Live data from Hacker News

US border forces are seizing Americans' phone data and storing it for 15 years

engadget.com

331–340 of 566 posts

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#331

This (and similar issues) is the main reason that I donate a non-trivial (10%) part of my earnings to ACLU (and 2 other) organization. Our rights and freedoms do not come without struggle. And they sure do not last without somebody constantly defending them. And it’s only bravado to assume that we can stand against the might of federal agents as individuals without dedicated organizations fighting for us. Please dona…

ACLU is a shadow of what it once was. Their unprincipled wavering on free speech ensures that I will not be donating to them. I would, however, love some new recommendations for where those donations can go.

If you are looking for something more right libertarian or conservative-supported, you probably want FIRE.

If you are looking for something more consistently progressive or liberal-supported, you might want to give the EFF a try.

If you specifically care about free speech above all, you're probably right libertarian. It's fine. There's no such thing as centrism in real life politics and an individual's political alignments can vary drastically in different issues rather than line up perfectly with any specific political movement. Especially if you consider yourself apolitical or haven't really reflected on the entirety of your political beliefs and how they interact with each other (most people haven't).

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#332
Did some thinking about this- Here's something no one has every ...thought of it seems-

Right now, from a steganography standpoint, there's no real way to be secure from this sort of thing. US Customs, or another country , from a tech standpoint. Yes, the cloud, though not everyone will have resources to access enough space online to keep their data secure - or be able to properly make a usable copy or image of their device that includes every aspect of their device, for a complete , fully restore later

-Why aren't there more plausible deniable, or just, stealthy encryption options? It appears, there's nearly NONE today for these advanced used cases.

Veracrypt is known for it's hidden features -but those are ...dangerously approaching obsolescence. Their Hidden OS option- ONLY works if you've formatted your system to MBR, not UEFI- otherwise you can't use the Hidden OS option. Are you telling me for every laptop you buy form here on out, you'll format it to the old MBR standard to use the Hidden OS option for your personal laptop that you want to take on a trip- or need to?

And sure, you can just put important data in Hidden Volumes as a fallback- but then you come to a common fight today in the tech world of system vs file level encryption. And sure, just hiding what is most crucial, is perhaps better form a standpoint of sneaking by- but is it truly now impossible to hide everything else that's not as important, by default? Furthermore, you have to wipe traces of the material's location where it was BEFORE you copied it into the hidden volume. Did you also eliminate all traces? Windows Shellbags are a thing, that nearly no one knows will be a smoking gun..

Veracrypt doesn't work on Mac or Linux with it's Hidden OS option, just volumes.

There was a really promising advanced system being built - here, and it was even presented at a blackhat conference i think https://portswigger.net/daily-swig/russian-doll-steganograph...

https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Schaub-Perfectl...

But i've heard nothing since- and right now, all your data will be at risk from your computers ,phones ,and tablets, when you go through Customs- even if it's encrypted, they'll hang on to it, and image and copy the data. If you refuse to provide encryption passwords, they'll potentially keep it and not return it to you in all cases. This is where the deniable systems would come into play- where you'd be okay, if they just unlock it. Now if they plug it in and image it regardless, you're at risk because theoretically they could be running exploits on your device(they won't let you watch them imaging it so you can'tverify that ever)

-encrypted data will be unreadable here, but it's not as good as if they can't tell it's hidden, from a imaging point when they plug in a Cellebrite or Greykey device and have it run it's exploits to get everything.

And i do not see the Forensic Security community often giving recommendations on what it takes to get around this, i think this leads to the public being at the mercy of officials-

This will become very destructive also, as this will become a precedent. Imagine Southern States checking devices like to look for evidence of abortion information-searches, for example. Imagine Abortion getting federally banned, and then customs checking for mentions of abortion .

- Technical solutions aren't a full solution, as the EFF loves to hamper on- but it appears everyone has given up with efforts to even provide them. I suppose if you want to stand a chance, you need to go become a expert on disks, and forensic techniques , in order to then even have a chance at experimenting on how to get around that- and if that sort of privacy ,security, and plausible deniability cannot be brought to the masses at large, the way Signal did for encrypted communications, ...

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#333

Earlier quoted context omitted.

