227 comments

[ 3.2 ms ] story [ 249 ms ] thread
> We need a ‘trip mode' for social media sites that reduces our contact list and history to a minimal subset of what the site normally offers. Not only would such a feature protect people forced to give their passwords at the border, but it would mitigate the many additional threats to privacy they face when they use their social media accounts away from home.

Border security officer: I see you have trip mode on. Turn it off, and give us the phone, or you're not getting into the country.

Reminds me a little of this: https://xkcd.com/538/

Please read the entire post.
If you're referring to a configurable duration: setting an expiration doesn't work either. They'll just detain you for that length of time.
A week? 2? I don't think technology changes are the right approach here, but you wouldn't be setting travel mode for a duration equal to transit time through an airport.
I understand, but their default response for "You've done something to hide information from us" isn't going to be "Oh well, we tried. On your way!"
Yeah, they will send you back where you came from and you will be fucked for life.
Exactly. They'll just take you to a computer they control and make you login there. Or there'll be a law that requires an override authority.
I'd love to see travel modes take off. I was talking with some friends about how great it would be to be able to switch my login credentials to some sort of shared multiple person-required password for the duration of a flight. Like Shamir's Secret Sharing, but temporarily.
To be effective, this would need to become a kind of norm for overseas travelers, the same way traveler's checks used to be. The idea would be that just as you don't carry a bag with your birth certificate, stock certificates, property titles, and jewelry with you, you also don't carry a 10 year archive of every email you've ever sent or a detailed list of every person you've ever spoken to.

In particular, it needs to be normal enough that a significant fraction of all travelers do it. The feature can't be marketed as a protection for at-risk travelers, but as a common-sense safety mechanism useful to all travelers.

I think it's crazy that people walk around with phones that have access to years of email communications, and that even in the happiest timeline we could have ended up on after 2016, features like this are long overdue.

>>In particular, it needs to be normal enough that a significant fraction of all travelers do it.

Yes, exactly.

Border agents are trained to look for anything out of the ordinary. Currently, using a feature like this would immediately raise a huge red flag and encourage more questioning, detention and possibly even deportation based on the person's country of origin and the mood of the border agent.

Incidentally, that's why I think there is virtually zero chance for these types of features to take off: the system strongly discourages early adopters from trying them.

Right, the idea is that US travelers would kick-start the norm by travel-locking their accounts; they're at little risk while traveling. It might take many months or even years before travel locks were normed enough that at-risk travelers could rely on them, but that just means we should get started on these features sooner than later.
Couldn't US CBP defeat that norm for non-citizens, just by announcing "don't enable travel lock until after you clear customs, or you may not be allowed in" in the same way that they eg. tell you not to bring your codeine with you?

Citizens are probably OK, at least until they bring in Exit Visas...

Plenty of non citizens are permanent (or just longterm) residents of the US who were leaving the country temporarily.
Incidentally, that's why I think there is virtually zero chance for these types of features to take off: the system strongly discourages early adopters from trying them.

That can be addressed by how it is marketed. Instead of calling it "Travel mode," it could be called "Work mode" or something like that. Commercials could target college students going home to visit parents and not wanting parents to see all their crap or that sort of thing.

Thankfully, as US citizens we are free to establish a norm of using features like this, with no fear of deportation.
And as a US citizen, if I want foreign nationals to be deported more easily, I will not help establish the norm.
If you are willing to do this, then why not just say "no" to the CBP and DHS? You must be allowed in if you are a citizen so the only risk is them keeping your phone for a few weeks while they try to hack it to get inside. I believe they are required to send it back to you once they are done by law or agency policy.

That's what I plan to do if I ever get asked - telling them to piss off. Worst they can do is confiscate my phone. I am choosing to remain silent. If they still persist on hassling me and end up taking my phone even temporarily, I will treat that device as now being compromised and will take the appropriate action.

Last year I was hassled (not at the border) on two occasions. Once in NYC in the Port Authority by the cops that patrol that facility and a second time in the suburbs of NJ. In NYC the cop didn't like that I was getting testy with a Port Authority employee for not letting me though to get to my bus. He intervened without cause and asked for my ID. I told him "nope". He tried making up some story to justify him asking me and I told him "I'm not giving you my ID. I'm leaving, bye." and then walked away.

