Some people my server admin uncle included believe that bringing any device to China automatically compromises it even if you reinstall a new OS. Is this warranted as some random person?

Can I go to my public sites and/or VPN into my servers?

  • @neatchee
    link
    English
    3
    edit-2
    20 minutes ago

    Do not bring your normal personal devices to China. They are notorious for injecting spyware on foreign devices at every opportunity. Use a freshly formatted device and create all new accounts to use with it.

    Regarding services: do not use self-hosted services unless you you spin up fresh, isolated instances of your services for use while abroad and spin them down afterwards, including formatting any OS they were hosted on.

    Regarding VPN: because we are assuming that any device used in China is compromised, do not connect to your VPN unless you have set up a segregated VLAN and are connecting through a VPN server instance created specifically for use while in China.

    Basically, assume anything you use in China is compromised. And assume your connections are being monitored. And assume that any device you are connecting to from China is at risk of being compromised. So everything needs to be segregated from the rest of your network and set up specifically to be deleted after you’re back home.

  • @[email protected]
    link
    fedilink
    English
    132 hours ago

    Get a new phone for use while traveling, then dump it when you’re back home. Leave your services behind.

    • Semi-Hemi-Lemmygod
      link
      English
      11 hour ago

      Leave it on some form of mass transit before you leave

  • @NeoNachtwaechter
    link
    English
    112 hours ago

    Can I go to my public sites

    I would not recommend. Remember, wherever you step, your feet are leaving traces. Your public sites may be a little too publicly well-known afterwards.

    and/or VPN into my servers?

    VPN’s might not work from there, or the use may be considered a crime.

  • @[email protected]
    link
    fedilink
    English
    123 hours ago

    If your device is out of your sight, then yeah, you should probably assume it’s compromised.

    Of course, that’s hardly JUST China doing funky shit with your devices, but depending where you’re calling home, odds are customs/immigration when you head home will try to do the exact same thing, too.

    And the answer to everything is yes, always use a VPN if you don’t trust the network and you should never trust the network.

    • @[email protected]
      link
      fedilink
      English
      127 minutes ago

      Well china does it to everyone, in the western countries usually it is targeted to individuals.

      • @[email protected]
        link
        fedilink
        English
        13 minutes ago

        For sure, just wanted to mention that it’s not just the China side of the trip you need to be vigilant about.