32 ms·
US border forces are seizing Americans' phone data and storing it for 15 years
- modzu 4y agothey can also search your anal cavity if they want to. #endborders
- notch656a 4y agoNot sure why you're downvoted. This actually happened to me last time I crossed the border.
- anon291 4y agoZuckerberg is illegally interfering with elections in Washington state and elsewhere. Honestly this is mor concerning. As we've learned over the past year, there's no recourse for private infringement of human rights. At least with the government you have someone to complain to
- rmdoss 4y agoThe border is often a lawless section of most countries - specially the US. People can get detained, deported and humiliated for no reason and with no resource. Specially foreigners trying to go through.
- vageli 4y agoI'm not sure I missed something, the title says "Americans" but I couldn't find an elaboration on exactly _who_ is subject to these searches. The ACLU [0] seems to contend that, at least, US citizens are not subject to these measures. [0]: https://www.aclu.org/know-your-rights/what-do-when-encountering-law-enforcement-airports-and-other-ports-entry-us https://www.aclu.org/know-your-rights/what-do-when-encounter...
- jaarse 4y agoFrom reading the directive it appears as though they don’t have an exemption for Americans: https://www.dhs.gov/sites/default/files/publications/PIA-CBP%20-%20Border-Searches-of-Electronic-Devices%20-January-2018%20-%20Compliant.pdf https://www.dhs.gov/sites/default/files/publications/PIA-CBP... Of course the official response is what you would expect: “CBP officials declined, however, to answer questions about how many Americans’ phone records are in the database, how many searches have been run or how long the practice has gone on, saying it has made no additional statistics available “due to law enforcement sensitivities and national security implications.””
- KMnO4 4y ago> national security implications There’s nothing more American than spying on your own people and blaming it on terrorists.
- londons_explore 4y agoA government that doesn't keep good enough control if it's people will soon be overthrown. When you give the people more freedom to protest, organise, mass communicate easily etc, you also have to add equal amounts of monitoring and restrictions to make sure that next movement to overthrow the government can't pick up speed without you catching it.
- thesuitonym 4y agoA government controlled by its people, instead of controlling its people, doesn't need to worry about being overthrown.
- lazyier 4y agoYeah, but that defeats the purpose of creating the state in the first place. The entire point is being able to tell people what to do for your own profit. It's a lot easier if you pretend you are doing it for the subject's benefit as it reduces the resistance to rule immensely. But you don't want to let that go too far or they start getting a big head and start thinking that paying you billions of dollars is optional.
- ep103 4y agoI mean, that's great and all, but IIRC this Supreme Court has been instituting a policy of Absolute Immunity related to immigration issues via Egbert v. Boule. If one has absolute immunity, the law simply isn't a concern for federal border security.
- giantg2 4y agoIf I remember correctly, it's not complete immunity, but they require a compensation mechanism approved by congress for any issue that doesn't have prior history of being compensated explicitly similar to the situation at hand. It's like 99% immunity.
- ep103 4y agoRight, so federal agents receive absolute immunity by default, and this is guaranteed to continue for every new issue, unless Congress magically becomes un-gridlocked in the meanwhile AND chooses to solve this issue AND chooses to do so every time a new unprecedent issue occurs involving a federal agent.
- giantg2 4y agoIt's not absolute. It's just the default. There are specific scenarios where it doesn't apply.
- mercy_dude 4y ago
- throwoutway 4y agoThe ACLU is wrong. The border does it all the time. Here is the one that sticks out in my mind as the most popular case: https://gizmodo.com/border-agent-demands-nasa-scientist-unlock-phone-before-1792275942 https://gizmodo.com/border-agent-demands-nasa-scientist-unlo...
- xoa 4y ago>The ACLU is wrong. The border does it all the time. Here is the one that sticks out in my mind as the most popular case: The ACLU is not wrong, if you actually read their actual words. Your case doesn't say what you think it does. From your own article: >Bikkannavar insisted that he wasn’t allowed to do that because the phone belonged to NASA’s JPL and he’s required to protect access. Agents insisted and he finally relented. As far as the law is concerned, he voluntarily let them look at it. It doesn't matter if they "insisted", he could have told them to pound sand. They could have kept the phone, but in its locked state it presumably wouldn't be that useful, and particularly since it wasn't merely a personal device JPL's legal department then could have easily gone right after them for it and won. Just because we have the legal right to something doesn't mean there is some magic barrier preventing LEOs from attempting to violating them, or implying the right doesn't exist. They have to be defended by people exercising them and potentially going to court. The very next paragraph states: >Hassan Shibly, chief executive director of CAIR Florida, tells The Verge that most people who are shown the form giving CBP authority to search their device believe that they have an obligation to help the agents. “They’re not obligated to unlock the phone,” she says. Right, same as a police officer who asks if they can "look around" or "ask a few questions". They may certainly ask that. You may choose to cooperate. But in general you'd be a fool to do so, and you also may say "no". If they arrest you they were almost certainly going to do so anyway but now they have less to go on and with more avenues to challenge it, and if they arrest you over exercising your rights you have a strong cause of action right there. CBP agents may well ask people this sort of thing all the time, but that doesn't mean citizens must comply.
- oneplane 4y agoThat sounds great when typing it up on the internet in a comfortable chair, but when a few power hungry workers with guns are breathing down your neck in a small room you can't get out of, the rules aren't going to make you feel 'safe'.
- laweijfmvo 4y agoAlso relevant/interesting is this "exception" the US government claims to the Constitution: https://www.aclu.org/know-your-rights/border-zone https://www.aclu.org/know-your-rights/border-zone I've heard of "border" being applied to anywhere 100 miles from an _airport_, but can't find the reference, which would cover like 99% of the country.
- JohnFen 4y agoFrom international airports. International airports themselves count as "the border", for obvious reasons.
- Spooky23 4y agoThey cannot deny a US citizen entry, but they can still mess with you.
