Live data from Hacker News

US border forces are seizing Americans' phone data and storing it for 15 years

engadget.com

271–280 of 566 posts

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#271

Terrifying for only 2 reasons: 1. Any malicious person savvy enough to pull off a crime of interest to the Feds is smart enough to provide a wiped or burner phone to DHS/ICE, and they have to know this. So, what is the point in doing this if not to target law abiding citizens. 2. USGOV has a spotty track record of keeping this information secure. A foreign actor is likely to access this info eventually. As one former…

> 1. Any malicious person savvy enough to pull off a crime of interest to the Feds is smart enough to provide a wiped or burner phone to DHS/ICE, and they have to know this. So, what is the point in doing this if not to target law abiding citizens. This isn't even remotely true. See for example the recent Anom honeypot[1]. Criminals do more or less the same things that ordinary citizens do, and often have strictly wo…

> Criminals do more or less the same things that ordinary citizens do, and often have strictly worse security practices because they believe "ordinary" things are weaker

This is a "survivor" bias fallacy.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#272
Unless this sort of thing gets corrected, it will be used in corrupt ways and to enforce tyrannical laws / regimes.

Did much of the progress in the past that led us to today's democratic institutions involve law-breaking, strictly interpreted, of the law of the day? Would too-effective, too-cheap enforcement have prevented that progress? I know little about history, but I suspect so.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#273

On my last trip back from Europe in June, when I re-entered the US, US Customs & Border Control didn't ask for my passport. No one did. They did wave a webcam connected to a computer in front of my face, and then a moment later, called out my name and said I could enter. Same with everyone coming through the international border area. I think that's just as weird a development and worthy of "WTH?" as this topic.

Were you on the illusion that they didn't have your biometric data? Or that they didn't have the passenger list with your name in it? Those two are pretty transparent (and honestly, not a big deal).

Does biometric here mean your passport photo? I totally believe this is the official name, but the nomenclature definitely opens up the possibility of concept creep so that biometric data can mean anything from the mundane to the terrifying

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#274

Earlier quoted context omitted.

Non removable sim? Who wants that?

It is less "sim card is tied to this phone and can't be moved" and more "sim card exists logically and doesn't require a physical presence in the phone it wants to be used in"

Which really sucks for travellers. High roaming costs? Just go to a gasstation and buy a travel sim card, put it inside, use it, put it in the walled when you leave, and if you still have any data left, use it the next time you come there.

eSIMs are a pain in the ass for that.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#275

Earlier quoted context omitted.

They can't actually do that. If you just refuse to give them the password they'll give it back to you.

In 2014, I (an American) refused to give my passwords to Canada and they denied me entry and never gave me back my phone or laptop.

How can USA deny you entry to your home country? Where are they going to send you?

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#276

As a thought experiment, what would happen if you wrote your own malicious payload to a burner device and handed that over? What if you warned the border agents that your device would deliver malicious code and they plugged it in anyway?

I believe there was a defcon talk about this but for the life of me I can't find it. My advice is to epoxy your lightning port closed (or snip the data connection inside the phone) and use wireless charging exclusively. edit: It was the Signal founder. https://appleinsider.com/articles/21/04/21/signal-hacks-cell...

what if its a laptop now?

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#277

This happened to me in 2016 crossing into Canada. Borders agents took my phone for no reason, demand I give them the password to unlock it (otherwise they would seize the phone), took it in the back for 45 min before returning it and letting me enter. I think it’s obvious they took all my data. So now when I travel I just bring my “travel” phone with no sensitive data on it.

One approach would be to upload everything, wipe the phone, then log back in but not connect to iCloud (or Google).

Once you've cleared the border, go to a coffee shop and download over their WiFi. Or not, if you're on a unlimited data plan.

That has the advantage of requiring only one phone but would definitely look like you were hiding something. So your approach of a travel phone is better.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#278

Earlier quoted context omitted.

What do you think would happen to a regular person performing such an act? Would it be like Texas Chainsaw Massacre or a James Bond movie?

Huh? I'm asking about the realistic outcome, whether that be denial of border crossing, criminal charges, or they choose to not examine the device and let you through.

now what if you bought the phone off craigslist?

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#279

Lot's of people fantasizing about what they'll do at the border with weaponizing the data on a burner phone. Let me present a "simpler" and actually realistic option (only for US citizens) on how to handle this: 1. Have a reasonable amount of emergency savings (6-8 months of expenses stored). 2. Have someone in-country who isn't traveling with you who can make sure your bills get paid (financial power of attorney). 3…

So you've been asked to unlock your phone, and refused, but were eventually released and allowed to enter? Which country?

Yes, it's happened to me twice, both times crossing from Canada to the US on a land border entry. There was a short period of time where the CBP was doing this in droves on Canada land border entries. The way it's generally structured is they ask permission, and if you refuse, they can't really do anything without a court order and can only hold you at most 72 hours. The time I was held up for 2 days was because they wanted to further inspect my vehicle, which I can't prevent. The only thing you really have any possible way to control is your digital devices, anything physically on your person / in your possession is open to physical inspection at a border entry point and there's no legal means to prevent it, so there's no point in even arguing. Your phone you /must/ relinquish to them, but you can refuse to unlock it if it's locked with a password. The only way to get around it is a court order, which they're not going to bother with if you're not actually suspected of anything.

Of course, YMMV, which is why I say the most important thing is realizing you could absolutely be arrested and charged for something stupid if you refuse, and should have 6-8 months of financial coverage. And of course, any non-citizen can be refused entry arbitrarily with no recourse.

FTA "(CBP) leaders have admitted to lawmakers in a briefing that its officials are adding information to a database from as many as 10,000 devices every year" this is not a rare occurrence, it's rare in the grand scheme of things because there's so many travelers in/out of the US, but it's not really that rare. If you travel internationally often enough, especially at land borders (I don't know why, but these get hassled more in my experience than airports), you will likely eventually get asked.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#280

Terrifying for only 2 reasons: 1. Any malicious person savvy enough to pull off a crime of interest to the Feds is smart enough to provide a wiped or burner phone to DHS/ICE, and they have to know this. So, what is the point in doing this if not to target law abiding citizens. 2. USGOV has a spotty track record of keeping this information secure. A foreign actor is likely to access this info eventually. As one former…

>This is the problem when a non-technical generation makes the rules and regs. If this is the doing of the "luddites" then I'm dreading the dawn of tech sawwy rulers.

It's not just luddites, it's also the knowledge that these rules will never apply to them or their children.
Post reply on HN