10 ms·
Passwords for social media accounts could be required for some to enter country
- salesguy222 10y agoi hope everyone can look at this and see the conclusive proof: many people in government from all sides abuse technology to control the lives of people in new, shocking, and totalitarian ways to say "i'm not muslim, or Iranian, or Mexican, or a dissident", or etc, will soon no longer suffice. Every conceivable activity and word you speak or think will eventually be evaluated if the technology is cheap enough and politicians are daring enough The constitution doesn't even stop people from doing things like this anymore, so I don't know how to fix this
- anigbrowl 10y agoThe Constitution is on it's way to becoming a dead letter. There's nothing wrong with rebooting the Republic, many countries go through such disruptions. I'm not saying just do it, but if the existing political consensus collapses we won't benefit from trying to back to how things used to be.
- andai 10y agoI was just thinking today about Thomas Jefferson's idea that the constitution be rewritten every 19 years (every generation). I arrived at that thought while thinking about how Dropbox Paper is more modern than Google Docs (which turns 12 this year). Sometimes it's better to start over from scratch. It lets you do things you actually couldn't do with lots of small changes.
- user982 10y agoOne of the very first changes of any new version of the Constitution arising from any major quarter would be the deletion of the First Amendment, with the Fourth following closely. I have no faith that a document reflecting contemporary American generational consensus, as Jefferson aspired to, would be better or more free.
- anigbrowl 10y agoCould =/= would. If you're arguing for the status quo because every alternative you can imagine is worse then you're essentially treating it as religious dogma.
- zouhair 10y agoWe are living all secret police's wet dream.
- salesguy222 10y agoThough I wish it were different, I can't help but feel that this truly is game over. The statists have won. The technology is too powerful, they're too easily able to afford it, and the public can't do much to stop it
- dahart 10y agoIt's sad to see such defeat. The tech is not too powerful, the public just has to care about privacy, that's all. We have the technology to prevent mass surveillance. We can stop it, as soon as we the people want to.
- salesguy222 10y agoI wish this were true. When you use technology to prevent mass survaillance, they criminalize its usage. Anyone can be thrown in jail at any time for relatively petty reasons, and you can be physically surveilled by detectives on mere suspicion. It isn't pretty, but it's the truth. Sure most of us will be fine with basic precautions but 20 years from now is a different story? I prefer not to think about it
- dahart 10y agoIt is true; we have tunneling, VPNs, ssh, Tor, FreeNet, I2P. None of these things have been criminalized, so what are you thinking about when you say "its" usage has been criminalized? Do you have some examples of when privacy tech has been criminalized in the past? I might be naive, it probably has happened, but I don't personally know of any privacy or security software or hardware that is illegal to use in the US. People being physically surveilled doesn't land in the same camp as mass digital surveillance. It requires a warrant, even if they can be obtained for petty reasons. The government doesn't have the bandwidth for physical surveillance of everyone. It just isn't the same thing. 20 years from now is a long way off, long enough for us to make it better. If you give up and don't think about it, people who care and work for what they want will probably get what they want. Money and government power certainly do want to watch what you're doing, if they can get away with it. But if the public, on the whole, really truly started to care about privacy, enough to vote on the issue and enough to make purchasing decisions based on privacy concerns, it would get better. The only reason it's bleak right now is the majority of the world is still giddy about joining Facebook, rather than concerned about the implications of digital public over-sharing. Give it time and get your friends & family to care, and it's more likely to improve than not. If we all look the other way, then we get what we get...
- tn13 10y agoOne of the simple ways to fix this is to by simply starving the beast. Constantly demanding lower taxes. In fact a constitutional amendment to limit US government's spending to may be 15% of GDP. Once US government is faced with either wage a war in country X under the pretense of WMD or Zombie virus or spend on public education I think we will see some sanity. But the war mongering right and welfare mongering on left will not let that pass.
- stuckagain 10y agoI don't fall for your both-sides-do-it framing. Fact is that the other side had power and didn't do it. Now we have insane cheetoh in office and we're getting insane cheetoh policy ideas. This is not a matter of equivalence.
- okreallywtf 10y agoAgreed, I came up with analogy that I intend to use whenever false equivalencies are used to try to scuttle an argument: there is a massive difference between going 65 (mph) in a 60 and 110 in a 60. While both are illegal, you can not use one to justify the other. We can have high standards and expect them to be met but if we cannot tell the difference in scale between two actions we are doomed.
