Live data from Hacker News

How to lock down your phone if you're traveling to the U.S.

washingtonpost.com

21–30 of 363 posts

Re: How to lock down your phone if you're traveling to the U.S.

#21
This article is a nice reminder that free speech is awesome.

Also, it is terribly unhelpful and uninformative.

Schneier’s blog post on this has tons of useful information in the comments: https://www.schneier.com/blog/archives/2025/04/cell-phone-op...

The EFF wrote the canonical guide to this in 2017: https://www.eff.org/wp/digital-privacy-us-border-2017. I don’t know if it has been updated, but there is a lot that’s useful there.

I think the main thing to decide ahead of time is: will you unlock a phone on request, or are you willing to lose the powered-down phone or be denied entry if you refuse? Most of your decisions flow from there.

If unlocked and it leaves your sight, ALL your messages and photos and documents will be stored forever and are available warrantless in probably every country in the world.

Re: How to lock down your phone if you're traveling to the U.S.

#22
post #5

I'm just not going to go to the US frankly. Only reason I would is tourism, and I like my vacations harassment & risk of detainment free

I stopped going when they introduced fingerprinting. This is not just a point of principle. While it is not known whether fingerprints are unique (as is often claimed), it is known that the information that is stored about fingerprints and which is used as the basis for matching records is not unique. The equivalent of hash collisions exist. Fingerprints are great as corroborative evidence, but if they are used as the means to find a suspect, you don't want your fingerprints in the system when Cletus Thugfester (the actual perpetrator) has matching prints that are not in the system. Far too likely that you'd get hauled across the Atlantic on this basis, then have to deal with the "justice" system over there.

Re: How to lock down your phone if you're traveling to the U.S.

#23

I've often wondered if there's a supported way to have a honeypot passcode, i.e., a secondary passcode that leads to a relatively empty account. (Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)

Certainly doable, grapheneOS has it https://grapheneos.org/features#duress .

[dead]

Re: How to lock down your phone if you're traveling to the U.S.

#24

I've often wondered if there's a supported way to have a honeypot passcode, i.e., a secondary passcode that leads to a relatively empty account. (Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)

Most android phones I use provide an option to wipe the device if the wrong passcode is entered too many times. There was a lot of talk about duress passcodes several years ago, but I don't think any phones ever got it. Sure would be nice to have

GrapheneOS has the duress password feature [1]. I have it enabled, but have never needed to use it.

[1] https://grapheneos.org/features#duress

Re: How to lock down your phone if you're traveling to the U.S.

#27

I've often wondered if there's a supported way to have a honeypot passcode, i.e., a secondary passcode that leads to a relatively empty account. (Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)

Yes, a duress account would be highly needed in these times. I'd even go as a whole partition and the whole thing enclaved so it's nearly impossible to know if there's another partition.

Re: How to lock down your phone if you're traveling to the U.S.

#29
post #18

I've often wondered if there's a supported way to have a honeypot passcode, i.e., a secondary passcode that leads to a relatively empty account. (Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)

This would be useful beyond getting in and out of customs too. For instance, most people don't want to carry around a work phone and a personal phone, so we end up mixing two personas on one device, and it gets awful. For instance I keep two 2fa apps, one for work stuff and one for personal stuff. It would be so much easier if I could have a separate login that showed just my work apps. Like ... wouldn't it be nice t…

Recent enough Androids have this "Work Profile" feature. You get two app stores, and work apps get little "work" overlay. There are separate lock settings and sound/notification settings for work profiles too - I think this means you can have simple pincode for personal stuff and more complex for work one. And you can turn off all work apps at once with a single button press. And if your admin gives "remote wipe" command, only work apps are wiped.

Sadly this is automatic, which means regular people can't use it. You workspace admin got to enable MDM, and then phone will prompt you if you want a work profile when you try to install it.

Re: How to lock down your phone if you're traveling to the U.S.

#30
post #18

I've often wondered if there's a supported way to have a honeypot passcode, i.e., a secondary passcode that leads to a relatively empty account. (Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)

This would be useful beyond getting in and out of customs too. For instance, most people don't want to carry around a work phone and a personal phone, so we end up mixing two personas on one device, and it gets awful. For instance I keep two 2fa apps, one for work stuff and one for personal stuff. It would be so much easier if I could have a separate login that showed just my work apps. Like ... wouldn't it be nice t…

This is built into Android as Work Profiles.
Post reply on HN