back
26 comments
It's really depressing that this kind of thing is even needed for the US. As a citizen with a lot of privileged status, I'd personally be pushing back a lot if any US CBP person ever asked me for anything beyond proof of citizenship and the bare minimum to show I'm not carrying contraband. I'd consider standing up to that as a way to help other people who can't as easily stand up to it. On the other hand when I'm visiting a foreign country on a visa, I'm in a similarly disadvantaged position.

(As an aside, if anyone in security is ever looking for a trustworthy and accurate journalist, I strongly endorse Andy Greenberg; consistently good at respecting "on the record" vs. "off the record", and he actually asks good questions.)

> On the other hand when I'm visiting a foreign country on a visa, I'm in a similarly disadvantaged position.

US citizens need to expect that this kind of thing will spread to other countries. Unless your government will be able to pressure other countries to make americans excepted from such laws abroad. I think what we essentially will see in the future would be a different kind of border control based on nationality even through the travel agreements would basically be the same.

> I'd consider standing up to that

What does that even mean? They'll detain you or deny entry. Then what?

I'm a US citizen. Aside from "is this actually Ryan Lackey, the US citizen?", immigration has no power to keep me out of the country.

"Do you have reason to believe I'm someone other than the US Citizen in this passport? Please articulate your specific reasons for concern." is itself a pretty solid validation of "this guy is 1) a US citizen 2) knows the law 3) is likely to have >50 lawyers as friends and will pursue the matter happily. I'm really polite/friendly with ICE/CBP -- usually all I get is "welcome home", very infrequently they ask "where were you?" -- but in principle they can hassle people.

Customs has some additional power -- do they believe you're transporting contraband -- illegal items, untaxed items, or dangerous items (agricultural contact). But since I never travel with illegal items, and generally have everything very nicely organized and minimalist, the only real thing they could claim is "you have digital files we want to access", and that is 1) an emerging area of law and 2) exactly the battle I want to fight. In general the law is on the side of citizens not turning over data at borders, although it's nowhere near as settled as most other things.

>I'm a US citizen. Aside from "is this actually Ryan Lackey, the US citizen?", immigration has no power to keep me out of the country.

This is a dangerously simplistic view of the US security apparatus that will almost certainly backfire on you if you actually try to test it out.

If you happen to resist inquiries in any meaningful way, there's a significant chance that they will seize everything you're carrying, find a means to force you into unlocking your digital devices, then hit them with a fine-toothed comb until they find enough to a straw-man justification to continue detaining you and making your life hell. A few sarcastic or otherwise disestablishmentarian remarks to a CBP offer it all it takes to turn a minute-long interaction into a days or weeks-long holiday in a detention cell.

And sure, the extent to which CBP has the right to pry into your digital life is still an emerging area of law, but in the status quo, things lean very much in CBP's (and whatever other law enforcement agencies they decide to pull in) favor.

Sure, if you're a US citizen, they'll likely need to eventually let you in, but that doesn't necessarily mean that you're out of trouble at that point either. At the very least, you're now a strong candidate for continued surveillance, if not further sanctioning, depending on how the information collected during your re-entry to the country might correlate you with various 'risks to national security'.

I would be exceptionally surprised if they did anything beyond ~hours of detention and confiscating as much stuff as they possibly could to "investigate" (essentially as punishment).
Please do put yourself in this position and refuse to give your password to unlock your phone or social media accounts. You may be detained and have your phone or laptop confiscated. In which case you can try to sue them, which I agree we all need to attempt to stand up to this sort of thing. For me though, I cannot currently not afford to lose my phone to make a point on principal.

But the reality is that customs and other agencies in places like airports seem to be getting away with pretty much any sort of invasion of privacy they want, very consistently, so things may not go the way you assume.

2FA? With a mobile number? Did the author completely forget Snowden, and how all the major phone companies give NSA direct access? Did the author forget the broad NSA information sharing that Obama enacted just before leaving office? Even that damned Coast Guard can get your 2FA code now.
> Even that damned Coast Guard can get your 2FA code now.

Posting unsourced and absolutely false claims does not help anyone, honestly. I would even consider it harmful.

Before Snowden, they liked to call it tin foil hats.

https://theintercept.com/2017/01/13/obama-opens-nsas-vast-tr...

One of those agencies is the Coast Guard. If the message crosses national boundaries, it's fair game.

http://www.nytimes.com/2013/08/08/us/broader-sifting-of-data...