- Inconel 10y agoI'm not really sure I agree with that analogy. My primary problem with it stems from the fact that current policies don't exist independently of previous policies. I agree that on a scale of badness, Trump certainly seems worse to me than Obama. But in your analogy it isn't so much that Trump took a car from zero to 110 in a 60 zone. The car he got in was already speeding thanks to the policies of the Obama administration, and prior administrations. I don't think pointing this out is necessarily excusing it through false equivalence. So while I agree that it's important to tell the difference in scale, I think it's equally important to realize that in most cases these policies don't come about out of thin air, they are built and extended from prior policies.
- okreallywtf 10y agoGranted, its a very simple analogy but it needs to be simple because it can be used to counter an equal simple false equivalency in conversation. My honest opinion is that we've unfortunately divided ourselves down the middle and we've picked causes and policies like we were picking players in dodgeball and you can only be on one team. I think it so happens either by chance or by some kind of underlying tendency that one side tends to be more correct or at least more progressive (which tends to be more correct in the long run) than the other. I know plenty of people who correctly (I think and I think the data supports) acknowledge climate change is real and largely man-made but could no more discuss the actual causes or ramification than your average climate denier. I want to be able to have honest, nuanced conversations with people but they typically end defensively and quickly (which is often the result of someone I agree with who can't help but be snarky and counterproductive) and I want to find quick and effective counters to some of these argument killers.
- nodesocket 10y agoI am failing to see how providing your Facebook password provides any legitimate confirmation about you and your associations. You can easily create a fake Facebook profile with your picture, fake posts, fake friends, fake everything. The internet is a cesspool of people who troll, create fake profiles, invoke reactions, behave completely different than they would on the streets, and intentionally hide their identity. Using it as a primary source of identity verification is a terrible idea. Why not require proof of a financial statement? Bank account in your name, or a process to verify somebody via their bank account without requiring their bank account password.
- pier25 10y agoIt's just as ridiculous as those forms you are asked to fill when entering the US as a foreigner. For example: > Do you seek to engage in terrorist activities while in the United States?
- jackweirdy 10y agoAnother example of an absurd question like that was one I was asked when I was applying for my visa; along the lines of "are you planning to commit espionage for another country against the United States". I assume they do it so they can pin you for perjury as well was whatever crime you committed should you turn out to be a spy. But it's just so absurd when asked deadpan like that.
- couchand 10y agoSure that question is dumb, but it's not at all comparable to forcing you to turn over a password. Why would you make that false equivalence?
- pier25 10y agoBecause you can as easily create a fake social media profile
- greglindahl 10y agoThey're just getting you to incriminate yourself. The standard of proof for excluding someone for lying on the forms is quite different from convicting them of an actual terrorism-related crime.
- ylecuyer 10y agoWhat happens if I have 2FA enables?
- differentView 10y agoFirst, you and your devices will be held for hours while they go through your accounts and devices. Then they'll require you to disable 2FA.
- MichaelGG 10y agoYeah the best approach, the one I use when crossing, is to encrypt everything, then send part of the password to someone else who won't give it to me until later. They can steal your hardware, I guess.
- guitarbill 10y agoAnd then you'll just be denied entry for "not cooperating". There is no technical solution to this political problem. (It also happens to be an ineffective measure, as false identities are easily crafted on the internet.)
- greglindahl 10y agoThat probably only works if you're entering a country that you're a citizen of, and not otherwise. BTW, legally speaking by US law, it's a lot easier to force someone to give up their thumbprint than a password. So whatever you do, don't go through an American border with touch-id unlocking your phone.
- deleted 10y ago[deleted]
- privong 10y agoThis has been discussed several times in the past few days: https://news.ycombinator.com/item?id=13600704 https://news.ycombinator.com/item?id=13600704 https://news.ycombinator.com/item?id=13598505 https://news.ycombinator.com/item?id=13598505
- hefeweizen 10y agoIn addition to other points against this measure, there are massive privacy implications. Loads of people could be reusing passwords or may reuse keywords for multiple passwords. A collection of such data by an organization can and will be misused.
