Live data from Hacker News

New DHS policy on demands for passwords to travelers’ electronic devices

papersplease.org

161–170 of 297 posts

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#161
So the DHS in the US began deploying facial recognition scan without any authorization and now they have gone and decided to implement collecting travelers passwords.

So the DHS requesting you passwords in order to enter and the DHS collecting your facial scan in order to exit will effectively bookend the experience of visiting the USA.

This agency seems to increasingly act with complete autonomy and impunity. The culture there seems to be one of arrogance and disregard. This is evident all the way down to the clowns at the airport who berate and harass regular folks who are just trying to get somewhere.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#162
We should resist this by wasting as much time as humanly possible. How about carrying multiple data devices with brute force able encryption for meaningless data? Encrypted linux ISOs, 8051 datasheets, trivial C programs, etc. There's clearly a file structure in place, it's clearly not easily readable, the person who was carrying it will not (or maybe cannot because they genuinely don't know) divulge how to read it. All this just to waste their time and resources dealing with piles of this shit.

Anybody remember that USB stick that kills whatever it's plugged into? I could throw 2-3 of those into my luggage and forget about them.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#163
post #141

Earlier quoted context omitted.

This. Being "difficult" might be an option for US citizens, but if you're a visitor you're really only going to have a choice between cooperating and being refused entry. If you're refused entry you'll have a much harder job returning.

that's what they want you to belive. and it saddens me that they are achieving their goals. as an immigrant, I have always opted out of the scanner with undocumented effectiveness and undocumented health effects with no consequences other than a pat down.

I (think I) get the point you're making and I broadly agree, but in the immigration case (on the way in to the country, rather than the way out) it's more than what they want you to believe: it's what they can and do enforce. For good or ill. And there's very little that you can do about it other than decide to not travel to the USA.

This link[0] is admittedly an advert for legal services, but there are a couple of interesting snippets in there such as:

> ... if you have been refused entry into the United States at any point in the past, even for an expired passport, the previous denial is reasoning enough for future denial.

IANAL but my understanding is that for non-residents there's no legal obligation to admit you outside of maybe some of the international refugee conventions (which are unlikely to apply). The law is deliberately discretionary. A refusal to admit can be based purely on "suspicion". You can imagine a CBP officer finding you suspicious (rightly or wrongly) because you refuse to hand over your passwords even if they don't have a legal right to force you to hand them over. They can simply offer you a choice of handing them over or going home.

To be clear: I'm not advocating for this state of affairs, but it does appear to be the case.

[0] https://www.visaplace.com/blog-immigration-law/denied-entry-...

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#164
post #157

Unfortunately the recommended behavior is to be "difficult". Trying to somehow state your own rights, demand that officers perform searches in accordance with law etc. - which is "being difficult". If you are on your way to a great holiday, important meeting etc, you aren't going to risk it. Because anyone "being difficult" will be detained or rejected. So I'll just fold and give them my password. And they know this.…

Then, bluntly, you have made your choice. Those unwilling to stand up for themselves can't expect anyone else to stand up for them.

Exactly. I can't afford to stand up for my ideals at the border. I expect people (including myself) to stand up for these things, just not at the border.

My main way of disagreeing with policies like this is to simply skip any travel to the US. I can't vote, but I can vote with my wallet.

But basically saying that people should either accept that their expensive holiday (or job) might go down the toilet, or they have no principles - is a bit much to expect I think.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#165

It would seem to me the answer is to factory reset your phone before travel and reinstate it after landing. However, the UK is not much better, given recent legislation. Until the average voter gets concerned enough about this to make it an election issue, our lives will be more and more constrained.

I wouldn't recommend this. You want your device to look innocuous and normal . Nobody carries around an unused phone, so having one would be a red flag. Your phone will be examined for hidden partitions, and you'll be detained for further scrutiny.

In iCloud ecosystem, create a family, with a child account AppleID.

Do a full backup. Wipe the phone, log in with child account.

You can now redownload a few key apps needed for the trip, as well as some normal apps: weather, TripIt/Uber/CityMapper, games, etc. Because it’s a family account, all the re-downloads are free.

Share essential data (that you don’t mind being taken) from your own account to this account the way you would to another family member. Use the iCloud “Family” calendar for your trip planning (useful anyway to share travel plans with partner etc), or subscribe this account to e.g. your TripIt/TripCase calendar. Invite this child account as a family member for your smart home etc., using child (parental controlled) config where available so it’s not an admin. Use secure Shared Notes from Apple Notes or Evernote to bridge travel lists. Subscribe to a shared iCloud Photos album so you can seamlessly post photos taken with this account back to your primary account (and that album will only contain photos you intend to be visible on this persona). Load in your business’s main contact info, your personal contact card with your business email and number, and then contacts for airlines, car rentals, hotels, and customer support numbers you use. If traveling with a partner, load their contact in as well, also using work info. Include a contact record for the ‘emergency contact’ you already disclosed on other forms (airline, customs). If the device is lost, searched, etc., revoke this child from everything you’d shared to it from.

