fire 2mo agoMaybe the actual solution is traveling with burner devices when you are concerned with border checks? Like, get a cheap phone, install the bare minimum stuff you need for travel. For extra safety, before returning home wipe it and just put back the exact apps you need for moving around (e.g.: ride hailing app). Same thing with laptops, tablets, etc.
- raxxorraxor 2mo agoWe probably need honey pod fake OS systems that boots up if not properly handled displaying some stars & stripes as background image and having the US national anthem playing for any sound the OS is trying to play.
- vintermann 2mo agoThis would unironically probably work pretty well. The bullies in airports don't have that much time to investigate a phone which "looks good".
- thewebguyd 2mo agoRight, these goons are hand searching through phones specifically to find something, anything, they can use to make your life suck and detain you further. A pin that boots into a dummy account, full of benign messages, photos, innocent web browsing, etc. is going to get you a pass. They'll flip through everything and get bored after a minute of not finding anything. Far less likely to aggravate them than wiping your phone
- Cider9986 2mo agoThey would learn about it and it would be standard practice when they see pixels. It's not possible unfortunately due to low level SSD architecture[1] and other reasons: https://nitter.net/GrapheneOS/status/2082153517234676150#m https://nitter.net/GrapheneOS/status/2082153517234676150#m [1] https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Wear-Leveling.html https://veracrypt.io/en/Wear-Leveling.html
- wffurr 2mo agoDon't forget to have the Official Social Media of the President of the United States(tm) installed, with an account following the correct list of truthtellers and rightthinkers.
- Lio 2mo agoI would prefer to backup and wipe my phone before travelling. Then have some planned means of restoring the backup when it's safe to do so. Being caught with a honeypot looks much worse than being caught with a new phone. You can always say you bought a cheap "travel" phone if asked.
- Havoc 2mo agoSo burner phone for US visits I guess
- TacticalCoder 2mo ago> ... you may have to think both about protecting your data by technical means, ... I thought about that. And I came to the conclusion that a phone is a pathetically bad device to both store your data and to access your data. Mediocre screen. Mediocre input methods. Moreover most phones happen to also be spying device. So if you think about "protecting your data", a reasonable idea is that a lot of data is way better kept on your homelab, with say encrypted backups in a safe at the bank, at a relative's place, on a server you rent, etc., rather than on your phone. And there's really little need to access your data from your phone. Oh and I'm no luddite: I've got a homelab, I rent servers, I pay three AI subscriptions, etc. But my phone is boring. There's no app on it besides the stock ones (say Google Maps) and then I added the Google Authenticator app (for stuff still using that kind of 2FA). If people were to wake up and stop being glued to that mediocre thing, the problem would already be 99% solved.
- Cider9986 2mo agoTotally wrong. Phones are much more secure at data storage than desktops. Agreed off-site is way better for duress though.
- Waterluvian 2mo agoYeah, you really can’t outsmart those with physical power and authority over you. Americans have asked for, or tacitly accepted this treatment of their visitors. The only big-picture solution is to stop visiting.
- baggachipz 2mo ago> Americans have asked for, or tacitly accepted this treatment of their visitors. Our citizens as well!
- buellerbueller 2mo ago>[Some] Americans have asked for, or tacitly accepted this treatment of their visitors. You forgot a word.
- Waterluvian 2mo agoI hope to meet one some day.
- buellerbueller 2mo agoUnlikely, because of your priors; you already think we are odious so it isn't like you are looking for the best in (or of) us, and second why would they want to meet you if you assume the worst of them? I don't support this Administration's behavior, but I'd rather meet an American who did and have a discussion with them about it than try to convince some dude who already decided I was an asshole, based on the country I'm from.
- rc5150 2mo ago[flagged]
- buellerbueller 2mo ago>If one's beliefs align with those who wish to strip civil rights from citizens who are different than one's own, then one is an asshole and doesn't deserve the time of day. Who are you talking about here? This isn't even half of voting Americans, who probably represent about 20-25% of the American population. Your argument is analogous to saying that all men are rapists, because many men have committed an act of sexual harassment. It's so shockingly Manichean that it wouldn't pass a middle-school composition assigment.
