6 ms·
For exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs. Imagine booting the phone from a flash drive, making a
by Zak 1mo ago
For exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs. Imagine booting the phone from a flash drive, making an encrypted image of the phone on said drive, and writing a fresh OS before reaching the border.
There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA).
Some time ago, Android with a custom recovery could come close to that, but it was fussy and as far as I know, no longer viable. Increased use of TPMs for storing credentials seems to be at least one of the reasons.
- abc123abc123 1mo agoWhy bother with the drive at all? Just store your image in the cloud, and once you're past the border, download and re-image.
- fhdkweig 1mo agoAlso, it is just a nice idea if you are prone to losing phones. Backups are good for all kinds of reasons.
- solid_fuel 1mo agoIt may be fun to fantasize about these things some times, but there is no technical solution to tyranny. Laws are not like code, intent matters. Ultimately if the intent is that the government wants to see your private data, hiding it in any way will be charged - it doesn't matter if you jump through hoops to avoid this specific instance.
- Zak 1mo agoThis is a half-truth. In a full banana republic, technical compliance with the law will not prevent consequences for failing to do what the authorities want. In a jurisdiction with perfect rule of law, it always will. The USA is somewhere in between. One of the laws that's enforced pretty well in the USA is the protection against unreasonable search. Most of the time, a search requires showing a judge evidence that the search is more likely than not to reveal evidence of a crime. Exceptions are narrow and specific; the government's options to punish someone who refuses to decrypt data at the border are limited to brief detention and seizure of the medium. Not yet tested is the idea that erasing data on the spot satisfies the purpose of the border search exception, which is to prevent importation of things that are illegal to import. This case might address that question.
- _heimdall 1mo agoUnreasonable search is always under attack though. There are many instances today of cops forcibly entering a home claiming nothing more than a welfare check, or "we received a call." Edit to add that its also more difficult than it should be to protect and exercise the right against unreasonable search. If a cop knocks on your door its a consent-based interaction. You can simply not respond, but if you do happen to crack the door they can and will look in for any signs to claim as probable cause. Further there are cases where a person stepped out to talk and when they turned around and walked inside the cop slid right in behind them and later claimed in court the open door was implied consent. (I don't have a link to the court docs unfortunately.)
- leptons 1mo ago>There are many instances today of cops forcibly entering a home claiming nothing more than a welfare check, or "we received a call." And there are also many instances of the city being sued, those cops being sued, losing qualified immunity, losing their jobs, etc, because we do still have recourse when cops do the wrong thing. If your rights were violated, you stand to get a big payout, and get the cops fired that violated your rights. We aren't powerless, yet.
- pstuart 1mo agoOr your family gets the payout because the cops killed you.
- WaxProlix 1mo agoCan you link to some of these cases of cops losing qualified immunity? It's an area in interested in but I understand that to be a vanishingly rare outcome - like only in very egregious cases, not just for run of the mill rights violations.
