Earlier quoted context omitted.
Thanks for your work on Heimdall btw. It the only reason my samsung s5 is still running fine years after it came out.
Did you put a new Android on it, or just a bloat-free ROM? My devices became noticably slower with (official) major Android version upgrades.
Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
471–480 of 483 posts
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#472Earlier quoted context omitted.
It was a sincere question. You say you've read up on this. I haven't, though I have lived in Thailand and travelled around the region, and from my personal experience (not as a consumer, but I don't need to be a smoker to have some idea (anecdotally) of the level of smoking around me) the vast majority of foreign men that were consumers were not involved in anything to do with children or any such thing. Hence, I was…
You may think I mean straight up pedopholia involving elementary school aged children. That can happen certainly. But a 17 year old is legally still a child in many jurisdictions. A lot of men in their twenties see nothing wrong with getting involved with a 17 year old. If you are talking a dating situation, my views on that get a lot more complicated. If you are talking prostitution, a 17 year old sex worker is high…
> At that point, it is, in fact, child rape, even if you aren't comfortable with the terminology and wish nicer language were used to describe it.
- Where did I say or imply that it wasn't child rape? - Where did I say or imply I wasn't comfortable with that terminology? - Where did I say or imply I was wishing nicer language were used to describe it?
I'm not sure how you hope to have an adult discussion on a sensitive topic if you're going to insinuate that asking you a question is tantamount to defending child rape.
I for my part have tried to find out more from someone who says they know more. I'm reading the research from one of the Wikipedia references you gave and questioning some of my assumptions while trying to remain sceptical and clear headed enough to analyse it.
> I don't feel compelled to try make it sound nicer given how damaging it can be to the child in question.
I think it's unlikely that most people in this discussion are condoning or defending this behaviour (or maybe they are but they should still get a chance to give their point and be challenged). Since we know most people will say they're for the protection of children wouldn't it be better to take them at their word, play the numbers and realise the majority here will be the same, and, if not tone down the description, tone down the attitude?
It's Hacker News, not Twitter.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#473Earlier quoted context omitted.
Fictional child pornography does not directly harm children, but it is likely that it does so indirectly by creating demand for actual CP. To me, it seems totally reasonable to make all sexualized depictions of children illegal for this reason.
I disagree. Texts and fictional drawings should not be made illegal, regardless of their content. (I am not so sure that even actual child pornography should be illegal, although maybe it should be illegal to buy and sell actual child pornography, and also illegal to take photographs of them without their permission (even if it isn't for money).)
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#474Earlier quoted context omitted.
How about we avoid that slippery slope entirely, by using a very expansive definition lumps in sex with anyone under 21 as going in the 'depraved or otherwise a problem' category. Now will you please consider giving some data or some kind of percentage or explain why you said "probably"? No one is trying to claim this kind of horrible behavior doesn't exist. But I want to understand the scale of the problem. Trying t…
Thailand’s Health System Research Institute reports that children in prostitution make up 40% of prostitutes in Thailand. In Cambodia, it has been estimated that about a third of all prostitutes are under 18. https://en.m.wikipedia.org/wiki/Child_sex_tourism There are many readily available articles on the topic just a Google away if you really want to know more.
> Thailand’s Health System Research Institute reports that children in prostitution make up 40 percent of sex workers in Thailand.
I can't find this report even though I've been using the HSRI's own searchable database[2] and search engines (you'll need Google Translate unless you can read Thai). I did, however, see see numerous other reports reusing the same quote in the searches returned by an engine, so it's well used.
If we continue the same paragraph:
> At the other end of this debate many NGOs estimate the number of CSEC victims to be in the hundreds of thousands. Other reports estimate the number of child victims of prostitution to be at least 80,000 but likely to be in the hundreds of thousands (ECPAT International; The Protection Project, 2002: 539).
I can't find any Protection Project report about Thailand in their publications[3], nor do they include Thailand in their list of country reports[4]. I also cannot be sure that either of the reports[5][6] I found on ECPAT's site are the one cited. The larger one, which was published in 2011 (but is the 2nd edition so perhaps it is from 2002) does not include the figure. It does however have this:
> Prostitution is technically illegal in Thailand, but sexual services are sold openly with an estimated 60,000 children under age 18 involved in prostitution.15
This is note 15: > U.S. Department of State, 2009 Country Report on Human Rights Practice, Thailand. Accessed on 13 July 2010 from: http://www.state.gov/g/drl/rls/ hrrpt/2009/index.htm
This is the statement in the report[7]:
> In 2007 the government, university researchers, and NGOs estimated that there were as many as 60,000 prostitutes under age 18.
No note for that one, it's a dead end.
This doesn't mean the figure is wrong, of course, but it does support the idea that people should be able to question figures, and when challenged, claims should be backed up by something better that circular references, missing reports, and dead ends.
[0] https://web.archive.org/web/20070712223227if_/http://www.uni...