In NJ I was detained for way too long under suspicion of several random things. This wasn't even a traffic stop. I parked the car and then they drove over and harassed me for a solid 45 minutes. First they claimed I was drunk. Then they said I was on this particular street to buy drugs. Then they said I could actually be dealing the drugs. They frisked me for "officer safety" and then tried to get me to walk the line and do a bunch of sobriety tests. I told them I wasn't doing any sobriety tests. They lied and said I could be arrested for mere refusal. I told them they were full of shit and that I can only be arrested for refusing the actual breathalyzer, not the voluntary tests. I then remained silent for rest of the encounter. Not a peep, just dirty looks back and forth. Eventually they had to let me go. Moral of the story is that cops do back down plenty of times but you have to have the will to test them. And it greatly helps if you know the law.

One last thing - if you are wondering why I didn't just take the sobriety tests if I'm sober, there's a damn good reason. Some years ago, my friend got arrested in that same town for blowing a 0.00. How you ask? Because first he did the voluntary tests which no one in the history of mankind has ever passed - at least not according to any police officer. Those tests are always used to compel something else like a search, breathalyzer, etc. It's an excuse to justify further harassment in many cases. So my friend did their tests and "failed". So they compel the breathalzyer and he gets a 0.00. He thinks he'll finally be free to go when they tell him that based on his failure on the voluntary tests he is clearly under the influence of something. And since it isn't alcohol, it must be drugs. So they arrest him, take him down to the station and draw blood. They charge him with intoxication and illegal drug use (because he said he doesn't take any medications for anything) before the blood results come back because those take 2 weeks or so. Even though they come back totally clean he has still been charged and is required to show up in court anyway. He had to spent $500 or so on a lawyer to represent him that day and get that bullshit dismissed. I am not sure if he got the arrest wiped from his record - I don't think he did. Which means he now has a record for no reason at all. Please take this story into consideration the next time you interact with law enforcement. I no longer cooperate with law enforcement for anything other than a minor traffic stop, maybe not even then. If a stop were to start going somewhere else (i.e. they are fishing for stuff or trying to screw me just because they feel like it) my attitude and strategy for dealing with them does a complete 180. The only reason I m...

Because you already know you will "win" the game of chicken between a citizen and CBP, but that win does nothing for non-citizens, for whom CBP has potent recourse.
(comment deleted)
> . Not a peep, just dirty looks back and forth. Eventually they had to let me go. Moral of the story is that cops do back down plenty of times but you have to have the will to test them. And it greatly helps if you know the law.

It also helps if you aren't a person of color.

Why wouldn't it be marketed as a feature for leaving the country, not returning? There's a very reasonable case to be made that other countries have substantially worse privacy protections than the US does. Whether or not that's true is a separate conversation, but for the purposes of the border conversation about why you've enabled it, blaming the lack of Constitutional protection in foreign countries seems like a good approach to me.
Good point, but it doesn't need to be anywhere near a majority. If just 1% is travelers use it, it would not trigger more than a few extra questions. Especially if those 1% are mostly computer professionals where deeper questioning hardly ever turns up anything.

One feature I'd like with this travel mode is having a log of every bit of data that was accessed during the trip. At least then I would know how much was copied. Some kind of rate limiting would be good too, so they cannot just copy everything.

> I think it's crazy that people walk around with phones that have access to years of email communications

The one anti-pattern on every website is using your primary email address for both notifications and password resets. There is zero reason why you'd ever want an email address you have authed on your phone to handle Facebook/Twitter password resets, but the only way to avoid this is if you're willing to give up receiving whatever notifications you'd normally want to receive via email on your phone.

> There is zero reason why you'd ever want an email address you have authed on your phone to handle Facebook/Twitter password resets

There's a really obvious reason: because you need to reset your password while on the go.

You can set a filter to only forward certain notifications.
It can be effective immediately.

Where do we have all this AI for?

+ Facebook can make a filter that only displays a tiny subset of all posts. A filter that only displays a tiny subset of my friends.

+ Gmail can make a filter that shows only a subset of my emails.

+ Preferably the AI can then fill it up with stuff. :-)

In this way it all looks perfectly fine. There is only way less info in it.

This would save me time from making accounts for traveling purposes.

> I think it's crazy that people walk around with phones that have access to years of email communications

You think its crazy in you wish you (and everyone else) had a viable alternative? Or, you think its crazy in that you do something else that others don't do?

If the latter, what do you do?

