When you go through customs, they can’t just search your brain. They can search your possessions, but they can’t mind dump you.
That’s the critical distinction. It’s not my property that’s the problem. It’s that it’s an extension of my brain.
> I know it's an encrypted, secured device I always have with me
What if you didn't know that? What if you thought of it as just a suitcase?
If someone carries a notebook that contains printed pages of encrypted material, what is the expectation?
Whatever the answer to that question is, the expectation shouldn't change based on what medium the material is stored in.
Historically, your luggage would contain personal pictures, credit card numbers, general banking statements, generally personal information, etc. The medium in which this information is stored and carried around has changed.
The need to inspect what you're bringing into the country has not.
These processes didn't originally come about because people wanted to inspect your 5 different pairs of underwear or what personal devices are exploring where the sun don't shine. The people decrying this as some sort of over reach are basically just admitting ignorance to the fact that these processes are just lagging behind how people actually carry and transmit the same information they've been inspecting for nearly a century. It's just a small update to continue doing what border patrol has always been doing.
What's actually problematic is the there's so much information housed together on one device. In border patrol/guard/police in customs/etc attempt to, again, continue doing what they've always been doing that particular advance in policy and process has incidentally lead them at the forefront of a lot of information people used to either keep in their homes or just in their head.
Personally I think this more of a data organization problem than it is a government over reach one. It definitely needs to be discussed. It doesn't need to include tired cries of a 1984-esque future.
This process came about because the public hasn’t demanded privacy protections as much as it has demanded safety, not out of any logical extension for existing policies.
No, but you definitely needed to have your banking information on you when traveling for an extended period of time, especially internationally.
>It’s an order of magnitude problem
I think we're talking past each other. This was my "data organization" point. All the data is now housed together.
> not out of any logical extension for existing policies.
Why do you say this? I outlined how it was a natural progression and you just went "nah."
Here, a country may be concerned about objects being physically brought into their country, but to be concerned about a persons digital life is a concern of a different kind, because of the scope of that search. It’s not a logical extension in the minds of most people who understand that magnitude of difference. I really hope I can convince you too!
I don’t think that border patrol was (in any meaningful numbers) catching financial crimes because people brought their bank accounts or private letters across borders. I really do not buy that this is a necessary step to fight crime at all (if it were, where are the unsolved crimes? What tragedies would have been prevented?) I think this was catching people moving cash/drugs/weapons off the grid and it can still function in that capacity without forcing digital searches.
Instead, this just grossly invades the privacy of tourists who don’t think to bring a burner phone.
I get that you don't think that is the case, but you're not really explaining why you believe so.
> but to be concerned about a persons digital life is a concern of a different kind
But as I said, they're just inspecting the same thing they've always been inspecting. The medium is different and it incidentally happens to be housed with a bunch of different data that historically was kept separate, purely for technological reasons.
You're implying that the cause here is "concern over a person's digital life" but you present no statement or proof that's what these policies are actually aimed at. I think it's fairly obvious that it's a simple reconfiguration of a policy to adapt to changing habits. And if it's not obvious I think the statements from government agencies explaining these policy changes shed further light on why it's being done. But you need to have a reason you believe this to not be the case. It can't just be.
Let's review some statements that hit on some of the above points:
Here's Canada, actively instructing people about to handle sensitive information: https://www.priv.gc.ca/en/privacy-topics/public-safety-and-l...
>Individuals entering Canada who are concerned about how this policy might be applied may wish to exercise caution by either limiting the devices they travel with or removing sensitive personal information from devices that could be searched. Another potential measure is to store it on a secure device in Canada or in a secure cloud which would allow you to retrieve it securely once you arrive at your destination.
Here's New Zealand's review of why they're changing the law: https://www.customs.govt.nz/globalassets/documents/c--e-subm...:
From page 63:
>Customs’ interest in relation to digital files is in the following enforcement areas:
> * Intercepting prohibited or restricted items
> * Identifying infringements of intellectual property rights
From page 64:
>Our Act does enable us to enforce the law in relation to the following prohibited goods when they are in a digital format:
> * Objectionable material and images – “objectionable” has a very broad definition under the Films, Videos, and Publications Classification Act 1993, and can capture material ranging from violent or degrading sexual images to material that encourages criminal acts or terrorism
> * Designs for weapons or for other items of potential military use
> * Designs and blueprints for making nuclear, biological, chemical or radiological weapons.
Pretty far away from "concerns about a person's digital life."
>in the same way I don’t think that the right to bear arms allows you to train and arm a private army with tanks and fighter jets.
This analogy in no way is relevant to data organization and transmission. It's pretty hyperbolic and distracts from any point you are trying to make.
