Hacker News new | ask | show | jobs
by msh 2 days ago
I dont understand why people like a journalist working on things they dont want seized would carry this kind of data on their device at a situation like this (border crossing), I see it as more useful to remove that kind of data from the device first.
4 comments

Probably because everything seems to be an "app" these days. Even when it has no business being one.
Exactly. Everything must be switched to Service as a Software Substitute. It's for your own safety, you see.
So delete messengers, email apps and other comms?

Delete the contact book? Clear calendars?

Where exactly should one stop?

You're misinterpreting. They mean that there are additional options next to only keeping these things on your phone.
What am I misinterpreting? OP literally said they don't understand why a journalist would carry these data with them. As if the data is a file on your phone. Data can be a contact book on your phone, or a messenger with E2E encrypted messages. What would the alternative to that be? Sending pigeons?
Restoring from remote backup when you reach your destination, then wiping again before you cross borders. Or shipping the (encrypted) data separately and picking it up after safe arrival.
What's the difference between this and wiping when under duress using the special PIN? If you aren't being checked you don't wipe and are gopd to go.
Because you show up with nothing on you, and there’s no way to prove that the backups even exist. Especially given how often people travel with blank/disposable phones.

Just as the border guard can’t require you to fetch something from your house before entry, they can’t require you to restore from a remote backup that they don’t even know about.

Wiping under duress is unlawful and could lead to prosecution in some juridictions.

On the other hand I don't know of any juridiction that force you to carry all the personal data in a single device when crossing borders. It would moat likely not even be possible.

The government can easily get your remote backup, of course. It's just that border control won't know you have one.
Not if it’s encrypted and self-hosted. Your doomerism is silly. “The government” is not all-powerful, or they wouldn’t need to pester people for PINs at the border.
If the government could easily get the remote backup they would have already done it.
Because you may need the data in the data during/after your travel and lack clean way to access safely, securely and anonymously remotely.
No one is stopped from backing up important data. It is, in fact, kind of boneheaded to keep all "valuables" on a single device. I don't understand the scenario of not trusting a device to safely access the Internet or the telephony grid while also insisting that they need a PHONE to keep all their stuff on where they're going, and at the same time somehow trust that both themselves and their possessions are perfectly safe from seizure and extortion in the very same location.
Personally I just got grapheneos to replace my normal phone. It's nice, it works for the user instead of the advertiser, and its security features help block antiuser features in apps
I personally run iOS but have given GrapheneOS an extended run on a development phone I use for work, and I have to say it really is a much tidier, less distracting, smoother and more responsive experience than any other Android setup I've used before.
This is where we need "cloud phones as a service" / "selfhosting a cellphone at home with some kind of remote access system".

Not even kidding here, it's time to bring out thin client computing to cellphones. Let the spicy stuff sit somewhere else. I could bootstrap a Tailscale or Netbird signin remotely, install the access client, and remote back into the 'normal phone'.

Would be then funny to map that to lockscreen PINs - enter a PIN to unlock the device, be remoted into "phone A", enter another pin and be remoted into "phone B", enter another PIN and you're on the 'local device' session. (Or duress-PIN kill "phone A" if someone attempts to bruteforce PINs, etc, etc...)

You can already do most of that with GrapheneOS or even an iPhone. My contacts, files, photos, etc. are on my home server, accessed through a VPN. My GrapheneOS phone only runs a handful of open source apps. If I were to lose the phone, I would simply revoke the Wireguard key and there wouldn't be anything valuable left on it.
> "selfhosting a cellphone at home with some kind of remote access system

You can use TeamViewer for that. Or maybe scrcpy could be coerced into working in a similar way.

Good luck making it work again remotely after a long power outage.
Not sure what do you mean? If that is a concern, there are solutions for this. Like UPSes and backup cellular connections.
Remove and securely overwrite, otherwise the data can still be recovered from the disk image. We have not made privacy easy.