8 ms·
What's a reasonable way to protect yourself here? Other than wiping and restoring. Are there any encryption tools, or ways to keep your emails and other data on
by luiperd 6y ago
What's a reasonable way to protect yourself here? Other than wiping and restoring. Are there any encryption tools, or ways to keep your emails and other data on your device safe?
Can CBP make you unlock your own phone?
- kortex 6y agoFrom all I've read, they will certainly try, even if they don't technically have the authority (I don't know if they do or do not, but CBP has broad authority). Encryption also incurs their ire. You need to either wipe the phone or have stegnograpic volumes. It's a sad state of affairs.
- traceroute66 6y agoOne word. Jurisdiction. What is on the device in their hands, on US soil, is subject to their stupidities, whatever those stupidities may be on the day their grubby hands get hold of your phone. What is located remotely, in a privacy conscious jurisdiction, say Switzerland, is outside of their remit. I know US courts like to think they have power over the world, but they don't. US courts and US law power stops at US borders. The trick is to make sure nothing gets cached on your local device (including authentication credentials, obviously). A bit like the old Thin Client computing really. If you want to go one step further, don't travel with working credentials. Rely on someone outside of US jurisdiction to provide you the last piece of the jigsaw in a secure manner once you are in a safe location.
- aneutron 6y agoWell, in theory, yes. In practice, there have been recorded instances where the US Government has asked people to disclose their social media [1] and in other ones (I failed to find the source) refused access to people who refused to log into their accounts. Also, if you're a non-american traveler, all the constitutional rights you're afforded as an American don't apply. So they can pretty much ask whatever and refuse you access for any reason. It's like the US is becoming more and more like China. But it's a worlwide trend, really, with old men screaming "We're gonna be in the dark !" ... It's thoroughly depressing. Edit: As written down in the comments, the part about foreigners' rights is wrong. See comment for correction. [1]: https://www.theverge.com/2016/12/22/14066082/us-customs-border-patrol-social-media-account-facebook-twitter https://www.theverge.com/2016/12/22/14066082/us-customs-bord...
- dragonwriter 6y ago> Well, in theory, yes. No, it's not true in theory, either.
- 2OEH8eoCRo0 6y ago>if you're a non-american traveler, all the constitutional rights you're afforded as an American don't apply. False https://www.maniatislawoffice.com/blog/2018/08/do-non-citizens-have-constitutional-rights/ https://www.maniatislawoffice.com/blog/2018/08/do-non-citize...
- aneutron 6y agoThank you, I was under the misconception that as a foreigner I wasn't afforded these right s.
- iso947 6y agoMany Americans don’t get those rights in practice - although I don’t think there have been any cases of the third ammendment being broken recently.
- samatman 6y agoIn fact, the Third Amendment came up recently, when some hotels in Washington DC kicked the National Guard out. Their right to do so wasn't challenged, so there's one plank of the Bill of Rights which hasn't rotted through...
- iso947 6y agoI’ve always considered America’s uniform worship to make the 3rd irellevent, I guess it goes to show that ensuring rights via law is good even if you think it unnecceraary
- yibg 6y agoBut can’t they just deny you entry? I mean you can have all the rights but if they can just let you in (especially if you live in the US), that’s still a pretty big lever.
- marcrosoft 6y ago> US law power stops at US borders. This also means US companies can ignore GDPR.
- Shared404 6y agoAs long as they don't do business in Europe.
- marcrosoft 6y agoLet me be more clear. If a European buys a product from a US company and that company operates and is incorporated in the US then GDPR can be ignored. The EU would say otherwise but fortunately they don’t get to police the world anymore than any other foreign country.
- rebuilder 6y agoTrue, but if you are on US soil, you fall under US jurisdiction for, e.g., contempt of court.
- dragonwriter 6y ago> US courts and US law power stops at US borders. No, it doesn't. US “law power” extends as far as the enforcers of that power are able and motivated to extend their reach, which very often extends far outside of US borders. OTOH, there's places and contexts where that reach tends to encompass more casually and with less case-specific motivation.
- jorblumesea 6y agoThat's not really accurate. The US, due to its historical position as a super power, has extradition treaties for many countries around the world. If charged with a crime in the US, your physical location might not matter. It very case/situation specific. The host country might block extradition for various reasons, but often, the US has global reach.
