Passwords for social media accounts could be required for some to enter country
techcrunch.com
techcrunch.com
We can discuss all we want whether it was wise for anyone to share, say, everyday normal photos of their children or themselves on Facebook.
If you think they shouldn't have shared normal, everyday, family photos on an online service, sure, fine, I don't know what to say. But let's say they did do so, which is pretty normal.
Are they entitled to some privacy from whatever pervs the DHS hires?
Remember "they" is the friends and family of the person visiting the US, not the person themselves.
Many of these friends and family will be US citizens, so arguments about differing rights for non-citizens, whether valid or invalid with respect to privacy rights, don't necessarily apply in those cases.
The way US government treats legal immigrants, they might as well ask them to bring a lube and drop pants and bend over at the immigration check. This comment might seem crass but it is nowhere close to the crassness with which US government has come to treat people who are going through all the ridiculous legal hoops and in process making criminals out of perfectly ordinary people.
This is like having a super complex CAPTCHA on your signup page for humans while letting bots pass through by some minor cookie manipulation.
I mean, the whole notion is horrific and abysmal, but in today's OAUTH world you're not just giving up the facebook goods, you're giving up co-logins to lots of other sites too. There's other technical issues too - I use 2FA everywhere. So, do I disable the 2FA or have to give that up too? In perpetuity? I mean, I don't trust law enforcement to not go around murdering people, why should they have access to passwords?
The very thought or suggestion that this could someday happen would make me cancel any and all trips to the US for the foreseeable future (if I weren't already a US citizen who lived here, that is, and as it is I'm seriously considering emigrating in response to this administration).
The brain drain effects will have to be enormous. There's already a company focused on helping startups use Vancouver to base their remote employees. [0]
On so many levels this is bad. I'd heard the notion floated under the Obama administration, but I trusted them to be adult and see all the possible ramifications. I do not trust the Trump administration to even be in the neighborhood of rational, let alone adult. I mean, they dumped the immigration executive order with no actual warning whatsoever (besides repeatedly saying he'd do just that, I suppose). So now we have no real choice but to take them at their word.
0: https://techvibes.com/2017/02/01/true-north-establish-vancou...
The internet is a cesspool of people who troll, create fake profiles, invoke reactions, behave completely different than they would on the streets, and intentionally hide their identity. Using it as a primary source of identity verification is a terrible idea.
Why not require proof of a financial statement? Bank account in your name, or a process to verify somebody via their bank account without requiring their bank account password.
Most people aren't gonna create fake profiles. Or if they do, they'll be suspiciously empty. If someone is gonna go through that effort to get entry they probably can just refrain from posting their plans online in the first place.
It will be effective initially, but people will catch wind of this and start to purge their Facebook profiles prior to entry. I'm certain that cheap online "Facebook cleaning" services will start to pop up very soon.
People who will go thru the hassle of dealing with a fake profile will just not post about their plans to enter "illegally" in the first place. People prone to writing dumb shit online are probably not going to wise up because of this.
Perjuring yourself to a border agent is inadvisable. The legal threat follows you whether or not you are granted or denied entry. At any time, it may be discovered and lead to very serious criminal and administrative consequences.
If you simply refuse to give over the password, they can refuse entry. But they can't necessarily treat you as an actual criminal.
It is never a good idea to lie to, mislead or interfere with law enforcement officers. If you are having trouble, get a lawyer as quickly as you can.
Speaking of which: I am not a lawyer and consequently this is not legal advice.
I suspect the that deliberately creating a false profile would push you into perjury territory. And in any case, even if the rulings come down otherwise, you'll still get arrested and remanded for a long time while the lawyers sort it out.
Again, though: I am not a lawyer. Consult a lawyer.
Things like this (and this[1]) just help destroy the idea that the US is a special haven of freedom that cause many people to want to visit in the first place.
At least in my opinion USA is one of the last countries on earth which is offering near 100% freedom of speech, largely free trade and individual freedom, right to own guns and many other things which you can not own without nonsensical bureaucracy, huge landmass, top notch education and a growing capitalistic society.
The way I see it countries like France, UK are pretty much going down the drain through which welfare states often go. In these countries government perhaps don't even need your password. They can do all sort of unauthorized searches any ways. Australian society remains hostile to non white people and China lacks individual and political freedom. Canada is close but it is far too cold for me. Japan is pretty much isolated because of the language and unique culture.
Good, don't come then. I've traveled the world a decent bit, and there is a reason why people from all over the world come to the US to start a business or try to make financial independence and a better life from their home country.
People that don't want to get caught entering under false pretenses can just delete social media or not post dumb stuff on it in the first place. This isn't gonna catch spies[1] and terrorists or whatever, it'll prevent visa overstays and stuff like that.