- nomdep 4y agoThey are searching anybody who they please, even Americans
- pigtailgirl 4y agohttps://legalservicesincorporated.com/immigration/border-phone-search/ https://legalservicesincorporated.com/immigration/border-pho... https://www.theverge.com/2021/2/10/22276183/us-appeals-court-first-circuit-border-phone-search-decision-fourth-amendment https://www.theverge.com/2021/2/10/22276183/us-appeals-court... "The court held that the government’s policy, described above, does not violate the Constitution. Border officers can continue to perform advanced searches without a warrant or probable cause and can perform basic searches without reasonable suspicion that there may be a violation of law or a national security concern."
- johndfsgdgdfg 4y agoThe way US treats the migrants is human rights violation at the border. Now add this to the pile of atrocities committed by the border patrol and ICE. It's high time we should consider open border.
- arein3 4y ago
- deleted 4y ago[deleted]
- n0tth3dro1ds 4y ago
- weard_beard 4y agoNo, for some time it’s been clear this is a safe space for, “just following orders” and future camp guards.
- _uhtu 4y agoThey do indeed have established processes. And the US violates the shit out of them and illegally detains people against international law. You really think the UN established processes involve caging people without checking their credentials or asylum claims? Do you think international law is big on freeing up border guards to violate civil liberties of both citizens and immigrants? No. After the Holocaust, where many countries turned away fleeing Jews, who would then end up getting gassed, the US made sure the UN implemented international law that would make seeking asylum more human rights friendly. Then we started violating those processes and cracking down on immigration, which actually increased illegal overstays because people stopped going home after their short term visa jobs because they knew they couldn't come back next year to pick strawberries if they left. This isn't wokeism, it's just history.
- cmrdporcupine 4y agoWow, it's almost like "human rights" are a cultural/political/ideological construct and not a legalistic one, and people might have varying differing opinions of what those rights are. And that there might be room in a democratic society for discussion of this, what is most just and sensible, and how we might accommodate a changing world situation. But no... the legal categories of border rights are immutable and constant. Citizenship is a fixed construct. Migrants fleeing starvation and war and climate crisis are criminals. And all these borders set and conquered by force 200-300 years ago are inviolable. Migrant go home.
- newaccount2021 4y ago[dead]
- iamdamian 4y agoIs there any significant effort in progress to combat this practice? I see that EFF has some old articles on the topic but I don't see anything current.
- Frost1x 4y agoFrom what I understand, the border is a sort of wild west in terms of citizens rights and lack there of. As usual with those seeking power and greed, boundary conditions that are not clearly defined are optimized around for their goals. Where do your rights begin and end as a US citizen? That's ignoring all the giant carve aways in your rights when it comes to reentry. Much of it's quite silly in the era of technology and current society scales anyways where most the nonsense they could be concerned about being on your personal phone in terms of data can be conducted right inside the border without ever leaving. So the excuses for cloning phones and archiving data outside of another loophole that let's them spy on US citizens are pretty limited. Anything on your phone they could be concerned about can be archived, encrypted, and tucked away somewhere on the internet that's far less tracable. So what information do you really need? Outside of the really stupid criminals (who will eventually learn to be more sophisticated and evade these approaches), what do you expect to catch? Preventing this practice should be a no brainer.
- AaronM 4y agohttps://www.eff.org/deeplinks/2019/08/ninth-circuit-goes-step-further-protect-privacy-border-device-searches https://www.eff.org/deeplinks/2019/08/ninth-circuit-goes-ste...
- cr555 4y ago"That's when they can plug in the traveler's phone, tablet or PC to a device that copies their information, ...". would really like to know which "devices" they are talking about. fkn hard to do a full android backup these days.. this world. im tellin ya. on another note: lets talk about how one would go about keeping ones privacy intact aka having a party in the capitol. 1. will they be able to get into my cryptrooted pinephone / hdd in those 5 days? 2. if not will this only make them more angry and privacy penetrating?
- Tijdreiziger 4y agoI'm guessing they're talking about Cellebrite gear: https://en.wikipedia.org/wiki/Cellebrite_UFED https://en.wikipedia.org/wiki/Cellebrite_UFED
- flaviut 4y agoTake a look at https://signal.org/blog/cellebrite-vulnerabilities/ https://signal.org/blog/cellebrite-vulnerabilities/
- oneplane 4y agoThey will get a $5 wrench and beat you until you give it up yourself, per XKCD https://xkcd.com/538/ https://xkcd.com/538/ In other words: this isn't a technical challenge, either you comply and give them your private stuff, or you're not going anywhere. Maybe you can con them into giving a 'public' part of the phone and pretending that's all there is, but again, that's social engineering and not a technical challenge.
- Nifty3929 4y agoThis! We are simply not allowed to have privacy and also live a meaningful life. Everything we want to do now requires us to surrender our privacy. Transact with money, see a medical professional, travel internationally, etc.
- JohnFen 4y ago> fkn hard to do a full android backup these days. No it's not. It's very easy. I do it all the time using adb. > will they be able to get into my cryptrooted pinephone / hdd in those 5 days? They don't need to. They can take a binary image of your encrypted partition(s) and take all the time they want to break into it later. Assuming they're sufficiently motivated.
- flenserboy 4y agoTreat every phone as a burner.
- josefresco 4y agoPretty difficult with 2FA
- DarthNebo 4y ago2FA should be TOTP not SMS
- unethical_ban 4y agoMy work-based 2FA is tied to my phone and is non-transferrable. If I lost my main phone without switching the 2FA install while logged in, I'd have to go through a recovery process. Culprits: RSA Authenticate and Okta Verify. My personal accounts that have 2FA are all backed up with Authy.
