I’ll never bring my phone on an international flight again. Neither should you
medium.freecodecamp.com
medium.freecodecamp.com
"It’s totally legal for a US Customs and Border Patrol officer to ask you to unlock your phone and hand it over to them. And they can detain you indefinitely if you don’t. Even if you’re a American citizen. [...] Barring the use of “excessive force,” agents can do whatever they want to you."
and
"[I]t’s illegal in most countries to profile individual travelers"
I don't think any of these things is accurate. Although courts have been extraordinarily deferential to customs authorities, they've also ruled that many things done in the name of border enforcement were unreasonable!
Fortunately I'm working with some lawyers on a new version of a border search guide, so hopefully we can get some informed legal information out there.
Most people who cross a border are on their way somewhere and have a limited window of time to spend at the border until the delay incurs a very unreasonable financial or scheduling hardship..
Either missing a flight, or hotel, or vacation booking, or business meeting, etc..
So while you may be within your rights to argue and resist these unreasonable searches, they come at a price that border control knows/expects most people will not be prepared to pay.
Also afaik, the ACLU has lost cases pertaining to defending liberties at the border
I also agree that some border and immigration challenges are lost in court and that it's a legally difficult context in which to defend individual rights, and I was responding to the article's claim that the only court-recognized limit is "excessive force", which is unnecessarily pessimistic.
> This may upset Customs and Border Patrol agents, who are probably smart enough to realize that 85% of Americans now have smart phones, and probably 100% of the Americans who travel internationally have smart phones. They may choose to detain you anyway, and force you to give them passwords to various accounts manually. But there’s no easy way for them to know which services you use and which services you don’t use, or whether you have multiple accounts.
You can be damn sure the government has a list of possible email addresses associated to individuals. That'd be be the first thing any modern SIGINT program would compose so as to link accounts. Assuming they have that (which again I'm assuming they do) it's trivially easy for them to go from "John Q. Citizen / SSN: 123-45-6789 / Podunk, USA" to a set of emails to cross reference against service providers.
Add five minutes in a dark room with piece of hose and... well you know the rest.
things the government knows, and things that a CBP agent knows, are not the same thing. They NSA doesn't just provide their database to all the hundreds of thousands of front-line law enforcement agents. If you're being specifically targeted for some reason, enforcement agencies might be provided with a history of your social media activity, but it's unlikely that they can just pull it up when they type in your drivers license number.
Source: https://www.engadget.com/2017/01/12/obama-expands-the-nsas-a...
Could you imagine if it were that easy to get info on any citizen? What's to stop a spy/traitor from becoming a border patrol guard, downloading all the info and selling it?
I don't think anyone really believes it'll catch a ton of "good to have you here, the bomb is ready"- or "whew so nervous carrying these 50 pounds of contraband!"-bad guys.
Also I'd slightly question the ease of creating burner accounts. Facebook will show your sign up date, and something too recent will be suspicious. Other things like "why don't you have pictures of your FB friends on your phone" and on and on could be clues to a fake account. Not saying it's really hard, but it's not something you'll whip together a week before your trip.
http://travel.trade.gov/view/m-2016-I-001/table1.asp
And apparently ~500,000 Visa overstays.
How many of the 40 million should we put off traveling here to catch a fraction of the 500,000? What ratio of turned away violators to hassled travelers is "very effective"?
Hell, I've already gotten more email from the current administration than I ever got from Obama, Clinton & Sanders combined, and I'm a confirmed lefty.
Supreme Court News [Getting ready to nominate]
Supreme Court Update [Gorsuch chosen]
A Vote for America's Future [from VP Pence about his DeVos vote]
Major Economic Update [jobs bragging]
President Trump's Weekly Address [solicitin FB & Twitter follows, petition signing, watch his speech]
Assuming that the law has no legal power to compel the associate to co-operate, is it then legal for said officer of the law to detain you if said associate—just of their own accord—decides not to cooperate?
(For example: I put all my money in a Russian bank. An IRS officer demands that I retrieve it so they can tax it. The Russian bank says that its policies prevent it from sending money to people who are making requests under duress, and so nothing I could say or do at that point would ever make them send the money. The US has no treaty enabling them to go through diplomatic channels to put pressure on the Russian bank. What happens?)
Or is this something they've already started doing? And if so, what makes it legal?
