you are viewing a single comment's thread
view the rest of the comments
[–] 56 points 9 months ago (27 children)

Always turn your phone offer before deplaning and don’t turn it back on until you’ve cleared customs. You can refuse a search and even if they take your phone they still don’t have a method of decrypting a phone that’s encrypted at rest after being turned off and all biometrics are disabled on start up until a password is entered (most phones).

You’ll most likely lose your phone and a few hours but that’s what you have backups for.

  • source
  • hideshow 27 child comments
  • [–] 43 points 9 months ago (4 children)

    Reminder that Apple/Google will absolutely give law enforcement all your cloud data if presented with a warrant. I know this for a fact. Most people's phone data is synced to the cloud. Be careful out there folks.

  • source
  • parent
  • hideshow 4 child comments
  • And this is why encrypted backups should become the norm. Sure, they could always try to crack the encrypted file after it gets turned over, but (assuming you have a good password set for your account) we’re talking about a scale somewhere between “a few billion years” and “the heat death of the universe” with conventional (non quantum) computers.

  • source
  • parent
  • [–] 12 points 9 months ago (11 children)

    *presuming you have a strong password set

    They can and still will run it through a password cracker with a dictionary provided the phone has some method of either exposing the password hash or can be bruteforced on device similar to PIN bruteforcing.

    You can refuse a search

    Which can lead to an up to 24 hour detainment which CBP has been allegedly doing, so do know the consequences.

  • source
  • parent
  • hideshow 11 child comments
  • [–] 1 point 9 months ago (10 children)

    PIN bruteforcing.

    Curious, how does that work? 10000 possibilities aren't many but you get 30s break every 3 failed attempts then 5 more then its every single failed attempts so that'd be ~5000minutes so that's about 3 days. Assuming they get "lucky" it's about 1.5 day. I don't know though what happens after 20 failed attempts, maybe it's 1min break or 20min break.

    Basically, does PIN bruteforcing actually work and if so on what timeframe?

  • source
  • parent
  • hideshow 10 child comments
  • [–] 4 points 9 months ago (1 child)

    I think Apple has fixed this, but they would remove the battery, hook it up to external power. When unlocking, there was a pause/dimming on the phone to show it was wrong, and the computer hacking it would kill the power before the phone wrote that there was a bogus attempt, so you got infinite attempts.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 9 months ago*

    I don't think infinite attempts is the issue, I think the timing of those attempts is what practically limit the usefulness of the attack. Here in the Apple example I imagine rebooting the phone takes longer than 30s. Also if one goes to the length of removing the battery of an iPhone to crack it, this is a pretty serious attempt. One better have proper protections in place.

  • source
  • parent
  • [–] 1 point 9 months ago

    Ah no it relies on either the battery drain method or another exploit that gives you a much higher rate without tripping the device.

    I haven't kept up with the CVEs for this, and I'm sure both Apple and Android have patched several, but for a while police forensics have had access to an AIO cracker tool made by a company that afaik never disclosed these CVEs for the sole purpose of keeping a method of PIN bruteforcing viable.

  • source
  • parent
  • [–] 1 point 9 months ago (1 child)

    It also depends wha kind of password. I know some phones allow longer than 4 digits, and some offer alphanumeric.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 9 months ago

    I don't think that matters as much as the delay because with brute force you can precisely go through a LOT of possibilities so the practical aspect is the attempt frequency. Even 1 number if it's 1 attempt per decade is enough to prevent intrusion.

  • source
  • parent
  • [+] 11 points 9 months ago (4 children)
  • [–] 2 points 9 months ago (2 children)

    I assume its because most people use 4 digit pins.

    Can they crack a long passphrase?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 9 points 9 months ago (3 children)

    I always wipe my phone before traveling.

    There's nothing in my phone that I'd be the least bit worried about "getting out" but it's the principle of the thing.

  • source
  • parent
  • hideshow 3 child comments