I use the he.net app for TOTP. Will I get those back in working order?
I have a billion photos I want to keep — were they properly backed up to iCloud?
My mail settings are a pita to recreate. Will those come back?
Are passwords stored in the Secure Enclave? Could I lose those?
When I sign back into iCloud am I going to be able to use a username and password, or is it going to require me to approve the login on my laptop — which I left at home — as a second factor?
WhatsApp, Signal — how much is tied to my physical phone and/or any key material unique to the OS — material that is irretrievably lost, by design, when it is wiped.
I think really the long term answer is to stop using an opaque, closed source iPhone. Maybe some time in the next five years one will emerge that competes with Apple’s quality? Until then, every border crossing is going to risk handing over a huge part of my life to ICE because I can’t risk losing anything in a backup/restore hysteresis loop.
Post.: Another future direction would be for iOS and apps to recognise this as a common use case and provide guarantees about what is and what isn’t restorable after a wipe.
There’s also a conflict here between wiping data so that it is irretrievable and wiping data to later retrieve it. If you wipe with the intent to retrieve I can believe that immigration will just detain you until you restore your phone so that it can be searched.
It feels like buying a fire safe (phone and app backups) without any kind of understanding if it works then burning your house down to see if it works. I want a fire safe (phone and app backups) that is up-front with guarantees it works!
I should have said this by the way: for a long time I did wipe my phone when crossing borders, learning the hard way all the little details that don’t quite work properly when doing a restore from backups.
Isn't that actually one of the things you want to do to validate the backup process?
Better to figure out in a non disaster scenario where you have alternatives.
It's quite easy to restore an icloud backup to a different phone or even ipad for testing purposes, if one were reliant on icloud to hold their data.
Ultimately it's not enough for individuals to spend this effort for themselves. We need a self-managed option that is nearly as turnkey as iCloud. A distro with it built from the outset.
It's not like my backup of my ~/Photos directory where I can copy to a USB and md5sum the files on a separate computer and check the match.
This is an issue I face- I have a collection of thermal cameras that use apps to control them- after every install onto a phone, they then reach out t oa server to authenticate.
Here's the issue- though I have a few older phones- these apps are 32 bit ones, so no modern phone after Android 13 will run them. And they are all now not on the app store anymore,as they all came out about around 2016. i did use a APK extractor to pull the APKs to store them - but the native backup functionality wouldn't capture that authorization in the future, I might rob myself of my ability to use some extremely expensive, and long-term invested capable hardware, by backing up and restoring-
I suspect a full image would solve this problem, but I don't think one can do that outside of things like TWRP- but that requires unlocking the bootloader, and if you do that it wipes your device- AND is more vulnerable to Custom's usage of Cellebrite and etc, to my undertanding.
I don't have this issue with laptops ,as I can fully image them and wipe and restore ahavend have a perfect replica/ no issues. But my thermal cameras do not run off of PC and th eform factor wouldn't work if they did
A lot of this is from anchoring important things to your phone. I practice, and strong recommend, avoiding that as much as possible. Your phone should be entirely disposable. If you drop it in the ocean, would you care (other than the monetary loss)? If yes, find way to detach those things from the phone. There should be nothing important on a phone.
So be it. I used to say that the reason I valued my privacy was not that I did not trust my government _today_, it was the fact that data would be available to every potential authoritarian government _tomorrow_.
Welp, today has become tomorrow, and yeah, I'd _absolutely_ rather just have my devices seized than have the contents of my phone dumped into a database that can be searched without a warrant, for the next 15 years.
Rights (like the 4th amendment) that are not exercised are not upheld. I'm sure the threat of having one's devices stolen (let's be clear, that's what this is), is enough to deter many people. For myself, my next course of action would be to contact the ACLU and sue the government for violating the 4th amendment.
Even if you do sue the gov't, it'll be at least a year before any kind of resolution that results in the return of that device. Them keeping my phone would be one thing, but if they also kept my laptop, I'd be screwed. My laptop is much more than $1k, and there's no free laptop with contract cell service I could use to replace it. Now I'd be without a means of working.
These kinds of situations make me really yearn for the days of replacing the internal hard drive of a laptop. I could swap out my daily use drive for a travel drive, which would be much less of a hassle than the options on offer for modern laptops.
