Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. We knew this was coming, but now the clock is running.

We knew this was coming, but now the clock is running.

Scheduled Pinned Locked Moved Uncategorized
426 Posts 315 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • revk@toot.me.ukR revk@toot.me.uk

    @briankrebs No way I could comply as I use wildcard email addressed (and have hundreds of domains) meaning I literally use a different email address on every form and web site and have no way to know them all. I have also had allocated to me well over a million phone numbers (as part of a junk call thing) - I could probably get a list of those and see if I can blow up the ESTA web site perhaps. And I have no right to give other people's numbers to the US either - does anyone, legally?

    floppyplopper@todon.nlF This user is from outside of this forum
    floppyplopper@todon.nlF This user is from outside of this forum
    floppyplopper@todon.nl
    wrote last edited by
    #327

    @revk @briankrebs@infosec.exchange
    the EU authorities announcing they will arrest anyone returning from FIFA2026 for breaching GDPR will be quite a thing

    1 Reply Last reply
    0
    • crankyotter@disabled.socialC crankyotter@disabled.social

      @briankrebs This is evil. Just straight evil. I guess the 4th amendment is vapor.

      mistheart@masto.esM This user is from outside of this forum
      mistheart@masto.esM This user is from outside of this forum
      mistheart@masto.es
      wrote last edited by
      #328

      @CrankyOtter
      Most likely, when conforted about this point, they will say that the 4th can only be applied to USA citizens.
      Then suddently they will forget how to read international treaties about tourists/business trips/scholarships and such...

      @briankrebs

      frantasaur@mastodon.ieF 1 Reply Last reply
      0
      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

        We knew this was coming, but now the clock is running. From Privacy International:

        "Yesterday the Trump Administration announced a proposed change in policy for travellers to the U.S. It applies to the powers of data collection by the Customs and Border Police (CBP)."

        "If the proposed changes are adopted after the 60-day consultation, then millions of travellers to the U.S. will be forced to use a U.S. government mobile phone app, submit their social media from the last five years and email addresses used in the last ten years, including of family members. They’re also proposing the collection of DNA."

        PI linked to and summarized a Federal Register entry describing the proposed requirements:

        -All visitors must submit ‘their social media from the last 5 years’

        -ESTA (Electronic System for Travel Authorization) applications will include ‘high value data fields’, ‘when feasible’
        ‘telephone numbers used in the last five years’
        -‘email addresses used in the last ten years’
        -‘family number telephone numbers (sic) used in the last five years’
        -biometrics – face, fingerprint, DNA, and iris
        -business telephone numbers used in the last five years
        -business email addresses used in the last ten years.

        Just a moment...

        favicon

        (www.privacyinternational.org)

        The Federal Register entry says comments are encouraged and
        must be submitted (no later than February 9, 2026) to be assured of consideration.

        Federal Register entry: https://www.govinfo.gov/content/pkg/FR-2025-12-10/pdf/2025-22461.pdf

        darkpaw@mstdn.socialD This user is from outside of this forum
        darkpaw@mstdn.socialD This user is from outside of this forum
        darkpaw@mstdn.social
        wrote last edited by
        #329

        @briankrebs Ha! LOLs. No freakin' way am I giving them that information.

        I'll just travel to Canada instead. Much nicer country. Not fascist.

        1 Reply Last reply
        0
        • tgg303@cyberplace.socialT tgg303@cyberplace.social

          @briankrebs right about now, no one should be going to the USA, the only language the 🟠 understands is money, he really doesn't care about people, no matter who they are.

          en3py@onlyarts.socialE This user is from outside of this forum
          en3py@onlyarts.socialE This user is from outside of this forum
          en3py@onlyarts.social
          wrote last edited by
          #330

          @TGG303 @briankrebs given the numbers he's spitting, I'd doubt about his general understanding of numbers (and how percentages work).

          But one thing sure: he knows how to make it work in his own bank account.

          1 Reply Last reply
          0
          • pesky_warlock@ioc.exchangeP pesky_warlock@ioc.exchange

            @briankrebs Apart from tourism, this is completely counter to GDPR, and any international company that has operations in the US is not going to send employees over. They may reconsider investing in the US. This is so short-sighted and heavy handed, typical of this "Administration".

            en3py@onlyarts.socialE This user is from outside of this forum
            en3py@onlyarts.socialE This user is from outside of this forum
            en3py@onlyarts.social
            wrote last edited by
            #331

            @pesky_warlock @briankrebs the times a US company violated GDPR rules... after Snowden's statements we shouldn't really expect anything else.