- nobody9999 4y ago>My work-based 2FA is tied to my phone and is non-transferrable. If that's the case with your workplace, do they issue you a phone to use for work-related stuff. If not, why not? Your personal device shouldn't be required to do work-related stuff, IMHO. I'd add that since there's work-related stuff on your phone, your employer can restrict what you do/don't do with that phone and subject your personal device to its corporate policies via Mobile Device Management (MDM)[0] systems. Even more, if you ensure that work-related stuff isn't on your personal device, issues with either device won't impact the other one. I realize that it's out of fashion these days to keep one's work and personal lives separate. But IME, doing so is generally a good idea. [0] https://en.wikipedia.org/wiki/Mobile_device_management https://en.wikipedia.org/wiki/Mobile_device_management
- unethical_ban 4y agoI don't have MDM on my phone (no alt-roots or anything). "Just" the 2FA, gmail and Slack. But I agree, I'm tempted to get the work stuff off and onto an old phone just to have the mental separation.
- O__________O 4y agoSeems like real solution are phones that by default provided end-to-end-encryption for cloud backups, no local data “travel modes”, secure wipes, multiple logins, etc. — since trying to get countries to uniformly play by same rules seem highly unlikely.
- Bakary 4y agoOr just a burner with plausible activity stored on it to give the impression that it's your main phone.
- excalibur 4y ago+1 for burner, but why bother loading it with data? Just throw on a few texts that say "Stop spying on me you useless cunts."
- joelhaasnoot 4y agoI believe for many companies that do business in China this is already standard procedure, also for laptops
- O__________O 4y agoIf by plausible, you mean intentionally false — then in many countries, if caught, that might result in being: blacklisted, deported, imprisoned, detained, lose of citizenship, etc.
- dylan604 4y agoI don't get the plausible activity bit. Just tell them it is your travel phone and be done.
- pdimitar 4y agoHonestly, as a non-American this scares me. I am absolutely not at all important and a fairly mediocre programmer as well, I don't store compromising data about anyone, never stole code or company data in my life (and never will), etc., you get it. A normal law-abiding citizen. I still don't want to get my phone taken on an US airport and returned an hour later with God knows how many viruses that even Apple wouldn't be able to detect on my iPhone. It's not about having something to hide. It's about not liking it when people poke their noses in your business without you being a criminal. And no I don't think installing backdoors on each device "to catch the criminals more easily" is a solution at all.
- Tijdreiziger 4y agoAlso, I'm sure the US isn't the only country that does this. So if you travel internationally at all, you're essentially boned when it comes to personal privacy.
- pdimitar 4y agoThat's absolutely true, we were just discussing USA at the time. I have heard plenty of stories where security randomly pulls somebody from the crowd and straight up orders them to unlock their phone, or else.
- Bakary 4y agoThe elephant in the room in this case is that at a most basic level a State is an entity that maintains a (near) monopoly of violence in a given area. Being a normal law-abiding citizen just means that you are currently functioning in an area where the State's goals somewhat coincide with you living with some degree of freedom and comfort. Or at least they have no current incentive to mess with your life. But the whole system of laws we see as normal is just an abstraction that masks the balance of power which is in itself not that different from gang warfare at a higher scale. When you are disturbed by having your phone searched, what is happening is that the balance has shifted a bit against your favor, and you subconsciously realize that your position is not as safe as it once was. But it was never truly safe, just stable in a certain point and time. The fact that you are not a criminal is irrelevant, because respecting or not respecting the law is very relative. The mental separation between the criminal and the law-abider is fictional in that both are just on a spectrum of usefulness and loyalty to the State.
- xyst 4y agowe need to end this useless security theater. only a matter of time until a bad actor gets ahold of this massive database and sells it off to the highest bidder
- colordrops 4y agoIt's useless for us but not the ruling class.
- xtracto 4y agoAs a foreigner to the US I see this as a simple display of power: See how powerful we are over you, we can and will exert control over you, your data and your belongings. If you want to enter our Empire you will belong to us and will allow us to plug all your orifices. No way I felt like that when travelling to the UK or to continental Europe. The real answer is to avoid traveling there. Empires crumble when they become irrelevant. And for US citizens, they should definitely strive to create a society with more freedom and privacy for them. But only if they want that, which doesn't seem that way nowadays.
- colordrops 4y agoThere's a social stigma here about being too vocal about this sort of thing, at least in the circles I encounter in California. You are either wasting your time or are a bit of a paranoid if you worry too much about these sorts of things. You even still see it here on HN, where people will pull out Hanlon's razor as some sort of proof that this sort of malfeasance doesn't exist.
- howmayiannoyyou 4y agoTerrifying for only 2 reasons: 1. Any malicious person savvy enough to pull off a crime of interest to the Feds is smart enough to provide a wiped or burner phone to DHS/ICE, and they have to know this. So, what is the point in doing this if not to target law abiding citizens. 2. USGOV has a spotty track record of keeping this information secure. A foreign actor is likely to access this info eventually. As one former government official once joked many years ago - concerning Chinese hacking - "Well, its probably more secure in the CCP's data center, so I wouldn't worry." This is the problem when a non-technical generation makes the rules and regs. Luddites ought not be permitted to ascend the GS ranks.
- dylan604 4y ago>Any malicious person savvy enough to pull off a crime of interest...and they have to know this. You'd be amazed at how many dumb things smart criminals/people can do. Maintaining proper OpSec is hard. It only takes one mistake to give the LEOs a string to pull to unravel the whole sweater. Everything else, I tend to feel the same way as you. Just wanted to mention the OpSec part
- rightbyte 4y agoOne of the Pirate Bay founders, Varg, a proper hacker, stored unecrypted mails from the others and "framed" them when the police seized his computer.
- CommitSyn 4y agoWhat do you mean by "framed" them?
- daniel-cussen 4y agoJust use stationary.
- dhruval 4y agoI just just reading this Bloomberg story about a Chinese spy who was busted. It’s mind boggling how sloppy even state backed malicious agents are at information security. https://www.bloomberg.com/news/newsletters/2022-09-16/chinese-spy-uses-gmail-icloud-showing-tech-privacy-is-harder-than-it-looks https://www.bloomberg.com/news/newsletters/2022-09-16/chines...
- jscipione 4y ago
- hedora 4y agoThis program predates Biden. The fact that the Biden administration is cooperating with the senator (a Democrat) suggests the Biden administration doesn’t support the program very strongly. Most of this stuff was enabled by the patriot act, which was pushed through by George W Bush. Also, the Republican controlled Supreme Court recently ruled it is legal for states pass laws that explicitly ignore vote tallies moving forward. If you want the US to be a democracy moving forward, I suggest you watch Biden’s Sept 1, 2022 speech. It touches on these issues.
- CabSauce 4y agoFortunately we still vote for our representatives. But I'm sure the US Federal government is interested in your veiled calls for violence.
- coldcode 4y agoEnjoy it while you can, Moore v. Harper is up for debate in the Supreme Court this year, and it appears to be in favor of this (insane) idea that voting is no longer a right.
- 4y ago
- jliptzin 4y agoThis happened to me in 2016 crossing into Canada. Borders agents took my phone for no reason, demand I give them the password to unlock it (otherwise they would seize the phone), took it in the back for 45 min before returning it and letting me enter. I think it’s obvious they took all my data. So now when I travel I just bring my “travel” phone with no sensitive data on it.
- pearjuice 4y ago45 minutes of unsupervised access to your phone? Even if it's a "travel" phone I wouldn't connect it to any other device after that.
- Havoc 4y agoWhat are you gonna do? Throw you new iphone in the bin?
- macrolime 4y agoSell it back to Apple with Apple Trade In and buy a new one
- N19PEDL2 4y agoBuy a 2nd-hand $40 scrap phone, erase it, save a few panorama pictures and a couple of selfies on it and put your SIM card in it every time you are about to cross a border. Then put the card back in your regular phone after that.
- clankyclanker 4y agoNope, get a new SIM. There’s some writable memory on them, iirc.
- Nifty3929 4y agoGood thing the trend is toward non-removable SIMs to stop that sort of shady business.
- jollyllama 4y agoDo they do this with laptops too? If not, the laziness of assuming everything is on the phone is amusing.
- dylan604 4y agoYes, they do, but not all people carry laptops where pretty much everyone will have a smartphone. There have been references to Cellebrite devices which target smartphones. So when all you have is a hammer, you focus on the nails. There are stories online of people having a "travel" laptop where they fill their USB/Thunderbolt ports with epoxy or similar to prevent device connections by anyone not just at border crossings.
- jollyllama 4y agoSo they just don't scan your laptop or phone if you gum up all the ports? They wouldn't pop out your hard drive? An alternative solution might be to backup to microsds.
- dylan604 4y agoPulling out the hard drive might be effective if it's 2002 or something. If you have a modern laptop like a MBP, then the drive isn't really removable. If you were to remove it, the use of encryption linked to the T2 chip makes the thing useless.
- jollyllama 4y agoGood point. I don't travel a lot and I use old hardware.
- Bakary 4y agoIf the border guards see that your laptop has epoxy in the ports, and that by definition you are using this technique for privacy-averse countries, sounds like you won't be making the flight any time soon.
- arc-in-space 4y agoUh, ok, sure, don't cross borders with devices with unencrypted sensitive data on them, got it.
- hedora 4y ago… and then physically destroy any device border agents touch. Also, make sure the device doesn’t have any credentials (especially avoid work SSO, Google and Apple credentials) on it, or things like signal, iMessage or RCS installed.
- intrasight 4y agoI guess the oft-cited advice to travel with a burner phone even applies to the USA. Sad to hear. I hope Wyden is successful in changing this practice, but I very much doubt that it'll change. Has anyone that this happen by US border patrol? What are the specifics?
- JustSomeNobody 4y agoI think at this point, if I were to travel internationally, I would not bring my EDC. I'd buy a cheap phone when I arrived at my destination and just chalk it up to travel expenses. I would tell everyone I'll email them my phone number when I get to my destination in case of emergency. I'd rather that complication than have some 'roid-redneck at the border capturing data that's really none of their business.
- _chu1 4y agoHope they have fun getting into the iOS 6 iPhone 4S I carry around, security by obscurity XD (And no, it's not my main phone, Pixel 5a with GrapheneOS is my daily driver)
- btbuildem 4y agoThe real question is, can you put something on your phone that will root their workstation & plant a worm on it?
- Nifty3929 4y agoWhile fun to think about, you'd be giving them plenty of reason to put you in jail for a long time.
- deleted 4y ago[deleted]
- algoatecorn 4y agoAs a thought experiment, what would happen if you wrote your own malicious payload to a burner device and handed that over? What if you warned the border agents that your device would deliver malicious code and they plugged it in anyway?
- beebeepka 4y agoWhat do you think would happen to a regular person performing such an act? Would it be like Texas Chainsaw Massacre or a James Bond movie?
- algoatecorn 4y agoHuh? I'm asking about the realistic outcome, whether that be denial of border crossing, criminal charges, or they choose to not examine the device and let you through.
- shabbatt 4y agonow what if you bought the phone off craigslist?
- algoatecorn 4y agoThat's likely not relevant since during a border crossing your identity has already been verified.
- shabbatt 4y ago"how was i supposed to know the phone i bought on craigslist had a payload?" plausible deniability. edit: please dont actually do this.
- shiftpgdn 4y agoI believe there was a defcon talk about this but for the life of me I can't find it. My advice is to epoxy your lightning port closed (or snip the data connection inside the phone) and use wireless charging exclusively. edit: It was the Signal founder. https://appleinsider.com/articles/21/04/21/signal-hacks-cellebrite-device-reveals-vulnerabilities-and-potential-apple-copyright-concerns https://appleinsider.com/articles/21/04/21/signal-hacks-cell...
