Social Media Needs a Travel Mode
idlewords.com
idlewords.com
In particular, it needs to be normal enough that a significant fraction of all travelers do it. The feature can't be marketed as a protection for at-risk travelers, but as a common-sense safety mechanism useful to all travelers.
I think it's crazy that people walk around with phones that have access to years of email communications, and that even in the happiest timeline we could have ended up on after 2016, features like this are long overdue.
Yes, exactly.
Border agents are trained to look for anything out of the ordinary. Currently, using a feature like this would immediately raise a huge red flag and encourage more questioning, detention and possibly even deportation based on the person's country of origin and the mood of the border agent.
Incidentally, that's why I think there is virtually zero chance for these types of features to take off: the system strongly discourages early adopters from trying them.
Citizens are probably OK, at least until they bring in Exit Visas...
That can be addressed by how it is marketed. Instead of calling it "Travel mode," it could be called "Work mode" or something like that. Commercials could target college students going home to visit parents and not wanting parents to see all their crap or that sort of thing.
That's what I plan to do if I ever get asked - telling them to piss off. Worst they can do is confiscate my phone. I am choosing to remain silent. If they still persist on hassling me and end up taking my phone even temporarily, I will treat that device as now being compromised and will take the appropriate action.
Last year I was hassled (not at the border) on two occasions. Once in NYC in the Port Authority by the cops that patrol that facility and a second time in the suburbs of NJ. In NYC the cop didn't like that I was getting testy with a Port Authority employee for not letting me though to get to my bus. He intervened without cause and asked for my ID. I told him "nope". He tried making up some story to justify him asking me and I told him "I'm not giving you my ID. I'm leaving, bye." and then walked away.
In NJ I was detained for way too long under suspicion of several random things. This wasn't even a traffic stop. I parked the car and then they drove over and harassed me for a solid 45 minutes. First they claimed I was drunk. Then they said I was on this particular street to buy drugs. Then they said I could actually be dealing the drugs. They frisked me for "officer safety" and then tried to get me to walk the line and do a bunch of sobriety tests. I told them I wasn't doing any sobriety tests. They lied and said I could be arrested for mere refusal. I told them they were full of shit and that I can only be arrested for refusing the actual breathalyzer, not the voluntary tests. I then remained silent for rest of the encounter. Not a peep, just dirty looks back and forth. Eventually they had to let me go. Moral of the story is that cops do back down plenty of times but you have to have the will to test them. And it greatly helps if you know the law.
One last thing - if you are wondering why I didn't just take the sobriety tests if I'm sober, there's a damn good reason. Some years ago, my friend got arrested in that same town for blowing a 0.00. How you ask? Because first he did the voluntary tests which no one in the history of mankind has ever passed - at least not according to any police officer. Those tests are always used to compel something else like a search, breathalyzer, etc. It's an excuse to justify further harassment in many cases. So my friend did their tests and "failed". So they compel the breathalzyer and he gets a 0.00. He thinks he'll finally be free to go when they tell him that based on his failure on the voluntary tests he is clearly under the influence of something. And since it isn't alcohol, it must be drugs. So they arrest him, take him down to the station and draw blood. They charge him with intoxication and illegal drug use (because he said he doesn't take any medications for anything) before the blood results come back because those take 2 weeks or so. Even though they come back totally clean he has still been charged and is required to show up in court anyway. He had to spent $500 or so on a lawyer to represent him that day and get that bullshit dismissed. I am not sure if he got the arrest wiped from his record - I don't think he did. Which means he now has a record for no reason at all. Please take this story into consideration the next time you interact with law enforcement. I no longer cooperate with law enforcement for anything other than a minor traffic stop, maybe not even then. If a stop were to start going somewhere else (i.e. they are fishing for stuff or trying to screw me just because they feel like it) my attitude and strategy for dealing with them does a complete 180. The only reason I may comply for minor things is simply because it's the quickest way to be back on my way. 99% of the time their minds are already made up. Nothing you say will get you out of a ticket in most cases, so there's no reason to cooperate anyway. Playing nice is just for expediency, but as soon as that turns into something else, you need to switch gears immediately.
