Court Rules No Suspicion Needed for Laptop Searches at Border
aclu.org
aclu.org
You think border means at the point you cross into another country.
That's not what it means. Government can now do this behavior a HUNDRED miles inland from a border. You could be just driving across town, to or from work, and they can use this border search law because you are a hundred miles from the border.
Oh and the border also includes the ocean, doesn't have to be another country.
https://d320ze5h7gg57a.cloudfront.net/sites/default/files/we...
100% of NY, NJ, Florida and half of Texas is subject to these searches as their state is blanketed by the hundred mile limit.
edited to correct hundred instead of hundreds, bad memory
https://www.aclu.org/national-security_technology-and-libert...
There was a guy who was almost beaten to death at one of them for refusing to comply, there is a youtube video somewhere of it.
News like this is buried just like all the gun deaths every week in Chicago, it never makes national news for some reason I don't quite understand.
Also: be careful that we're talking about the same thing. There are CBP searches that protect border integrity and search for contraband, and then there are ICE checkpoints that aim to catch illegal immigrants. In practice, ICE's authority is nothing like CBP's: CBP's is much more potent, and CBP is what this article is talking about.
http://www.azcentral.com/news/articles/2009/04/17/20090417bo...
Additional wrinkle in this case: a dog authorized the search.
It's basically a check point. The line to get through it can take a while and some vehicles are heavily searched. I've never had that opportunity fortunately.
For CBP to search you under the aegis of border security, you must have recently crossed the actual US border. The law doesn't require CBP searches to occur at the actual border; for instance, there may be so many possible crossing points at e.g. the Canadian border that, logistically, search only makes sense at some chokepoint 20-30 miles from the border. But they can't search people at random. The CRS says so, and, 30 years before that, so did SCOTUS.
They didn't ask to check my laptop or anything, but did want ID etc.
Can't talk to the legality of it all but they do exist.
But if CBP could not convince a judge or jury that you'd crossed the Canadian border, and demanded a search of your vehicle and found e.g. an eighth of weed, that evidence could probably be tossed in court; CBP needs both the fact of your crossing of the actual border and a reasonable suspicion to search you.
Having lived in both Europe in the US for large part of my life, I can tell you that this completely misses the mark.
Yes, you can be ID'd, but what law enforcement can get away with in the US would be inconceivable in most of Western Europe. I was never afraid of the cops before I came to the states.
Edit: Spelling.
At the border, sure, but inside the country?
But I guess it was speaking English without an awful accent. :-)
Denying the Holocaust and using Nazi symbols is illegal in Germany, but "papers please" is normal? I think they learned the wrong lesson.
I am now 32 years old. I have been in a police stop when driving my car only twice (and one of those was a mistake, I thought they wanted me to stop, but they actually meant another car).
I have never been controlled or ID checked by the police in any way when not travelling by car. Exceptions are border controls, of course. And private entities wishing to check my age: discos, liquor stores and so on.
On another note: I'm really tired about all this attitude we get from Americans regarding Nazi symbols and free speech. Maybe take a minute to contemplate why we have those laws?
"Because of Holocaust" is correct, but not what I'm getting at. We have those, because Americans (together with the other Allied Powers) forced us to after the war.
Unfortunately Americans have this tendency to think that their system is the very best and can't imagine why anyone could or should have another system, despite the fact that everywhere they were involved in nation-building they actively promoted other systems.
If you're saying that absent any other reason, you would have to have recently crossed a border for the initial stop to be legal, maybe you're right. But random checkpoints for intoxicated drivers happen everywhere, and are legal.
As you point out, Border Patrol are fully sworn law enforcement officers and can therefore enforce other laws besides mere border protection statutes.
However the legal requirements to perform a search of a vehicle (incl. the need to have crossed the border) are different from the requirements to stop a vehicle to interview the driver (which any LE can do incl. Border Patrol), which is one of the reasons that DUI checkpoints are legal in some circumstances.
