New Zealand travellers refusing digital search now face $5k Customs fine
radionz.co.nz
radionz.co.nz
It was extremely unnerving, they went through all our private pictures, messages, dropbox files, email, notes, dating apps, etc. It ruined the vacation for me, and I've stopped visiting Canada because of how disgusted I felt afterwards. I know Canada is not the only country doing that, so from now on when I cross an international border I wipe my phone (after backing up) and just have a few pictures and messages on there. Incidentally though, that's the only time it's happened to me.
I don't blame you for this at all, but I will say this is bi-directional; as a Canadian, when I travel to the US, I get the same bullshit questioning and phone snooping on occasion. The current controversy on border crossing is that, despite marijuana becoming legalized in Canada shortly, if you admit to smoking it when asked, you'll be barred from entering the US. So seems to me that both countries just love love love the opportunity to flex their power against people who have no recourse. If you want to see what cops do when they don't have to follow any rules on unreasonable searches, probable cause, reasonable suspicion, etc. then just look to our borders.
I wish our governments could get together and sort this junk out, but that would mean both agencies would have to lose some of their power to "secure the border" so it'll never go anywhere.
I'd be interested to know if they could!
That said I've travelled dozens of times in a multitude of ports of entries and the vast majority of people have no problem, they're not searched, they're not detained. I haven't seen anyone standing in front of me in line have a problem either. You can avoid 99% of the problem by being polite, answering questions truthfully, and treating the border guards with respect. Yeah, it sucks if they have a bad day and they're rude to you or they ask you invasive questions, just play along and be nice. You'll be fine. If you are suspicious or if you piss them off they will potentially make your day very very bad.
All that said, I think the land border between the US and Canada should just be open.
By the way, you can also go on vacation without a phone ;) disconnecting will make your vacation better!
I really like going to other countries, their customs tend to be reasonable. coming back home is always a nerve racking experience.
I haven't been asked for my phone yet, but have been asked for my camera.
I'm being drawn more and more to paying for online storage/sync solutions and clearing my phone and laptop before traveling to the USA or Canada. actually more worried about Canada.
Is it not illegal - the "snatching" part?
If I randomly got asked to do that, to be honest, I would rather turn around and go back instead of taking the risk that they maybe find something out of my past that can get me intro troubles.
:sigh:
I really think these are dangerous times and for some reason I only ever expected this from the US but never from Canada or New Zealand.
It says so in the Constitution. "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."
That is not how it is in practice, but the Constitution is quite clear on the subject.
Back up to iCloud
Wipe your phone
Cross the border
Restore from iCloud
And yes, this may fail visiting China, because who knows what the Great Firewall will block.Is that realistic? Would they actually be able to "crack" the encryption of a modern iPhone or Android phone?
>It ruined the vacation for me...
So what was the lesson?
I have found practical success by booting from an encrypted Linux partition that has absolutely nothing relevant on it, with a weak password I can always enter when requested by big guys with guns. Unbeknown to them on the same partition there sits another encrypted volume, at some offset from the outer's partition start. If I fail to enter the correct password for the outer partition, Ubuntu drops into the command line of the initrd, that is equiped with all the tools you need to mount the real, offset partition:
cryptsetup -o 100000000 create boot /dev/sdc3
So instead of having a nice GUI into which you directly enter the uber-secret password, you press enter a few times in the GUI, drop to command line, issue a single command and only then enter the uber-secret password. A mild nuisance in your bootup process, once you get the hang of it.It's impossible for any court forensic team, let alone an airport goon, to prove there is actually another partition inside the outer encrypted partition, unless you mount common volumes and cross-contaminate. An important caveat is to properly defragment the outer partition and fiddle with the offset and the size of the inner partition to prevent any conflicts, then avoid writing in the outer partition.
Customs staff typically don't know to prove there is, they just need reasonable suspicion to seize goods for further investigation. The fact you've booted into a 50GB partition on a 500GB disk may well be considered reasonable suspicion to seize the goods for the sake of further investigation.
In the free space of the large data partition there lives the sensitive hidden root. It's maybe 250GB, with a 100GB offset from the start of the decoy data, and 50GB guard space at the back, where ext4 writes all sorts of crap. So you get to use about 50% of your raw disk capacity inside the sensitive environment, as a single encrypted root.
https://www.truecrypt71a.com/documentation/plausible-deniabi...