Sorry for the long post. My interactions with police last year are a sore spot for me (there were other interactions I left out).
It also helps if you aren't a person of color.
One feature I'd like with this travel mode is having a log of every bit of data that was accessed during the trip. At least then I would know how much was copied. Some kind of rate limiting would be good too, so they cannot just copy everything.
The one anti-pattern on every website is using your primary email address for both notifications and password resets. There is zero reason why you'd ever want an email address you have authed on your phone to handle Facebook/Twitter password resets, but the only way to avoid this is if you're willing to give up receiving whatever notifications you'd normally want to receive via email on your phone.
There's a really obvious reason: because you need to reset your password while on the go.
Where do we have all this AI for?
+ Facebook can make a filter that only displays a tiny subset of all posts. A filter that only displays a tiny subset of my friends.
+ Gmail can make a filter that shows only a subset of my emails.
+ Preferably the AI can then fill it up with stuff. :-)
In this way it all looks perfectly fine. There is only way less info in it.
This would save me time from making accounts for traveling purposes.
You think its crazy in you wish you (and everyone else) had a viable alternative? Or, you think its crazy in that you do something else that others don't do?
If the latter, what do you do?
Each feature we add for our own convenience makes a more tempting prize for a potential adversary.
Edit: Whether or not a particular feature/behaviour is reasonable or crazy depends entirely on the level of threat.
Why? I thought the whole point of connected, portable computers is for one to have access to pretty much all their data on the go.
Much of the point of the cloud shift was to get your data into the ownership of a private company who can make money off it.
If, for example, Apple can make up some lost money on iCloud with new obsidian gunmetal TimeCapsules with plausible deniability and localhost-tunneling features to sell to rich people, I'm sure they will try and do it.
I'm not really sure why you mentioned this, did something bad happen?
I am not in that camp and I have my objections to it. But, in this case, I think the sentiment is reasonable wrt the topic at hand, basically.
1. I far as I understand there is legal precedent establishing that electronic devices are basically the same as suitcases, and both can be searched at the border (i.e. in the same way that border agents can rummage through a backpack looking for drugs, they can rummage through a laptop's hard drive looking for evidence of drug dealing). The key idea is that objects brought across the border are fair game for search. However, wouldn't accessing social media accounts require fetching data over the internet from a data center somewhere? Maybe there is some info cached locally on the phone, but for them to, say, look through a traveler's post history they'd have to access data that is _not_ being brought across the border. How is this different from border agents finding a house key in a traveler's bag and then using that key to go to the traveler's house, open it, and search everything they find there?
2. Searching the data on the device is one thing. Asking a traveler to provide passwords seems completely different. It seems like a pretty clear 5th amendment violation. There's a lot of precedent protecting people from being compelled to speak.
Just to be clear, I'm wondering about this for US citizens returning home. Obviously all bets are off for non-citizens.
Why shouldn't non-citizens be protected by The Constitution? Not a lawyer, but these came up pretty quick in a Google search.
"It is well established that, if an alien is a lawful permanent resident of the United States and remains physically present there, he is a person within the protection of the Fifth Amendment. He may not be deprived of his life, liberty or property without due process of law."
Kwong Hai Chew v. Colding
". . . The Bill of Rights is a futile authority for the alien seeking admission for the first time to these shores. But, once an alien lawfully enters and resides in this country, he becomes invested with the rights guaranteed by the Constitution to all people within our borders. Such rights include those protected by the First and the Fifth Amendments and by the due process clause of the Fourteenth Amendment. None of these provisions acknowledges any distinction between citizens and resident aliens. They extend their inalienable privileges to all 'persons,' and guard against any encroachment on those rights by federal or state authority."
Bridges v. Wixon
"The alien, to whom the United States has been traditionally hospitable, has been accorded a generous and ascending scale of rights as he increases his identity with our society. Mere lawful presence in the country creates an implied assurance of safe conduct and gives him certain rights; they become more extensive and secure when he makes preliminary declaration of intention to become a citizen, and they expand to those of full citizenship upon naturalization. During his probationary residence, this Court has steadily enlarged his right against Executive deportation except upon full and fair hearing. . . . And, at least since 1886, we have extended to the person and property of resident aliens important constitutional guaranties -- such as the due process of law of the Fourteenth Amendment."
