‹ BackHN Continuity

Thread

Border agents can search cellphones without a warrant or reasonable suspicion

235 points · 198 comments · mmh0000

  1. righthand · · focus · HN ↗
    So carry a separate device while traveling. Or wipe your phone, then restore after the border. This is just going to lead to a service that does this for you and the overreaching feds won’t be able to do anything about it.

    And as far as I can tell you still don’t have to give them your pin code.

    1. autoexec · · focus · HN ↗
      They don't need your pin, they can just hack the phone take all your data anyway. ICE has a contract with Cellebrite
      1. puppycodes · · focus · HN ↗
        Not really. Cellebrite isn't magic. If you have an up to date OS and a strong password not pin, encryption functions as it should. The best thing to do is simply have a travel phone.
        1. autoexec · · focus · HN ↗
          It's not magic, but that doesn't mean it doesn't work most of the time.

          From <a href="https:&#x2F;&#x2F;cellebrite.com&#x2F;en&#x2F;blog&#x2F;the-access-gap-is-closed-what-cellebrite-can-unlock-in-2026&#x2F;" rel="nofollow">https:&#x2F;&#x2F;cellebrite.com&#x2F;en&#x2F;blog&#x2F;the-access-gap-is-closed-what... :

          Here’s what that looks like in practice in 2026:

          iOS: Cellebrite supports access to the latest iPhone models and iOS versions, including both after-first-unlock (AFU) and before-first-unlock (BFU) states. Recent updates have introduced new AFU access methods for previously unsupported iOS device configurations, expanding the range of devices that can be accessed without requiring a prior unlock event.

          Android: The latest releases restored and expanded full file system (FFS) extraction across a broad range of newer Android models, which is an area where the competitive landscape had seen fluctuation. Coverage now spans Samsung, Google Pixel and other major Android manufacturers at their current OS versions.

          1. puppycodes · · focus · HN ↗
            &quot;Access&quot; is not what you think it means. This is marketing hype directly from their site. I have first hand experience using their extractors and its not as robust as they make it sound. They extract metadata outside of the encrypted volumes. It all depends on what your worried about.

            Actual hardware 0-days are highly coveted, extremely expensive, military classified tools that TSA does not have access too and never will.

            Edit: CBP not TSA (thanks good callout)

            1. righthand · · focus · HN ↗
              Minor nitpick this wouldnt be TSA but CBP; both are anti-American organizations under DHS.
        2. iAMkenough · · focus · HN ↗
          Imaged encrypted volumes can be decrypted later. We&#x27;re building massive amounts of compute with government bonds these days.
          1. puppycodes · · focus · HN ↗
            This is true for literally everything encrypted. Security is always a function of time and effort. The name of the game is being not worth the effort.
            1. iAMkenough · · focus · HN ↗
              When the effort becomes trivial, so does the justification for it. Doesn’t cost them any of their own money.
            2. puppycodes · · focus · HN ↗
              Once again its not as simple as oh its easy now. It&#x27;s highly dependent on how much time has passed, who you are, what your worried about... etc... making it out like everyone is on the same plane makes the threat assessment worthless.
        3. matheusmoreira · · focus · HN ↗
          Right now it seems GrapheneOS is the only OS capable of resisting Cellebrite.
          1. puppycodes · · focus · HN ↗
            Thats not at all accurate. When you say &quot;resisting&quot; you are glossing over really important distinctions. The lastest versions of iOS are perfectly capable of being locked down in a such a way that they are not able to be penetrated by Cellebrite.

            The info extracted is the nuance your missing here. Cellebrite doesnt break encryption, it brute forces weak PINs and passwords and collects metadata thats outside of the protected volume.

            Your online activity likely exposes much much more about you than the data extracted by Cellebrite. These distinctions matter as its really easy to misunderstand and sensitionalize their tools.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.