What personally identifiable information should I delete from my smartphone and email before travelling to a high-risk country?










18















I'll be travelling to Mongolia, and I've heard there's a non-trivial chance of theft. I'll be taking two Apple iPhones with me, and I'm not too concerned about the theft of the devices themselves, as that's a bounded cost.



Do I need to take precautions against identity theft, and if so, what personally identifiable information should I delete from my smartphone and email before travelling?



The only personally identifiable information on my email and smartphone relate to me as an Australian - I have worked for a year in the US, but that was prior to me setting up the only email account set up on my phones, and buying my iPhones.



Related questions: Photocopies of important documents stolen (more about what to do after theft has occurred, not beforehand), and What harm can be done with a copy of one's passport? (specific to passports). Wikivoyage has a section on identity theft, but it's more or less only about passports.










share|improve this question



















  • 8





    I don't see anything that makes this Q Mongolia-specific, so could you edit it to make it a general question?

    – mts
    Jul 2 '16 at 16:30











  • It took the FBI several weeks to find a person that could hack the iPhone in under 2 mins, there are apps and tools out now thanks to this that make it a one and two click operation to gain accessto an iPhone. Just take a dummy phone a cheap $10.00 touch screen while your on holiday so no personal info can be stolen.

    – user46893
    Jul 2 '16 at 23:02











  • What about source of your claim? (One click app for unlocking an iphone ios9+)

    – Kyslik
    Jul 3 '16 at 0:32






  • 1





    @mts how does it look now?

    – Andrew Grimm
    Jul 3 '16 at 3:27















18















I'll be travelling to Mongolia, and I've heard there's a non-trivial chance of theft. I'll be taking two Apple iPhones with me, and I'm not too concerned about the theft of the devices themselves, as that's a bounded cost.



Do I need to take precautions against identity theft, and if so, what personally identifiable information should I delete from my smartphone and email before travelling?



The only personally identifiable information on my email and smartphone relate to me as an Australian - I have worked for a year in the US, but that was prior to me setting up the only email account set up on my phones, and buying my iPhones.



Related questions: Photocopies of important documents stolen (more about what to do after theft has occurred, not beforehand), and What harm can be done with a copy of one's passport? (specific to passports). Wikivoyage has a section on identity theft, but it's more or less only about passports.










share|improve this question



















  • 8





    I don't see anything that makes this Q Mongolia-specific, so could you edit it to make it a general question?

    – mts
    Jul 2 '16 at 16:30











  • It took the FBI several weeks to find a person that could hack the iPhone in under 2 mins, there are apps and tools out now thanks to this that make it a one and two click operation to gain accessto an iPhone. Just take a dummy phone a cheap $10.00 touch screen while your on holiday so no personal info can be stolen.

    – user46893
    Jul 2 '16 at 23:02











  • What about source of your claim? (One click app for unlocking an iphone ios9+)

    – Kyslik
    Jul 3 '16 at 0:32






  • 1





    @mts how does it look now?

    – Andrew Grimm
    Jul 3 '16 at 3:27













18












18








18


3






I'll be travelling to Mongolia, and I've heard there's a non-trivial chance of theft. I'll be taking two Apple iPhones with me, and I'm not too concerned about the theft of the devices themselves, as that's a bounded cost.



Do I need to take precautions against identity theft, and if so, what personally identifiable information should I delete from my smartphone and email before travelling?



The only personally identifiable information on my email and smartphone relate to me as an Australian - I have worked for a year in the US, but that was prior to me setting up the only email account set up on my phones, and buying my iPhones.



Related questions: Photocopies of important documents stolen (more about what to do after theft has occurred, not beforehand), and What harm can be done with a copy of one's passport? (specific to passports). Wikivoyage has a section on identity theft, but it's more or less only about passports.










share|improve this question
















I'll be travelling to Mongolia, and I've heard there's a non-trivial chance of theft. I'll be taking two Apple iPhones with me, and I'm not too concerned about the theft of the devices themselves, as that's a bounded cost.



Do I need to take precautions against identity theft, and if so, what personally identifiable information should I delete from my smartphone and email before travelling?



The only personally identifiable information on my email and smartphone relate to me as an Australian - I have worked for a year in the US, but that was prior to me setting up the only email account set up on my phones, and buying my iPhones.



Related questions: Photocopies of important documents stolen (more about what to do after theft has occurred, not beforehand), and What harm can be done with a copy of one's passport? (specific to passports). Wikivoyage has a section on identity theft, but it's more or less only about passports.







security australian-citizens fraud






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Apr 13 '17 at 12:52









Community

1




1










asked Jul 2 '16 at 5:45









Andrew GrimmAndrew Grimm

12.3k971180




12.3k971180







  • 8





    I don't see anything that makes this Q Mongolia-specific, so could you edit it to make it a general question?

    – mts
    Jul 2 '16 at 16:30











  • It took the FBI several weeks to find a person that could hack the iPhone in under 2 mins, there are apps and tools out now thanks to this that make it a one and two click operation to gain accessto an iPhone. Just take a dummy phone a cheap $10.00 touch screen while your on holiday so no personal info can be stolen.

    – user46893
    Jul 2 '16 at 23:02











  • What about source of your claim? (One click app for unlocking an iphone ios9+)

    – Kyslik
    Jul 3 '16 at 0:32






  • 1





    @mts how does it look now?

    – Andrew Grimm
    Jul 3 '16 at 3:27












  • 8





    I don't see anything that makes this Q Mongolia-specific, so could you edit it to make it a general question?

    – mts
    Jul 2 '16 at 16:30











  • It took the FBI several weeks to find a person that could hack the iPhone in under 2 mins, there are apps and tools out now thanks to this that make it a one and two click operation to gain accessto an iPhone. Just take a dummy phone a cheap $10.00 touch screen while your on holiday so no personal info can be stolen.

