Google Search

Showing posts with label laptop. Show all posts
Showing posts with label laptop. Show all posts

Saturday, October 12, 2013

US upholds the right to search your laptop at the border without warrant

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Customs sign, courtesy of ShutterstockHere's a riddle: Why did the US customs agents search your laptop at the airport?

Answer: Oh, well, it's hard to say. They just kind of had a hunch that you were suspicious, you know?

It sounds like a hyperbolically offhand rationale to justify disregarding travelers' constitutional rights against unreasonable searches (at least, the rights of US citizens, supposedly guaranteed by the Fourth Amendment), but the glibness is barely exaggerated.

Here's the actual wording used by the Department of Homeland Security (DHS) to explain why it can't change its electronic device search policies:

...we have been presented with some noteworthy [Customs and Border Protection (CBP)] and [Immigration and Customs Enforcement (ICE)] success stories based on hard-to-articulate intuitions or hunches based on officer experience and judgment.

Under a reasonable suspicion requirement, officers might hesitate to search an individual's device without the presence of articulable factors capable of being formally defended, despite having an intuition or hunch based on experience that justified a search.

The quote comes from a statement [PDF] released by DHS on Wednesday.

The statement is in response to a Freedom of Information Act filed by the American Civil Liberties Union (ACLU). It includes a so-called complete version of its justification of warrantless border searches of laptops, of which it released an executive summary in February.

The executive summary [PDF] put out in February barely addressed questions of if and how warrantless searches violate First and Fourth Amendment rights.

Basically, DHS's rationale for warrantless searches being Constitutionally OK amounted to "because we said so."

An example of the executive summary's "we don't have to explain ourselves to you" style with regards to the First Amendment:

First Amendment

Some critics argue that a heightened level of suspicion should be required before officers search laptop computers in order to avoid chilling First Amendment rights. However, we conclude that the laptop border searches allowed under the ICE and CBP Directives do not violate travelers’ First Amendment rights.

The statement released on Wednesday has constitutional analysis, but it's largely redacted.

DHS Border Searches of Electronic Devices

In some of its non-redacted reasoning, however, DHS says that border agents have to act fast. If the legal threshold to search device content were to be raised, resulting litigation would muck thinks up:

... commonplace decisions to search electronic devices might be opened to litigation challenging the reasons for the search...

The litigation could directly undermine national security by requiring the government to produce sensitive investigative and national security information to justify some of the most critical searches...

Although this Office does not advocate arbitrary decision-making, we understand that there may be occasions where officers have only a few seconds to make important decisions about admissions and searches, and where they lack the opportunity to use routine criminal investigative techniques to develop reasonable suspicion or probable cause to justify the inspection of containers.

Officers must therefore frequently make important choices based on inadequate and imperfect information.

The ACLU takes issue with this notion.

ACLU legal fellow Brian Hauss wrote in a blog posting on Wednesday that the government has plenty of ways to keep sensitive information from leaking out in court:

The government has numerous resources at its disposal to prevent the disclosure of sensitive information.

The "state secrets privilege," to take just one example that is used in court cases, has been criticized on many grounds, but no one has ever seriously suggested that its protections are too anemic.

Although DHS might fear the prospect of being called into open court to explain its actions, executive accountability before the law is the bedrock on which our system of constitutional self-government is built.

Border patrol, courtesy of ShutterstockThe Feds also nixed suggestions that ICE and CBP revert to a 1986 policy that allowed agents to “briefly peruse” a traveler’s possessions to determine if there was probable cause or a reasonable suspicion for a further seizure.

Such a policy is "not tenable" given the capacity of modern devices, DHS wrote:

Gigabytes of information may be stored in password-protected files, encrypted portions of hard drives, or in a manner intended to obscure information from observation.

An on-the-spot perusal of electronic devices following the procedures established in 1986 could well result in a delay of days or weeks; even a cursory examination of the contents of a laptop might require a team of officers to spend days or weeks skimming the voluminous contents of the device.

At the same time, a firm time limit for completing a search risks allowing a wrongdoer to "run out the clock" by encrypting and password-protecting his device, or traveling with voluminous amounts of documents, or other measures to make the search very time consuming.

None of this is surprising.

Civil liberties advocates have long referred to US ports of entry as "Constitution-free zones".

The heavy black ink of redacted Constitutional analysis, to my mind, symbolizes the black hole where travelers' Constitutional rights go to die.

Follow @LisaVaas
Follow @NakedSecurity

Image of customs and border patrol courtesy of Shutterstock.

Tags: ACLU, CBP, Constitution, Customs and Border Protection, DHS, first amendment, Fourth Amendment, fourth amendment rights, ICE, Immigration and Customs Enforcement, laptops, Privacy, seizure


View the original article here

Sunday, December 30, 2012

NASA suffers major data breach over stolen laptop that wasn't encrypted

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

NASA image, courtesy of ShutterstockIn March 2011, algorithms used to command and control the International Space Station were exposed.

In March 2012, it was the personally identifiable information (PII) of 2,300 employees and students.

