Slashdot Log In
Securing Your Notebook Against US Customs
Posted by
timothy
on Thu May 15, 2008 11:21 AM
from the best-interests-at-heart dept.
from the best-interests-at-heart dept.
Nethemas the Great points out a piece from Bruce Schneier running in the UK's Guardian newspaper with some tips for international travelers on securing notebook computers for border crossings. A taste of the brief article:
"Last month a US court ruled that border agents can search your laptop, or any other electronic device, when you're entering the country. They can take your computer and download its entire contents, or keep it for several days. ... Encrypting your entire hard drive, something you should certainly do for security in case your computer is lost or stolen, won't work here. The border agent is likely to start this whole process with a 'please type in your password.' Of course you can refuse, but the agent can search you further, detain you longer, refuse you entry into the country and otherwise ruin your day."
Related Stories
[+]
IT: Inside The Twisted Mind of Bruce Schneier 208 comments
I Don't Believe in Imaginary Property writes "Bruce Schneier has an essay on the mind of security professionals like himself, and why it's something that can't easily be taught. Many people simply don't see security threats or the potential ways in which things can be abused because they don't intend to abuse them. But security pros, even those who don't abuse what they find, have a different way of looking at things. They always try to figure out all the angles or how someone could beat the system. In one of his examples, Bruce talks about how, after buying one of Uncle Milton's Ant Farms, he was enamored with the idea that they would mail a tube of live ants to anyone you asked them to. Schneier's article was inspired by a University of Washington course in which the professor is attempting to teach the 'security mindset.' Students taking the course have been encouraged to post security reviews on a class blog."
[+]
Hardware: US District Ct. Says Defendant Must Provide Decrypted Data 767 comments
An anonymous reader writes "If you're planning on traveling internationally with a laptop, consider the following: District Court Overturns Magistrate Judge in Fifth Amendment Encryption Case. Laptop searches at the border have been discussed many times previously. This is the case where a man entered the country allegedly carrying pornographic material in an encrypted file on his laptop. He initially cooperated with border agents during the search of the laptop then later decided not to cooperate citing the Fifth Amendment. Last year a magistrate judge ruled that compelling the man to enter his password would violate his Fifth Amendment right against self-incrimination. Now in a narrow ruling, US District Judge William K. Sessions III said the man had waived his right against self-incrimination when he initially cooperated with border agents."
sohp notes that "the order is not that he produce the key — just that he provide an unencrypted copy."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
This is why you make sure... (Score:5, Funny)
Re:This is why you make sure... (Score:5, Funny)
But I think that "1 minute to auto-destruct [bedug.com]" can be a bit too bad.
Parent
Re:This is why you make sure... (Score:5, Funny)
Parent
Re:This is why you make sure... (Score:5, Insightful)
No shit, Sherlock. That's sort of the point.
If nobody ever stands up to this kind of bullshit, even in these kinds of small ways, it's only going to get worse and we're *all* going to spend a lot more time in tiny cold waiting rooms whenever we try to get anything done.
Parent
Re:This is why you make sure... (Score:5, Insightful)
Parent
Mess with them (Score:5, Funny)
Yup (Score:5, Insightful)
The sad thing is that citizens think this idiotic idea of checking laptops at airports serve any kind of law enforcement objective other than generalized panic and further diminishment of democratic values such as the right to privacy.
This is your government fucking people up (and "people" can be foreigners or locals entering the country), attempting to find in informations traces of delincuent activity that, if youre a two bit moron you know you can save it anyhow, in a mostly anonymous fashion on google's, yahoo's or microsoft's servers for free, and any number of services that are available today.
True criminals simply have huge botnets and hidden servers behind the huge pr0n/spam nets and they DO NOT carry incriminating evidence with them and EVEN IF THEY DID, how in hell is a custom's agent going to find them?
I mean, i have a better solution than that of bruce: change your initab so initdefault is 3, make sure that that level does NOT turn on the wifi card or any networking at all, change your shell to ASH (hopefully temporarilly) and let them have the root password, who cares.... good luck, mister customs agent.
A naive suggestion (Score:5, Insightful)
The downsides? You probably won't be able to work in the airplane, but is it worth it now that the Customs are being so much trouble?
My laptop (Score:5, Funny)
It's actually because I need to load a device management driver that overrides the BIOS data for the hard disk, but it may actually be worth it for them to try to fiddle around at the MS-DOS prompt...
Yes it will work. (Score:5, Informative)
So first, they would have to know you even have something encrypted (which is just a guess if they see TrueCrypt installed). Then they'd have to know what/which files was/were encrypted (which can't be determined by examining the file). Then they'd have to ask you to mount the volume and provide the password (at which time you then provide the shadow volume password, which only contains innocuous files).