I have tar files of old maildirs, but they're encrypted and backed up and not readily accessible. My regular mail client has access to a smaller set of mails. Of course this requires an email setup that allows such easy bulk operations, which gmail isn't really.
I have the same setup with gmail. It really wasn't that hard to export a chunk by date, upload it to tarsnap, and delete the originals
It seems like there is an inherent trade-off here between the usefulness and vulnerability of our systems.

Each feature we add for our own convenience makes a more tempting prize for a potential adversary.

Edit: Whether or not a particular feature/behaviour is reasonable or crazy depends entirely on the level of threat.

> I think it's crazy that people walk around with phones that have access to years of email communications

Why? I thought the whole point of connected, portable computers is for one to have access to pretty much all their data on the go.

Yes, for one.

Much of the point of the cloud shift was to get your data into the ownership of a private company who can make money off it.

If, for example, Apple can make up some lost money on iCloud with new obsidian gunmetal TimeCapsules with plausible deniability and localhost-tunneling features to sell to rich people, I'm sure they will try and do it.

>even in the happiest timeline we could have ended up on after 2016

I'm not really sure why you mentioned this, did something bad happen?

Lots of people seem to be bemoaning 2016 as The Worst Year Evarrr or something.

I am not in that camp and I have my objections to it. But, in this case, I think the sentiment is reasonable wrt the topic at hand, basically.

Read this as "even if <your favorite political candidate> had won the US election"
Yes, an incompetent autoocrat got elected to the highest government office of the most powerful nation on earth. You almost certainly already knew this.
One thing I wonder about is how quickly a travel mode would become grounds for denial of entry.
Or how quickly Facebook/Google/Twitter would comply with some classified FBI/NSA directive to provide the data anyway.

The first mistake is trusting these networks with your personal life in the first place. Nothing can erase that except your ability and willpower to keep your secrets to yourself.

Illegitimate government actions are sort of out of scope for this discussion though (which is about convincing companies to mitigate legitimate government actions).

As for your second point, there's no going back for an awful lot of people. And holding that aside, it's a sad world where using a computer to communicate is somehow a mistake.

Note that CBP does not have access to all the data NSA has gathered. If they did, we wouldn't be talking about this at all; they'd already have everything they wanted.
Relying on dysfunctional communication between portions of government doesn't seem like a sustainable strategy.
It's not dysfunctional communication, it's legally mandated boundaries enforced by an independent judiciary.

Don't cede the thing you're fighting for.

> It's not dysfunctional communication, it's legally mandated boundaries enforced by an independent judiciary.

Do you really think that wouldn't dissolve in the face of "we already have the information, we're just improving communication between government organizations"? They shouldn't collect the information in the first place.

I've already accepted that if the NSA is interested in me, they'll acquire _any_ cloud hosted data about me (and if they're a little more curious, most likely every bit of non-cloud data stored on my personal hardware too).

I _still_ want to be able to defend myself and the people in my social graph against a bored/curious/vindictive/power-tripping CBP agent looking for excuses to meet their "must reject at least $N bearded border crossers per shift" quotas...

It's a real concern for non-citizens. US citizens can't be denied entry.
Right. I was assuming that was reasonably well understood.
I made the same assumption, until I published this article.
They could. CBP can deny any non-citizen entry for just about any reason. They could just start denying all non-citizens all the time, so why don't they? Because it would hurt business, tourism and other countries would retaliate and refuse US citizens entry. That is the power we have. The time to start using Travel Mode is now, before demands for passwords becomes stand procedure at the border.
The time to start using Travel Mode is now, before demands for passwords becomes stand procedure at the border.

Sure. I'm pretty sure I want to activate such a feature for my email on my phone just in general.

Airplane mode: from the end of the microwave peril to the era of alternative inspection, in under 10 years.
It's not like they couldn't make you turn travel mode off if they wanted to. How about pushing for a law closing this 4th amendment loophole at the borders, at least for citizens?

Not that it'd do much. If the border agents really want to see one's social media accounts, I have zero doubt they can get that data from other government agencies. In fact, they probably already have it. It sounds to me like they're just trying to assert their power and dominance over the people whose accounts they are demanding access to as a way to get off on intimidating others. Pretty typical behavior by law enforcement officers the world over.

The idea is that they cannot in fact make you turn travel mode off, because travel mode doesn't turn off. It's a time lock. The point is that while locked, Facebook and Google Mail are still usable; they just don't have your whole history available on them.

If we stipulate that your second paragraph is true, then travel mode is in fact a complete countermeasure to that behavior. (I don't think it's true).