[1] Though I heard of one spy getting caught cause she tried to collect frequent flier miles on her main account while traveling under aliases. So, who knows what kinda things will happen every now and then. But that can't be the primary aim of the idea.
For example:
> Do you seek to engage in terrorist activities while in the United States?
"I confirm under penalty of perjury that this is the only social media account I have." Later when the government wants to target you specifically they will point out that you had also owned an Orkut account which you had failed to disclose. Bam! you have to leave the country.
This is insanity.
The evidence to the contrary is in greater favor until you provide support.
I can only assume this threat of asking visitors to grant government agencies complete and unfettered access to their online accounts was conceived by people who don't know how the internet works. There are just so many logistical problems with it at so many levels that it's hard to imagine it ever working in practice.
I'll guessing the right thing to do, if you know about this requirement, is to set up a Facebook account specifically for this purpose, then right before you cross a border, change its password to something easy to remember.
(a) NSA info is drying up due to resistance from companies
(b) NSA info can't be shared due to low-priority targets
(c) NSA info can be shared but there's something going on between NSA and DHS that makes this difficult
(d) NSA info can be shared, but only to people of a certain clearance, which makes this non-scalable for ports of entry
(e) NSA info can be shared but the goal of the policy isn't info, it's signaling
The NSA is probably already cahooting with the CBP for selected cases.
most likely, I say, is that the data in NSA Utah is basically like a walled off test dev that only a few special people can query for currently important things. their main job is to determine how best to query it in the future
and then each agency maintains a prod database of its own data its collected to oppress everyone. very rarely would they ever get NSA data
I think that you are slightly overestimating how much the NSA can achieve with current technologies.
Then, of those conversations (presumably several billion), how many are stored with some identifiable metadata, like IP address, GPS tag, real name, photo?
Even if it is only a few million people, it's still way too much of an overreach, and still ridiculously cheap to store on tape and analyze on disk/ssd.
then you just pay someone who cant find any better work to type queries into a system.
How many times have you talked about potential crimes with your friends? how many times have they talked about using drugs, fake IDs, speeding, petty theft, etc
how many times has "child porn" inadvertantly made it into your browsers temporary files.
Almost everything is a crime, and the government's ability to cheaply prosecute is only growing
My issue is with your claim that the NSA could incriminate "literally" anyone on the planet.
many people in government from all sides abuse technology to control the lives of people in new, shocking, and totalitarian ways
to say "i'm not muslim, or Iranian, or Mexican, or a dissident", or etc, will soon no longer suffice.
Every conceivable activity and word you speak or think will eventually be evaluated if the technology is cheap enough and politicians are daring enough
The constitution doesn't even stop people from doing things like this anymore, so I don't know how to fix this
I arrived at that thought while thinking about how Dropbox Paper is more modern than Google Docs (which turns 12 this year).
Sometimes it's better to start over from scratch.
It lets you do things you actually couldn't do with lots of small changes.
Anyone can be thrown in jail at any time for relatively petty reasons, and you can be physically surveilled by detectives on mere suspicion. It isn't pretty, but it's the truth.
Sure most of us will be fine with basic precautions but 20 years from now is a different story? I prefer not to think about it
People being physically surveilled doesn't land in the same camp as mass digital surveillance. It requires a warrant, even if they can be obtained for petty reasons. The government doesn't have the bandwidth for physical surveillance of everyone. It just isn't the same thing.
20 years from now is a long way off, long enough for us to make it better. If you give up and don't think about it, people who care and work for what they want will probably get what they want. Money and government power certainly do want to watch what you're doing, if they can get away with it. But if the public, on the whole, really truly started to care about privacy, enough to vote on the issue and enough to make purchasing decisions based on privacy concerns, it would get better. The only reason it's bleak right now is the majority of the world is still giddy about joining Facebook, rather than concerned about the implications of digital public over-sharing. Give it time and get your friends & family to care, and it's more likely to improve than not. If we all look the other way, then we get what we get...
Once US government is faced with either wage a war in country X under the pretense of WMD or Zombie virus or spend on public education I think we will see some sanity. But the war mongering right and welfare mongering on left will not let that pass.
"You will not share your password (or in the case of developers, your secret key), let anyone else access your account, or do anything else that might jeopardize the security of your account." [1]
Perhaps this would give FaceBook the power to intervene and, well block their account or something.
The law always trumps contracts.
They are a US company, and their TOS says they can ban an account for any reason or no reason at all. If they chose to ban anyone who shares passwords, even with the US government, even if they are Americans or not, they are within their rights as a US company to do so.
Also, proximity in time to an event is admissible as evidence of intent.
