Live data from Hacker News

How to lock down your phone if you're traveling to the U.S.

washingtonpost.com

11–20 of 363 posts

Re: How to lock down your phone if you're traveling to the U.S.

#11
post #4

"Locking down" is almost always a bad approach when it comes to border crossings. You have very little rights at the border, so keeping your phone locked and refusing to divulge the 20 characters password isn't really an option. Even without the threat of detaining you, they can refuse entry (if you're not a citizen/permanent resident), or seize your $1000 phone/laptop. Far better to wipe your phone and restore from…

And maybe remove business critical or private data from "well known" online accounts or cloud services well known to US or from US or the one they might force you to give them access to - or the account where it might be trivial for them to show you have an account and then they might demand access. I know the article says they won't ask you for cloud accounts but I mean who the hell knows (esp. in today's USA), they might as well ask you to give access to iCloud Backup/restore because as you said they have close to or exactly zero rights there.

Re: How to lock down your phone if you're traveling to the U.S.

#13
I've often wondered if there's a supported way to have a honeypot passcode, i.e., a secondary passcode that leads to a relatively empty account.

(Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)

Re: How to lock down your phone if you're traveling to the U.S.

#14
The US is hardly the only country where this is the case and locking down your phone is almost entirely pointless (see xkcd #538).

If you're concerned about having it searched, don't bring your primary phone. Go to a phone shop, buy an old phone, put your SIM card in it, and use that instead.

Re: How to lock down your phone if you're traveling to the U.S.

#16

I've often wondered if there's a supported way to have a honeypot passcode, i.e., a secondary passcode that leads to a relatively empty account. (Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)

Most android phones I use provide an option to wipe the device if the wrong passcode is entered too many times.

There was a lot of talk about duress passcodes several years ago, but I don't think any phones ever got it. Sure would be nice to have

Re: How to lock down your phone if you're traveling to the U.S.

#17

I've often wondered if there's a supported way to have a honeypot passcode, i.e., a secondary passcode that leads to a relatively empty account. (Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)

Certainly doable, grapheneOS has it https://grapheneos.org/features#duress.

Re: How to lock down your phone if you're traveling to the U.S.

#18

I've often wondered if there's a supported way to have a honeypot passcode, i.e., a secondary passcode that leads to a relatively empty account. (Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)

This would be useful beyond getting in and out of customs too. For instance, most people don't want to carry around a work phone and a personal phone, so we end up mixing two personas on one device, and it gets awful. For instance I keep two 2fa apps, one for work stuff and one for personal stuff. It would be so much easier if I could have a separate login that showed just my work apps. Like ... wouldn't it be nice to only have to see work slacks when you log in using a work persona?

Re: How to lock down your phone if you're traveling to the U.S.

#20

I've often wondered if there's a supported way to have a honeypot passcode, i.e., a secondary passcode that leads to a relatively empty account. (Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)

[dead]
Post reply on HN