Why wouldn't they just detain you until the time runs out?
Because indefinite detention is not something they can lawfully do (in US, today).

In contrast, suspending 4th amendment at border has been made lawful by the courts.

Ideally it would not be evident that the account is in travel mode.
How can it possible be non-evident?
A travel-locked Facebook account should just look like a quieter Facebook account.
So, pretty evident from the most casual analysis.
I don't think any part of the proposal depends on it not being possible to detect whether an account is travel-locked, but I'm curious about why you think it's so straightforward to tell if an account is locked?

Surely, if this became popular, CBP would simply start asking aliens seeking entry whether their accounts were travel locked. And the standard advice would be, "never lie to CBP".

But I'm still curious about why you think this would be so obvious.

I think that would be difficult to achieve. If it's minimal enough to achieve the goal, it's minimal enough to look like travel mode.

If the only goal is to refuse them access to your account, you can do that already. Your devices will be confiscated, non-citizens will be refused entry, but you can do it if your device encryption is strong enough.

The goal here seems to be to give you the ability to get through the border without giving up your information. If it looks like "trip mode", it's failed at that goal, and I'm not sure it's possible to make it both mainstream and stealthy enough to work.

Because the time lock would be so long as to make it impractical to do that.
Wouldn't that also render your account essentially useless when your trip is over? (Unless you're traveling for, what, years at a time?)
No, again, the point of the travel lock isn't that you can't use Facebook at all, but rather than your history and social graphs are restricted. For most ordinary purposes, Facebook will probably get more usable while travel-locked.
Yeah. Everyone* would be able to see what I’m posting during my trip (which itself could be dangerous…), but no one could see the history until after the trip.

* who is normally allowed to see what is posted in the first place.

They don't have to detain you at all, they just have to deny you entry. Travel mode on? GTFO!

In fact, this is already happening: http://www.dailyxtra.com/canada/news-and-ideas/news/us-custo...

> “They said, ‘Next time you come through, don’t have a cleared phone,’ and that was it. I wasn’t let through.

Technological countermeasures don't seem to work. Sure, they work in the sense that they protect your data, but if the border guy doesn't like you, technology won't save you. You will be sent on your way.

Exactly - the correct solution is that border inspection of luggage (for contraband) NOT be considered a legal basis for searching my information storage.

Warrantless search of gadgets / accounts should be prohibited for citizens. For non-citizens, it should require a significant justification.

Finally, NONE of the data examined at the border should be stored for longer than necessary to reach a go/no-go determination.

While you get to work on repealing 223 years of jurisprudence about border searches, how about we explore things tech companies can do in the immediacy to mitigate their impact?
The idea is that it would be common, like not carrying large amounts of cash. There are good reasons for it other than limiting border searches.

Some people have suggested making travel mode invisible, but it might be better if it showed the start and end dates. Customs will ask anyway, but if the time period covers the entire trip, there's less reason to search the account.

Citizens AND permanent residents. For some reason everyone is just saying citizens. But the whole intention of asking for access to people's accounts is meant to be for verifying they are complying with their visa. [1] E.g. Similar to looking through someone's documents as they cross and seeing a letter that's an offer of work would be cause for refusal if they weren't entering with the correct work permit.

But in the case of citizens and permanent residents both have no cause for this kind of verification. They're allowed to enter for any purpose. So at the very least citizens and permanent residents should not be searched.

[1] I'm not defending the practice or saying this is how it's actually being used, but it is the only actual reasonable justification CBP have for the practice of searching phones.

How do you turn a travel mode off? Once border patrol knows this feature exists and how it works, the jig is up. Any expiration/timeout would just cause you to be detained for the duration the travel mode is enabled. A second password to turn it off would just cause that second password to be coerced out of you. Location-based deactivation can be spoofed.
From the fine article:

> To work effectively, a trip mode feature would need to be... irrevocable for an amount of time chosen by the user once it’s set. There’s no sense in having a ‘trip mode’ if the person demanding your password can simply switch it off, or coerce you into switching it off.

US citizens can't be detained indefinitely at the border. The limit is a few hours.
That's fine for US citizens entering the US, but any 'travel mode' needs to work for the outbound trip too. If the country you're visiting has adopted a US-style border stance, then you're in no better a position than a non-US citizen visiting the US: the border forces of that other country can detain you until travel mode expires if they want. It seems like "They can't hold me for days while they wait for the mode to expire" only works for citizens returning to their own countries.
More likely they'd just send you home. Either way, denying people entry is bad for business and tourism. If enough people want to protect their accounts when they travel, countries will have to weigh the trade-offs.
Sure, it is bad for business. It will likely be used disproportionately on brown people and minorities, just like "random" screenings at the airport. Yes, bad for tourism, but only consistently bad for a minority of the population and most others just have to take of their shoes etc.
So you keep stating but there is no codified limit short of 'indefinite'.