I don't know if other bootloaders outside GRUB have a silent/hidden start option, as well in a similar vein that would require you to hit a key in that first second to get the menu to appear, or else it just boots up normally
I wonder about the other approach, just going into the BIOS nad changing the order so Windows boots first, which should be doable in some setups. Lock the BIOS with a password, and you're in not bad shape. (Not sure if Secure Boot being enabled could also help here - probably couldn't hurt)
I am a US citizen though. The only real goal for me at CBP is to avoid secondary at all. I'm not worried at all about them coming for me after I leave the airport. If that sort of stuff starts to happen... I am screwed anyway. They can find records of everything I've said by just compelling US companies to disclose it to them.
I left a comment about Veracrypt offering the Hidden OS feature, with two passwords - one for the dummy OS and one for the real OS. However it doesn't seem to be supported anymore on Windows 11 or modern hardware, the option is greyed out on my laptop with no explanation.
I'd suggest that if $1K is a big deal to lose, one should not spend such an ungodly amount on a phone.
Perfectly adequate phones can be had for $100-$200. I couldn't imagine wasting more than that on a phone.
You're totally ignoring the option of wiping your phone prior to crossing, and avoiding both fates.
>Rights (like the 4th amendment) that are not exercised are not upheld. I'm sure the threat of having one's devices stolen (let's be clear, that's what this is), is enough to deter many people. For myself, my next course of action would be to contact the ACLU and sue the government for violating the 4th amendment.
This already has been litigated, and the courts have affirmed CBP can deny entry or seize your phone. By all means, try to affect change by writing to your senator or whatever, but displays of civil disobedience is mostly pointless. ACLU won't even take on your case because it's been settled, and the chance of it being overturned is slim.
China not anymore. You can now easily travel there without visa.
Turkey is still too aggressive and risky, but at least you don't have to wait 6 hrs at their border anymore.
> wipe your phone and restore from backup
If they can compel you to divulge the password, then they can compel you to restore from backup in front of them.
Of course, if your backup is to a US-based cloud service, they already have full access to it.
if they're really out to target you and they've got you under investigation, then maybe they know what your primary email account is and that your phone isn't signed in to it. but the advice here is for the traveller who just doesn't want to be hassled at the border by the guard who wants to flex their power.
It’s a mantra but it’s incorrect: You’re supposed to list your “online accounts” to the border agent in the US.
Thanks in advance.
> U.S. citizens cannot be denied entry to the United States for refusing to provide passwords or unlocking devices. Refusal to do so might lead to delay, additional questioning, and/or officers seizing your device for further inspection. [...] If an officer searches and/or confiscates your laptop or cell phone, get a receipt for your property.
[1]: https://www.aclu.org/know-your-rights/what-do-when-encounter...
[2]: https://www.aclu.org/news/privacy-technology/can-border-agen...
First, it's the fourth amendment that protects against unreasonable search. Fifth amendment is protection against self-incrimination.
My understanding is that fourth amendment protections effectively do not apply at the border [1] because the border is inherently a reasonable place to search people.
In regards to being compelled to unlock your phone, CBP maintains the position [2] that in order to uphold their duties they're inherently able to compel you. Anecdotally, if you don't unlock your device, they may (a) confiscate it (and possibly apply all sorts of cracking tech to it), or (b) refuse you entry. That said, a random law firm [3] cites that you can withhold a password-based lock, but CBP can compel you to provide biometric unlocking [3].
To me, this is a case of https://xkcd.com/538/ ; you may have a legal basis to refuse, but in the current iteration of the administration I find it unlikely that it would be a positive experience if you were to stand on it. (Not that CBP is going to beat you with a pipe wrench, but if they want in your phone, they're gonna get in your phone.)
[1] https://law.justia.com/constitution/us/amendment-04/19-borde... [2] https://www.cbp.gov/travel/cbp-search-authority/border-searc... [3] https://borderslawfirm.com/border-search-computers/
I.e., this warning example from this week,
https://news.ycombinator.com/item?id=43618754 ("Lawyer for U-M protester detained at airport after spring break trip with family (freep.com)")
(US citizen, attorney, detained for 90 minutes as punishment for asserting his rights and refusing to unlock his work phone, which contained privileged attorney-client communications).
IIRC there is a radius around every international airport where such warrantless searches are legal.
https://www.aclu.org/know-your-rights/what-do-when-encounter...