PS. password managers mean you won't suffer the same inconvenience.
If you offer to help a stranger fix something on their laptop, what percentage do you think would just tell you that their password is their kids' middle name -- and how many do you think would use the same password on their Gmail and bank accounts? The fact that so few people take privacy and security seriously is enraging; it's hard to go from enraged to outraged when most people don't even bother protecting themselves.
It's all so infuriating.
Fucking terrifying, and 99.9% of the people won't bat an eye before logging in. Thought policing is "for national security." That same percentage of people would be ok with the government raping their own mother if it was for national security.
This is all so damn frustrating.
Got fixed I think... but how many people cared?
Every try and roll out 2FA for an office and get the majority of people -- C-level folks included -- griping and giving pushback that they hate it because now they have to do one more tinsy little thing to sign in? After a while it's just sort of like... "Well... you've been warned you should care more about security, you have been given every opportunity to learn about how technology works, and bottom line I don't really care about your privacy if you don't..."
It's so frustrating is all I'm saying.
I wrote it off as a nice sound bite, but maybe he's right...
Hey I'm sure I'm not the only one to think of this, but to everyone trying to build the next social network, how about putting in a feature where a second password will open your scrubbed profile? You'd choose what goes in from your main account, and not have to build entirely fake accounts. There's a way to get some quick traction, should the Trump administration succeed at making a policy of asking for passwords!
https://en.wikipedia.org/wiki/Dishfire
It's not even out of the question for malicious private actors who don't have total control over the whole system:
https://krebsonsecurity.com/2016/09/the-limits-of-sms-for-2-...
BTW, legally speaking by US law, it's a lot easier to force someone to give up their thumbprint than a password. So whatever you do, don't go through an American border with touch-id unlocking your phone.
We detached this subthread from https://news.ycombinator.com/item?id=13626479 and marked it off-topic.
The concept is so old that not only did both side do it, but the previous administration has a court case judged against them. What we should say to the current administration is what the court said to the previous, which is that the 4th amendment applies at the border (https://www.techdirt.com/articles/20130308/13380622263/9th-c...). Password for social media, as with password to unlock the address book of a phone, cannot be demanded without reasonable suspicion.
Regardless of party, I would invite you to google the following governmental overreaches and then see which parties were in office:
The Pirate Bay raid, NATO bombing of Yugoslavia, NSA surveillance revelations, Superpredators, War on Drugs, War on Crime...
One of these things is not like the others
The West (mostly USA) bombed everyone regardless of ethnicity in Yugoslavia and then took their largest assets. If they really cared about democracy and freedom, and if the Serbs really were genocidal maniacs as many believe, then the evidence in this film that shows the contrary wouldn't exist
Off topic, but I cringe every time someone responds like that. It's essentially shows you can't (bother) to write a coherent response and instead want the other guy to waste 2 hours watching your video.
Upon Tito's death in 1980, Western European and US political and business interests _systemically destroyed_ Yugoslavia, undeniably.
They did so to "fight communism", "promote democracy", and more importantly, bomb Yugoslav mines, factories, etc that were competing with Western ones both in Yugoslavia and abroad.
Everyone from the IMF, UN, World Bank, Reagan Admin, Bush Admin, Clinton Admin (and all of their supporters like Biden and Albright), Germany, etc etc, all of these participants were DEEPLY and PUBLICLY involved.
The end result was the bombing of all ethnicities of people, including the ones that were supposed to be being "liberated", such as the Bosnians and Albanians.
So, lastly, to tie it back into my original point. In my opinion, if you view all of this video evidence, and still say "ONLY THE (democrats, republicans) DID THIS), then you are denying the vast evidence that it was a cross party, multi decade plan.
I hope you can take the time to reply on the quality of my analysis!
If they didn't, then it wouldn't be happening from both parties
I agree that on a scale of badness, Trump certainly seems worse to me than Obama.
But in your analogy it isn't so much that Trump took a car from zero to 110 in a 60 zone. The car he got in was already speeding thanks to the policies of the Obama administration, and prior administrations. I don't think pointing this out is necessarily excusing it through false equivalence.
So while I agree that it's important to tell the difference in scale, I think it's equally important to realize that in most cases these policies don't come about out of thin air, they are built and extended from prior policies.
My honest opinion is that we've unfortunately divided ourselves down the middle and we've picked causes and policies like we were picking players in dodgeball and you can only be on one team.
I think it so happens either by chance or by some kind of underlying tendency that one side tends to be more correct or at least more progressive (which tends to be more correct in the long run) than the other. I know plenty of people who correctly (I think and I think the data supports) acknowledge climate change is real and largely man-made but could no more discuss the actual causes or ramification than your average climate denier.