Continued by VeraCrypt: https://www.veracrypt.fr/
This regulation is clearly made by people who don't understand the technology and capabilities of these devices. A waste of time and money; who is going to train customs officials to search through phones?
Staying ahead of them with a technological trick is only a partial, temporary solution, though. Eventually you can expect that there will be an attack, whether purchased (see GreyKey) or legislated, on the workaround. What should happen is that the whole arms race should be nipped in the bud by outlawing this kind of data collection coercion. But I don't have a lot of hope about getting that genie back into the bottle.
the only safe harbor will be one you don't carry with you except as a device which can guarantee secure access to that remote information.
They boot, which drops to a linux (bsd?) command line. Agent is not pleased. User sets PS1 so the prompt now looks like DOS. Agent is satisfied (they may just have been satisfied that the device worked, but this story dates from when a DOS prompt was a believable thing for someone to recognize as "computer" )
If it works, customs officers cannot find actual illegal contents, and criminals walk free through customs.
If customs officers somehow detects you are doing this, you risk obstructing security measures.
This forum largely believes that the balance struck by New Zealand - that you don't have the right to data privacy when traveling - is completely unacceptable, and as technologists we try to find technical countermeasures.
"Illegal contents", as in what? Unflattering cartoons of the president? A spreadsheet marked "cocaine delivery schedule"? Why is this on the alleged criminal's phone while she's crossing the border? Has she never heard of the internet? No real criminal could be caught by any of this buffoonery. Lots of normal people whom the state would like to harass will be harassed, while wasting a great deal of money, which is the point.
It's a shame that people now have to guard their privacy like drugs.
No sane criminal would bring illegal electronic data with him on a physical device... He'll just download it when he gets there.
Or use same technique as Chinese fakers are using to create fake flash cards or SSD's: just reduce size of drive directly in the controller.
Not after they subpoena this HN comment. ;)
Anyone subpoenaing this comment would discover I post on HN exclusively over Tor :)
Once inside customs, i'd verify the SHA1 sum of the USB drive image vs. the one on the Debian site, and reinstall the machine, setup a VPN back home, and pull the data i need onto the machine.
Repeat the "dummy" install when leaving the country.
Secondly, high-entropy data is evident at even a courtesy glance - normal computer and filesystem operations do not produce high-entropy data on disk, therefore a large portion of high-entropy disk data is highly suspect. The author discusses this in detail in sections 2.4 and 5.2 of https://gitlab.com/cryptsetup/cryptsetup/wikis/FrequentlyAsk...
Be sure that doesn't get into your .bash_history
booting into a 50 GB partition on a 512GB SSD isn't suspicious?
It seems to me this would fix the larger problem most the time.
Access to physical phone/laptop is only the first step -- mark my words. Big Brother's bureaucrats are never satiated. Next, we will have demands for passwords and unrestricted access to : email, facebook, photo sharing, hacker news posts, social media, etc.
I see sudden spike in the market for burner phones. ANd a long-term opportunity for a company that can create a "burner" social media profile.
Nitpick: in Catholic dogma purgatory is a place of purification, those in purgatory know that they are there for a reason and only for a certain time, afterwards they enter heaven. Hell on the other hand, is for eternity and ugly. That's why the two are easily distinguished in their iconography, both involve imagery of flames, but souls in purgatory look joyful and those in hell look despondent.
In a few short years, you are the ones who will be justifying any of the following on grounds that "they already do the less-invasive thing, why not one step more?"
- Mandatory fingerprinting (USA does this for foreigners in some airports)
- Declare all cash, declare all crypto (with addresses / xpubs)
- Bank account logins
- Register electronic devices / install software trackers
- Hair sample for drug testing
- Cheek swab for DNA
- Blood draw to check for diseases / drugs / DNA
They've long had your bank account information (thanks to the PATRIOT Act). They probably have trackers installed on the chipsets of devices, but ignoring that, we know they are capable of intercepting most internet traffic.
Most people have their fingerprints taken, either as the result of a run-in with the law, legitimate or otherwise (clerical error). Or because they were incentivized in some manner (TSA Precheck). Federal IDs are rolling out now too.
> I see sudden spike in the market for burner phones. ANd a long-term opportunity for a company that can create a "burner" social media profile.
