Live data from Hacker News

Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

cbc.ca

101–110 of 483 posts

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#102

Earlier quoted context omitted.

Honestly, that's not something you can expect from regular non-power users. Full-disk encryption isn't enabled by default on most consumer laptops, and few regular users go out of their way to set it up.

You don't need "full" disk encryption on Chromebook devices or Android phones. Both ship with file-based disk encryption for all user data, on-by-default for all recent devices. When I travel out of the country, I reset my phone and Chromebook to their factory defaults and then provision a decoy account. Once I'm across the border, I provision my primary account. Even if they image my devices, all they'll get is old…

They could replace part of the password-checking software with a backdoored version that would send your password off to them. Your data is protected, but the OS can still compromise it and a bad actor can replace parts of the OS (which is open source in both of your cases, making the process even easier).

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#104
post #55

Earlier quoted context omitted.

Do you think its better to have an iPhone powered down or on? I am wondering if it would be possible to leverage remote wipe features, but maybe the border agents power off the device or put it in a bag / container that blocks cellular signals.

Powered off. Law enforcement has tools like Cellebrite and GrayKey that can unlock or extract data while the phone is powered on but locked. Apple is making this a bit more difficult by disabling the port if the phone hasn't been unlocked for seven days or more, but if the device is powered on and law enforcement acts fast, it's vulnerable. https://ios.gadgethacks.com/news/heres-apples-stopping-polic...

USB devices are disabled 1 hour since last unlock on recent version of iOS.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#105

Earlier quoted context omitted.

Plus it isn't hard to pick out people crossing consistently for work.

I mean what counts as work and where it occurs are becoming very difficult to manage? What happens if you have to do work while on a real holiday, should you be deported for this? Is it valid to allow these searches for these sort of offences, it seems like at some point everyone will be guilty of doing these things.

I wonder this myself. There is a difference between traveling for the purposes of work, and working while traveling. I have a 100% remote position. I normally do my work in the US. I've considered flying to Europe for a few weeks, where due to time zone differences I could do touristy stuff during the day and then work my US 9-5 shift in the EU evening. This would allow me to travel but to not take vacation time. Would this require a work visa?

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#106

> Officers uncovered a customs-related offence during 38 per cent of those searches, said the agency. I really want to understand what kind of digital data is considered a customs-related offence.

>I really want to understand what kind of digital data is considered a customs-related offence. Photo of someone smoking a joint in a legally (at the state level) operated dispensary. A pirated MP3 or video file. There's all sorts of minor "customs violations" that would come into view looking through a device that frankly, aren't serious enough to warrant the violation of privacy.

> A pirated MP3 or video file

In the first place, piracy is not illegal in Canada. Provisions surrounding copyright violations fall under bill C11, and that's a civil juncture, not a criminal one. So CBSA agents wouldn't be looking for that in the first place, nor would they have any grounds to do anything about it, since they aren't the rightsholders.

And even if they did, they have an interesting burden of proof in proving a given file was obtained via piracy. And what would they do? Detain you indefinitely because they want to "have a discussion" about some pirated Katy Perry song? I would agree that photos of doing drugs could be met with refusal at the border, but be reasonable.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#107
post #96
post #9

>Wright refused, telling the officer both devices contained confidential information protected by solicitor-client privilege. >He said the officer then confiscated his phone and laptop, and told him the items would be sent to a government lab which would try to crack his passwords and search his files. Can this be used to get whatever case(es) he was defending thrown out because solicitor-client privilege was violate…

> Can this be used to get whatever case(es) he was defending thrown out Along the same lines a case could be made for legal malpractice if it was reasonable for the attorney to know that there could be a search (and it is he is an attorney and the assumption is he is familiar with the law). It is similar to putting his phone unlocked in a car and the phone or the car is stolen. There is a reasonable expectation that…

Unlike the stolen phone, in this case it would be the same entity that's stealing confidential data, and holding him responsible for the data getting stolen - the government.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#108
post #99

I have asked this question before, but never really got a satisfiable answer: why do governments (not just USA/canada) spend these resources to check data physically at a border? It's not like you need to 'smuggle' any form of data physically. I mean, any data considered to be dangerous (like terrorist attack plans, atomic bomb designs or political inside information) can be accessed across borders via the internet.…

I think the goal is to get people who have incriminating evidence on their phone, however unlikely that might be for sensitive information.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#109

> Officers uncovered a customs-related offence during 38 per cent of those searches, said the agency. I really want to understand what kind of digital data is considered a customs-related offence.

Cardinal Richelieu only needed six lines. Imagine what he could do with 500 GB.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#110

Earlier quoted context omitted.

That's literally useless for government sponsored persistent malware.

Can you expand on this? I'm curious and a little Googling didn't yield much

Some russian hackers at DEFCON a few years back handed out power cables that leaked data via the hotel's power system.

I've also heard of altered USB-C power cables being used to exflitrate data, and a software-altered USB port used as a radio wire

Post reply on HN