‹ BackHN Continuity

Thread

Second Circuit allows government to search electronic devices at the border

131 points · 79 comments · HotGarbage

  1. k310 · · focus · HN ↗
    Everyone please read Surveillance Self Defense from EFF [0]

    My advice, take a burner phone to the airport (and elsewhere?), and since devices are subject to warrantless search anywhere and everywhere, via exceptions to the fourth amendment [1] (the constitution seems designed to be bent or outright ignored), keep your data at home and encrypted. The "cloud" is a government data supermarket.

    For example.

    > While the Fourth Amendment is the foundation, federal and state laws can add layers of complexity. For example, the Patriot Act expanded the government's ability to conduct surveillance and searches, particularly in national security cases, sometimes with a lower burden of proof than traditional criminal investigations.

    MUCH lower.

    [0] <a href="https:&#x2F;&#x2F;ssd.eff.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;ssd.eff.org&#x2F;

    [1] <a href="https:&#x2F;&#x2F;uslawexplained.com&#x2F;warrantless_search" rel="nofollow">https:&#x2F;&#x2F;uslawexplained.com&#x2F;warrantless_search

    1. FuriouslyAdrift · · focus · HN ↗
      When I travel internationally, I do not take any electronics with me.

      If I need a cell phone, laptop, etc., then I will buy or rent something cheap at the destination.

      I got into the habit while traveling back and forth the mainland China as it was our corporate policy (and we never brought any electronics back, either).

      1. alyeska2 · · focus · HN ↗
        I tried that once.

        Then when I tried to log in to my Gmail account at my destination, it flagged it as a suspicious login attempt and wouldn&#x27;t let me in without entering a code they texted to my American phone number, which meant I was locked out of my email for the duration of the trip.

        Plus travel day realities often require your phone and accounts - plane tickets, Uber&#x2F;Lyft, hotel reservations or updates from Airbnb with check-in instructions, door codes, etc.

        It&#x27;s a tremendous challenge and hassle for any regular person. We really just need to push back on the government overreach. It&#x27;s tragic that half of the Trump voters proclaim to be &quot;small government&quot; and &quot;Don&#x27;t tread on me&quot; but then tolerate things like this. There&#x27;s certainly a bipartisan group of people opposed that are large enough to effect change if we work together.

        1. belorn · · focus · HN ↗
          I 100% agree that the best solution would be for the law to catch up and actually treat privacy as a human right. Until that time there are things which, while challenging and a hassle, do help.

          I would use the same sim-card in the burner phone. Any attack by the government that they can do with your real sim card can also be done through phone number spoofing.

          For email, use unique emails (things like booking+youremail@...) for reservations&#x2F;bookings&#x2F;tickets and have those forwarded to a second email account that you want to use during the trip. It is already good privacy hygiene to use unique emails for all types of registrations, and you will have more control when services eventually have a leak.

          1. leptons · · focus · HN ↗
            &gt; (things like booking+youremail@...)

            This is so trivially easy to bypass. If you&#x27;re a service selling email addresses, just strip off the booking+ part and you have the &quot;real&quot; email address.

            All my sign-up email addresses are via a catch-all email, so I can just give a service &quot;thisservice@mydomain.com&quot;, or &quot;thatservice@mydomain.com&quot;, so I there is no single &quot;real&quot; email address, and I get to track who exactly is selling my email address. So far I haven&#x27;t had problems with anyone spamming &quot;anything@mydomain.com&quot;.

            1. belorn · · focus · HN ↗
              They can bypass it, and as the user you can also use any other sign or character that you want. If you email is foo@ then you can use the letter x, as registrationxfoo@. A popular choice for a company email is first.lastname@, so you can use a . for it, or the - character. + is just what some program, like procmail and Sieve, will recognize without much trouble.

              Using a a catch-all email with your own domain works also perfectly fine. Doesn&#x27;t work as well if there is multiple email users of that domain.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.