Live data from Hacker News

Another Hacker’s Laptop, Cell Phones Searched at Border

wired.com

11–20 of 89 posts

Re: Another Hacker’s Laptop, Cell Phones Searched at Border

#11
post #9

Let me get this straight. This is a person who has openly admitted to knowing how to hack banking systems among others, then travels to countries like Abu Dhabi and the Dominican Republic to present that information. We are surprised that he is searched at the border to the US? He was treated politely, not physically harmed and had his hardware returned. Sounds like the government is finally doing their job. Maybe th…

I think it would have been less of a problem if they had allowed him to be present while they were searching his hardware.

Re: Another Hacker’s Laptop, Cell Phones Searched at Border

#12
slightly relevant:

To protect his privacy and that of his clients, Mitnick encrypts all the confidential data on his laptops, transmits it over the Internet for storage on servers in the U.S., and wipes it from the computer before returning from any international trips, just in case officials decide to search or seize his equipment. He also encrypts his hard drive. And now, he says he is going to keep a "clone" of his MacBook at home so he will have an exact duplicate of it if it is ever seized.

http://news.cnet.com/8301-1009_3-10054569-83.html

Re: Another Hacker’s Laptop, Cell Phones Searched at Border

#13

If I were him, I'd be tempted to make an image of his drive, and compare that to an image made after the agents tampered with it, to see what changes occurred in the process. But like he said, he couldn't even trust them physically. I'd be tempted to just toss them in the trash, if I could afford to easily replace them.

I'd just start FedEx'ing things and just take a book... Perhaps travel with just a SIM card and pickup a new phone when I landed.

That's about the only thing you could really start to do.

Re: Another Hacker’s Laptop, Cell Phones Searched at Border

#14
post #8

Border search exception (to the 4th amendment warrant requirement): http://en.wikipedia.org/wiki/Border_search_exception In a similar vein, check out Exigent Circumstance: http://en.wikipedia.org/wiki/Exigent_circumstances The text of the fourth amendment to the constitution: "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be v…

The government has decided that the "border" extends 100 miles inland from official land/sea borders. This apparently covers 2/3rds to 4/5ths of the U.S. population.

Coverage on the 100-mile-thick ACLU-dubbed "Constitution-Free Zone":

Wired: http://www.wired.com/threatlevel/2008/10/aclu-assails-10/

Ars Technica: http://arstechnica.com/security/news/2008/10/aclu-23-of-us-p...

(Note the entire land area of the Hawaiian islands are covered, as is the entire state of Florida.)

I think it's probably even worse than that, though, because International airports count as "borders" no matter how far inland. So I would not be surprised to see this extended to a 100-mile radius of all international airports as well, which would cover almost everybody.

Re: Another Hacker’s Laptop, Cell Phones Searched at Border

#15
post #5

That's completely ridiculous. Makes me want to travel even less now ...

"The Fourth Amendment to the Constitution contains a border-related exception to unreasonable search and seizure laws, permitting searches at border checkpoints that wouldn't be permitted elsewhere. But federal statute 8 CFR 287.1 (a)(1-3) defines the border zone for enforcement purposes as encompassing an area within 100 miles of the actual border, with the possibility of extending it further under certain circumstances. This means that the US Border Patrol could conceivably set up random checkpoints asking travelers for a passport in places like Columbus, Ohio; Houston; or anywhere in the state of Florida. And, in fact, it appears that it has been doing exactly this."

http://arstechnica.com/security/news/2008/10/aclu-23-of-us-p...

Re: Another Hacker’s Laptop, Cell Phones Searched at Border

#16

If I were him, I'd be tempted to make an image of his drive, and compare that to an image made after the agents tampered with it, to see what changes occurred in the process. But like he said, he couldn't even trust them physically. I'd be tempted to just toss them in the trash, if I could afford to easily replace them.

I'd rather consider using truecrypt and do plausible deniability, and own hardware I don't have to get too emotional about keeping.

Sure, but the OS itself still has to be unencrypted, or at least the boot sector, right? Can't trust that, either, right?

Re: Another Hacker’s Laptop, Cell Phones Searched at Border

#17

Earlier quoted context omitted.

I'd rather consider using truecrypt and do plausible deniability, and own hardware I don't have to get too emotional about keeping.

Sure, but the OS itself still has to be unencrypted, or at least the boot sector, right? Can't trust that, either, right?

Yes, some code has to be unencrypted to use the passphrase to decrypt the rest of the disk. People who are serious about security will boot off a known-good USB drive or CD.

Re: Another Hacker’s Laptop, Cell Phones Searched at Border

#18
I wish this unconstitutional and overly broad border search policy would be cancelled.

Besides the chilling effect on the broader American surveillance society, it's also not very useful, and is even dangerous to national security. Only dumb criminals and people of interest are going to actually keep real data on their computing devices when crossing the US border. The smart ones will use any of the innumerable, trivial counter measures.

Border searches like this also opens the US up to a counter-intel attack. There's nothing to stop foreign agents from planting fake intel they want intercepted at the border, then watching what the watchers do with it, and thereby inferring how the US knows what they know.

I wouldn't worry about any kind of hyperbolic, sci-fi eavesdropping bugs being installed surreptitiously on personal hardware. The chances of their bugs being found, reversed engineered, and then used against them is too great of a risk for the US to regularly bug traveller's computers.

So almost all of this Constitutionally questionable seized data is useless, and not even worth collecting at the border. Besides, there are far more efficient and precise means of getting the data of targeted people than using airports for dragnets.

Ultimately the government's policy is just more ineffective security theater pandering to the terrorism hysteria and the defense industry profits. It's a total waste of our tax budget, needless harassment of citizens of the world, and it helps the growing culture of xenophobia in America more than it helps actual law enforcement.

Re: Another Hacker’s Laptop, Cell Phones Searched at Border

#19
Interestingly, I just had a discussion with my roomate about this. We were sitting in a coffee shop, and he was mad at himself because he forgot the latest copy of a game he is working on at the house...

Why is this a problem at all anymore? Hosting is cheaap. I have a linux VPS at linode that I pay $20/mo for and almost everything that i do is stored there. Honestly, the only things I can think of that aren't stored on that machine (which trades nightly rsyncs with another machine with a different provider and on a different network) are minecraft, my music collection, some photos, and a journal that I just started keeping a couple of weeks ago (gets encrypted with 256bit AES and lives in the home dir on my laptop).

My point is that there is absolutely no reason to keep anything on your local machine anymore, at least not ones that I can think of. Why not keep a server in the basement, and then just run SSH with X11 forwarding? Keep a cheap, disposable machine with you and if something like this happens, sell it and buy a new one.

It's really sad that this is even an issue, but I do think that there are solutions to it.

Re: Another Hacker’s Laptop, Cell Phones Searched at Border

#20
post #19

Interestingly, I just had a discussion with my roomate about this. We were sitting in a coffee shop, and he was mad at himself because he forgot the latest copy of a game he is working on at the house... Why is this a problem at all anymore? Hosting is cheaap . I have a linux VPS at linode that I pay $20/mo for and almost everything that i do is stored there. Honestly, the only things I can think of that aren't store…

Do you do your work on that linode directly (via ssh), or do you just use it for syncing?
Post reply on HN