Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To be effective, this would need to become a kind of norm for overseas travelers, the same way traveler's checks used to be. The idea would be that just as you don't carry a bag with your birth certificate, stock certificates, property titles, and jewelry with you, you also don't carry a 10 year archive of every email you've ever sent or a detailed list of every person you've ever spoken to.

In particular, it needs to be normal enough that a significant fraction of all travelers do it. The feature can't be marketed as a protection for at-risk travelers, but as a common-sense safety mechanism useful to all travelers.

I think it's crazy that people walk around with phones that have access to years of email communications, and that even in the happiest timeline we could have ended up on after 2016, features like this are long overdue.



>>In particular, it needs to be normal enough that a significant fraction of all travelers do it.

Yes, exactly.

Border agents are trained to look for anything out of the ordinary. Currently, using a feature like this would immediately raise a huge red flag and encourage more questioning, detention and possibly even deportation based on the person's country of origin and the mood of the border agent.

Incidentally, that's why I think there is virtually zero chance for these types of features to take off: the system strongly discourages early adopters from trying them.


Incidentally, that's why I think there is virtually zero chance for these types of features to take off: the system strongly discourages early adopters from trying them.

That can be addressed by how it is marketed. Instead of calling it "Travel mode," it could be called "Work mode" or something like that. Commercials could target college students going home to visit parents and not wanting parents to see all their crap or that sort of thing.


Why wouldn't it be marketed as a feature for leaving the country, not returning? There's a very reasonable case to be made that other countries have substantially worse privacy protections than the US does. Whether or not that's true is a separate conversation, but for the purposes of the border conversation about why you've enabled it, blaming the lack of Constitutional protection in foreign countries seems like a good approach to me.


Right, the idea is that US travelers would kick-start the norm by travel-locking their accounts; they're at little risk while traveling. It might take many months or even years before travel locks were normed enough that at-risk travelers could rely on them, but that just means we should get started on these features sooner than later.


Couldn't US CBP defeat that norm for non-citizens, just by announcing "don't enable travel lock until after you clear customs, or you may not be allowed in" in the same way that they eg. tell you not to bring your codeine with you?

Citizens are probably OK, at least until they bring in Exit Visas...


Plenty of non citizens are permanent (or just longterm) residents of the US who were leaving the country temporarily.


Thankfully, as US citizens we are free to establish a norm of using features like this, with no fear of deportation.


If you are willing to do this, then why not just say "no" to the CBP and DHS? You must be allowed in if you are a citizen so the only risk is them keeping your phone for a few weeks while they try to hack it to get inside. I believe they are required to send it back to you once they are done by law or agency policy.

That's what I plan to do if I ever get asked - telling them to piss off. Worst they can do is confiscate my phone. I am choosing to remain silent. If they still persist on hassling me and end up taking my phone even temporarily, I will treat that device as now being compromised and will take the appropriate action.

Last year I was hassled (not at the border) on two occasions. Once in NYC in the Port Authority by the cops that patrol that facility and a second time in the suburbs of NJ. In NYC the cop didn't like that I was getting testy with a Port Authority employee for not letting me though to get to my bus. He intervened without cause and asked for my ID. I told him "nope". He tried making up some story to justify him asking me and I told him "I'm not giving you my ID. I'm leaving, bye." and then walked away.

In NJ I was detained for way too long under suspicion of several random things. This wasn't even a traffic stop. I parked the car and then they drove over and harassed me for a solid 45 minutes. First they claimed I was drunk. Then they said I was on this particular street to buy drugs. Then they said I could actually be dealing the drugs. They frisked me for "officer safety" and then tried to get me to walk the line and do a bunch of sobriety tests. I told them I wasn't doing any sobriety tests. They lied and said I could be arrested for mere refusal. I told them they were full of shit and that I can only be arrested for refusing the actual breathalyzer, not the voluntary tests. I then remained silent for rest of the encounter. Not a peep, just dirty looks back and forth. Eventually they had to let me go. Moral of the story is that cops do back down plenty of times but you have to have the will to test them. And it greatly helps if you know the law.