- Mezzie 2mo agoI'm sharing this experience just to share, not suggesting or making any claims about what people should do with it: One of the best ways to get through airport CBP quickly without being overly hassled is to be overtly, clearly sick in a gross way. If you're about to vomit or have horrible diarrhea, they do not want you in that line any longer than you have to be. If they're the type to want to take people down a peg, they won't bother with you because they're already miserable, and if they like picking on the weak, they're probably going to go for a solo young female traveler who isn't ill. Nobody wants to risk getting vomit on their clothes or in their work area, having to close a line and shuffle people around while their coworkers glare daggers, or subject themselves or their coworkers to the very fun smells of human bodily fluids. At the same time, it isn't purposeful so it's not read as malicious.
- 15155 2mo agoSounds like you swallowed balloons containing drugs and one of them burst. You might need some additional screening or to have a seat on the Drugloo to make sure everything comes out OK.
- rng-concern 2mo agoI don't own a cell phone, haven't for years. I fear this alone would be enough to arouse suspicion and I'll be denied access. Not an immediate problem for my family: as a Canadian I have no plans to visit the states for a long time. However, I could see this being suspicious in other countries as well..
- mattlondon 2mo agoI think in these situations your absolute best bet is fawning compliance. Ask precisely how high they want you to jump. Perhaps your friendly smiling Yes-Sir-No-Sir-3-bags-Full-Sir act might just be enough to let you get on your way without anything else happening apart from a stamp in your passport. Even the slightest hint of defiance or surliness from you to a border guard/policeman/etc - potentially at the end of a long shift, tired, angry, pissed-off or whatever - and you're straight away hugely more likely to have a bad day. Finding strategies to "beat the system" will, I think, just be a shortcut to some other punishment/crime/taken-out-of-sight-and-given-a-proper-kicking-oh-they-resisted-and-went-for-my-gun/etc as this person found out the hard way by trying to be difficult. I genuinely don't think there is a "get out of jail free card" or magic incantation you can say to get out of these situations apart from just smiling and being polite and not being a dick - if you get into a "who can be more annoying" competition, then the border guards/police will always win since they hold all the cards and will happily ruin your day/holiday/meetings etc by detaining you (its their job to do this after all) There have been cases very recently in the US where the authority figures down dealing with the public are evidently in a very defensive, aggressive "us-vs-them" mindset, with an itchy trigger-finger to go with it. Don't be the person on the receiving end of a cop seeing-red because you're being a jerk. The house always wins.
- piltdownman 2mo ago"If you want a picture of the future, imagine a boot stamping on a human face - for ever"
- voakbasda 2mo agoI will ask this here again: At what point did the German people find it morally acceptable to start killing Nazis? At what point will the US stop accepting the boot and act to remove the tyranny stamping on our collective face?
- profunctor 2mo agoDid they ever?
- asdfasgasdgasdg 2mo agoThere’s more to it than just not antagonizing the guards. I mean if you make them mad by doing something that is legal that’s probably not ideal for you practically speaking, but it’s not the end of the world. Destroying evidence while they are investigating you is not just going to make them mad though. It is illegal (18 USC section 1519). Where I think people are a little confused here is not realizing that this would be equally illegal in many other countries. At least in the UK and France, border investigators also have the power to demand your PIN. And it is also illegal to wipe your phone during an investigation in those countries.
- account42 2mo agoYes but the parties running those countries are currently more ideologically aligned with the people that rally against the US in these cases so they don't think it affects them and thus is not a problem, forgetting that those laws will still be around if the political climate changes.
- hliyan 2mo agoI worry that at some point, the physical device won't matter. Border authorities will know your email address, and could force you to log into your account on a device they supply. Five years ago, I would have called anyone even bringing up this possibility paranoid, but a lot of things that were completely unimaginable outside of Hollywood political thrillers have already happened.
- Alive-in-2025 2mo agoAnd then there's the problem that you can't just log in with name and password to your email address. You need your special "authy" style number generator, or a software version on the phone. They know you probably have it on the phone. but what if you bring your other phone that doesn't have it on there - you removed the software before you left so no one could even log in. All these fancy tricks don't work because the doofus/poor soul at the border doesn't understand the nuances and they don't know if you are lying or not. Even if you wipe your phone and restore it once in the safe usa, that's no doubt suspicion of a crime.