- exogenousdata 1mo agoIn case this isn't a bot and simply someone unfamiliar with the internet search, here is a snippet from the Google AI results when searching for the phrase, "list of US court cases where police lost qualified immunity." -------- A federal court denies qualified immunity when an officer’s conduct violates a clearly established constitutional right or when material facts remain heavily disputed for a jury. While appellate and district courts routinely evaluate these claims, absolute lists contain thousands of entries because denials typically happen at the lower or circuit court levels rather than as sweeping national precedent.[0] Notable Federal and Supreme Court Cases Denying Immunity Taylor v. Riojas (2020): The U.S. Supreme Court summarily reversed a lower court and denied qualified immunity to correctional officers who housed an inmate in shockingly filthy, human-waste-packed cells for days, ruling that the extreme conditions-violating the Eighth Amendment-needed no prior identical precedent.[1] King v. Brownback (Sixth Circuit): The 6th U.S. Circuit Court of Appeals denied qualified immunity to members of a joint law enforcement task force after they aggressively tackled and beat an innocent man (James King) outside a convenience store when they mistook him for a suspect.[2] Schroeder v. City of Des Moines (2022): The Eighth Circuit Court of Appeals ruled that three police officers were not entitled to qualified immunity after conducting an unlawful, suspicionless car stop and subsequent arrest based on an unverified temporary license plate.[3] Glover v. City of Jackson (2024): A federal district court famously rejected a detective’s qualified immunity defense in a major civil rights action involving fabricated evidence and malicious prosecution, highlighting systemic flaws in the doctrine itself.[4] [0] - https://ij.org/press-release/massive-new-study-reveals-that-qualified-immunity-is-about-more-than-police-misconduct/ https://ij.org/press-release/massive-new-study-reveals-that-... [1] - https://leb.fbi.gov/articles/featured-articles/qualified-immunity-today https://leb.fbi.gov/articles/featured-articles/qualified-imm... [2] - https://ij.org/case/king-v-brownback/ https://ij.org/case/king-v-brownback/ [3] - https://iowaappeals.com/uncategorized/three-des-moines-police-officers-denied-immunity-by-u-s-court-of-appeals-in-traffic-stop-case/ https://iowaappeals.com/uncategorized/three-des-moines-polic... [4] - https://eji.org/news/federal-court-denies-qualified-immunity-and-explains-doctrines-fatal-flaws/ https://eji.org/news/federal-court-denies-qualified-immunity...
- tamimio 1mo agoYes, trying to solve a regulation or legal issue by some technical workaround will never work, you have to fight it at the same level, legally, or system-wise, otherwise, you will be like the person who tries to wash the stairs from the bottom all the way up, it rarely works, you gotta go up to down, collectively go against the matter rather than individually duct taping it for your own specific needs. In that example, it won’t be far fetched the same ones who made it illegal to wipe your phone to make illegal to install xyz OS or using abc protocol, in fact, that’s exactly what they are trying to do under the disguise of “protect the kids” and going after encryption or similar privacy related issues.
- cherryteastain 1mo agoThey would not be so vehemently against it if it did not work. There is a reason E2EE, duress passwords and similar technologies are under such intense assault these days.
- wat10000 1mo agoDestruction of evidence as a crime goes back a long, long way. There's no precedent for making it illegal to install some OS or protocol the feds don't like. I don't particularly like what's being done to this guy, but what he did was pretty stupid. You can't be obligated to incriminate yourself but you aren't allowed to destroy evidence.
- inigyou 1mo agoone part of resisting is installing GrapheneOS.
- XorNot 1mo agoNormally I agree, but making the implementation initially ineffective is a good way to complicate more far reaching measures. Americans aren't standing up against this, but they might have considerably more interest if the government was instead trying to ban encrypting data in cloud storage for everyone. There's also just the fact it's ridiculous I can't have a spare phone ready to go in a few minutes and get it back exactly as I left it.
- deleted 1mo ago[deleted]
- elihu 1mo agoHaving good technical tools won't fix a failing society, but they're still nice to have and they make state surveillance of its citizens just a little bit harder. I mean, where would we be without strong cryptography?
- sneak 1mo agoThis is false. If you can image and wipe your phone on the plane before landing, and write those random bytes to a usb stick, the usb stick will appear blank, because encrypted data is noise. You land with a factory blank phone. You clear customs and get where you are going and restore your phone. Substitute cloud storage for a USB stick if you do it at your departure hotel. There are absolutely technical solutions to the implementations of tyranny. Otherwise we wouldn’t bother with encryption. Violence can’t solve math problems.
- maxerickson 1mo agoHow do you solve it when they beat you for having a phone that doesn't look like they want? Like whatever arbitrary thing they decide it should look like that day.
- sneak 1mo agoYou can’t solve that in any case, but that has nothing to do with tech.