From 'rayiner's post, here's the 3-part test suggested by CRS:
* You have to recently have crossed the actual border
* "an agent should know that the object of a search hasn’t changed"
* Reasonable suspicion must exist
The first bullet here torpedoes the idea of a "100 mile wide Constitution free zone". But: that's also just CRS's interpretation; CRS is simply a Congressionally-funded think-tank. Without digging up the SCOTUS cite, I'll suggest that the judicial branch restrictions on these searches are even more severe.
One way to think of the "100 mile" concept is that the USG probably has the authority to put a border control check that would have applied to someone crossing the border anyways as many as 100 miles from the border, rather than at the border itself.
http://scholar.google.com/scholar_case?case=6933260753627774...
Here is the key quote, taken from section 273:
But the search of the petitioner's automobile by a roving patrol, on a California road that lies at all points at least 20 miles north of the Mexican border,[5] was of a wholly different sort. In the absence of probable cause or consent, that search violated the petitioner's Fourth Amendment right to be free of "unreasonable searches and seizures."
Edit: Reading through the decision, sections (pages?) 280-285 briefly summarize some of the conditions under which warrantless searches are permissible. This is very interesting reading, thanks for the heads up!http://www.youtube.com/embed/WVMZUgmrJrk
Ended very badly for them. Very badly.
So cite all the SCOTUS you want, police are doing whatever the hell they want in that 100 mile zone including false triggers by dogs that are proven wrong most of the time.
I'm not arguing that CBP doesn't abuse the law, but the notion that there is a "100 mile wide Constitution-free strip" of the US is harmful to citizens, who could be misled into believing that (a) they are required to consent to searches and (b) that they won't be able to fight the government if they are searched illegally. It is important that people know their rights, whether or not those rights are invariably respected.
I'm well aware that dog alerts are very questionable and are (arguably) regularly used as a pretext for illegal searches, but what you do in these situations is comply with ALL lawful orders (including GET OUT OF THE CAR) but decline to consent to searches. If you're not sure whether an order is lawful, you comply and let the lawyers and judges sort it out later.
Or put differently, "idiot."
There is a good argument to be made for this being civil disobedience in that he was refusing the orders of law enforcement officials, but in this particular case the evidence later showed that (roughly) A) the officers ordering him out of the car had no legal authority to do so and B) the officers who did have the legal authority to do so didn't actually order him out before breaking in, tasing, etc. At his later trial he was found not guilty of all the charges against him based on this - I don't know if civil disobedience was even brought up but I doubt it.
An agent provocateur a law enforcement agent who infiltrates a group. Once there, they get violent in order to justify reprisals against the group.
Of particular note: searches of passengers on trains from New York City to Chicago.
Whatever the permissible scope of intrusiveness of a routine border search might be, searches of this kind may in certain circumstances take place not only at the border itself, but at its functional equivalents as well. For 273273 example, searches at an established station near the border, at a point marking the confluence of two or more roads that extend from the border, might be functional equivalents of border searches. For another example, a search of the passengers and cargo of an airplane arriving at a St. Louis airport after a nonstop flight from Mexico City would clearly be the functional equivalent of a border search.[4]*
There are certainly important differences: the court gives the example of a search of passengers that definitively crossed a border and who are searched where they disembark.
That being said, since NY is a major international travel hub, the searches described in that article might qualify as "functionally equivalent" to border searches. In any case, I think it's a stretch to say that DHS treats everything 100 miles from the border as a "Constitution-free zone". Have we seen equivalent searches being performed in Georgia or Virginia?
And yes, it is possible to find places in the country, even in the 100-mile zone, where DHS is not engaged in abusive activity. That's cold comfort to folks who have to deal with them when they are.
ETA: if you're wondering about international train travel, like from Canada, I've taken one of those trains, from Montreal to New York. (Very scenic route, right down the shore of Lake Champlain.) The border-crossing inspection happened in Vermont, outside St. Albans, within minutes of where the train crossed the border. That's what "functionally equivalent to a border crossing" means, if it means anything at all.
