Live data from Hacker News

Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

cbc.ca

111–120 of 483 posts

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#111
post #100
post #14

Earlier quoted context omitted.

There’s a reality tv show that follows the Canadian border patrol, in the couple episodes I’ve seen the agents have found emails about the person crossing actually going for work when they say for tourism or visiting family.

I watch that show as well. But I don't remember if they simply asked the person if they could search or demanded that they be able to search. Anyone who watches reality tv (for example 'Live PD') knows there are many cases where the police officer simply gains consent from the suspect for a search without any particular legal reason or right to do so. Now if they suspect they can (from watching) bring in a canine and…

>Now if they suspect they can (from watching) bring in a canine and if the canine smells something they then have probable cause (I believe) w/o getting a warrant

They can't extend the traffic stop to bring in the dogs unless they have reasonable suspicion. https://en.wikipedia.org/wiki/Rodriguez_v._United_States

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#112

These cases keep on cropping up and you see people suggesting to do some sort of technical trick like taking the hard-disk out of the laptop and carrying a TailsOS live USB flash device for your computing. Other tricks might include mailing a USB flash disk to a hotel reception with the intent of picking it up when you arrive. These are all fraught with risk and you could appear extra suspicious by doing these. Anoth…

Well, I'm not sure if one wants to just call security approaches "tricks". A "trick" approach is often one that can be undone if your adversary knows about it (keeping your files hidden somewhere in your luggage would be a "trick"). A cohesive approach should be unbreachable if minimal conditions are met. If you can assure a "trustworthy" base computing environment (one that isn't keylogged etc), then having your val…

The “tricked-out-bootloader” approach also seems to be brought up often: have your hard drive portioned into two sections (or even have two hard drives), then configure your bootloader to start up the non-encrypted, not suspicious partition unless you press a specific key combo at boot and enter your disk encryption password.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#114
post #99

I have asked this question before, but never really got a satisfiable answer: why do governments (not just USA/canada) spend these resources to check data physically at a border? It's not like you need to 'smuggle' any form of data physically. I mean, any data considered to be dangerous (like terrorist attack plans, atomic bomb designs or political inside information) can be accessed across borders via the internet.…

It's basically be because the natural tendency of government is acquire and centralize as much power as possible. Now some forms of government take longer but without constant review and concern by citizens in a democracy it will gradually move towards a despotic regime. In some countries like China it has already happened because individual freedom isn't that valuable to the general citizenry, in the USA and Europe it is moving in that direction. Citizens need to become more active and vote for parties that advocate for more freedom rather than less.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#115

Earlier quoted context omitted.

> Does anyone have an idea of what 38% of the phones can have stored on them, that is illegal to have when crossing the border? Generally it's things like text messages from friends/family/potential employers that lead agents to think the person isn't going to abide by their non-work/short term visa.

that isn't a customs-related offence, though - that's an immigration related offence. Customs is concerned with the movement of goods, not movement of people.

They handle both at the border.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#116
post #74

Earlier quoted context omitted.

I've certainly reduced my tourism levels on account of CBP. Can you not rip my car to shreds every time I cross the border?

Thus reducing CO2 and working towards saving the planet

if you took cars away from the entire population that would only account for up to 25% of the CO2 being released. So, on this small a scale it's doing almost nothing.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#117
post #102

Earlier quoted context omitted.

You don't need "full" disk encryption on Chromebook devices or Android phones. Both ship with file-based disk encryption for all user data, on-by-default for all recent devices. When I travel out of the country, I reset my phone and Chromebook to their factory defaults and then provision a decoy account. Once I'm across the border, I provision my primary account. Even if they image my devices, all they'll get is old…

They could replace part of the password-checking software with a backdoored version that would send your password off to them. Your data is protected, but the OS can still compromise it and a bad actor can replace parts of the OS (which is open source in both of your cases, making the process even easier).

On Chrome OS, this should cause the “your OS is unverified” warning to show up.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#118
post #76
post #70

Earlier quoted context omitted.

who has the burden of proof though?

You do since the courts assume the parties behave honorably (I.e. they assume there is no parallel construction)

Sadly this is an incredibly cogent concept. We saw this with Lavabit and when courts accept patently false LE testimony.

The system works when corruption and deceit aren't present or tolerated - when they are the institutions become suspect.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#119
post #102

Earlier quoted context omitted.

They could replace part of the password-checking software with a backdoored version that would send your password off to them. Your data is protected, but the OS can still compromise it and a bad actor can replace parts of the OS (which is open source in both of your cases, making the process even easier).

On Chrome OS, this should cause the “your OS is unverified” warning to show up.

Does that mean that every OS file is signed and checksummed like on iOS (correct me if I’m wrong)?

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#120

Is it legal to take steps to intentionally frustrate any future searches that may be done against the device by border agents, in cases where the is no other crime being covered up? For example, having a trusted remote party encrypt your data, and that party will only decrypt it once you've cleared customs?

Why wouldn’t this be legal?
Post reply on HN