Live data from Hacker News

Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

cbc.ca

201–210 of 483 posts

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#201
post #125

Earlier quoted context omitted.

There are cases at the Canadian border in which the investigators search for "boy" or "girl" using the Windows search tools to see if there is child pornography on your device. In other circumstances, they uncover hentai[0] showing characters that appear to be underage - and bringing that into Canada is illegal (in fact, much like Australia and New Zealand, any sexual depiction of fictional minors is illegal, and tha…

It's sickening to think that, despite the ban in Canada, countless innocent anime girls are being abused in Japan every day - many of them children! The UN should apply pressure to get Japan to stop this vile abuse, and import of cartoons into Japan should be banned, as their safety cannot be guaranteed there.

Fictional child pornography does not directly harm children, but it is likely that it does so indirectly by creating demand for actual CP. To me, it seems totally reasonable to make all sexualized depictions of children illegal for this reason.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#202
post #195

Earlier quoted context omitted.

Encrypt the data (probably easiest way is to use encrypted 7z archive), memorize the password, upload the encrypted data into any cloud storage (e.g. Google Drive) and don't care about disclosing anything on your devices.

It's easy to break your encryption. Trust me, if you live in a country that has crap laws, they will actually extract the password from you: https://xkcd.com/538/ Edit I'm not saying it's a bad idea to encrypt your drives, just that it doesn't save you from someone determined..

This post is about western countries. The vast majority of western countries will not literally torture you to death, in order to get rando citizen's phone passwords.

Encryption works great for this usecase, that almost everyone in this thread will be using it for.

People being tortured for their personal phone password by a rando border guard in basically any country, just isn't something that happens, despite what the internet memes would lead you to believe.

Even in supposedly bad countries, I really doubt that this "attack vector" is something that happens frequently.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#203
post #126

Earlier quoted context omitted.

What exactly is wrong with this approach? It should get you through the border with no further suspicions, since I’m guessing they don’t have the time to be checking for hidden partitions for every traveler they pull over.

1) Because this can give officers probable cause to detain you. Just like if they find a hidden compartment in your luggage, even if there's no contraband in it, you'll be held many hours in a freezing cold room while they examine every detail of you and your property. 2) Because it could be a crime. Failure to disclose an encryption key if requested by UK Police and Customs authorities is a breach of The Terrorism A…

Yes, true.

But if you are at the border and give to the officers all what they want ( access to your laptop and phone ), why would they have further suspicions to interrogate and/or detain and deep search your devices, if you are really a clean person, dunno, white, 30-40 years, suit up, good clothing, no strange stuff in traveling history..etc.?

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#204

Earlier quoted context omitted.

Encrypt the data (probably easiest way is to use encrypted 7z archive), memorize the password, upload the encrypted data into any cloud storage (e.g. Google Drive) and don't care about disclosing anything on your devices.

Discover that your password has ended up in a swap file one day and hasn't been overwritten, and chrome left you logged into Google drive. I wouldn't trust this approach not to fail by accident.

Let the computer you used for encryption and uploading at home.. Take an empty/new notebook/smartphone with you to show at the border?

edit: place a big random data file, which looks like encrypted data on your alibi notebook. Refuse to give password and let the government lab try to find the password..

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#205
post #195

Earlier quoted context omitted.

Encrypt the data (probably easiest way is to use encrypted 7z archive), memorize the password, upload the encrypted data into any cloud storage (e.g. Google Drive) and don't care about disclosing anything on your devices.

It's easy to break your encryption. Trust me, if you live in a country that has crap laws, they will actually extract the password from you: https://xkcd.com/538/ Edit I'm not saying it's a bad idea to encrypt your drives, just that it doesn't save you from someone determined..

If I'm understanding vbezhenar correctly, the implied step after uploading the encrypted file to a cloud storage service is to securely delete it from the computer you're carrying. Then, the authorities won't know that there is anything to beat out of you with their $5 wrench.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#206

Is it legal to take steps to intentionally frustrate any future searches that may be done against the device by border agents, in cases where the is no other crime being covered up? For example, having a trusted remote party encrypt your data, and that party will only decrypt it once you've cleared customs?

The problem here is that they confiscate regardless. Even when it's very clear they do not have the means to break the encryption at all. Any excuse, reasonable or not, will dissatisfy them and they'll confiscating either permanently or temporarily (both seem to have happened).

It seems to me that the best option is to keep sensitive data on encrypted removable storage devices while having light security on the internal storage of a laptop or phone.

Access could then be granted to the laptop/phone, but refused for the external storage device. You want to indefinitely detain my $20 SD card if I won't give you the password? That's not a sufficient threat to convince me.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#207
post #81

Earlier quoted context omitted.

Remote wipe might not play very well. If it was detained in relation with a crime, they might go with 'attempting to destroy evidence'. Look at it this way. Suppose the seizure of the phone was totally reasonable (because that is how they will think about it). Now, that suspected criminal who apparently had something to hide decided to remotely tamper with evidence after we lawfully detained it? That is subversion of…

Isn't it legal to destroy evidence that can be used against you? That's basically exercising your right to not self-incriminate.

Oh dear no. The U.S. protection against compelled self-incrimination is for testimony, not seizure of papers/effects. Spoliation of evidence is illegal, and in some cases if it's not a crime by itself, it can still even lead to doubt being resolved against you (in other words, if you destroy a key document in a legal proceedings, the court might make a legal judgment that assumes the document's contents were as bad as possible for your case, even if it actually wasn't).

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#208
post #204

Earlier quoted context omitted.

Discover that your password has ended up in a swap file one day and hasn't been overwritten, and chrome left you logged into Google drive. I wouldn't trust this approach not to fail by accident.

Let the computer you used for encryption and uploading at home.. Take an empty/new notebook/smartphone with you to show at the border? edit: place a big random data file, which looks like encrypted data on your alibi notebook. Refuse to give password and let the government lab try to find the password..

> Let the computer you used for encryption and uploading at home.. Take an empty/new notebook/smartphone with you to show at the border?

This is certainly safer, though maybe not possible on the return trip (where you're returning from someplace where you only have access to your laptop). If you need to be this careful, maybe it's best to do your work after livebooting into tails or something like that.

> edit: place a big random data file, which looks like encrypted data on your alibi notebook. Refuse to give password and let the government lab try to find the password..

Funny, but unnecessarily risky if you ask me.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#209

Earlier quoted context omitted.

Encrypt the data (probably easiest way is to use encrypted 7z archive), memorize the password, upload the encrypted data into any cloud storage (e.g. Google Drive) and don't care about disclosing anything on your devices.

Not a great idea. You have no reason to believe deleted and cached copies aren’t lingering on you disk unprotected.

Can't you just use a tool like 'shred' to securely delete the file(s) ?

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#210

Earlier quoted context omitted.

Encrypt the data (probably easiest way is to use encrypted 7z archive), memorize the password, upload the encrypted data into any cloud storage (e.g. Google Drive) and don't care about disclosing anything on your devices.

Full drive encryption and then using spideroak for cloud storage is a better and easier solution

Full disk encryption doesn't help if you share the password that decrypts the disk.
Post reply on HN