k310
4 hours ago
Everyone please read Surveillance Self Defense from EFF [0]
My advice, take a burner phone to the airport (and elsewhere?), and since devices are subject to warrantless search anywhere and everywhere, via exceptions to the fourth amendment [1] (the constitution seems designed to be bent or outright ignored), keep your data at home and encrypted. The "cloud" is a government data supermarket.
For example.
> While the Fourth Amendment is the foundation, federal and state laws can add layers of complexity. For example, the Patriot Act expanded the government's ability to conduct surveillance and searches, particularly in national security cases, sometimes with a lower burden of proof than traditional criminal investigations.
MUCH lower.
rconti
2 hours ago
The resources you link to are helpful; however, this is not really practical advice for most people most of the time. To the extent that our smartphones are a very helpful device to have in our day-to-day lives at home, they're even more useful in a foreign country where they become our only available computing device; indispensable for keeping in touch back home, navigation on unfamiliar transit systems, translation of unfamiliar languages, and so on.
Of course, with great effort and moderate expense, you could setup a burner phone with access to many of your same accounts and resources, but the more features you add to the burner phone, the more it begins to look like the device you're leaving "safe" at home.
I'm traveling overseas tomorrow and my partner and I will both be taking our phones with us as we do every day in our home country.
palmotea
an hour ago
> Of course, with great effort and moderate expense, you could setup a burner phone with access to many of your same accounts and resources, but the more features you add to the burner phone, the more it begins to look like the device you're leaving "safe" at home.
The trick is to have alternate accounts, and not have your "real" ones configured as you transit sensitive locations like borders. Once you're past, download your apps and log in to your real accounts.
With LLMs that's even easier. I suppose you could set one up to populate your fake Facebook account with convincing, up-to-date "local sports team" fan activity.
Don't call attention to yourself, make noncompliance look like compliance.
zrm
an hour ago
> the more features you add to the burner phone, the more it begins to look like the device you're leaving "safe" at home.
Wouldn't a sensible way to do this be to create an encrypted backup of your device on a VPS, then restore it to the "burner phone" once you're on the other side of the border, and wipe the device again before you come back?
The idea being that whenever you're at the border crossing, the device contains nothing, and the passphrase for the backup is in your head.
finaard
2 hours ago
I find modern smartphones more and more unusable, both OS becoming more hostile towards the user, and applications widely moving to dropping logins in regular intervals. That has been happening for years already, so I slowly moved more and more stuff back to a computer.
By now I'm at a point where I no longer even backup my phone - there are a bunch of apps, but I can just install them and log in again on a different device as needed.
The final step to make it truly throwaway was me doing a custom matrix bridge for SMS earlier this year - I had voice routing setup for a while already. So now my old SIM cards are in a 4G modem at home, and the phone I carry around with me just has a data SIM. Huge quality of life improvement, as I can terminate as many numbers as I want there, and have access to both voice and SMS data from my computer as well.
FuriouslyAdrift
4 hours ago
When I travel internationally, I do not take any electronics with me.
If I need a cell phone, laptop, etc., then I will buy or rent something cheap at the destination.
I got into the habit while traveling back and forth the mainland China as it was our corporate policy (and we never brought any electronics back, either).
alyeska2
3 hours ago
I tried that once.
Then when I tried to log in to my Gmail account at my destination, it flagged it as a suspicious login attempt and wouldn't let me in without entering a code they texted to my American phone number, which meant I was locked out of my email for the duration of the trip.
Plus travel day realities often require your phone and accounts - plane tickets, Uber/Lyft, hotel reservations or updates from Airbnb with check-in instructions, door codes, etc.
It's a tremendous challenge and hassle for any regular person. We really just need to push back on the government overreach. It's tragic that half of the Trump voters proclaim to be "small government" and "Don't tread on me" but then tolerate things like this. There's certainly a bipartisan group of people opposed that are large enough to effect change if we work together.
belorn
3 hours ago
I 100% agree that the best solution would be for the law to catch up and actually treat privacy as a human right. Until that time there are things which, while challenging and a hassle, do help.
I would use the same sim-card in the burner phone. Any attack by the government that they can do with your real sim card can also be done through phone number spoofing.
For email, use unique emails (things like booking+youremail@...) for reservations/bookings/tickets and have those forwarded to a second email account that you want to use during the trip. It is already good privacy hygiene to use unique emails for all types of registrations, and you will have more control when services eventually have a leak.
leptons
2 hours ago
> (things like booking+youremail@...)
This is so trivially easy to bypass. If you're a service selling email addresses, just strip off the booking+ part and you have the "real" email address.
All my sign-up email addresses are via a catch-all email, so I can just give a service "thisservice@mydomain.com", or "thatservice@mydomain.com", so I there is no single "real" email address, and I get to track who exactly is selling my email address. So far I haven't had problems with anyone spamming "anything@mydomain.com".
belorn
an hour ago
They can bypass it, and as the user you can also use any other sign or character that you want. If you email is foo@ then you can use the letter x, as registrationxfoo@. A popular choice for a company email is first.lastname@, so you can use a . for it, or the - character. + is just what some program, like procmail and Sieve, will recognize without much trouble.
Using a a catch-all email with your own domain works also perfectly fine. Doesn't work as well if there is multiple email users of that domain.
alexgieg
2 hours ago
It isn't that they tolerate it, it simply doesn't affect them, so they don't care. Besides, it affects many they dislike, so that's always a bonus.
Remember, when ultra-partisans, of most political ideologies, demand rights and freedoms, there's almost always an implied "for me and mine" in there. Exceptions to this are extraordinarily rare, even more so nowadays.
FuriouslyAdrift
2 hours ago
You're not going to have any access to non-local data or services while traveling unless you set up a foreign office first (that's what we did).
Or go satellite which in someplaces is a major crime.
leptons
2 hours ago
>It's tragic that half of the Trump voters proclaim to be "small government" and "Don't tread on me" but then tolerate things like this.
Let's be real. Those people don't travel. They've never left the country, and most have likely never left their state, or even their hometown. I know a person like this - they refuse to fly on a plane to go anywhere because they are not allowed to bring their gun on the plane - they are a real "don't tread on me" 2nd amendment/NRA type. And they will never vote for anyone but a Republican no matter how bad things get.
iamnothere
an hour ago
You can bring a gun on the plane, you just need to have it in a locked case, and it can’t be a TSA lock. You also have to declare it and open the case for inspection when checking it.
It may be hard to bring it overseas though.
toyg
4 hours ago
has anybody ever challenged the PATRIOT Act on compliance with the 4th Amendment?
Not that it really matters, with the current Supreme Court being what it is, but still...
cogman10
3 hours ago
The issue, as I understand it, is that someone with standing to sue over the 4th amendment would be prosecuted under a FISA court. Those cases due to how the court was created and structured, do not end up in front of the supreme court.
It's one of those weird things in the US constitution which allow for congress to create new federal courts which don't ultimately fall under the jurisdiction of the regular federal courts.
doctorpangloss
2 hours ago
"Hey Mr. Border Guard, this is a burner phone, have at it!"
"Okay can you login to your email for me? If not I'm going to have to keep you here until you do."
iamnothere
2 hours ago
If you’re talking about a US citizen returning home, they can’t hold you indefinitely. If you disagree, I challenge you to find a counter example.
All bets are off if you’re a non-citizen entering another country, it depends on the laws and customs there.
trollbridge
2 hours ago
You have to set up trivial, low value “burner” email that you use for your emailing activity when overseas, and other related social media accounts, and make sure to keep them “warm”.
A spare old Pixel or iPhone SE is $20-$50 you can use for this purpose.