Comment by schoen

12 hours ago

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully).

The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that.

The end result (not inherently different from what we wrote in the guide) is that you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to. I was fascinated by techniques for being unable to comply (which is straightforward to achieve if you want!) but probably didn't think enough about how much this might antagonize border agents in many cases.

I definitely don't know a comprehensive big-picture solution.

There are 2 cases routine inspections and targeted investigations.

If it's a routine inspection, being uncooperative will probably lead them to escalate. You generally want to keep things routine and boring. If they want to access your device you have to weigh the costs, just log out of everything before you fly and throw away your device after they have had access to it, it's now compromised.

If you are targeted your compliance is irrelevant and only weakens your position, the thing is at the border you don't get all of the protections you get at say a traffic stop they can search everything you have on you without warrants reasonable suspicion or anything.

I am not a lawyer but if you are a citizen they probably can't deny you entry but can probably detain you for an uncomfortable amount of time, and seize whatever they want. Your best defense is to have a burner phone and no other devices nothing they can seize that would hurt you.

For foreign nationals pretty much the same applies except they can deny you entry and ship you off to alligator Alcatraz, just don't fly to America for a few years.

Remember he is not being prosecuted for not handing over his device but for destroying the data they were trying to seize, if he just let them keep the phone he would be Scott free. I.e.the best technical defense is secure encryption with a key thats long enough and not stored on the device.

Actually for the particular case the best technical defense is to not have any data whatsoever on you.

  • > I am not a lawyer but if you are a citizen they probably can't deny you entry but can probably detain you for an uncomfortable amount of time, and seize whatever they want. Your best defense is to have a burner phone and no other devices nothing they can seize that would hurt you.

    Even having a burner phone without any personal information on it can be deemed suspicious. It would be best for your phone to have a recently-reinstalled OS, with a few critical apps like Whatsapp or iMessage set up with a few personal messages sent. You need to be able to set those up without a password manager. Anything else needs to take place on devices that you aren't carrying with you. Fortunately enough people don't update their Facebook these days that just having an account that exists but you don't use will probably work, assuming you don't look like someone that would be obsessed with their socials.

    Maybe there are USB thumb drives that operate like a YubiKey unless special setup is performed to access the storage inside? That's one way to carry data with you if you have to.

    • You can offer the I don't travel with my real phone because it got stolen a bunch of times excuse.

      The point is even if they become suspicious all they can do is seize the burner ask you a bunch of questions etc. search you, etc they can't get access to your data. You can't get in real trouble, just majorly inconvenienced.

      4 replies →

  • > just log out of everything before you fly and throw away your device after they have had access to it, it's now compromised.

    I get what you are saying, but this is incredibly expensive and not really practical for most people.

    • > not really practical for most people

      Evaluate your threat model and the chance that a wipe and reinstall of the OS will be insufficient protection.

      If you were targeted, you may have some tough choices. Might as well think about them ahead of time.

> you may have to think both about protecting your data by technical means, and about not angering the agents more than you plan to

That's the same problem with technical solutions to crime.

I come from a very dangerous city and I used to have a car that needed a PIN to work. You could turn then engine on and drive but after a minute if you didn't input the PIN it would turn off without warning and start blasting the alarm. The idea being that if the car was stolen the thief would be stranded not far from home unsure about what's happening. Great technical solution but it ignores that a lot of the time the car is stolen with you in it (in a kidnapping, for example). Having the car shutoff in the middle of a highway next to a panicking guy with a gun and trying to remember a PIN is not a situation you want to be in, so I just had the PIN number written down on the dashboard, which worked very well when I was eventually kidnapped and just pointed at the piece of paper with the number.

  • In phone terms, that's the $5 wrench problem. The elaborate tech is not relevant if you can be simply coerced somehow to bypass it.

    Again in phone terms, maybe bring a blank phone through that border.

    • Coercion was the reason from start, it's explained in the article.

      "A motion filed by his defense argues the interrogation focused on child sexual abuse material as a pretext for investigating his connections to the protest movement."

      So the message was simple: don't protest and you will be not harassed.

  • And there's the problem that if the PIN or worse a biometric version of this becomes remotely well known you've now created an incentive for a car thief to kidnap people even if they only want the car.