If you need access to more while traveling, look into 1Password’s travel mode, and share a travel-safe vault from yourself to yourself:

https://blog.agilebits.com/2017/05/18/introducing-travel-mod...

When you are set up as you like, backup to iCloud. In the future, you can restore from this backup.

Caveat: On the parent ID, avoid applications that mark their data to exclude from iCloud backups unless they sync themselves to the cloud and auto-restore the data when restoring that Apple ID to a new device. For such apps, you will have to manually recreate their data, or use legacy iTunes wired backup and restore which defeats the purpose if you wish to restore at your trip destination. A common example might be Google Authenticator.

Pro-Tip: Restoring very large numbers of apps, as well as iCloud data such as files and photos, can take a very long time OTA. On a home Mac, set up iCloud Content Caching with a sufficient size to cache all apps, documents, and photo data, to radically improve restore times:

https://support.apple.com/en-gb/guide/mac-help/about-content...

This will speed up app restore for the child account as well, though that shouldn’t be an issue as you’ll maintain a very small number of apps.

The device will be useful from home to destination, and info (notes, photos, etc.) on the go can be shared back to the parent. Depending on length of trip, you can restore to your primary ID at destination and then flip again for the trip home.

The device will be normal.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#166
post #155

Basically, don’t carry data with you. Leave it all in the cloud. You can’t be compelled to provide the password for a service which contains data that is not on the device.

Really? For how long?

https://www.theguardian.com/technology/2016/jun/28/us-custom...

http://www.businessinsider.com/john-kelly-travel-ban-social-...

https://privacysos.org/blog/social-media-privacy-at-the-bord...

https://www.eff.org/deeplinks/2017/01/fear-materialized-bord...

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#167
post #141

Earlier quoted context omitted.

This. Being "difficult" might be an option for US citizens, but if you're a visitor you're really only going to have a choice between cooperating and being refused entry. If you're refused entry you'll have a much harder job returning.

that's what they want you to belive. and it saddens me that they are achieving their goals. as an immigrant, I have always opted out of the scanner with undocumented effectiveness and undocumented health effects with no consequences other than a pat down.

Are Airport Body Scanners Safe? (Time, 2017) [http://time.com/4909615/airport-body-scanners-safe/]

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#168
post #120

After the arrest of Marcus Hutchins I have already resolved not to set foot in the USA (unless badly necessary for business :/ ). It is surprising how little international outrage that arrest sparked: if the reasoning of the USA in this case were solid then international travel would halt. You would need to review everything you've done online (the last few years at least but possibly ever) and compare it to the laws…

>That case was one of the primary reasons I excluded the USA as my immigration target and landed in Canada instead (back in 2006 I was in a position where I could choose).

>This policy just makes my resolve stronger.

Canada (and the UK and Australia) has this same "give me your password" policy [1], too. They've even arrested re-entering Canadian citizens for refusing [2].

So while your decision may have been "noble", I'm not sure Canada was the right choice.

1: http://www.cbc.ca/news/technology/border-phone-laptop-search...

2: http://www.cbc.ca/news/canada/nova-scotia/alain-philippon-to...

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#169

We should resist this by wasting as much time as humanly possible. How about carrying multiple data devices with brute force able encryption for meaningless data? Encrypted linux ISOs, 8051 datasheets, trivial C programs, etc. There's clearly a file structure in place, it's clearly not easily readable, the person who was carrying it will not (or maybe cannot because they genuinely don't know) divulge how to read it.…

The US government would love nothing more than you wasting its time. I would argue that mutual time wasting is what it perceives to be its primary function.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#170

I don't know if it worries my American chums, but I won't visit the USA. As a foreign tourist bringing money into your economy I feel there is a very real risk to my privacy and increasingly my person. I am beginning to favour goods and services from EU where human rights still mean something. Perhaps it doesn't matter to you how the US is perceived overseas, perhaps you don't want my money. Perhaps you don't mind be…

Isn't it the same with Canada, though? I admit, I only watched those Border Patrol Shows on Netflix and what not, but it always disturbed me how much they always wanted to check the whole phone.

Yes, Canada, the UK, and Australia all have policies to ask travelers for their passwords for laptops/cell phones, and you'll be sent back home (if you're a foreigner) or arrested (if you're a citizen, at least in Canada [1]) if you refuse.

1: http://www.cbc.ca/news/canada/nova-scotia/alain-philippon-to...

Post reply on HN