Sounds like this lawyer arrived at the same plan I did:
Refuse the request, file a lawsuit, and contact the media when released to shame the government that saw fit to violate my rights.
Sounds like this lawyer arrived at the same plan I did:
Refuse the request, file a lawsuit, and contact the media when released to shame the government that saw fit to violate my rights.
Border services generally have extensive but constrained powers - in the US, they're limited in how far from a border they can exercise authority. So they don't get to arrest the administrator directly, or go and confiscate an access key sitting in Edmonton. They can still demand that whoever is at the border arrange for unlocking, and can probably seize the device if they're refused. But the threat "we'll lock you up until you open the device" is potentially legal, while "we'll lock you up because as a hostage until somebody else opens this" has far less merit. (Obviously, none of this applies if you go someplace where actual hostage takings might happen.)
If the administrator says "I need physical access to unlock that" or "our firm's policy says I can only open devices once they're at one of our offices being used for billable hours", there's no one handy to apply the wrench to. At that point, confiscate-and-image is as much access as anyone can hope to get.
Drill those, though.
Under stress, people fall back on learned patterns.
They aren't going to hit me with a wrench for the decryption password to a cloud-stored blob that's not on the device (and ideally, one they don't know about. Remember the password and the location of the data. Remember to secure-delete it from your device though. There should be an easy "prep for border crossing" checklist that includes this.)
If an LEO (claims to) need access to something and you give him a dead end, it's his job to assume you're lying and find the next legal option available to him.
The real question you should be asking yourselves isn't "How would you outsmart the caveman cop in this situation?" Rather, it's "What can/will you do, as a citizen, to resist the erosion of our civil liberties?" Sadly, I have no easy answers here.
Not sure where you live, but in the US it's actually his first and foremost responsibility to uphold a constitution that says that people are free from unreasonable searches and seizures.
I want to say "clearly you have never used US customs", though I suppose it's possible you have and you are just very lucky.
Spoiler alert: If not cooperating, then BPO not friendly; Else, please proceed.
than when CBP ask for password give it and watch them search the laptop..
You full filled your legal obligation to follow their orders despite the illegality its now their problem they cannot find anything
Note...all social public stuff is searchable on google..tweets facebook postings etc..
CBP never needs a password they are searching with that password for other reasons than the ones they GIVE
Nothing justifies an honest person going to great lengths to do some weird thing quite like "company policy".
Nothing makes officers think twice like the mention of lawyers backed by Apple / Google levels of money.
It's not always feasible, but the most secure way to protect clients'/employers' data is to encrypt the laptop and phone and ship to your destination via standard shipping services, then ship them back the same way before leaving for home. Carry a well used but non-critical burner laptop ($50 Chromebook off Craigslist) and/or phone ($20 Walmart smartphone) with you that won't wreck your world if it's confiscated and searched. If it is seized, take your receipt and go on about your business. When you get to your destination your actual devices will be waiting for you. You can safely forget about the burner devices.
I think the reality we have to grapple with, regardless of rights violated, is that if you want to cross a nation border, it's best to assume that all nations involved will end up with a copy of all the data (hopefully encrypted) you move across that border. In the face of that scenario, how do we proceed?
Still, if you are paranoid enough you can mitigate the danger of your data falling into unsecured hands (at the border or by mail intercept) by using an encrypted shadow volume:
Isn't "mailing a laptop" now counted as sending dangerous goods, due to the battery?[0]
If so, the chances of it being subject to interception and/or search might well be far higher than someone just carrying a laptop in hand luggage across an international border.
[0] https://www.dhl.com/en/express/shipping/shipping_advice/lith...
> RESTRICTED ITEMS The following items are deemed unsuitable for shipment by our services, and are therefore restricted. Any of these items being sent may result in surcharges, delays or confiscation by authorities where appropriate. No damage cover is available with these items:
> [a long list of stuff, including laptops]
So, who here would be happy to ship their laptop internationally without damage cover?
You're confusing "not perfect" with "not good". There's an old saying: when outrunning a bear, you don't have to be the fastest guy, you just have to be faster than the slowest guy.
is that really true? I would expect that they can just perform hardware tampering when you're not present when searching in mailed items, but given that customs might use racial profiling to target you at airport, you may be better off mailing the computer securely, such as using tamper-proof or tamper-evident stickers/bags.
I've only seen two articles claiming evidence of physical tampering - like a hoax about Dell from 2005 [1] and Bloomberg's dodgy story about spy chips from last year [2] - neither of which seems truthy, and neither of which involved mail interdiction.
(Of course, it's widely suspected mailed hardware can be tampered with, but most of the claims/speculation I've read has been about targeted tampering, not dragnet)
[1] https://www.snopes.com/fact-check/keyboard-loggers/ [2] https://techcrunch.com/2018/10/04/bloomberg-spy-chip-murky-w...
On what legal authority?
The border search exemption is about searching, not tampering.
The issue is more that border agents are taking advantage of a law written before the age of computers to use powers the founders probably never intended.
I seriously doubt that there's any legal basis to bug a computer just because it was shipped internationally.
So if the threat model is being asked for your password, not being present when the device crosses is a good mitigation.
(If you've done enough bad things they government is targeting you specifically, YMMV)
Inbound international mail is also subject to search by customs, that doesn't just happen to stuff the owner carries across the border.