    • Or anything else you can't easily transfer. I can't help but point at passkeys in particular (or 2FA in general).

      A variant of this is the well-known scene from a previous century's movie involving extracting an eye to bypass retinal scanner.

I think in these situations your absolute best bet is fawning compliance. Ask precisely how high they want you to jump.

Perhaps your friendly smiling Yes-Sir-No-Sir-3-bags-Full-Sir act might just be enough to let you get on your way without anything else happening apart from a stamp in your passport.

Even the slightest hint of defiance or surliness from you to a border guard/policeman/etc - potentially at the end of a long shift, tired, angry, pissed-off or whatever - and you're straight away hugely more likely to have a bad day.

Finding strategies to "beat the system" will, I think, just be a shortcut to some other punishment/crime/taken-out-of-sight-and-given-a-proper-kicking-oh-they-resisted-and-went-for-my-gun/etc as this person found out the hard way by trying to be difficult.

I genuinely don't think there is a "get out of jail free card" or magic incantation you can say to get out of these situations apart from just smiling and being polite and not being a dick - if you get into a "who can be more annoying" competition, then the border guards/police will always win since they hold all the cards and will happily ruin your day/holiday/meetings etc by detaining you (its their job to do this after all)

There have been cases very recently in the US where the authority figures down dealing with the public are evidently in a very defensive, aggressive "us-vs-them" mindset, with an itchy trigger-finger to go with it. Don't be the person on the receiving end of a cop seeing-red because you're being a jerk.

The house always wins.

  • This comment irritates me. On one hand, I agree with it. On the other: how is it not just a version of “if you have nothing to hide”?

    At some point, you should fight for what you consider basic human rights. Where you draw the line and how you fight is up to you.

    It sounds like your attitude is to comply with whatever the authorities want.

    It seems like a completely innocent person is the best one to push back on authoritarian overreach.

    Am I misunderstanding something here?

    • No, you're not.

      And idk how people don't understand how "politeness" gets weaponized.

      This video is an example

      https://youtu.be/amSIcL3V5C4?is=hmlOx2t7dHg5j-lJ

      Here, the only way this guy could've had a "good attitude" is if he had let the lady do whatever she wants with his service dog. This behavior is very common in situations where people feel entitled to something, but know the counterparty has the absolute right to refuse to cooperate. No matter how politely that information is conveyed, it's "rude" because they're being denied something they want.

      The police don't like my attitude when I firmly say "no, sorry, I won't be unlocking my phone. I will only do what I am legally required to do."

      People have a hard time understanding this because they are under the impression that they know how to be polite because they do what they think is polite. They are unaware that politeness is subjective and slippery and that people can and do use it to manipulate others into doing things they're uncomfortable with.

    • [Am in agreement with being conflicted about this advice]

      In a normal functioning society with law enforcement that is actually accountable to it's citizens, yes - polite pushback will likely have no horrible consequences.

      In a country that is either already in the depths of fascism/authoritarianism - or rapidly heading there, fighting for rights is seen as a "red flag".

      See also: "On Tyranny" (Timothy Snyder) and "Do Not Obey in Advance".

  • It’s weird how few people understand that just being courteous/polite eases most encounters considerably.

    Absolutely astonishing seeing people try the “I’m going to be as annoying as humanly possible” to the guy with the gun with the “my YouTube lawyer says I can” defense. You don’t want to have to defend your civil rights in court.

    This goes doubly when at immigration where you basically don’t have rights.

    This guidance also applies to: bank tellers, call takers, baristas, waiters, other people standing in line with you, the bus driver, your mom, the neighbors upstairs, the raccoon across the street, …

    • Politeness is the correct behavior on most walks of social life, but on this case it's a bit like the "turn the other cheek" approach, but in this case, it's turn the other butt-cheek because you're being effed in the A.

      Also, you do have rights, but don't seem to really care a lot about them since, in the face of unlawful and oppressive demands by overreaching authorities, your suggestion is to be courteous with the oppressors for some reason.

      "Land of the free, home of the brave"

  • > I genuinely don't think there is a "get out of jail free card" ...

    Being rich and politically connected would probably do it.

  • It's best to do that for things they have the right to do. Trying to resist being questioned or having your stuff searched is a fool's errand. They'll make it happen one way or another.

