I’ll never bring my phone on an international flight again
medium.freecodecamp.com
medium.freecodecamp.com
"Next programmer bro who explains his clever travel information security hack has to change his name to Mohamed Hussein Ali and try it at LAX"
https://www.aclu.org/other/constitution-100-mile-border-zone
The entirety of Lake Michigan is within the borders of the US, so while this entire "100-mile border zone" business is bizarre enough as it is, it's truly disingenuous to include the lower Lake Michigan coastline. It makes me wonder if this is an interpretational liberty taken solely by the ACLU, or if the government's demonstrated behavior truly justifies what is shown on the map.
http://www.great-lakes-sailing.com/canada_us_border.html
I guess sailing from the Canadian shores of Huron to somewhere in Michigan wouldn't be all that weird.
when i first learned about this, I scared my lawyer girlfriend about it and she helped me look into the actual court cases. they have been somewhat difficult to hold up. usually because LO abuses the rules by not following the three terms listed above. and it still takes getting all the way to Supreme Court which is a massive drain on resources for those typically affected by this.
Getting a case before the court takes tons of time and money.
If issues of abuse of power could be resolved by the states, people could see justice faster.
> Searches within the 100-mile extended border zone, and outside of the immediate border-stop location, must meet three criteria: a person must have recently crossed a border; an agent should know that the object of a search hasn’t changed; and that “reasonable suspicion” of a criminal activity must exist, says the CRS
We're fortunate to live in a timeframe where this sort of bullshit has been unusual up until now for most people.
Ask a US citizen of Pakisanti descent about travel to India sometime. International conflict gets taken out on poor saps trying to travel all of the time. Sometimes it's petty chickenshit, sometimes real.
From the customs agent and legal point of view, there is no distinction between hiding a secret compartment in your luggage and a device.
> They eventually returned and said they’d release him if he told them the password to unlock his phone.
How have I hindered official action or lied to a federal agent by providing one of my passwords?
The same way that your child disobeyed you when you say "Go to bed", and they lay in yours and tell you "You didn't say which bed".
Clearly, the border agent wasn't asking for the password to your alternate, fake part of the phone, and they aren't likely to be happy if they figure out that you followed your own interpretation of the letter of the order, rather than an interpretation that conforms to the spirit of the order.
Is it really illegal to have a secret compartment in your luggage? I mean, I have no doubt it's highly risky and that they will make the case you've done something wrong, but have you inherently done something illegal by merely having a secret compartment? Maybe only if you've explicitly represented that there are no other compartments? Or you've got contraband in there, or something else they've explicitly inquired about that you claimed you don't have? (But that's more about lying or existing laws, than the compartment itself.)
If you turned over your phone for inspection and could see they were looking in an app you don't use, are you committing a felony to not volunteer that they should look in the other browser for your real history or whatever? If having two profiles and only providing one is illegal, what about having two phones? (like your "real" one in your luggage, turned off.) Do I have to volunteer that when they asked for "my phone" that I actually have multiple? What if I kept the "real" one at home -- do I have to tell them the one they're looking at is only a subset of my property and doesn't represent what they probably actually meant when they asked for "my phone"?
I'm not entirely sure where "the lines" are here, but perhaps the passcode is part of it. Once they require that, they've crossed from dealing with physical items physically crossing the border, passing into things that are in your mind or physically located elsewhere. If they can require a lockscreen code, there's not really any reason they can't require every other password since those are "secret compartments" accessible from your phone, and if just having an undisclosed compartment really is illegal, I guess you'd better volunteer an exhaustive list of all your accounts...
In many cases, the customs people have discretion to not admit you for a variety of reasons. There's a tension between the process around physical goods and digital data that isn't clearly understood by the law. Until the law is more firmly established, you're better off not carrying stuff you care about.
Having multiple profiles per device and accessible in this manner would be preferable for a number of reasons. Least of which is not wanting anyone else access to your own sensitive information that they have no business looking at to begin with.
Immigration has very broad powers, but even then this sort of case would be difficult to make IMHO.
I agree. But who has the time and money to defend themselves in court against the unlimited resources of the government?
that is a serious felony in the United States
How so?Everyone has the feels over this border stuff and HN is collectively spewing the same inane questions repeatedly, but the reality is that people are more likely to get into trouble more often when spouses, employers, teachers, family, etc get to see things that weren't intended to be seen.