In another incident, it was sensitive data on NASA's Constellation and Orion programs.

This time around, on 31 October, it was PII on an unspecified, but large, number of NASA employees and contractors.

All these instances involved the theft of unencrypted laptops from NASA. With this most recent theft, the space agency is finally doing something about these incidents, beyond the limited scope of its previous remediation efforts.

NASA announced on Tuesday that, effective immediately, the agency is jumping on the encryption fast track.

By 21 December, no NASA-issued laptops containing sensitive information will be allowed to leave a NASA facility unless whole disk encryption software is enabled or sensitive files are individually encrypted.

In a message sent agency-wide to all employees, Associate Deputy Administrator Richard J Keegan Jr. informed NASA staff that somebody or somebodies broke into a locked vehicle and stole official NASA documents on 31 October.

The laptop contained records with PII for a large number of employees, contractors and others, Keegan said.

He gave no explanation as to why the agency waited weeks to inform employees.

Rocket. Image from ShutterstockThe computer was protected only with a password and lacked whole disk encryption, which left the information accessible to thieves.

NASA is taking standard breach precautions, including contracting a data breach specialist, ID Experts, to notify those whose PII was compromised.

The agency is offering free credit and identity monitoring, recovery services in cases of identity compromise, an insurance reimbursement policy, educational materials, access to fraud resolution representatives, and a call center and website.

It's recommending that anybody affected activate these services ASAP.

NASA is also recommending that those affected be wary of suspicious phone calls, emails, and other communications from individuals claiming to be from NASA or other official sources that ask for personal information or verification of it.

NASA and ID Experts won't be contacting employees to ask for or to confirm personal information, Keegan said, so any such communication is sure to be bogus.

NASA's embrace of full-disk encryption has up until now been less than comprehensive.

After the March 2012 stolen laptop and PII exposure, the agency pledged:

...a full review of current IT security policies and practices with the goal of making changes to prevent a similar incident.

At that time, NASA promised that all laptop computers at NASA Kennedy Space Center, not just ones with PII or sensitive data, would have their hard drives encrypted by September 2012.

In retrospect, it would have been smarter to extend that initiative to all hard drives, throughout the entire agency, not just those at Kennedy.

Secure laptop, courtesy of ShutterstockBut that is, apparently, a lesson that NASA has now taken to heart and will implement with all due haste.

The new full-disk encryption applies to all laptops containing PII, International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) data, procurement and human resources information, and other sensitive but unclassified (SBU) data.

Keegan said that NASA's Administrator and CIO have laid out the marching orders for agency CIOs to complete whole disk encryption of the maximum possible number of laptops by 21 November.

NASA plans to complete the effort by 21 December, after which no unencrypted laptop, regardless of whether it contains PII, will be allowed to leave its facilities.

In the meantime, employees working remotely or traveling have been told to use loaner laptops if their NASA-issued laptop contains unencrypted sensitive information.

On Wednesday, a security vendor (or then again, more likely, many security vendors, but only one wrote to me directly) sent out a statement on the NASA breach that said,

"OK, whole-disk encryption might be good, but is it good enough?"

It's a question worth asking. As he said, data is in fact moving to and from laptops, in emails, files, and as data traveling to and from apps and servers.

Fortunately, NASA has also declared that storage of sensitive information on smart phones or other mobile devices is now taboo.

Let's hope they also have an eye toward all the places that data propagates, whether it's in emailed attachments, on mail servers that might be in the cloud, on smartphone mail apps, on backup tapes, or in any internal or outsourced operations.

Follow @LisaVaas
Follow @NakedSecurity

NASA image, courtesy of Songquan Deng / Shutterstock.com. Secure laptop and rocket images courtesy of Shutterstock


View the original article here

Friday, June 15, 2012

Ex-MI5 boss loses laptop at Heathrow airport

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Stella RimingtonStella Rimington, the former Director-General of MI5 (Britain's Security Service), has had her laptop stolen according to media reports.

Dame Stella Rimington made the headlines in 1992 when she was publicly named as the first female chief of MI5, and is believed to have inspired Judi Dench's casting as spy chief "M" in the James Bond films. Dame Stella has since carved herself a career as a spy novelist.

The former boss of MI5 was said by The Sun newspaper to be "very upset" by the theft which occurred as she left Heathrow airport last Tuesday.

The Metropolitan Police's SO15 Counter-Terrorism division is reported to have been informed because of possible security concerns.

Although Dame Stella retired from MI5 in 1996, the concern will be that she may still have the contact details of former colleagues, and no doubt the authorities will want to quickly determine if strong passwords and encryption were in place on the laptop.

And that's an important consideration that all of us should bear in mind.

Chances are, of course, that whoever stole Dame Stella's laptop was not targeting her specifically and is more interested in selling the computer down the pub than attempting to uncover any secrets on her hard drive.

Three years ago, newspapers claimed that the incoming head of Britain's MI6 secret intelligence service, Sir John Sawers, could have had his security put at risk after his wife made publicly accessible posts on Facebook.

Follow @gcluley

Image source: www.stellarimington.com


View the original article here