Live data from Hacker News

New DHS policy on demands for passwords to travelers’ electronic devices

papersplease.org

231–240 of 297 posts

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#231
post #225

I've been working on an app/program that could be of use for this kind of situation. It's in way to early of a state to be released though. For the sake of giving it a name, we can call it Dead Man's Pass. Effectively, for phones or laptops, you would have your standard password as well as a secondary password. If you use your fingerprint to open your phone, you would be able to register a different print as your sec…

Might as well just travel with wiped devices.

If you're a U.S. person the worst case scenario is they keep them anyways.

BUT! if you're NOT a U.S. person do keep in mind that CBP takes wiped devices (and lack of devices) as suspicious in itself, and may deny you entry.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#232

Earlier quoted context omitted.

And you don't know, can't know which it is since they can remove the device from your presence. So you have to assume the latter.

Yeah, I would make that assumption if they confiscated the device and said "we'll send it back to you whenever." But why do I feel that "derpy DHS agent browses computer for a few minutes" is far, far more likely in a scenario where the device is taken to a back room? Is it really impossible to know anything about what is done with devices in the back room?

Let's say they had your device for 15 minutes. Thats enough to disassemble and copy a bunch of data and reassemble. Unless you have whole drive encryption they only need to copy the user folders (typically).

Or your machine might have been in a queue and only looked at for 2 minutes.

Or they might have not looked at it at all.

Now pick a few different timeframes and you tell me how hard it is to know?

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#233
post #71

Earlier quoted context omitted.

You do understand there's also a downward spiral for tourism, right? Tourism generated 1% of the GDP but you don't know the impact on other industries, you haven't seen figures on lost of tax revenue from jobs lost, cost of retraining people to find new jobs, burden on society from unemployment, etc. I don't think that tourism will cease in the US but any downturn on it has larger effects than just the GDP figure bro…

I never understood why US airports never implemented the transit concept. Theoretically it could be extremely convenient to use the US as a transit point if your final destination is, for example, a country in Latin America. But when you connect via any US airport you need to deal with imigration, pick up your luggage, deal with customs hassle, re-check your luggage and proceed through the entire TSA song and dance.…

Because statistically nobody transits through the US. Almost everyone ending up in the US is staying. A lengthy flight across the Atlantic/Pacific to then take another lengthy flight across the other ocean is just not something many people do.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#234
post #120

After the arrest of Marcus Hutchins I have already resolved not to set foot in the USA (unless badly necessary for business :/ ). It is surprising how little international outrage that arrest sparked: if the reasoning of the USA in this case were solid then international travel would halt. You would need to review everything you've done online (the last few years at least but possibly ever) and compare it to the laws…

> You would need to review everything you've done online (the last few years at least but possibly ever) and compare it to the laws of the country you are entering.

Yes, that's what you must do any time you enter a country. Any country is free to arrest you for past violations of its laws when it has the physical ability to do so. Once you're physically present in a country, it no longer needs to demand your extradition: you've extradited yourself.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#235
post #12

Absolutely not. Having lived outside the US for two years (so far), I halfway expect to encounter suspicion when I return. I absolutely will not stand for this. I will not cooperate and I will resist as much as possible, short of violence.

As someone who has been living overseas for over 11 years, I can honestly say that US border control and TSA have the most unprofessional and disrespectful employees I've encountered in my travels. It's unlikely they'll ask to check your electronics unless they suspect you've been someplace like Syria, Iraq, etc., but nevertheless they'll look for any reason at all to question you as if you're a criminal. If foreign…

> I wish more Americans traveled overseas because if they experienced the difference between how we treat people vs how others do, they'd be properly outraged.

Twelve years or so ago I was having serious doubts they were going to let me leave Amsterdam to travel back to the US (on a one way ticket) because I had a Iraqi customs stamp in my passport, they were quite concerned and inquisitive about it.

Previously on the same trip I was searched pretty thoroughly on the train because I just happened to be traveling between countries on the same day as the 2005 London bombings. I guess they figured anyone traveling around Eastern Europe with a ukulele probably isn't too much of a threat so they didn't hassle me too much.

That second one kind of surprised me because I thought they just let you travel within the eurozone without problem.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#236

It would seem to me the answer is to factory reset your phone before travel and reinstate it after landing. However, the UK is not much better, given recent legislation. Until the average voter gets concerned enough about this to make it an election issue, our lives will be more and more constrained.