Absolutely not. Any time your hardware is physically out of your control is a time when someone could install a hardware keylogger or replace your ethernet card with one that exfiltrates data or whatever.
The most secure option is to travel with an encrypted hdd/phone on you with no way to decrypt them, and separately acquire the private key (e.g. via shipping a secure hardware token which is made to be tamper resistant to a trusted friend at your destination).
If the devices leave your control for more than a few minutes, consider the hardware compromised and never unlock them again.
Laptops simply are not made to be highly resistant to an attacker with physical access, whereas hardware keys are, so it's not a good idea to ship them.
If you do ship them, you'll have to do a physical examination for suspicious hardware at your destination, (as you presumably did when you first received them if you're that paranoid), and it's damn hard to find a good lab for that in some countries.
Your advice is good as a way that's secure for most people's threat models, but it is a far cry from being the most secure solution, and I'd argue it's much less secure than simply carrying them with you.
Do not use a single key; require several keys that are with different people, combined only in the way that you know how. Ensure the people are present to notice if the police try to come in.
In short, the scope of my comment was avoiding a border seizure during travel, not 100% securing your devices from being compromised, which is an impossible goal short of just not using any devices, period.
More and more people are probably doing this so this is going to stop being suspicious.
Whenever I travel internationally on business and need a laptop, I'm required by company policy to bring a laptop freshly wiped by IT instead of my normal laptop.
edit: place a big random data file, which looks like encrypted data on your alibi notebook. Refuse to give password and let the government lab try to find the password..
This is certainly safer, though maybe not possible on the return trip (where you're returning from someplace where you only have access to your laptop). If you need to be this careful, maybe it's best to do your work after livebooting into tails or something like that.
> edit: place a big random data file, which looks like encrypted data on your alibi notebook. Refuse to give password and let the government lab try to find the password..
Funny, but unnecessarily risky if you ask me.
head -c 1000000000 /dev/urandom | openssl enc -aes-256-cbc -a > risky.1Giga.file
would have been considered tin-foil-hatty, and now we're just getting use to itI'm not sure this is good advice. I think it's almost certainly better to have an unblemished record of assertion than a mixed record of assertion and acquiescence. Surely the latter appears far more suspicious.
Edit I'm not saying it's a bad idea to encrypt your drives, just that it doesn't save you from someone determined..
Encryption works great for this usecase, that almost everyone in this thread will be using it for.
People being tortured for their personal phone password by a rando border guard in basically any country, just isn't something that happens, despite what the internet memes would lead you to believe.
Even in supposedly bad countries, I really doubt that this "attack vector" is something that happens frequently.
And for quite a lot of other people, even not being personally detained, but having to acquire new devices is inconvenient enough to compel cooperation. Who wants to buy new devices? Who has a need for two sets? It'd only be a cost of business for someone who does a decent amount of traveling and has confidential information to protect.
But then, that's a trap too because why should people need a reason? Why are only people with business/legal confidential information a protected class?
The answer is not very long. I'd call "a couple days" to be not a big deal, and not at all equivalent to being tortured to death, like the person I was responding to was implying would happen.
So yes, encryption does work, and all that will happen to you is that you could be moderately inconvenienced.
But even that I would expect to be rare. Most border security would just look at your computer, or whatever, not find anything on it (because the thing you show them just looks like an empty computer), and move on their way.
The narrative that I was responding to was this idea that technology solutions can always be bypassed, by torture or something, therefore technology solutions are worthless. And that's just not true.
An extremely effective technology solutions to an incompetent border guard that is interrogating you is for all your devices to just appear like there isn't anything on them, like a new factory default computer that you just bought.
A guard will just look at that, not see anything, and then move on to the rest of his crappy job.
I think a couple days is good enough because people will miss holidays, work, plans etc. That's Western nations "torture" equivalent of a wrench
Ok, and does this happen in real life?
The answer is no. It does not. In almost any western country in the world, the low paid border security guards are not detaining people in mass for days on end.
This stuff just isn't really happening to any large degree.
[0] https://nakedsecurity.sophos.com/2018/09/04/how-refusing-to-...
The answer is "not that often".
The example you gave was of someone who was suspected of murder.
The amount of people who are in the population of "people suspected of murder, and are jailed for not giving up their password", is a very small population size.
I never made any claims about what is or it is not OK.
The only claim that I am making is that this whole "XKCD wrench meme" is dumb, and that encryption actually works really well for the vast majority of people in the vast majority of usecases.
That's all. Encryption works, and you are not going to be tortured, or locked up forever, because you refused the order of a low paid border guard.
Such situations are extremely rare, and it is annoying that people keep bringing them up when they basically don't happen to anyone.
What country do you live in that has to worry about people being tortured to death on a frequent basis?
This stuff just doesn't happen often, despite what a silly XKCD comic would lead you to believe.
Encryption actually works pretty damn well, for basically all usecases that a normal person would come across.
The world is not a James Bond spy move.
Extraordinary rendition to the Guantanamo Bay is what concerns me.
That said, the most practical scenario here is to keep your important files secured somewhere else, cloud or elsewhere, and when they ask you to unlock your phone or laptop you say "Sure!" Because there's nothing to find and you're compliant and helpful so they quickly let you go after a proforma search.
Yeah, there is no James Bond outside the books and screen. But thermorectal cryptanalysis is out there and still beats most of cyphers with ease. And it's not letal!