    But I'd never unlock my phone for US immigration. That's my whole life on there, and they don't have the right to compel me to unlock it. Even there, be polite. You can say "no" politely.

    Where this guy went wrong was actively wiping his phone. That's no good. What you do is put your phone in its most secure state (generally powering it off) before you reach the immigration desk, and then if they seize it, you have to trust its security to keep them from getting into it.

  • "If you want a picture of the future, imagine a boot stamping on a human face - for ever"

    • I will ask this here again:

      At what point did the German people find it morally acceptable to start killing Nazis?

      At what point will the US stop accepting the boot and act to remove the tyranny stamping on our collective face?

      5 replies →

We probably need honey pod fake OS systems that boots up if not properly handled displaying some stars & stripes as background image and having the US national anthem playing for any sound the OS is trying to play.

  • A phone with a backup account, unlocked with duress pin makes sense to me.

    How hard would it be to admin-allow some apps to work across barriers. E.g., wallet apps work, airline tickets work, but email/socials do not.

    the issue is that when a phone is unlocked, they can just plug in a USB device and scrape everything off it. The TSA agent may not be eyeballing a facebook account so much as plugging in an exfiltration software stack or malware.

    • > the issue is that when a phone is unlocked, they can just plug in a USB device and scrape everything off it

      That's useless if the backup account and the main account use different keys for the home partition.

      VeraCrypt (used to?) have this. It was called a hidden volume. One volume, but two keys, two passwords, and two different containers full of data. Technically, the second volume is written into the partition "from the back" using key 2, while the first volume is written "from the front" using key 1.

      Fun fact, there's no protection against writing over data in the other volume if volume 1 + volume 2 exceed the size of the partition - and there can't be, otherwise the volume wouldn't be hidden.

      2 replies →

    • For now the courts in the US have set a different barrier for automated extraction and hand searches. For now.

    • Why does the USB port need to even work anyways? It could just be designed to look like a USB port but fry whatever expensive and proprietary phone hacking device they bought from some scuzzy Israeli ‘security’ company when it’s plugged in.

      4 replies →

  • This would unironically probably work pretty well. The bullies in airports don't have that much time to investigate a phone which "looks good".

    • Right, these goons are hand searching through phones specifically to find something, anything, they can use to make your life suck and detain you further.

      A pin that boots into a dummy account, full of benign messages, photos, innocent web browsing, etc. is going to get you a pass. They'll flip through everything and get bored after a minute of not finding anything.

      Far less likely to aggravate them than wiping your phone

  • I would prefer to backup and wipe my phone before travelling.

    Then have some planned means of restoring the backup when it's safe to do so.

    Being caught with a honeypot looks much worse than being caught with a new phone. You can always say you bought a cheap "travel" phone if asked.

    • Its such a shame Android's backup/restore is such a mess, even more so in GrapheneOS. I remember the era before Google and manufacturs started cracking down on bootloaders and custom ROMs - I used an app that could do effective, actually full backup and restore in single click.

      Good times.

    • It's hard to justify an iPhone Pro Max as a "cheap travel phone" though so you might actually need to buy a cheap travel phone.

  • Don't forget to have the Official Social Media of the President of the United States(tm) installed, with an account following the correct list of truthtellers and rightthinkers.

Me solving technical problems without motivating requirements:

Can you just like have the graphene OS device wipe itself if it knows that it's going through a border and you haven't logged into the device in 24 hours?

Or maybe, Enter into a precipitous one false move mode, where it's just about to wipe itself if the 24 hours elapses, And it does wipe itself if someone doesn't put in a code the next time the device recognizes that is being handled, within like 90 seconds of being picked up?

Yeah, you really can’t outsmart those with physical power and authority over you. Americans have asked for, or tacitly accepted this treatment of their visitors. The only big-picture solution is to stop visiting.

The comprehensive solution would be for the supreme Court to say this is unconstitutional. They don't seriously think that smuggling CSAM on phones is how it gets into the country. It's all pretext.

can you share the link? This?

https://www.eff.org/document/eff-border-search-pocket-guide

----

Seems the better strategy (for iOS) is come in with a plan to say yes to agents without pissing them off (like handing them an empty phone).

better to local back up, encrypt, upload to your home server etc.