- mathisfun123 1mo agoCorollary: this story has nothing to do with tech.
- solid_fuel 1mo agoSo you agree with my original comment, then.
- inigyou 1mo agoAll of your websites are missing the legally required Impressum, comrade. It must contain your full legal name and address. I'm serious, this is the law in Germany. It's also a great demonstration of a shitty law that people prefer to avoid complying with, which surely has something to do with the topic.
- sneak 1mo ago
- 8note 1mo agothese are abuses of existing powers, rather than acting with reckless abandon the government would have no ability to access the data if he didnt bring it on his person here. hell, he could have just continued to not given his password and left his phone with them, too.
- tjpnz 1mo agoThe only practical measure you can take is to wipe your devices before travel.
- chrisjj 1mo agoDefinitely sounds like the crime of hiding data.
- chrisjj 1mo ago> Ultimately if the intent is that the government wants to see your private data, hiding it in any way will be charged Inc. hiding by leaving it your home country?
- victorbjorklund 1mo agoReally? Does it take a long time to recover the phone? Haven’t really ever needed to recover a backup
- throwaway219450 1mo agoApple makes this very easy. I broke an iPhone and bought a replacement. If you have iCloud, you login to the new phone and you can see which backups you can recover from. If you are transferring a phone, say you upgraded, it’s even easier. You can also image the phone with a connected laptop and store it on a backup drive, which is nice to not use up iCloud limits. The transfer and backup system are pretty much the same mechanisms. Restoring is probably order of ~1 hour to go through all the setup. Then some hours to sync any data and updates that need to be redownloaded, apps reinstalled, etc.
- victorbjorklund 1mo agoAha that is actually pretty long
- rootusrootus 1mo agoThat's mostly time for data sync in the background. It takes 5-10 minutes tops to have the phone working again, but longer to get all of the media and other data restored. Depends on how good your connection is.
- weezing 1mo agoLast time it took me maybe 15 minutes on 600Mbps 5G to restore everything fully.
- rootusrootus 1mo agoI've restored iPhones before, and it does seem pretty simple. Easier than PCs for sure. It's not instant, but the basic configuration is restored pretty quickly while the bulk data restoration happens in the background while you're able to use the phone.
- thesimon 1mo agoWhat about banking apps and stuff? Does the device binding still work or do you need to set it up again?
- rootusrootus 1mo agoDepends on the app and security setup. If it's using old school Symantec VIP Access, it will not survive a restore. If it is using TOTP from 1Password, it will. Not sure about other options, those are the two I am most familiar with. Thankfully I only have a single app these days relying on VIP Access.
- weezing 1mo agoMy banking app required to log again to the bank account to bind new device and that's it. iOS is way better in this regard than stock Android. You pretty much get 1:1 copy on new device in an instant with the exceptions such as banking apps but that's kinda understandable.
- sneak 1mo agoIt is not remotely simple. So much is lost on device change.
- acdha 1mo agoIt is that simple for most people. Millions of people do this every time they buy a new iPhone and in practice it means waiting a bit while things download and logging into their banking app. It’s harder for people who don’t use cloud services and have to do things like copy TOTP seeds, but in this scenario you want those to live on a Yubikey with a PIN anyway.
- panny 1mo agoThink for a moment. What is the difference between giving them a password which wipes the phone and giving them a password which opens a blank phone? It's the same thing. They punched in a code, they are presented with a wiped phone. Can they prove the guy gave them a distress password and wasn't simply carrying a wiped phone to begin with? No, but they just need to imply that is the reason to charge him with the felony.
- namibj 1mo agoHave you considered "no password set"?
- teiferer 1mo agoTyranny does not care about "proof". It doesn't even care about plausible deniability. Best you can get away with is lack of suspicion. Have a secondary phone with some standard apps on that you use now and then so theyhave a history and just look like you are just not a technical person and read novels on dead trees instead. A lot of work but likely works.
