Live data from Hacker News

Documents Shed Light on Border Laptop Searches

aclu.org

41–50 of 59 posts

Re: Documents Shed Light on Border Laptop Searches

#41
post #10

Earlier quoted context omitted.

"I don't remember my password."

It's illegal not to provide your password in the UK, not sure what the rules are under these special powers in the US.

Then change your password to something that you don't actually know.

Generate a random password before your trip and print out a few copies. Take one with you and secure the remaining ones. Before you fly through the UK, change the password on your computer to the random one and destroy the printout. When you get back home use the remaining printouts to change your password back and then destroy them.

Re: Documents Shed Light on Border Laptop Searches

#42
post #40

Earlier quoted context omitted.

Look into Hidden Volume technology. Then you can give them the "password" and they can look around all they want.

I have. However, my fear is that it will either not work when it's needed, or that they may have some manner of technology that allows them to scan for such things, or possibly the footprints left behind by such software, or logging them into an OS that looks like a fresh install might be enough to illicit some suspicion. Politely declining to share your password is within your rights at the US border. However, givin…

You aren't giving them a "fake" password, you're just not giving them all of your passwords.

Re: Documents Shed Light on Border Laptop Searches

#43
post #41

Earlier quoted context omitted.

It's illegal not to provide your password in the UK, not sure what the rules are under these special powers in the US.

Then change your password to something that you don't actually know. Generate a random password before your trip and print out a few copies. Take one with you and secure the remaining ones. Before you fly through the UK, change the password on your computer to the random one and destroy the printout. When you get back home use the remaining printouts to change your password back and then destroy them.

At this point, why are you even bringing your computer along, if you have no way to log into it?

Re: Documents Shed Light on Border Laptop Searches

#44
post #41

Earlier quoted context omitted.

It's illegal not to provide your password in the UK, not sure what the rules are under these special powers in the US.

Then change your password to something that you don't actually know. Generate a random password before your trip and print out a few copies. Take one with you and secure the remaining ones. Before you fly through the UK, change the password on your computer to the random one and destroy the printout. When you get back home use the remaining printouts to change your password back and then destroy them.

These sorts of techniques make great comments, but are nearly useless in reality.

First of all, even if you're being truthful, saying "I don't know my password" will likely not be believed. Explaining the process you went through to safeguard your password will merely elicit suspicion by a border agent. Why would you go through such pains if you had nothing to hide? And once they are suspicious of you, you will almost surely be detained and have your equipment seized.

Yes, the government might not be able to decrypt it for years, but they still have your laptop, and they are still in possession of your data, encrypted as it may be. So, I ask you, who won this little battle? It sure wasn't you.

IMHO, the only valid approach here is to host everything on an external server, and VPN / SSH into it to do your work. Don't store the connection info locally, and don't store any passwords / keys locally. Make sure no confidential files ever touch your hard drive, even in a cache. Most agents have no idea how that process works, and unless you have a shortcut on your desktop / home directory labeled "connect to home fileserver" they probably won't even think to ask you for any further info.

EDIT: Stupid spelling error. Thanks, recursive.

Re: Documents Shed Light on Border Laptop Searches

#45
post #41

Earlier quoted context omitted.

It's illegal not to provide your password in the UK, not sure what the rules are under these special powers in the US.

Then change your password to something that you don't actually know. Generate a random password before your trip and print out a few copies. Take one with you and secure the remaining ones. Before you fly through the UK, change the password on your computer to the random one and destroy the printout. When you get back home use the remaining printouts to change your password back and then destroy them.

I haven't studied this law in detail, but it expect it is worded to avoid precisely this sort of manoeuvre, because the implication is quite clear - you have no right to privacy. If necessary they'd just confiscate your device and detain you on suspicion of perverting the course of justice etc, etc. they can hold you for 3 months for refusing to answer any questions they ask, including questions on your encryption scheme and how they can defeat it. They can also image all your hardware for future decryption, compromise it before returning it, etc.

I think the safer solution is not to travel with hardware you intend to use again.

