Cell Phone OPSEC for Border Crossings
schneier.com
schneier.com
This comment, at the end of the thread, is particularly interesting:
My Pixel 6 was confiscated by the German police after a political rally. I was recently able to pick it up again. From an inquiry with my lawyer, the following emerged: The authorities tried to read the device with both UFED4PC and Cellebrite Premium Touch. In addition, software from other forensic providers was used without success. The software did not succeed in breaking the system. The device was in BFU mode and had a 30-digit PIN. USB port was deactivated. As of March 2025, I can therefore say that it is not possible for Cellebrite to break a secured GrapheneOS.
Also lockdown mode to reduce attack surface area.
Unless border agents are burning 0-days on random passersby, it’s fairly unlikely they installed anything persistent that can’t be removed.
* https://www.cbsa-asfc.gc.ca/travel-voyage/edd-ean-eng.html
> A CBSA officer will start with some questions before examining your personal digital device. To examine the device, the officer will first ask for the password. If the device is password-protected, they will write your password on a piece of paper. You are obligated to provide your password when asked.
> Note Failure to grant access to your personal digital device may result in the detention of that device under section 101 of the Customs Act, or seizure of the device under subsection 140 (1) of the Immigration and Refugee Protection Act or under section 110 of the Customs Act.
Well guess we’re not going to Canada again.
It also never mentions them destroying the written down password.
Or Australia:
> Electronic devices held for forensic examination under section 186 of the Customs Act will be retained for no longer than 14 days, provided there is no content on any device retained which renders the device subject to seizure under Customs-related laws. If any device is subject to seizure, the examination of any associated retained devices may take longer than 14 days.
* https://www.abf.gov.au/entering-and-leaving-australia/crossi...
Or every other country.
You may be asked by a border agent from any country to unlock your electronic device.
Feel free to not unlock or give your password of course: every country has a law about confiscation and/or not allowing you in.
The good opsec in general, I think, is to comply, not have an obvious burning phone setup, but to have nothing capturing attention
From a comment in the article:
"Schneier’s border crossing opsec advice is characteristically thorough, but the recommendation to simply ‘turn off your phone’ undersells modern forensic capabilities. As a security consultant who’s testified in border device seizure cases, I’ve seen CBP’s Cellebrite tools extract data from ‘off’ iPhones up to 72 hours post-shutdown via remnant charge in memory chips (see 2024 DEFCON demo). The article’s Faraday bag suggestion works, but only if activated before entering the 100-mile border zone – we’ve documented RFID sniffers in airport limo services."
Anyone else feel like this? I simply do not have any desire to live in a world where this kind of behavior is required.
I like this idea. My burner laptop will open up to a bonanza of the most extreme but legal porn imaginable. Pop-ups and lurid ads everywhere, loud moaning, the works.
"Can I help you find anything, officer? What are you into? Why are you turning red?"
In addition to the US: Canada, Australia, New Zealand, Germany.
I'm sure there are others as well.
Bringing anything non-standard can be misinterpreted as, or worse, construed as something malicious.
The problem with an empty "burner phone" is, that can also look suspicious. Even if you have a receipt with you, they may wonder why you bought a new phone just for the trip. Lockdown mode seems even more suspicious.
Just don't stick out is unfortunately probably the best answer.
If you are returning to your own country say it is because you didn't want to risk having your expensive phone stolen while abroad so you travel with a cheap burner.
Keep in mind that they hear plenty of stories like this. What it amounts to is that you're trying to achieve plausible deniability even if they assume you're lying, i.e. don't give them any concrete basis for suspicion.
This is a easy one.
Both ios and android does the same thing -- the filesystem is always encrypted, factory reset discards the decryption key.
On macOS and windows, that's encryption by default. (yes, bitlocker is the default now)
This is pretty standard nowadays.
Linux, otoh, don't usually do the encrpytion.
When checked it uses cryptsetup and the full disk is encrypted.
Back in the day, everything of interest was on the device, and to be search-resistant, it was necessary to encrypt and hide it well. And most answers still seem to assume this is the case.
Nowadays, though, almost everything of interest is stored in the cloud and what the cops/CBP/three-letter agencies want is the credentials to access those. Sure, you can make their life a bit harder by logging out of everything, so access is not completely trivial, but they can still stick you in detention (or worse) until you cough up your passwords, regardless of what is or is not on your device. And the only way around this is to never show up on their radar in the first place.
Where is the answer? I only see the question (and comments section).
Source: https://www.theguardian.com/technology/2025/mar/26/phone-sea...
Given the authority of the author of the post this approach would seem to be necessary for almost everybody.