Am I being paranoid? (International travel with smart devices)

The OP is worried about their GrapheneOS phone being tampered with during a search. This app is preinstalled on GrapheneOS to verify the core operating system hasn’t been modified or substituted. It does require another Android device though. They may have used the word ‘tampering’ in another way but usually it means to modify or sabotage with malicious intent.

Realistically they will take a byte for byte copy of the device for analysis later. Hidden profiles won’t help there unless the data is at rest encrypted. On GrapheneOS this means after restarting but before entering the code. I don’t think customs would be satisfied with that though. It is also possible to disable data over USB, but again, they won’t like that.

That’s good to hear.

As I read people replies I see that I am.

Its nice to have this community. If I were ask anyone who was not privacy and security focused about even just take a burner phone, most people probably would say I am mad. We know there’s a legitimate reason to be wary, but sometimes it’s knowing where to find that fine line of concern and being unduly paranoid. So thank you for everyone’s replies it has reassured me.

Ah I didn’t think of that. I might be able to use someone else’s phone to verify this, thank you for your suggestion.

Again thank you everyone for your input it is appreciated :blush:

I agree with this. For all the FUD, the chances of a device being seized and searched at the (U.S.) border is extremely low. That being said, if you’re paranoid or truly have something to hide, don’t travel with your main phone.

No specific reports that I could find with a quick search, but it has definitely occurred. The risk would vary greatly by country and target I would imagine.

Not border-specific but a 2024 research report by Citizen Lab about Russia mentions device tampering. Citizen Lab makes the recommendation as emphasized below.

We encourage members of civil society that have lost physical custody of their device to a security service, especially a technically competent service in an authoritarian state like Russia, to seek expert assistance when the device is returned to them. Any person whose device was confiscated and later returned by such services should assume that the device can no longer be trusted without detailed, expert analysis. (emphasis mine)

I assume this recommendation is based on that digital security community (Citizen Lab, Access Now, Amnesty etc.) have received enough cases of security incidents involving device tampering, but I haven’t read case studies of tampering at borders myself. Their recommendation may also be biased in consideration of risks faced by civil society actors: journalists, activists, human rights defenders, lawyers, etc; and may not be the most appropriate for normies.

Some jurisdictions’ laws explicitly authorize adding, editing, removing etc of data held on devices, not just read-only operations like reading and copying, though I cannot recall what legal context (for instance whether it require a warrant). Laws like this may make tampering of data lawful.

Aside: Though tampering could also mean any operation of a person’s device by an unauthorized person (for instance a border agent), I narrowed my answer to unauthorized modifications to a device’s data, software or hardware.

Yes let’s not give them more power, but the real question is how best to protect ourselves from border fascists exercising power they already have.

Good warning. I would avoid tactics that require lying to border agents.

Not having data on devices in the first place is the best data protection tactic. Same applies to devices. Unfortunately there’s not much people can do to protect their hardware while traveling across a border, other than maybe deter/detect physical tampering by using tamper-evident techniques.

wait this made me wonder about something… Won’t they be able to tell that there’s a second profile if see a big size discrepancy? Like if there is 100gb of occupied storage and the innocent owner profile obviously doesn’t have that much data…

A second profile only protects against cursory inspection from your parents or colleagues. Forensic analysis would reveal the second profile immediately. Only full-disk encryption (in an undecrypted state) would conceal the second profile. Each user has their own encrypted home directory. These are impossible to hide, otherwise the phone wouldn’t be able to identify them either. Some operating systems don’t enable encryption by default, so the entire device can be browsed using a portable OS on a USB stick. There is nothing to prevent someone from browsing your downloads folder or Firefox bookmarks in that scenario. Only encryption and switching the device off can prevent that.

My man, you live in an authoritarian country, what do you mean? The developers of Samourai wallet are going to prison for 5 years for creating a wallet that protects people’s privacy. People are being sent back to their countries because their devices are searched at the airport. There’s nothing that isn’t authoritarian about that. And why are some of these people sent back? Because they have memes in their phones about US politicians. Is that not authoritarian? These are just two examples, I can provide many more, I just don’t have the time to list them all.

My man I could use almost the same examples for Australia or South Korea adjusted for local context.

Hell, it’s illegal in France to make fun of Macron’s wife on the internet.

A real authoritarian country would be China or Russia where there is no rule of law and no elections.

Edited to add:

You really shouldn’t be defending samurai wallet. It was designed and promoted as a money laundering tool for criminals on the dark web. Calling it a privacy tool is like saying ransomware MaaS is a cryptography enthusiast tool.

Well, no one said anything about Australia or South Korea. We were talking about the US. And yes, most countries are authoritarian.

To claim that China or Russia are “real authoritarian countries” just because they might be slightly worse off doesn’t mean the US isn’t a real authoritarian country. It totally is.

I would even argue that no elections are way better than the illusion of choice when the end result doesn’t matter. At least when there are no elections people aren’t duped into thinking that they have a choice. People in China live in reality. People in the US who think there’s any significant difference between coke flavoured political party and pepsi flavoured political party are simply delusional. That’s fantasy.

Next you’ll say that Monero should be outlawed because it’s “used as a laundering tool for criminals on the dark web.” You do realize that this is a privacy forum, right? Where people want more privacy, not less? Guess what, all tools can be used for bad purposes. That doesn’t mean that people don’t have a right to keep their finances private. Bad actors will launder money whether the general public has access to these tools or not. The only people that benefit from the general population’s lack of privacy and control over their finances are the criminal banksters. You know, those Epstein loved to work for.

edit: Don’t you feel any sense of irony saying that there’s no rule of law in China and Russia when the Epstein files exist? When absolutely no one involved has been charged? There is no rule of law in the US either. The samourai wallet case is a very recent highlight, but the existence of ICE is also another one. There’s also the case of Ross Ulbricht, who was only pardoned as part of a political campaign. There’s also the case of Julian Assange, who spent torturous years in a UK prison in part at the behest of the US government, trying to extradite him. There’s also the ongoing case of Roger Ver, whose only crime has been writing a book on Bitcoin. There’s also the case of Edward Snowden, who now had to flee for uncovering the criminality of the US government.

Rule of law and US just don’t go together in the same sentence.

The US actually jumps over international law every single day. The fact that the US can attempt regime changes in other countries and install their puppet leaders after decimating entire nations isn’t exactly aligned with “the rule of law” . Pissrael can only get away with a literal genocide because the US abides by it. The US is probably the world’s biggest terrorist dictator.

Hi guys I got through all okay. Just want to say thank you everyone who had input and gave advise, I was clearly worrying too much.