4 ms·
The secure way would be to upload an encrypted copy of the harddrive, bring across wiped hardware, and re-download the contents after clearing the boarder. FedE
by oniTony 16y ago
The secure way would be to upload an encrypted copy of the harddrive, bring across wiped hardware, and re-download the contents after clearing the boarder. FedEx packages go through customs, encrypted internet data does not.
That is to say -- if the intent is to sneak some data into the country, it seems obvious that it should not be available in plaintext on a physical device. With that in mind, is there ever a legitimate reason to seize all electronics, up to and including gaming consoles[1], from a security researcher (warrant had to do with MySpace, not anything console related)?
[1] http://www.youtube.com/watch?v=fEmO7wQKCMw#t=40s http://www.youtube.com/watch?v=fEmO7wQKCMw#t=40s
- jrockway 16y agoWith that in mind, is there ever a legitimate reason to seize all electronics, up to and including gaming consoles[1], from a security researcher (warrant had to do with MySpace, not anything console related)? Sure! A court would never convict the guy of anything, but Someone still thinks the guy should be punished. "Hi, we stole all your possessions again!" can be a good way to persuade people to interest themselves in a different field. (I have to think this is intentional. If the government didn't want seizures to be punitive, then there would be a law that every device has to be paid for or returned within 10 days. But this is like the bill of rights for the government; a convenient way of circumventing "oppressive" laws when necessary. Oh. I made myself sad...)
- Cushman 16y agoBetter idea: Any time anything is seized without an according arrest, they have to hand you a check right then and there for the retail value of the goods. If a conviction comes out of it, they can tack that check onto the amount of your restitution. Hey, I can dream.
- phlux 16y agoAgreed, I posted this the other day: http://news.ycombinator.com/item?id=2424678 http://news.ycombinator.com/item?id=2424678 --- Here's an idea: Take your primary hard drive out of your machine when crossing borders and put some vanilla install of whateveer on the machine. Fedex the primary drive to your destination or keep all your shit in the cloud. Some years ago I did a design spec for what is now the atrix -- I wrote a paper and tried to get some google eng contacts to work with me on the idea that all machiens are jsut a KVM for your data - and that our primary data device would be both our phones and datasets in the cloud... Sadly, I couldnt convince them this was true then - but i is clear now. So it would be great to have a /home/ on your mobile that you can sync to your machine when they are close. If the machine dissapears, no big deal. Here is how I would model that today: You carry three devices - laptop, mobile and a USB stick and cloud storage. Under normal operating circumstance, you work on your laptop as you would any other time. The mobile has some 32GB of storage -- this is a clean install backup of all your installed apps. The USB has a BASE install of your OS and whatever apps you can fit -- in a live USB install. All your personal data is in the cloud, such that if you lose any of the three devices - none of your data goes with it. Swap the HDD of the laptop when travelling to a clean install drive with no data - do not sync till you get to the destination. Should you lose your laptop, you can use the USB to run a live session on any machine you can boot to it from.
- ioerror 16y agoThat won't work for a number of reasons that are both technical and legal. I have a possible solution. I'll publish a paper on the topic in the near future for the benefit of everyone that has to deal with this kind of nonsense.
- phlux 16y agoCan you give more info? Why wouldn't having all your critical data online work. The idea being that you wouldn't access/sync any of it until you reached your destination and while you were traveling you only had a base install of the OS of choice? Further, I can see that if you were intending to malicious activities that this would be illegal -- but is there some other laws that would preclude one from using this model for 'user session portability'?
- nl 16y agoYou are assuming they don't alter the bios and/or hardware [1]. There is some suspicion that they can and/or do [2]. [1] http://en.wikipedia.org/wiki/Hardware_keylogger http://en.wikipedia.org/wiki/Hardware_keylogger [2] http://blogs.computerworlduk.com/unscrewing-security/2011/03/why-should-you-ever-trust-your-hardware/index.htm http://blogs.computerworlduk.com/unscrewing-security/2011/03...
- spot 16y agoOr better yet, keep no data on the laptap. Or just use ChromeOS.
- AretNCarlsen 16y agoAs of the last conference I attended (in Chicago), I have started bringing an extra hard drive filled with apparently random data with me. I'm not actually bothering to put an encrypted version of my laptop hard disk on the spare disk and place a stock honeypot image on my laptop HD -- or am I? Either way, I like to think that I'm lending plausible deniability to everyone else with extra hard disks.