We have airplane mode to shut off phone radios, why not a purge mode to whack marked data. On iOS, the most rudimentary level of this sort of protection is available with MDM -- you can configure a device to erase managed data when it leaves a building or campus. The device is still active and manageable, but the data is gone until it becomes compliant.
If what you want is a mode that wipes your phone only when a CBP agent looks at it, as other people have stated in the comments here, you'd probably be committing some sort of crime (e.g. destruction of evidence or lying to a federal agent).
The only truly safe way to cross is to not actually have your data when you cross, not to try and throw it away once you get singled out by agents.
I have nothing to hide personally. I'm more concerned about business secrets and SSH keys.
If you have nothing to hide you should have nothing to fear. Because you know that US is never involved in industrial espionage and Snowden NSA leaks have allegedly never happened.
You do. And even if you don't, you should hide it anyway. Please stop using that sentence at all.
“Never say anything in an electronic message that you wouldn’t want appearing, and attributed to you, in tomorrow morning’s front-page headline in the New York Times.” — Colonel David Russell, former head of DARPA’s Information Processing Techniques Office
Besides, I don't think my data is any more likely to end up in some newspaper if a government agent gets it than if (when) Google gets hacked.
Good advice, in general. I've never met anyone that didn't have something to hide from someone, though. But you're making an even stronger claim: That nothing that you've said or done will ever be something that you'd want to keep private. When data gets out, you don't get to call it back, even when circumstances in the world change.
In fact, your country's president probably wouldn't care too much if the stuff on his phone was exposed. He seems to be more than happy to make public all his thoughts and opinions.
That's the wrong question, though. (Despite the quote above.) The question is, do you have anything on your phone that someday a government may decide is a reason to do something bad to you?
The answer is always yes for two reasons: One, you can't know the future and what it will hold, for instance governments can make laws explicitly for the purpose of "getting" people, and two, the possible set of future governments pretty much has no safe behavior intersection.
The only missing piece is a easy way to restore the phone once I reach my destination.
'[X] You are proposing a technical solution to a non-technical problem'
The border agent of ${COUNTRY} doesn't care if you wiped your phone accidentally or deliberately; his flowchart says 'access subject's chat history on phone'. If that's not possible, goto 'reject'.
All that sounds like a UX nightmare.
The point is its all moot solving this at a technological level.
It does, but that wasn't the point I was trying to make.
> The point is its all moot solving this at a technological level.
If I'm reading that right, it's closer to what I was thinking when I wrote my comment. We can come up with a bunch of clever solutions, someone else can shoot them down with plausible scenarios, but regardless, some asshole at the border can still say "I don't believe your phone's blank, and I don't believe you don't have a Twitter/Facebook/etc account. So, you'll need to restore your phone and give us your social media passwords to get out of here"
Once you get home and want to untravel, you plug your phone in to your desktop and sign in to a cloud service that "untravels" your phone, restoring to the state it was in.
* Just to make the customs agents happy, I would fill the history of the fake profile with porn and pictures of donuts.
Option 2: If you're at the US border and a US citizen, "Sir, I'm an American citizen and just want want to get home" -- citizens can't be blocked from re-entering at the border.
Option 2, they can't stop you from entering but they can make you enter directly into a jail cell, or generally make your life miserable. See the owner of cock.li, who had all of his electronics seized twice.
Well, sort of. They have to let you in, but you can be held more or less indefinitely if you're suspected of committing a crime, or not complying with the border agent.
Define "blocked". Because Sidd Bikkannavar's recent experience tells a different story[0].
"The document given to Bikkannavar listed a series of consequences for failure to offer information that would allow CBP to copy the contents of the device. “I didn’t really want to explore all those consequences,” he says. “It mentioned detention and seizure.”"
[0] - http://www.theverge.com/2017/2/12/14583124/nasa-sidd-bikkann...
https://www.cbp.gov/sites/default/files/documents/inspection...
A few highlights:
You may be subject to an inspection for a variety of reasons, some of which include: [...] you have been selected for a random search."
You’re receiving this sheet because your electronic device(s) has been detained for further examination, which may include copying.
CBP may retain documents or information relating to immigration, customs, and other enforcement matters only if such retention is consistent with the privacy and data protection standards of the system in which such information is retained. Otherwise, if after reviewing the information, there exists no probable cause to seize it, CBP will not retain any copies.