Then login to a fresh iCloud account, selectively install apps, photos, and mail accounts. So it doesn't look like you're walking in suspicious.

  • This seems like an insane thing to have to do for visiting a supposed first world country. If phones had been around during USSR times I imagine you would have had to do the same. Personally I will rather just avoid any travel to the US, and I hope others do the same.

    • Security concerns you need to think about when visiting the US are absolutely no less than those when visiting China these days. Treat it like a totalitarian dictatorship with more technological means.

      23 replies →

    • I wouldn't say you are overreacting at all. I know someone who was detained for months on US soil after a phone search where the only "evidence" against him they found is illegal content sent by someone else to him on a group chat he doesn't even check. Had to get a lawyer and spend time in prison just waiting to be deported back.

      13 replies →

    • My dad's eighty+ years old, he was born in the States, though he did give up his citizenship. He brings a "fake" phone when visiting family, he's been doing so for years.

      Me; I just change all my tabs and recent history to slightly kinky porn and truth social. They do look hard, but they don't look hard.

      1 reply →

    • The US is first world on a technicality: the first world is defined as countries that were allied with the US during the cold war. If not for that, it'd be classified as developing.

      It's common to mix up developing/developed and third/first world because they were largely aligned during the cold war. But there is one first-world developing country.

      11 replies →

    • I used to love visiting the US. I have many friends there, and I really enjoy staying in places like Seattle and SF. But I haven't gone there since Trump 1.

      That said, I think protecting your privacy is a good idea in general.

    • Yes, I will probably never go back to the US. But I find it sad that my kids for example, will have to think twice before visiting, if they do.

    • > for visiting a supposed first world country.

      ... which by now is a banana republic of the worst kind. Can you interact sanely with an insane counterpart? Avoiding to visit would be my recommendation too.

    • Just out of curiosity, like what country would you not have to worry about this in?

      The US is quite transparent about these rules, and certainly other countries are not necessarily searching peoples phones as publicly

      But anytime I transit a country USA or any thing I fully expect to have zero rights

      9 replies →

  • Xiaomi phones have/had a feature where depending on which finger you unlock the phone with, it can hide certain applications/folders on the filesystem.

  • who believes an empty phone?

    • You need it to look set up enough to do critical communication / tourist activities. It should look like you had to reinstall your OS right before your trip, and only had time to get the basics on there. Most people will prioritize communications, maps, and payments over anything else, with video/music/books/podcasts following that, and signing into the vast universe of social apps later if ever.

    • You're right for non-citizens.

      For citizens, no one needs to believe it. You give them your empty phone and they can't download your phone contents and contacts.

      3 replies →

    • The point is not what they believe, but how to avoid both breaking the law and not giving up your data, isn't it?

      As long as that's legal, what they believe doesn't matter.

      You are not legally obliged to keep your data on your devices all the time.

  • I guess you could just bring a flip phone. But then that could be seen as suspicious these days.

    When a government is paranoid, everything is suspicious.

    Maybe just don't do anything on your phone but normal capitalist business sht.

I don't own a cell phone, haven't for years. I fear this alone would be enough to arouse suspicion and I'll be denied access. Not an immediate problem for my family: as a Canadian I have no plans to visit the states for a long time. However, I could see this being suspicious in other countries as well..

> I think they should not have this power, but the agents and courts probably don't care that I think that. ...

> and about not angering the agents more than you plan to

When I was a teenager (long ago at this point), I got into an argument with a police officer over surfing in a certain area. It was pouring down rain, so he was annoyed he had to sit outside and wait for my friends and me to come to shore. Once we got in, he was telling me that he could take my surfboard and my car, and all other craziness. Being the dumb smart-ass I was at the time, I laughed and told him he was full of shit, among other things. He went to take a swing at me but his partner grabbed him.

We all go to court and the judge immediately dismisses the case against all my friends. I had a lawyer with me that I knew and he went to talk to the cop and when he came back over he goes "I don't know what you did, but that cop hates you." I get up in front the judge and he praises me for understanding the law (and I could still see the cop was visibly pissed), but then says he can't have me disrespecting and being a smart-ass to his cops and gave me community service that once completed whatever the ticket was would go away.