- doodlebugging 4y agoThe easiest solution to this persistent storage of private citizen's personal data siphoned from their phones or other devices is to carry a burner phone on international trips and weaponize the data that you store on it before you travel. Infect some photos and PDFs with one of those silent exploits that, once it gets into their data center, maps all the drives and wipes them or one that wipes the devices that they are using to siphon all the data at the border crossing. Even sticking them with something like a shitcoin miner would be a win. Or, target the data storage center directly. I guarantee that someone in their custody chain is dumb enough to click a fake email link or visit that hijacked site to download code that wipes their data center drives. You only need to be lucky once to put them back at square one. Or better yet, someone could create a repository of shitty memes that can be downloaded to your burner phone before you travel. Just grab a bunch of "Yo' Mama" memes and let the agency hacks waste all their time reviewing the same well-worn collection over and over. The more boring the better.
- ck2 4y agoJust a reminder any email you have online that is over six months old can be read without a warrant.
- tristor 4y agoLot's of people fantasizing about what they'll do at the border with weaponizing the data on a burner phone. Let me present a "simpler" and actually realistic option (only for US citizens) on how to handle this: 1. Have a reasonable amount of emergency savings (6-8 months of expenses stored). 2. Have someone in-country who isn't traveling with you who can make sure your bills get paid (financial power of attorney). 3. Apply for Global Entry, which pre-clears you for border crossing. 4. Turn your phone /off/ when you land (usually a 15-20 minute walk to passport control in most airports). Powering off is important. 5. Refuse to provide the password, refuse to unlock. Provide all relevant travel documents and customs declarations, and allow free inspection of your baggage. 6. Wait... depends on the agent. Longest I've been detained was 2 days, most of the time they hem and haw for an hour or so and let you go. 7. Go on with your life. Step #1 and #2 is in case you get arrested, which will almost guarantee losing your job, at least for right then. Since you can clearly establish no priors and that you aren't a flight risk, getting bail and then finding another job should be relatively easy to do within 6-8 months for most of the HN crowd. Also, invest in pre-paid legal. Obviously, this is assuming things go mostly okay and you don't get murdered at the airport, however the realistic probability of this occurring is fantastically low (these types of crimes are almost always committed in the US by local law enforcement, not federal law enforcement, as feds undergo much more stringent requirements and aren't just your high school bully drunk on power with a gun). Steps #1 and #2 you should be doing anyway, just out of good financial sense. Step #3 you should do anyway if you're traveling internationally regularly just to make your life easier when black swan events don't happen. And Step #4 you should do EVERY time you are about to let your phone out of your possession, whether involving the government or not, because it prevents most forms of attacks against an encrypted device and disables biometric unlock (which can be coerced/forced/done when you are dead). The hardest step is honestly #7, because after what I've experienced in my travels (and let me tell you, the US CBP is MUCH MUCH more professional, courteous, and reasonable than many many other countries), nobody really believes you and there are way too many people that are apologists for the powerful. Governments, pretty much universally, suck. The only difference between whether you personally experience the suck or not is whether or not you happen to get randomly selected or fall outside the bounds of what the government expects of you. There is no requirement that you do anything "wrong" in either the moral or legal sense, to end up stuck in the suck. Embrace the suck early if you plan to exercise your rights, because doing so will bring the suck on to you full force, but if you're the self-righteous type at least you'll get some sense of satisfaction out of it.
- lasc4r 4y agoI need to prioritize phones with SD cards way more. This is ridiculous.
- browningstreet 4y agoOn my last trip back from Europe in June, when I re-entered the US, US Customs & Border Control didn't ask for my passport. No one did. They did wave a webcam connected to a computer in front of my face, and then a moment later, called out my name and said I could enter. Same with everyone coming through the international border area. I think that's just as weird a development and worthy of "WTH?" as this topic.
- pradn 4y agoAt the passport control kiosks, they can just scan your face and give you an exit ticket. It was super quick, and surprising. I was able to skip talking to an immigration agent completely. They can do this because they have photos of me from previous kiosk visits, and because they can restrict the universe of photos they need to check to just those who were on recent flights. I wonder how well it works for twins traveling together or something. For any level of uncertainty, they can just have you go talk to a human instead.
- Grimburger 4y agoPretty much all passports have biometrics now. I assume they can work out who you are from that. In Australia it's an autogate with a face scan for citizens and PR's, you only deal with a person if it can't identify you, which is rare.
- kube-system 4y agoAll US passports issued in the past 15 years are biometric passports.
- markus92 4y agoDo you have global entry?
- browningstreet 4y agoNo, but I do have TSA Pre, and this was the open entry point for all US citizens.
- caseysoftware 4y agoRead the book "Habeas Data" It's a great overview of digital privacy and protection laws in the US, how they came about, and what protections they actually offer. The short answer is "very few" and the long answer is "never ever ever turn over your data short of a court order and even then try to fight it." Then with Third Party Doctrine, most of the few/limited privacy/warrant rules go out the window. Also, I'm not a lawyer.
- sleepdreamy 4y agoIf you don't read the 'Accept Me' On most random websites nowadays, most people are just openly giving up access to their devices/data without even knowing it.
- macrolime 4y agoEven if you are a person who will never in your life end up as any kind of person of interest for the government, handing over data in this way could still be quite dangerous. Phones will often contain data that can facilitate theft and fraud if ending up in the wrong hands. If they're able to copy everything, including private data from all apps that could be quite bad. For example many countries now use apps to login to online banking, with private keys for the login stored in the app. Will that be copied? Will it ever be found out if one of the 3000 government officials with access to this data sold it on darknet markets? Maybe some months after your travel you suddenly wake up one day to find all your money transferred from your bank account to some account in Nigeria.
- dr-detroit 4y agothey are also tracking if women are pregnant when they travel so if you miscarry you go to jail
- nopenopenopeno 4y agoIt always blows my mind that the same people who insist they don’t trust the government are the first in line to hand over all their personal data to the government, whether by way of Google, Facebook, or otherwise.
- YeBanKo 4y agoThings like secured enclave should make it hard to extract private key from a device even if you have full access.
- bongobingo1 4y agoWhich assumes the keys are stored in there and not `bundle/user-data/please-dont-read`...
- LightG 4y agoYou're giving way too much credit to reality...
- nilespotter 4y ago
- _9hey 4y agoThis a clear and bold violation of the fourth amendment. Let the lawsuits begin!
