10 ms·
Can someone explain the reasoning behind these recommendations? Don't : > Use your fingerprint to lock/unlock devices. > Use an Android phone. > Take the de
by ploggingdev 10y ago
Can someone explain the reasoning behind these recommendations?
Don't :
> Use your fingerprint to lock/unlock devices.
> Use an Android phone.
> Take the devices you work on across the US border.
Anyone has experience with their devices being searched at the border? Do they just look at your social media and let you go or do they somehow copy the data on the devices or install any software on the devices? Will the persons devices always be in visibility or do the CBP officers handle them in separate rooms?
Assuming I have to carry my laptop and phone across the border, what precautions can I take to minimize the potential privacy violations? After crossing the border, do I just reinstall my OS of choice (Ubuntu) from scratch and reset all passwords?
Regarding the browser recommendation, why is Firefox not recommended? It's used in the Tor browser and I have not heard of any major security incident recently with Firefox.
- eropple 10y agoBorder patrol cannot force you to divulge a PIN or password. They can force you to apply your fingerprint. Look elsewhere in this thread for "why not use an Android device." Don't carry your work devices across the US border because they may be taken, can be taken out of your view, and may be duplicated (and yeah, you should have FDE on your computers etc., but don't take the chance).
- Buge 10y agoThe US border patrol cannot force you to give up your password. But other countries (including Canada) can. http://news.nationalpost.com/news/canada/guilty-plea-ends-case-that-pitted-cellphone-privacy-rights-against-border-security-powers http://news.nationalpost.com/news/canada/guilty-plea-ends-ca...
- tptacek 10y agoThey might not be able to force that on US citizens, who have an absolute right both to habeas and to enter the country. They can force it on nonresident aliens.
- ENOTTY 10y agoChrome has more robust exploit mitigations and its separated architecture is more mature than Firefox's.
- dguido 10y ago> Use your fingerprint to lock/unlock devices. Fingerprints have a different and weaker legal standard than passwords to protect them > Use an Android phone. It may be possible to get a secure Android phone, however, it is unlikely that the one you have is. Varying levels of quality for disk crypto and TPM key storage will do you in. > Take the devices you work on across the US border Any data or passwords you have on you is data you could lose, get forced to cough up, etc. > Assuming I have to carry my laptop and phone across the border, what precautions can I take to minimize the potential privacy violations? Put an encrypted blob on [name a cloud provider]. Download it once you cross through customs. > why is Firefox not recommended? Because Firefox has no sandbox and gets routinely exploited by Law Enforcement > It's used in the Tor browser The Tor Browser is an abomination. > I have not heard of any major security incident recently with Firefox. You have not been paying attention. Maybe consider accepting the advice of experts?
- tptacek 10y agoAdding: the Tor Browser might be the least safe browser to use of all available browsers that can be installed on modern computers. It is a perfect storm of "inferior security design" and "maximized adversarial value per exploit dollar spent". Don't use Tor Browser.
- vojnovski 10y agoWhy exactly?
- tptacek 10y agoThe comment I just wrote says why, succinctly. It helps if you understand the economics of browser exploit development, and then remind yourself that TBB collapses a whole set of valuable targets down to a single release chain.
- vojnovski 10y agoDoes make sense. Any advice on best way to access the Tor network, if not the Tor Browser?
- veeti 10y ago> I have not heard of any major security incident recently with Firefox. https://blog.mozilla.org/security/2016/11/30/fixing-an-svg-animation-vulnerability/ https://blog.mozilla.org/security/2016/11/30/fixing-an-svg-a... https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/ https://blog.mozilla.org/security/2015/08/06/firefox-exploit...
- krick 10y agoWhat can I subscribe to, to hear about news like that in a more systematic fashion? I mean, monitoring all CVEs might be a little to much for somebody who isn't full time security professional, but there surely must be some reasonable compromise between that and position like "this browser is secure because tptacek said so". I don't mean anything against tptacek personally, but without any substantial grounding this is as good as believing Keith Alexander/Michael Rogers/Vladimir Putin/Osama bin Laden/coin toss. In fact, coin toss might be the most secure of all, as I surely know it doesn't try to fool me on purpose.
- veeti 10y agoRefresh the HN front page all day long, like I do.
- discreditable 10y agoUS-CERT publishes alerts on vulnerabilities affecting common software. Several RSS feeds available. They also have weekly vulnerability summaries for a wide range of software. https://www.us-cert.gov/ncas https://www.us-cert.gov/ncas
- angry_octet 10y agolwn.net
- hackermailman 10y agothegrugq recently had a post about travel kits https://twitter.com/thegrugq/status/829855684636274688 https://twitter.com/thegrugq/status/829855684636274688 It's not just the US border, any border they can request you open up social media accounts or walk away with your laptop or phone and return it later filled with spyware. Business trips from here to China always involve buying a new phone and wiping/selling it on Craigslist after you return assuming it's been compromised.
- projektir 10y agoSeems like a travel guide could be useful for journalists, I'd imagine most people don't even think about something like a travel kit.
- flashman 10y ago> wiping/selling it on Craigslist after you return assuming it's been compromised. Seems like if you assume a phone is compromised, it would be immoral to sell it to someone else without full disclosure of your concerns.
- jedikv 10y ago>I have not heard of any major security incident recently with Firefox. There's a reason that pwn2own (the hacking competition) has much higher bounties for finding Chrome vulnerabilities than finding Firefox vulnerabilities - http://blog.trendmicro.com/pwn2own-returns-for-2017-to-celebrate-10-years-of-exploits/ http://blog.trendmicro.com/pwn2own-returns-for-2017-to-celeb...