I am sure that some folks will try those things and it may work for a while, but the way things are going, it's not going to matter whether you bring your device, a burner, or nothing at all. All it will take is one more 911-like crisis and inevitable fear-mongering.Then, your online profile is going to get mined along with everyone else's, continuously, by multiple state-level organizations who cooperate with each other-- whether you've booked travel or not.
By the time folks get to a border it will just matter of diverting anyone with a "red X" next to their name.
At least they banned software patents.
That hardly seems like totalitarian overreach. In fact it seems quite restrained and pretty reasonable - and presumably must be intelligence led, since I rather doubt they are doing this at random...!
0. https://en.wikipedia.org/wiki/List_of_the_busiest_airports_i...
Searching for the 540 figure it appears to be mobile phones only, there was another 300 computers. So ~840 searches for 2 million people.
https://www.mbie.govt.nz/info-services/sectors-industries/to...
https://fyi.org.nz/request/1119-how-many-digital-devices-are...
...anybody wanna sell insurance?
At all.
EDIT: I do this all the time and it’s not even remotely difficult or a big deal.
Now it will only bother and waste time of people who are serious about their privacy to apply this workaround as well.
Are you asking which countries do demand it?
Is being searched before you get on a plane or enter a customs checkpoint some kind of hideous infringement of your civil liberties? No!
There’s no problem with this in principle. The problem is that it’s silly, and it causes a privacy and security violation while not accomplishing anything.
It's not a problem for you, fine. I'd ask you to let me search you but that'd only be to prove a point, so by all means keep accepting it. But when you say it's not a problem, you do not speak for me.
It's pointless, degrading, and above all it's sad that you and many others accept it without questioning it.
Of course it is. We're simply used to it, because we're sheep and cowards. But it is. Searching everyone, without probable cause or reasonable suspicion of anything, is a violation of civil liberties, and of basic human decency. It's also pure theater and useless.
And because we have accepted this, other privacy agressions seem justified.
I'm willing to entertain arguments that it is a worthwhile trade-off, but we must acknowledge that it is an infringement on everyone's rights.
Every additional infringement should come with a justification, an analysis considering whether it will be effective, and a harm minimisation strategy.
Searching everything I've ever said or done online, my personal photos etc etc. is an entirely different proposition.
There are huge problems with this in principle!
No. But they are looking for items that would make the flight unsafe, as well as controlled substances.
If they are searching your bits, they are not looking for either of these things, they are looking for thought crimes. Not only now, but in your past.
There is a big difference.
We search things across borders for things our country does not want. We don't want drugs. We don't want fresh fruit (which will trip up more people than drugs).
We don't want child porn. And if a phone is a container for that content, we want to be able to explore the container.
Of course, there's a million different ways around this. Get burner phones. Store content in the cloud. Have seven firewalls. Whatever. But that doesn't change the concept of inspecting things across a border to make sure things we don't want, don't come in.
And if that's a totalitarian purgatory, then name a country (or external border for the EU) that isn't a totalitarian purgatory.
Entry to the US can be denied (for life even) if the customs agent suspects the traveler has involvement with Cannabis.
That includes having investments in Cannabis companies.
So if the take my phone and find any information on it connected to Cannabis I could be barred FOR LIFE from entry into the US.
That means that I am leaving a country where that is legal, and entering into a state that it is also legal some border gaourd can ban me for life - even if all I did was search for "Cannibis legal in Canada".
Where does it end?
I could be 100% wrong, but I feel like you could check every digital device entering the country all day with 100% accuracy and have less than a 1% impact on the amount of child porn (or any other digital contraband) being trafficked.
Instead, these kinds of searches catch people who don't know they're doing something illegal, or who the government finds undesirable due to their associations or business activities that are legal in their home jurisdiction. They may also be used to map out networks of contacts.
I do not want governments doing the things in the second paragraph.
Is this the new "think of the children"? The reasoning seems to be, criminals would rather carry their "digital crime-thingys" across the border saved on their phones, than upload it (encrypted) somewhere on the internet... Or is NZ planning to build a Firewall as well (better than China's)?
https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
I don’t think that’s a valid excuse to search devices though. If anything I think it proves work visas need to be more accessible so people don’t have to lie their way in for a job.
Yes, those are non-citizens requesting entry. This sounds like it applies to everyone - including NZ citizens.
And regardless, searches need to be proportional.