I can't be the only dummy to figure that out.
Refuse you entry to the contry (Score:5, Interesting)
Re:Refuse you entry to the contry (Score:5, Informative)
Or another example is detain you and/or the computer until they can image the drive.
And they can confiscate contraband (your definition may vary).
Ultimately, you have the right to enter the country.
Parent
Corporation Lawyers (Score:5, Interesting)
The IP on my laptop is easily worth 10x more than the value of the laptop itself.
Re:Corporation Lawyers (Score:5, Informative)
If the IP on your laptop is worth that much, you shouldn't be carrying it outside of the country on a laptop. I worked at a company that prohibited us from carrying certain information on our laptops to some middle eastern countries, as they were known for seizing/replicating hard drives from employees in certain industries.
If anything, you may face legal issues from your employer if you're taking that valuable of information out of the country.
Parent
US Customs has always been like this (Score:5, Informative)
I just pretty much walked right through in China - I handed them the entry form (one half of the two part form - the other half you give them when you leave) and they waved me through. Customs in China did not even ask to see my laptop, never mind read files or anything like that.
On returning to the US at Detroit International, I was given the 3rd degree by US Customs agents, and I'm a US Citizen. "How long were you in China?" (as if he couldn't tell by the side-by side entry/departure stamps in my passport) "What were you doing there?" (visiting friends) "What do these friends do for a living?" (A couple of college professors and a financial analyst)
This happened on both of my trips.
And I noticed that they were doing this to EVERYONE, not just me. (The plane had several hundred people on it.) I'd hate to see what they were doing to Chinese citizens entering the US.
I hope they realize that they are going to scare businesses away from the US if they keep this up.
I find it somewhat ironic that the captcha for this post is "undergo".
Simplest solution. Canada (Score:5, Insightful)
Truecrypt + Thumbdrive = Hidden OS (Score:5, Informative)
This post [truecrypt.org] on the Truecrypt forums describes a way to install two OSes, one for show, and one hidden. Unless there is a Truecrypt rescue CD or bootable USB thumbdrive inserted the system will boot to a normal Windows desktop. This method would hold up to any casual sort of inspection, such as those customs agents carry out dozens of times per day. There are a couple of traces that would need to be removed in order to actually have "plausible deniability", but to me not having the questions asked in the first place is preferable to being able to deny one of the potential answers.
It's sad that you might need to do things like this, but there are often technological solutions to social problems.
We have arrived! (Score:5, Insightful)
We are discussing "hiding legal and unincriminating" stuff so that we don't get hassled by government police. We have gone far beyond the "if you don't have anything to hide, you have nothing to fear" argument where now, even when you don't you have plenty to fear... in this case, potential loss of ability to work!!
They have been going too far for a while, but this is a point at which even the most common person can appreciate and understand the problem with this.
If the EFF were buying "public awareness" ad time on TV, radio and print (I haven't seen any if they already are) I'd donate $100 each month from now until "we've won" whatever that means. I'm sick of this.
Need One of These (Score:5, Informative)
Re:Dual Boot (Score:5, Informative)
It depends on what, in particular, you're concerned about. As far as I know, they don't currently routinely search laptops, so it'd be speculation to guess at what a routine search they don't do would miss.
Parent
Re:Dual Boot (Score:5, Insightful)
if you are a known individual (person of interest) and you expect to be stopped at the border, don't carry sensitive material with you. Hell, just mail a flash drive.
Parent
Re:Dual Boot (Score:5, Informative)
of course there's always deniable encryption, ie rubberhose [iq.org].
Parent
Re:Dual Boot (Score:5, Insightful)
If they want to clone your hard drive and disassemble it later, your secondary boot OS is going to stick out. Not that it is unusual for anyone to have more than one OS on a hard drive, but it won't be hidden. Remember, they essentially have physical control of the computer. "They" win. Unfortunately, it comes down to 1) security by obscurity or 2) nothing to hide.
Roll up your sleeves and bend over.
Parent
Re:Dual Boot (Score:5, Interesting)
I find the contrast sad... when I recently flew into Amsterdam, I grabbed my bag, the guy stamped my passport, and I walked through a door out into the real world. No questions, no forms, no inspections, no going through my bags. And this while I'm coming from the "land of the free" to one of those wacky socialist European countries.
