What am I misinterpreting? OP literally said they don't understand why a journalist would carry these data with them. As if the data is a file on your phone. Data can be a contact book on your phone, or a messenger with E2E encrypted messages. What would the alternative to that be? Sending pigeons?
Restoring from remote backup when you reach your destination, then wiping again before you cross borders. Or shipping the (encrypted) data separately and picking it up after safe arrival.
Because you show up with nothing on you, and there’s no way to prove that the backups even exist. Especially given how often people travel with blank/disposable phones.
Just as the border guard can’t require you to fetch something from your house before entry, they can’t require you to restore from a remote backup that they don’t even know about.
Wiping under duress is
unlawful and could lead to prosecution in some juridictions.
On the other hand I don't know of any juridiction that force you to carry all the personal data in a single device when crossing borders. It would moat likely not even be possible.
Not if it’s encrypted and self-hosted. Your doomerism is silly. “The government” is not all-powerful, or they wouldn’t need to pester people for PINs at the border.
Can the border guard go to your house and retrieve something, bring it to the checkpoint, and ask you to do something with it before entry? No. This is out of their legal authority.
Also, you could set up a system where the phone cannot restore the backup on reentry. Perhaps a single use restore key that you use at your original destination, so the restore cannot be performed again until you return home and generate a new code. This evades the (flimsy) charges that were applied in this case.
The best option, however, is to bring a blank disposable device, restore from backup at your destination, then discard the device before you cross the border again.
That's not my point. Rather that any self-hosted solution would. Encryption is completely optional and can be illegal in some places. As long as you trust the endpoint you only care about encryption in transit.
If your devices are seized having encrypted data can pose extra risk.
Deniable encryption exists and burden of proving that you haven't used it can be put on you.
Basically I'm trying to say "it depends". I'm not a fan of "let's just slap a(nother) layer of encryption on it" security model. My home servers aren't encrypted and I see no reason to do so. Sensitive data is encrypted based on the sensitivity.
> The best option
The best option is the one that is most convenient to the user and fits the task at hand.
If you are on a demonstration and need to broadcast status live then you don't have a luxury of bringing in a blank phone and restoring backup before each transmission
> If your devices are seized having encrypted data can pose extra risk.
I don’t think you can even set up an iPhone anymore without encryption. It’s just “on”, not even “on by default”.
> My home servers aren't encrypted and I see no reason to do so. Sensitive data is encrypted based on the sensitivity.
If you do sensitive work, you should be concerned about someone breaking in and running off with your storage. It’s unfortunate but that’s just how it is. Encryption adds very little overhead on modern hardware.
> If you are on a demonstration and need to broadcast status live then you don't have a luxury of bringing in a blank phone and restoring backup before each transmission
That’s not crossing a border then, is it? The case under discussion was about a border crossing, where (apparently?) Constitutional rights are suspended. A used phone adds little to the cost of an international trip.
A protest is a completely different situation. In that situation I’d recommend a burner phone that you can afford to lose or throw away. Ideally the cheapest one available. And never log in to your primary accounts on it.
What am I misinterpreting? OP literally said they don't understand why a journalist would carry these data with them. As if the data is a file on your phone. Data can be a contact book on your phone, or a messenger with E2E encrypted messages. What would the alternative to that be? Sending pigeons?
Restoring from remote backup when you reach your destination, then wiping again before you cross borders. Or shipping the (encrypted) data separately and picking it up after safe arrival.
What's the difference between this and wiping when under duress using the special PIN? If you aren't being checked you don't wipe and are gopd to go.
Because you show up with nothing on you, and there’s no way to prove that the backups even exist. Especially given how often people travel with blank/disposable phones.
Just as the border guard can’t require you to fetch something from your house before entry, they can’t require you to restore from a remote backup that they don’t even know about.
Wiping under duress is unlawful and could lead to prosecution in some juridictions.
On the other hand I don't know of any juridiction that force you to carry all the personal data in a single device when crossing borders. It would moat likely not even be possible.
The government can easily get your remote backup, of course. It's just that border control won't know you have one.
Not if it’s encrypted and self-hosted. Your doomerism is silly. “The government” is not all-powerful, or they wouldn’t need to pester people for PINs at the border.
Encryption in this case is irrelevant. If they get the encrypted backup they can already charge you if you don't decrypt it.
Self-hosting is the way obviously
Can the border guard go to your house and retrieve something, bring it to the checkpoint, and ask you to do something with it before entry? No. This is out of their legal authority.
Also, you could set up a system where the phone cannot restore the backup on reentry. Perhaps a single use restore key that you use at your original destination, so the restore cannot be performed again until you return home and generate a new code. This evades the (flimsy) charges that were applied in this case.
The best option, however, is to bring a blank disposable device, restore from backup at your destination, then discard the device before you cross the border again.
That's not my point. Rather that any self-hosted solution would. Encryption is completely optional and can be illegal in some places. As long as you trust the endpoint you only care about encryption in transit.
If your devices are seized having encrypted data can pose extra risk.
Deniable encryption exists and burden of proving that you haven't used it can be put on you.
Basically I'm trying to say "it depends". I'm not a fan of "let's just slap a(nother) layer of encryption on it" security model. My home servers aren't encrypted and I see no reason to do so. Sensitive data is encrypted based on the sensitivity.
> The best option
The best option is the one that is most convenient to the user and fits the task at hand.
If you are on a demonstration and need to broadcast status live then you don't have a luxury of bringing in a blank phone and restoring backup before each transmission
> If your devices are seized having encrypted data can pose extra risk.
I don’t think you can even set up an iPhone anymore without encryption. It’s just “on”, not even “on by default”.
> My home servers aren't encrypted and I see no reason to do so. Sensitive data is encrypted based on the sensitivity.
If you do sensitive work, you should be concerned about someone breaking in and running off with your storage. It’s unfortunate but that’s just how it is. Encryption adds very little overhead on modern hardware.
> If you are on a demonstration and need to broadcast status live then you don't have a luxury of bringing in a blank phone and restoring backup before each transmission
That’s not crossing a border then, is it? The case under discussion was about a border crossing, where (apparently?) Constitutional rights are suspended. A used phone adds little to the cost of an international trip.
No you just chose to ignore other cases that OP mentioned and focused on this one
A protest is a completely different situation. In that situation I’d recommend a burner phone that you can afford to lose or throw away. Ideally the cheapest one available. And never log in to your primary accounts on it.