Full blown cavity/strip searches at random could cut down on the importation of illegal drugs, but civilized countries require a reasonable suspicion for invasive searches.
Why not apply that logic to digital devices?
They did, at least according to the article. But it's a low hurdle, and cops quickly figure out the script to bypass restrictions like that.
It's no different than the mishandling of trained drug sniffing dogs so that they alert at the handler's command, rather than at drugs/bombs/money/whatever. Countless cars are stripped at border crossing and the side of the road because a cop didn't like someone's attitude.
Edit: I also find it funny when people get passionate about their "free" country's national anthems when they're one bad underpaid, undereducated border patrol agent away from not having any rights.
:)
According to the "Port Courtesy Handbook" it sounds like many foreign dignitaries go through a modified and expedited border check at the US border that the rest of us do not use. "A Port Courtesy or “Courtesy of the Port” provides Foreign Government Officials and their traveling parties expedited processing and clearance upon arrival into the United States. Requests for Port Courtesies are managed by the Office of the Chief of Protocol in coordination with U.S. Customs and Border Protection (CBP)." https://www.state.gov/documents/organization/170352.pdf
And anyway, my understanding is that if you're rich enough to charter a private jet, or to own one, you skip a lot of the border formalities.
Officer - Do you have multiple pins on your phone?
You - (if you say) No
Then you lied to an officer. They can also find it out.
This is already true of laptops, and with some simple setup beforehand that wouldn't be a lie. I highly doubt any customs officer would press further than that.
How do they know you lied?
I've lied to a great many people, including police officers on duty. They can't take me in if I wish them "a good day", or can they?
Granted, it's been very "totalitarian" when it comes to immigration for a long time. Not that I don't think they have the right to do this, but when I went to live there with my kiwi girlfriend, I had to give them actual copies of letters she and I sent each other and get a chest X-ray to prove that I'm not just taking advantage of their socialized medicine. So this sort of scrutiny isn't totally out of character for NZ, but the digital search is where it gets intolerable.
If NZ wants to innovate on anything or to have more movies filmed there, they'll have to do it mostly by themselves, or pay ass-loads to import skilled workers.
EDIT: I made a correction to a part that probably gave people the wrong impression. This was not meant to claim wrong of NZ. I love NZ, and they have every right. I only take issue with the digital search.
If you're likely to be a drain on the public healthcare system, then you're not likely to get permission to live here. Why? It's not fair to those people who have already paid into the system, to subsidise someone who hasn't.
And we are picky. There's no visa lottery here. A points-based system with high thresholds. And that's OK. Same as Australia. Same as Canada.
https://www.theguardian.com/world/2017/jun/29/new-zealand-ga...
Edit: oh sorry, he's "a great ambassador for New Zealand"
As a practical matter, it seems that the immigration officer you wind up with does have an impact on your application's success. I was initially turned down for a Skilled Migrant visa (which I believe is what you're referring to) because I had work experience in IT, but a degree in electrical and computer engineering, and though the points from those combined were well over the higher threshold (and both on the skills shortage lists at the time, ~2010), they weren't in the same enough field according to my assigned officer. That meant that I had to pick which one I wanted to use, but neither by itself put me over the line... An expat friend of mine had a similar experience.
I don't mean this to be a slight on Immigration NZ, just that the process can feel a bit arbitrary and bureaucratic - like a lottery. It creates a chicken-and-egg problem too: in order to get a skilled migrant visa, you really want a job offer, but you're only going to get a job offer by coming here and looking around in person...
I actually don't think there's anything wrong with NZ or any country doing those things. My point is that rooting through my computer, requiring me to hand over my credentials, is where I say no. Maybe they'll end up paying the price if enough educated people decide not to bother. I don't really know.
> We have a huge housing shortage
> get a chest X-ray to prove that I'm not just taking advantage of their socialized medicine.
We have a problem with TB. We have issues with other disease coming in too and don’t seem to screen for them, which we should.
> If NZ wants to innovate on anything or to have more movies filmed there, they'll have to do it mostly by themselves, or pay ass-loads to import skilled workers.
We do pay assloads. For some reason we subsidise the films that come here while they exploit their workers and get exemption from NZ laws. Our homegrown hero Peter Jackson had a role in that.
Your level of skepticism about NZ clearly indicates you belong here. Come back!
