Live data from Hacker News

Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

cbc.ca

341–350 of 483 posts

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#341

Earlier quoted context omitted.

Yeah, but you still get beat with the $5 wrench. And if it was going to work in compelling you to give the password, it will still be pretty effective getting you to provide access to the cloud storage and the encryption password to it.

How does the low paid border security drone even know you have a cloud storage account? What country do you live in that has to worry about people being tortured to death on a frequent basis? This stuff just doesn't happen often, despite what a silly XKCD comic would lead you to believe. Encryption actually works pretty damn well, for basically all usecases that a normal person would come across. The world is not a J…

I'm not saying any of this is likely. But, as the topic was raised, if they break you and you start talking, you will volunteer the information. They don't need to know before hand.

That said, the most practical scenario here is to keep your important files secured somewhere else, cloud or elsewhere, and when they ask you to unlock your phone or laptop you say "Sure!" Because there's nothing to find and you're compliant and helpful so they quickly let you go after a proforma search.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#342
post #169

Earlier quoted context omitted.

>> Can this be used to get whatever case(es) he was defending thrown out because solicitor-client privilege was violated or parallel construction was used? That isn't what this is about. Nobody is talking about what this is really about and it isn't anything to do with him being a lawyer. This guy (1) was traveling alone (2) to a distant (3) and poor (4) country without preexisting business ties (5). Those are all re…

It's still a dragnet. They're not SWATing a semiautomatic rifle up your nose - nobody's claiming they're not polite - but the fact remains.

Police generally have access to full-automatic machine guns. They’re not limited to the semi-automatic models sometimes available to civilians (e.g. in the US).

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#343
post #318

Earlier quoted context omitted.

This might partially answer your question... I had my laptop searched at the border once. It was my work laptop. They told me the same thing, if I didn't share the password they would confiscate my computer. It felt wrong that they should be able to search my computer, but I also felt bullied because I was going to need my computer the next day if I wanted to work and I think most people, including my boss at the tim…

Why do you think they did this kind of invasive search? It's very weird to me that border patrol would randomly search all the images on someone's computer. This doesn't even seem like an efficient way to catch criminals. Power trip?

Maybe just "a randomized search". Sounds very inefficient.

I think they are just looking for crimes like drug mules, people coming to work with tourist visa etc. Everyone here talks about nuclear plans but I doubt.. probably bully too but against simple minded criminals it can work. Texts of arranging work or when is the package going to arrive etc.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#344

Earlier quoted context omitted.

I mean what counts as work and where it occurs are becoming very difficult to manage? What happens if you have to do work while on a real holiday, should you be deported for this? Is it valid to allow these searches for these sort of offences, it seems like at some point everyone will be guilty of doing these things.

I wonder this myself. There is a difference between traveling for the purposes of work, and working while traveling. I have a 100% remote position. I normally do my work in the US. I've considered flying to Europe for a few weeks, where due to time zone differences I could do touristy stuff during the day and then work my US 9-5 shift in the EU evening. This would allow me to travel but to not take vacation time. Wou…

Generally speaking, there isn't a difference between traveling for the purpose of work and working while traveling for other reasons. If you are physically in one country while performing work it is considered working in that country and requires appropriate permission. Many countries do have a business visitor category that allows for some form of work (attending meetings, and the like, things that wouldn't be stealing the job of a resident).

I actually learned this the hard way, I was in your shoes, 100% remote job, for a US company, US clients, and went to Europe and thought I might work while traveling. I was detained at the border, interviewed, and very nearly denied entry. I was let after a couple fairly lengthy interviews (I was detained for about 16hours) and proving I had funds to support myself without working. I was given a "visitor record" and a firm exit by date, not sure what all the record entails but I get questioned every time I enter now.

Anyway, point being, legally speaking what generally matters is where you are located when performing the work, and that's really the only way that makes sense to judge where the work takes place.

With all that said, in reality being caught is extremely unlikely and plenty of people get away with it and I don't think there are many countries actively trying to crack down on that sort of short term work while being a tourist. If you want to be above the board though, unless your work counts as what a business visitor can do, you would need a visa to perform any work. There is generally no distinction between traveling for the purpose of working, and working while traveling for other reasons.