            1 Reply Last reply
            0
            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

              We knew this was coming, but now the clock is running. From Privacy International:

              "Yesterday the Trump Administration announced a proposed change in policy for travellers to the U.S. It applies to the powers of data collection by the Customs and Border Police (CBP)."

              "If the proposed changes are adopted after the 60-day consultation, then millions of travellers to the U.S. will be forced to use a U.S. government mobile phone app, submit their social media from the last five years and email addresses used in the last ten years, including of family members. They’re also proposing the collection of DNA."

              PI linked to and summarized a Federal Register entry describing the proposed requirements:

              -All visitors must submit ‘their social media from the last 5 years’

              -ESTA (Electronic System for Travel Authorization) applications will include ‘high value data fields’, ‘when feasible’
              ‘telephone numbers used in the last five years’
              -‘email addresses used in the last ten years’
              -‘family number telephone numbers (sic) used in the last five years’
              -biometrics – face, fingerprint, DNA, and iris
              -business telephone numbers used in the last five years
              -business email addresses used in the last ten years.

              Just a moment...

              favicon

              (www.privacyinternational.org)

              The Federal Register entry says comments are encouraged and
              must be submitted (no later than February 9, 2026) to be assured of consideration.

              Federal Register entry: https://www.govinfo.gov/content/pkg/FR-2025-12-10/pdf/2025-22461.pdf

              finchhaven@sfba.socialF This user is from outside of this forum
              finchhaven@sfba.socialF This user is from outside of this forum
              finchhaven@sfba.social
              wrote last edited by
              #332

              @briankrebs

              Looks like #CBP / #ICE is out in Italy doing a little advance work:

              "US to send ICE agents to Winter Olympics, prompting Italian anger"

              "The governor of Lombardy region, Attilio Fontana, sought to calm the situation, suggesting that ICE agents would be deployed in Italy to protect US Vice President JD Vance and Secretary of State Marco Rubio.Olympics, prompting Italian anger"

              Which should be the work of the US Secret Service, last time I heard...

              Here: https://www.bbc.com/news/articles/c5y29xzjdzvo

              frantasaur@mastodon.ieF 1 Reply Last reply
              0
              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                We knew this was coming, but now the clock is running. From Privacy International:

                "Yesterday the Trump Administration announced a proposed change in policy for travellers to the U.S. It applies to the powers of data collection by the Customs and Border Police (CBP)."

                "If the proposed changes are adopted after the 60-day consultation, then millions of travellers to the U.S. will be forced to use a U.S. government mobile phone app, submit their social media from the last five years and email addresses used in the last ten years, including of family members. They’re also proposing the collection of DNA."

                PI linked to and summarized a Federal Register entry describing the proposed requirements:

                -All visitors must submit ‘their social media from the last 5 years’

                -ESTA (Electronic System for Travel Authorization) applications will include ‘high value data fields’, ‘when feasible’
                ‘telephone numbers used in the last five years’
                -‘email addresses used in the last ten years’
                -‘family number telephone numbers (sic) used in the last five years’
                -biometrics – face, fingerprint, DNA, and iris
                -business telephone numbers used in the last five years
                -business email addresses used in the last ten years.

                Just a moment...

                favicon

                (www.privacyinternational.org)

                The Federal Register entry says comments are encouraged and
                must be submitted (no later than February 9, 2026) to be assured of consideration.

                Federal Register entry: https://www.govinfo.gov/content/pkg/FR-2025-12-10/pdf/2025-22461.pdf

                gumnos@mastodon.bsd.cafeG This user is from outside of this forum
                gumnos@mastodon.bsd.cafeG This user is from outside of this forum
                gumnos@mastodon.bsd.cafe
                wrote last edited by
                #333

                @briankrebs

                the "email addresses used in the last ten years" is ludicrous. I use catch-all email-addresses and hand out concocted addresses liberally. They expect me to remember every "joesblog@mydomain.example.com" address ever used?

                And every family-member's phone-number used? I barely remember my wife's phone-number let alone relatives I sporadically call via the phone.