If they sit down with me and allow me to maintain control of the device while they ask to see recent chats and emails etc I would feel much more comfortable (though don't get me wrong, I still see the whole process as a huge overstep and invasion of privacy).
I can see plenty of those inspection scenarios where I would not want to crush my device into pieces afterwards. And plenty of others where I would. There lies the difference.
Photos, logout of Google, clean up downloads, etc.
I don't have anything to hide, however having some random customs dude go into Google Photos which has over a decade of my life documented doesn't seem exactly ideal.
I was simply saying, I don't have photos of me doing lines of Cocaine off strippers. However I'm still concerned about the boarder patrol looking through my shit.
Holy fuck HN can sometimes go off on a tangent.
And besides, laws change. I have nothing to hide today; who knows in three months?
Focusing entirely on that one phrase -- I have nothing to hide -- twists the meaning intended, I think, especially given the manner in which it is being done here.
This law isn't too bad as far as a compromise bill goes. The problem is a lack of accountability. Three fixes and I'd be okay with it:
1) Officials must document their reasons for finding a "reasonable suspicion of wrongdoing";
2) Travellers should be able to challenge the search in a court proceeding to occur no later than close of business the next day (traveller must surrender their phone to the court in the interim, but is free to leave the airport after that); and
3) Searchers cannot (a) copy data from the phone while searching, (b) turn off airplane mode or (c) take more than [2] hours to conduct their search.
Just from a basic security perspective, this is teaching citizens it's okay to give your password out to authorities, and that's just fucking terrible.
So:
4) All third parties (meaning people other than the traveler) who have their privacy violated in the process must be informed immediately of the full details of the privacy violation. Which communications, pictures, etc. were viewed and or copied and by whom, and how to follow up on these violations.
This isn't a requirement when e.g. police search an office and so wouldn't seem appropriate in this case. NDAs, explicitly or implicitly (through statute), tend to exempt courts, regulators and law enforcement.
I agree, but I think historical precedent with books and papers is different from our phones. Note that my process still defaults to allowing the agent a casual search. The traveller simply has the right to call foul and require the agent to produce their reasons in front of a judge.
In the USA at least under third party doctorine that means none of that data is 'private' anymore and can be accessed without a warrant.
I don't know about NZ but I bet it's the same.
All humans inside the US border have the fifth amendment right to remain silent, so handing over encryption passwords to the CBP is a choice.
Unfortunately, the 5th amendment doesn't apply in New Zealand - if you remain silent at a NZ airport while customs ask for your password, they will impose a $5000 fine on you. The only viable solution I see is to only travel to places that do have 5th amendment protection or similar (which would immediately rule out Britain, Ireland, Australia, and now NZ as well).
If we were questioned at all about it (I never was, but others were), we were told to give them a business card from our direct Manager, and contact them with any questions. I have no idea what the Managers were trained to say or how they dealt with it as I was pretty low in the totem pole, but I assume there's standard practices out there for this.
I'm pretty sure that part of your contract would be invalid in such a case, especially if you were instructed to go to NZ.
This makes me particularly uncomfortable. There should be reasonable grounds.
> Border officials searched roughly 540 electronic devices at New Zealand airports in 2017.
That does seem low, out of what I assume is hundreds of thousands of travelers. With that said, it still doesn't sound reasonable.
What files are they looking for on the device?
I mean, it's not like a terrorist will have a plan_to_place_bomb.doc file on their device, so what's the point? What file could there possibly be on any device that will threaten the security? And how is scanning devices going to prevent you from downloading that file after you go through customs?
But it would be nice if the phone manufacturers made it easier to side step.
Android is close already: it has multiple users. If it allowed you to hide a user (so you had to type in a name, for example), it would be mostly there.
One thing I really wish they would provide is a decent backup service, ie something that allowed you to backup everything on the phone, to an encrypted binary blob. Mainly I want this because having a backup that allows me to restore my data if the phone gets destroyed would help sleep easier at night, but of course it also solves this problem too: backup the phone to a hidden cloud account, factory reset it, restore it on arrival.
Also, this issue raises some more questions:
1) It sounds like they might use a device to scan your hardware automatically, potentially opening the door to copying files for permanent record
2) It is a small step from here to install tracking software on your device (as China is doing in some places)
Just install macOS like you normally do, set it up with a user and some basic data. Then create a new partition in the same container and install what you normally use (or even clone the first one, if that's possible).