I don't disagree with you that DHS operations are often abusive, and I have even suggested that the examples cited by that article might not be justified as "functionally equivalent". I do think, however, that the idea of a "Constitution-free zone" isn't a useful concept for describing DHS practices.
There are dozens of immigration/law enforcement checkpoints routinely deployed around the U.S. They stop all persons and feel free to check them for suspected illegal immigration, drugs, and so on, with absolutely no reason to believe the searchees have ever crossed the border.
For instance, the Border Patrol runs a check near Camp Pendleton, California, about 70 miles north of the Mexican border. You can even check in with Foursquare:
https://foursquare.com/v/i5-border-patrol-checkpoint--weigh-...
All cars on the interstate are stopped, any time they feel like it, and searched or not as the Border Patrol desires. No suspicion exists or need exist. Most of those stopped have not crossed the Mexican border in years, or ever. And no, none of it is illegal in any way.
Or compare, if you like, the EXIT searches that Customs is now doing at many border crossings - people who are attempting to (but have not yet) exited the United States. By definition, they aren't entering the U.S. and haven't crossed any border, but again, they're being searched, entirely legally, every day, and woe to you if you attempt to resist, as author (and now convicted felon) Peter Watts will be happy to tell you.
Simple rule of thumb: if tptacek says it, you can ignore it.
The last sentence in your comment is simply incorrect.
(p23, https://www.nyed.uscourts.gov/sites/default/files/opinions/1...)
This is in the middle of a discussion of carrying lawyer-client privileged documents over the border; the judge says you should have no expectation of privacy because other countries may conduct invasive searches too. As advice, it's hard to disagree, that's where we are now; but surely two wrongs don't make a right?
It would be obviously wrong for police to confiscate your money because you were walking towards a rough part of town where you might be robbed. Yet that is the kind of logic the judge applies here; he relaxes the responsibilities of the US govt by invoking hypothetical actions by others. The example he cites was not even a normal border shakedown, but a specific action that was signed off by a government minister; do unusual acts like this change expectations of privacy in the normal course of events?
"Since the founding of the republic, the federal government has held broad authority to conduct searches at the border to prevent the entry of dangerous people and goods. In the 21st century, the most dangerous contraband is often contained in laptop computers or other electronic devices, not on paper. This includes terrorist materials and despicable images of child pornography."
Judge Korman is quoting Michael Chertoff, Searches Are Legal, Essential, USA Today, July 16, 2008, at A10.
If one wished to bring digital contraband into the US, why oh tell me why would anyone ever bring it physically over the border on a machine?!?
We invented a network of networks that makes this rather easier to securely do quite some years ago. :@ why would anyone think that contraband-based searches make sense here?
However, if you do want to implement a total surveillance policy this isn't completely stupid, because it helps fill in one of the NSA's blind spots.
It seems to me judges are starting to be co-opted by the corrupt power in US, too, lately. It's probably because many of them are starting to be given positions by corrupt administrations that are in favor of the surveillance state. This is also why I'm terrified about Obama naming any Supreme Court Justices by the time he leaves Office. The current Supreme Court is definitely not perfect, but I think so far they've erred on the side of privacy. I worry that balance will change if Obama gets to name 1 or 2 Justices.
As an example, ACLU had a talk at 30C3 where they mention Valerie Caproni, FBI's top lawyer until 2011, and how she was very focused on increasing surveillance capabilities for the FBI through "legal backdoors". And then she was recently named a federal judge in New York. I wouldn't be surprised if this was her giving this ruling, but just goes to show how good judges are starting to be replaced by bad ones, in favor of the surveillance and police state.
http://www.youtube.com/watch?v=txRdOjgokQ4&feature=youtu.be&...
http://www.amazon.co.uk/Drug-Warriors-Their-Prey-Police/dp/0...
