U.S. citizens are going to need obtain a burner phone before returning, and load it with the absolute minimum to load boarding passes, etc., perhaps some reading material or a movie to watch on the plane, and be prepared to share full credentials for thing at the border.
(I used to do some travel patterns where taking a certain client laptop wasn’t an option. It was an absolute gigantic pain for the type of work I did, but it was just too risky to have a laptop seized and be expected to input credentials.)
I think it's enough to shut down you phone. Then it needs a pin, and you're entitled to not give that over, I believe. So you should be safe, apart from some kind of rubber-hose cryptanalysis.
> So you should be safe, apart from some kind of rubber-hose cryptanalysis.
There are vendors that sell the technology to adversarially access phone data, the "Before First Unlock" is the safest state a phone can be, but it's not infallible. The safest option is to have a burner or factory-reset phone with nothing on it, even if the hack succeeds.
I've worked with Cellebrite, the industry standard in IT forensics for unlocking and imaging phones. It just runs a series of known exploits. PIN lock, data encryption and regular updates will beat it most of the time.
> I've worked with Cellebrite
Any chance you want to do a public service and publish the latest compatibility matrix?
Just joking, obviously…
Before First Unlock with recent hardware and an up to date OS is probably sufficiently infallible for an average person. I wouldn't want to rely on it if I was engaged in espionage, but for someone who won't get the NSA pulled into the case, I'd be pretty confident. This leaked Cellebrite support matrix shows that BFU was secure against them for iPhones that were nearly four years old at the time, and I doubt it's become significantly worse since then: https://ia800405.us.archive.org/32/items/inseyets-offline-uf...
If you don't give a pin, they can seize your devices (Andrew Tate on his 1st visit to Florida said that he refused to give pin and they seized phone and laptop)
They can't keep them, you'll get the devices back. Use a temp phone in the mean time.
Sad that we have to accept this as a risk of international travel, but here we are.
They can absolutely keep them. Or they can just "lose" them "accidentally". Who exactly would force them to give them back? Or put another way, who exactly will punish them if they break the law?
They can’t keep them permanently, but unfortunately they have in the past kept them from some people for years, until the hardware was past its useful life. It’s a good idea to only travel with electronics you don’t mind losing (and not just because of this).
You have a worldview that’s incompatible with the reality of the current US legal system where things work the way you believe they should, rather than the way they actually do.
Morality and direct commonsense interpretations of law do not apply when there are literally unlimited resources stacked against you. But, assuming you can wait the potential ~10y to receive your device back that it will take to get your device returned to you, good on you. If you think that the current SCOTUS will rule in your favor, good on you.
The reality is, we live in a time where the most horrendous interpretation of the law is the one that will happen. And it won’t be in your favor.
I don’t see how what you said contradicts anything I said, and I suspect you didn’t even read it. Yes, people have before had their devices seized for years, and courts wouldn’t return it sooner. That’s literally what I said.
Honestly, I think this is still fine for most people. The probability of a border agent asking me to unlock my phone is very, very low. The inconvenience of using a burner phone is high.
If they do take my phone (completely shut down, unlikely they'll be able to break in) and it's gone forever, that sucks, but then I get a new phone, restore from a backup, and move on with my life. Given that the probability of getting to this point is very low, I'm comfortable with the risk.
But sure, if I was at high risk of being detained at the border due to my profession, country of origin, ethnicity, etc., I'd probably look at this differently.
It's not sad, it's always been the case, and just expanding areas that are implementing it. It seems a lot of people here haven't travelled, or especially haven't travelled to 'restrictive' places in the past.
I've been to Russia, China (about ten times,) central Asian -stans, various parts of South America, Africa, etc. My phones and laptops (plural because I travel with >2/ea, and it looks kind of weird,) have never been inspected.
I really only hear these stories when people travel to the US, lol. It's especially sad+funny (darkly comic, say,) that the guy in OP is a US Citizen traveling back to the US.
They’ll keep them until you sue. A lawsuit costs more than the devices.
You will lose them.
That seems like a wildly different scenario to me. The OP is about a guy who has not committed any crimes. Andrew Tate is a known predator and CSAM peddler, with an active warrant in several countries.
I'll take that risk. It's pretty unlikely, and if it happens, having to buy a new phone is not the worst thing in the world.