    – user46893
    Jul 2 '16 at 23:02











  • What about source of your claim? (One click app for unlocking an iphone ios9+)

    – Kyslik
    Jul 3 '16 at 0:32






  • 1





    @mts how does it look now?

    – Andrew Grimm
    Jul 3 '16 at 3:27







8




8





I don't see anything that makes this Q Mongolia-specific, so could you edit it to make it a general question?

– mts
Jul 2 '16 at 16:30





I don't see anything that makes this Q Mongolia-specific, so could you edit it to make it a general question?

– mts
Jul 2 '16 at 16:30













It took the FBI several weeks to find a person that could hack the iPhone in under 2 mins, there are apps and tools out now thanks to this that make it a one and two click operation to gain accessto an iPhone. Just take a dummy phone a cheap $10.00 touch screen while your on holiday so no personal info can be stolen.

– user46893
Jul 2 '16 at 23:02





It took the FBI several weeks to find a person that could hack the iPhone in under 2 mins, there are apps and tools out now thanks to this that make it a one and two click operation to gain accessto an iPhone. Just take a dummy phone a cheap $10.00 touch screen while your on holiday so no personal info can be stolen.

– user46893
Jul 2 '16 at 23:02













What about source of your claim? (One click app for unlocking an iphone ios9+)

– Kyslik
Jul 3 '16 at 0:32





What about source of your claim? (One click app for unlocking an iphone ios9+)

– Kyslik
Jul 3 '16 at 0:32




1




1





@mts how does it look now?

– Andrew Grimm
Jul 3 '16 at 3:27





@mts how does it look now?

– Andrew Grimm
Jul 3 '16 at 3:27










6 Answers
6






active

oldest

votes


















37














If you have a sufficiently modern iPhone (eg. anything that runs iOS 9 would be fine), then enable a passcode, set "Require Passcode" to "Immediately" (so you have to enter it every time you open the phone) or something short. The phone's memory is encrypted using a key derived from the passcode. No passcode, no personally identifiable data.



If you do this, then the chance of identity theft due to a stolen phone is effectively zero.






share|improve this answer


















  • 17





    This answer is correct, but assumes the OP won't be in the situation of being forced to unlock the device (whether by police, immigration authorities, plain old criminals, etc.). If that's a concern then the question has a lot more interesting depth to it.

    – R..
    Jul 2 '16 at 18:26






  • 2





    @R.. I'm not that worried about that scenario, as at least I'd know about it happening. (Unless someone's snooping on me using the iPhone)

    – Andrew Grimm
    Jul 3 '16 at 3:55






  • 2





    You should also disable notification preview, as the iphone reveals a few lines of text. It is useful especially for messages

    – code ninja
    Jul 3 '16 at 16:08






  • 4





    @KeithM: The easiest way to mitigate that risk is to set the "Erase Data" option which erases all data on the device after 10 failed passcode attempts. The second easiest way is to use a longer alphanumeric passcode instead of a 4- or 6-digit one.

    – Greg Hewgill
    Jul 4 '16 at 2:18






  • 3





    @KeithM: the PIN code used in iOS and Android is very good. You have an exponential cool-down time between attempts (starting from the 5th) - that is it takes longer and longer between attempts to use the PIN. After some time you will have to wait a week between attempts. On top of this you can set the iPhone to erase after 10 missed attempts. The encryption behind this scheme is very good too.

    – WoJ
    Jul 4 '16 at 6:44


















20














None, as long as you lock your phone with a password. It took the FBI several weeks of efforts to crack an iPhone belonging to the San Bernardino mass shooter, so a random low-level thief won't have the skills or tools to access your encrypted information.



I would worry more about information stolen on your laptop, although that also can be mitigated by encrypting your drive with VeraCrypt or a similar piece of software.






share|improve this answer


















  • 7





    I use BitLocker that is shipped with Windows.

    – Nean Der Thal
    Jul 2 '16 at 8:47






  • 3





    @HeidelBerGensis Which again unless you're the government (whom definitely has BitLocker backdoors) no one can access it.

    – Insane
    Jul 3 '16 at 2:14







  • 5





    @Insane There are no backdoors in Bitlocker. (The FBI has asked and been rebuffed.)

    – HopelessN00b
    Jul 3 '16 at 2:25







  • 6





    @HopelessN00b Crap the FBI said they didn't? Guess they don't!

    – Insane
    Jul 3 '16 at 2:27






  • 4





    @Insane No, the Microsoft engineers told them shove it.

    – HopelessN00b
    Jul 3 '16 at 2:27


















8














Unless you need that specific device, I would get a throw-away device to carry in questionable situations. You can get decent Android devices for under $100 US.






share|improve this answer


















  • 2





    Using the specific device is more convenient, so that I'm taking photos on the same device as usual.

    – Andrew Grimm
    Jul 3 '16 at 3:35


















8














Most people that target identify theft are not looking at your cellular phone; they are looking at things that can be used to impersonate you - so your id card, passport, etc.



People stealing phones are looking at reselling them for a quick buck. So, if you put a passcode on your phone, it makes it less of a target for being sold on. iPhones in particular have robust security (as detailed by Greg).



I would not be worried about my identity being stolen via my phone.






share|improve this answer






























    6














    Everyone has given good advice about the phone and that it will almost undoubtedly be safe if you put a password on it (rather than a short PIN). The only issue that I see is to ensure that access to your email service is encrypted. Almost all are these days, so it's only a concern if you access mail without using SSL.



    You will see this under Advanced Settings in account setup where it should have "Use SSL" selected.






    share|improve this answer























    • How is this going to prevent identity theft?

      – Burhan Khalid
      Jul 4 '16 at 8:28











    • @BurhanKhalid If you're downloading and sending email over an unencrypted connection, you're likely to be providing access to PII

      – Berwyn
      Jul 4 '16 at 8:33






    • 1





      @BurhanKhalid Ensuring your email connection is protected by SSL prevents someone intercepting your email connection, learning your password and reading all your previous email. Within your email is likely to be other information about your identity, including name, birth date, address etc, sent in previous mails. Having access to someone's emails is a rich source of information useful for identity theft. Also you could use for some forms of 2FA also useful for identity theft in some cases.