Then set the basic one as default boot source, and hold alt on boot to select the other one to get work done.
A light version of the "hidden encrypted volume" solution, without any risk of overwriting your files.
So they've realised they can bring data into a country on a smart phone with a password. Law enforcement will really be screwed once organised crime figures out the other options.
They will see my genitals and the genitals of many other people. Not sure how not going accessing my off-phone backups is supposed to be better.
This is a shame, my partner and I have been spending the last couple months seriously considering new Zealand as a new home, after we tire of SF, specifically because we felt that legally it was going down a better path than the USA.
What made you think this? Have you been keeping an eye on the news regarding NZ?
For example, they allowed American billionaire Peter Thiel to obtain citizenship despite not meeting the residency requirements:
https://www.nzherald.co.nz/business/news/article.cfm?c_id=3&...
Unsurprisingly, countries where laws can be bent or broken by the rich tend to not respect individual rights.
The fact that billionaires do as they please is a global fact I have long gotten used to.
If the idea that 540 people out of 3.7M international visitors get their phones inspected worries you, then that's a valid concern.
For perspective, we issued over 9000 biosecurity infringements for people bringing in fresh fruit, meat, honey, etc.
Which is fine, completely reasonable, and unrelated. This isn't necessarily about the number of people getting their phones inspected. A huge problem is with there being no oversight or accountability, which can be abused at several levels.
Where are the protests, free press in arms, academics, ngos and call for sanctions by the 'international community'?
Is anyone going to bomb New Zealand and the US for violation of human rights and restore democracy? So much for 'our values' and the western tradition of 'enlightenment, freedom and democracy'.
Does the Law in NZ have any provisions against self-incrimination? The US has the 5th Amendment, some countries in the Americas signed the American Convention on Human Rights. How does NZ deal with this issue?
Can't it be considered that providing a password to a safe or personal device is akin to being a witness against oneself?
For example, the government/border agency decides that travellers must give up their phones and account passwords. In fact, other governments/agencies see this as leading by example and tag along for the ride.
The justification we hear is 'national security' and, since the first thing we were aware of was the solution itself, we treat it as viable without much scrutiny and proceed to fill in the blanks about what 'national security' means to us: is it terrorism? drug trafficking? illegal immigration? some other hot button topic?
It begs the question and the frustrating thing is; we know the real answer: governments just love authority and surveillance. Yet still, how about some other questions...
What is a better solution to preventing terrorists from hijacking your plane? It would make sense to address the circumstances that actively encourage terrorism, no? That's foreign policy.
Drugs crossing the border? How about checking for the physical presence of them as opposed to forcing people to incriminate themselves for recreational drug usage?
Illegal immigration? That means a lot of things to a lot of people and, if my experience in Canada is anywhere near representative, it might actually be more successful if it wasn't so strict.
In no case does getting unrestricted access to your social media accounts, your collection of nude selfies, entire history of messages going back years, etc. actually aim to tackle the real problems. All the reasoning does is save the government the job of justifying its pathological obsession with your private life.
> "You'd be mad to carry stuff over on your phone.
Of course, intelligent criminals would never have incriminating communications or evidence carried on a device across international borders. What's more, they would know that there is such a law and hence have their devices wiped clean or get devices with minimal information to support whatever cover they're using. Lawmakers and law enforcement must be idiots to imagine that serious crime could be prevented or caught by this measure.
> Privacy Commissioner John Edwards had some influence over the drafting of the legislation and said he was "pretty comfortable" with where the law stood.
This just shows how government appointed officers behave like puppets of the government, and rarely side with common people on big issues (such as mass surveillance).
Similar to DRM, these measures inconvenience the innocent while doing nothing to prevent the bad people from doing bad things. The balance is tilted heavily towards abuse and harassment of the innocent. Being one of the Five Eyes [1] countries, I'm not surprised that New Zealand does this kind of thing.
The lesson is loud and clear: if you're traveling, backup your phone online, wipe it, and then carry it with minimal personal information. Otherwise all your personal communications, including sensitive/intimate photos and private messages, will be taken by border patrol for their personal use.
It would be nice if phone vendors provided a mechanism to backup my phone, wipe it, then some time later merge the backup with the contents of the phone. Would be nice to be able to leave the primary contents of my phone at home while a travel and then merge my travel photos and messages and such back in when I restore my original contents after returning home.
