Live data from Hacker News

How to lock down your phone if you're traveling to the U.S.

washingtonpost.com

251–260 of 363 posts

Re: How to lock down your phone if you're traveling to the U.S.

#252
post #226

Earlier quoted context omitted.

As things currently stand, this wouldn't qualify for denaturalization. Even the Trump proposals have been to do it for fraudulently obtaining citizenship (e.g. lying about a criminal record), not general crimes, and certainly not for non-crimes like annoying CBP. But next week it could all be different.

> fraudulently obtaining citizenship It seems like they are claiming that “not saying you intended to protest” is essentially lying on the initial visa application, thus fraud and grounds for revocation of residence and deportation So, if CBP confiscated someone’s laptop or phone (because they don’t want to unlock it), then break into it, and find social media posts against genocide, and/or against the Trump administ…

I'm deeply displeased with their treatment of legal residents here, but denaturalizing a citizen is about a million times more severe than deporting a legal resident alien. The executive has pretty much unlimited authority to decide which non-citizens are allowed to enter or stay within the country, and has for a long time, whereas that's not the case with denaturalization.

Re: How to lock down your phone if you're traveling to the U.S.

#253
post #226

Earlier quoted context omitted.

> fraudulently obtaining citizenship It seems like they are claiming that “not saying you intended to protest” is essentially lying on the initial visa application, thus fraud and grounds for revocation of residence and deportation So, if CBP confiscated someone’s laptop or phone (because they don’t want to unlock it), then break into it, and find social media posts against genocide, and/or against the Trump administ…

I'm deeply displeased with their treatment of legal residents here, but denaturalizing a citizen is about a million times more severe than deporting a legal resident alien. The executive has pretty much unlimited authority to decide which non-citizens are allowed to enter or stay within the country, and has for a long time, whereas that's not the case with denaturalization.

Does knowingly blowing up a citizen with a drone count as denaturalization?

Re: How to lock down your phone if you're traveling to the U.S.

#254

Ignoring the US political situation for a moment I want to point out how ridiculous modern phones and apps storage access given to their users is. You used to be able to mount a phone as a full hard drive and have access to all your files, do a real full backup without some encrypted databases that only facebook, google or apple hold the key for. The first tragedy is that we accepted that the US gives no rights to no…

This is an issue I face- I have a collection of thermal cameras that use apps to control them- after every install onto a phone, they then reach out t oa server to authenticate.

Here's the issue- though I have a few older phones- these apps are 32 bit ones, so no modern phone after Android 13 will run them. And they are all now not on the app store anymore,as they all came out about around 2016. i did use a APK extractor to pull the APKs to store them - but the native backup functionality wouldn't capture that authorization in the future, I might rob myself of my ability to use some extremely expensive, and long-term invested capable hardware, by backing up and restoring-

I suspect a full image would solve this problem, but I don't think one can do that outside of things like TWRP- but that requires unlocking the bootloader, and if you do that it wipes your device- AND is more vulnerable to Custom's usage of Cellebrite and etc, to my undertanding.

I don't have this issue with laptops ,as I can fully image them and wipe and restore ahavend have a perfect replica/ no issues. But my thermal cameras do not run off of PC and th eform factor wouldn't work if they did

Re: How to lock down your phone if you're traveling to the U.S.

#255
post #4

"Locking down" is almost always a bad approach when it comes to border crossings. You have very little rights at the border, so keeping your phone locked and refusing to divulge the 20 characters password isn't really an option. Even without the threat of detaining you, they can refuse entry (if you're not a citizen/permanent resident), or seize your $1000 phone/laptop. Far better to wipe your phone and restore from…

I used to do this but these days I’m petrified of the restore being imperfect in some way. I use the he.net app for TOTP. Will I get those back in working order? I have a billion photos I want to keep — were they properly backed up to iCloud? My mail settings are a pita to recreate. Will those come back? Are passwords stored in the Secure Enclave? Could I lose those? When I sign back into iCloud am I going to be able…

I am in a similar pickle.

This is an issue I face- I have a collection of thermal cameras that use apps to control them- after every install onto a phone, they then reach out t oa server to authenticate.

Here's the issue- though I have a few older phones- these apps are 32 bit ones, so no modern phone after Android 13 will run them. And they are all now not on the app store anymore,as they all came out about around 2016. i did use a APK extractor to pull the APKs to store them - but the native backup functionality wouldn't capture that authorization in the future, I might rob myself of my ability to use some extremely expensive, and long-term invested capable hardware, by backing up and restoring-

I suspect a full image would solve this problem, but I don't think one can do that outside of things like TWRP- but that requires unlocking the bootloader, and if you do that it wipes your device- AND is more vulnerable to Custom's usage of Cellebrite and etc, to my undertanding.

I don't have this issue with laptops ,as I can fully image them and wipe and restore ahavend have a perfect replica/ no issues. But my thermal cameras do not run off of PC and th eform factor wouldn't work if they did

Re: How to lock down your phone if you're traveling to the U.S.

#256
post #247

Earlier quoted context omitted.

Having your $1000 device stolen by the government as an acceptable outcome is something only a fatcat on HN with their cushy salary would be able to tolerate. I'm not a FAANG employee, and don't make that kind of salary. Loosing a $1k anything would not be something I could just shrug my shoulders and just turn around and immediately replace it. Even if you do sue the gov't, it'll be at least a year before any kind o…

My Lenovo from last year still has non-soldered NVMe drives. I would probably just install Windows on a separate partition and set it to boot to that, then install a few games and set my Chrome homepage. I bet CBP won't be mucking around with bootloader settings looking for Linux, and even so it would be pretty trivial to just remove GRUB from the EFI partition for the travel days.

