8 ms·
I guess you need to make sure all your backups are in order before crossing the border.
by fry_the_guy 13y ago
I guess you need to make sure all your backups are in order before crossing the border.
- mortov 13y agoI guess you need to make sure your devices are wiped or left at home. A backup just means you have your own copy of what just got taken off you at the border for no good lawful reason. Having my own copy would not reassure me of much.
- willbill 13y agoMoxie Marlinespike of WhisperNet has explicitly said that he leaves his devices at home when traveling because of this.
- lambda 13y agoOr make sure that they have full-disk encryption and are cold shutdown when you cross the border. While jurisprudence is still a bit fuzzy on this (it has flipped back and forth on a few appeals in a few separate cases, and never been conclusively decided by the Supreme Court), there have been ruling upholding the fact that you can't be forced to hand over your password due to the fifth amendment, unless the Government can already show that they know via other means that you have incriminating files on there.[1] On the border, you would probably be safe from mandatory disclosure of your password without the border patrol getting a court order, and of course the whole point of this complaint is that the government is using border crossing as an end-run around the courts, being able to do searches that a court wouldn't otherwise approve. So, using full-disk encryption that you trust, on all electronic devices that you carry, and making sure that they are cold shutdown, is probably sufficient. You should of course have a backup as well, as the border patrol may impound your devices while they try to decrypt them. All in all, how much effort we have to do to defend ourselves from our own government is getting ridiculous. I don't know how to convince the American public of this, but we are not only violating the privacy of tons of people, but killing people who choose to drive rather than fly[2] due to the excess hassle that our "security" systems provide. 1: https://en.wikipedia.org/wiki/Key_disclosure_law#United_States https://en.wikipedia.org/wiki/Key_disclosure_law#United_Stat... 2: https://www.schneier.com/blog/archives/2013/09/excess_automobi.html https://www.schneier.com/blog/archives/2013/09/excess_automo...
- chiph 13y agoEven with full-disk encryption, an image will be made of the drive, and the government will keep a copy on the chance that the password will be revealed later. Or the algorithm gets broken/weak enough at some point in the future.
- toomuchtodo 13y agoSilly question. Let's assume you have a device like a Macbook Pro or a Macbook Air, where you can't physically remove the drive without ungluing the device. You hotrod the firmware so only trusted USB devices with a specific encryption key are permitted to connect. How would the drive be imaged?
- lambda 13y agoThunderbolt target disk mode: http://support.apple.com/kb/PH3838 http://support.apple.com/kb/PH3838 Perhaps you could solve this by "hotrodding" the firmware, but it's not particularly obvious how you could do that without risking bricking your laptop.
- toomuchtodo 13y agoPerhaps Apple needs to require a password to boot off USB or to access target disk mode.
- Torgo 13y agoIt's too bad the newer Macbook Pros don't come with ExpressCard slots anymore. I used to boot off a fast SSD expresscard. No disadvantages at all, other than the card ran hot. Remove the internal drive and when you pop out the Expresscard, much lower attack surface.
- andrewpi 13y agoAfter the past week's NSA revelations, just what full disk encryption system should we be trusting? I think it's fair to assume that any commercial implementation is compromised.