  • > but then says he can't have me disrespecting and being a smart-ass to his cops

    Maybe it's just me, but I am of the exact opposite opinion. Cops have enormous power, and any misuse of it should be pushed back on hard. Cops that misuse their power should not be respected. An informed citizenry is a wonderful asset in making that power imbalance less of a problem.

    • There's a difference between polite pushback and being straight up disrespectful. It shouldn't matter as the cops shouldn't abuse their power and shouldn't attack people, but we live in the real world. The judge probably didn't want to have to deal with the potential future mess if op didn't learn their lesson and got beat up by a cop.

      20 replies →

    • Yeah, but go tell that to the judge who’s just about to slap you with a sentence.

      Unless you want to fight that all the way up the judicial food chain

      1 reply →

    • There's a huge difference between misusing their power and not having perfect understanding of what they're allowed and not allowed to do.

      I'm sure there are scenarios where the cop can confiscate the surfboard and the car. The distinction is probably somewhat vague even for highly educated lawyers, and cops cannot expected to be that.

      He should have stood up for his rights, sure, but laughing in the cop's face and telling them they're full of shit is disrespectful, and at least where I live is a misdemeanor even if the original case is wrong.

      1 reply →

  • And what did this judge think (not much, apparently)? Punishing you will make you respect the cops?! This idiot confuses the fear of punishment with respect. Also, does not understand that respect is not to be forced but to be earned. Forcing it will erode respect and generate lots of pretension and covert hate. This judge basically endangers all cops (and the community) for giving revenge to this one prick lacking self control! It's mind-blowing that someone less mature than a teenager can become a judge!

  • Too bad you could not bring that judge up on charges of judicial misconduct - if he indeed told you that the charge against you had no merit, but decided to punish you anyway because he did not approve of your demeanor.

    ... or otherwise, that people in your community could not apply any counter-pressure to such judicial behavior, in the media and public fora.

    • To be fair to the judge we all had broken an ordinance about surfing in a certain area. It was enacted to protect swimmers in the summer. With that said, there was a storm with wind, rain, and currents that had pushed us into the area. Obviously there were also no swimmers out.

      The ordinance was removed a few years later. This cop was also known to hate surfers. All the small beach town BS you hear about.

    • at some point you just take your lumps.

      Most people don’t have boundless time or energy and just want things to go away.

      … ironically this fact is used a lot in gaining confessions by police.

I worry that at some point, the physical device won't matter. Border authorities will know your email address, and could force you to log into your account on a device they supply. Five years ago, I would have called anyone even bringing up this possibility paranoid, but a lot of things that were completely unimaginable outside of Hollywood political thrillers have already happened.

  • And then there's the problem that you can't just log in with name and password to your email address. You need your special "authy" style number generator, or a software version on the phone. They know you probably have it on the phone. but what if you bring your other phone that doesn't have it on there - you removed the software before you left so no one could even log in.

    All these fancy tricks don't work because the doofus/poor soul at the border doesn't understand the nuances and they don't know if you are lying or not. Even if you wipe your phone and restore it once in the safe usa, that's no doubt suspicion of a crime.

There’s more to it than just not antagonizing the guards. I mean if you make them mad by doing something that is legal that’s probably not ideal for you practically speaking, but it’s not the end of the world. Destroying evidence while they are investigating you is not just going to make them mad though. It is illegal (18 USC section 1519).

Where I think people are a little confused here is not realizing that this would be equally illegal in many other countries. At least in the UK and France, border investigators also have the power to demand your PIN. And it is also illegal to wipe your phone during an investigation in those countries.

What about simply not using a smartphone and accessing your data via internet when you're in the country? You could use Mega (secure file storage) to access your files, for example.

I wonder if border agents could coerce you into giving access to your internet file storage, though.

  • I believe they can. I believe they can even request your social media credentials, despite that being against the ToS for those sites. It's not against the law to refuse, but they can and will reject entry on that basis.

  • Remember that the creator of Mega is getting extradited to the USA - again - a country where he's never been, by the way - for basically this crime (using encryption).

Why not have a passcode that boots in to a second “safe for cops to look at” partition?

  • That partition will always be obviously out of date and obviously not the main partition.

