7 ms·
CBP Directive 3340-049B: Border Search of Electronic Devices
- itstotallykyle 4mo agoIt's wild, I have worked internationally for a long-time and the rule when going to certain countries was bring a burner device. Going to China essentially meant the device was nuked on return to the States, now it is the same feeling to/from the US.
- Caarticles 4mo agoThe list of countries where you need a burner phone will likely grow longer. Canada, Australia, UK, some developing countries, etc...
- 866-RON-0-FEZ 4mo agoAustralia's been doing this forever.
- smdyc1 4mo agoWe have? My international relatives have never been searched to that degree, if at all. That said, the whole thing is overreach in any democratic society.
- Spooky23 4mo agoRead the stories about people who actually have this happen. You can usually figure out why they are targeted. That may not be just. But it is. Customs agents are always given broad discretion and generally care about something. Most normal folks will never intact with these issues. The last time I travelled internationally, they weren’t even doing secondary customs screening upon return to the US.
- 866-RON-0-FEZ 4mo agoI've binge watched enough Australian Border Patrol videos to know that: 1. You don't fuck around with Australian customs agents. Ever. 2. They make every other country look like complete lightweights, Americans and EU included. These guys will fine you AU $500 for half an eaten apple in your bag.
- angry_octet 4mo agoThey may fine you for attempting to import a plant, but they won't imprison you in El Salvador for having liked a meme they don't like on US social media.
- jscho 4mo agoThey're fined because they lied on their declaration forms. Our customs agents are generally pretty fair and reasonable, but they do take their jobs very seriously. Tip for travelers to Australia/New Zealand: If you have something that is stated on the declaration form, just answer yes. Provided it's not some totally illegal substance, they'll inspect the items and if it's not allowed past the border it'll be seized without penalty. Someone will correct me if I'm wrong, but I believe in some few cases, you can even pick it up on your return. If it's something like large amounts of cash, goods, alcohol or cigarettes, you may have to pay a tax or import fee and answer a few questions. Just don't be a dimwit.
- smdyc1 4mo agoYes, it's a basic function of any customs and quarantine organisation. Australian Border Force don't care if you have memes mocking our PM or DJT. Inspection of electronic devices only happens when there's evidence of a crime.
- deleted 4mo ago[deleted]
- kelnos 4mo ago> These guys will fine you AU $500 for half an eaten apple in your bag. That seems entirely appropriate, no? Produce crossing international borders like that can be a huge problem.
- TimJRobinson 4mo agoI've had a full shakedown at the airport in Brisbane asking for passwords for phone/laptop and they will confiscate for 2 weeks if you don't comply. I'm an Australian citizen. They also didn't let me call anyone so my wife was left waiting for 3 hours wondering where I was.
- jandrewrogers 4mo agoGovernments maintain formal lists of countries for these types of things. I think people would be surprised how many diverse countries are on the formal lists. A number of European countries have been on them for years.
- antiframe 4mo agoI would like to be surprised. Can you share a list?
- gonzalohm 4mo agoSomeone should make an app to offload all your data to a personal cloud before going to the airport and then reload it into the phone after going through customs
- ZiiS 4mo agoAll backup apps work, no special requirements. Seedvault for my LiniageOS.
- aucisson_masque 4mo agoSeedvault doesn't work half of the time.
- XorNot 4mo agoThey don't work well in my experience. What I want is to get my home screen back exactly as I left it: I've not found anything able to pull it off on Android though. Ideally it would be an exact flash image of the phone.
- stavros 4mo agoAdb backup exists, though I haven't tried it, and Google cloud backup does this. However, if you trust Google, you probably already trust the US. Unfortunately, I don't know of any other app that does this on an unrooted phone.
- gruez 4mo ago>Adb backup exists, though I haven't tried it, It's very patchy, and many (most?) apps opt out, so it's functionally useless.
- XorNot 4mo agoGoogle cloud backup has never done this for me. It seems like it'll restore a whole lot of stuff, but details like getting my Nova Launcher screen back (version pinned to before it was sold - alternatives just aren't good enough yet) or a bunch of the little logins and details has never done it for me.
- jazz9k 4mo agoChina installs malware to spy on you. The US doesn't do this. Totally different situation. This also happens in many other countries
- gruez 4mo ago>China installs malware to spy on you. The US doesn't do this. Source? Are we talking on random travelers, or targeted individuals? I seriously doubt china is doing the former, and I also seriously doubt the US doesn't engage in the latter.