- kornork 4y agoI wish the 2nd Amendment folks would care about the 4th Amendment just as much.
- tarunupaday 4y agoThis (and similar issues) is the main reason that I donate a non-trivial (10%) part of my earnings to ACLU (and 2 other) organization. Our rights and freedoms do not come without struggle. And they sure do not last without somebody constantly defending them. And it’s only bravado to assume that we can stand against the might of federal agents as individuals without dedicated organizations fighting for us. Please donate to ACLU - as much as you can.
- thingification 4y agoNot claiming that ACLU does nothing useful -- I certainly don't know enough to say -- but what do you think about this (which suggests to me a damaged commitment to civil liberties): https://whyevolutionistrue.com/2022/01/30/the-aclu-reverses-course-once-again-in-the-interest-of-wokeness/ https://whyevolutionistrue.com/2022/01/30/the-aclu-reverses-... What other organisations do you donate to along the same lines?
- hnbad 4y agoMaybe it's just me but all unironic use of the term "wokeness", especially as an accusation, should be limited to post New Atheism era or Gamer Gate era YouTube channels by faceless cartoon narrators calling themselves things like Skeptical Panda, Truthoid or ${obscure_bronze_age_ruler_here}. It just instantly sinks any attempt at seriousness. The website might as well be called Destroying Creationists with Facts and Logic after publishing an article with a headline like that.
- awofford 4y agoACLU is a shadow of what it once was. Their unprincipled wavering on free speech ensures that I will not be donating to them. I would, however, love some new recommendations for where those donations can go.
- hnbad 4y agoIf you are looking for something more right libertarian or conservative-supported, you probably want FIRE. If you are looking for something more consistently progressive or liberal-supported, you might want to give the EFF a try. If you specifically care about free speech above all, you're probably right libertarian. It's fine. There's no such thing as centrism in real life politics and an individual's political alignments can vary drastically in different issues rather than line up perfectly with any specific political movement. Especially if you consider yourself apolitical or haven't really reflected on the entirety of your political beliefs and how they interact with each other (most people haven't).
- trident5000 4y agoThe reasons stuff like this happens is because there are no punitive repercussions such as jail time for the officials that oversee the programs. All that happens is a judge eventually strikes it down. This needs to change.
- noindiecred 4y agoWow can’t wait until this data is all exfiltrated and sold on the dark web!
- zitterbewegung 4y agoOne thing I learned at Defcon 30 was how to break encryption at rest by just storing the encrypted data and wait for a quantum computer to be developed but storing it for 15 years wouldn’t be long enough (average guess of scientists were 50 years in the future). It makes the NSAs Utah data center to have other applications like parallel reconstruction.
- deleted 4y ago[deleted]
- MrDresden 4y agoAs a European I find it strange how the article and many comments here seem to focus only on it being US citizen's data being hovered up by the boarder control. No one's private data should be taken without a legitimate cause, no matter their nationality.
- Dma54rhs 4y agoWhy strange if we very much do the same at external borders? Especially asylum seekers who get their phones confiscated but all in all the system is very similar when you entry outside Schengen, only imo Americans are more paranoid in a good way, about their privacy unlike euros.
- pessimizer 4y agoYou have to reset your perspective to a US one that believes that US laws only protect US citizens, and even those protections stop 100 miles from the border. It not at all evident that it is illegal for the US to summarily execute US citizens without trial if they are outside of US borders. The data protections of Europeans are without question non-existent. Europe would be upset if we did it anyway, since Europe depends on us to bypass its own domestic spying restrictions.
- arkadiyt 4y agoReminder for the folks using iPhones, you can prevent law enforcement from doing this by "pair locking" your device: https://arkadiyt.com/2019/10/07/pair-locking-your-iphone-with-configurator-2/ https://arkadiyt.com/2019/10/07/pair-locking-your-iphone-wit...
- JustSomeNobody 4y agoOof, what happens if your laptop dies and it's the pair?
- arkadiyt 4y ago- On step 11 you can choose to allow (or disallow) removing the profile with a password - Alternatively you can backup the pairing records from your laptop somewhere to be able to put them on a new laptop - Alternatively you can configure your iPhone to e.g. backup photos and so on to icloud, and then if you ever lose your laptop you can wipe your device and restore the data you chose to backup
- mrtesthah 4y agoJust a reminder that anything backed up to iCloud (besides iCloud Keychain) will be accessible to government authorities, including your iMessages.
- KMuncie 4y agoIsn't the new Lockdown Mode also a way to prevent this?
- arkadiyt 4y agoYes, although if the premise is that you're being compelled to unlock your device by law enforcement then it seems like they could also compel you to disable Lockdown Mode and restart your device - that's not possible with Pair Locking.
- scintill76 4y ago
- thingification 4y agoUnless this sort of thing gets corrected, it will be used in corrupt ways and to enforce tyrannical laws / regimes. Did much of the progress in the past that led us to today's democratic institutions involve law-breaking, strictly interpreted, of the law of the day? Would too-effective, too-cheap enforcement have prevented that progress? I know little about history, but I suspect so.
- bigbacaloa 4y agoHow is this constitutional? If it is, why the hell hasn't the broken constitution been fixed? This is fascism.
- JohnFen 4y agoThis is half of why I don't take my personal phone with me when travelling. I bring a burner, instead.
- Arrath 4y agoI often buy a cheap pay-as-you-go phone in my destination country when I travel (mostly because I think something internal is funky with my phone, despite all arrangements being made and plans authorized with my carrier for international travel/service, the damn thing never finds signal), I may just start leaving my own phone at home when I do so.
