Live data from Hacker News

New DHS policy on demands for passwords to travelers’ electronic devices

papersplease.org

181–190 of 297 posts

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#181

And you still call your country a democracy! If this doesn't change, I will never consider to move or even go on vacation to the USA, I might live in a state that has a lot of problems (Italy), but at least I have the right of privacy, and I can take a plane without having agents searching through my sensitive information on my devices.

It's not (nor has it ever been) a democracy. It's a Federal Republic. More info: https://en.wikipedia.org/wiki/United_States

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#182
post #157

Earlier quoted context omitted.

Then, bluntly, you have made your choice. Those unwilling to stand up for themselves can't expect anyone else to stand up for them.

Exactly. I can't afford to stand up for my ideals at the border . I expect people (including myself) to stand up for these things, just not at the border . My main way of disagreeing with policies like this is to simply skip any travel to the US. I can't vote, but I can vote with my wallet. But basically saying that people should either accept that their expensive holiday (or job) might go down the toilet, or they ha…

I'm not talking about your (or anyone else's) principles. I can't see into anyone's heart or mind.

I'm talking about revealed preference, more than anything else. Yes, fighting is risky and unpleasant. It always is. You make your choice and live with the result.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#184

Earlier quoted context omitted.

> These kinds of people have no choice but to be "difficult" Then they don't get in. Things like company secrets or client-lawyer confidentiality just doesn't apply here. You have a choice to give all that up and enter, or just return. The solution as others pointed out is not to travel with the data, but that's just cumbersome. You can always just use whatever cloud service you want, and delete the local copies, dow…

They may well ask for your passwords to the common cloud services; they already ask for your social media passwords.

A process that I've heard some financial people developing (highly secret/proprietary/potentially valuable) software use when traveling is:

1. Store confidential data on company servers or a secure/trusted/audited cloud service.

2. Protect that data with two factor authentication, ideally with an ephemeral/rotating factor.

3. Incorporate a duress code into one of the auth factors (e.g. "add one to the google authenticator result when logging in or you get fake data/get permanently locked out until you human-authenticate to regain access"), ideally both.

This is far from perfect, but reasonably secure and not terribly inconvenient in practice. Additional layers of protection can be added to the duress process, like defaulting to under-duress behavior until a certain timeframe (i.e. you're being searched at the airport and not during your appointment time slot), or when from an unrecognized network location. Like all duress-code-based responses, it is vulnerable to humanity (e.g. torture/intimidation).

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#186

Earlier quoted context omitted.

Isn't it the same with Canada, though? I admit, I only watched those Border Patrol Shows on Netflix and what not, but it always disturbed me how much they always wanted to check the whole phone.

Yes, Canada, the UK, and Australia all have policies to ask travelers for their passwords for laptops/cell phones, and you'll be sent back home (if you're a foreigner) or arrested (if you're a citizen, at least in Canada [1]) if you refuse. 1: http://www.cbc.ca/news/canada/nova-scotia/alain-philippon-to...

UK citizen here. I'm not aware of any policy in the UK that forces travellers to hand over their device passwords - i.e. not in the same draconian way that's happening in the US. Border control in the UK is pretty well overstretched as it is. I don't think they've got the resources to perform this type of intrusion, even if they wanted to.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#187
post #49

Earlier quoted context omitted.

I am an American living outside the US for ~5 years. It's become very difficult to plan for the future now that I am in a permanent relationship with a non-US citizen (we would be married already if not for the various complications associated with being different nationalities). Especially since she is from a so-called "shithole" country, one of the poorest on earth, we have doubts about whether it's even worth ever…

I went through this process in 2015-2016 after my fiancee was turned away while we were entering the US in PHL (they said she had already spent too much time with me there). We went back to Spain where she's from and started the 4+ month long process of getting her a K-1 fiancee visa. It is a lot of reading, a lot of forms, and nerve-wracking interviews so I understand where you're coming from. But now she has a gree…

The immigration system is horribly broken. My wife, too, is an immigrant, and our experience is vastly different from yours.

For example, they scheduled her for an interview on a date that was impossible for her to make (iirc, that was her first day of a new job). She went to the INS offices to ask to have it rescheduled, and the person at the desk just gave her a flat "no, we do not reschedule interviews". My wife asked to speak to a manager - something that's eminently reasonable, if maybe slightly annoying, at any business - at which point the INS employee bushed a button that summoned to burly guards to physically remove her from the premises, stating that she was a threat to the office's security.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#188

Earlier quoted context omitted.

Isn't it the same with Canada, though? I admit, I only watched those Border Patrol Shows on Netflix and what not, but it always disturbed me how much they always wanted to check the whole phone.

Yes, Canada, the UK, and Australia all have policies to ask travelers for their passwords for laptops/cell phones, and you'll be sent back home (if you're a foreigner) or arrested (if you're a citizen, at least in Canada [1]) if you refuse. 1: http://www.cbc.ca/news/canada/nova-scotia/alain-philippon-to...

I had a friend get refused entry to Australia because they made him open his Facebook messenger, and they found out he was planning to work on a tourist visa.

They only did that though because he just finished a 3 month tourist visa, left the country for a week, and then came back with another 3 months.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#189

Earlier quoted context omitted.

Yes, Canada, the UK, and Australia all have policies to ask travelers for their passwords for laptops/cell phones, and you'll be sent back home (if you're a foreigner) or arrested (if you're a citizen, at least in Canada [1]) if you refuse. 1: http://www.cbc.ca/news/canada/nova-scotia/alain-philippon-to...

UK citizen here. I'm not aware of any policy in the UK that forces travellers to hand over their device passwords - i.e. not in the same draconian way that's happening in the US. Border control in the UK is pretty well overstretched as it is. I don't think they've got the resources to perform this type of intrusion, even if they wanted to.

From 2013: http://www.telegraph.co.uk/technology/10177765/Travellers-mo...

Also a case in 2016 of a UK citizen being arrested for refusing to give his password to UK border police: https://www.theguardian.com/uk-news/2017/sep/25/campaign-gro...

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#190
post #155

Basically, don’t carry data with you. Leave it all in the cloud. You can’t be compelled to provide the password for a service which contains data that is not on the device.

I posted basically this elsewhere on this thread, but:

1. Make sure it's a cloud service that you trust (i.e. audited, self-hosted and you know what you're doing etc.), since they'll probably keep the data on it forever, regardless of whether you delete it.

2. They will eventually ask for your password for that cloud service and download the data from it. For the truly paranoid (which is increasingly coming to resemble "people who care about security at all", sadly), use a cloud service with a duress code https://en.wikipedia.org/wiki/Duress_code. Returning fake data with a duress response can get you through security quickly if the people searching your data don't identify it as fake. Otherwise, the response of "I just gave a duress response and was permanently locked out until I personally visit the agency holding it in $my_country_of_origin and re-authenticate" may have a slightly higher success rate of getting you through security than refusing to surrender passwords. But then you don't get access to your data until you do that. There's always the "inconvenience" bluff-call option of "after I gave the duress response, I won't have access to my data for a week", but depending on how petty/suspicious the officers are that can be equivalent to asking for a week's detention.

Post reply on HN