6 ms·
What happens if authorities seize your laptop?
- nekgrim 13y ago1. Backup your documents on Dropbox/GDrive/Whatever (edit: can be you personal server. You can use Truecrypt, and not upload your datas uncrypted. The point is that you must not have the datas on your pc when you pass the border). 2. Wipe your PC. Optional 2.5. Download a bunch of fake personal files. 3. Pass the border. 4. Access Internet. 5. Download your datas.
- lukasm 13y agoI don't trust these services.
- nekgrim 13y ago"Whatever" can include your personal server. And you can store a truecrypt drive, no need to put your datas uncrypted.
- grey-area 13y agoBetter just not to travel with your hardware, or if you have to, travel with something throwaway like a netbook without lots of personal data on it. Otherwise you risk having all your hardware confiscated by border guards and returned months later. Your plan above won't work if they confiscate your hardware as you'll have nothing to download onto.
- Shivetya 13y agoWith the recent history of topics here about the NSA having back doors into providers of services how is uploading your data where you suggest actually going to protect you? If anything, I would go to the point of screwing with border agents by having tens of thousands of pictures of my dogs, kids, flowers, and whatnot, all with naming similar to PICnnnnn or whatever is the current default of most digital cameras. Having them given the wrong doc type would be a nice touch too. Of course why not store your data on a SD card and just pop it somewhere they are not bound to look?
- logfromblammo 13y agoMake sure you include a few vanilla porn pics and only slightly embarrassing drunken party photos. If they don't find some evidence of vice, they will suspect it was just staged data, and they might keep digging.
- jasomill 13y agoWhen border patrol agents are looking for narcotics, do you honestly think they pass over the guy carrying rolling papers in favor of the one carrying nothing remotely suspicious due to lack of evidence of vice looking "staged" in the latter case? What's different about a porn- and photo-free hard drive full of boring business reports and uninteresting browser histories?
- logfromblammo 13y agoIf they are seizing and searching your laptop, it isn't because you're violating ITAR or carrying dual-use spreadsheets. There are few legitimate reasons why the authorities should be at all interested in the data on your devices when you are entering an area where both free speech and privacy are considered rights. Among other goals, they are assembling profiles on dissenters, to be used against them later. If you give them something that appears legal but still potentially embarrassing, that's disinformation that might save you from a stronger attack later. This differs from a narcotics search in that having data on electronic devices is not a crime. They could not perform such a search anywhere but at a border crossing.
- okamiueru 13y agoIf you are a political activist, don't backup your files to Dropbox og GDrive, unless it's data you are happy to allow the government to look into. Better to host the files yourself, encrypted with a one-time-pad, for which you have the matching pad with you in a microSD card. Then, upon reaching your destination, and knowing that no one had access to your random bits in the one-time-pad, download your documents from home, and decrypt it. No amount of processing power by the NSA will be able to help them get your files, and the only way the bits of your documents pass through the internet, is if you can confirm that the key to decrypt the file hasn't been touched.
- logfromblammo 13y agoOptional 2.75: Install every crapware toolbar available on the Internet, allocate all free disk space to browser cache, and fill it up with obnoxious ads. Requires a second wipe after step 3, and may get you into trouble, depending on what the crapware does without your input.
- zacinbusiness 13y agoIs it possible to encrypt two files together with two different keys? Say I have my class notes from freshman Latin and I have my plans to take over the world. I encrypt them together into a single file "dont_read_super_secret.encrypted" and if I enter "fuzzykitty98" as the key then I see only the notes. But if I enter "downwithfreedom2000" then I see only the diabolical plans. Is that possible? If anyone builds this app, I'd like a slice of the pie, please :-)
- oskarth 13y agoI believe this is possible with something like Truecrypt. http://www.truecrypt.org/docs/plausible-deniability http://www.truecrypt.org/docs/plausible-deniability
- kybernetikos 13y agoTruecrypt supports multiple encrypted partitions, and if you've got the details to decrypt one, you still can't tell if there are any others. http://www.truecrypt.org/docs/plausible-deniability http://www.truecrypt.org/docs/plausible-deniability
- nmc 13y agoOf course this is possible. You can even take it a step further: full disk encryption, one key will give an innocent Windows install, and another key will give the diabolical plans. However, information is only compressible to the extent of redundancy involved, so this can be spotted: compare the amount of encrypted data with the size of the innocent data.