I wonder if the smarter thing to do would be to quietly nuke it as soon as it becomes clear that you'll be detained, so they can't really know that it wasn't already blank (IE you aren't nuking it in their presence).

  • The smarter thing to do is to just wipe your phone of everything you don't want border patrol to see before going to an airport.

    • With self-hosting, it's possible to easily bootstrap a clean phone with all your data and passwords from scratch, without relying on any third-party cloud services. The only thing you need to bring across the border is your brain (which contains the most basic information on how to set up your password manager) and maybe some kind of 2FA generator. Your password manager then contains all the other information you need to get everything running.

      I don't think it ever makes sense to transport actual data across borders if you care about governments gaining access to it.

      5 replies →

I don't carry a smartphone, is this likely to be a red flag if I'm stopped?

  • Many countries now assume you have a phone. For example getting UK visa requires a smartphone. I don't think going without a phone is feasible nowadays.

    Another question is if going with a burner phone that has just sim card and bank card, sufficient. But then you need appleid/google account on the device, and this again links back to your phone number, and it's not easy in practice to have proper clean device.

So I guess what you really want is a duress PIN that loads into a fake innocent profile.

  • Yes I thought this was the standard solution?

    People have been doing this since way back in the TrueCrypt days - IIRC you could configure it to run a whole fake version of Windows if you wanted without easily revealing your actual main volume.

    Most hardware crypto wallets also have a "duress wallet" feature where you keep a low balance for the same reason.

    Wiping is obviously extremely suspicious and asking for trouble

    • "Wiping is obviously extremely suspicious and asking for trouble"

      It's sad this is the default view. It's his device, his data, his life on that phone. If he had wiped the phone before the interrogation it wouldn't be a problem. How long before? A second before? A week before? But wiping the data a minute later is suddenly asking for trouble.

      6 replies →

    • We noted in the border search guide that lying to the agents in response to their questions is potentially a crime in its own right (even if it's not done in order to hide anything illegal). We thought that this made hidden volumes quite tricky, particularly if one's intent was to pretend to comply with a question or request while actually not complying.

      7 replies →

  • Not enough, e.g. when crossing the Russian border (even as a citizen) your phone can be connected via USB to a device that uses exploits and whatnot to download all of the data. Surely US border guard can do something similar.

    And using encryption will only make you more suspicious, and may be a reason to get jail time until the situation is "cleared up" one way or another (e.g. by getting even more jail time).

    Only a second phone works, if you can make it seem like a device you're actually using (though also not a silver bullet as e.g. a lot of messenger metadata is available to governments and border control can physically coerce you to log in to your real accounts)

  • Or that just selectively wipes only stuff you have marked for deletion. That way the profile stays up to date and believable.

    • Problem is „are you sure you marked for deletion all the correct things” because you could have already deleted it before traveling or moved to other device you don’t travel with.

      Selection on border control might be arbitrary, they can hold you or send you back over a photo or something you wouldn’t think should be a problem.

      Ideally you would like to have all wiped just in case but then you really stand out…

      3 replies →

    • That's a more risky strategy. What if you added new files since the last time you updated the deletion profile? It's also technically more challenging. You have to think about what might be in RAM, caches, backups, etc.

      The good thing about a total wipe is that it's very easy to implement, and it's hard for it to go wrong. You just encrypt the whole drive and, when you want to wipe it, erase the key.

      1 reply →

    • Deleted stuff can easily be recovered. I think the full clean will remove the encryption keys hence making it unrecoverable.

    • Yes, this also has the advantage of speed perhaps. I can see, deleting specific apps (and their data) as thing #1, and thing #2 would be certain directories. Of course, the problem is, are icons going to be vanishing off the home screen, when the agent is looking at it? Or will the unlock -> screen coming on, be super slow?

      Of course the problem there is, many people have an app store installed, and app stores have histories. And logs. And "what you used to have installed" is so easily found under Google Play, for example.

      As someone else said in this thread, the law isn't code. It's not if-then statement based. It's also predicated upon intent in many cases. What actions did a person take, and why, when told to (for example) unlock their phone.

      The problem here is that if you are asked to unlock your phone, any action you take to thwart that request by "trickery" to get data deleted, could be construed as 'deleting evidence'. So while some methods might make it more difficult for the border agent to realise "something happened", if they're suspicious still, then you're still in hot water.