- Tharre 10y agoWhat if I don't have any social media accounts? Do the officials just assume I'm lying and deny me entry? This is insanity.
- x1798DE 10y agoAlternatively, what if you do have such accounts and don't know the passwords? I keep all my passwords in a password manager, and if I'm crossing a border, I'm probably going to make sure I can't access it until after I'm across. I'll guessing the right thing to do, if you know about this requirement, is to set up a Facebook account specifically for this purpose, then right before you cross a border, change its password to something easy to remember.
- roywiggins 10y agoThey'll make you sign something that asserts you don't have any other social media accounts, and now you've lied to a federal agent, oops.
- x0x0 10y agoYou know what's better? Other countries will follow our lead and demand the same. Particularly of American visitors. And why should they not?
- adventured 10y agoYou act like that's some kind of revelation. Countries such as France, Britain, Germany, Sweden, the Netherlands, Australia, India, Russia and China are already on par with or beyond the US when it comes to abusive domestic espionage.
- hellofunk 10y agoYou can't make a statement like that without backing it up. The evidence to the contrary is in greater favor until you provide support.
- 10y ago
- oskarth 10y agoConsidering how the NSA probably has access to this already, what does this mean? A few options off the top of my head. Not putting any probabilities on these, but it's interesting to think about. The options are neither exhaustive nor exclusive. (a) NSA info is drying up due to resistance from companies (b) NSA info can't be shared due to low-priority targets (c) NSA info can be shared but there's something going on between NSA and DHS that makes this difficult (d) NSA info can be shared, but only to people of a certain clearance, which makes this non-scalable for ports of entry (e) NSA info can be shared but the goal of the policy isn't info, it's signaling
- salesguy222 10y agoI would say everything except option (a). additionally, it's possible that data streams are drying up into the NSA (i dont think they are), but the NSA already has enough to incriminate literally every human on earth for any petty thoughtcrime most likely, I say, is that the data in NSA Utah is basically like a walled off test dev that only a few special people can query for currently important things. their main job is to determine how best to query it in the future and then each agency maintains a prod database of its own data its collected to oppress everyone. very rarely would they ever get NSA data
- Cyph0n 10y ago> but the NSA already has enough to incriminate literally every human on earth for any petty thoughtcrime I think that you are slightly overestimating how much the NSA can achieve with current technologies.
- salesguy222 10y agoInteresting. How many people, would you say, have a textual conversation over email or FB or a forum, etc, that had ended up in an NSA dragnet? Then, of those conversations (presumably several billion), how many are stored with some identifiable metadata, like IP address, GPS tag, real name, photo? Even if it is only a few million people, it's still way too much of an overreach, and still ridiculously cheap to store on tape and analyze on disk/ssd. then you just pay someone who cant find any better work to type queries into a system. How many times have you talked about potential crimes with your friends? how many times have they talked about using drugs, fake IDs, speeding, petty theft, etc how many times has "child porn" inadvertantly made it into your browsers temporary files. Almost everything is a crime, and the government's ability to cheaply prosecute is only growing
- simplemath 10y agoThis is as good a time as any to stop using social media.
- ben0x539 10y agoI hope other countries introduce that requirement for US-based travelers too, that'd probably be the quickest way to get the US to knock it off.
- adventured 10y agoMost other countries have been thrilled to abuse their own people when it comes to espionage. So no, they'll jump right on board, gladly. Not primarily to punish the US, but because it's a perfect excuse to expand their existing spying programs.
- deleted 10y ago[deleted]
- natch 10y agoIf they get a person's password, the largest privacy violation is not to that person. It's to all that person's friends and family who shared private material. We can discuss all we want whether it was wise for anyone to share, say, everyday normal photos of their children or themselves on Facebook. If you think they shouldn't have shared normal, everyday, family photos on an online service, sure, fine, I don't know what to say. But let's say they did do so, which is pretty normal. Are they entitled to some privacy from whatever pervs the DHS hires? Remember "they" is the friends and family of the person visiting the US, not the person themselves. Many of these friends and family will be US citizens, so arguments about differing rights for non-citizens, whether valid or invalid with respect to privacy rights, don't necessarily apply in those cases.