I mean, to me the fact that they acknowledge that anyone serious about privacy can take measures to circumvent it pretty much blows the story that this will be effective at catching people smuggling weapons designs or other serious crimes out of the water.
>This analogy in no way is relevant to data organization and transmission. It's pretty hyperbolic and distracts from any point you are trying to make.
I’m trying to make the case that clearly magnitude affects whether or not something is a reasonable extension, perhaps poorly. But you’ll surely concede that doing something at increased scale often changes the nature of that thing? And that’s what I’m saying here, you aren’t just giving away what would have been in your suitcase, you are giving away the keys to your house, car, mailbox, safety deposit box, diary and family photo album. That means it changes the nature of the request, and can’t be considered along the same lines as a suitcase.
Okay but there's no "sake" about, that's literally what we are trying to establish. If you don't believe that a logical progression of existing laws and processes into new mediums is there reason why these policy changes are taking place, contrary to basic reasoning and explicit statements from these governments while pushing for these changes, you have to have an actual reason why you believe this not to be the case.
>I mean, to me the fact that they acknowledge that anyone serious about privacy can take measures to circumvent it pretty much blows the story that this will be effective at catching people smuggling weapons designs or other serious crimes out of the water.
There are plenty of ways to get away with murder but that doesn't mean we take it off the law books because of its efficacy. That's a really silly view point.
>But you’ll surely concede that doing something at increased scale often changes the nature of that thing?
As I said in my original post, it's worth discussing and certainly worth finding a solution too. But the particular governments we're talking about have well stated reasons for their policy changes, they aren't doing it to be draconian. We all started clumping our data together. Governments didn't increase the scope of what they were looking for.
>That means it changes the nature of the request, and can’t be considered along the same lines as a suitcase.
But that's exactly what it is. There's a reason we have have "files" and "folders" as basic user data organization schemes. Border policies haven't actually changed in any of dramatic fashion. Again we just started storing more data by other data, data they were already inspecting. You might argue that this little fact is the basis for why the policy should be changed, but you have to actually argue it.
If you bring an electronic device in to Australia full of 0s and 1s that can be decoded to display as pictures of bananas, customs will just think your a bananaphile and shuffle you along.
Digital goods are fundamentally different.
You can’t cross the border, buy a suitcase, then download a bunch of bananas to fill it.
You can cross the border, buy a phone, then download instructions from your terrorist boss.
Whatever else these digital searches are I don’t know, but they’re certainly ham fisted to the point of embarrassment for the agents and agencies.
If you have something to hide, it would be trivial to store it on a web storage service that those searching you would have no way of knowing you possess (how would they know you have an account on some obscure storage platform that you paid for with monero? Or even just information stored in S3, they would need a list of all users linked to passport numbers for every service available around the world, since if they don't block VPNs you'll just use a service not available in NZ). So you wouldn't have it physically on your device, but you would be able to access it just as easily in 2018.
Or a free solution would be a noise.raw file that is actually an encrypted volume (many encryption formats are indistinguishable from random data).
At this rate, I wouldn't be surprised if in a few years, a person needs to punch in their SSN (or the equivalent in whichever country we are talking about) simply to access the internet and any service on the internet.
But for today's case - this is just security theater. Just a reminder to average Joe that he can be harassed anytime.
True. It went from zero to.. zero.
* Invasive species. This includes plants, not just animals.
* Drugs
* In times of known or potential epidemics, screening people for obvious sickness.
* Weapons or tools that could be used for the purposes of terrorism.
Why would you say that there's no reason to inspect what people are bringing into your country?
2) None of those are digital, so your earlier justification is moot anyway.
As to your first statement, ignoring how disingenuous it is, if those standards did have a reasonable justification for applying them to inter-regional travel the fact that we do not apply those policies to inter-regional travel does not negate the justification for applying those policies on the international border. It's not binary.
So what is that justifying difference that you seem to think exists?
+ Communications with my lawyer
+ My private health information
+ My detailed financial information
+ My communications with significant others which may be of various degrees of sfw
+ My work files, including proprietary or secret information
Any of those things would absolutely require a warrant, and may even require a specialized warrant in some cases (communications with my lawyer, health information).
Sure, any country is welcome to violate that norm, just the same as any country is welcome to force it's people in labor camps for insulting Dearest Leader. The rest of the world is also welcome to respond appropriately.
Can you give me an example of a non-EU country, or an EU country admitting a non-EU citizen, that has strict rules on how a visitor must be treated?
Again, this law will primarily inconvenience / harm law-abiding folks, while not preventing the "bad guys" from doing what they want.
That means, that you should expect your device and all access tokens on that device compromised.