      In the eyes of the law, the court, and likely the jury, you've done a sneaky thing to thwart evidence collection.

      The only safe method is a full wipe prior to travel. In this manner, you're not deleting evidence when told to hand it over. It's an entirely different bar. They can be cruel about it, and take your phone for a few months, but you're not going to be in legal hot water.

      In as no one will see the phone is wiped until you are compelled to unlock it, there's no greater change of the phone being seized. You're already being investigated. Just be blunt, say "Whenever I travel, I just wipe it", and that's that.

      This is why it's a shame that GrapheneOS has no viable backup solution. Its build in method is unreliable, and doesn't work very well, and is gitchy, it's a very well known problem.

      And Android and ADB sometimes have issues with large backups of directories, and so you have to manage that with tar + stream and other business, but at least working around that is easy.

      But if you could backup individual apps and all their data, you could uninstall all your privacy laden stuff, cross the border, and reinstall in minutes.

      That's the true, legal way to travel safely. Especially if the app removal resulted in a 'shred' of the data files instead of delete.

      If anyone has ever struggled with large data backup/restore, here's the only real method I've found for copying large swaths of files from/to via adb:

        adb exec-out 'tar --dereference --create /storage/emulated/0/dir/  2>/sdcard/backup-errors.txt' |dd of=/tmp/backup-$(date +%Y%m%d).tar && adb shell cat /sdcard/backup-errors.txt
      

      and to restore

        dd if=backup-20250309.tar | \
        adb exec-in 'cd /storage/emulated/0/tempdir; tar xpvf -  2>/sdcard/restore-errors.txt' && \
        adb shell cat /sdcard/restore-errors.txt
      

      Or something similar.

      4 replies →

My friends from the German CCC are mostly like (1) do not travel to the US and (2) if you absolutely must, travel with an empty device with decoy data and download all data you need once you're there.

Tell me if I'm wrong but it seems that if you cross borders a lot the solution is straightforward. Have a second set of disposable devices for out of country usage with nothing but a VPN to virtual desktop. Give them the password and your mailing address to return when they are done, or just consider it abandoned?

Can they force you to log into another remote computer in another country to examine it? I'm not discussing politics, simply the solution that you can actually do now side of things.

I don't have any hope of this situation improving globally and my gut says it will get much worse over time. I wonder if in the future you will have to not only give them your computer but have some sort of follow up investigation of your "real" computer if you do this two device method.

> The big picture problem is that the agents performing the searches have an enormous amount of power in terms of potentially seizing devices and potentially denying entry for non-citizens. I think they should not have this power, but the agents and courts probably don't care that I think that.

That's the reason I never traveled to the US and never will, just having IT security in your CV is enough to make the border gamble not worth it

  • Note that border searches of electronic devices are extremely rare overall. There were some statistics from CBP implying a base rate lower than 1 in 10,000 (I think lower than 1 in 100,000) border crossings.

    I do know two people who have experienced them as a result of the government taking a personal interest in them, so it's certainly not impossible. However, it's not a common experience.

    I've personally experienced searches of my suitcases about four times in about 100 U.S. border crossings (as a U.S. citizen, but the people performing or directing those searches generally didn't know my citizenship status), and zero electronic device searches.

    • I'm European and I know plenty, albeit the minority of those I know that went to the US, so I wonder how reliable are CBP stats.

      Maybe my anecdotal experience is influenced by me being in IT, but still.

    • But why would that be legal? The device is owned by the individual. No judge signed any warrant search for the device. I can do what I want with my device - that is a basic right of property. Imagine if border guards seize money willy-nilly.

      6 replies →

  • It's also quite surprising that all socials need to be declared. And presumably them AI vetted in time for you to get to the border.

    • This part is pretty new. I wonder if my former colleagues have done any FOIA work looking into how travelers' disclosed social media accounts have been reviewed or analyzed!

    • You also have to provide every single email account you have used in the last ten years, all of them, forgetting to declare one is an offense.

      There's no chances I can remember them all, especially as I've been contracting and get a new email every 3-4 months or so.

    • It's reasonable for a country to want to know if you're likely to abuse your visa.

