Live data from Hacker News

Documents Shed Light on Border Laptop Searches

aclu.org

21–30 of 59 posts

Re: Documents Shed Light on Border Laptop Searches

#21

They say that there were ~5000 such searches per year, which makes them extremely rare occurrences given the hundreds of millions of people crossing the borders in a year.

Next year, there'll be 7,000, and the year after that, 10,000, etc.

Re: Documents Shed Light on Border Laptop Searches

#22
post #10

Earlier quoted context omitted.

"I don't remember my password."

It's illegal not to provide your password in the UK, not sure what the rules are under these special powers in the US.

IIRC the 5th amendment allows you to not divulge your password, unless they can prove that there is illegal content .

Re: Documents Shed Light on Border Laptop Searches

#23
post #13
post #7

Earlier quoted context omitted.

Or make sure that they have full-disk encryption and are cold shutdown when you cross the border. While jurisprudence is still a bit fuzzy on this (it has flipped back and forth on a few appeals in a few separate cases, and never been conclusively decided by the Supreme Court), there have been ruling upholding the fact that you can't be forced to hand over your password due to the fifth amendment, unless the Governme…

Even with full-disk encryption, an image will be made of the drive, and the government will keep a copy on the chance that the password will be revealed later. Or the algorithm gets broken/weak enough at some point in the future.

Silly question.

Let's assume you have a device like a Macbook Pro or a Macbook Air, where you can't physically remove the drive without ungluing the device. You hotrod the firmware so only trusted USB devices with a specific encryption key are permitted to connect. How would the drive be imaged?

Re: Documents Shed Light on Border Laptop Searches

#24
post #7

Earlier quoted context omitted.

Or make sure that they have full-disk encryption and are cold shutdown when you cross the border. While jurisprudence is still a bit fuzzy on this (it has flipped back and forth on a few appeals in a few separate cases, and never been conclusively decided by the Supreme Court), there have been ruling upholding the fact that you can't be forced to hand over your password due to the fifth amendment, unless the Governme…

After the past week's NSA revelations, just what full disk encryption system should we be trusting? I think it's fair to assume that any commercial implementation is compromised.

I FDE (on macs, FileVault 2 is by far the easiest, even though Apple is one of the more likely backdoor providers), but I also don't keep anything sensitive on it.

If seized at the airport, it provides a useful bit of information on whether they can break filevault 2. It seems implausible they would even if they could without a "plausible non-cryptographic alternative".

Re: Documents Shed Light on Border Laptop Searches

#25

They say that there were ~5000 such searches per year, which makes them extremely rare occurrences given the hundreds of millions of people crossing the borders in a year.

Yes, but they are targeting individual US citizens and using the broad authority that has been granted to them "to evade the constitution," as the article states. Ostensibly, this authority was granted in order to protect our borders.

Re: Documents Shed Light on Border Laptop Searches

#26
The fact such an article has to be written at all is highly concerning. What kind of free society are we living in when we have to guard heavily against our devices being confiscated and snooped through just because a border agent feels like it? To my knowledge there's only precedent of this happening in the UK and US, but I wouldn't be surprised if other countries are going to join in on these shenanigans.

Re: Documents Shed Light on Border Laptop Searches

#28

Is the best strategy here to leave your devices at home and just bring a burner phone on holiday or other travels and no other devices? It's strange as an ordinary citizen who might choose to contribute to someone like Manning's defence fund, or post statements supportive of Snowden online, to have to consider that GCHQ or the Homeland Security might put your name on a list for questioning and confiscation at the bor…

Carrying a burner is itself also suspicious -- the safest course it to be as normal as possible which means having a regular computer/phone with some stuff on it, or nothing. Also, it isn't sufficient to focus the the border policies for re-entry to your own country, you also have to consider every country you would travel to, all of which have their own laws, all of which can change at any moment, even while you are…

It's not a "burner" phone, it's an "international quad band unlocked" phone for local sims.

Re: Documents Shed Light on Border Laptop Searches

#29
post #7

Earlier quoted context omitted.

Or make sure that they have full-disk encryption and are cold shutdown when you cross the border. While jurisprudence is still a bit fuzzy on this (it has flipped back and forth on a few appeals in a few separate cases, and never been conclusively decided by the Supreme Court), there have been ruling upholding the fact that you can't be forced to hand over your password due to the fifth amendment, unless the Governme…

After the past week's NSA revelations, just what full disk encryption system should we be trusting? I think it's fair to assume that any commercial implementation is compromised.

[TrueCrypt](http://www.truecrypt.org/) or [dm-crypt](https://en.wikipedia.org/wiki/Dm-crypt) are both open source (technically, TrueCrypt has source available but doesn't meet the definition of an open-source license, though there's some debate on that point), and thus publicly auditable.

Also, I'm less worried about FDE being vulnerable to Border Patrol than about, say, SSL vulnerabilities across the whole network. The plausible deniability, which they would need to use to protect their sources if they found information, is a lot lower if you know you have been stopped and your laptop searched, rather than just tapping all internet traffic so you don't even know when you've been searched. Mac OS X's File Vault 2 and Windows's BitLocker are probably sufficient if if you aren't particularly paranoid about being individually targeted for something big, but I would be more inclined to trust the open solutions.

Re: Documents Shed Light on Border Laptop Searches

#30
post #13

Earlier quoted context omitted.

Even with full-disk encryption, an image will be made of the drive, and the government will keep a copy on the chance that the password will be revealed later. Or the algorithm gets broken/weak enough at some point in the future.

Silly question. Let's assume you have a device like a Macbook Pro or a Macbook Air, where you can't physically remove the drive without ungluing the device. You hotrod the firmware so only trusted USB devices with a specific encryption key are permitted to connect. How would the drive be imaged?

Thunderbolt target disk mode: http://support.apple.com/kb/PH3838

Perhaps you could solve this by "hotrodding" the firmware, but it's not particularly obvious how you could do that without risking bricking your laptop.

Post reply on HN