←back to thread

17 points OrbitalShotput_ | 3 comments | | HN request time: 0s | source

This is coming up a lot these days in the news- but Customs and Border Patrol have increased the amount of searches they do for travelers coming to and leaving the US. I find this fascinating- because it feels like an area that should have answers -but that there are only some.

With Laptops, one can do things like dual booting, and basic file or OS encryption -so if you are asked to unlock your laptop, you can show someone your OS- and if they decide to do a advanced search, take it and image it- files and items will still be encrypted. Now, this is the sort of thing Veracrypt's Hidden OS would solve without resorting to individual container and file encryption- however that is not a real option these days as that only works with MBR partitioning, not EFI- and nothing else in that space has appeared.

For phones - the situation is messier.

It appears there is no general encrypted profile app or feature one can do in a similar manner, say with steganography features- Sure one could obtain a Graphene phone or the very latest updated Apple or Android device so the Cellebrite or Greykey device can't break into it if you refuse to unlock your password and they take it to image it. If you cooperate and unlock something for them to do a basic search on and then they take it to image presumably- there's a lack of hidden/profile options that are encrypted or steganographically able to hide files in files which would be enough for this sort of thing.

There also is no whole-imaging solution to make a perfect backup, as current backup methods don't include everything, like if someone has apps not covered by a backup or full settings.

And one does not want to unlock the bootloader or Root a phone to attempt this,that would make them easier from a Cellebrite type attack.

For those of you a bit privacy minded who do like to see how private and secure a setup you can do- How do you handle this? This isn't something totally new, but mobile devices are not as far along as computers it appears- and that is something the general public is fully susceptible to.

1. LinuxBender ◴[] No.43568498[source]
If I had to travel I would just FedEx things to myself at the destination. I like to travel light.

Call ahead to the hotel one is staying at and arrange for the box to show up with the instructions that if travel plans change they are to open the box. Inside will be another box with a FedEx label that returns the box to its origin. Attach a page on the inner box that explains this as well. Sometimes communication is poor at hotels among staff. Attach a coffee gift card to the note on the inside and annotate the card is for whomever is shipping the box back to its origin.

replies(1): >>43572951 #
2. giantg2 ◴[] No.43572951[source]
Customs could still search it if they want. It might be less hassel but more risky if it's out of your hands.
replies(1): >>43585706 #
3. LinuxBender ◴[] No.43585706[source]
That's the idea. I would use disposable things and if they are intrigued by something then they detain the disposable thing and not me.