Live data from Hacker News

US border forces are seizing Americans' phone data and storing it for 15 years

engadget.com

411–420 of 566 posts

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#411

Earlier quoted context omitted.

2FA should be TOTP not SMS

My work-based 2FA is tied to my phone and is non-transferrable. If I lost my main phone without switching the 2FA install while logged in, I'd have to go through a recovery process. Culprits: RSA Authenticate and Okta Verify. My personal accounts that have 2FA are all backed up with Authy.

>My work-based 2FA is tied to my phone and is non-transferrable.

If that's the case with your workplace, do they issue you a phone to use for work-related stuff.

If not, why not?

Your personal device shouldn't be required to do work-related stuff, IMHO.

I'd add that since there's work-related stuff on your phone, your employer can restrict what you do/don't do with that phone and subject your personal device to its corporate policies via Mobile Device Management (MDM)[0] systems.

Even more, if you ensure that work-related stuff isn't on your personal device, issues with either device won't impact the other one.

I realize that it's out of fashion these days to keep one's work and personal lives separate. But IME, doing so is generally a good idea.

[0] https://en.wikipedia.org/wiki/Mobile_device_management

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#412

Earlier quoted context omitted.

BOS got unstaffed camera kiosks some years back, and being the wise-ass I am, I made a funny face for the camera, figuring the picture would end up stored for all eternity on a computer, never having been seen by human eyes. At that point in time, they were still having humans in the loop, and I got a different kind of funny look from the customs or immigration person I spoke to some minutes later. I got a third kind…

Never have fun with border control. Know your audience.

-- dad only had two hard fast rules with us growing up - never ever ride a motorbike - never ever joke around at border control --

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#413

Earlier quoted context omitted.

I believe there was a defcon talk about this but for the life of me I can't find it. My advice is to epoxy your lightning port closed (or snip the data connection inside the phone) and use wireless charging exclusively. edit: It was the Signal founder. https://appleinsider.com/articles/21/04/21/signal-hacks-cell...

what if its a laptop now?

Buy a laptop that has a charging port. Then same advice applies.

But I would just format it.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#414

Honestly, as a non-American this scares me. I am absolutely not at all important and a fairly mediocre programmer as well, I don't store compromising data about anyone, never stole code or company data in my life (and never will), etc., you get it. A normal law-abiding citizen. I still don't want to get my phone taken on an US airport and returned an hour later with God knows how many viruses that even Apple wouldn't…

>It's not about having something to hide. It's about not liking it when people poke their noses in your business without you being a criminal. And no I don't think installing backdoors on each device "to catch the criminals more easily" is a solution at all.

As an American, I couldn't agree more.

It's been a while since I've been outside the US, but given how so many (not least of which is the US) countries are doing intrusive things with mobile devices at the border, I will most certainly back up (nandroid, which I do anyway for backups) my phone and flash a stock ROM before leaving the US.

Upon my return, I'll restore my backup and pick up where I left off.

Not because I have anything very interesting (to law "enforcement", or anyone other than me for that matter), but rather because my business is my business and no one else's.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#415
post #2

I'm not sure I missed something, the title says "Americans" but I couldn't find an elaboration on exactly _who_ is subject to these searches. The ACLU [0] seems to contend that, at least, US citizens are not subject to these measures. [0]: https://www.aclu.org/know-your-rights/what-do-when-encounter...

https://legalservicesincorporated.com/immigration/border-pho...

https://www.theverge.com/2021/2/10/22276183/us-appeals-court...

"The court held that the government’s policy, described above, does not violate the Constitution. Border officers can continue to perform advanced searches without a warrant or probable cause and can perform basic searches without reasonable suspicion that there may be a violation of law or a national security concern."

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#416

Even if you are a person who will never in your life end up as any kind of person of interest for the government, handing over data in this way could still be quite dangerous. Phones will often contain data that can facilitate theft and fraud if ending up in the wrong hands. If they're able to copy everything, including private data from all apps that could be quite bad. For example many countries now use apps to log…

Why the hell would anybody sane, especially with all knowledge average HN user has about government overreach and greed, hacks, 0days, bugs etc. ever put such a critical item as banking app on their phone?

Apple vs Android is irrelevant in this, there is no truly safe mainstream phone in 2022, period. Are people really that lazy?