- mschuster91 13y agoThere's an even bigger weakness: timestamps in files and the Windows event log. These will show if your "innocent" OS hasn't been booted for $long_time...
- alextingle 13y agoJust reset the hardware clock back whenever you power off. The pretend your clock is three years out of whack, and that you don't care. Hey presto - your ancient windows install looks "fresh".
- etanazir 13y agooh so, we must upload custom encrypted files somewhere obscure and scrub our electronics before traveling; then download them again after we reach our destination. and then this border seizure non-sense is really a waste of time.
- joshka 13y ago"Or you can scrub your laptop clean, storing everything on an external hard drive that you leave at home. Then you know you are safe from prying authorities, at least at the border." That is unless you believe that those prying authorities have the will and the way to leave an undetectable backdoor in your laptop. Breaking the chain of custody in any laptop today is akin to destruction of trust in that device. Who is responsible then for paying for this damage?
- nhaehnle 13y agoI would second this. We know for a fact that the NSA uses BIOS malware. I don't believe we know for a fact that such malware is routinely installed by border guards, but it's not a very far-fetched worry at this point. The technical expertise required to do so is very limited as long as you don't password-protect the BIOS: Basically, they only need to be able to plug in a USB stick and reconfigure the BIOS to boot from it. In other words: If you leave your laptop outside of your physical control for even a few minutes, you may have to assume that it is totally compromised as long as you don't have a BIOS password. If the laptop is outside of your control for a longer period of time, you probably have to assume that it has passed through the hands of somebody with sufficient technological know-how to work around the BIOS password as well.
- javajosh 13y agoDo MacBooks have the option to password protect the BIOS?
- ddinh 13y agoYes, you can set an EFI password on Macbooks: https://support.apple.com/kb/HT1352 https://support.apple.com/kb/HT1352
- javajosh 13y agoThanks. But it looks like the "Firmware Password Utility" is not available by default in OSX 10.9, and those instructions only describe how to get it for OSX 10.5 and below. Thoughts?
- oracuk 13y agoI have seen the corporate response of only providing remote desktops via browser and SSL to foreign (US) deployed personnel. Means the data never physically crosses the border. No clear players in this market for consumers though. Where is the consumer remote desktop via browser+SSL that doesn't rely on a US hosted cloud service?
- blueskin_ 13y ago>Where is the consumer remote desktop via browser+SSL that doesn't rely on a US hosted cloud service? The one you host on your own infrastructure?
- oracuk 13y agoWhich software? Remote Desktop + SSL. I don't know of a good self-hosted combination for that.
- a3n 13y agoSeems like a natural thing to offer for someone like Skype or Google. /s
- markeganfuller 13y ago"During their inspection of your laptop, the authorities will disregard files that are not germane to their investigation, says Rosenzweig, explaining that the official policy is to 'flush all non-criminal data'." How exactly do they tell the difference, what if I use steganography to hide stuff in my family pictures? They won't flush anything, they will keep everything in case it's relevant.
- thirdsight 13y agoI don't travel with any hardware other than a DSLR and then I mail the SD cards home. I'll use internet cafes and my phone and that is it. It gets broken, searched, x-rayed, fucked up and generally treated like shit. At Zurich airport, they managed to break my old IBM T42. Had to get my company at the time to courier a new one overnight from the UK by road which cost £1150 just for the courier.
- Mithaldu 13y agoSo is the only correct answer to package the hdd in a sales package, then send it and the laptop separately with UPS or DHL in and out of the country?