Unfortunately ICE/CBP has policies [1] in place to require the phone's password that they believe are legitimate per 8 USC § 1357(a) (3). It's likely that only a court ruling weighing the policy regarding this statute against the bill of rights would make them change.
[1] https://www.dhs.gov/xlibrary/assets/ice_border_search_electr...
18 U.S. Code § 1001 - Statements or entries generally
Current through Pub. L. 114-38. (See Public Laws for the current Congress.)
(a) Except as otherwise provided in this section, whoever, in any matter
within the jurisdiction of the executive, legislative, or judicial branch
of the Government of the United States, knowingly and willfully—
(1) falsifies, conceals, or covers up by any trick, scheme, or device a material fact;
(2) makes any materially false, fictitious, or fraudulent statement or representation; or
(3) makes or uses any false writing or document knowing the same to
contain any materially false, fictitious, or fraudulent statement or entry;
shall be fined under this title, imprisoned not more than 5 years or, if
the offense involves international or domestic terrorism (as defined in
section 2331), imprisoned not more than 8 years, or both. If the matter
relates to an offense under chapter 109A, 109B, 110, or 117, or section
1591, then the term of imprisonment imposed under this section shall be
not more than 8 years."Oh, that broke off years ago. I just charge batteries in a separate charger now."
"My regular phone is SIM locked and my plan doesn't have international roaming, so it's useless to carry it. I bought a cheap unlocked phone so I could get a SIM card at my destination, because I only use it when traveling."
The judicial system has no sway in Gitmo. Good luck!
Each one of these border issues (phone passwords, checkpoints inside the US, travel bans) increases the total law enforcement "resistance" we face when traveling internationally. As the resistance increases, at what point does it become an "open circuit" ?
Just like during communism in Poland. My parents told me such stories. I think they wouldn't believe me if I said them that it looks like it will be implemented again in USA.
I never bring my US phone on international travel, because it just won't work. Instead, I carry a cheap Chinese GSM phone that's wiped before every trip and preloaded with some music and entertainment videos (TV Shows, etc.)
I buy the sim-card at my destination and throw it away when I go back to the States.
I'm not sure this solves anything, but then again, I don't work for a company that makes me required to be able to access sensitive data from any point in the world. YMMV.
You should be able to create two passwords for all devices. One, your password, would allow you to use the device normally, the other, your lastword, would start a silent erasure of the device. The device could even present a fake successful authentication, like dumping you to some fake desktop, while it erases your data.
While in this case it would not really benefit someone in situations like US border crossings who have almost no rights, I think it would be very effective at discouraging attempts to force people to divulge their passwords, as the person entering the lastword would effectively be informing the device that it was under attack. With something like this I would think that questioning people for their passwords would be pointless.
As said in other threads, the solution is not technology.
If the technology could remove everything that would be incriminating and leave benign data you would just be another non-techie traveler.
If it became commonplace, providing such a password to law enforcement would likely be criminalized.
The simpler way to deal with it that doesn't involve the potential of breaking laws is to carry a travel device and straightforwardly identify it as such if asked. Or don't carry any device at all.
1/ I legitimately do not know a lot of my usernames and passwords. I sign up with a unique email that includes the name of the site (I'm not particularly religious about the format of this and usually end up checking previous email to figure it out). Passwords are saved in Chrome and I mostly don't remember them. I'm sure I am not unique. Where would one stand with this scenario?
2/ Wherever I can, I use a U2F device as a second factor. Could one be compelled to provide this along with the passwords (providing I can remember them)? Where would one stand if the key was unavailable - i.e. lost/left at home? Assuming they have a PC nearby for checking your social media accounts, I'd very much doubt it had it's USB ports enabled so, even if I did provide it, I would suggest they probably couldn't use it. Is there any documented precedent for how this is handled?
This makes me wonder: is it true? Is the data truly unrecoverable if you factory-reset your phone? I doubt so. But maybe there's some special tool to truly wipe a device (say like the equivalent of DBAN)
Please don't hijack an important security discussion to engage in meaningless platform flamage. Users with Android phones have this available and they should enable it, not be told that they need to "guess".
Also the parent post was talking about usage, not availability of encryption. So while recent Android versions most certainly offer encryption, it might not be enabled. iOS encrypted by default, as it should be.
