Live data from Hacker News

Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

cbc.ca

291–300 of 483 posts

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#291
post #9

>Wright refused, telling the officer both devices contained confidential information protected by solicitor-client privilege. >He said the officer then confiscated his phone and laptop, and told him the items would be sent to a government lab which would try to crack his passwords and search his files. Can this be used to get whatever case(es) he was defending thrown out because solicitor-client privilege was violate…

>> Can this be used to get whatever case(es) he was defending thrown out because solicitor-client privilege was violated or parallel construction was used? That isn't what this is about. Nobody is talking about what this is really about and it isn't anything to do with him being a lawyer. This guy (1) was traveling alone (2) to a distant (3) and poor (4) country without preexisting business ties (5). Those are all re…

> other less-pubic successes

Freudian slip right there if I've ever seen one

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#292

Earlier quoted context omitted.

Fictional child pornography does not directly harm children, but it is likely that it does so indirectly by creating demand for actual CP. To me, it seems totally reasonable to make all sexualized depictions of children illegal for this reason.

>but it is likely that it does so indirectly by creating demand for actual CP Until there is evidence of that, it seems strange to say that's a conclusion at all, or that it's likely. In fact, Patrick Galbraith's work on how users of fictional CP actually interact with their materials suggests exactly the opposite: they have developed a form of sexuality for the representations themselves - the more fictional, the mo…

Perhaps what you suggest is true. I don't pretend that I have done tons of research on this; I only say that it is not inconceivable to me that fictional CP increases demand for real CP.

> do we apply this standard elsewhere in society?

If there is a demonstrable link between them, sure. The same way real CP is illegal because it creates demand, which causes more CP to be made. Remember, owning CP does not directly harm anyone.

> If there were no research on the link between video games and violence, would you conclude that it is "likely" it indirectly creates a demand for videos of real violence?

No, because video games and videos are completely different things. People who play violent video games don't do it because they like watching violence, they do it because they like playing video games.

> isn't punishing someone for something they might do (access real CP) unjust?

They're not being punished for something they might do, but that they did do. If fictional CP is illegal and someone is in possession of it, then they've committed a crime.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#294

Earlier quoted context omitted.

Not a great idea. You have no reason to believe deleted and cached copies aren’t lingering on you disk unprotected.

Can't you just use a tool like 'shred' to securely delete the file(s) ?

My understanding is that shred hasn't been reliable for many years now due to smarter and less predictable firmware in modern storage devices. Basically, you can't trust that your SSD deleted the data it said it did, or that it writes data to the place you told it.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#295
post #228

Earlier quoted context omitted.

For work data such as the lawyer in the article I would recommend go one step further and not having the password in the first place. You can achieve this by for example having the server admin at work remotely unlock the device at request, have hardware tokens at trusted locations, or software that provide similar effect. No amount of $5 wrench or legal threats can change the situation as it not in your hand to give…

Like, leave a private key at home and encrypt your drive with the public key before crossing the border? Yeah, at that point you are powerless to do anything until you are at home.

But what's the difference? The end result is the same: your device(s) are confiscated and they attempt to brute force the password. Telling an officer that you cannot give them the password because you did some techno-mumbo-jumbo is just going to piss them off and make them assume you have "something to hide" because "no honest person would go to those lengths".

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#296
I'm planning a trip overseas sometime in the future, and I'm sorely tempted to write up some malware that will activate if someone attempts to download my hard drive in the wrong way. I'll provide the password, along with a statement that I'm not authorizing a search of the drive, and if they want to break the law they are doing so at their own expense. Any lawyers know if I would still be liable for the outcome?

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#297
post #99

I have asked this question before, but never really got a satisfiable answer: why do governments (not just USA/canada) spend these resources to check data physically at a border? It's not like you need to 'smuggle' any form of data physically. I mean, any data considered to be dangerous (like terrorist attack plans, atomic bomb designs or political inside information) can be accessed across borders via the internet.…

This might partially answer your question... I had my laptop searched at the border once. It was my work laptop. They told me the same thing, if I didn't share the password they would confiscate my computer. It felt wrong that they should be able to search my computer, but I also felt bullied because I was going to need my computer the next day if I wanted to work and I think most people, including my boss at the tim…

When I was working for $Big$Corp, I was explicitly instructed to 1) always shut down the devices with full-disk encryption 2) never give up passwords 3) surrender devices without opposition or bargaining (cooperate) and 4) call company lawyers as soon as possible

Never have faced any search, but interesting stance there.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#298

I've always preferred having a dedicated desktop that acts as a personal server and then a small cheap laptop that I use to remotely access it. While this preference is mostly driven by capitalizing on the performance/price/size difference between desktops and laptops, it has lots of advantages when it comes to these situations. My Dell XPS 13 only has 128GB of storage so none of the data exists solely on that device…

>traveling to countries with weak or no privacy laws.

Like Canada?

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#299

Earlier quoted context omitted.

Canada is successful 38% of the time when checking electronics. Common scenarios are seeing text messages showing someone has accepted a new job and will be working while on a visa waiver/tourist stay, or planning to get married while on a work visa.

However, in this case, they're checking the electronics of a Canadian citizen who has every right to be in the country.

But they don't stop people coming into the country or seizing their property. They are temporarily withholding the devices and copy the data. That's why you use full disk encryption - is they want to copy and store pseudo random data, let them.

Re: Canada Border Services seizes lawyer's phone, laptop for not sharing passwords

#300
post #231

Earlier quoted context omitted.

This action can be flagged as suspicious as well, triggering a deeper investigation into the traveler. It's not always feasible, but the most secure way to protect clients'/employers' data is to encrypt the laptop and phone and ship to your destination via standard shipping services, then ship them back the same way before leaving for home. Carry a well used but non-critical burner laptop ($50 Chromebook off Craigsli…

Your advice to mail ahead your secure computer is not good. Mailed electronics are just as susceptible to search, if not more so, as what you keep with you. I think the reality we have to grapple with, regardless of rights violated, is that if you want to cross a nation border, it's best to assume that all nations involved will end up with a copy of all the data (hopefully encrypted) you move across that border. In t…

Unless you are under an active investigation, the chances of your mailed laptop or phone being intercepted and searched are far, far less than if they are on your person at the border.

Still, if you are paranoid enough you can mitigate the danger of your data falling into unsecured hands (at the border or by mail intercept) by using an encrypted shadow volume:

https://www.veracrypt.fr/en/Hidden%20Volume.html

Post reply on HN