I do manage quite a few financial things but for none of those phone apps is crucial and I use exactly 0 of them. There is ebanking login app, but on its own its useless, another 3 factors are required for login. There is always desktop browser variant for everything, with firefox with ublock origin and few other plugins making internet a bit more as it was intended to be.

So yes US government can hack my phone if they havent already, they will see what kind of photography and travelling I do, which family members I write to, and some online shopping history. Thats it.

Phones are not secure and probably never will be for anything more. Anybody telling you otherwise is either dangerously clueless or worse

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#417

Earlier quoted context omitted.

Yes, it's happened to me twice, both times crossing from Canada to the US on a land border entry. There was a short period of time where the CBP was doing this in droves on Canada land border entries. The way it's generally structured is they ask permission, and if you refuse, they can't really do anything without a court order and can only hold you at most 72 hours. The time I was held up for 2 days was because they…

This demonstrates a clear lack of understanding on the rules and how ports of entry are "special" > There was a short period of time where the CBP was doing this in droves on Canada land border entries. The way it's generally structured is they ask permission, and if you refuse, they can't really do anything without a court order and can only hold you at most 72 hours. They can do worse, they can : - enforce travel b…

> enforce travel bans (starting at 5 years) and issue large fines.

This only affects future travel and is subject to court oversight. You cannot be refused entry as a US citizen. You can however find that just on the other side of the border you'll be sitting in a detention holding cell.

> Failure to grant access to your digital device may result in the detention of that device under section 101 of the Customs Act, or seizure of the device under subsection 140 (1) of the Immigration and Refugee Protection Act.

Yes, they have broad powers of search and seizure for anything physically in your possession when you cross the border. You MUST physically turn over the device, you have no legal recourse. You do not have to give them the password or unlock it for them (short of a court order compelling you to do so). They can absolutely just take your phone and laptop and essentially never give it back if it's considered evidence in an ongoing investigation. In practice, they generally return them when you are released, and if they hold them longer are required to return them within 30 days if it's not part of an ongoing investigation.

If you are traveling internationally and want to protect your rights and your privacy, it's a good idea to have a lot of money so you can afford possible job loss due to detention, to pay for attorneys, and to buy new electronics if/when they are seized. This is kind of implied and somewhat explicitly said in my original comment.

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#418

Terrifying for only 2 reasons: 1. Any malicious person savvy enough to pull off a crime of interest to the Feds is smart enough to provide a wiped or burner phone to DHS/ICE, and they have to know this. So, what is the point in doing this if not to target law abiding citizens. 2. USGOV has a spotty track record of keeping this information secure. A foreign actor is likely to access this info eventually. As one former…

>>So, what is the point in doing this if not to target law abiding citizens. It's the old rule known to governments all over the world - there is no such thing as an innocent citizen, there is only a citizen who you haven't investigated enough. Call me cynical but storing ALL of your digital data allows the agencies to basically find something, anything, that will allow them to further blackmail you into complying. E…

This became clear when the border police checked my phone and ended up in my spam box… it was not pretty

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#419

On my last trip back from Europe in June, when I re-entered the US, US Customs & Border Control didn't ask for my passport. No one did. They did wave a webcam connected to a computer in front of my face, and then a moment later, called out my name and said I could enter. Same with everyone coming through the international border area. I think that's just as weird a development and worthy of "WTH?" as this topic.

[deleted]

Re: US border forces are seizing Americans' phone data and storing it for 15 years

#420

Earlier quoted context omitted.

Good thing the trend is toward non-removable SIMs to stop that sort of shady business.

Non removable sim? Who wants that?

If any company you depend on uses your phone number for 2FA, then SIMless is useful. A SIM can be removed and put into another phone to receive authentication txts.

Mostly relevant if your phone is lost or stolen, or perhaps even if criminals are directly threatening you. For example, I worry about bank accounts when I travel to some countries because criminals would be highly motivated to steal from me - the only thing protecting me is their ignorance. In some countries a few thousand dollars is a lot of motivation. Unfortunately my primary bank does not provide secure 2FA but only provides phone auth, and I am locked into my bank because of my mortgage (I have a mortgage, and conditions have changed which prevent me from getting a different mortgage from another bank). I could cancel revolving credit (the main financial risk) but that has other opportunity costs for me.

Also SIMless helps prevent unwanted telephone charges - important if roaming in other countries on account. Phone companies do not make it easy to limit your liability, so if you are unlucky you could end up owing many thousands.

Post reply on HN