- anonunivgrad 6y agoThat’s not true. A US court can order you to go to another country, retrieve documents, and bring them back to the US, even if you doing so is in violation of that other country’s laws. This is more reasonable than you might think, because otherwise companies and individuals could hide all of their incriminating data in such ways and evade accountability under US law. Further, being involved in any violation of or conspiracy to violate American law is a crime, even if you never actually step foot in the US. Companies can be sued in US courts for actions they took overseas. None of this is particular to American law, the same is true in any advanced legal system. American law just has particular significance because of American economic preeminence. Some of the most vexing legal issues, both theoretical and practical, surround this cross-border application of law. And I guarantee you wouldn’t like the result if countries took a strictly physical, territorial approach to their legal authority.
- pmoriarty 6y agoIt's interesting that you single out Switzerland as a jurisdiction that the US can't touch. It used to be that Switzerland had iron-tight bank secrecy regulations that the US (and the rest of the world) really couldn't breach. Yet over the years the US has managed to force massive changes on Switzerland's financial institutions, and for decades now there's been much more transparency, and Switzerland's banks are not nearly as secret nor as effective at hiding assets as they used to be. Apart from getting other countries to change their financial regulations to be more in line with what the US wants, the US has also been very successful in doing the same in regards to issues like drug enforcement, human trafficking, child molestation, and many other issues. So, depending on your threat model and what data you're trying to keep private, I wouldn't count on any jurisdiction ultimately being and remaining safe for your data. Something else to consider is that once your data is out of your hands, it's easy for whoever has it to make a copy to archive and work on at their leisure. Even if they don't share, sell, compromise, or trade away that data today, that doesn't mean they won't do so at some time in the future when laws, technical capabilities, or incentives change.
- Youden 6y agoI think you're drastically overstating what happened regarding Swiss banking secrecy. Switzerland agreed to FATCA, which only applies to people subject to US taxes and allows those people to refuse to have their information shared with the IRS, in which case the IRS has to specifically request it. The "massive changes" you mention essentially consist of banks asking you if you're a US person and then, for the big banks, making you fill out a bunch of paperwork and for the small banks, refusing to open an account for you. If you're not subject to US taxes, there's no effect on you whatsoever. I think the _much_ more interesting thing, which is unrelated to the US (as it's not a party to the agreement) is the AEOI [0]. Anyhow, Switzerland is still very much a sovereign nation and the fact that it has agreed to give limited financial information to the US, with consent of the account holder, does not change that. A fun bit of proof: copyright infringement, one of the US's pet peeves, is still very much alive in Switzerland. It's your legal right to make as many copies of something as you want and give them to your friends and family [1]. And ultimately, the US' power over Switzerland is quite limited due to the referendum system. Any change they'd like the government to make has to have the consent of the people. The Swiss are quite protective of their privacy so I don't see the US having any success weakening that. [0]: https://www.efd.admin.ch/efd/en/home/themen/wirtschaft--waehrung--finanzplatz/finanzmarktpolitik/automatic-exchange-of-information--aeoi-.html https://www.efd.admin.ch/efd/en/home/themen/wirtschaft--waeh... [1]: https://www.admin.ch/opc/en/classified-compilation/19920251/index.html#a19 https://www.admin.ch/opc/en/classified-compilation/19920251/...
- gred 6y agoCalling your congressman makes the most sense, IMO. As technologists we have an inclination to jump to the technical workaround, but the workaround should not be needed to begin with.
- mlthoughts2018 6y agoThis would have no effect. “Call your congressperson” should never, under any circumstances, be considered useful or effective. Policies are decided in the interest of plutocrats. Very occasionally when it would generate good PR or if disenfranchisement gets too bad, some retroactive number fudging will be used to whip up a press release or report on the number of calls or letters to a congressional office, as if to make it seem like a policy was affected by democratic consideration of constituents, but that is purely theatrics and publicity and has no bearing on or connection to the way congressional offices pursue legislation.
- gred 6y agoThe alternative cynical view (which I subscribe to) is that this small-to-medium amount of pain can sometimes tip the scales in the right direction. There are of course other tools, but they require a bit more dedication: regular donations to think tanks and lobbyists who agree with you and can spend time schmoozing/convincing congressmen, regular donations to legal foundations who challenge overreach in court, and of course voting when the time comes.
- mlthoughts2018 6y agoWhat part of my response was cynical?
- techbio 6y agoFor the uncertain: cyn·i·cal /ˈsinək(ə)l/ 1. believing that people are motivated by self-interest; distrustful of human sincerity or integrity. "her cynical attitude" 2.concerned only with one's own interests and typically disregarding accepted or appropriate standards in order to achieve them. "a cynical manipulation of public opinion"
- tazjin 6y agoDon't go to the US.
