← Back to context

Comment by throwawayffffas

5 hours ago

There are 2 cases routine inspections and targeted investigations.

If it's a routine inspection, being uncooperative will probably lead them to escalate. You generally want to keep things routine and boring. If they want to access your device you have to weigh the costs, just log out of everything before you fly and throw away your device after they have had access to it, it's now compromised.

If you are targeted your compliance is irrelevant and only weakens your position, the thing is at the border you don't get all of the protections you get at say a traffic stop they can search everything you have on you without warrants reasonable suspicion or anything.

I am not a lawyer but if you are a citizen they probably can't deny you entry but can probably detain you for an uncomfortable amount of time, and seize whatever they want. Your best defense is to have a burner phone and no other devices nothing they can seize that would hurt you.

For foreign nationals pretty much the same applies except they can deny you entry and ship you off to alligator Alcatraz, just don't fly to America for a few years.

Remember he is not being prosecuted for not handing over his device but for destroying the data they were trying to seize, if he just let them keep the phone he would be Scott free. I.e.the best technical defense is secure encryption with a key thats long enough and not stored on the device.

Actually for the particular case the best technical defense is to not have any data whatsoever on you.

> I am not a lawyer but if you are a citizen they probably can't deny you entry but can probably detain you for an uncomfortable amount of time, and seize whatever they want. Your best defense is to have a burner phone and no other devices nothing they can seize that would hurt you.

Even having a burner phone without any personal information on it can be deemed suspicious. It would be best for your phone to have a recently-reinstalled OS, with a few critical apps like Whatsapp or iMessage set up with a few personal messages sent. You need to be able to set those up without a password manager. Anything else needs to take place on devices that you aren't carrying with you. Fortunately enough people don't update their Facebook these days that just having an account that exists but you don't use will probably work, assuming you don't look like someone that would be obsessed with their socials.

Maybe there are USB thumb drives that operate like a YubiKey unless special setup is performed to access the storage inside? That's one way to carry data with you if you have to.

  • You can offer the I don't travel with my real phone because it got stolen a bunch of times excuse.

    The point is even if they become suspicious all they can do is seize the burner ask you a bunch of questions etc. search you, etc they can't get access to your data. You can't get in real trouble, just majorly inconvenienced.

    • You "can't get in real trouble" but teh last time I crossed with basically nothing, they wrote a search warrant by literally fabricating almost everything in it. They wrote that an anonymous dog told an unnamed officer I had drugs, then a completely separate HSI officer signed it and a judge signed it based on complete inter-species hearsay two links removed from any named entity to face to question it.

      So yeah you can be imprisoned, brought to ERs while they run up private medical bills (they told doctors I had drugs up my ass), have a search warrant executed, and then at the end of the day be chased by debt collectors for the search that turned up nothing.

      4 replies →

  • Suspicious, maybe; but not criminal (like lying to a federal officer in the course of an investigation, or willfully destroying what they’re lawfully trying to search).

    Probably even more suspicious if you make sketchy excuses when the truth is fine. I’d go with “I (or %COMPANY%) figure electronic devices get imaged at borders or potentially stolen abroad, so we don’t carry them when we travel.” Blame the other country you’re coming from if you want.

    Although I’d just not carry a phone across a border in the first place.

    Related, regarding the “hiding a partition on a thumb drive” thing (8 days ago, 287 / 166; project is cool but note that tptacek and others in the comments know what they’re talking about):

    https://www.usenix.org/system/files/1401_08-12_mickens.pdf

    • Unfortunately I agree with James Mickens. If CBP asks me to turn on and unlock my phone, I do it.

      It is the same advice that cops give to young black men in “the talk”. Comply, don’t get killed, hire a lawyer and fight injustice in court.

      1 reply →

    • >YOU’RE STILL GONNA BE MOSSAD'ED UPON

      Thanks for that, it's been a few years and I'd forgotten about this.

> just log out of everything before you fly and throw away your device after they have had access to it, it's now compromised.

I get what you are saying, but this is incredibly expensive and not really practical for most people.

  • > not really practical for most people

    Evaluate your threat model and the chance that a wipe and reinstall of the OS will be insufficient protection.

    If you were targeted, you may have some tough choices. Might as well think about them ahead of time.