- More porn sneaks onto the iPhone
- 'Swatting' case shows need to ban caller-ID spoofing
- Why the iPhone can't be "killed"
- Nortel enterprise chief wants to bring back Bay
- US sets final emergency responder wireless pilot
Mich Kabay takes a high-level view of security issues and provides resources to help safeguard your corporate and personal security.
In my last column, I introduced the issue of crossing U.S. borders with encrypted data and advised corporate users to think carefully about whether to do so. Today I want to discuss the implications of the way the U.S. Customs and Border Protection (CBP) service is demanding decryption keys from travelers and seizing portable electronic devices.
In February, the Electronic Freedom Foundation and the Asian Law Caucus sued the U.S. Department of Homeland Security for “release of agency records concerning CBP’s policies and procedures on the questioning, search, and inspection of travelers entering or returning to the United States at ports of entry.”
We have now lost the benefits of strong disk encryption when crossing U.S. borders. A bureaucrat can demand our encryption key and seize our computers with no way to prevent the seizure or even to demand (let alone receive) an explanation of that demand.
How do we ensure chain of custody if there’s no available documentation, even under court order? How do we ensure protection of confidential corporate data if the rules of investigation are undocumented? Judging by the resistance of the USBCI to demands for information about their investigative process, the border entry points have become a constitutional-protection-free zone.
Corporate information about new products, new marketing plans, new business strategies and even detailed customer records may be worth millions to competitors. Do you really want to entrust such information to people who are entirely without judicial oversight? How much do you think a border agent earns in a year? How much do you think an industrial spy would be willing to pay for some of your corporate secrets? For that matter, how much do you think ordinary criminals would be willing to pay for personally identifiable information on your encrypted - and now decrypted - hard drive? Why would anyone assume that a secret process, closed to judicial or indeed any form of external oversight or control, is necessarily secure and immune to corruption? Faith? Hope? Patriotism defined as subservience to power?
It seems to me that we are experiencing a level of unchecked government intrusion that justifies a corporate policy dictating that employees, whether U.S. citizens or not, should not carry any confidential corporate data at all on their laptop computers unless they feel like having unnamed judicially uncontrolled agents of the U.S. government examining company information.
M. E. Kabay, PhD, CISSP-ISSMP, specializes in security and operations management consulting services. CV online.
Comments (9)
saving a click...By heh on June 2, 2008, 11:26 amCan't say enough nice things about truecrypt--the previous commenter is referring to the "plausible deniability" feature of the software. If customs officials want...
Reply | Read entire comment
Disk WipeBy Paul Masley on May 30, 2008, 8:26 pmA very simple solution to this problem is "They Wanna Password," give them one. The password activates two programs. Once that looks like it is starting a directory...
Reply | Read entire comment
RightsBy Richard Anon on May 28, 2008, 9:23 amRandy, The constitution allows border inspection without search warrent. The supreme court has ruled this can take place up to fifty miles from the border. ...
Reply | Read entire comment
Please explain to the learned justicesBy Anonymous on May 28, 2008, 2:25 amThat taking someone's property without permission or recourse is known as THEFT.
Reply | Read entire comment
RightsBy Randy Grein on May 28, 2008, 12:42 amCheck the Declaration of Independence and Constitution. All rights are vested in the individual, exceptions are noted. This is known as freedom. The reverse, where...
Reply | Read entire comment
View all comments