Johnson v. Eisentrager
For me, this feels like China all over again. If requesting passwords becomes prevalent in the US, then the same precautions that travelers take when entering China will become the norm from the US.
I did that and life goes on perfectly - I don't miss them a bit and I don't think anyone noticed.
My wife and daughter are right here at home, I use Skype, Whatsapp or Slack to talk to my friends and colleagues.
So there is nothing that's missing.
Social networks are brainwashing farms (yes, advertising is a form of brainwashing) so stay away from them.
I don't want to sound too negative, but we all sense it: tough times are coming and these accounts will become a liability, even if you have 'nothing to hide'.
That looks like a major chilling effect[1], and it makes life that much easier for those instigating the toughness.
It's not obvious to me, therefore, that opting out now is the right choice.
Social media is not the best nor the only place to share your opinions, political or not.
In fact this is the exact danger that these networks pose - people start thinking that it's the only place where we can express our right to free speech.
But this is not what social networks were designed for. They were designed to distribute advertising; all the rest of the features are just clever ways to disguise the real purpose of the SN. Even people who work at these companies are delusional about their company's real purpose.
The place to express our right to free speech is 'the Internet'.
Distributed, resilient, no central control.
Plenty of space for anyone to shout as loud as they like and 'share' it with their friends, without selling their soul.
As an employer if I read something that genuinely offended me (I have no idea if that's even possible) I wouldn't hire them. I hire people I think are going to make the team better and that I think we would want to work with.
So, yeah, if that hot take you wrote on the internet was a tad incendiary, why is it bad that people passed on you?
I'd like to think that I'm evolved enough that I could disagree with someone's opinion and work just fine with them- but if what they said struck a chord, I can't say that I wouldn't pass on them.
At the end of the day your freedom keeps you out of jail and my freedom gives me the ability to say no thanks. What you say in the public square isn't consequence free.
What I had originally written on my personal web site was standard, old-fashioned Christian teaching about homosexuality, based on the Bible. Hate the sin; love the sinner. That sort of thing. (No, it wasn't incendiary calls to violence against people.)
If I'm not allowed to say what I want to say, by being fired by my employer and blackballed from further employment, or by being downvoted to oblivion or filtered or shadowbanned by Ycombinator or Facebook or Reddit, or having my account cancelled at the web host provider I use, what good are my Constitutional rights of freedom of speech and religion? You may find this situation wonderful because you hate what I have to say, but I think everyone should find the trend alarming.
Maybe you really are arguing that freedom of speech and religion only grants someone the right to not being jailed when all they have left is to stand, homeless, on the street corner with a sign, shouting at passerby -- and then they'll be jailed for not having a permit, or something -- but I would have thought that the Constitution meant the First Amendment for more protection than that.
And, furthermore, if it's only Christians that are being affected by these discriminations, then hasn't the government declared a side? All this talk on the left about how the US government is prejudiced against anything other than Christianity, and, yet, I have no doubt that my company would LOVE foreign nationals to preach their religion to people in the work place, when I would be fired for it, if overheard.
I'm saying the consequences are one-sided.
> "If I'm not allowed to say what I want to say, by being fired by my employer and blackballed from further employment, or by being downvoted to oblivion or filtered or shadowbanned by Ycombinator or Facebook or Reddit, or having my account cancelled at the web host provider I use, what good are my Constitutional rights of freedom of speech and religion? You may find this situation wonderful because you hate what I have to say, but I think everyone should find the trend alarming."
If a private employer decides to fire you because of something you said, that's not a violation of your First Amendment rights. Or are you trying to argue that the First Amendment should encompass more than government restrictions on speech? If so that's not clear from what you wrote - it sounds like you believe it already should protect that.
> "Maybe you really are arguing that freedom of speech and religion only grants someone the right to not being jailed when all they have left is to stand, homeless, on the street corner with a sign, shouting at passerby -- and then they'll be jailed for not having a permit, or something -- but I would have thought that the Constitution meant the First Amendment for more protection than that."
No one is argueing that. That's exactly what the First Amendment says (only pertains to government restrictions).