                (I mean, the rest is pretty over-the-top too, so the whole "avoid the US" is good advice regardless, but some elements are nigh-impossible)

                gumnos@mastodon.bsd.cafeG drscriptt@oldbytes.spaceD 2 Replies Last reply
                0
                • auxonic@ottawa.placeA auxonic@ottawa.place

                  @revk not to mention that the form validation would probably reject that short domain that gives your trouble sometimes

                  revk@toot.me.ukR This user is from outside of this forum
                  revk@toot.me.ukR This user is from outside of this forum
                  revk@toot.me.uk
                  wrote last edited by
                  #334

                  @auxonic Not mentioning the @fuck.me.uk email addresses 🙂

                  klefstadmyr@social.vivaldi.netK 1 Reply Last reply
                  0
                  • revk@toot.me.ukR revk@toot.me.uk

                    @briankrebs No way I could comply as I use wildcard email addressed (and have hundreds of domains) meaning I literally use a different email address on every form and web site and have no way to know them all. I have also had allocated to me well over a million phone numbers (as part of a junk call thing) - I could probably get a list of those and see if I can blow up the ESTA web site perhaps. And I have no right to give other people's numbers to the US either - does anyone, legally?

                    tautology@infosec.exchangeT This user is from outside of this forum
                    tautology@infosec.exchangeT This user is from outside of this forum
                    tautology@infosec.exchange
                    wrote last edited by
                    #335

                    @revk @briankrebs Yeah I'm like you and have used hundreds of different email addresses, depending on context.

                    And in terms of family telephone numbers, what definition of family are they using, does this include spouse? Children? Siblings? Parents? Cousins? Niblings? I'm not certain I even have some of their phone numbers. What about if said family members are juvenile?

                    In terms of social media, what counts? Discord? Forums? What if my social media accounts (like FB and LI) is restricted, do I need to give them access to it?

                    Terrible idea.

                    revk@toot.me.ukR 1 Reply Last reply
                    0
                    • tautology@infosec.exchangeT tautology@infosec.exchange

                      @revk @briankrebs Yeah I'm like you and have used hundreds of different email addresses, depending on context.

                      And in terms of family telephone numbers, what definition of family are they using, does this include spouse? Children? Siblings? Parents? Cousins? Niblings? I'm not certain I even have some of their phone numbers. What about if said family members are juvenile?

                      In terms of social media, what counts? Discord? Forums? What if my social media accounts (like FB and LI) is restricted, do I need to give them access to it?

                      Terrible idea.

                      revk@toot.me.ukR This user is from outside of this forum
                      revk@toot.me.ukR This user is from outside of this forum
                      revk@toot.me.uk
                      wrote last edited by
                      #336

                      @tautology @briankrebs It is terrible, but there are people with no "social media", and whose phone is in fact a phone not a mobile computer. Would I even get an ESTA if I said I had no social media? And go me a dumb phone.

                      revk@toot.me.ukR 1 Reply Last reply
                      0
                      • revk@toot.me.ukR revk@toot.me.uk

                        @tautology @briankrebs It is terrible, but there are people with no "social media", and whose phone is in fact a phone not a mobile computer. Would I even get an ESTA if I said I had no social media? And go me a dumb phone.

                        revk@toot.me.ukR This user is from outside of this forum
                        revk@toot.me.ukR This user is from outside of this forum
                        revk@toot.me.uk
                        wrote last edited by
                        #337

                        @tautology @briankrebs To be honest, if I *had* to go to US (like that would happen) it would be worth changing my name, getting a new passport in that uniquely rare name, and getting a totally dumb phone on a totally new number, and going as an "oldie" - or even not having a phone.

                        wink@chaos.socialW 1 Reply Last reply
                        0
                        • farbel@mas.toF farbel@mas.to

                          @briankrebs

                          Link Preview Image
                          ben@snac.benbuhse.comB This user is from outside of this forum
                          ben@snac.benbuhse.comB This user is from outside of this forum
                          ben@snac.benbuhse.com
                          wrote last edited by
                          #338
                          You have cpb instead of cbp 😛
                          1 Reply Last reply
                          0
                          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                            @farbel Did you try to send to cbp_pra@cbp.dhs.gov? Did you get a bounce?

                            ben@snac.benbuhse.comB This user is from outside of this forum
                            ben@snac.benbuhse.comB This user is from outside of this forum
                            ben@snac.benbuhse.com
                            wrote last edited by
                            #339
                            I was getting a bounce until I realized I was writing CPB_PRA instead of CBP_PRA 🤦

                            CC: @farbel@mas.to
                            1 Reply Last reply
                            0
                            • gumnos@mastodon.bsd.cafeG gumnos@mastodon.bsd.cafe

                              @briankrebs

                              the "email addresses used in the last ten years" is ludicrous. I use catch-all email-addresses and hand out concocted addresses liberally. They expect me to remember every "joesblog@mydomain.example.com" address ever used?

                              And every family-member's phone-number used? I barely remember my wife's phone-number let alone relatives I sporadically call via the phone.

                              (I mean, the rest is pretty over-the-top too, so the whole "avoid the US" is good advice regardless, but some elements are nigh-impossible)

                              gumnos@mastodon.bsd.cafeG This user is from outside of this forum
                              gumnos@mastodon.bsd.cafeG This user is from outside of this forum
                              gumnos@mastodon.bsd.cafe
                              wrote last edited by
                              #340

                              A quick bit of shell-scripting against my Inbox maildir shows 38 unique addresses just there, and that doesn't consider all the mail in folders.

