This is indeed a cautionary tale. But soon enough, this taking out electronics at airports will be a thing of the past as more and more airports deploy luggage scanners like the ones at Dubai airport where you don't have to take anything out of the bag.<p>In general, here's my operational security to prevent scenarios like this:<p>1. All my luggage has uniquely identifiable tags and stickers on them. This includes my laptop, mobile phone, chargers and cables. This largely avoids myself or someone else mistakenly picking up wrong things.
When I'm asked to take out electronics at airport security, I use 4 trays in sequence – carry-on luggage, all my electronics in the tray, and my backpack, my shoes. This way, my electronics tray is sandwiched between my luggages. I also put my laptop in a thin cushion sleeve and I have not been asked to remove the sleeve. I also put all my smaller electronics and cables in a clear plastic zip bag and put it in the tray. Then, I try to cross the human x-ray at the same time as my luggage (most airports do a good job of ensuring this if you stay in the lane next to the luggage line). When I pickup my luggage I'm super focused to make sure I verify I got back my stuff correctly.<p>2. My corporate MacBook and iPhone does not allow iCloud account on it. Hence, there is no Find My. But it is tied to corp MDM. If anyone were to find it and try to wipe and install, the MDM will force a profile on it. When I report my laptop is lost, they will put it in lost mode (via MDM) and also remote wipe it. Also, they have loss/theft insurance to cover the cost of the laptop.<p>3. On my personal MacBook and iPhone, I have had firmware lock (on Intel ones), and always had FileVault (for M1/M2 silicon, this is same as firmware lock) on with recovery key (not iCloud recovery). Recently I have turned on lockdown mode as well. I do have an apple account for Activation Lock, App Store and TV. And I have advanced data protection mode on for this iCloud account and I have disabled iCloud Web. I have recovery key and recovery contact for this iCloud account. I don't want my data on iCloud servers without end to end encryption nor do I want Apple to be able to unlock/wipe my devices without a cryptographic consent from another iDevice I possess. With File Vault on, nobody else who gets my laptop can unlock it or wipe it or reinstall it. On some of my devices, location service is off, so Find My can't show the location but it can still activate lost mode or remote wipe the device.<p>4. I have both physical sim which is locked and eSIM on my iPhone. And my iPhone is locked with a password. I disable Face ID while traveling.<p>5. Similarly, I have advanced data protection on my Google accounts.<p>6. I use physical Yubikeys with pin locks for 2FA.