By reason of the First Amendment and the Equal Protection clause, all manner of discrimination has been made illegal. All except discrimination against conservative or Christian speech. I fear for my job if I so much am overheard to speak on these issues in a way that would imply that I think someone else is morally wrong.
"$Company noticed an intrusion by the US Federal Agents, Border Guards, and have marked this as a compromised account. Please have your designated friend, if set, to authenticate your account."
Its now out of the persons sphere to fix, even if coerced. And companies can defend this by fact of an Acceptable Use Agreement violation itself is breaking a federal law: CFAA.
That, and it seems the only way to stop these issues now is to jam it up in legal limbo by citizens.
Frankly, denying everyone at the border is probably a good thing due to the brain-drain it causes. We're not going to get saner laws without some serious economic impairments to punish these 'lawmakers' (really, religious zealots WRT to a very narrow system).
In all honesty, I'm looking at other countries that have saner laws, and less overall problems. I'm looking at the Nordic countries right now, along with Australia... But no country is free from really nasty influences of xenophobia, racism, and hatred.
The only way this is going to change is with a change in the law.
The point of the travel-lock proposal is that it's actually common sense. Everyone should want this feature. It is actually weird that we walk around all the time with unfettered access to decades of personal correspondence and a detailed log of every person we've ever meet even fleetingly online. The default should be different: getting access to years-old emails or a photographic memory of every acquaintance you have should be extraordinary.
Firstly, social media's only incentive is to make your data as widely available as possible (in the interests of ad revenue), and maintain a good relationship with the government in their jurisdiction. Every other existing "privacy" setting on Facebook, LinkedIn, etc is already obfuscated to the point of unusability, for this reason, and "travel mode" would be no different.
Secondly, lets imagine that FB did implement a watertight "travel mode" that hid your embarrassing data effectively while you were travelling. Third parties would just start capturing and storing posts while you have "travel mode" off, and sell that to CBP, or whoever else wants to pay for it.
Does that possibility worry you? Wouldn't that also put you in a position where you’re lying at the border?
edit: readability
https://boingboing.net/2016/11/13/the-surveillance-economy-h...
I fell strange linking to your own warning...
I just think that the use of a such a travel mode could be likened to/misconstrued as the practice (perilous, as you indicate), of using a decoy account, given for example, some previous snapshots of any public/semipublic social media activity suddenly invisible for the border agents.
Just trying to get a clearer view of your proposition (I think I'm doing it, thanks for answering!)
What are they paid to do?
> They can do whatever they want to do, including organize, work to rule, walk out, or go on strike.
Observationally, they don't organize or go on strike. Maybe some "work to rule", get PIP'd and walked out. Maybe some actually walk out on their own.
In the long run, the "People who care deeply about these issues" get boiled off.
In fact, they probably are largely boiled off by now. Probable, because that's consistent with observable Google behavior.
I see no actual reason beyond "be nice to everybody" to assume a random Googler "cares deeply".
Doing something like this requires that you consider the risks of your phone seizure versus the risks you may face without your primary smart phone. If your an activist flying from London to D.C then fine. But what about if your an activist flying from D.C to the D.R.C and back - then your threat model changes from potential TSA problems to physical security threats.
For just one example of this, let's say you ask people to ditch their phones and take a burner because of a potential risk at the US border. Now you have removed one of the best devices for the person's physical security - a smartphone that can update people about security alerts, about local news, weather, disease risk, riots (e.g the stuff we put in the Umbrella App dashboard - shameless plug -> https://www.secfirst.org), share data amongst groups of people on the ground, can send GPS alerts in a emergency, can help them navigate if there is a problem, has a flashlight on it in darkness, has access to emergency contact details, insurance information, medical data, nearest hospitals etc. Now, your relatively low likelihood/low impact potential digital security risk at a US border has overridden the low/medium likelihood but high impact physical security risks...
Ditto it's important to thing about basic tactical things like that people are lazy, data is expensive and they will often not bother to restore the most important contacts and information that they may need when they travel, which can be a problem in an emergency...
Again, it's great to see people engaging on security issues but please be aware of the threat model, context and consequences of what you are trading off.
