I’ll never bring my phone on an international flight again. Neither should you
21–30 of 118 posts
Re: I’ll never bring my phone on an international flight again. Neither should you
#22The article claims that they can hold you indefinitely if you do not turn over your password. What could happen if I smashed my phone?
If you don't cooperate, they don't have to let you into the country. They can simply tell you to turn around and go somewhere else.
Re: I’ll never bring my phone on an international flight again. Neither should you
#23Earlier quoted context omitted.
If you have 2FA then some of those accounts may not be accessible without your phone. For instance, if I didn't bring my phone with me (which I use to authenticate) I wouldn't even be able to log in to my email. Or, taken a little further, I don't even know my email password anyways. Its locked in a password manager which requires 2FA. I would myself be locked out of almost all of my accounts if I didn't bring my pho…
And that makes resetting it a non-starter too doesn't it?
But this also raises the question of them believing me that I can't login because I don't know my password.
Re: I’ll never bring my phone on an international flight again. Neither should you
#24From the article (emphasis mine): > This may upset Customs and Border Patrol agents, who are probably smart enough to realize that 85% of Americans now have smart phones, and probably 100% of the Americans who travel internationally have smart phones. They may choose to detain you anyway, and force you to give them passwords to various accounts manually. But there’s no easy way for them to know which services you use…
You can always claim that you don't know the password because you use an offline password manager that you don't have with you. Also, use 2 factor authentication of course.
Re: I’ll never bring my phone on an international flight again. Neither should you
#25I wonder how possible it would be to create a jailed environment on Android or iOS that can not access any of the data on your phone and could be entered by putting in a false password. That would allow you to enter your "password" on-demand and then only present a jailed process to those seeking to violate your privacy. It could appear to be a full experience, but not actually contain any personal data, or contain f…
Re: I’ll never bring my phone on an international flight again. Neither should you
#26"It’s totally legal for a US Customs and Border Patrol officer to ask you to unlock your phone and hand it over to them. And they can detain you indefinitely if you don’t. Even if you’re a American citizen. [...] Barring the use of “excessive force,” agents can do whatever they want to you."
and
"[I]t’s illegal in most countries to profile individual travelers"
I don't think any of these things is accurate. Although courts have been extraordinarily deferential to customs authorities, they've also ruled that many things done in the name of border enforcement were unreasonable!
Fortunately I'm working with some lawyers on a new version of a border search guide, so hopefully we can get some informed legal information out there.
Re: I’ll never bring my phone on an international flight again. Neither should you
#27I wonder how possible it would be to create a jailed environment on Android or iOS that can not access any of the data on your phone and could be entered by putting in a false password. That would allow you to enter your "password" on-demand and then only present a jailed process to those seeking to violate your privacy. It could appear to be a full experience, but not actually contain any personal data, or contain f…
Re: I’ll never bring my phone on an international flight again. Neither should you
#28Re: I’ll never bring my phone on an international flight again. Neither should you
#29From the article (emphasis mine): > This may upset Customs and Border Patrol agents, who are probably smart enough to realize that 85% of Americans now have smart phones, and probably 100% of the Americans who travel internationally have smart phones. They may choose to detain you anyway, and force you to give them passwords to various accounts manually. But there’s no easy way for them to know which services you use…
things the government knows, and things that a CBP agent knows, are not the same thing. They NSA doesn't just provide their database to all the hundreds of thousands of front-line law enforcement agents. If you're being specifically targeted for some reason, enforcement agencies might be provided with a history of your social media activity, but it's unlikely that they can just pull it up when they type in your drivers license number.
Re: I’ll never bring my phone on an international flight again. Neither should you
#30I wonder how possible it would be to create a jailed environment on Android or iOS that can not access any of the data on your phone and could be entered by putting in a false password. That would allow you to enter your "password" on-demand and then only present a jailed process to those seeking to violate your privacy. It could appear to be a full experience, but not actually contain any personal data, or contain f…
Why would it be illegal? They told you to put in your password, and you put in one of your passwords. If they want to fuck with technology and they're too stupid to understand it, that's their loss.
The best you can do is make the process as frictionless as possible for the border thugs, to get them to mislead themselves. For instance, imagine encrypted steganographic storage that seamlessly unlocks with a key retrieved from a remote server. If a GPS fix says you're in a dangerous area (eg border crossing), the server only unlocks the uninteresting bits [0]. A connection from your home network and/or designated third party is then required to switch the server's mode back to supplying full functionality.
And this needs to become the default mode of operation for a sizable chunk of phones, so that the "intent" bullshit becomes inapplicable. This is how the legal system works - you can only obtain safety through technical means en masse. Yes, we have a long hill to climb.
[0] Obviously this is trusting the phone and could be spoofed, but this isn't the threat model. The point is to make the behavior change passively.