Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Bordering on insanity

Why you probably shouldn't bring any sensitive data across U.S. borders
Security Strategies Alert By M. E. Kabay , Network World , 05/27/2008
Sign up for this newsletter now!

Mich Kabay takes a high-level view of security issues and provides resources to help safeguard your corporate and personal security.

  • Share/Email
  • Tweet This
  • Comment
  • Print

In my last column, I introduced the issue of crossing U.S. borders with encrypted data and advised corporate users to think carefully about whether to do so. Today I want to discuss the implications of the way the U.S. Customs and Border Protection (CBP) service is demanding decryption keys from travelers and seizing portable electronic devices.

In February, the Electronic Freedom Foundation and the Asian Law Caucus sued the U.S. Department of Homeland Security for “release of agency records concerning CBP’s policies and procedures on the questioning, search, and inspection of travelers entering or returning to the United States at ports of entry.” 

We have now lost the benefits of strong disk encryption when crossing U.S. borders. A bureaucrat can demand our encryption key and seize our computers with no way to prevent the seizure or even to demand (let alone receive) an explanation of that demand.

How do we ensure chain of custody if there’s no available documentation, even under court order? How do we ensure protection of confidential corporate data if the rules of investigation are undocumented? Judging by the resistance of the USBCI to demands for information about their investigative process, the border entry points have become a constitutional-protection-free zone.

Corporate information about new products, new marketing plans, new business strategies and even detailed customer records may be worth millions to competitors. Do you really want to entrust such information to people who are entirely without judicial oversight? How much do you think a border agent earns in a year? How much do you think an industrial spy would be willing to pay for some of your corporate secrets? For that matter, how much do you think ordinary criminals would be willing to pay for personally identifiable information on your encrypted - and now decrypted - hard drive? Why would anyone assume that a secret process, closed to judicial or indeed any form of external oversight or control, is necessarily secure and immune to corruption? Faith? Hope? Patriotism defined as subservience to power?

It seems to me that we are experiencing a level of unchecked government intrusion that justifies a corporate policy dictating that employees, whether U.S. citizens or not, should not carry any confidential corporate data at all on their laptop computers unless they feel like having unnamed judicially uncontrolled agents of the U.S. government examining company information.

M. E. Kabay, PhD, CISSP-ISSMP, specializes in security and operations management consulting services. CV online.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comments (9)
Login
Forgot your account info?

No surprisingBy Anonymous on May 27, 2008, 3:15 pmIt's not surprising. our country seems to think stupid ways of handling issues is the best way.

Reply | Read entire comment

why carry?By Anonymous on May 27, 2008, 4:59 pmwhy carry around encrypted data. use other means to beat them. set up an FTP server in your place of origine, put all your encrypted data there and then download...

Reply | Read entire comment

A right you never hadBy Anonymous on May 27, 2008, 6:05 pmSo, here's yet another rant from someone who thinks they had a right they never did. When exactly was it that you thought you could cross the border and expect...

Reply | Read entire comment

TrueCrypt hidden volume capability?By Anonymous on May 27, 2008, 9:16 pmWhat about using the hidden volume capability of TrueCrypt? http://www.truecrypt.org/docs/hidden-volume.php

Reply | Read entire comment

RightsBy Randy Grein on May 28, 2008, 12:42 amCheck the Declaration of Independence and Constitution. All rights are vested in the individual, exceptions are noted. This is known as freedom. The reverse, where...

Reply | Read entire comment

Please explain to the learned justicesBy Anonymous on May 28, 2008, 2:25 amThat taking someone's property without permission or recourse is known as THEFT.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed