Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

11–20 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#11
post #7

Isn't the counter simple; they ask for your logins to the 1Password vault? I guess this just adds an extra layer of obfuscation. The most secure way I can think of is to either encrypt your drive (or wipe for travel and online restore once arriving) and physically mail the new password (or hand over to a trusted friend/store location) to the destination. Then there is no way of restoring at the airport. Of course, th…

,,even if you’re asked to unlock 1Password by someone at the border, there’s no way for them to tell that Travel Mode is even enabled.''

It looks similar to hidden partition in TrueCrypt

Re: 1Password Travel Mode: Protect your data when crossing borders

#13
post #7

Isn't the counter simple; they ask for your logins to the 1Password vault? I guess this just adds an extra layer of obfuscation. The most secure way I can think of is to either encrypt your drive (or wipe for travel and online restore once arriving) and physically mail the new password (or hand over to a trusted friend/store location) to the destination. Then there is no way of restoring at the airport. Of course, th…

There are competing reports, but the maximum detention time for US citizens crossing the US border is about four hours.

If you are a foreign citizen, you are looking at about twenty four hours, and then refusal of admittance.

This information is the case for keeping a cheap back up device(s).

Re: 1Password Travel Mode: Protect your data when crossing borders

#14
post #7

Isn't the counter simple; they ask for your logins to the 1Password vault? I guess this just adds an extra layer of obfuscation. The most secure way I can think of is to either encrypt your drive (or wipe for travel and online restore once arriving) and physically mail the new password (or hand over to a trusted friend/store location) to the destination. Then there is no way of restoring at the airport. Of course, th…

They can ask for logins for the vaults they see on your device. But those vaults are the ones you've marked "travel-safe", so you're accepting the risk of these being breached by invasive governmental searches.

However, non-travel-safe vaults a) won't show up on your devices, so they can't ask for what they don't know the existence of, and more importantly b) there is no evidence on the device of "hidden" vaults, or that you're in travel mode, so they doubly don't know the existence of those vaults.

Re: 1Password Travel Mode: Protect your data when crossing borders

#15
post #11
post #7

Isn't the counter simple; they ask for your logins to the 1Password vault? I guess this just adds an extra layer of obfuscation. The most secure way I can think of is to either encrypt your drive (or wipe for travel and online restore once arriving) and physically mail the new password (or hand over to a trusted friend/store location) to the destination. Then there is no way of restoring at the airport. Of course, th…

,,even if you’re asked to unlock 1Password by someone at the border, there’s no way for them to tell that Travel Mode is even enabled.'' It looks similar to hidden partition in TrueCrypt

Any subscription-based 1Password can be accessed from the web. Couldn't they just demand those credentials?

Re: 1Password Travel Mode: Protect your data when crossing borders

#17
post #7

Isn't the counter simple; they ask for your logins to the 1Password vault? I guess this just adds an extra layer of obfuscation. The most secure way I can think of is to either encrypt your drive (or wipe for travel and online restore once arriving) and physically mail the new password (or hand over to a trusted friend/store location) to the destination. Then there is no way of restoring at the airport. Of course, th…

They can ask for logins for the vaults they see on your device. But those vaults are the ones you've marked "travel-safe", so you're accepting the risk of these being breached by invasive governmental searches. However, non-travel-safe vaults a) won't show up on your devices, so they can't ask for what they don't know the existence of, and more importantly b) there is no evidence on the device of "hidden" vaults, or…

How is the web interface handled? Essentially, where do you turn this on and off? Wouldn't it become standard ptotocol to just demand web credentials for 1Password? This feature is only for subscription based 1Password accounts, so it would seem to me it would just be easiest to delete the app and re-download after crossing?

Re: 1Password Travel Mode: Protect your data when crossing borders

#18
Wouldn't an alternative "destroy everything" password be a good idea also ?

Would work like this : When forced to enter / give the password to your vault, you enter/give this one, and everything the vault contains is wiped out before the vault is unlocked.

Re: 1Password Travel Mode: Protect your data when crossing borders

#19
post #2

The implementation looks sound, and it's easy to use. Props to Agile Bits for making this feature a priority. So this is great! -- I think. My only concern is that if the authorities are already suspicious of you, and find no password vaults (or practically nothing in your password vault), they may just detain you until you reveal what you haven't disclosed to them. There's clearly a technical solution to the problem…

Could they try to go with the truecrypt method?

Instead of removing the password data off the device, replace it with "junk" data.

"Low security" accounts that you wouldn't mind the "adversaries" having, sacrificial accounts, or even just a randomly generated selection of fake passwords for a selection of accounts, etc...

It still won't fully protect you (obviously a "targeted" adversary would know that you have an account at "X" with "Y" username and the password in your vault doesn't work for that so tie him up!), but being able to hand over something when being questioned might be better than nothing for some.

Re: 1Password Travel Mode: Protect your data when crossing borders

#20
post #7

Isn't the counter simple; they ask for your logins to the 1Password vault? I guess this just adds an extra layer of obfuscation. The most secure way I can think of is to either encrypt your drive (or wipe for travel and online restore once arriving) and physically mail the new password (or hand over to a trusted friend/store location) to the destination. Then there is no way of restoring at the airport. Of course, th…

There are competing reports, but the maximum detention time for US citizens crossing the US border is about four hours. If you are a foreign citizen, you are looking at about twenty four hours, and then refusal of admittance. This information is the case for keeping a cheap back up device(s).

I thought that, according to the NDAA Obama signed, that the military can detain Americans indefinitely without reason.
Post reply on HN