Live data from Hacker News

New DHS policy on demands for passwords to travelers’ electronic devices

papersplease.org

221–230 of 297 posts

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#222
post #16

Earlier quoted context omitted.

> Talking to your representative is roughly as useful in curbing these things, as doing nothing at all Have you ever called your representatives?

www.google.com/search?q=i+contacted+my+representative+site%3Areddit.com Knock yourself out. Spoiler alert: almost everyone reports getting a cookie-cutter email or scripted response about why the rep will stay the course. They clearly have an established strategy of how to handle the 'contact your rep' crowd and channel their efforts to /dev/null.

Every single one of those "contacts" was people emailing their representative. Emailing your representative isn't an effective means of communication. It takes no effort to write an email. Most political offices assume an email is a form letter drafted by some special interest.

Call your representative, or meet them in person when they're back in the district. If they know you're a real person, they will respond to you directly with something more than a scripted response.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#223
post #82

Earlier quoted context omitted.

> thousands of reddit stories Many of “thousand of Reddit stories” are just like your comment. Repeating a meme, nothing more. Will your representatives always be responsive? No. Some are worse than others. On some issues, the political tea leaves are too obvious to merit discussion. By and large, however, representatives and their staff care about their constituents. When you call (better than form responses on webs…

> Many of “thousand of Reddit stories” are just like your comment. Repeating a meme, nothing more. Demonstrably, provably, completely, wrong. https://www.reddit.com/r/netneutrality/comments/7kzblu/i_con... - 4 page account of comms https://www.reddit.com/r/Firearms/comments/75yjkd/the_offici... - photos showing redditor attended in person instead of making a phone call. Was told their concerns would be 'passed along'…

You need to actually read your cites. Many of your link actually support what we've been saying. Their concerns were passed along to the representatives and they were pleased with the responses they got.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#224

I don't know if it worries my American chums, but I won't visit the USA. As a foreign tourist bringing money into your economy I feel there is a very real risk to my privacy and increasingly my person. I am beginning to favour goods and services from EU where human rights still mean something. Perhaps it doesn't matter to you how the US is perceived overseas, perhaps you don't want my money. Perhaps you don't mind be…

Isn't it the same with Canada, though? I admit, I only watched those Border Patrol Shows on Netflix and what not, but it always disturbed me how much they always wanted to check the whole phone.

Essentially every country in the world asserts the right to carry out a thorough inspection of anything crossing its border.

I'm not sure why people think electronics would be an exception to this general rule (which has been in effect, like, forever... the only exception that comes to mind is diplomatic pouches).

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#225
I've been working on an app/program that could be of use for this kind of situation. It's in way to early of a state to be released though. For the sake of giving it a name, we can call it Dead Man's Pass.

Effectively, for phones or laptops, you would have your standard password as well as a secondary password. If you use your fingerprint to open your phone, you would be able to register a different print as your secondary print.

Using your regular password/fingerprint would unlock the device normally. Using the secondary (dead man's pass) would either wipe the device, or open it to a honeypot state.

I think this would be useful for phones and perhaps laptops. If a memory card is confiscated, perhaps it could be encrypted with a program that follows the same concept. Either way, it allows people like DHS to demand a password, and have one given to them while also solving the problem of not wanting to show them private information.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#226

Earlier quoted context omitted.

I'm not an expert in the applicability of that law, but if they're systematically asking people for passwords, that's not necessarily "addressed to a single person".

Paperwork Reduction Act is an attempt to reduce paperwork. Customs and immigration questions are not paperwork, despite how systematic they are. Consider if they have an OMB number for "Citizenship? Duration of stay? Purpose of visit?", the questions nearly every traveller gets asked. They don't. Of course they don't. They don't need one.

These questions are present on customs form 6059B. Asking them again verbally probably isn't illegal. This form does have an OMB number: it's 1651-0009.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#227

An obvious solution is to upload your data to a cloud service before passing the border and download them later. Will that be declared a contraband soon?

I trust my country more than I trust Google/iCloud/Dropbox/etc. I'll take my chances.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#228
post #212

Earlier quoted context omitted.

Wouldn’t an immigration interview trump any other reaponsibility a person has? I’d explain to my boss the situation and see if I can get my day switched way before I’d expect any government agency to shuffle things around for my work schedule (especially any agency that’s immigration related).

I'm sure it would if the conflict cannot be resolved, i.e. both the immigration officials and the boss are unwilling to accommodate the other requirement. Missing one's first day of work generally looks bad though, and trying to avoid that if possible is reasonable. Attempting to reschedule an immigration interview doesn't strike me as unreasonable, nor does escalating to a supervisor if you don't like the answer you…

I agree that the latter part sounds very excessive, but I still can't understand how protecting one's legal status in the country they are in wouldn't far and away be the most important thing on their calendar.

Given how long everything takes when dealing with immigration, it's not exactly surprising that they aren't able to accommodate people's schedules.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#229

If you are a U.S. person they cannot deny you entry for not giving them your passwords, though they can keep your devices for some time.

I think I remember reading that they can still detain you "indefinitely" even if you're a US Citizen. Is that not correct?

They can detain you indefinitely even if you're a US Citizen, but afterwards they will be sending you a rather sizable check to settle the lawsuit you file for getting your civil rights violated.

Unless you commit a crime crossing the border (like getting caught with drugs), CBP does not have the authority to detain a US citizen without probable cause. Refusing to provide a password is not probable cause.

Re: New DHS policy on demands for passwords to travelers’ electronic devices

#230

Earlier quoted context omitted.

> These kinds of people have no choice but to be "difficult" Then they don't get in. Things like company secrets or client-lawyer confidentiality just doesn't apply here. You have a choice to give all that up and enter, or just return. The solution as others pointed out is not to travel with the data, but that's just cumbersome. You can always just use whatever cloud service you want, and delete the local copies, dow…

They may well ask for your passwords to the common cloud services; they already ask for your social media passwords.

I'm not trying to be facetious but what if they do ask and you say "sorry I don't have any cloud services" or more realistic "what are cloud services?"

I'm no digital security expert and I haven't ever, and don't ever want to, travel to the US but if I was to travel there any devices I took would be blank. All data I needed would be in the cloud. How are they going to know?

Post reply on HN