Everything this book discusses is going on now, under the guise of combating terrorism. It is like there is a general blueprint for creating an authoritarian state, and it doesn't require a grand conspiracy, only the repeated short sighted actions of corrupt people with the same flawed worldview. It's like an unconscious conspiracy.
These policies have no legitimate reason to exist, and can perhaps only be explained by a combination of paranoia, ignorance, and incompetence. It would stand to reason that any terrorists or criminals foiled by these methods would tend to be of the exceedingly dumb variety.
Hell, there are plenty of people dumb enough to video themselves or friends breaking and entering, beating up people and stabbing people, stealing cars, and the like and POST THESE VIDEOS TO YOUTUBE OR ON SOCIAL NETWORKS.
People do in fact cross borders with ridiculously incriminating things on their laptops and phones, such as photos of the kiddie sex tourism, email or logs of chats from the person who talked them into carrying drugs, and things like that.
My response was trying to say that he's way off in his understanding of what people of average intelligence do when they do criminal things. There are plenty of arguments one can use to make a plausible case against widespread border searches. The argument that basically no one is dumb enough to carry a phone or laptop with incriminating data across the border is not one of them.
Invading everyone's privacy to catch a few dumb criminals (because all non-dumb criminals would have just sent their data through the internet) is a really really bad tradeoff, because the cost:benefit ratio is too high.
My point was, I fail to see why such people can't be brought to justice via methods that don't involve shredding travelers' personal freedoms, the vast majority of whom are completely innocent.
Policies often have to strike a balance between positive and negative effects. When the negative greatly exceeds the positive, then the legitimacy of the policy should be called into question, even if the policy is effective at achieving its stated goal.
Data can be an extremely personal thing, and rummaging through it or storing it indefinitely, without any cause whatsoever, should be an embarrassment to any Western democracy that engages in the practice.
Buy a QIC tape cartridge, as used on workstations and servers in the 1990's. Get a dyslexic child to label it with 'Snowden Docs' in faux Cyrillic and then carry that with you, in the top of your luggage.
The tape need not have anything on it, although, should you find a QIC drive, you could go for some ASCII art porn that only reveals itself if you pipe the output of dd into od. Obviously, before writing this to the drive, put some adjustments on the tape head so that a correctly calibrated drive won't read it too well.
To make sure they don't accidentally miss the tape, deliberately contaminate it with a substance of interest. A bag of fertiliser should suffice. Before you head off on your travels pop the tape in the fertiliser and give it a good rummage so that it gets suitably covered with a fine dust of known-bad-stuff.
The outcome of carrying the tape can go one of two ways. Either they give you untold hassle for 'just carrying a QIC tape' (as the headline in Slashdot screams) or they completely ignore the tape, in which case you have 'proven' the way to thwart the TSA is to carry secret documents on a legacy format.
The USG does not give a shit if you donate to ACLU or Ron Paul.
It's becoming more and more clear that the USG didn't set up all this infrastructure to fight terrorism. Forgive me for assuming the worst. I'm just connecting the dots.
I'm an Aussie. I have nothing to hide in terms of data on my computer, as far as I know. If I was flying to USA (as an example) tomorrow, I'd wipe my laptop and phone clean, put images on my server, and access them via SSH once I'm through the border... Why the hell do I need to do that?
In all seriousness, I don't think there's anything in particular they're looking for. They're just looking for anything that gives them suspicion, which gives them an excuse to question and investigate you further.
I haven't crossed the border in the past decade, but may need to semi-frequently in the near future.
Still it is outrageous that a court feels this is not a violation of your 4th, 5th, and 14th amendment rights.
Which always makes me think of this:
Bye-bye laptop for a few weeks.
I'll get me coat....... ;)
First of all, if you won't enter your password, they confiscate your computer.
