Live data from Hacker News

Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

theregister.co.uk

1–10 of 378 posts

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#3

I'm hoping that manufactures will start building a plausible deniability user profile you can log into while leaving your actual profile encrypted, appearing to be slack space. This kind of thuggery seems to be getting more common.

Keep data off your devices during travel, and download it once you're safe. If corporate, require external activation by someone from the company before the contents of your device are restored. That way you cannot be forced to divulge any company trade secrets, because you simply don't have access to them while you're crossing the border.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#4
post #3

I'm hoping that manufactures will start building a plausible deniability user profile you can log into while leaving your actual profile encrypted, appearing to be slack space. This kind of thuggery seems to be getting more common.

Keep data off your devices during travel, and download it once you're safe. If corporate, require external activation by someone from the company before the contents of your device are restored. That way you cannot be forced to divulge any company trade secrets, because you simply don't have access to them while you're crossing the border.

So what if you are asked if your device is in its normal state or whether you deleted any data from your device before travelling?

Lying in that situation would seem like a very bad idea (I'm not a US national) - I've had a few uncomfortable experiences over the years entering the US and I certainly wouldn't want to do anything that would give cause to escalate things on their side.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#5
post #3

I'm hoping that manufactures will start building a plausible deniability user profile you can log into while leaving your actual profile encrypted, appearing to be slack space. This kind of thuggery seems to be getting more common.

Keep data off your devices during travel, and download it once you're safe. If corporate, require external activation by someone from the company before the contents of your device are restored. That way you cannot be forced to divulge any company trade secrets, because you simply don't have access to them while you're crossing the border.

Some companies issue "China" Laptops to their executives that they must discard after visiting China. Now I believe we all need throw away laptops and cell phones and Facebook accounts for any sort of international travel.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#6

I'm hoping that manufactures will start building a plausible deniability user profile you can log into while leaving your actual profile encrypted, appearing to be slack space. This kind of thuggery seems to be getting more common.

That will do more harm than good. In order to build such a device the feature would need to be advertised, which TSA can see just like everyone else. Then when they see such a device, it becomes incumbent on you to prove you’re not using the feature, even when you’re not using it. So you can never prove you’re not using it and therefor could be detained. You might think you have more rights if you’re in the US, but there are many regimes where you don’t have them.

Also: https://xkcd.com/538/

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#7
post #6

I'm hoping that manufactures will start building a plausible deniability user profile you can log into while leaving your actual profile encrypted, appearing to be slack space. This kind of thuggery seems to be getting more common.

That will do more harm than good. In order to build such a device the feature would need to be advertised, which TSA can see just like everyone else. Then when they see such a device, it becomes incumbent on you to prove you’re not using the feature, even when you’re not using it. So you can never prove you’re not using it and therefor could be detained. You might think you have more rights if you’re in the US, but t…

Also, such a mechanism necessarily involves lying to law enforcement, which is generally considered a bad idea.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#8
Some discussion from yesterday: https://news.ycombinator.com/item?id=19558161

See also Andreas Gal's blog post https://medium.com/@andreasgal/no-one-should-have-to-travel-... , the ACLU's press release https://www.aclunc.org/news/aclu-files-complaint-department-... , and the ACLU's formal complaint https://www.aclunc.org/docs/ACLU-NC_2019-03-28_Letter_re._El... .

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#9

I'm hoping that manufactures will start building a plausible deniability user profile you can log into while leaving your actual profile encrypted, appearing to be slack space. This kind of thuggery seems to be getting more common.

You could on Android add a dummy, unprivileged account under your name and rename your real account "Guest" or something. Not that this stops a motivated person, but it may placate a border officer who really just wants to thumb through your photos and downloads folder.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#10
post #4
post #3

Earlier quoted context omitted.

Keep data off your devices during travel, and download it once you're safe. If corporate, require external activation by someone from the company before the contents of your device are restored. That way you cannot be forced to divulge any company trade secrets, because you simply don't have access to them while you're crossing the border.

So what if you are asked if your device is in its normal state or whether you deleted any data from your device before travelling? Lying in that situation would seem like a very bad idea (I'm not a US national) - I've had a few uncomfortable experiences over the years entering the US and I certainly wouldn't want to do anything that would give cause to escalate things on their side.

What do they do if you say no in this situation though? Escort you home and inspect your desktop computer there? If I were to tell them that I carry a travel laptop/phone with no information on, there's little they'd be able to do about it unless that in itself was somehow made a crime.
Post reply on HN