← Back to context

Comment by pkulak

3 hours ago

I think it's enough to shut down you phone. Then it needs a pin, and you're entitled to not give that over, I believe. So you should be safe, apart from some kind of rubber-hose cryptanalysis.

> So you should be safe, apart from some kind of rubber-hose cryptanalysis.

There are vendors that sell the technology to adversarially access phone data, the "Before First Unlock" is the safest state a phone can be, but it's not infallible. The safest option is to have a burner or factory-reset phone with nothing on it, even if the hack succeeds.

  • I've worked with Cellebrite, the industry standard in IT forensics for unlocking and imaging phones. It just runs a series of known exploits. PIN lock, data encryption and regular updates will beat it most of the time.

    • > I've worked with Cellebrite

      Any chance you want to do a public service and publish the latest compatibility matrix?

      Just joking, obviously…

  • Before First Unlock with recent hardware and an up to date OS is probably sufficiently infallible for an average person. I wouldn't want to rely on it if I was engaged in espionage, but for someone who won't get the NSA pulled into the case, I'd be pretty confident. This leaked Cellebrite support matrix shows that BFU was secure against them for iPhones that were nearly four years old at the time, and I doubt it's become significantly worse since then: https://ia800405.us.archive.org/32/items/inseyets-offline-uf...

> Then it needs a pin

A compromise to this is that many phones have a "lockdown" mode, where it isn't fully off but refuses to accept biometrics until a code/pattern is used to bring it to a more day-to-day mode.

It's less-secure than being fully off, but it also means if you do need to access your phone you can do so more-quickly.

If you don't give a pin, they can seize your devices (Andrew Tate on his 1st visit to Florida said that he refused to give pin and they seized phone and laptop)

  • They can't keep them, you'll get the devices back. Use a temp phone in the mean time.

    Sad that we have to accept this as a risk of international travel, but here we are.

    • They can absolutely keep them. Or they can just "lose" them "accidentally". Who exactly would force them to give them back? Or put another way, who exactly will punish them if they break the law?

      3 replies →

  • I'll take that risk. It's pretty unlikely, and if it happens, having to buy a new phone is not the worst thing in the world.

If you’re a U.S. citizen: CBP cannot deny you entry to the United States merely because you refuse to unlock the phone. If you’re a non-citizen seeking admission: refusal is much riskier.

The important wrinkle is that CBP’s published policy expressly guarantees that a person being admitted as a U.S. citizen won’t be denied entry solely because CBP couldn’t inspect the device. It doesn’t give lawful permanent resident (green card holders) that same explicit statement. Instead, it says refusal by a “foreign national” can be considered in an admissibility determination.

  • this only applies if they don't refuse to acknowledge your papers as valid and/or they haven't previously put you on some hidden list of people of interest, in which case the instance where you get to prove you're who you say you are will be mediated, like the rest of the (as per the current system) nonpeople, by as many layers of humilliation and risk to your life and health as they can place.