Imagine I am a CBP agent. State your argument that I must release you after, say, 23 hours

US Marshal arriving with a court order compelling my release.
That worked so well when this exact situation happened weeks ago.
You have to fight for the rights you want to keep.
If they get your password can't they just turn of travle mode for you? Or wait until you do the same? I don't know that there is a technical answer here accept wiping your phone/laptop before you go through customes.

The real solution is a political one where we speak up and legeislate and litigate that the 4th amendment applies a the border.

From the article:

> To work effectively, a trip mode feature would need to be easy to turn on, configurable (so you can choose how long you want the protection turned on for) and irrevocable for an amount of time chosen by the user once it’s set. There’s no sense in having a ‘trip mode’ if the person demanding your password can simply switch it off, or coerce you into switching it off.

Then if border agents really want to get in to a particular individual's device, they'll just detain them (or seize their device) until trip mode automatically turns off.
They would be required to detain people for an indeterminate amount of time, potentially weeks. The idea is that it's impractical (and also illegal) for them to do that. If enough people travel-locked their accounts, invasive social media monitoring would be off the table.
Indeterminate? Being a non-citizen with a one way ticket is already pretty good cause for being subject to high scrutiny - this would likely tip the balance in favor of refusal.

Most people have return tickets. So (and don't think for a second I'm in favor of this) they'd know exactly how long your detention would need to be.

Would they? If someone is traveling for a week and presets their social media account to be in travel mode for 1 week, wouldn't they then just need to be detained for a week until the lock expired?
CBP is not allowed to detain US citizens past some nebulous limit measured in hours.
My gut feeling is that non-US citizens are more likely to be affected by this CBP policy than US citizens. Don't get me wrong here, happy if some solutions works for some subset of people, but as a non-US citizen I want something that works for me.
Hey, you have any easy solution: never ever visit the US. The overwhelming majority of non-citizens passing through the border are on some kind of temporary visit, so it's relatively easy to choose to stay the hell away.
That's a very defeatist position (not to mention that this policy is emulated, or will be soon emulated by many other countries). Isolationisms won't help neither the political situation in the world at large, nor the situation in the US right now. The US is a great place to visit, a great place to do business in, and a great place to live in. Not to mention that many, many people that are affected by this policy are non-citizens that are in the process of becoming a citizen (either formally, or not started yet). Or many are employees of some US company living in some other country.

My parents and my partner are in the US. They have lived there for 27 years, but I am not a US citizen. Are you telling me that I should just give up on my family?

Perhaps, but sometimes the realistic option is to admit that you have been defeated, and choose to play a different game instead.

The choice faced by travellers to the US is essentially the same as that faced by all consumers of a product declining in quality: Voice, or Exit.

I agree with you. Non-citizens traveling to the US are in a very bad position right now.
A significant part of why things are bad for non-resident aliens is that protecting your social media accounts is abnormal, so doing it flags you as an anomaly.

But that's not because people don't want to protect their social media accounts. You could probably make decent money with a "travel lock" product that groomed your accounts this way, in fact. The reason nobody does it is that the big cloud services don't offer this as a built-in feature.

So this is a case, it seems to me, where helping citizens will have a knock-on effect of also helping non-resident aliens.

TillE: If your immigrating (this includes green card holders) to the USA, and have lived there for years, that isn't a very practical solution.
No, but they can "tip off" law enforcement who will tap you on the shoulder as soon as you leave the customs area and start the clock again, with different rules.
It doesn't even have to be a time lock, what if you left behind a key or random passcode at home that could be used to switch it off when you return?
The point is to make it impossible even for the owner to disable the lock, so there isn't even a conversation to be had about whether you're a phone call away from getting a family member, friend, or neighbor to read off the passcode to open access to the account.
What about a location or IP-lock? That way the only way to unlock it is to literally bring it to a location inside the US, where Constitutional protections do apply.
This is addressed in the article: you say how long travel mode should last and once set it cannot be undone, even by the owner of the account.
Wiping your stuff does no good at all. As pointed out in the article, they know who is on the flight hours before you land. They'll know you have a Facebook profile. The difference between having a laptop already logged into Facebook and a wiped laptop with no data is quite literally the time it takes them to tell you to type in the password for them. Ignorance isn't an escape clause.

