Live data from Hacker News

Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

cbc.ca

81–90 of 483 posts

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#81
post #2

> He said the officer then confiscated his phone and laptop, and told him the items would be sent to a government lab which would try to crack his passwords and search his files. Hopefully they were powered down and used proper full-disk encryption.

Do you think its better to have an iPhone powered down or on? I am wondering if it would be possible to leverage remote wipe features, but maybe the border agents power off the device or put it in a bag / container that blocks cellular signals.

Remote wipe might not play very well. If it was detained in relation with a crime, they might go with 'attempting to destroy evidence'.

Look at it this way. Suppose the seizure of the phone was totally reasonable (because that is how they will think about it). Now, that suspected criminal who apparently had something to hide decided to remotely tamper with evidence after we lawfully detained it? That is subversion of justice!

The above is an argument I'd expect to hear from them.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#82
post #2

> He said the officer then confiscated his phone and laptop, and told him the items would be sent to a government lab which would try to crack his passwords and search his files. Hopefully they were powered down and used proper full-disk encryption.

Honestly, that's not something you can expect from regular non-power users. Full-disk encryption isn't enabled by default on most consumer laptops, and few regular users go out of their way to set it up.

You don't need "full" disk encryption on Chromebook devices or Android phones. Both ship with file-based disk encryption for all user data, on-by-default for all recent devices.

When I travel out of the country, I reset my phone and Chromebook to their factory defaults and then provision a decoy account. Once I'm across the border, I provision my primary account.

Even if they image my devices, all they'll get is old encrypted garbage for which the key is unavailable because the key was rendered inaccessible when the device was reset to factory defaults.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#83

Earlier quoted context omitted.

Most criminals don’t actually have great OpSec. I’m sure there are tons of phones that have incriminating photographs in the default camera app, or incriminating text messages or saved voicemails or who knows what.

Most people don't have great opsec, and most people are technically criminals.

> most people are technically criminals.

Wat?

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#84

Earlier quoted context omitted.

That's literally useless for government sponsored persistent malware.

Can you expand on this? I'm curious and a little Googling didn't yield much

Snowden revealed that the government is capable of planting malware in peripheral firmware. So you can have a hacked bios/EFI, system controller, security chip, hard drive, SSD, GPU, WiFi/networking card/chip that is virtually impossible to detect from the main OS.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#85

Earlier quoted context omitted.

That's literally useless for government sponsored persistent malware.

Can you expand on this? I'm curious and a little Googling didn't yield much

I think we simply don’t know in this case.

But if a super sophisticated approach is used, they could just as well catch and prepare your computer before you receive it i.e. if you ordered it by mail.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#86

Earlier quoted context omitted.

I would think most offenses are for improper entry, visa, etc. If you were entering to work on a tourism visa I think it would be very easy to find proof in a simple email, text or document.

Plus it isn't hard to pick out people crossing consistently for work.

I mean what counts as work and where it occurs are becoming very difficult to manage? What happens if you have to do work while on a real holiday, should you be deported for this? Is it valid to allow these searches for these sort of offences, it seems like at some point everyone will be guilty of doing these things.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#87
post #75
post #9

>Wright refused, telling the officer both devices contained confidential information protected by solicitor-client privilege. >He said the officer then confiscated his phone and laptop, and told him the items would be sent to a government lab which would try to crack his passwords and search his files. Can this be used to get whatever case(es) he was defending thrown out because solicitor-client privilege was violate…

If it can, sounds like a loophole to get a case you're working on thrown out. If it cannot, sounds like a convenient way to gain extra leverage. And all it takes is to bribe an officer.

Even an attempt at Bribing a law enforcement officer is a felony.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#89
post #12

> Officers uncovered a customs-related offence during 38 per cent of those searches, said the agency. This is hard for me to comprehend. Does anyone have an idea of what 38% of the phones can have stored on them, that is illegal to have when crossing the border?

> Does anyone have an idea of what 38% of the phones can have stored on them, that is illegal to have when crossing the border? Generally it's things like text messages from friends/family/potential employers that lead agents to think the person isn't going to abide by their non-work/short term visa.

that isn't a customs-related offence, though - that's an immigration related offence. Customs is concerned with the movement of goods, not movement of people.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#90

Earlier quoted context omitted.

Can you expand on this? I'm curious and a little Googling didn't yield much

Snowden revealed that the government is capable of planting malware in peripheral firmware. So you can have a hacked bios/EFI, system controller, security chip, hard drive, SSD, GPU, WiFi/networking card/chip that is virtually impossible to detect from the main OS.

Yes, if determined the government agencies have tremendous capabilities. But will they use it at a large scale, i.e. against an arbitrary lawyer?
Post reply on HN