(评论)
(comments)

原始链接: https://news.ycombinator.com/item?id=43441895

Hacker News 上的一个帖子讨论了 EFF 的“边境搜查袖珍指南”和边境过境安全问题。一些用户警告说,使用加密或复杂的安保措施可能会引起怀疑,导致设备被扣押或被列入监视名单。用户建议通过在过境后从备份恢复来最小化敏感数据。 讨论还强调了在美国边境(以及 100 英里范围内)缺乏权利,包括无证搜查。重点是如何禁用生物识别锁,因为可能面临强制解锁,一些人建议在美国境内禁用生物识别功能。建议 iPhone 用户按五次电源按钮来禁用 Face ID。其他人建议在过境前关闭设备电源。一个用户质疑使用 PIN 码而不是指纹是“极端”的安全措施。另一个用户建议使用密码而不是 PIN 码来获得更强的安全性。最后一位用户表示,拥有这份指南可能会引起怀疑。

相关文章
  • 电子前哨基金会边境搜查袖珍指南 2025-03-22
  • (评论) 2024-07-28
  • (评论) 2025-03-20
  • (评论) 2025-03-21
  • (评论) 2024-09-04

  • 原文
    Hacker News new | past | comments | ask | show | jobs | submit login
    EFF Border Search Pocket Guide (eff.org)
    49 points by doener 49 minutes ago | hide | past | favorite | 12 comments










    Back in 2009, Bruce Schnier described a process to cross borders: https://www.schneier.com/blog/archives/2009/07/laptop_securi...


    Some comments on that 2009 article.

      [1] Step 6 will probably never happen if you show a border guard or customs official an article about encryption. You will not get safely through customs, you’ll end up on a secret list and get hassled every single time you travel for the rest of your life. As the database you’re in ages (and people begin to forget how it was created), you might be simply barred entry into places you want to go.
    
      [2] This kind of elaborate setup will make you loose your computer at the customs. They will ask you to boot it up… when you’ll not be able to do that, they’ll will not listen to your story and will just keep the computer.
    
      [3] The solution you propose will just make you look like a dangerous bad guy to the border guards. They want to inspect your laptop, and you propose to tell them that you’re resorting to extreme measures to foil them. Very bad move.


    No one in, or on the border of, the United States should use a biometric lock.

    The police can apparently force you to unlock

    E.g., https://proceedings.nyumootcourt.org/2023/11/press-to-unlock...



    Even US citizens have basically no rights at a border. You can be subjected to any search without warrants. And this applies to within 100 miles of a coast or border, which is pretty much every major city.

    The real way to minimize risk is to not carry any sensitive data, as in the first item on that pamphlet, and restore from a backup once you get past the screening. This is a little difficult with mobile phones, however.



    Fun tip: If you have an iPhone, rapidly pressing the power button five times will force your phone to require a password before Face ID will work again. Turning your device off entirely will also necessitate password reentry.


    Doesn't help if you're snagged and handcuffed before you can get to the power button!


    Right, I'd recommend anyone worried about this to power off their laptop (assuming you've got full disk encryption turned on) and phone before going through security, customs, etc.


    Disabling biometrics the whole time you're in the US is a bit extreme unless you have a target on your back, but most phones have a way to quickly disable biometrics until you next unlock with your PIN. At least learn how to do that just in case the shit unexpectedly hits the fan, on iPhones you press the power button 5 times in a row.


    "unless you have a target on your back"

    If you are in, or on the border of, the United States, it's reasonable to assume you have a target on your back.

    Otherwise the courts would not have made such ridiculous rulings.



    >Disabling biometrics the whole time you're in the US is a bit extreme...

    How on Earth, in any situation, for any reason, can inputting a PIN instead of using your fingerprint be considered... "extreme"?



    I'd argue it's not extreme enough: Use an alphanumeric password or passphrase, as long as you can tolerate, instead of a PIN.


    It must be said that having this document in your possession when crossing the border may itself lead to suspicion.






    Join us for AI Startup School this June 16-17 in San Francisco!


    Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact



    Search:
    联系我们 contact @ memedata.com