I imagine it would be illegal, but there may be a market for it.
You could theoretically load one ROM up with all your personal data (and have it encrypted) then have another for customs usage, just boot it up before you reach the agent. Remember to load it with plausible data to prevent any suspicions and you should be good to go.
The odds of the border agent messing around in your recovery to boot the other ROM... I'd say fairly low.
This may be a practical solution today for people who want privacy at the border.
Dumping your entire flash would take a serious amount of time and would be so varied from device to device that it'd likely be impossible in practice.
The best you can do is make the process as frictionless as possible for the border thugs, to get them to mislead themselves. For instance, imagine encrypted steganographic storage that seamlessly unlocks with a key retrieved from a remote server. If a GPS fix says you're in a dangerous area (eg border crossing), the server only unlocks the uninteresting bits [0]. A connection from your home network and/or designated third party is then required to switch the server's mode back to supplying full functionality.
And this needs to become the default mode of operation for a sizable chunk of phones, so that the "intent" bullshit becomes inapplicable. This is how the legal system works - you can only obtain safety through technical means en masse. Yes, we have a long hill to climb.
[0] Obviously this is trusting the phone and could be spoofed, but this isn't the threat model. The point is to make the behavior change passively.
Well, most likely because things like "obstruction of justice" are crimes.
I don't really get the notion that the law works like Airbud, where the rules have to be specific and anything not banned is permitted. It's totally possible to criminalize subjective things like "trying to trick us" which apply even if the means used are novel and not banned.
Whether or not they will find out about your lie is a different question.
[1]I was going to say "for the next four years", but this problem is bigger than Trump.
IIRC they're actually already demanding Facebook credentials from certain travelers.
Unless you literally have no internet accounts, or what you do use is obscure enough to give you plausible deniability, it seems like you're fucked either way.
If they say they're not letting you go until you unlock your phone, you get to decide if you want to stay there in the interests of your privacy.
The author is arguing that they wouldn't know the usernames or even the services themselves of your accounts and as such could not ask for them. I call bullshit on that (see my top level comment on this).
Or, taken a little further, I don't even know my email password anyways. Its locked in a password manager which requires 2FA. I would myself be locked out of almost all of my accounts if I didn't bring my phone.
But this also raises the question of them believing me that I can't login because I don't know my password.
Works best if you are a citizen of the country you try to enter.
Take a backup and upload (encrypted) to the cloud. Factory reset in transit. Get where you are going, download and apply.
You might need some of your important numbers written down I suppose.
If you have any doubts about that, you should visit a US-Canada border crossing. The overwhelming majority of travelers are not subjected to through inspection.
Wipe it, restore after crossing the border, it's not really a big deal.
IANAL but reading other articles on this topic I don't think this is true - I think it's just that the 4th amendment rights that all searches and seizes have to be with done with warrant or probable cause are suspended at border due to doctrine of "border search exception".
DO NOT BE COMPLACENT.
So next year that's what they will know.
If you personally do not care about your privacy, why should someone else care?
Your particular risk model may or may not include CBP, both others' might. Immigration lawyers (for whom attorney-client privilege should hold), immigration NGO workers (for whom it almost certainly doesn't), journalists, asylees, among others.
The protections which apply to you also apply to them, and aren't granted conditionally. Which is why, if you believe in civil liberties, liberal democracy, and freedom, you should fight like motherfucking hell for them.
Unless, of course, you don't.
It's an invasion of privacy (to what extent is debatable, but I'd rather not make a stance there), but so is going through my luggage, x-rays, etc. I understand why they're there, and I have a tiny twinge of "what if they find something weird" every time I go through the airport, but I also trust the system (again, to some extent) and recognize why these processes exist.
Fun fact: I've accidentally tried to go through security post-9/11 with a half-dozen hunting knives in my carry-on (after a camping trip) and they were very concerned at first, but just asked some questions, told me to throw them out, and let me through.
Saying "if you've got nothing to hide, why worry?" is a trope by now, but I'm clearly not the person they're looking for and I'm not too worried about a mild, temporary inconvenience if they mistake me for a Bad Guy.
The Android ecosystem had already gone down that rabbit hole years ago. I think we're at the stage where it doesn't seem like a commercial identity provider is going to look out for our privacy at all. Definitely a challenging space, but one where we can wrestle back a lot of privacy we've lost.