I'm confused about why you're implying a burner/temp travel phone can't do these things. You can get a cheap & fully capable android phone at best buy for $40
The other form of this which would make sense: worksafe mode or public mode. If you're logging into your facebook/twitter account from a public computer, perhaps it doesn't have as full and unlimited access, and doesn't have access to non-reversible account actions, and strongly logs out. If you're logging in from a place defined as "work", it doesn't have notifications, certain groups, etc. (the "giving a meeting presentation on your laptop when a racy notification from spouse pops up" problem).
Not that it'd do much. If the border agents really want to see one's social media accounts, I have zero doubt they can get that data from other government agencies. In fact, they probably already have it. It sounds to me like they're just trying to assert their power and dominance over the people whose accounts they are demanding access to as a way to get off on intimidating others. Pretty typical behavior by law enforcement officers the world over.
If we stipulate that your second paragraph is true, then travel mode is in fact a complete countermeasure to that behavior. (I don't think it's true).
In contrast, suspending 4th amendment at border has been made lawful by the courts.
* who is normally allowed to see what is posted in the first place.
Surely, if this became popular, CBP would simply start asking aliens seeking entry whether their accounts were travel locked. And the standard advice would be, "never lie to CBP".
But I'm still curious about why you think this would be so obvious.
If the only goal is to refuse them access to your account, you can do that already. Your devices will be confiscated, non-citizens will be refused entry, but you can do it if your device encryption is strong enough.
The goal here seems to be to give you the ability to get through the border without giving up your information. If it looks like "trip mode", it's failed at that goal, and I'm not sure it's possible to make it both mainstream and stealthy enough to work.
In fact, this is already happening: http://www.dailyxtra.com/canada/news-and-ideas/news/us-custo...
> “They said, ‘Next time you come through, don’t have a cleared phone,’ and that was it. I wasn’t let through.
Technological countermeasures don't seem to work. Sure, they work in the sense that they protect your data, but if the border guy doesn't like you, technology won't save you. You will be sent on your way.
Warrantless search of gadgets / accounts should be prohibited for citizens. For non-citizens, it should require a significant justification.
Finally, NONE of the data examined at the border should be stored for longer than necessary to reach a go/no-go determination.
Some people have suggested making travel mode invisible, but it might be better if it showed the start and end dates. Customs will ask anyway, but if the time period covers the entire trip, there's less reason to search the account.
But in the case of citizens and permanent residents both have no cause for this kind of verification. They're allowed to enter for any purpose. So at the very least citizens and permanent residents should not be searched.
[1] I'm not defending the practice or saying this is how it's actually being used, but it is the only actual reasonable justification CBP have for the practice of searching phones.
The real solution is a political one where we speak up and legeislate and litigate that the 4th amendment applies a the border.
> To work effectively, a trip mode feature would need to be easy to turn on, configurable (so you can choose how long you want the protection turned on for) and irrevocable for an amount of time chosen by the user once it’s set. There’s no sense in having a ‘trip mode’ if the person demanding your password can simply switch it off, or coerce you into switching it off.
Most people have return tickets. So (and don't think for a second I'm in favor of this) they'd know exactly how long your detention would need to be.
My parents and my partner are in the US. They have lived there for 27 years, but I am not a US citizen. Are you telling me that I should just give up on my family?
The choice faced by travellers to the US is essentially the same as that faced by all consumers of a product declining in quality: Voice, or Exit.
But that's not because people don't want to protect their social media accounts. You could probably make decent money with a "travel lock" product that groomed your accounts this way, in fact. The reason nobody does it is that the big cloud services don't offer this as a built-in feature.
So this is a case, it seems to me, where helping citizens will have a knock-on effect of also helping non-resident aliens.
Which is, I think, the same problem Maciel's solution faces. Border patrol can possibly just see that you've enabled "trip mode" (by the anemic presence) and put you back on a plane. You're welcome to try again after your trip mode expires, but if they want to see your account, there is, as sure as mathematical logic, no possible "out". Anything you do to deny them that access can be grounds to refuse you entry (if you're a non-citizen).