- tn13 10y agoUS citizens must thank the founding fathers for all the amendments else the feds would have treated all of us just like this.These wannabe immigrants have 0 rights or voting power so they are being treated like complete shit. The way US government treats legal immigrants, they might as well ask them to bring a lube and drop pants and bend over at the immigration check. This comment might seem crass but it is nowhere close to the crassness with which US government has come to treat people who are going through all the ridiculous legal hoops and in process making criminals out of perfectly ordinary people. This is like having a super complex CAPTCHA on your signup page for humans while letting bots pass through by some minor cookie manipulation.
- zitterbewegung 10y agoI don't have a Facebook account so will I be let in the country?
- differentView 10y agoDepends how much the border officer likes you.
- matt_wulfeck 10y agoI hope that we can keep this issue "apartisan", because the importance absolutely transcends past or future political affiliation. What has become "reasonable" is slowly but surely come to mean "what we can get away with".
- lechevalierd3on 10y agoWouldn't two factor make this irrelevant?
- jewbacca 10y agoA state actor wouldn't even break a sweat getting around 2FA, individually or at scale, if the 2nd factor involves SMS (or the phone system in general) (which, for 99% percent of the 1% of people using it, it currently does): https://en.wikipedia.org/wiki/Dishfire https://en.wikipedia.org/wiki/Dishfire It's not even out of the question for malicious private actors who don't have total control over the whole system: https://krebsonsecurity.com/2016/09/the-limits-of-sms-for-2-factor-authentication/ https://krebsonsecurity.com/2016/09/the-limits-of-sms-for-2-...
- differentView 10y agoYes, those people will simply be denied entry.
- tptacek 10y agoNo, because if you refuse to help them access your account, they will detain or turn you back.
- deleted 10y ago[deleted]
- thunderrabbit 10y agoDear government, Did you know it's possible for people to have fake social media accounts?
- dbg31415 10y agoLook, as much as we all get up in arms about this... total access to my email, calendar, and contacts were required to play Pokemon Go. I hate it, but until people starting taking privacy seriously, what is an appropriate response? The encroachments are everywhere and so prevalent (and people are so dulled) that nobody bats an eye when "the authority" (or just someone who seems mildly trustworthy) asks for things they shouldn't ask for. If you offer to help a stranger fix something on their laptop, what percentage do you think would just tell you that their password is their kids' middle name -- and how many do you think would use the same password on their Gmail and bank accounts? The fact that so few people take privacy and security seriously is enraging; it's hard to go from enraged to outraged when most people don't even bother protecting themselves. It's all so infuriating.
- romanows 10y agoYikes, was that on an iPhone? I'm not seeing permissions to read email or calendar content on the Android version. It does have permissions to read your contacts.
- dbg31415 10y ago* Pokémon Go shouldn’t have full access to your Gmail, Docs and Google account — but it does | TechCrunch || https://techcrunch.com/2016/07/11/pokemon-go-shouldnt-have-full-access-to-your-gmail-docs-and-google-account-but-it-does/ https://techcrunch.com/2016/07/11/pokemon-go-shouldnt-have-f... Got fixed I think... but how many people cared? Every try and roll out 2FA for an office and get the majority of people -- C-level folks included -- griping and giving pushback that they hate it because now they have to do one more tinsy little thing to sign in? After a while it's just sort of like... "Well... you've been warned you should care more about security, you have been given every opportunity to learn about how technology works, and bottom line I don't really care about your privacy if you don't..." It's so frustrating is all I'm saying.
- curriedbits 10y agoMaybe if they change this to an app that was required for entry, instead of turning over passwords.
- irishcoffee 10y agoIf you put it on the internet, it isn't private. There really isn't a debate to be had about this. I think requiring passwords for social media is fucking stupid. Really, really stupid. People who expects to have "privacy on the internet" are also fucking stupid. Yes, this includes facebook, twitter, instagram, email, et. al. If you wan't to keep a secret, don't tell anyone. If you put something "private" on the internet, you've ostensibly told 3-4 billion people.
- trendia 10y ago> If you put it on the internet, it isn't private. Access to social media accounts includes access to private communications, e.g. messages that were sent with the understanding that only the recipient would receive it. But those nudes your girlfriend sent you are now in the hands of an immigration agent working in the name of "border security".
