‹ BackHN Continuity

Thread

Returning from vacation? The government can search your phone without a warrant

411 points · 378 comments · rbanffy

  1. gblargg · · focus · HN ↗
    Too bad phones aren't easy to do a full back up of, wipe, then restore after you are past the border agents. Or can keep all user data on a microSD card that you remove and secure before the search.
    1. duskdozer · · focus · HN ↗
      Explain how? I've yet to find something reliable like this. At best you can have a decent number of apps automatically reinstalled to the original state, but not all, and most settings don't transfer, etc. And that requires root access, which most people don't have afaik.
      1. ssl-3 · · focus · HN ↗
        I used to do this kind of thing with TiBackup when Android phones were easy to play with and experimentation was more common.

        I'd back up the phone to an SD card and/or send the backup offsite over the network.

        After that, I could nuke whatever I wanted -- or factory reset it, switch to a different OS (we often called them "ROMs" back then), play with that for a bit, switch back and forth, or whatever.

        When the time was right, I'd use TiBackup to restore the backup. It didn't even have to be the same phone. Apps and data were restored to where they had been. Home screens looked the same. Settings and preferences went back to how they were. The same web stuff remained in browser cache, alongside the same cookies.

        There were occasional outliers that didn't come back perfectly, of course, but broadly speaking: It worked very well. Those outliers were few and easy to deal with.

        This required root access. But for a time (years), that was easy.

        (I will never accept any defense of any proclamations that we must be restricted from doing whatever the fuck we want with the hardware that we own. If I can do things with a desktop PC, then I should also be able to do those same things with a pocket computer.)

        1. LWIRVoltage · · focus · HN ↗
          Elsewhere in this very thread I talk about how we need a modern solution for full true image backup for phones; I'm also an example of somebody who could use it, as I have phones where if I was to back up and wipe them I would lose the ability to use some extremely expensive old thermal cameras that work by attaching to them, - if I wiped and reinstalled, even having the apps, they require reaching out to servers for initial authentication that no longer exists. A full image backup would solve this.

          Rooting is now far more difficult unfortunately, and isn't even available mostly; but I don't see a real method to do a full proper image backup of phones today.

          1. ssl-3 · · focus · HN ↗
            I'd like to think that the old TiBackup method would have worked for your cameras. It tried to save the applications along with their data -- including old, online auth data. Almost all of my stuff Just Worked after using it.

            At very least it was way, way better than the wink-and-a-smirk, blind, opaque, vague-handwaving "Your phone is backed up on Google servers!" process that we have these days, wherein: As a practical matter, if I can't touch the backup to examine it, or exercise it at my whim, then that backup doesn't meaningfully exist.

            But as I understand it: Your problem is deeper, and riskier. You can't goof around with these existing phones in any way. If you poke at one and the closed-source black-box app decides that it is unhappy, then that means that there is one fewer phone in the world that can do the things you need to do with your cameras.

            Maybe the best answer for you is to leave those phones alone, and get another phone you can hack on for the express purpose of trying to to get the camera working on it. This takes the risk out of the loop.

            Maybe that means something that passively monitors data over the USB connection and putting together a new app that operates the camera in the same way.

            Or perhaps beginning that process would allow recognition: Maybe it's already using a bog-standard protocol on the wire to talk to the camera and it's NBD to download another app that works with your cameras on any new, random phone.

            Maybe it instead involves a patch for your existing app's APK that bypasses the authentication step, and this can then be used on a different phone.

            Whatever form this liberation takes, it is the kind of thing that a person of adequate skill, or with the right kind of wit and a good LLM, or all of these together, can almost certainly solve. (It might even be easy.)

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.