- hnbad 4y agoThis is tangential to the content of the article but this site's data protection consent pop-up (not sure if this is EU-only) is actually an own-goal when it comes to EU GDPR compliance: If you can revoke consent for "legitimate interest", it's not legitimate interest. Legitimate interest is a legal basis for collecting and processing data without explicit consent (i.e. it's an alternative mechanism to explicit consent and you can merely inform the user of it, not ask them to consent to it). If you can opt out, it's not legitimate interest. And if it's not actually legitimate interest, you have to make it an opt-in option like the other consent prompts, not an opt-out (tho at least this site doesn't make you select them individually). I'm not sure what marketing firm convinced publishers they could use "legitimate consent opt-outs" as a fallback for the consent many people probably don't opt in to, but their advice is flat out wrong at best and illegal at worst. They'd be better of not providing a detailed consent popup than doing this because the former at least allows them to claim ignorance whereas this clearly demonstrates an attempt to circumvent consent requirements. Not to mention the current state of the law explicitly requires them to provide both "opt in to all" and "opt out of all" options without additional clicks and dark pattern shenanigans (i.e. they have to be equally prominent and the same color and design). Also if you find these popups annoying keep in mind that there's literally no legal requirement to have a consent popup under the EU GDPR. You don't even need one if you use cookies. The only reason these sites need them is because they use third party embeds, resources and scripts that set non-essential (e.g. tracking) cookies or want to record/process user data (e.g. for targeted ads). It's the death pains of a failing business model that's making this annoying for you, not the law.
- rhacker 4y agothere should be an unlock code, that if entered, wipes and writes over all dram bits with random data, including the OS and a big fuck you to gov types that want this data
- sometimeshuman 4y agoI am planning on travel to Mexico soon. A few days ago my sister in-law sent photos and videos of my nephew in bed with his 7 year old girl friend in the family WhatsApp channel. He is only in his underwear and she is topless and crawling around in her underwear and giving him hugs. She repeatedly does this with my nephew's bath-time as well. Out of context it looks creepy and perhaps would be flagged by an AI classifying for exploitation. So if the AI has me marked as a person of interest and they seize my phone at the border, it won't be a good day for me. Am I just being paranoid and lacking perspective because I have never been a parent who spends a lot of time with naked children ? Is this so common that I shouldn't be concerned ?
- hedora 4y agoIt doesn’t really matter if it is common. What matters is what the undertrained CBP officer thinks. Based on the fact that you are concerned, I’d say there is some agent out there that would flag it and ruin your / the kids’ lives, etc.
- LWIRVoltage 4y agoDid some thinking about this- Here's something no one has every ...thought of it seems- Right now, from a steganography standpoint, there's no real way to be secure from this sort of thing. US Customs, or another country , from a tech standpoint. Yes, the cloud, though not everyone will have resources to access enough space online to keep their data secure - or be able to properly make a usable copy or image of their device that includes every aspect of their device, for a complete , fully restore later -Why aren't there more plausible deniable, or just, stealthy encryption options? It appears, there's nearly NONE today for these advanced used cases. Veracrypt is known for it's hidden features -but those are ...dangerously approaching obsolescence. Their Hidden OS option- ONLY works if you've formatted your system to MBR, not UEFI- otherwise you can't use the Hidden OS option. Are you telling me for every laptop you buy form here on out, you'll format it to the old MBR standard to use the Hidden OS option for your personal laptop that you want to take on a trip- or need to? And sure, you can just put important data in Hidden Volumes as a fallback- but then you come to a common fight today in the tech world of system vs file level encryption. And sure, just hiding what is most crucial, is perhaps better form a standpoint of sneaking by- but is it truly now impossible to hide everything else that's not as important, by default? Furthermore, you have to wipe traces of the material's location where it was BEFORE you copied it into the hidden volume. Did you also eliminate all traces? Windows Shellbags are a thing, that nearly no one knows will be a smoking gun.. Veracrypt doesn't work on Mac or Linux with it's Hidden OS option, just volumes. There was a really promising advanced system being built - here, and it was even presented at a blackhat conference i think https://portswigger.net/daily-swig/russian-doll-steganography-allows-users-to-mask-covert-drives https://portswigger.net/daily-swig/russian-doll-steganograph... https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Schaub-Perfectly-Deniable-Steganographic-Disk-Encryption.pdf https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Schaub-Perfectl... But i've heard nothing since- and right now, all your data will be at risk from your computers ,phones ,and tablets, when you go through Customs- even if it's encrypted, they'll hang on to it, and image and copy the data. If you refuse to provide encryption passwords, they'll potentially keep it and not return it to you in all cases. This is where the deniable systems would come into play- where you'd be okay, if they just unlock it. Now if they plug it in and image it regardless, you're at risk because theoretically they could be running exploits on your device(they won't let you watch them imaging it so you can'tverify that ever) -encrypted data will be unreadable here, but it's not as good as if they can't tell it's hidden, from a imaging point when they plug in a Cellebrite or Greykey device and have it run it's exploits to get everything. And i do not see the Forensic Security community often giving recommendations on what it takes to get around this, i think this leads to the public being at the mercy of officials- This will become very destructive also, as this will become a precedent. Imagine Southern States checking devices like to look for evidence of abortion information-searches, for example. Imagine Abortion getting federally banned, and then customs checking for mentions of abortion . - Technical solutions aren't a full solution, as the EFF loves to hamper on- but it appears everyone has given up with efforts to even provide them. I suppose if you want to stand a chance, you need to go become a expert on disks, and forensic techniques , in order to then even have a chance at experimenting on how to get around that- and if that sort of privacy ,security, and plausible deniability cannot be brought to the masses at large, the way Signal did for encrypted communications, ...
- elzbardico 4y agoAll way downhill since the patriot act. Don't say nobody told you so.
- cbpthrowaway32 4y agoThis happened to me, a US citizen, when I was returning to the US from Europe. They stopped me and asked me to hand over my electronics with passwords. I refused and they told me I had to sit in the room by myself until I gave them my electronics. I asked for a lawyer and they told me I am not entitled to a lawyer because I had not fully entered the US yet. After over an hour I finally gave them my electronics and passwords. After CBP gave the electronics back to me I threw them away.
- lizardactivist 4y agoImagine having a knock on your door because you exchanged a few friendly text messages 15 years ago with someone who is being investigated for a crime committed today. Citizens are suspects. Tourists are terrorists. Everyone is a potential criminal in the land of the free.