Since I wanted to keep my computer, they opened windows explorer and searched for all JPGs and GIFs. Then they asked me, "What kind of photos am I going to find on here?" It was a female agent, and the conclusion I came to is that they're looking for kiddie porn.
I had no exciting photos on my computer, but I did have a shit-ton of boring photos so it wasted 30 minutes of my time and made me think that they think I look like a perv.
Not to mention, the legality of porn varies drastically over jurisdictions.
For this kind of scenario, I have a 2011ish MB Air that is too small to do anything (4gb RAM) and gets re-puppeted fairly frequently to test the system. When I worked in China, I took my iPad, Bluetooth keyboard, and strongvpn account.
Of course, these are all without me trying to hide anything (the encrypted loopback is mostly a matter of principle, I don't actually have anything stored in it).
Still, this is a bad policy which you guys should try to get repealed. If they do this regularly, they must obviously stumble across home-made porn all the time. None of my sex partners have ever consented to have their naked bodies examined by some high-school dropout border guard somewhere.
Like you say, there is little a spot check could easily and quickly find. Therefor, IMHO there must be another reason. So, what if they are not looking for anything? What if its just to put people under pressure in the hope of having the "suspect" give away signs of guilt? That would be my rational.
Oh, another thing, checking to see that it is actually a laptop and not a banned fruit.
(There's also the "travel loaner laptop pool" concept, and the restricted access for remote people. Works a lot better for an organization than for individuals; this would be kind of an interesting appliance or service for individual professionals and for SMBs.)
Just write data up to its size. Multiple times, just to be sure
Read it from /dev/urandom
It's certainly better than nothing, but not sufficient practice in a business or high-security-professional environment.
An attacker is willing to load custom firmware onto the drive, or to move the chips into a new device, or otherwise read it out raw, and will have access to more material than your dd can write.
The standard should be "can I prove this will work reliably, given all the layers beneath me", and for that, the only adequate answer is physical destruction. You could possibly design a drive where you're guaranteed to know if everything is fully deleted, and as long as you trusted the design/implementation/current-status, you could rely on it, but then you'd have a $100k 100GB SSD. So much easier just to replace old drives, or to guarantee that nothing interesting every touched the disk unencrypted, or ideally both.
Yes, that's why you fill it multiple times. But yes, you can have information leaking in a sector that went bad and was remapped
But the good thing about SSDs as well is that they're much easier to destroy, just microwave it, or provide an excess voltage to it (may need more work than simply connect the power input to wires coming from the wall)
A lot of SIGINT/COMINT gear designed for field use had magic destructo-capability designed in, too. I think after the USS Pueblo, especially.
There are tools called "Secure Erase" that use special functions on the disk to wipe it without wearing it out.
This means your attempt to write the same address 7 times actually goes to 7 different storage locations and the original data might still be stored wherever it first landed.
(Within an organization at the same security level, deletion and then wipe is enough to re-issue a laptop, but not going from top researcher to intern, and certainly not from inside to outside.)
Leave everything up and running on a desktop safely inside your own home and connected to the internet 24/7.
Bring your own barebones laptop with nothing installed on it to COUNTRY_PARANOID_OF_EVERYTHING.
Using X11 forwarding, one must only remember the password to their home desktop in order to gain full access to it and all of it's graphical programs.
https://wiki.archlinux.org/index.php/Secure_Shell#X11_forwar...
c2.com/cgi/wiki?TheKenThompsonHack
Trying to browse your photo collection over a 1Mbps connection ain't fun.
Perhaps he meant "...are NOT an issue." ???
Oh, and whats this assumption about running a safe PC from home? You have read the Snowden stuff, right? And even if you cant go with all that, if you are at the US border, while your PC is in , er, Berlin, who says that as you stand there spooks are at your house raiding all the data they like? You know, if you are of that much interest to the authorities. And if you are not, SD card type thing.
Lastly, if one is all doom and gloom (maybe a bit foil hat) about this stuff, like me, I'd assume the buggers had the data I was worried about anyway, if I at some point it had been on an electronic device with communications capabilities.