- irishcoffee 10y agoYeah, and those nudes are also visible on whatever server they're stored on, with whatever rootkit is installed on it, or to whatever bored employee decides to look at them. Or to the jackass who saw you looking at your phone and took a picture, or the asshole who rooted your girlfriends phone, or the neighbor who hopped on your wireless router and guessed your "test12" password. God forbid anyone uses their phone to sign onto a public wifi somewhere, don't even get me started on that. It is very foolish to consider anything, sent across any digital medium "private" in any sense.
- andai 10y agoI reckon you got downvoted not because you're wrong, but because it makes people uncomfortable to consider that.
- nl 10y agoI think the comment was downvoted because it was unnecessarily rude, and the examples were almost all illegal. I don't think anyone argues it is possible to violate privacy by acting illegally.
- pfooti 10y agoI wonder if this includes google accounts (since you know, google plus). I mean, the whole notion is horrific and abysmal, but in today's OAUTH world you're not just giving up the facebook goods, you're giving up co-logins to lots of other sites too. There's other technical issues too - I use 2FA everywhere. So, do I disable the 2FA or have to give that up too? In perpetuity? I mean, I don't trust law enforcement to not go around murdering people, why should they have access to passwords? The very thought or suggestion that this could someday happen would make me cancel any and all trips to the US for the foreseeable future (if I weren't already a US citizen who lived here, that is, and as it is I'm seriously considering emigrating in response to this administration). The brain drain effects will have to be enormous. There's already a company focused on helping startups use Vancouver to base their remote employees. [0] On so many levels this is bad. I'd heard the notion floated under the Obama administration, but I trusted them to be adult and see all the possible ramifications. I do not trust the Trump administration to even be in the neighborhood of rational, let alone adult. I mean, they dumped the immigration executive order with no actual warning whatsoever (besides repeatedly saying he'd do just that, I suppose). So now we have no real choice but to take them at their word. 0: https://techvibes.com/2017/02/01/true-north-establish-vancouver-hub-foreign-workers-trump https://techvibes.com/2017/02/01/true-north-establish-vancou...
- PakG1 10y agoHere's the question I want answered. How does this type of thinking affect the future of Snapchat. The future of Signal is easy to predict. Back door. Snapchat? This type of thinking seems like an existential threat to Snapchat.
- westmeal 10y agoEasy fix: Delete your Facebook and Twitter accounts.
- dahart 10y agoI saw a video interview with the CEO of Hotspot shield vpn the other day, he had a quote ready that went something like 'The first 3 companies to hit 1 billion users did it by selling private information, the next 3 are going to make it by protecting private information.' I wrote it off as a nice sound bite, but maybe he's right... Hey I'm sure I'm not the only one to think of this, but to everyone trying to build the next social network, how about putting in a feature where a second password will open your scrubbed profile? You'd choose what goes in from your main account, and not have to build entirely fake accounts. There's a way to get some quick traction, should the Trump administration succeed at making a policy of asking for passwords!
- mistersquid 10y agoPerhaps I'm not understanding something. Why wouldn't an information-hungry regime simply ask for both passwords given that this would be a known feature?
- dahart 10y agoPlausible deniability.
- averagewall 10y agoThose travelers would be violating their FaceBook ToS: "You will not share your password (or in the case of developers, your secret key), let anyone else access your account, or do anything else that might jeopardize the security of your account." [1] Perhaps this would give FaceBook the power to intervene and, well block their account or something. [1] https://www.facebook.com/terms https://www.facebook.com/terms
- otterley 10y agoAny term in contract that is contradictory to law is null and void. That's been in contract law since forever. The law always trumps contracts.
- DiabloD3 10y agoIANAL, but even though this is true, Facebook could still ban accounts for complying. They are a US company, and their TOS says they can ban an account for any reason or no reason at all. If they chose to ban anyone who shares passwords, even with the US government, even if they are Americans or not, they are within their rights as a US company to do so.
- otterley 10y agoIt's quite likely that any law promulgated to compel the production of passwords or any other authentication information would include language prohibiting a provider from terminating an account for complying with the law.
- jackjeff 10y agoI heard you can have password hundreds of characters long for Facebook... it'd be nice to have some long random gibberish impossible to type or maybe the full text of the 4th amendment to remind these people that what they do is against the constitution. PS. password managers mean you won't suffer the same inconvenience.