Warrantless airport seizure of laptop “cannot be justified,” judge rules
arstechnica.com
arstechnica.com
[The hard drive was searched, and...] After incriminating emails were uncovered
through that process, the agent sought and obtained a warrant based upon the
content of the emails to conduct the search of the hard drive that had already
been completed and to seize the emails that had already been reviewed. Those
mails now form a part of the basis of this prosecution, and Kim moves to
suppress that evidence, arguing that his rights under the Fourth Amendment of
the Constitution have been violated.
Isn't that post-facto application for a warrant precisely an admission that the initial search was illegal?Look for the SIGINT connection. How did they know to seize the laptop, and why did they immediately whisk it away "before" they knew the contents?
If they had detective work in hand at the time of seizure which demonstrated the content of these emails, they'd have been able to get a warrant for the search on that basis.
They didn't search "certain emails", they searched all of the emails on the laptop. It's not improbable that there would be interesting evidence in someone's email after a trip when you expect they will have been up to no good, and it's not improbable that a broad keyword search over those .pst's would find something.
> If they had detective work in hand at the time of seizure which demonstrated the content of these emails, they'd have been able to get a warrant for the search on that basis.
Yes, but they evidently didn't think they needed one: the dominant culture the agents were working in seems to say that this constituted a reasonable search, and that applying for a warrant after the fact was proper - that is the real problem here, and the one the judge is picking up on. The opinion describes this: they had enough warning of the guy's trip that they could decide whether to seize the laptop on the way into the country or on the way out, but decided on the latter to give the guy a chance to generate incriminating evidence, because they didn't think they'd catch him in the act otherwise.
Seriously, this looks more like an everyday process that's evolved in a bad direction than parallel construction. They weren't expecting to have to defend this search procedure.
"...that wherever the Supreme Court or the Court of Appeals eventually draws the precise boundary of a routine border search, or however either Court ultimately defines a forensic – as opposed to a conventional – computer search, this search was qualitatively and quantitatively different from a routine border examination, and therefore, it was unreasonable given the paucity of grounds to suspect that criminal activity was in progress."
That said, I've always been curious (but insufficiently brave) to create a 'bait' laptop which would be a laptop designed to exfiltrate video and audio of everything that goes on around it into a cloud server. Then tweet in passing I finally got some juicy bits and head off on an international jaunt to provide a seizure opportunity.
I might have realized that laptops weren't in common use at the time. I remember his secretary Fawn Hall smuggled documents out in her boots for him. How old school. https://en.wikipedia.org/wiki/Fawn_Hall
The purpose of America is not to make cops' jobs as easy as possible.
Why not make cops jobs as easy as possible?
The down side is that public opinion and policy making are constantly changing. A person who is constantly monitored needs to worry that any activity they take part in today, regardless of how legal/acceptable, may become unacceptable tomorrow. Take, for example, boycotting by Canadian citizens of goods made in Israeli settlements. A year ago one may have disagreed with the sentiment, but it certainly wouldn't have seemed illegal. Today the Canadian government is threatening to bring these citizens up on hate crime charges. (As an aside I am not deeply familiar with this particular issue and am using it only as and example and as described at face value. Its entirely possible that some people have committed hate crimes.)
The Canadian government certainly already has files on some, if not all, of the biggest actors in this movement.
In a truly democratic society we need to tolerate and even bolster the voice of dissent. We claim to value our (nearly) unlimited freedom of speech. But a person who needs to worry that all of their words are recorded and can be used out of context later to condemn them will be less likely to voice their dissent. That loss of freedom is the cost of making police job's as easy as possible.
Don't forget the issue of abuse of surveillance data- see for example NSA and CIA analysts using our databases to stalk their exes, or cops using their legally-acquired surveillance powers in illegal ways to suppress dissent.
And there's another facet that I don't hear discussed enough- Take, for example, the crime of speeding. What if speeding resulted in immediate traffic fines, 100% of the time, with perfect enforcement. Is that how we want it to work? Speeding is always possibile, and always punishable? Or is it actually better to live in a world where speeding carries the risk of traffic fines?
http://en.wikipedia.org/wiki/Life,_Liberty_and_the_pursuit_o...
Cops are people too, and sometimes people are assholes. Really, really big assholes. This is why we have rules instead of a police state. Well, had.
If I understand you correctly, you are implying that we should make the argument that searching everything will result in less effective law enforcement because there will be so much more data that we will miss more things.
If this were true, then it would be an excellent argument -- rather like the argument against using torture in interrogations because it actually does a WORSE job of getting people to tell you (true) information than other techniques. This is in addition to the argument against torture that claims that torture is simply evil and we shouldn't be doing it.
I think that invading everyone's privacy without a warrant and without any good REASON to suspect an individual ("reasonable and articulable suspicion") is simply evil and we shouldn't be doing it. But I do NOT also believe that invading everyone's privacy will reduce the number of criminals caught. I actually think it would be quite effective at catching criminals. The massive amount of data available would be create more work, but investigators would spend time only on people they had vague inarticulable reasons to suspect, and this would be quite efficient. For instance, if you focused just on black males age 17-29 and combed through every email or electronic communication they had ever made, I am sure you could find tens of thousands of felonies -- but such a process would be profoundly unfair. In addition, you can use computers to search through the giant haystacks very efficiently.
I find this an excellent lens to examine issues like this.
I am arguing it won't.
What it does is it makes it easier for the government to manufacture bad guys* to then continue manipulating the public.
[*] How is that done? Gov. agency finds patsy; Gov. agency entraps patsy; Gov. agency blames patsy, says he is a terrorist, arrests/kills/tortures patsy, gets confession, passes new legislation, all in a day's work. If not a patsy, an ally disguised as "enemy".
They had enough warning that he was going to be going through customs to decide whether to grab the laptop when he arrived in the country or when he left it, opting for the latter, so yes, they would have had plenty of time to apply for a warrant if they thought they needed one up-front.
All it said was that he was selling accelerometers, which could be used in a variety of things (i.e. autonomous vehicles, commercial aircraft, etc.):
The defendant was accused of unlawfully selling Q-Flex Accelerometers—models QA-2000-10, QA-2000-20, and QA-3000
There was no statement of intent (in the article at least), so saying these were to be used for weapons seems a bit premature.
It upsets me that we don't learn from what happened in the US and just repeating history while everyone else is making progress on theses particular issues.
https://www.aclu.org/know-your-rights-governments-100-mile-b...
I also heard they put surveillance cameras and licence plate readers all over Massena[0]. There's nothing there. College kids roll through it all the time to go to Cornwall to drink. That's about it.
The nexus with reality of that "100 mile" figure is that it represents the limit of the distance at which the USG can establish a permanent checkpoint --- at which CBP is allowed only to stop people who have actually crossed the border. Some DHS person misspoke when describing that process, and ACLU picked it up as "the USG believes it has border search rights for anyone living within 100 miles of the border". Which is a farcical position.
That's not been true in my experience. I've done some traveling in the southwest and have been regularly stopped at these checkpoints. They are on U.S. highways far from the border and they stop everybody, not people actually crossing the border or who have recently crossed the border.
Now, it is true that their search powers are more limited at these checkpoints than at the border, but they do have the power to stop everyone who passes through. (Whether or not they have the power to question you doesn't seem to be settled, but to try to exercise your right to remain silent is a risky endeavor. Some civil libertarians who have tried to exercise this right have ended up in the hospital.) Which court case are you referring to?
Have you been forcibly searched at any of those checkpoints?
There is a popular series of Youtube videos of drivers refusing to comply at some of these checkpoints.
What they do not have the power to do is conduct a warrantless search in the absence of any evidence that the person has actually crossed the border on that particular trip.
Whether or not you've crossed the border recently seems like fairly ineffective criteria. Are you sure that's the case? Where did you see that?
In reality any such stop is a detainment, and it is being done without any suspicion whatsoever. Exactly like drunk driving checkpoints (think of the children). But of course that's ignoring that our legal system has been turned to Swiss cheese by contradictions.
In this case, the court did not feel that the search was reasonable, citing such factors as the actual search not taking place until after the person had left, and the search taking place far away from the border.
Simply make an encrypted backup and wipe everything before traveling through airports and borders.
what it has always done: Provide free equipment for border agents.
Which helps against a border guard installed hardware keylogger how…? There's been reports of border guards flashing laptop firmwares (no idea how credible they are), which would make "wiping everything" rather difficult (you can re-flash the main firmware, but what about e.g. the Intel Management Engine firmware? That thing is a hardware rootkit by design).
True, but in some countries (such as the UK, under RIPA) it's illegal to refuse to give authorities your password or decryption key. You'd really want to use a decoy disk image with some content; an empty disk on an otherwise used-looking laptop arouses suspicion and would probably lead to further scrutiny.
Or keep your data on a server somewhere and hide the address and key, accessing your data remotely when you get to your destination.
Of course, there's the question of how to make a realistic-looking decoy account that doesn't look suspicious on account of not having any files created in the past year or two, but with a little creativity you could pull it off.
The implication that just because a best-prepared "opponent" can thwart someone, there's no point in engaging the <unknown>-prepared.
Turns out after a quick Google search there are a plethora of articles titled "Why are so many terrorists engineers?"
I wonder if there are many more good terrorists engineers who just haven't been caught yet.
Simply carry around an encrypted local copy that's always secure and available, and never let any traffic traverse an uncontrolled network.
Specifically would that have inoculated him in this instance, where they did a bit-for-bit copy of the HD and then returned the laptop to him?
And wouldn't Apple be destroying the product's reputation and severely harming their own reputation by providing that backdoor access and having it hit the news?
I'm not saying it's impossible, it just seems so unlikely as to not even register on the list of concerns for a typical security-minded individual unless that person is storing nuke codes or something.
They'd be in much safer territory to just not include encryption software with their products at all, unless the whole NSA surveillance thing is so complex and intrusive that they force large OS makers to specifically develop backdoored encryption technology for the specific purpose of encouraging people to store sensitive information on FileVault encrypted drives so that the government to access it at it's will.
But, that doesn't really stand to reason in my mind.
I say "theoretically" because there might be weaknesses or backdoors in any given implementation that would permit decryption. (Hence the discussion of whether Apple's Filevault can be trusted against law enforcement.)
You might also face personal pressure to provide the key to decrypt.