      – Berwyn
      Jul 4 '16 at 8:40






    • 2





      @BurhanKhalid You cannot spoof an SSL connection without installing a root CA on the phone. If an attacker can do that, they can do anything.

      – Berwyn
      Jul 4 '16 at 8:46






    • 1





      @BurhanKhalid GMail in Chrome has certificate pinning, although if you go to the trouble of installing a root certificate with global signing privileges, it will be ignored for the reasons you cite (app testing and system administrators imposing policy on employees). If a Chinese proxy asked me to install a root certificate, I'd probably decline ;)

      – Calchas
      Jul 4 '16 at 23:17



















    2














    The only other recommendation I have is to delete (uninstall/remove) any banking related apps on the phone before your travel, for 3 reasons:



    1. It is not too difficult to retrieve logs generated by apps installed on a phone and I wouldn't completely rely on the banks that they have secured their apps in all possible ways

    2. You are likely to access internet via public WiFi

    3. If for any reason you need the apps, you can always re-install them





    share|improve this answer

























    • The question is about identity theft, not general phone security. Why stop at banking apps? Why not delete social network and email apps?

      – Burhan Khalid
      Jul 4 '16 at 8:30











    • @BurhanKhalid my bank account is more important to me than my privacy!

      – Rocky Inde
      Jun 18 '18 at 12:05










    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "273"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: false,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: null,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    noCode: true, onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2ftravel.stackexchange.com%2fquestions%2f72683%2fwhat-personally-identifiable-information-should-i-delete-from-my-smartphone-and%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    6 Answers
    6






    active

    oldest

    votes








    6 Answers
    6






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    37














    If you have a sufficiently modern iPhone (eg. anything that runs iOS 9 would be fine), then enable a passcode, set "Require Passcode" to "Immediately" (so you have to enter it every time you open the phone) or something short. The phone's memory is encrypted using a key derived from the passcode. No passcode, no personally identifiable data.



    If you do this, then the chance of identity theft due to a stolen phone is effectively zero.






    share|improve this answer


















    • 17





      This answer is correct, but assumes the OP won't be in the situation of being forced to unlock the device (whether by police, immigration authorities, plain old criminals, etc.). If that's a concern then the question has a lot more interesting depth to it.

      – R..
      Jul 2 '16 at 18:26






    • 2





      @R.. I'm not that worried about that scenario, as at least I'd know about it happening. (Unless someone's snooping on me using the iPhone)

      – Andrew Grimm
      Jul 3 '16 at 3:55






    • 2





      You should also disable notification preview, as the iphone reveals a few lines of text. It is useful especially for messages

      – code ninja
      Jul 3 '16 at 16:08






    • 4





      @KeithM: The easiest way to mitigate that risk is to set the "Erase Data" option which erases all data on the device after 10 failed passcode attempts. The second easiest way is to use a longer alphanumeric passcode instead of a 4- or 6-digit one.

      – Greg Hewgill
      Jul 4 '16 at 2:18






    • 3





      @KeithM: the PIN code used in iOS and Android is very good. You have an exponential cool-down time between attempts (starting from the 5th) - that is it takes longer and longer between attempts to use the PIN. After some time you will have to wait a week between attempts. On top of this you can set the iPhone to erase after 10 missed attempts. The encryption behind this scheme is very good too.

      – WoJ
      Jul 4 '16 at 6:44















    37














    If you have a sufficiently modern iPhone (eg. anything that runs iOS 9 would be fine), then enable a passcode, set "Require Passcode" to "Immediately" (so you have to enter it every time you open the phone) or something short. The phone's memory is encrypted using a key derived from the passcode. No passcode, no personally identifiable data.



    If you do this, then the chance of identity theft due to a stolen phone is effectively zero.






    share|improve this answer


















    • 17





      This answer is correct, but assumes the OP won't be in the situation of being forced to unlock the device (whether by police, immigration authorities, plain old criminals, etc.). If that's a concern then the question has a lot more interesting depth to it.

      – R..
      Jul 2 '16 at 18:26






    • 2





      @R.. I'm not that worried about that scenario, as at least I'd know about it happening. (Unless someone's snooping on me using the iPhone)

      – Andrew Grimm
      Jul 3 '16 at 3:55






    • 2





      You should also disable notification preview, as the iphone reveals a few lines of text. It is useful especially for messages

      – code ninja
      Jul 3 '16 at 16:08






    • 4





      @KeithM: The easiest way to mitigate that risk is to set the "Erase Data" option which erases all data on the device after 10 failed passcode attempts. The second easiest way is to use a longer alphanumeric passcode instead of a 4- or 6-digit one.

      – Greg Hewgill
      Jul 4 '16 at 2:18






    • 3





      @KeithM: the PIN code used in iOS and Android is very good. You have an exponential cool-down time between attempts (starting from the 5th) - that is it takes longer and longer between attempts to use the PIN. After some time you will have to wait a week between attempts. On top of this you can set the iPhone to erase after 10 missed attempts. The encryption behind this scheme is very good too.

      – WoJ
      Jul 4 '16 at 6:44













    37












    37








    37







    If you have a sufficiently modern iPhone (eg. anything that runs iOS 9 would be fine), then enable a passcode, set "Require Passcode" to "Immediately" (so you have to enter it every time you open the phone) or something short. The phone's memory is encrypted using a key derived from the passcode. No passcode, no personally identifiable data.



    If you do this, then the chance of identity theft due to a stolen phone is effectively zero.






    share|improve this answer













    If you have a sufficiently modern iPhone (eg. anything that runs iOS 9 would be fine), then enable a passcode, set "Require Passcode" to "Immediately" (so you have to enter it every time you open the phone) or something short. The phone's memory is encrypted using a key derived from the passcode. No passcode, no personally identifiable data.



    If you do this, then the chance of identity theft due to a stolen phone is effectively zero.







    share|improve this answer












    share|improve this answer



    share|improve this answer










    answered Jul 2 '16 at 8:07









    Greg HewgillGreg Hewgill

    26.9k372100




    26.9k372100







    • 17





      This answer is correct, but assumes the OP won't be in the situation of being forced to unlock the device (whether by police, immigration authorities, plain old criminals, etc.). If that's a concern then the question has a lot more interesting depth to it.

      – R..
      Jul 2 '16 at 18:26






    • 2





      @R.. I'm not that worried about that scenario, as at least I'd know about it happening. (Unless someone's snooping on me using the iPhone)

      – Andrew Grimm
      Jul 3 '16 at 3:55






    • 2





      You should also disable notification preview, as the iphone reveals a few lines of text. It is useful especially for messages

      – code ninja
      Jul 3 '16 at 16:08






    • 4





      @KeithM: The easiest way to mitigate that risk is to set the "Erase Data" option which erases all data on the device after 10 failed passcode attempts. The second easiest way is to use a longer alphanumeric passcode instead of a 4- or 6-digit one.

      – Greg Hewgill
      Jul 4 '16 at 2:18






    • 3





      @KeithM: the PIN code used in iOS and Android is very good. You have an exponential cool-down time between attempts (starting from the 5th) - that is it takes longer and longer between attempts to use the PIN. After some time you will have to wait a week between attempts. On top of this you can set the iPhone to erase after 10 missed attempts. The encryption behind this scheme is very good too.

      – WoJ
      Jul 4 '16 at 6:44












    • 17





      This answer is correct, but assumes the OP won't be in the situation of being forced to unlock the device (whether by police, immigration authorities, plain old criminals, etc.). If that's a concern then the question has a lot more interesting depth to it.

      – R..
      Jul 2 '16 at 18:26






    • 2





      @R.. I'm not that worried about that scenario, as at least I'd know about it happening. (Unless someone's snooping on me using the iPhone)

      – Andrew Grimm
      Jul 3 '16 at 3:55






    • 2





      You should also disable notification preview, as the iphone reveals a few lines of text. It is useful especially for messages

      – code ninja
      Jul 3 '16 at 16:08






    • 4





      @KeithM: The easiest way to mitigate that risk is to set the "Erase Data" option which erases all data on the device after 10 failed passcode attempts. The second easiest way is to use a longer alphanumeric passcode instead of a 4- or 6-digit one.

      – Greg Hewgill
      Jul 4 '16 at 2:18






    • 3





      @KeithM: the PIN code used in iOS and Android is very good. You have an exponential cool-down time between attempts (starting from the 5th) - that is it takes longer and longer between attempts to use the PIN. After some time you will have to wait a week between attempts. On top of this you can set the iPhone to erase after 10 missed attempts. The encryption behind this scheme is very good too.

      – WoJ
      Jul 4 '16 at 6:44







    17




    17





    This answer is correct, but assumes the OP won't be in the situation of being forced to unlock the device (whether by police, immigration authorities, plain old criminals, etc.). If that's a concern then the question has a lot more interesting depth to it.

    – R..
    Jul 2 '16 at 18:26





    This answer is correct, but assumes the OP won't be in the situation of being forced to unlock the device (whether by police, immigration authorities, plain old criminals, etc.). If that's a concern then the question has a lot more interesting depth to it.

    – R..
    Jul 2 '16 at 18:26




    2




    2





    @R.. I'm not that worried about that scenario, as at least I'd know about it happening. (Unless someone's snooping on me using the iPhone)

    – Andrew Grimm
    Jul 3 '16 at 3:55





    @R.. I'm not that worried about that scenario, as at least I'd know about it happening. (Unless someone's snooping on me using the iPhone)

    – Andrew Grimm
    Jul 3 '16 at 3:55




    2




    2





    You should also disable notification preview, as the iphone reveals a few lines of text. It is useful especially for messages

    – code ninja
    Jul 3 '16 at 16:08





    You should also disable notification preview, as the iphone reveals a few lines of text. It is useful especially for messages

    – code ninja
    Jul 3 '16 at 16:08




    4




    4





    @KeithM: The easiest way to mitigate that risk is to set the "Erase Data" option which erases all data on the device after 10 failed passcode attempts. The second easiest way is to use a longer alphanumeric passcode instead of a 4- or 6-digit one.

    – Greg Hewgill
    Jul 4 '16 at 2:18





    @KeithM: The easiest way to mitigate that risk is to set the "Erase Data" option which erases all data on the device after 10 failed passcode attempts. The second easiest way is to use a longer alphanumeric passcode instead of a 4- or 6-digit one.

    – Greg Hewgill
    Jul 4 '16 at 2:18




    3




    3





    @KeithM: the PIN code used in iOS and Android is very good. You have an exponential cool-down time between attempts (starting from the 5th) - that is it takes longer and longer between attempts to use the PIN. After some time you will have to wait a week between attempts. On top of this you can set the iPhone to erase after 10 missed attempts. The encryption behind this scheme is very good too.

    – WoJ
    Jul 4 '16 at 6:44





    @KeithM: the PIN code used in iOS and Android is very good. You have an exponential cool-down time between attempts (starting from the 5th) - that is it takes longer and longer between attempts to use the PIN. After some time you will have to wait a week between attempts. On top of this you can set the iPhone to erase after 10 missed attempts. The encryption behind this scheme is very good too.

    – WoJ
    Jul 4 '16 at 6:44













    20














    None, as long as you lock your phone with a password. It took the FBI several weeks of efforts to crack an iPhone belonging to the San Bernardino mass shooter, so a random low-level thief won't have the skills or tools to access your encrypted information.