- Spooky23 4mo agoThere are many well cited examples. I believe in politically sensitive areas like Xinjiang it happens to everyone. A past employer gave specific advice regarding Hong Kong as well. I think the key thing as a traveller isn’t the righteousness of China vs. US. It’s the chilling effect on travel and trade. We really depend on these devices that have access to vast scopes of personal and other data. That sexy text you got a year ago is still in your text message store and may be a problem in some places.
- gruez 4mo agoIf we're talking about targeted hacks, are we sure the US doesn't do this? Is US soil off limits for hacks somehow? What plausible exploits could be done when someone is on US soil, but not over the internet, especially on modern phones where the baseband is isolated?
- Spooky23 4mo agoI'm not making any subjective or moral judgement. I'm an american who lives and works in the US, so there are a wide variety of ways law enforcement or others can get data from me, and a variety of legal protections that make certain risks unlikely. TBH, I don't know what the US does or doesn't do, and if I was visiting the US as a citizen of another country, I'd think about risks from the perspective of my experience.
- abujazar 4mo agoThat's exactly what European governments and corporations will have to start doing. Adding the US to the same list as Russia, China, Israel, Iran etc.
- chasd00 4mo agoGoing to China means your devices are owned when the plane touches down if not before. That’s why you bring a burner device (including laptop and anything else), never log into anything, and throw it in the trash when you leave.
- gruez 4mo ago>Going to China means your devices are owned when the plane touches down if not before. ??? Are American made operating systems (Android, iOS, Windows, Mac) so full of 0days that the Chinese are burning them on random travelers? This just feels like either severe paranoia and/or chinese/american psyop, making people think that China has some magic hacking power.
- eff-nix 4mo ago[dead]
- deleted 4mo ago[deleted]
- paulsen 4mo agoI wouldn't say your devices are owned, but you should expect being monitored and your communications being recorded. You could make an argument about the security of the modem of your devices, as that was often a target due to it not being particularly secure and it having wide access to your device, but I believe that started changing some years ago when this started being a more widely reported issue.
- Kim_Bruning 4mo agoFor GDPR reasons alone it's probably not a good idea to take a business phone across certain borders. You run the risk of disclosing customer data to a 3rd party, if only because the customer data in your phone book counts as PII. So long as only a few countries are doing this, it might seems doable. If everyone starts doing it, international travel becomes rather annoying to say the least. Realistically I think at some point a detente might want to be reached, with everyone agreeing not to search everyone else's electronics.
- gruez 4mo ago>For GDPR reasons alone it's probably not a good idea to take a business phone across certain borders. You run the risk of disclosing customer data to a 3rd party, if only because the customer data in your phone book counts as PII. But "law enforcement" is specifically exempt? https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Exemptions https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
- buzer 4mo agoLaw enforcement refers to EU member states law enforcement and processing by them in their context. But even in the EU controller needs legal basis to disclose personal data to law enforcement inside the EU. Normally that is handled by local law, but it's not carte blanche, that law still needs to take e.g. rights granted by EU Charter in account. Search by border officers may very well be GDPR breach for that controller if there was data of EU data subjects, but I don't think there is currently any case law around it.
- antman 4mo agoHad the same guidance for many years for visiting the US given by the large US firm that employed me
- simoncion 4mo agoI heard that soon after the extent of NSA's domestic surveillance programs were revealed to the public, at least one FAANG changed its US border-crossing policy to those used for countries known to tamper with your computers during border crossings. That is, bring a blank computer that you connect to the corporate VPN and load after you arrive at work on the far side of your trip, let IT wipe that computer before you travel back to the US (or just leave it behind), and assume that computer is compromised if it leaves your sight at a checkpoint for longer than it takes to run it through the x-ray scanner. So, yeah, savvy companies have had these policies for like twenty years now.
- NoImmatureAdHom 4mo agoThis is cray. Protections at the U.S. border and within the U.S. are actually pretty good. Much of Europe isn't as good. Hell, the British will throw you in jail for refusing to unlock.
- deleted 4mo ago[deleted]
- userbinator 4mo agoThe legalese is thick but this is a notable point I saw from a quick skim: 5.3.2 "Passcodes or other means of access may not be utilized to access information that is only stored remotely."
- geekone 4mo agolooks like they can request your passcode to unlock the phone so anything local and/or cached before they disable network connectivity would be there.