- nmc 13y agoA frightening thought: if it was practical to search each and every device going through the border, they probably would do so. Happily enough, statistical sampling techniques can make that possible [1]. [1] S. Garfinkel. Searching A Terabyte of Data in 10 minutes. http://simson.net/ref/2013/2013-01-07%20Forensics%20Innovation.pdf http://simson.net/ref/2013/2013-01-07%20Forensics%20Innovati...
- ludoo 13y agoHardware is cheap in the US, I'd leave my laptop at home and get something cheap (either a Chromebook or a used laptop), then access/transfer data and configuration over the net. As for my phone, if I were in a position to be worried about customs installing backdoors, I'd prepare a recovery zip beforehand with all my data, then download it from my own server or a secure storage, and flash it after passing customs. Or better yet, travel with a SIM and buy a cheap Moto G, the resale value alone once back at home would make up its US price.
- plg 13y agoCan the authorities ever compel you to provide a password?
- andrewcooke 13y agoin the uk you can be imprisoned (up to 2 years) for not revealing your password. i am surprised the bbc didn't mention that (maybe i missed it?) http://en.wikipedia.org/wiki/Key_disclosure_law#United_Kingdom http://en.wikipedia.org/wiki/Key_disclosure_law#United_Kingd... (also contains details for other countries)
- powertower 13y ago> Between October 2008-August 2009, for example, more than 220 million people travelled to and from the US, according to Department of Homeland Security officials. > During that time authorities searched about 1,000 laptops carried by travellers. We don't live in the police state that most Snowden and Kim Dotcom supporters here tell us that we do. I get really tired of seeing anecdotes used to represent the average.
- iaskwhy 13y agoTangential. One of the reason I love "V for Vendetta" is how it shows how normal it is to live under a dictatorship. Thing is, for most people, there's almost no difference, mainly during the most recent dictatorships. But for a very particular minority, life is very very different. I should know, I'm currently in a country where 50 years ago there was a dictator and it's not uncommon for normal people to claim how things were maybe better during those decades. Well, my grandfather, tortured by the state police for being part of an union, wouldn't agree. But for the other 99% of the population, life was, give or take, just as it is.
- powertower 13y ago> But for a very particular minority, life is very very different. That's pretty much true for any and every society.
- iaskwhy 13y agoCan you expand on that?
- wvenable 13y agoIf you are a political activist, it seems the odds of getting your laptop searched is many orders of magnitude greater than the general population.
- erichocean 13y agoWhich is, in effect, a prior restraint on political speech, so you'd think the Supreme Court would be all over that.
- a3n 13y agoActivists and other "interesting" people have their own particular security problems. For most of the rest of us, we really have no data of any interest to the authorities. That doesn't mean we shouldn't care about data security, if that's important to us. But it's not the real problem with border confiscation. The real problem is not having your hardware or software tools at your destination. So don't bring any hardware or data that you can't afford to lose. Certainly don't bring anything that you're emotionally attached to, particularly inbound. Either don't bring anything, and buy it all at the destination, or just bring the cheapest stuff you can use productively, and be prepared to replace it at the destination. The NSA already has my email. But I'd hate to be without a camera, or phone, or laptop, or data, or whatever other tools I was going to use at the destination. Plan for that, it's the more likely and practical threat.
- salient 13y agoFrom what I hear, SSD's can't be wiped completely, so be careful with such laptops (Macbook Airs, etc).
- kps 13y agoTheoretically true, but practically misleading. Each block of flash can be written only a limited number of times, so flash drives (SSDs, cards, USB sticks) all have more blocks than are visible as part of the disk. Drives internally rotate active blocks in and out of the spare pool to try to keep the number of writes to each similar ('wear levelling'). When you write to a flash drive — including trying to overwrite data to destroy it as someone might on a magnetic disk — it will generally pull a block from the spare pool for the new data, and put the old block in the spare pool. The spare pool is invisible to the OS, but it is reasonable to assume that there are ‘secret’ commands to access it — not because some TLA demands it, but because the hardware/firmware engineers need it for development and debugging. BUT there is a great big BUT. Writing flash is a two-step process. Programming flash can only change a 1 bit to a 0. Before this, there has to be a slower erase step, that sets the block to all 1s. In order to avoid this performance-killing overhead on every write, flash drives erase as much as possible (whether spare pool blocks or TRIMmed visible blocks) in the background as soon as possible.
