Comment by trollbridge

4 hours ago

U.S. citizens are going to need obtain a burner phone before returning, and load it with the absolute minimum to load boarding passes, etc., perhaps some reading material or a movie to watch on the plane, and be prepared to share full credentials for thing at the border.

(I used to do some travel patterns where taking a certain client laptop wasn’t an option. It was an absolute gigantic pain for the type of work I did, but it was just too risky to have a laptop seized and be expected to input credentials.)

I think it's enough to shut down you phone. Then it needs a pin, and you're entitled to not give that over, I believe. So you should be safe, apart from some kind of rubber-hose cryptanalysis.

  • > So you should be safe, apart from some kind of rubber-hose cryptanalysis.

    There are vendors that sell the technology to adversarially access phone data, the "Before First Unlock" is the safest state a phone can be, but it's not infallible. The safest option is to have a burner or factory-reset phone with nothing on it, even if the hack succeeds.

    • I've worked with Cellebrite, the industry standard in IT forensics for unlocking and imaging phones. It just runs a series of known exploits. PIN lock, data encryption and regular updates will beat it most of the time.

      1 reply →

    • Before First Unlock with recent hardware and an up to date OS is probably sufficiently infallible for an average person. I wouldn't want to rely on it if I was engaged in espionage, but for someone who won't get the NSA pulled into the case, I'd be pretty confident. This leaked Cellebrite support matrix shows that BFU was secure against them for iPhones that were nearly four years old at the time, and I doubt it's become significantly worse since then: https://ia800405.us.archive.org/32/items/inseyets-offline-uf...

  • > Then it needs a pin

    A compromise to this is that many phones have a "lockdown" mode, where it isn't fully off but refuses to accept biometrics until a code/pattern is used to bring it to a more day-to-day mode.

    It's less-secure than being fully off, but it also means if you do need to access your phone you can do so more-quickly.

  • If you don't give a pin, they can seize your devices (Andrew Tate on his 1st visit to Florida said that he refused to give pin and they seized phone and laptop)

    • They can't keep them, you'll get the devices back. Use a temp phone in the mean time.

      Sad that we have to accept this as a risk of international travel, but here we are.

      5 replies →

    • I'll take that risk. It's pretty unlikely, and if it happens, having to buy a new phone is not the worst thing in the world.

  • If you’re a U.S. citizen: CBP cannot deny you entry to the United States merely because you refuse to unlock the phone. If you’re a non-citizen seeking admission: refusal is much riskier.

    The important wrinkle is that CBP’s published policy expressly guarantees that a person being admitted as a U.S. citizen won’t be denied entry solely because CBP couldn’t inspect the device. It doesn’t give lawful permanent resident (green card holders) that same explicit statement. Instead, it says refusal by a “foreign national” can be considered in an admissibility determination.

    • this only applies if they don't refuse to acknowledge your papers as valid and/or they haven't previously put you on some hidden list of people of interest, in which case the instance where you get to prove you're who you say you are will be mediated, like the rest of the (as per the current system) nonpeople, by as many layers of humilliation and risk to your life and health as they can place.

I’ve been asked to hand over my phone when I entered India as a visitor with a valid visa. Yes it was a burner phone. Yes the officer questioned me after seeing only 7 photos in the entire Photos app. It was very obvious that it was a burner phone.

  • Yep, travelling outside your country of origin, expect that your phone/laptop/ect is subject to search. Anything on you is, it's literally stated. Want to push against that? Sure, makes sense, but just carry a burner phone/device and not worry about it. Literally what the US government recommends when traveling to places like China.

Giving up knowledge (password) is something that is typically scrutinized at the border as well. Had he just handed over the phone and the phone had abilities to self destruct if tampered with (e.g too many incorrect pin entries) -- well the gov's case wouldn't been much harder. If they seized property and accidently destroyed the data, then that's on them.

  • You are correct, you have to give up the phone but can't be compelled to give up the password, and you'd get it back some indeterminate amount of time later.

    It's actually been on the books for a while (decades at least) that customs can search you at the border without a warrant even if you are a citizen.

    This case seems to have become a big 'Trump bad' poster child (people are calling the US East Germany in these comments...), but if this exact scenario happened at least in the last two decades (I found an example upholding the searches from 2004) then it would at least be possible to charge them with deleting evidence. Even this probably would have been nothing if he refused to give up his password, not being required to provide a password has been upheld for years. They can seize your phone for some time but I'm unsure on the times they ask and then just let you move on when they find out your a citizen.

As everything on your phone should be backed up, you could just wipe your phone to new.

Then log in with another temp account and use that for border pass etc, and then after border checks log back into your normal account?

leave electronics at home. never take electronics to any airport unless you don't care if everything is read. your only option now.

or have a good enough decoy or encryption system in place. Such as pressing a button to lock or replace key documents but keep the rest intact. So what looks like a sensitive document omits key information but still appears to be legit to observer.

  • That's probably a bit overkill. TSA doesn't have nearly as much power as CBP, so it's only a concern when coming back across the international border.