Live data from Hacker News

New DHS policy on demands for passwords to travelers’ electronic devices

papersplease.org

251–260 of 297 posts

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#251
post #239

Earlier quoted context omitted.

Might as well just travel with wiped devices. If you're a U.S. person the worst case scenario is they keep them anyways. BUT! if you're NOT a U.S. person do keep in mind that CBP takes wiped devices (and lack of devices) as suspicious in itself, and may deny you entry.

Under this concern, perhaps the if being used in "honeypot" mode, it could act as a reverse vault. Rather than setting up what you don't want people to see, you would instead set what you do want them to see. Regardless, implementation details would probably be better for a different topic.

Well, yes, CBP will be seeing a lot of what they don't care about (boring stuff), no doubt.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#252
I would note that DHS/CBP can't do too much of this. It's very time-consuming even to set aside a passenger and demand their devices and passwords, and CBP has large plane loads to process quickly. So obviously they must only bother with this policy when they think they have reason to -- because you're on some list, or perhaps because someone with the same name as you is on a list (scary!). There are some natural limits to this policy.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#254

Earlier quoted context omitted.

Yeah, I would make that assumption if they confiscated the device and said "we'll send it back to you whenever." But why do I feel that "derpy DHS agent browses computer for a few minutes" is far, far more likely in a scenario where the device is taken to a back room? Is it really impossible to know anything about what is done with devices in the back room?

Let's say they had your device for 15 minutes. Thats enough to disassemble and copy a bunch of data and reassemble. Unless you have whole drive encryption they only need to copy the user folders (typically). Or your machine might have been in a queue and only looked at for 2 minutes. Or they might have not looked at it at all. Now pick a few different timeframes and you tell me how hard it is to know?

15m seems like too little unless the traveler is a high-priority target. CBP is often crushed.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#255
post #92

Earlier quoted context omitted.

> use truecrypt be coerced to give away your truecrypt password.

Truecrypt has deniable encryption and duress passwords.

No such thing.

CBP aren't stupid. If they see you have something like Truecrypt installed, then they will assume you have "deniable" stuff stored and will demand to see it. And if you don't actually have it? Too bad for you.

Cryptography cannot help you defeat a government's rubber host cryptanalysis.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#256
post #191

I understand the anger, and I understand people wanting to protest. But why on earth would most people here feel the need to travel with a wiped, or factory-defaulted device? I mean, if you have something to hide, or sensitive information, sure, I guess. But it's not like they stop and ask for a password from everyone. This probably applies to 1 in thousands, if not tens of thousands of passengers. What on earth do y…

I'm not sure what you work on but literally any laptop I'd bring with me while traveling has sensitive materials on them.

You should use a laptop only as a thin client -- a really smart dumb terminal. Put nothing of value on it, then nothing of value can be lost when you lose the laptop (or it gets stolen, or whatever).

CBP can probably demand your passwords for your devices. Can they demand your passwords for remote services? Probably not. "Sorry, my employer demands I not reveal my work passwords to anyone, but you can have the password to my laptop, and you can even keep it!"

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#257
post #250
post #218

Earlier quoted context omitted.

I understand your desire to push back. Having "opted out" at TSA checkpoints for a year, I can tell you that the righteous feeling does little to counteract annoyance from fellow travelers (especially those in my own party). Yes, en masse it would be effective, but until then it's not worth the individual effort IMO. Anyway, governments can't tolerate explicit affronts to their authority. The better course of action…

This is an argument against representative democracy and assumes that we are already essentially at war with our government. Civil disobedience has a long and successful history in this country. The rule of law still stands. Establishing privacy measures as tool of criminals operating outside the law does no good. TSA/DHS needs to be lobotomized/euthanized. Vote.

The main problem for this is the vast majority of the population is totally okay with these procedures, so one cannot even argue against it nit being representative or it being repressive because if you put it to popular vote, you will not get the result you wish for.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#258
post #244
post #156

Earlier quoted context omitted.

People need to push back. I know there's risk, but if you take this shit, they just keep pushing. I will be traveling with throwaway, obviously tailored devices with insulting passwords, lock-screens and documents and a huge pile of encrypted chaff. Let them document me as a troublemaker. Better, let them document hundreds of thousands of us as troublemakers. CBP and ICE have been drifting towards authoritarian-shith…

Hopefully more U.S. citizens stand up and push back against this bullshit. As for me, a foreigner living in the U.S., there's really nothing I could do other than complying, since they can just kick me out at any time.

> As for me, a foreigner living in the U.S., there's really nothing I could do other > than complying, since they can just kick me out at any time.

Be care.. on HN "there's really nothing I could" sounds a bit defeatist.. :P

Some ideas..

One could use this as an opportunity to learn about how to still do work without using your predominate computer. Assuming if you lost your computer it would be a PITA to reset it? Not a good position to be in. But it's a solvable problem.

Can your project be dockerized? Before you leave can can you have a AWS instance primed for you to hit it rather than localhost. Don't know about docker.. great opportunity.

Do you have crazy configs/environ-files stored on your computer? Stick them in github with scripts that set them up from a clean machine.

Is this all a pain? yeah of course.. but I'll bet you that you'll gain a whole bunch of new skills.

The general thoughts here (AFAIK) is to bring a clean burner phone and a clean machine (such as chromeos with maybe a clean ubuntu crouton on it).

Good luck... I'll look forward to your how-to post.. I'll sure there will be many HN'ers that will too. :)

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#259
post #218
post #156

Earlier quoted context omitted.

People need to push back. I know there's risk, but if you take this shit, they just keep pushing. I will be traveling with throwaway, obviously tailored devices with insulting passwords, lock-screens and documents and a huge pile of encrypted chaff. Let them document me as a troublemaker. Better, let them document hundreds of thousands of us as troublemakers. CBP and ICE have been drifting towards authoritarian-shith…

I understand your desire to push back. Having "opted out" at TSA checkpoints for a year, I can tell you that the righteous feeling does little to counteract annoyance from fellow travelers (especially those in my own party). Yes, en masse it would be effective, but until then it's not worth the individual effort IMO. Anyway, governments can't tolerate explicit affronts to their authority. The better course of action…

>I can tell you that the righteous feeling does little to counteract annoyance from fellow travelers (especially those in my own party).

Phuu.. then tell them up front you'll meet them at the gate.

I great excuse (I have read this somewhere) is that you've heard they keep screwing the calibration of the of the ray-machine and over zapping people and don't want to trust your life to some min wager who really don't care if you lose 10 years or not.

I've always opted out.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#260
post #205

Unfortunately the recommended behavior is to be "difficult". Trying to somehow state your own rights, demand that officers perform searches in accordance with law etc. - which is "being difficult". If you are on your way to a great holiday, important meeting etc, you aren't going to risk it. Because anyone "being difficult" will be detained or rejected. So I'll just fold and give them my password. And they know this.…

Personally I'm just gonna skip the USA altogether for holidays and work - the world is pretty huge and full of interesting places. I know it's not an option for US citizens and it's a shame for the rest of us but I've decided it's not worth it.

US citizen here. Haven't visited the US in years. Myriad reasons why, but the CBP policy is part of it. Just don't like the idea of people demanding I let them go through my stuff, but also don't like the idea of sitting around for 8 or 9 hours or having my machine confiscated if I won't give up the password, either.

I should also note that at least as a US citizen, having traveled through some 40 or so different countries, US customs is the third most unfriendly customs I have traveled through. Only ones worse for me have been Canada (last trip to Canada was likely the last I will make after my last customs experience there) and Czech. I feel much more comfortable visiting supposedly authoritarian countries than I do the United States.

Post reply on HN