    I would worry more about information stolen on your laptop, although that also can be mitigated by encrypting your drive with VeraCrypt or a similar piece of software.






    share|improve this answer


















    • 7





      I use BitLocker that is shipped with Windows.

      – Nean Der Thal
      Jul 2 '16 at 8:47






    • 3





      @HeidelBerGensis Which again unless you're the government (whom definitely has BitLocker backdoors) no one can access it.

      – Insane
      Jul 3 '16 at 2:14







    • 5





      @Insane There are no backdoors in Bitlocker. (The FBI has asked and been rebuffed.)

      – HopelessN00b
      Jul 3 '16 at 2:25







    • 6





      @HopelessN00b Crap the FBI said they didn't? Guess they don't!

      – Insane
      Jul 3 '16 at 2:27






    • 4





      @Insane No, the Microsoft engineers told them shove it.

      – HopelessN00b
      Jul 3 '16 at 2:27















    20














    None, as long as you lock your phone with a password. It took the FBI several weeks of efforts to crack an iPhone belonging to the San Bernardino mass shooter, so a random low-level thief won't have the skills or tools to access your encrypted information.



    I would worry more about information stolen on your laptop, although that also can be mitigated by encrypting your drive with VeraCrypt or a similar piece of software.






    share|improve this answer


















    • 7





      I use BitLocker that is shipped with Windows.

      – Nean Der Thal
      Jul 2 '16 at 8:47






    • 3





      @HeidelBerGensis Which again unless you're the government (whom definitely has BitLocker backdoors) no one can access it.

      – Insane
      Jul 3 '16 at 2:14







    • 5





      @Insane There are no backdoors in Bitlocker. (The FBI has asked and been rebuffed.)

      – HopelessN00b
      Jul 3 '16 at 2:25







    • 6





      @HopelessN00b Crap the FBI said they didn't? Guess they don't!

      – Insane
      Jul 3 '16 at 2:27






    • 4





      @Insane No, the Microsoft engineers told them shove it.

      – HopelessN00b
      Jul 3 '16 at 2:27













    20












    20








    20







    None, as long as you lock your phone with a password. It took the FBI several weeks of efforts to crack an iPhone belonging to the San Bernardino mass shooter, so a random low-level thief won't have the skills or tools to access your encrypted information.



    I would worry more about information stolen on your laptop, although that also can be mitigated by encrypting your drive with VeraCrypt or a similar piece of software.






    share|improve this answer













    None, as long as you lock your phone with a password. It took the FBI several weeks of efforts to crack an iPhone belonging to the San Bernardino mass shooter, so a random low-level thief won't have the skills or tools to access your encrypted information.



    I would worry more about information stolen on your laptop, although that also can be mitigated by encrypting your drive with VeraCrypt or a similar piece of software.







    share|improve this answer












    share|improve this answer



    share|improve this answer










    answered Jul 2 '16 at 8:17









    JonathanReezJonathanReez

    49.8k41237511




    49.8k41237511







    • 7





      I use BitLocker that is shipped with Windows.

      – Nean Der Thal
      Jul 2 '16 at 8:47






    • 3





      @HeidelBerGensis Which again unless you're the government (whom definitely has BitLocker backdoors) no one can access it.

      – Insane
      Jul 3 '16 at 2:14







    • 5





      @Insane There are no backdoors in Bitlocker. (The FBI has asked and been rebuffed.)

      – HopelessN00b
      Jul 3 '16 at 2:25







    • 6





      @HopelessN00b Crap the FBI said they didn't? Guess they don't!

      – Insane
      Jul 3 '16 at 2:27






    • 4





      @Insane No, the Microsoft engineers told them shove it.

      – HopelessN00b
      Jul 3 '16 at 2:27












    • 7





      I use BitLocker that is shipped with Windows.

      – Nean Der Thal
      Jul 2 '16 at 8:47






    • 3





      @HeidelBerGensis Which again unless you're the government (whom definitely has BitLocker backdoors) no one can access it.

      – Insane
      Jul 3 '16 at 2:14







    • 5





      @Insane There are no backdoors in Bitlocker. (The FBI has asked and been rebuffed.)

      – HopelessN00b
      Jul 3 '16 at 2:25







    • 6





      @HopelessN00b Crap the FBI said they didn't? Guess they don't!

      – Insane
      Jul 3 '16 at 2:27






    • 4





      @Insane No, the Microsoft engineers told them shove it.

      – HopelessN00b
      Jul 3 '16 at 2:27







    7




    7





    I use BitLocker that is shipped with Windows.

    – Nean Der Thal
    Jul 2 '16 at 8:47





    I use BitLocker that is shipped with Windows.

    – Nean Der Thal
    Jul 2 '16 at 8:47




    3




    3





    @HeidelBerGensis Which again unless you're the government (whom definitely has BitLocker backdoors) no one can access it.

    – Insane
    Jul 3 '16 at 2:14






    @HeidelBerGensis Which again unless you're the government (whom definitely has BitLocker backdoors) no one can access it.

    – Insane
    Jul 3 '16 at 2:14





    5




    5





    @Insane There are no backdoors in Bitlocker. (The FBI has asked and been rebuffed.)

    – HopelessN00b
    Jul 3 '16 at 2:25






    @Insane There are no backdoors in Bitlocker. (The FBI has asked and been rebuffed.)

    – HopelessN00b
    Jul 3 '16 at 2:25





    6




    6





    @HopelessN00b Crap the FBI said they didn't? Guess they don't!

    – Insane
    Jul 3 '16 at 2:27





    @HopelessN00b Crap the FBI said they didn't? Guess they don't!

    – Insane
    Jul 3 '16 at 2:27




    4




    4





    @Insane No, the Microsoft engineers told them shove it.

    – HopelessN00b
    Jul 3 '16 at 2:27





    @Insane No, the Microsoft engineers told them shove it.

    – HopelessN00b
    Jul 3 '16 at 2:27











    8














    Unless you need that specific device, I would get a throw-away device to carry in questionable situations. You can get decent Android devices for under $100 US.






    share|improve this answer


















    • 2





      Using the specific device is more convenient, so that I'm taking photos on the same device as usual.

      – Andrew Grimm
      Jul 3 '16 at 3:35















    8














    Unless you need that specific device, I would get a throw-away device to carry in questionable situations. You can get decent Android devices for under $100 US.






    share|improve this answer


















    • 2





      Using the specific device is more convenient, so that I'm taking photos on the same device as usual.

      – Andrew Grimm
      Jul 3 '16 at 3:35













    8












    8








    8







    Unless you need that specific device, I would get a throw-away device to carry in questionable situations. You can get decent Android devices for under $100 US.






    share|improve this answer













    Unless you need that specific device, I would get a throw-away device to carry in questionable situations. You can get decent Android devices for under $100 US.







    share|improve this answer












    share|improve this answer



    share|improve this answer










    answered Jul 2 '16 at 13:50









    Johns-305Johns-305

    29.9k15899




    29.9k15899







    • 2





      Using the specific device is more convenient, so that I'm taking photos on the same device as usual.

      – Andrew Grimm
      Jul 3 '16 at 3:35












    • 2





      Using the specific device is more convenient, so that I'm taking photos on the same device as usual.

      – Andrew Grimm
      Jul 3 '16 at 3:35







    2




    2





    Using the specific device is more convenient, so that I'm taking photos on the same device as usual.

    – Andrew Grimm
    Jul 3 '16 at 3:35





    Using the specific device is more convenient, so that I'm taking photos on the same device as usual.

    – Andrew Grimm
    Jul 3 '16 at 3:35











    8














    Most people that target identify theft are not looking at your cellular phone; they are looking at things that can be used to impersonate you - so your id card, passport, etc.



    People stealing phones are looking at reselling them for a quick buck. So, if you put a passcode on your phone, it makes it less of a target for being sold on. iPhones in particular have robust security (as detailed by Greg).



    I would not be worried about my identity being stolen via my phone.






    share|improve this answer



























      8














      Most people that target identify theft are not looking at your cellular phone; they are looking at things that can be used to impersonate you - so your id card, passport, etc.



      People stealing phones are looking at reselling them for a quick buck. So, if you put a passcode on your phone, it makes it less of a target for being sold on. iPhones in particular have robust security (as detailed by Greg).



      I would not be worried about my identity being stolen via my phone.






      share|improve this answer

























        8












        8








        8







        Most people that target identify theft are not looking at your cellular phone; they are looking at things that can be used to impersonate you - so your id card, passport, etc.



        People stealing phones are looking at reselling them for a quick buck. So, if you put a passcode on your phone, it makes it less of a target for being sold on. iPhones in particular have robust security (as detailed by Greg).



        I would not be worried about my identity being stolen via my phone.






        share|improve this answer













        Most people that target identify theft are not looking at your cellular phone; they are looking at things that can be used to impersonate you - so your id card, passport, etc.



        People stealing phones are looking at reselling them for a quick buck. So, if you put a passcode on your phone, it makes it less of a target for being sold on. iPhones in particular have robust security (as detailed by Greg).



        I would not be worried about my identity being stolen via my phone.







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Jul 2 '16 at 16:04









        Burhan KhalidBurhan Khalid

        36.6k372147




        36.6k372147





















            6














            Everyone has given good advice about the phone and that it will almost undoubtedly be safe if you put a password on it (rather than a short PIN). The only issue that I see is to ensure that access to your email service is encrypted. Almost all are these days, so it's only a concern if you access mail without using SSL.



            You will see this under Advanced Settings in account setup where it should have "Use SSL" selected.






            share|improve this answer























            • How is this going to prevent identity theft?

              – Burhan Khalid
              Jul 4 '16 at 8:28











            • @BurhanKhalid If you're downloading and sending email over an unencrypted connection, you're likely to be providing access to PII

              – Berwyn
              Jul 4 '16 at 8:33






            • 1





              @BurhanKhalid Ensuring your email connection is protected by SSL prevents someone intercepting your email connection, learning your password and reading all your previous email. Within your email is likely to be other information about your identity, including name, birth date, address etc, sent in previous mails. Having access to someone's emails is a rich source of information useful for identity theft. Also you could use for some forms of 2FA also useful for identity theft in some cases.

              – Berwyn
              Jul 4 '16 at 8:40






            • 2





              @BurhanKhalid You cannot spoof an SSL connection without installing a root CA on the phone. If an attacker can do that, they can do anything.

              – Berwyn
              Jul 4 '16 at 8:46






            • 1





              @BurhanKhalid GMail in Chrome has certificate pinning, although if you go to the trouble of installing a root certificate with global signing privileges, it will be ignored for the reasons you cite (app testing and system administrators imposing policy on employees). If a Chinese proxy asked me to install a root certificate, I'd probably decline ;)

              – Calchas
              Jul 4 '16 at 23:17
















            6














            Everyone has given good advice about the phone and that it will almost undoubtedly be safe if you put a password on it (rather than a short PIN). The only issue that I see is to ensure that access to your email service is encrypted. Almost all are these days, so it's only a concern if you access mail without using SSL.



            You will see this under Advanced Settings in account setup where it should have "Use SSL" selected.






            share|improve this answer























            • How is this going to prevent identity theft?

              – Burhan Khalid
              Jul 4 '16 at 8:28











            • @BurhanKhalid If you're downloading and sending email over an unencrypted connection, you're likely to be providing access to PII

              – Berwyn
              Jul 4 '16 at 8:33






            • 1





              @BurhanKhalid Ensuring your email connection is protected by SSL prevents someone intercepting your email connection, learning your password and reading all your previous email. Within your email is likely to be other information about your identity, including name, birth date, address etc, sent in previous mails. Having access to someone's emails is a rich source of information useful for identity theft. Also you could use for some forms of 2FA also useful for identity theft in some cases.

              – Berwyn
              Jul 4 '16 at 8:40






            • 2





              @BurhanKhalid You cannot spoof an SSL connection without installing a root CA on the phone. If an attacker can do that, they can do anything.

              – Berwyn
              Jul 4 '16 at 8:46






            • 1





              @BurhanKhalid GMail in Chrome has certificate pinning, although if you go to the trouble of installing a root certificate with global signing privileges, it will be ignored for the reasons you cite (app testing and system administrators imposing policy on employees). If a Chinese proxy asked me to install a root certificate, I'd probably decline ;)

              – Calchas
              Jul 4 '16 at 23:17














            6












            6








            6







            Everyone has given good advice about the phone and that it will almost undoubtedly be safe if you put a password on it (rather than a short PIN). The only issue that I see is to ensure that access to your email service is encrypted. Almost all are these days, so it's only a concern if you access mail without using SSL.



            You will see this under Advanced Settings in account setup where it should have "Use SSL" selected.






            share|improve this answer













            Everyone has given good advice about the phone and that it will almost undoubtedly be safe if you put a password on it (rather than a short PIN). The only issue that I see is to ensure that access to your email service is encrypted. Almost all are these days, so it's only a concern if you access mail without using SSL.



            You will see this under Advanced Settings in account setup where it should have "Use SSL" selected.







            share|improve this answer












            share|improve this answer



            share|improve this answer










            answered Jul 2 '16 at 16:27









            BerwynBerwyn

            26.3k658133




            26.3k658133












            • How is this going to prevent identity theft?

              – Burhan Khalid
              Jul 4 '16 at 8:28











            • @BurhanKhalid If you're downloading and sending email over an unencrypted connection, you're likely to be providing access to PII

              – Berwyn
              Jul 4 '16 at 8:33






            • 1





              @BurhanKhalid Ensuring your email connection is protected by SSL prevents someone intercepting your email connection, learning your password and reading all your previous email. Within your email is likely to be other information about your identity, including name, birth date, address etc, sent in previous mails. Having access to someone's emails is a rich source of information useful for identity theft. Also you could use for some forms of 2FA also useful for identity theft in some cases.

              – Berwyn
              Jul 4 '16 at 8:40






            • 2





              @BurhanKhalid You cannot spoof an SSL connection without installing a root CA on the phone. If an attacker can do that, they can do anything.

              – Berwyn
              Jul 4 '16 at 8:46






            • 1





              @BurhanKhalid GMail in Chrome has certificate pinning, although if you go to the trouble of installing a root certificate with global signing privileges, it will be ignored for the reasons you cite (app testing and system administrators imposing policy on employees). If a Chinese proxy asked me to install a root certificate, I'd probably decline ;)

              – Calchas
              Jul 4 '16 at 23:17


















            • How is this going to prevent identity theft?

              – Burhan Khalid
              Jul 4 '16 at 8:28











            • @BurhanKhalid If you're downloading and sending email over an unencrypted connection, you're likely to be providing access to PII

              – Berwyn
              Jul 4 '16 at 8:33






            • 1





              @BurhanKhalid Ensuring your email connection is protected by SSL prevents someone intercepting your email connection, learning your password and reading all your previous email. Within your email is likely to be other information about your identity, including name, birth date, address etc, sent in previous mails. Having access to someone's emails is a rich source of information useful for identity theft. Also you could use for some forms of 2FA also useful for identity theft in some cases.

              – Berwyn
              Jul 4 '16 at 8:40






            • 2





              @BurhanKhalid You cannot spoof an SSL connection without installing a root CA on the phone. If an attacker can do that, they can do anything.

              – Berwyn
              Jul 4 '16 at 8:46






            • 1





              @BurhanKhalid GMail in Chrome has certificate pinning, although if you go to the trouble of installing a root certificate with global signing privileges, it will be ignored for the reasons you cite (app testing and system administrators imposing policy on employees). If a Chinese proxy asked me to install a root certificate, I'd probably decline ;)

              – Calchas
              Jul 4 '16 at 23:17

















            How is this going to prevent identity theft?

            – Burhan Khalid
            Jul 4 '16 at 8:28





            How is this going to prevent identity theft?

            – Burhan Khalid
            Jul 4 '16 at 8:28













            @BurhanKhalid If you're downloading and sending email over an unencrypted connection, you're likely to be providing access to PII

            – Berwyn
            Jul 4 '16 at 8:33





            @BurhanKhalid If you're downloading and sending email over an unencrypted connection, you're likely to be providing access to PII

            – Berwyn
            Jul 4 '16 at 8:33




            1




            1





            @BurhanKhalid Ensuring your email connection is protected by SSL prevents someone intercepting your email connection, learning your password and reading all your previous email. Within your email is likely to be other information about your identity, including name, birth date, address etc, sent in previous mails. Having access to someone's emails is a rich source of information useful for identity theft. Also you could use for some forms of 2FA also useful for identity theft in some cases.

            – Berwyn
            Jul 4 '16 at 8:40





            @BurhanKhalid Ensuring your email connection is protected by SSL prevents someone intercepting your email connection, learning your password and reading all your previous email. Within your email is likely to be other information about your identity, including name, birth date, address etc, sent in previous mails. Having access to someone's emails is a rich source of information useful for identity theft. Also you could use for some forms of 2FA also useful for identity theft in some cases.

            – Berwyn
            Jul 4 '16 at 8:40




            2




            2





            @BurhanKhalid You cannot spoof an SSL connection without installing a root CA on the phone. If an attacker can do that, they can do anything.

            – Berwyn
            Jul 4 '16 at 8:46





            @BurhanKhalid You cannot spoof an SSL connection without installing a root CA on the phone. If an attacker can do that, they can do anything.

            – Berwyn
            Jul 4 '16 at 8:46




            1




            1





            @BurhanKhalid GMail in Chrome has certificate pinning, although if you go to the trouble of installing a root certificate with global signing privileges, it will be ignored for the reasons you cite (app testing and system administrators imposing policy on employees). If a Chinese proxy asked me to install a root certificate, I'd probably decline ;)

            – Calchas
            Jul 4 '16 at 23:17






            @BurhanKhalid GMail in Chrome has certificate pinning, although if you go to the trouble of installing a root certificate with global signing privileges, it will be ignored for the reasons you cite (app testing and system administrators imposing policy on employees). If a Chinese proxy asked me to install a root certificate, I'd probably decline ;)

            – Calchas
            Jul 4 '16 at 23:17












            2














            The only other recommendation I have is to delete (uninstall/remove) any banking related apps on the phone before your travel, for 3 reasons:



            1. It is not too difficult to retrieve logs generated by apps installed on a phone and I wouldn't completely rely on the banks that they have secured their apps in all possible ways

            2. You are likely to access internet via public WiFi

            3. If for any reason you need the apps, you can always re-install them





            share|improve this answer

























            • The question is about identity theft, not general phone security. Why stop at banking apps? Why not delete social network and email apps?

              – Burhan Khalid
              Jul 4 '16 at 8:30











            • @BurhanKhalid my bank account is more important to me than my privacy!

              – Rocky Inde
              Jun 18 '18 at 12:05















            2














            The only other recommendation I have is to delete (uninstall/remove) any banking related apps on the phone before your travel, for 3 reasons:



            1. It is not too difficult to retrieve logs generated by apps installed on a phone and I wouldn't completely rely on the banks that they have secured their apps in all possible ways

            2. You are likely to access internet via public WiFi

            3. If for any reason you need the apps, you can always re-install them





            share|improve this answer

























            • The question is about identity theft, not general phone security. Why stop at banking apps? Why not delete social network and email apps?

              – Burhan Khalid
              Jul 4 '16 at 8:30











            • @BurhanKhalid my bank account is more important to me than my privacy!

              – Rocky Inde
              Jun 18 '18 at 12:05













            2












            2








            2







            The only other recommendation I have is to delete (uninstall/remove) any banking related apps on the phone before your travel, for 3 reasons:



            1. It is not too difficult to retrieve logs generated by apps installed on a phone and I wouldn't completely rely on the banks that they have secured their apps in all possible ways

            2. You are likely to access internet via public WiFi

            3. If for any reason you need the apps, you can always re-install them





            share|improve this answer















            The only other recommendation I have is to delete (uninstall/remove) any banking related apps on the phone before your travel, for 3 reasons:



            1. It is not too difficult to retrieve logs generated by apps installed on a phone and I wouldn't completely rely on the banks that they have secured their apps in all possible ways

            2. You are likely to access internet via public WiFi

            3. If for any reason you need the apps, you can always re-install them






            share|improve this answer














            share|improve this answer



            share|improve this answer








            edited Jul 4 '16 at 8:02

























            answered Jul 4 '16 at 7:00









            Rocky IndeRocky Inde

            1292




            1292












            • The question is about identity theft, not general phone security. Why stop at banking apps? Why not delete social network and email apps?

              – Burhan Khalid
              Jul 4 '16 at 8:30











            • @BurhanKhalid my bank account is more important to me than my privacy!

              – Rocky Inde
              Jun 18 '18 at 12:05

















            • The question is about identity theft, not general phone security. Why stop at banking apps? Why not delete social network and email apps?

              – Burhan Khalid
              Jul 4 '16 at 8:30











            • @BurhanKhalid my bank account is more important to me than my privacy!

              – Rocky Inde
              Jun 18 '18 at 12:05
















            The question is about identity theft, not general phone security. Why stop at banking apps? Why not delete social network and email apps?

            – Burhan Khalid
            Jul 4 '16 at 8:30





            The question is about identity theft, not general phone security. Why stop at banking apps? Why not delete social network and email apps?

            – Burhan Khalid
            Jul 4 '16 at 8:30













            @BurhanKhalid my bank account is more important to me than my privacy!

            – Rocky Inde
            Jun 18 '18 at 12:05





            @BurhanKhalid my bank account is more important to me than my privacy!

            – Rocky Inde
            Jun 18 '18 at 12:05

















            draft saved

            draft discarded
















































            Thanks for contributing an answer to Travel Stack Exchange!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2ftravel.stackexchange.com%2fquestions%2f72683%2fwhat-personally-identifiable-information-should-i-delete-from-my-smartphone-and%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            𛂒𛀶,𛀽𛀑𛂀𛃧𛂓𛀙𛃆𛃑𛃷𛂟𛁡𛀢𛀟𛁤𛂽𛁕𛁪𛂟𛂯,𛁞𛂧𛀴𛁄𛁠𛁼𛂿𛀤 𛂘,𛁺𛂾𛃭𛃭𛃵𛀺,𛂣𛃍𛂖𛃶 𛀸𛃀𛂖𛁶𛁏𛁚 𛂢𛂞 𛁰𛂆𛀔,𛁸𛀽𛁓𛃋𛂇𛃧𛀧𛃣𛂐𛃇,𛂂𛃻𛃲𛁬𛃞𛀧𛃃𛀅 𛂭𛁠𛁡𛃇𛀷𛃓𛁥,𛁙𛁘𛁞𛃸𛁸𛃣𛁜,𛂛,𛃿,𛁯𛂘𛂌𛃛𛁱𛃌𛂈𛂇 𛁊𛃲,𛀕𛃴𛀜 𛀶𛂆𛀶𛃟𛂉𛀣,𛂐𛁞𛁾 𛁷𛂑𛁳𛂯𛀬𛃅,𛃶𛁼

            Edmonton

            Crossroads (UK TV series)