Live data from Hacker News

Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

cbc.ca

391–400 of 483 posts

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#391
post #228

Earlier quoted context omitted.

For work data such as the lawyer in the article I would recommend go one step further and not having the password in the first place. You can achieve this by for example having the server admin at work remotely unlock the device at request, have hardware tokens at trusted locations, or software that provide similar effect. No amount of $5 wrench or legal threats can change the situation as it not in your hand to give…

How 5 dollar wrench won't work in this case? Isn't administrator going to follow his order, so he can made to call the administrator and reset keys etc..?

This assumes you can get the wrench close enough to the admin. If they are in another country, one that is outside of your jurisdiction you'll have a hard time applying your wrench.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#392
If you demonstrate that government employees changed files all over your hard drive during a "search" then I wonder if recourse or compensation or legal action is possible.

I understand the law permits CBSA agents to perform warrantless searches. e.g. reading the contents of your hard drive. This is, rightly, controversial. But then does the law also permit them to modify the contents of your hard drive?

The act of logging in and browsing your computer will make many changes to system log files, to metadata of documents (e.g. last accessed date), etc. (Just thinking out loud about technicalities and other angles on this.)

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#393
post #388
post #381

Earlier quoted context omitted.

Yes. This thread is full of people proposing inventive technical solutions to genuinely prohibit your own access to the device while you're going through customs, as if border patrol a) knows the difference and b) gives a damn. These are all functionally equivalent to "Um, I forgot my password." (Or, if you wish for a more plausible but equally ineffective excuse, "This is actually my mother's laptop; I'm bringing it…

> it's his job to assume you're lying and find the next legal option available to him. Not sure where you live, but in the US it's actually his first and foremost responsibility to uphold a constitution that says that people are free from unreasonable searches and seizures.

Well, in a country with a for-profit, for-"performance" law enforcement system, where prosecutors are paid by how many people they put in jail and cops are paid by how many traffic tickets they write, do you really think some paper from 1787 is going to have much influence on a TSA agent if their paycheck depends on sorting out as many "bad guys" as possible?

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#394
post #186
post #42

Earlier quoted context omitted.

CBSA officers are directed to disable any internet connection and only examine content that is already stored on a device

Perhaps one could add a specific sort of legal DRM crypto layer and then get them for anti-circumvention. No internet connection required.

As you might expect, law enforcement is specifically exempt from the DMCA's antcircumvention provisions. I would imagine that's true for other countries' equivalents as well.

Same with the CFAA.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#395
"During 38 per cent of those searches, officers uncovered evidence of a customs-related offence — which can include possessing prohibited material or undeclared goods, and money laundering, said the agency."

If this is true ... wow.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#396

> Officers uncovered a customs-related offence during 38 per cent of those searches, said the agency. I really want to understand what kind of digital data is considered a customs-related offence.

"what kind of digital data is considered a customs-related offence"

It's not the data, it's what the data reveals.

Like an SMS with 'I put $100K in your panama account'.

Obviously a bad example but you get the idea.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#397

Earlier quoted context omitted.

If I'm understanding vbezhenar correctly, the implied step after uploading the encrypted file to a cloud storage service is to securely delete it from the computer you're carrying. Then, the authorities won't know that there is anything to beat out of you with their $5 wrench.

Yeah, but you still get beat with the $5 wrench. And if it was going to work in compelling you to give the password, it will still be pretty effective getting you to provide access to the cloud storage and the encryption password to it.

But it will not work if you do not know the password. (It can also be time locked with false data; they don't know whether or not it is the real data.)

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#398
post #228

Earlier quoted context omitted.

Encrypt the data (probably easiest way is to use encrypted 7z archive), memorize the password, upload the encrypted data into any cloud storage (e.g. Google Drive) and don't care about disclosing anything on your devices.

For work data such as the lawyer in the article I would recommend go one step further and not having the password in the first place. You can achieve this by for example having the server admin at work remotely unlock the device at request, have hardware tokens at trusted locations, or software that provide similar effect. No amount of $5 wrench or legal threats can change the situation as it not in your hand to give…

The usefulness of this "trick" relies on not having the _data_.

They aren't going to hit me with a wrench for the decryption password to a cloud-stored blob that's not on the device (and ideally, one they don't know about. Remember the password and the location of the data. Remember to secure-delete it from your device though. There should be an easy "prep for border crossing" checklist that includes this.)

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#399
Get a Chromebook, factory reset before going through security, go through the security, then login. Same for the phone for android. Nowadays both Chromebook and Android recover almost all states back fairly quickly and smoothly that you can do this with minimal hassle.

i.e. There's no password to share if the devices are fresh.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#400
post #125

Earlier quoted context omitted.

It's sickening to think that, despite the ban in Canada, countless innocent anime girls are being abused in Japan every day - many of them children! The UN should apply pressure to get Japan to stop this vile abuse, and import of cartoons into Japan should be banned, as their safety cannot be guaranteed there.

Fictional child pornography does not directly harm children, but it is likely that it does so indirectly by creating demand for actual CP. To me, it seems totally reasonable to make all sexualized depictions of children illegal for this reason.

I disagree. Texts and fictional drawings should not be made illegal, regardless of their content. (I am not so sure that even actual child pornography should be illegal, although maybe it should be illegal to buy and sell actual child pornography, and also illegal to take photographs of them without their permission (even if it isn't for money).)
Post reply on HN