Live data from Hacker News

How to lock down your phone if you're traveling to the U.S.

washingtonpost.com

281–290 of 363 posts

Re: How to lock down your phone if you're traveling to the U.S.

#281
post #104

Even Arab dictatorships don't search phones on entry. What's happening here?

Where did you get that idea? First one I picked to look up (Saudi Arabia) does, and I guarantee all the rest do as well

https://travel.state.gov/content/travel/en/international-tra...

Re: How to lock down your phone if you're traveling to the U.S.

#283

Earlier quoted context omitted.

Same. I wish I had visited the US back in the days, especially pre-9/11 times when flying was super hassle free and people were optimistic about the future. Sadly I was still quite young. Oh well, there are many other beautiful countries in the Americas. And especially south-America is substantially cheaper.

My family has a large bottle of wine my mother took from Italy to New York in the 90s. Wild how the times change.

That hasn't changed, they could still bring a bottle back if they choose

Re: How to lock down your phone if you're traveling to the U.S.

#284

Earlier quoted context omitted.

This 100x, last time I crossed a border I shutdown my phone and because my phone was off the border guard considered that suspicious. Also apparently not using google maps is considered suspicious even if you're in an area you've lived your entire life.

I would definitely come across as suspicious to any border inspection. I have no Google apps, I have no social media apps. I have very few apps at all. I definitely qualify as someone that would be the type to wipe their phone. Also, my photos would definitely look like something someone staged to show activity, as the vast majority of my photos are of my fur babies. I don't do selfies, so that would be sus too. My b…

Someone needs to implement an application that fakes these things convincingly...

Re: How to lock down your phone if you're traveling to the U.S.

#285
post #114

Earlier quoted context omitted.

> refusing to divulge the 20 characters password isn't really an option > wipe your phone and restore from backup If they can compel you to divulge the password, then they can compel you to restore from backup in front of them.

I think their point is that you have plausible deniability because they wouldn't know you have a backup.

Except they might know that if it's a major provider. That's easier to learn than the password to unlock it.

Re: How to lock down your phone if you're traveling to the U.S.

#286
post #248
post #237

Earlier quoted context omitted.

China is not on the list. We never had any difficulty or problem in the Chinese border.

Oh interesting. They were on our list (US company). In fact, our official guidance suggested not bringing work hardware to China at all.

That's mostly not due to their border security services but industrial espionage, theft and maybe special security.

Re: How to lock down your phone if you're traveling to the U.S.

#287

Earlier quoted context omitted.

> Far better to wipe your phone and restore from backup after you've crossed the border. It’s a mantra but it’s incorrect: You’re supposed to list your “online accounts” to the border agent in the US.

don't have your backup online

Sure you can, don't have it on any "account". :)

Re: How to lock down your phone if you're traveling to the U.S.

#288

Earlier quoted context omitted.

Certainly doable, grapheneOS has it https://grapheneos.org/features#duress .

I really want to respond to the dead comment under this. Setting a duress password is not tedious. AFAIK the justification for them to say "don't rely on adblockers for security/privacy" is that you can be more easily fingerprinted and those adblock lists are a moving target, vs. having better sandbox capabilities in the browser. The rest is conjecture I don't have the motivation to debate at the moment. As for the r…

More easily fingerprinted by which blocked script or request? (Personally I prefer a whitelist on these.)

If they rely on phoning home, such as a comparison of requests on different access, that's some top notch log analysis. Expensive too, compared to just running JS.

Re: How to lock down your phone if you're traveling to the U.S.

#289
post #24

Earlier quoted context omitted.

GrapheneOS has the duress password feature [1]. I have it enabled, but have never needed to use it. [1] https://grapheneos.org/features#duress

A duress password that booted into an innocuous "safe mode" without access to your full browser and chat history would be a whole lot less likely to get you into more trouble than one which wipes the phone...

Unfortunately your phone may get backdoored in that scenario anyway if it's known to have that feature. In graphene and most Android phones with unlocked flashing, easily achieved in a few minutes. (Special recovery. It's hard to catch if done right.)

There's no way around the wipe at least and better hope the bugger installed is not persistent in some firmware.

Re: How to lock down your phone if you're traveling to the U.S.

#290
post #81

Earlier quoted context omitted.

It has to do with your argument of "if you don't like it, don't go there". Also, you specifically asked "who came for you" so it's direct answer to your question.

Well yes, just don't go there with incriminating devices. They will try to bully us in many other ways but this has nothing to do with the devices and how to hide stuff.

Personally I would not go with any device at all I cannot afford to throw in a trashcan. You can buy a cheap one in the US anyway... For now.
Post reply on HN