Skip to main content

Crossing a Hostile Border

I've been rethinking my personal threat model due to wholesale scanning of electronic devices at the U.S. border. I think I've figured out a few things that I can use that might be useful for others.

The problem is this: Currently, Customs and Border Patrol (CBP) is scanning devices, but they are not scanning data that's not on the device or not directly reachable with the device. This is due to their interpretation of Riley v. California -- a U.S. Supreme Court decision that said that law enforcement can't use credentials found on the phone to gather additional data without a warrant. If they're suspicious (or if you annoy them), they can seize your phone. So, I need to be sure that my phone is "disposable" and I won't lose any critical data.

Wiping my phone might work, but there's some information that I'd like to install on my phone before I leave (phone numbers of people I'll be visiting, for example), and if searched, a wiped phone is very suspicious. Instead, I'm planning to use a new "US Only" account that will have phone numbers for the people and hotels I'll be visiting and little else. I can survive with that until I return. I keep most of my passwords in a password manager, so if I've forgotten anything, I can install the password manager and retrieve my passwords after I've crossed the border.

One thing that becomes much more complicated is two-factor authentication (2FA). I don't want to use something like Google Authenticator that stores keys on the phone, because then I won't be able to log in to anything if my phone is lost. Fortunately, I use a Yubikey for 2FA whenever possible. So long as it's not seized (Since I'm a US citizen, they'd really be stretching their legal authority to try), I should be able to keep using it. If not, I've configured my accounts to use a second Yubikey that I'll leave at home.

My process will look like this:

  1. A day or two before the trip, wipe my phone and start forwarding email to my US-only account.
  2. Use the EFF dice list to change the password of my US-only account to something I can remember (so that I can provide the password if ordered to do so). I normally use very long randomly generated passwords, so that even I don't know the passwords to most of my accounts.
  3. Reinstall with a clean US-only account. Install as few apps as possible.
  4. Install anything that will help with the trip itself: US contacts, trip itinerary, etc. (This information may be seized by CBP, but it's all easily discoverable anyway.)
  5. After crossing the border, if I need to do anything weird, reinstall my password manager and any required apps.
  6. When it's time to return home (and cross the border again), repeat this process starting at step 1.
This process should leave me with a phone that's not wiped and has as little information as possible, but it will still have enough information for the trip, and if I'm wrong, I'll be able to install anything else that I need.

One thing that needs to be mentioned here: I'm a boring white guy with a common American first name and a European-sounding last name. I'm also a former U.S. government employee who has been validated with Global Entry. The chance of me being detained or searched at the border is close to zero. I'm doing all of this only because it's good operational security practice. That is the ONLY reason that I'm willing to talk about this. I know that plenty of other people have similar concerns and are doing similar things, but their names are a little bit more strange, or their skin is a bit darker, so they don't dare talk about it publicly. Being able to speak freely about this is a luxury.

Comments

Popular posts from this blog

The Virus By the Numbers

I'm writing this because there's some really insane stuff that's being said by people who should really know better, and I'm sick of discussing it one post or email at a time. So, this is my One Big Post that I'll point people toward rather than bringing it up again and again. In case you haven't noticed, we're in the middle of a pandemic. Just so that we're all using the same terminology:  The virus is Severe acute respiratory syndrome Coronavirus 2 . It's usually abbreviated SARS-CoV-2. It's a brand new kind of Coronavirus, so for a while, before it had this awkward name, people were calling it "novel coronavirus". (For the non-English speakers and D students, "novel" is another word for "new".) The disease that the virus causes is called Coronavirus Disease 2019 , and it's usually abbreviated COVID-19. It's called that because it was discovered in 2019. This came out of nowhere in China in late

The Chromecast conceptual model

Google makes a device called Chromecast . It's a relatively inexpensive way to turn any TV into a "Smart" TV capable of playing movies or music. It's a clever bit of engineering, but I've run into a few people who have trouble understanding how they work. The key thing to understand is that the Chromecast is the device that's actually receiving and playing the movie (or whatever), and your phone is just the remote. Here's how the process works at a high level: You start watching a video on Youtube 30 seconds in, you decide that you'd like to watch the rest on your TV, so you press the "Cast" button. Your phone stops playing and tells the Chromecast "Get this video directly from Youtube and start playing at the 0:30 mark"  When your phone initially asks the Chromecast to start playing, it also specifies a "default thing" to do when the Chromecast is finished. If the Chromecast is playing a Youtube video, it might

Audio upgrade: Schiit Fulla 2

I recently purchased a Schiit Fulla 2 . I was on the fence about it for a long time, but it's held up well, and I'm pretty happy with it. So, here's a small product review. I should probably mention that I'm generally skeptical about "audiophile" anything. I've known too many people who spend way too much money on voodoo like "oxygen-free speaker cables". This makes me reluctant to trust reviews or spend money on anything that I can't test for myself.  I've heard good audio. I go to concerts. I know what music is  supposed to  sound like, and it wasn't what I was getting from any of my computers, even with decent headphones, lossless audio codecs, etc. On the other hand, we have some  Sonos speakers , and with those speakers and a good audio source, music can sound really good. Since I wasn't getting that level of quality at the computer, it meant that there was something between the computer and my ears that was part of