- maerF0x0 4mo agoThis is an element of 1Password's travel mode, if i understand it correctly...
- KennyBlanken 4mo agoThat's not notable at all given a lot of content is synced to the device, not even counting temporary and cache files.
- userbinator 4mo agoIt's notable in that I've seen an increasing number of companies where employees are essentially given a thin client to connect to a remote server for work, and are sometimes even prohibited from transferring that data out of that environment to the local machine.
- Spooky23 4mo agoYeah that’s really critical if you use O365, as the encryption terminates in each local jurisdiction and is in cleartext on that front end device. So if you connecting in Germany, you’re hitting a front end in Germany or at least the EU, and so forth. One easier way to do that is to use a Chromebook Public Session with a VPN, then connect to SaaS or a hosted desktop in your jurisdiction.
- 4mo ago
- Topology1 4mo agoIs this not old? Since then they have also required all social media to be public.
- somebudyelse 4mo agoDon't think this is anything new? Have seen various cases from years ago where they searched texts to determine if the person was planning on working or visiting. Edit: the first directive apparently was from 2009: https://www.jdsupra.com/legalnews/new-policy-for-device-searches-at-32514/ https://www.jdsupra.com/legalnews/new-policy-for-device-sear...
- rockskon 4mo agoExpanding the scope of it is new.
- soyunpendej0 4mo ago> 5.1.3 An officer may conduct a basic search of an electronic device with or without suspicion, subject to the requirements and limitations provided herein and applicable law. > 5.1.4 An officer may perform an advanced search of an electronic device only in instances in which there is reasonable suspicion of activity in violation of the laws enforced or administered by CBP or, in the absence of individualized reasonable suspicion when there is a national security concern. In this climate, the qualifiers in 5.1.4 should be assumed to apply 100% of the time. So, if you bring a device, be prepared to either unlock it and hand it over to be mirrored or abandon it and deal with whatever consequences fall out of that decision. I'm probably never leaving this shithole again but, if I do, I'm coming and going empty-handed.
- cyanydeez 4mo agothat's not your only options, but the ones likely everyone will follow. Guidance does not equal law.
- 217 4mo agowhat does this mean in practice? is everyone being / going to be forced to unlock the devices during the border crossing
- chrsstrm 4mo agoThis directive was issued in January of this year, what is relevance of being posted today? I love all the instances where it says, we will not do this or infringe in this way... unless it is a matter of national security, which we don't have to disclose to you. So basically, do what you want as long as you write it up properly. And this part: 5.3 Review and Handling of Passcode-Protected or Encrypted Information 5.3.1 Travelers are obligated to present electronic devices and the information contained therein in a condition that allows inspection of the device and its contents. If presented with an electronic device that is protected by a passcode, encryption, or other security mechanism, an officer may request the individual's assistance in presenting the electronic device and the information contained therein in a condition that allows inspection of the device and its contents. Passcodes or other means of access may be requested and maintained for the duration of the search if needed to facilitate the examination of an electronic device or information contained on an electronic device, including information on the device that is accessible through software applications present on the device that is being inspected or has been detained, seized, or retained in accordance with this Directive. I had thought (and Supreme Court ruled) you could not be compelled to unlock an encrypted device, which is why I always powered mined down before crossing. That goes against the obligated to present devices in a condition that allows inspection portion.
- mtremsal 4mo agoI think the context is just mass international travel due to the US hosting the World Cup, no?
- 1over137 4mo agoco-hosting
- dylan604 4mo ago> I had thought (and Supreme Court ruled) you could not be compelled to unlock an encrypted device, which is why I always powered mined down before crossing. Does that apply to non-citizens? If a CBP officer doesn't like you as a non-citizen, like your lack of cooperation during an interview, they could just deny your visa and your entry into the US. If you're a citizen, they can't deny your re-entry. They can delay you for however long and ruin your day and even keep your devices, but you get to go home.
- KennyBlanken 4mo agoA friendly reminder that the CBP has decreed itself to have authority within 100 miles of any US border, as that it is its interpretation of "a reasonable distance" from said border. That basically encompasses two thirds of the population. The last two years have demonstrated a radical need to curtail that range of authority and shift from it being vaguely specified to a concrete legislative specification. Even ten miles seems (pardon the pun) borderline excessive. There is no reason CBP can't hand off stuff to local, county, state, or federal domestic law enforcement. We have no shortage whatsoever of law enforcement in this country and they're able to communicate inter-agency better than ever via cell phone, tools like slack/teams, text messages, email, and long distance digital radio systems. Maybe in the 1950's when all they had were shitty radios given them that sort of range was appropriate. Not anymore.
