Live data from Hacker News

Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

theregister.co.uk

221–230 of 378 posts

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#221
post #182

The message it sends to me is, never visit America. I appreciate horrible things likely happen in my own country, but this is just disgusting.

> the message it sends to me is, never visit America Message? So you read one story and a bunch of HN comments and that is how you decide?

OP didn't say it was a decision, just the message perceived. If you live outside the US, hearing stories or reading what happens to others is enough to know these things happen, anyway.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#222
post #117

This assumes that he was not picked by random but instead there is some sort of list of people to check at airports that you can be put on because of your work within IT-security. That would be a big story if that is the case. I will offer a counter-narrative which is more in line with my own experience (from other places than the US): The people who work at border control in particular in airports are bored. They ar…

Um, this is definitely the case. DHS has an advanced record keeping system. They have tons of information on every person arriving in the US. Yes they even know what you ordered on your in flight meal.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#223
post #212

Earlier quoted context omitted.

Because it's someone else's hardware, someone else's software, and someone else's firmware.

To be pedantic, unless you flashed coreboot it's not your own firmware and if you aren't using an open hardware laptop then it's not really your hardware either.

But you can have a bit more trust in the supply chain to get to you than that it hasn't been tampered with afterwards.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#224
post #117

This assumes that he was not picked by random but instead there is some sort of list of people to check at airports that you can be put on because of your work within IT-security. That would be a big story if that is the case. I will offer a counter-narrative which is more in line with my own experience (from other places than the US): The people who work at border control in particular in airports are bored. They ar…

When I was returning from Hong Kong a few weeks ago, the agent asked what city I was born in (fine) what hospital I was born in (I remember where it used to be, but I can't remember the name) and what the "number" of the county was I grew up in. What he meant was the prefix for the license plate. Luckily I remembered it. I suspect he grew up in the area, but it was super weird; also, he was probably fairly bored.

>what hospital I was born in

people are expected to know this?

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#225

Earlier quoted context omitted.

> Make sure your devices are turned off prior to even leaving for the airport. Security may ask you to turn them back on, not to search them, but to verify that they are actual working devices, and not a bomb.

Turning them on doesn't reduce the security. The issue is unlocking them. As far as the security of the data on the device is concerned, a powered-off device is equivalent to a powered-on device that hasn't been unlocked since it was powered on.

Pro tip: on newer iPhones with either Face ID or Touch ID, holding the sleep/wake button and the volume down button for some time puts the device in a mode where Touch/Face ID are disabled, the phone is locked, and the device passcode is required to unlock.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#226

Earlier quoted context omitted.

Even that is not sufficient short of a full factory reset. It can be very difficult to impossible to clear all caches and logs, or even know about them. Once the agent has your password and takes the device into their back room for an hour, you have to assume that all data has been offloaded and the device has had an undetectable rootkit added. This gentleman's expertise is in security and encryption and now he works…

> Any device that you lose physical control of during these encounters must be presumed to be compromised and should be physically destroyed afterwards. Seems unwise to destroy evidence. Find the rootkit, or have your employer or security researcher do so, prove it's existence, and sue the Government. But yes, definitely get a new laptop.

I don't think that will go anywhere. How do you prove the government did it and that it wasn't on there before the encounter?

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#227

Earlier quoted context omitted.

> but never unlock your device based on the idea that it’s the only way to go free. Best to enter the customs zone with the phone powered off, your device's security is likely better in this state, less likely to be circumvented while you surrender it.

Good advice! Things like mobile boarding passes and the "Mobile Passport" app encourage and train people to hand their devices over to TSA and CBP personnel. In that later case, unlocked and with an app CBP/DHS controls already installed (with a lengthy ToS no one ever reads).

I’ve been using mobile boarding passes exclusively for the past few years and it doesn’t even remotely work in the way you describe (within the US, at least; cannot comment on CBP).

1. There is no special app you need for mobile boarding passes. It has always been either a PDF or a PNG file emailed to you.

2. I was never asked to hand over my phone to TSA agents at any point. They just ask you to put your phone with the boarding pass QR code displayed over a QR scanner. At no point the phone leaves your hands.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#228
post #208

Earlier quoted context omitted.

I had no idea, thank you.

This is often called "sterile transit" (the ability to depart the airport without passing through immigration), and the U.S. and Mexico (and apparently Canada) don't allow this, while generally European and Asian countries do. https://wikitravel.org/en/Avoiding_a_transit_of_the_United_S...

No EU airport allows this for flights from outside the EU/Schengen zone. Every international airport has dedicated "EU internal" and "all other" terminal pathways for this reason.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#229
post #182

The message it sends to me is, never visit America. I appreciate horrible things likely happen in my own country, but this is just disgusting.

> the message it sends to me is, never visit America Message? So you read one story and a bunch of HN comments and that is how you decide?

No, honestly, the rest of the world has been getting this message from the US since 9/11.

Re: Ex-Mozilla CTO: I was grilled for three hours at US airport by border cops

#230

I'm hoping that manufactures will start building a plausible deniability user profile you can log into while leaving your actual profile encrypted, appearing to be slack space. This kind of thuggery seems to be getting more common.

> I'm hoping that manufactures will start building a plausible deniability user profile Deniable encryption can actually be very dangerous for people who are detained in places where torture is used. Even if you unlock your device, law enforcement have no proof that you have unlocked your real profile[0]. This is relevant to countries where people can be detained for not unlocking their devices, like Australia. [0]:…

Hence why it needs to be the default. The some sort of problem kinda exists with encryption. If nobody encrypted their phones, having one immediately makes you a suspect. However, if everyone had an encrypted phone (default on ios/android), nobody would bat an eye.
Post reply on HN