Parent
Re:Dual Boot (Score:5, Informative)
In my own case, I encrypt it (using Truecrypt - awesomest OSS program I've found in a long time) because while my family knows I keep porn on my computer, if I ever have a random car accident or something I don't want them to see exactly HOW MUCH I have on the system once they start looking through my files
Parent
Depends upon how proficient they are. (Score:5, Informative)
Parent
Re:Dual Boot (Score:5, Informative)
Parent
Re:Dual Boot (Score:5, Funny)
Parent
Security through Obscurity requires Good Camo (Score:5, Insightful)
What is this, people? Waving flags screaming "I'm hiding something!"
If I actually had something to hide, say, key NDA-restricted docs, and I HAD to carry them on me, I wouldn't put up red flags like obvious encryption or a partition with some weird-ass hippiecommie suspicious linux install. If you want to fly below radar, you need stealth.
First: a vanilla install of windows or macOS. Standard business apps, standard documents folder with typical usage, such as correspondence, presentations, expenses, etc.
Second: family photos. Friends on vacation, etc. Make them more than typical: lots of them, and innocuous. If you're too straightlaced to keep personal stuff on your computer, that's suspicious too.
Third: on a different computer, encrypt your files with decent encryption, AES or something, using strong password. Make sure the file name isn't interesting. Doesn't matter, if a professional gets the files, they'll be cracked; the point is to keep them unobserved, so this part's kind of optional.
Fourth: mask them inside innocuous files like the photos. Transfer them to your laptop. Now you're camouflaged. Smile, respect, make eye contact, be naturally a tiny bit nervous but with nothing to hide.
The secret to security? don't get caught.
[/theory]
Parent
Not dual boot; the network IS the computer (Score:5, Insightful)
Parent
Re:Dual Boot (Score:5, Funny)
Parent
Re:Dual Boot (Score:5, Informative)
Parent
Re:Dual Boot (Score:5, Insightful)
Sounds like a small price to pay in order to protect my right to liberty. Just because the government demands access does not mean I have to comply.
Other people have paid a far higher price for liberty ("the full measure of devotion" aka death).
Parent
Re:Dual Boot (Score:5, Insightful)
Being detained by customs does not give you a criminal record. If you're a non-citizen, it may indeed cause trouble in entering the country again. To get a criminal record, you must be tried and convicted of a crime.
Parent
Re:Dual Boot (Score:5, Informative)
While all of that is true, nowadays being put on the "naughty list", or having a name like someone on the naughty list, or being brown-skinned is enough to effectively punish you as much as if you'd been convicted.
There has been a Canadian citizen in Sudan [www.ctv.ca] who has (had?) been trapped there because, while he had never been charged with anything, he had been suspected of doing something. He got trapped, and could come home due to being on the no-fly list. Basically, years in legal limbo.
I wouldn't assume getting detained by customs wouldn't necessarily cause you problems. When your name ends up on the unpublished, unfixable, or secret lists of people they don't want to fly
Do you really want to find out the limits of where your theoretical rights end and where your abridged, post 9-11 rights end?
Cheers
Parent
Re:Dual Boot (Score:5, Interesting)
Parent
Re:Not enitrely true... (Score:5, Insightful)
I have been denied access to countries for less than not providing a password. They can pretty much turn you away because they feel like it.
Parent
Re:Not enitrely true... (Score:5, Insightful)
America is just now doing this? I was returned from Canada and they searched my luggage, laptop, read private conversations, opened letters all cause i was going to be staying 2 months which was too long of a vacation/job for them apparently. The guy was just a prick and didn't want anyone taking jobs. Canada is terrible for this but on Slashdot everything is the big bad USA. I'm so sick of the slant on slashdot. All countries do this its their right to refuse what type of people in their country. Some agents turn away illegal Mexicans cause they're scared of them taking jobs, some customs agents dont like the idea of a foreigner getting paid more than them.
Parent
Re:Not enitrely true... (Score:5, Insightful)
This amendment exists to protect citizens from a government that may object to the content they create or possess. Maybe someone can explain why the act of entering the country nullifies my constitutional rights.
Parent
Re:Not enitrely true... (Score:5, Informative)
Because legally you have not entered the country until you pass through customs. Up until that point you are in international waters, so to speak.
If you're not here, you're not under the jurisdiction of our laws.
Parent
Re:Not enitrely true... (Score:5, Insightful)
Try not to confuse 'legal fictions' with reality
Parent
Re:Not enitrely true... (Score:5, Interesting)
IANAL.
Because technically it doesn't. You said it yourself:
I changed the emphasis, but as you can see the 4th amendment only protects you from unreasonable searches. Most people believe that searching a person's belongings before granting entry into a country is a reasonable search.