"If it takes them 15 years to realise they shouldn't have let someone over the border it is around 14 to 14.995 years too late." Well, hypothetically some old data could be combined with some new data, to not let a potentially terrorist in NOW (or let them in, but supervised). So more data to have is definitely useful for the agencies (if they can analyse it and do not drown in data). And a total surveillance state w…

I just wish government agencies used data driven decision making vs feelings and intuition more of the time. If there’s data showing a 15 year retention rate is worthwhile. Great. But I have nothing in front of me which states this objectively

if there is data suggesting it, it would be classified. the Government isn't in an equal information relationship with the population, nor can it be, to effectively use intel domestically and abroad.

just a counter-argument. I am not in favor of this obvious overreach. But I don't need data to tell me that.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#334
post #37

Seems like real solution are phones that by default provided end-to-end-encryption for cloud backups, no local data “travel modes”, secure wipes, multiple logins, etc. — since trying to get countries to uniformly play by same rules seem highly unlikely.

Or just a burner with plausible activity stored on it to give the impression that it's your main phone.

Why even bother with plausible activity? Just don't have your real phone with you at all. You can't produce what's not in your possession.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#335

Earlier quoted context omitted.

Ah, so criminals that get busted follow poor practices that lead to them getting busted. Not sure what this has to do with criminals at large, you know, the ones that do stuff like use a safe phone when traveling abroad.

This is unfalsifiable: are you saying that there's some unquantifiable number of perfectly competent criminals? How would we go about verifying that? On an individual level, I am positive that there are criminals that escape the (not particularly competent) techniques of DHS/CBP. But the GP's claim (that Federal criminals are, as a category, completely above and beyond this kind of enforcement) is just not true.

its really not though. Look up estimates of dark net economies. Obviously there is plenty of criminals not getting caught

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#337

As a thought experiment, what would happen if you wrote your own malicious payload to a burner device and handed that over? What if you warned the border agents that your device would deliver malicious code and they plugged it in anyway?

What if you planted a bomb in a package on your doorstep with instructions on it telling people not to open it? What if the package thief stealing your package opens it and causes an explosion injuring themselves and maybe others?

You're describing a (digital) booby trap. Since you're knowingly targeting law enforcement officers, I'm not sure legal theory factors into whether you could get away with it in practice but even theoretically the answer is probably no, that's a computer crime.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#338
post #236

Earlier quoted context omitted.

To add to your point, our laws are so overly broad that it is impossible to exist without breaking some law. (your point talks of 'digital data' my comment refers to real-life) From driving 1mph over the speed limit, to skipping FBI warnings on DVDs, to countless other "innocent" infractions. If they look hard enough they will find SOMETHING. And that's all they need.

For people renting it is routine to receive mail for several previous tenants. Everytime you throw away a credit card sign-up offer for someone else, you are committing a felony.

why is this specific to renting? what about previous owners? and yes I do get stuff for people not here for more that 12 years now, and I toss it, and I dare them to do anything about that.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#339

Earlier quoted context omitted.

No because if it's standard, they will ask you to disable travel mode and download all the data. You can say no, but you can't refuse and cross the border. It's not a technical problem.

> You can say no, but you can't refuse and cross the border. They can't prevent Americans from entering the country.

Article says they can hold onto your electronic devices tho. They can also probably arrest you for the legal maximum (which unlike proper jail probably won't result in you losing your living but could result in you losing money in addition to time).

They don't have to literally prevent you from entering your own country in order to make refusal to cooperate extremely unpleasant for you. Not to mention they can do this every time going forward and they can do this to other people in your group as well. Good luck proving this is harassment and not due dilligence.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#340

Earlier quoted context omitted.

This is unfalsifiable: are you saying that there's some unquantifiable number of perfectly competent criminals? How would we go about verifying that? On an individual level, I am positive that there are criminals that escape the (not particularly competent) techniques of DHS/CBP. But the GP's claim (that Federal criminals are, as a category, completely above and beyond this kind of enforcement) is just not true.

its really not though. Look up estimates of dark net economies. Obviously there is plenty of criminals not getting caught

Of course there are. I said that in the last comment.

There are two points here:

* Estimates of "darknet" economies (and "criminal" economies in general) strongly express preferences for the mostly unfalsifiable LEO hypothesis that there's lots of crime just floating around out there, and they could do so much more about it if we just put up with a little more surveillance, etc.

* There's no particular evidence that there's a bimodal distribution between incompetent criminals who get caught and competent criminals who don't. There are probably lots of competent criminals who don't get caught, but there are also probably lots of incompetent ones who don't (and vice versa). The strongest predictor for successful interdiction (especially at borders) isn't competence, but sheer numbers: criminals have to succeed every time, cops only have to succeed once.

Post reply on HN