That headline reads as if it is from some dystopian cyberpunk novel. We've reached the age where governments are conducting "digital searches" at whim without just cause, gaining access to everything that makes you "you", and claiming it's for your own safety.
Give those pesky 5 eyes poison data of a fictional life via a 2nd phone.
one case I know about: tatoo artists travel the world for work as guests in different studios. most do so under tourism visa sice its only a couple months each place. their managers (and online forums) already have a list of things that can be in the luggage and in their phones and instagram feeds so that they really do look like tourists.
security theaters is security theater.
Presumably,refusing to submit my phone to search is an criminal offence, the mind bending part is that I can get out of this by paying money to the government. I can see how a terrorist or drug dealer could be happy with this.
This sucks all round
https://en.wikipedia.org/wiki/Sinking_of_the_Rainbow_Warrior
They were caught by a normal homicide investigation, as almost all murders in New Zealand are. No special terrorism laws, border searches or secret warrants.
This is not just a pointless invasion of privacy in the name of security theatre, it’s a needless waste of time and money.
It's not about "I just want to get high", it's about removing insidious incentives for the destruction of democracy.
Is it permissible to punish somebody for not knowing or for forgetting? And if not, who has the burden of proof? I find that these questions have no good answer. For this reason alone I regard laws that take away the right to remain silent as flawed in principle.
It's not really seen as a 'punishment', since no one has the 'right' to visit New Zealand who isn't a citizen.
Anyone who has something to hide will either be smart enough to hide it or not bring the device altogether. Really all they're doing is annoying those who are not a threat.
Don't go around saying how it doesn't work. It makes the life of criminals harder. So it absolutely works. People will be caught by this. The question is: Is it worth it to lose the right to remain silent over it? In my view: Never.
It's like it's a pan five eyes scheduled implementation.
My iPhone isn't logged into any cloud services and the only apps I have installed are Google Maps and Gmail. I don't log into my Apple account and don't have the Dropbox app installed. Much of my data is stored in an S3 bucket. Simply giving an officer my phone means I'm surrendering my Gmail account and local phone data i.e. contacts and reminders. Not terribly worried about that. To really investigate my digital presence they'd need access to my Dropbox, AWS account, personal email etc. Can they request that information despite not having any trace of it on my phone.
How deep do they go?
It's still a huge disaster of a law, though. It's an unnecessary invasion of normal citizen's privacy, while not stopping actual criminals.
When I first read the headline, I thought of something else...
I could see this happening in a privacy oriented Android image though.
The idea being that before you travel, you upload the encrypted image and wipe the phone, then after passing through customs you restore.
That sounds like willfully evading customs, which is a serious crime.
Not for privacy reasons -- but instead because my US-based phone wouldn't work in some of the other countries I'd be in. (At the protocol level, I suppose.)
Assuming it's not prohibitively expensive, why not do the same thing, now?
I agree that this is a troubling policy. But it seems simple to get around, if you were interested in doing so. It's also possible that this suggestion is naive, and feel free to let me know why, if so. =)
I traveled all around Europe, South East Asia and US/Canada only ~5 years ago with all my hard drives (and as such, a copy of all my pictures, documents, but some movies and music too), and most of the time, the fact that I carried 4 or 5 2.5"hard drives on me was just considered funny, once I explained that it was hard drives with work & personal stuff on it.
Also, the device is in "plane mode", but they will read your facebook password from lastpass and off they go on _their_ desktop computer -- looking at your FB profile, history, etc...
I accept that argument in principle, but practically, since it’s so easy to keep any illegal materials on the internet and retrieve them post-security, how does digital search still make sense?
Bad people are going to find ways to find ways to take advantage of a system in place, but at least we can try to make it a safe for those innocent.
I give pause when pondering international business travel. I can’t very well wipe my laptop, nor could I hand it over given what’s on it. Put everything on a VM and move it off the device for border crossings?
So if it can be got across the border digitally, why would they put it on their phone that can be seized and searched?
The efficacy of this law wrt. the new challenges we face is at best questionable.
Of course they don’t have to tell you why they want to look at your phone or what they’re doing with the stuff they’ve copied off it.
It’s basically a pant sniffers charter.
As the comments above can attest to, there's multiple ways of circumventing these searches. And we've given it what, 5 minutes of thought? Imagine what you could come up with if you actually had something to hide.
