Live data from Hacker News

US border forces are seizing Americans' phone data and storing it for 15 years

engadget.com

471–480 of 566 posts

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#471
post #220

Earlier quoted context omitted.

Although grandparent's logic is faulty, I think it does go to an important point. They don't need 15 years warrantless storage of phone data. On anyone, including foreigners. If it takes them 15 years to realise they shouldn't have let someone over the border it is around 14 to 14.995 years too late. The powers these agencies have is far in excesses of what they need to do their jobs, and it is going to be abused. Th…

It's called security theatre. And 15 years is corruption driven, because now you are spending X millions. of taxpayer money to store this data.

There are a few reasons why government would want to keep data for that long. Educated guess: playing the odds that currently encrypted data could be broken in the near future.

My primary argument isn’t security theater, although I do agree it applies. My argument is that no democracy / republic should assume that every resident/citizen is a potential criminal without some probable cause / particularized suspicion/ significant evidence. The larger the percentage of citizens who experience unjustified searches, the lower the institutional trust level falls. Eventually citizens stop trusting elections, courts, police, etc. then people start massive social panics on the assumption that everything government is corrupt.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#472

Earlier quoted context omitted.

My work-based 2FA is tied to my phone and is non-transferrable. If I lost my main phone without switching the 2FA install while logged in, I'd have to go through a recovery process. Culprits: RSA Authenticate and Okta Verify. My personal accounts that have 2FA are all backed up with Authy.

>My work-based 2FA is tied to my phone and is non-transferrable. If that's the case with your workplace, do they issue you a phone to use for work-related stuff. If not, why not? Your personal device shouldn't be required to do work-related stuff, IMHO. I'd add that since there's work-related stuff on your phone, your employer can restrict what you do/don't do with that phone and subject your personal device to its c…

I don't have MDM on my phone (no alt-roots or anything). "Just" the 2FA, gmail and Slack. But I agree, I'm tempted to get the work stuff off and onto an old phone just to have the mental separation.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#473
post #465

Earlier quoted context omitted.

Why the hell would anybody sane, especially with all knowledge average HN user has about government overreach and greed, hacks, 0days, bugs etc. ever put such a critical item as banking app on their phone? Apple vs Android is irrelevant in this, there is no truly safe mainstream phone in 2022, period. Are people really that lazy? I do manage quite a few financial things but for none of those phone apps is crucial and…

>ever put such a critical item as banking app on their phone? Because my PC isn't meaningfully more secure. Because in the overwhelming majority of situations, if that security is compromised, my bank will eventually cough up my money. Also because I also expect neither Google, Apple, my carrier, nor the dab gum gubment is likely to rob me by... * checks notes * Compromising the banking app on my phone. Or my PC. Or…

As someone who works very prominently in mobile device security, and had to long ago come to the realization that I actually KNEW the people who could manage to hack into my phones... I agree with your answer 100%. The threat analysis here leading to only using Firefox on your desktop computer to access your bank makes absolutely no sense to me and--to inject some conspiracy theory back into this (for shits and giggles)--almost feels like "what the enemy wants you to do" ;P.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#474

Earlier quoted context omitted.

Nigerian here. At some point it gets old and you just get used to it.

A Nigerian and a Florida Man walk into a bar. They order drinks and nachos and have a reasonable conversation that concludes in a legitimate business deal.

That's a nice one - would love to see that play more often IRL.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#475
post #456

Earlier quoted context omitted.

Believing government acts on your behalf reeks of 'very high privilege.' If you think shop-keeps won't protect their stores once the chains of SF/Cali government come off, I have a bridge to sell you. Edit: thank you for spelling correction. Wreaks changed to reeks

Of course the shop-keeps will attmpt to protect their stores. That is completely beside the point. The point is that without a democratic government that is at least attempting to self-govern, the alternative is either a new autocracy comes in (see Russia, CCP, Venezuela, Myanmar, etc.), or it starts with anarchy, and quickly falls to the first crimelord/warlord. Every one of those options is far worse than a flawed…

What is your test to determine whether a nation has reached the level of "flawed democracy?"

