Live data from Hacker News

CBP Directive 3340-049B: Border Search of Electronic Devices

cbp.gov

101–110 of 142 posts

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#101

This directive was issued in January of this year, what is relevance of being posted today? I love all the instances where it says, we will not do this or infringe in this way... unless it is a matter of national security, which we don't have to disclose to you. So basically, do what you want as long as you write it up properly. And this part: 5.3 Review and Handling of Passcode-Protected or Encrypted Information 5.3…

I read “may request” and “may be requested” quite literally. They may request it, but it doesn’t say providing it is compulsory. I have nothing to hide, but still no intention to provide my passcode.

If you have any friends or contacts or family who have ever shared any private information with you of any kind (phone number, address, photo, private opinions, etc.) you damn well have something to hide.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#102

Earlier quoted context omitted.

They can't compel you to decrypt anything, and powering down is a good idea. There are consequences for not decrypting, though: for a U.S. citizen, they can seize your stuff for up to 5 days. For non-citizens, they can elect to not let you in. Concerning "obligated", I would point out that regulations aren't laws. Governing bodies can say whatever they want, but that doesn't make it so. For instance, the TSA continue…

"For instance, the TSA continues to publicly insist that ID (especially "Real" ID) is required to fly within the U.S., but it's not." Explain, please, because you seem to be implying that someone can board a plane from New York to LA without being legally required to show any identification.

If you tell the TSA you’re a sovereign citizen for 15 minutes they’re legally required to let you fly.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#103

Earlier quoted context omitted.

I think assuming that the CBP will adhere to the law is based on a pretty outdated mindset. I'd say at least since the current management, but more likely since 9/11...

I'd even call it a delusional mindset. For context, CBP and ICE were both formed in 2003. Jenn Budd has several books on this topic if you want to understand why a growing number of people want to abolish CBP, ICE, and even the entire DHS, which itself was formed only a year prior in 2002. These are very recent organizations in our nation's history, and if we're fine putting things like the Dpt of Education on the ch…

I personally remember that people were calling the DHS a mistake since 2002. I also, as a DC native, was utterly shocked when I first heard "normies" taking DHS seriously as an entity. A friend mentioned DHS was hiring, and I thought to myself ... "wait, but isn't that place bullshit?" Among a certain set of people, it had a bad reputation from day one.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#104
post #99
post #48

Earlier quoted context omitted.

It ONLY applies to citizens. The CBP cannot deny an American citizen entry into the country for any reason. They cannot compel a citizen to unlock their devices. All bets are off for non-citizens, sadly.

They can't prevent you from entering the country. You do not have an unlimited right to bring items into the country with you, though. They can absolutely prevent you from bringing your phone across the border if you decline to unlock it

> They can absolutely prevent you from bringing your phone across the border if you decline to unlock it

Under what grounds?

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#105
post #28
post #17

Earlier quoted context omitted.

They don't work well in my experience. What I want is to get my home screen back exactly as I left it: I've not found anything able to pull it off on Android though. Ideally it would be an exact flash image of the phone.

Adb backup exists, though I haven't tried it, and Google cloud backup does this. However, if you trust Google, you probably already trust the US. Unfortunately, I don't know of any other app that does this on an unrooted phone.

Nothing works on Android. Not even for basic app data. The biggest problem is keystore keys and e.g. bank authenticator apps tied to them.

AFAIK iPhone backups, if restored on the exact same device (i.e. a CPU with the correct decryption key embedded in it) will restore almost everything, including authenticator apps.

The only realistic option for Android is a separate "burner" device.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#106

Earlier quoted context omitted.

> I had thought (and Supreme Court ruled) you could not be compelled to unlock an encrypted device, which is why I always powered mined down before crossing. Does that apply to non-citizens? If a CBP officer doesn't like you as a non-citizen, like your lack of cooperation during an interview, they could just deny your visa and your entry into the US. If you're a citizen, they can't deny your re-entry. They can delay…

> but you get to go home Not always. They must admit you, but they can arrest you one second later

They still need to charge you with something. If they can't, they can't hold you.

Yes, I know, they can theoretically do whatever they want, but realistically it would take the most spiteful of spiteful agents to arrest you without cause (just because you refused to unlock your device). Just the act of doing this would create a lot of extra work and paperwork for the agent that most of them are not going to want to deal with. Plus, asserting your rights is a sign to them that you aren't a pushover and aren't going to get trampled on easily. The bullies prefer easier targets, usually.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#107

Earlier quoted context omitted.

They can't compel you to decrypt anything, and powering down is a good idea. There are consequences for not decrypting, though: for a U.S. citizen, they can seize your stuff for up to 5 days. For non-citizens, they can elect to not let you in. Concerning "obligated", I would point out that regulations aren't laws. Governing bodies can say whatever they want, but that doesn't make it so. For instance, the TSA continue…

"For instance, the TSA continues to publicly insist that ID (especially "Real" ID) is required to fly within the U.S., but it's not." Explain, please, because you seem to be implying that someone can board a plane from New York to LA without being legally required to show any identification.

I lost my ID once around 15 years ago and was able to board my return flight just fine. I had to get to the airport early because I -- correctly -- expected a longer, personalized security check, but I was on my flight on time, as expected.

Yes, things have changed in that time with regard to the zealousness of the TSA, but the laws and regulations behind them have not.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#108
post #25

Earlier quoted context omitted.

We have? My international relatives have never been searched to that degree, if at all. That said, the whole thing is overreach in any democratic society.

I've binge watched enough Australian Border Patrol videos to know that: 1. You don't fuck around with Australian customs agents. Ever. 2. They make every other country look like complete lightweights, Americans and EU included. These guys will fine you AU $500 for half an eaten apple in your bag.

> These guys will fine you AU $500 for half an eaten apple in your bag.

That seems entirely appropriate, no? Produce crossing international borders like that can be a huge problem.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#109
post #50

It's wild, I have worked internationally for a long-time and the rule when going to certain countries was bring a burner device. Going to China essentially meant the device was nuked on return to the States, now it is the same feeling to/from the US.

Had the same guidance for many years for visiting the US given by the large US firm that employed me

I heard that soon after the extent of NSA's domestic surveillance programs were revealed to the public, at least one FAANG changed its US border-crossing policy to those used for countries known to tamper with your computers during border crossings. That is, bring a blank computer that you connect to the corporate VPN and load after you arrive at work on the far side of your trip, let IT wipe that computer before you travel back to the US (or just leave it behind), and assume that computer is compromised if it leaves your sight at a checkpoint for longer than it takes to run it through the x-ray scanner.

So, yeah, savvy companies have had these policies for like twenty years now.

Re: CBP Directive 3340-049B: Border Search of Electronic Devices

#110
post #18

It's wild, I have worked internationally for a long-time and the rule when going to certain countries was bring a burner device. Going to China essentially meant the device was nuked on return to the States, now it is the same feeling to/from the US.

China installs malware to spy on you. The US doesn't do this. Totally different situation. This also happens in many other countries

Malware seems somewhat implausible. Why would they bother, when they have access to the carrier logs? Knowing your exact location at all times, and who you communicate isn't enough?
Post reply on HN