I wouldn't recommend this. You want your device to look innocuous and normal . Nobody carries around an unused phone, so having one would be a red flag. Your phone will be examined for hidden partitions, and you'll be detained for further scrutiny.

If it's been factory reset and wiped, there's not going to be much that they can do about it.

They could detain you - but for what reason? Because you have a blank phone?

What if you don't have any social media presence? What if you simply don't remember your passwords (because they are stored on your browser at home, or you have some kind of device like a yubikey, and that's at home too)?

So they detain you, because...why? "Innocuous and normal"? So anyone who decides to forgo any electronic devices while traveling and doesn't have a social media presence (or maybe even an internet presence!) is considered "suspect"?

The more I hear and read about stuff like this, the more I just want to log off, move to the middle of nowhere, and switch back to coding on my old 8-bit microcomputer from the 1980s - this world and my country has gone insane.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#237

Earlier quoted context omitted.

I think a cheaper alternative is to only allow access to non-sensitive information when initially logging into the device, then hide any substantial information behind another layer. Don't think the average customs officer has time or skills to dig out files containing encrypted volumes on your device.

The average customs officer will not do that. But they will potentially take an image of the hard drive (possibly by removing it and connecting it to an imaging computer) and store it, after which people/programs with both the time and skills can find your hidden data.

If that data is encrypted properly, then finding it after you've already left the country can't help you.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#238

I don't know if it worries my American chums, but I won't visit the USA. As a foreign tourist bringing money into your economy I feel there is a very real risk to my privacy and increasingly my person. I am beginning to favour goods and services from EU where human rights still mean something. Perhaps it doesn't matter to you how the US is perceived overseas, perhaps you don't want my money. Perhaps you don't mind be…

You do realize that all those policies you don't like got going under past Administrations? Obama could have rolled it all back but he chose not to. It seems like under Trump, especially since the FISA law was abused during his campaign against him personally, that he might be the one most amenable to stronger privacy protections especially since Binney has his ear.

You have to understand something--the US isn't run by the President. The US is run by the bureaucracy and there is currently a war underway inside that bureaucracy, especially in the intelligence community. One side wants the protections enshrined in the Constitution, the others side are totalitarians. The Bush family has much to answer for as most of this recent crap got going under them. But again, Obama's administration weaponized it against the people. Look at the IRS audits of conservative non-profits (or the outright denial of non-profit status) and Fast & Furious.

"Trump Chumps" are regular people trying to work and raise families and are tired of two things: Leftist thugs, and big government. I'm sorry you think I'm just a label, but I'm not. Hillary Clinton, and the whole Clinton family, is a crime cabal and I'm glad she didn't get elected because the US would be in even worse shape right now if she had. At least Trump seems to put citizens ahead of all others, which is quite the novel concept.

Also, btw, the Clintons stole a ton of money from under-developed countries.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#239
post #225

I've been working on an app/program that could be of use for this kind of situation. It's in way to early of a state to be released though. For the sake of giving it a name, we can call it Dead Man's Pass. Effectively, for phones or laptops, you would have your standard password as well as a secondary password. If you use your fingerprint to open your phone, you would be able to register a different print as your sec…

Might as well just travel with wiped devices. If you're a U.S. person the worst case scenario is they keep them anyways. BUT! if you're NOT a U.S. person do keep in mind that CBP takes wiped devices (and lack of devices) as suspicious in itself, and may deny you entry.

Under this concern, perhaps the if being used in "honeypot" mode, it could act as a reverse vault. Rather than setting up what you don't want people to see, you would instead set what you do want them to see.

Regardless, implementation details would probably be better for a different topic.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#240

Earlier quoted context omitted.

I went through this process in 2015-2016 after my fiancee was turned away while we were entering the US in PHL (they said she had already spent too much time with me there). We went back to Spain where she's from and started the 4+ month long process of getting her a K-1 fiancee visa. It is a lot of reading, a lot of forms, and nerve-wracking interviews so I understand where you're coming from. But now she has a gree…

The immigration system is horribly broken. My wife, too, is an immigrant, and our experience is vastly different from yours. For example, they scheduled her for an interview on a date that was impossible for her to make (iirc, that was her first day of a new job). She went to the INS offices to ask to have it rescheduled, and the person at the desk just gave her a flat "no, we do not reschedule interviews". My wife a…

Is it horribly broken because it is completely overwhelmed? Also, we're talking about US Govt. employees here...
Post reply on HN