- thewebcount 4y agoSomething like this happened to a friend of mine. He was using a work-allocated phone. He didn't directly get contacted by authorities, but someone at the company tipped him off that they had been contacted. Turns out the phone number he was assigned had previously belonged to a drug kingpin's burner phone or something like that. When my friend got a new phone and ended up with the number, he made calls from the US to Pakistan because he was going to attend a friend's wedding there. The authorities saw these things and at some point contacted the owner of the phone (the company) to try to figure out what was going on.
- mring33621 4y agoCan I ask how long it takes to 'copy' someone's phone data? The mid-level consumer tech I have access to takes a most of a work day to copy my wife's 80GB of iphone 7+ data to a flash drive. Based on this, I doubt they have some sort of magic thing that will just copy everything on your phone as you pass through a checkpoint. Do they hold you until the copy is done? Or do they have some super fast thing that works on every device? Honestly curious.
- elliekelly 4y agoI’m also curious whether the copying device works with all models. If I went back to my old iPhone 3, for example, would they still be able to snag a copy? Might their surveillance be foiled by want of a dongle? Edit— From the photos posted further down thread it seems like they’re armed with every imaginable dongle...
- mancerayder 4y agoWhat difference does it make if EvilCorp can store the data (phone location data, search data, etc.) on its systems, and then will volunteer to hand over to authorities when requested? Sorry, I meant to say Google.
- neycoda 4y agoI wonder if I'd get arrested for bringing a wiped phone with me with just a phone number on it.
- eriknj99 4y agoI wonder how much trouble I would get in if I broke my phone in half before handing it over to the agents. I can't imagine it would go over well, especially with the damaged lithium ion battery and broken glass involved.
- kelnos 4y agoI submitted this the other day but it didn't get any traction: the Protecting Data at the Border Act[0] is a thing, but has barely been touched by the relevant Senate committee since it was introduced nearly a year ago. As expected, it's not perfect: it has some carve-outs, and only applies to US citizens (and maybe permanent residents; I forget the exact definition of "U.S. person"). But it would definitely improve things. Maybe something to bug your Senators about. https://www.congress.gov/bill/117th-congress/senate-bill/2957 https://www.congress.gov/bill/117th-congress/senate-bill/295...
- throwaway12557 4y agoThis recently happened to me earlier this year. I am a U.S. citizen, coming back to the states from South America. I have not broken any laws nor do I intend to. I put up a fuss and almost missed my flight, but they took both my laptop and cellphone into a back room with about 5-8 other people on my flight. Made me unlock of course. Here is the pamphlet they let me take… saved and documented. They take down hardware addresses and more, and would not allow lawyers on the scene or for me to witness their search. Here are all the pages of the pamphlet: https://imgur.com/a/qNovC83 https://imgur.com/a/qNovC83 As a tech worker and privacy advocate for all I was rightfully not thrilled. I still need to buy new hardware, I had no idea this was the case as far as data storage and 15 years but figured they probably upload malware and all that fun stuff. Neat. I have been a citizen my whole life. Reading through the comments now, I am glad I learned a little. If they pull the stunt again I will happily deny and wait however long and just rebook a flight and maybe hire a lawyer. It’s a gross abuse of power.
- quantum_state 4y agoLawless in the name of security… this is what an authoritarian regime would use.
- geoffpado 4y agoCan we request it back later? This sounds like a great publicly-funded backup service if they can get the user experience right. I certainly haven't nailed storing my own data for 15 years.
- BXLE_1-1-BitIs1 4y agoUS CBP and other national border agencies change target priorities from time to time, which is reflected in the questions they ask you. I recently had a long discussion with CBP about my Canadian passport showing a US birthplace. Under a repealed section of the INA my US nationality lapsed some half a century ago and I suspect a call was made to the Port Manager. Since then my entries have not discussed this point which leads me to suspect their system has been updated. The current question is your plate number (already displayed by the camera). You need written permission from the vehicle owner to cross the border, even if the owner is family. Border officers may also have quotas for more thorough examinations. I remember a lawyer on radio saying that they take "naked" laptops across the border. Most definitely DO NOT cross ANY border with anything that in the most remote possibility would trigger the interest of customs. To sanitise a phone or tablet, fill it with dashcam video, encrypt and factory reset. Then set it up with a fresh Google or Apple ID. Maybe leave your sim card at home. Having repartitioned a tablet, I discovered that there is a massive amount of hardware data in partitions that most people are totally unaware of.
- bioinformatics 4y agoThank God, there are adults in WH now. Enjoy guys, you deserve this!
- mnming 4y agoSpeaking from an odd angle, I kinda wish there is an alternative universe where the US government would ask me: "Would you like to download your phone backup at 2010". I've lost a phone back then and lost a lot photos in it.
- pyuser583 4y agoI’d really I like to know how they store data from a wide variety of sources for 15 years. Mobile device file systems, etc, have changed a lot during that time. 15 years ago Blackberries were the big mobile thing. Can you easily store data from a 2007 Blackberry on the same disk as an iPhone 14?
- StanislavPetrov 4y agoThey are going to be sorely disappointed with the 30 dpi picture of my cat from my flip phone.
- Schnurpel 4y agoAlways travel with two mobiles. Hand over the one you don't use. Don't use the one you hand over. It will carry a virus when you get it back.
- ajvs 4y agoDoes anybody know the legality of this for other countries' border forces? Is there a list anywhere?
- Wseries 4y agoI once had my all my devices searched when returning to my home country (Australia). They kept my phone for a few days too. They didn't find anything and I wasn't charged wth any crime. But you only have to suffer this massive invasion of privacy once to make make sure it never happens again. Now when I return home I wipe all my devices in the time it takes to de-plane, collect bags and get to customs. Easy enough to get back up and running fairly quickly with an iCloud backup once I get home. Looks like I might have to do the same if I ever decide to visit the US again.
- mon3y11 4y ago