A good friend of mine was blackmailed by her boyfriend that her sensitive pictures would be released on the Internet if she didn't return his calls. It was the first time she realized that what was considered silly can really be very serious. She deleted her Facebook and Twitter account.
I really want to see a big hack, sort of a global financial crisis level on the surveillance govt is collecting for people to realize this shit can really fuck society up.
(then back up your data, ship the computer device with an insurance policy, and give the border crossing another shot)
Don't try shenanigans at the border.
My understanding is that they are permitted to search you, for the narrow purpose of border security. (I.e., the search here is not a violation of fourth amendment rights.) But I don't see how they can force you to divulge your password. You might not get the phone back, though, and they'd likely make your life very difficult; it's probably better to not mess around with them, and plan ahead. Specifically, I don't think leaving and trying again is ever an option, and wouldn't look good to the officer.
Forcing you to restore your entire account is a whole 'nother level beyond simple forcing you to unlock your phone.
adb backup -apk -shared -all -f backupname.ab
adb restore backupname.abNotably, if you use google authenticator for 2FA, it won't backup and you'll restore a device that will no longer work as your second factor.
For non rooted this seems very tricky, that's why I asked. Most likely you will spend hours getting your phone to work again.
This would seem to imply lying, or at least deceiving, a federal agent. IANAL, but https://en.m.wikipedia.org/wiki/Making_false_statements
As long as you aren't taking pictures of the procedures they don't really care.
Care to share the reason it hasn't taken off? Or are you here just to call me out?
Other commenters on my comment have not provided a good reason. Like I said, I walk through customs and passport control with my phone in my hand all the time (20 or so trips per year) and could easily click this button the instant something unusual happens.
I suspect your tune may change when you find yourself in indefinite detention, have missed your connecting flight, and your family/friend/spouse/boss has called said phone and been told by CBP that you're refusing to comply with an investigation.
If my peers find it acceptable that I am detained indefinitely simply for not unlocking my phone, then throw away the key because all is lost.
That would probably look even more suspicious.
This is my main phone I use when crossing constitution-free zones.
> it's a felony to lie to a customs & border patrol officer
That makes me livid: "Oh, sorry, the constitutional laws (that apply to us) don't apply here, see it's not technically the US because reasons." [lies to officer] "FELONY!".
me: "no it's not"
I don't claim "all laws go out the window". No clue how you reached that conclusion.
Remember they're not just dumping the contents for analysis, but also installing a rootkit, assuming the phone isn't already rooted, so once it leaves your presence or they plug anything into it, its no longer a trustworthy device.
Something I don't understand is the postal system is essentially wide open for transportation of drugs and stuff as per numerous dark web stories, so simply putting the phone in a box and mailing it would seem to reduce the chance of anyone in the .gov accessing it down to roughly 0% odds.
I'm convinced most of these stories are submarine marketing by big internet companies that have a wide open door to the NSA as most of the discussion revolves around the government not accessing your "private" Facebook activities where no such situation could possibly exist, so there's no point in not unlocking the phone. Ignore the man behind the curtain providing the NSA root privs on the server, the problem is individual officers gaining access to your CRUD app end user device LOL.
Given that the government already has all the data, the real battle is you are trying to appear to be an individual in their database and they'd like to know exactly who, which makes it about as nefarious as asking for your passport, and they know and understand that, so they freak if you won't give them access. As an analogy they know they have all the data on your drivers license and if you refuse to show them your drivers license that will make them extremely interested in why not, you claim you're j random hacker and you claim thats j random hackers drivers license and we have all the license data for j random hacker now why won't you show it, perhaps you have a fake ID for j random hacker or you're someone else trying to set up j random hacker or ...
EDIT:
"I bring dumbphones when traveling because battery lasts two weeks, unlike iPhone"
"I heard that there are lot of thieves in the country I visited, so I was afraid to bring my real phone"
"I heard that airport X-ray machine can brick iPhone"
"I really like cheap, Chinese phones, they are so cute"
"iPhones are for hipsters, I prefer cheap, practical devices"
possibilities for excuse are endless. And, as the old rule goes, the stupider the excuse the better - if you can convince CBP agents that you are harmless idiot you win.
Edit: I didn't realize virtually all phones' storage is encrypted nowadays.