You're right that the only real solution is a political one. Unfortunately, there are no political solutions to any problem anymore. Not in the US at least. The days when government was even interested in solving problems are gone and I doubt they're ever coming back.
No, that's not how it works. Border agents are entitled to "search" your laptop. They can't force you to retrieve arbitrary data from a remote server.
All this with the caveat that they can, of course, refuse non-citizens for basically any reason.
The thing I think I see a lot of people missing here is that travel-lock doesn't wipe or disable your accounts; it just restricts history and breadth. For a lot of people, I think these services will get easier and more pleasant to use while travel-locked, so it's relatively painless to give yourself a generous margin before departing and after arriving.
And I want that when I'm traveling anywhere.
[later] we want to normalize the idea that access permission to our data is context aware based on what we are doing. To me this is true independent of border crossings. For instance there are things I want in the cloud for backup purposes that I don't want be able to access from anywhere but home normally.
I have no idea what most of my passwords are. They're complex strings of ASCII stored in an encrypted file on my personal machine and a few backups. If I travel internationally, I can just leave my personal machine at home.
Considering the tiny percentage of Americans that travel overseas or even hold passports, I'm not sure a political solution is realistic. I think we might be outnumbered by the people who don't care about such privacy issues because it will never affect them.
The Android backup feature that comes with the phone backs up contacts and photos, but it's very incomplete. Settings, saved logins, and other stuff gets lost. You have to reinstall swype every time. It's too inconvenient to use the way I've described. Other phone cloning apps exist, but a cursory google search only finds ones that require two phones, rather than a phone and a PC.
However, it doesn't solve your real problem, which is that you can be compelled to log into your social media accounts in the presence of the border control officers. You can do that from the browser on a wiped phone, or on their equipment.
Google and/or Apple could add this as a new menu toggle similar to Airplane mode. Once switched on, while in an airport, prevents the device from being unlocked. Then by utilizing geofencing, once the device leaves the airport it unlocks and can be used again.
> Tell me your password > OK, not sit here while I go out to unlock your phone.
But I guess there could be an option to extend the range of the original airport geofence.
(I suspect there's companies already trying to sell them that technology...)
Basically, you can turn over the phone to border guards in a way which gives them access to what is on the phone, but which logs actions, and allows you to easily revert/revoke any changes they make. (This would also be a mode you'd turn over to an employer demanding access).
Potentially this mode might also block access to certain things (secret FB groups, archives over a certain age, some chat logs), but would otherwise be fully functional.
The benefit would mainly be that all actions taken would be logged and reportable, as a way to try to keep authorities from poking in places they shouldn't. It seems they are NOT mostly using forensic imaging tools, but logging in directly on the devices, at least right now, so there would be some value.
The first mistake is trusting these networks with your personal life in the first place. Nothing can erase that except your ability and willpower to keep your secrets to yourself.
As for your second point, there's no going back for an awful lot of people. And holding that aside, it's a sad world where using a computer to communicate is somehow a mistake.
Don't cede the thing you're fighting for.
Do you really think that wouldn't dissolve in the face of "we already have the information, we're just improving communication between government organizations"? They shouldn't collect the information in the first place.
I _still_ want to be able to defend myself and the people in my social graph against a bored/curious/vindictive/power-tripping CBP agent looking for excuses to meet their "must reject at least $N bearded border crossers per shift" quotas...
Sure. I'm pretty sure I want to activate such a feature for my email on my phone just in general.
Why?
- We first had PIN numbers. Easyily cracked/defeated.
- We then had passwords. Provide them or go back home where you came from.
- We might have travel mode. Defeated or made illegal. Go back home.
I think the only resolution to this is political. Make these searches go away - worldwide - as we near a very bad precedent.
The point is not that this is a perfect solution. It's a better solution than the status quo.
In fact, this situation might even be worse for those passing through the Canadian border. Please see: http://www.canada-usblog.com/2017/02/03/what-canadians-shoul...
& the linked: http://www.lexsage.com/documents/Border%20Searches%20of%20El...
What, exactly, has been gained from the days of just posting on anonymous message boards and using email?
Nothing but giving unimaginable power to creepy guys like Zuckerberg and the ability for governments and employers to track your entire life. I'll pass.
