> Graphene OS has a duress password and PIN, which “will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested.”
iOS kinda also offers such a solution, though a bit more suspicious to perform: "Erase all data on this iPhone after 10 failed passcode attempts"
Turn on Advanced Data protection, which encrypts it so Apple can give them the data, but they don't have the keys to decrypt it. Doesn't help if the other person you're talking to doesn't have it turned on though.
iPhones have unique identifiers. So do you, via your set of emails used. The email maps to the iCloud account, which then maps to the iPhone. It would be trivial to map a backup to an iPhone.
"If you’re a fan of privacy in our age of creeping digital authoritarianism, there’s one famously effective way to pass through U.S. Customs at an airport without worrying about a device search: travel with a burner phone only."
What about setting your phone from the get go to store all data on the micro sim card ? Then, when traveling through airports, swap out for another micro sim that has some small, useless data on it, fake contact list, etc. ?
Real sim card is so small can be hidden in a million places.
At least on Android they've removed the ability to encrypt data stored on external media, so in exchange for the ability to do this you're carrying around everything unencrypted (except what individual apps might encrypt themselves).
I thought the play was to travel with a burner and mail the real phone to a drop somewhere in the destination country. Supposing you could just put all your sensitive data on a microsim or microsd and do the same thing, but this all feels like different colored wrappers on the same piece of candy: don't bring data you want to keep secret to the place where they're allowed to use force to steal secret data. Obv packages are subject to search and seizure at borders the same way you and your phone are but a package in the mail has the advantage of volume and relative anonymity. There are a lot of packages and not enough resources to seize and search all of them, and it's harder to tie the package to a person or entity that warrants increased suspicion if it's mailed anonymously from another country than it is to tie a phone to the guy whose pocket it was in when he tried to cross the border.
Disgusting. I’ve never had to let anyone touch my phone in my entire life in any country I’ve visited.
Is there a list of countries that does this? At this point it’s obvious I won’t ever be traveling to the US, but I’m curious if genuinely authoritarian countries like China are actually less of a police state at the border than the USA.
I think almost all countries do this if your name is on a list (as this person's is). It's the nature of the lists and what gets your name added to them that varies from country to country.
It means you aren't entitled to visit a foreign country. You aren't entitled to them letting you in.
Of course in a perfect world we all trust each other and have open borders, but that's a privilege we have to work for. I'm European and enjoy the open borders, but also am well aware that such a situation is not a given.
Cannot mean loss of personal rights, sure. Showing up at a border and being required to give up personal rights isn't ok.
But many people in this thread are writing as if they actually believe they have a right to go anywhere, and that simply isn't the case. It's the kind of thing you need live in a strong passport country to believe.
I've been to China recently. No phone search whatsoever. Their Internet is behind the famous Great Firewall though, but there is no issue using a (foreigner-only) unlocked sim or e-sim to access the rest of the Internet.
> Graphene OS has a duress password and PIN, which “will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested.”
iOS kinda also offers such a solution, though a bit more suspicious to perform: "Erase all data on this iPhone after 10 failed passcode attempts"
But if the data is backed up on iCloud, Apple will provide it with a warrant.
Turn on Advanced Data protection, which encrypts it so Apple can give them the data, but they don't have the keys to decrypt it. Doesn't help if the other person you're talking to doesn't have it turned on though.
But how will they prove which Apple account was just wiped from that iPhone?
iPhones have unique identifiers. So do you, via your set of emails used. The email maps to the iCloud account, which then maps to the iPhone. It would be trivial to map a backup to an iPhone.
Ah yes that makes sense, they can retrieve the iPhone's serial number and warrant Apple to handover the associated iCloud backup.
[dead]
Can be set to less attempts via MDM profiles.
Same for Android.
"If you’re a fan of privacy in our age of creeping digital authoritarianism, there’s one famously effective way to pass through U.S. Customs at an airport without worrying about a device search: travel with a burner phone only."
What about setting your phone from the get go to store all data on the micro sim card ? Then, when traveling through airports, swap out for another micro sim that has some small, useless data on it, fake contact list, etc. ?
Real sim card is so small can be hidden in a million places.
At least on Android they've removed the ability to encrypt data stored on external media, so in exchange for the ability to do this you're carrying around everything unencrypted (except what individual apps might encrypt themselves).
This is not true at all, adopted storage is encrypted.
It seems like I was wrong about the platform support, but in fact some OEMs like Samsung have disabled it.
https://www.androidauthority.com/using-microsd-card-android-...
Most of the budget / midrange devices likely to have SD card slots do support it though.
I thought the play was to travel with a burner and mail the real phone to a drop somewhere in the destination country. Supposing you could just put all your sensitive data on a microsim or microsd and do the same thing, but this all feels like different colored wrappers on the same piece of candy: don't bring data you want to keep secret to the place where they're allowed to use force to steal secret data. Obv packages are subject to search and seizure at borders the same way you and your phone are but a package in the mail has the advantage of volume and relative anonymity. There are a lot of packages and not enough resources to seize and search all of them, and it's harder to tie the package to a person or entity that warrants increased suspicion if it's mailed anonymously from another country than it is to tie a phone to the guy whose pocket it was in when he tried to cross the border.
That isn't something that actually exists
Replace micro SIM with micro SD, and it can be done on android.
Still no. Plenty of references to SD card stuff in the main storage.
If you root it, you can put all writable storage on the SD card, and the phones internal memory becomes readonly
less than a minute of an duckduckgo search: https://www.sysmocom.de/products/sim/sysmousim/index.html
This does at best 1% of what the parent mentions. Is that going to hold all your data across all your phone apps?
Do not cross with your gadgets. And just do not go to / via the US.
“just do not go to / via the US” is not a serious solution for a lot of people.
When this hits the supreme Court they need to debar the prosecutors who bring these cases to begin with.
Fascinating case and arms-race, seems like part of the issue is the bricking is too obvious...
Title is: A Feature That Makes Your Phone Data Self-Destruct in Authorities’ Hands May Soon Have Its Day in Court
And it's 3 day old news
[dupe] https://news.ycombinator.com/item?id=49024436
Disgusting. I’ve never had to let anyone touch my phone in my entire life in any country I’ve visited.
Is there a list of countries that does this? At this point it’s obvious I won’t ever be traveling to the US, but I’m curious if genuinely authoritarian countries like China are actually less of a police state at the border than the USA.
I think almost all countries do this if your name is on a list (as this person's is). It's the nature of the lists and what gets your name added to them that varies from country to country.
Visiting another country is a privilege, not a right.
This is a US citizen, so that’s a moot point
That, whatever it means, cannot mean losses of personal rights.
It means you aren't entitled to visit a foreign country. You aren't entitled to them letting you in.
Of course in a perfect world we all trust each other and have open borders, but that's a privilege we have to work for. I'm European and enjoy the open borders, but also am well aware that such a situation is not a given.
Cannot mean loss of personal rights, sure. Showing up at a border and being required to give up personal rights isn't ok.
But many people in this thread are writing as if they actually believe they have a right to go anywhere, and that simply isn't the case. It's the kind of thing you need live in a strong passport country to believe.
Most countries disagree?
Rights are universal, whether a state cares about them or not.
Some might even say these are natural rights.
I've been to China recently. No phone search whatsoever. Their Internet is behind the famous Great Firewall though, but there is no issue using a (foreigner-only) unlocked sim or e-sim to access the rest of the Internet.
I travelled to the US three times and once had my devices checked. Travelled to China more than 50 times, never had anything checked.
That's because they already checked in advance :)
UK passed a law for this recently. Germany has been doing it for a while.
[dead]
[dead]