Live data from Hacker News

New DHS policy on demands for passwords to travelers’ electronic devices

papersplease.org

151–160 of 297 posts

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#151

> “What is the password to this device?” is a verbal collection of information, which is prohibited by the Paperwork Reduction Act (PRA) unless it has been approved in advance by the Office of Management and Budget (OMB), a “control number” has been assigned by OMB, and individuals from whom information is to be collected are given notice of this. I find this extremely implausible. If it were true, wouldn't it also i…

I'm not an expert in the applicability of that law, but if they're systematically asking people for passwords, that's not necessarily "addressed to a single person".

Paperwork Reduction Act is an attempt to reduce paperwork. Customs and immigration questions are not paperwork, despite how systematic they are. Consider if they have an OMB number for "Citizenship? Duration of stay? Purpose of visit?", the questions nearly every traveller gets asked. They don't. Of course they don't. They don't need one.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#152

It seems to me that few people are talking about what actually happens to phones/laptops when they're unlocked by a password given by the passenger. There's a HUGE difference between... A) A derpy mall-cop DHS agent casually browsing through your laptop/phone for a minute or two, looking at emails, pictures etc. B) The contents of hard-drive/flash/phone being copied to a government server, stored in perpetuity, and s…

And you don't know, can't know which it is since they can remove the device from your presence. So you have to assume the latter.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#153

I remember reading a traveller's guide to the Soviet Union, and talking about precautions you need to take while using your camera. It was written for the 1980s, I wonder if people back then would've thought, that 40 years later...

What kind of precautions did they recommend?

I’m not sure of the guide referenced, but I traveled in Russia extensively not long after the fall of the Soviet Union. Based on the advice we received, don’t do stuff like take pictures of government facilities, bridges, airports, etc. Don’t attempt to be discreet in your photo taking when you do take photos - hold your camera in plain view as to not appear you’re attempting to hide your activities. Don’t take pictures of things that might have the possibility to show the country negatively such as a dilapidated buildings, street beggars, etc.

Also, not directly related but be incredibly careful around military installations, and be aware that many strategic military installations are not clearly identified with signs (if you’re walking in a forest and hit a chain link fence don’t climb it).

Stuff like that.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#154

It would seem to me the answer is to factory reset your phone before travel and reinstate it after landing. However, the UK is not much better, given recent legislation. Until the average voter gets concerned enough about this to make it an election issue, our lives will be more and more constrained.

I wouldn't recommend this. You want your device to look innocuous and normal . Nobody carries around an unused phone, so having one would be a red flag. Your phone will be examined for hidden partitions, and you'll be detained for further scrutiny.

It might make sense to have two images that you can switch between with TWRP or similar. One that is whatever you normally use, and one that is aggressively normal - factory reset, then add a secondary Google account, social media apps (with secondary accounts, maybe, depending), and casual games.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#156
post #43

"In other words, CBP is now claiming the authority to confiscate your cellphones, laptops, memory cards, and any other electronic devices if you won’t tell CBP your passwords, and to retain the passwords you give them as well as the contents of those devices. Yes, this applies to U.S. citizens and permanent residents as well as visitors." That is just insane and unacceptable.

People need to push back. I know there's risk, but if you take this shit, they just keep pushing.

I will be traveling with throwaway, obviously tailored devices with insulting passwords, lock-screens and documents and a huge pile of encrypted chaff. Let them document me as a troublemaker.

Better, let them document hundreds of thousands of us as troublemakers. CBP and ICE have been drifting towards authoritarian-shitheaddom for a long time and really needs a serious pruning/lobotomy. It won't stop until there's noise about it.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#157

Unfortunately the recommended behavior is to be "difficult". Trying to somehow state your own rights, demand that officers perform searches in accordance with law etc. - which is "being difficult". If you are on your way to a great holiday, important meeting etc, you aren't going to risk it. Because anyone "being difficult" will be detained or rejected. So I'll just fold and give them my password. And they know this.…

Then, bluntly, you have made your choice. Those unwilling to stand up for themselves can't expect anyone else to stand up for them.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#158
post #42

Is it an option to just feign ignorance and claim not to know the password? Sure, they might confiscate it but I guess then you'll have to find a cheap alternative to restore your backups to until/if you get it back.

Why bother feigning ignorance? If you don't want them to have it, and you're willing to deal with the hassle, tell them that you won't give it to them. More people standing up and saying no is one of the few things that might actually make a difference.

Plausible deniability in case of consequences for not revealing password.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#159

Earlier quoted context omitted.

> These kinds of people have no choice but to be "difficult" Then they don't get in. Things like company secrets or client-lawyer confidentiality just doesn't apply here. You have a choice to give all that up and enter, or just return. The solution as others pointed out is not to travel with the data, but that's just cumbersome. You can always just use whatever cloud service you want, and delete the local copies, dow…

They may well ask for your passwords to the common cloud services; they already ask for your social media passwords.

Luckily most places have 2FA so giving them the password to Facebook or Gmail is "only" equivalent to logging in so they can look around then and there. They can't look around once you have passed the border, and they can't sabotage you by setting a new password unless they keep your device or actually change the 2FA settings. I think that's pretty rare.

I honestly don't think they need/use/keep passwords after I pass through. They may want to look in rare cases, but I actually think it's more of a "control question". If you don't have a normal set of social media accounts you are not normal or you are hiding something. If you aren't willing to show it, you are hiding something. What you are hiding doesn't matter. They use it as a "tell" to see if you need to be investigated further.

These questions have always existed. They ask you what your business is entering the country etc, but they are as interested in whether you are sweating as they are in what you respond. Same here. They don't need to see your family photos they need to see you give up your privacy like a "normal person"

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#160
post #92

Earlier quoted context omitted.

> use truecrypt be coerced to give away your truecrypt password.

Truecrypt has deniable encryption and duress passwords.

Whether something is deniable is not a matter of software features, but your acting skill.
Post reply on HN