Which is, I think, the same problem Maciel's solution faces. Border patrol can possibly just see that you've enabled "trip mode" (by the anemic presence) and put you back on a plane. You're welcome to try again after your trip mode expires, but if they want to see your account, there is, as sure as mathematical logic, no possible "out". Anything you do to deny them that access can be grounds to refuse you entry (if you're a non-citizen).

You're right that the only real solution is a political one. Unfortunately, there are no political solutions to any problem anymore. Not in the US at least. The days when government was even interested in solving problems are gone and I doubt they're ever coming back.

> The difference between having a laptop already logged into Facebook and a wiped laptop with no data is quite literally the time it takes them to tell you to type in the password for them.

No, that's not how it works. Border agents are entitled to "search" your laptop. They can't force you to retrieve arbitrary data from a remote server.

All this with the caveat that they can, of course, refuse non-citizens for basically any reason.

If you're an at-risk traveler, you'd enable travel-lock pretty much as soon as you decide on your itinerary, potentially before you ever get on an airline manifest.

The thing I think I see a lot of people missing here is that travel-lock doesn't wipe or disable your accounts; it just restricts history and breadth. For a lot of people, I think these services will get easier and more pleasant to use while travel-locked, so it's relatively painless to give yourself a generous margin before departing and after arriving.

I'd turn this feature on my phone right now for gmail just for "lost phone" mitigation.
The problem with that is that CBP can (and surely soon will) compel travelers to log into their accounts from CBP's own equipment.
Sure. But a setting that said "always on mobile" and another one where they schedule it for me based on my airline emails makes uptake faster.

And I want that when I'm traveling anywhere.

[later] we want to normalize the idea that access permission to our data is context aware based on what we are doing. To me this is true independent of border crossings. For instance there are things I want in the cloud for backup purposes that I don't want be able to access from anywhere but home normally.

Yes! Sorry, we were agreeing but I well-actuallied you.
Into their gmail accounts? That seems a little unlikely short of 'looking for any excuse to deny you entry' and there's no technical defense against that.
(comment deleted)
> The difference between having a laptop already logged into Facebook and a wiped laptop with no data is quite literally the time it takes them to tell you to type in the password for them.

I have no idea what most of my passwords are. They're complex strings of ASCII stored in an encrypted file on my personal machine and a few backups. If I travel internationally, I can just leave my personal machine at home.

I don't think that gets you entry into the country though. There's not much difference between can't and won't. I suppose, that if you were a citizen, you could take that up with a judge, but if you're not, you don't even get the opportunity.
> The real solution is a political one where we speak up and legeislate and litigate that the 4th amendment applies a the border.

Considering the tiny percentage of Americans that travel overseas or even hold passports, I'm not sure a political solution is realistic. I think we might be outnumbered by the people who don't care about such privacy issues because it will never affect them.

This is completely naive.

Firstly, social media's only incentive is to make your data as widely available as possible (in the interests of ad revenue), and maintain a good relationship with the government in their jurisdiction. Every other existing "privacy" setting on Facebook, LinkedIn, etc is already obfuscated to the point of unusability, for this reason, and "travel mode" would be no different.

Secondly, lets imagine that FB did implement a watertight "travel mode" that hid your embarrassing data effectively while you were travelling. Third parties would just start capturing and storing posts while you have "travel mode" off, and sell that to CBP, or whoever else wants to pay for it.

He's pointing out what social media companies should do, not predicting that they'll actually do it. That is not naive. Imagine what would happen to the Overton window if we never talked about what people should do, even when we expect them never to do it.
People who care deeply about these issues work at Facebook and Google.
Please clarify: I take your answer as a (fair) response to the first objection, but what about the other ("third parties would just start capturing and storing posts while you have "travel mode" off, and sell that to CBP, or whoever else wants to pay for it")?

Does that possibility worry you? Wouldn't that also put you in a position where you’re lying at the border?

edit: readability

I'm not sure I understand that objection. How will a third party collect non-public information from my Facebook account, or my email?
Maybe the surveillance economy can send a diff or two?

https://boingboing.net/2016/11/13/the-surveillance-economy-h...

I fell strange linking to your own warning...

