Live data from Hacker News

CBP Directive 3340-049B: Border Search of Electronic Devices

cbp.gov

91–100 of 142 posts

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#91

It's wild, I have worked internationally for a long-time and the rule when going to certain countries was bring a burner device. Going to China essentially meant the device was nuked on return to the States, now it is the same feeling to/from the US.

This is cray.

Protections at the U.S. border and within the U.S. are actually pretty good. Much of Europe isn't as good. Hell, the British will throw you in jail for refusing to unlock.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#92
post #87
post #85

Earlier quoted context omitted.

"The exception zone" is a myth.

Tell that to the US Government: https://www.congress.gov/crs-product/R46601

Nobody disputes that border searches are constitutional at the functional equivalents of the border; if you fly in from Canada and land in Tulsa, Tulsa includes a de jure international border.

The dispute (it's not really a dispute, there's a line of SCOTUS precedent explicitly about this question) is whether a 25-100 mile zone extends outwards the airport customs gates. No.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#93

This directive was issued in January of this year, what is relevance of being posted today? I love all the instances where it says, we will not do this or infringe in this way... unless it is a matter of national security, which we don't have to disclose to you. So basically, do what you want as long as you write it up properly. And this part: 5.3 Review and Handling of Passcode-Protected or Encrypted Information 5.3…

I think the context is just mass international travel due to the US hosting the World Cup, no?

co-hosting

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#94

This directive was issued in January of this year, what is relevance of being posted today? I love all the instances where it says, we will not do this or infringe in this way... unless it is a matter of national security, which we don't have to disclose to you. So basically, do what you want as long as you write it up properly. And this part: 5.3 Review and Handling of Passcode-Protected or Encrypted Information 5.3…

I read “may request” and “may be requested” quite literally. They may request it, but it doesn’t say providing it is compulsory.

I have nothing to hide, but still no intention to provide my passcode.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#96
post #42

Earlier quoted context omitted.

For GDPR reasons alone it's probably not a good idea to take a business phone across certain borders. You run the risk of disclosing customer data to a 3rd party, if only because the customer data in your phone book counts as PII. So long as only a few countries are doing this, it might seems doable. If everyone starts doing it, international travel becomes rather annoying to say the least. Realistically I think at s…

>For GDPR reasons alone it's probably not a good idea to take a business phone across certain borders. You run the risk of disclosing customer data to a 3rd party, if only because the customer data in your phone book counts as PII. But "law enforcement" is specifically exempt? https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

Law enforcement refers to EU member states law enforcement and processing by them in their context. But even in the EU controller needs legal basis to disclose personal data to law enforcement inside the EU. Normally that is handled by local law, but it's not carte blanche, that law still needs to take e.g. rights granted by EU Charter in account.

Search by border officers may very well be GDPR breach for that controller if there was data of EU data subjects, but I don't think there is currently any case law around it.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#97

This directive was issued in January of this year, what is relevance of being posted today? I love all the instances where it says, we will not do this or infringe in this way... unless it is a matter of national security, which we don't have to disclose to you. So basically, do what you want as long as you write it up properly. And this part: 5.3 Review and Handling of Passcode-Protected or Encrypted Information 5.3…

They can't compel you to decrypt anything, and powering down is a good idea. There are consequences for not decrypting, though: for a U.S. citizen, they can seize your stuff for up to 5 days. For non-citizens, they can elect to not let you in. Concerning "obligated", I would point out that regulations aren't laws. Governing bodies can say whatever they want, but that doesn't make it so. For instance, the TSA continue…

"For instance, the TSA continues to publicly insist that ID (especially "Real" ID) is required to fly within the U.S., but it's not."

Explain, please, because you seem to be implying that someone can board a plane from New York to LA without being legally required to show any identification.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#98

Earlier quoted context omitted.

The list of countries where you need a burner phone will likely grow longer. Canada, Australia, UK, some developing countries, etc...

Governments maintain formal lists of countries for these types of things. I think people would be surprised how many diverse countries are on the formal lists. A number of European countries have been on them for years.

I would like to be surprised. Can you share a list?

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#99
post #48

Earlier quoted context omitted.

> I had thought (and Supreme Court ruled) you could not be compelled to unlock an encrypted device, which is why I always powered mined down before crossing. Does that apply to non-citizens? If a CBP officer doesn't like you as a non-citizen, like your lack of cooperation during an interview, they could just deny your visa and your entry into the US. If you're a citizen, they can't deny your re-entry. They can delay…

It ONLY applies to citizens. The CBP cannot deny an American citizen entry into the country for any reason. They cannot compel a citizen to unlock their devices. All bets are off for non-citizens, sadly.

They can't prevent you from entering the country. You do not have an unlimited right to bring items into the country with you, though. They can absolutely prevent you from bringing your phone across the border if you decline to unlock it

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#100
This kind of device access also affects others whose private information is shared privately on the device of the traveler.

CBP partly justify the invasion of privacy by citing a supposed reduced expectation of privacy when traveling. But people whose data is caught up on the devices of others are not the ones traveling, but they are still having their messages read and photos copied.

Post reply on HN