- qwerta 13y agoThere is vague sentence "Afterwards you get your laptop back ", but not much else. Perhaps it would be worth to create serious article on subject. Who pays for damages? If harddrive is separated from laptop, does it get seized as well? What if I have 100GB of random data on hdd? Is there obligation to provide technical support to officers? Not everyone knows howto boot FreeBSD without bootloader. Do I get written certificate of what was seized? There could be some bitcoins on hdd...
- pcvarmint 13y agoYou can hide your (encrypted) Micro SD cards inside fake nickels: http://www.amazon.com/dp/B006BFCOIE http://www.amazon.com/dp/B006BFCOIE But really, it's safer to not physically carry data across the border, but to access it over VPN or another secure tunnel while abroad.
- perlpimp 13y agoSuch an inconvenience. They should reimburse the cost of the laptop say to standard tune of 3-5k government cheques and allow for you to pick up your laptop in return for the money, if you need it. Full on encryption, tmp lock and filesystem hashing via tripwire then is mandatory. Fun thing is that you can screw up the malware to send all kinds nasty shit back to them, like trojans and viruses, PIF files and EXE files and whatever might tickle your fancy. Then get your malware do maximum damage on their network. After all they hacked your laptop, they engaged in illegal activity and it is only fare for you to punish them to the fullest extent of your technical capability. They cannot acknowledge the fact that they hacked your laptop without a warrant. etc.etc. There's tons of fun to have this way. Since people who are doing these things are expecting you to be retarded luser and so you can set a trap and have them fall straight into that. Make a blog post and example of malware and how to entrap the said trespassers, what does malware do etc. my 2c.
- mindslight 13y agoThis has been the case for some time, and I doubt the unaccountable bureaucracy is going to change. So the only thing we can do is disrespect, mitigate, and undermine. Here was my ad-hoc procedure from traveling internationally a few months ago (tourism), with a prior of not really expecting to be hassled on the way there, but unknown for the way back: 1. Choose the laptop I'm least likely to miss in the case it gets stolen by JBTs, with respect to the functionality I require. 2. Wipe(1) the first 10MB of disk (has only ever been LUKS), then one /dev/urandom pass into the entire thing. (In retrospect, zeros may have been better than random) 3. Reinstall Debian, with a passphrase I don't mind giving up. Sync over only files that I don't mind giving up. 4. Go through Japanese customs - the only question asked was "Are you with him?" (friend in front of me). 5a. At this point, I possess a still uncompromised machine at the destination, with stored ssh host keys, etc. When (last-minute) prepping, this possibility didn't quite occur to me. Not being prepared to take full advantage of this was regrettable. 5b. (If machine had been molested, I would have not logged into my privileged accounts at all. For the most part I didn't have to anyway, but since I wasn't fully prepared it came in handy once or twice) 6. For return, wipe first 10MB of disk again, then one /dev/zero pass to the entire thing (so there was no argument that I had encrypted data). Then mkdosfs on a whole-disk partition for derp-nothingness. (This was done with a Debian install image written to an old flash drive I had with me for the purpose. My only concern at this point is the hardware getting stolen. 7. Take hard drive out of laptop so that it is a separate device. This would most likely increase suspicion, but make them even less justified in stealing the whole machine (not that this would stop them). 8. Get waved through coming back through USG because laptop "searches" aren't actually that common for people not on the primary watchlist (everyone is on the secondary watchlist). Still, I will do the same thing next time, and think it irresponsible to not. There are of course improvements that could be made to this, including a small default-booting "nothing to see here" install, with file times etc automatically adjusted. Automatic copying of machine credentials etc when you're at your destination. Using a separate partition instead of the flash drive. And of course automation of the process so it's easy for everyone to do :)
- toomuchtodo 13y agoWhat tools could be used to boot off a trusted, non-writable USB stick to checksum the BIOS? Difficulty level: Macbook Air