- convolvatron 1mo agoare we seriously approaching a point where its quasi-illegal to not participate in the socials?
- hallway_monitor 1mo agoMore like they've looked you up and the apps being missing would be a giveaway about the dummy phone
- taneq 1mo agoSo it’s becoming illegal to not have the Facebook app installed on your phone if you have a Facebook account?
- 1mo ago
- echelon_musk 1mo ago> ...making an encrypted image of the phone on said drive... refuse to unlock the drive How is this any different than refusing to unlock the phone? It just seems you've added unnecessary extra steps.
- Doohickey-d 1mo agoAs I understand it, the drive can thus be seized, and a potential loss of a cheap flash drive is a lower inconvenience than loss of the phone.
- ratelimitsteve 1mo agoI mean, you could ship your real phone to w/e destination ahead of you and bring a $50 burner to the border. If you're a person of interest this won't work because they can monitor you and the destination but if you're a regular schmuck then a burner that never touches your private data or accounts and has a bunch of dummy stuff on it will get you past the border goons.
- trencedamp 1mo agoThere's a way simpler solution and it's just to leave your phone at home and put your SIM in a different handset without all your data on it
- Terr_ 1mo agoAn increasing portion of phones are eSIM [0] only these days, and the difficulty of swapping can be weirdly-bad depending on provider. [0] https://en.wikipedia.org/wiki/ESIM https://en.wikipedia.org/wiki/ESIM
- trencedamp 1mo agoBut non esims exist still, and if you're that worried about security, you can get one.
- Doohickey-d 1mo agoNot forever though, and if you're an iPhone user, already current iPhones sold in the US are eSIM only. So in some number of years (depenfing on your device oldness tolerance), they will become obsolete eventually.
- inigyou 1mo agoWhy would you use an iPhone?
- sneak 1mo agoUS iPhones don’t have sim slots at all anymore.
- lstodd 1mo agoCan't one just buy some craphone for like $50? with whatever sim. The whole problem as I see it is that people for some reason submit all their life to a device they can not control. And when it bites them they go all suprised.
- grapheneos 1mo agoGrapheneOS has built-in encrypted backup and restore. It backs up the same data transferred by Google's device transfer feature for moving to a new phone which is nearly all app data, the data in the home directory, contacts and a bit more. Certain apps such as Signal encrypt their own data with another layer of encryption using a hardware keystore key. Signal's own backup system needs to be used for that, although it can just be used as a way to get data into the system backup. It's worth noting wiping a device shortly before an anticipated search could also be considered destruction of evidence in the same way. It doesn't have to be done after a request for the data to be considered that. > There's no deception required to protect sensitive data or avoid the seizure of an expensive phone. Consent to unlocking the phone, refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA). This was likely the best move for him to take. They could have held him for a while and wasted his time but eventually would have had to give him access to a lawyer and let him go. Unless they had a recording of him entering a PIN/password, they were nearly certainly not going to get his data from it. He very likely didn't gain anything from wiping it. He did help every GrapheneOS user by spreading awareness of the duress PIN/password. It was designed around an adversary aware of it and therefore not wanting to attempt using a PIN/password obtained via coercion. In the future, we want to integrate the feature into the secure element rate limiting for key derivation so it can't be avoided by exploiting the OS.
- deleted 1mo ago[deleted]
- Cider9986 1mo ago[flagged]
- deleted 1mo ago[deleted]
- deleted 1mo ago[deleted]
- deleted 1mo ago[deleted]
- GeekyBear 1mo ago> For exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs. You're always been able to backup and restore your iPhone to your local Windows PC or a Mac using free first party software from Apple.
- wombatpm 1mo agoOnly app data, not the apps themselves. On restore you need an internet connection to redownload the applications.