My private email account can't be proven to exist, or submit to NSA requests either.
Sure, you can open Facebook and stare at a loading icon until you give up. You can go to a profile page and see images that are failing to load. At some point you're going to stop wasting everyone's time.
The reason this is better than just a "trip mode" is that it's so banally realistic. Of note: because of the weirdness of connecting to cell networks after having moved thousands of miles in airplane mode, most phones I've owned already do this to some extent.
Any countermeasure on the device will just result in you being asked to log in on a CBP laptop.
Edit: Actually, a sufficiently robust Suck Mode would make 2FA impossible. And I think all you have to do to get there is configure your cell network settings wrong, set Boingo Wireless as the top Wi-Fi SSID to connect to, and not pay for Boingo.
Of course, there's a question of the risk to that device, which somehow has to cross the border separate from you, which creates its own ream of problems (you could protect the access to that device with 2FA that uses the device you do keep with you, which mitigates the security risk of loss, but you still risk losing access to the services it protects if it is lost in transit; obviously, you want to make sure your 2FA has a recovery process and one that isn't usable from arbitrary locations or the device you carry across the border, but will be usable by you when you get home, at least.)
There are many good ideas here and I'll even wager that a 'trip mode' of some sort could even produce benefits outside of the held-at-the-border use case. It really does seem silly at retrospect that these tech giants have decided the default needed to be "expose all of the connections"
However, foreigners would likely be turned back. Because using travel mode is arguably evidence of hiding stuff. And citizens might still be detained. It seems unlikely that they'd send agents to homes, to turn off travel mode. But it's arguably not impossible.
I don't want to take my digital possessions through customs if they can request access or deny me.
I don't want a burner that is subpar and I can't afford another phone with great camera etc.
So, I can see two options:
A virtualbox/dualboot where you run two OSes of your devices with full encryption - and one is a dumb/fake install with no personal data that you enable when traveling. It doesn't login to your mail or your facebook and doesn't have your real contacts, photos, passwords on it. You can do this trivially (still for the technically savvy) for a laptop, probably for an android it is not too hard with a custom bootloader. If you were more paranoid, you could create 'dumb' social media accounts, but that starts being time consuming.
Second option is you make an encrypted snapshot of your system before travel. Then you reset / wipe your system before traveling, and then reload the snapshot once you are through customs. This could be done more securely by not actually taking the snapshot on physical media across borders, but storing on a server and downloading once you are through customs. The downside of this is you need data access during travel.
As an aside, I am curious how they would react to someone like me who has no social media accounts. Do I need a fake one to make me look 'real'?
Do they automatically suspect someone who denies using it and what would follow in that event?
Technology cannot solve the problem we currently face with erosion of privacy at the border! These clever tricks trying to get around the issue only kicks the problem downfield, and likely won't effectively work. If they found out you have travel mode enabled - you may be denied entry or worse (note the comment from @mholt) - they would just detain you until the time lock runs out.
Sadly this policy is being picked up in many other countries :(
As a non-american looks like I'm fucked if I want to fly into my own country with my own electronics.
> To work effectively, a trip mode feature would need to be... irrevocable for an amount of time chosen by the user once it’s set. There’s no sense in having a ‘trip mode’ if the person demanding your password can simply switch it off, or coerce you into switching it off.
Imagine I am a CBP agent. State your argument that I must release you after, say, 23 hours
What if you have a long password that you cannot remember? Same for email, etc.
I don't have fb on my phone. And I don't remember the password. They would have to make me do a password reset via email, which might work.
Same for hosted email.
The software with a human-usable UI (automated backups, viewable in a useful client) for all this doesn't yet exist, but it could.
The Women's March was organized mostly on Facebook. Why does that list of people have to be stored in perpetuity?
So, in context, this is about stopping one branch of government - CBP - from being able to compile data that another branch of government already has.
I love the idea but worry it might be a form of security theater, given the three lettered elephant in the room.
Phones could use GPS to detect when their in/near airports and inject an X-Travel-Mode cookie into HTTP requests.
Border security officer: I see you have trip mode on. Turn it off, and give us the phone, or you're not getting into the country.
Reminds me a little of this: https://xkcd.com/538/