If your desktop was on 24/7 and you're the one who set it up, it would be trivial to determine if somebody other than yourself had physically accessed it. Applebaum's computer equipment was turned off when he left Berlin from what I understand.
-------------------------
Encrypt files with a suitably long pass-phrase, upload to some random server somewhere, set home computer to keep over-writing its HD & memory/whatever data-destroying activity you favour.
Travel to other country, buy a laptop from a store selected by fair dice throw, download file and decrypt it.
So far, the reaction on intrusion of privacy by the government from the people was to circumvent it, go underground. A reaction commonly expected from a country like Soviet Union where people had zero say on the rulings and had to be creative to avoid surveillance.
I'm saddened to see a similar attitude in the US.
> riot
~50% of people have already determined that voting isn't worth their time - wise up and get with the program. The jury box has been thoroughly pwned as well. Traditionally, the remaining step is the ammo box. But that lacks popular support because people are well fed, so we might as well try to turn things around this new fangled computational b0x before that stops being the case.
NSA/etc has been fucking with people's rights for so long and I'm surprised that their main building is not yet burned down.
Someone one time said "[..] by the people, for the people [..]".
If you think that your responsibility begins and ends with a simple vote, you're far away from reality. ;)
The last time someone attacked a federal office building it did not end well.
I mean, I agree with the idea that if a Constitutional law professor allows this stuff to happen on his watch, we're sunk. But I wouldn't describe it as "we tried electing a civil libertarian constitution scholar." We elected a "rock star" politician who happens to have taught Constitutional law in a past life, and paid lip service to liberty for his biggest supporters.
Mentioned by Jacob Applebaum in "To Protect and Infect" from 30c3: http://www.youtube.com/watch?v=vILAlhwUgIU
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized"
Would it be worth stashing my phone in my underwear in my luggage in my trunk, then handing them a dumb old flip phone when they ask for my phone? They probably won't search all of my stuff and find the other phone, right?
I don't have anything on my phone that would get myself or others arrested, but I nevertheless want privacy. Would it be best to just give up on bringing a phone with access to any of my real data across the border?
It seems the only way now to keep secret data is :
- to be a top expert in security, be able to assess provenly secure software, have a whole chain of them and constantly keep track of what might have been compromised
- keep the data in a safe, never fly it, never come near a border, never connect to the internet
What would be the next step to make it worse now ?
The company in question doesn't use this policy for all countries, typically just China, Russia and some of the more questionable nations they do business in (Nigeria, Kazakhstan, etc). They don't bother for travel to, say, London.
>In his opinion, Judge Edward R. Korman of the Federal District Court for the Eastern District of New York found that the plaintiffs did not have standing for their lawsuit because such searches occur so rarely that “there is not a substantial risk that their electronic devices will be subject to a search or seizure without reasonable suspicion.”
>Even if the plaintiffs did have standing, Judge Korman found that they would lose on the merits of the case, ruling that the government does not need reasonable suspicion to examine or confiscate a traveler’s laptop, cellphone or other device at the border.
[1] http://www.nytimes.com/2014/01/01/business/judge-upholds-us-...
edit: I find this reasoning quite similar to the recent ruling in NSA surveillance of "[You wouldn't have known about it without the Snowden leak, so you don't have standing since Congress did not intent for you to know about surveillance]".
IANAL, but it makes me wonder if it is sufficient protection to have a password protected/encrypted device.
The news from CCC shows the tip of the iceberg of capabilities including injection-molding hidden radios, JTAG, i2c and hd firmware.
I would also desolder and epoxy over any ports that aren't necessary.
This year, I would expect to see tools to check for hardware tampering (HIDS for hardware) that can checksum firmware and other non-user data areas. I've forked O-S Tripwire (mostly C++) in case anyone wants to take a crack at it.
Are there actually exceptions to this?