- yapyap 1mo ago> refuse to unlock the drive. The drive gets seized and you go on your way (if you're a US citizen entering the USA) … yeah I doubt that nowadays honestly
- Aurornis 1mo ago> I wish smartphones could be imaged and restored as easily as PCs. Imagine booting the phone from a flash drive, making an encrypted image of the phone on said drive, and writing a fresh OS before reaching the border. Backing up and restoring an iPhone is extremely easy. You don't need to imagine all of this flash drive or encrypted imaging stuff. You plug it into your computer and do a backup. You can then wipe the phone through the menus. Restoring from the same computer is easy.
- grishka 1mo agoExcept apps themselves don't get backed up, only their data. So if you had any apps that are no longer in the app store or that came from outside of it (e.g. TestFlight or development builds), those won't be restored.
- Razengan 1mo agoHow about every civilian banding together and refusing to comply? in before those fucking "I hAvE nOtHiNg tO hIdE" twats
- sneak 1mo agoI already refuse to comply with questioning at the border. Been being harassed and my non-citizen travel companions being SA’d by CBP for decades. Get with the program.
- dredmorbius 1mo ago"SA'd"? CBP: Customs & Border Protection
- sneak 1mo agoSexually assaulted.
- opan 1mo agoPinePhone will boot off a microSD before the internal flash, so you could have a clean OS on the card and your real one on the flash. The SD card is under the back cover with the battery and SIM, so chances are they won't think to try to remove it.
- utopiah 1mo agoSomebody who doesn't know what they are doing, sure. Somebody who does, and maybe even enjoy doing it, and the challenge of it, will surely know about it simply because they are maybe two dozens of types of smartphones out there. Android (including of course GrapheneOS) based ones, iOS ... then PinePhones, Volla, Purism and few others. So having a guide on how each one can have hidden partitions or booting mechanisms is tractable. Point being that relying on a hidden trick (rather than encryption) is a very risky bet.
- utopiah 1mo agoCoincidence but I just started to listen to 404 media podcast on tracking rare books being scanned in AI facilities thanks to just a cheap AirTag. I find this a good illustration of how easy it is to find something if you know how to look for it, and thus again why encryption is the only safe way.
- grishka 1mo agoThose "nandroid" backups weren't "close" to that, they were literally that initially. Then, when Android phones started coming with the /sdcard partition mapped to the internal flash memory (a subdirectory of /data) instead of an actual SD card, the /data partition backup mechanism was changed to copy individual files into some sort of archive, but the end result remained the same. You can still do it on modern Android devices, as long as the bootloader is unlocked. Yes, the file system is encrypted, but a modern custom recovery is able decrypt and mount it.
- malfist 1mo agoHow many mainstream phones come with unlocked bootloaders? Just pixel right?
- tcfhgj 1mo agoFairphone
- theokrueger 1mo agoFrom memory: - non-US Samsung phones - Most Sony, HTC, Motorola are unlocked - Chinese brands like Xiaomi Not all Pixels are unlocked; carrier-bought US phones are usually OEM locked.
- inigyou 1mo agoXiaomi has fake unlock. It has an unlock button that never works and never has worked. Instead you have to write a letter to get their approval code or some complete bullshit like that. Of course this is because unlocking is illegal in China and they sell a lot of phones in China.
- grishka 1mo agoIn my own experience, you need a Windows app and a Xiaomi account, and then it will ask you to wait for days, and only then can you unlock it.
- hirvi74 1mo agoIt'd be less of a hassle to buy a burner phone to travel with. It's not a felony to not bring your main phone when leaving the country.
- deleted 1mo ago[deleted]
- dyauspitr 1mo agoIsn’t this basically what you do with an iPhone. You reset/format it then it gets back to its original state with iCloud?
- awruko 1mo agosome of the banking apps, UBS banking require reactivation. So most of the apps yes with exceptions.
- unethical_ban 1mo agoI agree. Here's my method. I have my passwords on proton pass with 2fa. I back my pics to private cloud storage. I keep 2fa backup codes in my wallet. Wiping the phone on a whim is a minor inconvenience. Full image restoration would be neat.