One last thing - if you are wondering why I didn't just take the sobriety tests if I'm sober, there's a damn good reason. Some years ago, my friend got arrested in that same town for blowing a 0.00. How you ask? Because first he did the voluntary tests which no one in the history of mankind has ever passed - at least not according to any police officer. Those tests are always used to compel something else like a search, breathalyzer, etc. It's an excuse to justify further harassment in many cases. So my friend did their tests and "failed". So they compel the breathalzyer and he gets a 0.00. He thinks he'll finally be free to go when they tell him that based on his failure on the voluntary tests he is clearly under the influence of something. And since it isn't alcohol, it must be drugs. So they arrest him, take him down to the station and draw blood. They charge him with intoxication and illegal drug use (because he said he doesn't take any medications for anything) before the blood results come back because those take 2 weeks or so. Even though they come back totally clean he has still been charged and is required to show up in court anyway. He had to spent $500 or so on a lawyer to represent him that day and get that bullshit dismissed. I am not sure if he got the arrest wiped from his record - I don't think he did. Which means he now has a record for no reason at all. Please take this story into consideration the next time you interact with law enforcement. I no longer cooperate with law enforcement for anything other than a minor traffic stop, maybe not even then. If a stop were to start going somewhere else (i.e. they are fishing for stuff or trying to screw me just because they feel like it) my attitude and strategy for dealing with them does a complete 180. The only reason I may comply for minor things is simply because it's the quickest way to be back on my way. 99% of the time their minds are already made up. Nothing you say will get you out of a ticket in most cases, so there's no reason to cooperate anyway. Playing nice is just for expediency, but as soon as that turns into something else, you need to switch gears immediately.

Sorry for the long post. My interactions with police last year are a sore spot for me (there were other interactions I left out).


Because you already know you will "win" the game of chicken between a citizen and CBP, but that win does nothing for non-citizens, for whom CBP has potent recourse.


> . Not a peep, just dirty looks back and forth. Eventually they had to let me go. Moral of the story is that cops do back down plenty of times but you have to have the will to test them. And it greatly helps if you know the law.

It also helps if you aren't a person of color.


> I think it's crazy that people walk around with phones that have access to years of email communications

The one anti-pattern on every website is using your primary email address for both notifications and password resets. There is zero reason why you'd ever want an email address you have authed on your phone to handle Facebook/Twitter password resets, but the only way to avoid this is if you're willing to give up receiving whatever notifications you'd normally want to receive via email on your phone.


> There is zero reason why you'd ever want an email address you have authed on your phone to handle Facebook/Twitter password resets

There's a really obvious reason: because you need to reset your password while on the go.


You can set a filter to only forward certain notifications.


Good point, but it doesn't need to be anywhere near a majority. If just 1% is travelers use it, it would not trigger more than a few extra questions. Especially if those 1% are mostly computer professionals where deeper questioning hardly ever turns up anything.

One feature I'd like with this travel mode is having a log of every bit of data that was accessed during the trip. At least then I would know how much was copied. Some kind of rate limiting would be good too, so they cannot just copy everything.


> I think it's crazy that people walk around with phones that have access to years of email communications

You think its crazy in you wish you (and everyone else) had a viable alternative? Or, you think its crazy in that you do something else that others don't do?

If the latter, what do you do?


I have tar files of old maildirs, but they're encrypted and backed up and not readily accessible. My regular mail client has access to a smaller set of mails. Of course this requires an email setup that allows such easy bulk operations, which gmail isn't really.


I have the same setup with gmail. It really wasn't that hard to export a chunk by date, upload it to tarsnap, and delete the originals


It seems like there is an inherent trade-off here between the usefulness and vulnerability of our systems.

Each feature we add for our own convenience makes a more tempting prize for a potential adversary.

Edit: Whether or not a particular feature/behaviour is reasonable or crazy depends entirely on the level of threat.


> I think it's crazy that people walk around with phones that have access to years of email communications

Why? I thought the whole point of connected, portable computers is for one to have access to pretty much all their data on the go.


Yes, for one.

Much of the point of the cloud shift was to get your data into the ownership of a private company who can make money off it.

If, for example, Apple can make up some lost money on iCloud with new obsidian gunmetal TimeCapsules with plausible deniability and localhost-tunneling features to sell to rich people, I'm sure they will try and do it.


>even in the happiest timeline we could have ended up on after 2016

I'm not really sure why you mentioned this, did something bad happen?


Lots of people seem to be bemoaning 2016 as The Worst Year Evarrr or something.

I am not in that camp and I have my objections to it. But, in this case, I think the sentiment is reasonable wrt the topic at hand, basically.


Yes, an incompetent autoocrat got elected to the highest government office of the most powerful nation on earth. You almost certainly already knew this.


That happens every 4 years.


Prince died.


RIP Phife


Read this as "even if <your favorite political candidate> had won the US election"


It can be effective immediately.

Where do we have all this AI for?

+ Facebook can make a filter that only displays a tiny subset of all posts. A filter that only displays a tiny subset of my friends.

+ Gmail can make a filter that shows only a subset of my emails.

+ Preferably the AI can then fill it up with stuff. :-)

In this way it all looks perfectly fine. There is only way less info in it.

This would save me time from making accounts for traveling purposes.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: