Friendly reminder. Full disk encryption on a server you have no physical access to grants you no security, same for your laptop if you carry it around in sleep mode. FDE protects your data at rest as from a cold boot you need to provide the passphrase. If your box is running the secret is present in memory and can be grabbed by a dedicated attacker.

For the same reason, when approaching border control, TURN OFF your phone, just locking the screen is often not enough.

@mulander and even then if asked for your password , what do you do?
@MrTumnusInfosec don't travel to countries that want this. That's why I don't plan to visit or attend any events in the USA. Still, with a password you can at least refuse to provide it with plausible deniability that you forgot it. Can't do the same with a fingerprint scan.
@mulander true but then I can’t afford to have a $600 device taken away from me every time i fly. Best option is to remotely sync the content once at your destination, host your NextCloud and pull it down. Anyone made an App for that, a fresh phone reimage tool once in-situ?

@MrTumnusInfosec I can't afford that also. Hence I avoid places that are likely to seize my devices on border checks.

I haven't heard of a fresh phone re-image stuff.

@mulander yeah, but listen, this also applies to MY own country! Wtf!!!?!

@MrTumnusInfosec in that case you have two choices.

1. Get politically involved in changing the laws in your country. Educate people, vote, try to pass better laws.
2. Migrate to a different country.

@mulander so 1. Is a slow burn but essential 2. Is just delaying the inevitable as the laws will follow me there one day, sooner rather than later. This needs an immediate technological fix as well as a political one. Imagine being able to arrive at the airport and plausibility deny that your phone (which has an encrypted deeply hidden cryptovault on it) is just boring and used as a old-School phone, no / minimal Apps installed. Then the moment you get online...magic! Your old phone back
@MrTumnusInfosec if I was running the border checks I would have them image all phones that pass through - encrypted or not. If one year from now I learn how to detect hidden crypto volumes I would get back to you for further investigation. Obscurity is not security, if it's illegal to pass without decrypting your phone then hiding an encrypted volume is not the solution.
@mulander so good encryption is by definition indistinguishable from random noise, so it’s doable in theory. And if not then it has to be done after the event with a Live re-image on a device once destination is reached. Or always done Citrix style, so remote RDP for Mobile devices.