This is something no on discusses but I've wondered heavily- GRUB can be made to not show a menu and then boot up Windows automatically, in like a second or two with no one the wiser. [There is an obnoxious welcome to grub message that pops up now but I see a public project out there that solves this very easily called GRUB shusher]

I don't know if other bootloaders outside GRUB have a silent/hidden start option, as well in a similar vein that would require you to hit a key in that first second to get the menu to appear, or else it just boots up normally

I wonder about the other approach, just going into the BIOS nad changing the order so Windows boots first, which should be doable in some setups. Lock the BIOS with a password, and you're in not bad shape. (Not sure if Secure Boot being enabled could also help here - probably couldn't hurt)

Re: How to lock down your phone if you're traveling to the U.S.

#257

I've often wondered if there's a supported way to have a honeypot passcode, i.e., a secondary passcode that leads to a relatively empty account. (Although as per the article, a fully wiped account looks suspicious -- it would need some innocuous apps or apps with no login info, etc.)

Truecrypt supported this decades ago, obviously not a full phone OS though.

Veracrypt. It's successor, keeps this feature - of allowing for a truly hidden OS- but there's a HUGE flaw everyone missed- it requires your laptop to be setup as MBR-= which only allows for 4 partitions, and you can't have more than like 2 TB of filespace on it total.

We need a similar solution for UEFI- that allows for truly hidden, foolproof hidden OS installs.

Re: How to lock down your phone if you're traveling to the U.S.

#258
post #244

I wish Android had a better backup story. If you're using iOS, it's as simple as the article describes. If you use even modern Android on modern Pixel, backup only includes a fraction of what you need to recover. Things like Signal keys, 2FA tokens, and more were not included in my last backup. GrapheneOS had an opportunity to do this 1000% better... and they instead ship a kinda broken fork of SeedVault, which they…

This annoys me to no end and is a serious problem in my own use cases...

This is an issue I face- I have a collection of thermal cameras that use apps to control them- after every install onto a phone, they then reach out t oa server to authenticate.

Here's the issue- though I have a few older phones- these apps are 32 bit ones, so no modern phone after Android 13 will run them. And they are all now not on the app store anymore,as they all came out about around 2016. i did use a APK extractor to pull the APKs to store them - but the native backup functionality wouldn't capture that authorization in the future, I might rob myself of my ability to use some extremely expensive, and long-term invested capable hardware, by backing up and restoring-

I suspect a full image would solve this problem, but I don't think one can do that outside of things like TWRP- but that requires unlocking the bootloader, and if you do that it wipes your device- AND is more vulnerable to Custom's usage of Cellebrite and etc, to my undertanding.

I don't have this issue with laptops ,as I can fully image them and wipe and restore ahavend have a perfect replica/ no issues. But my thermal cameras do not run off of PC and th eform factor wouldn't work if they did

Re: How to lock down your phone if you're traveling to the U.S.

#259

Earlier quoted context omitted.

So did I - and I kinda liked the place (not the border police, it seemed as if they hated me and hated the fact that I was coming to spend money there).

CBP hates everybody, citizen and non-citizen alike.

Agreed. As a citizen, most interactions with border control are unpleasant. The only positive experience I've ever had was at a quiet border crossing in Maine where I met what was probably the country's only friendly CBP agent.

Re: How to lock down your phone if you're traveling to the U.S.

#260
Does obtaining Global Entry minimize the chance of them deciding to harass a citizen crossing the border, I wonder? It is at the cost of your biometric - but data on your devices might be worth more, and as I note elsewhere in this thread, you can image a computer and back it up fully, but not a phone without some data loss, unfortunately. [ TWRP possibly can do it right perhaps, but it requires unlocking the bootloader (which wipes the phone), and once bootloader is unlocked, it's more vulnerable to Cellebrite and company, to my understanding, ]

seeing the latest (leaked?) Cellebrite info from 2024 Summer- BFU State[Before First Unlock state] after posting on, modernimoPuxelsiPhones on the latest OS, and graphene devices see moto be the hardest to get into.

Anyway- , with computers - this was a solved problem from a technical standpoint- Yes I'm talking Truecrypt then, and today Veracrypt. The Hidden Container feature is impressive- but the Hidden OS feature allows for a truly hidden OS behind the scenes that can't be found at all. However, there's a unfortunate weakness that makes this hard to use today- it's limited to MBR , not UEFI [GPT]systems- so unless you like your computer not being able to have more than 2 Tb - and only 4 partitions (so good luck If you do a lot of stuff from dualbooting to other whatnot) We need a Veracrypt Hidden OS equivalent for UEFI systems that's truly undetectable.(That also will work for Linux and maybemeMac not just Windows as Veracrypt currently does - you can only make the Hidden Volumes on the non Windows versions of VC) There was one project to do it - and there were articles and a black hat presentation on 'Russian Doll Steganogrpahy" for a OS- but it didn't go anywhere from what I can tell, and everyone is now wide open .... Unless you have a MBR system. I also think I've heard UEFI is more easily secured than MBR in general and for the foreseeable future...

https://portswigger.net/daily-swig/russian-doll-steganograph...

https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Schaub-Perfectl...

Post reply on HN