The surveillance economy is not a magic thing that sees all, though. What's the specific way in which third parties end up with my email and private Facebook data?
Sorry, I don't use Facebook, and I applaud the initiative (as I understand it, it's about limiting the exposure).

I just think that the use of a such a travel mode could be likened to/misconstrued as the practice (perilous, as you indicate), of using a decoy account, given for example, some previous snapshots of any public/semipublic social media activity suddenly invisible for the border agents.

Just trying to get a clearer view of your proposition (I think I'm doing it, thanks for answering!)

That's a statement that's true for all sorts of issues, for all sorts of people, at all sorts of places. But what matters is whether their employer has made them responsible for solving those issues.

What are they paid to do?

They can do whatever they want to do, including organize, work to rule, walk out, or go on strike.
They don't seem to be in positions of any authority though -- see eg realnames. Or maybe this is enough of a threat to the core business for them to care?
This is the problem that trade unions solve.
Facebook and Google also cooperate closely with the US government, law enforcement, intelligence services and state department. How can they be part of the solution when they're part of the problem?
If they already have unlimited access to your account, they wouldn't need to ask for the password. But ok, fine, stipulate that the US knows everything. The feature is still useful for people going to Canada.
(comment deleted)
You also wrote

> They can do whatever they want to do, including organize, work to rule, walk out, or go on strike.

Observationally, they don't organize or go on strike. Maybe some "work to rule", get PIP'd and walked out. Maybe some actually walk out on their own.

In the long run, the "People who care deeply about these issues" get boiled off.

In fact, they probably are largely boiled off by now. Probable, because that's consistent with observable Google behavior.

I see no actual reason beyond "be nice to everybody" to assume a random Googler "cares deeply".

Facebook has incentives to make your data available to advertisers. That does not mean it needs to make your data available to someone who possesses a device that you accessed Facebook from. The point of the idea is that when you turn it on, your data isn't removed, it's simply not accessible via a device until it's turned off.
If a third party could access my private Facebook posts then border patrol wouldn't require my phone in the first place.
I feel it would be quite obvious looking at your device and it's lack of data that such a feature was in force and they would just deny you entry. Nice idea but the problems need fixed in law. IMO technical solutions are just temporary bandaids.
I agree that technical solutions are bandaids. However, US citizens can't be denied entry. They can be delayed for a few hours, not longer.
Your device can be confiscated for much longer, of course. You could take that time difference and hopefully permanently wipe account data before the lock expired, but that has the drawback that it's terribly inconvenient for you and causes the government no great concern at all, so it might simply become routine procedure.
You can imagine a scenario where you leave detention and then de-authorize impounded devices.

The point is not that this is a perfect solution. It's a better solution than the status quo.

There is no technical solution to this. If you want there to be no searches of your phone when crossing the border, speak to your representative in Congress and your Senator. If they don't listen, then vote for someone else or even better, run yourself.

The only way this is going to change is with a change in the law.

I appreciate the sentiment here and think that tech as an industry could do with a lot more humility about its intersection with public policy. I feel like I know the people involved in this proposal well enough to say that they agree with this as well.

The point of the travel-lock proposal is that it's actually common sense. Everyone should want this feature. It is actually weird that we walk around all the time with unfettered access to decades of personal correspondence and a detailed log of every person we've ever meet even fleetingly online. The default should be different: getting access to years-old emails or a photographic memory of every acquaintance you have should be extraordinary.

Yes, for that at least, I agree completely. I'm not sure how much the idea would do for border crossing, but just as a general mitigation of risk, it's extremely sensible.
I feel that all technical modes will fail.

Why?

- We first had PIN numbers. Easyily cracked/defeated.

- We then had passwords. Provide them or go back home where you came from.

- We might have travel mode. Defeated or made illegal. Go back home.

I think the only resolution to this is political. Make these searches go away - worldwide - as we near a very bad precedent.

(comment deleted)
An article with an interesting suggestion and a noble goal but I'm not the first one to say it:

Technology cannot solve the problem we currently face with erosion of privacy at the border! These clever tricks trying to get around the issue only kicks the problem downfield, and likely won't effectively work. If they found out you have travel mode enabled - you may be denied entry or worse (note the comment from @mholt) - they would just detain you until the time lock runs out.

They can't detain US citizens longer than a few hours.
What if I'm a US citizen traveling to Canada, and their border patrol is similarly vigilant? I could be denied entry to Canada.