> Then it needs a pin
A compromise to this is that many phones have a "lockdown" mode, where it isn't fully off but refuses to accept biometrics until a code/pattern is used to bring it to a more day-to-day mode.
It's less-secure than being fully off, but it also means if you do need to access your phone you can do so more-quickly.
That’s probably why they’ve been pushing the MPC app heavily.
If you’re a U.S. citizen: CBP cannot deny you entry to the United States merely because you refuse to unlock the phone. If you’re a non-citizen seeking admission: refusal is much riskier.
The important wrinkle is that CBP’s published policy expressly guarantees that a person being admitted as a U.S. citizen won’t be denied entry solely because CBP couldn’t inspect the device. It doesn’t give lawful permanent resident (green card holders) that same explicit statement. Instead, it says refusal by a “foreign national” can be considered in an admissibility determination.
Isn't the guarantee for citizens a bit stronger than CBP's policy? I don't think they can lawfully deny entry of a citizen, period.
They cannot (lawfully) deny entry. But they can admit you and then immediately detain and/or arrest you.
Sure, if they have a warrant or probable cause, just like any other law enforcement officer.
In theory, yes, but in practice they can do whatever they want, and suing them after the fact is going to be expensive, and have a high probability of not working out for you.
When interacting with border officials (or any LEOs, for that matter), be polite, don't get hostile or aggressive, but also be firm and don't volunteer any information that you're not required to give.
this only applies if they don't refuse to acknowledge your papers as valid and/or they haven't previously put you on some hidden list of people of interest, in which case the instance where you get to prove you're who you say you are will be mediated, like the rest of the (as per the current system) nonpeople, by as many layers of humilliation and risk to your life and health as they can place.
[dead]
I’ve been asked to hand over my phone when I entered India as a visitor with a valid visa. Yes it was a burner phone. Yes the officer questioned me after seeing only 7 photos in the entire Photos app. It was very obvious that it was a burner phone. I didn’t deceive the officer, instead I just nicely explained why this was a burner phone.
Yep, travelling outside your country of origin, expect that your phone/laptop/ect is subject to search. Anything on you is, it's literally stated. Want to push against that? Sure, makes sense, but just carry a burner phone/device and not worry about it. Literally what the US government recommends when traveling to places like China.
Giving up knowledge (password) is something that is typically scrutinized at the border as well. Had he just handed over the phone and the phone had abilities to self destruct if tampered with (e.g too many incorrect pin entries) -- well the gov's case wouldn't been much harder. If they seized property and accidently destroyed the data, then that's on them.
You are correct, you have to give up the phone but can't be compelled to give up the password, and you'd get it back some indeterminate amount of time later.
It's actually been on the books for a while (decades at least) that customs can search you at the border without a warrant even if you are a citizen.
This case seems to have become a big 'Trump bad' poster child (people are calling the US East Germany in these comments...), but if this exact scenario happened at least in the last two decades (I found an example upholding the searches from 2004) then it would at least be possible to charge them with deleting evidence. Even this probably would have been nothing if he refused to give up his password, not being required to provide a password has been upheld for years. They can seize your phone for some time but I'm unsure on the times they ask and then just let you move on when they find out your a citizen.
As everything on your phone should be backed up, you could just wipe your phone to new.
Then log in with another temp account and use that for border pass etc, and then after border checks log back into your normal account?
I wouldn't really want to deal with the suspicions of having a freshly-wiped phone, or the suspicions of having no phone at all.
A proper burner phone has basic usage on it. Link it to a Gmail account you don't use for anything else so you can have your ridesharing apps on it. Just enough for travel purposes, but nothing else.
If you really have to, have some social media accounts on it too and give them a basic amount of usage. Snap photos of the country you went on the trip to, etc.
Just get a boarding pass from the counter old school style. They still print them.
Why would they need to do that?
leave electronics at home. never take electronics to any airport unless you don't care if everything is read. your only option now.
or have a good enough decoy or encryption system in place. Such as pressing a button to lock or replace key documents but keep the rest intact. So what looks like a sensitive document omits key information but still appears to be legit to observer.
That's probably a bit overkill. TSA doesn't have nearly as much power as CBP, so it's only a concern when coming back across the international border.
the best decoy is a cheap burner phone that you only use for travel purposes