- unethical_ban 1mo agoedit to say: Apparently GrapheneOS has an image backup feature, which I will investigate shortly. So perhaps what you're asking for exists!
- skinfaxi 1mo agoYou have to ask yourself why this isn't possible anymore. Similar to how recording calls used to be possible but no longer. I don't know why it is but it is awfully strange that they keep tightening the belt on what we can do with our own devices.
- Gigachad 1mo agoYou can do it on iOS officially. Android never had an official backup process, it was always through root apps. Backups could just be a casualty of killing rooted Android.
- ajsnigrutin 1mo agoWhy would recording calls not be possible anymore? On a rooted phone you can do it, some amixer and arecords might be needed, but it stores the audio of both sides.
- sfdlkj3jk342a 1mo agoI really really want this for GrapheneOS. The current backup situation is terrible and nowhere near being able to easily image and restore the entire phone (or at least user data).
- zuhsetaqi 1mo agoWell it’s really easy to do that with an iPhone. Just with the inconvenience of needing to use a computer for that. You can just create an encrypted backup of an iPhone and store that anywhere.
- dotBen 1mo agoYour setup doesn't really work. At the border you have the same right to refuse to provide the pin/password on boot of your otherwise encrypted phone as you do to refuse to provide the key for an encrypted USB. (That right differs slightly depending on whether you are a US citizen or not). What the subject in question of this new story did was cause the border official to inadvertently destroy the evidence on the phone and therefore indirectly destroyed the evidence himself. (I'm not making a commentary as to whether or not it's a valid charge and criticism, or not. I'm just saying that's the material difference between your scenario and the original scenario)
- talon8635 1mo agoSo, how easy is this today on computers? If I have an Ubuntu 26.04 machine running, I can easily image the entire thing, completely wipe the machine, then reinstall from a flash drive and it behaves as if nothing happened? This isn’t my territory, so excuse my ignorance, but I’d love to know how
- eugene3306 1mo agoeasy! google "archwiki dd" scroll to 2.2
- ajsnigrutin 1mo agoJust get a larger drive than the internal one, and "dd" (copy byte by byte) the whole internal drive into a file on that external drive. There could be issues with the TPM chips, having to re-enroll fingerprints or something, but not a problem in the case of a border search, since they can't pull out anything. So you could backup your whole system, install a clean ubuntu without anything special on the system (just if they check), and then download the image wherever you are and do whatever you want.
- talon8635 1mo agoThank you! So on a Luks encrypted xubuntu, o can dd to an external and then my laptop can fall in a lake the next day and I run some simple command to unwind that on a fresh laptop and I’m off to the races? I presume it’s much slower than rsync, since it’s comprehensive each time. Are there any gotchas? This sounds too simple to be true—but again, my knowledge on backup is very unprofessional
- ajsnigrutin 1mo agoYou can do exactly that, yes, dd whole disk to external drive, dd it back. Of course this assumes you'll be buying the same laptop, otherwise, you'll have to reconfigure stuff, from graphics drivers, resolution etc., resize the partitions (assuming the new hdd is larger, and you can't use a smaller one). The problem with dd is, that you can't really run it on a running system, because stuff is constantly being written to the drive (this is same for rsync too, but usualy the damage is smaller), so you have to boot a live linux from usb, dd the whole drive to an external drive, and then after swimming ashore, boot a live linux on the new laptop, and dd the backup to the new drive.
- ajsnigrutin 1mo agoThey could be, easily so, twrp backup (and clockworkmod recovery before that), you'd just create the image of the phone (all partitions, everything), dump it to wherever, and then restore it, it was a standard system for testing new android versions on the phone. The "secure enclaves" and other related stuff have made this harder in the recent years.
- p0w3n3d 1mo agoSadly both Google and Apple allow this only when using the cloud... You even can't configure your own cloud provider for the backup