And before you pass through customs, you are considered outside the country.

All legal. Checkmate.

Fortunately, I've just discovered that the SMS option isn't required on a Google account. Now you just have to remember to remove your travel yubikey from the account before you fly home.

Please review the post linked from the beginning of the linked The Intercept article, here: https://icontherecord.tumblr.com/post/155766682978/fact-shee...

You'll see that SIGINT sharing is not a free-for-all in any manner, it is restricted. It seems dishonest to tell people the Coast Guard can use it to compromise SMS 2FA (I'd be far more worried about other countries compromising SMS 2FA in a close-access scenario, using an "IMSI catcher" or similar device to intercept the incoming message).

>You'll see that SIGINT sharing is not a free-for-all in any manner, it is restricted.

Before Snowden, we were told investigatory powers were "restricted" as well. Then we learned linux journal readers were put on watch lists as extremists, and system administrators are routinely targeted for compromise.

The point being, there's no technical reason to stop them from intercepting the 2FA over SMS, so they will. That's been clearly demonstrated by earlier leaks. Those people weren't fired/jailed/etc. They'll just do it again.

> Before Snowden, we were told investigatory powers were "restricted" as well. Then we learned linux journal readers were put on watch lists as extremists, and system administrators are routinely targeted for compromise.

Again, I'm sorry but none of this is true at all. I could absolutely believe that a journalist misunderstood something they read in a leak and then made such a claim (Happened with most of the Snowden leaks), but that does not make it true.

> The point being, there's no technical reason to stop them from intercepting the 2FA over SMS, so they will. That's been clearly demonstrated by earlier leaks. Those people weren't fired/jailed/etc. They'll just do it again.

To the contrary. When you say "clearly demonstrated by earlier leaks" I believe you may be mixing up an inquiry made to NSA with regards to improper access to DNI (Or perhaps that was not supposed to be a public response and was indeed leaked? Not certain). Action was taken against these individuals who "tested the system" by trying to look up themselves and/or someone they knew, even if the system blocked the query from actually running due to the fact that they were prevented from targeting US persons.

I believe you are being genuine about your concerns, but again, it can be harmful to spread falsehoods when people reading these comments may not know better and could believe what you're saying to be true (Especially in a thread like this).

>Again, I'm sorry but none of this is true at all.

http://www.linuxjournal.com/content/are-you-extremist

It's you against the world here. Trying to rewrite history?

>I could absolutely believe that a journalist misunderstood something they read in a leak

Literally, the document title is "I hunt sys admins"

https://theintercept.com/2014/03/20/inside-nsa-secret-effort...

There's nothing to misunderstand. They used automated attacks on readers of Slashdot and LinkedIn.

http://www.ibtimes.com/edward-snowden-reveals-quantum-insert...

Compromising system admins is a routine part of their job. It's one way they collect private keys to decrypt internet traffic. That is an established fact from the Snowden leaks.

Step 1: Don't travel to the U.S.
step 0: use a password manager. step 1: use randomly generated passwords for every account in that manager. step 2: neglect to bring that password file, or any means of accessing it, across a border.

Them: Give us your password! You: I literally cannot. Your move!

Them: Ok, we're denying you entry to this country.

Alternatively, if you are a citizen:

Them: We'll just keep these devices, then. When you get the password maybe you can get them back after we've searched them. Just wait here for 6-24 hours while we do our alternative background check.

If you're a US citizen and are harassed by CBP at the border (and you know you're not doing anything wrong), you should stand up for your rights.
Sure, I'm just saying that they aren't going to just be impressed with your awesome op-sec, they are going to seize your devices as evidence and harass you to the full extent that their inappropriately broad powers allow. If you're not ready for that to happen, probably best to make other arrangements.
Yeah, and I'm saying that if you can do this, you should, to help the many people who can't. I'd get more lulz value out of a $250 chromebook being taken for 6mo on bogus grounds than the cost of the chromebook.

It's not a solution (since they can easily pre-sort citizen vs. non-citizen, and treat one group dramatically worse, even beyond the legal or threat-model requirements), but it's a start.

I've had a lot of practice being stubbornly bright and chipper and polite at bureaucrats. I am happy to be obnoxiously polite for days at a time, if need be.
i'm in a position where i'm able to be very happy indeed to make CBP do their jobs and waste as much of their time as possible to prove a point. (white, male, christian background, well educated, "looks like a good guy". might as well exploit those advantages)