Sadly this policy is being picked up in many other countries :(

Our border patrol isn't "similarly vigilant". That's a meme being spread by a very dedicated account on HN, probably to seed the grounds for a lot of "whataboutism".
What is actually needed is a dead man's switch: a secondary password that, when entered, destroys the security enclave/TPM to render the device unreadable
Then the border guards send you home. What mission has been accomplished?
I'd been thinking about a similar thing: a "limited access for border guards" mode.

Basically, you can turn over the phone to border guards in a way which gives them access to what is on the phone, but which logs actions, and allows you to easily revert/revoke any changes they make. (This would also be a mode you'd turn over to an employer demanding access).

Potentially this mode might also block access to certain things (secret FB groups, archives over a certain age, some chat logs), but would otherwise be fully functional.

The benefit would mainly be that all actions taken would be logged and reportable, as a way to try to keep authorities from poking in places they shouldn't. It seems they are NOT mostly using forensic imaging tools, but logging in directly on the devices, at least right now, so there would be some value.

Why not go further with the idea of a Travel Mode toggle and have it be tied to the device itself. This cuts out any possibility of any data being left on the device from being analyzed easily, social media or otherwise.

Google and/or Apple could add this as a new menu toggle similar to Airplane mode. Once switched on, while in an airport, prevents the device from being unlocked. Then by utilizing geofencing, once the device leaves the airport it unlocks and can be used again.

What if the border agent takes your phone outside? It would go something like:

> Tell me your password > OK, not sit here while I go out to unlock your phone.

I doubt that border agents will want to walk every phone outside and then come back in. It is security through inconvenience.

But I guess there could be an option to extend the range of the original airport geofence.

<agent presses button that fires up their gps signal jammer and turns on some wifi networks impersonating the Starbucks at Grand Central Station>

(I suspect there's companies already trying to sell them that technology...)

This would make it very difficult to call a Lyft or let your family/friend know you're ready to be picked up.
Didn't Moxie come up with something like this a while back? It was a bit of a non-starter since you had to install a custom version of Android in order to get it work
I think you could easily justify something like this as a "travel mode" not just for border security, but "in case your phone is lost/stolen while traveling". Make it so you have full or enhanced access to very recent stuff (photos, status updates, etc.) from the trip itself, and don't have access to as much from before the trip. Help defeat localization settings in the place where you're traveling, and get tourist/visitor-specific ads instead of local ads. Value for the user (usability and safety) as well as for the social media network and advertisers.

The other form of this which would make sense: worksafe mode or public mode. If you're logging into your facebook/twitter account from a public computer, perhaps it doesn't have as full and unlimited access, and doesn't have access to non-reversible account actions, and strongly logs out. If you're logging in from a place defined as "work", it doesn't have notifications, certain groups, etc. (the "giving a meeting presentation on your laptop when a racy notification from spouse pops up" problem).

Nice idea. But it's treating the symptom rather than the root problem.
I agree. But the practical alternative right now is doing nothing.
Fair enough!

There are many good ideas here and I'll even wager that a 'trip mode' of some sort could even produce benefits outside of the held-at-the-border use case. It really does seem silly at retrospect that these tech giants have decided the default needed to be "expose all of the connections"

In fact, the border case is just an edge case. You also want your accounts protected if you lose your unlocked phone, have it stolen, have your password stolen, log in on a dodgy public computer, plug in an infected USB stick, or leave your laptop unattended in the wrong hotel room.
The root problem is terrorists wanting to kill people.
Inbound foreign travelers to the US have pretty much already been screened.
And in the US, almost all of those terrorists are white male American citizens.
That's not a good excuse for denying ordinary people of their basic rights. There will always be killers anytime, anywhere.
Why is it a bad idea to have fake FB/Gmail/Twitter accounts?
They look you up before you arrive and find out what your real account it.
This isn't very different from refusing to provide login credentials. Sure, turning travel mode on and off could require keys, which are present only on primary devices, which are left at home. So there'd be no need to lie.

However, foreigners would likely be turned back. Because using travel mode is arguably evidence of hiding stuff. And citizens might still be detained. It seems unlikely that they'd send agents to homes, to turn off travel mode. But it's arguably not impossible.

This may be a hugely naive question but what could they do if I simply don't use social media?

Do they automatically suspect someone who denies using it and what would follow in that event?

If you legit don't have a Facebook account, you're fine. The problem is that most people do have them, and it's an extremely bad idea to try to sneak them past CBP.