I'm not a lawyer though but I've spent a fair bit of time actually looking at the restrictions on the tourism and business visitor visas to stay legal while traveling long-term and working remotely.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#345

I've always preferred having a dedicated desktop that acts as a personal server and then a small cheap laptop that I use to remotely access it. While this preference is mostly driven by capitalizing on the performance/price/size difference between desktops and laptops, it has lots of advantages when it comes to these situations. My Dell XPS 13 only has 128GB of storage so none of the data exists solely on that device…

Do you have a citation on how using Linux can get you detained?

I haven't heard of Linux getting people detained at border crossings, but it definitely gets you more scrutiny from other government organizations like the NSA[1].

[1] https://www.eweek.com/security/linux-lands-on-nsa-watch-list

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#346
post #160
post #99

I have asked this question before, but never really got a satisfiable answer: why do governments (not just USA/canada) spend these resources to check data physically at a border? It's not like you need to 'smuggle' any form of data physically. I mean, any data considered to be dangerous (like terrorist attack plans, atomic bomb designs or political inside information) can be accessed across borders via the internet.…

There is actually a Canadian Border Patrol TV show you can watch, and they don't even try and hide that they do this. They very openly show when they check someones phone and laptop. I have seen it on the show, and they have shown them "catching" people. They'll usually use it to check if people are intending to stay and work in Canada, such as seeing in their texts or emails that they were arranging work and/or plac…

Even if I agreed with customs officers rifling through my devices, I would only ever want them to have read-only access. Like, you'd hope they're not malicious, but can you really trust some in-a-hurry agent with little to no training in this area to not accidently wipe half your hard drive?

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#347
post #206

Earlier quoted context omitted.

The problem here is that they confiscate regardless. Even when it's very clear they do not have the means to break the encryption at all. Any excuse, reasonable or not, will dissatisfy them and they'll confiscating either permanently or temporarily (both seem to have happened).

It seems to me that the best option is to keep sensitive data on encrypted removable storage devices while having light security on the internal storage of a laptop or phone. Access could then be granted to the laptop/phone, but refused for the external storage device. You want to indefinitely detain my $20 SD card if I won't give you the password? That's not a sufficient threat to convince me.

They could also refuse entry or detain you if your not a citizen for obstruction of justice.

These laws that give border security unfettered search and seizure authority along with issuing punishment for non-compliance is the problem.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#348
post #339

Earlier quoted context omitted.

Would this system come with plausible deniability? Also, does anything like this exist for desktop operating systems?

If there is a common mechanism for triggering dual boot, they would know about it and try it out too. So, not unless you use a unique, inconspicuous mechanism.

I don't know much about cryptography or low-level software, but could you hide the second profile inside the encrypted data?

For example, I believe Truecrypt has a dual container system with two passwords in addition to their regular encrypted containers. You enter one password to get to the "fake" container and another password to get to the "hidden" container. Plausible deniability exists where it is impossible to prove whether you are providing the hidden password and whether there is a second hidden container.

Could a similar system be employed for a mobile device? The core OS components could be shared by both containers and it's clear that you could potentially have a second hidden profile, but it's not possible to prove that it exists.

Of course just the presence of countermeasures on your devices would raise suspicion.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#349

It's stuff like this that makes me want to build after-market privacy-oriented Samsung firmware, that at a low level (secondary bootloader) supports dual booting. By default you'd boot into the "non-private" environment. That way if customs asks to see your device, you simply boot it up and hand it over. Could make life a lot easier for lawyers, doctors, C-level executives etc. I should note, dual-booting Android pho…

Providing the fake password would be, at the very least, lying to the border patrol agent. Which is an actual crime.

This might be a reasonable solution if it's a one-off unique solution and is therefore unlikely to be detected. But if you can't count on security through obscurity, this is a good way to end up serving real jail time.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#350

Earlier quoted context omitted.

This might partially answer your question... I had my laptop searched at the border once. It was my work laptop. They told me the same thing, if I didn't share the password they would confiscate my computer. It felt wrong that they should be able to search my computer, but I also felt bullied because I was going to need my computer the next day if I wanted to work and I think most people, including my boss at the tim…

>it was a pretty innocuous search You and I disagree wholeheartedly there, that's an extremely invasive search.

In particular, a perfectly reasonable answer to the question "what am I going to find on this computer?" might be "Naked pictures of me/my spouse" if it's a non-work laptop.

It's extremely invasive for some random civil servant to execute an unexpected search on a device that most reasonable people assume is private.

Post reply on HN