Earlier quoted context omitted.
For work data such as the lawyer in the article I would recommend go one step further and not having the password in the first place. You can achieve this by for example having the server admin at work remotely unlock the device at request, have hardware tokens at trusted locations, or software that provide similar effect. No amount of $5 wrench or legal threats can change the situation as it not in your hand to give…
How 5 dollar wrench won't work in this case? Isn't administrator going to follow his order, so he can made to call the administrator and reset keys etc..?
Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
391–400 of 483 posts
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#392I understand the law permits CBSA agents to perform warrantless searches. e.g. reading the contents of your hard drive. This is, rightly, controversial. But then does the law also permit them to modify the contents of your hard drive?
The act of logging in and browsing your computer will make many changes to system log files, to metadata of documents (e.g. last accessed date), etc. (Just thinking out loud about technicalities and other angles on this.)
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#393Earlier quoted context omitted.
Yes. This thread is full of people proposing inventive technical solutions to genuinely prohibit your own access to the device while you're going through customs, as if border patrol a) knows the difference and b) gives a damn. These are all functionally equivalent to "Um, I forgot my password." (Or, if you wish for a more plausible but equally ineffective excuse, "This is actually my mother's laptop; I'm bringing it…
> it's his job to assume you're lying and find the next legal option available to him. Not sure where you live, but in the US it's actually his first and foremost responsibility to uphold a constitution that says that people are free from unreasonable searches and seizures.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#394Earlier quoted context omitted.
CBSA officers are directed to disable any internet connection and only examine content that is already stored on a device
Perhaps one could add a specific sort of legal DRM crypto layer and then get them for anti-circumvention. No internet connection required.
Same with the CFAA.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#395If this is true ... wow.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#396> Officers uncovered a customs-related offence during 38 per cent of those searches, said the agency. I really want to understand what kind of digital data is considered a customs-related offence.
It's not the data, it's what the data reveals.
Like an SMS with 'I put $100K in your panama account'.
Obviously a bad example but you get the idea.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#397Earlier quoted context omitted.
If I'm understanding vbezhenar correctly, the implied step after uploading the encrypted file to a cloud storage service is to securely delete it from the computer you're carrying. Then, the authorities won't know that there is anything to beat out of you with their $5 wrench.
Yeah, but you still get beat with the $5 wrench. And if it was going to work in compelling you to give the password, it will still be pretty effective getting you to provide access to the cloud storage and the encryption password to it.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#398Earlier quoted context omitted.
Encrypt the data (probably easiest way is to use encrypted 7z archive), memorize the password, upload the encrypted data into any cloud storage (e.g. Google Drive) and don't care about disclosing anything on your devices.
For work data such as the lawyer in the article I would recommend go one step further and not having the password in the first place. You can achieve this by for example having the server admin at work remotely unlock the device at request, have hardware tokens at trusted locations, or software that provide similar effect. No amount of $5 wrench or legal threats can change the situation as it not in your hand to give…
They aren't going to hit me with a wrench for the decryption password to a cloud-stored blob that's not on the device (and ideally, one they don't know about. Remember the password and the location of the data. Remember to secure-delete it from your device though. There should be an easy "prep for border crossing" checklist that includes this.)
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#399i.e. There's no password to share if the devices are fresh.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#400Earlier quoted context omitted.
It's sickening to think that, despite the ban in Canada, countless innocent anime girls are being abused in Japan every day - many of them children! The UN should apply pressure to get Japan to stop this vile abuse, and import of cartoons into Japan should be banned, as their safety cannot be guaranteed there.
Fictional child pornography does not directly harm children, but it is likely that it does so indirectly by creating demand for actual CP. To me, it seems totally reasonable to make all sexualized depictions of children illegal for this reason.