Parent
Re:Not enitrely true... (Score:5, Informative)
Parent
Re:Not enitrely true... (Score:5, Insightful)
I would say that most sovereign nations have the power, not the right, to control who and what enters the country.
Parent
Re:TrueCrypt (Score:5, Insightful)
If you're going to carry stuff over the border you don't wan't The Man to look at, put it on a thumb drive and attach it to your keys.
Parent
Re:TrueCrypt (Score:5, Interesting)
I think TrueCrypt needs to have an offset for its containers, so that it expects the data to begin at that offset, and ignore whatever is before that..
Parent
Re:TrueCrypt (Score:5, Interesting)
Parent
Re:One more reason not to fly. (Score:5, Funny)
Parent
Re:Problem? (Score:5, Insightful)
First, I'm not American. I have visited but these incidents literally remove the country from the list of viable or "safe" foreign countries I could travel to.
"I carry corporate source, designs and some customer data on my laptop. Yes, it would be a problem if it were made public. I encrypt it, but do not hide it. I see no reason that a border guard, a TSA guard or even the (whisper) NSA would choose to give it to a competitor if they had it."
-Several thousand dollars.
- Industrial espionage.
Even in the UK, some staff at airports have been caught selling on items stolen from baggage, there's nothing to stop a corrupt official doing so. By giving them to ability and "legitimate" reason to search ANY laptop for ANY reason, it's inviting problems.
- A letter from Microsoft offering a reward for non-licensed or pirate software.
- Anything that could accidentally tag you as a terrorist.
Customs officer browsing through my web history: You read wikileaks lately? We'll have that as evidence of, in your own words, being an anarchist.
- THIS POST. Say I took a laptop with a copy of my posting history to slashdot to the US... they could EASILY use this very post against me. Evidence of "wanting to avoid customs" or some such rubbish.
"What's the problem here? Is this a matter of principle or is there something to hide?"
Neither. It's my data. You have no right to go through it without reasonable suspicion FIRST. And then in a certified, supervised way to ensure you keep within your stated use of the data. No other civilised country in the world currently does this and the UK has been dealing with terrorism for FAR, FAR longer than the US has (a UK airport security expert was told that he was "being paranoid" before 9/11 when he visited a US airport and complained about their lax security - within days he was on BBC News recounting the tale because 9/11 happened).
My workplace cannot even throw a hard drive out with having it professionally destroyed, whether it's been exposed to confidential data or not. What makes you think I can let a customs officer copy it without MASSIVE assurances of everywhere the data could end up? The chances are I'd be in a questioning room while all the copying was going on.
"Consider how important your data is to a customs official. News flash: I'd bet a lot that they don't give a rat's ass what you've got, as long as it's not illegal. If it's illegal, then the problem is totally different and you have no right to complain about it."
Define illegal. I think you'll find it depends on jurisdiction, for a start, and includes such things as data protection laws. This is the problem.
As a business, I would be required to NOT TAKE SOME DATA into the US because of this - UK and EU data protection laws means that I *can't* let anyone see it, whether or not it's "secret". If your salesman is going to have to break British law to make a sale in the US, then he's not going to GO to the US. Or he'll have to take the steps mentioned in this article.
Say my office gave me a laptop with copy of Windows that was installed from a pirate key... that's "illegal". I could get detained *without reasonable suspicion* and possibly convicted because of that. Say I *don't know* the password to an "encrypted-looking" file on the laptop (like, I don't know, say a database contained within a business program accessed only by Word macros or company-created utilities - I have seen many such systems loaded on laptops for employee use). I'm detained until I release it.
It's not that I have anything illegal under US law - the US is not the world, though. Things that the US does are considered illegal in other countries. Let's not go too far down that avenue because it's just too easy to get into country-bashing.
It's that the US customs have no reason to demand inspections without reasonable suspicion. They certainly s
Parent
Re:embolden? (Score:5, Funny)
Because
We have a whole plethora of words at our disposal with which to convey subtly nuanced meaning and/or sound like pompous gits, depending on the gravity and artifice of the situation. Why, the sheer range of verbal and literary shenanigans available to us is both rejuvenating and invigorating -- allowing us to express ourselves through many permutations of linguistic machinations.
I suppose we could go the 1984 route and strip out all of the words for which people think there is no longer a valid purpose. That way we'd all come down to a nice, easy level of communication, and eventually strip certain kinds of thoughts from people.
In the meantime, some of us will reinforce the veracity of our arguments and interactions with our more polysyllabic linguistic choices to more adequately articulate the lucidity of our positions on topical considerations.
Cheers
Parent