- TylerE 4mo agoMore importantly, they count ocean as border.
- wilted-iris 4mo agoInternational airports as well.
- jkestner 4mo agoAnd Lake Michigan, as it’s connected to international water. Suppose next they’ll claim all rivers as borders.
- deleted 4mo ago[deleted]
- tptacek 4mo agoThis is false. It's an old fundraising claim used by the ACLU; they have since set up pages backing away from it (because convincing people in the US that they don't have rights they do in fact have is not good civil liberties advocacy). There's direct SCOTUS precedent on this. There's a 100 air mile border definition that's material to immigration enforcement (with complicated limitations). It does not determine where searches under the border search exception can occur.
- trebligdivad 4mo agoSo hmm this allows 'electronic or digital' information to be examined - so you're fine transporting your information read out on cine film?
- delichon 4mo agoWe need a constitutional amendment that says "we really mean it" with respect to the 4th and 9th amendments, explicitly including personal digital data and criminalizing general surveillance. With fangs.
- tptacek 4mo agoThe border search exception was designed by the framers.
- themafia 4mo agoThe collection act originally was intended to apply to merchandise and merchant ports. The concept was judicially expanded upon in 1925 but wasn't fully ensconced into federal law until 1952.
- tptacek 4mo agoAt actual border crossings, the practice at the time of the framers was that warrantless searches/inspections at border crossings were normal and permissible.
- simoncion 4mo agoAt actual border crossings, the practice at the time of the framers was not to carry along all of your private correspondence, business records, reading lists, and so forth. Related to that, given the complaints that started the war, I'd strongly expect that in Washington's day it was not permitted to perform unwarranted searches of one's sealed correspondence going through the US Post. [0] As the ability to perform surveillance on members of the public expands, laws and regulations must be reconsidered with these new capabilities in mind if just outcomes are to be maintained. Laws, regulations, and punishments that were just and reasonable when one expected to learn about and prosecute one offender in -say- a million are likely unjust and unreasonable when one expects to learn about and prosecute every single offender. [2] [0] See also Section 16 on numbered page 236 of [1] [1] <https://govtrackus.s3.amazonaws.com/legislink/pdf/stat/1/STATUTE-1-Pg232.pdf https://govtrackus.s3.amazonaws.com/legislink/pdf/stat/1/STA...> [2] Yes, there are offenses -such as murder- for which this doesn't hold. I'd expect that these are the minority of offenses.
- Rekindle8090 4mo ago[dead]
- floatin 4mo agoI just factory reset the phone or tablet and pull my data back down from cloud storage.just show up with the phone on the choose your language screen.
- bsimpson 4mo agoIt says they're supposed to put it in airplane mode before searching. Of course, there's nothing preventing a Snowden-style klep the cookies and let a three letter agency reuse them later.
- SanjayMehta 4mo agoWhen you enter Tibet, Chinese Border Patrol (heh!) will go through your photo album looking for images of the Dalai Lama. If you have a picture of yourself wearing a "Free Tibet" t shirt they will delete it. That's about it.
- ChrisArchitect 4mo agoMore recently: EFF to 4th Circuit: Electronic Device Searches at the Border Require a Warrant https://news.ycombinator.com/item?id=48115059 https://news.ycombinator.com/item?id=48115059
- natch 4mo agoThis kind of device access also affects others whose private information is shared privately on the device of the traveler. CBP partly justify the invasion of privacy by citing a supposed reduced expectation of privacy when traveling. But people whose data is caught up on the devices of others are not the ones traveling, but they are still having their messages read and photos copied.
- bsimpson 4mo agoThe Supreme Court has recently had an appetite to overturn precedent deemed to be rooted in faulty case law/reasoning (controversially, Roe v Wade). It would be nice to see that energy pointed at blatantly unconstitutional notions like "you have no privacy when traveling." Except for the parts that say "we get to be even more invasive for 'national security concerns'" and that they can compel you to provide a password, this doc seems mostly reasonable if you accept that they can search you. Then again, it's not clear _why_ they should be able to search your devices. There are no foreign pests nor WMDs that exist as documents on a device. This is clearly just the government being nosy because they think they can.