6 ms·
A security company I contracted for has a policy when people are traveling to certain countries that they can't bring a company laptop or phone with them. They
by nullwarp 5y ago
A security company I contracted for has a policy when people are traveling to certain countries that they can't bring a company laptop or phone with them. They have to purchase a laptop while in the country to use and log onto the systems from there.
- ohyoutravel 5y agoI’m curious because this seems worse in many ways than purchasing in your home country and carrying across. I understand you go through the airport with a fresh laptop and that gives the opportunity for the airport security agents to mess with it, but in all recent travels when I’ve done this the only time I haven’t seen the laptop directly is when it’s in the X-ray machine for 30 secs. Seems like purchasing in visiting country would be less secure. Can you elaborate?
- londons_explore 5y agoI assume the "and log in from there" consists of a very limited login that only allows access to videocalls and a few other basics to allow work to get done... Not the whole document repository of the whole company.
- Nextgrid 5y agoPurchasing within the country is more secure unless you assume all devices sold within the country are compromised and monitored in real-time which seems unfeasible. Of course for this to be effective you should just purchase it in-person in a mall or something, and ideally don't provide any identifying information so they can't "customize" the device just for you, otherwise all bets are off and at that point it indeed becomes more secure to just bring your own and not let it out of your sight.
- ohyeshedid 5y ago> Purchasing within the country is more secure unless you assume all devices sold within the country are compromised and monitored in real-time which seems unfeasible. One preinstalled mitm cert, or sketch CA, is within the realm of feasibility.
- Nextgrid 5y agoAn MITM cert or compromised CA used to spy on the entire country would require the adversary to be able to capture, store, process and search through all that traffic in near-real-time. Sounds pretty much impossible both from a infrastructure as well as manpower point of view.
- kevin_thibedeau 5y agoIf you're an espionage target they'll arrange more than 30 seconds of alone time for your laptop. Either overtly at customs/security or discretely when you're away from the machine.
- kmeisthax 5y agoCarrying devices across a border gives the Nation State Actors both physical access to your machine and a legal basis to mess with it - either by searching the device for secrets or by installing malware onto it. Some countries are better at this than others. I wouldn't bother doing this if I was just going from, say, the US to Canada[0]. However, China is notorious for messing with any Android[1] phones that cross their borders. Depending on what countries your company trades with, this policy might make sense. In contrast, bulk shipments of imported devices are not usually tampered with in the same way[2]. Some countries do have similar restrictions on data import, but they can't mess with or spy on that data because you actually have end-to-end encryption in that case. [0] I have heard reports of immigration officers demanding device passwords in such a case, but it's rare. If you're really paranoid, enough to want to do this when crossing US borders, I should point out that you should never live within 100 miles of them. Anything 100 miles or closer to a US border gives the US government power to demand your papers; furthermore, the people in border control treat this as a blank check to search for anything they want. https://www.aclu.org/other/constitution-100-mile-border-zone https://www.aclu.org/other/constitution-100-mile-border-zone [1] I have yet to hear reports of iPhone users getting their phones searched. [2] Yes I know "Tailored Access Operations" exist, but this usually involves shipping intercepts, not someone buying a device in a store.
- raincom 5y agoIf CBP gets suspicious, they will ask for the device password to gather evidence from one's phone to deport back. This happened to a couple of people I know of.
- jon-wood 5y agoI haven’t travelled to China since before Covid was a thing, but when I went previously border control weren’t at all interested in our phones, and more or less waved us into the country once they’d checked our visas. To say they mess with any Android phone crossing the border is either massive hyperbole, or they’re doing it remotely as you run them through X-ray scanners.
- hedora 5y ago
- jrm4 5y agoIf you presume encryption (SSL et al) in its present state generally works, this strikes me as obviously superior? I genuinely don't understand the argument? You carry your password in your head, buy the new machine, phone home, and you're good? Ditch the machine on the way home if it's that serious.