I want to be able to have honest, nuanced conversations with people but they typically end defensively and quickly (which is often the result of someone I agree with who can't help but be snarky and counterproductive) and I want to find quick and effective counters to some of these argument killers.
> Visitors entering the country under the Visa Waiver Program, which allows citizens of some countries to visit up to 90 days without a visa, would not be required to list their social media accounts, and the forms would not ask for passwords.
> The department said that while it does not consistently examine social media accounts of applicants for visas or immigration, it has a list of nearly three dozen situations in which social media can be examined to screen applicants.
They say they didn't ask for passwords, which is the main objection, and also said it was optional (see also the same thing in this very article). How does it make sense to call it the same idea?
Most people involved in federal agencies don't get purged and replaced at every election; they have long careers in their chosen agency, regardless of who's in the White House. So it's easy to find someone who's been there through a few administrations and say "this guy has consistently proposed this idea under multiple administrations", but present it as "this idea dates to the administration I want to falsely paint as identical to another one".
The related trick is the West Wing bit with the reporter who keeps asking the press secretary to give an answer on whether the President has considered calling a lame-duck session of Congress: the reporter knows, and the press secretary knows, that if she asks the President whether it's been considered then it'll be true that the topic came up in a discussion the President was part of, and the reporter will be able to spin that to claim "PRESIDENT CONSIDERING LAME-DUCK SESSION" without an outright lie being involved.
(I wish you wouldn't call him names, it's a little uncivil.)
stuckagain wrote (above) that "Now we have insane cheetoh in office and we're getting insane cheetoh policy ideas", I was pointing out that while he may support it, this idea didn't came from the current POTUS, there was even a bill proposal during the previous administration.
I actually wrote in protesting this policy over a year ago when they proposed it. It has nothing at all to do with Trump.
both parties are guilty. if trump doesn't want to enforce it, he wouldn't. if obama admin didn't want to brainstorm it, they wouldn't have
All of this is trivially verifiable, just look at when the proposal was submitted, accepted, and then enacted. All of them were before election day. All of it within the executive branch's umbrella (i.e. there was no act of congress).
If he does, do you agree that he too is at fault?
or are you of the opinion that he will enforce something he doesn't agree with, just because Obama made it?
the evidence still shows both sides at fault
I think requiring passwords for social media is fucking stupid. Really, really stupid.
People who expects to have "privacy on the internet" are also fucking stupid. Yes, this includes facebook, twitter, instagram, email, et. al.
If you wan't to keep a secret, don't tell anyone. If you put something "private" on the internet, you've ostensibly told 3-4 billion people.
Access to social media accounts includes access to private communications, e.g. messages that were sent with the understanding that only the recipient would receive it.
But those nudes your girlfriend sent you are now in the hands of an immigration agent working in the name of "border security".
It is very foolish to consider anything, sent across any digital medium "private" in any sense.
I'll risk an analogy (I know, I know) and compare your examples of digital trespass to examples of physical trespass.
If someone can physically enter your (perhaps unlocked) home/place of business/doctor's office, etc. and expropriate copies and originals of documents associated with you--documents that are very likely protected by law as they are in the case of digital documents--would you also assert there is no such thing as something being "private"?
Your argument, to my mind, seems to blame people for having reasonable expectations of privacy and absolving criminals who violate that privacy.
EDIT: Recast caveat/second paragraph. Readability.
irishcoffee is taking the "don't walk there at that time, everybody knows that" position, and you're taking the "everyone should be able to walk there at any time" position. You're both right, and yet these two positions never ever get reconciled in a productive manner.
irishcoffee is engaging in the victim blaming fallacy, which makes him wrong.
"They violated my privacy! I didn't intend for them to see that!"
They didn't. You put private information in a public place. I'm floored how on hn I'm having to describe how the internet works.
If you put something on the Internet, you are putting trust in those people (and companies).
I what was meant was, most people do not understand that when they send nudes to someone, that person is not the only person that has access to those nudes.
As an example, let's say Alice sends nudes to Bob, by way of a simple email. In this example they do not use encryption or even SSL.
Apart from Alice and Bob, there are others who can access the nudes:
* others on the local network
* the ISPs (of both parties)
* email server providers (of both parties)
* anybody recording internet traffic at any relevant point in this process
This is where the metaphor of sending a letter breaks down. People use the Internet as though messages only reach their desired recipients.
I'm assuming I don't need to name the specific agency which has been intercepting nudes and forwarding them to their colleagues.
It is true that that is illegal.
It is true that (most) people have an expectation of privacy.
It is also true that that expectation is broken on a regular basis.
Therefore, unfortunately, in the world we currently live in (which is not an ideal world where corporations and governments always follow the law), that expectation is unfounded.