Re: Documents Shed Light on Border Laptop Searches

#46
post #44
post #41

Earlier quoted context omitted.

Then change your password to something that you don't actually know. Generate a random password before your trip and print out a few copies. Take one with you and secure the remaining ones. Before you fly through the UK, change the password on your computer to the random one and destroy the printout. When you get back home use the remaining printouts to change your password back and then destroy them.

These sorts of techniques make great comments, but are nearly useless in reality. First of all, even if you're being truthful, saying "I don't know my password" will likely not be believed. Explaining the process you went through to safeguard your password will merely elicit suspicion by a border agent. Why would you go through such pains if you had nothing to hide? And once they are suspicious of you, you will almos…

> Why would you go through such pains if you had nothing to hide?

Why would you not want a camera in your bathroom, if you have nothing to hide?

Re: Documents Shed Light on Border Laptop Searches

#47
post #42
post #40

Earlier quoted context omitted.

I have. However, my fear is that it will either not work when it's needed, or that they may have some manner of technology that allows them to scan for such things, or possibly the footprints left behind by such software, or logging them into an OS that looks like a fresh install might be enough to illicit some suspicion. Politely declining to share your password is within your rights at the US border. However, givin…

You aren't giving them a "fake" password, you're just not giving them all of your passwords.

The point is you might still be considered to be interfering with the investigation, should they find out.

Everything I've ever read about topic stresses that you should be absolutely truthful with a border officer. At least in the US, lying to one is a serious offense. Your post encourages hiding behind semantics and technicalities- and while those might save you in a courtroom (if you have a good lawyer), they won't save you when you're face to face with an angry border agent who just discovered your ruse.

Again, this is why I don't use this method. It didn't work on my parents when I was a kid, and I don't think it will work in this case either.

Re: Documents Shed Light on Border Laptop Searches

#48
post #40

Earlier quoted context omitted.

Look into Hidden Volume technology. Then you can give them the "password" and they can look around all they want.

I have. However, my fear is that it will either not work when it's needed, or that they may have some manner of technology that allows them to scan for such things, or possibly the footprints left behind by such software, or logging them into an OS that looks like a fresh install might be enough to illicit some suspicion. Politely declining to share your password is within your rights at the US border. However, givin…

I understand- the software behind hidden volumes is relatively new. I think this is an area the open source/security community should really put some effort behind.

It is recommended that you use the regular non-hidden volume OS for trivial tasks frequently to make it a normal OS. If you do this, you are giving them your password. You just use a differnet password and a hidden volume for all of your private stuff.

Leaving it behind works as well, if that is acceptable to you! And is probably the most secure thing. :)

Re: Documents Shed Light on Border Laptop Searches

#49
post #44

Earlier quoted context omitted.

These sorts of techniques make great comments, but are nearly useless in reality. First of all, even if you're being truthful, saying "I don't know my password" will likely not be believed. Explaining the process you went through to safeguard your password will merely elicit suspicion by a border agent. Why would you go through such pains if you had nothing to hide? And once they are suspicious of you, you will almos…

> Why would you go through such pains if you had nothing to hide? Why would you not want a camera in your bathroom, if you have nothing to hide?

Please note that I personally hate the phrase "if you have nothing to hide, you have nothing to fear." I was using it in this case because many people still operate like that and because, for better or worse, I assume all 'police type' people fall into this category.

I merely figured the HN community would pick up on the sarcasm.

So please do not patronize me.

Re: Documents Shed Light on Border Laptop Searches

#50
post #41

Earlier quoted context omitted.

Then change your password to something that you don't actually know. Generate a random password before your trip and print out a few copies. Take one with you and secure the remaining ones. Before you fly through the UK, change the password on your computer to the random one and destroy the printout. When you get back home use the remaining printouts to change your password back and then destroy them.

At this point, why are you even bringing your computer along, if you have no way to log into it?

This obviously depends on your travel plans. For the US, for example, CBP can only search your belongings on entry into the US. If you are traveling from the US -> wherever -> US then you only need to secure your laptop for your return flight.
Post reply on HN