      Eg your socials might show you are a professional paid speaker at conferences. If you applied for a tourist visa that would be reasonable to flag you and ask you if you have paid gigs on the wrong visa.

      Europe will also ask the same questions for foreigners. If you're a young woman travelling on your own you can expect questions to challenge if you might be earning money as a nanny on a visitor visa. Checking their phone messages to see if they've been making arrangements to this effect is a very straightforward way to determine intent.

      Not everything is an evil conspiracy.

Just don't travel to the US.

  • This is an increasingly popular solution. Foreign tourism has crashed.

    I love the geography of the US, and it has some truly stunning places to visit.

    But they're not so stunning that I need to risk my freedom - risk my freedom - to visit them in person.

  • This person is a US citizen. What happens if he just said nothing (beyond identifying and answering basic questions) and refused to cooperate? How long could they hold him? As a citizen they have to allow him to enter eventually.

    According to the ACLU I think this person would have been better off saying little and not wiping their phone.

    https://www.aclu.org/know-your-rights/what-do-when-encounter...

    • And they would have taken his phone, pulled it apart and cloned the memory to get the data. And in a month or three, returned his phone to him in some condition which may or may not include "working".

      1 reply →

    • I've done that and they held me for about a day, strip and cavity searched me, imprisoned me, "diesel therapy" me across the state while taking me to multiple private ER claiming there were drugs up my ass to run up hospital bills in my name. They've also threatened to revoke my passport or deny me entry to the country (both failed).

      They also would not allow me access to a lawyer during questioning or imprisonment.

      Another woman was at the same port of entry, was raped to "check for drugs", sued, and lost. Apparently raping is a legal way to search for drugs (that were not there).

  • This. If any country won't treat you like a guest, avoid travelling to it.

    If it's your own, that's harder to do – time to fight and change the system before it gets worse and will swallow you whole.

I'm sharing this experience just to share, not suggesting or making any claims about what people should do with it:

One of the best ways to get through airport CBP quickly without being overly hassled is to be overtly, clearly sick in a gross way. If you're about to vomit or have horrible diarrhea, they do not want you in that line any longer than you have to be. If they're the type to want to take people down a peg, they won't bother with you because they're already miserable, and if they like picking on the weak, they're probably going to go for a solo young female traveler who isn't ill.

Nobody wants to risk getting vomit on their clothes or in their work area, having to close a line and shuffle people around while their coworkers glare daggers, or subject themselves or their coworkers to the very fun smells of human bodily fluids.

At the same time, it isn't purposeful so it's not read as malicious.

Maybe the actual solution is traveling with burner devices when you are concerned with border checks?

Like, get a cheap phone, install the bare minimum stuff you need for travel.

For extra safety, before returning home wipe it and just put back the exact apps you need for moving around (e.g.: ride hailing app).

Same thing with laptops, tablets, etc.

This is one of the reasons I also won't ever go to the US again.

While most of my Italian/Polish friends had 0 issues, on a handful of occasions people were stopped and questioned for hours with agents pretending full access to every single device and just overall treating you as criminals.

In one occasion a friend of mine stated that he was quite sure they just enjoyed that kind of sweeping power and it had nothing to do with border security, it was just fun to them.

In another one, the suspicion was on the fact that this person did not have socials, he just disliked them and had nothing except a Google account for Youtube. This fact made them super suspicious and the person was stuck at La Guardia for 3 hours, even his body was inspected. Disgusting.

> ... you may have to think both about protecting your data by technical means, ...

I thought about that. And I came to the conclusion that a phone is a pathetically bad device to both store your data and to access your data. Mediocre screen. Mediocre input methods. Moreover most phones happen to also be spying device.

So if you think about "protecting your data", a reasonable idea is that a lot of data is way better kept on your homelab, with say encrypted backups in a safe at the bank, at a relative's place, on a server you rent, etc., rather than on your phone. And there's really little need to access your data from your phone.

Oh and I'm no luddite: I've got a homelab, I rent servers, I pay three AI subscriptions, etc.

But my phone is boring. There's no app on it besides the stock ones (say Google Maps) and then I added the Google Authenticator app (for stuff still using that kind of 2FA).

If people were to wake up and stop being glued to that mediocre thing, the problem would already be 99% solved.