- throwawayffffas 2mo agoThere are 2 cases routine inspections and targeted investigations. If it's a routine inspection, being uncooperative will probably lead them to escalate. You generally want to keep things routine and boring. If they want to access your device you have to weigh the costs, just log out of everything before you fly and throw away your device after they have had access to it, it's now compromised. If you are targeted your compliance is irrelevant and only weakens your position, the thing is at the border you don't get all of the protections you get at say a traffic stop they can search everything you have on you without warrants reasonable suspicion or anything. I am not a lawyer but if you are a citizen they probably can't deny you entry but can probably detain you for an uncomfortable amount of time, and seize whatever they want. Your best defense is to have a burner phone and no other devices nothing they can seize that would hurt you. For foreign nationals pretty much the same applies except they can deny you entry and ship you off to alligator Alcatraz, just don't fly to America for a few years. Remember he is not being prosecuted for not handing over his device but for destroying the data they were trying to seize, if he just let them keep the phone he would be Scott free. I.e.the best technical defense is secure encryption with a key thats long enough and not stored on the device. Actually for the particular case the best technical defense is to not have any data whatsoever on you.
- cortesoft 2mo ago> just log out of everything before you fly and throw away your device after they have had access to it, it's now compromised. I get what you are saying, but this is incredibly expensive and not really practical for most people.
- fn-mote 2mo ago> not really practical for most people Evaluate your threat model and the chance that a wipe and reinstall of the OS will be insufficient protection. If you were targeted, you may have some tough choices. Might as well think about them ahead of time.
- tmp10423288442 2mo ago> I am not a lawyer but if you are a citizen they probably can't deny you entry but can probably detain you for an uncomfortable amount of time, and seize whatever they want. Your best defense is to have a burner phone and no other devices nothing they can seize that would hurt you. Even having a burner phone without any personal information on it can be deemed suspicious. It would be best for your phone to have a recently-reinstalled OS, with a few critical apps like Whatsapp or iMessage set up with a few personal messages sent. You need to be able to set those up without a password manager. Anything else needs to take place on devices that you aren't carrying with you. Fortunately enough people don't update their Facebook these days that just having an account that exists but you don't use will probably work, assuming you don't look like someone that would be obsessed with their socials. Maybe there are USB thumb drives that operate like a YubiKey unless special setup is performed to access the storage inside? That's one way to carry data with you if you have to.
- kridsdale1 2mo agoWhy not have a passcode that boots in to a second “safe for cops to look at” partition?
- inigyou 2mo agoThat partition will always be obviously out of date and obviously not the main partition.
- Cider9986 2mo agoNot possible to be robust unfortunately due to low level SSD architecture[1] and other reasons: https://nitter.net/GrapheneOS/status/2082153517234676150#m https://nitter.net/GrapheneOS/status/2082153517234676150#m [1] https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Trim%20Operation.html https://veracrypt.io/en/Wear-Leveling.html https://veracrypt.io/en/Wear-Leveling.html
- citizenpaul 2mo agoTell me if I'm wrong but it seems that if you cross borders a lot the solution is straightforward. Have a second set of disposable devices for out of country usage with nothing but a VPN to virtual desktop. Give them the password and your mailing address to return when they are done, or just consider it abandoned? Can they force you to log into another remote computer in another country to examine it? I'm not discussing politics, simply the solution that you can actually do now side of things. I don't have any hope of this situation improving globally and my gut says it will get much worse over time. I wonder if in the future you will have to not only give them your computer but have some sort of follow up investigation of your "real" computer if you do this two device method.
- amanaplanacanal 2mo agoThe comprehensive solution would be for the supreme Court to say this is unconstitutional. They don't seriously think that smuggling CSAM on phones is how it gets into the country. It's all pretext.
- ncr100 2mo agoMe solving technical problems without motivating requirements: Can you just like have the graphene OS device wipe itself if it knows that it's going through a border and you haven't logged into the device in 24 hours? Or maybe, Enter into a precipitous one false move mode, where it's just about to wipe itself if the 24 hours elapses, And it does wipe itself if someone doesn't put in a code the next time the device recognizes that is being handled, within like 90 seconds of being picked up?
- Cider9986 2mo agoWouldn't be effective because would have to be implemented at hardware level which it's not. Unreliable at software OS level. How would it reliably reach the internet. No real advantage over cloud backup and way more risk. There's already the reboot timer which works fine for securing data but not under duress. Us citizens should use that.
- slim 2mo agothe solution is not to travel with your phone. Most people don't travel that much and do it essentially for holiday. So having a factory reset phone for traveling is totally doable. That's what I do
- pickdig 2mo agocan you use a faked account that looks like you but hides all the important information so when your phone is in search mode you just show the agent that, giving them something to work on and protecting your privacy
- Melatonic 2mo agoMakes me wonder if there's a creative and maybe low tech way to incentivise them to not want to keep searching through your phone