                              Digging though the whole mail-tree turns up 461 unique addresses. 😑

                              find ~/Mail -type f -name '*:*' -print0 |
                              xargs -0 awk -F" *: *" '/^$/{nextfile} {$0 = tolower($0)} $1 =="to" || $1 == "cc" || $1 == "envelope-to"{print $2}' * |
                              sed 's/.*<\([^>]*\)>.*/\1/g;s/, */,/g' |
                              tr , '\012' |
                              grep $MYDOMAIN |
                              sort -u |
                              wc -l

                              1 Reply Last reply
                              0
                              • revk@toot.me.ukR revk@toot.me.uk

                                @auxonic Not mentioning the @fuck.me.uk email addresses 🙂

                                klefstadmyr@social.vivaldi.netK This user is from outside of this forum
                                klefstadmyr@social.vivaldi.netK This user is from outside of this forum
                                klefstadmyr@social.vivaldi.net
                                wrote last edited by
                                #341

                                @revk @auxonic I wonder if the Norwegian address @fuck.no is taken.

                                revk@toot.me.ukR 1 Reply Last reply
                                0
                                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                  @ferricoxide there's an email address listed in the Federal Register entry: CBP_
                                  PRA@cbp.dhs.gov. Submissions have to include the OMB Control Number 1651-0111.

                                  ferricoxide@blahaj.zoneF This user is from outside of this forum
                                  ferricoxide@blahaj.zoneF This user is from outside of this forum
                                  ferricoxide@blahaj.zone
                                  wrote last edited by
                                  #342

                                  @briankrebs@infosec.exchange Ah. Thank you! I was looking for the wrong string. Once I had the email address, I could search for that and get:

                                  ADDRESSES: Written comments and/or suggestions regarding the item(s) contained in this notice must include the OMB Control Number 1651–0111 in the subject line and the agency name. Please submit written comments and/or suggestions in English. Please use the following method to submit comments: Email: Submit comments to: CBP_ PRA@cbp.dhs.gov. FOR FURTHER INFORMATION

                                  1 Reply Last reply
                                  0
                                  • cascheranno@hachyderm.ioC This user is from outside of this forum
                                    cascheranno@hachyderm.ioC This user is from outside of this forum
                                    cascheranno@hachyderm.io
                                    wrote last edited by
                                    #343

                                    @jimfl @AAKL @briankrebs not enough ketchup squandered to make up the trillions in tourism impacts over decades.

                                    1 Reply Last reply
                                    0
                                    • revk@toot.me.ukR revk@toot.me.uk

                                      @tautology @briankrebs To be honest, if I *had* to go to US (like that would happen) it would be worth changing my name, getting a new passport in that uniquely rare name, and getting a totally dumb phone on a totally new number, and going as an "oldie" - or even not having a phone.

                                      wink@chaos.socialW This user is from outside of this forum
                                      wink@chaos.socialW This user is from outside of this forum
                                      wink@chaos.social
                                      wrote last edited by
                                      #344

                                      @revk If you're so lucky as to be able to change your name at all (to my limited understanding it does not even compare between DE and UK for example)

                                      revk@toot.me.ukR 1 Reply Last reply
                                      0
                                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                        @ferricoxide there's an email address listed in the Federal Register entry: CBP_
                                        PRA@cbp.dhs.gov. Submissions have to include the OMB Control Number 1651-0111.

                                        ferricoxide@blahaj.zoneF This user is from outside of this forum
                                        ferricoxide@blahaj.zoneF This user is from outside of this forum
                                        ferricoxide@blahaj.zone
                                        wrote last edited by
                                        #345

                                        @briankrebs@infosec.exchange

                                        Email sent. Hopefully my submission was sufficiently-conformant that it won't end up on the discard-pile. Hopefully, it was adequately-expressive of my perceived personal impacts to actually mean something to whoever reads — though, I guess, at this point, that would be "whatever AI processes" — it.

                                        1 Reply Last reply
                                        0
                                        • klefstadmyr@social.vivaldi.netK klefstadmyr@social.vivaldi.net

                                          @revk @auxonic I wonder if the Norwegian address @fuck.no is taken.

                                          revk@toot.me.ukR This user is from outside of this forum
                                          revk@toot.me.ukR This user is from outside of this forum
                                          revk@toot.me.uk
                                          wrote last edited by
                                          #346

                                          @klefstadmyr @auxonic % No match

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups