Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Under the assumption that this framework is somewhat sane and only shares biometric data of those people who actually request an ESTA, I don't see the issue.

    This data already leaks whenever you travel legally to the US, because they take it from you as a requirement of entry. All this does is let them check the data they take on entry against the provided data. Which seems fair. The fact this data is already in passports is a very different matter, but that is something the EU has done voluntarily.

  • > those people who actually request an ESTA

    I order to know who actually requested it, information needs to be shared that previously was not. (I can think of technical schemes to limit this to less scary recipients and data, but however you do it, some necessary side-effect remains: Citizens of the EU who do not make such request cannot remain entirely unaffected.)

  • As an aside, I always find it amusing that as a British person that have visited both the US and the Schengen area since the new entry/exit system. Both the US and EU have taken my biometric information (i.e fingerprints) but the UK government has not.
  • My UK passport from 8 years ago has biometric info.
  • Unless it has changed recently Germany has no general database of biometric data. Of course law enforcement has for the cases they work on, but for the average passport holder the data gets destroyed once the passport has been accepted by the citizen. So it remains only decentralized in passport chips.

    It's probably an exception in EU.

  • It is exactly the same in Sweden: biometrics are stored only until the passport/ID is manufactured, then destroyed. Only copy is on the chip.

    At least this is what the law says, and how it is supposed to be. Reality on the ground, though? I am skeptical that the implementation is as perfect as the law requires it to be, especially judging by the quality of the average government IT system...

  • I do not agree and do not consent to give away my biometric data. With which authority is this happening? Some are about to loose their job.
  • This is exactly what the EU does for foreigners entering
  • It would be the same if US also shared US nationals fingerprints with EU.
  • So let me get this straight:

    - Currently travelers to the US need to give biometric data each time they enter

    - New DB connection between EU and US for this purpose

    - People will _still_ need to give biometric data each time they enter in order to validate that they carry valid information

    Further more, they claim that _the US_ will only request data from travelers. But, my country doesn't know if I travel and where. So the supposed privacy guarantees are empty claims. It's not 2012 anymore. Everyone knows better, as soon as they get access to that DB, they will start working on scraping all data from it.

    There is 0 upsides to this.

  • What a stupid, hysterical claim. This "sensitive data" is just what's on your passport, fingerprints, criminal history, and terrorism flags (from European agencies), only for people crossing the border. I don't see how you could defend not sharing any of that.
  • ...uhm You are happy to share your home address and everything else to securely identify you to a government acting increasingly erratic? Because I am not. I would be happy if terrorism-flagged people are shared across borders, but not everyone.

    Remember once the dataset is there, it is not ever going to go away, regardless of who is in power

  • It shouldn't be possible for the US to request this data without the passport being physically present at a US entry facility (border, airport checkin scan, consulate) where fingerprints/photos are actually compared.

    Before that point, only passport information tuples should be queryable, i.e., "Is {passport number, name, dob, pob, issue date, expiry} valid?".

    We should remember that the current (and likely future) administration is actively hostile to transgender and intersex people, and persecutes US citizens with changed gender identifiers. Discrimination based on ethnicity is only one Overton-lurch away.

  • This is a good thing for travellers.

    In border security there are generally two camps, one that uses data and intelligence to go after the worst, large-scale criminal operations and networks, and generally makes travelling easy for the average person, and the other is like traditional cops using traditional tactics… the kind that will miss the person smuggling a kilogram of cocaine in their suitcase but will go after the old man who didn’t declare a pair of socks he bought on a trip. They generally make travel awful.

    Support the intelligence-driven side of border security and reject the traditional cop camp.

  • Hey that’s not what “intelligence” means. What you’re arguing for is data-driven automation, taking the human out of the loop. You’re describing “computer says no” level border control, with Google-level human support (ie none) and somehow spinning that as better than real human cops doing what they do best.

    Maybe this resonates in the American case where cops are notoriously undertrained and over-violent, but I gotta say it sounds extremely dystopian to me. All-power computerized control isn’t “intelligence”.

    It’s also a false dichotomy. You can have lots of automation with humans in the loop. Humans can use automation to be faster and this is common.

  • > In border security there are generally two camps

    Well, there is a third camp. Israeli-style bio-social profiling of 100% of travelers.

    That really makes travel awful !

  • > one that uses data and intelligence to go after the worst, large-scale criminal operations and networks

    History shows that the main question with government and data collection is not "what X makes life easier for citizens" but "who collects/uses X and for what purpose". In the happy case, this may be all well and peachy. The case people rightfully worry about is not that case.

  • I want to agree with this. My fear is that governments and corporations love using technology to launder evil shit. Once security is automated, entire groups of people can be quickly and effortlessly disenfranchised by flipping a bool on a server somewhere. No appeal, no recourse, no human faces. You get to find out from some LLM that you aren't allowed in the country anymore because the "algorithm" identitifed you as a risk. uwu so sawd

    It only works if the "intellence-driven security" is being developed in good faith.

  • The same can be said about Flock, or other surveillance state mechanisms.

    It's good for security, it's more convenient than police doing police work.

    Until it's not. Until it's hacked or abused as powerful mechanisms commonly are.

  • I fail to understand the distinction between an ESTA and a visa to be honest. You need to do the paperwork in advance, pay, provide all sort of personal information, and it can be denied, and if approved only for a limited amount of time. Given that both the EU and the UK have reciprocated, it is a fiction that there exists some visa free travel between these 3 zones. And the more hassle you create, the less tourism you will get.
  • The distinction still matters legally and administratively
  • All it means that you do not have to go to the embassy and stand in line
  • Yeah is a far cry from other countries where you can just show up and maybe fill out an A5 form on arrival.
  • If you try actually filling out DS-160 and going through the rest of the process the difference will become really clear.
  • ESTA and visas are two different things:

    - with ESTA, your country of origin is "trusted" and individuals in general undergo a lower level of scrutiny at a US port of entry.

    - with a VISA, you country of origin is "not trusted" and individuals are granted the right to travel to the US after they undergo interviews at an US embassy and get approved.

    Neither is a right to enter the US. Just a right to be transported by air/ship to a US port of entry. If the CBP lets you in it is a different story.

    This is the US version. Other countries have their own rules.

  • It's to get around bilateral arrangements where counties have mutually agreed to not require visas (IE visa-on-arrival).

    This allows doing visa type checks but not technically violating the agreement as it's not called a visa.

  • The amount of data you need to provide for ESTA and a B1/B2 US Visa is not remotely comparable - the visa process has way more steps and requirements.
  • They're identical but countries pretend they're different. I got an evisa when I went to Indonesia and India. For each country, the process involved uploading a picture, filling in some basic details, and paying a fee. I was approved in 30 seconds for each. I'm pretty sure it was automatic.

    ESTA is supposed to be a lower hurdle than a visa. But from what I've heard, approvals take longer and quite a few people get rejected.

    Countries like to pretend they're still visa free, but honestly, it's just a pain in the ass and I'd rather they call it a visa. It's very, very easy to book a plane to a country, see all info indicating its visa free and you can just go, then right as you're about to head out, you decide to check for the 50th time just to be sure... and it turns out there's some "visa free process" for your country called EDtdjvubHHVJVF or some other random assortment of letters that involves a 2 hour application process and 24-72 hours (business days only) for approval results to come in. A visa would be preferable because it's more transparent.

  • It's not clear to me if this would allow access to all biometric data, or "just" to that of people crossing the US border?

    And for the latter, what data are we talking about? If it's mostly fingerprints, don't those already get collected upon crossing the border? And can't they already be read from a passport's chip?

  • If it lets the US use that identity to query European databases and retrieve associated information, that is a much larger change