Skip to main content

Crossing a Hostile Border

I've been rethinking my personal threat model due to wholesale scanning of electronic devices at the U.S. border. I think I've figured out a few things that I can use that might be useful for others.

The problem is this: Currently, Customs and Border Patrol (CBP) is scanning devices, but they are not scanning data that's not on the device or not directly reachable with the device. This is due to their interpretation of Riley v. California -- a U.S. Supreme Court decision that said that law enforcement can't use credentials found on the phone to gather additional data without a warrant. If they're suspicious (or if you annoy them), they can seize your phone. So, I need to be sure that my phone is "disposable" and I won't lose any critical data.

Wiping my phone might work, but there's some information that I'd like to install on my phone before I leave (phone numbers of people I'll be visiting, for example), and if searched, a wiped phone is very suspicious. Instead, I'm planning to use a new "US Only" account that will have phone numbers for the people and hotels I'll be visiting and little else. I can survive with that until I return. I keep most of my passwords in a password manager, so if I've forgotten anything, I can install the password manager and retrieve my passwords after I've crossed the border.

One thing that becomes much more complicated is two-factor authentication (2FA). I don't want to use something like Google Authenticator that stores keys on the phone, because then I won't be able to log in to anything if my phone is lost. Fortunately, I use a Yubikey for 2FA whenever possible. So long as it's not seized (Since I'm a US citizen, they'd really be stretching their legal authority to try), I should be able to keep using it. If not, I've configured my accounts to use a second Yubikey that I'll leave at home.

My process will look like this:

  1. A day or two before the trip, wipe my phone and start forwarding email to my US-only account.
  2. Use the EFF dice list to change the password of my US-only account to something I can remember (so that I can provide the password if ordered to do so). I normally use very long randomly generated passwords, so that even I don't know the passwords to most of my accounts.
  3. Reinstall with a clean US-only account. Install as few apps as possible.
  4. Install anything that will help with the trip itself: US contacts, trip itinerary, etc. (This information may be seized by CBP, but it's all easily discoverable anyway.)
  5. After crossing the border, if I need to do anything weird, reinstall my password manager and any required apps.
  6. When it's time to return home (and cross the border again), repeat this process starting at step 1.
This process should leave me with a phone that's not wiped and has as little information as possible, but it will still have enough information for the trip, and if I'm wrong, I'll be able to install anything else that I need.

One thing that needs to be mentioned here: I'm a boring white guy with a common American first name and a European-sounding last name. I'm also a former U.S. government employee who has been validated with Global Entry. The chance of me being detained or searched at the border is close to zero. I'm doing all of this only because it's good operational security practice. That is the ONLY reason that I'm willing to talk about this. I know that plenty of other people have similar concerns and are doing similar things, but their names are a little bit more strange, or their skin is a bit darker, so they don't dare talk about it publicly. Being able to speak freely about this is a luxury.

Comments

Popular posts from this blog

Stinky cheese, man

I'm living in a place that's known for it's cheese. There are hundreds of kinds of cheese at my local grocery store. I try something different every time I go shopping, and I've still barely scratched the surface of what's available. There's one kind of cheese that deserves special mention: Raclette . Raclette is strange for a few different reasons. Most notably, it's almost always served cooked, and there's a bit of a ritual around cooking it. You will never be offered raw raclette. Why? Raw raclette is pungent stuff. It's hard to describe the smell, but I've heard it described as a cross between sweat socks, vomit, and curdled milk. To say that it stinks is a polite understatement. So, why on earth would anyone eat it? Because when you cook it, you somehow cook the stink out of it, and what's left is sublime. It's a sort of oily cheese, and you get something like the best pizza or nacho cheese you've ever had. I've hea...

Sometimes, things work as intended

A small computer success story: I have a Synology NAS at home. For those who aren't familiar with them, they're small computers that are set up to make storing and sharing files easy. They keep your data across multiple hard drives so that if a hard drive fails, no data is lost. Or, at least, that's the theory. After we moved last year, I set up the NAS and ran all of the status checks. It reported that one drive was still working but starting to have problems. I bought another drive, plugged it in, and set it as a "hot spare" (basically, the system knew about it, but it wasn't being used). I also turned on monthly disk checks. Months passed with no more problems. ...until last Tuesday. On Tuesday night, the system automatically sent us mail to tell us that The troubled disk had finally failed. Since we had a hot spare, it would be used as a replacement disk and our data would be copied to it. When everything was finished, the system would let us k...

Actual Size

I get a lot of questions about Switzerland's size. So, I put together a spreadsheet showing Switzerland's size relative to each US State. You can view the full spreadsheet on Google Sheets , but here are some highlights: The two states that are closest in size to Switzerland are Maryland and West Virginia. Maryland is 61% (about 2/3x) of the size of Switzerland. West Virginia is 151% (about 1 and 1/2x) of the size of Switzerland. Pennsylvania is 281% (about 3x) of the size of Switzerland. One of the nice things about living in a small country is the short distance to the borders. I can be in Germany in an hour. France, Lichtenstein, or Austria in 2 hours, or Italy in 4 hours (less when full service through t he Gotthard Tunnel opens later this year). This weekend, we're going to visit... somewhere, and "do you want to go to Milan or Munich" is about as difficult as "Do you want to go to Columbus or Buffalo?"