"But non-citizens, possibly including LPRs, cannot: if an alien attempts to cross the border with a device they can't unlock "because they don't have the corresponding 2FA token with them" (as one friend suggested they do), they'll be detained, their devices confiscated, and then put on a flight out of the country."
I'm not a US citizen. I don't have anything in particular I care about the CBP seeing. But, I'd rather they not have all of my 400 passwords. I'd then have to change everything, and also be breaking a bunch of bank terms of service.
I don't think CBP actually wants my bank info. But with all passwords in a manager, they would get it if they had access. However, with no passwords, they may bar entry.
"if an alien attempts to cross the border with a device they can't unlock "because they don't have the corresponding 2FA token with them" (as one friend suggested they do), they'll be detained, their devices confiscated, and then put on a flight out of the country."
I guess they haven't yet started asking for social media passwords, so maybe I'm overthinking this. I'm certainly going to be prepared to unlock any devices. It's the web passwords I'm not sure what to do with.
Understand that you may be denied entry to any country but your own. It's a fact of life which you cannot do anything about, so you might as well accept it.
What I do is:
- travel with a machine which is not logged into any of my accounts
- if asked, I can honestly say that I do not know any of my social-media passwords (because they are all of the form mZOH05WaxeAWqI79myMxcx or SWwDmDOkyHCVdX8eOiTLXC1U1psffeXfFgNx6PaZZhp); if that's unacceptable to customs in any country, they can send me back home
- if they press, I can honestly say that my computer back home (not the computer I have with me) has my master password file, and that there is no other copy