Live data from Hacker News

Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

theregister.co.uk

11–20 of 378 posts

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#11

I'm hoping that manufactures will start building a plausible deniability user profile you can log into while leaving your actual profile encrypted, appearing to be slack space. This kind of thuggery seems to be getting more common.

This seems like a good idea, but it may land you in even more trouble. If it can be shown that you intentionally misled officers about content on your device, not merely denied questioning, you risk an obstruction of justice charge.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#12
post #3

I'm hoping that manufactures will start building a plausible deniability user profile you can log into while leaving your actual profile encrypted, appearing to be slack space. This kind of thuggery seems to be getting more common.

Keep data off your devices during travel, and download it once you're safe. If corporate, require external activation by someone from the company before the contents of your device are restored. That way you cannot be forced to divulge any company trade secrets, because you simply don't have access to them while you're crossing the border.

Can they ask for online logins?

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#13
post #3

Earlier quoted context omitted.

Keep data off your devices during travel, and download it once you're safe. If corporate, require external activation by someone from the company before the contents of your device are restored. That way you cannot be forced to divulge any company trade secrets, because you simply don't have access to them while you're crossing the border.

Some companies issue "China" Laptops to their executives that they must discard after visiting China. Now I believe we all need throw away laptops and cell phones and Facebook accounts for any sort of international travel.

I'm actually wondering what happens if I'm ever asked about Facebook credentials when travelling to the US.

Fact is: I don't do Facebook, nor any other Facebook product, so I'm really not able to hand over any such credentials.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#14
Quick reminder: US citizens have an absolute right to reenter the country. Customs can temporarily detain you, but they cannot refuse entry. Any threat, whether implied or stated, that they will hold you until you unlock your device is not real. They can hold your stuff indefinitely, so be prepared to lose it if you go this route, but never unlock your device based on the idea that it’s the only way to go free.

Non-citizens are in a totally different boat. You can be denied entry for any reason whatsoever. Tread carefully....

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#15
post #3

I'm hoping that manufactures will start building a plausible deniability user profile you can log into while leaving your actual profile encrypted, appearing to be slack space. This kind of thuggery seems to be getting more common.

Keep data off your devices during travel, and download it once you're safe. If corporate, require external activation by someone from the company before the contents of your device are restored. That way you cannot be forced to divulge any company trade secrets, because you simply don't have access to them while you're crossing the border.

Even that is not sufficient short of a full factory reset. It can be very difficult to impossible to clear all caches and logs, or even know about them.

Once the agent has your password and takes the device into their back room for an hour, you have to assume that all data has been offloaded and the device has had an undetectable rootkit added.

This gentleman's expertise is in security and encryption and now he works for Apple, a company that makes products that the US government can't always crack. He was clearly targeted in his encounter because of his current position, based on the questions they were asking. Surreptitious access to his devices is highly desirable to US intelligence services.

Any device that you lose physical control of during these encounters must be presumed to be compromised and should be physically destroyed afterwards.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#16
post #4
post #3

Earlier quoted context omitted.

Keep data off your devices during travel, and download it once you're safe. If corporate, require external activation by someone from the company before the contents of your device are restored. That way you cannot be forced to divulge any company trade secrets, because you simply don't have access to them while you're crossing the border.

So what if you are asked if your device is in its normal state or whether you deleted any data from your device before travelling? Lying in that situation would seem like a very bad idea (I'm not a US national) - I've had a few uncomfortable experiences over the years entering the US and I certainly wouldn't want to do anything that would give cause to escalate things on their side.

Say, "yes I wiped it in case it got lost whilst I was travelling"?

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#17
post #4
post #3

Earlier quoted context omitted.

Keep data off your devices during travel, and download it once you're safe. If corporate, require external activation by someone from the company before the contents of your device are restored. That way you cannot be forced to divulge any company trade secrets, because you simply don't have access to them while you're crossing the border.

So what if you are asked if your device is in its normal state or whether you deleted any data from your device before travelling? Lying in that situation would seem like a very bad idea (I'm not a US national) - I've had a few uncomfortable experiences over the years entering the US and I certainly wouldn't want to do anything that would give cause to escalate things on their side.

You can be as honest as you like. Or just say you don't take data with you when you travel. For security reasons. If it's work related, this is trivial to justify: company policy, trade secrets shouldn't fall in the wrong hands, etc. And even if private, phone theft and identity theft are serious concerns.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#19
post #3

I'm hoping that manufactures will start building a plausible deniability user profile you can log into while leaving your actual profile encrypted, appearing to be slack space. This kind of thuggery seems to be getting more common.

Keep data off your devices during travel, and download it once you're safe. If corporate, require external activation by someone from the company before the contents of your device are restored. That way you cannot be forced to divulge any company trade secrets, because you simply don't have access to them while you're crossing the border.

Won't this basically end up in the same situation as the one here? You will be detained for a few hours and then released?

He wasn't FORCED to unlock his computer, he was just detained for three hours because he wasn't. Adding technical restrictions won't stop that.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#20
post #3

I'm hoping that manufactures will start building a plausible deniability user profile you can log into while leaving your actual profile encrypted, appearing to be slack space. This kind of thuggery seems to be getting more common.

Keep data off your devices during travel, and download it once you're safe. If corporate, require external activation by someone from the company before the contents of your device are restored. That way you cannot be forced to divulge any company trade secrets, because you simply don't have access to them while you're crossing the border.

For anyone who has 1Password, they have built-in support for doing this https://support.1password.com/travel-mode/
Post reply on HN