- robin_reala 6y agoAvoiding visiting the US is a good start. If you live there already, I guess avoiding leaving?
- the8472 6y agoAnd don't come within 100 miles of the border.
- aaomidi 6y agoWhich is near impossible if you live in any city with an international airport.
- leesalminen 6y agoDFW and DEN come to mind.
- peterwwillis 6y ago2 out of 3 people in the U.S. live within 100 miles of a border zone. About 200 million people. https://www.aclu.org/other/constitution-100-mile-border-zone https://www.aclu.org/other/constitution-100-mile-border-zone
- 0xcde4c3db 6y agoThe rule is apparently phrased as being within 100 miles of any "external boundary", which doesn't just mean borders with other countries, but also the entire coastline, including the coasts of the Great Lakes. Most Americans live in this area.
- fauigerzigerk 6y agoI think the rule applies to incoming travellers only, not everyone who happens to be near the border. The Fourteenth Amendment doesn't just lose force for everyone living in one of the coastal cities.
- nwallin 6y agoThere are a plethora of full disk encryption tools. Linux has dm-crypt, Windows has BitLocker, iOS and Android have it. I assume there's a way to enable full disk encryption in OSX but I'm not familiar with the ecosystem. They can force you to unlock/provide password to your devices if they have probable cause that there is evidence of a crime on the disk. Typically this is because someone looked over a shoulder and saw child porn on the screen. I'm not aware of anyone being forced to provide passwords or keys in any other circumstance, but I'm not an expert. Encrypt your data, keep your devices off. Do this even if you have "nothing to hide".
- peterwwillis 6y ago> What's a reasonable way to protect yourself here? Contact your representatives in government and tell them to make legislation banning this practice. Donate to the ACLU.
- 762236 6y agoFedEx. Don't carry the devices on you.
- mcguire 6y agoTwo words: tamper evident packaging.
- inetsee 6y agoIf you're seriously concerned about the security of the information on your phone, you could look at the NSA's Security Configuration recommendations. [1] These recommendations are intended for "Apple iOS 5 Devices", and many of the recommendations sound like they would not be appropriate for the average traveler. [1] https://apps.nsa.gov/iaarchive/library/ia-guidance/security-configuration/operating-systems/security-configuration-recommendations-for-apple-ios-5.cfm https://apps.nsa.gov/iaarchive/library/ia-guidance/security-... What I would recommend is to keep as much information off your phone as possible. Save emails on your personal computer, and delete them from your phone before traveling. Log out from online accounts like web-based email accounts before traveling. Don't have sensitive files on your phone; encrypt them and download them from a server somewhere that you control. Finally, as "sumanthvepa" recommended, "keep all interactions with (Border Patrol Agents) on a cordial basis and cooperate immediately and completely when ordered."
- M2Ys4U 6y ago>What's a reasonable way to protect yourself here? Refusing to travel to the United States would prevent this from happening.
- neltnerb 6y agoYou could try to push your luck, if you're an American citizen. More realistic is to just wipe your phone and reset it to factory settings using a throwaway google account. They probably won't ask for it but that way it looks unremarkable and you don't have to waste your time arguing with them. I wouldn't even bring a computer across the border anymore, at least not for a vacation. I always use full disk encryption and I am not interested in giving the CBP (which I'm sure has great IT security) copies of all my confidential work documents to just leave sitting around for the next 20 to 75 years waiting to get exfiltrated by who knows what hacker group will get to it first.
- Marsymars 6y agoChromebooks are great for this - they're fast to wipe and fast to set back up. I travel with a Chromebook and a phone that I wipe before crossing international borders.
- hughw 6y agoWiping and restoring is underrated. I feel pretty safe about my Apple encrypted cloud backups. It's a minor inconvenience to wipe the phone before crossing the border, and restore on the other side. Now - if they can make you restore in their presence, that would be a big problem.
- Terretta 6y agoEasiest, leverage USB restricted mode: https://www.theverge.com/2018/7/10/17550316/apple-iphone-usb-restricted-mode-how-to-use-security https://www.theverge.com/2018/7/10/17550316/apple-iphone-usb... Reasonable: use Apple's free device management app and lock out sync to any other / unknown hosts, along with a few other settings. Note that 1Password for iOS has a travel mode for this situation as well.
- jomnasi 6y agoVeraCrypt encryption tool for one, offers hidden encrypted volumes. If I remember correctly, you would have 2 passwords for the same encrypted container. One pw for a decoy volume if forced to decrypt your files such as in this case, other pw would reveal your true data.