> If people refused to comply, they could be fined up to $5000 and their device would be seized and forensically searched.
You fly through security, both on land and in airports, and you even get expedited through domestic security screening. It has made flying 10x better for me.
Is there no collective legal recourse for us?
Maybe they considered this ;)
Now when the rent-a-cop futzes with my phone, it's a GDPR violation. But am I to blame or the border agent?
the restriction and surveillance of their citizens within their country are far, far more troubling to me.
If someone has access to your phone they can always find something.
I wonder if there's a technological solution for this other than wiping the phone clear?
Taking a laptop means running tails or having a second partition, something simple/windows to boot up. Customs just wants to see a desktop im guessing.
as for file searches on the phone, its a bit more complicated...
1. run syncthing on your phone, send your data to the cloud.
2. wipe/factory reset the phone. now you're ready for that inspection.
3. restore/load once on the ground and in your hotel.
With all that what I'd like to see is a simple interface to create arbitrary numbers of custom Views with associated triggers. The default one would be as we have it now: everything you load is visible at all times after unlock. But then you could create a new one, and select which apps (and in turn associated data in that app silo) appear and which preferences are accessible, then have a "This view will be made active when..." with nice UI for various key conditionals (time, geography, speed, network connection, biometrics, and/or password). It'd then be easy to ensure that while traveling between locations only maps, ride hailing and airline apps would be available for example. If anyone stole the device, or for that matter compelled it in any other way, none of my financials or private info would be available. I couldn't even be compelled to do it at that location, it'd be genuinely out of my control, backed by the same hardware crypto system providing standard FDE. This isn't even about government fully or even in large part, in dangerous parts of the world just as modern device net locks reduced the value of stealing a device a spread of "tourists and the like literally cannot be made to transfer money or the like on the street" could reduce the incentives for certain crime.
And again it'd be a very grokable common sense feature for the attention issue too. These days information overload and things trying to grab for some of our mindshare is a huge source of stress. I'd love if my devices, rather then always being a matter of adding on, started being able to actively help me subtract instead. I could compartmentalize work apps to only even "exist" away from home, no temptation or notifications even show up. And vice versa, entertainment distractions vanish as I enter certain locations. "Willpower" is something of a limited resource too and in practice often comes down to essentially planning ahead to avoid temptations in the first place, not going to the grocery store when starving for example. Our digital devices should be, at our individual direction, automatically helping us as humans. I think that'd be a valuable next step anyway, but the fact that vastly more powerful and user friendly coercion code type systems could be made widespread too would also be helpful in taking back some of the privacy digital can also take away.
iOS12 Shortcuts may enable this in the future, if apps can be tagged by users with custom metadata, which then drives a OS-wide policy engine.
iOS "Screen Time" has arbitrary categories of apps, some of which incorrectly classify social apps (like Flipboard) as "Reading". This need to be customizable based on user priorities.
And what are they going to look for?
do they still give you trouble, like over why you dont travel with your regular phone?
Evidently, severe brain damage is no hindrance to securing a commissioner's appointment in New Zealand.
Also, in the case that your view is correct, stooping that low discredits the truth. That's bad for everybody.
If you had that stored in your suitcase, it can be discovered, and a prosecution started.
If you had that stored in your phone, it can be discovered, and a prosecution started.
Phones aren't magical parts of your brain, that can cross borders without being inspected. There's no digital 'diplomatic pouch'. Just because there's lots of sensitive goodies inside doesn't mean it's immune to inspection. Why would it?
Guy was reading her Tinder messages and accusing her of being a prostitute. He brought up some saucy messages and would say things like “girls don’t do this kind of stuff for free...” Finally handed her back her phone with a comment like “well, maybe you are a good girl ;)”
He was fixated on some message where she commented how much a meal might cost at some restaurant and used that as an excuse to ask personal questions about sex and prostitution.
This is an essential element of situational crap that I am referring to when I complain about sexism in the world. Meanwhile, other people seem to think I mean "Men who firmly believe women should be barefoot and pregnant and who have some conscious intent to prevent them from having real careers." or some nonsense along those lines.
Should have replied, "Maybe Stateside, they don't!"
I hope this sort of malarkey doesn't become the norm. This seems rife for abuse. If you have good enough information to demand to rifle though someone's phone or computer, you have good enough information for a damn warrant.
Ha-ha-ha, sweet, sweet summer boy...