[2] http://kb.hsri.or.th/dspace/
[3] http://www.protectionproject.org/publications/
[4] http://www.protectionproject.org/country-reports/
[5] https://www.ecpat.org/wp-content/uploads/legacy/Factsheet_Th...
[6] https://www.ecpat.org/wp-content/uploads/legacy/a4a_v2_eap_t...
[7] http://www.state.gov/g/drl/rls/hrrpt/2009/index.htm
Edit: formatting, a little bit of javascript wouldn't go amiss for the comment boxes!
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#475I recently returned from a trip to the US, and prior to boarding (in any direction) i wiped my browser history, and logged out of iCloud, wiping all message history etc. When i arrived at my destination i simply restored from the last iCloud backup, and things "magically" reappeared.
Reading the comments here made me realize that it's much more than just personal emails/notes, but also things like Uber history, frequent locations, frequent calls, etc. Basically anything you do that has a pattern to it, or matches a list of keywords.
As i don't see the need nor justification for any government to profile me in detail, I'm seriously considering doing a complete wipe of the phone for my next trip, setting it up as a basic _phone_ and restore a backup once i arrive. For a laptop i would probably set it up as new, and bring an installation media with me, reinstalling when i arrive.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#476I’d love to have a second password that when I enter it automatically encrypts the phone and simultaneously loads a dummy user account. This way I can give them my password, let them look around at some basic programs, benign emails, photos, etc. and then hand me back the phone. Perhaps even a couple dummy passwors so I can keep a password like “1111” to generate a false positive if they try to brute force my phone.…
The problem is if these features become common enough you will start getting asked about them. Even worse, if you aren't using them you may be asked to provide something that is impossible to provide.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#477Earlier quoted context omitted.
You don't have any rights at the border. The moment they decide to search you they will ask for your passwords. If you don't give it, they'll detain you until you do.
What if you do not know the password for the computer (e.g. if you are transporting someone else's computer, or because it is damaged and need to be repaired), or if it is time locked?
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#478Earlier quoted context omitted.
For work data such as the lawyer in the article I would recommend go one step further and not having the password in the first place. You can achieve this by for example having the server admin at work remotely unlock the device at request, have hardware tokens at trusted locations, or software that provide similar effect. No amount of $5 wrench or legal threats can change the situation as it not in your hand to give…
How 5 dollar wrench won't work in this case? Isn't administrator going to follow his order, so he can made to call the administrator and reset keys etc..?
Border services generally have extensive but constrained powers - in the US, they're limited in how far from a border they can exercise authority. So they don't get to arrest the administrator directly, or go and confiscate an access key sitting in Edmonton. They can still demand that whoever is at the border arrange for unlocking, and can probably seize the device if they're refused. But the threat "we'll lock you up until you open the device" is potentially legal, while "we'll lock you up because as a hostage until somebody else opens this" has far less merit. (Obviously, none of this applies if you go someplace where actual hostage takings might happen.)
If the administrator says "I need physical access to unlock that" or "our firm's policy says I can only open devices once they're at one of our offices being used for billable hours", there's no one handy to apply the wrench to. At that point, confiscate-and-image is as much access as anyone can hope to get.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#479Earlier quoted context omitted.
The wrench need only be applied to whomever tells the admin to unlock the archive. In a manner that the admin is likely to accept the request.
This is where duress codes can be useful.
Drill those, though.
Under stress, people fall back on learned patterns.
Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords
#480>Wright refused, telling the officer both devices contained confidential information protected by solicitor-client privilege. >He said the officer then confiscated his phone and laptop, and told him the items would be sent to a government lab which would try to crack his passwords and search his files. Can this be used to get whatever case(es) he was defending thrown out because solicitor-client privilege was violate…
There's more to it than potentially thrown out. Could he be censured for failing to secure information about clients? IANAL, but I'm pretty sure that over-sharing about clients can be a poor career move. And what if this had been a US lawyer, who was representing someone who'd received a US NSL? Would he have violated the NSL? Who would the US go after, him or Canada Border Services?
If this were a US attorney at a US border, almost certainly not. ABA rules permit attorneys to disclose client information (among other reasons) "to comply with other law or a court order."
Even as far as a US attorney receiving orders from another country, or a blatantly illegal instruction within the US, they should be alright. The lawyer didn't actually disclose client information, they just lost control of it. The ABA only requires "reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information" about clients. Offering up the password might not have been a reasonable effort, especially in the absence of consequences for refusing, but having the device imaged and cracked seems to clearly exceed reasonable efforts to prevent unauthorized access.
As for NSLs, what a mess. I'm not sure anyone can answer this for you. They already push the established bounds of compelled speech, so general precedent wouldn't be a trustworthy guide. And any NSL-specific precedent was almost certainly set in closed, confidential hearings, so the people only people familiar with it wouldn't be able to discuss it.