> He said the officer then confiscated his phone and laptop, and told him the items would be sent to a government lab which would try to crack his passwords and search his files. Hopefully they were powered down and used proper full-disk encryption.
> Hopefully they were powered down and used proper full-disk encryption. What exactly is full-disk encryption? How do I do it the way a government lab won't be able to crack it?
Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
351–360 of 483 posts
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#352It's stuff like this that makes me want to build after-market privacy-oriented Samsung firmware, that at a low level (secondary bootloader) supports dual booting. By default you'd boot into the "non-private" environment. That way if customs asks to see your device, you simply boot it up and hand it over. Could make life a lot easier for lawyers, doctors, C-level executives etc. I should note, dual-booting Android pho…
Providing the fake password would be, at the very least, lying to the border patrol agent. Which is an actual crime. This might be a reasonable solution if it's a one-off unique solution and is therefore unlikely to be detected. But if you can't count on security through obscurity, this is a good way to end up serving real jail time.
However, it's pretty well understood criminals aren't legally required to self-incriminate. For example, if a criminal was to hand over their password, they're not then obligated to assist border security in navigating through their phone's storage to specifically point out evidence against themselves.
Whilst I'm not advocating this solution for criminals(!), I'd assume the same logic ought to hold true for those that have careers where privacy is paramount.
If you simply boot up your phone (into the "non-private" environment) and have no password, or perhaps even use the same real password (remember to change it later), then it's not necessarily your fault the border agents don't know how to use your phone.
EDIT: In terms of lying / being discovered, this is why I'm proposing a low-level dual-booting solution, rather than simply having multiple profiles on the device. It ought to be 100% undetectable that the device supports dual-booting at all, unless the user performs a precise action to boot into the private environment e.g. connect the phone to PC, and submit a specific boot command with a user provided password. Without the correct password being provided, the phone should respond no differently than a phone that does not support dual booting.
Although, IANAL nor have I made any attempt to look into the laws surrounding this. I would be surprised, although not too surprised, to hear there are laws specifically covering this situation. Nonetheless, it'd be a loophole for sure, and presumably easy enough to close off with further legislation.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#353Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#354This is one problem asking for a sass solution. What services exist to help this situation?
if a solution were to be created, could the company be held liable for obstruction of justice via aiding and abetting? I guess this could be taken care of with an extended terms of service which lay out how the product shouldn't be used to prevent search and seizure by government officials...
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#355Earlier quoted context omitted.
I took a workshop on custom Kali builds where they specifically spoke about LUKS headers and shipping them via email/gdrive to yourself and removing them from the physical device. It renders the partition useless. This was viewed as a better alternative than something like TrueCrypt with decoy passwords since if the government can ever prove you did it then that's obstruction. With the headers gone and no local copy…
> This was viewed as a better alternative than something like TrueCrypt with decoy passwords since if the government can ever prove you did it then that's obstruction. If that qualifies as a type of legally actionable obstruction, it would seem that intentionally wiping your device before you cross a border and then reloading data onto it once you arrive at your destination would also qualify.
ETA: To complete the threat analysis, and if they seize two devices, one with a password protected key and a LUKS volume without headers? I'll take LUKS.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#356Earlier quoted context omitted.
If you're THAT worried, then securely reformat disk and reinstall OS just before travel.
This action can be flagged as suspicious as well, triggering a deeper investigation into the traveler. It's not always feasible, but the most secure way to protect clients'/employers' data is to encrypt the laptop and phone and ship to your destination via standard shipping services, then ship them back the same way before leaving for home. Carry a well used but non-critical burner laptop ($50 Chromebook off Craigsli…
Whenever I travel internationally on business and need a laptop, I'm required by company policy to bring a laptop freshly wiped by IT instead of my normal laptop.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#357Earlier quoted context omitted.
Why do you think they did this kind of invasive search? It's very weird to me that border patrol would randomly search all the images on someone's computer. This doesn't even seem like an efficient way to catch criminals. Power trip?
Maybe just "a randomized search". Sounds very inefficient. I think they are just looking for crimes like drug mules, people coming to work with tourist visa etc. Everyone here talks about nuclear plans but I doubt.. probably bully too but against simple minded criminals it can work. Texts of arranging work or when is the package going to arrive etc.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#358Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#359>Wright refused, telling the officer both devices contained confidential information protected by solicitor-client privilege. >He said the officer then confiscated his phone and laptop, and told him the items would be sent to a government lab which would try to crack his passwords and search his files. Can this be used to get whatever case(es) he was defending thrown out because solicitor-client privilege was violate…
Could he be censured for failing to secure information about clients? IANAL, but I'm pretty sure that over-sharing about clients can be a poor career move.
And what if this had been a US lawyer, who was representing someone who'd received a US NSL? Would he have violated the NSL? Who would the US go after, him or Canada Border Services?
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#360Earlier quoted context omitted.
> A relatively wealthy, privileged person going someplace poor for sex is probably doing it because it facilitates doing rather nasty things in a way that is comfortable for them Or simply because it's easier because prostitution is not (as) criminal and/or it's well organised (e.g. red light zones), and not forgetting it's likely to be much cheaper. To assume their choice of destination for something as nasty as rap…
It's not an assumption. That's based on reading about the topic. It may not be universally true, but the fact that it is fairly often true is why the term has such negative meaning for most people.