Is the US one?

I mean even anarchism could be considered 'flawed democracy.' The power is theoretically at the individual level, with the population of each government split down to a democracy of size '1' and the individual voting how to dictate his/her own life, although of course even that is flawed.

Then again, if you frame it as "flawed democracy" vs "everything worse than that" then almost by definition flawed democracy is going to win...

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#476
post #408

Earlier quoted context omitted.

> Even if you are a person who will never in your life end up as any kind of person of interest for the government Literally no way to ensure that.

The chances of becoming a person of interest will always be non-zero, but I think I a lot of people can be reasonably confident that they are not likely to become a person of interest.

Given that 0.5—1% of the US population is incarcerated[1], and that getting a prison sentence is far from the only way to become a person of interest, it is quite reasonable to say that chances of getting some unwanted attention from various government and government-adjacent institutions are too damn high to ignore it.

[1] https://www.prisonpolicy.org/blog/2020/01/16/percent-incarce...

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#477

Earlier quoted context omitted.

>My work-based 2FA is tied to my phone and is non-transferrable. If that's the case with your workplace, do they issue you a phone to use for work-related stuff. If not, why not? Your personal device shouldn't be required to do work-related stuff, IMHO. I'd add that since there's work-related stuff on your phone, your employer can restrict what you do/don't do with that phone and subject your personal device to its c…

I don't have MDM on my phone (no alt-roots or anything). "Just" the 2FA, gmail and Slack. But I agree, I'm tempted to get the work stuff off and onto an old phone just to have the mental separation.

>I don't have MDM on my phone (no alt-roots or anything). "Just" the 2FA, gmail and Slack. But I agree, I'm tempted to get the work stuff off and onto an old phone just to have the mental separation.

Gotcha. I encourage you to do so. I'd further encourage you (if this isn't the case already) to have your employer pay all costs associated with that other device. As it's their requirements that put you in this situation.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#478
post #175

Earlier quoted context omitted.

Let me know how successful you are crossing the border and getting home when you tell CBP to “pound sand”. They’ll just deny you entry and you’re left with very little recourse. Effectively they are the judge and jury and you’re stuck in the waiting area if you’re lucky, a holding cell if you’re not If you think you’re immune just because you’re a US citizen, you’re not.

This is false. A friend came back to the US after 3 years. A time period you typically lose your green card. However friend was smart to ask a lawyer and the lawyer said “agree to nothing, sign nothing, only a judge can take your green card”. So she did just that. Put up with about an hour of shit. “No, im not signing anything”, “No, I don’t agree that I’m no longer a permanent resident of the US”. Was eventually let…

I'm shocked it went that well for her. I've had agents simply lie on their report, including lying to (and waking up) a federal judge and US assistant attorney in the search warrant DHS got for me. Also had them lie to me and tell me I wasn't permitted to enter the US with my US passport.

I'm quite certain if she had dealt with some of the agents I dealt with they simply would have lied or signed the form for her and kicked her out of the country. If they would have simply taken the green card from her and said "good fuckin luck" it would have been a hell of a road getting it back after being gone 3 years. Either way good on her for calling the bluff.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#480

Earlier quoted context omitted.

> ever put such a critical item as banking app on their phone? Laziness has nothing to do with it. Why? Three of my bank accounts cannot be accessed without a phone app, and some of my credit cards will not authorise payments without a phone app. It's not a choice. Two of the bank accounts do have web banking too, i.e. from a desktop browser. But you have to use the phone app to authenticate the browser login! I foun…

Some banks certainly don't help themselves when it comes to security practises they foist on their customers. My bank supports 2FA, but only via SMS...

My bank sent me a little fob that generates a one time code. Of course, they will also use SMS, the app on your phone, or email for 2FA. They are all considered equally valid and there is no intermediate step should you wish to use one over the other at any time.

So really the fob is theater.

Post reply on HN